IP Library Granted Patent US 11,477,269
Granted Patent B2
US 11,477,269 · App. 17/371,856 · Granted Oct 18, 2022

Hybrid cloud computing network management with synchronization features across different cloud service providers

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L67/10H04L41/0803H04L41/0893H04L41/0895H04L43/0817H04L63/1425H04L67/1095
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,269
App. No.
17/371,856
Granted
Oct 18, 2022
Kind
B2
Abstract

A network manager configures a first node to participate in a node cluster that spans at least a first cloud service provider and the second cloud service provider. The network manager configures a second node to participate in the node cluster. The network manager configures a third node to participate in the node cluster. The network manager initiates the first node as a virtual machine. The network manager initiates the second node as a containerized program. The network manager initiates the third node as a containerized program. The network manager sends messages into the first cloud serves and into the second cloud service to cause the containerized program of the second node and the containerized program of the third node to synchronize data such that the containerized program of the second node and the containerized program of the first node perform the same network security actions.

Claims (40)

1. A computer-implemented method executed by one or more processors comprising:

configuring, by a network manager operating outside of a first cloud service provider and outside of a second cloud service provider that is logically distinct from the first cloud service provider and outside of a client network, a first node to participate in a node cluster that spans at least the first cloud service provider and the second cloud service provider, wherein the first node is hosted by the first cloud service provider, and wherein participating in the node cluster includes performing one or more network security actions on traffic between remote servers and the client network, the client network separate from the first and second cloud service providers and the remote servers remote from the client network and from the first and second cloud service providers;

configuring, by the network manager, a second node to participate in the node cluster, wherein the second node is hosted by the first cloud service provider;

configuring, by the network manager, a third node to participate in the node cluster, wherein the third node is hosted by the second cloud service provider communicably coupled to the first cloud service provider via computer networking;

initiating the first node as a virtual machine instance within a virtual machine environment of the first cloud service provider;

initiating the second node as a containerized program executing within an operating-system-level virtualization environment of the first cloud service provider;

initiating the third node as a second containerized program executing within a second operating-system-level virtualization environment of the second cloud service provider; and

sending, by the network manager, messages into the first cloud service and into the second cloud service to cause the containerized program of the second node and the containerized program of the third node to synchronize data such that the containerized program of the second node and the containerized program of the third node operate with the same configuration data to perform the same network security actions regardless of the cloud service to which they belong.

2. The method of claim 1 , wherein:

instantiating the first node as a virtual machine comprises invoking a virtual-machine application programming interface (API) configured to instantiate virtual machines; and

instantiating the second node as a containerized program comprises invoking a operating-system level API configured to launch operating-system-level execution.

3. The method of claim 1 , wherein the operating-system-level virtualization environment of the first cloud service provider is a DOCKER environment.

4. The method of claim 1 , the method further comprising synchronizing data between the first node and the second node within the first cloud service provider.

5. A system comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

configuring, by a network manager operating outside of a first cloud service provider and outside of a second cloud service provider that is logically distinct from the first cloud service provider and outside of a client network, a first node to participate in a node cluster that spans at least the first cloud service provider and the second cloud service provider, wherein the first node is hosted by the first cloud service provider, and wherein participating in the node cluster includes performing one or more network security actions on traffic between remote servers and the client network, the client network separate from the first and second cloud service providers and the remote servers remote from the client network and from the first and second cloud service providers;

configuring, by the network manager, a second node to participate in the node cluster, wherein the second node is hosted by the first cloud service provider;

configuring, by the network manager, a third node to participate in the node cluster, wherein the third node is hosted by the second cloud service provider communicably coupled to the first cloud service provider via computer networking;

initiating the first node as a virtual machine instance within a virtual machine environment of the first cloud service provider;

initiating the second node as a containerized program executing within an operating-system-level virtualization environment of the first cloud service provider;

initiating the third node as a second containerized program executing within a second operating-system-level virtualization environment of the second cloud service provider; and

sending, by the network manager, messages into the first cloud service and into the second cloud service to cause the containerized program of the second node and the containerized program of the third node to synchronize data such that the containerized program of the second node and the containerized program of the third node operate with the same configuration data to perform the same network security actions regardless of the cloud service to which they belong.

6. The system of claim 5 , wherein:

instantiating the first node as a virtual machine comprises invoking a virtual-machine application programming interface (API) configured to instantiate virtual machines; and

instantiating the second node as a containerized program comprises invoking a operating-system level API configured to launch operating-system-level execution.

7. The system of claim 5 , wherein the operating-system-level virtualization environment of the first cloud service provider is a DOCKER environment.

8. The system of claim 5 , the operations further comprising synchronizing data between the first node and the second node within the first cloud service provider.

9. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

configuring, by a network manager operating outside of a first cloud service provider and outside of a second cloud service provider that is logically distinct from the first cloud service provider and outside of a client network, a first node to participate in a node cluster that spans at least the first cloud service provider and the second cloud service provider, wherein the first node is hosted by the first cloud service provider, and wherein participating in the node cluster includes performing one or more network security actions on traffic between remote servers and the client network, the client network separate from the first and second cloud service providers and the remote servers remote from the client network and from the first and second cloud service providers;

configuring, by the network manager, a second node to participate in the node cluster, wherein the second node is hosted by the first cloud service provider;

configuring, by the network manager, a third node to participate in the node cluster, wherein the third node is hosted by the second cloud service provider communicably coupled to the first cloud service provider via computer networking;

initiating the first node as a virtual machine instance within a virtual machine environment of the first cloud service provider;

initiating the second node as a containerized program executing within an operating-system-level virtualization environment of the first cloud service provider;

initiating the third node as a second containerized program executing within a second operating-system-level virtualization environment of the second cloud service provider; and

sending, by the network manager, messages into the first cloud service and into the second cloud service to cause the containerized program of the second node and the containerized program of the third node to synchronize data such that the containerized program of the second node and the containerized program of the third node operate with the same configuration data to perform the same network security actions regardless of the cloud service to which they belong.

10. The medium of claim 9 , wherein:

instantiating the first node as a virtual machine comprises invoking a virtual-machine application programming interface (API) configured to instantiate virtual machines; and

instantiating the second node as a containerized program comprises invoking a operating-system level API configured to launch operating-system-level execution.

11. The medium of claim 9 , the operations further comprising synchronizing data between the first node and the second node within the first cloud service provider.

Assignments (4)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2021
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 056824/0286 →
Continuity (3)
Continuation 16388551 · Apr 18, 2019
Provisional Application 62659644 · Apr 18, 2018
Related Publication 20210337017A1 · Oct 28, 2021
Cited By (1)
US 12,481,531