IP Library Granted Patent US 11,818,200
Granted Patent B2
US 11,818,200 · App. 17/945,905 · Granted Nov 14, 2023

Hybrid cloud computing network management with synchronization features across different cloud service providers

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L67/10H04L41/0803H04L41/0893H04L41/0895H04L43/0817H04L63/02H04L63/0209H04L63/1425H04L67/1095
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,200
App. No.
17/945,905
Granted
Nov 14, 2023
Kind
B2
Abstract

Techniques for delivering a distributed network security service providing isolation of customer data are described. One example method includes configuring a first node to participate in a node cluster, wherein the first node is hosted by a first cloud service provider, and wherein participating in the node cluster includes performing one or more processing actions specific to the node cluster on data received by the node; configuring a second node to participate in the node cluster, the second node hosted by a second cloud service provider; receiving a status indication from the first node over a network; determining a synchronization mechanism for the first node based on a network configuration of the first node, wherein the determined synchronization mechanism is configured to allow the first node to acquire synchronization data from other nodes in the node cluster; and transmitting the synchronization mechanism to the first node over the network.

Claims (41)

1. A system comprising:

a first node hosted by a first cloud service provider;

a second node hosted by a second cloud service provider distinct from the first cloud service provider;

a firewall configured to:

permit network traffic between the first node and the second node that is initiated by the second node; and

block network traffic between the first node and the second node that is initiated by the first node;

a node-cluster comprising at least the first node and the second node, the node-cluster configured to use a node as a coordinating node tasked with ensuring that synchronization data are kept up-to-date on each of the nodes of the node-cluster; and

a network manager configured to:

determine that the first node has been selected to be used as the coordinating node;

determine that the firewall is configured to block network traffic between the first node and the second node that is initiated by the first node including network traffic initiated by the first node comprising the synchronization data;

instruct the second node to initiate a request for the synchronization data, resulting in the firewall permitting the synchronization data to reach the second node from the first node.

2. The system of claim 1 , wherein the first cloud service provider and the second cloud service provider are regional networks that are each specific to different geographic areas.

3. The system of claim 1 , wherein the network manager is further configured to select the first node to be used as the coordinating node.

4. The system of claim 1 , wherein the node-cluster is further configured to select the first node to be used as the coordinating node.

5. The system of claim 1 , wherein:

the node-cluster further comprises a third node; and

the network manager is further configured to instruct the first node to send the synchronization data to the third node.

6. A system comprising:

one or more processors; and

computer memory comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

operating a firewall configured to:

permit network traffic between a first node and a second node that is initiated by the second node, wherein the first node is hosted by a first cloud service provider and the second node is hosted by a second cloud service provider distinct from the first cloud service provider; and

block network traffic between the first node and the second node that is initiated by the first node;

operating a node-cluster comprising at least the first node and the second node, the node-cluster configured to use a node as a coordinating node tasked with ensuring that synchronization data are kept up-to-date on each of the nodes of the node-cluster; and

operating a network manager configured to:

determine that the first node has been selected to be used as the coordinating node;

determine that the firewall is configured to block network traffic between the first node and the second node that is initiated by the first node including network traffic initiated by the first node comprising the synchronization data;

instruct the second node to initiate a request for the synchronization data, resulting in the firewall permitting the synchronization data to reach the second node from the first node.

7. The system of claim 6 , wherein the first cloud service provider and the second cloud service provider are regional networks that are each specific to different geographic areas.

8. The system of claim 6 , wherein the node-cluster is further configured to select the first node to be used as the coordinating node.

9. A non-transitory computer-readable medium tangibly storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

operating a node-cluster comprising at least a first node and a second node, the node-cluster configured to use a node as a coordinating node tasked with ensuring that synchronization data are kept up-to-date on each of the nodes of the node-cluster, wherein a firewall is configured to:

permit network traffic between a first node and a second node that is initiated by the second node, wherein the first node is hosted by a first cloud service provider and the second node is hosted by a second cloud service provider distinct from the first cloud service provider; and

block network traffic between the first node and the second node that is initiated by the first node; and

operating a network manager configured to:

determine that the first node has been selected to be used as the coordinating node;

determine that the firewall is configured to block network traffic between the first node and the second node that is initiated by the first node including network traffic initiated by the first node comprising the synchronization data;

instruct the second node to initiate a request for the synchronization data, resulting in the firewall permitting the synchronization data to reach the second node from the first node.

10. The non-transitory computer-readable medium of claim 9 , wherein the first cloud service provider and the second cloud service provider are regional networks that are each specific to different geographic areas.

11. The non-transitory computer-readable medium of claim 9 , wherein the network manager is further configured to select the first node to be used as the coordinating node.

12. The non-transitory computer-readable medium of claim 9 , wherein the node-cluster is further configured to select the first node to be used as the coordinating node.

Assignments (2)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2022
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 061219/0281 →
Continuity (4)
Continuation 17371856 · Jul 9, 2021
Continuation 16388551 · Apr 18, 2019
Provisional Application 62659644 · Apr 18, 2018
Related Publication 20230017709A1 · Jan 19, 2023