Terminal Device Capability Management via Segmented Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management solutions struggle to centrally manage and control device capabilities on terminals, particularly in security zones where functions like photography and videography need to be disabled to ensure information security.
Innovation Solution
A method and system that allow a terminal to execute device capability management operations based on received commands, using a device management agent and a device capability management agent to transition the status of device capabilities, such as enabling or disabling camera functions, through a device capability management object within a communication system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device capabilities are managed directly by users on terminals, then ease of operation is improved, but centralized control and information security are worsened
Solution Approach 1:
The patent segments device capability management into two distinct parts: a device management agent on the terminal that handles user interactions and local operations, and a management server that provides centralized control and security policies. This segmentation allows users to operate devices conveniently while the server ensures information security through centralized authorization.
Solution Approach 2:
The patent introduces a device management agent as an intermediary component on the terminal that mediates between user operations and device capabilities. This agent receives user requests, validates them against security policies from the management server, and executes authorized operations. The intermediary structure enables both user convenience and centralized security control.
2Reliability
If centralized management of device capabilities is implemented, then information security is improved, but device complexity increases
Solution Approach 1:
The patent extracts complex security management logic from the terminal device and places it in a separate management server. The terminal only needs to implement a lightweight device management agent that communicates with the server, rather than containing all security management complexity locally. This extraction reduces terminal device complexity while maintaining centralized security control.
Solution Approach 2:
The management server provides universal security management capabilities that can be applied to multiple terminals and various device capabilities. By implementing security policies centrally, the system avoids duplicating complex security management logic in each terminal, reducing overall system complexity while maintaining robust information security across the network.
3Extent of automation
If all device operations are controlled by management server, then centralized control is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements dynamic control where the device management agent on the terminal can autonomously execute user operations within authorized boundaries, while the management server dynamically adjusts control based on security policies and operational context. This dynamic approach allows routine operations to proceed quickly with minimal server intervention, while maintaining centralized control for security-critical operations.
Solution Approach 2:
The management server performs preliminary actions by pre-configuring security policies and authorization rules before user operations occur. The device management agent receives these pre-established guidelines and can autonomously make decisions within the predefined boundaries, eliminating the need for real-time server approval for every operation while maintaining centralized control framework.
Data Source
AI summary
A method for executing a management operation by a terminal in a communications system. The method comprises the followings: The terminal receives the management operation commands that indicate the operation to target operation nodes in the device capability management object and operates them. The said operation initiates the process for executing the corresponding device capability management operation, then the said management operation transfers the device capability status. Also, the corresponding terminal and system are disclosed. The present invention can centrally manage and control the terminal capability.


