Cloud Service Provisioner with Persistent Agent Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In educational settings in developing countries, end users with administrative rights on client devices can deactivate or disable cloud-based services without authorization, posing a challenge in maintaining secure and persistent provisioning of services like MDM, SSO, and web filtering.

Innovation Solution

An administrative console dynamically selects and manages cloud services on computing devices using a provisioner with an activator module and loader module, ensuring secure installation and maintenance of service agents, even in the face of user attempts to disable them, through secure communication protocols and persistent agent management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If end users are granted administrative rights on client devices for ease of operation, then ease of operation is improved, but service security deteriorates as users can deactivate or disable cloud-based services without authorization

Engineering Contradiction:
Improveease of operationVSAvoidservice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments administrative rights by introducing multiple levels of authentication. The first level allows users to access device functions, while the second level (requiring organization-specific credentials) is needed to modify service provisioning. This segmentation enables ease of operation for daily tasks while protecting service security for critical operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication mechanism between the user and the service provisioning system. When service modification is attempted, an intermediary credential verification process intercepts the action, requiring organization-specific credentials before allowing any changes. This intermediary layer prevents unauthorized service deactivation while maintaining user operational freedom.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud-based services are provisioned on client devices for enhanced security and management, then service management capability is improved, but device complexity increases due to multiple service agents and management layers

Engineering Contradiction:
Improveservice management capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal service agent architecture where a single multi-functional agent handles multiple cloud-based services (MDM, SSO, web filtering, theft protection) rather than requiring separate agents for each service. This universal agent reduces device complexity while maintaining comprehensive service management capability through a consolidated management approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The service provisioning system implements self-service capabilities where the service agent automatically detects, installs, configures, and manages cloud-based services without requiring manual intervention on each device. The system self-provisions services based on organizational policies, automatically updating and maintaining service agents across the device fleet, thereby reducing operational complexity while enhancing management capability.

Inventive Principle:
Principle #25Self-service

3Duration of action of stationary object

If service agents are installed on client devices for persistent service delivery, then service persistence is improved, but ease of removal deteriorates as users cannot easily uninstall services

Engineering Contradiction:
Improveservice persistenceVSAvoidease of removal
Core Design Contradiction:
Duration of action of stationary objectVSEase of operation

Solution Approach 1:

The system applies preliminary anti-action by pre-configuring the service agent with protection mechanisms that prevent unauthorized removal attempts. The agent includes self-protection features that detect and block uninstallation attempts, and requires organization-specific credentials for any removal operation. This preliminary protective action ensures service persistence while controlling the removal process through authorized channels.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system performs preliminary action by pre-establishing the service agent with embedded authentication and protection logic before deployment. The agent is pre-configured with organizational credentials and protection mechanisms that automatically activate upon installation, ensuring persistent service delivery from the outset. Removal operations are pre-restricted to authorized users only, maintaining persistence while providing controlled removal capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902112B2Provisioning persistent, dynamic and secure cloud services
Publication Date: 2024.02.13 INTEL CORP
  • US11902112B2 patent drawing
  • US11902112B2 patent drawing
  • US11902112B2 patent drawing

AI summary

Systems and methods may provide for confirming, by a loader module having administrative rights with respect to a computing device, the operability of an activator module on the computing device. Additionally, the activator module may be used to manage an installation status of one or more service agents or software components on the computing device and making them persistent. In one example, confirming the operability of the activator module includes conducting a presence verification and/or authentication of the activator module, wherein a replacement activator module may be downloaded to the computing device if the presence verification and/or authentication is unsuccessful.