Remote Device Onboarding via Kiosk Mode Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a bring-your-own-device (BYOD) environment, enterprises face risks due to lack of control over employee devices, which can be tampered with, stolen, or infected with malware, and training employees on corporate policies is costly and time-consuming, with no assurance that they have read or viewed important content.

Innovation Solution

A remote management service that disables device functions until employees complete onboarding by watching videos, signing agreements, and acknowledging policies, using a client application to authenticate users, determine their role, and enable device features only after required content is consumed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees are allowed to use personal devices to access enterprise data, then employee productivity and flexibility are improved, but device security control and data protection are worsened

Engineering Contradiction:
Improveemployee productivityVSAvoiddevice security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments device functionality into two categories: personal functions and enterprise functions. The kiosk mode creates a distinct segmented environment where enterprise applications and data are isolated from personal device operations, allowing employees to access enterprise resources while maintaining personal device control and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a kiosk mode as an intermediary layer between the employee's personal device and enterprise data. This intermediary environment acts as a controlled sandbox that mediates access to enterprise resources, providing security oversight while enabling productive work on personal devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If traditional employee training methods are used for policy education, then employees can be informed about corporate policies, but training cost and time consumption increase

Engineering Contradiction:
Improvepolicy understandingVSAvoidtraining time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent implements self-service onboarding where employees independently complete policy acknowledgments, watch required videos, and sign agreements at their own pace through the kiosk mode interface. This eliminates the need for organized training sessions while ensuring all employees receive and acknowledge required information

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system requires employees to complete all onboarding tasks (watching videos, signing agreements, acknowledging policies) before gaining access to enterprise functions. This preliminary action ensures policy understanding occurs before productivity begins, eliminating the need for separate training phases

Inventive Principle:
Principle #10Preliminary action

3Productivity

If device functions are enabled immediately upon enrollment, then employee productivity is improved, but policy compliance verification is worsened

Engineering Contradiction:
Improveemployee productivityVSAvoidpolicy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent requires employees to complete all onboarding tasks (policy acknowledgments, video viewing, agreement signing) before enterprise device functions are enabled. This preliminary action sequence ensures policy compliance is verified and recorded before any productive work can occur, making compliance a prerequisite for productivity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9510182B2User onboarding for newly enrolled devices
Publication Date: 2016.11.29 OMNISSA LLC
  • US9510182B2 patent drawing
  • US9510182B2 patent drawing
  • US9510182B2 patent drawing

AI summary

Disclosed are various embodiments for onboarding users of devices newly enrolled with a remote service. According to various embodiments described herein, a computing environment operated by an enterprise can be employed to disable a function of a client device owned or operated by a user. The computing environment is employed to determine a role of the user. Content to be presented on the client device can be determined based at least in part on the role of the user. In response to a determination that the content has been presented to, viewed, and/or consumed by the user of the client device, the computing environment may remotely enable the previously disabled function of the client device.