Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

158 results about "Cloud provider" patented technology

A cloud provider is a company that delivers cloud computing based services and solutions to businesses and/or individuals. This service organization may provide rented and provider-managed virtual hardware, software, infrastructure and other related services.

Dynamic availability zones in radio-based networks

Disclosed are various embodiments for dynamic availability zones in radio-based networks. In one embodiment, excess resource capacity on a radio access network (RAN)-enabled edge server in a cloud provider network is determined. The RAN-enabled edge server is located at a cell site and is configured to perform distributed unit (DU) and / or centralized unit (CU) functions for a RAN. The excess resource capacity is offered as part of a cellular capacity zone that is generally available to customers of the cloud provider network.
Owner:AMAZON TECH INC

Cloud deployment automation system with integrated resource orchestration and customizable deployment workflows

ActiveDE202025104332U1Resource allocationResourcesAsynchronous operationExecution control
A cloud deployment automation system consisting of: a deployment automation device housed in a rack-mountable enclosure, the device comprising: a multi-core orchestration processor configured to execute deployment logic as compiled execution graphs; a storage module operatively coupled to the orchestration processor, the storage storing a set of deployment templates, real-time execution states, telemetry logs, and policy configurations; a secure credential management processing unit embedded in the device, configured to generate, store, and rotate cloud access tokens, API keys, and user-specific credentials, and to provide encrypted access to those credentials during deployment execution; an in-memory workflow execution engine executed by the orchestration processor, configured to analyze a user-defined deployment configuration that includes a declarative specification of infrastructure resources and compile that configuration into a directed acyclic graph (DAG) that represents the resource deployment order, dependency mapping, and rollback relationships, a cloud provider interface subsystem communicatively connected to multiple heterogeneous cloud platforms via appropriate API adapters, the subsystem enabling the orchestration processor to send provisioning requests and receive status events from the platforms; a customizable workflow compiler unit configured to convert graphical workflow definitions or domain-specific language (DSL) scripts into execution sequences that can be used by the workflow execution engine, where the workflow compiler unit supports conditional branching, asynchronous operations, and runtime variable resolution; and A policy enforcement control unit integrated into the deployment automation device, with the policy engine configured to apply organization-specific compliance rules, tagging conventions, security group configurations, and runtime resource limits to all deployment actions in a context-aware manner prior to execution.
Owner:THASON JUSTIN RAJAKUMAR MARIA FAIRFAX

Host fleet management optimizations in a cloud provider network

Techniques for host fleet management in a cloud provider network are described. Forecast data including a forecasted demand for virtual machines in each capacity pool of a set of capacity pools is obtained. A mathematical optimizer application is executed to generate a first optimal fleet plan, the mathematical optimizer application having an objective function to minimize a number of new host computer systems to add to the set of host computer systems to satisfy the forecasted demand for each capacity pool, the first optimal fleet plan includes an identification of a set of hardware types and, for each hardware type in the set, a quantity of new host computer systems of the hardware type. A plurality of new host computer systems is deployed, based on the first optimal fleet plan, for a hardware type in the set of hardware types into the set of host computer systems.
Owner:AMAZON TECH INC

Architecture for selective use of private paths between cloud services

Systems and methods are provided for allowing function-initiated traffic of an on-demand code execution system within a cloud provider network to be routed to a private path such based on opt-in settings. An opt-in request may be received indicating a desire of a function invoker to use a private path. Subsequent to the opt-in request, a function invocation request may be received to send communication to a service within the cloud provider network and external to the on-demand code execution system. Subsequent to the function invocation request, a virtual execution environment may be configured to execute the function with mapping of a network-based service to an IP address of a private endpoint. The function is then executed with its traffic sent to the private endpoint.
Owner:AMAZON TECH INC

Extending customer premises networks onto a cloud provider network

Disclosed are various embodiments that extend customer premises networks onto a cloud provider network. In one embodiment, a layer-3 virtual private network is established between a tunneling agent and a virtual private network server on a cloud provider network. The tunneling agent is executed on an edge customer premises equipment (CPE) device on a customer premises network. A layer-2 virtual interface is established for an edge application on the cloud provider network using a tunnel to encapsulate layer-2 traffic between the customer premises network and the edge application over the layer-3 virtual private network.
Owner:AMAZON TECH INC

User-configured multi-location service deployment and scaling

Techniques for intelligent user-configured multi-location service deployment and scaling are described. Autoscaling configuration data is received, the autoscaling configuration data including an application redistribution trigger condition and a placement optimization constraint, the application redistribution trigger condition based on a variable associated with a state of an application, the application deployed across a first set of deployment zones of a plurality of deployment zones of a cloud provider network. The application redistribution trigger condition is determined to be satisfied. A redistribution placement plan is obtained that satisfies the placement optimization constraint and identifies a second set of deployment zones of the plurality of deployment zones of the cloud provider network across which to deploy the application. The application is redistributed across the second set of deployment zones.
Owner:AMAZON TECH INC

Dedicated cloud regions at customer premises

Techniques are disclosed for managing aspects of a dedicated region cloud at a customer location (a “DRCC”). A DRCC may comprise cloud infrastructure components provided by a cloud provider and hosted by computing devices located at the customer's (a “cloud owner's”) location. Services of the central cloud-computing environment may be similarly executed at the DRCC. The DRCC may include a service configured to collect, store, and / or present data corresponding to the cloud infrastructure components via one or more interfaces (e.g., interfaces provided to the cloud provider and / or the cloud owner). Data collected within the DRCC (e.g., capacity and usage data, etc.) may be provided and accessible to the central cloud at any suitable time. Obtaining such data enables the user to ascertain various operational aspects of the DRCC, while enabling the system and / or user to execute various DRCC-specific operations regarding capacity planning, health and performance, change management, and the like.
Owner:ORACLE INT CORP

Optimized container image retrieval for devices at edge locations

Techniques are described for enabling computing devices in computing environments distinct from a cloud provider network to use temporally staggered container image pull requests upon initiating execution of a container-based task. For example, upon determining to launch a container on a computing device running in a computing environment that is distinct from a cloud provider network, an agent running on the computing device can select a time in the future at which to request the container image(s) to be used to launch the container from a container registry based on a randomized value. The randomized value, for example, can enable each computing device in the environment to request the container image(s) at a time that differs from times at which other computing devices in the environment generate similar requests (e.g., such that the request times are “staggered” relative to one another).
Owner:AMAZON TECH INC

Automatic rebalancing of container-based services for high availability

Techniques are described for enabling a container service of a cloud provider network to detect imbalances of container placements across a selected set of availability zones (AZs) and to automatically rebalance placement of the containers, if needed. An actual distribution of containers may differ from an expected distribution according to a configured placement strategy, e.g., due to an outage or other operational issue affecting one or more of the AZs, scaling operations over time, and the like. In these and other scenarios, the container service can rebalance placement of the containers by terminating one or more containers in one or more of the AZs and launching additional containers in one or more other AZs to restore a more desirable balance. The periodic rebalancing of containers in this manner improves a container-based application's ability to load balance demand and further improves application availability by ensuring sufficient capacity is spread across multiple AZs.
Owner:AMAZON TECH INC

Remotely connecting to customer premises networks to access cloud-executed edge applications

Disclosed are various embodiments relating to remotely connecting to customer premises networks to access cloud-executed edge applications. In one embodiment, a layer-3 virtual private network is established between a cloud provider network and a customer premises network of a customer. A layer-2 virtual interface is established for an edge application executed on the cloud provider network using a tunnel to encapsulate layer-2 traffic over the layer-3 virtual private network. A client device outside of the cloud provider network is connected to the customer premises network via the layer-3 virtual private network.
Owner:AMAZON TECH INC

System and method for dynamic provisioning of cloud desktop pools from multiple public cloud providers

A system and method for providing virtual desktops to client devices of users is disclosed. The system includes available cloud regions that each can provide virtual desktops and associated resources. A desktop pool resource management engine is coupled to the available cloud regions and collects constraint data from the available cloud regions as well as operational data from desktop clients and desktop agents. A cloud usage profile is created for a subset of the users from the operational data. A priority list of available cloud regions for a user in the subset is created based on the usage profile and the constraint data of the available cloud regions. The highest priority cloud region from the priority list is recommended for the user requesting a desktop. A control plane selects the highest priority cloud region according to the priority list to provide the desktop to the client device.
Owner:WORKSPOT INC

Exposing interfaces on customer premises networks for use by cloud-executed edge applications

Disclosed are various embodiments that expose interfaces on customer premises networks for use by cloud-executed edge applications. In one embodiment, a layer-3 virtual private network is established between a cloud provider network and a customer premises network of a customer. A layer-2 virtual interface is established for an edge application executed on the cloud provider network using a tunnel to encapsulate layer-2 traffic over the layer-3 virtual private network. An interface on an edge device of the customer premises network is mapped so that the interface is accessible by the edge application via the tunnel.
Owner:AMAZON TECH INC

System and method for dynamic provisioning of cloud desktop pools from multiple public cloud providers

A system and method for providing virtual desktops to client devices of users is disclosed. The system includes available cloud regions that each can provide virtual desktops and associated resources. A desktop pool resource management engine is coupled to the available cloud regions and collects constraint data from the available cloud regions as well as operational data from desktop clients and desktop agents. A cloud usage profile is created for a subset of the users from the operational data. A priority list of available cloud regions for a user in the subset is created based on the usage profile and the constraint data of the available cloud regions. The highest priority cloud region from the priority list is recommended for the user requesting a desktop. A control plane selects the highest priority cloud region according to the priority list to provide the desktop to the client device.
Owner:WORKSPOT INC

Offloading container runtime environment orchestration

Disclosed are systems and methods that offload the work traditionally performed by a thick software client operating on each container instance of a cloud provider network with a thin and generalized agent that can be instructed in a piece-wise manner to perform operations as instructed by a workload manager executing on a control plane that is separate from the container instance. The workload manager, executing on the control plane of a cloud provider network, may precompute a set of operations and order of execution of those operations in the control plane and present those operations in a controlled manner to the agent that executes each operation as instructed. The agent executing on the data plane, rather than polling an orchestrator for work and then establishing the runtime environment based on a received Application Specification, awaits an operation or task that is pushed to the agent from the control plane.
Owner:AMAZON TECH INC

Authentication Mechanisms In A Container Orchestration System

Techniques for a container orchestration system are disclosed. A container orchestration API server receives a request from a virtual agent in a container orchestration cluster that includes a cloud provider authentication token. The request is generated by the virtual agent using a resource principal that corresponds to the virtual agent. The container orchestration API server attempts authentication of the virtual agent using a container orchestration native authentication. Upon failure of the container orchestration native authentication, the container orchestration API server authenticates the virtual agent using a cloud provider authentication unit via an authentication webhook using the cloud provider authentication token.
Owner:ORACLE INT CORP

Managing excess capacity in radio access network edge systems

PCT designated stageWO2025170920A1Wireless communicationAccess networkThird party
Disclosed are various embodiments for managing excess capacity in radio access network (RAN) edge systems. In one embodiment, a RAN-enabled edge server is located at a cell site, is configured to execute distributed unit (DU) and / or centralized unit (CU) functions for a RAN, and includes a physical layer accelerator specialized for DU physical layer communication. A computing device is configured to determine that the RAN-enabled edge server has excess resource capacity beyond a quantity necessary to execute the DU / CU functions for the RAN, determine a demand for the excess resource capacity from a cloud provider network, and determine whether to offer the excess resource capacity to third-party customers of the cloud provider network based at least in part on the demand.
Owner:AMAZON TECH INC

Provider substrate extension connectivity using secure service links

ActiveUS12719842B1Substrate networkEngineering
Techniques for utilizing a cloud-side link module and a provider substrate extension (PSE) link module to secure a communications channel between a cloud provider network and a provider substrate extension are described. A PSE link module receives a request originated by a compute instance in the PSE that is destined to a destination within the cloud provider network. The request was encrypted using an encryption scheme that encrypts traffic of a virtual private cloud that the compute instance operates in. The PSE link module decrypts the first request, encrypts it using a separate encryption scheme, and transmits it via a secure tunnel to a second link module in the cloud provider network. The second link module can decrypt the encrypted traffic and cause it to be validated before it is passed on via the cloud provider's substrate network to be processed.
Owner:AMAZON TECH INC

Value chain workload autoscaling in an industry cloud

The technology described herein is directed towards automatically scaling cloud provider resources allocated for one enterprise's service based on the resources being used or expected to be used by another enterprise's service, in which there is a value chain-based load-dependency relationship between the two enterprises' services. In one example implementation, a first prediction engine determines a predicted workload for a first enterprise service, and sends that information to a load manager that allocates resources for the first enterprise service based on the prediction. Based on the load-dependency relationship, the first prediction engine sends the predicted workload to a second prediction engine, which predicts a second predicted workload for a second enterprise's service, and sends the second prediction information to a load manager that allocates resources for the second enterprise service based on the second prediction. The automatic scaling is done without sharing any enterprise-sensitive data among the enterprises.
Owner:DELL PROD LP

Method and system for generating key performance indicator prediction model for multi-cloud applications

ActiveUS12664506B2InstrumentsAutoregressive integrated moving averageCloud provider
This disclosure relates generally to method and system for generating key performance indicator prediction model for multi-cloud applications. The disclosed method determines an optimized resource model and a predictive cost structure for one or more multi-cloud applications. The method receives a composite usage request to obtain a current resource consumption metrics and a cost structure for each cloud application identifier (ID). Further, a set of cloud provider API endpoints are invoked to obtain a plurality of usage tracking metrics. Further, a plurality of views are generated for each cloud application ID by processing every record associated with each API response file with allocated resource data. Then, a KPI prediction model is generated by leveraging autoregressive integrated moving average on the KPI time series data to determine an optimized resource model and a cost structure.
Owner:TATA CONSULTANCY SERVICES LTD

Code execution on a distributed unit

Systems and methods are described for implementing a distributed unit in a radio access network that executes code on behalf of mobile devices. A distributed unit may be implemented on an edge server that is in close physical proximity to a radio unit, with few or no intervening devices. The edge server may thus provide services to mobile devices, such as executing code on behalf of a mobile device in an execution environment on the edge server, at significantly lower latency than more distant cloud-based servers. The edge server may preload computing environments with code for which a mobile device is likely to request execution (e.g., because a particular application is executing on the mobile device), and may determine whether to execute code on the edge server or on a cloud provider network.
Owner:AMAZON TECH INC

System and method for use of in-memory data grid as a vector database for use in retrieval-augmented generation

In accordance with an embodiment, described herein are systems and methods for use of an in-memory data grid as a vector database, with linearly-scalable data ingestion, for use in generative artificial intelligence (AI), data visualization, or other applications that include the use of a large language model (LLM) or a retrieval-augmented generation (RAG) process. In accordance with an embodiment, the in-memory data grid provides functionality to represent content as document chunks containing text, embedding, and metadata, which allows the system to support a variety of RAG framework integrations in a consistent manner. To further support the use of RAG processes, the system can support document ingestion via various types of document sources, such as the use of HTTP URLs that allow retrieval of documents using HTTP GET calls; or, for example in cloud environments, the use of object storage and / or other cloud provider storage services as appropriate.
Owner:ORACLE INT CORP

Resource sharing between cloud-hosted virtual networks

Techniques for resource sharing between cloud-hosted virtual networks are described. A first network address of a first virtual network is associated with a resource connected to a second virtual network, the first and second virtual networks within a cloud provider network. A service of the cloud provider network receives a message destined for the first network address. The service translates the first network address to a second network address of the resource in the second virtual private network. The service sends the message to the resource at the second network address in the second virtual network.
Owner:AMAZON TECH INC

Multi-cloud site-site secure connectivity as a service

The present technology provides intercloud connectivity as a service by discovering components of the organization's deployment in various sites, irrespective of the cloud provider, such that two sites can merely be selected along with a few standard options, and the controller can handle the complexity of instantiating a tunnel between the cloud sites automatically. Further, the controller can monitor the health of one or more tunnels between the cloud sites to automatically scale bandwidth up or down.
Owner:CISCO TECHNOLOGY INC

Reconciler engine(s) for managing external resources within a cloud-based environment

Various embodiments of the present technology generally relate to a VnicSet operator system containing instructions to implement a process to manage a virtual network interface controller (Vnic) on an application pod of a containerized software environment, the Vnic being directly reachable from a network external to the containerized software environment. In an aspect, the VnicSet operator may include a reconciler engine that determines one or more reconciliation actions for one or more Vnics. The reconciler engine may determine a first reconciliation action for a first worker node and acquire a node lock for the first worker node based on the first reconciliation action. Responsive to acquiring the node lock, the reconciler engine may transmit a first reconciliation action request to a cloud provider, where the cloud provider performs the first reconciliation action responsive to receiving the first reconciliation action request.
Owner:ORACLE INT CORP

Local container image caching and retrieval for devices at edge locations

Techniques are described for enabling computing devices in computing environments distinct from a cloud provider network to use temporally staggered container image pull requests upon initiating execution of a container-based task. For example, upon determining to launch a container on a computing device running in a computing environment that is distinct from a cloud provider network, an agent running on the computing device can select a time in the future at which to request the container image(s) to be used to launch the container from a container registry based on a randomized value. The randomized value, for example, can enable each computing device in the environment to request the container image(s) at a time that differs from times at which other computing devices in the environment generate similar requests (e.g., such that the request times are “staggered” relative to one another).
Owner:AMAZON TECH INC

Power oversubscription in LLM cloud providers

Systems and methods for implementing power oversubscription in graphic processing unit (GPU) servers are provided. An increase to a quantity of servers allocated to a group of GPU servers in an inference cluster is applied. Based on the power consumption of the group of GPU servers exceeding a first threshold, a frequency of low priority inference workloads is capped, and based on the power consumption of the group of GPU servers exceeding a second threshold, the frequency of the low priority inference workloads are capped and a frequency of high priority inference workloads are capped, enabling an increase in allocated server capacity in the existing inference clusters while maintaining service level objectives (SLOs).
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Integrating sd-wan constructs with SASE security policies

Techniques for automatically integrating SD-WAN constructs to security policies are described. The techniques may include defining, by a security cloud provider, a security policy for an entity, the entity represented by a VPN security policy label and the security policy absent source and destination CIDR IP addresses. The security cloud provider notifies an SD-WAN controller of the security policy. The SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID. The SD-WAN controller generates an enhanced security policy by automatically adding source and destination CIDR IP addresses to the security policy. The SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router and generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.
Owner:CISCO TECHNOLOGY INC