IP Library › Granted Patent US 10,212,195
Granted Patent B2
US 10,212,195 · App. 14/981,424 · Granted Feb 19, 2019

Multi-spoke connectivity of private data centers to the cloud

Inventors: Serge Maskalik (Los Gatos, CA); Aravind Srinivasan (Santa Clara, CA); Debashis Basak (San Jose, CA); Sachin Thakkar (San Jose, CA); Allwyn Sequeira (Saratoga, CA)
Assignee: VMware, Inc.
H04L65/1069H04L43/0852H04L65/102H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,195
App. No.
14/981,424
Filed
Dec 28, 2015
Granted
Feb 19, 2019
Kind
B2
Examiner
LING, CHHIAN
Art Unit
2446
USPC
709/224
Abstract

A hybrid computing system includes an on-premise data center and a cloud computing system. To connect between an organization's multiple data centers, a gateway may instead utilize the connections between the private data center and the cloud computing system rather than a direct connection to the other of the organizations' data centers.

Claims (53)

1. A method of providing connectivity between data centers in a hybrid cloud system, the method comprising:

transmitting and receiving first test packets including an Internet Protocol (IP) flow tuple between a gateway of a first data center managed by a first organization and a gateway of a second data center managed by the first organization, wherein the IP flow tuple includes a source IP address, source port, destination IP address, and destination port;

determining a first latency between the first and second data centers managed by the first organization based on the first test packets;

transmitting and receiving second test packets including an IP flow tuple between the gateway of the first data center and a gateway of a cloud computing system managed by a second organization;

determining a second latency between the first data center and the cloud computing system managed by the second organization based on the second test packets, the first organization being a tenant in the cloud computing system; and

establishing a path-optimized connection between the first and second data centers based on the first latency and the second latency, wherein the path-optimized connection travels between the gateway of the first data center through the gateway of the cloud computing system and to the gateway of the second data center.

2. The method of claim 1 , wherein the cloud computing system comprises a first cloud data center communicatively coupled to the first data center and a second cloud data center communicatively coupled to the second data center, wherein the first and second cloud data centers are communicatively coupled together.

3. The method of claim 2 , wherein the path-optimized connection through the gateway of the cloud computing system comprises a path-optimized connection through a gateway of the first cloud data center to a gateway of the second cloud data center.

4. The method of claim 1 , wherein the path-optimized connection between the first and second data centers is established responsive to determining that the second latency is less than the first latency.

5. The method of claim 1 , wherein transmitting and receiving the second test packets including the IP flow tuple between the first data centers and the cloud computing system comprises:

probing a wide area network (WAN) with the second test packets by varying the IP flow tuple of the second test packets across a set of IP flows;

identifying a plurality of paths between the gateway of the first data center and a gateway of the cloud computing system associated with the set of IP flows; and

selecting an IP flow from the set of IP flows for an application executing in the first data center.

6. The method of claim 1 , wherein the step of establishing the path-optimized connection comprises:

establishing a secure channel between the gateway of the first data center and the gateway of the cloud computing system;

encapsulating application packets from the application within path-optimized packets according to the selected IP flow; and

encrypting the path-optimized packets for transmission over the secure channel.

7. The method of claim 6 , wherein the step of establishing the secure channel comprises sending an IP flow tuple for the selected IP flow from the gateway of the first data center to the gateway of the cloud computing system.

8. A non-transitory computer-readable storage medium comprising instructions that, when executed in a computing device, provide connectivity between data centers in a hybrid cloud system, by performing the steps of:

transmitting and receiving first test packets including an Internet Protocol (IP) flow tuple between a gateway of a first data center managed by a first organization and a gateway of a second data center managed by the first organization, wherein the IP flow tuple includes a source IP address, source port, destination IP address, and destination port;

determining a first latency between the first and second data centers managed by the first organization based on the first test packets;

transmitting and receiving second test packets including an IP flow tuple between the gateway of the first data center and a gateway of a cloud computing system managed by a second organization;

determining a second latency between the first data center and the cloud computing system managed by the second organization based on the second test packets, the first organization being a tenant in the cloud computing system; and

establishing a path-optimized connection between the first and second data centers based on the first latency and the second latency, wherein the path-optimized connection travels between the gateway of the first data center through the gateway of the cloud computing system and to the gateway of the second data center.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the cloud computing system comprises a first cloud data center communicatively coupled to the first data center and a second cloud data center communicatively coupled to the second data center, wherein the first and second cloud data centers are communicatively coupled together.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the path-optimized connection through the gateway of the cloud computing system comprises a path-optimized connection through a gateway of the first cloud data center to a gateway of the second cloud data center.

11. The non-transitory computer-readable storage medium of claim 8 , wherein the path-optimized connection between the first and second data centers is established responsive to determining that the second latency is less than the first latency.

12. The non-transitory computer-readable storage medium of claim 8 , wherein transmitting and receiving the second test packets including the IP flow tuple between the first data centers and the cloud computing system comprises:

probing a wide area network (WAN) with the second test packets by varying the IP flow tuple of the second test packets across a set of IP flows;

identifying a plurality of paths between the gateway of the first data center and a gateway of the cloud computing system associated with the set of IP flows; and

selecting an IP flow from the set of IP flows for an application executing in the first data center.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the step of establishing the path-optimized connection comprises:

establishing a secure channel between the gateway of the first data center and the gateway of the cloud computing system;

encapsulating application packets from the application within path-optimized packets according to the selected IP flow; and

encrypting the path-optimized packets for transmission over the secure channel.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the step of establishing the secure channel comprises sending an IP flow tuple for the selected IP flow from the gateway of the first data center to the gateway of the cloud computing system.

15. A computer system for provide connectivity between data centers in a hybrid cloud system, the computer system comprising a system memory and a processor programmed to:

transmit and receive first test packets including an Internet Protocol (IP) flow tuple between a gateway of a first data center managed by a first organization and a gateway of a second data center managed by the first organization, wherein the IP flow tuple includes a source IP address, source port, destination IP address, and destination port;

determine a first latency between the first and second data centers managed by the first organization;

transmit and receive second test packets including an IP flow tuple between the gateway of the first data center and a gateway of a cloud computing system managed by a second organization;

determine a second latency between the first data center and the cloud computing system managed by a second organization based on the second test packets, the first organization being a tenant in the cloud computing system; and

establish a path-optimized connection between the first and second data centers based on the first latency and the second latency, wherein the path-optimized connection travels between the gateway of the first data center through the gateway of the cloud computing system and to the gateway of the second data center.

16. The computer system of claim 15 , wherein the cloud computing system comprises a first cloud data center communicatively coupled to the first data center and a second cloud data center communicatively coupled to the second data center, wherein the first and second cloud data centers are communicatively coupled together.

17. The computer system of claim 16 , wherein the path-optimized connection through the gateway of the cloud computing system comprises a path-optimized connection through a gateway of the first cloud data center to a gateway of the second cloud data center.

18. The computer system of claim 15 , wherein the path-optimized connection between the first and second data centers is established responsive to determining that the second latency is less than the first latency.

19. The computer system of claim 15 , wherein transmitting and receiving the second test packets including the IP flow tuple between the first data centers and the cloud computing system comprises:

probing a wide area network (WAN) with the second test packets by varying the IP flow tuple of the second test packets across a set of IP flows;

identifying a plurality of paths between the gateway of the first data center and a gateway of the cloud computing system associated with the set of IP flows; and

selecting an IP flow from the set of IP flows for an application executing in the first data center.

20. The computer system of claim 15 , wherein the processor configured to establish the path-optimized connection is further configured to:

establish a secure channel between the gateway of the first data center and the gateway of the cloud computing system;

encapsulate application packets from the application within path-optimized packets according to the selected IP flow; and

encrypt the path-optimized packets for transmission over the secure channel.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2016
From: MASKALIK, SERGE; SRINIVASAN, ARAVIND; BASAK, DEBASHIS; THAKKAR, SACHIN; SEQUEIRA, ALLWYN
To: VMWARE, INC.
Reel/Frame 038187/0247 →
Continuity (2)
Provisional Application 62211696 · Aug 29, 2015
Related Publication 20170063667A1 · Mar 2, 2017
Cited By (7)
US 12,306,819 US 12,481,638 US 12,613,857 US 12,657,097 US 12,693,999 US 12,699,685 US 12,730,914