IP Library Granted Patent US 10,887,228
Granted Patent B2
US 10,887,228 · App. 16/271,307 · Granted Jan 5, 2021

Distributed methodology for peer-to-peer transmission of stateful packet flows

Inventors: Robert Bays (San Francisco, CA); Mike Larson (San Francisco, CA); Stephen Hemminger (Beaverton, OR)
Assignee: AT&T Intellectual Property I, L.P.
H04L45/74G06F9/45558H04L45/302H04L45/586H04L47/10H04L47/2441H04L67/104G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,887,228
App. No.
16/271,307
Granted
Jan 5, 2021
Kind
B2
Abstract

Techniques for enabling peer-to-peer transmission of stateful packet flows in a network environment are provided. In certain embodiments, a computer system receives a packet belonging to a stateful flow, determines a query subset from a plurality of query subsets based on information from the packet, determines a first forwarding plane from a plurality of forwarding planes as an owner of the query subset, sends the packet to the first forwarding plane that owns the query subset, receives from the first forwarding plane information indicating that a second forwarding plane from the plurality of forwarding planes is a state analysis owner for the packet, and transmits the packet to the second forwarding plane. Examples of stateful flow include firewall traffic, network address translation traffic, or application layer classification for Quality of Service. In certain embodiments, the state analysis owner for the stateful flow may perform routing functions for the packet.

Claims (40)

1. A method comprising:

receiving, by a computer system, a packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing, by the computer system, flow associating information from the packet, the flow associating information comprising a source network address for the first virtual machine and a destination network address for the second virtual machine;

performing one of:

(i) responsive to determining, by the computer system and using the source network address and the destination network address, that a network address of a source host hosting the first virtual machine is known and a network address of a destination host hosting the second virtual machine is unknown, selecting the source host as a state analysis owner for the stateful flow, or

(ii) responsive to determining, by the computer system and using the source network address and the destination network address, that the network address of the destination host is known and the network address of the source host is unknown, selecting the destination host as the state analysis owner for the stateful flow; and

transmitting, by the computer system, the packet to the state analysis owner.

2. The method of claim 1 , wherein the state analysis owner performs run-to-completion state processing on the packet.

3. The method of claim 1 , wherein the state analysis owner performs routing functions for packets between the first virtual machine and the second virtual machine.

4. The method of claim 1 , wherein the stateful flow associating information further comprises one or more of a session ID or a query subset for a packet belonging to the stateful flow.

5. The method of claim 1 , wherein the state analysis owner performs routing functions for the packet.

6. The method of claim 1 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

7. The method of claim 1 , wherein the stateful flow comprises a sequence of packets, wherein processing of a past packet affects the processing or transmission of the packet or a future packet.

8. A computer system comprising

a processor; and

a non-transitory computer readable medium having stored thereon executable program code that, when executed by the processor, causes the processor to perform operations comprising:

receiving a packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing flow associating information from the packet, the flow associating information comprising a source network address for the first virtual machine and a destination network address for the second virtual machine;

performing one of:

(i) responsive to determining, using the source network address and the destination network address, that a network address of a source host hosting the first virtual machine is known and a network address of a destination host hosting the second virtual machine is unknown, selecting the source host as a state analysis owner for the stateful flow, or

(ii) responsive to determining, using the source network address and the destination network address that the network address of the destination host is known and the network address of the source host is known, selecting the destination host as the state analysis owner for the stateful flow; and

transmitting the packet to the state analysis owner.

9. The computer system of claim 8 , wherein the state analysis owner performs run-to-completion state processing on the packet.

10. The computer system of claim 8 , wherein the state analysis owner performs routing functions for packets between the first virtual machine and the second virtual machine.

11. The computer system of claim 8 , wherein the flow associating information further comprises one or more of a session ID or a query subset for a packet belonging to the stateful flow.

12. The computer system of claim 8 , wherein the state analysis owner performs routing functions for the packet.

13. The computer system of claim 8 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

14. The computer system of claim 8 , wherein the stateful flow comprises a sequence of packets, wherein processing of a past packet affects the processing or transmission of the packet or a future packet.

15. A non-transitory computer readable medium having stored thereon program code that, when executed by a processor, cause the processor to perform operations comprising:

receiving a packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing flow associating information from the packet, the flow associating information comprising a source network address for the first virtual machine and a destination network address for the second virtual machine;

performing one of:

(i) responsive to determining, using the source network address and the destination network address, that a network address of a source host hosting the first virtual machine is known and a network address of a destination host hosting the second virtual machine is unknown, selecting the source host as a state analysis owner for the stateful flow, or

(ii) responsive to determining, using the source network address and the destination network address that the network address of the destination host is known and the network address of the source host is unknown, selecting the destination host as the state analysis owner for the stateful flow; and

transmitting the packet to the state analysis owner.

16. The non-transitory computer readable medium of claim 15 , wherein the state analysis owner performs run-to-completion state processing on the packet.

17. The non-transitory computer readable medium of claim 15 , wherein the operations further comprise causing the state analysis owner to perform routing functions for packets between the first virtual machine and the second virtual machine.

18. The non-transitory computer readable medium of claim 15 , wherein the flow associating information further comprises one or more of a session ID or a query subset for a packet belonging to the stateful flow.

19. The non-transitory computer readable medium of claim 15 , wherein the operations further comprise causing the state analysis owner to perform routing functions for the packet.

20. The non-transitory computer readable medium of claim 15 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2021
From: AT&T INTELLECTUAL PROPERTY I, LP
To: CIENA CORPORATION
Reel/Frame 058088/0833 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2019
From: BAYS, ROBERT; LARSON, MIKE; HEMMINGER, STEPHEN
To: BROCADE COMMUNICATIONS SYSTEMS, INC.
Reel/Frame 048588/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2019
From: BROCADE COMMUNICATION SYSTEMS, INC.
To: AT&T INTELLECTUAL PROPERTY I, L. P.
Reel/Frame 048589/0900 →
Continuity (5)
Continuation 15476820 · Mar 31, 2017
Continuation 15159567 · May 19, 2016
Continuation 14262694 · Apr 25, 2014
Provisional Application 61816571 · Apr 26, 2013
Related Publication 20190173787A1 · Jun 6, 2019