IP Library Granted Patent US 11,856,041
Granted Patent B2
US 11,856,041 · App. 17/231,366 · Granted Dec 26, 2023

Distributed routing and load balancing in a dynamic service chain

Inventors: Umesh Bangalore Muniyappa (Bangalore, IN); Ravi Ithal (Los AltosLos Altos, CA)
Assignee: Netskope, Inc.
H04L65/613H04L9/3242H04L43/0876H04L45/7453H04L61/2503H04L65/80H04L67/1001H04L69/16H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,856,041
App. No.
17/231,366
Granted
Dec 26, 2023
Kind
B2
Abstract

Disclosed is distributed routing and load balancing in a dynamic service chain, receiving a packet at a first service instance, including a NSH imposed on the by a service classifier. The NSH includes a stream affinity code consistent for packets in a stream. The method also includes processing the packet at the first instance where the instance performs a first service in a service chain that includes second and third services. The first service instance accesses a flow table using the stream affinity code to select a second service instance performing the second service from among service instances performing the second service, and the first instance routes the packet to the selected second service instance upon egress from the first service instance. The method can include hashing the stream affinity code to access the flow table and access an available instance using the hash as a key to a CHT.

Claims (37)

1. A method of distributed routing and load balancing in a dynamic service chain of services running on servers, including:

receiving a packet at a first service instance, including a network service header (abbreviated NSH) added to the packet after receipt by a service classifier of the packet from a source, wherein the NSH includes a stream affinity code that is consistent for packets in a stream;

processing the packet at the first service instance, wherein the first service instance performs a first service in a service chain that further includes at least second and third services;

the first service instance accessing a local flow table using the stream affinity code to select a second service instance, from among a plurality of service instances performing the second service; and

the first service instance routing the packet to the selected second service instance upon egress from the first service instance.

2. The method of claim 1 , wherein the NSH is implemented as a user datagram protocol (abbreviated UDP) header.

3. The method of claim 1 , further including hashing the stream affinity code to access the flow table.

4. The method of claim 1 , wherein the local flow table lacks an entry for the second service corresponding to the stream affinity code in the NSH, further including:

accessing a consistent hash table (abbreviated CHT) of service instances performing the second service;

selecting an available instance using a six-tuple hash as a key to the CHT to select the second service instance; and

updating the local flow table to specify the second service instance as providing the second service for packets sharing the header.

5. The method of claim 4 , further including selecting an alternate second service instance from the CHT and updating the local flow table to specify the alternate second service instance.

6. The method of claim 4 , wherein the NSH header includes a client ID, and wherein the six-tuple hash is generated using the client ID and using source IP, source port, destination IP, destination port and IP protocol number for the packet.

7. The method of claim 1 , wherein the service chain is a security service chain and at least the second and third services are security services.

8. The method of claim 1 , wherein instances of the first, second and third services run in containers and the containers are hosted in pods.

9. The method of claim 1 , wherein instances of the first, second and third services are implemented on virtual machines, bare metal servers or custom hardware.

10. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a computer-implemented method of distributed routing and load balancing in a dynamic service chain of services running on servers, including:

receiving a packet at a first service instance, including a network service header (abbreviated NSH) added to the packet after receipt by a service classifier of the packet from a source, wherein the NSH includes a stream affinity code that is consistent for packets in a stream;

processing the packet at the first service instance, wherein the first service instance performs a first service in a service chain that further includes at least second and third services;

the first service instance accessing a local flow table using the stream affinity code to select a second service instance, from among a plurality of service instances performing the second service; and

the first service instance routing the packet to the selected second service instance upon egress from the first service instance.

11. The tangible non-transitory computer readable storage media of claim 10 , wherein the NSH is implemented as a user datagram protocol (abbreviated UDP) header.

12. The tangible non-transitory computer readable storage media of claim 10 , wherein the local flow table lacks an entry for the second service corresponding to the stream affinity code in the NSH, further including:

accessing a consistent hash table (abbreviated CHT) of service instances performing the second service;

selecting an available instance using a six-tuple hash as a key to the CHT to select the second service instance; and

updating the local flow table to specify the second service instance as providing the second service for packets sharing the header.

13. The tangible non-transitory computer readable storage media of claim 12 , further including selecting an alternate second service instance from the CHT and updating the local flow table to specify the alternate second service instance.

14. The tangible non-transitory computer readable storage media of claim 12 , wherein the NSH header includes a client ID, and wherein the six-tuple hash is generated using the client ID and using source IP, source port, destination IP, destination port and IP protocol number for the packet.

15. The tangible non-transitory computer readable storage media of claim 10 , wherein instances of the first, second and third services run in containers and the containers are hosted in pods.

16. The tangible non-transitory computer readable storage media of claim 10 , wherein instances of the first, second and third services are implemented on virtual machines, bare metal servers or custom hardware.

17. A system for distributed routing and load balancing in a dynamic service chain of services running on servers, the system including a processor, memory coupled to the processor, and computer instructions from the tangible non-transitory computer readable storage media of claim 10 loaded into the memory.

18. The system of claim 17 , wherein the local flow table lacks an entry for the second service corresponding to the stream affinity code in the NSH, further including:

accessing a consistent hash table (abbreviated CHT) of service instances performing the second service;

selecting an available instance using a six-tuple hash as a key to the CHT to select the second service instance; and

updating the flow table to specify the second service instance as providing the second service for packets sharing the header.

19. The system of claim 18 , further including selecting an alternate second service instance from the CHT and updating the local flow table to specify the alternate second service instance.

20. The system of claim 18 , wherein the NSH header includes a client ID, and wherein the six-tuple hash is generated using the client ID and using source IP, source port, destination IP, destination port and IP protocol number for the packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2021
From: ITHAL, RAVI; MUNIYAPPA, UMESH BANGALORE
To: NETSKOPE, INC.
Reel/Frame 055930/0480 →
Continuity (4)
Continuation 16807128 · Mar 2, 2020
Provisional Application 62812760 · Mar 1, 2019
Provisional Application 62812791 · Mar 1, 2019
Related Publication 20210306393A1 · Sep 30, 2021