Mobile Device Classification for Multi-Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data synchronization solutions, such as Exchange ActiveSync, require significant administrative effort to manage multiple mobile devices per user, leading to labor-intensive exception requests due to their restrictive policies, which were designed for a single device per user era.
Innovation Solution
Implement a device classification system that automatically classifies mobile computing devices into predefined categories based on attributes like name, model, and operating system, allowing users to self-register up to a specified number of devices per class without needing administrator intervention, thereby streamlining access and synchronization policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Exchange ActiveSync uses single device per user policy, then security is improved, but user convenience deteriorates as users cannot access enterprise data with multiple devices
Solution Approach 1:
The patent segments device access rights by classifying devices into different categories (e.g., smartphones, tablets, laptops) and applying different policies to each class. This allows users to access enterprise data with multiple devices while maintaining security through differentiated access levels based on device type and risk profile.
Solution Approach 2:
The patent changes the policy parameter from a binary single-device restriction to a multi-device allowance with classification-based rules. By introducing device classification parameters and associated access rules, the system enables multiple device access while maintaining security through customizable policies that can be adjusted based on device characteristics and user needs.
2Reliability
If administrators manually approve each device connection, then security control is improved, but administrative workload increases significantly
Solution Approach 1:
The patent implements self-service by allowing users to automatically register and access enterprise data with multiple devices without requiring manual administrator approval for each device. The system automatically classifies devices and applies appropriate access policies, eliminating the need for administrators to manually review each connection request.
Solution Approach 2:
The patent performs preliminary device classification and policy determination before device registration. By pre-defining device classes and associated access rules, the system automatically determines appropriate access rights when a device connects, eliminating the need for real-time administrator intervention and significantly improving administrative efficiency.
3Adaptability or versatility
If device classification rules are highly customizable, then policy flexibility is improved, but system complexity increases
Solution Approach 1:
The patent segments the policy configuration into discrete device classes with associated rules, making the system easier to manage despite the flexibility it provides. By organizing policies into distinct classes (e.g., smartphones, tablets, laptops) with specific access rules, the system achieves high adaptability while reducing the complexity of configuring and managing overall policy.
Data Source
AI summary
Attempts by computing devices to access centralized data are managed according to device classification level rules. A request to access centralized data is received from an unclassified computing device. The unclassified computing device is classified into a specific one of the defined classes, based at least partially on information concerning the computing device read from the received request. Where a definition of the unclassified computing device has already been assigned to a specific class, the unclassified computing device is classified accordingly. Otherwise, the unclassified computing device is compared to multiple classified computing devices, and the unclassified computing device is classified according to the one that is most similar. Responsive to the classification of the computing device, the received request to access centralized data is governed according to a device classification level rule which specifies access policy for computing devices of the defined class.


