IP Library Granted Patent US 12,375,449
Granted Patent B2
US 12,375,449 · App. 18/659,847 · Granted Jul 29, 2025

Virtual private cloud network switching

Inventors: Maurilio Cometto (Redwood City, CA); Mate Ferenczy (Mountain View, CA); Sriganesh Kini (Fremont, CA); Mohammad Y. Hajjat (Sunnyvale, CA); Manoj Sharma (Sunnyvale, CA)
Assignee: Google LLC
H04L63/0263G06F9/45558H04L12/4633H04L12/4641H04L61/2575H04L63/0209H04L63/101H04L67/1001G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,449
App. No.
18/659,847
Granted
Jul 29, 2025
Kind
B2
Abstract

In one embodiment, a system includes a plurality of first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines comprises at least one public-cloud virtual machine (VM) that performs network address translation; and a plurality of second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines comprises one or more private-cloud virtual machines, wherein the public-cloud VM is configured to receive, via a network tunnel from the private-cloud VM, one or more first packets to be sent to a public Internet Protocol (IP) address of a public network host, translate, using a NAT mapping, a source address of each first packet from a private IP address of the private-cloud VM to an IP address of the public-cloud VM, and send the first packet to the IP address of the public-cloud VM.

Claims (44)

1. A computer-implemented method comprising:

identifying, by data processing hardware, a first firewall rule associated with a first subnet of a virtual private cloud, the first firewall rule specifying a first source address and a destination for network packets;

generating, by data processing hardware, a first network switch access rule comprising a second source address corresponding to an intersection between the first source address of the first firewall rule and the first subnet;

identifying, by data processing hardware, a second firewall rule associated with a second subnet of the virtual private cloud;

generating, by data processing hardware, a second network switch access rule comprising a third source address corresponding to an intersection between the second source address of the first network switch access rule and the second subnet of the second firewall rule; and

transmitting, by data processing hardware and using the first network switch access rule and the second network switch access rule, the network packets to the destination.

2. The computer-implemented method of claim 1 , wherein the destination for the network packets specifies the Internet.

3. The computer-implemented method of claim 1 , wherein the first firewall rule comprises a set of fields.

4. The computer-implemented method of claim 3 , wherein each field of the set of fields comprises:

a priority;

a protocol;

a source port;

a destination port;

an allow or deny indicator; or

a direction indicator.

5. The computer-implemented method of claim 1 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises controlling how the network packets are processed.

6. The computer-implemented method of claim 1 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises controlling how the network packets transmitted to the destination.

7. The computer-implemented method of claim 1 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises identifying malware from the network packets.

8. The computer-implemented method of claim 7 , wherein identifying malware from the network packets comprises comparing the network packets to known malware data.

9. The computer-implemented method of claim 1 , wherein the first firewall rule comprises an address prefix and a next hop address.

10. The computer-implemented method of claim 9 , wherein the next hop address indicates another destination in the virtual private cloud.

11. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

identifying a first firewall rule associated with a first subnet of a virtual private cloud, the first firewall rule specifying a first source address and a destination for network packets;

generating a first network switch access rule comprising a second source address corresponding to an intersection between the first source address of the first firewall rule and the first subnet;

identifying a second firewall rule associated with a second subnet of the virtual private cloud;

generating a second network switch access rule comprising a third source address corresponding to an intersection between the second source address of the first network switch access rule and the second subnet of the second firewall rule; and

transmitting, using the first network switch access rule and the second network switch access rule, the network packets to the destination.

12. The system of claim 11 , wherein the destination for the network packets specifies the Internet.

13. The system of claim 11 , wherein the first firewall rule comprises a set of fields.

14. The system of claim 13 , wherein each field of the set of fields comprises:

a priority;

a protocol;

a source port;

a destination port;

an allow or deny indicator; or

a direction indicator.

15. The system of claim 11 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises controlling how the network packets are processed.

16. The system of claim 11 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises controlling how the network packets transmitted to the destination.

17. The system of claim 11 , wherein transmitting the network packets to the destination using the first network switch access rule and the second network switch access rule comprises identifying malware from the network packets.

18. The system of claim 17 , wherein identifying malware from the network packets comprises comparing the network packets to known malware data.

19. The system of claim 11 , wherein the first firewall rule comprises an address prefix and a next hop address.

20. The system of claim 19 , wherein the next hop address indicates another destination in the virtual private cloud.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: COMETTO, MAURILIO; FERENCZY, MÁTÉ; HAJJAT, MOHAMMAD Y.; SHARMA, MANOJ; KINI, SRIGANESH
To: CLOUDSIMPLE, INC.
Reel/Frame 067366/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: CLOUDSIMPLE, INC.
To: GOOGLE LLC
Reel/Frame 067366/0045 →
Continuity (4)
Continuation 17651417 · Feb 16, 2022
Continuation 16167361 · Oct 22, 2018
Provisional Application 62734993 · Sep 21, 2018
Related Publication 20240356897A1 · Oct 24, 2024
References Cited (21)
US 11271905B2 · Cometto · 2022 [cited by examiner]
US 20040003290A1 · Malcolm · 2004 [cited by examiner]
US 20060215657A1 · Lee · 2006 [cited by examiner]
US 20130283364A1 · Chang · 2013 [cited by examiner]
US 20140020072A1 · Thomas · 2014 [cited by examiner]
US 20140164595A1 · Bray · 2014 [cited by examiner]
US 20150281059A1 · Xiao · 2015 [cited by applicant]
US 20160164914A1 · Madhav et al. · 2016 [cited by applicant]
US 20170024260A1 · Chandrasekaran et al. · 2017 [cited by applicant]
US 20170026355A1 · Mathaiyan · 2017 [cited by examiner]
US 20170026470A1 · Bhargava et al. · 2017 [cited by applicant]
US 20170097841A1 · Chang · 2017 [cited by examiner]
US 20170099188A1 · Chang et al. · 2017 [cited by applicant]
US 20170317901A1 · Agrawal et al. · 2017 [cited by applicant]
US 20170317978A1 · Diaz-Cuellar · 2017 [cited by examiner]
US 20180026873A1 · Cheng · 2018 [cited by examiner]
US 20180063176A1 · Katrekar · 2018 [cited by examiner]
US 20180063193A1 · Chandrashekhar · 2018 [cited by examiner]
US 20180183760A1 · Kurkure · 2018 [cited by examiner]
US 20190327144A1 · Tembey et al. · 2019 [cited by applicant]
USPTO. Office Action relating to U.S. Appl. No. 17/651,417, dated Sep. 29, 2023. [cited by applicant]