IP Library Granted Patent US 10,205,701
Granted Patent B1
US 10,205,701 · App. 14/852,579 · Granted Feb 12, 2019

Cloud network automation for IP address and DNS record management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,205,701
App. No.
14/852,579
Granted
Feb 12, 2019
Kind
B1
Abstract

Techniques for cloud network automation for IP address and DNS record management are disclosed. In some embodiments, a system, process, and/or computer program product for cloud network automation for IP address and DNS record management includes receiving at a cloud platform appliance (e.g., a virtual or physical IP address and/or DNS management appliance) a cloud request related to a resource (e.g., a virtual or physical resource) in a cloud environment from a global cloud manager; and processing the cloud request at the cloud platform appliance to determine whether to proxy the cloud request to another cloud platform appliance or a grid master or to locally process the cloud request, wherein a storage of infrastructure metadata information for IP address and/or DNS record management is updated based on the cloud request.

Claims (43)

1. A system for cloud network automation for IP address and DNS record management, comprising:

a processor of a cloud platform appliance configured to:

receive a cloud request related to a resource in a cloud environment from a global cloud manager, wherein the cloud platform appliance is configured as a primary cloud platform appliance for receiving cloud requests from the global cloud manager; and

process the cloud request to determine whether to proxy the cloud request to another cloud platform appliance or a grid master or to locally process the cloud request, wherein a storage of infrastructure metadata information for IP address and/or DNS record management is updated based on the cloud request, wherein the processing of the cloud request comprises to:

determine whether the cloud platform appliance has authorization to process the cloud request based on an access control list; and

in response to a determination that the cloud platform appliance does not have authorization:

determine whether the other cloud platform appliance has authorization to process the cloud request based on the access control list;

proxy the cloud request to the other cloud platform appliance, wherein the other cloud platform appliance is authoritative for an object associated with the cloud request, and wherein the object is associated with an IP address space or DNS record space managed by the other cloud platform appliance; and

in response to a determination that the other cloud platform appliance does not have authorization, proxy the cloud request to the grid master to process the cloud request, wherein the cloud platform appliance is a member of a grid, wherein the grid includes a plurality of cloud platform appliances and the grid master, wherein the plurality of cloud platform appliances includes the other cloud platform appliance, wherein the grid master maintains a centralized data store of IP address management (IPAM) related data of the grid, DNS related data of the grid, Dynamic Host Configuration Protocol (DHCP) related data of the grid, or any combination thereof; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the cloud platform appliance includes an IP address and/or DNS record management appliance.

3. The system recited in claim 1 , wherein the cloud platform appliance includes a virtual IP address and/or DNS record management appliance.

4. The system recited in claim 1 , wherein the resource in the cloud environment is associated with a virtual resource.

5. The system recited in claim 1 , wherein the resource in the cloud environment is associated with a physical resource.

6. The system recited in claim 1 , wherein the cloud request is an application programming interface (API) request.

7. The system recited in claim 1 , wherein the cloud request is an application programming interface (API) request that indicates whether the resource is a newly added resource in the cloud environment, a deleted resource in the cloud environment, or a modified resource in the cloud environment.

8. The system recited in claim 1 , wherein the cloud request is sent from a cloud adapter integrated with the global cloud manager.

9. The system recited in claim 1 , wherein the processor is further configured to:

process the cloud request using a cloud application programming interface (API) service executed on the cloud platform appliance.

10. The system recited in claim 1 , wherein the cloud request is sent from a cloud adapter integrated with the global cloud manager, and wherein the processor is further configured to:

process the cloud request using a cloud application programming interface (API) service executed on the cloud platform appliance, wherein the cloud API service and the cloud adapter communicate using a secure protocol.

11. The system recited in claim 1 , wherein the processor is further configured to:

authenticate the cloud request.

12. The system recited in claim 1 , wherein the processor is further configured to:

authorize the cloud request.

13. The system recited in claim 1 , wherein the processor is further configured to:

validate the cloud request.

14. A method of cloud network automation for IP address and DNS record management, comprising:

receiving at a cloud platform appliance a cloud request related to a resource in a cloud environment from a global cloud manager, wherein the cloud platform appliance is configured as a primary cloud platform appliance for receiving cloud requests from the global cloud manager; and

processing the cloud request at the cloud platform appliance to determine whether to proxy the cloud request to another cloud platform appliance or a grid master or to locally process the cloud request, wherein a storage of infrastructure metadata information for IP address and/or DNS record management is updated based on the cloud request, wherein the processing of the cloud request comprises:

determining whether the cloud platform appliance has authorization to process the cloud request based on an access control list; and

in response to a determination that the cloud platform appliance does not have authorization:

determining whether the other cloud platform appliance has authorization to process the cloud request based on the access control list;

proxying the cloud request to the other cloud platform appliance, wherein the other cloud platform appliance is authoritative for an object associated with the cloud request, and wherein the object is associated with an IP address space or DNS record space managed by the other cloud platform appliance; and

in response to a determination that the other cloud platform appliance does not have authorization, proxying the cloud request to the grid master to process the cloud request, wherein the cloud platform appliance is a member of a grid, wherein the grid includes a plurality of cloud platform appliances and the grid master, wherein the plurality of cloud platform appliances includes the other cloud platform appliance, wherein the grid master maintains a centralized data store of IP address management (IPAM) related data of the grid, DNS related data of the grid, Dynamic Host Configuration Protocol (DHCP) related data of the grid, or any combination thereof.

15. A computer program product for cloud network automation for IP address and DNS record management, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving at a cloud platform appliance a cloud request related to a resource in a cloud environment from a global cloud manager, wherein the cloud platform appliance is configured as a primary cloud platform appliance for receiving cloud requests from the global cloud manager; and

processing the cloud request at the cloud platform appliance to determine whether to proxy the cloud request to another cloud platform appliance or a grid master or to locally process the cloud request, wherein a storage of infrastructure metadata information for IP address and/or DNS record management is updated based on the cloud request, wherein the processing of the cloud request comprises:

determining whether the cloud platform appliance has authorization to process the cloud request based on an access control list; and

in response to a determination that the cloud platform appliance does not have authorization:

determining whether the other cloud platform appliance has authorization to process the cloud request based on the access control list;

proxying the cloud request to the other cloud platform appliance, wherein the other cloud platform appliance is authoritative for an object associated with the cloud request, and wherein the object is associated with an IP address space or DNS record space managed by the other cloud platform appliance; and

in response to a determination that the other cloud platform appliance does not have authorization, proxying the cloud request to the grid master to process the cloud request, wherein the cloud platform appliance is a member of a grid, wherein the grid includes a plurality of cloud platform appliances and the grid master, wherein the plurality of cloud platform appliances includes the other cloud platform appliance, wherein the grid master maintains a centralized data store of IP address management (IPAM) related data of the grid, DNS related data of the grid, Dynamic Host Configuration Protocol (DHCP) related data of the grid, or any combination thereof.

Assignments (7)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS (RELEASES RF 040575/0549) Recorded Dec 3, 2020
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: INFOBLOX INC.
Reel/Frame 054585/0914 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0317 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0331 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (RELEASES RF 040579/0302) Recorded Oct 23, 2019
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: INFOBLOX, INC.
Reel/Frame 050809/0980 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 8, 2016
From: INFOBLOX INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 040579/0302 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 7, 2016
From: INFOBLOX INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040575/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2015
From: VOSS, JOHN CHARLES; CLARK, THOMAS S.; WOIRGARD, SEBASTIEN; WANG, WEI
To: INFOBLOX INC.
Reel/Frame 036867/0817 →