IP Library Granted Patent US 12,395,556
Granted Patent B2
US 12,395,556 · App. 18/766,015 · Granted Aug 19, 2025

State management and storage with policy enforcement in a distributed cloud computing network

Inventors: Kenton Taylor Varda (Austin, TX); Alex Dwane Robinson (Austin, TX); Brett Joseph Hoerner (Austin, TX); Loren Cody Koeninger (Austin, TX); Gregory Richard McKeon (New York, NY)
Assignee: CLOUDFLARE, INC.
H04L67/1097H04L63/10H04L67/01H04L67/1021
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,556
App. No.
18/766,015
Granted
Aug 19, 2025
Kind
B2
Abstract

An object worker is instantiated at a compute server of a distributed cloud computing network, where the object worker includes a single instantiation of a piece of code that solely controls reading/writing to an object. An external communication policy is associated with the first object worker. If the external communication policy does not allow the object worker to send communications with the object to an asset that is external to the distributed cloud computing network, the communication is prevented from being sent. If the external communication policy allows the object worker to send communications with the object to the asset that is external to the distributed cloud computing network, the communication is sent from the first object worker to the asset.

Claims (59)

1. A method, comprising:

instantiating a first object worker on a first compute server of a plurality of compute servers of a distributed cloud computing network, wherein the first object worker is associated with a first object, and wherein the first object worker includes a single instantiation of a first piece of code that solely controls reading and writing to the first object;

receiving, at a first compute server, a first request for the first object worker to send a first communication with the first object to a first asset that is on a first network that is external to the distributed cloud computing network;

accessing a first set of one or more policies that are applicable for processing the first object, wherein the first set of one or more policies include an external communication policy;

determining, based on an external communication policy associated with the first object worker, that the first object worker is not allowed to send the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network, and responsive to this determination, preventing the first object worker from sending the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network;

receiving, at the first compute server, a second request for the first object worker to send a second communication with the first object to a second asset that is on a second network that is external to the distributed cloud computing network;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the second communication with the first object to the second asset that is on the second network that is external to the distributed cloud computing network, and responsive to this determination, allowing the first object worker to send the second communication with the first object to the second asset.

2. The method of claim 1 , wherein the external communication policy specifies a set of one or conditions that control whether communication can be sent to assets on networks external to the distributed cloud computing network.

3. The method of claim 1 , further comprising:

receiving, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is not allowed to send the third communication with the first object to the second object worker, and responsive to this determination, preventing the first object worker from sending the third communication with the first object to the second object worker.

4. The method of claim 1 , further comprising:

receiving, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the third communication with the first object to the second object worker and responsive to this determination, transmitting the third communication with the first object from the first object worker to the second object worker.

5. The method of claim 1 , wherein the first set of one or more policies are defined by an owner of the first object.

6. The method of claim 1 , wherein the first set of one or more policies are defined by an end user.

7. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to carry out the operations comprising:

instantiating a first object worker on a first compute server of a plurality of compute servers of a distributed cloud computing network, wherein the first object worker is associated with a first object, and wherein the first object worker includes a single instantiation of a first piece of code that solely controls reading and writing to the first object;

receiving, at a first compute server, a first request for the first object worker to send a first communication with the first object to a first asset that is on a first network that is external to the distributed cloud computing network;

accessing a first set of one or more policies that are applicable for processing the first object, wherein the first set of one or more policies include an external communication policy;

determining, based on an external communication policy associated with the first object worker, that the first object worker is not allowed to send the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network, and responsive to this determination, preventing the first object worker from sending the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network;

receiving, at the first compute server, a second request for the first object worker to send a second communication with the first object to a second asset that is on a second network that is external to the distributed cloud computing network;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the second communication with the first object to the second asset that is on the second network that is external to the distributed cloud computing network, and responsive to this determination, allowing the first object worker to send the second communication with the first object to the second asset.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the external communication policy specifies a set of one or conditions that control whether communication can be sent to assets on networks external to the distributed cloud computing network.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is not allowed to send the third communication with the first object to the second object worker, and responsive to this determination, preventing the first object worker from sending the third communication with the first object to the second object worker.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

accessing the first set of one or more policies that are applicable for processing the first object; and

determining, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the third communication with the first object to the second object worker and responsive to this determination, transmitting the third communication with the first object from the first object worker to the second object worker.

11. The non-transitory machine-readable storage medium of claim 7 , wherein the first set of one or more policies are defined by an owner of the first object.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the first set of one or more policies are defined by an end user.

13. A first compute server, comprising:

a processor; and

a non-transitory machine-readable storage medium coupled to the processor, wherein the non-transitory machine-readable storage medium stores instructions that, when executed by the processor, causes the server to perform operations including:

instantiate a first object worker on the first compute server of a plurality of compute servers of a distributed cloud computing network, wherein the first object worker is associated with a first object, and wherein the first object worker includes a single instantiation of a first piece of code that solely controls reading and writing to the first object;

receive, at the first compute server, a first request for the first object worker to send a first communication with the first object to a first asset that is on a first network that is external to the distributed cloud computing network;

access a first set of one or more policies that are applicable for processing the first object, wherein the first set of one or more policies include an external communication policy;

determine, based on an external communication policy associated with the first object worker, that the first object worker is not allowed to send the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network, and responsive to this determination, prevent the first object worker from sending the first communication with the first object to the first asset that is on the first network that is external to the distributed cloud computing network;

receive, at the first compute server, a second request for the first object worker to send a second communication with the first object to a second asset that is on a second network that is external to the distributed cloud computing network;

access the first set of one or more policies that are applicable for processing the first object; and

determine, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the second communication with the first object to the second asset that is on the second network that is external to the distributed cloud computing network, and responsive to this determination, allowing the first object worker to send the second communication with the first object to the second asset.

14. The first compute server of claim 13 , wherein the external communication policy specifies a set of one or conditions that control whether communication can be sent to assets on networks external to the distributed cloud computing network.

15. The first compute server of claim 13 , wherein the operations further include:

receive, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

access the first set of one or more policies that are applicable for processing the first object; and

determine, based on the external communication policy associated with the first object worker, that the first object worker is not allowed to send the third communication with the first object to the second object worker, and responsive to this determination, prevent the first object worker from sending the third communication with the first object to the second object worker.

16. The first compute server of claim 13 , wherein the operations further include:

receive, at the first compute server, a third request for the first object worker to second a third communication with the first object to a second object worker that is associated with another organization or domain compared to the first object worker;

access the first set of one or more policies that are applicable for processing the first object; and

determine, based on the external communication policy associated with the first object worker, that the first object worker is allowed to send the third communication with the first object to the second object worker and responsive to this determination, transmit the third communication with the first object from the first object worker to the second object worker.

17. The first compute server of claim 13 , wherein the first set of one or more policies are defined by an owner of the first object.

18. The first compute server of claim 13 , wherein the first set of one or more policies are defined by an end user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2024
From: VARDA, KENTON TAYLOR; ROBINSON, ALEX DWANE; HOERNER, BRETT JOSEPH; KOENINGER, LOREN CODY; MCKEON, GREGORY RICHARD
To: CLOUDFLARE, INC.
Reel/Frame 067928/0356 →
Continuity (4)
Continuation 17566539 · Dec 30, 2021
Continuation 17484807 · Sep 24, 2021
Provisional Application 63121793 · Dec 4, 2020
Related Publication 20240364783A1 · Oct 31, 2024
References Cited (57)
US 5892900A · Ginter et al. · 1999 [cited by applicant]
US 8458125B1 · Chong et al. · 2013 [cited by applicant]
US 8601134B1 · Sorenson et al. · 2013 [cited by applicant]
US 8639921B1 · Sorenson et al. · 2014 [cited by applicant]
US 8793343B1 · Sorenson et al. · 2014 [cited by applicant]
US 9411671B1 · Johnson et al. · 2016 [cited by applicant]
US 9628473B1 · Odom et al. · 2017 [cited by applicant]
US 9852149B1 · Taylor et al. · 2017 [cited by applicant]
US 10152467B2 · Chan et al. · 2018 [cited by applicant]
US 10333711B2 · Fleischman et al. · 2019 [cited by applicant]
US 10498812B1 · Varda · 2019 [cited by examiner]
US 10819576B2 · Seshadri et al. · 2020 [cited by applicant]
US 11070621B1 · Tornow et al. · 2021 [cited by applicant]
US 20040107342A1 · Pham et al. · 2004 [cited by applicant]
US 20090282273A1 · Hamilton et al. · 2009 [cited by applicant]
US 20130117252A1 · Samaddar et al. · 2013 [cited by applicant]
US 20140123316A1 · Leggette et al. · 2014 [cited by applicant]
US 20140149794A1 · Shetty et al. · 2014 [cited by applicant]
US 20140215574A1 · Erb et al. · 2014 [cited by applicant]
US 20170318093A1 · Muhlestein et al. · 2017 [cited by applicant]
US 20170330149A1 · Hunter et al. · 2017 [cited by applicant]
US 20180114015A1 · Nuseibeh et al. · 2018 [cited by applicant]
US 20180114334A1 · Desai et al. · 2018 [cited by applicant]
US 20180146069A1 · Du et al. · 2018 [cited by applicant]
US 20200026732A1 · Bequet et al. · 2020 [cited by applicant]
US 20200053397A1 · Zhou · 2020 [cited by applicant]
US 20200204651A1 · Xi et al. · 2020 [cited by applicant]
US 20210026611A1 · Bequet et al. · 2021 [cited by applicant]
US 20210406381A1 · Heisrath et al. · 2021 [cited by applicant]
EP 1914655A2 · 2008 [cited by applicant]
EP 3933630A1 · 2022 [cited by applicant]
KR 1020180032524A · 2018 [cited by applicant]
WO 2017096920A1 · 2017 [cited by applicant]
Brooks et al. A Component Architecture for the Internet of Things. Proceedings of the IEEE. vol. 106, Issue 9, 2018. pp. 1527-1542 (Year: 2018). [cited by examiner]
Etchevers et al. Automated Configuration of Legacy Applications in the Cloud. 2011 Fourth IEEE International Conference on Utility and Cloud Computing. pp. 170-177. (Year: 2011). [cited by examiner]
Ayache et al., “Access Control Policies Enforcement in a Cloud Environment: Openstack”, IEEE, 2015 11th International Conference on Information Assurance and Security (IAS), 2015, pp. 26-31 (7 pages). [cited by applicant]
Cabrera et al., “Softwarization and Network Coding in the Mobile Edge Cloud for the Tactile Internet”, Proceedings of the IEEE, 2018, pp. 1-14. [cited by applicant]
European search report and Search Opinion, EP App. No. 21901618.5, Oct. 10, 2024, 06 pages. [cited by applicant]
Ex Parte Quayle Action, U.S. Appl. No. 17/566,539, Dec. 22, 2023, 6 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/346,746, May 2, 2022, 16 pages. [cited by applicant]
How Sandstorm Works: Containerize data, not services, Feb. 28, 2019, 12 pages, downloaded at: https://web.archive.org/web/20190228074058/https:/sandstom.io/how-it-works. [cited by applicant]
International Preliminary Report on Patentability, PCT App. No. PCT/US2019/063428, Dec. 9, 2021, 6 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App No. PCT/US2019/063428, Mar. 27, 2020, 9 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2021/062071, Apr. 15, 2022, 8 pages. [cited by applicant]
Joshua Fox, “When is a Singleton not a Singleton?”, Java World , Jan. 2001, 9 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/696,879, Aug. 18, 2020, 10 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/346,746, Feb. 22, 2022, 13 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/958,087, Mar. 15, 2023, 19 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/508,201, Jul. 17, 2024, 16 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/425,415, mailed Aug. 1, 2019, 13 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/425,415, Oct. 17, 2019, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/696,879, Feb. 11, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/346,746, Sep. 13, 2022, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/484,807, Dec. 15, 2021, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/566,539, Mar. 13, 2024, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/566,539, Mar. 20, 2024, 12 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/958,087, Jul. 12, 2023, 7 pages. [cited by applicant]