Virtual Network Interface Objects
    1.
    发明申请
    Virtual Network Interface Objects 有权
    虚拟网络接口对象

    公开(公告)号:US20130132545A1

    公开(公告)日:2013-05-23

    申请号:US13339985

    申请日:2011-12-29

    IPC分类号: G06F15/173

    摘要: Methods and apparatus for interfaces to manage virtual network interface objects. A system may include resource instances and a network interface virtualization coordinator. Responsive to a record creation request, the coordinator creates an interface records that may include an IP address, subnet information and security properties. The coordinator may, in response to a request to attach the record to a resource instance, enable traffic directed to the IP address to flow to the resource instance. In response to a subsequent detach request, the traffic to the IP address may be disabled at the resource instance. The same interface record may be attached to another resource instance in response to another attach request, enabling traffic directed to the IP address to flow to the second resource instance.

    摘要翻译: 用于管理虚拟网络接口对象的接口的方法和设备。 系统可以包括资源实例和网络接口虚拟化协调器。 响应于记录创建请求,协调器创建可以包括IP地址,子网信息和安全属性的接口记录。 协调器可以响应于将记录附加到资源实例的请求,使得指向IP地址的流量流向资源实例。 响应于后续的分离请求,可能在资源实例处禁用到IP地址的流量。 响应于另一附加请求,可以将相同的接口记录附加到另一资源实例,使得指向IP地址的流量能够流向第二资源实例。

    Virtual network interface objects
    2.
    发明授权
    Virtual network interface objects 有权
    虚拟网络接口对象

    公开(公告)号:US08868710B2

    公开(公告)日:2014-10-21

    申请号:US13339985

    申请日:2011-12-29

    IPC分类号: G06F15/173

    摘要: Methods and apparatus for interfaces to manage virtual network interface objects. A system may include resource instances and a network interface virtualization coordinator. Responsive to a record creation request, the coordinator creates an interface records that may include an IP address, subnet information and security properties. The coordinator may, in response to a request to attach the record to a resource instance, enable traffic directed to the IP address to flow to the resource instance. In response to a subsequent detach request, the traffic to the IP address may be disabled at the resource instance. The same interface record may be attached to another resource instance in response to another attach request, enabling traffic directed to the IP address to flow to the second resource instance.

    摘要翻译: 用于管理虚拟网络接口对象的接口的方法和设备。 系统可以包括资源实例和网络接口虚拟化协调器。 响应于记录创建请求,协调器创建可以包括IP地址,子网信息和安全属性的接口记录。 协调器可以响应于将记录附加到资源实例的请求,使得指向IP地址的流量流向资源实例。 响应于后续的分离请求,可能在资源实例处禁用到IP地址的流量。 响应于另一附加请求,可以将相同的接口记录附加到另一资源实例,使得指向IP地址的流量能够流向第二资源实例。

    Flexibly configurable remote network identities
    3.
    发明授权
    Flexibly configurable remote network identities 有权
    灵活配置的远程网络身份

    公开(公告)号:US09438556B1

    公开(公告)日:2016-09-06

    申请号:US13461661

    申请日:2012-05-01

    IPC分类号: G06F15/177 H04L29/12

    摘要: A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.

    摘要翻译: 代表客户实体实现网络网关。 网络网关可以使用分布式计算机系统来实现,并且网络网关可以将客户实体的网络连接到公共通信网络。 网络网关可以包括网络相关服务,而不需要添加专门的硬件。 响应于从客户实体接收到的指令,网络网关可以以编程方式提供。 网络网关可以通过几种不同类型的数据连接进行配置和访问。 网络网关凭借在分布式计算机系统上的实现,可根据需要进行扩展,而无需客户实体的额外输入。

    Remotely configured network appliances and services
    5.
    发明授权
    Remotely configured network appliances and services 有权
    远程配置的网络设备和服务

    公开(公告)号:US09294437B1

    公开(公告)日:2016-03-22

    申请号:US13461478

    申请日:2012-05-01

    IPC分类号: G06F15/173 H04L29/06

    摘要: A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.

    摘要翻译: 代表客户实体实现网络网关。 网络网关可以使用分布式计算机系统来实现,并且网络网关可以将客户实体的网络连接到公共通信网络。 网络网关可以包括网络相关服务,而不需要添加专门的硬件。 响应于从客户实体接收到的指令,网络网关可以以编程方式提供。 网络网关可以通过几种不同类型的数据连接进行配置和访问。 网络网关凭借在分布式计算机系统上的实现,可根据需要进行扩展,而无需客户实体的额外输入。

    Network gateway services and extensions
    6.
    发明授权
    Network gateway services and extensions 有权
    网络网关服务和扩展

    公开(公告)号:US09288182B1

    公开(公告)日:2016-03-15

    申请号:US13461566

    申请日:2012-05-01

    摘要: A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.

    摘要翻译: 代表客户实体实现网络网关。 网络网关可以使用分布式计算机系统来实现,并且网络网关可以将客户实体的网络连接到公共通信网络。 网络网关可以包括网络相关服务,而不需要添加专门的硬件。 响应于从客户实体接收到的指令,网络网关可以以编程方式提供。 网络网关可以通过几种不同类型的数据连接进行配置和访问。 网络网关凭借在分布式计算机系统上的实现,可根据需要进行扩展,而无需客户实体的额外输入。

    Managing use of intermediate destination computing nodes for provided computer networks
    8.
    发明授权
    Managing use of intermediate destination computing nodes for provided computer networks 有权
    管理提供的计算机网络的中间目的地计算节点的使用

    公开(公告)号:US08224931B1

    公开(公告)日:2012-07-17

    申请号:US12752034

    申请日:2010-03-31

    IPC分类号: G06F15/16

    摘要: Techniques are described for providing managed computer networks. In some situations, the techniques include managing communications for computing nodes of a managed computer network by using one or more particular computing nodes of the managed computer network that are configured to operate as intermediate destinations to handle at least some communications that are sent by and/or directed to one or more other computing nodes of the managed computer network. For example, a manager module associated with a source computing node may select one or more particular intermediate destination computing nodes to use for one or more particular communications from the source computing node to an indicated final destination, such as based on a configured logical network topology for the managed computer network. The manager module then forwards those communications to a first of the selected intermediate destination computing nodes for further handling.

    摘要翻译: 描述了提供托管计算机网络的技术。 在一些情况下,这些技术包括通过使用被管理计算机网络的一个或多个特定计算节点来管理被管理计算机网络的计算节点的通信,该特定计算节点被配置为作为中间目的地来操作至少一些由 或被引导到被管理计算机网络的一个或多个其他计算节点。 例如,与源计算节点相关联的管理器模块可以选择一个或多个特定的中间目的地计算节点,以用于从源计算节点到指定的最终目的地的一个或多个特定通信,诸如基于配置的逻辑网络拓扑 用于托管计算机网络。 管理器模块然后将这些通信转发到所选择的中间目的地计算节点中的第一个,以便进一步处理。

    Packet authentication and encryption in virtual networks

    公开(公告)号:US08584228B1

    公开(公告)日:2013-11-12

    申请号:US12654706

    申请日:2009-12-29

    IPC分类号: H04L29/06 H04L9/14

    摘要: Systems and methods provide logic for distributing cryptographic keys in a physical network comprising a plurality of physical nodes. In one implementation, a computer-implemented method is provided for distributing cryptographic keys in a physical network. The method includes receiving information mapping a virtual network address of a virtual node to a physical network address of a physical node. The virtual node may be associated with a virtual network hosted by the physical node, and the received mapping information identifies a virtual network address of the node and the physical network address of the node. The mapping service transmits a current version of a cryptographic key and an identifier of the current version to the physical node.