Mobile Device Policy Enforcement via Pre-Access Configuration Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mobile devices operating in unsecured environments face increased risks of unauthorized access due to lack of control over configuration and policy settings, making it difficult for administrators to enforce security policies and ensure data protection.

Innovation Solution

A computer system enforces appropriate device configuration and policy settings for mobile devices before allowing access to sensitive data by determining the current configuration and policy settings, sending necessary updates, and verifying compliance before granting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices are allowed to access data from unsecured environments, then accessibility and mobility are improved, but security and data protection deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by checking device configuration and policy settings before granting data access. The server evaluates security criteria, verifies device compliance, and enforces configuration requirements in advance of any data transfer, ensuring security measures are established before the mobile device can access protected resources.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device configuration settings are enforced before data access, then security is improved, but device complexity and administrative overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing mobile devices to automatically check their own configuration compliance and receive automated responses from the server. Devices can self-diagnose whether they meet security criteria, and the system provides automated configuration enforcement without requiring manual administrative intervention for each access request.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the server evaluates device configurations and provides responses indicating compliance status. The system feeds back configuration requirements to mobile devices and adjusts access permissions based on evaluated compliance, creating a closed-loop system that automatically enforces security policies.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If policy settings are updated remotely, then ease of operation is improved, but loss of information and configuration errors may increase

Engineering Contradiction:
Improveremote managementVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system uses feedback to verify configuration updates by evaluating whether updated policy settings meet security criteria before applying them. The server provides feedback on configuration compliance and only enforces settings that pass security evaluations, reducing the risk of configuration errors from remote updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8626128B2Enforcing device settings for mobile devices
Publication Date: 2014.01.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8626128B2 patent drawing
  • US8626128B2 patent drawing
  • US8626128B2 patent drawing

AI summary

The present invention extends to methods, systems, and computer program products for enforcing device settings for mobile devices. Generally, a computer system enforces appropriate mobile device settings (e.g., policy and/or configuration settings) prior to permitting a mobile device to access maintained data. The computer system receives a request from a mobile device. The computer system determines that current mobile device settings are not appropriate for accessing the maintained data. The computer system sends device settings, representing a new mobile device configuration that is appropriate accessing the maintained data, to the mobile device. The computer system receives an indication that the mobile device is configured in accordance with the device settings. The computer system permits the mobile device to access the maintained data in response to receiving the indication that the mobile device is configured in accordance with the device settings.