Device-Type Policy Management for Enterprise Content Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management services, such as MDM and MAM, struggle to support a wide range of device types and operating systems, limiting security and IT management controls, and fail to isolate personal and enterprise content effectively, especially in multi-authoritative source environments.

Innovation Solution

The implementation of a device-type based management system that defines community policies and device-community policies to manage enterprise content, using a combination of management services like MDM, MAM, and dedicated tools, allowing for flexible access and security controls across various devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional MDM or MAM services are used to manage enterprise content, then security controls can be implemented, but the system cannot support a wide range of device types and operating systems

Engineering Contradiction:
Improvedevice type supportVSAvoidsecurity control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal device-type based management system that can manage enterprise content across multiple device types (smartphones, tablets, laptops, desktops) and operating systems (iOS, Android, Windows, macOS, Linux) through a single unified platform. The system uses device-type identification and policy mapping to provide universal security controls that adapt to each device category while maintaining consistent enterprise security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If standardized management services are offered to multiple customers, then service delivery is simplified, but the services cannot satisfy specific customer requirements or support all device types

Engineering Contradiction:
Improveservice delivery simplicityVSAvoidcustomer requirement satisfaction
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the management approach by creating distinct device-type policies (smartphone policy, tablet policy, laptop policy, desktop policy) that can be independently configured and applied. Each policy segment addresses specific device characteristics and requirements while being managed through a unified system, allowing standardized service delivery with customized policy segments for different customer needs and device types.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If enterprise content is made accessible on personally owned devices, then employee flexibility increases, but isolating personal and enterprise content becomes difficult

Engineering Contradiction:
Improveemployee access flexibilityVSAvoidcontent isolation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts enterprise content management from the personal device operating system by implementing a separate device-type based management layer. This extraction mechanism allows enterprise content to be delivered and managed independently on personally owned devices through device-type identification and policy-based content provisioning, ensuring that enterprise content remains isolated and secure while maintaining employee access flexibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10116701B2Device-type based content management
Publication Date: 2018.10.30 ENT SERVICES DEV CORP LP
  • US10116701B2 patent drawing
  • US10116701B2 patent drawing
  • US10116701B2 patent drawing

AI summary

Examples of systems and methods for device-type content management are described herein. In an example, at least one of a community policy and a community-device type policy may be generated. The community policy may be generated for a community defined for an enterprise and may be enforced on a plurality of user devices registered with the community. Further, the device-community policy may be enforced on a user device, from among the plurality of user devices, based on a device-type of the user device. The device-community policy may indicate a management service to be used to realize the community policy. Further, a management service agent (MS agent) may be provided to the user device, based on the management service indicated by the device-community policy. The MS agent may provide for managing enterprise content on the user device as indicated by the community policy.