IP Library › Granted Patent US 12,210,895
Granted Patent B2
US 12,210,895 · App. 17/690,654 · Granted Jan 28, 2025

Updating a cluster of nodes in a network appliance

Inventors: Biju Ramachandra Kaimal (Bangalore, IN); Srisakthi Subramaniam (Bangalore, IN); Nikhil Bhandari (Bangalore, IN)
Assignee: Sophos Limited
G06F9/45558G06F3/0482G06F8/65G06F8/71G06F9/4401G06F9/5077G06F11/1438G06F11/1451G06F21/6209H04L9/3213H04L9/3228H04L9/3247H04L12/66H04L41/082H04L43/0811H04L63/02H04L63/029H04L63/0869H04L63/0876H04L63/20H04L67/141H04L67/146G06F2009/4557G06F2009/45595G06F2209/505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,895
App. No.
17/690,654
Filed
Mar 9, 2022
Granted
Jan 28, 2025
Kind
B2
Art Unit
2444
USPC
718/1
Abstract

An administrator can initiate an automatic software update to a network appliance that is configured as a cluster of nodes. The update is performed sequentially on a node-by-node basis in order to maintain availability and performance of the network appliance during the update.

Claims (36)

1. A non-transitory computer readable medium storing executable code that, when executing on one or more computing devices, performs the steps of:

providing a network appliance associated with an enterprise network, wherein the network appliance is configured to manage secure connections to zero trust network access (ZTNA) applications according to a security policy for use of the ZTNA applications by users associated with the enterprise network, and configured in a cluster of nodes, each node of the network appliance similarly configured to support network functions and each node of the network appliance including a bootable partition executing an update agent and an update partition configured to store a different version of the node;

providing a notification to a network administrator of an update available for the network appliance from a user interface of a threat management facility for an enterprise network, the notification including an indication of whether the update is a full update to each node or an incremental update to each node;

receiving an update request from the network administrator to perform the update to the cluster of nodes;

automatically and sequentially updating each node in the cluster from the threat management facility according to the update while continuing to operate each other node in the cluster that is not being updated, wherein updating each node includes operating the update agent for the node to perform the steps of:

when the update is the incremental update, updating one or more software components on a first system image executing from the bootable partition of the node, and

when the update is the full update, copying the update to the update partition and rebooting the node from the update partition so as to execute a second system image from the full update, such that the update partition becomes the bootable partition of the node and the bootable partition becomes the update partition of the node; and

upon a completion of the update on each node in the cluster, updating version information for the network appliance at the threat management facility.

2. The non-transitory computer readable medium of claim 1 , wherein the cluster shares responsibility for network functions to support high availability and scalability.

3. The non-transitory computer readable medium of claim 1 , wherein the network appliance includes a gateway for the enterprise network.

4. The non-transitory computer readable medium of claim 1 , wherein the network appliance includes a gateway for a zero trust network access application.

5. The non-transitory computer readable medium of claim 1 , wherein the network appliance includes a firewall for the enterprise network.

6. The non-transitory computer readable medium of claim 1 , wherein the cluster includes a plurality of virtual compute instances.

7. The non-transitory computer readable medium of claim 1 , wherein the cluster includes a plurality of physical compute instances.

8. A method comprising:

receiving an update request from a network administrator to perform an update to a network appliance associated with an enterprise network, wherein the network appliance is configured to manage secure connections to zero trust network access (ZTNA) applications according to a security policy for use of the ZTNA applications by users associated with the enterprise network, the network appliance including a cluster of nodes, each node including a bootable partition executing an instance of the network appliance including an update agent and each node including an update partition configured to store a different version of the network appliance;

automatically and sequentially updating each node in the cluster from a remote resource according to the update while continuing to operate each other node in the cluster that is not being updated, wherein updating each node includes operating the update agent for the node to perform the steps of:

when the update is an incremental update, updating one or more software components on a first system image executing from the bootable partition of the node, and

when the update is a full update, copying the update to the update partition and rebooting the node from the update partition so as to execute a second system image from the full update, such that the update partition becomes the bootable partition of the node and the bootable partition becomes the update partition of the node; and

upon a completion of the update on each node in the cluster, updating version information for the network appliance at a threat management facility.

9. The method of claim 8 , wherein the cluster shares responsibility for network functions to support high availability and scalability.

10. The method of claim 8 , wherein the network appliance includes a gateway for an enterprise network.

11. The method of claim 8 , wherein the network appliance includes a gateway for a zero trust network access application.

12. The method of claim 8 , wherein the network appliance includes a firewall for an enterprise network.

13. The method of claim 8 , wherein the cluster includes a plurality of virtual compute instances.

14. The method of claim 8 , wherein the cluster includes a plurality of physical compute instances.

15. The method of claim 8 , wherein the update partition stores a prior bootable version of the network appliance from before a most recent full update of the network appliance.

16. The method of claim 15 , wherein the update agent is configured to facilitate an update rollback by reverting to the prior bootable version of the network appliance on the update partition.

17. The method of claim 8 , wherein the remote resource is configured to roll back the update to a previous software configuration in response to a remote request from the network administrator.

18. A system comprising:

a network appliance for an enterprise network, the network appliance configured to manage secure connections to zero trust network access (ZTNA) applications according to a security policy for use of the ZTNA applications by users associated with the enterprise network, and configured in a cluster of nodes each similarly configured to support network functions and each including a bootable partition providing functions of the network appliance and an update partition configured to store a different version of the node;

a data store storing an updated version of the network appliance;

a threat management facility configured to provide a user interface for receiving an update request from a network administrator to perform an update to the cluster of nodes based on the updated version of the network appliance, the threat management facility further configured to respond to the update request by automatically and sequentially updating each node in the cluster according to the update while permitting continued operation of each other node in the cluster that is not being updated; and

an update agent executing on each node in the cluster, the update agent responsive to the threat management facility to install the update according to the updated version of the network appliance by performing the steps of: when the update is an incremental update, updating one or more software components on a first system image executing from the bootable partition of the node, and when the update is a full update, copying the update to the update partition and rebooting the node from the update partition so as to execute a second system image from the full update, such that the update partition becomes the bootable partition of the node and the bootable partition becomes the update partition of the node.

19. The system of claim 18 , wherein each node in the cluster is a physical compute instance.

20. The system of claim 18 , wherein each node in the cluster is a virtual compute instance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2022
From: KAIMAL, BIJU RAMACHANDRA; SUBRAMANIAM, SRISAKTHI; BHANDARI, NIKHIL
To: SOPHOS LIMITED
Reel/Frame 059268/0071 →
Priority Claims (1)
IN 202111047216 · Oct 18, 2021 · national
Continuity (3)
Continuation PCTUS2022018635 · Mar 3, 2022
Provisional Application 63271652 · Oct 25, 2021
Related Publication 20230120785A1 · Apr 20, 2023
References Cited (156)
US 6484261B1 · Wiegel · 2002 [cited by applicant]
US 6769008B1 · Kumar · 2004 [cited by examiner]
US 6801949B1 · Bruck · 2004 [cited by examiner]
US 7676829B1 · Gui et al. · 2010 [cited by applicant]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9306864B2 · Thakkar · 2016 [cited by examiner]
US 9378359B2 · Qureshi et al. · 2016 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10348767B1 · Lee · 2019 [cited by examiner]
US 10411894B1 · Yavnilovich et al. · 2019 [cited by applicant]
US 10958662B1 · Sole · 2021 [cited by examiner]
US 11005853B1 · Agarwal et al. · 2021 [cited by applicant]
US 11019166B2 · Brasetvik · 2021 [cited by examiner]
US 11050716B1 · De Hoz Diego · 2021 [cited by examiner]
US 11134058B1 · Sole · 2021 [cited by examiner]
US 11159546B1 · Moore · 2021 [cited by examiner]
US 11200123B2 · Ding et al. · 2021 [cited by applicant]
US 11218446B2 · Leon · 2022 [cited by applicant]
US 11316842B2 · Bendersky et al. · 2022 [cited by applicant]
US 11356508B1 · Vergara · 2022 [cited by examiner]
US 11363496B2 · Raleigh et al. · 2022 [cited by applicant]
US 11409622B1 · Kaushik et al. · 2022 [cited by applicant]
US 11457040B1 · Sole · 2022 [cited by examiner]
US 11522904B2 · Mcardle et al. · 2022 [cited by applicant]
US 11573786B1 · Kiselev · 2023 [cited by examiner]
US 11588794B2 · Keith, Jr. et al. · 2023 [cited by applicant]
US 11652815B2 · Keith, Jr. et al. · 2023 [cited by applicant]
US 11663030B2 · Kaimal et al. · 2023 [cited by applicant]
US 11695733B2 · Hastings · 2023 [cited by applicant]
US 11729144B2 · Ahn · 2023 [cited by examiner]
US 11799831B2 · Vemulpali · 2023 [cited by applicant]
US 11841781B2 · Kaushik et al. · 2023 [cited by applicant]
US 11861221B1 · Richardson et al. · 2024 [cited by applicant]
US 11886932B1 · Dasgupta et al. · 2024 [cited by applicant]
US 20020161869A1 · Griffin · 2002 [cited by examiner]
US 20050204041A1 · Blinn et al. · 2005 [cited by applicant]
US 20060271931A1 · Harris · 2006 [cited by examiner]
US 20070156889A1 · Bhrara · 2007 [cited by examiner]
US 20080034401A1 · Wang · 2008 [cited by applicant]
US 20080109871A1 · Jacobs · 2008 [cited by applicant]
US 20080177994A1 · Mayer · 2008 [cited by applicant]
US 20100094981A1 · Cordray · 2010 [cited by examiner]
US 20100325588A1 · Reddy et al. · 2010 [cited by applicant]
US 20110107331A1 · Evans · 2011 [cited by examiner]
US 20110231361A1 · Patchava · 2011 [cited by examiner]
US 20130117817A1 · Gantman et al. · 2013 [cited by applicant]
US 20130201821A1 · Yamato · 2013 [cited by examiner]
US 20140007222A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140047227A1 · Breternitz · 2014 [cited by examiner]
US 20140047342A1 · Breternitz · 2014 [cited by examiner]
US 20140172783A1 · Suzuki · 2014 [cited by examiner]
US 20160092203A1 · Filali-Adib · 2016 [cited by examiner]
US 20160173535A1 · Barabash et al. · 2016 [cited by applicant]
US 20160212167A1 · Dotan et al. · 2016 [cited by applicant]
US 20160306862A1 · Sitsky et al. · 2016 [cited by applicant]
US 20170090903A1 · Bainville · 2017 [cited by examiner]
US 20170099280A1 · Goel et al. · 2017 [cited by applicant]
US 20170187750A1 · Zhang et al. · 2017 [cited by applicant]
US 20170250867A1 · Kohli et al. · 2017 [cited by applicant]
US 20170316400A1 · Venkatakrishnan et al. · 2017 [cited by applicant]
US 20170318092A1 · Maredia · 2017 [cited by examiner]
US 20180293152A1 · Sherafat Kazemzadeh · 2018 [cited by examiner]
US 20190007392A1 · Rubiyath et al. · 2019 [cited by applicant]
US 20190050296A1 · Luo · 2019 [cited by examiner]
US 20190149418A1 · Bertsche · 2019 [cited by examiner]
US 20190229987A1 · Shelke · 2019 [cited by examiner]
US 20190361915A1 · Weaver et al. · 2019 [cited by applicant]
US 20190372938A1 · Pasdar · 2019 [cited by examiner]
US 20200067938A1 · Smith et al. · 2020 [cited by applicant]
US 20200092254A1 · Goeringer et al. · 2020 [cited by applicant]
US 20200137125A1 · Patnala et al. · 2020 [cited by applicant]
US 20200153898A1 · Sabath · 2020 [cited by examiner]
US 20200162922A1 · Kang et al. · 2020 [cited by applicant]
US 20200236112A1 · Pularikkal et al. · 2020 [cited by applicant]
US 20200249928A1 · Zeng · 2020 [cited by examiner]
US 20200296119A1 · Lim et al. · 2020 [cited by applicant]
US 20200326930A1 · Suryanarayana · 2020 [cited by examiner]
US 20200344115A1 · Power et al. · 2020 [cited by applicant]
US 20200351157A1 · Patterson · 2020 [cited by examiner]
US 20210029119A1 · Raman · 2021 [cited by examiner]
US 20210224093A1 · Fu · 2021 [cited by examiner]
US 20210266346A1 · Gordon · 2021 [cited by examiner]
US 20210314301A1 · Chanak · 2021 [cited by examiner]
US 20210334004A1 · Krivenok · 2021 [cited by examiner]
US 20210334222A1 · Wood · 2021 [cited by examiner]
US 20210336959A1 · Shah · 2021 [cited by examiner]
US 20210385129A1 · Shadbolt et al. · 2021 [cited by applicant]
US 20210389968A1 · Majewski · 2021 [cited by examiner]
US 20220012042A1 · Doshi et al. · 2022 [cited by applicant]
US 20220021665A1 · Barton · 2022 [cited by examiner]
US 20220027138A1 · Stevens · 2022 [cited by examiner]
US 20220078267A1 · Nixon · 2022 [cited by examiner]
US 20220114157A1 · Rangasamy · 2022 [cited by examiner]
US 20220191099A1 · Pieczul · 2022 [cited by examiner]
US 20220191248A1 · Pieczul · 2022 [cited by examiner]
US 20220210128A1 · Allam · 2022 [cited by examiner]
US 20220210173A1 · Katmor · 2022 [cited by examiner]
US 20220224621A1 · Devarajan · 2022 [cited by examiner]
US 20220239491A1 · Sugarev · 2022 [cited by applicant]
US 20220247785A1 · Ly · 2022 [cited by examiner]
US 20220255822A1 · Yousouf · 2022 [cited by examiner]
US 20220272082A1 · Gupta · 2022 [cited by examiner]
US 20220272111A1 · Rao et al. · 2022 [cited by applicant]
US 20220278900A1 · Pieczul · 2022 [cited by examiner]
US 20220337576A1 · Rao Krishnagi et al. · 2022 [cited by applicant]
US 20220342775A1 · Takubo · 2022 [cited by examiner]
US 20220350675A1 · Navali · 2022 [cited by examiner]
US 20220368691A1 · Desarda · 2022 [cited by examiner]
US 20220377093A1 · Crabtree · 2022 [cited by examiner]
US 20220385563A1 · Lalani · 2022 [cited by examiner]
US 20220400114A1 · Sreedhar · 2022 [cited by examiner]
US 20220400116A1 · Sreedhar · 2022 [cited by examiner]
US 20230025529A1 · Fu · 2023 [cited by examiner]
US 20230035486A1 · Vergara · 2023 [cited by examiner]
US 20230038058A1 · May · 2023 [cited by examiner]
US 20230060895A1 · Wu · 2023 [cited by examiner]
US 20230069738A1 · Sreedhar · 2023 [cited by examiner]
US 20230080458A1 · Lok et al. · 2023 [cited by applicant]
US 20230097099A1 · Kothiyal · 2023 [cited by examiner]
US 20230109926A1 · Nair · 2023 [cited by examiner]
US 20230111304A1 · Thomas · 2023 [cited by examiner]
US 20230111864A1 · Thomas · 2023 [cited by examiner]
US 20230113375A1 · Thomas · 2023 [cited by examiner]
US 20230113621A1 · Griffin · 2023 [cited by examiner]
US 20230114719A1 · Thomas · 2023 [cited by examiner]
US 20230114821A1 · Thomas · 2023 [cited by examiner]
US 20230117962A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230119503A1 · Maheve et al. · 2023 [cited by applicant]
US 20230119767A1 · Pabón · 2023 [cited by examiner]
US 20230120522A1 · Bhandari et al. · 2023 [cited by applicant]
US 20230121834A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230123781A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230216685A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230254318A1 · Hu · 2023 [cited by examiner]
US 20230362202A1 · Li · 2023 [cited by examiner]
CN 112788019 · 2021 [cited by applicant]
WO WO2023069129 · 2023 [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,766 Final Office Action mailed Nov. 8, 2023”, 25 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,681 Notice of Allowance mailed Feb. 8, 2024”, 6 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,607 Notice of Allowance mailed Jan. 12, 2023”, 11 pages. [cited by applicant]
ISA/EP, “PCT Application No. PCT/US22/18635 International Search Report and Written Opinion mailed Aug. 16, 2022”, 19 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,766 Non-Final Office Action mailed May 10, 2023”, 20 pages. [cited by applicant]
ISA/EP, “PCT Application No. PCT/US22/18635 Invitation to Pay Additional Fees mailed Jun. 24, 2022”, 15 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/690,632 Non-Final Office Action mailed Apr. 24, 2024”, , 15 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/690,766 Non-Final Office Action mailed Apr. 10, 2024”, , 28 pages. [cited by applicant]
WIPO, , “PCT Application No. PCT/US22/18635 International Preliminary Report on Patentability mailed May 2, 2024”, , 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,704 Non-Final Office Action mailed Sep. 16, 2024”, 8 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/690,766 Final Office Action mailed Nov. 19, 2024”, 26 pages. [cited by applicant]
Cited By (1)
US 12,307,246