Remote Client Device Restriction via Management Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise environments, there is a need to restrict client devices from accessing unauthorized applications and data, particularly in scenarios like exams or classrooms, where test-takers or students should only access permitted applications and information to prevent cheating or distractions.

Innovation Solution

A management service and client application that allow administrators to remotely place client devices into a restricted mode, disabling application switching capabilities and limiting access to only authorized applications and networks, while providing remote monitoring and control through a management console.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If client devices are restricted to only permitted applications, then security and compliance are improved, but device functionality and user flexibility deteriorate

Engineering Contradiction:
Improvesecurity complianceVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts device functionality by implementing kiosk modes that can be activated or deactivated based on administrative decisions. The client application can switch between restricted and unrestricted states, allowing the device to adapt its functionality rather than being permanently limited. This resolves the contradiction by making the restriction temporary and controllable rather than fixed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters of the client device by modifying application execution permissions, network access rules, and interface behaviors through administrative commands. These parameter changes enable the device to operate in different modes (restricted vs. unrestricted) without permanent hardware modifications, thus maintaining versatility while achieving security compliance when needed.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If administrators implement remote monitoring and control, then security oversight is improved, but system complexity and administrative overhead increase

Engineering Contradiction:
Improvesecurity oversightVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The client application on each device provides self-service capabilities by automatically enforcing restrictions and monitoring its own state. The application includes built-in functionality to detect kiosk mode activation, control application execution, and report status back to administrators. This self-service approach reduces the need for complex external monitoring infrastructure while maintaining security oversight.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The management service and client application are designed as universal systems that can handle multiple administrative tasks through a single integrated platform. The same client application provides both restricted mode enforcement and monitoring capabilities, while the management service can control multiple devices from a central interface. This multi-functionality reduces overall system complexity compared to separate specialized tools for each administrative need.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12099689B2Remotely restricting client devices
Publication Date: 2024.09.24 OMNISSA LLC
  • US12099689B2 patent drawing
  • US12099689B2 patent drawing
  • US12099689B2 patent drawing

AI summary

Disclosed are various examples for remotely restricting client devices. A client device can be placed into a restricted mode in which application switching capabilities of the client device are disabled. Additionally, the client device can transmit screen capture data to a management service, which can provide the ability for an administrator user to monitor data shown on a display associated with the client device. The client device can also be removed from the restricted mode in response to a command sent from the management service to the client device.