IP Library Granted Patent US 11,336,733
Granted Patent B2
US 11,336,733 · App. 16/125,792 · Granted May 17, 2022

Networking connection management based on container identification

Inventors: Nilesh Awate (Pune, IN); Vivek Parikh (Pune, IN); Amit Vasant Patil (Pune, IN); Vaibhav Rekhate (Pune, IN)
Assignee: Nicira, Inc.
H04L67/141G06F9/45558H04L45/306H04L45/72H04L45/745H04L61/1552G06F2009/45562H04L61/3065H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,733
App. No.
16/125,792
Granted
May 17, 2022
Kind
B2
Abstract

Described herein are systems, methods, and software to enhance packet . In one implementation, a host computing element identifies a packet from a process executing on the host computing element. In response to identifying the packet, the host computing element determines whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element. If the packet originates from a container namespace, the host computing element may determine supplemental information for the container associated with the container namespace, and process the packet based on the supplemental information.

Claims (39)

1. A method of processing packets in a host computing element, the method comprising:

identifying, in a kernel of the host computing element, a packet for communication to a second computing element;

determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element based on process identification numbers (PIDs) associated with an originating process for the packet;

when the packet originates from a container namespace, determining supplemental information for a container associated with the container namespace, wherein the supplemental information comprises a container type, a container identifier, or an absolute binary path to the originating process in the container; and

processing the packet in the kernel of the host computing element based on the supplemental information.

2. The method of claim 1 , wherein determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element based on the PIDs associated the originating process for the packet comprises:

identifying a PID for a local namespace of the packet;

identifying a PID for a global namespace of the packet; and

determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element based on whether the PID for the local namespace matches the PID for the global namespace.

3. The method of claim 1 , wherein the host computing element comprises a virtual machine executing on a host computing system.

4. The method of claim 1 , wherein the second computing element comprises a second container.

5. The method of claim 1 further comprising identifying whether the packet comprises a connection establishment packet, and wherein determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element occurs in response to identifying that the packet comprises a connection establishment packet.

6. The method of claim 1 , wherein the connection establishment packet comprises an acknowledgment packet or a synchronization packet.

7. A computing apparatus comprising:

one or more non-transitory computer readable storage media;

a processing system operatively coupled to the one or more non-transitory computer readable storage media; and

program instructions stored on the one or more computer readable storage media to process packets in a host computing element that, when read and executed by the processing system, direct the processing system to at least:

identify, in a kernel of the host computing element, a packet for communication to a second computing element;

determine whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element based on process identification numbers (PIDs) associated with an originating process for the packet;

when the packet originates from a container namespace, determining supplemental information for a container associated with the container namespace, wherein the supplemental information comprises a container type, a container identifier, or an absolute binary path to the originating process in the container; and

process the packet in the kernel of the host computing element based on the supplemental information.

8. The computing apparatus of claim 7 , wherein determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element comprises:

identifying a PID for a local namespace of the packet;

identifying a PID for a global namespace of the packet; and

determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element based on whether the PID for the local namespace matches the PID for the global namespace.

9. The computing apparatus of claim 7 , wherein the host computing element comprises a virtual machine.

10. The computing apparatus of claim 7 , wherein the second computing element comprises a second container.

11. The computing apparatus of claim 7 , wherein the program instructions further direct the processing system to identify whether the packet comprises a connection establishment packet, and wherein determining whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element occurs in response to identifying that the packet comprises a connection establishment packet.

12. The computing apparatus of claim 11 , wherein the connection establishment packet comprises a Transmission Control Protocol (TCP) acknowledgment packet or synchronization packet.

13. An apparatus comprising:

one or more non-transitory computer readable storage media; and

program instructions stored on the one or more computer readable storage media to process packets in a host virtual machine that, when read and executed by a processing system, direct the processing system to at least:

identify, in a kernel of the host virtual machine, a packet for communication to a destination computing element;

identify a process identification number (PID) for a local namespace of the packet;

identify a PID for a global namespace of the packet;

determine whether the packet originates from a container namespace corresponding to a container on the host virtual machine or a host namespace corresponding to the host virtual machine based on whether the PID for the local namespace matches the PID for the global namespace;

if the packet originates from a container namespace, determining supplemental information for a container associated with the container namespace, wherein the supplemental information comprises a container type, a container identifier, or an absolute binary path to the originating process in the container; and

process the packet in the kernel of the host virtual machine based on the supplemental information.

14. The apparatus of claim 13 , wherein the program instructions further direct the processing system to identify whether the packet comprises a connection establishment packet, and wherein determining whether the packet originates from a container namespace corresponding to a container on the host virtual machine or a host namespace corresponding to the host virtual machine occurs in response to identifying that the packet comprises a connection establishment packet.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2018
From: AWATE, NILESH; PARIKH, VIVEK; PATIL, AMIT VASANT; REKHATE, VAIBHAV
To: NICIRA, INC.
Reel/Frame 046822/0767 →
Priority Claims (1)
IN 201841023152 · Jun 21, 2018 · national
Continuity (1)
Related Publication 20190394281A1 · Dec 26, 2019
Cited By (1)
US 12,498,966