Automated Software Deployment via Device-Specific Parameter Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions fail to efficiently and automatically deploy preconfigured software on diverse user devices across a computer network, considering varying security policies, user access rights, and device configurations, especially in large enterprises with mixed infrastructure and personal devices lacking administration tools.

Innovation Solution

A system comprising a task manager and configurator module that custom-configures software installation packages based on user and device attributes, including access privilege levels and network connectivity, to create tailored installation packages and data transfer channels suitable for each device, enabling automated deployment across multiple user devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If remote administration tools are used to manage user devices, then administrators can set up security tools after installation, but these tools cannot be installed on all computer systems especially personal devices without administration agents

Engineering Contradiction:
Improvedevice compatibilityVSAvoidautomatic deployment capability
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent introduces a data store as an intermediary component that stores installation parameters for multiple user devices. This data store acts as a mediator between the administration server and diverse user devices, enabling the system to retrieve device-specific installation parameters without requiring administration agents on the target devices. This resolves the contradiction by providing a universal mechanism that works across different device types and operating systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-storing installation parameters for multiple user devices in a data store before actual software deployment. The administration server retrieves these pre-configured parameters based on device identifiers, enabling automatic customization of installation packages without real-time interaction with each device. This allows seamless deployment on personal devices without administration agents while maintaining device-specific configuration.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If security software is deployed across diverse devices with different configurations, then coverage is improved, but the complexity of configuring each device individually increases significantly

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by storing multiple sets of installation parameters in a data store, each set corresponding to different user devices. The administration server dynamically retrieves and applies the appropriate parameter set based on the target device identifier. This allows the system to handle device diversity through parameter variation rather than structural complexity, maintaining simple deployment processes while adapting to different device configurations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the configuration management by separating device-specific installation parameters from the core installation package. Each user device has its own parameter set stored in the data store, which is retrieved and applied during deployment. This segmentation allows the administration server to manage diverse device configurations through simple parameter retrieval rather than complex device-by-device configuration procedures.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual configuration of security software is performed on each device, then security policies can be properly applied, but administrative time and effort increase substantially

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the administration server to automatically retrieve and apply device-specific installation parameters from the data store without requiring manual administrator intervention for each device. The system uses device identifiers to automatically match the correct security policy parameters, ensuring compliance while eliminating repetitive manual configuration tasks. This maintains reliable security policy application across all devices while dramatically reducing administrative time investment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2750350B1System and method for deploying preconfigured software
Publication Date: 2017.03.29 AO KASPERSKY LAB
  • EP2750350B1 patent drawing
  • EP2750350B1 patent drawing
  • EP2750350B1 patent drawing

AI summary

Automated deployment of a security application user agent to be installed via a software installation package onto different user devices ((100), (101), (102), (103), (200)) for different users. An initial software installation package (131), is obtained, along with information representing (a) associations between the users and the user devices, (b) user attributes from which access privilege level information for individual users is determinable, and (c) device attributes for each of the plurality of user devices, including network connectivity information. The initial software installation package (131) is custom-configured for individual user devices based on the information representing (a) and (b) to produce different specially-configured software installation packages (141). Each one includes installation parameters that establish functionality for the security application user agent based on the access privilege level of the corresponding user. Data transfer channels are custom-configured for individual user devices based on the information representing (a) and (c).