Managed OS Image Assembly via BIOS Server Contact

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the PC ecosystem, there is no centralized method for administrators to easily enroll and manage Windows devices, leading to inefficient and resource-intensive setup processes, fragmented trusted boot processes, and difficulties in tracking device ownership and configuration, which hinders secure and efficient deployment of Enterprise Mobility Management systems.

Innovation Solution

A system that enables automatic enrollment of computing devices by using a BIOS process to contact a vendor server for ownership and configuration details, allowing the device to download and install managed OS images and management policies before the user logs in, thereby establishing a secure and standardized environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually configure each PC device individually, then device security and proper enrollment can be ensured, but the setup process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvedevice securityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring golden images with all necessary software, hardware drivers, and EMM enrollment settings before devices are deployed. The BIOS automatically contacts the vendor server during initial boot to retrieve and apply the appropriate golden image, eliminating the need for manual post-deployment configuration and significantly reducing setup time while maintaining security standards

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device performs self-service enrollment by automatically contacting the vendor server through its BIOS during the initial boot process. The system autonomously retrieves ownership information, downloads the appropriate golden image, and applies configurations without requiring manual administrator intervention for each device, thereby reducing both time and resource requirements while ensuring consistent security enrollment

Inventive Principle:
Principle #25Self-service

2Productivity

If a centralized vendor server system is implemented to automate device enrollment, then administrative efficiency improves and setup time decreases, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improveenrollment efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The vendor server is designed as a universal platform that handles multiple functions including storing golden images for different device configurations, managing EMM enrollment credentials, tracking device ownership information, and providing automated delivery mechanisms. This multi-functional approach consolidates what would otherwise require multiple separate systems into a single infrastructure, reducing overall complexity while maintaining high enrollment efficiency

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The BIOS acts as an intermediary layer between the hardware device and the vendor server, handling the automated communication and enrollment process. By embedding the enrollment logic in the BIOS rather than requiring complex operating system-level software, the system reduces overall complexity while enabling automated productivity improvements through the vendor server infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If golden images are used for device deployment, then consistent configurations can be achieved, but the approach only works when device hardware and configurations are the same

Engineering Contradiction:
Improveconfiguration consistencyVSAvoidhardware compatibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by creating distinct golden images tailored to specific hardware configurations, device types, and organizational requirements. Each golden image contains precisely the software, drivers, and settings needed for that particular device category, ensuring configuration consistency within each group while maintaining adaptability across diverse hardware platforms through the vendor server's ability to match devices with appropriate images

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If EMM functionality is customized for different employees and departments, then specific organizational needs are met, but the constant changes make OEM customization impractical

Engineering Contradiction:
ImproveEMM customizationVSAvoidOEM customization feasibility
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The vendor server performs preliminary actions by pre-configuring multiple golden images with different EMM functionalities tailored to various departments, employee roles, and organizational needs. When a device is deployed, the system automatically selects and applies the appropriate pre-configured golden image based on device type and organizational requirements, enabling EMM customization without requiring ongoing OEM intervention even as organizational needs evolve

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11709684B2Configuring a computing device using managed operating system images
Publication Date: 2023.07.25 OMNISSA LLC
  • US11709684B2 patent drawing
  • US11709684B2 patent drawing
  • US11709684B2 patent drawing

AI summary

Systems and methods are included for causing a computing device to assemble and boot from a managed operating system. When the computing device is powered on, it can execute firmware that specifies a server to contact. The server can identify an operating system (OS) to boot, and the location of a pre-enrollment installer for assembling the OS image. The pre-enrollment installer can download base OS images in one or more pieces from multiple locations determined based on ownership information of the computing device. The multiple OS images can relate to enterprise management and company-specific applications and drivers. Once the pre-enrollment installer has combined the base OS images, the computing device reboots using the combined OS image.