User-Centric Device Management via Agent Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing multiple mobile devices across a corporate network is cumbersome due to the need for administrators to manually select devices and protocols for policy application, as existing solutions do not efficiently associate management agents with users and management centers.

Innovation Solution

A system that simplifies device management by associating users with device management agents at a user or group level, allowing administrators to apply commands and policies without needing to know which agents manage which devices, enabling automatic identification and association of devices and users with management agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators manually select devices and protocols for policy application, then policy control can be applied to specific devices, but the management process becomes labor-consuming and complex

Engineering Contradiction:
Improveease of device managementVSAvoidtime for manual device selection
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service by automatically detecting management agents on the network and performing identification and association without administrator intervention. The management server autonomously discovers agents, gathers device information, identifies users, and creates associations between users, devices, and agents, eliminating the need for manual device selection and protocol configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-establishing the association infrastructure before policy application is needed. Management agents are pre-deployed on devices, and the system pre-configures the association mechanism between users, devices, and agents, so that when policies need to be applied, administrators can simply select users without needing to manually configure device connections.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple management protocols are supported on different devices, then device compatibility is improved, but the complexity of managing separate connections increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidcomplexity of managing multiple protocols
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The management server acts as an intermediary that handles the complexity of multiple protocols. Instead of administrators directly managing separate protocol connections, the server receives policy requests, automatically selects the appropriate protocol based on the target device, and routes the policy through the correct management agent, thereby hiding protocol complexity from users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal management interface that works across multiple protocols. The association mechanism between users, devices, and agents is protocol-agnostic, allowing the same user-level policy application approach to work regardless of which specific management protocol (EAS, iOS MDM, etc.) is used on the target device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If administrators need to know which agents manage which devices, then precise device control is achieved, but the operational burden and knowledge requirements increase

Engineering Contradiction:
Improveprecision of device controlVSAvoidease of policy application
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system adds a new dimension of abstraction by introducing user-level management as an intermediate layer between administrators and devices. Instead of managing devices directly (one-dimensional), administrators manage users who are associated with devices (two-dimensional), allowing precise device control through user associations without requiring administrators to know agent-device mappings.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If separate services manage different management agents, then protocol-specific functionality is maintained, but the lack of direct connection to specific devices reduces management efficiency

Engineering Contradiction:
Improveprotocol-specific management reliabilityVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system merges the functionality of separate protocol-specific services into a unified user-centric management framework. The management server combines multiple protocol handlers and integrates them with the user-device-agent association system, allowing a single policy application action to trigger the appropriate protocol-specific management functions while maintaining the reliability of each protocol's native capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2882138B1System and method for linking various protocols for controlling devices with their owners
Publication Date: 2019.10.23 AO KASPERSKY LAB
  • EP2882138B1 patent drawingFigure 1
  • EP2882138B1 patent drawingFigure 2
  • EP2882138B1 patent drawingFigure 3

AI summary

System and methods for the association of one or more devices over a computer network. A management agent module running on a device coupled to the network is configured to communicate with a server agent module running on a management server. An association linking the management agent with the server agent is created by the management server. Associations with device users and the agents managing the devices can also be made. Associations allow network administration commands and policy controls to be issued at a user, rather than device, level.