Remote Enterprise Policy Configuration via Signed Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise computing device management systems face security risks due to administrators inadvertently or maliciously corrupting operating system settings and require cumbersome login credential management for multiple devices, lacking a secure and efficient solution for remote policy/client configuration updates.
Innovation Solution
A computing device with an operating system enterprise control module that receives and authenticates updated enterprise policy/client configurations via a network, ensuring that at least a portion of the configuration can only be updated through a message with a valid signature, eliminating the need for a local administrator mode and simplifying credential management by allowing a single administrator to manage multiple devices remotely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a local administrator mode is provided on computing devices, then administrators can adjust operating system settings and configurations, but users may inadvertently or maliciously corrupt the operating system settings or configurations
Solution Approach 1:
The patent extracts the administrator authentication and configuration update functionality from the local device level to a remote server level. The server validates administrator credentials and signs configuration updates, preventing local users from corrupting system settings even if they have physical access to the device.
Solution Approach 2:
The patent introduces a remote server as an intermediary between the administrator and the computing devices. The server acts as a trusted mediator that authenticates administrators and securely distributes configuration updates, eliminating the need for local administrator modes that could be compromised.
2Reliability
If an administrator maintains multiple login identifiers and passwords for multiple devices, then each device can be administered securely, but the administrator needs to memorize or maintain multiple credentials
Solution Approach 1:
The patent implements a universal authentication system where a single administrator account can access and manage multiple computing devices through the remote server. The server handles device-specific authentication internally, allowing the administrator to work with a single set of credentials across the entire device fleet.
Solution Approach 2:
The patent merges multiple device-specific authentication mechanisms into a single centralized authentication system. Instead of requiring separate login credentials for each device, the system combines all authentication functions into one remote server that manages access to multiple devices uniformly.
3Device complexity
If an administrator uses a single login identifier and password for all devices, then credential management is simplified, but all devices may be compromised if the credentials are learned by another person
Solution Approach 1:
The patent segments the authentication and authorization functions across multiple levels: the remote server handles universal administrator authentication, while device-specific access control and configuration validation occur at the server level before distribution. This segmentation allows a single administrator account to manage multiple devices without exposing all devices to a single point of compromise.
4Adaptability or versatility
If enterprise policy/client configuration can be updated locally without network access, then devices can be updated offline, but security risks increase from unauthorized local modifications
Solution Approach 1:
The patent implements preliminary action by requiring that all configuration updates be authenticated and signed by the remote server before being distributed to devices. The server performs security validation in advance, and devices only execute pre-approved, signed configuration updates, eliminating the need for runtime local administrator privileges.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for remote an enterprise policy/client configuration installation for client computing devices are provided. In some aspects, a method includes receiving, on a client computing device, via a network, a message including an updated enterprise policy/client configuration associated with an operating system and a signature. The signature identities a source of the message. The method also includes authenticating the message based on the signature. The method also includes installing the updated an enterprise policy/client configuration. At least a first portion of an enterprise policy/client configuration is configured not to be updatable without receiving the message via the network.