Quarantine for cloud-based services

US2021176210A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2021176210-A1
Application numberUS-202017113825-A
CountryUS
Kind codeA1
Filing dateDec 7, 2020
Priority dateDec 6, 2019
Publication dateJun 10, 2021
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A quarantine system could be disposed between an outer firewall and an inner firewall. The quarantine system may include persistent storage containing mappings between computing devices disposed within the inner firewall and data sources disposed outside the outer firewall. The quarantine system may include one or more processors configured to perform operations that include requesting and receiving, based on the mappings, a software-related update from a data source, the software-related update being targeted for deployment on the computing devices. The operations may also include assigning the software-related update for review by a group of one or more agents authorized to approve or reject the software-related update. The operations may also receiving an indication that the software-related update has been approved by the one or more agents and, responsive to receiving the indication, transmitting, based on the mappings, the software-related update to a recipient device within the inner firewall.

First claim

Opening claim text (preview).

What is claimed is: 1 . A quarantine system disposed between an outer firewall and an inner firewall, wherein the inner firewall is disposed within the outer firewall, the quarantine system comprising: persistent storage containing mappings between computing devices disposed within the inner firewall and data sources disposed outside the outer firewall, wherein the data sources contain software-related updates for the computing devices; and one or more processors configured to perform operations comprising: requesting and receiving, based on the mappings, a particular software-related update from a particular data source of the data sources, wherein the particular software-related update is targeted for deployment on one or more particular computing devices of the computing devices; assigning the particular software-related update for review by a group of one or more agents authorized to approve or reject the particular software-related update, wherein the one or more agents can access information regarding the particular software-related update by way of the quarantine system; receiving an indication that the particular software-related update has been approved by the one or more agents; and responsive to receiving the indication, transmitting, based on the mappings, the particular software-related update to a recipient device within the inner firewall. 2 . The quarantine system of claim 1 , wherein the data sources operate within a remote network management platform, and wherein the remote network management platform hosts its software services on at least one of the computing devices disposed within the inner firewall. 3 . The quarantine system of claim 2 , wherein the remote network management platform provides software services to a managed network, and wherein the software services provided by the remote network management platform to the managed network are provided by way of on at least one of the computing devices disposed within the inner firewall. 4 . The quarantine system of claim 1 , wherein the recipient device is one of the computing devices disposed within the inner firewall. 5 . The quarantine system of claim 1 , wherein the recipient device is a software repository disposed within the inner firewall, wherein at least some of the computing devices disposed within the inner firewall are configured to request and receive software-related updates from the software repository. 6 . The quarantine system of claim 1 , wherein the mappings further contain respective frequencies for requesting the software-related updates, and wherein the operations further comprise: requesting and receiving, based on the mappings, a second particular software-related update from the particular data source, the second particular software-related update requested by the quarantine system in a threshold time period after receiving the particular software-related update, the threshold time period being based on the mappings; assigning the second particular software-related update for review by the group of one or more agents; receiving an indication that the second particular software-related update has been approved by the one or more agents; and responsive to receiving the indication that the second particular software-related update has been approved, transmitting, based on the mappings, the second particular software-related update to the recipient device. 7 . The quarantine system of claim 6 , wherein the respective frequencies vary between the data sources of the software-related updates. 8 . The quarantine system of claim 6 , wherein the respective frequencies vary between recipient devices for the software-related updates. 9 . The quarantine system of claim 1 , wherein the mappings further contain respective target groups of agents associated with the software-related updates, and wherein assigning the particular software-related update for review by the group of one or more agents comprises assigning, based on the mappings, the particular software-related update to a target group of agents associated with the particular software-related update. 10 . The quarantine system of claim 9 , wherein the respective target groups of agents vary between the data sources of the software-related updates. 11 . The quarantine system of claim 9 , wherein the respective target groups of agents vary between recipient devices for the software-related updates. 12 . The quarantine system claim 1 , wherein the operations further comprise: after receiving the particular software-related update, storing the particular software-related update in a queue disposed within the quarantine system; determining that at least one agent in the group of one or more agents is available to review the particular software-related update; and in response to at least one agent in the group of one or more agents being available to review the particular software-related update, transmitting a representation of the particular software-related update to at least one agent. 13 . The quarantine system of claim 12 , wherein transmitting the representation of the particular software-related update to the at least one agent comprises providing, to the at least one agent, a representation of a dependency tree, the dependency tree identifying all computing devices operating disposed within the inner firewall that are affected by the particular software-related update. 14 . The quarantine system of claim 12 , wherein transmitting the representation of the particular software-related update to the at least one agent comprises providing, to the at least one agent, a graphical interface containing a comparison between content of the particular software-related update and content of a previous version of the particular software-related update. 15 . The quarantine system of claim 1 , wherein requesting and receiving the particular software-related update from the particular data source is initiated by the quarantine system. 16 . The quarantine system of claim 1 , wherein transmitting the particular software-related update to the recipient device is initiated by the quarantine system. 17 . The quarantine system of claim 1 , further comprising: requesting and receiving, based on the mappings, a second particular software-related update from a second particular data source of the data sources, wherein the second particular software-related update is targeted for deployment on one or more second particular computing devices of the computing devices assigning the second particular software-related update for review by the group of one or more agents; receiving an indication that the second particular software-related update has been rejected by the one or more agents; and responsive to receiving the indication that the second particular software-related update has been rejected, transmitting, to the group of one or more agents, a request for information from the group of one or more agents regarding a reason for rejecting the second particular software-related update. 18 . The quarantine system of claim 17 , further comprising: responsive to receiving the indication that the second particular software-related update has been rejected, isolating software-related updates that are associated with the second particular software-related update from being assigned for review by any agent. 19 . The quarantine system of claim 1 , wherein the group of one or more agents operate within the outer firewall. 20 . The quarantine system of cla

Assignees

Inventors

Classifications

  • Discovery or management of network topologies · CPC title

  • Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements · CPC title

  • using virtualisation of network functions or resources, e.g. SDN or NFV entities · CPC title

  • Indicating network or usage conditions on the user display · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2021176210A1 cover?
A quarantine system could be disposed between an outer firewall and an inner firewall. The quarantine system may include persistent storage containing mappings between computing devices disposed within the inner firewall and data sources disposed outside the outer firewall. The quarantine system may include one or more processors configured to perform operations that include requesting and rece…
Who is the assignee on this patent?
Servicenow Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0209. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 10 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).