IP Library › Granted Patent US 11,438,194
Granted Patent B2
US 11,438,194 · App. 16/706,456 · Granted Sep 6, 2022

Scalable tenant networks

Inventors: Poornananda R. Gaddehosur (Redmond, WA); Benjamin M. Schultz (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L12/4675G06F9/45537H04L41/0893H04L41/12H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,438,194
App. No.
16/706,456
Granted
Sep 6, 2022
Kind
B2
Abstract

Template-driven locally calculated policy updates for virtualized machines in a datacenter environment are described. A central control and monitoring node calculates and pushes down policy templates to local control and monitoring nodes. The templates provide boundaries and/or a pool of networking resources, from which the local control and monitoring node is enabled to calculate policy updates for locally instantiated virtual machines and containers.

Claims (46)

1. A system comprising:

one or more processors; and

computer-readable media storing programming instructions executable by the one or more processors to:

monitor resource allocation for one or more a plurality of virtual machines;

request, based at least in part on the monitoring, additional resources; and

receive a policy template for allocation of the additional resources amongst the plurality of virtual machines.

2. The system of claim 1 , wherein the programming instructions are further executable by the one or more processors to:

determine that a threshold amount of available resources for the plurality of virtual machines are allocated; and

determine to request the additional resources based at least in part on the determining that the threshold amount of available resources for the plurality of virtual machines are allocated.

3. The system of claim 1 , wherein the policy template indicates a change to one or more configurable policy elements allocated to the plurality of virtual machines.

4. The system of claim 3 , wherein the one or more configurable policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, or port numbers.

5. The system of claim 3 , wherein the one or more configurable policy elements comprise customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

6. The system of claim 3 , wherein the one or more configurable policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

7. The system of claim 3 , wherein:

the one or more configurable policy elements comprise constraints for service chain configuration;

the service chain configuration comprises a path of service chain elements a data packet traverses during communication to or from a destination in a datacenter; and

an individual service chain element comprises a load balancer, an anti-virus scanner, a firewall, or a packet inspection server.

8. The system of claim 3 , wherein the one or more configurable policy elements comprise an access control list (ACL) useable to enforce security policies, wherein the ACL specifies one or more of a source port, a source address, a protocol, a destination port, or a destination address that define packets that are allowed or denied entry into a network through a network device.

9. The system of claim 3 , wherein the one or more configurable policy elements comprise local forwarding tables that include a destination with which a virtual machine of the plurality of virtual machines is able to communicate, wherein the local forwarding tables include encapsulate/decapsulate rules, network address translation rules, or a range of IP addresses that are reachable by the virtual machine.

10. The system of claim 1 , wherein:

the plurality of virtual machines are instantiated within one or more nodes that comprise a local environment of a datacenter; and

the programming instructions are further executable by the one or more processors to:

calculate a policy based at least in part on the policy template; and

distribute the policy to the one or more nodes.

11. The system of claim 1 , wherein the system is external to the plurality of virtual machines.

12. A system comprising:

one or more processors; and

computer-readable media storing programming instructions executable by the one or more processors to:

monitor resource allocation for a plurality of containers;

request, based at least in part on the monitoring, additional resources; and

receive a policy template for allocation of the additional resources amongst the plurality of containers.

13. The system of claim 12 , wherein the programming instructions are further executable by the one or more processors to:

determine that a threshold amount of available resources for the plurality of containers are allocated; and

determine to request the additional resources based at least in part on the determining that the threshold amount of available resources for the plurality of containers are allocated.

14. The system of claim 12 , wherein the system is external to the plurality of containers.

15. A method comprising:

monitoring, by one or more processors of a system that is external to a plurality of virtual machines, resource allocation for the plurality of virtual machines;

requesting, based at least in part on the monitoring, additional resources; and

receiving a policy template for allocation of the additional resources amongst the plurality of virtual machines.

16. The method of claim 15 , further comprising:

determining that a threshold amount of available resources for the plurality of virtual machines are allocated; and

determining to request the additional resources based at least in part on the determining that the threshold amount of available resources for the plurality of virtual machines are allocated.

17. The method of claim 15 , wherein the policy template indicates a change to one or more configurable policy elements allocated to the plurality of virtual machines.

18. The method of claim 17 , wherein the one or more configurable policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, or port numbers.

19. The method of claim 17 , wherein the one or more configurable policy elements comprise customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

20. The method of claim 17 , wherein the one or more configurable policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2019
From: GADDEHOSUR, POORNANANDA R.; SCHULTZ, BENJAMIN M.
To: MICROSOFT TECHNOLOGY LICENSING, LLC.
Reel/Frame 051207/0712 →
Continuity (5)
Continuation 16054638 · Aug 3, 2018
Continuation 15859247 · Dec 29, 2017
Continuation 15075049 · Mar 18, 2016
Provisional Application 62267664 · Dec 15, 2015
Related Publication 20200119951A1 · Apr 16, 2020