Mobile Device Management Agent Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in effectively managing and controlling mobile devices, applications, and resources within their networks, particularly in enforcing policies and securing enterprise data on diverse mobile platforms.

Innovation Solution

Implementing a mobile device management system that includes a mobile device management agent to monitor state information and enforce policies on mobile devices, manage browser functionalities, application tunneling, device clouds, and secure document containers, ensuring secure access and usage of resources based on real-time device and application states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile devices are provided to employees with increasing functionality, then employee productivity and access to resources is improved, but control and security over device usage and data access deteriorates

Engineering Contradiction:
Improveemployee productivityVSAvoidcontrol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments mobile devices into managed and unmanaged partitions, allowing different policy enforcement levels for different applications and data. This enables organizations to maintain productivity by allowing unrestricted use of unmanaged apps while enforcing security policies on managed enterprise applications and data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A mobile device management agent acts as an intermediary between the device operating system and enterprise resource systems. This agent enforces policies, monitors device state, and controls access to enterprise resources without requiring direct control of the entire device, thus maintaining productivity while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mobile device management policies are enforced to improve security, then data protection is improved, but device functionality and user convenience deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts policy enforcement based on real-time device state information such as location, network connectivity, and device integrity. Policies are applied selectively rather than uniformly, allowing users to maintain convenience when device state is acceptable while ensuring data protection when risks are detected.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different security policies are applied to different applications and data partitions based on their sensitivity and requirements. Enterprise-critical applications receive stricter controls while personal or less-sensitive applications maintain greater user freedom, thus protecting data while preserving user convenience.

Inventive Principle:
Principle #3Local quality

3Reliability

If real-time monitoring of device state is implemented to enforce policies dynamically, then policy enforcement effectiveness is improved, but system resource consumption and device performance deteriorates

Engineering Contradiction:
Improvepolicy enforcement effectivenessVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The mobile device management agent monitors device state periodically rather than continuously, checking for changes at scheduled intervals or when triggered by specific events. This approach maintains effective policy enforcement by detecting state changes while significantly reducing energy consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The device itself generates and reports state information to the management agent, rather than requiring constant external polling. Event-driven architecture allows the system to respond to actual state changes only, reducing unnecessary processing and energy usage while maintaining enforcement effectiveness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9985850B2Providing mobile device management functionalities
Publication Date: 2018.05.29 CITRIX SYSTEMS INC
  • US9985850B2 patent drawing
  • US9985850B2 patent drawing
  • US9985850B2 patent drawing

AI summary

Methods, systems, computer-readable media, and apparatuses for providing mobile device management functionalities are presented. In various embodiments, a mobile device management agent may monitor state information associated with a mobile computing device. The monitored state information may be analyzed on the mobile computing device and/or by one or more policy management servers. In some instances, the one or more policy management servers may provide management information to the mobile computing device, and the management information may include one or more commands (which may, e.g., cause the mobile computing device to enforce one or more policies) and/or one or more policy updates. Subsequently, one or more policies may be enforced on the mobile computing device based on the monitored state information and/or based on the management information.