Dynamic Account and Device Management via Delegate Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing personal computing devices and monitoring data within a corporate setting becomes increasingly challenging due to the complexity of integrating multiple management systems and accounts, especially with Bring Your Own Device (BYOD) policies.

Innovation Solution

A system and method for dynamic account and device management that allows for the delegation of authority through various communication methods, such as emails, text messages, or URL links, enabling seamless network access and control across corporate, enterprise, residential, and private networks, using a management module that interacts with personal user accounts to grant and manage delegate authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple management systems and accounts are used to manage personal devices in a corporate setting, then device management coverage is improved, but system complexity increases

Engineering Contradiction:
Improvedevice management coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple management systems and accounts into a unified management interface. The system integrates personal device management with corporate network access control, allowing a single system to perform functions that previously required separate management tools and accounts, thereby reducing overall system complexity while maintaining comprehensive device management coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The management system is designed to be universal, supporting multiple device types, operating systems, and network environments through a single platform. It can manage personal devices across corporate, enterprise, residential, and private networks, eliminating the need for separate specialized systems for different device categories or network types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If dynamic delegate authority is implemented for device management, then ease of operation is improved, but security risks may increase

Engineering Contradiction:
Improvedevice management easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic delegate authority where management permissions are not static but adapt based on device posture, network context, and security requirements. Delegates can be granted temporary or conditional access rights that automatically adjust based on the device's compliance status and the specific network environment, making operation easier while maintaining security through context-aware authorization.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors device posture and security compliance, providing feedback that influences delegate authority levels. If a device meets security requirements, delegates gain broader access rights; if compliance deteriorates, authority is automatically restricted. This feedback mechanism enables easy operation for compliant devices while maintaining security through automated enforcement of policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2862318B1Techniques for providing dynamic account and device management
Publication Date: 2019.07.31 GEN DIGITAL INC
  • EP2862318B1 patent drawingFigure 1
  • EP2862318B1 patent drawingFigure 2
  • EP2862318B1 patent drawingFigure 3

AI summary

Techniques for providing data in dynamic account and device management are disclosed. In one particular exemplary embodiment, the techniques may be realized as a system for providing data in dynamic account and device management. The system may comprise one or more processors communicatively coupled to a network. The one or more processors may be configured to identify a user device to be managed. The one or more processors may be configured to transmit a request for delegate authority to manage the user device. The one or more processors may be configured to receive delegate authority to manage the user device. The one or more processors may be configured to provide network access to the user device. The one or more processors may also be configured to manage the user device and monitor data communicated to and from the user device.