IP Library Granted Patent US 12,131,150
Granted Patent B2
US 12,131,150 · App. 16/693,123 · Granted Oct 29, 2024

System and methods for patch management

Inventors: Michael Fahland (Oakdale, MN); Nicholas Krueger (Somerset, WI); Sean McDonald (St. Paul, MN)
Assignee: Ivanti, Inc.
G06F8/71G06F8/65
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,131,150
App. No.
16/693,123
Granted
Oct 29, 2024
Kind
B2
Abstract

A method for patch management is described. The method includes downloading a patch that is incompatible with a patch management system. The method also includes creating an archive that is executable by the patch management system. The archive includes the incompatible patch. The method further includes sending the archive to the patch management system.

Claims (70)

1. A method of patch management, the method comprising:

downloading, at a compute device and from a first provider, a patch, wherein the patch is incompatible with an automated patch management system of the compute device because the downloaded patch is a non-monolithic patch having two or more entry points of execution to effect installation of the downloaded patch and the automated patch management system is limited to execution of patches having a single entry point of execution to effect the installation of the downloaded patch;

downloading, at the compute device and from a second provider, supplemental processor executable content;

producing, at the compute device, a non-self-extracting archive having a single entry point of execution that satisfies distribution and invocation requirements of the automated patch management system, the non-self-extracting archive including:

the downloaded patch,

at least a portion of the downloaded supplemental processor executable content, and

a script including code executable on the compute device to perform command line instructions that are configured to be invoked by the automated patch management system to effectuate the installation of the non-self-extracting archive and actions performed to install the downloaded patch, wherein the actions include a pre-processing action, installation action, and post-processing action required to install the downloaded patch;

compiling, at the compute device, the non-self-extracting archive;

calling, by the compute device, an application program interface (API) on the automated patch management system; and

using the API of the automated patch management system, publishing the compiled archive in the automated patch management system such that the command line instructions of the compiled archive are automatically executed to invoke the script to effectuate installation the downloaded patch and the supplemental processor executable content on the compute device.

2. The method of claim 1 , wherein:

the post-processing action includes an exit process that satisfies the automated patch management system, and

the exit process includes one or more or a combination of:

determining whether the downloaded patch is installed correctly;

identifying an error associated with installing the downloaded patch; or

determining whether a system reboot is required.

3. The method of claim 1 , wherein the installation action includes launching a patch installer that occurs between the pre-processing action and the post-processing action.

4. The method of claim 1 , wherein:

the supplemental processor executable content is in a format that is incompatible with the automated patch management system;

and

the installation action includes an operation to enable installation of the supplemental processor executable content.

5. The method of claim 1 , wherein the supplemental processor executable content comprises at least one utility program that is invoked by at least a portion of the script.

6. The method of claim 1 , wherein:

the downloaded patch includes one or more or a combination of:

an update for an operating system of the compute device;

an update for installed computer programs;

an update for installed hardware; and

the actions include one or more or a combination of:

halting a previous version of an application;

uninstalling a previous version of an application;

rebooting the compute device before installation of the downloaded patch;

rebooting the compute device during installation of the downloaded patch;

rebooting the compute device after installation of the downloaded patch;

responding by a user to a prompt during installation; and

extracting one or more files.

7. One or more non-transitory media configured storing instructions that are configured in response to execution by one or more processors, cause a system to perform or control performance of operations comprising:

downloading, at a compute device and from a first provider, a patch, wherein the patch is incompatible with an automated patch management system of the compute device because the downloaded patch is a non-monolithic patch having two or more entry points of execution to effect installation of the downloaded patch and the automated patch management system is limited to execution of patches having a single entry point of execution to effect the installation of the downloaded patch;

downloading, at the compute device and from a second provider, supplemental processor executable content;

producing, at the compute device, a non-self-extracting archive having a single entry point of execution that satisfies distribution and invocation requirements of the automated patch management system, the non-self-extracting archive including:

the downloaded patch,

at least a portion of the downloaded supplemental processor executable content, and

a script including code executable on the compute device to perform command line instructions that are configured to be invoked by the automated patch management system to effectuate the installation of the non-self-extracting archive and actions performed to install the downloaded patch, wherein the actions include a pre-processing action, installation action, and post-processing action required to install the downloaded patch;

compiling, at the compute device, the non-self-extracting archive;

calling, by the compute device, an application program interface (API) on the automated patch management system; and

using the API of the automated patch management system, publishing the compiled archive in the automated patch management system such that the command line instructions of the compiled archive are automatically executed to invoke the script to effectuate installation the downloaded patch and the supplemental processor executable content on the compute device.

8. The one or more non-transitory media of claim 7 , wherein:

the post-processing action includes an exit process that satisfies the automated patch management system, and

the exit process includes one or more or a combination of:

determining whether the downloaded patch is installed correctly;

identifying an error associated with installing the downloaded patch; or

determining whether a system reboot is required.

9. The one or more non-transitory media of claim 7 , wherein the installation action includes launching a patch installer that occurs between the pre-processing action and the post-processing action.

10. The one or more non-transitory media of claim 7 , wherein:

the supplemental processor executable content is in a format that is incompatible with the automated patch management system;

and

the installation action includes an operation to enable installation of the supplemental processor executable content.

11. The one or more non-transitory media of claim 7 , wherein the supplemental processor executable content comprises at least one utility program that is invoked by at least a portion of the script.

12. The one or more non-transitory media of claim 7 , wherein:

the downloaded patch includes one or more or a combination of:

an update for an operating system of the compute device;

an update for installed computer programs;

an update for installed hardware; and

the actions include one or more or a combination of:

halting a previous version of an application;

uninstalling a previous version of an application;

rebooting the compute device before installation of the downloaded patch;

rebooting the compute device during installation of the downloaded patch;

rebooting the compute device after installation of the downloaded patch;

responding by a user to a prompt during installation; and

extracting one or more files.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
Continuity (2)
Continuation 14504169 · Oct 1, 2014
Related Publication 20200142689A1 · May 7, 2020