IP Library Granted Patent US 8,954,957
Granted Patent B2
US 8,954,957 · App. 12/496,430 · Granted Feb 10, 2015

Network traffic processing according to network traffic rule criteria and transferring network traffic metadata in a network device that includes hosted virtual machines

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,954,957
App. No.
12/496,430
Granted
Feb 10, 2015
Kind
B2
Abstract

Network devices include hosted virtual machines and virtual machine applications. Hosted virtual machines and their applications implement additional functions and services in network devices. Network devices include data taps for directing network traffic to hosted virtual machines and allowing hosted virtual machines to inject network traffic. Network devices include unidirectional data flow specifications, referred to as hyperswitches. Each hyperswitch is associated with a hosted virtual machine and receives network traffic received by the network device from a single direction. Each hyperswitch processes network traffic according to rules and rule criteria. A hosted virtual machine can be associated with multiple hyperswitches, thereby independently specifying the data flow of network traffic to and from the hosted virtual machine from multiple networks. The network device architecture also enables the communication of additional information between the network device and one or more virtual machine applications using an extended non-standard network protocol.

Claims (30)

1. A network device adapted to process network traffic, the network device comprising:

a memory;

a first network connection adapted to communicate first network traffic, wherein the first network connection is connected with a first network;

a second network connection adapted to communicate second network traffic, wherein the second network connection is connected with a second network;

a network traffic processing module connected with the first network connection and the second network connection;

a plurality of hosted virtual machines each adapted to execute at least one virtual machine application;

a virtual machine data interface connected with the plurality of hosted virtual machines and the network traffic processing module, wherein the virtual machine data interface is adapted to direct a first portion of the first network traffic and a first portion of the second network traffic according to network traffic rule criteria and network traffic rules;

a first network traffic tap adapted to direct at least the first portion of the first network traffic between the first network connection and the virtual machine data interface; and

a second network traffic tap adapted to direct at least a first portion of the second network traffic between the second network connection and the virtual machine data interface; and

at least one intra-module network traffic tap adapted to direct network traffic metadata from the network traffic processing module to the virtual machine data interface, wherein the network traffic metadata includes additional information describing application associated with the network traffic, and wherein the network traffic metadata is communicated to one or more virtual machine applications using an extended non-standard protocol that provides functionality of application programming interface;

wherein the virtual machine data interface is adapted to direct the first portion of the first network traffic and the first portion of the second network traffic between the first and second network traffic taps and the plurality of hosted virtual machines;

wherein the virtual machine data interface is adapted to direct the network traffic metadata between the intra-module network traffic tap and the plurality of hosted virtual machines.

2. The network device of claim 1 , wherein the first portion of the processed network traffic includes network traffic generated by the plurality of hosted virtual machines.

3. The network device of claim 1 , wherein:

the plurality of hosted virtual machines includes a first hosted virtual machine and a first virtual machine application adapted to perform a sequence of operations on processed network traffic, wherein the processed network traffic includes a second portion of the first network traffic, a second portion of the second network traffic, or both the second portion of the first network traffic and the second portion of the second network traffic.

4. The network device of claim 3 , comprising:

at least one intra-module network traffic tap adapted to direct at least a first portion of the processed network traffic within the sequence of operations between the first hosted virtual machine and the virtual machine data interface;

wherein the virtual machine data interface is adapted to direct the first portion of the processed network traffic between the plurality of hosted virtual machines and the first and second network traffic taps.

5. The network device of claim 1 , wherein:

the plurality of hosted virtual machines includes a first hosted virtual machine, wherein the first hosted virtual machine includes a first virtual network interface adapted to communicate the first portions of the first and second network traffic with a first virtual machine application, wherein the first portions of the first and second network traffic are received from the virtual machine data interface.

6. The network device of claim 1 , wherein the first network traffic includes network traffic received from a first network via the first network connection.

7. The network device of claim 1 , wherein the first network traffic includes network traffic generated by the plurality of hosted virtual machines and directed towards a first network via the first network connection.

8. The network device of claim 1 , wherein the network traffic rules include a redirect rule adapted to direct at least one of the first portions of the first and second network traffic to one of the plurality of hosted virtual machines.

9. The network device of claim 1 , wherein the network traffic rules include a copy rule adapted to direct a copy of the first portion of the first network traffic, the first portion of the second network traffic, or both first portion of the first network traffic and the first portion of the second network traffic to one of the plurality of hosted virtual machines.

10. The network device of claim 1 , wherein the network traffic rules include a drop rule adapted to discard one of the first portions of the first and second network traffic.

11. The network device of claim 1 , comprising:

a management module adapted to configure the first and second network traffic taps and the virtual machine data interface.

12. The network device of claim 1 , wherein the first network connection and the second network connection are connected with the first network.

13. The network device of claim 1 , wherein the first network connection is connected with the first network and the second network connection is connected with the second network.

14. The network device of claim 1 , wherein the network traffic rules include a pass rule adapted to bypass at least one of the first portions of the first and second network traffic around one of the plurality of hosted virtual machines.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2012
From: WU, DAVID; LY, KAND; TRAP, LAP; POTASHNIK, ALEXEI
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 028874/0589 →