IP Library Granted Patent US 12,068,889
Granted Patent B2
US 12,068,889 · App. 17/882,438 · Granted Aug 20, 2024

Scalable tenant networks

Inventors: Poornananda R. Gaddehosur (Redmond, WA); Benjamin M. Schultz (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L12/4675G06F9/45537H04L41/0893H04L41/12H04L41/122H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,068,889
App. No.
17/882,438
Granted
Aug 20, 2024
Kind
B2
Abstract

Template-driven locally calculated policy updates for virtualized machines in a datacenter environment are described. A central control and monitoring node calculates and pushes down policy templates to local control and monitoring nodes. The templates provide boundaries and/or a pool of networking resources, from which the local control and monitoring node is enabled to calculate policy updates for locally instantiated virtual machines and containers.

Claims (43)

1. A computerized system comprising:

one or more computer processors; and

computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations comprising:

allocating, by a central controller, a policy for a tenant network;

receiving, at the central controller and from a local controller associated with the tenant network, a declaration of a number of containers hosted by one or more nodes or one or more virtual machines of the tenant network; and

sending, from the central controller to the local controller and based at least in part on the declaration, a policy template associated with the policy for the tenant network.

2. The system of claim 1 , the operations further comprising:

calculating, by the local controller, a network virtualization policy based at least in part on the policy template; and

distributing the network virtualization policy to the one or more nodes or the one or more virtual machines of the tenant network.

3. The system of claim 1 , wherein the tenant network comprises at least one of a routing domain identifier (RDID) or a host domain.

4. The system of claim 1 , wherein the policy template indicates a change to one or more configurable policy elements.

5. The system of claim 4 , wherein the one or more configurable policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, port numbers, or customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

6. The system of claim 4 , wherein the one or more configurable policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

7. The system of claim 4 , wherein:

the one or more configurable policy elements comprise constraints for service chain configuration;

the service chain configuration comprises a path of service chain elements a data packet traverses during communication to or from a destination in a datacenter; and

an individual service chain element comprises a load balancer, an anti-virus scanner, a firewall, or a packet inspection server.

8. The system of claim 4 , wherein the one or more configurable policy elements comprise local forwarding tables that include a destination with which a node or a virtual machine is able to communicate, wherein the local forwarding tables include encapsulate/decapsulate rules, network address translation rules, or a range of IP addresses that are reachable by the node or the virtual machine.

9. One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations comprising:

allocating, by a central controller, a policy for a tenant network;

receiving, at the central controller and from a local controller associated with the tenant network, a declaration of a number of containers hosted by one or more nodes or one or more virtual machines of the tenant network; and

sending, from the central controller to the local controller and based at least in part on the declaration, a policy template associated with the policy for the tenant network.

10. The media of claim 9 , the operations further comprising:

calculating, by the local controller, a network virtualization policy based at least in part on the policy template; and

distributing the network virtualization policy to the one or more nodes or the one or more virtual machines of the tenant network.

11. The media of claim 9 , wherein the tenant network comprises at least one of a routing domain identifier (RDID) or a host domain.

12. The media of claim 9 , wherein the policy template indicates a change to one or more configurable policy elements.

13. The media of claim 12 , wherein the one or more configurable policy elements comprise one or more of: Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, port numbers, or customer addresses (CAs) for one or more routing domain identifiers (RDIDs).

14. The media of claim 12 , wherein the one or more configurable policy elements comprise load balancer virtual Internet Protocol (VIP) address to dynamic Internet Protocol (DIP) address mappings.

15. The media of claim 12 , wherein:

the one or more configurable policy elements comprise constraints for service chain configuration;

the service chain configuration comprises a path of service chain elements a data packet traverses during communication to or from a destination in a datacenter; and

an individual service chain element comprises a load balancer, an anti-virus scanner, a firewall, or a packet inspection server.

16. The media of claim 12 , wherein the one or more configurable policy elements comprise local forwarding tables that include a destination with which a node or a virtual machine is able to communicate, wherein the local forwarding tables include encapsulate/decapsulate rules, network address translation rules, or a range of IP addresses that are reachable by the node or the virtual machine.

17. A computer-implemented method, the method comprising:

allocating, by a central controller, a policy for a tenant network;

receiving, at the central controller and from a local controller associated with the tenant network, a declaration of a number of containers hosted by one or more nodes or one or more virtual machines of the tenant network; and

sending, from the central controller to the local controller and based at least in part on the declaration, a policy template associated with the policy for the tenant network.

18. The method of claim 17 , the operations further comprising:

calculating, by the local controller, a network virtualization policy based at least in part on the policy template; and

distributing the network virtualization policy to the one or more nodes or the one or more virtual machines of the tenant network.

19. The method of claim 17 , wherein the tenant network comprises at least one of a routing domain identifier (RDID) or a host domain.

20. The method of claim 17 , wherein the policy template indicates a change to one or more configurable policy elements.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2022
From: GADDEHOSUR, POORNANANDA R.; SCHULTZ, BENJAMIN M.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061081/0812 →
Continuity (6)
Division 16706456 · Dec 6, 2019
Continuation 16054638 · Aug 3, 2018
Continuation 15859247 · Dec 29, 2017
Continuation 15075049 · Mar 18, 2016
Provisional Application 62267664 · Dec 15, 2015
Related Publication 20220374253A1 · Nov 24, 2022