Mobile Enterprise Management System Malware Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in ensuring application security on personal mobile devices used for work purposes, as they cannot control or vet all applications installed by employees, leading to a risk of malware infection from various sources, including third-party app stores.

Innovation Solution

Integration of malware scanning into mobile device management software deployed by enterprises, which scans client applications for compliance with predefined policies and performs remedial actions such as uninstallation or upgrading to secure versions, ensuring only approved applications are installed and used on employee devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If enterprises allow employees to install applications from various sources including third-party stores, then employees have flexibility and ease of operation, but the risk of malware infection increases

Engineering Contradiction:
Improveapplication installation flexibilityVSAvoidmalware infection risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an enterprise server as an intermediary between the application store and the mobile device. The server receives application information, scans it for malware, and only allows installation of approved applications. This mediator resolves the contradiction by enabling flexible application installation while blocking malicious applications through centralized security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary scanning and approval of applications before they are installed on mobile devices. The enterprise server scans applications from stores and pre-approves them before deployment to employee devices. This preliminary action prevents malware from reaching the device, maintaining both flexibility and security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If enterprises implement strict application vetting and approval processes, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveapplication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The enterprise server acts as a centralized intermediary that handles all scanning and approval operations. Instead of embedding complex scanning mechanisms in each mobile device, the server performs all security checks centrally and distributes approved applications. This reduces device complexity while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the complex malware scanning and approval functionality from individual mobile devices and relocates it to a centralized enterprise server. This extraction reduces the complexity burden on employee devices while maintaining comprehensive security vetting processes on the server side.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If enterprises block installation from third-party stores, then malware risk is reduced, but adaptability and ease of operation are limited

Engineering Contradiction:
Improvemalware exposureVSAvoidapplication source flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic approval system where the enterprise server can adaptively manage application sources. Rather than statically blocking all third-party stores, the server dynamically evaluates applications from any source, granting approval based on real-time security assessment. This dynamic approach maintains flexibility while protecting against malware.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The enterprise server provides universal security scanning capabilities that work with applications from any source including official stores, third-party stores, and custom sources. This multi-functional approach allows employees to access applications from diverse sources while maintaining consistent security protection across all application types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9917862B2Integrated application scanning and mobile enterprise computing management system
Publication Date: 2018.03.13 OMNISSA LLC
  • US9917862B2 patent drawing
  • US9917862B2 patent drawing
  • US9917862B2 patent drawing

AI summary

Disclosed are various approaches for integrating application scanning into a mobile enterprise computing management system. A management service can add a first command to a command queue associated with a client device, wherein the first command instructs the client device to provide a unique device identifier associated with the client device to the management service and the unique device identifier uniquely identifies the client device with respect to at least one other client device. Then, the management service can receive a first request from the client device for the first command stored in the command queue. Later, the management service sends the first command to the client device. When the management service receives the unique device identifier from the client device, the management service sends the unique device identifier to a scanning service and a policy linked with the unique device identifier to the scanning service. The policy comprises an identifier of a client application prohibited on the client device. The management service then receives a notification from the scanning service. The notification comprises the unique device identifier and an indication that the client application is present on the client device. Later, the management service adds a second command to the command queue, wherein the second command instructs the client device to perform a remedial action specified by the policy. When the management service receives a second request from the client device for the second command stored in the command queue, the management service sends the second command to the client device.