Dynamic Policy Control for Mobile Devices via Dual-Channel Notifications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Mobile Device Management (MDM) systems require lengthy redeployment and republishing of applications to update policies, and cannot granularly control device functions without affecting all users, leading to inefficiencies and compliance issues.
Innovation Solution
A system and method for dynamically updating policies on user devices via policy notifications, using primary and alternate communications channels to ensure policy updates are applied without user intervention or application redeployment, allowing granular control of device functions based on user actions and location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MDM policies are implemented to control device functions, then security compliance is improved, but device functionality is overly restricted affecting all users
Solution Approach 1:
The patent implements application-specific policy controls that allow different security policies to be applied to different applications on the same device. Instead of uniformly blocking all screen capture functions across the entire device, the system can selectively control screen capture only within specific applications that contain sensitive information, while allowing it in other applications. This localizes the policy enforcement to where it is actually needed, maintaining security compliance without unnecessarily restricting overall device functionality.
2Manufacturing precision
If policies are hard coded into applications, then policy control precision is improved, but policy update complexity increases
Solution Approach 1:
The patent implements a dynamic policy control system where policies are not statically hard-coded but can be remotely updated and modified without requiring application redeployment. The system allows administrators to change policies in real-time based on changing security requirements, and these updates are pushed to the applications automatically. This dynamic approach maintains precise policy control while eliminating the complexity of manual policy updates and application republishing.
Solution Approach 2:
The patent introduces a policy management server as an intermediary between the application and the policy enforcement mechanism. This server handles policy storage, update distribution, and enforcement coordination, allowing policies to be updated centrally without modifying the application code itself. The intermediary absorbs the complexity of policy management, enabling precise control while simplifying the update process.
3Reliability
If entire device functions are blocked, then security policy enforcement is improved, but user productivity deteriorates
Solution Approach 1:
The patent enables selective policy enforcement at the application level rather than device-wide blocking. Administrators can configure policies to restrict specific functions only within specific applications that handle sensitive data, while leaving other applications and device functions fully operational. This localized approach ensures security policy enforcement where needed without impacting overall user productivity across the device.
4Manufacturing precision
If application redeployment is required for policy updates, then policy accuracy is improved, but update time increases
Solution Approach 1:
The patent implements a dynamic policy update mechanism that allows policies to be modified and pushed remotely without requiring application redeployment or republishing. When a policy needs to be updated, the change is made on the policy management server and automatically distributed to the relevant applications, taking effect immediately or at a scheduled time. This dynamic update capability maintains precise policy control while eliminating the time-consuming redeployment process.
Data Source
AI summary
A computer-implemented method, comprises: providing, by a computing device, a policy notification to selected one or more user devices via a primary communications channel to cause the selected one or more user devices to update a policy when the policy notification is received by the user device; and providing, by the computing device, an alternate policy to the selected one or more user devices via an alternate communications channel when the selected one or more user devices does not receive the policy notification via the primary communications channel, wherein providing the alternate policy notification causes the selected one or more user devices to update the policy.


