IP Library Patent Application 18530458
Patent Application
App. No. 18/530,458

Managing Cloud-Based Networks

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/530,458
Abstract

Edge clusters execute in a plurality of regional clouds of a cloud computing platforms, which may include cloud POPs. Edge clusters may be programmed to control access to applications executing in the cloud computing platform. A network object is created and represents network resources, such as IP addresses, subnetworks, or virtual networks. Permissions of one or more entities to access the network resources are associated with the network object. Identifiers of entities, including other network resources, are added to the network object to indicate network connections to the network resources. The edge clusters, and possibly one or more virtual networks, are configured by a network orchestrator according to the network object to implement the permissions and network connections.

Claims (36)

1 . A method comprising:

instantiating a plurality of edge clusters on one or more cloud computing platforms, each edge cluster of the plurality of edge clusters being located in a different regional cloud of a plurality of regional clouds in the one or more cloud computing platforms;

receiving, by a computing device, a network object defining a storing (a) a definition of one or more network resources of the one or more cloud computing platforms, (b) network connections between the one or more network resources and one or more entities executing in the one or more cloud computing platforms, and (c) permissions of the one or more entities; and

configuring, by the computing device, the plurality of edge clusters to implement routing of packets according to (b) and grant access to the one or more network resources according to (c).

2 . The method of claim 1 , wherein the one or more cloud computing platforms are multiple cloud computing platforms and the one or more network resources are multiple network resources of the multiple cloud computing platforms.

3 . The method of claim 1 , wherein the one or more network resources are internet protocol addresses.

4 . The method of claim 1 , wherein the one or more network resources are subnetworks.

5 . The method of claim 1 , wherein the one or more network resources are virtual networks.

6 . The method of claim 1 , further comprising configuring the plurality of edge clusters to implement the routing of the packets according to (b) by: configuring routing tables in the plurality of edge clusters according to (b).

7 . The method of claim 6 , further comprising configuring the plurality of edge clusters to implement the routing of the packets according to (b) by: configuring routing tables in one or more virtual networks according to (b).

8 . The method of claim 1 , further comprising:

receiving, by the computing device, an instruction to delete the network object;

in response to the instruction to delete the network object performing, by the computing device:

configuring the plurality of edge clusters to cease implementing routing of packets according to (b); and

configuring the plurality of edge clusters to cease granting access to the one or more network resources according to (c).

9 . The method of claim 1 , wherein the one or more entities include at least one of a user account, group of users, business unit, or user endpoints within a geographic area.

10 . The method of claim 1 , wherein the one or more entities include at least one of an application, a database, a storage resource, or a management tool.

11 . A system comprising:

one or more cloud computing platforms comprising a plurality of regional clouds;

a plurality of edge clusters on the one or more cloud computing platforms, each edge cluster being located in a different regional cloud of the one or more cloud computing platforms; and

a network orchestrator coupled to the plurality of edge clusters and programmed to:

receive a network object defining a storing (a) a definition of one or more network resources of the one or more cloud computing platforms, (b) network connections between the one or more network resources and one or more entities executing in the one or more cloud computing platforms, and (c) permissions of the one or more entities; and

configure the plurality of edge clusters to implement routing of packets according to (b) and grant access to the one or more network resources according to (c).

12 . The system of claim 11 , wherein the one or more cloud computing platforms are multiple cloud computing platforms and the one or more network resources are multiple network resources of the multiple cloud computing platforms.

13 . The system of claim 11 , wherein the one or more network resources are internet protocol addresses.

14 . The system of claim 11 , wherein the one or more network resources are subnetworks.

15 . The system of claim 11 , wherein the one or more network resources are virtual networks.

16 . The system of claim 11 , wherein the network orchestrator is further programmed to configure the plurality of edge clusters to implement the routing of the packets according to (b) by: configuring routing tables in the plurality of edge clusters according to (b).

17 . The system of claim 16 , wherein the network orchestrator is further programmed to configure the plurality of edge clusters to implement the routing of the packets according to (b) by: configuring routing tables in one or more virtual networks according to (b).

18 . The system of claim 11 , wherein the network orchestrator is further programmed to:

receive an instruction to delete the network object;

in response to the instruction to delete the network object:

configure the plurality of edge clusters to cease implementing routing of packets according to (b); and

configure the plurality of edge clusters to cease granting access to the one or more network resources according to (c).

19 . The system of claim 11 , wherein the one or more entities include at least one of a user account, group of users, business unit, or user endpoints within a geographic area.

20 . The system of claim 11 , wherein the one or more entities include at least one of an application, a database, a storage resource, or a management tool.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Oct 31, 2025
From: BHAU, NEHAL SATISHBHAI
To: PROSIMO INC.
Reel/Frame 072742/0877 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2025
From: PROSIMO INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 071425/0477 →
RELEASE OF SECURITY INTEREST Recorded Jan 24, 2025
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: PROSIMO INC.
Reel/Frame 069996/0300 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE NAME OF THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 65778 FRAME: 531. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 15, 2025
From: SIDDIQUI, FARAZ; THAKUR, GAURAV; MOORE, ERICK
To: PROSIMO INC.
Reel/Frame 069930/0532 →
SECURITY INTEREST Recorded Sep 27, 2024
From: PROSIMO INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 068719/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2023
From: SIDDIQUI, FARAZ; THAKUR, GAURAV; MOORE, ERICK
To: PROSIMO INC
Reel/Frame 065778/0531 →