Managed Virtual Machines for BYOD Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of Bring Your Own Device (BYOD) and other devices used outside enterprise networks poses challenges due to the lack of continuous management and compliance enforcement, especially when devices go offline, leading to complications in accessing enterprise resources and maintaining data security.

Innovation Solution

A networked environment utilizing managed virtual machines (VMs) with a management service that enrolls and manages both host and guest devices, even when unmanaged, through a unified endpoint management platform, ensuring compliance and security by enforcing policies and configuration rules, and providing offline access solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal devices are used for access to enterprise computing systems (BYOD), then productivity gains and cost savings are achieved, but security concerns and management challenges arise

Engineering Contradiction:
Improveproductivity gainsVSAvoidsecurity concerns
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the device into managed and unmanaged portions by implementing a management service that can selectively apply management policies to specific applications and data on the BYOD device. This allows enterprise resources to be managed securely while leaving personal areas untouched, thus maintaining productivity while addressing security concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a management service as an intermediary between the enterprise and the BYOD device. This service acts as a mediator that enforces security policies, manages access to enterprise resources, and handles compliance requirements without requiring full control over the personal device, thereby enabling secure BYOD access while maintaining productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If management service enforces policies and compliance rules on BYOD devices, then security and compliance are improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvecompliance enforcementVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by implementing management only where necessary - specifically for enterprise applications and data on the BYOD device. The management service selectively enforces policies on relevant portions of the device rather than imposing comprehensive control, thus ensuring compliance while minimizing management complexity and user impact.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The management service is designed to operate autonomously on the BYOD device, automatically enforcing policies and managing compliance without requiring constant administrative intervention. This self-service capability reduces management overhead and complexity while maintaining reliable compliance enforcement for enterprise resources.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If devices are used offline or taken to remote locations, then flexibility and mobility are improved, but continuous management and monitoring become difficult

Engineering Contradiction:
Improvemobility flexibilityVSAvoidmanagement information loss
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by having the management service pre-establish policies, security configurations, and management rules on the BYOD device before the device goes offline or to remote locations. This ensures that management controls are already in place and can be enforced even without continuous network connectivity, preventing management information loss while maintaining mobility flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management service incorporates feedback mechanisms that allow devices to report their status, compliance state, and security events even when offline or at remote locations. This feedback capability ensures continuous management visibility and prevents information loss about device status and compliance, while still allowing flexible offline use.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12118377B2Transition to modern management using managed virtual machines
Publication Date: 2024.10.15 OMNISSA LLC
  • US12118377B2 patent drawing
  • US12118377B2 patent drawing
  • US12118377B2 patent drawing

AI summary

Examples of enterprise management using managed virtual machines are described. A host user context configuration can be received from a host management agent. The host user context configuration can include one or more policies. A managed virtual machine user context configuration can be received from a guest management agent within a managed virtual machine. A portion of the host user context configuration can be processed using a translation matrix to identify a configuration service provider (CSP)-based profile that is mapped to a policy from the host user context configuration. A command to enforce the CSP-based profile on the managed virtual machine can be transmitted.