Large-Scale Update Recovery for Corrupt Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large deployments of information handling systems, updating processes are time-consuming, and existing solutions for addressing corrupted or vulnerable updates are not optimal, often requiring manual intervention and multiple cycles.
Innovation Solution
An automated system for managing updates that includes a management server to identify corrupted or vulnerable applications, notify endpoints to skip problematic installations, and schedule corrective actions such as installing newer versions or uninstalling affected applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated update deployment is implemented, then update speed and productivity are improved, but the ability to respond to corrupted or vulnerable updates deteriorates
Solution Approach 1:
The system performs preliminary actions by automatically detecting corrupted or vulnerable updates before they are deployed to endpoints. The management server checks update integrity and vulnerability status in advance, allowing the system to prepare corrective actions (such as blocking the update or deploying a different version) before the problematic update reaches the endpoints, thus maintaining both speed and reliability.
Solution Approach 2:
The system implements feedback mechanisms where the management server continuously monitors update status, endpoint responses, and update integrity. When corruption or vulnerability is detected, the system receives feedback about the problematic update and automatically adjusts the deployment strategy, notifying endpoints to skip the problematic update or applying corrective actions, thereby maintaining reliability without sacrificing deployment efficiency.
2Reliability
If manual intervention is used for update remediation, then reliability of corrupted update response is improved, but time consumption and loss of time worsen
Solution Approach 1:
The system enables self-service by automatically detecting and remediating corrupted or vulnerable updates without requiring manual intervention. The management server autonomously identifies problematic updates, determines appropriate corrective actions (such as blocking the update, deploying an alternative version, or notifying endpoints), and executes these actions automatically across the deployment, thereby eliminating time consumption while maintaining high reliability through automated integrity checking and response.
3Productivity
If multiple update cycles are implemented, then completeness of update deployment is improved, but device complexity and operational complexity worsen
Solution Approach 1:
The system applies segmentation by dividing the update management process into distinct, manageable phases: update detection, integrity verification, vulnerability assessment, corrective action determination, and endpoint notification. This segmentation allows each phase to be handled independently and efficiently, reducing overall complexity while ensuring complete deployment through systematic progression through each segment.
Solution Approach 2:
The management server performs multiple functions within a single unified system: it monitors update status, detects corruption, identifies vulnerability, determines corrective actions, and notifies endpoints. This multi-functionality consolidates what would otherwise require multiple separate systems or cycles into one comprehensive update management platform, reducing operational complexity while maintaining deployment completeness.
Data Source
AI summary
An information handling system may include at least one processor and a memory. The information handling system may be configured to provide update management services for a group of managed information handling systems by: transmitting instructions to the group to deploy a first update policy, wherein the first update policy includes installation of a selected version of a selected application; determining that the selected version of the selected application is corrupt and/or subject to a known vulnerability; and transmitting instructions to the group to deploy a second update policy, wherein the second update policy includes: installation of a newer version of the selected application in response to a determination that the newer version is available; and uninstallation of the selected version of the selected application in response to a determination that the newer version is not available.


