IP Library Granted Patent US 12,348,392
Granted Patent B2
US 12,348,392 · App. 17/988,690 · Granted Jul 1, 2025

Lightweight container networking solution for resource constrained devices

Inventors: Anil Kumar Vishnoi (Sacramento, CA); Brent Salisbury (Frankfort, KY)
Assignee: Red Hat, Inc.
H04L43/028H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,392
App. No.
17/988,690
Granted
Jul 1, 2025
Kind
B2
Abstract

A networking request is received from a first workload, within a first container, on an edge device. A determination is made that the destination of the networking request is a second workload, within a second container, on the edge device. In response to determining the destination of the networking request, the networking request is forwarded to the second application, wherein the forwarding comprises intercepting the networking request at a socket associated with the first workload and delivering the network request to a socket associated with the second workload.

Claims (49)

1. A method comprising:

receiving, from a first workload executing within a first container on an edge device, a request to send data to a second workload;

determining that the second workload is executing within a second container on the edge device, wherein the first container and the second container are different; and

in response to the determining:

identifying, by a processing device and using a map, a first socket on the first container, wherein the first socket is associated with the first workload;

identifying, by the processing device and using the map, a second socket on the second container, wherein the second socket is associated with the second workload; and

routing, by the processing device, a set of data packets associated with the data from the first socket to the second socket,

wherein the routing comprises:

intercepting the request at a socket layer to determine a socket address of the second workload;

routing the request according to socket address while bypassing one or more Transmission Control Protocol/Internet Protocol (TCP/IP) layers that are lower than the socket layer; and

executing an extended Berkeley packet filter.

2. The method of claim 1 , wherein the request comprises a networking system call.

3. The method of claim 2 , wherein the networking system call comprises a payload.

4. The method of claim 1 , wherein the request is intercepted at the socket layer using a hook.

5. The method of claim 1 , wherein the map is created during orchestration of the first container and the second container on the edge device.

6. The method of claim 1 , wherein routing the set of data packets from the first socket to the second socket comprises obtaining a payload of the data prior to encapsulating the payload within a TCP/IP packet.

7. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

receive, from a first workload executing within a first container on an edge device, a request to send data to a second workload;

determine that the second workload is executing within a second container on the edge device, wherein the first container and second container are different; and

in response to the determining:

identify, by a processing device and using a map, a first socket on the first container, wherein the first socket is associated with the first workload;

identify, by the processing device and using the map, a second socket on the second container, wherein the second socket is associated with the second workload; and

route, by the processing device, a set of data packets associated with the data from the first socket to the second socket,

wherein, to route the set of data packets, the processing device is to:

intercept the request at a socket layer to determine a socket address of the second workload;

route the request according to socket address while bypassing one or more Transmission Control Protocol/Internet Protocol (TCP/IP) layers that are lower than the socket layer; and

execute an extended Berkeley packet filter.

8. The system of claim 7 , wherein the request is intercepted at the socket layer using a hook.

9. The system of claim 8 , wherein the hook is an operating system hook.

10. The system of claim 8 , wherein the hook is a sandboxed hook.

11. The system of claim 7 , wherein the map is created during orchestration of the first container and the second container on the edge device.

12. The system of claim 7 , wherein the map comprises a set of entries, an entry comprising:

a network address;

a socket; and

a workflow.

13. The system of claim 7 , wherein the first container and the second container reside within one or more execution environments.

14. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, from a first workload executing within a first container on an edge device, a request to send data to a second workload;

determine that the second workload is executing within a second container on the edge device, wherein the first container and second container are different; and

in response to the determining:

identify, by a processing device and using a map, a first socket on the first container, wherein the first socket is associated with the first workload;

identify, by the processing device and using the map, a second socket on the second container, wherein the second socket is associated with the second workload; and

route, by the processing device, a set of data packets associated with the data,

wherein, to route the set of data packets, the instructions cause the processing device to:

intercept the request at a socket layer to determine a socket address of the second workload;

route the request according to socket address while bypassing one or more Transmission Control Protocol/Internet Protocol (TCP/IP) layers that are lower than the socket layer; and

execute an extended Berkeley packet filter.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: VISHNOI, ANIL KUMAR; SALISBURY, BRENT
To: RED HAT, INC.
Reel/Frame 061971/0532 →
Continuity (1)
Related Publication 20240163184A1 · May 16, 2024
References Cited (56)
US 6301615B1 · Kutcher · 2001 [cited by examiner]
US 6963575B1 · Sistanizadeh · 2005 [cited by examiner]
US 9860429B1 · Silverstein · 2018 [cited by examiner]
US 10127091B1 · MacNeil · 2018 [cited by examiner]
US 20040205231A1 · Clarke · 2004 [cited by examiner]
US 20050030965A1 · Aoki · 2005 [cited by examiner]
US 20050117546A1 · Lioy · 2005 [cited by examiner]
US 20050175016A1 · Kim · 2005 [cited by examiner]
US 20060023713A1 · Choi · 2006 [cited by examiner]
US 20060159088A1 · Aghvami · 2006 [cited by examiner]
US 20070147320A1 · Sattari · 2007 [cited by examiner]
US 20070288619A1 · Jun · 2007 [cited by examiner]
US 20080016339A1 · Shukla · 2008 [cited by examiner]
US 20090031005A1 · Swanson · 2009 [cited by examiner]
US 20090083756A1 · Kim · 2009 [cited by examiner]
US 20100198050A1 · Mori · 2010 [cited by examiner]
US 20120030687A1 · Bhandiwad · 2012 [cited by examiner]
US 20130080650A1 · Cherian · 2013 [cited by examiner]
US 20130107887A1 · Pearson · 2013 [cited by examiner]
US 20140019572A1 · Cardona · 2014 [cited by examiner]
US 20140059206A1 · Venkateshwaran · 2014 [cited by examiner]
US 20140068103A1 · Gyambavantha · 2014 [cited by examiner]
US 20140095691A1 · Ganguli · 2014 [cited by examiner]
US 20140211807A1 · Takenaka · 2014 [cited by examiner]
US 20140333924A1 · Martin · 2014 [cited by examiner]
US 20150172153A1 · Sharma · 2015 [cited by examiner]
US 20150281047A1 · Raju · 2015 [cited by examiner]
US 20150304450A1 · van Bemmel · 2015 [cited by examiner]
US 20150373615A1 · Hampel · 2015 [cited by examiner]
US 20160070755A1 · Kramer · 2016 [cited by examiner]
US 20160094581A1 · Kasbekar · 2016 [cited by examiner]
US 20160231948A1 · Gupta · 2016 [cited by examiner]
US 20160366026A1 · Bartfai-Walcott · 2016 [cited by examiner]
US 20170171159A1 · Kumar · 2017 [cited by examiner]
US 20180041613A1 · Lapidous · 2018 [cited by examiner]
US 20180183725A1 · Ben-Hagai · 2018 [cited by examiner]
US 20190037391A1 · Pignataro · 2019 [cited by examiner]
US 20190141571A1 · Kim · 2019 [cited by examiner]
US 20190207776A1 · Wang · 2019 [cited by examiner]
US 20190238509A1 · Hira · 2019 [cited by examiner]
US 20200252376A1 · Feng · 2020 [cited by examiner]
US 20200310693A1 · Kim · 2020 [cited by examiner]
US 20210344606A1 · Taylor et al. · 2021 [cited by applicant]
US 20210352044A1 · Asveren et al. · 2021 [cited by applicant]
US 20220129541A1 · Scrivano et al. · 2022 [cited by applicant]
US 20220407625A1 · Radi · 2022 [cited by examiner]
US 20230006898A1 · Albrecht · 2023 [cited by examiner]
US 20230052452A1 · Choochotkaew · 2023 [cited by examiner]
US 20230066013A1 · Ball · 2023 [cited by examiner]
US 20230127468A1 · Kondapavuluru · 2023 [cited by examiner]
US 20230315850A1 · Strogov · 2023 [cited by examiner]
CN 111556136A · 2020 [cited by applicant]
CN 114265760A · 2022 [cited by applicant]
Choochotkaew, et al. “Bypass Container Overlay Networks with Transparent BPF-driven Socket Replacement,” 2022 IEEE 15th International Conference on Cloud Computing (CLOUD), Jul. 10-16, 2022, pp. 134-143, doi: 10.1109/CL… [cited by applicant]
Nakamura et al. “Grafting Sockets for Fast Container Networking”, In ANCS '18: Symposium on Architectures for Networking and Communications Systems, Jul. 23-24, 2018, Ithaca, NY, USA. ACM, New York, NY, USA, 13 pages. h… [cited by applicant]
Zavarella, Timothy D. “A methodology for using eBPF to efficiently monitor network behavior in Linux Kubernetes clusters”, thesis submitted to the Department of Electrical Engineering and Computer Science, Massachusetts… [cited by applicant]