IP Library Granted Patent US 9,009,782
Granted Patent B2
US 9,009,782 · App. 13/970,535 · Granted Apr 14, 2015

Steering traffic among multiple network services using a centralized dispatcher

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,009,782
App. No.
13/970,535
Granted
Apr 14, 2015
Kind
B2
Abstract

A network service dispatcher is provided that transparently navigates network traffic through network service appliances utilizing sub-session connection information generated in accordance with policies pertaining to a client-server session. The network service dispatcher intercepts a first data packet of a new session between two computer systems and generates sub-session connection information that navigates the data packet through one or more network service appliances in a manner transparent to the client or server. In turn, the network service dispatcher utilizes the sub-session connection information to navigate subsequent forward or reverse data packets in the session without performing a policy-based search for each data packet.

Claims (85)

1. A method comprising:

receiving a data packet from a first computer system at a network service dispatcher system, wherein the data packet includes session attributes identifying the first computer system and a second computer system;

identifying, by the network service dispatcher, one or more policies that correspond to sending the data packet between the first computer system and the second computer system;

generating, by the network service dispatcher, one or more sets of sub-session connection information corresponding to the identified one or more policies, wherein at least one of the one or more sets of sub-session connection information correspond to sending the data packet to one or more network service appliances prior to sending the data packet to the second computer system;

generating a forward session entry that includes a session identifier based upon the session attributes, wherein the forward session entry links the session identifier to the one or more sets of sub-session connection information; and

sending, by the network service dispatcher, the data packet to the one or more network service appliances based upon the forward session entry.

2. The method of claim 1 further comprising:

generating a hash value of the session attributes included in the data packet; and

storing the hash value as the session identifier in the forward session entry stored in a session table.

3. The method of claim 2 further comprising:

receiving, at the network service dispatcher, a subsequent data packet from the first computer system, wherein the subsequent data packet includes subsequent session attributes identifying the first computer system and the second computer system;

generating, by the network service dispatcher, a subsequent hash of the subsequent session attributes;

matching, by the network service dispatcher, the subsequent hash to the hash value included in the forward session entry;

retrieving, by the network service dispatcher, the one or more sets of sub-session connection information in response to the matching; and

sending, by the network service dispatcher, the subsequent data packet to the one or more network service appliances based upon the retrieved one or more sets of sub-session connection information.

4. The method of claim 2 further comprising:

storing each of the one or more sets of sub-session connection information in one of one or more links included in a forward session link list, wherein the forward session entry includes a forward session link list pointer that points to the forward session link list.

5. The method of claim 4 wherein the generating of the one or more sets of sub-session connection information further comprises:

selecting a source/destination segment pair included in a selected one of the one or more policies;

identifying a first network service appliance from the one or more network service appliances based upon the selected source/destination segment pair;

assigning a first zone that connects the first computer system to the network service dispatcher, and assigning a second zone that connects the network service dispatcher to the first network service appliance, wherein the first zone and the second zone are virtual local area networks;

including a first zone identifier and a second zone identifier in a first set of the one or more sets of sub-session connection information, the first zone identifier corresponding to the first zone and the second zone identifier corresponding to the second zone; and

storing the first set of sub-session connection information in one of the one or more links included in the forward session link list.

6. The method of claim 5 wherein the selected policy comprises:

a plurality of traffic classification criteria sets, wherein at least one the plurality of traffic classification criteria sets matches the session attributes included in the data packet; and

a plurality of source/destination segment pairs corresponding to a plurality of the one or more network service appliances, the selected source/destination segment pair included in the plurality of source/destination segment pairs.

7. The method of claim 4 further comprising:

generating, by the network service dispatcher, one or more reverse sets of sub-session connection information based upon the one or more sets of sub-session connection information, wherein the one or more reverse sets of sub-session connection information corresponds to sending data from the second computer system to the first computer system;

storing the one or more reverse sets of sub-session connection information in a reverse session link list;

generating a reverse hash of the session attributes, wherein the reverse hash is based upon changing attributes corresponding to the first computer system with attributes corresponding to the second computer system; and

storing the reverse hash and a reverse session link list pointer in a reverse session entry, the reverse session link list pointer pointing to the reverse session link list.

8. The method of claim 7 further comprising:

receiving a subsequent data packet from the second computer system, wherein the subsequent data packet includes subsequent session attributes identifying the second computer system and the first computer system;

generating a subsequent hash of the subsequent session attributes;

matching the subsequent hash to the reverse session entry;

retrieving the one or more reverse sets of sub-session connection information in response to the matching; and

sending the subsequent data packet to one or more of the network service appliances based upon the retrieved one or more reverse sets of sub-session connection information.

9. The method of claim 1 wherein the one or more sets of sub-session connection information include:

a first endpoint set of sub-session connection information that corresponds to the first computer system and one of the one or more network service appliances;

a second endpoint set of sub-session connection information that corresponds to the second computer system and one of the one or more network service appliances; and

one or more intermediate sets of sub-session connection information, wherein each of the one or more intermediate sets of sub-session connection information correspond to two of the network service appliances.

10. The method of claim 1 wherein the received data packet fails to include address information corresponding to the network service dispatcher system.

11. A network service dispatcher comprising:

one or more processors;

one or more memories accessible by at least one of the processors;

a communication interface that receives a data packet from a first computer system and provides the data packet to at least one of the one or more processors, the data packet including session attributes identifying the first computer system and a second computer system;

policy identification circuitry utilized by at least one of the processors to identify one or more policies corresponding to sending the data packet between the first computer system and the second computer system;

sub-session generation circuitry utilized by at least one of the processors to generate one or more sets of sub-session connection information corresponding to the identified one or more policies, wherein at least one of the one or more sets of sub-session connection information correspond to sending the data packet to one or more network service appliances prior to sending the data packet to the second computer system;

forward session generation circuitry utilized by at least one of the processors to generate a forward session entry that includes a session identifier based upon the session attributes, wherein the forward session entry links the session identifier to the one or more sets of sub-session connection information; and

a transmission interface that sends the data packet from the network service dispatcher to the one or more network service appliances based upon the forward session entry.

12. The network service dispatcher of claim 11 further comprising:

hash generation circuitry utilized by at least one of the processors to generate a hash value of the session attributes included in the data packet; and

storage circuitry utilized by at least one of the processors to store the hash value as the session identifier in the forward session entry stored in a session table.

13. The network service dispatcher of claim 12 further comprising:

the communication interface that receives a subsequent data packet from the first computer system and provides the subsequent data packet to at least one of the one or more processors, the subsequent data packet including subsequent session attributes identifying the first computer system and the second computer system;

the hash generation circuitry utilized by at least one of the processors to generate a subsequent hash of the subsequent session attributes;

comparison circuitry utilized by at least one of the processors to match the subsequent hash to the hash value included in the forward session entry;

retrieval circuitry utilized by at least one of the processors to retrieve the one or more sets of sub-session connection information in response to the matching; and

the transmission interface that sends the subsequent data packet to the one or more network service appliances based upon the retrieved one or more sets of sub-session connection information.

14. The network service dispatcher of claim 12 further comprising:

segment pair circuitry to select a source/destination segment pair included in a selected one of the one or more policies;

network service appliance identification circuitry utilized by at least one of the processors to identify a first network service appliance from the one or more network service appliances based upon the selected source/destination segment pair;

zone assignment circuitry utilized by at least one of the processors to assign a first zone that connects the first computer system to the information handling system, and assign a second zone that connects the information handling system to the first network service appliance, wherein the first zone and the second zone are virtual local area networks;

the sub-session generation circuitry utilized by at least one of the processors to include a first zone identifier and a second zone identifier in a first set of the one or more sets of sub-session connection information, the first zone identifier corresponding to the first zone and the second zone identifier corresponding to the second zone; and

the storage circuitry utilized by at least one of the processors to store the first set of sub-session connection information in one of one or more links included in a forward session link list, wherein the forward session entry includes a forward session link list pointer that points to the forward session link list.

15. The network service dispatcher of claim 14 wherein the selected policy comprises:

a plurality of traffic classification criteria sets, wherein at least one the plurality of traffic classification criteria sets matches the session attributes included in the data packet; and

a plurality of source/destination segment pairs corresponding to a plurality of the one or more network service appliances, the selected source/destination segment pair included in the plurality of source/destination segment pairs.

16. The network service dispatcher of claim 12 further comprising:

the sub-session generation circuitry utilized by at least one of the processors to generate one or more reverse sets of sub-session connection information based upon the one or more sets of sub-session connection information, wherein the one or more reverse sets of sub-session connection information corresponds to sending data from the second computer system to the first computer system;

the storage circuitry utilized by at least one of the processors to store the one or more reverse sets of sub-session connection information in a reverse session link list;

the hash generation circuitry utilized by at least one of the processors to generate a reverse hash of the session attributes, wherein the reverse hash is based upon changing attributes corresponding to the first computer system with attributes corresponding to the second computer system; and

the storage circuitry utilized by at least one of the processors to store the reverse hash and a reverse session link list pointer in a reverse session entry, the reverse session link list pointer pointing to the reverse session link list.

17. The network service dispatcher of claim 16 further comprising:

the communication interface that receives a subsequent data packet from the second computer system and provides the subsequent data packet to at least one of the one or more processors, wherein the subsequent data packet includes subsequent session attributes identifying the second computer system and the first computer system;

the hash generation circuitry utilized by at least one of the processors to generate a subsequent hash of the subsequent session attributes;

comparison circuitry utilized by at least one of the processors to match the subsequent hash to the reverse session entry;

retrieval circuitry utilized by at least one of the processors to retrieve the one or more reverse sets of sub-session connection information in response to the matching; and

the transmission interface that sends the subsequent data packet to one or more of the network service appliances based upon the retrieved one or more reverse sets of sub-session connection information.

18. A system comprising:

a plurality of network nodes, the plurality of network nodes including a first network node and a second network node;

a plurality of network service appliances; and

a network service dispatcher that generates sub-session connection information based upon one or more policies in response to receiving a data packet sent from the first network node with a target destination at the second network node, wherein the network service dispatcher generates a forward session entry that includes a session identifier based upon the session attributes, the forward session entry linking the session identifier to the one or more sets of sub-session connection information, and wherein the network service dispatcher sends the data packet to at least one of the plurality of network service appliances based upon the forward session entry.

19. The system of claim 18 wherein the data packet corresponds to a first session between the first network node and the second network node, and wherein the network service dispatcher re-uses the sub-session connection information to direct one or more subsequent data packets belonging to the first session to at least one of the plurality of network service appliances prior to sending the one or more subsequent data packets to the second network node.

20. The system of claim 19 wherein the network service dispatcher generates reverse sub-session connection information based upon the sub-session connection information, and wherein the network service dispatcher uses the reverse sub-session connection information to direct one or more reverse data packets belonging to the first session to at least one of the plurality of network service appliances, the one or more reverse data packets sent from the second network node with a destination at the first network node.

Assignments (18)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040652 FRAME: 0241. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Jan 5, 2017
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 041260/0850 →
MERGER Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 040652/0241 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT PCT NUMBERS IB2013000664, US2013051970, US201305935 PREVIOUSLY RECORDED AT REEL: 037444 FRAME: 0787. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Oct 17, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 040450/0715 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 5, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037444/0787 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037357/0874 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Nov 13, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 031627/0158 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Nov 13, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031627/0201 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2013
From: MYLA, JOHN; ADDEPALLI, SRINIVASA R.
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 031039/0369 →