Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

96 results about "Cloud provider" patented technology

A cloud provider is a company that delivers cloud computing based services and solutions to businesses and/or individuals. This service organization may provide rented and provider-managed virtual hardware, software, infrastructure and other related services.

User-configured multi-location service deployment and scaling

Techniques for intelligent user-configured multi-location service deployment and scaling are described. Autoscaling configuration data is received, the autoscaling configuration data including an application redistribution trigger condition and a placement optimization constraint, the application redistribution trigger condition based on a variable associated with a state of an application, the application deployed across a first set of deployment zones of a plurality of deployment zones of a cloud provider network. The application redistribution trigger condition is determined to be satisfied. A redistribution placement plan is obtained that satisfies the placement optimization constraint and identifies a second set of deployment zones of the plurality of deployment zones of the cloud provider network across which to deploy the application. The application is redistributed across the second set of deployment zones.
Owner:AMAZON TECH INC

Automatic rebalancing of container-based services for high availability

Techniques are described for enabling a container service of a cloud provider network to detect imbalances of container placements across a selected set of availability zones (AZs) and to automatically rebalance placement of the containers, if needed. An actual distribution of containers may differ from an expected distribution according to a configured placement strategy, e.g., due to an outage or other operational issue affecting one or more of the AZs, scaling operations over time, and the like. In these and other scenarios, the container service can rebalance placement of the containers by terminating one or more containers in one or more of the AZs and launching additional containers in one or more other AZs to restore a more desirable balance. The periodic rebalancing of containers in this manner improves a container-based application's ability to load balance demand and further improves application availability by ensuring sufficient capacity is spread across multiple AZs.
Owner:AMAZON TECH INC

System and method for dynamic provisioning of cloud desktop pools from multiple public cloud providers

A system and method for providing virtual desktops to client devices of users is disclosed. The system includes available cloud regions that each can provide virtual desktops and associated resources. A desktop pool resource management engine is coupled to the available cloud regions and collects constraint data from the available cloud regions as well as operational data from desktop clients and desktop agents. A cloud usage profile is created for a subset of the users from the operational data. A priority list of available cloud regions for a user in the subset is created based on the usage profile and the constraint data of the available cloud regions. The highest priority cloud region from the priority list is recommended for the user requesting a desktop. A control plane selects the highest priority cloud region according to the priority list to provide the desktop to the client device.
Owner:WORKSPOT INC

Offloading container runtime environment orchestration

Disclosed are systems and methods that offload the work traditionally performed by a thick software client operating on each container instance of a cloud provider network with a thin and generalized agent that can be instructed in a piece-wise manner to perform operations as instructed by a workload manager executing on a control plane that is separate from the container instance. The workload manager, executing on the control plane of a cloud provider network, may precompute a set of operations and order of execution of those operations in the control plane and present those operations in a controlled manner to the agent that executes each operation as instructed. The agent executing on the data plane, rather than polling an orchestrator for work and then establishing the runtime environment based on a received Application Specification, awaits an operation or task that is pushed to the agent from the control plane.
Owner:AMAZON TECH INC

Provider substrate extension connectivity using secure service links

ActiveUS12719842B1Substrate networkEngineering
Techniques for utilizing a cloud-side link module and a provider substrate extension (PSE) link module to secure a communications channel between a cloud provider network and a provider substrate extension are described. A PSE link module receives a request originated by a compute instance in the PSE that is destined to a destination within the cloud provider network. The request was encrypted using an encryption scheme that encrypts traffic of a virtual private cloud that the compute instance operates in. The PSE link module decrypts the first request, encrypts it using a separate encryption scheme, and transmits it via a secure tunnel to a second link module in the cloud provider network. The second link module can decrypt the encrypted traffic and cause it to be validated before it is passed on via the cloud provider's substrate network to be processed.
Owner:AMAZON TECH INC

Value chain workload autoscaling in an industry cloud

The technology described herein is directed towards automatically scaling cloud provider resources allocated for one enterprise's service based on the resources being used or expected to be used by another enterprise's service, in which there is a value chain-based load-dependency relationship between the two enterprises' services. In one example implementation, a first prediction engine determines a predicted workload for a first enterprise service, and sends that information to a load manager that allocates resources for the first enterprise service based on the prediction. Based on the load-dependency relationship, the first prediction engine sends the predicted workload to a second prediction engine, which predicts a second predicted workload for a second enterprise's service, and sends the second prediction information to a load manager that allocates resources for the second enterprise service based on the second prediction. The automatic scaling is done without sharing any enterprise-sensitive data among the enterprises.
Owner:DELL PROD LP

Method and system for generating key performance indicator prediction model for multi-cloud applications

ActiveUS12664506B2InstrumentsAutoregressive integrated moving averageCloud provider
This disclosure relates generally to method and system for generating key performance indicator prediction model for multi-cloud applications. The disclosed method determines an optimized resource model and a predictive cost structure for one or more multi-cloud applications. The method receives a composite usage request to obtain a current resource consumption metrics and a cost structure for each cloud application identifier (ID). Further, a set of cloud provider API endpoints are invoked to obtain a plurality of usage tracking metrics. Further, a plurality of views are generated for each cloud application ID by processing every record associated with each API response file with allocated resource data. Then, a KPI prediction model is generated by leveraging autoregressive integrated moving average on the KPI time series data to determine an optimized resource model and a cost structure.
Owner:TATA CONSULTANCY SERVICES LTD

Code execution on a distributed unit

Systems and methods are described for implementing a distributed unit in a radio access network that executes code on behalf of mobile devices. A distributed unit may be implemented on an edge server that is in close physical proximity to a radio unit, with few or no intervening devices. The edge server may thus provide services to mobile devices, such as executing code on behalf of a mobile device in an execution environment on the edge server, at significantly lower latency than more distant cloud-based servers. The edge server may preload computing environments with code for which a mobile device is likely to request execution (e.g., because a particular application is executing on the mobile device), and may determine whether to execute code on the edge server or on a cloud provider network.
Owner:AMAZON TECH INC

System and method for use of in-memory data grid as a vector database for use in retrieval-augmented generation

In accordance with an embodiment, described herein are systems and methods for use of an in-memory data grid as a vector database, with linearly-scalable data ingestion, for use in generative artificial intelligence (AI), data visualization, or other applications that include the use of a large language model (LLM) or a retrieval-augmented generation (RAG) process. In accordance with an embodiment, the in-memory data grid provides functionality to represent content as document chunks containing text, embedding, and metadata, which allows the system to support a variety of RAG framework integrations in a consistent manner. To further support the use of RAG processes, the system can support document ingestion via various types of document sources, such as the use of HTTP URLs that allow retrieval of documents using HTTP GET calls; or, for example in cloud environments, the use of object storage and / or other cloud provider storage services as appropriate.
Owner:ORACLE INT CORP

Resource sharing between cloud-hosted virtual networks

Techniques for resource sharing between cloud-hosted virtual networks are described. A first network address of a first virtual network is associated with a resource connected to a second virtual network, the first and second virtual networks within a cloud provider network. A service of the cloud provider network receives a message destined for the first network address. The service translates the first network address to a second network address of the resource in the second virtual private network. The service sends the message to the resource at the second network address in the second virtual network.
Owner:AMAZON TECH INC

Reconciler engine(s) for managing external resources within a cloud-based environment

Various embodiments of the present technology generally relate to a VnicSet operator system containing instructions to implement a process to manage a virtual network interface controller (Vnic) on an application pod of a containerized software environment, the Vnic being directly reachable from a network external to the containerized software environment. In an aspect, the VnicSet operator may include a reconciler engine that determines one or more reconciliation actions for one or more Vnics. The reconciler engine may determine a first reconciliation action for a first worker node and acquire a node lock for the first worker node based on the first reconciliation action. Responsive to acquiring the node lock, the reconciler engine may transmit a first reconciliation action request to a cloud provider, where the cloud provider performs the first reconciliation action responsive to receiving the first reconciliation action request.
Owner:ORACLE INT CORP

Local container image caching and retrieval for devices at edge locations

Techniques are described for enabling computing devices in computing environments distinct from a cloud provider network to use temporally staggered container image pull requests upon initiating execution of a container-based task. For example, upon determining to launch a container on a computing device running in a computing environment that is distinct from a cloud provider network, an agent running on the computing device can select a time in the future at which to request the container image(s) to be used to launch the container from a container registry based on a randomized value. The randomized value, for example, can enable each computing device in the environment to request the container image(s) at a time that differs from times at which other computing devices in the environment generate similar requests (e.g., such that the request times are “staggered” relative to one another).
Owner:AMAZON TECH INC

Power oversubscription in LLM cloud providers

Systems and methods for implementing power oversubscription in graphic processing unit (GPU) servers are provided. An increase to a quantity of servers allocated to a group of GPU servers in an inference cluster is applied. Based on the power consumption of the group of GPU servers exceeding a first threshold, a frequency of low priority inference workloads is capped, and based on the power consumption of the group of GPU servers exceeding a second threshold, the frequency of the low priority inference workloads are capped and a frequency of high priority inference workloads are capped, enabling an increase in allocated server capacity in the existing inference clusters while maintaining service level objectives (SLOs).
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Integrating sd-wan constructs with SASE security policies

Techniques for automatically integrating SD-WAN constructs to security policies are described. The techniques may include defining, by a security cloud provider, a security policy for an entity, the entity represented by a VPN security policy label and the security policy absent source and destination CIDR IP addresses. The security cloud provider notifies an SD-WAN controller of the security policy. The SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID. The SD-WAN controller generates an enhanced security policy by automatically adding source and destination CIDR IP addresses to the security policy. The SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router and generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.
Owner:CISCO TECHNOLOGY INC

Data flow analysis of cloud-based software applications

Techniques for data flow analysis of cloud-based software applications are described. A first portion of source code of a software application is determined to obtain data from a data source identified by a first resource identifier of a cloud provider network, the determination based on a mapping of a first statement in the first portion of the source code to an application programming interface (API) call. A trace of a data flow from the first portion of the source code to a second portion of the source code is obtained. A data sink identified by a second resource identifier of the cloud provider network is determined based on a mapping of a second statement in the second portion of the source code to another API call. A result that includes an identification of a data flow from the data source identified by the first resource identifier to the data sink identified by the second resource identifier is generated.
Owner:AMAZON TECH INC

Authentication mechanisms in a container orchestration system

Techniques for a container orchestration system are disclosed. A container orchestration API server receives a request from a virtual agent in a container orchestration cluster that includes a cloud provider authentication token. The request is generated by the virtual agent using a resource principal that corresponds to the virtual agent. The container orchestration API server attempts authentication of the virtual agent using a container orchestration native authentication. Upon failure of the container orchestration native authentication, the container orchestration API server authenticates the virtual agent using a cloud provider authentication unit via an authentication webhook using the cloud provider authentication token.
Owner:ORACLE INT CORP

Microservices Based Simultaneous Execution via Multiple Cloud Service Providers

A system and method for dynamically selecting, executing, and optimizing microservices across multiple cloud service providers is disclosed. A workload management system receives a microservice execution request, retrieves metadata from a microservices catalog, and selects an optimal cloud provider using a weighted cost function based on execution performance, cost, security compliance, and availability. A machine learning model refines provider selection using historical execution data. An API abstraction layer formats and encrypts execution requests before transmission. A performance monitoring module tracks execution, while a fault detection module identifies failures and triggers automated failover via a failover module that preemptively replicates execution state data. A response processing module validates execution results before returning them to the requesting application. The system ensures dynamic, cost-efficient, and secure workload distribution while maintaining seamless failover resilience. By leveraging real-time performance metrics, historical data, and predictive analytics, the system optimizes microservice execution across diverse cloud environments.
Owner:BANK OF AMERICA CORP

Distributed and synchronized network core for radio-based networks

Various embodiments are provided for dynamically reconfiguring radio access network (RAN) functionality between edge and cloud computing environments. A RAN-enabled edge server deployed at an edge location is configured to perform a set of distributed unit (DU) functions for a radio-based network, while a server hosted at a regional data center of a cloud provider network is configured to perform a set of core network functions for the radio-based network. The system monitors availability of the core network functions at the edge location and determines that the set of core network functions provided by the server at the regional data center is unavailable. In response to determining that the core network functions are unavailable, the RAN-enabled edge server is dynamically reconfigured to perform the set of core network functions.
Owner:AMAZON TECH INC

Fine-grained lightweight DPU performance isolation method

The invention provides a fine-grained lightweight DPU performance isolation method. The method comprises the following steps: firstly, entering an offline stage, representing a partial systematic analysis task execution mode through offline analysis resources, and modeling a mapping relationship between task parameters and resource consumption; then entering an online stage, intercepting submission of an application task, evaluating a resource demand according to an offline model, decomposing a large task by applying a self-adaptive task splitting and result recombination part, executing a scheduling process guided by a working load, and realizing dynamic allocation through a global scheduler and an application agent; the global scheduler allocates time slices or subtasks based on workload characteristics; after execution, results are recombined and returned to the application. Therefore, under the condition that hardware or proprietary software is not modified, accurate resource management is achieved by directly constructing on an existing manufacturer SDK, the isolation challenge of the DPU is effectively solved through the technologies, and efficient resource utilization of cloud providers in PaaS and SaaS modes is promoted.
Owner:BEIHANG UNIV

Remotely managing execution of containerized applications across user-managed and server-managed data centers

Generally described, the present application relates to providing a container orchestration service that can enable and manage execution of containerized applications on user-owned infrastructure and cloud-provided compute capacity. In some embodiments, a request to execute a task may indicate the type of compute capacity (e.g., internal / external, computing resource amount, etc.) to be used to execute the task. For example, if the task indicates that internal compute capacity is to be used, compute capacity hosted the cloud provider network can be identified and used to execute the task. Alternatively, if the task indicates that external compute capacity is to be used, instructions for executing the task can be generated and sent to the user-owned infrastructure, and the task can be executed using compute capacity provided within the user-owned infrastructure, which is external to the cloud provider network implementing the container orchestration service.
Owner:AMAZON TECH INC

Method for improving connection pool efficiency to improve object storage access performance

Embodiments of the present disclosure provide a method, an electronic device, and a computer program product for connection pool efficiency. The method may include determining a set of connections in a connection pool of a storage system, the set of connections corresponding to open connections established by the storage system to a set of end-points of an object storage service of a cloud provider, wherein an application of the storage system accesses the object storage service through one or more connections from the set of connections; monitoring data transfers over the set of connections; collecting performance metrics associated with the data transfers; identifying a first connection having performance metrics below a predetermined threshold; identifying a second connection being added to the set of connections in the connection pool, wherein the second connection is a new connection; and marking the first connection for removal from the connection pool.
Owner:DELL PROD LP

Shadow satisfiability modulo theories solver systems

Techniques are described for executing satisfiability modulo theories (SMT) solvers in a "shadow" system configuration where input queries are provided to a primary SMT solver system and additionally to one or more secondary SMT solver systems. SMT solver systems can be used by cloud providers and in other computing environments to analyze the implications of configured user account policies defining permissions with respect to users' computing resources and associated actions within a computing environment, to help ensure the security of computing resources and user data, etc. The results generated by a primary SMT solver system can be provided to one or more secondary SMT solver systems, where each of the secondary SMT systems can comprise different system components or different versions of system components, to assess the correctness of the primary SMT solver system, to compare performance metrics, among other possible types of analyses.
Owner:AMAZON TECH INC

Virtual machine host health monitoring with untrusted sources in a cloud provider network

Techniques for monitoring virtual machine host system health with untrusted sources are described. An agent receives a request to terminate a first virtual machine, the request including an untrusted status indicator originating from an environment executing untrusted software. The agent sends first termination event data to a differential health service of the provider network, the first termination event data including an indication of a host computer system and the untrusted status indicator. The differential health service determines that a first metric associated with the first host computer system differs from a second metric associated with a pool of host computer systems by at least a first amount and based at least in part on the untrusted status indicator, wherein the pool of host computer systems includes the first host computer system. The differential health service sends a second request to cause a corrective action to be taken.
Owner:AMAZON TECH INC

Large-scale exchange of cyber threat intelligence via routing protocols

PendingUS20260129069A1Securing communicationCyber threat intelligenceExchange network
The techniques described herein provide a transport mechanism for large-scale exchange of cyber threat intelligence between entities and / or within an entity. Cyber threats evolve rapidly, and entities face challenges in efficiently sharing threat intelligence at “network speed” and applying mitigations across their networks. Existing techniques lack scalability, real-time updates, and coordination among organizations. Moreover, there is no existing technique for large-scale exchange of cyber threat intelligence. Additionally identifying threat data is often performed manually and is subjective. The techniques described herein provide mechanisms that leverage BGP or other routing protocols to facilitate large-scale threat intelligence exchange and mitigation across entities in real-time. The techniques described herein enable entities, including cloud providers, internet service providers, and others, to collaboratively mitigate cyber threats by disseminating real-time confirmed and actionable threat intelligence across their networks.
Owner:CISCO TECHNOLOGY INC

Fully-managed secure connectivity among constituent services of distributed applications

ActiveUS12683949B1EngineeringCloud provider
A control plane server of a network-accessible service of a cloud provider network obtains an indication from a client that security artifacts to be used for establishing connections among constituent services of an application are to be obtained automatically by the service. The control plane server transmits, to a first agent established at a first resource at which a first constituent service of the application runs, a set of security artifacts obtained from an artifact source and assigned to the first constituent service by the control plane server. The set of artifacts is used to establish a connection between the first agent and a second agent at a second execution resource at which a second constituent service of the application runs. Messages between the constituent services are sent using the connection.
Owner:AMAZON TECH INC

Techniques for discovering data store locations via initial scanning

A system and method for discovering data store locations. A method includes reading, for each disk of a plurality of disks deployed in a cloud environment, only a portion of a snapshot of the disk accessed via a cloud provider tool, wherein the portion of the snapshot of each disk accessed via the cloud provider tool includes file system metadata of a file system of the disk, wherein the cloud provider tool is configured to provide direct access to data from each of the plurality of disks; analyzing the portion of the snapshot of each disk of the plurality of disks to determine whether each disk contains a data store; and identifying, based on the analysis, at least one data store in the cloud environment.
Owner:CYERA LTD

User-friendly model deployment for secure processing of machine learning-based workloads

A user-friendly platform provides a simplified procedure for end users to deploy models that utilize generative AI to perform tasks (hereinafter simply “AI model”) in a deployment environment (e.g. in a data center). Upon selection of an AI model to be deployed, the platform orchestrates deployment and allocation of resources that satisfy hardware requirements of the AI model. The platform includes an agent that communicates with infrastructure of the cloud provider or virtualization platform that manages deployed resources tracks allocation of hardware resources to virtual / cloud resources running on the deployment environment. The platform handles deployment of resources for deployment of the AI model “behind-the-scenes” from the user's perspective based on the monitored availability of hardware resources. For added security, the platform performs DLP scanning of data uploaded to the platform for input to an AI model that has been deployed.
Owner:PALO ALTO NETWORKS INC

Functions as a service

Some embodiments of the invention provide a method of implementing a FaaS (functions as a service) framework executing in a first cloud for multiple applications operating on multiple machines in the first cloud. The method provides to the FaaS framework (1) multiple sets of credentials for accessing of multiple cloud providers and (2) a set of selection rules for selecting cloud providers from the multiple cloud providers to execute multiple functions for the multiple programs. For each particular function in the multiple functions, the method configures the FaaS framework to use the set of selection rules to select a particular cloud provider from the multiple cloud providers to execute the particular function, and configures the FaaS framework to use a particular set of credentials associated with the selected particular cloud provider from the multiple sets of credentials to forward the particular function to the selected particular cloud provider for execution.
Owner:VMWARE INC