OS Refresh Recovery via Partitioned Storage and Auto-Reenrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Enterprise Mobility Management (EMM) and Mobile Device Management (MDM) systems, refreshing or resetting a device's operating system (OS) disrupts device management, requiring time-consuming reinstallation of management and managed applications, and poses security risks due to lost authentication channels.
Innovation Solution
A method that stores device identification data, management application installation files, and managed application files in a recovery folder, allowing for the creation of a new OS instance while preserving these files, and automatically re-enrolling the device in the management platform upon login, using command files to reinstall applications and re-establish communication with the management server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the OS is refreshed or reset to resolve performance issues, then device performance is improved, but device management functionality is lost and requires time-consuming reinstallation
Solution Approach 1:
The patent creates a recovery folder before OS refresh/reset that pre-stores device identification data, management application installation files, and managed application installation files. This preliminary preparation enables automatic reinstallation and re-enrollment after the OS refresh, eliminating the time-consuming manual reinstallation process while preserving the ability to improve device performance through OS refresh.
2Reliability
If the OS is refreshed or reset to resolve security issues, then device security is improved, but authentication channels are lost creating security risks
Solution Approach 1:
The recovery folder is created in advance with all necessary authentication data including device identification data and enrollment information. This preliminary action ensures that when the OS is refreshed for security reasons, the authentication channels can be automatically restored without requiring manual re-enrollment, thereby maintaining security while eliminating the security risks associated with manual re-authentication processes.
3Reliability
If manual reinstallation of management applications is performed after OS refresh, then device management is restored, but user and administrator burden increases
Solution Approach 1:
The system is configured to automatically execute command files from the recovery folder that perform the reinstallation of management applications and managed applications, and automatically re-enroll the device with the management server. This self-service mechanism restores device management functionality without requiring manual user or administrator intervention, thereby maintaining reliable device management restoration while significantly reducing operational burden.
4Ease of operation
If device identification data and application files are preserved during OS refresh, then re-enrollment is simplified, but device complexity increases
Solution Approach 1:
The patent extracts and isolates the essential data needed for re-enrollment (device identification data, application installation files) into a separate recovery folder that is preserved during OS refresh. This extraction approach simplifies the re-enrollment process by having all necessary components in one location, while the modular nature of the recovery folder minimizes the impact on overall device complexity, as it functions as a self-contained restoration package.
Data Source
AI summary
Examples described here include systems and methods for refreshing the operating system (“OS”) of a device enrolled in a management platform. Execution of a first command file ensures that necessary components of the management platform residing on the device are stored in a partitioned portion of the device hard drive to preserve them during the OS refresh. After a new instance of the OS has been installed, execution of a second command file migrates the necessary components from the partitioned portion of the hard drive to the new OS instance. When the user logs back into the refreshed device, a third command file installs all necessary device management components at the new OS instance and re-enrolls the device with the management platform. In this manner, the OS of a managed device can be refreshed and re-enrolled in the management platform without significant input from a user or administrator.


