IP Library Granted Patent US 12,058,207
Granted Patent B2
US 12,058,207 · App. 17/582,444 · Granted Aug 6, 2024

Load balancing and secure tunneling for cloud-based network controllers

Inventors: Yu-Cheng Kung (Taipei, TW); Chien-Hua Chen (Taipei, TW)
Assignee: Ruckus IP Holdings LLC
H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,058,207
App. No.
17/582,444
Filed
Jan 24, 2022
Granted
Aug 6, 2024
Kind
B2
Art Unit
2449
USPC
709/225
Abstract

Methods, systems, and devices for using secured tunnels (e.g., SSH tunnels), for example with microservices-based architectures and/or operating-system level virtualization technologies, An example method may include receiving, by a secured tunnel server and via a secured tunnel, network traffic intended for a first original destination of the plurality of original destinations; selecting, using a plurality of override rules that indicate mappings between a plurality of original destinations and respective override destinations, an override destination for the network traffic intended for the first original destination; and forwarding, by the secured tunnel server, the network traffic to the override destination.

Claims (34)

1. A method comprising:

instantiating an instance of a first containerized software component within an orchestrated cluster, wherein the first containerized software component is configured to provide a secured tunnel server;

instantiating a plurality of instances of a second containerized software component within the orchestrated cluster;

receiving, by the secured tunnel server and via a secured tunnel, network traffic intended for a first original destination;

selecting, based on a plurality of override rules, an override destination for the network traffic intended for the first original destination, wherein selecting the override destination for the network traffic intended for the first original destination comprises selecting one of the plurality of instances of the second containerized software component within the orchestrated cluster; and

forwarding, by the secured tunnel server, the network traffic to the selected override destination,

wherein the network traffic intended for the first original destination is received from a wireless access point and comprises control plane traffic.

2. The method of claim 1 , further comprising receiving, by the secured tunnel server, data related to each of the plurality of instances of the second containerized software component within the orchestrated cluster, and wherein selecting one of the plurality of instances of the second containerized software component within the orchestrated cluster is based on the received data.

3. A method comprising:

operating an orchestrated cluster comprising a plurality of containerized software components, wherein the plurality of containerized software components includes at least one instance of a first containerized software component that is configured to provide a secured tunnel server and a plurality of instances of a second containerized software component configured to control and/or manage wireless access points;

receiving, by the secured tunnel server and via a secured tunnel, first network traffic from a wireless access point addressed to a port on the secured tunnel server;

selecting, based on a plurality of override rules, one of the instances of the second containerized software component for the first network traffic;

forwarding, by the secured tunnel server, the first network traffic to the selected one of the instances of the second containerized software component;

receiving, by the secured tunnel server and via a secured tunnel, second network traffic from the wireless access point addressed to the port on the secured tunnel server; and

forwarding, by the secured tunnel server, the second network traffic to the selected one of the instances of the second containerized software component.

4. The method of claim 3 , wherein selecting the one of the plurality of instances of the second containerized software component comprises selecting among the plurality of instances of the second containerized software component randomly.

5. A method comprising:

operating an orchestrated cluster comprising a plurality of containerized software components, wherein the plurality of containerized software components includes at least one instance of a first containerized software component that is configured to provide a secured tunnel server and a plurality of instances of a second containerized software component configured to control and/or manage wireless access points;

receiving, by the secured tunnel server and via a secured tunnel, first network traffic from a wireless access point addressed to a port on the secured tunnel server;

selecting, based on a plurality of override rules, one of the instances of the second containerized software component for the first network traffic;

forwarding, by the secured tunnel server, the first network traffic to the selected one of the instances of the second containerized software component; and

receiving, by the first containerized software component, data related to each of the plurality of instances of the second containerized software component, and wherein selecting the one of the plurality of instances of the second containerized software component is based on the received data.

6. The method of claim 5 , wherein the received data regarding each of the plurality of instances of the second containerized software component comprises processor usage data for each of the plurality of instances of the second containerized software component.

7. The method of claim 6 , wherein selecting the one of the plurality of instances of the second containerized software component comprises selecting an instance of the second containerized software component associated with a lowest processor usage from among the plurality of instances of the second containerized software component.

8. The method of claim 5 , wherein the received data regarding each of the plurality of instances of the second containerized software component comprises memory usage data for each of the plurality of instances of the second containerized software component.

9. The method of claim 8 , wherein selecting the one of the plurality of instances of the second containerized software component comprises selecting an instance of the second containerized software component associated with a lowest memory usage from among the plurality of instances of the second containerized software component.

10. The method of claim 5 , further comprising:

receiving, by the secured tunnel server and via a secured tunnel, second network traffic from the wireless access point addressed to the port on the secured tunnel server; and

forwarding, by the secured tunnel server, the second network traffic to the selected one of the instances of the second containerized software component.

11. The method of claim 2 , wherein the data related to each of the plurality of instances of the second containerized software components comprises processor usage data, and wherein selecting one of the plurality of instances of the second containerized software component within the orchestrated cluster comprises selecting an instance of the second containerized software component associated with a lowest processor usage from among the plurality of instances of the second containerized software component.

12. The method of claim 2 , wherein the data related to each of the plurality of instances of the second containerized software components comprises memory usage data, and wherein selecting one of the plurality of instances of the second containerized software component within the orchestrated cluster comprises selecting an instance of the second containerized software component associated with a lowest memory usage from among the plurality of instances of the second containerized software component.

13. The method of claim 1 , wherein the network traffic is first network traffic, the method further comprising:

receiving, by the secured tunnel server, second network traffic intended for the first original destination from the wireless access point and comprising further control plane traffic; and

forwarding, by the secured tunnel server, the second network traffic to the selected one of the instances of the second containerized software component.

Assignments (9)
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 2, 2026
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075892/0107 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067252/0657 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074593/0348 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067259/0697 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069790/0575 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
PATENT SECURITY AGREEMENT (ABL) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067252/0657 →
PATENT SECURITY AGREEMENT (TERM) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067259/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2022
From: KUNG, YU-CHENG; CHEN, CHIEN-HUA
To: ARRIS ENTERPRISES LLC
Reel/Frame 059208/0696 →
Continuity (2)
Provisional Application 63141143 · Jan 25, 2021
Related Publication 20220239632A1 · Jul 28, 2022