Managed Application Detection Logic for Offline EMM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise Mobility Management (EMM) systems face challenges in detecting and managing applications on devices without network connectivity, leading to security concerns and administrative inefficiencies when unmanaged versions of applications are installed on managed devices.

Innovation Solution

Implementing local detection logic on client devices to determine the management status of applications, using unique tokens and configuration data to identify whether an application was installed by an EMM service, allowing for remedial actions even without network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If EMM relies on network connection to detect application management status, then centralized management control is improved, but system reliability deteriorates when network connection is unavailable

Engineering Contradiction:
Improvecentralized management controlVSAvoidsystem reliability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding detection logic and tokens directly into the application package during the installation process. The application includes self-contained detection capabilities and management tokens that allow it to determine its own management status without requiring real-time network connectivity to the EMM server, thus resolving the contradiction between centralized control and reliability.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If EMM uses centralized server communication to identify managed applications, then management precision is improved, but loss of information increases when network connection fails

Engineering Contradiction:
Improvemanagement precisionVSAvoidapplication status information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies copying by creating local copies of management information within the application itself. The application package contains embedded tokens and detection logic that replicate the management status information, allowing the application to determine its managed status locally without relying on continuous communication with the centralized EMM server, thus preventing information loss when network connection is unavailable.

Inventive Principle:
Principle #26Copying

3Measurement precision

If device communicates with management server to determine application status, then detection accuracy is improved, but loss of time increases due to network dependency

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies self-service by enabling the application to autonomously determine its own management status using embedded detection logic and tokens. The application does not need to externally query the management server to ascertain its status; instead, it self-determines whether it is a managed or unmanaged application, eliminating network communication delays and enabling immediate detection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10592259B2Managed application detection logic
Publication Date: 2020.03.17 OMNISSA LLC
  • US10592259B2 patent drawing
  • US10592259B2 patent drawing
  • US10592259B2 patent drawing

AI summary

Various examples for application management detection are described. In one example, depending upon whether an installation token includes a unique token value, a client device can determine whether an application is managed or unmanaged. Additionally, the client device can determine whether the application is managed or unmanaged based on whether a keychain installation token includes a unique token value, a value of a keychain installation token, and a value of a launched flag for the application. Using the concepts described herein, an unmanaged application can proceed to execute with limited functionality, present a notification that it should be reinstalled by the management service, stop executing, or take other measures.