Dynamic Enterprise Policy Adaptation via Violation Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Mobile Application Management (MAM) systems face challenges in dynamically adapting and enforcing enterprise policies across a diverse set of users, apps, and devices, often requiring manual administration and lacking adaptability to changing usage patterns and security needs.

Innovation Solution

A method for dynamically modifying enterprise usage policies by a policy management server, which receives policy violation notices, determines modification precedence, and adjusts conditions and restrictions to create a modified policy, allowing for broader application and more restrictive access controls, and can restore previous settings if violations cease.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprise policies are manually administered and statically enforced, then policy administration is simple and predictable, but the system lacks adaptability to changing usage patterns and security needs

Engineering Contradiction:
Improveadaptability to changing usage patternsVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy modification by automatically adjusting policy conditions and restrictions based on detected policy violations. The system transitions from static manual policy administration to dynamic automated policy enforcement, where policies adapt in real-time to changing usage patterns and security threats without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where policy violations are detected, analyzed, and used to trigger automatic policy modifications. The violation detection mechanism provides continuous feedback to the policy management system, enabling adaptive response to security incidents and usage pattern changes while maintaining automated control.

Inventive Principle:
Principle #23Feedback

2Reliability

If policy restrictions are made more narrow and specific, then security control is enhanced, but the complexity of policy administration increases

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy administration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service policy administration where the system automatically modifies its own policies based on detected violations. The automated policy modification mechanism eliminates the need for manual policy administration even for narrow and specific security controls, as the system autonomously adjusts conditions and restrictions in response to security events.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes policy parameters such as conditions and restrictions based on violation patterns. By automatically adjusting these parameters in response to security incidents, the system achieves enhanced security control through narrow and specific policies without increasing administrative complexity, as the changes are driven by automated violation detection and analysis.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the system dynamically modifies policy conditions and restrictions in response to violations, then adaptability improves, but the risk of excessive restriction or false positives increases

Engineering Contradiction:
Improvedynamic policy adaptationVSAvoidexcessive restriction risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements partial policy modification by selectively adjusting only the necessary policy conditions and restrictions based on specific violation patterns. Rather than applying blanket restrictions, the system modifies policies proportionally to the detected violations, reducing the risk of excessive restriction while maintaining dynamic adaptability to security threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10122758B2Dynamic management of enterprises policies
Publication Date: 2018.11.06 CA TECH INC
  • US10122758B2 patent drawing
  • US10122758B2 patent drawing
  • US10122758B2 patent drawing

AI summary

A method includes receiving a notice of a policy violation of an enterprise usage policy by a managed application on a user device wherein the managed application is managed by a mobile application management module on the user device, retrieving the enterprise usage policy from a policy database. The method further includes determining a modification precedence of the active condition and the active restriction, selecting one of the active condition and the active restriction for modification in response to the modification precedence, modifying the selected one of the active condition and the active restriction in response to the notice of the policy violation to provide a modified enterprise usage policy, and transmitting the modified enterprise usage policy to the user device.