Automated Mobile Device Management Profile Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems face challenges in automating the enrollment of client devices with mobile device management profiles, leading to manual navigation and administrative overhead in accessing restricted resources.

Innovation Solution

A method that determines whether a client device is enrolled with a mobile device management system and provides a redirect to a mobile device management resource, allowing automated enrollment by presenting a user interface for profile installation, enabling access to restricted resources once the profile is installed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual enrollment process is used for mobile device management profiles, then users can install profiles through manual navigation, but administrative overhead and time consumption increase significantly

Engineering Contradiction:
Improvemanual profile installationVSAvoidenrollment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables devices to automatically enroll themselves with the mobile device management system by detecting restricted resource access attempts and autonomously installing required profiles, eliminating the need for manual user navigation and administrative intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures automated enrollment mechanisms that activate when a device attempts to access restricted resources, automatically providing and installing the necessary management profiles before resource access is granted, thereby preventing time loss during the enrollment process

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated enrollment is implemented, then administrative overhead is reduced, but system complexity increases due to automatic detection and redirect mechanisms

Engineering Contradiction:
Improveenrollment efficiencyVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary component that sits between the device and restricted resources, automatically detecting unenrolled devices attempting to access restricted resources and redirecting them to profile installation resources, thereby automating enrollment without significantly complicating the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access to restricted resources is blocked for unenrolled devices, then security is enhanced, but user convenience is reduced due to automatic redirect requirements

Engineering Contradiction:
Improvesecurity enforcementVSAvoidresource access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system converts the potentially harmful action of blocking unenrolled devices from accessing restricted resources into a beneficial automated enrollment opportunity, where the access denial triggers an automatic profile installation process that ultimately improves both security compliance and user convenience

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS9160751B2Mobile device management profile distribution
Publication Date: 2015.10.13 IBOSS INC
  • US9160751B2 patent drawing
  • US9160751B2 patent drawing
  • US9160751B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for automated mobile device management profile distribution. One of the methods includes receiving a first request for access to a first network resource from a client device, the first network resource corresponding to one of a plurality of restricted resources accessible only by devices enrolled with a mobile device management system, determining that the client device is not enrolled with the mobile device management system, preventing the client device access to the first network resource, providing to the client device a redirect to a mobile device management resource that is different from the first network resource, providing instructions for presentation of a user interface to the client device, and enrolling the client device with the mobile device management system, the enrolling comprising providing a copy of the mobile device management profile to the client device.