IP Library Granted Patent US 9,921,819
Granted Patent B2
US 9,921,819 · App. 14/584,681 · Granted Mar 20, 2018

Persistent mobile device enrollment

Inventors: Spencer Reagan (Atlanta, GA); Prasad Sawant (Atlanta, GA)
Assignee: AirWatch LLC
G06F8/61H04L63/0807H04L63/0869H04L63/0876H04L67/32H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,921,819
App. No.
14/584,681
Granted
Mar 20, 2018
Kind
B2
Abstract

Embodiments of the disclosure are directed to a persistent enrollment of a device in a management system. Upon detection of a triggering event, detection of whether an activator application is installed is performed. Then, detection of whether an agent application is installed also performed. The agent application can then complete an enrollment of the device with a management system. Certain components of such a process can be bundled with the device operating system or as a system application.

Claims (44)

1. A method for persistently enrolling a client device with a management system, comprising:

determining, by a loader service application installed on a client device, in response to determining that the client device has been powered on, whether an activator application is installed upon the client device, the activator application being configured to initiate registration with the management system by obtaining an agent application;

transmitting, from the client device, an indication that the activator application is not installed to a first computing environment external to the client device and accessible through a network;

obtaining, from the first computing environment, the activator application in response to determining that the activator application is not installed;

installing, on the client device, the activator application in response to determining that the activator application is not installed;

determining, by the activator application, whether the agent application is installed on the client device, the agent application being configured to enroll the client device with the management system; and

obtaining, by the activator application, the agent application from a second computing environment accessible through the network in response to determining that the agent application is not installed on the client device.

2. The method of claim 1 , further comprising:

transmitting, from the activator application, a device identifier associated with the client device to the second computing environment; and

obtaining, using the activator application, a credential associated with an account in the second computing environment.

3. The method of claim 2 , further comprising enrolling the client device in a management system implemented by the second computing environment using the credential associated with the account.

4. The method of claim 2 , wherein the credential comprises an authentication token associated with a user account in a management system.

5. The method of claim 1 , further comprising installing, by the activator application, the agent application on the client device in response to determining that the agent application is not installed on the client device.

6. The method of claim 1 , wherein the activator application is platform-signed by a private key associated with an original equipment manufacturer associated with the client device.

7. The method of claim 1 , wherein determining whether the agent application is installed on the client device further comprises detecting, using the activator application, deletion of the agent application from the client device.

8. The method of claim 7 , wherein detecting deletion of the agent application from the client device further comprises obtaining, using the activator application, an event triggered by the agent application signifying uninstallation of the agent application.

9. A non-transitory computer-readable medium embodying program instructions executable in a client device that persistently enroll a client device with a management system, the program instructions being configured to cause the client device to at least:

determine, by a loader service application installed on the client device, in response to determining that the client device has been powered on, whether an activator application is installed upon the client device, the activator application being configured to initiate registration with the management system by obtaining an agent application;

transmit, to a first computing environment external to the client device, an indication that the activator application is not installed upon the client device;

obtain the activator application in response to determining that the activator application is not installed;

install the activator application in response to determining that the activator application is not installed;

determine whether an agent application is installed on the client device, the agent application being configured to enroll the client device with the management system; and

obtain the agent application from a second computing environment accessible from the network in response to determining that the agent application is not installed on the client device.

10. The non-transitory computer-readable medium of claim 9 , the program further being configured to cause the client device to at least:

transmit a device identifier associated with the client device to the second computing environment; and

obtain a credential associated with an account in the second computing environment.

11. The non-transitory computer-readable medium of claim 10 , the program further being configured to cause the client device to at least enroll the client device in a management system implemented by the second computing environment using the credential associated with the account.

12. The non-transitory computer-readable medium of claim 9 , wherein startup of the client device comprises a boot-up of an operating system or a powering on of the client device.

13. The non-transitory computer-readable medium of claim 9 , the program further being configured to cause the client device to at least:

install the agent application on the client device in response to determining that the agent application is not installed on the client device.

14. The non-transitory computer-readable medium of claim 9 , wherein the activator application is platform-signed by a private key associated with an original equipment manufacturer associated with the client device.

15. The non-transitory computer-readable medium of claim 9 , wherein the agent application is determined to be installed on the client device by detecting deletion of the agent application from the client device.

16. The non-transitory computer-readable medium of claim 15 , wherein deletion of the agent application from the client device is detected by obtaining an event triggered by the agent application signifying uninstallation of the agent application.

17. A client device configured to be persistently enrolled with a management system, comprising:

an operating system executable by at least one processor associated with the client device; and

a loader service application bundled with the operating system, the loader service application, in response to the client device powering on, configured to cause the client device to at least:

determine that an activator application is not installed;

install, on the client device, the activator application in response to determining that the activator application is not installed, wherein the activator application is configured to initiate registration with the management system by obtaining an agent application; and

install, on the client device, an agent application on the client device in response to determining that the agent application is not installed, the agent application being configured to enroll the client device with the management system.

18. The client device of claim 17 , wherein the activator application is configured to activate elevated privileges within the client device without user intervention.

19. The client device of claim 17 , wherein the activator application is configured to:

transmit a device identifier associated with the client device to a second computing environment; and

obtain a credential associated with an account in the second computing environment.

20. The client device of claim 17 , wherein the loader service application is a system application bundled with the operating system and the activator application is platform-signed by a private key associated with an original equipment manufacturer associated with the client device.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2015
From: REAGAN, SPENCER; SAWANT, PRASAD
To: AIRWATCH LLC
Reel/Frame 036657/0909 →
Continuity (1)
Related Publication 20160188307A1 · Jun 30, 2016