Cloud-Based Mobile Device Management Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing mobile device management (MDM) solutions require organizations to install and maintain third-party MDM servers, incurring additional capital and time expenses for IT administrators, and are complex to manage, especially when enforcing policies across multiple devices.
Innovation Solution
A Software as a Service (SaaS) model for MDM that allows IT administrators to remotely enforce policies, configure, and manage mobile devices without the need for an MDM server within the organization's IT environment, using a cloud-based console to manage policies, enforce compliance, and secure data access, including geofencing and application whitelisting/blacklisting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations install and maintain third-party MDM servers, then they can enforce policies and manage mobile devices, but they incur additional capital expenditure and time expenses
Solution Approach 1:
The patent introduces a cloud-based MDM service as an intermediary between the organization and mobile devices. Instead of deploying physical MDM servers on-premises, the organization accesses MDM capabilities through cloud services, eliminating the need for capital expenditure on server hardware while maintaining full policy enforcement capability. The cloud service acts as a mediator that provides all MDM functions remotely.
Solution Approach 2:
The patent replaces the mechanical/physical MDM server infrastructure with a software-based cloud service. The physical server system is substituted with virtualized cloud computing resources, transforming the MDM deployment from a capital-intensive hardware model to an operational expense software subscription model, thereby reducing capital expenditure while maintaining functionality.
2Reliability
If organizations install and maintain third-party MDM servers, then they can manage mobile devices, but it requires additional time and effort from IT administrators
Solution Approach 1:
The cloud-based MDM service is designed to be self-service oriented, allowing IT administrators to manage mobile devices through web-based interfaces and automated processes. The system automatically handles device enrollment, policy deployment, and compliance monitoring without requiring manual server maintenance, reducing the time IT administrators spend on routine tasks while maintaining full device management capability.
3Reliability
If organizations use traditional MDM servers, then they can enforce policies across devices, but the system becomes complex to manage
Solution Approach 1:
The patent extracts the MDM server functionality from the organization's on-premises infrastructure and relocates it to cloud-based services. This extraction simplifies the organization's IT environment by removing complex server installation, configuration, and maintenance tasks, while retaining full policy enforcement capability through the cloud service provider's managed infrastructure.
4Reliability
If organizations deploy MDM servers on-premises, then they have full control over device management, but they bear the burden of installation, integration, and maintenance
Solution Approach 1:
The cloud-based MDM service acts as an intermediary that provides organization-controlled device management without requiring on-premises infrastructure. The service maintains organizational control over policies and device configurations while handling all installation, integration, and maintenance burdens, effectively transferring the deployment complexity from the organization to the service provider.
Data Source
AI summary
Technology is disclosed for implementing a mobile device management service. The technology includes a first computing device behind a first firewall, for providing device management as a software as a service that is configured to (a) receive one or more policies from an entity, the entity managing a second server computing device that is behind a second firewall, wherein the first firewall and the second firewall are different firewalls, further wherein at least one of the received policies is indicated to pertain to a group of mobile computing devices; and (b) upon receiving a communication from a mobile computing device belonging to the group of mobile computing devices, transmit to the mobile computing device the received policy pertaining to the group of mobile computing devices, wherein the received policy specifies a condition for future communications between the mobile computing device and the second server computing device.


