Persistent Device Enrollment via Firmware Deployment Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack efficient methods for enrolling non-APPLE user devices in Unified Endpoint Management (UEM) systems, making it difficult to determine which devices should be enrolled, manage configurations, and ensure secure re-enrollment after device wipe or decommissioning, with no centralized tracking and remote control options available for administrators.

Innovation Solution

The implementation of a system that enables persistent enrollment for user devices through an administrator console, using a deployment agent loaded into the BIOS, which automatically enrolls devices upon boot and allows remote control of enrollment status, ensuring secure and centralized management of device configurations and policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual device enrollment is performed, then device security and configuration control are improved, but administrative workload and time consumption increase significantly

Engineering Contradiction:
Improvedevice securityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables devices to automatically enroll themselves in the UEM system upon first boot by executing enrollment software stored in the firmware. The device autonomously contacts the enrollment service, transmits device information, and receives configuration without requiring manual administrator intervention, thus maintaining security while dramatically reducing enrollment time and administrative workload.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The enrollment software is pre-loaded into the device firmware during manufacturing, before the device is deployed to users. This preliminary preparation ensures that the device is capable of automatic enrollment from its first boot, eliminating the need for manual setup and allowing immediate integration into the UEM system while maintaining security policies.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If individual device configuration is required before enrollment, then device customization is improved, but user security risks and policy circumvention opportunities increase

Engineering Contradiction:
Improvedevice configuration flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs device configuration and enrollment automatically during the boot process before the user can access the operating system. The enrollment software executes in advance, secures the device with UEM policies, and only then allows user access, thereby eliminating the security gap that would otherwise exist during manual configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of allowing user access first and then applying security policies, the system inverts the sequence by applying security policies and completing enrollment before the user can access the device. This reversal ensures that security measures are in place from the moment the device starts, preventing policy circumvention while still allowing necessary configurations.

Inventive Principle:
Principle #13The other way round (Inversion)

3Productivity

If devices can be decommissioned from UEM, then device lifecycle management is improved, but risk of unauthorized re-enrollment and data theft increases

Engineering Contradiction:
Improvedevice lifecycle management efficiencyVSAvoidenrollment control security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements a feedback mechanism where the enrollment service continuously monitors device status and communicates with the device to verify its enrollment state. When a device is decommissioned, the system provides feedback to the device to prevent re-enrollment, and the enrollment software checks this status before allowing enrollment, creating a closed-loop control system that maintains security while enabling lifecycle management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-action by implementing checks and controls that prevent unauthorized re-enrollment before it can occur. The enrollment service maintains a record of decommissioned devices and blocks them from re-enrolling, and the enrollment software on the device verifies this blocking status before proceeding with enrollment, thereby preventing potential security breaches in advance.

Inventive Principle:
Principle #9Preliminary anti-action

4Adaptability or versatility

If no centralized tracking system exists, then device diversity compatibility is improved, but ability to track and manage device configurations is reduced

Engineering Contradiction:
Improvemulti-vendor device compatibilityVSAvoiddevice configuration tracking
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The enrollment service is designed as a universal system that can handle devices from multiple vendors and operating systems through a standardized interface. The service receives device information in a common format and applies unified enrollment procedures, enabling the system to track and manage diverse devices centrally without requiring vendor-specific implementations, thus maintaining both compatibility and tracking capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11868787B2Managing persistent enrollment of a user device
Publication Date: 2024.01.09 OMNISSA LLC
  • US11868787B2 patent drawing
  • US11868787B2 patent drawing
  • US11868787B2 patent drawing

AI summary

Systems and methods are included for managing persistent enrollment of a user device. The persistent enrollment can be controlled by an administrator at an administrator console. The administrator can enable or disable persistent enrollment for the user device at the admin console. A deployment agent can be provided to the user device. During the boot process, the deployment agent can verify the persistent enrollment status of the user device. The deployment agent can retrieve and install a software package for a management agent. The management agent can enroll the user device with an enterprise under a staging user profile. The management agent can install a provisioning package associated with the staging user profile. The management agent can receive user input login credentials. The management agent can change the ownership of the user device with the enterprise. The management agent can configure the user device for the user profile.