IP Library Granted Patent US 7,823,147
Granted Patent B2
US 7,823,147 · App. 11/160,439 · Granted Oct 26, 2010

Non-invasive automatic offsite patch fingerprinting and updating system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,823,147
App. No.
11/160,439
Granted
Oct 26, 2010
Kind
B2
Abstract

Methods, systems, and configured storage media are provided for discovering software updates, discovering if a given computer can use the software update, and then updating the computers with the software as needed automatically across a network without storing the updates on an intermediate machine within the network. Furthermore, when a failure is detected, the rollout is stopped and the software can be automatically removed from those computers that already were updated. The software update can be stored originally at an address that is inaccessible through the network firewall by intermediately uploading the software update to an update computer which is not a part of the network but has access through the firewall, which is then used to distribute the update.

Claims (33)

1. A system comprising:

(a) a package computer having a plurality of patch fingerprints;

(i) wherein the plurality of patch fingerprints includes at least a first patch fingerprint and a second patch fingerprint, different than the first patch fingerprint;

(i) wherein at least the first and second patch fingerprints each comprises at least one Extensible Markup Language (XML) metadata query, wherein the first patch fingerprint includes a first XML metadata query, and wherein the second patch fingerprint includes a second XML metadata query, different than the first XML metadata query;

(ii) wherein at least the first and second patch fingerprints are both associated with a specific software update;

(b) an update server in communication with the package computer;

(i) wherein the update server stores at least the first and second patch fingerprints of the package computer;

(ii) wherein the update server is located remote from the package computer; and

(c) a discovery agent configured to separately interact with both the first XML metadata query and the second XML metadata query to produce first target computer information relating to the first target computer;

wherein the system is configured to:

(A) send the first XML metadata query and the second XML metadata query of the first and second patch fingerprints from the update server to the discovery agent to gather the first target computer information;

(I) wherein the first target computer information is related to at least registry information, software presence information, and software version information relative to the first target computer;

(II) wherein a first portion of the first target computer information is associated with the first patch fingerprint and the first XML metadata query;

(III) wherein a separate second portion of the first target computer information is associated with the second patch fingerprint and the second XML metadata query;

(B) determine, at the update server based on the first target computer information, whether the specific software update is both applicable to and absent from the first target computer;

(i) wherein the determination step comprises:

(1) evaluating the first portion of the first target computer information to determine the applicability of the specific software update to the first target computer; and

(2) if the specific software update is applicable to the first target computer, then evaluating the second portion of the first target computer information to determine the presence or absence of:

(A) the applicable files;

(B) the applicable registry keys; and

(C) the applicable configuration information of the specific software update;

wherein the system is configured to, based on the determination (B), download the specific software update to one of (i) the update server and (ii) the first target computer.

2. The system of claim 1 , wherein the specific software update is one of patch files, data files, script files, new application files, and executable files, or any combination thereof.

3. The system of claim 1 , wherein the update server is configured to:

monitor the package computer for a new patch fingerprint; and

receive the new patch fingerprint from the package computer.

4. The system of claim 1 , wherein the first target computer information is contained in a results file, wherein the results file is in an XML format, and wherein the results file is stored at the update server.

5. The system of claim 1 , further comprising:

an update task list located on the update server;

wherein the update server is configured to review the update task list for a target computer that has not received the specific software update and, if one is found, add an update task identifier for that target computer to the update task list.

6. The system of claim 5 , further comprising:

a monitor configured to monitor the installation of the specific software update on the first target computer;

wherein, if the monitor determines that the installation of the specific software update was successful, the update server reviews the update task list for a target computer that has not received the specific software update and, if one is found, adds an update task identifier for that target computer to the update task list.

Assignments (13)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0436 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0713 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0735 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2019
From: MOSHIR, SEAN; HUDLER, JACK LEE; ANDREW, CHRISTOPHER A.H.; FERGUSON, DAN; LI, LEON; GORDON, JONATHAN M.; BACON, MICHAEL; HORTON, JAMES J.
To: PATCHLINK.COM, CORPORATION
Reel/Frame 048042/0391 →
CHANGE OF NAME Recorded Jan 17, 2019
From: PATCHLINK.COM CORPORATION
To: PATCHLINK CORPORATION
Reel/Frame 048083/0220 →
MERGER Recorded Jan 10, 2019
From: HEAT SOFTWARE USA INC.
To: IVANTI, INC.
Reel/Frame 047950/0296 →
RELEASE OF SECURITY INTERESTS IN PATENTS AT REEL/FRAME NO. 33380/0644 Recorded Jan 21, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: HEAT SOFTWARE USA INC., AS SUCCESSOR IN INTEREST TO LUMENSION SECURITY, INC.
Reel/Frame 041052/0794 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0436 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0735 →
MERGER AND CHANGE OF NAME Recorded Jan 18, 2017
From: LUMENSION SECURITY INC.; HEAT SOFTWARE USA INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 041010/0854 →
RELEASE OF SECURITY INTEREST Recorded Oct 25, 2016
From: CONSORTIUM FINANCE, LLC
To: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
Reel/Frame 040479/0001 →