IP Library › Granted Patent US 11,405,318
Granted Patent B2
US 11,405,318 · App. 17/089,530 · Granted Aug 2, 2022

Collaborative traffic balancer

Inventor: Chunhui Wong (Santa Clara, CA)
Assignee: Cisco Technology, Inc.
H04L47/125H04L41/5003H04L47/825H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,405,318
App. No.
17/089,530
Granted
Aug 2, 2022
Kind
B2
Abstract

This disclosure describes techniques for employing a collaborate traffic balancer in communications among network devices. The techniques include dynamic traffic engineering concepts to improve network communications. The techniques may include causing a headend device to establish a secure communication session between a client device and a server in a resource infrastructure supporting the service. The techniques may include selecting a tunnel for the secure communication session to reach the resource infrastructure. The techniques may further include migrating the secure communication session from a current tunnel to a new tunnel where a degradation in quality of the secure communication session is predicted.

Claims (57)

1. A computer-implemented method comprising:

receiving a request to establish a secure communication session between a client device and a service;

causing a headend device to establish the secure communication session between the client device and a first server in a first cloud computing infrastructure supporting the service;

receiving first telemetry data from the headend device indicating a first performance metric associated with the secure communication session between the client device and the first server;

receiving second telemetry data from a backend device associated with the first cloud computing infrastructure indicating a second performance metric that comprises load information from within the first cloud computing infrastructure supporting the service;

determining that at least one of the first performance metric or the second performance metric is within a threshold amount from violating a quality of service (QoS) policy; and

in response to determining that at least one of the first performance metric or the second performance metric is within the threshold amount from violating the QoS policy, causing the headend device to migrate the secure communication session between the client device and the service from the first server in the first cloud computing infrastructure to a second server in a second cloud computing infrastructure that supports the service.

2. The method of claim 1 , further comprising:

selecting a tunnel associated with the second server in the second cloud computing infrastructure; and

causing the headend device to migrate the secure communication session to the tunnel.

3. The method of claim 2 , further comprising:

selecting the tunnel based at least in part on load capacity of the tunnel and a stability of the tunnel.

4. The method of claim 3 , further comprising:

determining the load capacity of the tunnel by estimating the load capacity of the tunnel that would remain where the secure communication session is migrated to the tunnel.

5. The method of claim 1 , further comprising:

sending a probe to the first cloud computing infrastructure; and

receiving the second telemetry data in response to the probe.

6. The method of claim 1 , wherein the first telemetry data correspond to roundtrip latency from the first cloud computing infrastructure to the headend device.

7. The method of claim 1 , wherein the second performance metric is within the threshold amount from violating the QoS policy and the QoS policy is related to numbers of sessions served by the service.

8. A controller device comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to:

receive, at the controller device and from a headend device, a request to establish a secure communication session between a client device and a service;

cause the headend device to establish the secure communication session between the client device and a first server in a first cloud computing infrastructure supporting the service;

receive telemetry data from a backend device associated with the first cloud computing infrastructure, the telemetry data associated with a performance metric of the first cloud computing infrastructure supporting the service, the telemetry data including load information of the service;

determine that the performance metric is within a threshold amount from violating a quality of service (QoS) policy; and

based at least in part on the performance metric being within the threshold amount, cause the headend device to migrate the secure communication session between the client device and the service from the first server in the first cloud computing infrastructure to a second server in a second cloud computing infrastructure that supports the service.

9. The controller device of claim 8 , wherein the computer-executable instructions further cause the one or more processors to:

select a tunnel associated with the second server in the second cloud computing infrastructure; and

cause the headend device to migrate the secure communication session to the tunnel.

10. The controller device of claim 9 , wherein the computer-executable instructions further cause the one or more processors to:

select the tunnel based at least in part on load capacity of the tunnel and a stability of the tunnel.

11. The controller device of claim 10 , wherein the computer-executable instructions further cause the one or more processors to:

determine the load capacity of the tunnel by estimating the load capacity of the tunnel that would remain where the secure communication session is migrated to the tunnel.

12. The controller device of claim 8 , wherein the computer-executable instructions further cause the one or more processors to:

send a probe to the first cloud computing infrastructure; and

receive the telemetry data in response to the probe.

13. The controller device of claim 8 , wherein the load information includes numbers of sessions served by the service via the first cloud computing infrastructure.

14. The controller device of claim 8 , wherein the QoS policy is related to the first cloud computing infrastructure.

15. A method comprising:

receiving a request to establish a secure communication session between a client device and a service;

selecting a first tunnel for the secure communication session based at least in part on a first load capacity of the first tunnel and a first stability of the first tunnel;

causing a headend device to establish the secure communication session between the client device and a server in a first cloud computing infrastructure supporting the service using the first tunnel;

receiving telemetry data indicating that performance of the secure communication session is predicted to degrade below a threshold performance level at an upcoming time; and

in response to determining that the performance is predicted to degrade below the threshold performance level, automatically:

selecting a second tunnel for the secure communication session based at least in part on a second load capacity of the second tunnel and a second stability of the second tunnel, the second tunnel connecting the headend device to a second server in a second cloud computing infrastructure supporting the service; and

causing the headend device to migrate the secure communication session to the second tunnel before the upcoming time.

16. The method of claim 15 , wherein the telemetry data comprise historical data, the method further comprising:

analyzing the historical data to determine that the performance of the secure communication session is predicted to degrade below the threshold performance level at the upcoming time.

17. The method of claim 15 , wherein the telemetry data comprise crowdsourced data, the method further comprising:

analyzing the crowdsourced data to determine that the performance of the secure communication session is predicted to degrade below the threshold performance level at the upcoming time.

18. The method of claim 15 , wherein the telemetry data comprise peer data, the method further comprising:

receiving observed data from the headend device; and

comparing the peer data to the observed data to determine that the performance of the secure communication session is predicted to degrade below the threshold performance level at the upcoming time.

19. The method of claim 18 , wherein the peer data and the observed data relate to application throughput.

20. The method of claim 15 , further comprising:

in response to determining that the performance is predicted to degrade below the threshold performance level, sending a message to the client device regarding the secure communication session.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2020
From: WONG, CHUNHUI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 054275/0940 →
Continuity (1)
Related Publication 20220141139A1 · May 5, 2022