IP Library Granted Patent US 12,021,898
Granted Patent B2
US 12,021,898 · App. 16/713,025 · Granted Jun 25, 2024

Processes and systems that translate policies in a distributed computing system using a distributed indexing engine

Inventors: Prashant Ambardekar (Pune, IN); Rajiv Krishnamurthy (Palo Alto, CA); Prayas Gaurav (Pune, IN); Ujwala Kawalay (Pune, IN); Gurprit Johal (Pune, IN)
Assignee: NICIRA, INC.
H04L63/20G06F9/45558G06F16/289H04L63/10G06F2009/45587G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,021,898
App. No.
16/713,025
Granted
Jun 25, 2024
Kind
B2
Abstract

This disclosure presents processes and systems that translate policies defined for virtual objects, such as virtual servers, applications, and databases, of a distributed computing system into identity information of services provided by virtual objects to computing devices located outside the distributed computing system. Processes and systems form object graphs of computing device identity information, virtual objects, and virtual object identify information. Processes and systems translate polices for controlling network between the computing devices and the virtual objects into identity information of the computing devices and the virtual objects. The identify information of the virtual objects and the computing devices is used to create rules for controlling network traffic between the virtual objects and the computing devices. The rules are distributed to hosts of the distributed computing system that execute the rules, allowing access by the computing devices to services provided by the virtual objects.

Claims (55)

1. In a process stored in one or more data-storage devices and executed using one or more processors of a computer system to translate policies for virtual objects of a distributed computing system, the specific improvement comprising:

in response to a request to translate a policy to allow access to services of the virtual objects by computing devices located outside the distributed computing system, traversing an object graph that represents relationships between users of the computing devices and identity information of the computing devices and represents relationships between the virtual objects and identity information of the virtual objects to determine the identity information of the computing devices and the virtual objects;

presenting the identify information of the computing devices and the virtual objects in an application programming interface that enables creation of rules that control access to services provided the virtual objects by the computing devices; and

distributing the rules to hosts of the distributed computing system that execute the rules, thereby allowing the computing devices located outside the distributed computing system to access the services and processes provided by the virtual objects.

2. The process of claim 1 further comprises:

receiving user information and the identity information of the computing devices used by the users;

storing the identify information of the computing devices in a distributed indexing engine database;

searching the distributed computing system for identify information of virtual objects of the distributed computing system;

storing the identify information of virtual objects of the distributed computing system in the distributed indexing engine database; and

constructing the object graph that represents relationships between users of the computing devices and the identity information of the computing devices and represents relationships between the virtual objects and the identity information of the virtual objects.

3. The process of claim 1 wherein traversing an object graph comprises using a distributed indexing engine to

fetching user information from a distributed indexing engine database;

fetching IP address information of the computing devices from the distributed indexing engine database; and

fetching IP addresses of the virtual objects from the distributed indexing engine database.

4. The process of claim 1 wherein traversing the object graph comprises:

storing the object graph in a distributed indexing engine database; and

using a distributed indexing engine to traverse the object graph.

5. The process of claim 1 wherein the hosts are any one or more of virtual switches, virtual routers, and server computers that host the virtual objects.

6. A computer system to translate policies for virtual objects of a distributed computing system, the system comprising:

one or more processors;

one or more data-storage devices; and

machine-readable instructions stored in the one or more data-storage devices that when executed using the one or more processors controls the system to perform operations comprising:

in response to a request to translate a policy to allow access to services of the virtual objects by computing devices located outside the distributed computing system, traversing an object graph that represents relationships between users of the computing devices and identity information of the computing devices and represents relationships between the virtual objects and identity information of the virtual objects to determine the identity information of the computing devices and the virtual objects;

presenting the identify information of the computing devices and the virtual objects in an application programming interface that enables creation of rules that control access to services provided the virtual objects by the computing devices; and

distributing the rules to hosts of the distributed computing system that execute the rules.

7. The computer system of claim 6 further comprises:

receiving user information and the identity information of the computing devices used by the user;

storing the identify information of the computing devices in a distributed indexing engine database;

searching the distributed computing system for identify information of virtual objects of the distributed computing system;

storing the identify information of virtual objects of the distributed computing system in the distributed indexing engine database; and

constructing the object graph that represents relationships between users of the computing devices and the identity information of the computing devices and represents relationships between the virtual objects and the identity information of the virtual objects.

8. The computer system of claim 6 wherein traversing an object graph comprises:

fetching user information from a distributed indexing engine database;

fetching IP address information of the computing devices from the distributed indexing engine database; and

fetching IP addresses of the virtual objects from the distributed indexing engine database.

9. The computer system of claim 6 wherein traversing the object graph comprises:

storing the object graph in a distributed indexing engine database; and

using a distributed indexing engine to traverse the object graph.

10. Apparatus for translating policies for virtual objects of a distributed computing system, the apparatus comprising:

means for receiving a request to translate a policy to allow access to services of virtual objects by computing devices located outside the distributed computing system;

means for traversing an object graph that represents relationships between users of the computing devices and identity information of the computing devices and represents relationships between the virtual objects and identity information of the virtual objects to determine the identity information of the computing devices and the virtual objects; and

means for distributing the rules to hosts of the distributed computing system that execute the rules.

11. The apparatus of claim 10 further comprises:

means for receiving user information and the identity information of the computing devices used by the users;

means for storing the identify information of the computing devices in a distributed indexing engine database;

means for searching the distributed computing system for identify information of virtual objects of the distributed computing system;

means for storing the identify information of virtual objects of the distributed computing system in the distributed indexing engine database; and

means for constructing the object graph that represents relationships between users of the computing devices and the identity information of the computing devices and represents relationships between the virtual objects and the identity information of the virtual objects.

12. The apparatus of claim 10 wherein the means for traversing the object graph comprises a distributed indexing engine that

fetches user information from a distributed indexing engine database;

fetches IP address information of the computing devices from the distributed indexing engine database; and

fetches IP addresses of the virtual objects from the distributed indexing engine database.

13. The apparatus of claim 10 wherein means for traversing the object graph

stores the object graph in a distributed indexing engine database; and

uses a distributed indexing engine to traverse the object graph.

Assignments (3)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 052125 FRAME 0553. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 18, 2022
From: AMBARDEKAR, PRASHANT; GAURAV, PRAYAS; KAWALAY, UJWALA
To: NICIRA, INC.
Reel/Frame 060116/0618 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2020
From: AMBARDEKAR, PRASHANT; GAURAV, PRAYAS; KAWALAY, UJWALA
To: NICRA, INC.
Reel/Frame 052125/0553 →