iOS Configuration Profile Validation via SSL Handshake
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile device management solutions exert excessive control over personal devices, making employees reluctant to use them, and alternative approaches cannot leverage configuration profile capabilities to ensure security settings are implemented for a 'workspace' environment, as they lack the ability to validate the presence of a configuration profile.
Innovation Solution
A mobile device application that receives a configuration profile from a policy server, verifies the installation of security-related properties by checking the SSL handshake and client SSL certificate, and ensures access to business-related applications is granted only when the profile is correctly installed, using a loopback URL and https server to validate the presence of the configuration profile.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional MDM servers are used to impose security measures on personal mobile devices, then security control and data protection are improved, but device control complexity and user reluctance increase
Solution Approach 1:
The patent segments the device into two distinct environments: a workspace environment for business applications and a personal environment for user applications. The configuration profile applies security measures only to the workspace environment through specific settings that affect only business-related functions, leaving personal applications unaffected. This segmentation reduces overall control complexity while maintaining security where needed.
Solution Approach 2:
The configuration profile implements local quality by applying different security properties to different parts of the device. Specifically, it sets security attributes (such as encryption requirements, remote wipe capabilities, and passcode policies) only for the workspace container and business applications, while leaving personal data and applications with different or no security restrictions. This targeted approach improves security where necessary without uniformly increasing control complexity across the entire device.
2Ease of operation
If alternative less heavy-handed approaches are used to control only workspace data and applications, then user acceptance and ease of operation are improved, but the ability to validate configuration profile presence and ensure security settings are lost
Solution Approach 1:
The patent implements feedback mechanisms where the configuration profile includes settings that enable the workspace management application to verify its own installation and configuration status. The profile contains specific properties (such as container encryption settings, authentication requirements, and policy enforcement flags) that the application can read and validate to confirm that security measures are properly in place before allowing workspace access.
Solution Approach 2:
The configuration profile is installed and validated in advance before workspace access is granted. The profile pre-configures security settings, encryption parameters, and policy enforcement mechanisms that are verified by the workspace management application during initialization. This preliminary configuration and validation ensures that security measures are confirmed to be in place before any business applications or data are accessed, maintaining measurement precision without requiring continuous heavy-handed control.
3Reliability
If configuration profiles are installed to enforce security policies, then data security and reliability are improved, but device functionality and user autonomy may be restricted
Solution Approach 1:
The configuration profile segments security enforcement to apply only within the workspace container and business applications. Personal applications and data remain outside the scope of MDM-controlled security policies, allowing users to maintain full functionality and autonomy in their personal space while ensuring data security within the business workspace environment.
Solution Approach 2:
The configuration profile applies security measures with local quality by setting different properties for different parts of the device. Business-critical functions receive enhanced security controls (such as mandatory encryption, remote wipe capability, and authentication requirements), while personal functions maintain their original functionality without additional restrictions. This targeted approach preserves device adaptability and versatility overall while ensuring reliability where data security is paramount.
Data Source
AI summary
An application management agent running on a wireless communications device restricts access to device functionality (e.g., applications and device features) unless the application management agent has determined that a particular configuration profile has been installed on the device (after which the application management agent permits access to device functionality, and an operating system of the device enforces policy settings specified in the configuration profile). The application management agent confirms the presence of the configuration profile by initiating an SSL handshake with a client certificate request for a client SSL certificate embedded in the configuration profile. Validation against the embedded client SSL certificate implicitly confirms the presence of the configuration profile and validates the content of the configuration profile.


