Volume Encryption Suspension for Managed Device Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Device updates such as hardware, software, and firmware updates can fail or cause system failure when volume encryption is enforced, posing a challenge for enterprises managing mobile devices with unified endpoint management (UEM) services.
Innovation Solution
Implementing secure scheduled and on-demand volume encryption suspension mechanisms within a UEM service to enable updates on managed client devices, using cloud computing environments and UEM platforms to manage encryption policies, suspension limits, and recovery keys, allowing for temporary suspension of encryption during updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If volume encryption is enforced on client devices, then security is improved, but device updates may fail or cause system failure
Solution Approach 1:
The encryption state is made dynamic rather than static. The system temporarily suspends volume encryption during device updates and restores it after updates complete. This dynamic adjustment allows the system to adapt its security posture based on operational requirements, enabling updates to succeed while maintaining security during normal operation.
Solution Approach 2:
The system performs preliminary suspension of encryption before updates are applied and restores encryption after updates complete. By proactively managing the encryption state before and after update operations, the system prevents update failures while ensuring security is maintained during non-update periods.
2Productivity
If volume encryption is suspended to enable updates, then device update success is improved, but security risk increases
Solution Approach 1:
Encryption suspension is applied periodically and temporarily only when updates are being applied, rather than being continuously active or completely disabled. The system enters suspension mode during update operations and restores encryption afterward, creating a periodic pattern that balances update requirements with security maintenance.
Solution Approach 2:
The system monitors update status and provides feedback to control the encryption suspension state. When updates are detected as in progress, encryption is suspended; when updates complete or fail, encryption is restored. This feedback mechanism ensures encryption is suspended only when necessary for updates while automatically restoring security protection.
3Adaptability or versatility
If encryption is temporarily suspended during updates, then system adaptability is improved, but complexity of managing encryption policies increases
Solution Approach 1:
The unified endpoint management service acts as an intermediary between the encryption system and update operations. It receives update notifications, determines when encryption suspension is necessary, manages the suspension and restoration of encryption, and coordinates with both the update mechanism and encryption system. This intermediary simplifies policy management by centralizing control logic.
Data Source
AI summary
Examples of scheduled and on-demand volume encryption suspension are described. In some examples, volume encryption is to be suspended for a client device. A suspension limit is identified for a volume encryption suspension for the client device. A suspend encryption command is generated to include instructions for the client device to apply the volume encryption suspension according to the suspension limit. The suspend encryption command is transmitted to the client device for execution.


