IP Library › Granted Patent US 11,212,136
Granted Patent B2
US 11,212,136 · App. 16/844,929 · Granted Dec 28, 2021

Infrastructure support in cloud environments

Inventors: Anna Skobodzinski (New York, NY); Lamia Youseff (Stanford, CA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L12/44H04L67/1091
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,212,136
App. No.
16/844,929
Granted
Dec 28, 2021
Kind
B2
Abstract

Techniques are disclosed for implementing networks in a virtualized computing environment. One or more spoke virtual networks are instantiated and connected to a first virtual network hub to form a first hub and spoke topology. One or more spoke virtual networks are instantiated and connected to a second hub virtual network to form a second hub and spoke topology. A virtual connection is established from the first virtual network hub to the second hub virtual network. The first and second hub and spoke networks are allocated to a user of the virtualized computing environment.

Claims (34)

1. A method for implementing a network topology in a virtualized computing environment comprising a plurality of computing devices that are configured to host a plurality of virtual machines communicatively coupled via virtual networks, the method comprising:

determining that a number of nodes in the network topology exceeds a first threshold;

allocating nodes and interconnections in the network topology to one or more spoke virtual networks of a first virtual hub network;

allocating nodes and interconnections in the network topology to additional spoke virtual networks connected to the first virtual hub network until a number of spoke virtual networks reaches a second threshold or the nodes and interconnections in the network topology are fully allocated; and

in response to determining that the number of spoke virtual networks exceeds the second threshold and the nodes and interconnections in the network topology have not been fully allocated, allocating unallocated nodes and interconnections in the network topology to spoke virtual networks of additional virtual hub networks until the nodes and interconnections in the network topology have been fully allocated.

2. The method of claim 1 , further comprising establishing a virtual connection from the first virtual network hub to the additional virtual hub networks.

3. The method of claim 1 , wherein the first and second thresholds are determined based on performance parameters of the virtualized computing environment.

4. The method of claim 1 , wherein the first and second thresholds are dynamically determined based on performance objectives for the network topology.

5. The method of claim 1 , further comprising allowing allocation of the spoke virtual networks and corresponding virtual hub networks to different lines of businesses.

6. The method of claim 1 , wherein the first and second thresholds are determined in accordance with policies of the virtualized computing environment.

7. The method of claim 1 , further comprising allowing establishment of different security policies to each virtual hub network and its corresponding spoke virtual networks.

8. A system, comprising:

one or more processors; and

a memory in communication with the one or more processors, the memory having computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising:

determining that a number of nodes in a network topology exceeds a first threshold;

allocating nodes and interconnections in the network topology to one or more spoke virtual networks of a first virtual hub network;

allocating nodes and interconnections in the network topology to additional spoke virtual networks connected to the first virtual hub network until a number of spoke virtual networks reaches a second threshold or the nodes and interconnections in the network topology are fully allocated; and

in response to determining that the number of spoke virtual networks exceeds the second threshold and the nodes and interconnections in the network topology have not been fully allocated, allocating unallocated nodes and interconnections in the network topology to spoke virtual networks of additional virtual hub networks until the nodes and interconnections in the network topology have been fully allocated.

9. The system of claim 8 , further comprising computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising allowing deployment of one virtual network per project environment.

10. The system of claim 8 , further comprising computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising allowing the hub and spoke topologies to access one or more shared resources.

11. The system of claim 8 , further comprising computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising enabling Role-Based Access Control (RBAC) to regulate access to resources based on the roles established by a user.

12. The system of claim 11 , further comprising computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising using a combination of RBAC and policies to reduce a number of virtual network peering links.

13. The system of claim 8 , wherein the first and second thresholds are dynamically determined based on performance objectives for the network topology.

14. The system of claim 8 , wherein a maximum number of the spoke virtual networks in the hub and spoke networks is determined in accordance with policies of the spoke virtual networks.

15. The system of claim 8 , further comprising computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the system to perform operations comprising allowing allocation of the spoke virtual networks and corresponding virtual hub networks to different lines of businesses.

16. The system of claim 8 , wherein the first and second thresholds are determined in accordance with policies of the spoke virtual networks.

17. A non-transitory computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by one or more processors of a computing device, cause the computing device to perform operations comprising:

determining that a number of nodes in a network topology exceeds a first threshold;

allocating nodes and interconnections in the network topology to one or more spoke virtual networks of a first virtual hub network;

allocating nodes and interconnections in the network topology to additional spoke virtual networks connected to the first virtual hub network until a number of spoke virtual networks reaches a second threshold or the nodes and interconnections in the network topology are fully allocated; and

in response to determining that the number of spoke virtual networks exceeds the second threshold and the nodes and interconnections in the network topology have not been fully allocated, allocating unallocated nodes and interconnections in the network topology to spoke virtual networks of additional virtual hub networks until the nodes and interconnections in the network topology have been fully allocated.

18. The non-transitory computer-readable storage medium of claim 17 , further comprising computer-executable instructions stored thereupon which, when executed by one or more processors of a computing device, cause the computing device to perform operations comprising establishing a virtual connection from the first virtual network hub to the additional virtual hub networks.

19. The non-transitory computer-readable storage medium of claim 17 , further comprising computer-executable instructions stored thereupon which, when executed by one or more processors of a computing device, cause the computing device to perform operations comprising allowing establishment of different security policies to each virtual hub network and its corresponding spoke virtual networks.

20. The non-transitory computer-readable storage medium of claim 17 , wherein the network topology is mapped to a topologically equivalent network in the virtual hub networks and corresponding spoke virtual networks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2020
From: SKOBODZINSKI, ANNA; YOUSEFF, LAMIA
To: MICROSOFT TECHNOLOGY LICENSING, LLC.
Reel/Frame 053593/0586 →
Continuity (2)
Continuation 16191252 · Nov 14, 2018
Related Publication 20200304338A1 · Sep 24, 2020