IP Library Granted Patent US 11,108,643
Granted Patent B2
US 11,108,643 · App. 16/568,325 · Granted Aug 31, 2021

Performing ingress side control through egress side limits on forwarding elements

Inventors: Raja Kommula (Cupertino, CA); Constantine Polychronopoulos (Saratoga, CA); Thayumanavan Sridhar (Palo Alto, CA); Marc-Andre Bordeleau (Shawinigan, CA); Edward Choh (Richmond, CA); Ojas Gupta (Mountain View, CA); Robert Kidd (Champaign, IL); Georgios Oikonomou (Patras, GR); Jeremy Tidemann (Urbana, IL)
Assignee: VMWARE, INC.
H04L41/12G06F9/45541G06F9/45558G06F9/546H04L41/082H04L41/0893H04L41/0896H04L45/38H04L49/9068G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,643
App. No.
16/568,325
Granted
Aug 31, 2021
Kind
B2
Abstract

Some embodiments of the invention provide a novel method of performing network slice-based operations on a data message at a hardware forwarding element (HFE) in a network. For a received data message flow, the method has the HFE identify a network slice associated with the received data message flow. This network slice in some embodiments is associated with a set of operations to be performed on the data message by several network elements, including one or more machines executing on one or more computers in the network. Once the network slice is identified, the method has the HFE process the data message flow based on a rule that applies to data messages associated with the identified slice.

Claims (29)

1. A method for enforcing a level of service for ingress side data message traffic to a computer in a datacenter, the datacenter comprising a plurality of hardware forwarding elements (HFEs), the method comprising:

receiving, from the HFEs, egress side statistics relating to data messages forwarded to the computer by the HFEs;

aggregating and analyzing the received statistics to determine whether the data message traffic has exceeded a first threshold level for ingress side data message traffic to the computer;

when the first threshold has been exceeded, distributing to the HFEs a set of secondary threshold levels to reduce the data message traffic from the HFEs to the computer;

wherein the receiving, aggregating, and distributing are performed by a set of controllers that enforces the service level for ingress side data message traffic to the computer through egress side limits on the HFEs.

2. The method of claim 1 , wherein the set of secondary threshold levels includes an identical second threshold level distributed to all HFEs.

3. The method of claim 1 , wherein the set of secondary threshold levels includes at least two different second threshold levels distributed to at least two different HFEs.

4. The method of claim 1 , wherein based on the distributed set of secondary threshold levels an HFE drops or delays data messages when data message traffic from the HFE to the computer reaches a secondary threshold level.

5. The method of claim 1 further comprising:

before receiving the egress side statistics, distributing to the HFEs an earlier set of primary threshold levels to define a limit on data message traffic from each HFE to the computer.

6. The method of claim 5 , wherein the set of primary threshold levels includes an identical primary threshold level distributed to all HFEs.

7. The method of claim 5 , wherein the set of primary threshold levels includes at least two different primary threshold levels distributed to at least two different HFEs.

8. The method of claim 1 , wherein the data message traffic comprises data message traffic associated with a particular group identifier specifying a group of two or more data message flows.

9. The method of claim 1 , wherein the data message traffic comprises data message traffic associated with a particular slice identifier associated with a network slice in a network.

10. The method of claim 9 , wherein the computer executes a machine associated with the network slice.

11. A non-transitory machine readable medium storing a program for executing by at least one processing unit, the program for enforcing a level of service for ingress side data message traffic to a computer in a datacenter, the datacenter comprising a plurality of hardware forwarding elements (HFEs), the program comprising sets of instructions for:

receiving, from the HFEs, egress side statistics relating to data messages forwarded to the computer by the HFEs;

aggregating and analyzing the received statistics to determine whether the data message traffic has exceeded a first threshold level for ingress side data message traffic to the computer;

when the first threshold has been exceeded, distributing to the HFEs a set of secondary threshold levels to reduce the data message traffic from the HFEs to the computer;

the program is a controller of a set of controllers that enforces the service level for ingress side data message traffic to the computer through egress side limits on the HFEs.

12. The non-transitory machine readable medium of claim 11 , wherein the set of secondary threshold levels includes an identical second threshold level distributed to all HFEs.

13. The non-transitory machine readable medium of claim 11 , wherein the set of secondary threshold levels includes at least two different second threshold levels distributed to at least two different HFEs.

14. The non-transitory machine readable medium of claim 11 , wherein based on the distributed set of secondary threshold levels an HFE drops or delays data messages when data message traffic from the HFE to the computer reaches a secondary threshold level.

15. The non-transitory machine readable medium of claim 11 , wherein the program further comprises a set of instructions for distributing, before receiving the egress side statistics, an earlier set of primary threshold levels to the HFEs to define a limit on data message traffic from each HFE to the computer.

16. The non-transitory machine readable medium of claim 15 , wherein the set of primary threshold levels includes an identical primary threshold level distributed to all HFEs.

17. The non-transitory machine readable medium of claim 15 , wherein the set of primary threshold levels includes at least two different primary threshold levels distributed to at least two different HFEs.

18. The non-transitory machine readable medium of claim 11 , wherein the data message traffic comprises data message traffic associated with a particular group identifier specifying a group of two or more data message flows.

19. The non-transitory machine readable medium of claim 11 , wherein the data message traffic comprises data message traffic associated with a particular slice identifier associated with a network slice in a network.

20. The non-transitory machine readable medium of claim 19 , wherein the computer executes a machine associated with the network slice.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2019
From: KOMMULA, RAJA; POLYCHRONOPOULOS, CONSTANTINE; SRIDHAR, THAYUMANAVAN; BORDELEAU, MARC-ANDRE; CHOH, EDWARD; GUPTA, OJAS; KIDD, ROBERT; OIKONOMOU, GEORGIOS; TIDEMANN, JEREMY
To: VMWARE, INC.
Reel/Frame 050357/0474 →
Continuity (2)
Provisional Application 62891425 · Aug 26, 2019
Related Publication 20210064451A1 · Mar 4, 2021
Cited By (5)
US 12,244,466 US 12,413,468 US 12,438,769 US 12,530,214 US 12,581,392