Patents Assigned to Red Hat, Inc.
  • Publication number: 20260205465
    Abstract: Replicated secrets can be migrated from a cloud environment to a local system. For example, a system can receive a secret stored in a first geographic region and a second geographic region of a cloud environment. The system can determine a first security level associated with a first source location of the secret and a second security level associated with a second source location of the secret. The system can encrypt the secret using a first encryption key associated with the first security level to generate a first encrypted secret. The system can determine that a first filesystem in a physical server corresponds to the first source location of the secret and store the first encrypted secret in the first filesystem of the physical server. The first encrypted secret can be usable to control access of one or more protected computing resources.
    Type: Application
    Filed: January 16, 2025
    Publication date: July 16, 2026
    Applicant: Red Hat, Inc.
    Inventors: Leigh Griffin, Andrea Cosentino, Paolo Antinori
  • Patent number: 12681708
    Abstract: Control nodes can execute configuration files from remote locations according to some examples described herein. For example, a control node may receive an input indicating a remote location, which can include configuration files. In response to receiving the input, the control node may retrieve a configuration file from the remote location. The configuration file can be used by the control node to deploy a software entity at one or more nodes. The control node may analyze the configuration file to detect one or more references indicating one or more resources associated with the configuration file. The control node can then generate an executable version of the configuration file by retrieving each of the resources. The control node can further execute the executable version of the configuration file to deploy the software entity at each of the nodes.
    Type: Grant
    Filed: October 11, 2023
    Date of Patent: July 14, 2026
    Assignee: Red Hat, Inc.
    Inventors: Pierre-Yves Chibon, Adam John Miller
  • Publication number: 20260195191
    Abstract: A container process mapping can be used for container layer management in a computing environment. For example, a system can receive a mapping file indicating a mapping of one or more processes to one or more container layers of a container image. Each process can be mapped to a container layer in the mapping file. The system can determine, for an execution of a container associated with the container image, a first resource usage of each process of the one or more processes. The system can determine, based on the mapping file and the first resource usage, a second resource usage of each container layer of the one or more container layers. The system can perform, based on the second resource usage, an action for a container file that is executable to generate the one or more container layers.
    Type: Application
    Filed: January 8, 2025
    Publication date: July 9, 2026
    Applicant: Red Hat, Inc.
    Inventors: Leigh Griffin, Pierre-Yves Chibon
  • Publication number: 20260195144
    Abstract: A mapper service can be implemented to map container processes to individual container layers. For example, the mapper service can receive a container file executable to generate one or more container layers of a container image in a computing environment. The mapper service can determine one or more processes associated with the container image in the computing environment. Each process of the one or more processes can be generated by a respective container layer of the container file. Based on the container file, the mapper service can determine a respective mapping of each process to a corresponding container layer. The mapper service can generate a mapping file indicating the respective mapping of each process to the corresponding container layer.
    Type: Application
    Filed: January 8, 2025
    Publication date: July 9, 2026
    Applicant: Red Hat, Inc.
    Inventors: Leigh Griffin, Pierre-Yves Chibon
  • Patent number: 12675726
    Abstract: Embodiments of the present disclosure provide techniques for implementing a service provider to collect quantum service metadata about multiple quantum systems on multiple quantum machines and storing this quantum service metadata in a service registry. The service provider may transmit a request for access with a qubit registry to each of a plurality of quantum machines, where the plurality of qubit registries store quantum service metadata associated with a plurality of quantum services configured on the plurality of quantum machines. The service provider may receive acceptance for access to each of the plurality of qubit registries. In addition, the service provider may periodically request the quantum service metadata from the plurality of qubit registries and store the received quantum service metadata in a service provider registry.
    Type: Grant
    Filed: January 26, 2023
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Leigh Griffin, Stephen Coady
  • Patent number: 12675346
    Abstract: Systems and methods for implementing a targeted port allowance for unprivileged processes are presented. The systems and methods determine, from a plurality of ports, a first set of ports from which a process is configured to receive information. The systems and methods configure the first set of ports to be unprivileged, and then configure a second set of the plurality of ports to be privileged. The second set of ports includes each one of the plurality of ports that is absent from the first set of ports. In turn, the systems and methods bind the process to the first set of ports.
    Type: Grant
    Filed: July 26, 2024
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Yuval Kashtan, Mario Vazquez Cebrian
  • Patent number: 12675589
    Abstract: A computing system can execute a continuous integration (CI) pipeline for merging a code commit into a software project. The CI pipeline can include CI phases that can output sets of result data. Each CI phase can generate a respective set of result data among the sets of result data. The computing system can determine delay times associated with the sets of result data, each respective set of result data being assigned a corresponding delay time among the delay times. For each respective delay time, the computing system can prevent a set of users from accessing the respective set of result data prior to an expiration of the corresponding delay time. The computing system can also permit the set of users to access the respective set of result data following the expiration of the corresponding delay time.
    Type: Grant
    Filed: January 23, 2023
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Avraham Talmor, Arie Bregman
  • Patent number: 12676835
    Abstract: A method to migrate workload between a single node environment and a multi-node environment over a Transport Layer Security (TLS) network, the method comprises running an application on a first machine in a first environment, wherein the first environment is any one of the environments. The method further comprises generating a first file for the application running on the first machine and storing the first file and the workload created from the first file in the first machine. The method further comprises accessing a second machine that runs a container cluster in a second environment, wherein the second environment is different from the first environment. The method further comprises reading a second file from the container cluster and storing the second file in the first machine. The method further comprises connecting the first machine to the container cluster of the second machine using access information stored in the second file.
    Type: Grant
    Filed: December 22, 2022
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Urvashi Mohnani, Leigh Griffin
  • Patent number: 12675326
    Abstract: Methods, systems, and computer program products herein provide operations or techniques for managing resource allocation in a data storage environment. According to aspects of the present disclosure, one or more storage nodes of hierarchy on a common hierarchy level are identified as a management group. For example, the one or more storage nodes of hierarchy may include one or more object storage daemons (OSDs) of a controlled replication under scalable hashing (CRUSH) group or the like. The resource utilization in a subset of the one or more storage nodes in the management group are monitored. Based on the monitored resource utilization, a processing device may determine respective scaling factors for allocating resources to the one or more storage nodes in the management group. The processing device may then adjust the resource allocation using the respective scaling factors in the one or more storage nodes.
    Type: Grant
    Filed: June 27, 2022
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Huamin Chen, Chen Wang, Yuval Lifshitz
  • Patent number: 12675288
    Abstract: A method is described that includes executing a container image that is configured as an image repository mirror for a remote server and executing an application that is configured to provide a request for one or more images to the remote server. The method further includes reconfiguring the application to cause the application to provide the request for the one or more images to the container image instead of the remote server.
    Type: Grant
    Filed: January 9, 2024
    Date of Patent: July 7, 2026
    Assignee: Red Hat, Inc.
    Inventors: Andrea Tarocchi, Paolo Antinori
  • Patent number: 12670014
    Abstract: An example system includes a memory, at least one processor in communication with the memory, a plurality of threads executing on the at least one processor, and a supervisor. The supervisor is configured to preempt a first thread of the plurality of threads and determine a status of the first thread as either (i) executing in an atomic section or (ii) executing outside of the atomic section. The atomic section is a region of code tagged as atomic, and the atomic section includes instructions that run under a lock. Responsive to determining the status as executing in the atomic section, the supervisor is configured to notify a second thread of the plurality of threads to execute a system call based lock to block execution until the lock is released by the first thread.
    Type: Grant
    Filed: October 18, 2021
    Date of Patent: June 30, 2026
    Assignee: Red Hat, Inc.
    Inventor: Michael Tsirkin
  • Patent number: 12670370
    Abstract: A system and method for performing multiplication for a neural network, e.g. for data of one or more layers in a neural network, may include loading a portion of a compressed version of a sparse input matrix into a cache memory; uncompressing a subset of the data in the portion of the compressed version of the sparse input matrix; and multiplying a sparse kernel matrix by the subset of the data using a set of instructions which are themselves created based on the sparse kernel matrix.
    Type: Grant
    Filed: April 22, 2021
    Date of Patent: June 30, 2026
    Assignee: Red Hat, Inc.
    Inventors: Alexander Matveev, Nir Shavit
  • Patent number: 12670005
    Abstract: Systems and methods for secure saving sand restoration of virtualized states is disclosed herein, wherein a guest and/or a virtual machine is aware of being executed from a restored snapshot. An example system comprises a hypervisor; an application running in an encrypted virtual machine; a memory; a processor in communication with the memory executing an application, wherein the application is configured to modify, by an application running in an encrypted VM, a shadow identifier (Shadow ID) saved in private memory; and save a state of the encrypted VM, as a snapshot.
    Type: Grant
    Filed: March 22, 2023
    Date of Patent: June 30, 2026
    Assignee: Red Hat, Inc.
    Inventor: Michael Tsirkin
  • Patent number: 12664450
    Abstract: Lambda expressions in a Rete network class can be replaced with code classes according to some examples herein. In one particular example, a system can generate a Rete network based on a set of rules. The Rete network can include nodes corresponding to conditions defined in the set of rules. The system can generate a network class based on the Rete network, where the network class is source code that includes lambda expressions representing the conditions associated with the nodes. The system can also generate replacement classes based on the lambda expressions. The system can then generate a modified network class by replacing the lambda expressions with the replacement classes in the network class.
    Type: Grant
    Filed: October 24, 2022
    Date of Patent: June 23, 2026
    Assignee: Red Hat, Inc.
    Inventors: Luca Molteni, Francesco Nigro
  • Patent number: 12665749
    Abstract: Secrets can be migrated from a cloud environment to a local system. For example, a computing system can receive a secret stored in a cloud environment from a secret manager associated with the cloud environment. The computing system can identify a source location associated with the secret. The secret can map to a location identifier representing a geographic region that includes the source location of the secret. The computing system can determine that a filesystem in a physical server corresponds to the location identifier of the secret. The computing system then can store the secret in the filesystem of the physical server. The secret can be used to control access of one or more protected computing resources.
    Type: Grant
    Filed: March 3, 2023
    Date of Patent: June 23, 2026
    Assignee: Red Hat, Inc.
    Inventors: Leigh Griffin, Andrea Cosentino, Paolo Antinori
  • Patent number: 12659384
    Abstract: Dynamic, client-specific retrieval of data can be performed for edge devices using data services. For example, a system can receive a data request from a client device. The data request can include a type of data and one or more parameters for the type of data. In response to receiving the data request, the system can further detect data services that include the type of data. Additionally, the system can generate application programming interface (API) contracts. Each of the API contracts can define a communication protocol between the client device and each of the data services. The system can also deploy a deployable object, which may include the API contracts, on the client device to cause the client device to receive data satisfying the data request from each of the data services.
    Type: Grant
    Filed: June 22, 2023
    Date of Patent: June 16, 2026
    Assignee: Red Hat, Inc.
    Inventors: Leigh Griffin, Aoife Moloney
  • Patent number: 12657108
    Abstract: Execution of software applications can be controlled based on application profiles to facilitate safety compliance. For example, a system can execute a test suite to identify a function call of a software application that is associated with a functional safety standard issued by a standard-setting organization. In response to identifying the function call, the system can generate a risk score for the function call. The risk score can indicate a likelihood of the function call causing non-compliance with the functional safety standard. The system can further generate an application profile including a permission for the software application based on the risk score. The permission may disable the function call of the software application. The system may then execute the software application based on the application profile. As a result, execution of the software application can comply with the functional safety standard.
    Type: Grant
    Filed: October 13, 2023
    Date of Patent: June 16, 2026
    Assignee: Red Hat, Inc.
    Inventors: Leigh Griffin, Priyanka Verma
  • Patent number: 12659282
    Abstract: Cloud networks can be dynamically deployed for edge computing environments. For example, a control plane of a computing environment can detect a set of device identifiers and a set of priority levels for data transmitted by a set of edge devices in the computing environment. Each device identifier can correspond to an edge device in the set of edge devices. A network deployment service of the control plane can determine a network weight for the set of edge devices based on a set of device identifiers and the set of priority levels. The network deployment service can determine an adjustment to a virtual gateway based on the network weight. The virtual gateway can transmit data from the set of edge devices to a compute node in the computing environment. The network deployment service can execute the adjustment to the virtual gateway.
    Type: Grant
    Filed: February 21, 2024
    Date of Patent: June 16, 2026
    Assignee: Red Hat, Inc.
    Inventors: Stephen Coady, Archana Ravindar
  • Publication number: 20260161438
    Abstract: Techniques described herein relate to supporting legacy input/output (I/O) device functionality for virtual machines. For example, an I/O device can be communicatively coupled to a computing system. The I/O device may have an actual identification number. The I/O device may expose a window of I/O device memory to the computing system. The window of I/O device memory may be associated with a virtual I/O port that has a virtual identification number that differs from the actual identification number. An intermediate driver executed by the computing system can expose the window of I/O device memory to a virtual machine. the intermediate driver can map, for the virtual machine, access to the virtual I/O port via the window of I/O device memory using the virtual identification number. The virtual machine can, based on the mapping, transmit an access request to the window of I/O device memory via the virtual I/O port.
    Type: Application
    Filed: December 10, 2024
    Publication date: June 11, 2026
    Applicant: Red Hat, Inc.
    Inventor: Michael Tsirkin
  • Patent number: 12650868
    Abstract: System and method for running virtual machines within containers. An example method may include: running, by a host computer system, a hypervisor managing a first virtual machine implemented by a first container with a first set of resources, creating, by the hypervisor, a second container implementing the second virtual machine, wherein the second container is nested within the first container, determining, by the first virtual machine of the first container, one or more of the first set of resources to assign to the second container, and assigning, by the hypervisor, to the second container one or more of the first set of resources.
    Type: Grant
    Filed: August 3, 2021
    Date of Patent: June 9, 2026
    Assignee: Red Hat, Inc.
    Inventors: Michael Tsirkin, Amnon Ilan