Patents Assigned to VMWARE LLC
-
Patent number: 12743283Abstract: Disclosed are various embodiments for a unified boot image that can be used to install an operating system onto a host machine and a respective operating system onto a data processing units (DPU) installed on a host machine. The unified boot image contains installation files for installing an operating system on the host machine and an installation depot that can be used to create a boot image for installing the same or different operating system on the DPU. During installation of an operating system on a host machine the installation workflow can also require installation of an additional operating system or other configuration of a DPU installed in a host machine. In response to determining that an operating system is to be installed on the DPU, the installation depot can be obtained and reformatted into a downloadable format that is compatible with the DPU.Type: GrantFiled: June 17, 2024Date of Patent: September 22, 2026Assignee: VMware LLCInventors: Aravinda Haryadi, Karthik Ramachandra, Suman Boro
-
Patent number: 12739189Abstract: Some embodiments provide a novel method for efficiently assigning replication-multicast network addresses to overlay-multicast groups of machines executing on host computers of a software-defined network (SDN). For a source machine that is a source of one or more multicast flows, an SDN controller receives from the source machine an overlay-multicast group network address of an overlay-multicast group for which the source machine is the source, and an overlay-multicast source network address associated with the source machine. The SDN controller uses the overlay-multicast group and source network addresses to determine a replication-multicast network address for the overlay-multicast group. The replication-multicast group network address is determined using both the overlay-multicast group and source network address to avoid different overlay-multicast groups being assigned a same replication-multicast network address.Type: GrantFiled: July 11, 2023Date of Patent: September 15, 2026Assignee: VMware LLCInventors: Chidambareswaran Raman, Senthilkumar Karunakaran, Subin Cyriac Mathew
-
Patent number: 12739253Abstract: Systems, apparatus, articles of manufacture, and methods are disclosed for converting enforcement policy information into provisioning template information by instantiating or executing machine-readable instructions to determine a type of a first placeholder of a provisioning template with a plurality of placeholders, copy enforcement policy data corresponding to the determined type of the first placeholder, fill the first placeholder of the provisioning template with the copied enforcement policy data, and save the provisioning template.Type: GrantFiled: April 26, 2024Date of Patent: September 15, 2026Assignee: VMware LLCInventors: Siddharth Sukumar Burle, Manish Jain, Vishal Gupta, Amit Meena, Suraj Malgave
-
Patent number: 12739259Abstract: Example methods and systems for multi-engine intrusion detection are described. In one example, a computer system may configure a set of multiple intrusion detection system (IDS) engines that include at least a first IDS engine and a second IDS engine. In response to detecting establishment of a first packet flow and a second packet flow, the computer system may assign the first packet flow to the first IDS engine and second packet flow to the second engine based on an assignment policy. This way, first packet flow inspection may be performed using the first IDS engine to determine whether first packet(s) associated with the first packet flow are potentially malicious. Second packet flow inspection may be performed using the second IDS engine to determine whether second packet(s) associated with the second packet flow are potentially malicious.Type: GrantFiled: May 31, 2023Date of Patent: September 15, 2026Assignee: VMware LLCInventors: Mandar Nanivadekar, Paraskumar Prajapati
-
Patent number: 12737211Abstract: Some embodiments provide a method for establishing secure connections between several services operating in an on-premises network and external devices operating in an external network. The method configures each service to communicate with a reverse proxy operating in the on-premises network. The reverse proxy establishes a secure connection with each service. The method programs the reverse proxy to communicate with a forward proxy that establishes communications with the external devices. In some embodiments, the forward proxy is part of the on-premises network, while in other embodiments the forward proxy is a cloud-based service. Through the reverse and forward proxies, the on-premises services communicate with the external devices securely. For instance, in some embodiments, the forward proxy hides internal network addresses (e.g., IP addresses) and domain names of on-premises services and allows administrators to configure network monitoring to monitor and block malicious activities.Type: GrantFiled: June 19, 2023Date of Patent: September 15, 2026Assignee: VMware LLCInventors: Anant Bobde, Ashwin Manekar, Ankur Gupta, Anima Jain
-
Patent number: 12724631Abstract: A method of deploying virtual infrastructure on hardware infrastructure to support execution of software on the virtual infrastructure, includes the steps of: retrieving a hardware bill of materials (BOM) separately for each of a plurality of hardware devices of a group of hardware devices by using identifying information of each of the plurality of hardware devices, wherein the retrieved hardware BOMs include details about hardware components of different hardware device models corresponding to the plurality of hardware devices; determining, based on the details from the retrieved hardware BOMs, policies to apply to a deployment of the virtual infrastructure on the plurality of hardware devices; and deploying the virtual infrastructure on the plurality of hardware devices according to the determined policies.Type: GrantFiled: May 24, 2023Date of Patent: September 1, 2026Assignee: VMware LLCInventors: Emily Hong Xu, Russell Jew, Rama Koteswari Sudireddi
-
Patent number: 12726402Abstract: Some embodiments provide an elastic architecture for providing a service in a computing system. To perform a service on the data messages, the service architecture uses a service node (SN) group that includes one primary service node (PSN) and zero or more secondary service nodes (SSNs). The service can be performed on a data message by either the PSN or one of the SSN. However, in addition to performing the service, the PSN also performs a load balancing operation that assesses the load on each service node (i.e., on the PSN or each SSN), and based on this assessment, has the data messages distributed to the service node(s) in its SN group. Based on the assessed load, the PSN in some embodiments also has one or more SSNs added to or removed from its SN group. To add or remove an SSN to or from the service node group, the PSN in some embodiments directs a set of controllers to add (e.g., instantiate or allocate) or remove the SSN to or from the SN group.Type: GrantFiled: June 19, 2023Date of Patent: September 1, 2026Assignee: VMware LLCInventors: Jayant Jain, Anirban Sengupta, Mohan Parthasarathy
-
Patent number: 12726429Abstract: Example methods and systems for connectivity service provisioning for a software-defined data center (SDDC) group are described. In one example, a computer system may detect an event that affects a first connectivity service connecting multiple members of the SDDC group. The computer system may obtain first routing information that is applicable in a first SDDC; and second routing information that is applicable in a second SDDC. In response to the event, the computer system may generate and send a first instruction towards the first SDDC and a second instruction towards the second SDDC to cause: (a) the first SDDC and second SDDC to establish a second connectivity service; (b) the first SDDC to update the first routing information to associate a first flow with the second connectivity service; and (c) the second SDDC to update the second routing information to associate a second flow with the second connectivity service.Type: GrantFiled: August 23, 2024Date of Patent: September 1, 2026Assignee: VMware LLCInventors: Chandan Ghosh, Gaurav Jindal, Neeraj Mantri
-
Patent number: 12719746Abstract: Some embodiments of the invention provide a method for implementing an edge device that handles data traffic between a logical network and an external network. The method monitors resource usage of a node pool that includes multiple nodes that each executes a respective set of pods. Each of the pods is for performing a respective set of data message processing operations for at least one of multiple logical routers. The method determines that a particular node in the node pool has insufficient resources for the particular node's respective set of pods to adequately perform their respective sets of data message processing operations. Based on the determination, the method automatically provides additional resources to the node pool by instantiating at least one additional node in the node pool.Type: GrantFiled: November 27, 2024Date of Patent: August 25, 2026Assignee: VMware LLCInventors: Yong Wang, Cheng-Chun Tu, Sreeram Kumar Ravinoothala, Yu Ying
-
Patent number: 12710997Abstract: An example system obtains a request to deploy a cloud template, sorts a plurality of cloud zones in a list based on cost, the plurality of cloud zones being candidates to execute the cloud template, selects a first one of the cloud zones in the list based on the first one of the cloud zones corresponding to a first cost that is lower than second costs of other ones of the cloud zones in the list, and deploys the cloud template on one or more instances of the computing resources corresponding to the first one of the cloud zones.Type: GrantFiled: June 6, 2023Date of Patent: August 18, 2026Assignee: VMware LLCInventors: Stoyan Genchev, Marin Dzhigarov, Ventsyslav Raikov
-
Patent number: 12712761Abstract: Example methods and systems for health-aware overlay packet forwarding are described. In one example, a first computer system may monitor multiple paths between a first tunnel endpoint (TEP) group and a second TEP group. The first computer system may update health information to indicate that at least a first path is healthy, and a second path is unhealthy. In response to detecting an egress packet that is associated with a packet flow, the first computer system may map the egress packet to the first path instead of the second path based on the health information. The first computer system may generate and forward an encapsulated packet along the first path towards the second computer system, wherein the encapsulated packet includes the egress packet and an outer header that is addressed from a first TEP to a second TEP associated with the first path.Type: GrantFiled: October 29, 2024Date of Patent: August 18, 2026Assignee: VMware LLCInventors: Subin Cyriac Mathew, Kaiwei Fan, Chidambareswaran Raman, Thea Corinne Rossman, Shuomin Liu
-
Patent number: 12712844Abstract: A method for network address management is provided. Embodiments include determining a creation of a namespace associated with a cluster of computing devices, wherein a subset of computing resources of the cluster of computing devices is allocated to the namespace. Embodiments include assigning, to the namespace, a network address pool comprising a plurality of network addresses in a subnet, wherein the assigning causes the plurality of network addresses to be reserved exclusively for the namespace. Embodiments include receiving an indication that a pod is added to the namespace. Embodiments include, in response to the receiving of the indication, assigning a network address from the network address pool to the pod.Type: GrantFiled: September 23, 2024Date of Patent: August 18, 2026Assignee: VMware LLCInventors: Xiaopei Liu, Jianjun Shen, Donghai Han, Wenfeng Liu, Danting Liu
-
Patent number: 12705085Abstract: Some embodiments provide a method for operating a physical server in a network. The method stores multiple copies of a virtual machine (VM) image at a network-accessible storage. The method uses a first copy of the VM image as a virtual disk to execute a VM on a hypervisor of a first physical computing device. The method uses a second copy of the VM image as a virtual disk accessible via a smart network interface controller (NIC) of a second physical computing device to execute an operating system of the second physical computing device.Type: GrantFiled: January 15, 2024Date of Patent: August 11, 2026Assignee: VMware LLCInventor: Renaud B. Voltz
-
Patent number: 12706820Abstract: A method of collecting health check metrics for a network is provided. The method, at a deep packet inspector on a physical host in a datacenter, receives a copy of a network packet from a load balancer. The packet includes a plurality of layers. Each layer corresponds to a communication protocol in a plurality of communication protocols. The method identifies an application referenced in the packet. The method analyzes the information in one or more layers of the packet to determine metrics for the source application. The method sends the determined metrics to the load balancer.Type: GrantFiled: August 30, 2024Date of Patent: August 11, 2026Assignee: VMware LLCInventors: Alok S. Tiagi, Jayant Jain, Anirban Sengupta, Srinivas Nimmagadda, Rick Lund
-
Patent number: 12705082Abstract: Some embodiments of the invention provide a method of migrating a VM from a first host computer to a second host computer, the first host computer having a first PNIC that performs at least one of network forwarding operations and middlebox service operations for the VM. At an RDMA client executing on a set of one or more processors of the first host computer, the method directs an RDMA server executing on the first PNIC to provide networking state data associated with at least one of network forwarding operations and middlebox service operations that the first PNIC performs for the VM. The provided networking state data resides in a memory of the first PNIC that is accessible to the RDMA server. At the RDMA client, the method provides the obtained networking state data to the second host computer as part of a data migration that is performed to migrate the VM from the first host computer to the second host computer.Type: GrantFiled: August 21, 2023Date of Patent: August 11, 2026Assignee: VMware LLCInventors: Wenyi Jiang, Jingchun Jason Jiang, Ankur Kumar Sharma
-
Patent number: 12699671Abstract: Some embodiments provide a method of providing distributed storage services to a host computer from a network interface card (NIC) of the host computer. At the NIC, the method accesses a set of one or more external storages operating outside of the host computer through a shared port of the NIC that is not only used to access the set of external storages but also for forwarding packets not related to an external storage. In some embodiments, the method accesses the external storage set by using a network fabric storage driver that employs a network fabric storage protocol to access the external storage set. The method presents the external storage as a local storage of the host computer to a set of programs executing on the host computer. In some embodiments, the method presents the local storage by using a storage emulation layer on the NIC to create a local storage construct that presents the set of external storages as a local storage of the host computer.Type: GrantFiled: October 2, 2023Date of Patent: August 4, 2026Assignee: VMware LLCInventors: Shoby A. Cherian, Anjaneya P. Gondi, Hemanth Kalluri, Sanjay Vasudev Acharya, Marcus Armando Benedetto Campi
-
Patent number: 12699582Abstract: An example system may include a first endpoint executing a remote collector and a second endpoint in communication with the first endpoint. The remote collector may monitor the second endpoint. The remote collector may include an agent installation unit to install a monitoring agent with configuration data on the second endpoint. The configuration data may specify a configuration for the monitoring agent to monitor a first program executing in the second endpoint. Further, the second endpoint may include a buffer limit configuration unit to execute the monitoring agent in a test mode to determine a first number of metrics to be collected in one cycle based on the configuration data. Furthermore, the buffer limit configuration unit may configure a buffer limit of the monitoring agent based on the first number of metrics and, upon configuring the buffer limit, enable the monitoring agent to monitor the first program.Type: GrantFiled: May 10, 2023Date of Patent: August 4, 2026Assignee: VMware LLCInventors: Abhishek Singh, Vinothkumar D, Atreyee Bhaduri, Bhuvaneswari Addanki, Akansha Srivastava
-
Patent number: 12701145Abstract: Some embodiments provide a novel method for defining a set of policies for a set of applications executing on a host computer of a software-defined network (SDN). The method configures, on a physical network interface card (PNIC) connected to the host computer, a network adapter to create a logical port that connects an interface of the host computer to a virtual distributed switch (VDS) executing on the PNIC. The method defines the set of policies based on the logical port for the VDS to apply to data message flows sent from the set of applications on the host computer to one or more other host computers of the SDN.Type: GrantFiled: October 19, 2023Date of Patent: August 4, 2026Assignee: VMware LLCInventors: Subin Cyriac Mathew, Chidambareswaran Raman, Mukesh Hira
-
Patent number: 12695699Abstract: Some embodiments provide a novel method for configuring edge routers in a first network. The method configures on a first compute node of the first network (1) a first higher-level edge router and (2) a set of lower-level edge routers. Each lower-level edge router is configured for a different set of subnetworks defined in the first network and is connected to an external second network through the first higher-level edge router. The method detects a condition that requires a particular lower-level edge router for a particular subnetwork to be moved to another compute node. The method configures the particular lower-level edge router to operate on a second compute node below a second higher-level edge router operating on the second compute node to connect the particular lower-level edge router to the external second network.Type: GrantFiled: April 30, 2024Date of Patent: July 28, 2026Assignee: VMware LLCInventors: Gaurav Jindal, Chandan Ghosh, Neeraj Mantri
-
Patent number: 12695667Abstract: For a network control system that receives, from a user, logical datapath sets that logically express desired forwarding behaviors that are to be implemented by a set of managed switching elements, a controller for managing several managed switching elements that forward data in a network that includes the managed switching elements is described. The controller includes a set of modules for detecting a change in one or more managed switching elements and for updating logical datapath set based on the detected change. The logical datapath set is for subsequent translation into a set of physical forwarding behaviors of the managed switching elements.Type: GrantFiled: April 11, 2024Date of Patent: July 28, 2026Assignee: VMware LLCInventors: Martin Casado, Teemu Koponen, W. Andrew Lambeth, Pankaj Thakkar