IP Library › Granted Patent US 12,363,062
Granted Patent B2
US 12,363,062 · App. 18/465,750 · Granted Jul 15, 2025

High availability of cloud-based serivces with address translation

Inventors: Shu Lin (Saratoga, CA); Patrick Xu (Santa Clara, CA); Eswar Rao Sadaram (San Jose, CA); Hao Long (Campbell, CA)
Assignee: Palo Alto Networks, Inc.
H04L61/2517G06F9/45558G06F11/2023H04L67/10H04L69/40G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,062
App. No.
18/465,750
Granted
Jul 15, 2025
Kind
B2
Abstract

Described herein are systems, methods, and software to enhance failover operations in a cloud computing environment. In one implementation, a method of operating a first service instance in a cloud computing environment includes obtaining a communication from a computing asset, wherein the communication comprises a first destination address. The method further provides replacing the first destination address with a second destination address in the communication, wherein the second destination address comprises a shared address for failover from a second service instance. After replacing the address, the method determines whether the communication is permitted based on the second destination address, and if permitted, processes the communication in accordance with a service executing on the service instance.

Claims (43)

1. A method comprising:

providing high availability of a cloud-based service with a first network address that is shared between a primary instance of the cloud-based service and a backup instance of the cloud-based service, wherein providing high availability of the cloud-based service comprises,

maintaining session information for one or more sessions established with the primary service instance, wherein the maintained session information comprises connection information prior to translation of the first network address to a private network address of the primary service instance and wherein the first network address is a destination address for the one or more sessions prior to address translation;

periodically providing the maintained session information to the backup service instance;

identifying a failover condition for the primary service instance; and

transitioning, with software-defined networking, the one or more sessions from the primary service instance to the backup service instance based on identifying the failover condition and the backup service instance performing packet inspection on received communications based on the connection information to determine whether communications are permitted.

2. The method of claim 1 , wherein the cloud-based service comprises one of a web-hosting service, a firewall service, a data storage service, and a data processing service.

3. The method of claim 1 further comprising, the primary instance, caching the connection information when the one or more sessions are initiated with the primary instance.

4. The method of claim 1 , wherein transitioning the one or more sessions comprises indicating the backup service instance as active.

5. The method of claim 4 , wherein transitioning the one or more sessions comprises, based on receiving a first packet from a source computing asset after the failover condition has been identified, a software defined networking process detecting the first network address in the first packet and translating the first network address to a second network address of the backup service instance, wherein the packet inspection is performed based on the first network address prior to translation instead of the second network address.

6. The method of claim 5 further comprising forwarding the first packet to a virtual network interface of the backup service instance based on translating the first network address to the second network address.

7. The method of claim 4 further comprising:

based on receiving a second packet that indicates the first network address as a destination address, determining which of the primary and backup service instances is active; and

translating the first network address to a private network address of the active service instance and forwarding the second packet according to the address translation.

8. The method of claim 1 , wherein the primary service instance and the backup service instance correspond to different subnets, and wherein the first network address is a network address that does not belong to either of the different subnets.

9. One or more non-transitory computer-readable media having program code stored thereon, the program code comprising instructions to:

provide high availability of a cloud-based service with a first network address that is shared between a primary instance of the cloud-based service and a backup instance of the cloud-based service, wherein the instructions to provide high availability of the cloud-based service comprise instructions to,

maintain session information for one or more sessions established with the primary service instance, wherein the maintained session information comprises connection information prior to translation of the first network address to a private network address of the primary service instance and wherein the first network address is a destination address for the one or more sessions prior to address translation;

periodically provide the maintained session information to the backup service instance;

identify a failover condition for the primary service instance; and

transition, with software-defined networking, the one or more sessions from the primary service instance to the backup service instance based on identifying the failover condition; and

perform, at the backup service instance, packet inspection on received communications based on the connection information to determine whether communications are permitted.

10. The non-transitory computer-readable media of claim 9 , wherein the cloud-based service comprises one of a web-hosting service, a firewall service, a data storage service, and a data processing service.

11. The non-transitory computer-readable media of claim 9 , wherein the program code further comprises instructions to cache connection information for the primary instance when the one or more sessions are initiated with the primary instance.

12. The non-transitory computer-readable media of claim 9 , wherein the instructions to transition the one or more sessions comprise instructions to indicate the backup service instance as active.

13. The non-transitory computer-readable media of claim 12 , wherein the instructions to transition the one or more sessions comprise instructions to, based on receipt of a first packet from a source computing asset after the failover condition has been identified, detect the first network address in the first packet and translate the first network address to a second network address of the backup service instance, wherein the packet inspection is performed based on the first network address prior to translation instead of the second network address.

14. The non-transitory computer-readable media of claim 13 , wherein the program code further comprises instructions to forward the first packet to a virtual network interface of the backup service instance based on translation of the first network address to the second network address.

15. The non-transitory computer-readable media of claim 14 , wherein the program code further comprises instructions to:

based on receipt of a second packet that indicates the first network address as a destination address, determine which of the primary and backup service instances is active; and

translate the first network address to a private network address of the active service instance and forward the second packet according to the address translation.

16. An system comprising:

a processor; and

a computer-readable medium having instructions stored thereon that are executable by the processor to cause the system to,

provide high availability of a cloud-based service with a first network address that is shared between a primary instance of the cloud-based service and a backup instance of the cloud-based service, wherein the instructions to provide high availability of the cloud-based service comprise instructions executable by the processor to cause the system to,

maintain session information for one or more sessions established with the primary service instance, wherein the maintained session information comprises connection information prior to translation of the first network address to a private network address of the primary service instance and wherein the first network address is a destination address for the one or more sessions prior to address translation;

periodically provide the maintained session information to the backup service instance;

identify a failover condition for the primary service instance; and

transition, with software-defined networking, the one or more sessions from the primary service instance to the backup service instance based on identifying the failover condition; and

perform, at the backup service instance, packet inspection on received communications based on the connection information to determine whether communications are permitted.

17. The system of claim 16 , wherein the computer-readable medium further has stored thereon instructions executable by the processor to cause the system to cache the connection information for the primary instance when the one or more sessions are initiated with the primary instance.

18. The system of claim 16 , wherein the instructions to transition the one or more sessions comprise instructions executable by the processor to cause the system to indicate the backup service instance as active.

19. The system of claim 18 , wherein the instructions to transition the one or more sessions comprise instructions executable by the processor to cause the system to, based on receipt of a first packet from a source computing asset after the failover condition has been identified, detect the first network address in the first packet and translate the first network address to a second network address of the backup service instance, wherein the packet inspection is performed based on the first network address prior to translation instead of the second network address.

20. The system of claim 19 , wherein the computer-readable medium further has stored thereon instructions executable by the processor to cause the system to forward the first packet to a virtual network interface of the backup service instance based on translation of the first network address to the second network address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: LIN, SHU; XU, PATRICK; SADARAM, ESWAR RAO; LONG, HAO
To: PALO ALTO NETWORKS, INC.
Reel/Frame 064879/0660 →
Continuity (4)
Continuation 17651143 · Feb 15, 2022
Continuation 16848041 · Apr 14, 2020
Continuation 15917254 · Mar 9, 2018
Related Publication 20240007431A1 · Jan 4, 2024
References Cited (33)
US 7480737B2 · Chauffour et al. · 2009 [cited by applicant]
US 7542987B2 · Lubbers et al. · 2009 [cited by applicant]
US 7702947B2 · Peddada · 2010 [cited by examiner]
US 7788345B1 · Sukiman et al. · 2010 [cited by applicant]
US 8051322B2 · Matsumoto et al. · 2011 [cited by applicant]
US 8589514B2 · Duggal et al. · 2013 [cited by applicant]
US 8751691B1 · Brandwine et al. · 2014 [cited by applicant]
US 9319272B1 · Brandwine et al. · 2016 [cited by applicant]
US 9473481B2 · Lietz et al. · 2016 [cited by applicant]
US 9628294B1 · Brandwine et al. · 2017 [cited by applicant]
US 9787503B2 · Moreman · 2017 [cited by applicant]
US 9813374B1 · Magerramov et al. · 2017 [cited by applicant]
US 11513828B1 · Zelenov et al. · 2022 [cited by applicant]
US 20020178268A1 · Aiken, Jr. et al. · 2002 [cited by applicant]
US 20060146879A1 · Anthias et al. · 2006 [cited by applicant]
US 20060215546A1 · Tochio · 2006 [cited by applicant]
US 20060262785A1 · Duggal et al. · 2006 [cited by applicant]
US 20140282525A1 · Sapuram et al. · 2014 [cited by applicant]
US 20150339136A1 · Suryanarayanan et al. · 2015 [cited by applicant]
US 20160057031A1 · Gedam · 2016 [cited by examiner]
US 20160065448A1 · Loveless · 2016 [cited by examiner]
US 20160210209A1 · Verkaik et al. · 2016 [cited by applicant]
US 20160212012A1 · Young et al. · 2016 [cited by applicant]
US 20170075719A1 · Scallan et al. · 2017 [cited by applicant]
US 20170083354A1 · Thomas et al. · 2017 [cited by applicant]
US 20170126626A1 · Datta et al. · 2017 [cited by applicant]
US 20170214550A1 · Kumar et al. · 2017 [cited by applicant]
US 20170244593A1 · Rangasamy · 2017 [cited by examiner]
US 20180018195A1 · Kim et al. · 2018 [cited by applicant]
US 20180152455A1 · Lee · 2018 [cited by examiner]
US 20190036819A1 · Kancherla · 2019 [cited by examiner]
US 20190327135A1 · Johnson · 2019 [cited by examiner]
US 20200336420A1 · Joshi · 2020 [cited by examiner]