Enterprise Application Store Single Sign-On Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in efficiently controlling and managing mobile devices and applications within their enterprise environments, particularly in ensuring secure access to resources and enforcing policies across diverse devices and platforms.

Innovation Solution

An enterprise application store is implemented, providing single sign-on functionality, mobile device management, and policy updates, allowing administrators to define and enforce policies on applications, and ensuring secure interactions between mobile devices and enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional mobile device management methods are used, then basic device control is possible, but efficient control and management of mobile devices and applications within enterprise environments is insufficient

Engineering Contradiction:
Improveefficiency of controlling and managing mobile devicesVSAvoidcomplexity of management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an enterprise application store as an intermediary system between mobile devices and enterprise resources. This store provides a centralized platform for distributing applications, enforcing policies, and managing device access, thereby improving management efficiency without directly complicating individual devices. The application store acts as a mediator that handles the complexity of enterprise resource management while presenting a simplified interface to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mobile devices are enabled with increasing functions, then user capability and resource access improve, but control over device usage and resource access becomes more difficult

Engineering Contradiction:
Improvefunctionality of mobile devicesVSAvoidease of controlling device usage
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the mobile device environment into managed and unmanaged partitions. The enterprise application store distributes applications to specific partitions based on policy requirements, allowing different levels of control over different device functions. This segmentation enables sophisticated resource access control while maintaining ease of operation for users within each segmented environment.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If applications are freely distributed to mobile devices, then user access to applications is improved, but secure access to enterprise resources cannot be ensured

Engineering Contradiction:
Improveaccess to applicationsVSAvoidsecurity of enterprise resource access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The enterprise application store performs preliminary actions by pre-configuring applications with security policies, authentication credentials, and access controls before distribution to mobile devices. Applications are packaged with embedded security configurations that are enforced automatically upon installation and execution. This preliminary configuration ensures secure access to enterprise resources while maintaining ease of application distribution and user access.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If policy enforcement is implemented across diverse devices and platforms, then security and control are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidcomplexity of policy management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The enterprise application store implements a universal policy management system that can enforce policies across diverse devices and platforms through a single interface. The system uses standardized application packaging and configuration formats that work across different mobile operating systems and device types. This universal approach enables comprehensive policy enforcement while reducing the complexity of managing separate systems for different platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3726816B1Providing an enterprise application store
Publication Date: 2023.08.23 CITRIX SYSTEMS INC
  • EP3726816B1 patent drawingFigure 1
  • EP3726816B1 patent drawingFigure 2
  • EP3726816B1 patent drawingFigure 3

AI summary

Methods, systems, and computer-readable media for providing an application store are presented. In some embodiments, a request for a software application may be received at an application store. Subsequently, the software application may be configured, at the application store, based on a single sign-on credential. The configured software application then may be provided, by the application store, to at least one recipient device associated with the single sign-on credential.