IP Library Patent Application 13107434
Patent Application
App. No. 13/107,434

Distributed Policy Service

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/107,434
Abstract

According to one embodiment of the present disclosure, an approach is provided in which a policy server receives a request for a policy from a requestor. The policy server identifies an initiating virtual machine; the initial virtual machine's corresponding virtual network; and a destination virtual machine. Next, a policy corresponding to sending data from the first virtual machine to the second virtual machine is selected. The policy includes one or more logical references to the virtual network and does not include a physical reference to a physical entity located on a physical network. In turn, a physical path translation corresponding to the selected policy is identified and sent to the requestor.

Claims (66)

1 . (canceled)

2 . (canceled)

3 . (canceled)

4 . (canceled)

5 . (canceled)

6 . (canceled)

7 . (canceled)

8 . (canceled)

9 . (canceled)

10 . (canceled)

11 . (canceled)

12 . An information handling system comprising:

one or more processors;

one or more memories coupled to at least one of the processors;

a set of computer program instructions stored in one or more of the memories and executed by at least one of the processors in order to perform actions of:

receiving, at a first policy server, a policy request from a requestor;

identifying a first virtual machine and a second virtual machine that correspond to the policy request, wherein each of the virtual machines correspond to one or more virtual networks, and wherein the first virtual machine corresponds to a first virtual network included in the one or more virtual networks;

selecting a policy that corresponds to sending data from the first virtual machine to the second virtual machine, wherein the policy includes one or more logical references to the first virtual network and is devoid of a physical reference to a physical entity located on a physical network;

identifying a physical path translation that corresponds to the selected policy; and

sending the physical path translation to the requestor.

13 . The information handling system of claim 12 wherein one or more of the processors perform additional actions comprising:

determining that the first policy server does not correspond with the first virtual network;

in response to the determination, identifying a second policy server that corresponds to the first virtual network;

sending a query to the second policy server, the query corresponding to the physical path translation; and

receiving the physical path translation from the second policy server in response to the querying.

14 . The information handling system of claim 13 wherein one or more of the processors perform additional actions comprising:

in response to determining that the first policy server does not correspond to the first virtual network, querying a third policy server for a remote policy server identifier that corresponds to the first virtual network; and

receiving, by the third policy server at the first policy server, the remote policy server identifier that identifies the second policy server.

15 . The information handling system of claim 12 wherein the requestor is a policy module.

16 . The information handling system of claim 15 wherein a plurality of policies and a plurality of physical path translations are included in a distributed policy service that includes a plurality of policy servers, wherein the plurality of policy servers include one or more policy information servers and one or more policy reference servers; and

wherein the plurality of policy servers are configured hierarchically such that, upon failing to provide the physical path translation to the policy module, one of the policy information servers queries one of the policy reference servers to identify a different one of the policy information servers.

17 . The information handling system of claim 15 wherein, prior to receiving the request, one or more of the processors perform additional actions comprising:

determining, by the policy module, that the policy fails to be located in a local cache managed by the policy module; and

sending, by the policy module, the request for the policy to the first policy server in response to determining that the policy fails to be located in a local cache managed by the policy module.

18 . The information handling system of claim 15 wherein, prior to receiving the request, one or more of the processors perform additional actions comprising:

retrieving, by the policy module, a deprecated policy from a local cache managed by the policy module;

encapsulating the data with a deprecated physical path translation that corresponds to the deprecated policy;

sending the encapsulated data to the second virtual machine through a destination policy module;

receiving, at the policy module, a message from the destination policy module that the deprecated policy is invalid; and

sending, by the policy module, the request for the policy to the first policy server in response to receiving the message from the destination policy module that the deprecated policy is invalid.

19 . A computer program product stored in a computer readable storage medium, comprising computer program code that, when executed by an information handling system, causes the information handling system to perform actions comprising:

receiving, at a first policy server, a policy request from a requestor;

identifying a first virtual machine and a second virtual machine that correspond to the policy request, wherein each of the virtual machines correspond to one or more virtual networks, and wherein the first virtual machine corresponds to a first virtual network included in the one or more virtual networks;

selecting a policy that corresponds to sending data from the first virtual machine to the second virtual machine, wherein the policy includes one or more logical references to the first virtual network and is devoid of a physical reference to a physical entity located on a physical network;

identifying a physical path translation that corresponds to the selected policy; and

sending the physical path translation to the requestor.

20 . The computer program product of claim 19 wherein the information handling system performs further actions comprising:

determining that the first policy server does not correspond with the first virtual network;

in response to the determination, identifying a second policy server that corresponds to the first virtual network;

sending a query to the second policy server, the query corresponding to the physical path translation; and

receiving the physical path translation from the second policy server in response to the querying.

21 . The computer program product of claim 20 wherein the information handling system performs further actions comprising:

in response to determining that the first policy server does not correspond to the first virtual network, querying a third policy server for a remote policy server identifier that corresponds to the first virtual network; and

receiving, by the third policy server at the first policy server, the remote policy server identifier that identifies the second policy server.

22 . The computer program product of claim 19 wherein the requestor is a policy module.

23 . The computer program product of claim 22 wherein a plurality of policies and a plurality of physical path translations are included in a distributed policy service that includes a plurality of policy servers, wherein the plurality of policy servers include one or more policy information servers and one or more policy reference servers; and

wherein the plurality of policy servers are configured hierarchically such that, upon failing to provide the physical path translation to the policy module, one of the policy information servers queries one of the policy reference servers to identify a different one of the policy information servers.

24 . The computer program product of claim 22 wherein, prior to receiving the request, the information handling system performs further actions comprising:

determining, by the policy module, that the policy fails to be located in a local cache managed by the policy module; and

sending, by the policy module, the request for the policy to the first policy server in response to determining that the policy fails to be located in a local cache managed by the policy module.

25 . The computer program product of claim 22 wherein, prior to receiving the request, the information handling system performs further actions comprising:

retrieving, by the policy module, a deprecated policy from a local cache managed by the policy module;

encapsulating the data with a deprecated physical path translation that corresponds to the deprecated policy;

sending the encapsulated data to the second virtual machine through a destination policy module;

receiving, at the policy module, a message from the destination policy module that the deprecated policy is invalid; and

sending, by the policy module, the request for the policy to the first policy server in response to receiving the message from the destination policy module that the deprecated policy is invalid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: BARABASH, KATHERINE; COHEN, RAMI; JAIN, VINIT; RECIO, RENATO J.; ROCHWERGER, BENNY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 026396/0408 →