Identity Service Mediator for Scalable Device Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for enforcing compliance of mobile devices with corporate policies before accessing corporate resources are difficult to scale as more services and client applications are added, requiring a direct connection between corporate services and policy management systems.

Innovation Solution

A method that allows IT administrators to manage device compliance through a common identity management system, enabling conditional access by registering devices with an identity service and a policy management service, without a direct connection, using tokens to indicate compliance status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a direct connection between corporate service and policy management system is established to determine device compliance, then access control reliability is improved, but system complexity and scalability deteriorate

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity service as an intermediary component that mediates between the corporate service and the policy management system. The identity service receives compliance indications from the policy management system and stores them in a database, allowing corporate services to query compliance status without direct connections to the policy management system. This intermediary architecture maintains access control reliability while reducing system complexity and improving scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If direct connections are established for each service to verify device compliance, then policy enforcement accuracy is improved, but scalability deteriorates

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidscalability
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent merges the compliance verification function into a centralized identity service that is shared across multiple corporate services. Instead of each service independently connecting to the policy management system, all services use the common identity service to verify device compliance. This consolidation maintains policy enforcement accuracy while significantly improving scalability as new services can leverage the existing identity service without additional direct connections.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple direct connections are created between services and policy management system, then compliance verification capability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecompliance verification capabilityVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The identity service is designed as a universal component that serves multiple functions: storing device compliance information, verifying compliance status for multiple services, and managing identity credentials. This multi-functional design provides comprehensive compliance verification capability while simplifying operations, as all services interact with a single standardized interface rather than managing multiple direct connections to the policy management system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3195174B1Conditional access to services based on device claims
Publication Date: 2018.08.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3195174B1 patent drawingFigure 1
  • EP3195174B1 patent drawingFigure 2
  • EP3195174B1 patent drawingFigure 3

AI summary

Providing access to one or more resources to a user device. A method includes at a user device, registering with an identity service to obtain an identity credential. The method further includes at the user device, registering with a policy management service by presenting the identity credential. The method further includes at the user device, providing an indication of current state of the user device to the policy management service. The policy management service can then indicate to the identity service the compliance level of the user device. The method further includes the user device receiving a token from the identity service based on the policy management level of the user device as compared to a policy set.