Peer-to-peer offline access mode for enterprise resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are unable to access enterprise resources such as data content or applications when a client device is offline, as management services require online connectivity to verify compliance with enterprise policies.
Innovation Solution
Implementing a peer-to-peer (P2P) offline access mode that allows an offline enrolled client device to communicate its compliance status to a management service through an online enrolled client device, using a secure P2P channel to verify the offline device's compliance and enable access to enterprise resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a client device is offline, then the user cannot access enterprise resources such as data content or applications, but the device can maintain compliance with enterprise policies without constant Internet connectivity
Solution Approach 1:
The patent introduces a peer-to-peer communication channel as an intermediary between the offline client device and the management service. This intermediary allows compliance verification to occur without requiring direct Internet connectivity from the offline device, enabling resource access while maintaining policy compliance through the peer device that acts as a mediator.
Solution Approach 2:
The system performs preliminary compliance verification actions when the device is online, storing verification results that can be used later when the device is offline. This preliminary action allows the device to access enterprise resources during offline periods without needing to connect to the Internet at the moment of access.
2Reliability
If management services require online connectivity to verify compliance, then security is maintained, but users lose flexibility to access resources offline
Solution Approach 1:
The peer device serves as an intermediary that bridges the gap between compliance verification requirements and offline access needs. It establishes a secure P2P communication channel that allows the management service to verify compliance with the offline device without requiring the offline device to have direct Internet connectivity, thus maintaining security while enabling offline access.
Solution Approach 2:
The patent shifts the compliance verification process from a single-dimension direct connection model to a multi-dimensional peer-to-peer model. Instead of requiring the offline device to directly connect to the management service, the system uses a peer device as an intermediate node, adding a new dimension to the verification process that enables offline access while maintaining security.
3Ease of operation
If the system allows offline access without P2P verification, then ease of access is improved, but security and compliance cannot be ensured
Solution Approach 1:
The peer-to-peer verification channel acts as a security intermediary that enables offline access while maintaining compliance verification. The peer device mediates the verification process by establishing a secure communication channel with the offline device, allowing the management service to verify compliance without requiring direct Internet connectivity, thus enabling easy offline access while preventing security risks.
Solution Approach 2:
The system implements a feedback mechanism where the peer device provides verification feedback to the management service about the offline device's compliance status. This feedback loop ensures that even though the offline device cannot directly communicate with the management service, its compliance status is still verified and communicated back through the peer device, maintaining security while enabling offline access.
Data Source
AI summary
Disclosed are various embodiments for enabling an enrolled client device of a user to access an enterprise resource via a second enrolled client device of the user. One such method comprises launching, by the first client device, a peer-to-peer communication channel between the first client device and a second client device of the user that is online with the management server; transmitting, by the first client device, a peer-to-peer offline access mode request over the peer-to-peer communication channel for the first client device to be given access to an enterprise resource that is being managed by the management server, wherein the request includes instructions for the second client device to forward the request to the management server, wherein the request further includes enterprise resource identification and verification data showing that the first client device is in compliance with a compliancy policy of the management service.


