Software Update Distribution via Non-Affiliated Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software updates may not be timely or accessible to clients when company servers are inaccessible due to reasons like bandwidth depletion or denial of service attacks.
Innovation Solution
Implementing a system where software updates are distributed through a network that includes both affiliated and non-affiliated servers, using update sets with time-to-live (TTL) values and cryptographic signatures, allowing user devices to independently authenticate and download updates even when the enterprise network is unavailable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software updates are distributed only through company servers, then enterprise control over updates is maintained, but updates become inaccessible when servers are unavailable due to bandwidth depletion or attacks
Solution Approach 1:
The patent segments the centralized update distribution system into multiple independent components: primary company servers, secondary non-affiliated servers, and local caching mechanisms. This segmentation allows updates to be distributed through alternative paths when primary servers are unavailable, improving reliability without requiring a completely complex new system architecture.
Solution Approach 2:
The patent introduces non-affiliated servers as intermediary nodes that can host and distribute update packages when company servers are inaccessible. These intermediaries act as backup distribution points, ensuring update availability while maintaining a manageable system structure through standardized protocols and interfaces.
2Reliability
If updates are made available through multiple network locations, then update accessibility is improved, but control over update timing and authenticity becomes difficult to maintain
Solution Approach 1:
The patent implements preliminary actions by digitally signing update packages with cryptographic signatures before distribution and pre-establishing trust relationships with authorized non-affiliated servers. This ensures that even when updates are distributed through multiple locations, the enterprise maintains control over timing and authenticity through pre-configured security mechanisms.
Solution Approach 2:
The patent incorporates feedback mechanisms where client devices report back to the enterprise about update installations and where the enterprise can remotely manage and control update distributions across all network locations. This feedback loop ensures continuous enterprise oversight and control while maintaining broad update availability.
3Speed
If update packages are distributed widely across the network, then download speed is improved, but bandwidth consumption increases
Solution Approach 1:
The patent implements partial distribution where update packages are selectively cached at non-affiliated servers and local devices based on predicted demand and priority levels. Not all updates are distributed to all locations, but rather only those likely to be needed, reducing overall bandwidth consumption while maintaining fast access for critical updates.
Solution Approach 2:
The patent uses preliminary actions by pre-distributing update packages to authorized servers and local caches before they are actually needed by clients. This proactive distribution allows updates to be available locally when needed, reducing real-time bandwidth consumption while maintaining fast download speeds through local retrieval.
Data Source
AI summary
Updates for an enterprise's software product are made available to user devices on-line, even when network resources of the enterprise are unavailable. Software update sets and notifications concerning the update sets may be published by an enterprise for consumption by content distribution partners of the enterprise and parties not affiliated with the enterprise. Each abstraction relating to an update, including update notifications and update sets may include a cryptographic signature for later use in authenticating the source of the abstraction. Update notifications also may include information indicative of: available update sets; and network locations at which the update sets can be accessed. Further, an update notification may be configured with a time-to-live (TTL) value indicating a value of time after which the notification expires. TTL values give the enterprise some control over the distribution of update sets by limiting the lifespan of the update notifications corresponding to the update sets.


