Location-Based Device Enrollment for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing management services do not effectively enroll computing devices based on their location relative to an enterprise facility, leading to potential security risks due to unauthorized access to enterprise resources.

Innovation Solution

A management service that enrolls client devices based on their geographical location by comparing device-provided location information with a facility's floor plan, associating them with organizational groups, and applying corresponding management policies to ensure compliance and mitigate security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security measures are not properly implemented and maintained, then access to enterprise resources is easier, but unauthorized users can potentially access enterprise resources

Engineering Contradiction:
Improveaccess to enterprise resourcesVSAvoidsecurity of enterprise resources
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter of access control from static (always permitted or always prohibited) to dynamic (based on real-time location). The system continuously monitors the geographical location of computing devices and adjusts access permissions accordingly, allowing access when devices are within authorized locations and blocking access when they are outside authorized locations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system automatically enforces location-based access control without requiring manual intervention from security administrators. The management service autonomously determines whether a computing device is within an authorized location and applies the appropriate access policy, eliminating the need for manual security checks.

Inventive Principle:
Principle #25Self-service

2Reliability

If geo-fence based access control is implemented, then security of computing systems is improved, but existing management services cannot enroll computing devices based on location

Engineering Contradiction:
Improvesecurity of computing systemsVSAvoidenrollment capability of management services
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the management service universal by enabling it to perform both device enrollment and location-based access control functions. The management service is enhanced to not only enroll computing devices but also to continuously monitor their locations and enforce location-based policies, consolidating multiple security functions into a single system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the geo-fence access control system with the existing management service. Instead of operating as separate systems, the location-based security features are integrated into the management service, allowing it to handle both device provisioning and ongoing location-based access control in a unified manner.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10779112B2Location-based organizational groupings for management services
Publication Date: 2020.09.15 OMNISSA LLC
  • US10779112B2 patent drawing
  • US10779112B2 patent drawing
  • US10779112B2 patent drawing

AI summary

Examples relate to devices being managed based on their locations relative to a facility. In some examples, the location of a client device can be determined relative to a facility. An organizational group can be associated with the location. The client device can be associated with the organizational group. Whether the client device complies with a compliance policy associated with the organizational group can be determined.