IP Library › Granted Patent US 12,255,817
Granted Patent B2
US 12,255,817 · App. 18/102,630 · Granted Mar 18, 2025

Executing workloads across multiple cloud service providers

Inventors: Saulius Mašnauskas (Vilnius, LT); Rokas Bilevičius (Vilnius, LT); Tadeuš Varnas (Vilnius, LT); Augustinas Stirbis (Vilnius, LT); Leonid Kuperman (Tarzana, CA)
Assignee: CAST AI Group, Inc.
H04L45/741H04L12/4633H04L12/4641H04L63/029H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,817
App. No.
18/102,630
Granted
Mar 18, 2025
Kind
B2
Abstract

A multi-cloud service system establishes tunnels and network overlays across multiple CSPs while meeting a criterion for a latency threshold. The system conducts a latency benchmarking evaluation across each cloud region for multiple CSPs and based on the latency bench marking evaluation results, the system may identify a group of cloud regions that satisfy a criterion such as predetermined maximum latency threshold or geographical restriction. The system may provision the group of cloud regions by provisioning a tunnel between nodes of the multiple CSPs. The system further establishes an overlay network on top of the tunnel by encapsulating packets using encapsulation end point such as VTEP (VXLAN tunnel end point) over VXLAN (Virtual Extension Local Area Network), which may help to ensure reliable transmission of packets from pod to pod. The system may inject user data into each node to initiate operations across the provisioned nodes using injected user data.

Claims (34)

1. A non-transitory machine-readable medium comprising memory with instructions encoded thereon, the instructions causing one or more processors to perform operations when executed, the instructions comprising instructions to:

provision a tunnel between nodes of two or more CSPs (Cloud Service Providers), each node having associated Kubernetes pods provisioned for the node that run workloads of the node;

provision an overlay network on top of the tunnel having an encapsulation scheme that enables pod-to-pod communication of the Kubernetes pods between the nodes on each of the two or more CSPs across the two or more CSPs notwithstanding the Kubernetes pods comprising applications that each have their own addressing scheme based on internal domain names;

establish a network infrastructure of the overlay network for compute resources to be communicated between the two or more CSPs over a virtual private network (VPN), wherein provisioning the overlay network comprises opening a firewall port on each node, thereby completing provisioning of the nodes;

responsive to completing provisioning of the nodes, initiating operations across the provisioned nodes by injecting data comprising tokens, certificates, and Internet Protocol (IP) addresses into each node.

2. The non-transitory machine-readable medium of claim 1 , wherein the instructions further comprise instructions to select the nodes of the two or more CSPs based on the nodes being within CSP regions satisfying a criterion.

3. The non-transitory machine-readable medium of claim 2 , wherein the criterion comprises a minimum latency between two of the CSP regions.

4. The non-transitory machine-readable medium of claim 1 , wherein the Kubernetes pods of the nodes comprise applications operating on a given node, each application having a respective addressing scheme based on internal domain names.

5. The non-transitory machine-readable medium of claim 4 , wherein the instructions to provision the overlay network comprise instructions to generate an encapsulation scheme that enables pod-to-pod communications across the two or more CSPs notwithstanding each of the applications having a respective network naming scheme.

6. The non-transitory machine-readable medium of claim 4 , wherein the instructions to provision the overlay network comprise instructions to generate a routing table comprising address information for the Kubernetes pods.

7. The non-transitory machine-readable medium of claim 1 , wherein the injected data is derived based on credentials input by a user.

8. A method comprising:

provisioning a tunnel between nodes of two or more CSPs (Cloud Service Providers), each node having associated Kubernetes pods provisioned for the node that run workloads of the node;

provisioning an overlay network on top of the tunnel having an encapsulation scheme that enables pod-to-pod communication of the Kubernetes pods between the nodes on each of the two or more CSPs across the two or more CSPs notwithstanding the Kubernetes pods comprising applications that each have their own addressing scheme based on internal domain names;

establishing a network infrastructure of the overlay network for compute resources to be communicated between the two or more CSPs over a virtual private network (VPN), wherein provisioning the overlay network comprises opening a firewall port on each node, thereby completing provisioning of the nodes;

responsive to completing provisioning of the nodes, initiating operations across the provisioned nodes by injecting data comprising tokens, certificates, and Internet Protocol (IP) addresses into each node.

9. The method of claim 8 , wherein the method further comprises selecting the nodes of the two or more CSPs based on the nodes being within CSP regions satisfying a criterion.

10. The method of claim 9 , wherein the criterion comprises a minimum latency between two of the CSP regions.

11. The method of claim 8 , wherein the Kubernetes pods of the nodes comprise applications operating on a given node, each application having a respective addressing scheme based on internal domain names.

12. The method of claim 11 , wherein provisioning the overlay network comprises generating an encapsulation scheme that enables pod-to-pod communications across the two or more CSPs notwithstanding each of the applications having a respective network naming scheme.

13. The method of claim 11 , wherein provisioning the overlay network comprises generating a routing table comprising address information for the Kubernetes pods.

14. The method of claim 8 , wherein the injected data is derived based on credentials input by a user.

15. A system comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions, the instructions, when executed by the one or more processors, cause the processor to perform operations comprising:

provisioning a tunnel between nodes of two or more CSPs (Cloud Service Providers), each node having associated Kubernetes pods provisioned for the node that run workloads of the node;

provisioning an overlay network on top of the tunnel having an encapsulation scheme that enables pod-to-pod communication of Kubernetes pods between the nodes on each of the two or more CSPs across the two or more CSPs notwithstanding the Kubernetes pods comprising applications that each have their own addressing scheme based on internal domain names;

establishing a network infrastructure of the overlay network for compute resources to be communicated between the two or more CSPs over a virtual private network (VPN), wherein provisioning the overlay network comprises opening a firewall port on each node, thereby completing provisioning of the nodes;

responsive to completing provisioning of the nodes, initiating operations across the provisioned nodes by injecting data comprising tokens, certificates, and Internet Protocol (IP) addresses into each node.

16. The system of claim 15 , wherein the operations further comprise selecting the nodes of the two or more CSPs based on the nodes being within CSP regions satisfying a criterion.

17. The system of claim 16 , wherein the criterion comprises a minimum latency between two of the CSP regions.

18. The system of claim 15 , wherein the pods of the nodes comprise applications operating on a given node, each application having a respective addressing scheme based on internal domain names.

19. The system of claim 18 , wherein provisioning the overlay network comprises generating an encapsulation scheme that enables pod-to-pod communications across the two or more CSPs notwithstanding each of the applications having a respective network naming scheme.

20. The system of claim 18 , wherein provisioning the overlay network comprises generating a routing table comprising address information for the Kubernetes pods.

Assignments (3)
SECURITY INTEREST Recorded Sep 26, 2025
From: CAST AI GROUP, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 072393/0541 →
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST, SECOND AND THIRD INVENTOR NAMES PREVIOUSLY RECORDED AT REEL: 062531 FRAME: 0019. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 17, 2024
From: MASNAUSKAS, SAULIUS; BILEVICIUS, ROKAS; VARNAS, TADEUS; STIRBIS, AUGUSTINAS; KUPERMAN, LEONID
To: CAST AI GROUP, INC.
Reel/Frame 069060/0337 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2023
From: MA¿NAUSKAS, SAULIUS; BILEVIČIUS, ROKAS; VARNAS, TADEU¿; STIRBIS, AUGUSTINAS; KUPERMAN, LEONID
To: CAST AI GROUP, INC.
Reel/Frame 062531/0019 →
Continuity (3)
Continuation 17380729 · Jul 20, 2021
Provisional Application 63054978 · Jul 22, 2020
Related Publication 20230179522A1 · Jun 8, 2023
References Cited (22)
US 10355989B1 · Panchal et al. · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 11089105B1 · Karumbunathan et al. · 2021 [cited by applicant]
US 11159366B1 · Gawade · 2021 [cited by examiner]
US 20160127454A1 · Maheshwari · 2016 [cited by examiner]
US 20160234059A1 · Gu · 2016 [cited by examiner]
US 20160323184A1 · Li et al. · 2016 [cited by applicant]
US 20170257439A1 · Wang · 2017 [cited by examiner]
US 20190238508A1 · Hira · 2019 [cited by examiner]
US 20190319892A1 · Ganguli et al. · 2019 [cited by applicant]
US 20190356609A1 · Grunwald · 2019 [cited by examiner]
US 20200099659A1 · Cometto et al. · 2020 [cited by applicant]
US 20200177503A1 · Hooda et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar et al. · 2020 [cited by applicant]
US 20200296026A1 · Michael · 2020 [cited by examiner]
US 20210019194A1 · Bahl · 2021 [cited by examiner]
United States Office Action, U.S. Appl. No. 17/380,732, Sep. 16, 2022, 11 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/380,729, Dec. 9, 2021, 10 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/380,729, Jun. 16, 2022, 11 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/380,732, Jan. 25, 2023, 11 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/380,732, Jul. 21, 2023, 12 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/380,732, Nov. 9, 2023, 14 pages. [cited by applicant]