IP Library Granted Patent US 8,634,437
Granted Patent B2
US 8,634,437 · App. 12/496,466 · Granted Jan 21, 2014

Extended network protocols for communicating metadata with virtual machines

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,634,437
App. No.
12/496,466
Granted
Jan 21, 2014
Kind
B2
Abstract

Network devices include hosted virtual machines and virtual machine applications. Hosted virtual machines and their applications implement additional functions and services in network devices. Network devices include data taps for directing network traffic to hosted virtual machines and allowing hosted virtual machines to inject network traffic. Network devices include unidirectional data flow specifications, referred to as hyperswitches. Each hyperswitch is associated with a hosted virtual machine and receives network traffic received by the network device from a single direction. Each hyperswitch processes network traffic according to rules and rule criteria. A hosted virtual machine can be associated with multiple hyperswitches, thereby independently specifying the data flow of network traffic to and from the hosted virtual machine from multiple networks. The network device architecture also enables the communication of additional information between the network device and one or more virtual machine applications using an extended non-standard network protocol.

Claims (41)

1. A method of exchanging data between hosted virtual machines within a network device, the method comprising:

receiving, via a first network connection of a first network device, a first network packet directed to a destination network device outside the first network device;

redirecting the first network packet to a first virtual machine hosted by the first network device;

adding extension data to the first network packet within the first virtual machine to form a first modified network packet;

forwarding the first modified network packet towards the destination network device outside the first network device;

redirecting the first modified network packet to a second virtual machine hosted by the first network device;

extracting the extension data from the first modified network packet within the second virtual machine; and

providing the extension data to a first virtual machine application executing within the second virtual machine.

2. The method of claim 1 , wherein the first network packet includes network packet data, wherein adding the extension data comprises:

adding the extension data to a portion of the first network packet outside the network packet data.

3. The method of claim 2 , wherein the first network packet includes network packet attributes, wherein adding the extension data comprises:

adding the extension data to a portion of the first network packet outside the network packet attributes.

4. The method of claim 3 , wherein the extension data is added to the first network packet as at least one layer 2 packet attribute.

5. The method of claim 4 , wherein the network packet attributes include layer 4 attributes.

6. The method of claim 1 , wherein the first network packet includes network packet data, wherein adding the extension data comprises:

receiving, by a first virtual network interface associated with the first virtual machine, the extension data from a second virtual machine application executing within the first virtual machine; and

adding, by the first virtual network interface, the received extension data to a portion of the first network packet outside the network packet attributes.

7. The method of claim 1 , wherein the first modified network packet includes network packet data received with the first network packet, wherein extracting the extension data comprises:

receiving, by a first virtual network interface associated with the second virtual machine, the first modified network packet;

searching the first modified network packet for a first network packet attribute added after the first network packet was received via the first network connection of the first network device; and

extracting the extension data from the first network packet attribute.

8. The method of claim 7 , comprising:

forwarding the network packet data to the first virtual machine application without the extension data;

receiving a query from the first virtual machine application; and

providing the extension data to the first virtual machine application in response to the query.

9. The method of claim 8 , wherein the query is received by the first virtual network interface associated with the second virtual machine.

10. The method of claim 1 , wherein adding the extension data comprises:

generating the extension data within the first virtual machine.

11. The method of claim 10 , wherein the first network packet includes network packet data, wherein adding the extension data comprises:

analyzing the network packet data using a second virtual machine application executing within the first virtual machine; and

generating the extension data based on at least the analysis of the network packet data.

12. The method of claim 11 , wherein the first network packet includes network packet attributes, wherein the extension data is not based on the network packet attributes included in the first network packet.

13. The method of claim 1 , wherein redirecting the first network packet to the first virtual machine hosted by the first network device comprises:

transporting the first network packet through a virtual network within the first network device to a first virtual network interface associated with the first virtual machine.

14. The method of claim 13 , wherein transporting the first network packet through the virtual network with the first network device comprises:

using network address translation to redirect the first network packet to a virtual network address on the virtual network within the first network device associated with the first virtual machine.

15. The method of claim 1 , wherein the first network packet and the first modified network packet includes network packet data received with the first network packet, the method comprising:

forwarding a second network packet including the network packet data from the second virtual machine towards the destination network device outside the first network device via a virtual network within the first network device; and

outputting the second network packet to a physical network via a second network connection of the network device.

16. The method of claim 1 , wherein the first modified network packet includes network packet attributes including the extension data, wherein the network packet attributes include an identifier of an application associated with the network packet data.

17. The method of claim 1 , wherein the first modified network packet includes network packet attributes including the extension data, wherein the network packet attributes include an identifier of a data type associated with the network packet data.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2015
From: WU, DAVID
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035096/0551 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →