Dynamic Patch Management in Virtual Desktop Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional patch management in Virtual Desktop Infrastructure (VDI) platforms is inefficient, leading to manpower wastage, downtime, and increased vulnerability to cyberattacks due to manual intervention, lack of real-time monitoring, and inability to identify and update virtual machines promptly.

Innovation Solution

A dynamic patch management method that retrieves operational and vulnerability remediation data, detects patching gaps, calculates a patch prediction score, and executes an optimal patching plan based on industrial standards and prediction parameters to minimize downtime and ensure timely updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual patch management is performed by shutting down virtual machines, then patches can be installed, but service availability deteriorates and downtime increases

Engineering Contradiction:
Improvepatch installation reliabilityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by identifying and prioritizing patches before shutdown is required. The patch management system analyzes patch requirements, determines priority levels, and prepares patching schedules in advance, allowing patches to be applied during planned maintenance windows rather than causing unexpected service interruptions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops by monitoring patch compliance status, service performance, and security vulnerability levels. This feedback enables dynamic adjustment of patching schedules and priorities, ensuring that critical security patches are applied while minimizing impact on service availability through informed decision-making.

Inventive Principle:
Principle #23Feedback

2Reliability

If continuous monitoring and real-time patch management is implemented, then security vulnerability detection improves, but system complexity increases

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidpatch management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patch management system is designed as a multi-functional platform that combines vulnerability scanning, patch analysis, compliance tracking, and automated deployment capabilities into a single unified system. This universal approach consolidates multiple functions that would otherwise require separate tools, reducing overall system complexity while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates self-service capabilities through automated patch compatibility testing, risk assessment, and deployment scheduling. The patch management system autonomously evaluates patches against the virtualized environment, determines optimal deployment timing, and executes patching operations without requiring constant manual intervention, thereby reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If patches are applied during business hours, then security updates are timely, but work interruption and productivity loss occur

Engineering Contradiction:
Improvepatch timelinessVSAvoidwork continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts patch deployment timing based on real-time monitoring of service usage patterns, business criticality levels, and user activity. Patches are automatically scheduled for deployment during periods of lowest impact, such as off-hours or maintenance windows, while critical security patches receive priority scheduling that balances security needs with business continuity requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patch management system implements periodic assessment and scheduling cycles that evaluate patch priorities, service availability requirements, and business operational patterns. This periodic action enables the system to identify optimal patching windows and schedule deployments in a rhythm that maintains security compliance while minimizing disruption to business operations.

Inventive Principle:
Principle #19Periodic action

4Productivity

If drone virtual machines are used for asynchronous patch management, then service interruption is reduced, but patching time and resource overhead increase

Engineering Contradiction:
Improveservice interruption minimizationVSAvoidpatching process time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system extracts the patching operation from the production virtualized environment by utilizing isolated patching infrastructure. Drone virtual machines or separate patching servers are employed to apply patches to cloned or snapshot versions of virtual machines, thereby completely isolating patching activities from production services and eliminating service interruption while managing patching time through efficient resource allocation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12001836B2Method and system for performing dynamic patch management in a virtual desktop infrastructure (VDI) platform
Publication Date: 2024.06.04 WIPRO LTD
  • US12001836B2 patent drawing
  • US12001836B2 patent drawing
  • US12001836B2 patent drawing

AI summary

The present disclosure is related to Virtual Desktop Infrastructure (VDI) that discloses a method and system for performing dynamic patch management in VDI platform. A patch managing system retrieves operational data and vulnerability remediation data related to IT services and infrastructures of the VDI platform from first and second data sources. Thereafter, the patch managing system detects gap in patching level based on operational data, vulnerability remediation data and corresponding industrial standard, and rolls out patches based on detected gap in patching level. Further, a patch prediction score that facilitates in identifying a probability of rolling back the patches rolled out for patching IT services and infrastructures of VDI platform is determined based on prediction parameters. A plan is generated based on the patch prediction score and executed to optimally patch the patches to IT services and infrastructures of the VDI platform, based on patching rules.