Location-Based Device Enrollment for Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing management services do not effectively enroll computing devices based on their location relative to an enterprise facility, leading to potential security risks due to unauthorized access to enterprise resources.
Innovation Solution
A management service that enrolls client devices based on their geographical location by comparing device-provided location information with a facility's floor plan, associating them with organizational groups, and applying corresponding management policies to ensure compliance and mitigate security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security measures are not properly implemented and maintained, then access to enterprise resources is easier, but unauthorized users can potentially access enterprise resources
Solution Approach 1:
The patent changes the parameter of access control from static (always permitted or always prohibited) to dynamic (based on real-time location). The system continuously monitors the geographical location of computing devices and adjusts access permissions accordingly, allowing access when devices are within authorized locations and blocking access when they are outside authorized locations.
Solution Approach 2:
The system automatically enforces location-based access control without requiring manual intervention from security administrators. The management service autonomously determines whether a computing device is within an authorized location and applies the appropriate access policy, eliminating the need for manual security checks.
2Reliability
If geo-fence based access control is implemented, then security of computing systems is improved, but existing management services cannot enroll computing devices based on location
Solution Approach 1:
The patent makes the management service universal by enabling it to perform both device enrollment and location-based access control functions. The management service is enhanced to not only enroll computing devices but also to continuously monitor their locations and enforce location-based policies, consolidating multiple security functions into a single system.
Solution Approach 2:
The patent merges the geo-fence access control system with the existing management service. Instead of operating as separate systems, the location-based security features are integrated into the management service, allowing it to handle both device provisioning and ongoing location-based access control in a unified manner.
Data Source
AI summary
Examples relate to devices being managed based on their locations relative to a facility. In some examples, the location of a client device can be determined relative to a facility. An organizational group can be associated with the location. The client device can be associated with the organizational group. Whether the client device complies with a compliance policy associated with the organizational group can be determined.


