IP Library › Granted Patent US 12,598,215
Granted Patent B1
US 12,598,215 · App. 18/342,261 · Granted Apr 7, 2026

Centralized secure policy configuration synchronization mechanism for virtual network devices

Inventors: Amith Ramanagar Chandrashekar (San Jose, CA); Avinash Kumar Singh (Fremont, CA); Xiaodong Zhu (Fremont, CA)
Assignee: Juniper Networks, Inc.
H04L63/20H04L41/0895
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,215
App. No.
18/342,261
Granted
Apr 7, 2026
Kind
B1
Abstract

A device may detect a first event associated with modifying a policy configuration for a group of virtual network devices of a cloud computing environment, and may retrieve the modified policy configuration. The device may receive the policy configuration from the group, and may cause policy statements not included in the modified policy configuration and included in the policy configuration to be deleted from the group. The device may cause policy statements included in the modified policy configuration and not included in the policy configuration to be added to the group. The device may detect a second event associated with adding a new virtual network device to the group, and may cause the new virtual network device to be created. The device may retrieve a policy configuration associated with the group, and may provide the policy configuration to the new virtual network device for installation.

Claims (95)

1 . A method, comprising:

detecting, by a device, a first event associated with modifying a policy configuration, associated with a group of virtual network devices of a cloud computing environment, and to generate a modified policy configuration;

retrieving, by the device, the modified policy configuration based on the first event;

establishing, by the device, connections with the group of virtual network devices;

receiving, by the device, the policy configuration from the group of virtual network devices based on establishing the connections with the group of virtual network devices;

identifying, by the device, first policy statements not included in the modified policy configuration and included in the policy configuration;

identifying, by the device, second policy statements included in the modified policy configuration and not included in the policy configuration;

causing the first policy statements to be deleted from the group of virtual network devices; and

causing the second policy statements to be added to the group of virtual network devices, wherein deletion of the first policy statements and addition of the second policy statements causes the group of virtual network devices to be resynchronized with the modified policy configuration.

2 . The method of claim 1 ,

wherein retrieving the modified policy configuration based on the first event comprises:

retrieving the modified policy configuration from a secure object storage service of the device based on the first event.

3 . The method of claim 1 , further comprising:

preventing further modification of the modified policy configuration until the group of virtual network devices are resynchronized with the modified policy configuration.

4 . The method of claim 1 , further comprising:

enabling further modification of the modified policy configuration after the group of virtual network devices are resynchronized with the modified policy configuration.

5 . The method of claim 1 , further comprising:

preventing further modification of the modified policy configuration until the group of virtual network devices are resynchronized with the modified policy configuration; and

enabling further modification of the modified policy configuration after the group of virtual network devices are resynchronized with the modified policy configuration.

6 . The method of claim 1 ,

wherein the device includes a scaling service, a serverless function service, a queue service, and a secure object storage service.

7 . A device, comprising:

one or more memories; and

one or more processors to:

detect a first event associated with modifying a policy configuration, associated with a group of virtual network devices of a cloud computing environment, and to generate a modified policy configuration;

retrieve the modified policy configuration based on the first event;

establish connections with the group of virtual network devices;

receive the policy configuration from the group of virtual network devices based on establishing the connections with the group of virtual network devices;

identify first policy statements not included in the modified policy configuration and included in the policy configuration;

identify second policy statements included in the modified policy configuration and not included in the policy configuration;

cause the first policy statements to be deleted from the group of virtual network devices; and

cause the second policy statements to be added to the group of virtual network devices, wherein deletion of the first policy statements and addition of the second policy statements causes the group of virtual network devices to be resynchronized with the modified policy configuration.

8 . The device of claim 7 ,

wherein the one or more processors are further to:

detect a second event associated with adding a new virtual network device to the group of virtual network devices;

cause, based on the second event, the new virtual network device to be created in the cloud computing environment;

associate the new virtual network device with the group of virtual network devices;

retrieve the policy configuration associated with the group of virtual network devices;

establish a connection with the new virtual network device; and

provide the policy configuration to the new virtual network device based on establishing the connection with the new virtual network device and to cause the virtual network device to install the policy configuration.

9 . The device of claim 8 ,

wherein the one or more processors, to cause the new virtual network device to be created in the cloud computing environment, are to:

utilize a scaling service of the device to cause the new virtual network device to be created in the cloud computing environment.

10 . The device of claim 8 ,

wherein the one or more processors are further to:

provide, to a queue service of the device, a message indicating that the new virtual network device needs the policy configuration; and

receive a trigger to provide the policy configuration to the new virtual network device,

wherein the one or more processors, to retrieve the policy configuration associated with the group of virtual network devices, are configured to:

retrieve the policy configuration associated with the group of virtual network devices based on the trigger.

11 . The device of claim 8 ,

wherein the one or more processors, to retrieve the policy configuration associated with the group of virtual network devices, are to:

retrieve the policy configuration associated with the group of virtual network devices from a secure object storage service of the device.

12 . The device of claim 8 ,

wherein the one or more processors, to detect the second event associated with adding the new virtual network device to the group of virtual network devices, are to:

detect the second event associated with adding the new virtual network device based on a health check failure associated with the group of virtual network devices.

13 . The device of claim 7 ,

wherein the one or more processors are further to:

detect a second event associated with removing a virtual network device from the group of virtual network devices of the cloud computing environment; and

cause, based on the second event, the virtual network device to be removed from the group of virtual network devices.

14 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect a first event associated with modifying a policy configuration, associated with a group of virtual network devices of a cloud computing environment, and to generate a modified policy configuration;

retrieve the modified policy configuration based on the first event;

establish connections with the group of virtual network devices;

receive the policy configuration from the group of virtual network devices based on establishing the connections with the group of virtual network devices;

identify first policy statements not included in the modified policy configuration and included in the policy configuration;

identify second policy statements included in the modified policy configuration and not included in the policy configuration;

cause the first policy statements to be deleted from the group of virtual network devices; and

cause the second policy statements to be added to the group of virtual network devices,

wherein deletion of the first policy statements and addition of the second policy statements causes the group of virtual network devices to be resynchronized with the modified policy configuration.

15 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions, that cause the device to retrieve the modified policy configuration based on the first event, cause the device to:

retrieve the modified policy configuration from a secure object storage service of the device based on the first event.

16 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions further cause the device to:

prevent further modification of the modified policy configuration until the group of virtual network devices are resynchronized with the modified policy configuration.

17 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions further cause the device to:

enable further modification of the modified policy configuration after the group of virtual network devices are resynchronized with the modified policy configuration.

18 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions further cause the device to:

prevent further modification of the modified policy configuration until the group of virtual network devices are resynchronized with the modified policy configuration; and

enable further modification of the modified policy configuration after the group of virtual network devices are resynchronized with the modified policy configuration.

19 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions further cause the device to:

detect a second event associated with adding a new virtual network device to the group of virtual network devices;

cause, based on the second event, the new virtual network device to be created in the cloud computing environment;

associate the new virtual network device with the group of virtual network devices;

retrieve the policy configuration associated with the group of virtual network devices;

establish a connection with the new virtual network device; and

provide the policy configuration to the new virtual network device based on establishing the connection with the new virtual network device and to cause the virtual network device to install the policy configuration.

20 . The non-transitory computer-readable medium of claim 14 ,

wherein the one or more instructions further cause the device to:

detect a second event associated with removing a virtual network device from the group of virtual network devices of the cloud computing environment; and

cause, based on the second event, the virtual network device to be removed from the group of virtual network devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2023
From: CHANDRASHEKAR, AMITH RAMANAGAR; SINGH, AVINASH KUMAR; ZHU, XIAODONG
To: JUNIPER NETWORKS, INC.
Reel/Frame 064084/0613 →
References Cited (8)
US 9866594B2 · Lim · 2018 [cited by examiner]
US 11120156B2 · Handy Bosma · 2021 [cited by examiner]
US 20140122672A1 · Chen · 2014 [cited by examiner]
US 20140189050A1 · Rijsman · 2014 [cited by examiner]
RLI 49000: Functional specification, “vSRX Deployment with AWS GWLB,” Website: https://github.com/Juniper/vSRX-AWS/tree/master/vSRX_AWS_GWLB#local-config-sync, Obtained May 1, 2024, 11 Pages. [cited by applicant]
Amazon EC2 Auto Scaling, User Guide, Website: https://docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html, 2023, 445 Pages. [cited by applicant]
Amazon Elastic Compute Cloud, User Guide for Linux Instances, Website: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/user-data.html, 2023, 2141 Pages. [cited by applicant]
Junos PyEZ Developer Guide, Juniper Networks, Website: https://www.juniper.net/documentation/us/en/software/junos-pyez/junos-pyez-developer/index.html, Oct. 31, 2022, 333 Pages. [cited by applicant]