Certificate Enrollment for Unmanaged App Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management platforms struggle to ensure secure inter-application communications, especially between applications that are not fully enrolled for management, as they rely on both applications being managed, which poses challenges for unmanaged applications.

Innovation Solution

The approach employs certificate enrollment to enable secure communication between unmanaged and managed applications using a management agent that verifies identities, obtains and manages certificates, and facilitates secure data sharing through a cloud sharing service with TLS mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile device management platforms use traditional management mechanisms requiring both applications to be enrolled, then secure communication between managed applications is achieved, but unmanaged applications cannot participate in secure communication

Engineering Contradiction:
Improvecompatibility with unmanaged applicationsVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a management agent as an intermediary component that runs within the unmanaged application process. This agent acts as a bridge, allowing the unmanaged application to participate in secure communication without requiring full enrollment. The management agent handles certificate enrollment and communication management, enabling the unmanaged application to securely communicate with other managed applications while maintaining its unmanaged status.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the management functionality from the application itself by introducing a separate management agent component. This segmentation allows the unmanaged application to retain its independence while the management agent handles security-related tasks. The management agent can be independently enrolled and managed, while the unmanaged application continues to operate without full management enrollment.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If both applications must be fully enrolled for secure communication, then comprehensive management control is maintained, but the system loses flexibility to work with unmanaged applications

Engineering Contradiction:
Improvesimplicity of integrationVSAvoidmanagement enrollment requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The management agent enables the unmanaged application to self-enroll for certificate-based security without requiring full management enrollment. The agent can automatically obtain certificates and configure security settings, allowing the unmanaged application to participate in secure communication with minimal intervention. This self-service capability simplifies integration while maintaining security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional certificate enrollment is used requiring full management enrollment, then strong authentication is established, but unmanaged applications are excluded from secure communication

Engineering Contradiction:
Improveauthentication strengthVSAvoidapplicability to unmanaged applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The management agent serves as an intermediary that handles certificate enrollment and authentication on behalf of the unmanaged application. This allows the unmanaged application to obtain strong cryptographic authentication without requiring full management enrollment. The agent manages the certificate lifecycle, including enrollment, storage, and usage, maintaining strong authentication while enabling participation from unmanaged applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12081537B2Secure inter-application communication with unmanaged applications using certificate enrollment
Publication Date: 2024.09.03 OMNISSA LLC
  • US12081537B2 patent drawing
  • US12081537B2 patent drawing
  • US12081537B2 patent drawing

AI summary

Disclosed are various approaches for secure inter-application communication with unmanaged applications using certificate enrollment. A certificate signing request can be received from an unmanaged application via an inter-application communication method supported by an operating system of a computing device, and an identity of the unmanaged application can be verified. The certificate signing request can be provided to a certifying authority, and a certificate can be received from the certifying authority. The certificate can be provided to the unmanaged application.