Distributed zero trust network access
US-2023123781-A1 · Apr 20, 2023 · US
US12401625B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12401625-B2 |
| Application number | US-202318178832-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 6, 2023 |
| Priority date | Jan 16, 2023 |
| Publication date | Aug 26, 2025 |
| Grant date | Aug 26, 2025 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods for exchanging network information between member clusters include configuring a gateway pool of a member cluster, the gateway pool comprising a plurality of gateway nodes, the member cluster comprising the plurality of gateway nodes and one or more nodes, configuring a gateway node of the plurality of gateway nodes as an active gateway node for the member cluster, writing member cluster information to a storage, the member cluster information indicating address information of the gateway node, reading second member cluster information from the storage, the second member cluster information indicating address information of a gateway node of a second member cluster, establishing a tunnel between the gateway node and the second gateway node based on the second member cluster information, and communicating network traffic from at least one node of the member cluster to at least one node of the second member cluster via the tunnel.
Opening claim text (preview).
We claim: 1. A method for exchanging network information between member clusters, the method comprising: configuring a first gateway pool of a first member cluster, the first gateway pool comprising a first plurality of gateway nodes, the first member cluster comprising the first plurality of gateway nodes and one or more first nodes; configuring a first gateway node of the first plurality of gateway nodes as an active gateway node for the first member cluster; writing first member cluster information to a storage, the first member cluster information indicating address information of the first gateway node; reading second member cluster information from the storage, the second member cluster information indicating address information of a gateway node of a second member cluster; establishing a tunnel between the first gateway node and the second gateway node based on the second member cluster information; and communicating network traffic from at least one node of the first member cluster to at least one node of the second member cluster via the tunnel. 2. The method of claim 1 , further comprising: in response to determining the first gateway node has failed, configuring a second gateway node of the first plurality of gateway nodes as the active gateway node for the first member cluster; and in response to the configuring the second gateway node as the active gateway node, updating the first member cluster information at the storage to indicate address information of the second gateway node. 3. The method of claim 1 , wherein the first member cluster information further comprises address information of each of the first plurality of gateway nodes, and an indication of the active gateway. 4. The method of claim 1 , wherein each of the one or more first nodes is configured to run a pod of containers. 5. The method of claim 1 , wherein the address information comprises at least one of a pod CIDR of the first member cluster, a service CIDR of the first member cluster, or an Internet Protocol (IP) address of the first gateway node. 6. The method of claim 1 , wherein the storage comprises a third member cluster. 7. The method of claim 1 , further comprising routing traffic within the first member cluster, that is from the first plurality of gateway nodes and one or more first nodes and to the second member cluster, to the first gateway node. 8. A non-transitory computer readable medium comprising instructions that, when executed by one or more processors of a computing system, cause the computing system to perform a method for exchanging network information between member clusters, the method comprising: configuring a first gateway pool of a first member cluster, the first gateway pool comprising a first plurality of gateway nodes, the first member cluster comprising the first plurality of gateway nodes and one or more first nodes; configuring a first gateway node of the first plurality of gateway nodes as an active gateway node for the first member cluster; writing first member cluster information to a storage, the first member cluster information indicating address information of the first gateway node; reading second member cluster information from the storage, the second member cluster information indicating address information of a gateway node of a second member cluster; establishing a tunnel between the first gateway node and the second gateway node based on the second member cluster information; and communicating network traffic from at least one node of the first member cluster to at least one node of the second member cluster via the tunnel. 9. The non-transitory computer readable medium of claim 8 , the method further comprising: in response to determining the first gateway node has failed, configuring a second gateway node of the first plurality of gateway nodes as the active gateway node for the first member cluster; and in response to the configuring the second gateway node as the active gateway node, updating the first member cluster information at the storage to indicate address information of the second gateway node. 10. The non-transitory computer readable medium of claim 8 , wherein the first member cluster information further comprises address information of each of the first plurality of gateway nodes, and an indication of the active gateway. 11. The non-transitory computer readable medium of claim 8 , wherein each of the one or more first nodes is configured to run a pod of containers. 12. The non-transitory computer readable medium of claim 8 , wherein the address information comprises at least one of a pod CIDR of the first member cluster, a service CIDR of the first member cluster, or an Internet Protocol (IP) address of the first gateway node. 13. The non-transitory computer readable medium of claim 8 , wherein the storage comprises a third member cluster. 14. The non-transitory computer readable medium of claim 8 , the method further comprising routing traffic within the first member cluster, that is from the first plurality of gateway nodes and one or more first nodes and to the second member cluster, to the first gateway node. 15. A computer system, the computer system comprising: a memory; and a processor communicatively coupled to the memory, the processor being configured to: configure a first gateway pool of a first member cluster, the first gateway pool comprising a first plurality of gateway nodes, the first member cluster comprising the first plurality of gateway nodes and one or more first nodes; configure a first gateway node of the first plurality of gateway nodes as an active gateway node for the first member cluster; write first member cluster information to a storage, the first member cluster information indicating address information of the first gateway node; read second member cluster information from the storage, the second member cluster information indicating address information of a gateway node of a second member cluster; establish a tunnel between the first gateway node and the second gateway node based on the second member cluster information; and communicate network traffic from at least one node of the first member cluster to at least one node of the second member cluster via the tunnel. 16. The computer system of claim 15 , the processor further configured to: in response to determining the first gateway node has failed, configure a second gateway node of the first plurality of gateway nodes as the active gateway node for the first member cluster; and in response to the configuring the second gateway node as the active gateway node, update the first member cluster information at the storage to indicate address information of the second gateway node. 17. The computer system of claim 15 , wherein the first member cluster information further comprises address information of each of the first plurality of gateway nodes, and an indication of the active gateway. 18. The computer system of claim 15 , wherein each of the one or more first nodes is configured to run a pod of containers. 19. The computer system of claim 15 , wherein the address information comprises at least one of a pod CIDR of the first member cluster, a service CIDR of the first member cluster, or an Internet Protocol (IP) address of the first gateway node. 20. The computer system of claim 15 , wherein the storage comprises a third member cluster.
Hypervisor-specific management and integration aspects · CPC title
Network integration; Enabling network access in virtual machine instances · CPC title
Firewall traversal, e.g. tunnelling or, creating pinholes · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.