Dynamic Enterprise Policy Adaptation via Violation Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Mobile Application Management (MAM) systems face challenges in dynamically adapting and enforcing enterprise policies across a diverse set of users, apps, and devices, often requiring manual administration and lacking adaptability to changing usage patterns and security needs.
Innovation Solution
A method for dynamically modifying enterprise usage policies by a policy management server, which receives policy violation notices, determines modification precedence, and adjusts conditions and restrictions to create a modified policy, allowing for broader application and more restrictive access controls, and can restore previous settings if violations cease.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If enterprise policies are manually administered and statically enforced, then policy administration is simple and predictable, but the system lacks adaptability to changing usage patterns and security needs
Solution Approach 1:
The patent implements dynamic policy modification by automatically adjusting policy conditions and restrictions based on detected policy violations. The system transitions from static manual policy administration to dynamic automated policy enforcement, where policies adapt in real-time to changing usage patterns and security threats without requiring manual reconfiguration.
Solution Approach 2:
The system establishes a feedback loop where policy violations are detected, analyzed, and used to trigger automatic policy modifications. The violation detection mechanism provides continuous feedback to the policy management system, enabling adaptive response to security incidents and usage pattern changes while maintaining automated control.
2Reliability
If policy restrictions are made more narrow and specific, then security control is enhanced, but the complexity of policy administration increases
Solution Approach 1:
The patent enables self-service policy administration where the system automatically modifies its own policies based on detected violations. The automated policy modification mechanism eliminates the need for manual policy administration even for narrow and specific security controls, as the system autonomously adjusts conditions and restrictions in response to security events.
Solution Approach 2:
The system dynamically changes policy parameters such as conditions and restrictions based on violation patterns. By automatically adjusting these parameters in response to security incidents, the system achieves enhanced security control through narrow and specific policies without increasing administrative complexity, as the changes are driven by automated violation detection and analysis.
3Adaptability or versatility
If the system dynamically modifies policy conditions and restrictions in response to violations, then adaptability improves, but the risk of excessive restriction or false positives increases
Solution Approach 1:
The patent implements partial policy modification by selectively adjusting only the necessary policy conditions and restrictions based on specific violation patterns. Rather than applying blanket restrictions, the system modifies policies proportionally to the detected violations, reducing the risk of excessive restriction while maintaining dynamic adaptability to security threats.
Data Source
AI summary
A method includes receiving a notice of a policy violation of an enterprise usage policy by a managed application on a user device wherein the managed application is managed by a mobile application management module on the user device, retrieving the enterprise usage policy from a policy database. The method further includes determining a modification precedence of the active condition and the active restriction, selecting one of the active condition and the active restriction for modification in response to the modification precedence, modifying the selected one of the active condition and the active restriction in response to the notice of the policy violation to provide a modified enterprise usage policy, and transmitting the modified enterprise usage policy to the user device.


