Mobile Device Policy Enforcement via Local Drivers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems fail to effectively enforce administrative policies across various mobile devices, particularly in ensuring users comply with organizational policies regarding resource access and feature usage, both online and offline.

Innovation Solution

A system comprising a policy server that creates and enforces administrative policies on mobile devices through an enforcement device driver and monitor, controlling access to resources and features, regardless of network connectivity, using encryption to prevent policy modification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrative policies are enforced on mobile devices, then organizational security and compliance are improved, but device functionality and user flexibility deteriorate

Engineering Contradiction:
Improveorganizational securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments device resources into controllable entities (applications, features, resources) that can be individually managed through policy templates. The enforcement mechanism divides policy management into administrative functions (policy creation) and enforcement functions (policy execution), allowing security controls to be applied selectively to specific device components without completely restricting device functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different policy restrictions to be applied to different device resources and applications. Each application or resource can have its own specific policy rules, enabling fine-grained control where security requirements vary by resource type rather than applying uniform restrictions across the entire device.

Inventive Principle:
Principle #3Local quality

2Reliability

If policies are enforced when mobile devices are offline, then policy compliance is maintained, but real-time policy updates and monitoring are lost

Engineering Contradiction:
Improvepolicy complianceVSAvoidreal-time policy updates
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary action by caching enforcement policies and configuration data locally on the mobile device before offline operation is required. The enforcement mechanism uses pre-loaded policy templates and device information stored in local databases, enabling policy compliance to be maintained during offline periods without real-time network connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that log policy enforcement events, access attempts, and compliance status locally on the device. These logs are maintained even when offline and can be synchronized with the policy server when connectivity is restored, providing continuous monitoring capability that bridges the gap between offline enforcement and online update synchronization.

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If users are prevented from modifying policies, then policy integrity is maintained, but user autonomy and adaptability deteriorate

Engineering Contradiction:
Improvepolicy integrityVSAvoiduser autonomy
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The system performs preliminary action by encrypting policy data with device-specific keys before storage on the mobile device. This encryption is established in advance during policy deployment, making policies tamper-resistant while allowing legitimate users to access and view policy contents. The cryptographic protection is set up beforehand, maintaining policy integrity without requiring continuous user intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic intermediaries (encryption keys, digital signatures) as mediators between policy administrators and users. These cryptographic mechanisms serve as trusted intermediaries that verify policy authenticity and prevent unauthorized modification, while still allowing users to interact with policies through approved interfaces. The cryptographic layer acts as an intermediary that preserves integrity while enabling controlled user access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8935741B2Policy enforcement in mobile devices
Publication Date: 2015.01.13 IANYWHERE SOLUTIONS INC
  • US8935741B2 patent drawing
  • US8935741B2 patent drawing
  • US8935741B2 patent drawing

AI summary

Systems, methods and computer program products for enabling enforcement of an administrative policy on one or more mobile devices are described herein. In an embodiment, an administrator uses a policy server to create and provide an enforcement policy to a mobile device. An enforcement policy may include information on mobile device resources which may be controlled by an administrator. An enforcement policy also includes information on how mobile device features will be set, configured or disabled. An enforcement device driver and an enforcement monitor on a mobile device use the enforcement policy to control access to resources associated with the mobile device regardless of whether the mobile device is “online” and connected to a network or “offline” and disconnected from a network.