IP Library Granted Patent US 11,894,947
Granted Patent B2
US 11,894,947 · App. 18/067,713 · Granted Feb 6, 2024

Network layer performance and security provided by a distributed cloud computing network

Inventors: Nicholas Alexander Wondra (Savoy, IL); Achiel Paul van der Mandele (Austin, TX); Alexander Forster (Austin, TX); Eric Reeves (Austin, TX); Joaquin Madruga (Austin, TX); Rustam Xing Lalkaka (San Francisco, CA); Marek Przemyslaw Majkowski (Warsaw, PL)
Assignee: CLOUDFLARE, INC.
H04L12/4633H04L2101/618
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,894,947
App. No.
18/067,713
Granted
Feb 6, 2024
Kind
B2
Abstract

A GRE tunnel is configured between multiple computing devices of a distributed cloud computing network and a single origin router of the origin network. The GRE tunnel has a first GRE endpoint that has an IP address that is shared among the computing devices of the distribute cloud computing network and a second GRE endpoint that has a publicly routable IP address of the origin router. A first computing device receives an IP packet from a client that is destined to an origin server. The first computing device processes the received IP packet and encapsulates the IP packet inside an outer packet to generate a GRE encapsulated packet whose source address is the first GRE endpoint and the destination address is the second GRE endpoint. The GRE encapsulated packet is transmitted over the GRE tunnel to the single origin router.

Claims (44)

1. A method in a distributed cloud computing network that includes a plurality of computing devices, the method comprising:

receiving a first IP packet at a first one of the plurality of computing devices of a first data center, wherein the received first IP packet is destined to a first origin server of a first origin network, wherein the received first IP packet has destination IP address, and wherein the first computing device does not have a private network interconnect (PNI) connection with the first origin network;

processing the received first IP packet at the first computing device;

determining that a second data center has the PNI connection with the first origin network;

encapsulating the processed first IP packet inside a first outer packet to generate a first encapsulated packet that uses IP as a transport protocol;

transmitting the first encapsulated packet from the first data center to the second data center that has the PNI connection with the first origin network;

processing, at a second one of the plurality of computing devices of the second data center, the first encapsulated packet including decapsulating the first encapsulated packet to reveal the first IP packet; and

transmitting the first IP packet to the first origin server of the first origin network over the PNI connection.

2. The method of claim 1 , wherein processing the received first IP packet at the first computing device includes performing a distributed denial of service (DDoS) mitigation on the first IP packet.

3. The method of claim 1 , wherein the first destination IP address is an anycast IP address.

4. The method of claim 1 , wherein processing the received first IP packet includes performing layer 4 and/or layer 7 processing.

5. The method of claim 1 , wherein the first encapsulated packet is User Datagram Protocol (UDP) encapsulated.

6. The method of claim 1 , further comprising:

wherein the first IP packet is received from a client device;

receiving, at the second data center, a second IP packet from the first origin server of the first origin network over the PNI connection, wherein the second IP packet is in response to the first IP packet;

encapsulating the second IP packet inside a second outer packet to generate a second encapsulated packet that uses IP as a transport protocol;

transmitting the second encapsulated packet from the second data center to the first data center;

decapsulating, at the first data center, the second encapsulated packet to reveal the second IP packet; and

transmitting the second IP packet from the first data center to the client device.

7. The method of claim 6 , wherein the second encapsulated packet is User Datagram Protocol (UDP) encapsulated.

8. A distributed cloud computing network that includes a plurality of computing devices, comprising:

a first one of the plurality of computing devices of a first data center that includes a first non-transitory machine-readable storage medium that provides instructions that, when executed by a processor of the first computing device, cause the first computing device to perform first operations comprising:

receiving a first IP packet, wherein the received first IP packet is destined to a first origin server of a first origin network, wherein the received first IP packet has a first destination IP address, and wherein the first computing device does not have a private network interconnect (PNI) connection with the first origin network;

processing the received first IP packet at the first computing device;

determining that a second data center has the PNI connection with the first origin network;

encapsulating the processed first IP packet inside a first outer packet to generate a first encapsulated packet that uses IP as a transport protocol;

transmitting the first encapsulated packet from the first data center to the second data center that has the PNI connection with the first origin network; and

a second one of the plurality of computing devices of the second data center that includes a second non-transitory machine-readable storage medium that provides instructions that, when executed by a processor of the second computing device, cause the second computing device to perform second operations comprising:

processing, at a second computing device, the first encapsulated packet including decapsulating the first encapsulated packet to reveal the first IP packet; and

transmitting the first IP packet to the first origin server of the first origin network over the PNI connection.

9. The distributed cloud computing network of claim 8 , wherein processing the received first IP packet at the first computing device includes performing a distributed denial of service (DDoS) mitigation on the first IP packet.

10. The distributed cloud computing network of claim 8 , wherein the first destination IP address is an anycast IP address.

11. The non-transitory machine-readable storage medium of claim 8 , wherein processing the received first IP packet includes performing layer 4 and/or layer 7 processing.

12. The distributed cloud computing network of claim 8 , wherein the first encapsulated packet is User Datagram Protocol (UDP) encapsulated.

13. The distributed cloud computing network of claim 8 , further comprising:

wherein the first IP packet is received from a client device;

wherein the second operations further include:

receiving a second IP packet from the first origin server of the first origin network over the PNI connection, wherein the second IP packet is in response to the first IP packet;

encapsulating the second IP packet inside a second outer packet to generate a second encapsulated packet that uses IP as a transport protocol; and

transmitting the second encapsulated packet from the second data center to the first data center;

wherein the first operations further include:

decapsulating the second encapsulated packet to reveal the second IP packet; and

transmitting the second IP packet from the first data center to the client device.

14. The distributed cloud computing network of claim 13 , wherein the second encapsulated packet is User Datagram Protocol (UDP) encapsulated.

Assignments (1)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (4)
Continuation 17481177 · Sep 21, 2021
Continuation 16993181 · Aug 13, 2020
Provisional Application 62886314 · Aug 13, 2019
Related Publication 20230124628A1 · Apr 20, 2023
Cited By (1)
US 12,452,333