IP Library › Granted Patent US 10,742,743
Granted Patent B2
US 10,742,743 · App. 16/195,146 · Granted Aug 11, 2020

Systems and methods for managing IOT/EOT devices

Inventors: Balasubrahmanyam Gattu (San Ramon, CA); Bryan Nelson Grunow (Raleigh, NC); Tyler Coffin (Guelph, CA); Michael John Higgs (Waterloo, CA)
Assignee: BlackBerry Limited
H04L67/125H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,743
App. No.
16/195,146
Granted
Aug 11, 2020
Kind
B2
Abstract

A method for managing enrollments of an IoT device is disclosed. The method includes: transmitting a request to enroll the device with a first device management service; receiving, from a server associated with the first device management service, a first policy profile including one or more first device management policies, the first policy profile defining at least one restriction on management of the device by other device management services with which the device enrolls; transmitting a request to enroll the device with a second device management service; receiving, from a server associated with the second device management service, a second policy profile including one or more second device management policies; identifying a subset of the one or more second device management policies which comply with the at least one restriction; and applying the identified subset of the one or more second device management policies on the device.

Claims (42)

1. A method implemented by an Internet-connected client device, the method comprising:

transmitting, to a server associated with a first device management service, a request to enroll the client device with the first device management service;

receiving, from the server associated with the first device management service, a first policy profile including one or more first device management policies, the first policy profile defining at least one restriction on management of the client device by other device management services with which the client device enrolls;

transmitting, to a server associated with a second device management service, an indication of the at least one restriction and a request to enroll the client device with the second device management service;

receiving, from the server associated with the second device management service, a second policy profile including one or more second device management policies;

identifying a subset of the one or more second device management policies which comply with the at least one restriction; and

applying the identified subset of the one or more second device management policies on the client device,

wherein the at least one restriction indicates one or more features of the client device which are not manageable by the second device management service.

2. The method of claim 1 , wherein the first device management service and the second device management service are implemented at different servers.

3. The method of claim 1 , further comprising installing, on the client device, at least one enrollment client application for managing enrollment of the client device with one or both of the first device management service and the second device management service.

4. The method of claim 3 , wherein the at least one enrollment client application comprises a first enrollment client application for managing enrollment of the client device with the first device management service and a second enrollment client application for managing enrollment of the client device with the second device management service.

5. The method of claim 1 , wherein the one or more first device management policies comprise first compliance rules and wherein the at least one restriction indicates one or more rules in addition to the first compliance rules that are required to be enforced by the second device management service.

6. The method of claim 1 , wherein the at least one restriction sets a limit on duration of device control by the second device management service.

7. The method of claim 1 , further comprising:

receiving, from the server associated with the first device management service, an instruction to terminate enrollment with the second device management service; and

in response to receiving the instruction, terminating the enrollment with the second device management service.

8. An Internet-connected client device, comprising:

memory;

a processor coupled to the memory, the processor being configured to:

transmit, to a server associated with a first device management service, a request to enroll the client device with the first device management service;

receive, from the server associated with the first device management service, a first policy profile including one or more first device management policies, the first policy profile defining at least one restriction on management of the client device by other device management services with which the device enrolls;

transmit, to a server associated with a second device management service, an indication of the at least one restriction and a request to enroll the client device with the second device management service;

receive, from the server associated with the second device management service, a second policy profile including one or more second device management policies;

identify a subset of the one or more second device management policies which comply with the at least one restriction; and

apply the identified subset of the one or more second device management policies on the client device,

wherein the at least one restriction indicates one or more features of the client device which are not manageable by the second device management service.

9. The device of claim 8 , wherein the first device management service and the second device management service are implemented at different servers.

10. The device of claim 8 , wherein the processor is further configured to install, on the client device, at least one enrollment client application for managing enrollment of the client device with one or both of the first device management service and the second device management service.

11. The device of claim 10 , wherein the at least one enrollment client application comprises a first enrollment client application for managing enrollment of the client device with the first device management service and a second enrollment client application for managing enrollment of the client device with the second device management service.

12. The device of claim 8 , wherein the one or more first device management policies comprise first compliance rules and wherein the at least one restriction indicates one or more rules in addition to the first compliance rules that are required to be enforced by the second device management service.

13. The device of claim 8 , wherein the at least one restriction sets a limit on duration of device control by the second device management service.

14. The device of claim 8 , wherein the processor is further configured to:

receive, from the server associated with the first device management service, an instruction to terminate enrollment with the second device management service; and

in response to receiving the instruction, terminate the enrollment with the second device management service.

15. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor in an Internet-connected client device, cause the processor to:

transmit, to a server associated with a first device management service, a request to enroll the client device with the first device management service;

receive, from the server associated with the first device management service, a first policy profile including one or more first device management policies, the first policy profile defining at least one restriction on management of the client device by other device management services with which the device enrolls;

transmit, to a server associated with a second device management service, an indication of the at least one restriction and a request to enroll the client device with the second device management service;

receive, from the server associated with the second device management service, a second policy profile including one or more second device management policies;

identify a subset of the one or more second device management policies which comply with the at least one restriction; and

apply the identified subset of the one or more second device management policies on the client device,

wherein the at least one restriction indicates one or more features of the client device which are not manageable by the second device management service.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2019
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 047886/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2018
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 047841/0252 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2018
From: GRUNOW, BRYAN NELSON
To: BLACKBERRY CORPORATION
Reel/Frame 047551/0447 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2018
From: GATTU, BALASUBRAHMANYAM
To: BLACKBERRY CORPORATION
Reel/Frame 047551/0562 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2018
From: COFFIN, TYLER; HIGGS, MICHAEL JOHN
To: BLACKBERRY LIMITED
Reel/Frame 047551/0630 →
Continuity (1)
Related Publication 20200162557A1 · May 21, 2020