Volume Encryption Suspension for Managed Device Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Device updates such as hardware, software, and firmware updates can fail or cause system failure when volume encryption is enforced, posing a challenge for enterprises managing mobile devices with unified endpoint management (UEM) services.

Innovation Solution

Implementing secure scheduled and on-demand volume encryption suspension mechanisms within a UEM service to enable updates on managed client devices, using cloud computing environments and UEM platforms to manage encryption policies, suspension limits, and recovery keys, allowing for temporary suspension of encryption during updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If volume encryption is enforced on client devices, then security is improved, but device updates may fail or cause system failure

Engineering Contradiction:
ImprovesecurityVSAvoiddevice update success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The encryption state is made dynamic rather than static. The system temporarily suspends volume encryption during device updates and restores it after updates complete. This dynamic adjustment allows the system to adapt its security posture based on operational requirements, enabling updates to succeed while maintaining security during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary suspension of encryption before updates are applied and restores encryption after updates complete. By proactively managing the encryption state before and after update operations, the system prevents update failures while ensuring security is maintained during non-update periods.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If volume encryption is suspended to enable updates, then device update success is improved, but security risk increases

Engineering Contradiction:
Improvedevice update success rateVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Encryption suspension is applied periodically and temporarily only when updates are being applied, rather than being continuously active or completely disabled. The system enters suspension mode during update operations and restores encryption afterward, creating a periodic pattern that balances update requirements with security maintenance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system monitors update status and provides feedback to control the encryption suspension state. When updates are detected as in progress, encryption is suspended; when updates complete or fail, encryption is restored. This feedback mechanism ensures encryption is suspended only when necessary for updates while automatically restoring security protection.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If encryption is temporarily suspended during updates, then system adaptability is improved, but complexity of managing encryption policies increases

Engineering Contradiction:
Improveupdate capabilityVSAvoidencryption policy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The unified endpoint management service acts as an intermediary between the encryption system and update operations. It receives update notifications, determines when encryption suspension is necessary, manages the suspension and restoration of encryption, and coordinates with both the update mechanism and encryption system. This intermediary simplifies policy management by centralizing control logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11805108B2Secure volume encryption suspension for managed client device updates
Publication Date: 2023.10.31 OMNISSA LLC
  • US11805108B2 patent drawing
  • US11805108B2 patent drawing
  • US11805108B2 patent drawing

AI summary

Examples of scheduled and on-demand volume encryption suspension are described. In some examples, volume encryption is to be suspended for a client device. A suspension limit is identified for a volume encryption suspension for the client device. A suspend encryption command is generated to include instructions for the client device to apply the volume encryption suspension according to the suspension limit. The suspend encryption command is transmitted to the client device for execution.