Automated connectivity to cloud resources
US-2024223403-A1 · Jul 4, 2024 · US
US2025330499A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2025330499-A1 |
| Application number | US-202519254855-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jun 30, 2025 |
| Priority date | Dec 10, 2021 |
| Publication date | Oct 23, 2025 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods are provided for obtaining policy data associated with a private network implemented at least partly within a cloud provider network; establishing, based on the policy data, a first segment within the private network, wherein in a first geographic region of the cloud provider network, traffic associated with the first segment is isolated from traffic associated with a second segment of the private network, and wherein in a second geographic region of the cloud provider network, traffic associated with the first segment is isolated from traffic associated with a third segment of the private network; obtaining metadata indicating an isolated network of the cloud provider network is associated with the first segment; and enabling the isolated network to communicate, over the first segment, across the first geographic region and the second geographic region.
Opening claim text (preview).
What is claimed is: 1 . A computer-implemented method comprising: under control of a computing system comprising memory and one or more computer processors configured to execute specific instructions: obtaining policy data associated with a private network implemented at least within a cloud provider network; establishing, based on the policy data, a first segment within the private network; obtaining attachment metadata indicating a first isolated network of the cloud provider network is associated with the first segment; enabling, based on the attachment metadata, the first isolated network to communicate over the first segment; preventing, based on the policy data, the first isolated network from communicating with a second isolated network associated with the first segment; enabling, based on the policy data, communications between the first isolated network and a shared resource segment; and enabling, based on the policy data, communications between the second isolated network and the shared resource segment. 2 . The computer-implemented method of claim 1 , wherein establishing the first segment comprises: configuring, based on the policy data, a first gateway node in a first geographic region of a plurality of geographic regions of the cloud provider network; and configuring, based on the policy data, a second gateway node in a second geographic region of the plurality of geographic regions to isolate at least a portion of traffic associated with the first segment from at least a portion of traffic associated with a different segment of the private network. 3 . The computer-implemented method of claim 2 , further comprising: configuring the first gateway node to route packets associated with the first segment using a first route table associated with the first segment; and configuring the first gateway node to route packets associated with a second segment using a second route table different from the first route table. 4 . The computer-implemented method of claim 2 , further comprising determining, based on the policy data, a subset of the plurality of geographic regions in which the first segment is to be established, wherein the subset of the plurality of geographic regions comprises fewer than all of the plurality of geographic regions. 5 . The computer-implemented method of claim 4 , further comprising determining, based on the policy data, a second subset of the plurality of geographic regions in which a second segment is to be established, wherein the second subset of the plurality of geographic regions is different than the subset of the plurality of geographic regions. 6 . The computer-implemented method of claim 1 , further comprising generating a graphical user interface comprising: a first display object representing the first segment; a second display object representing a second segment; a third display object representing an attachment of the first isolated network to the first segment; and a fourth display object representing a path shared between the first segment and the second segment. 7 . The computer-implemented method of claim 1 , further comprising: determining that the policy data indicates acceptance is required to enable the first isolated network to communicate over the first segment; and receiving acceptance data representing approval to enable the first isolated network to communicate over the first segment, wherein the first isolated network is enabled to communicate over the first segment in response to receiving the acceptance data. 8 . The computer-implemented method of claim 1 , further comprising determining, based on the policy data, that isolated networks enabled to communicate over the first segment are prohibited from communicating with each other over the first segment. 9 . The computer-implemented method of claim 1 , further comprising determining, based on the policy data, to deny sharing of a route from a second segment with the first segment. 10 . The computer-implemented method of claim 1 , further comprising determining, based on the policy data, to permit sharing of a route from a second segment with the first segment. 11 . A system comprising: computer-readable memory storing executable instructions; and one or more processors in communication with the computer-readable memory and programmed by the executable instructions to: obtain policy data associated with a private network implemented at least within a cloud provider network; establish, based on the policy data, a first segment within the private network; obtain attachment metadata indicating a first isolated network of the cloud provider network is associated with the first segment; enable, based on the attachment metadata, the first isolated network to communicate over the first segment; prevent, based on the policy data, the first isolated network from communicating with a second isolated network associated with the first segment; enable, based on the policy data, communications between the first isolated network and a shared resource segment; and enable, based on the policy data, communications between the second isolated network and the shared resource segment. 12 . The system of claim 11 , wherein to establish the first segment, the one or more processors are further programmed by the executable instructions to: configure, based on the policy data, a first gateway node in a first geographic region of a plurality of geographic regions of the cloud provider network; and configure, based on the policy data, a second gateway node in a second geographic region of the plurality of geographic regions to isolate at least a portion of traffic associated with the first segment from at least a portion of traffic associated with a different segment of the private network. 13 . The system of claim 12 , wherein the one or more processors are further programmed by the executable instructions to: configuring the first gateway node to route packets associated with the first segment using a first route table associated with the first segment; and configuring the first gateway node to route packets associated with a second segment using a second route table different from the first route table. 14 . The system of claim 12 , wherein the one or more processors are further programmed by the executable instructions to determine,, based on the policy data, a subset of the plurality of geographic regions in which the first segment is to be established, wherein the subset of the plurality of geographic regions comprises fewer than all of the plurality of geographic regions. 15 . The system of claim 14 , wherein the one or more processors are further programmed by the executable instructions to determine,, based on the policy data, a second subset of the plurality of geographic regions in which a second segment is to be established, wherein the second subset of the plurality of geographic regions is different than the subset of the plurality of geographic regions. 16 . The system of claim 11 , wherein the one or more processors are further programmed by the executable instructions to generate a graphical user interface comprising: a first display object representing the first segment; a second display object representing a second segment; a third display object representing an attachment of the first isolated network to the first segment; and a fourth display object representing a path shared between the first segment and the second segment. 17 . The system of claim 11 , wherein the one or more processors
Traffic policing · CPC title
Dynamic sharing of VLAN information amongst network nodes (configuration of the network or of network elements H04L41/08) · CPC title
Multipath · CPC title
Virtual private networks · CPC title
Assignment of logical groups to network elements · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.