Mobile Device Configuration Profile Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment, management, and configuration of mobile devices in enterprise environments are challenging due to the vast and constantly changing variety of device types, functions, and capabilities, particularly in verifying and updating configuration profiles across these devices.
Innovation Solution
A mobile device management system that generates and distributes configuration profiles with embedded verification tokens, allowing devices to compare and verify the installed profiles against the latest ones, ensuring successful application and governing access based on profile compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration profiles are distributed to mobile devices, then device configuration and management is improved, but verification of successful installation and application becomes difficult
Solution Approach 1:
A verification token is embedded in the configuration profile before distribution. This token serves as a pre-prepared verification mechanism that enables later confirmation of successful installation and application without requiring complex verification procedures.
Solution Approach 2:
The system implements a feedback loop where the mobile device reports back to the device management server whether the configuration profile was successfully installed and applied. The server uses this feedback to determine whether to grant or deny enterprise access, creating a closed-loop verification system.
2Productivity
If configuration profiles are updated remotely, then device management efficiency is improved, but ensuring successful application across all devices becomes challenging
Solution Approach 1:
The mobile device sends a status report to the device management server indicating whether the configuration profile was successfully installed and applied. This feedback mechanism enables the server to verify successful application and take appropriate actions, such as granting or denying access.
Solution Approach 2:
The patent replaces manual verification methods with an automated electronic verification system. The verification token and automated status reporting eliminate the need for manual checking, thereby improving both efficiency and reliability of configuration profile updates.
3Reliability
If enterprise access is granted based on configuration profile installation, then security is improved, but false positives from failed installations may cause access denial
Solution Approach 1:
The verification token is embedded in advance in the configuration profile, enabling the system to verify successful installation and application before making access decisions. This preliminary preparation ensures accurate detection of installation status.
Solution Approach 2:
The system uses feedback from the mobile device about whether the configuration profile was successfully installed and applied to make informed access decisions. This feedback mechanism reduces false positives by ensuring that access denial is based on accurate installation status information.
Data Source
AI summary
In various embodiments, a control client is configured to determine whether or not the most current configuration profile has been installed within a corresponding mobile device. In particular embodiments, the client is configured to store its own copy of a configuration profile and to compare its copy with the most current configuration profile generated by a device management system as well as to the configuration profile currently installed and applied by a configuration manager within the mobile device. Each configuration profile includes an embedded verification token that facilitates this process. Furthermore, the client may be configured to inform the device management system as to whether or not the current configuration profile has been installed. The device management system may govern enterprise access by the mobile device based on whether or not the current configuration profile has been installed.


