Mobile Device Management Filtering for iOS Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively limit access to mobile network devices while allowing users limited control, and they do not provide differentiated filtering levels for various devices or connection requests on a network.

Innovation Solution

A method involving the installation of a mobile device management (MDM) system and a control application that allows remote server access to manage applications, restrict user actions, and apply different filtering levels based on device signals and behavior, using SSL/TLS packet handling and signaling modules to differentiate filtering levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a local user interface is provided for application removal, then user control and ease of operation are improved, but the ability to prevent access to certain content and applications deteriorates

Engineering Contradiction:
Improveuser controlVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the application management functionality into two distinct interfaces: a local user interface for permitted operations and a remote server interface for restricted operations. This segmentation allows the system to provide user-friendly control for allowed actions while maintaining security for blocked actions through centralized management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote server as an intermediary between the local device and the application management system. The server acts as a mediator that receives removal requests, evaluates them against policy rules, and selectively processes them. This intermediary enables the system to maintain both user convenience for permitted operations and security control for restricted operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If remote server access is enabled for application management, then the ability to limit access to certain content is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvecontent filteringVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal remote server interface that handles multiple functions: permitted application removals, blocked application removals, and content filtering. This multi-functional approach consolidates complexity into a single centralized system rather than requiring separate mechanisms for each function, thereby managing device complexity while maintaining comprehensive control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the remote server receives removal requests, evaluates them against configured policies, and returns appropriate responses. This feedback loop enables the system to automatically enforce content filtering and application restrictions without requiring complex local decision-making logic, thus managing device complexity while maintaining effective content control.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If selective filtering is implemented for different devices, then adaptability and network security are improved, but measurement precision and detection difficulty increase

Engineering Contradiction:
Improvefiltering differentiationVSAvoiddevice identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by implementing device-specific filtering policies that are tailored to individual devices or device types. Each device receives customized filtering based on its characteristics, usage pattern, and security requirements. This approach improves adaptability and network security while using straightforward device identification methods that do not significantly increase detection difficulty.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12022292B2Partial limitation of a mobile network device
Publication Date: 2024.06.25 NETABPARK
  • US12022292B2 patent drawing
  • US12022292B2 patent drawing
  • US12022292B2 patent drawing

AI summary

In some embodiments, a local user is prevented from accessing certain content and/or capabilities of a mobile network device while allowing him control over other functions of the device. For example, an administrator may prevent certain undesired activities. Optionally, by means of an MDM server and/or a remote server, the local user controls other aspects of his device as he wills More specifically but not exclusively the method works on IOS devices. An aspect of some embodiments of the current invention relates to a method of selecting a level of filtering for individual members of a network and/or packets. Optionally, a device pertinent to aggressive filtering may signal to the server and/or other devices will be less aggressively filtered. Alternatively or additionally, a server may determine from certain behaviors and/or packet characteristics that a device and/or packet should be filtered aggressively or not.