Platform Management Server for Secure Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT administrators face challenges in rapidly provisioning devices across various organizations due to the need for unique configurations, which can be time-consuming and costly, especially when switching between different enterprise mobility management (EMM) services and managing diverse device types.

Innovation Solution

A platform management server acts as an intermediary between EMMs and devices, applying configuration settings using common templates that include placeholders for sensitive data, ensuring secure and efficient device management by precomputing settings and resolving conflicts, while maintaining encryption for sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of each device is performed to enforce organization rules, then device security and compliance are ensured, but provisioning time and administrative effort increase significantly

Engineering Contradiction:
Improvedevice securityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device automatically performs self-provisioning by executing configuration instructions received from the management server, eliminating the need for manual administrator intervention. The device autonomously applies security policies, network settings, and software configurations based on its device type and organization requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Configuration templates are pre-configured with device-type-specific settings and security policies before deployment. The management server prepares and stores these templates in advance, allowing rapid provisioning when devices are deployed without requiring administrators to create configurations from scratch for each device.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If unique configurations are applied to each device type to meet specific requirements, then device functionality and security are optimized, but configuration complexity and administrative burden increase

Engineering Contradiction:
Improvedevice functionalityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The configuration system is segmented into device-type-specific templates, where each template contains pre-defined settings appropriate for that device category. This segmentation allows administrators to manage configurations at the template level rather than individual device level, reducing complexity while maintaining device-specific optimization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system automatically adjusts configuration parameters based on device type identification. When a device checks in, the management server determines the device type and applies the appropriate template with pre-configured parameters, eliminating the need for administrators to manually adjust complex settings for each device type.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If configuration templates are used for device provisioning, then provisioning speed and consistency improve, but adaptability to different device types and EMM services decreases

Engineering Contradiction:
Improveprovisioning speedVSAvoiddevice type adaptability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The management server implements a universal template system that can adapt to multiple device types and EMM services. Templates are designed with device-type-specific parameters that allow the same template framework to serve smartphones, tablets, laptops, and other devices while working with different EMM service providers through standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The configuration template system is dynamic and adaptable, allowing templates to be selected and modified based on the specific device type and EMM service being used. The system can automatically adjust template application based on device characteristics and service requirements, maintaining both speed and adaptability.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If multiple EMM services are supported with device-specific configurations, then service flexibility and device compatibility improve, but management overhead and costs increase

Engineering Contradiction:
ImproveEMM service flexibilityVSAvoidmanagement overhead
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The management server acts as an intermediary layer between administrators and multiple EMM services. It provides a unified interface for managing device configurations across different EMM providers, translating organization-wide policies into service-specific configurations automatically, thereby reducing management overhead while supporting multiple services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12107730B2Secure management of devices
Publication Date: 2024.10.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12107730B2 patent drawing
  • US12107730B2 patent drawing
  • US12107730B2 patent drawing

AI summary

This document relates to a process for supporting the management of a variety of types of deployed devices. Administrators utilizing enterprise services can provide generic configuration data using configuration templates, which can be provided to a management server. The management server can then precompute device-specific configuration settings and resolve any conflicts that may arise based on the configuration templates. The configuration templates can also include placeholders for secret values, and once a managed device checks in to the management server, the secret values can be retrieved from an applicable enterprise service and provided to the managed device at the time of applying the configuration template.