IP Library Granted Patent US 12,659,368
Granted Patent B2
US 12,659,368 · App. 18/155,654 · Granted Jun 16, 2026

Peripheral device enabling virtualized computing service extensions

Inventors: Anthony Nicholas Liguori (Bainbridge Island, WA); Eric Jason Brandwine (Haymarket, VA)
Assignee: Amazon Technologies, Inc.
H04L67/10H04L12/4633H04L12/4641H04L61/50H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,368
App. No.
18/155,654
Granted
Jun 16, 2026
Kind
B2
Abstract

A peripheral device includes one or more processors and a memory storing program instructions that when executed implement an extension manager of a virtualized computing service. The extension manager establishes a secure network channel for communications between the peripheral device, which is located at a premise external to a provider network, and a data center of the provider network. The extension manager assigns a network address of the substrate network of the service to a hardware server at the external premise. The substrate address is also assigned to an extension traffic intermediary at the data center. In response to a command directed to the virtualized computing service, one or more compute instance configuration operations are performed at the hardware server.

Claims (57)

1 . A method of managing virtual machines on remote computing devices, comprising:

causing a virtualization management component to be implemented on at least one of one or more computing devices located at a premises external to a cloud service provider substrate network;

receiving a request, from a customer, at a customer interface of a virtualized computing service of the cloud service provider substrate network;

performing, at the virtualization management component in response to receiving the request at the customer interface of the virtualized computing service, one or more configuration operations to instantiate a virtual machine on at least one of the one or more computing devices located at the premises external to the cloud service provider substrate network; and

performing one or more operations to manage the virtual machine instantiated on the computing device located at the premises external to the cloud service provider substrate network.

2 . The method of managing virtual machines on remote computing devices of claim 1 , further comprising:

establishing a virtual private network (VPN) connection between an endpoint of the cloud service provider network and an endpoint associated with the virtualization management component; and

sending one or more management tasks from a control plane of the virtualized computing service to the virtualization management component via the VPN connection, wherein the one or more management tasks cause, at least in part, the performance of the one or more configuration operations or the performance of the one or more operations to manage the virtual machine.

3 . The method of managing virtual machines on remote computing devices of claim 1 , further comprising:

sending one or more management tasks from a control plane of the virtualized computing service to the virtualization management component via a direct physical connection between the cloud service provider substrate network and a network associated with the virtualization management component, wherein the one or more management tasks cause, at least in part, the performance of the one or more configuration operations or the performance of the one or more operations to manage the virtual machine.

4 . The method of managing virtual machines on remote computing devices of claim 1 ,

wherein said causing the virtualization management component to be implemented on the at least one of one or more computing devices located at a premises external to the cloud service provider substrate network comprises:

providing the at least one computing device to a customer of the cloud service provider, wherein the at least one computing device stores program instructions for implementing the virtualization management component.

5 . The method of managing virtual machines on remote computing devices of claim 1 , further comprising:

providing access to a block storage service to the virtual machine.

6 . The method of managing virtual machines on remote computing devices of claim 1 , further comprising:

assigning an IP address to the virtual machine that is within a range of IP addresses of a virtual network within the cloud service provider substrate network.

7 . The method of managing virtual machines on remote computing devices of claim 6 , wherein the virtual network comprises:

the virtual machine implemented on the one or more computing devices located at the premises external to the cloud service provider substrate network; and

one or more a second virtual machine implemented on one or more computing resources within the cloud service provider substrate network.

8 . The method of managing virtual machines on remote computing devices of claim 1 , wherein the virtualization management component implemented on the at least one of the one or more computing devices located at the premises external to the cloud service provider substrate network implements a bridge between the virtualized computing service of the cloud service provider substrate network and a network associated with the virtualization management component implemented at the premises external to the cloud service provider substrate network.

9 . The method of managing virtual machines on remote computing devices of claim 1 , wherein the customer interface comprises one or more of:

a web-based console;

a command-line tool;

a graphical user interface; or

an application programming interface (API).

10 . The method of managing virtual machines on remote computing devices of claim 1 , wherein the one or more computing devices located at the premises external to the cloud service provider substrate network operate in a multitenant mode.

11 . A system, comprising:

one or more computing devices of a cloud service provider network configured to implement virtual machines for a virtualized computing service of the cloud service provider network; and

one or more computing devices configured to implement a management component of the virtualized computing service, the management component configured to:

receive, from a customer via a customer interface of the virtualized computing service, at the management component of the virtualized computing service, a request to implement a virtual machine on one or more additional computing devices located at a premises external to the cloud service provider network; and

cause one or more configuration operations to be performed to instantiate the virtual machine on the one or more additional computing devices located at the premises external to the cloud service provider network.

12 . The system of claim 11 , wherein the management component is further configured to:

perform one or more operations to manage the virtual machine instantiated on the one or more additional computing devices located at the premises external to the cloud service provider network.

13 . The system of claim 12 , wherein the cloud service provider network comprises one or more computing devices configured to:

establish a virtual private network (VPN) connection between an endpoint of the cloud service provider network and an endpoint associated with a virtualization management component implemented at the premises external to the cloud service provider network; and

send management traffic from a control plane of the virtualized computing service to the virtualization management component via the VPN connection, wherein the management traffic causes, at least in part, the performance of the one or more configuration operations or the performance of the one or more operations to manage the virtual machine.

14 . The system of claim 12 , wherein the cloud service provider network comprises:

a router configured to establish a direct physical connection between the cloud service provider network and a network that includes a virtualization management component implemented at the premises external to the cloud service provider network; and

one or more computing devices configured to:

send management traffic from a control plane of the virtualized computing service to the virtualization management component via the direct physical connection, wherein the management traffic causes, at least in part, the performance of the one or more configuration operations or the performance of the one or more operations to manage the virtual machine.

15 . The system of claim 11 , wherein the management component of the virtualized computing service is further configured to:

cause a virtual machine of the virtualized computing service to be connected to a given one of the one or more additional computing devices located at the premises external to the cloud service provider network,

wherein the virtual machine connected to the given additional computing device implements a bridge between the management component of the virtualized computing service and the virtual machine instantiated on the one or more additional computing devices located at the premise external to the cloud service provider network.

16 . One or more non-transitory, computer-readable, storage media storing program instructions that, when executed on or across one or more processors, cause the one or more processors to:

receive, from a customer, at a customer interface of a virtualized computing service of a cloud service provider network, a request to implement a virtual machine on a computing device located at a premises external to the cloud service provider network; and

cause one or more configuration operations to be performed to instantiate the virtual machine on the computing device located at the premises external to the cloud service provider network.

17 . The one or more non-transitory, computer-readable storage media of claim 16 , wherein the program instructions, when executed on or across the one or more processors, further cause the one or more processors to:

present a list of virtualization hosts that are available to be used to instantiate virtual machines, wherein the computing device located at the premises external to the cloud service provider network is included in the list.

18 . The one or more non-transitory, computer-readable storage media of claim 16 , wherein the program instructions, when executed on or across the one or more processors, further cause the one or more processors to:

perform one or more operations to provide the virtual machine, instantiated on the computing device located at the premises external to the service provider network, access to contents of a volume stored in a storage service of the cloud service provider network;

wherein the contents of the volume are used to boot an operating system of the virtual machine.

19 . The one or more non-transitory, computer-readable storage media of claim 16 , wherein the program instructions, when executed on or across the one or more processors, further cause the one or more processors to:

cause a virtual machine of the virtualized computing service to be connected to the computing device located at the premises external to the cloud service provider network,

wherein the virtual machine of the virtualized computing service connected to the computing device external to the cloud service provider network implements a bridge between a management component of the virtualized computing service and the virtual machine instantiated on the computing device located at the premises external to the cloud service provider network.

20 . The one or more non-transitory, computer-readable storage media of claim 16 , wherein the program instructions, when executed on or across the one or more processors, further cause the one or more processors to:

assign one or more IP addresses to the virtual machine such that the virtual machine, instantiated on the computing device located at the premises external to the cloud service provider network, is included in a virtual network of a customer of the cloud service provider network.

Continuity (3)
Continuation 17371772 · Jul 9, 2021
Continuation 16581646 · Sep 24, 2019
Related Publication 20230262111A1 · Aug 17, 2023
References Cited (146)
US 6741585B1 · Munoz et al. · 2004 [cited by applicant]
US 7484091B2 · Bade et al. · 2009 [cited by applicant]
US 7620731B1 · Dasan · 2009 [cited by applicant]
US 7814255B1 · Deva et al. · 2010 [cited by applicant]
US 7996836B1 · McCorkendale et al. · 2011 [cited by applicant]
US 8032899B2 · Archer et al. · 2011 [cited by applicant]
US 8127292B1 · Dobrovolskiy et al. · 2012 [cited by applicant]
US 8201161B2 · Challener et al. · 2012 [cited by applicant]
US 8239557B2 · McCune et al. · 2012 [cited by applicant]
US 8396946B1 · Brandwine et al. · 2013 [cited by applicant]
US 8433802B2 · Head et al. · 2013 [cited by applicant]
US 8514868B2 · Hill · 2013 [cited by applicant]
US 8589918B1 · Sapuntzakis et al. · 2013 [cited by applicant]
US 8612968B2 · DeHaan et al. · 2013 [cited by applicant]
US 8745755B2 · Borzycki et al. · 2014 [cited by applicant]
US 9042384B2 · Sridharan et al. · 2015 [cited by applicant]
US 9137205B2 · Rogers et al. · 2015 [cited by applicant]
US 9203748B2 · Jiang et al. · 2015 [cited by applicant]
US 9270703B1 · Clough et al. · 2016 [cited by applicant]
US 9323552B1 · Adogla et al. · 2016 [cited by applicant]
US 9361145B1 · Wilson et al. · 2016 [cited by applicant]
US 9407599B2 · Koponen et al. · 2016 [cited by applicant]
US 9485323B1 · Stickle et al. · 2016 [cited by applicant]
US 9703581B2 · Duchastel · 2017 [cited by examiner]
US 9860168B1 · Seshadri · 2018 [cited by applicant]
US 9954763B1 · Ye et al. · 2018 [cited by applicant]
US 9979694B2 · Brandwine et al. · 2018 [cited by applicant]
US 10057267B1 · Miller et al. · 2018 [cited by applicant]
US 10095537B1 · Neogy et al. · 2018 [cited by applicant]
US 10348767B1 · Lee et al. · 2019 [cited by applicant]
US 10498611B1 · Kloberdans et al. · 2019 [cited by applicant]
US 10748221B2 · Chen · 2020 [cited by examiner]
US 10812366B1 · Berenberg et al. · 2020 [cited by applicant]
US 10833949B2 · Liguori et al. · 2020 [cited by applicant]
US 11064017B2 · Liguori et al. · 2021 [cited by applicant]
US 11469964B2 · Liguori et al. · 2022 [cited by applicant]
US 11520530B2 · Liguori et al. · 2022 [cited by applicant]
US 11563799B2 · Liguori et al. · 2023 [cited by applicant]
US 11569997B1 · Gabrielson · 2023 [cited by applicant]
US 11989101B2 · Ramohalli Gopala Rao · 2024 [cited by examiner]
US 20030070027A1 · Ng · 2003 [cited by applicant]
US 20040177132A1 · Zhang et al. · 2004 [cited by applicant]
US 20050013280A1 · Buddhikot et al. · 2005 [cited by applicant]
US 20050224307A1 · Steffen · 2005 [cited by applicant]
US 20050251806A1 · Auslander et al. · 2005 [cited by applicant]
US 20060206658A1 · Hendel et al. · 2006 [cited by applicant]
US 20080244553A1 · Cromer et al. · 2008 [cited by applicant]
US 20090327576A1 · Oshins · 2009 [cited by applicant]
US 20100070970A1 · Hu et al. · 2010 [cited by applicant]
US 20100106822A1 · Nagai et al. · 2010 [cited by applicant]
US 20100205375A1 · Challener et al. · 2010 [cited by applicant]
US 20110075667A1 · Li et al. · 2011 [cited by applicant]
US 20110131443A1 · Laor et al. · 2011 [cited by applicant]
US 20110255423A1 · Gustin · 2011 [cited by applicant]
US 20110314469A1 · Qian et al. · 2011 [cited by applicant]
US 20120054832A1 · Ghosh et al. · 2012 [cited by applicant]
US 20120110650A1 · Van Biljon et al. · 2012 [cited by applicant]
US 20120124129A1 · Klimentiev et al. · 2012 [cited by applicant]
US 20120179802A1 · Narasimhan et al. · 2012 [cited by applicant]
US 20130287026A1 · Davie · 2013 [cited by applicant]
US 20130291087A1 · Kailash et al. · 2013 [cited by applicant]
US 20130305341A1 · Baker et al. · 2013 [cited by applicant]
US 20130315243A1 · Huang et al. · 2013 [cited by applicant]
US 20140108665A1 · Arora et al. · 2014 [cited by applicant]
US 20140208413A1 · Grobman et al. · 2014 [cited by applicant]
US 20140336785A1 · Asenjo · 2014 [cited by examiner]
US 20150160884A1 · Scales et al. · 2015 [cited by applicant]
US 20150172169A1 · DeCusatis et al. · 2015 [cited by applicant]
US 20150195137A1 · Kashyap et al. · 2015 [cited by applicant]
US 20150271027A1 · Goldberg · 2015 [cited by examiner]
US 20150350011A1 · Cohn · 2015 [cited by applicant]
US 20150356031A1 · Gintis · 2015 [cited by applicant]
US 20150381484A1 · Hira et al. · 2015 [cited by applicant]
US 20150381773A1 · Visser · 2015 [cited by applicant]
US 20160026573A1 · Jacobs et al. · 2016 [cited by applicant]
US 20160056975A1 · Marin · 2016 [cited by examiner]
US 20160072816A1 · Makhervaks et al. · 2016 [cited by applicant]
US 20160072910A1 · Eicher et al. · 2016 [cited by applicant]
US 20160077845A1 · Earl et al. · 2016 [cited by applicant]
US 20160134616A1 · Koushik et al. · 2016 [cited by applicant]
US 20160170781A1 · Liguori et al. · 2016 [cited by applicant]
US 20160170785A1 · Liguori et al. · 2016 [cited by applicant]
US 20160253254A1 · Krishnan · 2016 [cited by examiner]
US 20160315879A1 · Morris · 2016 [cited by examiner]
US 20170123935A1 · Pandit et al. · 2017 [cited by applicant]
US 20170286486A1 · Pang · 2017 [cited by applicant]
US 20170300354A1 · Dalal et al. · 2017 [cited by applicant]
US 20170322899A1 · Ni et al. · 2017 [cited by applicant]
US 20170366606A1 · Ben-Shaul et al. · 2017 [cited by applicant]
US 20170371546A1 · Rivera et al. · 2017 [cited by applicant]
US 20180004954A1 · Liguori et al. · 2018 [cited by applicant]
US 20180024964A1 · Mao et al. · 2018 [cited by applicant]
US 20180032360A1 · Agarwal et al. · 2018 [cited by applicant]
US 20180139174A1 · Thakkar et al. · 2018 [cited by applicant]
US 20180196947A1 · Davis et al. · 2018 [cited by applicant]
US 20180260125A1 · Botes et al. · 2018 [cited by applicant]
US 20180287879A1 · Guigli · 2018 [cited by examiner]
US 20190149406A1 · Fratini · 2019 [cited by applicant]
US 20190188763A1 · Ye et al. · 2019 [cited by applicant]
US 20200004572A1 · Faynberg · 2020 [cited by examiner]
US 20200057664A1 · Durham et al. · 2020 [cited by applicant]
US 20200092138A1 · Tillotson et al. · 2020 [cited by applicant]
US 20200099549A1 · Gummadidala · 2020 [cited by examiner]
US 20200142842A1 · Ryu · 2020 [cited by applicant]
US 20200159555A1 · Liguori et al. · 2020 [cited by applicant]
US 20200344305A1 · Lee · 2020 [cited by examiner]
US 20210037105A1 · Smith-Denny · 2021 [cited by applicant]
US 20210326160A1 · Bansal · 2021 [cited by examiner]
US 20220019367A1 · Freilich · 2022 [cited by examiner]
CN 105027108 · 2015 [cited by applicant]
CN 105308931 · 2016 [cited by applicant]
EP 1701259 · 2006 [cited by applicant]
EP 2557498 · 2013 [cited by applicant]
IN 108431778 · 2018 [cited by applicant]
JP 2016536721 · 2016 [cited by applicant]
JP 2016224484A · 2016 [cited by applicant]
KR 20040001211 · 2004 [cited by applicant]
KR 20120049929 · 2012 [cited by applicant]
WO 2011041162 · 2011 [cited by applicant]
WO 2015042559 · 2015 [cited by applicant]
U.S. Appl. No. 16/196,723, filed Nov. 20, 2018, Anthony Nicholas Liguori. [cited by applicant]
Zsgur Ulusoy, “Processing Real-Time Transactions in a Replicated Database System,” 1994 Kluwer Academic Publishers, Boston, Revised Sep. 10, 1993, pp. 1-32. [cited by applicant]
Sergio Almeida, et al., “ChainReaction: a Causal+ Consistent Datastore based on Chain Replication,” Eurosys'13 Apr. 15-17, 2013, Prague, Czech Republic, Copyright 2013 ACM 978-1-4503-1994—Feb. 13, 2004, pp. 85-98. [cited by applicant]
Scott Lystig Fritchie, “Chain Replication in Theory and in Practice,” Erlang'10, Sep. 30, 2010, Baltimore, Maryland, USA. Copyright 2010 ACM 978-1-4503-0253—Jan. 10, 2009, pp. 1-11. [cited by applicant]
Robbert van Renesse, et al., “Chain Replication for Supporting High Throughput and Availability,” USENIX Association, OSDI 2004: 6th Symposium on Operating Systems Design and Implementation, pp. 91-104. [cited by applicant]
Philip A. Bernstein, et al., “Concurrency Control and Recovery in Database Systems,” Addison-Wesley Publication Company, ISBN 0-201-10715-5, 1987, pp. 1-58. [cited by applicant]
From Wikipedia, the free encyclopedia, “Bromium,” downloaded on Jun. 27, 2016 from https://en.wikipedia.org/wiki/Bromium, pp. 1-4. [cited by applicant]
Xen, “Dom0” downloaded Jun. 6, 2016 from http://wiki.xen.org/wiki/Dom0, last updated Mar. 29, 2015, pp. 1-2. [cited by applicant]
Amazon Web Services, “Amazon Elastic Compute Cloud: User Guide for Linux Instances,” Latest Version update 2015, pp. 1-816. [cited by applicant]
IBM, General Information, Version 4, Release 3.0, Fifth Edition, Apr. 2002, pp. 1-101. [cited by applicant]
From Wikipedia, the free encyclopedia, “Hypervisor,” downloaded Jun. 6, 2016 from https://en.wikipedia.org/wiki/Hypervisor, pp. 1-7. [cited by applicant]
Axel Buecker, et al., “Reduce Risk and Improve Security on IBM Mainframes: Volume 1 Architecture and Platform Security,” Redbooks, IBM, Dec. 2014, pp. 1-308. [cited by applicant]
From Wikipedia, the free encyclopedia, “VMware ESX,” downloaded Jun. 6, 2016 from https://en.wikipedia.org/wiki/VMware_ESX, pp. 1-13. [cited by applicant]
From Wikipedia, the free encyclopedia, “Xen,” downloaded from Jun. 6, 2016 from https://en.wikipedia.org/wiki/Xen, pp. 1-12. [cited by applicant]
Udo Steinberg, et al., “NOVA: A Microhypervisor-Based Secure Virtualization Architecture”, ACM, EuroSys'10, Apr. 13-16, 2010, pp. 209-222. [cited by applicant]
Sangster, et al., TCG Published, Virtualized Trusted Platform Architecture Specification, Specification Version 1.0, Revision 0.26, Sep. 27, 2011, pp. 1-60. [cited by applicant]
Network Functions Virtualisation (NFV); NFV Security; Security and Trust Guidance, ETSI GS NFV-SEC 003, V1.1.2, downloaded by EP on Jun. 4, 2016, pp. 1-57. [cited by applicant]
Cong Xu, et al., “vSlicer: Latency-Aware Virtual Machine Scheduling via Differentiated-Frequency CPU Slicing”, Purdue University, Purdue e-Pubs, 2012, pp. 1-14. [cited by applicant]
Amazon Web Services, “Amazon Elastic Container Service: Developer Guide” API Version, Nov. 13, 2014, pp. 1-386. [cited by applicant]
Amazon Web Services, “AWS Lambda: Developer Guide” 2018, pp. 1-539. [cited by applicant]
AWS, “Annoucing Amazon EC2 Bare Metal Instances (Preview)”, Retrieved from URL: https://aws.amazon.com/about-aws/whats-new/2017/11/announcing-amazon-ec2-bare-metal-instances-preview/ on Jan. 15, 2018, pp. 1-4. [cited by applicant]
Amazon, “Announcing Amazon EC2 Bare Metal Instances (Preview)”, Retrieved from URL: https://aws.amazon.com/about-aws/whats-new/2017/11/announcing-amazon-ec2-bare-metal-instances-preview/, pp. 1-4. [cited by applicant]
Brendan Gregg's Blog, “AWS EC@ Virtualization 2017: Introducing Nitro”, Retrieved from URL: http://www.brendangregg.com/blog/2017-11-29/aws-ec2-virtualization-2017.html, pp. 1-11. [cited by applicant]
Amazon Web Services, “Amazon Elastic Compute Cloud: User Guide for Linux Instances,” Latest Version update 2018, pp. 1-884. [cited by applicant]
Amazon AWS, Example: Cisco ASA Device, Retrieved from http://docs.aws.amazon.com/ AmazonVPC/latest/NetworkAdminGuide/Cisco_ASA(WaybackMachine); Feb. 2013, pp. 1-5. [cited by applicant]
Extended European Search report mailed Jan. 9, 2026 in European Patent Application No. 25208695.4, Amazon Technologies, Inc., 11 pages. [cited by applicant]