EMM Server Provisioning via Cloud Infrastructure Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise service provisioning systems face challenges in managing access and security when infrastructure service servers are located in cloud computing platforms, requiring complex security procedures and separate setup for enterprise mobility management (EMM) servers and infrastructure service servers, which complicates the provisioning process.

Innovation Solution

A method and system that establishes a trust relationship between an EMM server and an infrastructure service server, allowing the EMM server to provision enterprise services securely through a cloud-based infrastructure service server, using authentication credentials and client certificates to obscure physical topology and enable secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If an administrator accesses the EMM server and infrastructure service server separately to complete enterprise service setup, then the service can be provisioned, but the provisioning process becomes complicated and time-consuming

Engineering Contradiction:
Improveease of service provisioningVSAvoidcomplexity of provisioning process
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent merges the EMM server and infrastructure service server into a single integrated server that performs both functions. This consolidation eliminates the need for administrators to separately access and configure multiple servers, thereby simplifying the provisioning process while maintaining all necessary service delivery capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated server is designed to perform multiple functions - both EMM operations and infrastructure service operations - within a single system. This multi-functionality allows the server to handle enterprise service provisioning, management, and delivery through a unified interface, reducing complexity and improving ease of manufacture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the EMM server is located on-premise and infrastructure service server is in the cloud, then service flexibility is improved, but secure communication and authentication become more complex

Engineering Contradiction:
Improveservice deployment flexibilityVSAvoidcomplexity of security procedures
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

By combining EMM and infrastructure service functions into a single server, the patent eliminates the need for complex inter-server communication and authentication protocols that would be required between on-premise and cloud-based systems. The unified architecture maintains deployment flexibility while simplifying security procedures

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate authentication procedures are implemented for EMM server and infrastructure service server, then security is maintained, but the setup process becomes more complex

Engineering Contradiction:
Improvesecurity of service provisioningVSAvoidease of server setup
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The integrated server implements a unified authentication mechanism that handles both EMM and infrastructure service access through a single authentication process. This eliminates the need for separate authentication procedures while maintaining security, thereby improving ease of operation without compromising reliability

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3232695B1Provisioning enterprise services
Publication Date: 2019.08.14 BLACKBERRY LTD
  • EP3232695B1 patent drawingFigure 1
  • EP3232695B1 patent drawingFigure 2~3
  • EP3232695B1 patent drawingFigure 4~5

AI summary

Systems, methods, and software can be used to share content. In some aspect, an enterprise mobility management (EMM) server receives a command for provisioning a user for an enterprise service at an identity provider (IDP). The EMM server sends a user provisioning request to the IDP. The user provisioning request includes a user identity attribute and a user entitlement attribute, the user identity attribute identifies the user, and the user entitlement attribute indicates an access level associated with the user for the enterprise service. The EMM server receives a user provisioning response from the IDP. The user provisioning response indicates that the user is provisioned at the IDP for the enterprise service.