Terminal Device Capability Management via Segmented Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management solutions struggle to centrally manage and control device capabilities on terminals, particularly in security zones where functions like photography and videography need to be disabled to ensure information security.

Innovation Solution

A method and system that allow a terminal to execute device capability management operations based on received commands, using a device management agent and a device capability management agent to transition the status of device capabilities, such as enabling or disabling camera functions, through a device capability management object within a communication system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device capabilities are managed directly by users on terminals, then ease of operation is improved, but centralized control and information security are worsened

Engineering Contradiction:
Improveuser direct controlVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments device capability management into two distinct parts: a device management agent on the terminal that handles user interactions and local operations, and a management server that provides centralized control and security policies. This segmentation allows users to operate devices conveniently while the server ensures information security through centralized authorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a device management agent as an intermediary component on the terminal that mediates between user operations and device capabilities. This agent receives user requests, validates them against security policies from the management server, and executes authorized operations. The intermediary structure enables both user convenience and centralized security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized management of device capabilities is implemented, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidmanagement system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex security management logic from the terminal device and places it in a separate management server. The terminal only needs to implement a lightweight device management agent that communicates with the server, rather than containing all security management complexity locally. This extraction reduces terminal device complexity while maintaining centralized security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The management server provides universal security management capabilities that can be applied to multiple terminals and various device capabilities. By implementing security policies centrally, the system avoids duplicating complex security management logic in each terminal, reducing overall system complexity while maintaining robust information security across the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If all device operations are controlled by management server, then centralized control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecentralized controlVSAvoiduser direct control
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent implements dynamic control where the device management agent on the terminal can autonomously execute user operations within authorized boundaries, while the management server dynamically adjusts control based on security policies and operational context. This dynamic approach allows routine operations to proceed quickly with minimal server intervention, while maintaining centralized control for security-critical operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The management server performs preliminary actions by pre-configuring security policies and authorization rules before user operations occur. The device management agent receives these pre-established guidelines and can autonomously make decisions within the predefined boundaries, eliminating the need for real-time server approval for every operation while maintaining centralized control framework.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9838267B2Method for executing management operation by communication terminal and a terminal and system thereof
Publication Date: 2017.12.05 HUAWEI TECH CO LTD
  • US9838267B2 patent drawing
  • US9838267B2 patent drawing
  • US9838267B2 patent drawing

AI summary

A method for executing a management operation by a terminal in a communications system. The method comprises the followings: The terminal receives the management operation commands that indicate the operation to target operation nodes in the device capability management object and operates them. The said operation initiates the process for executing the corresponding device capability management operation, then the said management operation transfers the device capability status. Also, the corresponding terminal and system are disclosed. The present invention can centrally manage and control the terminal capability.