Federated Mobile Device Management via Trust Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device management systems face challenges in managing client devices across different platforms, as they often prohibit administration by multiple management services simultaneously, leading to cumbersome enrollment processes and potential security risks when sharing enterprise data between organizations without a common element of trust.

Innovation Solution

Federated device management is achieved by establishing a relationship of trust between different management services through identity authentication certificates, allowing the exchange of management data, policies, and rules, enabling seamless management of client devices across multiple platforms while ensuring security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a client device is enrolled with one management service, then device management is established, but the device cannot be administered by another management service simultaneously

Engineering Contradiction:
ImproveAbility to manage device across multiple organizationsVSAvoidEnrollment process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments device management into separate containers - a first container for the first organization's management service and a second container for the second organization's management service. This allows each organization to manage its own portion of the device independently without conflict, enabling multi-organization management while maintaining clear boundaries between management domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a containerization mechanism as an intermediary layer between the device and multiple management services. This container acts as a mediator that allows the device to be enrolled with one management service while still permitting another management service to administer specific portions through separate containers, thus resolving the exclusivity constraint.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If management data is shared between different organizations, then collaborative device management is enabled, but security risks increase without a common element of trust

Engineering Contradiction:
ImproveCross-organization management capabilityVSAvoidSecurity of enterprise data
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments management data into organization-specific containers, where each container holds management data from a specific organization. This segmentation ensures that management data from different organizations remains separated and protected, with each organization's data accessible only to its authorized management service, thereby maintaining security while enabling cross-organization management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by giving each container specific security properties tailored to its organizing organization's requirements. Each container can have its own access controls, encryption, and trust relationships specific to its originating organization, allowing customized security measures for each organization's data without compromising overall system security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11477096B2Federated mobile device management
Publication Date: 2022.10.18 OMNISSA LLC
  • US11477096B2 patent drawing
  • US11477096B2 patent drawing
  • US11477096B2 patent drawing

AI summary

In one example of federated mobile device management, a first management service federates with a second management service based on an exchange of one or more identity authentication certificates. After the management services have federated or affiliated, the first service can enroll a client device for management based on federated management data, where the federated management data includes first device management data of the first management service and second device management data of the second management service. The first service can also identify a change in affiliation associated with at least one of the client device or the second management service and cause the client device to check in for a device management update based on the change in affiliation.