IP Library Granted Patent US 8,572,609
Granted Patent B2
US 8,572,609 · App. 12/496,484 · Granted Oct 29, 2013

Configuring bypass functionality of a network device based on the state of one or more hosted virtual machines

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,572,609
App. No.
12/496,484
Granted
Oct 29, 2013
Kind
B2
Abstract

Network devices include hosted virtual machines and virtual machine applications. Hosted virtual machines and their applications implement additional functions and services in network devices. Network devices include data taps for directing network traffic to hosted virtual machines and allowing hosted virtual machines to inject network traffic. Network devices include unidirectional data flow specifications, referred to as hyperswitches. Each hyperswitch is associated with a hosted virtual machine and receives network traffic received by the network device from a single direction. Each hyperswitch processes network traffic according to rules and rule criteria. A hosted virtual machine can be associated with multiple hyperswitches, thereby independently specifying the data flow of network traffic to and from the hosted virtual machine from multiple networks. The network device architecture also enables the communication of additional information between the network device and one or more virtual machine applications using an extended non-standard network protocol.

Claims (38)

1. A method of maintaining a network device including a plurality of hosted virtual machines, the method comprising:

the network device communicating a first message to a first hosted virtual machine, wherein the network device includes the first hosted virtual machine and a second hosted virtual machine;

waiting a time duration to receive a second message from the first hosted virtual machine, wherein the second message is received in response to the first message;

in response to not receiving the second message from the first hosted virtual machine within the time duration, configuring a virtual machine data interface in the network device such that network traffic in the network device bypasses the first hosted virtual machine but does not bypass the second hosted virtual machine, wherein the network traffic that bypasses the first hosted virtual machine is either dropped or communicated to an intended destination;

in response to not receiving the second message within the time duration from the first hosted virtual machine and detecting that a virtual machine application in the first hosted virtual machine is expected to perform a critical function, enabling a network device bypass function so that the network device does not process any portion of the network traffic;

in response to receiving the second message within the time duration and determining that the virtual machine data interface is configured such that the network traffic bypasses the first hosted virtual machine but does not bypass the second hosted virtual machine, configuring the virtual machine data interface such that the network traffic does not bypass the first hosted virtual machine and also does not bypass the second hosted virtual; and

in response to receiving the second message within the time duration and determining that the network device bypass function is enabled, disabling the network device bypass functioned.

2. The method of claim 1 , wherein the first message is adapted to be received and processed by a virtual network interface executing within the first hosted virtual machine.

3. The method of claim 2 , wherein the first message is a ping message.

4. The method of claim 1 , comprising:

enabling a network device bypass function, such that the network traffic bypasses all processing by the network device.

5. The method of claim 1 , comprising:

directing the network device to reset at least the first hosted virtual machine.

6. The method of claim 1 , wherein configuring the virtual machine data interface comprises:

configuring a first hyperswitch interface associated with the first hosted virtual machine to enable a first bypass mode, such that the first hyperswitch interface passes the network traffic without evaluation by network traffic rule criteria included in the first hyperswitch interface.

7. The method of claim 6 , comprising:

configuring a second hyperswitch interface associated with the first hosted virtual machine to enable a second bypass mode, such that the second hyperswitch interface passes the network traffic without evaluation by network traffic rule criteria included in the second hyperswitch interface.

8. The method of claim 7 , wherein the first hyperswitch interface is adapted to process a first portion of the network traffic directed in a first direction and the second hyperswitch interface is adapted to process a second portion of the network traffic directed in a second direction.

9. A method of maintaining a network device including a plurality of hosted virtual machines, the method comprising:

waiting a time duration to receive a first message from the first hosted virtual machine, wherein the first message is generated by the first hosted virtual machine, wherein the network device includes the first hosted virtual machine and a second hosted virtual machine;

in response to not receiving the first message within the time duration, the network device configuring a virtual machine data interface such that network traffic bypasses the first hosted virtual machine but does not bypass the second hosted virtual machine, wherein the network traffic that bypasses the first hosted virtual machine is either dropped or communicated to an intended destination;

in response to not receiving the first message within the time duration from the first hosted virtual machine and detecting that a virtual machine application in the first hosted virtual machine is expected to perform a critical function, enabling a network device bypass function so that the network device does not process any portion of the network traffic;

in response to receiving the first message within the time duration and determining that the virtual machine data interface is configured such that the network traffic bypasses the first hosted virtual machine but does not bypass the second hosted virtual machine, configuring the virtual machine data interface such that the network traffic does not bypass the first hosted virtual machine and also does not bypass the second hosted virtual machine; and

in response to receiving the first message within the time duration and determining that the network device bypass function is enabled, disabling the network device bypass function.

10. The method of claim 9 , wherein the first message is adapted to be received and processed by a module of the network device outside of the first hosted virtual machine.

11. The method of claim 10 , wherein the first message is a ping message.

12. The method of claim 9 , wherein the first message is generated by a virtual machine application executed by the first hosted virtual machine.

13. The method of claim 9 , wherein the first message is generated by a virtual machine network interface executed by the first hosted virtual machine.

14. The method of claim 9 , wherein the first message is generated according to a periodic schedule based on the time duration.

15. The method of claim 9 , comprising:

enabling a network device bypass function, such that the network traffic bypasses all processing by the network device.

16. The method of claim 9 , comprising:

directing the network device to reset at least the first hosted virtual machine.

17. The method of claim 9 , wherein configuring the virtual machine data interface comprises:

configuring a first hyperswitch interface associated with the first hosted virtual machine to enable a first bypass mode, such that the first hyperswitch interface passes the network traffic without evaluation by network traffic rule criteria included in the first hyperswitch interface.

18. The method of claim 17 , comprising:

configuring a second hyperswitch interface associated with the first hosted virtual machine to enable a second bypass mode, such that the second hyperswitch interface passes the network traffic without evaluation by network traffic rule criteria included in the second hyperswitch interface.

19. The method of claim 18 , wherein the first hyperswitch interface is adapted to process a first portion of the network traffic directed in a first direction and the second hyperswitch interface is adapted to process a second portion of the network traffic directed in a second direction.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2015
From: WU, DAVID
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035096/0549 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →