Mobile Device Management via Secure OTA Enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing mobile devices due to scalability, data and network security, reliability of communication channels, and the need for flexible management as devices are frequently added, removed, or changed, posing security risks and resource management issues.
Innovation Solution
A method for managing mobile devices over-the-air (OTA) in a flexible, scalable, and secure manner using push network infrastructures and standard protocols, allowing devices to enroll and leave enterprise services without physical access, with secure network sessions and mutual verifications for management operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If enterprises deploy enterprise services supporting mobile devices, then service coverage and functionality are improved, but resource costs (IT personnel, device capabilities, network bandwidth, power consumption) increase to unsustainable levels
Solution Approach 1:
The patent extracts and separates device management functions from physical device control. Management servers remotely provision, configure, and manage mobile devices without requiring physical access or continuous resource allocation to each device, thereby reducing IT personnel requirements and infrastructure costs while maintaining service coverage.
Solution Approach 2:
The management server implements universal functions to serve multiple devices simultaneously. A single management server can provision, configure, and manage numerous mobile devices across different enterprises, reducing the need for dedicated resources per device and achieving economies of scale.
2Adaptability or versatility
If enterprises provide flexible management for frequently added or removed devices, then adaptability is improved, but security risks increase
Solution Approach 1:
The system performs preliminary security actions during device enrollment before the device accesses enterprise resources. Management servers pre-provision security policies, certificates, and configuration profiles, ensuring devices are securely configured before they can pose security risks, thus enabling flexible device addition without compromising security.
Solution Approach 2:
The management server continuously monitors device status and security compliance. When devices are added or removed, the system receives feedback and automatically updates management policies, ensuring security is maintained dynamically as the device fleet changes.
3Manufacturing precision
If IT personnel physically access devices for configuration, then configuration accuracy is improved, but operational efficiency deteriorates
Solution Approach 1:
The patent replaces mechanical/physical configuration methods with automated remote provisioning. Management servers digitally push configuration profiles, policies, and software updates to devices remotely, eliminating the need for physical device access while maintaining configuration accuracy through standardized automated processes.
Solution Approach 2:
Devices automatically receive and apply configuration profiles from management servers without requiring manual intervention. The system enables self-service provisioning where devices are automatically configured upon enrollment, significantly improving operational efficiency while maintaining consistent configuration accuracy.
Data Source
AI summary
Methods and apparatuses that enroll a wireless device into an enterprise service with a management server addressed in a management profile are described. The enrollment may grant a control of configurations of the wireless device to the management server via the management profile. In response to receiving a notification from the management server, a trust of the notification may be verified against the management profile. If the trust is verified, a network session may be established with the management server. The network session may be secured via a certificate in the management profile. Management operations may be performed for management commands received over the secure network session to manage the configurations transparently to a user of the wireless device according to the control.


