IP Library Granted Patent US 10,505,761
Granted Patent B2
US 10,505,761 · App. 16/054,638 · Granted Dec 10, 2019

Scalable tenant networks

Inventors: Poornananda R. Gaddehosur (Redmond, WA); Benjamin M. Schultz (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L12/4675G06F9/45537H04L41/0893H04L41/12H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,761
App. No.
16/054,638
Granted
Dec 10, 2019
Kind
B2
Abstract

Template-driven locally calculated policy updates for virtualized machines in a datacenter environment are described. A central control and monitoring node calculates and pushes down policy templates to local control and monitoring nodes. The templates provide boundaries and/or a pool of networking resources, from which the local control and monitoring node is enabled to calculate policy updates for locally instantiated virtual machines and containers.

Claims (40)

1. A system comprising:

one or more processors;

computer-readable media;

programming instructions stored on the computer-readable media and executable by the one or more processors to:

monitor network resource allocation for one or more virtual machines instantiated within one or more nodes;

determine, based on the monitoring of the network resource allocation, to request additional network resources;

request, based on the determining, the additional network resources; and

receive a policy template for allocation of the additional network resources amongst the one or more virtual machines instantiated within the one or more nodes.

2. The system of claim 1 , wherein the programming instructions are further executable by the one or more processors to determine that a threshold amount of available network resources are allocated, the determining to request the additional network resources is based on the determining that the threshold amount of available network resources are allocated.

3. The system of claim 1 , wherein the policy template indicates a change to one or more configurable network policy elements allocated to the one or more virtual machines instantiated within the one or more nodes.

4. The system of claim 3 , wherein the one or more configurable network policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, or port numbers.

5. The system of claim 3 , wherein the one or more configurable network policy elements comprise customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

6. The system of claim 3 , wherein the one or more configurable network policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

7. The system of claim 3 , wherein the one or more configurable network policy elements comprise constraints for service chain configuration, wherein the service chain configuration comprise a path of service chain elements a data packet traverses during communication to or from a destination in a datacenter.

8. The system of claim 7 , wherein an individual service chain element comprises a load balancer, an anti-virus scanner, a firewall, or a deep-packet inspection server.

9. The system of claim 3 , wherein the one or more configurable network policy elements comprise an access control list (ACL) useable to enforce security policies, wherein the ACL specifies one or more of a source port, a source address, a protocol, a destination port, or a destination address that define packets that are allowed or denied entry into a network through a network device.

10. The system of claim 3 , wherein the one or more configurable network policy elements comprise local forwarding tables that include a destination with which a virtual machine is able to communicate, wherein the local forwarding tables include encapsulate/decapsulate rules, network address translation rules, or a range of IP addresses that are reachable by the virtual machine.

11. The system of claim 1 , wherein the one or more nodes comprise a local environment of a datacenter, at least one of the one or more virtual machines comprises a nested virtual machine, and the programming instructions are further executable by the one or more processors to:

calculate a policy based on the policy template and distribute the policy; and

distribute the policy to the one or more nodes.

12. A system comprising:

one or more processors;

computer-readable media;

programming instructions stored on the computer-readable media and executable by the one or more processors to:

monitor network resource allocation for one or more containers instantiated within one or more nodes;

determine, based on the monitoring of the network resource allocation, to request additional network resources;

request, based on the determining, the additional network resources; and

receive a policy template for allocation of the additional network resources amongst the one or more containers instantiated within the one or more nodes.

13. The system of claim 12 , wherein the programming instructions are further executable by the one or more processors to determine that a threshold amount of available network resources are allocated, the determining to request the additional network resources is based on the determining that the threshold amount of available network resources are allocated.

14. The system of claim 12 , wherein the policy template indicates a change to one or more configurable network policy elements allocated to the one or more containers instantiated within the one or more nodes.

15. The system of claim 14 , wherein the one or more configurable network policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, port numbers, or customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

16. The system of claim 14 , wherein the one or more configurable network policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

17. The system of claim 14 , wherein the one or more configurable network policy elements comprise constraints for service chain configuration, wherein the service chain configuration comprise a path of service chain elements a data packet traverses during communication to or from a destination in a datacenter and an individual service chain element comprises a load balancer, an anti-virus scanner, a firewall, or a deep-packet inspection server.

18. The system of claim 14 , wherein the one or more configurable network policy elements comprise an access control list (ACL) useable to enforce security policies, wherein the ACL specifies one or more of a source port, a source address, a protocol, a destination port, or a destination address that define packets that are allowed or denied entry into a network through a network device.

19. The system of claim 14 , wherein the one or more configurable network policy elements comprise local forwarding tables that include a destination with which a container is able to communicate, wherein the local forwarding tables include encapsulate/decapsulate rules, network address translation rules, or a range of IP addresses that are reachable by the container.

20. A method comprising:

monitoring, by a local controller, network resource allocation for one or more virtual machines or containers instantiated within one or more nodes;

determining, based on the monitoring of the network resource allocation, to request additional network resources;

requesting, based on the determining, the additional network resources from a central controller; and

receiving, from the central controller, a policy template for allocation of the additional network resources amongst the one or more virtual machines or containers instantiated within the one or more nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2018
From: GADDEHOSUR, POORNANANDA R.; SCHULTZ, BENJAMIN M.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 046553/0405 →
Continuity (4)
Continuation 15859247 · Dec 29, 2017
Continuation 15075049 · Mar 18, 2016
Provisional Application 62267664 · Dec 15, 2015
Related Publication 20180375687A1 · Dec 27, 2018