IP Library › Granted Patent US 12,425,483
Granted Patent B2
US 12,425,483 · App. 18/770,287 · Granted Sep 23, 2025

Framework for managing configurations of cloud computing resources

Inventors: Sameer Kumar Patro (Bhubaneswar, IN); Aritra Basu (Bangalore, IN); Raghavendra Subhash (Bangalore, IN)
Assignee: Microsoft Technology Licensing, LLC
H04L67/51H04L41/0813
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,483
App. No.
18/770,287
Granted
Sep 23, 2025
Kind
B2
Abstract

The present disclosure relates to generating, updating, modifying, and otherwise managing configurations for virtual services on a cloud computing system. The present disclosure provides example implementations of a configuration management system and configuration handlers on respective server nodes that receive and process requests for modifying one or more configurations that manage operation of virtual services on the cloud. Systems described herein involve leveraging a hierarchical model of configuration characteristics to facilitate both large and small scale modifications. Moreover, the systems described herein leverage a persistent store on server nodes to identify how to update a current base configuration and sub-version as well as synchronize modifications across a set of server nodes.

Claims (40)

1. A method comprising:

receiving a request to modify service configurations for a plurality of virtual services on a cloud computing system, the request including a hierarchical declaration indicating a permission or access policy corresponding to a grouping of virtual services from the plurality of virtual services, the permission or access policy being represented within a first hierarchical model that defines different levels of the permission or access policy in association with the plurality of virtual services on the cloud computing system;

determining a subset of virtual services from the plurality of virtual services based on the permission or access policy indicated by the hierarchical declaration; and

causing one or more service modifications indicated within the request to be applied to service configurations for the subset of virtual services.

2. The method of claim 1 , wherein each of the different levels in the first hierarchical model corresponds to a permission level and indicates a subset of the service configurations for the plurality of virtual services that are modifiable by an individual with the permission level.

3. The method of claim 1 , wherein the request further includes a second hierarchical declaration indicating a location characteristic corresponding to a grouping of virtual services from the plurality of virtual services, the location characteristic being represented within a second hierarchical model that defines different levels of the location characteristic in association with server nodes executing the plurality of virtual services on the cloud computing system.

4. The method of claim 3 , wherein determining the subset of virtual services from the plurality of virtual services is further based on the location characteristic indicated by the second hierarchical declaration.

5. The method of claim 3 , wherein the second hierarchical model includes a geographic hierarchical structure based on physical locations of server nodes on which the plurality of virtual services are implemented.

6. The method of claim 1 , wherein determining the subset of virtual services includes identifying a plurality of server nodes hosting the subset of virtual services.

7. The method of claim 1 , further comprising:

maintaining a record of base configuration identifiers corresponding to base versions of the service configurations and associated version identifiers corresponding to sub-versions of the service configurations indexed within the record according to key pairs.

8. The method of claim 7 , further comprising, upon causing the one or more service modifications to be applied to the service configurations for the subset of virtual services, storing an updated key pair including a base version identifier and a sub-version identifier indicating a log of changes implemented in response to the request to modify service configurations.

9. The method of claim 1 , wherein causing the one or more service modifications to be applied to service configurations for the subset of virtual services includes:

determining that a number of the subset of virtual services indicated by the hierarchical declaration exceeds a threshold number of virtual services; and

based on the number of the subset of virtual services exceeding the threshold number of virtual services, invoking a gossip protocol in which a primary server node confirms a current base version and sub-version of a configuration and provides instructions to additional nodes in connection with updating to the current base version of the configuration.

10. The method of claim 1 , wherein causing the one or more service modifications to be applied to service configurations for the subset of virtual services includes:

In response to determining that the subset of virtual services satisfy predefined criteria, invoking a synchronization protocol in which a key pair for a current base version and sub-version of a configuration are broadcast to server nodes on which the subset of virtual services are hosted, the broadcast causing one or more service modifications indicated within the request to be applied to service configurations for the subset of virtual services.

11. The method of claim 10 , wherein the subset of virtual services satisfy the predefined criteria when a number of the subset of virtual services is less than a threshold number of virtual services or when the subset of virtual services are within a single compute zone.

12. A system, comprising:

one or more processors;

memory in electronic communication with the one or more processors;

instructions stored in the memory, the instructions being executable by the one or more processors to:

receive a request to modify service configurations for a plurality of virtual services on a cloud computing system, the request including a hierarchical declaration indicating a permission or access policy corresponding to a grouping of virtual services from the plurality of virtual services, the permission or access policy being represented within a first hierarchical model that defines different levels of the permission or access policy in association with the plurality of virtual services on the cloud computing system;

determine a subset of virtual services from the plurality of virtual services based on the permission or access policy indicated by the hierarchical declaration; and

cause one or more service modifications indicated within the request to be applied to service configurations for the subset of virtual services.

13. The system of claim 12 , wherein each of the different levels in the first hierarchical model corresponds to a permission level and indicates a subset of the service configurations for the plurality of virtual services that are modifiable by an individual with the permission level.

14. The system of claim 12 , wherein the request further includes a second hierarchical declaration indicating a location characteristic corresponding to a grouping of virtual services from the plurality of virtual services, the location characteristic being represented within a second hierarchical model that defines different levels of the location characteristic in association with server nodes executing the plurality of virtual services on the cloud computing system.

15. The system of claim 14 , wherein the instructions are further executable processors to:

determine the subset of virtual services from the plurality of virtual services based, at least in part, on the location characteristic indicated by the second hierarchical declaration.

16. The system of claim 14 , wherein the second hierarchical model includes a geographic hierarchical structure based on physical locations of server nodes on which the plurality of virtual services are implemented.

17. One or more non-transitory computer-readable storage media encoding processor-executable instructions for executing a computer process, the computer process comprising:

receiving a request to modify service configurations for a plurality of virtual services on a cloud computing system, the request including a hierarchical declaration indicating a permission or access policy corresponding to a grouping of virtual services from the plurality of virtual services, the permission or access policy being represented within a first hierarchical model that defines different levels of the permission or access policy in association with the plurality of virtual services on the cloud computing system;

determining a subset of virtual services from the plurality of virtual services based on the permission or access policy indicated by the hierarchical declaration; and

causing one or more service modifications indicated within the request to be applied to service configurations for the subset of virtual services.

18. The one or more non-transitory computer-readable storage media of claim 17 , wherein each of the different levels in the first hierarchical model corresponds to a permission level and indicates a subset of the service configurations for the plurality of virtual services that are modifiable by an individual with the permission level.

19. The one or more non-transitory computer-readable storage media of claim 17 , wherein the computer process further comprises:

determining that a number of the subset of virtual services indicated by the hierarchical declaration exceeds a threshold number of virtual services; and

based on the number of the subset of virtual services exceeding the threshold number of virtual services, invoking a gossip protocol in which a primary server node confirms a current base version and sub-version of a configuration and provides instructions to additional nodes in connection with updating to the current base version of the configuration.

20. The one or more non-transitory computer-readable storage media of claim 17 , wherein the computer process further comprises:

in response to determining that a number of the subset of virtual services is less than a threshold number of virtual services or that the subset of virtual services are within a single compute zone, invoking a synchronization protocol in which a key pair for a current base version and sub-version of a configuration are broadcast to server nodes on which the subset of virtual services are hosted, the broadcast causing one or more service modifications indicated within the request to be applied to service configurations for the subset of virtual services.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2024
From: PATRO, SAMEER KUMAR; BASU, ARITRA; SUBHASH, RAGHAVENDRA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 067969/0108 →
Continuity (2)
Continuation 17483496 · Sep 23, 2021
Related Publication 20240406278A1 · Dec 5, 2024
References Cited (17)
US 8954399B1 · Balakrishnan · 2015 [cited by examiner]
US 10977068B2 · Cortez · 2021 [cited by examiner]
US 11206269B1 · Van Deman · 2021 [cited by examiner]
US 11962571B2 · Pasdar · 2024 [cited by examiner]
US 20020145981A1 · Klinker · 2002 [cited by examiner]
US 20140089474A1 · Zenz · 2014 [cited by examiner]
US 20170085640A1 · Mandal · 2017 [cited by examiner]
US 20210142223A1 · Choudhury · 2021 [cited by examiner]
US 20220215775A1 · Kosstrin-Greenberg · 2022 [cited by examiner]
US 20230090828A1 · Patro et al. · 2023 [cited by applicant]
US 20230376918A1 · Gangadarappa · 2023 [cited by examiner]
US 20240037639A1 · Ratliff · 2024 [cited by examiner]
Papazoglou, et al., “Service oriented architectures: approaches, technologies and research issues”, In Journal of VLDB journal, vol. 16, Issue 3, Jul. 2007, pp. 389-415. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/039227”, Mailed Date: Oct. 13, 2022, 12 Pages. [cited by applicant]
Final Office Action mailed on Jan. 5, 2024 in U.S. Appl. No. 17/483,496, 18 pages. [cited by applicant]
Notice of Allowance mailed on Apr. 17, 2024 in U.S. Appl. No. 17/483,496, 12 pages. [cited by applicant]
Non-Final Office Action mailed on May 25, 2023 in U.S. Appl. No. 17/483,496, 15 pages. [cited by applicant]