Multi-State Access Control for Mobile Device Quarantine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and synchronizing data across multiple mobile devices while ensuring device compatibility and security is challenging, particularly in enterprise environments where unapproved devices may not meet company policies, leading to user frustration and administrative difficulties in controlling access.

Innovation Solution

Implementing a computing environment with an access control component that uses multiple access states (allowed, blocked, quarantined, and device discovery) to control access to data and services, allowing trusted devices to synchronize while restricting untrusted or unknown devices, and using granular quarantine operations to assess and manage trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user registers each approved device with the IT administrator before allowing synchronization, then device compatibility and trustworthiness are ensured, but user frustration increases and administrative burden increases

Engineering Contradiction:
Improvedevice trustworthinessVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the device access control process into distinct phases: device discovery phase where devices are automatically detected and added to a discovery list, and approval phase where administrators review and approve devices. This segmentation eliminates the need for pre-registration while maintaining security through structured approval workflows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary device discovery and automatic addition to a discovery list before administrator approval. This preliminary action allows devices to be identified and prepared for approval without requiring user intervention, reducing administrative burden while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the administrator controls access to the network by requiring device approval, then security is improved, but it becomes a daunting and often futile task since it may be unclear as to whether a particular device conforms with required company policies

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms that automatically provide administrators with device information including device type, operating system, and compliance status. This feedback enables administrators to make informed approval decisions without manually assessing each device, reducing the complexity and burden of access control while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Devices automatically perform self-registration by providing their own identification information to the server. This self-service approach eliminates the need for administrators to manually verify device details, reducing administrative complexity while maintaining security through automated information collection and approval workflows.

Inventive Principle:
Principle #25Self-service

3Reliability

If unapproved devices are blocked from accessing company resources, then security is maintained, but user frustration increases when users want to use unapproved devices

Engineering Contradiction:
Improvesecurity complianceVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where devices transition through different states: discovery list, approved, and blocked. Devices on the discovery list can be reviewed and approved by administrators, providing flexibility for legitimate unapproved devices while maintaining security for truly unauthorized devices. This dynamic approach adapts to different device scenarios rather than applying rigid blocking rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the access parameter from binary (blocked/allowed) to multi-state (discovery/approved/blocked). Devices can be moved between these states based on administrator review and device compliance, allowing the system to adapt to different security requirements and device types while maintaining overall security compliance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8621574B2Opaque quarantine and device discovery
Publication Date: 2013.12.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8621574B2 patent drawing
  • US8621574B2 patent drawing
  • US8621574B2 patent drawing

AI summary

Embodiments described herein provide communication control features and functionality, but are not so limited. In an embodiment, a computing environment includes an access control component that can use a number of access states to control access to computing data and/or services. In one embodiment, a server computer can control access to data and/or services using a number of access states including, but not limited to: an allowed state, a blocked state, a device discovery state, and/or a quarantined state. Other embodiments are available.