IP Library Granted Patent US 10,470,148
Granted Patent B2
US 10,470,148 · App. 16/013,434 · Granted Nov 5, 2019

Mobile device management

Inventors: Michael Stricklen (Manchester, NH); Thomas McHale (Reston, VA); Marc Caminetsky (Newton, MA); Venkat Reddy Pagadala (Hyderabad, IN)
Assignee: CA, Inc.
H04W60/00H04L67/125H04W8/20H04W8/22H04W12/06H04W24/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,470,148
App. No.
16/013,434
Granted
Nov 5, 2019
Kind
B2
Abstract

The invention provides systems and methods for managing mobile devices of supported by different platforms. In some embodiments, the invention provides this management capability by utilizing one or more agents or modules native to the platforms themselves to provide interaction with individual mobile. In some embodiments, the invention provides an abstraction layer by which management tasks or other functions relating to mobile devices of different types may be generally defined and translated for application to mobile devices supported by different platforms. In some embodiments, the invention utilizes existing organizational structure of an enterprise or organization to define management permission for mobile device administrators and end users as well as to define policy configuration schemes for mobile devices. In some embodiments, the invention tracks the lifecycle of mobile devices within an enterprise or organization as assets within the organization.

Claims (126)

1. A method, comprising:

at least partially specifying, with one or more processors, configurations of mobile computing devices of users of an enterprise with a mobile device management (MDM) application based on mobile-device configuration policies;

updating, with one or more processors, records of the MDM application with changes in user profiles obtained from an enterprise directory of the enterprise;

changing, with one or more processors, specified configurations of at least some of the mobile computing devices based on both changes indicated by the updated records in group membership of users associated with the at least some of the mobile computing devices and one of the mobile-device configuration policies corresponding to the group; and

causing, with one or more processors, with the MDM application, via instructions sent wirelessly to mobile computing devices on a plurality of different mobile-device platforms, the at least some of the mobile computing devices to change to the changed specified configuration, wherein the MDM application is configured to manage mobile computing devices on the plurality of different mobile-device platforms based on information about users obtained via the enterprise directory, and wherein:

specifying configurations of mobile computing devices comprises specifying logical states of the mobile computing devices; and

the method comprises executing a compliance scan and reporting which mobile computing devices are out of compliance.

2. The method of claim 1 , wherein:

the MDM application stores the one of the mobile-device configuration policies and the policy indicates that the policy is applicable to members of the group;

the policy specifies the changed specified configuration; and

the update indicates that a user or users associated with the at least some of the mobile computing devices became members of the group in the enterprise directory.

3. The method of claim 2 , wherein:

the user or users associated with the at least some of the mobile computing devices become members of the group in virtue of the enterprise directory documenting the user or users changing role in the enterprise; and

the group is defined, at least in part, by role in the enterprise as designated by the enterprise directory.

4. The method of claim 1 , wherein:

the changed specified configuration is determined based on both user location indicated by the enterprise directory and a change in group membership indicated by the enterprise directory; and

the one of the mobile-device configuration policies of the MDM application includes criteria identifying the group and the location; and

the one of the mobile-device configuration policies of the MDM application specifies the changed configuration.

5. The method of claim 1 , wherein:

the enterprise directory is a Lightweight Directory Access Protocol (LDAP) directory; and

the method comprises steps for applying a policy to an end user group of mobile devices.

6. The method of claim 1 , wherein:

different mobile devices on different mobile-device platforms are caused to change configurations via different respective platform-specific agents external to the MDM application.

7. The method of claim 1 , wherein:

the MDM application is configured to determine a level of access to the MDM application based on enterprise role indicated by the update from the enterprise directory.

8. The method of claim 1 , wherein:

changing the specified configuration is based a plurality of configuration sets that are associated with the group in the one of the mobile-device configuration policies.

9. The method of claim 1 , wherein:

the MDM application is configured to synchronize enterprise role information with the enterprise directory on a scheduled basis and change mobile device configurations in response to changes indicated by the synchronizations.

10. The method of claim 1 , wherein:

the update is from a synchronization initiated responsive to the addition of a new user or mobile device; and

the synchronization is one-way, from the enterprise directory to the MDM application.

11. The method of claim 1 , wherein:

group membership is defined, at least in part, by both a job title and a location; and

the method comprises steps for managing mobile devices.

12. The method of claim 1 , wherein:

the MDM application is configured to manage mobile computing devices by managing configuration of at least three of the following on mobile computing devices:

a Bluetooth interface;

a browser;

a password policy, or

use of a camera.

13. The method of claim 1 , wherein;

the MDM application is configured to present an asset tracking dashboard indicating state of managed mobile computing devices, and

the MDM application is configured to wirelessly effectuate management tasks comprising at least three of the following:

activating or deactivating mobile computing devices,

wiping part of the contents of mobile computing devices,

changing a policy or other configuration on mobile computing devices,

obtaining status information from mobile computing devices,

rebooting mobile computing devices, or

displaying histories of operations performed by mobile computing devices.

14. The method of claim 1 , wherein:

the MDM application stores the one of the mobile-device configuration policies and the policy indicates that the policy is applicable to members of the group;

the policy specifies the changed specified configuration;

the update indicates that a user or users associated with the at least some of the mobile computing devices became members of the group in the enterprise directory;

the user or users associated with the at least some of the mobile computing devices become members of the group in virtue of the enterprise directory documenting the user or users changing role in the enterprise;

the group is defined, at least in part, by role in the enterprise as designated by the enterprise directory;

the changed specified configuration is determined based on both user location indicated by the enterprise directory and a change in group membership indicated by the enterprise directory;

the one of the mobile-device configuration policies of the MDM application includes criteria identifying the group and the location;

the one of the mobile-device configuration policies of the MDM application specifies the changed configuration;

specifying configurations of mobile computing devices comprises specifying logical states of the mobile computing devices;

the method comprises executing a compliance scan and reporting which mobile computing devices are out of compliance;

the enterprise directory is a Lightweight Directory Access Protocol (LDAP) directory;

different mobile devices on different mobile-device platforms are caused to change configurations via different respective platform-specific agents external to the MDM application;

the MDM application is configured to manage mobile computing devices by managing configuration of each of the following on mobile computing devices:

a Bluetooth interface;

a browser;

a password policy, or

use of a camera;

the MDM application is configured to present an asset tracking dashboard indicating state of managed mobile computing devices, and

the MDM application is configured to wirelessly effectuate management tasks comprising at least five of the following:

activating or deactivating mobile computing devices,

wiping part of the contents of mobile computing devices,

changing a policy or other configuration on mobile computing devices,

obtaining status information from mobile computing devices,

rebooting mobile computing devices, or

displaying histories of operations performed by mobile computing devices.

15. A tangible, non-transitory, machine-readable medium storing instructions that when executed by one or more processors effectuate operations comprising:

at least partially specifying, with one or more processors, configurations of mobile computing devices of users of an enterprise with a mobile device management (MDM) application based on mobile-device configuration policies;

updating, with one or more processors, records of the MDM application with changes in user profiles obtained from an enterprise directory of the enterprise;

changing, with one or more processors, specified configurations of at least some of the mobile computing devices based on both changes indicated by the updated records in group membership of users associated with the at least some of the mobile computing devices and one of the mobile-device configuration policies corresponding to the group; and

causing, with one or more processors, with the MDM application, via instructions sent wirelessly to mobile computing devices on a plurality of different mobile-device platforms, the at least some of the mobile computing devices to change to the changed specified configuration,

wherein the MDM application is configured to manage mobile computing devices on the plurality of different mobile-device platforms based on information about users obtained via the enterprise directory, and wherein the MDM application is configured to synchronize enterprise role information with the enterprise directory on a scheduled basis and change mobile device configurations in response to changes indicated by the synchronizations.

16. The medium of claim 15 , wherein:

the changed specified configuration is determined based on both user location indicated by the enterprise directory and a change in group membership indicated by the enterprise directory;

the enterprise directory is a Lightweight Directory Access Protocol (LDAP) directory; and

the MDM application is configured to determine a level of access to the MDM application based on enterprise role indicated by the update from the enterprise directory.

17. The medium of claim 15 , wherein:

different mobile devices on different mobile-device platforms are caused to change configurations via different respective platform-specific agents external to the MDM application; and

the MDM application is configured to wirelessly effectuate management tasks comprising at least two of the following:

activating or deactivating mobile computing devices,

wiping part of the contents of mobile computing devices,

changing a policy or other configuration on mobile computing devices,

obtaining status information from mobile computing devices,

rebooting mobile computing devices, or

displaying histories of operations performed by mobile computing devices.

18. The medium of claim 15 , wherein:

the different mobile-device platforms correspond to different mobile-device makers;

the different mobile-device platforms comprise three or more mobile-device platforms; and

the one of the mobile-device configuration policies is based on a policy template provided by the MDM application.

19. The medium of claim 15 , wherein:

group membership is defined, at least in part, by both a job title and a location; and

the method comprises steps for managing mobile devices.

20. A tangible, non-transitory, machine-readable medium storing instructions that when executed by one or more processors effectuate operations comprising:

obtaining, with one or more processors executing at least part of a mobile device management (MDM) application, access to:

user records associating a respective mobile computing device with a respective user in an enterprise managing mobile computing devices with the MDM application,

a plurality of policies specifying configuration settings applicable to mobile computing devices to which the respective policy applies, and

policy criteria at least partially indicating which policies apply to which mobile computing devices, wherein a given policy among the plurality of policies has a given policy criterion specifying that applicability of the given policy to mobile computing devices is based on mobile computing devices being associated with users having membership in a given user group;

synchronizing, with one or more processors executing at least part of MDM application, the MDM application with an enterprise directory by updating program state of the MDM application to include membership of users in groups designated in the enterprise directory, wherein the enterprise directory is configured to authenticate users to a network or other information technology resources of the enterprise;

in response to the synchronizing, with one or more processors executing at least part of MDM application, determining that a first user is in the given user group and that the first users is associated with a first mobile device on a first mobile-device platform based on at least some of the user records;

in response to the determination regarding the first user, with one or more processors executing at least part of MDM application, causing an over the air update to the first mobile device that applies the given policy to the first mobile device;

in response to the synchronizing, with one or more processors executing at least part of MDM application, determining that a second user is in the given user group and that the second users is associated with a second mobile device on a second mobile-device platform based on at least some of the user records, the second mobile-device platform being a different mobile-device platform from the first mobile-device platform; and

in response to the determination regarding the second user, with one or more processors executing at least part of MDM application, causing an over the air update to the second mobile device that applies the given policy to the second mobile device.

21. A tangible, non-transitory, machine-readable medium storing instructions that when executed by one or more processors effectuate operations comprising:

at least partially specifying, with one or more processors, configurations of mobile computing devices of users of an enterprise with a mobile device management (MDM) application based on mobile-device configuration policies;

updating, with one or more processors, records of the MDM application with changes in user profiles obtained from an enterprise directory of the enterprise;

changing, with one or more processors, specified configurations of at least some of the mobile computing devices based on both changes indicated by the updated records in group membership of users associated with the at least some of the mobile computing devices and one of the mobile-device configuration policies corresponding to the group; and

causing, with one or more processors, with the MDM application, via instructions sent wirelessly to mobile computing devices on a plurality of different mobile-device platforms, the at least some of the mobile computing devices to change to the changed specified configuration, wherein the MDM application is configured to manage mobile computing devices on the plurality of different mobile-device platforms based on information about users obtained via the enterprise directory, wherein:

the changed specified configuration is determined based on both user location indicated by the enterprise directory and a change in group membership indicated by the enterprise directory; and

the one of the mobile-device configuration policies of the MDM application includes criteria identifying the group and the location; and

the one of the mobile-device configuration policies of the MDM application specifies the changed configuration.

22. A tangible, non-transitory, machine-readable medium storing instructions that when executed by one or more processors effectuate operations comprising:

at least partially specifying, with one or more processors, configurations of mobile computing devices of users of an enterprise with a mobile device management (MDM) application based on mobile-device configuration policies;

updating, with one or more processors, records of the MDM application with changes in user profiles obtained from an enterprise directory of the enterprise;

changing, with one or more processors, specified configurations of at least some of the mobile computing devices based on both changes indicated by the updated records in group membership of users associated with the at least some of the mobile computing devices and one of the mobile-device configuration policies corresponding to the group; and

causing, with one or more processors, with the MDM application, via instructions sent wirelessly to mobile computing devices on a plurality of different mobile-device platforms, the at least some of the mobile computing devices to change to the changed specified configuration, wherein the MDM application is configured to manage mobile computing devices on the plurality of different mobile-device platforms based on information about users obtained via the enterprise directory, wherein:

the MDM application is configured to synchronize enterprise role information with the enterprise directory on a scheduled basis and change mobile device configurations in response to changes indicated by the synchronizations.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2019
From: STRICKLEN, MICHAEL; MCHALE, THOMAS; CAMINETSKY, MARC; REDDY, VENKAT
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 050468/0521 →
MERGER Recorded Sep 24, 2019
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 050468/0583 →
Continuity (4)
Continuation 14556829 · Dec 1, 2014
Division 11841256 · Aug 20, 2007
Provisional Application 60838366 · Aug 18, 2006
Related Publication 20190141655A1 · May 9, 2019