iOS Configuration Profile Validation via SSL Handshake

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management solutions exert excessive control over personal devices, making employees reluctant to use them, and alternative approaches cannot leverage configuration profile capabilities to ensure security settings are implemented for a 'workspace' environment, as they lack the ability to validate the presence of a configuration profile.

Innovation Solution

A mobile device application that receives a configuration profile from a policy server, verifies the installation of security-related properties by checking the SSL handshake and client SSL certificate, and ensures access to business-related applications is granted only when the profile is correctly installed, using a loopback URL and https server to validate the presence of the configuration profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional MDM servers are used to impose security measures on personal mobile devices, then security control and data protection are improved, but device control complexity and user reluctance increase

Engineering Contradiction:
Improvesecurity controlVSAvoidcontrol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the device into two distinct environments: a workspace environment for business applications and a personal environment for user applications. The configuration profile applies security measures only to the workspace environment through specific settings that affect only business-related functions, leaving personal applications unaffected. This segmentation reduces overall control complexity while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The configuration profile implements local quality by applying different security properties to different parts of the device. Specifically, it sets security attributes (such as encryption requirements, remote wipe capabilities, and passcode policies) only for the workspace container and business applications, while leaving personal data and applications with different or no security restrictions. This targeted approach improves security where necessary without uniformly increasing control complexity across the entire device.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If alternative less heavy-handed approaches are used to control only workspace data and applications, then user acceptance and ease of operation are improved, but the ability to validate configuration profile presence and ensure security settings are lost

Engineering Contradiction:
Improveuser acceptanceVSAvoidconfiguration validation capability
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the configuration profile includes settings that enable the workspace management application to verify its own installation and configuration status. The profile contains specific properties (such as container encryption settings, authentication requirements, and policy enforcement flags) that the application can read and validate to confirm that security measures are properly in place before allowing workspace access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The configuration profile is installed and validated in advance before workspace access is granted. The profile pre-configures security settings, encryption parameters, and policy enforcement mechanisms that are verified by the workspace management application during initialization. This preliminary configuration and validation ensures that security measures are confirmed to be in place before any business applications or data are accessed, maintaining measurement precision without requiring continuous heavy-handed control.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If configuration profiles are installed to enforce security policies, then data security and reliability are improved, but device functionality and user autonomy may be restricted

Engineering Contradiction:
Improvedata securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The configuration profile segments security enforcement to apply only within the workspace container and business applications. Personal applications and data remain outside the scope of MDM-controlled security policies, allowing users to maintain full functionality and autonomy in their personal space while ensuring data security within the business workspace environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The configuration profile applies security measures with local quality by setting different properties for different parts of the device. Business-critical functions receive enhanced security controls (such as mandatory encryption, remote wipe capability, and authentication requirements), while personal functions maintain their original functionality without additional restrictions. This targeted approach preserves device adaptability and versatility overall while ensuring reliability where data security is paramount.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9094413B2Configuration profile validation on iOS Using SSL and redirect
Publication Date: 2015.07.28 VMWARE INC
  • US9094413B2 patent drawing
  • US9094413B2 patent drawing
  • US9094413B2 patent drawing

AI summary

An application management agent running on a wireless communications device restricts access to device functionality (e.g., applications and device features) unless the application management agent has determined that a particular configuration profile has been installed on the device (after which the application management agent permits access to device functionality, and an operating system of the device enforces policy settings specified in the configuration profile). The application management agent confirms the presence of the configuration profile by initiating an SSL handshake with a client certificate request for a client SSL certificate embedded in the configuration profile. Validation against the embedded client SSL certificate implicitly confirms the presence of the configuration profile and validates the content of the configuration profile.