Mobile Device Management Agent Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in effectively managing and controlling mobile devices, applications, and resources within their networks, particularly in enforcing policies and securing enterprise data on diverse mobile platforms.

Innovation Solution

Implementing a mobile device management system that includes a mobile device management agent to monitor state information and enforce policies on mobile devices, manage browser functionalities, application tunneling, device clouds, and secure document containers, ensuring secure access and usage of enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices are provided to employees with increasing functions and popularity, then user convenience and productivity are improved, but control over device usage and security management become more difficult

Engineering Contradiction:
Improveuser convenienceVSAvoidcontrol complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A mobile device management agent is introduced as an intermediary component installed on mobile devices. This agent acts as a mediator between the device and the management system, enabling centralized policy enforcement while maintaining device functionality. The agent receives policies from a management server and applies them to control device usage, application installation, and data security without requiring direct user intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management system is segmented into separate functional components: a management server that defines policies, mobile device management agents that enforce policies on individual devices, and a database that stores device and policy information. This segmentation allows centralized control while maintaining device autonomy and simplifying the overall system architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If policies are applied to control mobile device functionalities, then security and resource access control are improved, but device flexibility and adaptability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic policy enforcement where management policies can be updated and applied in real-time based on device state, user role, and organizational requirements. The mobile device management agent continuously monitors device conditions and adjusts policy application accordingly, allowing the system to adapt to changing security needs while maintaining device flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different policies can be applied to different aspects of device functionality based on local requirements. The system allows granular control where specific policies can be targeted at particular applications, data types, or device functions without affecting the entire device. This enables customized security measures for different organizational needs while preserving overall device adaptability.

Inventive Principle:
Principle #3Local quality

3Stability of the object's composition

If centralized management is implemented, then policy enforcement consistency is improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improvepolicy consistencyVSAvoidsystem complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The mobile device management agent performs self-service functions by automatically installing itself on the device, monitoring local system state, and applying policies without requiring manual intervention. The agent autonomously communicates with the management server to receive policy updates and independently enforces these policies on the device, reducing the complexity of centralized management deployment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of requiring complex centralized control mechanisms, the system uses simplified policy templates that are copied and applied to individual devices through the management agent. The agent replicates management functions locally while maintaining communication with the central server, reducing the complexity burden on the centralized system while ensuring consistent policy enforcement.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8910264B2Providing mobile device management functionalities
Publication Date: 2014.12.09 CITRIX SYSTEMS INC
  • US8910264B2 patent drawing
  • US8910264B2 patent drawing
  • US8910264B2 patent drawing

AI summary

Methods, systems, computer-readable media, and apparatuses for providing mobile device management functionalities are presented. In various embodiments, a mobile device management agent may monitor state information associated with a mobile computing device. The monitored state information may be analyzed on the mobile computing device and/or by one or more policy management servers. In some instances, the one or more policy management servers may provide management information to the mobile computing device, and the management information may include one or more commands (which may, e.g., cause the mobile computing device to enforce one or more policies) and/or one or more policy updates. Subsequently, one or more policies may be enforced on the mobile computing device based on the monitored state information and/or based on the management information.