IP Library Granted Patent US 12694115
Granted Patent B2
US 12694115 · App. 18/791,528 · Granted Jul 28, 2026

Patching endpoints in an isolated, air-gapped environment

Inventors: Shodhan Shetty (Udupi, IN); Virginia Mayo (Jersey City, NJ); Cindy J. Mullen (Madison, WI)
Assignee: Kyndryl, Inc.
G06F21/57G06F21/53H04L63/0263G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694115
App. No.
18/791,528
Granted
Jul 28, 2026
Kind
B2
Abstract

A computer-implemented method may include querying a centralized patch repository for new patch data; receiving a confirmation that there is new patch data in the centralized patch repository; spinning-up a proxy in an isolated computing environment in response to the receiving the confirmation; disabling an air-gap of the isolated computing environment configured to receive the new patch data; and receiving the new patch data at the isolated computing environment from the centralized patch repository.

Claims (40)

1 . A method, comprising:

querying, by a computing device, a centralized patch repository for new patch data;

receiving, by the computing device, a confirmation that there is new patch data in the centralized patch repository;

spinning-up, by the computing device, a proxy in an isolated computing environment in response to the receiving the confirmation;

disabling, by the computing device, an air-gap of the isolated computing environment configured to receive the new patch data; and

receiving, by the computing device, the new patch data at the isolated computing environment from the centralized patch repository.

2 . The method of claim 1 , further comprising:

querying, by the computing device, the centralized patch repository for a success criteria of the receiving the new patch data; and

enabling, by the computing device, the air-gap based on the success criteria comprising enabling gateway firewall rules configured to block network communication with the centralized patch repository.

3 . The method of claim 1 , further comprising spinning-down the proxy based on a success criteria, wherein the spinning-down comprises powering off or disabling the proxy in the isolated environment.

4 . The method of claim 1 , wherein the spinning-up comprises powering on or enabling the proxy in the isolated environment.

5 . The method of claim 1 , wherein the air-gap comprises gateway firewall rules configured to block network communication with the centralized patch repository.

6 . The method of claim 1 , wherein the air-gap comprises a virtual network layer comprising tiered gateways configured to block network communication with the centralized patch repository.

7 . The method of claim 1 , wherein the air-gap is configured to prevent network communication between the proxy and the centralized patch repository in response to the air-gap being enabled and allow network communication between the proxy and the centralized patch repository in response to the air-gap being disabled.

8 . The method of claim 1 , wherein the centralized patch repository is external from the proxy.

9 . The method of claim 1 , wherein the computing device includes software provided as a service in a cloud environment.

10 . A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:

query a centralized patch repository for new patch data;

receive a confirmation that there is new patch data in the centralized patch repository;

spin-up a proxy in an isolated computing environment in response to the receiving the confirmation;

disable an air-gap of the isolated computing environment configured to receive the new patch data; and

receive the new patch data at the isolated computing environment from the centralized patch repository.

11 . The computer program product of claim 10 , wherein the program instructions are further executable to:

query the centralized patch repository for a success criteria of the receiving the new patch data; and

enable the air-gap based on the success criteria comprising enabling gateway firewall rules configured to block network communication with the centralized patch repository.

12 . The computer program product of claim 10 , wherein the program instructions are further executable to spin-down the proxy based on a success criteria, wherein the spinning-down comprises powering off or disabling the proxy in the isolated environment.

13 . The computer program product of claim 10 , wherein the spinning-up comprises powering on or enabling the proxy in the isolated environment.

14 . The computer program product of claim 10 , wherein the air-gap comprises gateway firewall rules configured to block network communication with the centralized patch repository.

15 . The computer program product of claim 10 , wherein the air-gap comprises a virtual network layer comprising tiered gateways configured to block network communication with the centralized patch repository.

16 . The computer program product of claim 10 , wherein the air-gap is configured to prevent network communication between the proxy and the centralized patch repository in response to the air-gap being enabled and allow network communication between the proxy and the centralized patch repository in response to the air-gap being disabled.

17 . The computer program product of claim 10 , wherein the air-gap is configured to allow network communication between the proxy and the centralized patch repository.

18 . The computer program product of claim 10 , wherein the centralized patch repository is external from the proxy.

19 . The computer program product of claim 10 , wherein the computing device includes software provided as a service in a cloud environment.

20 . A system comprising:

a processor, a computer readable memory, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:

query a centralized patch repository for new patch data;

receive a confirmation that there is new patch data in the centralized patch repository;

spin-up a proxy in an isolated computing environment in response to the receiving the confirmation;

disable an air-gap of the isolated computing environment configured to receive the new patch data; and

receive the new patch data at the isolated computing environment from the centralized patch repository.