IP Library Granted Patent US 12,166,681
Granted Patent B2
US 12,166,681 · App. 18/170,917 · Granted Dec 10, 2024

Enhanced management of communication rules over multiple computing networks

Inventors: Arijit Chanda (San Jose, CA); Rajiv Krishnamurthy (San Jose, CA)
Assignee: Nicira, Inc.
H04L47/20H04L49/309H04L49/35H04L49/355H04L49/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,166,681
App. No.
18/170,917
Granted
Dec 10, 2024
Kind
B2
Abstract

Described herein are systems, methods, and software to enhance the implementation of communication rules in a computing network. In one example, a method of operating a communication settings system maintains communication rules for a plurality of networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from applications in the plurality of computing networks. The service further identifies a configuration request from a computing network with applications executing in the computing network, identifies a subset of the communication rules based on the plurality of applications, and provides the subset of the communication rules to the computing network.

Claims (34)

1. A method comprising:

identifying a configuration request for a computing network, wherein the configuration request indicates information about a plurality of applications executing in the computing network;

in response to the configuration request, identifying a subset of computing networks from a plurality of computing networks that meet similarity criteria to the computing network based on the information about the plurality of applications; and

identifying communication rules for the computing network from the subset of computing networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from virtual nodes in the subset of computing networks based on information about applications on the virtual nodes.

2. The method of claim 1 , wherein identifying the configuration request from the computing network comprises receiving the configuration request from a management system associated with the computing network.

3. The method of claim 1 , wherein the virtual nodes comprise virtual machines and/or containers.

4. The method of claim 1 , wherein each of the communication rules define a source, a destination, and a forwarding action.

5. The method of claim 4 , wherein at least one of the source or the destination comprises at least one application group.

6. The method of claim 1 , further comprising providing the communication rules to the computing network.

7. The method of claim 6 , wherein providing the subset of the communication rules to the computing network comprises initiating an implementation of the communication rules in the computing network.

8. The method of claim 6 , wherein providing the subset of the communication rules to the computing network comprises transferring the communication rules to a management system of the computing system for selection by an administrator of the computing network.

9. The method of claim 1 , wherein the similarity criteria comprise application types and network size.

10. A computing apparatus comprising:

one or more non-transitory computer readable storage media;

a processing system operatively coupled to the one or more non-transitory computer readable media; and

program instructions stored on the one or more non-transitory computer readable storage media that, when read and executed by the processing system, direct the computing apparatus to:

identify a configuration request for a computing network, wherein the configuration request indicates information about a plurality of applications executing in the computing network;

in response to the configuration request, identify a subset of computing networks from a plurality of computing networks that meet similarity criteria to the computing network based on the information about the plurality of applications; and

identify communication rules for the computing network from the subset of computing networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from virtual nodes in the subset of computing networks based on information about applications on the virtual nodes.

11. The computing apparatus of claim 10 , wherein identifying the configuration request from the computing network comprises receiving the configuration request from a management system associated with the computing network.

12. The computing apparatus of claim 10 , wherein the virtual nodes comprise virtual machines and/or containers.

13. The computing apparatus of claim 10 , wherein each of the communication rules define a source, a destination, and a forwarding action.

14. The computing apparatus of claim 13 , wherein at least one of the source or the destination comprises at least one application group.

15. The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to provide the communication rules to the computing network.

16. The computing apparatus of claim 15 , wherein providing the subset of the communication rules to the computing network comprises initiating an implementation of the communication rules in the computing network.

17. The computing apparatus of claim 15 , wherein providing the subset of the communication rules to the computing network comprises transferring the communication rules to a management system of the computing system for selection by an administrator of the computing network.

18. The computing apparatus of claim 10 , wherein the similarity criteria comprise application types and network size.

19. An apparatus comprising:

one or more non-transitory computer readable storage media; and

program instructions stored on the one or more non-transitory computer readable storage media that, when executed by at least one processor, direct the at least one processor to:

identify a configuration request for a computing network, wherein the configuration request indicates information about a plurality of applications executing in the computing network;

in response to the configuration request, identify a subset of computing networks from a plurality of computing networks that meet similarity criteria to the computing network based on the information about the plurality of applications, wherein wherein the similarity criteria comprise application types and network size; and

identify communication rules for the computing network from the subset of computing networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from virtual nodes in the subset of computing networks based on information about applications on the virtual nodes.

20. The apparatus of claim 19 , wherein the program instructions further direct the at least one processor to initiate an implementation of the communication rules in the computing network.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: CHANDRA, ARIJIT; KRISHNAMURTHY, RAJIV
To: NICIRA, INC.
Reel/Frame 062733/0554 →