Aviatrix Systems, Inc.

United States of America

Back to Profile

1-100 of 102 for Aviatrix Systems, Inc. Sort by
Query
Aggregations
IP Type
        Patent 96
        Trademark 6
Jurisdiction
        United States 72
        World 30
Date
New (last 4 weeks) 3
2025 January (MTD) 2
2024 December 2
2024 November 6
2024 October 1
See more
IPC Class
H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways 36
H04L 12/46 - Interconnection of networks 33
H04L 61/5007 - Internet protocol [IP] addresses 23
H04L 67/10 - Protocols in which an application is distributed across nodes in the network 23
H04L 9/40 - Network security protocols 22
See more
Status
Pending 19
Registered / In Force 83
  1     2        Next Page

1.

SYSTEM AND METHOD FOR SELECTING VIRTUAL APPLIANCES IN COMMUNICATIONS WITH VIRTUAL PRIVATE CLOUD NETWORKS

      
Application Number 18908784
Status Pending
Filing Date 2024-10-07
First Publication Date 2025-01-23
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

A system for facilitating communications between client devices in geographically separated networks is described. First, message monitoring is conducted by each of a plurality of virtual appliances within a local network to detect a message of a first message type. Responsive to failing to locate a Media Access Control (MAC) address of a destination for the message within a prescribed table by a default gateway, one of the plurality of virtual appliances is selected for handling a forwarding of the message to a plurality of remote networks, and the message via the selected virtual appliance is forwarded to a plurality of gateways associated with a plurality of remote networks. Responsive to locating the MAC address of the destination within the table, the virtual appliance previously handling communications with the destination to forward the message to the destination.

IPC Classes  ?

  • G01M 3/32 - Investigating fluid tightness of structures by using fluid or vacuum by measuring rate of loss or gain of fluid, e.g. by pressure-responsive devices, by flow detectors for containers, e.g. radiators
  • H04L 12/64 - Hybrid switching systems
  • H04L 61/103 - Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
  • H04L 101/622 - Layer-2 addresses, e.g. medium access control [MAC] addresses

2.

Multi-cloud active mesh network system and method

      
Application Number 17332994
Grant Number 12206728
Status In Force
Filing Date 2021-05-27
First Publication Date 2025-01-21
Grant Date 2025-01-21
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sun, Yixin
  • Xu, Shanshan
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

In one embodiment, a controller features a first data store, a second data store and route determination logic. The first data store is configured to store current routing information from a source transit gateway within at least a first transit cloud network to a destination transit gateway within at least a second transit cloud network of the cloud network. Each of the source transit gateway and the destination transit gateway being one of a plurality of transit gateways associated with the cloud network. The second data store is configured to store alternative routing information between the source transit gateway and the destination transit gateway. The route determination logic is configured to (i) conduct analytics on all available route paths for a message intended to be sent from the source transit gateway to the destination transit gateway and (ii) select a best route path for the message.

IPC Classes  ?

  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 45/12 - Shortest path evaluation

3.

INGRESS GATEWAY WITH DATA FLOW CLASSIFICATION FUNCTIONALITY

      
Application Number 18829254
Status Pending
Filing Date 2024-09-09
First Publication Date 2024-12-26
Owner Aviatrix Systems, Inc. (USA)
Inventor Lenglet, Romain

Abstract

A computerized method for providing network policy-based routing of a data flow is described. After obtaining attributes associated with an incoming data flow, a first gateway is configured to determine one or more network policies based on the attributes associated with the incoming data flow and assign a classification identifier based on the one or more network policies. The classification identifier is configured to influence routing paths through at least one cloud network, where the classification identifier is encapsulated into content of the incoming data flow to generate a classified data flow for routing from a source to a destination through the at least one cloud network.

IPC Classes  ?

  • H04L 47/2441 - Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 45/00 - Routing or path finding of packets in data switching networks

4.

SYSTEM AND METHOD FOR ENABLING COMMUNICATION BETWEEN NETWORKS WITH OVERLAPPING IP ADDRESS RANGES

      
Application Number 18795163
Status Pending
Filing Date 2024-08-05
First Publication Date 2024-12-05
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Manglik, Pankaj
  • Kishen, Sunil

Abstract

A method is described that enables communication between two disjoined networks with overlapping IP address ranges. An intermediary function in each of the networks and a unique IP address pool are deployed to facilitate the communication. This method also enables communications between one network with a group of networks with overlapping IP address ranges.

IPC Classes  ?

  • H04L 61/106 - Mapping addresses of different types across networks, e.g. mapping telephone numbers to data network addresses
  • H04L 45/586 - Association of routers of virtual routers
  • H04L 45/745 - Address table lookupAddress filtering
  • H04L 61/4535 - Network directoriesName-to-address mapping using an address exchange platform which sets up a session between two nodes, e.g. rendezvous servers, session initiation protocols [SIP] registrars or H.323 gatekeepers

5.

Cloud-based egress filtering system

      
Application Number 17405881
Grant Number 12155626
Status In Force
Filing Date 2021-08-18
First Publication Date 2024-11-26
Grant Date 2024-11-26
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Cheung, Lee-Chik

Abstract

In one embodiment, a computing platform features a controller in communication with one or more virtual private cloud networks, including a first virtual private cloud network (VPC). The virtual private cloud network includes at least a first egress filtering gateway configured to filter egress traffic data received from a first gateway and route the filtered egress traffic data to a public network in accordance with a first set of filter rules. The first set of filter rules are included as part of a first security policy provided by the controller.

IPC Classes  ?

6.

MANAGEMENT NETWORK AND METHOD OF OPERATION

      
Application Number 18780448
Status Pending
Filing Date 2024-07-22
First Publication Date 2024-11-14
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen
  • Zheng, Steve
  • Hsiang, Cheng

Abstract

A computerized method for utilizing private Internet Protocol (IP) addressing for communications between components of one or more public cloud networks. The method features determining whether outbound traffic corresponds to a first type of outbound traffic being forwarded from a cloud instance supported by the gateway. In response to determining that the first type of outbound traffic is being forwarded from the cloud instance, the first type of outbound traffic is directed via a data interface of the gateway. Also, the method features determining whether the outbound traffic corresponds to a second type of outbound traffic being initiated by logic within the gateway. In response to determining that the second type of outbound traffic is being initiated by logic within the gateway, directing the second type of outbound traffic via a management interface of the gateway.

IPC Classes  ?

7.

AVIATRIX CLOUD NETWORK SECURITY PLATFORM-AS-A-SERVICE

      
Serial Number 98851912
Status Pending
Filing Date 2024-11-13
Owner Aviatrix Systems, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing; Providing temporary use of nondownloadable software for public, private or hybrid cloud networks for enterprise-grade connection to, within and between clouds and enterprise applications; Providing temporary use of on-line nondownloadable software for monitoring and managing API traffic across private, public and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of hosting virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid on premise private cloud and public cloud environments; Infrastructure as a service (IaaS), namely, hosting software for infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenter, cloud and edge environments and applications; providing temporary use of on-line non-downloadable cloud computing software in combination with data science, machine learning (ML) and artificial intelligence (AI) for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing

8.

AVIATRIX PAAS

      
Serial Number 98851958
Status Pending
Filing Date 2024-11-13
Owner Aviatrix Systems, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing; Providing temporary use of nondownloadable software for public, private or hybrid cloud networks for enterprise-grade connection to, within and between clouds and enterprise applications; Providing temporary use of online nondownloadable software for monitoring and managing API traffic across private, public and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of hosting virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid on premise private cloud and public cloud environments; Infrastructure as a service (IaaS), namely, hosting software for infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenter, cloud and edge environments and applications; providing temporary use of on-line non-downloadable cloud computing software in combination with data science, machine learning (ML) and artificial intelligence (AI) for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing

9.

AVIATRIX CLOUD NETWORK SECURITY PLATFORM

      
Serial Number 98851882
Status Pending
Filing Date 2024-11-13
Owner Aviatrix Systems, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing; Providing temporary use of non-downloadable software for public, private or hybrid cloud networks for enterprise-grade connection to, within and between clouds and enterprise applications; Providing temporary use of on-line non-downloadable software for monitoring and managing API traffic across private, public and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of hosting virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid on premise private cloud and public cloud environments; Infrastructure as a service (IaaS), namely, hosting software for infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenter, cloud and edge environments and applications; providing temporary use of on-line non-downloadable cloud computing software in combination with data science, machine learning (ML) and artificial intelligence (AI) for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing

10.

Systems and methods for monitoring of a network topology through graphical user interfaces

      
Application Number 17880523
Grant Number 12143279
Status In Force
Filing Date 2022-08-03
First Publication Date 2024-11-12
Grant Date 2024-11-12
Owner Aviatrix Systems, Inc. (USA)
Inventor Jegarajan, Brighton Vino

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic that, upon execution by one or more processors, causes performance of operations including: obtaining metadata pertaining to each of the first gateway and the second gateway, obtaining network data, wherein a combination of the metadata and the network data identify each of a plurality of constructs, the communication paths between each construct, and in which cloud computing network each construct is deployed, generating an elliptical layout of a network topology graph illustrating a first segment including the first gateway representing deployment in the first cloud network and a second segment including the second gateway representing deployment in the second cloud computing network, and causing rendering of the visualization on a network device display screen.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/0864 - Round trip delays

11.

GLOBAL MULTI-CLOUD OVERLAY NETWORK WITH REGIONAL PREFERENCE

      
Application Number 18738861
Status Pending
Filing Date 2024-06-10
First Publication Date 2024-10-03
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Delecroix, Nicholas
  • Konda, Praveen

Abstract

A computerized method for avoiding cross-region communications when utilizing a cloud overlay network is described. The method involves an operation of deploying one or more spoke gateways within at least a first region and a second region of a first virtual private cloud network. Thereafter, a region and a virtual private cloud network associated with a source and a destination of a communication are determined. Upon determining that the destination of the communication resides within a second virtual private cloud network, which is different than the first virtual private cloud network, the routing of the communication between the source and the destination is controlled by one or more spoke gateways solely residing within the region in which the source.

IPC Classes  ?

  • H04L 45/76 - Routing in software-defined topologies, e.g. routing between virtual machines

12.

Ingress gateway with data flow classification functionality

      
Application Number 17727884
Grant Number 12088503
Status In Force
Filing Date 2022-04-25
First Publication Date 2024-09-10
Grant Date 2024-09-10
Owner Aviatrix Systems, Inc. (USA)
Inventor Lenglet, Romain

Abstract

A computerized method for providing network policy-based routing of a data flow is described. After obtaining attributes associated with an incoming data flow, a first gateway is configured to determine one or more network policies based on the attributes associated with the incoming data flow and assign a classification identifier based on the one or more network policies. The classification identifier is configured to influence routing paths through at least one cloud network, where the classification identifier is encapsulated into content of the incoming data flow to generate a classified data flow for routing from a source to a destination through the at least one cloud network.

IPC Classes  ?

  • H04L 47/2441 - Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 45/00 - Routing or path finding of packets in data switching networks

13.

Systems and methods for firewall deployment in a transit virtual private cloud network deployed in a cloud computing environment

      
Application Number 17216628
Grant Number 12088557
Status In Force
Filing Date 2021-03-29
First Publication Date 2024-09-10
Grant Date 2024-09-10
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

A distributed cloud computing system is statistics logic a controller configured to deploy a first gateway in a spoke virtual private cloud network (VPC) and a second gateway in a transit VPC, wherein the second gateway is configured to connect to a first firewall instance deployed within the transit VPC. The spoke VPC and the transit VPC are both located within a cloud computing network. The logic, upon execution by one or more processors, causes performance of operations including receiving network traffic by the second gateway from the first gateway, providing the network traffic to the first firewall instance for inspection, and routing the network traffic to a destination VPC deployed within the cloud computing network. In some embodiments, the first gateway is attached to a first interface of the second gateway and the first firewall instance is connected to a second interface.

IPC Classes  ?

  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • G06F 9/48 - Program initiatingProgram switching, e.g. by interrupt
  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • H04L 9/40 - Network security protocols
  • H04L 12/26 - Monitoring arrangements; Testing arrangements
  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
  • H04L 12/46 - Interconnection of networks
  • H04L 15/16 - Apparatus or circuits at the transmitting end with keyboard co-operating with code discs
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

14.

Display screen of a network device with graphical user interface

      
Application Number 29848600
Grant Number D1040169
Status In Force
Filing Date 2022-08-03
First Publication Date 2024-08-27
Grant Date 2024-08-27
Owner Aviatrix Systems, Inc. (USA)
Inventor Jegarajan, Brighton Vino

15.

System and method for enabling communication between networks with overlapping IP address ranges

      
Application Number 17504481
Grant Number 12058094
Status In Force
Filing Date 2021-10-18
First Publication Date 2024-08-06
Grant Date 2024-08-06
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Manglik, Pankaj
  • Kishen, Sunil

Abstract

A method is described that enables communication between two disjoined networks with overlapping IP address ranges. The method features receiving a first address mapping query message from a first intermediary device and returning a first private IP address map. The first private IP address map includes at least a first plurality of private IP addresses each uniquely assigned to a computing device residing in the first network. In response to a triggering event, recovering a second private IP address map by a second intermediary device. Herein, the second private IP address map includes at least a second plurality of private IP addresses each uniquely assigned to a computing device residing in the second network. Thereafter, the source IP address for a private IP address associated with the computing device is substituted prior to transmission of a message from the first intermediary device to the second intermediary device upon determining that the first network and the second network include overlapping private IP address ranges.

IPC Classes  ?

  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
  • H04L 45/586 - Association of routers of virtual routers
  • H04L 45/745 - Address table lookupAddress filtering
  • H04L 61/106 - Mapping addresses of different types across networks, e.g. mapping telephone numbers to data network addresses
  • H04L 61/4535 - Network directoriesName-to-address mapping using an address exchange platform which sets up a session between two nodes, e.g. rendezvous servers, session initiation protocols [SIP] registrars or H.323 gatekeepers

16.

SYSTEM FOR SCALING NETWORK ADDRESS TRANSLATION (NAT) AND FIREWALL FUNCTIONS

      
Application Number 18628800
Status Pending
Filing Date 2024-04-08
First Publication Date 2024-07-25
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network device may be adapted to operate within a virtual private cloud where network address translation (NAT) is performed through virtual machines and each network address translation is handled differently by a different NAT control logic unit. The network device features one or more hardware processors, and a memory that stores at least a plurality of network address translation (NAT) control logic unit and demultiplexer logic. The demultiplexer logic, when executed, receives an incoming message and, based at least in part on information within the incoming message, determines a selected NAT control logic unit to receive at least a portion of the information within the incoming message. The selected NAT control logic unit handles address translation for routing of a message based on the incoming message to a public network.

IPC Classes  ?

17.

Management network and method of operation

      
Application Number 17396630
Grant Number 12047280
Status In Force
Filing Date 2021-08-06
First Publication Date 2024-07-23
Grant Date 2024-07-23
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen
  • Zheng, Steve
  • Hsiang, Cheng

Abstract

A computerized method for utilizing private Internet Protocol (IP) addressing for communications between components of one or more public cloud networks. The method features determining whether outbound traffic corresponds to a first type of outbound traffic being forwarded from a cloud instance supported by the gateway. In response to determining that the first type of outbound traffic is being forwarded from the cloud instance, the first type of outbound traffic is directed via a data interface of the gateway. Also, the method features determining whether the outbound traffic corresponds to a second type of outbound traffic being initiated by logic within the gateway. In response to determining that the second type of outbound traffic is being initiated by logic within the gateway, directing the second type of outbound traffic via a management interface of the gateway.

IPC Classes  ?

  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 45/02 - Topology update or discovery
  • H04L 45/302 - Route determination based on requested QoS
  • H04L 61/5007 - Internet protocol [IP] addresses

18.

SYSTEM AND METHOD FOR RESTRICTING COMMUNICATIONS BETWEEN VIRTUAL PRIVATE CLOUD NETWORKS THROUGH SECURITY DOMAINS

      
Application Number 18616156
Status Pending
Filing Date 2024-03-25
First Publication Date 2024-07-11
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

A computerized method for restricting communications between virtual private cloud networks comprises creating a plurality of security domains. Each of the plurality of security domains identifies gateways associated with one or more virtual private cloud networks. Also, the method features generating transit routing data stores in accordance with each of the plurality of security domains; determining whether a connection policy exists between at least a first security domain and a second security domain of the plurality of security domains; and precluding communications between gateways associated with the first security domain and gateways associated with the second security domain in response to determining that no connection policy exists between the first security domain and the second security domain.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 3/0482 - Interaction with lists of selectable items, e.g. menus
  • H04L 12/46 - Interconnection of networks
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

19.

SYSTEM AND METHOD FOR SEGMENTING TRANSIT CAPABILITIES WITHIN A MULTI-CLOUD ARCHITECTURE

      
Application Number 18587387
Status Pending
Filing Date 2024-02-26
First Publication Date 2024-06-20
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

In one embodiment, a computing platform features a controller, one or more transit virtual private cloud networks (VPCs), and a plurality of spoke VPCs. Communicatively coupled to the transit virtual VPCs, the spoke VPCs include (i) a first spoke VPC associated with a first security region and (ii) a second spoke VPC associated with a second security region. Herein, the first security region is configured to permit spoke gateways of the first spoke VPC to communicate with each other while precluding communications with spoke gateways associated with another security region absent a connectivity policy being a set of rules established by the administrator/user of the network concerning permitted connectivity between different security regions.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

20.

Global multi-cloud overlay network with regional preference

      
Application Number 17900858
Grant Number 12010022
Status In Force
Filing Date 2022-08-31
First Publication Date 2024-06-11
Grant Date 2024-06-11
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Delecroix, Nicholas
  • Konda, Praveen

Abstract

A computerized method for avoiding cross-region communications when utilizing a cloud overlay network is described. The method involves an operation of deploying one or more spoke gateways within at least a first region and a second region of a first virtual private cloud network. Thereafter, a region and a virtual private cloud network associated with a source and a destination of a communication are determined. Upon determining that the destination of the communication resides within a second virtual private cloud network, which is different than the first virtual private cloud network, the routing of the communication between the source and the destination is controlled by one or more spoke gateways solely residing within the region in which the source.

IPC Classes  ?

  • G06F 15/173 - Interprocessor communication using an interconnection network, e.g. matrix, shuffle, pyramid, star or snowflake
  • H04L 45/76 - Routing in software-defined topologies, e.g. routing between virtual machines

21.

SYSTEMS AND METHODS FOR VIRTUAL PRIVATE NETWORK AUTHENTICATION

      
Application Number 18399698
Status Pending
Filing Date 2023-12-29
First Publication Date 2024-05-30
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sreekumar, Arvind
  • Kunnath, Ramakrishnan
  • Wei, Xiaobo Sherry

Abstract

A computerized method for establishing a secure channel between a virtual private network (VPN) client processing on a network device for a user and a network gateway is disclosed. The computerized method includes operations of the controller of transmitting an authentication request to an identity provider based on receipt of a resource request from the VPN client, receiving an authentication response from the identity provider, generating an authentication token based on the authentication response and transmitting the authentication token to the VPN client, wherein the controller further stores the authentication token. The method includes operations of the network gateway of receiving a secure connection request from the VPN client that includes the authentication token, validating the authentication token by querying the controller, in response to validation of the authentication token, establishing the secure connection with VPN client, and providing the VPN client with access to resources via the secure connection.

IPC Classes  ?

22.

SYSTEMS AND METHODS FOR TRANSIT GATEWAY/TRANSIT SEGMENTATION INTEROPERABILITY

      
Application Number US2023080622
Publication Number 2024/108232
Status In Force
Filing Date 2023-11-20
Publication Date 2024-05-23
Owner AVIATRIX SYTEMS, INC. (USA)
Inventor
  • Xu, Shanshan
  • Li, Jialiang

Abstract

In some aspects, a system for maintaining segmentation of network traffic includes a first shared service domain comprising a first VPC, a first edge domain comprising a first transit gateway, a second edge domain comprising a second transit gateway communicatively coupled to the first transit gateway, and a second shared service domain comprising a second VPC. A first gateway connects the first shared service domain and the first edge domain, and a second gateway connects the second edge domain and the second shared service domain.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 69/166 - IP fragmentationTCP segmentation
  • H04L 67/141 - Setup of application sessions
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 67/104 - Peer-to-peer [P2P] networks

23.

SYSTEM AND METHOD FOR RESTRICTING COMMUNICATIONS BETWEEN VIRTUAL PRIVATE CLOUD NETWORKS THROUGH CENTRALIZED TRANSIT ARCHITECTURES

      
Application Number US2023080620
Publication Number 2024/108230
Status In Force
Filing Date 2023-11-20
Publication Date 2024-05-23
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Xu, Shanshan
  • Xu, Wanjing
  • Guo, Ruomiao

Abstract

A two-tier firewall system includes a primary' and a secondary firewall gateway. The primary firewall gateway includes at least one spoke and a plurality of firewalls communicatively coupled to the at least one spoke. The secondary firewall gateway includes at least one spoke. The secondary firewall gateway is communicatively coupled to the primary firewall gateway.

IPC Classes  ?

  • H04W 12/088 - Access security using filters or firewalls
  • H04L 9/40 - Network security protocols
  • H04L 65/102 - Gateways
  • H04L 41/08 - Configuration management of networks or network elements
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

24.

SYSTEM AND METHOD FOR ZERO TRUST ORCHESTRATION OF AN EDGE GATEWAY WITHIN A CLOUD OR MULTI-CLOUD NETWORK

      
Application Number 17985819
Status Pending
Filing Date 2022-11-12
First Publication Date 2024-05-16
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Gunturu, Purnima
  • Vannarath, Praveen

Abstract

An edge gateway deployed within an overlay network interconnecting a first public cloud network with an on-premises network is described. Coupled to a controller, the edge gateway is configured to receive a configuration file and attestation data from a controller, analyze the configuration file to obtain at least a first network address being used as an interface for secure communications with the controller, establish a secure interconnect with the controller based on the attestation data, and conduct a provisioning operation to initiate a request to the controller for edge gateway software thereby automated provisioning the edge gateway without human intervention. The edge gateway experiences automated provisioning based on a configuration file and attestation data upload.

IPC Classes  ?

  • H04L 41/0803 - Configuration setting
  • H04L 12/46 - Interconnection of networks
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

25.

SYSTEM AND METHOD FOR ZERO TRUST ORCHESTRATION OF AN EDGE GATEWAY WITHIN A CLOUD OR MULTI-CLOUD NETWORK

      
Application Number US2023037182
Publication Number 2024/102488
Status In Force
Filing Date 2023-11-13
Publication Date 2024-05-16
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Gunturu, Purnima
  • Vannarath, Praveen

Abstract

An edge gateway deployed within an overlay network interconnecting a first public cloud network with an on-premises network is described. Coupled to a controller, the edge gateway is configured to receive a configuration file and attestation data from a controller, analyze the configuration file to obtain at least a first network address being used as an interface for secure communications with the controller, establish a secure interconnect with the controller based on the attestation data, and conduct a provisioning operation to initiate a request to the controller for edge gateway software thereby automated provisioning the edge gateway without human intervention. The edge gateway experiences automated provisioning based on a configuration file and attestation data upload.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

26.

SYSTEMS AND METHODS FOR AUTOMATIC AND MANUAL GATEWAY SCALING

      
Application Number US2023036779
Publication Number 2024/097400
Status In Force
Filing Date 2023-11-03
Publication Date 2024-05-10
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Zhao, Yue
  • Lynch, Ryan
  • Chen, Tony
  • Jegarajan, Brighton, Vino
  • Juen, Joshua
  • Sun, Albert

Abstract

In an embodiment, the present disclosure pertains to a method for creating a policy. In general, the method includes: (1) displaying a user interface to a user; (2) receiving, from the user, a policy type; (3) receiving a selection of at least one resource within a network; (4) receiving a resource operating parameter relative to the at least one resource within the network; (5) displaying previous data based, at least in part, on the resource operating parameter relative to the at least one resource responsive to a query by the user; (6) determining a recommended operation based, at least in part, on the previous data; and (7) displaying the recommended operation to the user via the user interface.

IPC Classes  ?

  • H04L 41/08 - Configuration management of networks or network elements
  • G06F 15/173 - Interprocessor communication using an interconnection network, e.g. matrix, shuffle, pyramid, star or snowflake
  • H04L 12/46 - Interconnection of networks
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 67/00 - Network arrangements or protocols for supporting network services or applications

27.

SYSTEMS AND METHODS FOR AUTONOMOUS NETWORK SCALING USING ARTIFICIAL INTELLIGENCE

      
Application Number US2023036783
Publication Number 2024/097402
Status In Force
Filing Date 2023-11-03
Publication Date 2024-05-10
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Ali, Shahzad
  • Alam, Hammad
  • Mirza, Saad
  • Mustafa, Nauman

Abstract

In an embodiment, the present disclosure pertains to method for autonomous network scaling. In general, the method includes; (1) monitoring at least one resource within a network; (2) determining an operational load of the at least one resource; (3) comparing the operation load to a resource operating parameter of the at least one resource; determining a recommended operation based, at least in part, on the comparison of the operational load to the resource operating parameter of the at least one resource; and (4) modifying network topology of the network by performing at least one action including, but not limited to, adding or removing an additional resource response to the determining of the recommended operation. In some embodiments, the network includes a plurality of resources.

IPC Classes  ?

  • H04L 12/54 - Store-and-forward switching systems
  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
  • H04L 12/40 - Bus networks

28.

SYSTEMS AND METHODS FOR LOAD BALANCING NETWORK TRAFFIC AT FIREWALLS DEPLOYED IN A CLOUD COMPUTING ENVIRONMENT

      
Application Number 18536225
Status Pending
Filing Date 2023-12-11
First Publication Date 2024-04-18
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Cheung, Lee-Chik
  • Wei, Xiaobo Sherry
  • Xu, Shanshan
  • Vannarath, Praveen

Abstract

A computerized method for directing transmission of a data packet within a distributed cloud computing system is disclosed. The computerized method includes operations of receiving, by a receiving gateway instance deployed within the distributed cloud computing system, the data packet, when a session corresponding to the data packet is found via a session lookup, forwarding the data packet to a destination in accordance with the session lookup, and when the session is not found via the session lookup, creating a tentative forward session and forwarding the data packet to a peer gateway instance. In some instances, the data packet is a User Datagram Protocol (UDP) packet. In some instances, the data packet is received from either of a spoke gateway instance or a transit gateway instance, and wherein the spoke gateway instance or the transit gateway instance is deployed within the distributed cloud computing system.

IPC Classes  ?

  • H04L 45/74 - Address processing for routing
  • H04L 9/40 - Network security protocols
  • H04L 12/46 - Interconnection of networks
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

29.

SYSTEMS AND METHODS FOR IMPROVED MONITORING OF A NETWORK TOPOLOGY AND CORRESPONDING USER INTERFACES

      
Application Number US2023034494
Publication Number 2024/076651
Status In Force
Filing Date 2023-10-04
Publication Date 2024-04-11
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Jegarajan, Brighton, Vino
  • Malyala, Arno, Lenin
  • Wu, Joshua
  • Sundarrajan, Shiva
  • Luo, Henry
  • Hu, Michael
  • Cridlebaugh, Josh
  • Crimmins, Ken
  • Kariyanahalli, Praveen, Raju
  • Nguyen, Khanh

Abstract

A distributed cloud computing system is disclosed that includes a. controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network. The system includes logic stored on non-transitory, computer-medium, that, upon execution by one or more processors, causes performance of operations including: receiving, from a controller, metadata pertaining to a plurality of constructs; receiving, from each of the first gateway and the second gateway, network data, wherein a combination of the metadata and the network data identify each of the plurality' of constructs and in which cloud computing network each construct is deployed: generating a visualization illustrating a cost analysis of at least one construct of the plurality of constructs, and causing rendering of the visualization on a display' screen of a network device.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 67/75 - Indicating network or usage conditions on the user display
  • H04L 41/0826 - Configuration setting characterised by the purposes of a change of settings, e.g. optimising configuration for enhancing reliability for reduction of network costs
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 43/20 - Arrangements for monitoring or testing data switching networks the monitoring system or the monitored elements being virtualised, abstracted or software-defined entities, e.g. SDN or NFV

30.

System for scaling network address translation (NAT) and firewall functions

      
Application Number 17941625
Grant Number 11956100
Status In Force
Filing Date 2022-09-09
First Publication Date 2024-04-09
Grant Date 2024-04-09
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network device may be adapted to operate within a virtual private cloud where network address translation (NAT) is performed through virtual machines and each network address translation is handled differently by a different NAT control logic unit. The network device features one or more hardware processors, and a memory that stores at least a plurality of network address translation (NAT) control logic unit and demultiplexer logic. The demuliplexer logic, when executed, receives an incoming message and, based at least in part on information within the incoming message, determines a selected NAT control logic unit to receive at least a portion of the information within the incoming message. The selected NAT control logic unit handles address translation for routing of a message based on the incoming message to a public network.

IPC Classes  ?

31.

System and method for restricting communications between virtual private cloud networks through security domains

      
Application Number 17368689
Grant Number 11943223
Status In Force
Filing Date 2021-07-06
First Publication Date 2024-03-26
Grant Date 2024-03-26
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

A computerized method for restricting communications between virtual private cloud networks comprises creating a plurality of security domains. Each of the plurality of security domains identifies gateways associated with one or more virtual private cloud networks. Also, the method features generating transit routing data stores in accordance with each of the plurality of security domains; determining whether a connection policy exists between at least a first security domain and a second security domain of the plurality of security domains; and precluding communications between gateways associated with the first security domain and gateways associated with the second security domain in response to determining that no connection policy exists between the first security domain and the second security domain.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 3/0482 - Interaction with lists of selectable items, e.g. menus
  • H04L 12/46 - Interconnection of networks
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

32.

SYSTEM AND METHOD FOR AUTOMATIC APPLIANCE CONFIGURATION AND OPERABILITY

      
Application Number 18515242
Status Pending
Filing Date 2023-11-20
First Publication Date 2024-03-14
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Vannarath, Praveen
  • Chung, Wing-Kuen

Abstract

In one embodiment, a cloud connection appliance features a processor and a non-transitory storage medium. The non-transitory storage medium comprises management control logic, that when executed by the processor, controls registration with a controller adapted to control data traffic between gateway instance and to establish a communication path including a reverse tunnel with the controller. The controller and cloud connection appliance operate in a client-server relationship with the cloud connection appliance operates as a client when establishing the communication path and operates as a server when receiving control information through the reverse tunnel. The reverse tunnel enables the cloud connection appliance to directly receive the control information from the controller despite the cloud connection application lacking a publicly routable Internet Protocol (IP) address.

IPC Classes  ?

  • H04L 45/74 - Address processing for routing
  • H04L 9/40 - Network security protocols
  • H04L 12/46 - Interconnection of networks
  • H04L 67/025 - Protocols based on web technology, e.g. hypertext transfer protocol [HTTP] for remote control or remote monitoring of applications
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 67/141 - Setup of application sessions
  • H04L 69/00 - Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass

33.

CONTROLLER FOR COORDINATING FLOW SEPARATION OF INTRA-VPC OR INTER-VPC COMMUNICATIONS

      
Application Number US2023031540
Publication Number 2024/049905
Status In Force
Filing Date 2023-08-30
Publication Date 2024-03-07
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Anandakrishnan, Geetha
  • Hinrichs, Susan
  • Meiyyappan, Narayanan
  • Vemuri, Sai, Kartikeya
  • Yan, Li
  • Jog, Mandar

Abstract

A system and method for controlling the handling of intra- VPC and inter- VPC communications is described. First, a destination of a communication is determined it resides within a first virtual private cloud network (VPC) of a source of the communication. If so, filtering communications between the destination and the source is controlled by native cloud constructs associated with a cloud service provider (CSP) underlay network for the first public cloud network. Otherwise, filtering communication between the destination and the source is controlled by a spoke gateway. The spoke gateway is part of a cloud overlay network configured to provide a communication path between the first virtual private cloud network and the second private cloud network.

IPC Classes  ?

34.

System and method for segmenting transit capabilities within a multi-cloud architecture

      
Application Number 17368685
Grant Number 11916883
Status In Force
Filing Date 2021-07-06
First Publication Date 2024-02-27
Grant Date 2024-02-27
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

In one embodiment, a computing platform features a controller, one or more transit virtual private cloud networks (VPCs), and a plurality of spoke VPCs. Communicatively coupled to the transit virtual VPCs, the spoke VPCs include (i) a first spoke VPC associated with a first security region and (ii) a second spoke VPC associated with a second security region. Herein, the first security region is configured to permit spoke gateways of the first spoke VPC to communicate with each other while precluding communications with spoke gateways associated with another security region absent a connectivity policy being a set of rules established by the administrator/user of the network concerning permitted connectivity between different security regions.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

35.

System and method for secure data transfer

      
Application Number 18378147
Grant Number 12192177
Status In Force
Filing Date 2023-10-10
First Publication Date 2024-02-08
Grant Date 2025-01-07
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Kunnath, Ramakrishnan
  • Sreekumar, Arvind

Abstract

In one embodiment, a secure exchange system is described. The secure exchange system includes a virtual private cloud network and a controller. The virtual private cloud network includes a plurality of gateways, each gateway of the plurality of gateways is configured to generate one or more local directories. Each local directory of the one or more local directories representing one or more stored objects within a public cloud storage element. The controller is configured to authenticate a user prior to granting the user access to the virtual private cloud network. The gateways are accessible by the user over AWS Direct Connect, where the public cloud storage element is a S3 bucket.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • H04L 12/46 - Interconnection of networks
  • H04L 67/1001 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
  • H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
  • H04L 67/50 - Network services
  • H04L 67/51 - Discovery or management thereof, e.g. service location protocol [SLP] or web services

36.

SYSTEMS AND METHODS FOR MONITORING OF A NETWORK TOPOLOGY THROUGH GRAPHICAL USER INTERFACES

      
Application Number US2023029170
Publication Number 2024/030403
Status In Force
Filing Date 2023-08-01
Publication Date 2024-02-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Jegarajan, Brighton, Vino

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic that, upon execution by one or more processors, causes performance of operations including: obtaining metadata pertaining to each of the first gateway and the second gateway, obtaining network data, wherein a combination of the metadata and the network data identify each of a plurality of constructs, the communication paths between each construct, and in which cloud computing network each construct is deployed, generating an elliptical layout of a network topology graph illustrating a first segment including the first gateway representing deployment in the first cloud network and a second segment including the second gateway representing deployment in the second cloud computing network, and causing rendering of the visualization on a network device display screen.

IPC Classes  ?

  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

37.

SYSTEMS AND METHODS FOR GENERATION OF A NETWORK TOPOLOGY AND CORRESPONDING USER INTERFACES

      
Application Number US2023029448
Publication Number 2024/030589
Status In Force
Filing Date 2023-08-03
Publication Date 2024-02-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Jegarajan, Brighton, Vino

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic that, upon execution by one or more processors, causes performance of operations including: obtaining metadata pertaining to each of the first gateway and the second gateway, obtaining network data, wherein a combination of the metadata and the network data identify each of a plurality of constructs, the communication paths between each construct, and in which cloud computing network each construct is deployed, generating an elliptical layout of a network topology graph illustrating a first segment including the first gateway representing deployment in the first cloud network and a second segment including the second gateway representing deployment in the second cloud computing network, and causing rendering of the visualization on a network device display screen.

IPC Classes  ?

  • G06F 3/04847 - Interaction techniques to control parameter settings, e.g. interaction with sliders or dials
  • G06F 8/60 - Software deployment
  • G06F 8/75 - Structural analysis for program understanding
  • H04L 41/122 - Discovery or management of network topologies of virtualised topologies e.g. software-defined networks [SDN] or network function virtualisation [NFV]
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/065 - Generation of reports related to network devices
  • H04L 45/02 - Topology update or discovery
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • G06F 3/04842 - Selection of displayed objects or displayed text elements
  • G06F 8/71 - Version control Configuration management
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/0266 - Exchanging or transporting network management information using the InternetEmbedding network management web servers in network elementsWeb-services-based protocols using meta-data, objects or commands for formatting management information, e.g. using eXtensible markup language [XML]
  • H04L 41/082 - Configuration setting characterised by the conditions triggering a change of settings the condition being updates or upgrades of network functionality
  • H04L 41/0853 - Retrieval of network configurationTracking network configuration history by actively collecting configuration information or by backing up configuration information

38.

System and method for selecting virtual appliances in communications with virtual private cloud networks

      
Application Number 18380648
Grant Number 12113767
Status In Force
Filing Date 2023-10-16
First Publication Date 2024-02-08
Grant Date 2024-10-08
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

A method for facilitating communications between client devices in geographically separated networks is described. First, message monitoring is conducted by each of a plurality of virtual appliances within a local network to detect a message of a first message type. Responsive to failing to locate a Media Access Control (MAC) address of a destination for the message within a prescribed table by a default gateway, one of the plurality of virtual appliances is selected for handling a forwarding of the message to a plurality of remote networks, and the message via the selected virtual appliance is forwarded to a plurality of gateways associated with a plurality of remote networks. Responsive to locating the MAC address of the destination within the table, the virtual appliance previously handling communications with the destination to forward the message to the destination.

IPC Classes  ?

  • H04L 61/103 - Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
  • H04L 12/64 - Hybrid switching systems
  • H04L 101/622 - Layer-2 addresses, e.g. medium access control [MAC] addresses

39.

SYSTEMS AND METHODS FOR IMPROVED MONITORING FEATURES FOR OF A NETWORK TOPOLOGY AND CORRESPONDING USER INTERFACES

      
Application Number US2023029447
Publication Number 2024/030588
Status In Force
Filing Date 2023-08-03
Publication Date 2024-02-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Jegarajan, Brighton, Vino
  • Malyala, Arno, Lenin
  • Wu, Joshua
  • Sundarrajan, Shiva
  • Luo, Henry
  • Hu, Michael
  • Cridlebaugh, Josh
  • Crimmins, Ken
  • Kariyanahalli, Praveen, Raju
  • Nguyen, Khanh

Abstract

A distributed cloud computing system includes a controller configured to (i) deploy and manage a first gateway in a first cloud computing network and a second gateway in a second cloud computing network, and (ii) manage a plurality of constructs; and logic, stored on non- transitory, computer-readable medium, that, upon execution by one or more processors, causes performance of operations. The operations include: receiving, from each of the first gateway and the second gateway, network data, generating an expected network traffic based upon the network data, generating a visualization illustrating an anomaly that deviates from the expected network traffic, and causing rendering of the visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

40.

SYSTEMS AND METHODS FOR GENERATION OF A NETWORK TOPOLOGY AND CORRESPONDING USER INTERFACES

      
Application Number CN2022110059
Publication Number 2024/026745
Status In Force
Filing Date 2022-08-03
Publication Date 2024-02-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Jegarajan, Brighton Vino
  • Chen, Yi Tung
  • Lu, Wei-Hsu
  • Wen, Tzung Han
  • Hu, Michael

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy network constructs including any of transit gateways, spoke gateways, subnets, or private networks and logic that, upon execution by one or more processors, causes performance of operations including: causing rendering of a graphical user interface that includes a display panel configured to display progress of a build process for a network topology graph, receiving first user input through the graphical user interface indicating selection of a first cloud service provider, a first access account, and a first cloud region, receiving second user input through the graphical user interface indicating selection of one or more of the network constructs to be deployed in the first cloud region, instructing the controller to deploy the one or more of the network constructs in the first cloud region according to the first user input and the second user input.

IPC Classes  ?

  • H04L 41/0895 - Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements
  • H04L 41/122 - Discovery or management of network topologies of virtualised topologies e.g. software-defined networks [SDN] or network function virtualisation [NFV]
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

41.

Multi-cloud active mesh network system and method

      
Application Number 18378145
Grant Number 12177294
Status In Force
Filing Date 2023-10-09
First Publication Date 2024-02-01
Grant Date 2024-12-24
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sun, Yixin
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network system features a first virtual private cloud (VPC) network and a second VPC network. The first VPC network includes a first plurality of gateways. Each gateway of the first plurality of gateways is in communications with other gateways. Similarly, a second VPC network includes a second plurality of gateways. Each of the second plurality of gateways is communicatively coupled to the each of the first plurality of gateways to support data exchanges between resources deployed in different public cloud networks.

IPC Classes  ?

42.

Systems and methods for virtual private network authentication

      
Application Number 17307885
Grant Number 11863530
Status In Force
Filing Date 2021-05-04
First Publication Date 2024-01-02
Grant Date 2024-01-02
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sreekumar, Arvind
  • Kunnath, Ramkrishnan
  • Wei, Xiaobo Sherry

Abstract

A computerized method for establishing a secure channel between a virtual private network (VPN) client processing on a network device for a user and a network gateway is disclosed. The computerized method includes operations of the controller of transmitting an authentication request to an identity provider based on receipt of a resource request from the VPN client, receiving an authentication response from the identity provider, generating an authentication token based on the authentication response and transmitting the authentication token to the VPN client, wherein the controller further stores the authentication token. The method includes operations of the network gateway of receiving a secure connection request from the VPN client that includes the authentication token, validating the authentication token by querying the controller, in response to validation of the authentication token, establishing the secure connection with VPN client, and providing the VPN client with access to resources via the secure connection.

IPC Classes  ?

  • H04L 29/00 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups
  • H04L 9/40 - Network security protocols

43.

Systems and methods for load balancing network traffic at firewalls deployed in a cloud computing environment

      
Application Number 17216601
Grant Number 11855896
Status In Force
Filing Date 2021-03-29
First Publication Date 2023-12-26
Grant Date 2023-12-26
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Cheung, Lee-Chik
  • Wei, Xiaobo Sherry
  • Xu, Shanshan
  • Vannarath, Praveen

Abstract

A computerized method for directing transmission of a data packet within a distributed cloud computing system is disclosed that includes receiving the data packet by a receiving gateway instance deployed within the distributed cloud computing system, when a session corresponding to the data packet is found via a session lookup, forwarding the data packet to a destination in accordance with the session lookup, when the session is not found via the session lookup, determining whether one least one peer firewall instance is available, and when a first peer firewall instance is available and the data packet is a synchronize packet, forwarding the data packet to the first peer firewall instance. In some instances, the data packet is a TCP packet and in others, the data packet is received from either of a spoke gateway or a transit gateway that is deployed within the distributed cloud computing system.

IPC Classes  ?

  • H04L 47/125 - Avoiding congestionRecovering from congestion by balancing the load, e.g. traffic engineering
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 12/46 - Interconnection of networks
  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

44.

System and method for non-disruptive migration of software components to a public cloud system

      
Application Number 18231224
Grant Number 12192279
Status In Force
Filing Date 2023-08-07
First Publication Date 2023-12-21
Grant Date 2025-01-07
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

A system supporting transferring content between an on-premises network and a public cloud network includes a first cloud computing platform comprising a first software instance having a first IP address, a subnet configured to extend across on-premises network and a public cloud network, a first gateway associated with the on-premises network, a second gateway associate with the public cloud network, a secure communication path between the first and second gateways. The subnet comprises a shared IP address range between the public cloud network and the on-premises network, and the first IP address of the first software instance is the same as an IP address of the first software instance that resided on the on-premises network.

IPC Classes  ?

  • H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
  • H04L 61/5007 - Internet protocol [IP] addresses
  • H04L 101/622 - Layer-2 addresses, e.g. medium access control [MAC] addresses

45.

HIGH-PERFORMANCE COMMUNICATION LINK AND METHOD OF OPERATION

      
Application Number US2023025643
Publication Number 2023/244853
Status In Force
Filing Date 2023-06-17
Publication Date 2023-12-21
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Sundarrajan, Shiva
  • Kariyanahalli, Praveen, Raju
  • Terentyev, Andrey
  • Vannarath, Praveen

Abstract

Embodiments of the disclosure relate to a secure, high-performance communication link that relies on single network, multiple logical port addressing. Embodiments of an infrastructure are associated with a high-performance communication link that allows for distribution of network traffic across multiple interconnects using a single network address with different logical network port addressing. This high-performance communication link supports data traffic across different processing logic units residing within a destination computing device.

IPC Classes  ?

  • H04L 61/5007 - Internet protocol [IP] addresses
  • H04L 47/125 - Avoiding congestionRecovering from congestion by balancing the load, e.g. traffic engineering
  • H04L 67/2514 -
  • H04L 61/2521 - Translation architectures other than single NAT servers
  • H04L 43/12 - Network monitoring probes
  • H04L 41/0893 - Assignment of logical groups to network elements

46.

System and method for determination of network operation metrics and generation of network operation metrics visualizations

      
Application Number 18231228
Grant Number 12132625
Status In Force
Filing Date 2023-08-07
First Publication Date 2023-12-14
Grant Date 2024-10-29
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A non-transitory storage medium featuring logic to obtain construct metadata and network data spanning multiple cloud networks includes a path determination logic, upon execution by one or more processors, configured to perform operations including: generate a topology mapping including a plurality of constructs and connections between the plurality of constructs extending across a multi-cloud network including a first cloud network and a second cloud network different than the first cloud network; receive user input corresponding to a selection of a source construct operating in the first cloud network and a destination construct operating in the second cloud network; analyze metadata and network data regarding the source construct and the destination construct to determine a data transmission path between the source and destination constructs; and determine a shortest path between the source construct and the destination constructs. An interface generation logic generates a visualization illustrating the data transmission path extending between the source construct and the destination construct.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/122 - Discovery or management of network topologies of virtualised topologies e.g. software-defined networks [SDN] or network function virtualisation [NFV]
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • H04L 61/5007 - Internet protocol [IP] addresses
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

47.

SYSTEM, METHOD AND APPARATUS FOR GENERATING AND SEARCHING A TOPOLOGY OF RESOURCES AMONG MULTIPLE CLOUD COMPUTING ENVIRONMENTS

      
Application Number 18329397
Status Pending
Filing Date 2023-06-05
First Publication Date 2023-12-14
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic, stored on non-transitory, computer-medium. The logic, upon execution by one or more processors, causes performance of operations including: transmitting one or more requests to the controller for metadata of at least the first gateway and the second gateway; receiving, from at least one of the first gateway and the second gateway, network data of the corresponding gateway; generating a visualization illustrating the metadata and the network data, wherein the metadata and the network data pertain to multiple cloud computing networks; and causing rendering of the visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

48.

Systems and methods for load balancing network traffic at firewalls deployed in a cloud computing environment

      
Application Number 17216625
Grant Number 11843539
Status In Force
Filing Date 2021-03-29
First Publication Date 2023-12-12
Grant Date 2023-12-12
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Cheung, Lee-Chik
  • Wei, Xiaobo Sherry
  • Xu, Shanshan
  • Vannarath, Praveen

Abstract

A computerized method for directing transmission of a data packet within a distributed cloud computing system is disclosed. The computerized method includes operations of receiving, by a receiving gateway instance deployed within the distributed cloud computing system, the data packet, when a session corresponding to the data packet is found via a session lookup, forwarding the data packet to a destination in accordance with the session lookup, and when the session is not found via the session lookup, creating a tentative forward session and forwarding the data packet to a peer gateway instance. In some instances, the data packet is a User Datagram Protocol (UDP) packet. In some instances, the data packet is received from either of a spoke gateway instance or a transit gateway instance, and wherein the spoke gateway instance or the transit gateway instance is deployed within the distributed cloud computing system.

IPC Classes  ?

  • H04L 45/74 - Address processing for routing
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 9/40 - Network security protocols
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 12/46 - Interconnection of networks

49.

SYSTEMS AND METHODS FOR IMPROVING PACKET FORWARDING THROUGHPUT FOR ENCAPSULATED TUNNELS

      
Application Number 18228668
Status Pending
Filing Date 2023-07-31
First Publication Date 2023-11-23
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen

Abstract

A computerized method for increasing throughput of encapsulated data over a network is described. First, a determination, at a first network device, of a number of available processing resources located at a second network device is conducted. Thereafter, a plurality of connections are generated between the first network device and the second device. The plurality of connections corresponding in number to the number of available processing resources. Data received by the first network device is associated with a first connection of the plurality of tunneling connections. Thereafter, translation data unique to a tunneling session associated with the first connection is generated and the received data is encapsulated with the translation data to generate the encapsulated data for transmission to the second network device.

IPC Classes  ?

  • H04L 61/2592 - Translation of Internet protocol [IP] addresses using tunnelling or encapsulation
  • H04L 45/125 - Shortest path evaluation based on throughput or bandwidth
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 45/7453 - Address table lookupAddress filtering using hashing
  • H04L 61/5007 - Internet protocol [IP] addresses

50.

SYSTEM AND METHOD FOR DEPLOYING A DISTRIBUTED CLOUD MANAGEMENT SYSTEM CONFIGURED FOR GENERATING INTERACTIVE USER INTERFACES OF THE STATE OF A MULTI-CLOUD ENVIRONMENT OVER TIME

      
Application Number 18200547
Status Pending
Filing Date 2023-05-22
First Publication Date 2023-11-23
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network, and logic. The logic, upon execution by one or more processors, causes performance of operations including receiving, from the controller, metadata pertaining to a plurality of constructs corresponding to a plurality of time instances, receiving, from each of the first and second gateways, network data corresponding to the plurality of time instances, wherein the metadata and the network data identify each of the plurality of constructs, communication paths between each construct, and in which cloud computing network each construct is deployed, generating a visualization illustrating differences between the plurality of constructs and communication paths at the first time instance and at the second time instance, and causing rendering of the visualization on a display screen.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

51.

System and method for automatic appliance configuration and operability

      
Application Number 17332990
Grant Number 11824777
Status In Force
Filing Date 2021-05-27
First Publication Date 2023-11-21
Grant Date 2023-11-21
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Vannarath, Praveen
  • Chung, Wing-Kuen

Abstract

In one embodiment, a cloud connection appliance features a processor and a non-transitory storage medium. The non-transitory storage medium comprises management control logic, that when executed by the processor, controls registration with a controller adapted to control data traffic between gateway instance and to establish a communication path including a reverse tunnel with the controller. The controller and cloud connection appliance operate in a client-server relationship with the cloud connection appliance operates as a client when establishing the communication path and operates as a server when receiving control information through the reverse tunnel. The reverse tunnel enables the cloud connection appliance to directly receive the control information from the controller despite the cloud connection application lacking a publicly routable Internet Protocol (IP) address.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 45/74 - Address processing for routing
  • H04L 69/00 - Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
  • H04L 12/46 - Interconnection of networks
  • H04L 9/40 - Network security protocols
  • H04L 67/025 - Protocols based on web technology, e.g. hypertext transfer protocol [HTTP] for remote control or remote monitoring of applications
  • H04L 67/141 - Setup of application sessions
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

52.

Systems and methods for deploying a cloud management system configured for tagging constructs deployed in a multi-cloud environment

      
Application Number 18217251
Grant Number 12206562
Status In Force
Filing Date 2023-06-30
First Publication Date 2023-11-09
Grant Date 2025-01-21
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network, and a topology system logic, stored on non-transitory, computer-medium, and comprising a topology snapshot logic. Upon execution by one or more processors, the topology system logic causes performance of operations that includes periodically saving states of a plurality of constructs at first and second time states, receiving user input corresponding to a selection of one or more constructs of the plurality of constructs, generating a topology mapping visualization that illustrates differences between the first and second states of the selection of one or more constructs of the plurality of constructs, and causing rendering of the topology mapping visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/122 - Discovery or management of network topologies of virtualised topologies e.g. software-defined networks [SDN] or network function virtualisation [NFV]
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

53.

SYSTEM AND METHOD FOR APPLICATION-BASED MICRO-SEGMENTATION

      
Application Number US2023020513
Publication Number 2023/212388
Status In Force
Filing Date 2023-04-30
Publication Date 2023-11-02
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Anandakrishnan, Geetha
  • Hinrichs, Susan
  • Xu, Daniel
  • Meiyyappan, Narayanan
  • Jog, Mandar

Abstract

A system and method for controlling the handling of intra- VPC and inter-VPC communications is described. First, a destination of a communication is determined it resides within a first virtual private cloud network (VPC) of a source of the communication. If so, filtering communications between the destination and the source is controlled by native cloud constructs associated with a cloud service provider (CSP) underlay network for the first public cloud network. Otherwise, filtering communication between the destination and the source is controlled by a spoke gateway. The spoke gateway is part of a cloud overlay network configured to provide a communication path between the first virtual private cloud network and the second private cloud network and using micro-segmentation to set and manage security policies.

IPC Classes  ?

  • H04L 67/104 - Peer-to-peer [P2P] networks
  • H04L 12/46 - Interconnection of networks
  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]

54.

System and method for selecting virtual appliances in communications with virtual private cloud networks

      
Application Number 17409668
Grant Number 11788924
Status In Force
Filing Date 2021-08-23
First Publication Date 2023-10-17
Grant Date 2023-10-17
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

A method for facilitating communications between client devices in geographically separated networks is described. First, message monitoring is conducted by each of a plurality of virtual appliances within a local network to detect a message of a first message type. Responsive to failing to locate a Media Access Control (MAC) address of a destination for the message within a prescribed table by a default gateway, one of the plurality of virtual appliances is selected for handling a forwarding of the message to a plurality of remote networks, and the message via the selected virtual appliance is forwarded to a plurality of gateways associated with a plurality of remote networks. Responsive to locating the MAC address of the destination within the table, the virtual appliance previously handling communications with the destination to forward the message to the destination.

IPC Classes  ?

  • G01M 3/32 - Investigating fluid tightness of structures by using fluid or vacuum by measuring rate of loss or gain of fluid, e.g. by pressure-responsive devices, by flow detectors for containers, e.g. radiators
  • H04L 12/64 - Hybrid switching systems
  • H04L 101/622 - Layer-2 addresses, e.g. medium access control [MAC] addresses

55.

System and method for secure data transfer

      
Application Number 17010822
Grant Number 11784976
Status In Force
Filing Date 2020-09-02
First Publication Date 2023-10-10
Grant Date 2023-10-10
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Kunnath, Ramakrishnan
  • Sreekumar, Arvind

Abstract

In one embodiment, a secure exchange system is described. The secure exchange system includes a virtual private cloud network and a controller. The virtual private cloud network includes a plurality of gateways, each gateway of the plurality of gateways is configured to generate one or more local directories. Each local directory of the one or more local directories representing one or more stored objects within a public cloud storage element. The controller is configured to authenticate a user prior to granting the user access to the virtual private cloud network. The gateways are accessible by the user over AWS Direct Connect, where the public cloud storage element is a S3 bucket.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • H04L 12/46 - Interconnection of networks
  • H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
  • H04L 67/51 - Discovery or management thereof, e.g. service location protocol [SLP] or web services
  • H04L 67/50 - Network services
  • H04L 67/1001 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers

56.

Multi-cloud active mesh network system and method

      
Application Number 17862110
Grant Number 11785078
Status In Force
Filing Date 2022-07-11
First Publication Date 2023-10-10
Grant Date 2023-10-10
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sun, Yixin
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network system features a first virtual private cloud (VPC) network and a second VPC network. The first VPC network includes a first plurality of gateways. Each gateway of the first plurality of gateways is in communications with other gateways. Similarly, a second VPC network includes a second plurality of gateways. Each of the second plurality of gateways is communicatively coupled to the each of the first plurality of gateways to support data exchanges between resources deployed in different public cloud networks.

IPC Classes  ?

57.

SYSTEM AND METHOD FOR ANOMALY DETECTION IN A DISTRIBUTED CLOUD ENVIRONMENT

      
Application Number US2023012584
Publication Number 2023/154315
Status In Force
Filing Date 2023-02-08
Publication Date 2023-08-17
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Cherkas, Jacob
  • Malyala, Arno, Lenin
  • Ashley, Bryan

Abstract

A distributed cloud computing system further includes logic, stored on non-transitory, computer-medium, that, upon execution by one or more processors, causes performance of operations including generating a first fingerprint for the first VPC being a statistical measure of a plurality of network metrics during a learning phase, generating a second fingerprint for the second VPC being a statistical measure of the plurality of network metrics during the learning phase, receiving, from the controller, metadata pertaining to each of the first gateway and the second gateway, receiving, from each of the first gateway and the second gateway, network data, wherein the metadata and the network data identify each of the plurality of constructs, the communication paths between each construct, and in which cloud computing network each construct is deployed, detecting an anomaly in one or more network traffic metrics of either the first VPC or the second VPC based on a comparison of received network traffic and a corresponding fingerprint, and generating an alert that the anomaly was detected.

IPC Classes  ?

  • G06F 11/00 - Error detectionError correctionMonitoring
  • G06F 11/30 - Monitoring
  • G06Q 10/06 - Resources, workflows, human or project managementEnterprise or organisation planningEnterprise or organisation modelling
  • G06F 21/50 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
  • G06F 9/46 - Multiprogramming arrangements
  • G06F 21/36 - User authentication by graphic or iconic representation
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

58.

System and method for determination of network operation metrics and generation of network operation metrics visualizations

      
Application Number 17698850
Grant Number 11722387
Status In Force
Filing Date 2022-03-18
First Publication Date 2023-08-08
Grant Date 2023-08-08
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

Logic for generating virtualization(s) based on metadata and network data for at least constructs spanning multiple cloud networks is described. The logic is configured to (i) generate a topology mapping including a plurality of constructs and connections extending across a multi-cloud network including a first cloud network and a second cloud network different than the first cloud network, (ii) receive input corresponding to a selection of a source construct and a destination construct, and (iii) determine a data transmission path between the source construct and the destination construct. Also, the logic is configured to generate a visualization illustrating the data transmission path extending between the source constraint operating in the first cloud network and the destination construct operating in the second cloud network. Lastly, the logic is configured to perform operations including a computation of latency periods between a pair of constructs included in the data transmission path.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

59.

System and method for non-disruptive migration of software components to a public cloud system

      
Application Number 17339928
Grant Number 11722565
Status In Force
Filing Date 2021-06-04
First Publication Date 2023-08-08
Grant Date 2023-08-08
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

One embodiment of the invention features a system that includes a first virtual appliance and a second virtual appliance that support a transfer of content between an on-premises network and a public cloud network. Deployed as part of the on-premises network, the first virtual appliance translates a network address assigned to the content stored within a first non-transitory storage medium, which is associated with on-premises host residing within a first subnetwork of the on-premises network, to a temporary address associated with a second subnetwork. Deployed as part of the public cloud network, the second virtual appliance translates the temporary address back to the network address. The content, such as a software instance, is stored within a second non-transitory storage medium of the public cloud network with a network address identical to the network address used when stored within the first non-transitory storage medium pertaining to the on-premises network.

IPC Classes  ?

  • H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
  • H04L 61/5007 - Internet protocol [IP] addresses
  • H04L 101/622 - Layer-2 addresses, e.g. medium access control [MAC] addresses

60.

Systems and methods for improving packet forwarding throughput for encapsulated tunnels

      
Application Number 17208749
Grant Number 11716306
Status In Force
Filing Date 2021-03-22
First Publication Date 2023-08-01
Grant Date 2023-08-01
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen

Abstract

A computerized method for increasing throughput of encapsulated data over a network is described. First, a determination, at a first network device, of a number of available processing resources located at a second network device is conducted. Thereafter, a plurality of connections are generated between the first network device and the second device. The plurality of connections corresponding in number to the number of available processing resources. Data received by the first network device is associated with a first connection of the plurality of tunneling connections. Thereafter, translation data unique to a tunneling session associated with the first connection is generated and the received data is encapsulated with the translation data to generate the encapsulated data for transmission to the second network device.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 61/2592 - Translation of Internet protocol [IP] addresses using tunnelling or encapsulation
  • H04L 45/125 - Shortest path evaluation based on throughput or bandwidth
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 45/7453 - Address table lookupAddress filtering using hashing
  • H04L 61/5007 - Internet protocol [IP] addresses

61.

Systems and methods for deploying a cloud management system configured for tagging constructs deployed in a multi-cloud environment

      
Application Number 17510293
Grant Number 11695661
Status In Force
Filing Date 2021-10-25
First Publication Date 2023-07-04
Grant Date 2023-07-04
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes performance of operations including generating a topology mapping visualization illustrating a plurality of constructs and communication paths therebetween, wherein a first subset of the plurality of constructs are deployed in the first cloud computing network and a second subset of the plurality of constructs are deployed in the second cloud computing network, receiving user input corresponding to (i) a selection of one or more constructs and (ii) an identifier for the selection, generating a filtered topology mapping visualization of the selection of the one or more constructs and any connections therebetween, and causing rendering of the filtered topology mapping visualization on a display screen.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 41/122 - Discovery or management of network topologies of virtualised topologies e.g. software-defined networks [SDN] or network function virtualisation [NFV]
  • H04L 43/028 - Capturing of monitoring data by filtering

62.

Systems and methods for controlling accessing and storing objects between on-prem data center and cloud

      
Application Number 18111594
Grant Number 12166760
Status In Force
Filing Date 2023-02-19
First Publication Date 2023-06-22
Grant Date 2024-12-10
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Kunnath, Ramakrishnan

Abstract

In an embodiment, a secure object transfer system is described. The system features a virtual private cloud network (VPC) and a controller. The VPC includes a plurality of gateways and a network load balancer, which configured to conduct a load balancing scheme on access messages from computing devices deployed within an on-premises network to direct the access memory to one of the plurality of gateways for storage or retrieval of an object from a cloud-based storage element. Each gateway includes Fully Qualified Domain Name (FQDN) filtering logic to restrict access of the computing devices to certain cloud-based storage elements in accordance with a security policy. The controller is configured to maintain and update the security policy utilized by each gateway of the plurality of gateways.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/1036 - Load balancing of requests to servers for services different from user content provisioning, e.g. load balancing across domain name servers

63.

SYSTEM AND METHOD FOR CLOUD-BASED FILTERING AND MODIFICATION OF MESSAGES WITH OVERLAPPING ADDRESSES

      
Application Number US2022051387
Publication Number 2023/102036
Status In Force
Filing Date 2022-11-30
Publication Date 2023-06-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Delecroix, Nicholas
  • Mirza, Saad

Abstract

A network traffic filter system operates to detect network address overlapping conditions and, in response, preclude continued propagation over a cloud platform. Implemented with a controller, the network traffic filter system is configured to determine whether an incoming message is associated with a network address overlapping condition. This condition is detected when the incoming message received from a first tenant resource includes a subnetwork address that overlaps a subnetwork address relied upon by either (a) a component within the cloud platform or (b) a component associated with a second tenant resource different from the first tenant resource. Upon detecting the network address overlapping condition, the network traffic filter system signals a gateway, being a cloud component in communication with the first tenant resource, to either prevent messages associated with the subnetwork address from being routed over the cloud platform or substitute the subnetwork address with a non-overlapping, virtual subnetwork address.

IPC Classes  ?

  • H04L 45/745 - Address table lookupAddress filtering
  • H04L 61/103 - Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
  • H04L 45/44 - Distributed routing
  • H04L 45/64 - Routing or path finding of packets in data switching networks using an overlay routing layer
  • H04L 61/2503 - Translation of Internet protocol [IP] addresses
  • H04L 61/4535 - Network directoriesName-to-address mapping using an address exchange platform which sets up a session between two nodes, e.g. rendezvous servers, session initiation protocols [SIP] registrars or H.323 gatekeepers
  • H04L 61/5046 - Resolving address allocation conflictsTesting of addresses

64.

CONTROLLER-BASED TRAFFIC FILTERING AND ADDRESS MODIFICATION

      
Application Number US2022051418
Publication Number 2023/102058
Status In Force
Filing Date 2022-11-30
Publication Date 2023-06-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Delecroix, Nicholas
  • Mirza, Saad

Abstract

In communication with components of a cloud platform, namely a software-defined network constructed to overlay at least one public cloud network, a controller features a virtual processor and a data store. The data store includes network address translation (NAT) processing logic configured to determine whether a control plane message from tenant resources is associated with a network address overlapping condition, which represents a first network address included in the control plane message overlaps a network address range relied upon by either (a) at least one of the components of the cloud platform or (b) a component associated with other tenant resources. The NAT processing logic is further configured to alter routing data stores that maintain routing information for each of the components of the cloud platform to substitute the first network address with a first virtual network address for subsequent data message routing.

IPC Classes  ?

65.

SYSTEM AND METHOD FOR GENERATING A NETWORK HEALTH DASHBOARD FOR A MULTI-CLOUD ENVIRONMENT

      
Application Number 17962495
Status Pending
Filing Date 2022-10-08
First Publication Date 2023-06-08
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes operations including receiving, from the controller, metadata pertaining to a plurality of constructs, receiving, from each of the first and second gateways, network data, deriving gateway metrics spanning multiple cloud computing networks including at least the first and second cloud computing networks, wherein the deriving is based on at least the metadata and the network data of each of the first and second gateways, generating a dashboard visualization illustrating the gateway metrics, wherein the gateway metrics pertain to characteristics of each gateway and deployed constructs associated with each gateway, and causing rendering of the dashboard visualization on a display screen.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

66.

System and method for deploying a distributed cloud management system configured for generating interactive user interfaces detailing link latencies

      
Application Number 17833467
Grant Number 11658890
Status In Force
Filing Date 2022-06-06
First Publication Date 2023-05-23
Grant Date 2023-05-23
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network, and logic. The logic, upon execution by one or more processors, causes performance of operations including receiving, from the controller, metadata pertaining to a plurality of constructs corresponding to a plurality of time instances, receiving, from each of the first and second gateways, network data corresponding to the plurality of time instances, wherein the metadata and the network data identify each of the plurality of constructs, communication paths between each construct, and in which cloud computing network each construct is deployed, generating a visualization illustrating differences between the plurality of constructs and communication paths at the first time instance and at the second time instance, and causing rendering of the visualization on a display screen.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

67.

PRIVATE MANAGEMENT OF MULTI-CLOUD OVERLAY NETWORK

      
Application Number US2022046962
Publication Number 2023/069392
Status In Force
Filing Date 2022-10-18
Publication Date 2023-04-27
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Delecroix, Nicholas
  • Yan, Li
  • Witkin, Spencer
  • Mirza, Saad

Abstract

A multi-cloud overlay network for supporting communications between a first public cloud network and a second public cloud network. The overlay network features a management virtual private network, which includes a network load balancing (NLB) component and a controller registered as a target on a port of the NLB component. The overlay network further includes one or more spoke or transit gateways and a multi-cloud access virtual private cloud (VPC) operating within the first public cloud network, and a remote cloud load balancer component operating the second public cloud network. The remote cloud load balancer component is communicatively coupled between the multi-cloud access VPC and one or more remote spoke or transit gateways. The multi-cloud access VPC includes a VPC endpoint that is assigned a private IP address and communicatively coupled to the NLB component and a virtual private network (VPN) gateway communicatively coupled to a private transport.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

68.

GLOBAL MULTI-CLOUD OVERLAY NETWORK WITH REGIONAL PREFERENCE

      
Application Number US2022046964
Publication Number 2023/069393
Status In Force
Filing Date 2022-10-18
Publication Date 2023-04-27
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Delecroix, Nicholas
  • Konda, Praveen

Abstract

A computerized method for avoiding cross-region communications when utilizing a cloud overlay network is described. The method involves an operation of deploying one or more spoke gateways within at least a first region and a second region of a first virtual private cloud network. Thereafter, a region and a virtual private cloud network associated with a source and a destination of a communication are determined. Upon determining that the destination of the communication resides within a second virtual private cloud network, which is different than the first virtual private cloud network, the routing of the communication between the source and the destination is controlled by one or more spoke gateways solely residing within the region in which the source.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 9/40 - Network security protocols
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

69.

System and methods for controlling accessing and storing objects between on-prem data center and cloud

      
Application Number 17010820
Grant Number 11588819
Status In Force
Filing Date 2020-09-02
First Publication Date 2023-02-21
Grant Date 2023-02-21
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Kunnath, Ramakrishnan

Abstract

In one embodiment, a secure object transfer system is described. The system features a virtual private cloud network (VPC) and a controller. The VPC includes a plurality of gateways and a network load balancer, which configured to conduct a load balancing scheme on access messages from computing devices deployed within an on-premises network to direct the access memory to one of the plurality of gateways for storage or retrieval of an object from a cloud-based storage element. Each gateway includes Fully Qualified Domain Name (FQDN) filtering logic to restrict access of the computing devices to certain cloud-based storage elements in accordance with a security policy. The controller is configured to maintain and update the security policy utilized by each gateway of the plurality of gateways.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/40 - Network security protocols
  • H04L 67/1036 - Load balancing of requests to servers for services different from user content provisioning, e.g. load balancing across domain name servers
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways

70.

A MULTI-CLOUD ACTIVE MESH NETWORK SYSTEM AND METHOD

      
Application Number US2022016196
Publication Number 2022/250750
Status In Force
Filing Date 2022-02-11
Publication Date 2022-12-01
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Sun, Yixin
  • Xu, Shanshan
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

In one embodiment, a controller features a first data store, a second data store and route determination logic. The first data store is configured to store current routing information from a source transit gateway within at least a first transit cloud network to a destination transit gateway within at least a second transit cloud network of the cloud network. Each of the source transit gateway and the destination transit gateway being one of a plurality of transit gateways associated with the cloud network. The second data store is configured to store alternative routing information between the source transit gateway and the destination transit gateway. The route determination logic is configured to (i) conduct analytics on all available route paths for a message intended to be sent from the source transit gateway to the destination transit gateway and (ii) select a best route path for the message.

IPC Classes  ?

  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 12/46 - Interconnection of networks
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 45/00 - Routing or path finding of packets in data switching networks

71.

SYSTEM AND METHOD FOR AUTOMATING APPLIANCE CONFIGURATION AND OPERABILITY

      
Application Number US2022030769
Publication Number 2022/251250
Status In Force
Filing Date 2022-05-24
Publication Date 2022-12-01
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Vannarath, Praveen
  • Chung, Wing-Kuen

Abstract

In one embodiment, a cloud connection appliance features a processor and a non- transitory storage medium. The non -transitory storage medium comprises management control logic, that when executed by the processor, controls registration with a controller adapted to control data traffic between gateway instance and to establish a communication path including a reverse tunnel with the controller. The controller and cloud connection appliance operate in a client-server relationship with the cloud connection appliance operates as a client when establishing the communication path and operates as a server when receiving control information through the reverse tunnel. The reverse tunnel enables the cloud connection appliance to directly receive the control information from the controller despite the cloud connection application lacking a publicly routable Internet Protocol (IP) address.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 43/026 - Capturing of monitoring data using flow identification
  • H04L 69/22 - Parsing or analysis of headers

72.

Active mesh network system and method

      
Application Number 17079399
Grant Number 11502942
Status In Force
Filing Date 2020-10-23
First Publication Date 2022-11-15
Grant Date 2022-11-15
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sun, Yixin
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network system features a first virtual private cloud (VPC) network and a second VPC network. The first VPC network includes a first plurality of gateways. Each gateway of the first plurality of gateways is in communications with other gateways of the first plurality of gateways in accordance with a first tunnel protocol. Similarly, a second VPC network includes a second plurality of gateways. Each of the second plurality of gateways is communicatively coupled to the each of the first plurality of gateways in accordance with a second security protocol to provide redundant routing.

IPC Classes  ?

  • H04L 45/24 - Multipath
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 12/46 - Interconnection of networks
  • H04L 67/1029 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers using data related to the state of servers by a load balancer
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • H04L 67/1087 - Peer-to-peer [P2P] networks using cross-functional networking aspects

73.

INGRESS GATEWAY WITH DATA FLOW CLASSIFICATION FUNCTIONALITY

      
Application Number US2022026802
Publication Number 2022/232441
Status In Force
Filing Date 2022-04-28
Publication Date 2022-11-03
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Lenglet, Romain

Abstract

A computerized method for providing network policy-based routing of a data flow is described. After obtaining attributes associated with an incoming data flow, a first gateway is configured to determine one or more network policies based on the attributes associated with the incoming data flow and assign a classification identifier based on the one or more network policies. The classification identifier is configured to influence routing paths through at least one cloud network, where the classification identifier is encapsulated into content of the incoming data flow to generate a classified data flow for routing from a source to a destination through the at least one cloud network.

IPC Classes  ?

74.

SYSTEM, CLASSIFIER AND METHOD FOR NETWORK POLICY-BASED TRAFFIC MANAGEMENT OF DATA FLOWS

      
Application Number US2022026808
Publication Number 2022/232445
Status In Force
Filing Date 2022-04-28
Publication Date 2022-11-03
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Lenglet, Romain

Abstract

A system features classification architectures for policy-based, data traffic management. A first architecture type is a controller and nodes operating as a Kubernetes cluster. The cluster includes a master node and an ingress node configured to access the master node to obtain attribute(s) for a data flow received by the ingress node, determine a network policy applicable to the data flow based on the attribute(s), and determine a classification identifier, based on the network policy, to provide context associated with the data flow and reliable association. The second architecture type features an ingress gateway including data analytic logic and message reconfiguration logic. The data analytic logic determines a network policy applicable to the data flow and assigns the classification identifier to influence routing paths. The message reconfiguration logic encapsulates the classification identifier into data flow content to generate a classified data flow for routing through a cloud or multi-cloud network.

IPC Classes  ?

75.

Scaling network address translation (NAT) and firewall functionality to support public cloud networks

      
Application Number 17087553
Grant Number 11444808
Status In Force
Filing Date 2020-11-02
First Publication Date 2022-09-13
Grant Date 2022-09-13
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

According to one embodiment, a computerized method conducted by logic deployed within a network device implemented within a virtual private cloud network for supporting network address translations within a public cloud network is described. Herein, after receipt of a message, based on content within the message, a network address translation (NAT) control logic unit from a plurality of NAT control logic units is selected. The selected NAT control logic unit is configured to perform address translations on information within the message to produce a translated message. Thereafter, the translated message is routed to a destination network device located on the public network.

IPC Classes  ?

76.

SYSTEM AND METHOD FOR INCREASED THROUGHPUT AND SCALABILITY

      
Application Number US2022016074
Publication Number 2022/177808
Status In Force
Filing Date 2022-02-11
Publication Date 2022-08-25
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen

Abstract

A network architecture including a layered transit virtual private cloud network and interface logic that controls the egress and ingress of messages between the transit VPC and an on- premises network. First, the layered transit VPC includes a first transit gateway cluster communicatively coupled to one or more spoke VPCs for receipt of messages from cloud instances and a second transit gateway cluster communicatively coupled to the on-premises network. The layered transit VPC supports increased scalability for the spoke VPCs. Second, the interface logic is configured to operate in concert with a gateway cluster that controls operability of a router by at least controlling propagation of messages into or from the on- premises network via one or more selected gateways forming the gateway cluster.

IPC Classes  ?

  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 49/15 - Interconnection of switching modules
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 47/10 - Flow controlCongestion control

77.

SYSTEM AND METHOD FOR RESTRICTING COMMUNICATIONS BETWEEN VIRTUAL PRIVATE CLOUD NETWORKS THROUGH SECURITY DOMAINS

      
Application Number US2022016197
Publication Number 2022/177829
Status In Force
Filing Date 2022-02-11
Publication Date 2022-08-25
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

A computerized method for restricting communications between virtual private cloud networks comprises creating a plurality of security domains. Each of the plurality of security domains identifies gateways associated with one or more virtual private cloud networks. Also, the method features generating transit routing data stores in accordance with each of the plurality of security domains; determining whether a connection policy exists between at least a first security domain and a second security domain of the plurality of security domains; and precluding communications between gateways associated with the first security domain and gateways associated with the second security domain in response to determining that no connection policy exists between the first security domain and the second security domain.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • G06F 15/173 - Interprocessor communication using an interconnection network, e.g. matrix, shuffle, pyramid, star or snowflake
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal

78.

SYSTEM AND METHOD FOR SEGMENTING TRANSIT CAPABILITIES WITHIN A MULTI-CLOUD ARCHITECTURE

      
Application Number US2022016081
Publication Number 2022/177810
Status In Force
Filing Date 2022-02-11
Publication Date 2022-08-25
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Xu, Shanshan

Abstract

In one embodiment, a computing platform features a controller, one or more transit virtual private cloud networks (VPCs), and a plurality of spoke VPCs. Communicatively coupled to the transit virtual VPCs, the spoke VPCs include (i) a first spoke VPC associated with a first security region and (ii) a second spoke VPC associated with a second security region. Herein, the first security region is configured to permit spoke gateways of the first spoke VPC to communicate with each other while precluding communications with spoke gateways associated with another security region absent a connectivity policy being a set of rules established by the administrator/user of the network concerning permitted connectivity between different security regions.

IPC Classes  ?

79.

MULTI-CLOUD NETWORK TRAFFIC FILTERING SERVICE

      
Application Number US2022016111
Publication Number 2022/177819
Status In Force
Filing Date 2022-02-11
Publication Date 2022-08-25
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Cheung, Lee-Chik

Abstract

In one embodiment, a computing platform featuring a controller and a first virtual private cloud network, which is communicatively coupled to the controller. The first virtual private cloud network includes at least a first gateway including egress filtering logic. The egress filtering logic is configured to (i) filter messages routed from the first gateway in accordance with a first set of filtering rules maintained by the first gateway and (ii) bypass the filtering of messages directed to or originating from one or more subnetworks in accordance with the first set of filtering rules.

IPC Classes  ?

  • H04L 45/586 - Association of routers of virtual routers
  • H04L 45/64 - Routing or path finding of packets in data switching networks using an overlay routing layer
  • H04L 45/74 - Address processing for routing
  • H04L 12/46 - Interconnection of networks

80.

CLOUD-BASED EGRESS FILTERING SYSTEM

      
Application Number US2022016201
Publication Number 2022/177830
Status In Force
Filing Date 2022-02-11
Publication Date 2022-08-25
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Cheung, Lee-Chik

Abstract

In one embodiment, a computing platform features a controller in communication with one or more virtual private cloud networks, including a first virtual private cloud network (VPC). The virtual private cloud network includes at least a first egress filtering gateway configured to filter egress traffic data received from a first gateway and route the filtered egress traffic data to a public network in accordance with a first set of filter rules. The first set of filter rules are included as part of a first security policy provided by the controller.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 41/00 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks

81.

AVIATRIX COPILOT

      
Serial Number 97515663
Status Registered
Filing Date 2022-07-22
Registration Date 2024-12-17
Owner Aviatrix Systems, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing; Providing temporary use of non-downloadable software for public, private or hybrid cloud networks for enterprise-grade connection to, within and between clouds and enterprise applications; Providing temporary use of on-line non-downloadable software for monitoring and managing API traffic across private, public and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of hosting virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid on premise private cloud and public cloud environments; Infrastructure as a service (IaaS), namely, hosting software for infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenter, cloud and edge environments and applications; providing temporary use of on-line non-downloadable cloud computing software in combination with data science, machine learning (ML) and artificial intelligence (AI) for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing

82.

AVIATRIX

      
Serial Number 97515667
Status Registered
Filing Date 2022-07-22
Registration Date 2023-11-21
Owner Aviatrix Systems, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing; Providing temporary use of non-downloadable software for public, private or hybrid cloud networks for enterprise-grade connection to, within and between clouds and enterprise applications; Providing temporary use of on-line non-downloadable software for monitoring and managing API traffic across private, public and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of hosting virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid on premise private cloud and public cloud environments; Infrastructure as a service (IaaS), namely, hosting software for infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenter, cloud and edge environments and applications; providing temporary use of on-line non-downloadable cloud computing software in combination with data science, machine learning (ML) and artificial intelligence (AI) for use in managing network connections, facilitating automation, troubleshooting network and security issues, and providing analytics in the field of cloud computing

83.

Multi-cloud active mesh network system and method

      
Application Number 17186911
Grant Number 11388227
Status In Force
Filing Date 2021-02-26
First Publication Date 2022-07-12
Grant Date 2022-07-12
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Sun, Yixin
  • Wen, Colby
  • Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network system features a first virtual private cloud (VPC) network and a second VPC network. The first VPC network includes a first plurality of gateways. Each gateway of the first plurality of gateways is in communications with other gateways. Similarly, a second VPC network includes a second plurality of gateways. Each of the second plurality of gateways is communicatively coupled to the each of the first plurality of gateways to support data exchanges between resources deployed in different public cloud networks.

IPC Classes  ?

84.

MANAGEMENT NETWORK AND METHOD OF OPERATION

      
Application Number US2021065548
Publication Number 2022/147152
Status In Force
Filing Date 2021-12-29
Publication Date 2022-07-07
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor
  • Wei, Xiaobo, Sherry
  • Vannarath, Praveen
  • Zheng, Steve
  • Hsiang, Cheng

Abstract

A computerized method for utilizing private Internet Protocol (IP) addressing for communications between components of one or more public cloud networks. The method features determining whether outbound traffic corresponds to a first type of outbound traffic being forwarded from a cloud instance supported by the gateway. In response to determining that the first type of outbound traffic is being forwarded from the cloud instance, the first type of outbound traffic is directed via a data interface of the gateway. Also, the method features determining whether the outbound traffic corresponds to a second type of outbound traffic being initiated by logic within the gateway. In response to determining that the second type of outbound traffic is being initiated by logic within the gateway, directing the second type of outbound traffic via a management interface of the gateway.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol

85.

SYSTEM, METHOD AND APPARATUS FOR GENERATING AND SEARCHING A TOPOLOGY OF RESOURCES AMONG MULTIPLE CLOUD COMPUTING ENVIRONMENTS

      
Application Number US2021028243
Publication Number 2021/216613
Status In Force
Filing Date 2021-04-20
Publication Date 2021-10-28
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes operations including receiving, from the controller, metadata pertaining to a plurality of constructs, receiving, from each of the first and second gateways, network data, deriving heat map information detailing a density of network traffic at a plurality of geographic locations, wherein the network traffic is transmitted across multiple cloud computing networks, generating a heat map visualization illustrating the density of the network traffic that includes a map of a geographic region as well as an overlay of visual indicators representing the density of the network traffic, and causing rendering of the heat map visualization on a display screen of a network device.

IPC Classes  ?

  • G06Q 10/00 - AdministrationManagement
  • G06F 3/00 - Input arrangements for transferring data to be processed into a form capable of being handled by the computerOutput arrangements for transferring data from processing unit to output unit, e.g. interface arrangements

86.

SYSTEM AND METHOD FOR GENERATING A NETWORK HEALTH DATA AND OTHER ANALYTICS FOR A MULTI-CLOUD ENVIRONMENT

      
Application Number US2021028248
Publication Number 2021/216616
Status In Force
Filing Date 2021-04-20
Publication Date 2021-10-28
Owner AVIATRIX SYSTEMS, INC. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes operations including receiving, from the controller, metadata pertaining to a plurality of constructs, receiving, from each of the first and second gateways, network data, deriving heat map information detailing a density of network traffic at a plurality of geographic locations, wherein the network traffic is transmitted across multiple cloud computing networks, generating a heat map visualization illustrating the density of the network traffic that includes a map of a geographic region as well as an overlay of visual indicators representing the density of the network traffic, and causing rendering of the heat map visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 12/24 - Arrangements for maintenance or administration
  • G06F 3/048 - Interaction techniques based on graphical user interfaces [GUI]
  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines

87.

System, method and apparatus for generating and searching a topology of resources among multiple cloud computing environments

      
Application Number 17127920
Grant Number 11671337
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2023-06-06
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic, stored on non-transitory, computer-medium. The logic, upon execution by one or more processors, causes performance of operations including: transmitting one or more requests to the controller for metadata of at least the first gateway and the second gateway; receiving, from at least one of the first gateway and the second gateway, network data of the corresponding gateway; generating a visualization illustrating the metadata and the network data, wherein the metadata and the network data pertain to multiple cloud computing networks; and causing rendering of the visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

88.

System and method for generating a network health dashboard for a multi-cloud environment

      
Application Number 17127922
Grant Number 11469977
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2022-10-11
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes operations including receiving, from the controller, metadata pertaining to a plurality of constructs, receiving, from each of the first and second gateways, network data, deriving gateway metrics spanning multiple cloud computing networks including at least the first and second cloud computing networks, wherein the deriving is based on at least the metadata and the network data of each of the first and second gateways, generating a dashboard visualization illustrating the gateway metrics, wherein the gateway metrics pertain to characteristics of each gateway and deployed constructs associated with each gateway, and causing rendering of the dashboard visualization on a display screen.

IPC Classes  ?

  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

89.

System and method for conducting intelligent traffic flow analytics

      
Application Number 17127924
Grant Number 11863410
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2024-01-02
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to manage a plurality of constructs, wherein a first subset are deployed in a first cloud computing network and a second subset are deployed in a second cloud computing network, and logic. The logic, upon execution by a processor, causes operations including receiving, from the controller, metadata pertaining to the plurality of constructs, receiving, from one or more gateways, network data associated with the one or more gateways, receiving network data, wherein the metadata and the network data identify each of the plurality of constructs, the communication paths between each construct, and in which cloud computing network each construct is deployed, deriving network traffic metrics from the metadata and the network data, generating a visualization illustrating the network traffic metrics, and causing rendering of the visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

90.

System and method for determination of network operation metrics and generation of network operation metrics visualizations

      
Application Number 17006657
Grant Number 11283695
Status In Force
Filing Date 2020-08-28
First Publication Date 2021-10-21
Grant Date 2022-03-22
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a plurality of gateways in a first cloud computing network and logic, stored on non-transitory, computer-medium. The logic, upon execution by one or more processors, causes performance of operations including: generating a topology mapping of the first cloud computing network including a plurality of constructs and connections therebetween, wherein the plurality of constructs includes the plurality of gateways, receiving input corresponding to a selection of a source construct and a destination construct, determining a data transmission path between the source construct and the destination construct, generating a visualization illustrating the data transmission path, and causing rendering of the visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 12/26 - Monitoring arrangements; Testing arrangements
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • H04L 12/24 - Arrangements for maintenance or administration
  • G06F 3/0481 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 61/5007 - Internet protocol [IP] addresses

91.

System and method for generating a global traffic heat map

      
Application Number 17127925
Grant Number 11265233
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2022-03-01
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes operations including receiving, from the controller, metadata pertaining to a plurality of constructs, receiving, from each of the first and second gateways, network data, deriving heat map information detailing a density of network traffic at a plurality of geographic locations, wherein the network traffic is transmitted across multiple cloud computing networks, generating a heat map visualization illustrating the density of the network traffic that includes a map of a geographic region as well as an overlay of visual indicators representing the density of the network traffic, and causing rendering of the heat map visualization on a display screen of a network device.

IPC Classes  ?

  • H04L 12/26 - Monitoring arrangements; Testing arrangements
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • H04L 61/5007 - Internet protocol [IP] addresses

92.

Systems and methods for deploying a cloud management system configured for tagging constructs deployed in a multi-cloud environment

      
Application Number 17127927
Grant Number 11159383
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2021-10-26
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network and logic. The logic, upon execution by one or more processors, causes performance of operations including generating a topology mapping visualization illustrating a plurality of constructs and communication paths therebetween, wherein a first subset of the plurality of constructs are deployed in the first cloud computing network and a second subset of the plurality of constructs are deployed in the second cloud computing network, receiving user input corresponding to (i) a selection of one or more constructs and (ii) an identifier for the selection, generating a filtered topology mapping visualization of the selection of the one or more constructs and any connections therebetween, and causing rendering of the filtered topology mapping visualization on a display screen.

IPC Classes  ?

  • H04L 12/24 - Arrangements for maintenance or administration
  • H04L 12/26 - Monitoring arrangements; Testing arrangements

93.

System and method for deploying a distributed cloud management system configured for generating interactive user interfaces of the state of a multi-cloud environment over time

      
Application Number 17127955
Grant Number 11356344
Status In Force
Filing Date 2020-12-18
First Publication Date 2021-10-21
Grant Date 2022-06-07
Owner Aviatrix Systems, Inc. (USA)
Inventor Cherkas, Jacob

Abstract

A distributed cloud computing system is disclosed that includes a controller configured to deploy a first gateway in a first cloud computing network and a second gateway in a second cloud computing network, and logic. The logic, upon execution by one or more processors, causes performance of operations including receiving, from the controller, metadata pertaining to a plurality of constructs corresponding to a plurality of time instances, receiving, from each of the first and second gateways, network data corresponding to the plurality of time instances, wherein the metadata and the network data identify each of the plurality of constructs, communication paths between each construct, and in which cloud computing network each construct is deployed, generating a visualization illustrating differences between the plurality of constructs and communication paths at the first time instance and at the second time instance, and causing rendering of the visualization on a display screen.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/028 - Capturing of monitoring data by filtering
  • H04L 12/66 - Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0852 - Delays
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • G06F 3/04817 - Interaction techniques based on graphical user interfaces [GUI] based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance using icons
  • H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
  • G06T 11/00 - 2D [Two Dimensional] image generation
  • H04L 61/5007 - Internet protocol [IP] addresses

94.

System and method for enabling communication between networks with overlapping IP address ranges

      
Application Number 16746738
Grant Number 11153262
Status In Force
Filing Date 2020-01-17
First Publication Date 2021-10-19
Grant Date 2021-10-19
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Manglik, Pankaj
  • Kishen, Sunil

Abstract

A method is described that enables communication between two disjoined networks with overlapping IP address ranges. An intermediary function in each of the networks and a unique IP address pool are deployed to facilitate the communication. This method also enables communications between one network with a group of networks with overlapping IP address ranges.

IPC Classes  ?

  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 12/741 - Header address processing for routing, e.g. table lookup
  • H04L 12/713 - Route fault prevention or recovery, e.g. rerouting, route redundancy, virtual router redundancy protocol [VRRP] or hot standby router protocol [HSRP] using node redundancy, e.g. VRRP

95.

System and method for selecting virtual appliances in communications with virtual private cloud networks

      
Application Number 15889131
Grant Number 11099099
Status In Force
Filing Date 2018-02-05
First Publication Date 2021-08-24
Grant Date 2021-08-24
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

A method for facilitating communications between client devices in geographically separated networks is described. First, message monitoring is conducted by each of a plurality of virtual appliances within a local network to detect a message of a first message type. Responsive to failing to locate a Media Access Control (MAC) address of a destination for the message within a prescribed table by a default gateway, one of the plurality of virtual appliances is selected for handling a forwarding of the message to a plurality of remote networks, and the message via the selected virtual appliance is forwarded to a plurality of gateways associated with a plurality of remote networks. Responsive to locating the MAC address of the destination within the table, the virtual appliance previously handling communications with the destination to forward the message to the destination.

IPC Classes  ?

  • H04L 12/64 - Hybrid switching systems
  • G01M 3/32 - Investigating fluid tightness of structures by using fluid or vacuum by measuring rate of loss or gain of fluid, e.g. by pressure-responsive devices, by flow detectors for containers, e.g. radiators
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal

96.

System and method for non-disruptive migration of software components to a public cloud system

      
Application Number 16114150
Grant Number 11032369
Status In Force
Filing Date 2018-08-27
First Publication Date 2021-06-08
Grant Date 2021-06-08
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

One embodiment of the invention features a system including a first gateway and a second gateway that operate in concert to support a migration of a software component from an on-premises network to a public cloud network while preserving an Internet Protocol (IP) address assigned to the software component. The first gateway deployed as part of the on-premises network, and the second gateway deployed as part of the public cloud network. The first and second gateways are in communication via a secure communication path. To support migration of the software component to the public cloud network while retaining its IP address, the second gateway is configured to resolve a media access control (MAC) address for an on-premises host connected to the on-premises network. Similarly, the first gateway is configured to resolve a MAC address for a cloud host connected to the public cloud network.

IPC Classes  ?

  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal

97.

Systems and methods for improving packet forwarding throughput for encapsulated tunnels

      
Application Number 16403353
Grant Number 10958620
Status In Force
Filing Date 2019-05-03
First Publication Date 2021-03-23
Grant Date 2021-03-23
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Vannarath, Praveen

Abstract

A computerized method for increasing throughput of encapsulated data through tunnels, the computerized method including receiving data at a first network device for transmission over a network to a second network device. Then determining at the first network device the number of available processing cores on the second network device and generating a plurality of tunneling sessions between the first network device and the second device. Associating the received data with a particular tunneling session and then generating translation data unique to the associated tunneling session prior to encapsulating the received data with the translation data. Finally, transmitting the encapsulated data to the second network device and processing the transmitted encapsulated data received at the second network device with a particular processing core based on the received translation data.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 12/729 - Selecting a path with suitable bandwidth or throughput
  • H04L 12/721 - Routing procedures, e.g. shortest path routing, source routing, link state routing or distance vector routing
  • H04L 12/743 - Header address processing for routing, e.g. table lookup using hashing techniques

98.

System for scaling network address translation (NAT) and firewall functions

      
Application Number 15280890
Grant Number 10826725
Status In Force
Filing Date 2016-09-29
First Publication Date 2020-11-03
Grant Date 2020-11-03
Owner Aviatrix Systems, Inc. (USA)
Inventor Wei, Xiaobo Sherry

Abstract

According to one embodiment, a network device may be adapted to operate within a virtual private cloud where network address translation (NAT) is performed through virtual machines and each network address translation is handled differently by a different NAT control logic unit. The network device features one or more hardware processors, and a memory that stores at least a plurality of network address translation (NAT) control logic unit and demultiplexer logic. The demuliplexer logic, when executed, receives an incoming message and, based at least in part on information within the incoming message, determines a selected NAT control logic unit to receive at least a portion of the information within the incoming message. The selected NAT control logic unit handles address translation for routing of a message based on the incoming message to a public network.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal

99.

System and method for enabling communication between networks with overlapping IP address ranges

      
Application Number 15201187
Grant Number 10541966
Status In Force
Filing Date 2016-07-01
First Publication Date 2020-01-21
Grant Date 2020-01-21
Owner Aviatrix Systems, Inc. (USA)
Inventor
  • Wei, Xiaobo Sherry
  • Manglik, Pankaj
  • Kishen, Sunil

Abstract

A method is described that enables communication between two disjoined networks with overlapping IP address ranges. An intermediary function in each of the networks and a unique IP address pool are deployed to facilitate the communication. This method also enables communications between one network with a group of networks with overlapping IP address ranges.

IPC Classes  ?

  • H04L 12/28 - Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 12/713 - Route fault prevention or recovery, e.g. rerouting, route redundancy, virtual router redundancy protocol [VRRP] or hot standby router protocol [HSRP] using node redundancy, e.g. VRRP
  • H04L 12/741 - Header address processing for routing, e.g. table lookup

100.

AVIATRIX

      
Serial Number 88456693
Status Registered
Filing Date 2019-06-03
Registration Date 2020-03-10
Owner Aviatrix Systems, Inc ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Providing temporary use of on-line non-downloadable software for cloud infrastructure management and automation; Providing temporary use of on-line non-downloadable cloud computing software for use in managing network connections, facilitating automation, troubleshooting hardware issues, and providing analytics in the field of cloud computing; Providing temporary use of non-downloadable software for public, private or hybrid cloud networks for enterprise-grade connection to cloud and enterprise applications; Providing temporary use of on-line non-downloadable software for monitoring and managing API traffic across private and hybrid clouds; Hybrid cloud infrastructure as a service (IaaS), namely, providing software, software platforms and infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters and in hybrid "on premise" private cloud and public cloud environments; Infrastructure as a service (IAAS), namely, providing temporary use of non-downloadable software, software platforms and infrastructure services in the nature of providing virtual computer systems and virtual computer environments through cloud computing to manage and deploy business applications and data applications in the field of datacenters
  1     2        Next Page