IP Library Granted Patent US 12,267,366
Granted Patent B2
US 12,267,366 · App. 17/569,278 · Granted Apr 1, 2025

System and method for scheduling virtual machines based on security policy

Inventor: Ashwini Vasanth (West Lafayette, IN)
Assignee: Nutanix, Inc.
H04L63/20G06F9/45558G06F2009/4557G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,366
App. No.
17/569,278
Filed
Jan 5, 2022
Granted
Apr 1, 2025
Kind
B2
Art Unit
2451
USPC
726/4
Abstract

An illustrative embodiment disclosed herein is an apparatus including a processor and a memory. In some embodiments, the memory includes programmed instructions that, when executed by the processor, cause the apparatus to apply a category to a first virtual machine (VM) and a second VM, schedule the first VM and the second VM to be placed on a host at least based on the first VM and the second VM including the category, and apply a security policy to the first VM and the second VM at least based on the first VM and the second VM including the category.

Claims (38)

1. An apparatus comprising a processor and a memory, wherein the memory includes programmed instructions that, when executed by the processor, cause the apparatus to:

identify a first virtual machine (VM) and a second VM having characteristics corresponding to a security policy;

apply a category to the first VM and the second VM;

schedule the first VM and the second VM to be placed on a same host at least based on the first VM and the second VM including the category; and

apply the security policy to the first VM and the second VM at the same host after the first VM and the second VM are placed on the same host at least based on the first VM and the second VM including the category, the security policy identifying permissible network traffic for the first VM and the second VM.

2. The apparatus of claim 1 , wherein the memory includes the programmed instructions that, when executed by the processor, further cause the apparatus to:

apply the security policy to the first VM and the second VM responsive to the first VM and the second VM being placed on the same host.

3. The apparatus of claim 1 , wherein the memory includes the programmed instructions that, when executed by the processor, further cause the apparatus to:

schedule the first VM and the second VM to be placed on the same host at least based on determining that no anti-affinity policies prevent the first VM and the second VM from being on the same host.

4. The apparatus of claim 1 , wherein the security policy includes a policy identifying at least one of permissible inbound traffic or permissible outbound traffic.

5. A non-transitory computer readable storage medium comprising instructions stored thereon that, when executed by a processor, cause the processor to:

identify a first virtual machine (VM) and a second VM having characteristics corresponding to a security policy;

apply a category to the first VM and the second VM;

schedule the first VM and the second VM to be placed on a same host at least based on the first VM and the second VM including the category; and

apply the security policy to the first VM and the second VM at the same host after the first VM and the second VM are placed on the same host at least based on the first VM and the second VM including the category, the security policy identifying permissible network traffic for the first VM and the second VM.

6. The medium of claim 5 , comprising the instructions stored thereon that, when executed by a processor, further cause the processor to:

apply the security policy to the first VM and the second VM responsive to the first VM and the second VM being placed on the same host.

7. The medium of claim 5 , comprising the instructions stored thereon that, when executed by a processor, further cause the processor to:

schedule the first VM and the second VM to be placed on the same host at least based on determining that no anti-affinity policies prevent the first VM and the second VM from being on the same host.

8. The medium of claim 5 , wherein the security policy includes a policy identifying at least one of permissible inbound traffic or permissible outbound traffic.

9. A computer-implemented method comprising:

identifying, by a processor, a first virtual machine (VM) and a second VM having characteristics corresponding to a security policy;

applying, by the processor, a category to the first VM and the second VM;

scheduling, by the processor, the first VM and the second VM to be placed on a same host at least based on the first VM and the second VM including the category; and

applying, by the processor, the security policy to the first VM and the second VM at the same host after the first VM and the second VM are placed on the same host at least based on the first VM and the second VM including the category, the security policy identifying permissible network traffic for the first VM and the second VM.

10. The method of claim 9 , further comprising:

applying the security policy to the first VM and the second VM responsive to the first VM and the second VM being placed on the same host.

11. The method of claim 9 , further comprising:

scheduling the first VM and the second VM to be placed on the same host at least based on determining that no anti-affinity policies prevent the first VM and the second VM from being on the same host.

12. The method of claim 9 , wherein the security policy includes a policy identifying at least one of permissible inbound traffic or permissible outbound traffic.

13. An apparatus comprising a processor and a memory, wherein the memory includes programmed instructions that, when executed by the processor, cause the apparatus to:

identify a first virtual machine (VM) and a second VM having characteristics corresponding to a security policy;

apply a category to the first VM hosted on a first host and the second VM hosted on a second host;

migrate one of the first VM or the second VM such that the first VM and the second VM are on a same host at least based on the first VM and the second VM including the category; and

apply the security policy to the first VM and the second VM at the same host after the first VM and the second VM are placed on the same host at least based on the first VM and the second VM including the category, the security policy identifying permissible network traffic for the first VM and the second VM.

14. The apparatus of claim 13 , wherein the memory includes the programmed instructions that, when executed by the processor, further cause the apparatus to: apply the security policy to the first VM and the second VM responsive to migrating one of the first VM or the second VM such that the first VM and the second VM are on the same host.

15. The apparatus of claim 13 , wherein the memory includes the programmed instructions that, when executed by the processor, further cause the apparatus to:

migrate one of the first VM or the second VM such that the first VM and the second VM are on the same host at least based on determining that no anti-affinity policies prevent the first VM and the second VM from being on the host.

Assignments (2)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2022
From: VASANTH, ASHWINI
To: NUTANIX, INC.
Reel/Frame 058587/0113 →
Continuity (2)
Provisional Application 63282112 · Nov 22, 2021
Related Publication 20230164188A1 · May 25, 2023
References Cited (69)
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron · 2014 [cited by examiner]
US 8863124B1 · Aron · 2014 [cited by examiner]
US 9009106B1 · Aron · 2015 [cited by examiner]
US 9069708B2 · Gill · 2015 [cited by examiner]
US 9336132B1 · Aron · 2016 [cited by examiner]
US 9565129B2 · Bai · 2017 [cited by examiner]
US 9652265B1 · Narayanasamy · 2017 [cited by examiner]
US 9772866B1 · Aron · 2017 [cited by examiner]
US 10498608B2 · Sethi · 2019 [cited by examiner]
US 11025647B2 · Cooper · 2021 [cited by examiner]
US 20080155537A1 · Dinda · 2008 [cited by examiner]
US 20120096271A1 · Ramarathinam · 2012 [cited by examiner]
US 20120233668A1 · Leafe · 2012 [cited by examiner]
US 20130227560A1 · McGrath · 2013 [cited by examiner]
US 20130227561A1 · Walsh · 2013 [cited by examiner]
US 20130227635A1 · Walsh · 2013 [cited by examiner]
US 20140189684A1 · Zaslavsky · 2014 [cited by examiner]
US 20140196039A1 · Kottomtharayil · 2014 [cited by examiner]
US 20150012962A1 · Walsh · 2015 [cited by examiner]
US 20150295792A1 · Cropper · 2015 [cited by examiner]
US 20150319160A1 · Ferguson · 2015 [cited by examiner]
US 20150341318A1 · Lee · 2015 [cited by examiner]
US 20160321095A1 · Cropper · 2016 [cited by examiner]
US 20160342436A1 · Cropper · 2016 [cited by examiner]
US 20170024260A1 · Chandrasekaran · 2017 [cited by examiner]
US 20170093918A1 · Banerjee · 2017 [cited by examiner]
US 20170134422A1 · Shieh · 2017 [cited by examiner]
US 20170220376A1 · Cropper · 2017 [cited by examiner]
US 20170371717A1 · Kiess · 2017 [cited by examiner]
US 20180046807A1 · Patil · 2018 [cited by examiner]
US 20180074670A1 · Cropper · 2018 [cited by examiner]
US 20180074838A1 · Cropper · 2018 [cited by examiner]
US 20180176261A1 · Bansal · 2018 [cited by examiner]
US 20180285166A1 · Roy · 2018 [cited by examiner]
US 20190158541A1 · Miriyala · 2019 [cited by examiner]
US 20190171491A1 · Das · 2019 [cited by examiner]
US 20190230064A1 · Soman · 2019 [cited by examiner]
US 20190342335A1 · Ni · 2019 [cited by examiner]
US 20190361727A1 · Thakkar · 2019 [cited by examiner]
US 20190392150A1 · Shevade · 2019 [cited by examiner]
US 20200167184A1 · Kouznetsov · 2020 [cited by examiner]
US 20200201664A1 · Panse · 2020 [cited by examiner]
US 20200201665A1 · Panse · 2020 [cited by examiner]
US 20200244702A1 · Ambardekar · 2020 [cited by examiner]
US 20200366572A1 · Chauhan · 2020 [cited by examiner]
US 20200366697A1 · Vittal · 2020 [cited by examiner]
US 20210184977A1 · Testicioglu · 2021 [cited by examiner]
US 20210224088A1 · Wiggers · 2021 [cited by examiner]
US 20210227023A1 · Wiggers · 2021 [cited by examiner]
US 20220014500A1 · Xu · 2022 [cited by examiner]
US 20220237048A1 · Wiggers · 2022 [cited by examiner]
US 20220237049A1 · Wiggers · 2022 [cited by examiner]
US 20220303246A1 · Miriyala · 2022 [cited by examiner]
US 20230125661A1 · Jebakumar · 2023 [cited by examiner]
Cano, Ignacio, et al. “Curator: Self-Managing Storage for Enterprise Clusters” (Mar. 27, 2017), from https://www.usenix.org/conference/nsdi17/. [cited by applicant]
Create NSX security groups and policies—Deep Security, https://help.deepsecurity.trendmicro.com/10/0/Reference/ref-create-vmw-grps.html, 8 pages. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http:/stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 17, 2019), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
VMware, Inc., “Performance of vSphere 6.7 Scheduling Options,” Performance Study (Apr. 11, 2019), https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/performance/scheduler-options-vsphere67u2-per… [cited by applicant]
VMware, Inc., “Virtual Machine Affinity and Anti-Affinity,” (May 31, 2019), https://docs.vmware.com/en/VMware-Cloud-Director/9.7/com.vmware.vcloud.user.doc/GUID-103BE81A-0762-45C6-915D-19B2B75DEE05.html, 1-3 pages. [cited by applicant]
“Create NSX security groups and policies|Deep Security,” https://help.deepsecurity.trendmicro.com/10/0/Reference/ref-create-vmw-grps.html, pp. 1-8. [cited by applicant]
VMware, “Performance of vSphere 6.7 Scheduling Options,” (Apr. 11, 2019), https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/performance/scheduler-options-vsphere67u2-perf.pdf, pp. 1-17. [cited by applicant]
VMware, “Virtual Machine Affinity and Anti-Affinity,” (May 31, 2019), https://docs.vmware.com/en/VMware-Cloud-Director/9.7/com.vmware.vcloud.user.doc/GUID-103BE81A-0762-45C6-915D-19B2B75DEE05.html, pp. 1-3. [cited by applicant]