Mobile Device Management via Secure OTA Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing mobile devices due to scalability, data and network security, reliability of communication channels, and the need for flexible management as devices are frequently added, removed, or changed, posing security risks and resource management issues.

Innovation Solution

A method for managing mobile devices over-the-air (OTA) in a flexible, scalable, and secure manner using push network infrastructures and standard protocols, allowing devices to enroll and leave enterprise services without physical access, with secure network sessions and mutual verifications for management operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises deploy enterprise services supporting mobile devices, then service coverage and functionality are improved, but resource costs (IT personnel, device capabilities, network bandwidth, power consumption) increase to unsustainable levels

Engineering Contradiction:
Improveservice coverageVSAvoidresource costs
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts and separates device management functions from physical device control. Management servers remotely provision, configure, and manage mobile devices without requiring physical access or continuous resource allocation to each device, thereby reducing IT personnel requirements and infrastructure costs while maintaining service coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The management server implements universal functions to serve multiple devices simultaneously. A single management server can provision, configure, and manage numerous mobile devices across different enterprises, reducing the need for dedicated resources per device and achieving economies of scale.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If enterprises provide flexible management for frequently added or removed devices, then adaptability is improved, but security risks increase

Engineering Contradiction:
Improvemanagement flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security actions during device enrollment before the device accesses enterprise resources. Management servers pre-provision security policies, certificates, and configuration profiles, ensuring devices are securely configured before they can pose security risks, thus enabling flexible device addition without compromising security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management server continuously monitors device status and security compliance. When devices are added or removed, the system receives feedback and automatically updates management policies, ensuring security is maintained dynamically as the device fleet changes.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If IT personnel physically access devices for configuration, then configuration accuracy is improved, but operational efficiency deteriorates

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidoperational efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent replaces mechanical/physical configuration methods with automated remote provisioning. Management servers digitally push configuration profiles, policies, and software updates to devices remotely, eliminating the need for physical device access while maintaining configuration accuracy through standardized automated processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Devices automatically receive and apply configuration profiles from management servers without requiring manual intervention. The system enables self-service provisioning where devices are automatically configured upon enrollment, significantly improving operational efficiency while maintaining consistent configuration accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9027112B2Mobile device management
Publication Date: 2015.05.05 APPLE INC
  • US9027112B2 patent drawing
  • US9027112B2 patent drawing
  • US9027112B2 patent drawing

AI summary

Methods and apparatuses that enroll a wireless device into an enterprise service with a management server addressed in a management profile are described. The enrollment may grant a control of configurations of the wireless device to the management server via the management profile. In response to receiving a notification from the management server, a trust of the notification may be verified against the management profile. If the trust is verified, a network session may be established with the management server. The network session may be secured via a certificate in the management profile. Management operations may be performed for management commands received over the secure network session to manage the configurations transparently to a user of the wireless device according to the control.