The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 18, 2021

Filed:

Jun. 05, 2018
Applicant:

Illumio, Inc., Sunnyvale, CA (US);

Inventors:

Juraj George Fandli, Campbell, CA (US);

Mukesh Gupta, Fremont, CA (US);

Assignee:

ILLUMIO, INC., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 9/455 (2018.01); H04L 12/24 (2006.01); H04L 29/06 (2006.01); H04L 29/08 (2006.01); H04L 9/30 (2006.01);
U.S. Cl.
CPC ...
H04L 41/0893 (2013.01); G06F 9/45558 (2013.01); H04L 9/3073 (2013.01); H04L 63/0263 (2013.01); H04L 63/12 (2013.01); H04L 67/303 (2013.01); G06F 2009/45562 (2013.01); G06F 2009/45579 (2013.01);
Abstract

A container orchestration server stores pairing keys in association with container profiles. A container orchestration agent executing on an operating system instance instantiates a new container according to a particular container profile in response to an instruction from the container orchestration server and stores the pairing key as metadata associated with the container. An enforcement module detects the instantiation of the container and obtains the corresponding pairing key from the container orchestration agent. The enforcement module transmits the pairing key to a segmentation server for validation. If the segmentation server validates the key, the segmentation server determines a label set corresponding to the container profile associated with the pairing key and generates management instructions for the container based on the label set. The management instructions, when enforced by the operating system, controls communications between the container and other workloads in accordance with a segmentation policy.


Find Patent Forward Citations

Loading…