Transparent enforcement of data policies

    公开(公告)号:US11228615B2

    公开(公告)日:2022-01-18

    申请号:US16051147

    申请日:2018-07-31

    Abstract: Methods, systems, and devices for transparent data encryption are described. A transparent proxy may enforce a specific encryption policy for a data transmission from a source host to a target host, where the transparent proxy determines if the data transmission is encrypted according to a specific encryption policy prior to forwarding the data transmission to the target host. As such, if the data transmission is not encrypted according to the specific encryption policy, the transparent proxy may encrypt the data transmission and then forward it to the target host. Alternatively, if the transparent proxy determines that the data transmission is encrypted according to the specific encryption policy, then the transparent proxy may refrain from further encrypting the data transmission and forward the data transmission to the target host without the additional encryption.

    PRIVATE COMMUNICATION SERVICE IN A PUBLIC CLOUD ENVIRONMENT

    公开(公告)号:US20220141195A1

    公开(公告)日:2022-05-05

    申请号:US17085169

    申请日:2020-10-30

    Abstract: A private communication set-up service enables scalable private connectivity between producers and consumers residing within a public cloud environment. A producer exposes metadata information about a new or updated resource within the public cloud environment using a tag. The system monitors the public cloud environment for tagged metadata about new resources and configures a producer-side service to a private link. Subsequently, the system exposes metadata information about the private link. The system monitors for tagged metadata about private links and configures the consumer-side private link endpoint to the private link. The producer and the consumer communicate using the configured private link.

    Private communication service in a public cloud environment

    公开(公告)号:US11757845B2

    公开(公告)日:2023-09-12

    申请号:US17085169

    申请日:2020-10-30

    CPC classification number: H04L63/04 H04L43/08 H04L43/12 H04L63/10

    Abstract: A private communication set-up service enables scalable private connectivity between producers and consumers residing within a public cloud environment. A producer exposes metadata information about a new or updated resource within the public cloud environment using a tag. The system monitors the public cloud environment for tagged metadata about new resources and configures a producer-side service to a private link. Subsequently, the system exposes metadata information about the private link. The system monitors for tagged metadata about private links and configures the consumer-side private link endpoint to the private link. The producer and the consumer communicate using the configured private link.

    ENABLING PRIVATE COMMUNICATION IN PUBLIC MULTI-CLOUD ENVIRONMENTS

    公开(公告)号:US20220141189A1

    公开(公告)日:2022-05-05

    申请号:US17167625

    申请日:2021-02-04

    Abstract: A multi-cloud private communication set-up service enables scalable private connectivity between producers and consumers residing within different public cloud environments. A producer publishes metadata information about a resource within the public cloud environment where the producer resides. The public cloud environment of the publisher is monitored for tagged metadata about new resources. Identified metadata is used to configure a producer-side private link service to a private communication link, and metadata information about the configured producer-side private link service to the private communication link is published within the public cloud environment of the producer. The metadata is identified and used to configure a communication path to the consumer based on a combination of the private communication link, leveraging native multi-VPC network connectivity capabilities between virtual private clouds residing within a public cloud environment, and virtual private network (VPN) tunnel connectivity between the public cloud environments of the producer and the consumer, so that the configured private communication path may be used by the consumer to access the resource from the producer.

    Multi-tenant routing management
    5.
    发明授权

    公开(公告)号:US10757015B2

    公开(公告)日:2020-08-25

    申请号:US15885661

    申请日:2018-01-31

    Abstract: Techniques are disclosed relating to establishing routes to access services executing on host computer systems. In some embodiments, a computing system receives a request to distribute routing data for a first service to switches of a plurality of host computer systems. The first service is one of a plurality of services belonging to a plurality of tenants supported by the plurality of host computer systems. The computing system analyzes the routing data to determine whether distribution of the routing data is in accordance with a set of criteria established for a first tenant associated with the first service. Based on the analyzing, the computing system permits communication of the routing data via one or more border gateway protocol (BGP) update messages to the switches.

    TRANSPARENT ENFORCEMENT OF DATA POLICIES
    6.
    发明申请

    公开(公告)号:US20200045080A1

    公开(公告)日:2020-02-06

    申请号:US16051147

    申请日:2018-07-31

    Abstract: Methods, systems, and devices for transparent data encryption are described. A transparent proxy may enforce a specific encryption policy for a data transmission from a source host to a target host, where the transparent proxy determines if the data transmission is encrypted according to a specific encryption policy prior to forwarding the data transmission to the target host. As such, if the data transmission is not encrypted according to the specific encryption policy, the transparent proxy may encrypt the data transmission and then forward it to the target host. Alternatively, if the transparent proxy determines that the data transmission is encrypted according to the specific encryption policy, then the transparent proxy may refrain from further encrypting the data transmission and forward the data transmission to the target host without the additional encryption.

    MULTI-TENANT ROUTING MANAGEMENT
    7.
    发明申请

    公开(公告)号:US20190238456A1

    公开(公告)日:2019-08-01

    申请号:US15885661

    申请日:2018-01-31

    Abstract: Techniques are disclosed relating to establishing routes to access services executing on host computer systems. In some embodiments, a computing system receives a request to distribute routing data for a first service to switches of a plurality of host computer systems. The first service is one of a plurality of services belonging to a plurality of tenants supported by the plurality of host computer systems. The computing system analyzes the routing data to determine whether distribution of the routing data is in accordance with a set of criteria established for a first tenant associated with the first service. Based on the analyzing, the computing system permits communication of the routing data via one or more border gateway protocol (BGP) update messages to the switches.

Patent Agency Ranking