IP Library Granted Patent US 9,912,582
Granted Patent B2
US 9,912,582 · App. 14/546,276 · Granted Mar 6, 2018

Multi-tenant isolation in a cloud environment using software defined networking

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,582
App. No.
14/546,276
Granted
Mar 6, 2018
Kind
B2
Abstract

Systems and methods for ensuring multi-tenant isolation in a data center are provided. A switch, or virtualized switch, can be used to de-multiplex incoming traffic between a number of data centers tenants and to direct traffic to the appropriate virtual slice for an identified tenant. The switch can store tenant identifying information received from a master controller and packet forwarding rules received from at least one tenant controller. The packet handling rules are associated with a specific tenant and can be used to forward traffic to its destination.

Claims (48)

1. A method for processing packet traffic by a switch in a multi-tenant network, comprising:

receiving a packet;

responsive to determining that a tenant associated with the received packet cannot be determined by a first table lookup, requesting tenant information from a first controller;

receiving the requested tenant information from the first controller and installing the tenant information in the first table;

responsive to determining that a forwarding rule associated with the received packet cannot be determined by a second table lookup, requesting the forwarding rule from a second controller;

receiving the requested forwarding rule from the second controller and installing the forwarding rule in the second table; and

transmitting the packet in accordance with the received forwarding rule;

wherein the first controller is associated with a plurality of tenants in the multi-tenant network and the second controller is associated with one tenant of the plurality of tenants.

2. The method of claim 1 , wherein the first controller is a master software defined networking (SDN) controller associated with the plurality of tenants in the multi-tenant network.

3. The method of claim 1 , wherein the second controller is a tenant software defined networking (SDN) controller associated with the tenant.

4. The method of claim 1 , wherein the tenant information is a tenant table identifier.

5. The method of claim 1 , further comprising, performing the first table lookup to select a tenant table identifier associated with the received packet from the first table.

6. The method of claim 5 , wherein the first table lookup is performed in accordance with an input port on which the packet was received.

7. The method of claim 1 , wherein requesting tenant information includes sending the received packet to the first controller.

8. The method of claim 1 , further comprising, storing the received tenant information as a flow entry in the first table.

9. The method of claim 1 , further comprising, performing the second table lookup to select the forwarding rule associated with the received packet from the second table.

10. The method of claim 9 , wherein the second table lookup is performed in accordance with at least one header field of the received packet.

11. The method of claim 10 , wherein the at least one header field is selected from a group comprising: a source IP address, a destination IP address, a source port, a destination port, and a protocol.

12. The method of claim 1 , wherein requesting the forwarding rule from a second controller includes sending the received packet to the second controller.

13. The method of claim 1 , further comprising, storing the received forwarding rule as a flow entry in the second table.

14. The method of claim 1 , wherein the first table is a master table associated with the plurality of tenants in the multi-tenant network.

15. The method of claim 1 , wherein the second table is a tenant table uniquely associated with the tenant.

16. A switch in a multi-tenant network comprising a processor and a memory, the memory containing instructions executable by the processor whereby the switch is operative to:

receive a packet;

responsive to determining that a tenant associated with the received packet cannot be determined by a first table lookup, request tenant information from a first controller;

receive the requested tenant information from the first controller and install the tenant information in the first table;

responsive to determining that a forwarding rule associated with the received packet cannot be determined by a second table lookup, request the forwarding rule from a second controller;

receive the requested forwarding rule from the second controller and install the forwarding rule in the second table; and

transmit the packet in accordance with the received forwarding rule;

wherein the first controller is associated with a plurality of tenants in the multi-tenant network and the second controller is associated with one tenant of the plurality of tenants.

17. The switch of claim 16 , wherein the first controller is a master software defined networking (SDN) controller associated with the plurality of tenants in the multi-tenant network.

18. The switch of claim 16 , wherein the second controller is a tenant software defined networking (SDN) controller associated with the tenant.

19. The switch of claim 16 , wherein the tenant information is a tenant table identifier.

20. The switch of claim 16 , further operative to perform the first table lookup to select a tenant table identifier associated with the received packet from the first table.

21. The switch of claim 20 , wherein the first table lookup is performed in accordance with an input port on which the packet was received.

22. The switch of claim 16 , wherein requesting tenant information includes sending the received packet to the first controller.

23. The switch of claim 16 , further operative to store the received tenant information as a flow entry in the first table.

24. The switch of claim 16 , further operative to perform the second table lookup to select the forwarding rule associated with the received packet from the second table.

25. The switch of claim 24 , wherein the second table lookup is performed in accordance with at least one header field of the received packet.

26. The switch of claim 25 , wherein the at least one header field is selected from a group comprising: a source IP address, a destination IP address, a source port, a destination port, and a protocol.

27. The switch of claim 16 , wherein requesting the forwarding rule from a second controller includes sending the received packet to the second controller.

28. The switch of claim 16 , further operative to store the received forwarding rule as a flow entry in the second table.

29. A switch comprising:

a receiving module for receiving a packet;

a tenant identification module for requesting tenant information from a first controller in response to determining that a tenant associated with the received packet cannot be determined by a first table lookup, and for receiving the requested tenant information from the first controller and installing the tenant information in the first table;

a rule identification module for requesting a forwarding rule from a second controller in response to determining that the forwarding rule associated with the received packet cannot be determined by a second table lookup, and for receiving the requested forwarding rule from the second controller and installing the forwarding rule in the second table; and

a transmitting module for transmitting the packet in accordance with the received forwarding rule;

wherein the first controller is associated with a plurality of tenants in the multi-tenant network and the second controller is associated with one tenant of the plurality of tenants.

Assignments (7)
SECURITY AGREEMENT Recorded Apr 24, 2025
From: NOVACLOUD LICENSING LLC
To: NCLD1 LLC
Reel/Frame 071033/0001 →
SECURITY AGREEMENT Recorded Apr 18, 2025
From: NOVACLOUD LICENSING LLC
To: NCLD1 LLC
Reel/Frame 070888/0066 →
SECURITY INTEREST Recorded Feb 13, 2025
From: NOVACLOUD LICENSING LLC
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 070226/0533 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2024
From: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
To: NOVACLOUD LICENSING LLC
Reel/Frame 068522/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2016
From: FEKIH AHMED, MOHAMED; CHERIET, MOHAMED; TALHI, CHAMSEDDINE
To: ECOLE DE TECHNOLOGIE SUPERIEURE
Reel/Frame 040242/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2016
From: POURZANDI, MAKAN
To: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
Reel/Frame 040243/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2016
From: ECOLE DE TECHNOLOGIE SUPERIEURE
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 040244/0221 →