Managed Virtual Machines for BYOD Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The management of Bring Your Own Device (BYOD) and other devices used outside enterprise networks poses challenges due to the lack of continuous management and compliance enforcement, especially when devices go offline, leading to complications in accessing enterprise resources and maintaining data security.
Innovation Solution
A networked environment utilizing managed virtual machines (VMs) with a management service that enrolls and manages both host and guest devices, even when unmanaged, through a unified endpoint management platform, ensuring compliance and security by enforcing policies and configuration rules, and providing offline access solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If personal devices are used for access to enterprise computing systems (BYOD), then productivity gains and cost savings are achieved, but security concerns and management challenges arise
Solution Approach 1:
The patent segments the device into managed and unmanaged portions by implementing a management service that can selectively apply management policies to specific applications and data on the BYOD device. This allows enterprise resources to be managed securely while leaving personal areas untouched, thus maintaining productivity while addressing security concerns.
Solution Approach 2:
The patent introduces a management service as an intermediary between the enterprise and the BYOD device. This service acts as a mediator that enforces security policies, manages access to enterprise resources, and handles compliance requirements without requiring full control over the personal device, thereby enabling secure BYOD access while maintaining productivity.
2Reliability
If management service enforces policies and compliance rules on BYOD devices, then security and compliance are improved, but device complexity and management overhead increase
Solution Approach 1:
The patent applies partial action by implementing management only where necessary - specifically for enterprise applications and data on the BYOD device. The management service selectively enforces policies on relevant portions of the device rather than imposing comprehensive control, thus ensuring compliance while minimizing management complexity and user impact.
Solution Approach 2:
The management service is designed to operate autonomously on the BYOD device, automatically enforcing policies and managing compliance without requiring constant administrative intervention. This self-service capability reduces management overhead and complexity while maintaining reliable compliance enforcement for enterprise resources.
3Adaptability or versatility
If devices are used offline or taken to remote locations, then flexibility and mobility are improved, but continuous management and monitoring become difficult
Solution Approach 1:
The patent implements preliminary action by having the management service pre-establish policies, security configurations, and management rules on the BYOD device before the device goes offline or to remote locations. This ensures that management controls are already in place and can be enforced even without continuous network connectivity, preventing management information loss while maintaining mobility flexibility.
Solution Approach 2:
The management service incorporates feedback mechanisms that allow devices to report their status, compliance state, and security events even when offline or at remote locations. This feedback capability ensures continuous management visibility and prevents information loss about device status and compliance, while still allowing flexible offline use.
Data Source
AI summary
Examples of enterprise management using managed virtual machines are described. A host user context configuration can be received from a host management agent. The host user context configuration can include one or more policies. A managed virtual machine user context configuration can be received from a guest management agent within a managed virtual machine. A portion of the host user context configuration can be processed using a translation matrix to identify a configuration service provider (CSP)-based profile that is mapped to a policy from the host user context configuration. A command to enforce the CSP-based profile on the managed virtual machine can be transmitted.


