Update Management for Non-Domain Devices via Local Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT departments in corporate settings lack control over updating computing devices that are not joined to a domain, as they cannot test or manage updates for non-domain devices, leading to uncontrolled and potentially incompatible software updates.

Innovation Solution

A management agent on the device communicates with a management service to enroll and configure the device to use a specific update service, such as WSUS, without requiring domain membership, allowing IT to manage and control update installations for all devices, including those not connected to a directory service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If devices are joined to a domain to enable centralized update management, then update control and testing capability is improved, but device enrollment complexity and network configuration requirements worsen

Engineering Contradiction:
Improveupdate management controlVSAvoiddomain joining requirement
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent extracts the update management functionality from the domain joining requirement. Instead of requiring devices to be domain-joined to enable centralized update control, the solution allows standalone devices to be managed through local configuration files and automated update agents that can communicate with external update servers, thereby separating update management capability from domain membership

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary configuration mechanism that bridges standalone devices and centralized update management. Configuration files stored locally on devices act as intermediaries, containing update policy information that enables the update agent to communicate with external update servers without requiring domain authentication or joining

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic update option is used from vendor servers, then update installation simplicity is improved, but IT department control and testing capability worsens

Engineering Contradiction:
Improveupdate installation simplicityVSAvoidIT department control
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent implements dynamic update management where the update agent can adapt its behavior based on locally stored configuration files. The system dynamically switches between automatic updates from vendor servers and controlled updates through centralized repositories, allowing IT departments to enforce policies while maintaining automated operation without requiring manual intervention for each update

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where the update agent continuously checks for configuration file changes and updates its behavior accordingly. The system provides feedback loops that allow IT departments to push policy updates to configuration files, which the agent then detects and implements, enabling remote control while maintaining automated update operations

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If non-domain devices are excluded from centralized update management, then device enrollment simplicity is improved, but update security and compatibility control worsens

Engineering Contradiction:
Improvedevice enrollment flexibilityVSAvoidupdate compatibility control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary configuration where update policies and server information are pre-configured in configuration files before updates are applied. This preliminary setup enables standalone devices to be pre-configured with trusted update sources and security policies, ensuring that even without domain joining, devices receive updates from controlled and tested sources, maintaining security and compatibility

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10860304B2Enforcement of updates for devices unassociated with a directory service
Publication Date: 2020.12.08 OMNISSA LLC
  • US10860304B2 patent drawing
  • US10860304B2 patent drawing
  • US10860304B2 patent drawing

AI summary

Disclosed are approaches for enforcement of updates for devices unassociated with a directory service. An application executing on a computing device can determine, based on a policy received from a management service, that the computing device is to use an update service specified in the policy to receive updates. The application then modifies a setting of the computing device to specify the use of the update service by the computing device.