IP Library › Granted Patent US 12,542,763
Granted Patent B2
US 12,542,763 · App. 18/105,768 · Granted Feb 3, 2026

Techniques for a virtual bootstrap environment using a distributed virtual private network

Inventor: Michel Belleau (L'Ange-Gardien, CA)
Assignee: Oracle International Corporation
H04L63/0272H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,763
App. No.
18/105,768
Filed
Feb 3, 2023
Granted
Feb 3, 2026
Kind
B2
Art Unit
2497
USPC
726/15
Abstract

Techniques are disclosed for establishing a distributed virtual private network within a virtual bootstrap environment. A distributed computing system can generate a virtual cloud network in a data center of a host region. The virtual cloud network can include a plurality of host instances, including an instance hosting a virtual private network router. A second instance can provide a secondary network address to the virtual private network router. A third instance can send a request addressed to the secondary network address. The virtual cloud network may route the request to the virtual private network router according to a default route of a routing table. The request may then be forwarded by the virtual private network router to the secondary address using a networking tunnel established between the first instance and the second instance.

Claims (67)

1 . A method, comprising:

generating, by a distributed computing system of a cloud service provider, a virtual cloud network in a data center of a host region, the virtual cloud network comprising a plurality of host instances each having primary network addresses associated with a routing table of the virtual cloud network;

implementing, on a first instance of the plurality of host instances, a virtual private network router;

sending, by a second instance of the plurality of host instances, a secondary network address of the second instance to the virtual private network router, the second instance of the plurality of host instances comprising a netmesh component used to send the secondary network address;

sending, from a third instance of the plurality of host instances, a request addressed to the secondary network address;

routing the request to the virtual private network router according to a default route of the routing table, the default route identifying the primary network address of the first instance of the plurality of host instances;

establishing a networking tunnel between the first instance of the plurality of host instances and the second instance of the plurality of host instances according to the secondary network address exposed by the netmesh component; and

forwarding, by the virtual private network router using the networking tunnel, the request to the second instance of the plurality of host instances.

2 . The method of claim 1 , further comprising:

provisioning, by a first service hosted in the virtual cloud network, a network host in a data center of a target region, the network host comprising an additional netmesh component;

establishing a first network connection between the first instance and network host in a target region;

receiving, from the network host using the first network connection, routing information comprising a network address of a target region instance; and

provisioning, by the first service hosted in the virtual cloud network and using the network address of the target region instance and the first network connection, a target region service at the target region instance, wherein a portion of traffic for the provisioning is routed to the target region instance using the additional netmesh component of the network host.

3 . The method of claim 2 , further comprising:

sending, from the third instance of the plurality of host instances, a second request addressed to the network address of the target region instance; and

routing the second request to the target region instance according to the routing information and using the first network connection.

4 . The method of claim 2 , further comprising:

establishing a second network connection between the third instance of the plurality of host instances and the network host; and

sending, from the third instance, a second request addressed to the network address of the target region instance, the second request sent using the second network connection.

5 . The method of claim 2 , wherein provisioning the network host comprises provisioning the network host using an out-of-band network connection between the first service and the data center of the target region.

6 . The method of claim 2 , wherein the first network connection is a first IPSec tunnel, and wherein establishing the first network connection comprises terminating the first IPSec tunnel at the network host.

7 . The method of claim 4 , wherein the second network connection is a second IPSec tunnel, and wherein establishing the second network connection comprises terminating the second IPSec tunnel at the network host.

8 . The method of claim 1 , wherein the request is an anycast request.

9 . The method of claim 1 , wherein the networking tunnel comprises an IP-in-IP tunnel.

10 . A computing system comprising:

one or more processors; and

one or more memories storing computer-executable instructions that, when executed with the one or more processors, cause the computing system to at least:

generate a virtual cloud network in a data center of a host region, the virtual cloud network comprising a plurality of host instances each having primary network addresses associated with a routing table of the virtual cloud network;

implement, on a first instance of the plurality of host instances, a virtual private network router;

send, by a second instance of the plurality of host instances, a secondary network address of the second instance to the virtual private network router, the second instance of the plurality of host instances comprising a netmesh component used to send the secondary network address;

send, from a third instance of the plurality of host instances, a request addressed to the secondary network address;

route the request to the virtual private network router according to a default route of the routing table, the default route identifying the primary network address of the first instance of the plurality of host instances;

establish a networking tunnel between the first instance of the plurality of host instances and the second instance of the plurality of host instances according to the secondary network address exposed by the netmesh component; and

forward, by the virtual private network router using the networking tunnel, the request to the second instance of the plurality of host instances.

11 . The computing system of claim 10 , wherein the one or more memories store additional instructions that, when executed with the one or more processors, further cause the computing system to at least:

provision, by a first service hosted in the virtual cloud network, a network host in a data center of a target region, the network host comprising an additional netmesh component;

establish a first network connection between the first instance and the virtual private network host in a target region;

receive, from the network host using the first network connection, routing information comprising a network address of a target region instance; and

provisioning, by the first service hosted in the virtual cloud network and using the network address of the target region instance and the first network connection, a target region service at the target region instance, wherein a portion of traffic for the provisioning is routed to the target region instance using the additional netmesh component of the network host.

12 . The computing system of claim 11 , wherein the one or more memories store additional instructions that, when executed with the one or more processors, further cause the computing system to at least:

send, from the third instance of the plurality of host instances, a second request addressed to the network address of the target region instance; and

route the second request to the target region instance according to the routing information and using the first network connection.

13 . The computing system of claim 11 , wherein the one or more memories store additional instructions that, when executed with the one or more processors, further cause the computing system to at least:

establish a second network connection between the third instance of the plurality of host instances and the network host; and

send, from the third instance, a second request addressed to the network address of the target region instance, the second request sent using the second network connection.

14 . The computing system of claim 11 , wherein provisioning the network host comprises provisioning the network host using an out-of-band network connection between the first service and the data center of the target region.

15 . The computing system of claim 11 , wherein the first network connection is a first IPSec tunnel, and wherein establishing the first network connection comprises terminating the first IPSec tunnel at the network host.

16 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed with one or more processors, cause a computing system to at least:

generate a virtual cloud network in a data center of a host region, the virtual cloud network comprising a plurality of host instances each having primary network addresses associated with a routing table of the virtual cloud network;

implement, on a first instance of the plurality of host instances, a virtual private network router;

send, by a second instance of the plurality of host instances, a secondary network address of the second instance to the virtual private network router, the second instance of the plurality of host instances comprising a netmesh component used to send the secondary network address;

send, from a third instance of the plurality of host instances, a request addressed to the secondary network address;

route the request to the virtual private network router according to a default route of the routing table, the default route identifying the primary network address of the first instance of the plurality of host instances;

establish a networking tunnel between the first instance of the plurality of host instances and the second instance of the plurality of host instances according to the secondary address exposed by the netmesh component; and

forward, by the virtual private network router using the networking tunnel, the request to the second instance of the plurality of host instances.

17 . The non-transitory computer-readable medium of claim 16 , storing further instructions that, when executed with the one or more processors, cause the computing system to further:

provision, by a first service hosted in the virtual cloud network, a network host in a data center of a target region, the network host comprising an additional netmesh component;

establish a first network connection between the first instance and the virtual private network host in a target region;

receive, from the network host using the first network connection, routing information comprising a network address of a target region instance; and

provisioning, by the first service hosted in the virtual cloud network and using the network address of the target region instance and the first network connection, a target region service at the target region instance, wherein a portion of traffic for the provisioning is routed to the target region instance using the additional netmesh component of the network host.

18 . The non-transitory computer-readable medium of claim 17 , storing further instructions that, when executed with the one or more processors, cause the computing system to further:

send, from the third instance of the plurality of host instances, a second request addressed to the network address of the target region instance; and

route the second request to the target region instance according to the routing information and using the first network connection.

19 . The non-transitory computer-readable medium of claim 17 , storing further instructions that, when executed with the one or more processors, cause the computing system to further:

establish a second network connection between the third instance of the plurality of host instances and the network host; and

send, from the third instance, a second request addressed to the network address of the target region instance, the second request sent using the second network connection.

20 . The non-transitory computer-readable medium of claim 17 , wherein the first network connection is a first IPSec tunnel, and wherein establishing the first network connection comprises terminating the first IPSec tunnel at the network host.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2023
From: BELLEAU, MICHEL
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 062785/0447 →
Continuity (4)
Provisional Application 63314953 · Feb 28, 2022
Provisional Application 63308003 · Feb 8, 2022
Provisional Application 63312814 · Feb 22, 2022
Related Publication 20230254287A1 · Aug 10, 2023
References Cited (17)
US 9813379B1 · Shevade et al. · 2017 [cited by applicant]
US 10171292B1 · Dolan · 2019 [cited by examiner]
US 10853111B1 · Gupta et al. · 2020 [cited by applicant]
US 11363113B1 · Edwards · 2022 [cited by examiner]
US 11853802B1 · Wei et al. · 2023 [cited by applicant]
US 11991254B1 · Liu · 2024 [cited by examiner]
US 20170228227A1 · Winterfeldt et al. · 2017 [cited by applicant]
US 20210168052A1 · Parulkar et al. · 2021 [cited by applicant]
US 20210266256A1 · Janakiraman et al. · 2021 [cited by applicant]
US 20220327007A1 · Adogla et al. · 2022 [cited by applicant]
WO WO0233987A2 · 2002 [cited by examiner]
WO 2021150307A1 · 2021 [cited by applicant]
U.S. Appl. No. 18/105,766, Non-Final Office Action mailed on May 23, 2024, 9 pages. [cited by applicant]
Bari et al., Data Center Network Virtualization: A Survey, Institute of Electrical and Electronics Engineers Communications Surveys & Tutorials, vol. 15, No. 2, Jan. 2013, pp. 909-928. [cited by applicant]
Hao et al., Enhancing Dynamic Cloud-based Services Using Network Virtualization, ACM Digital Library, vol. 40, No. 1, Jan. 7, 2010, pp. 67-74. [cited by applicant]
International Application No. PCT/US2023/062058, International Search Report and Written Opinion mailed on May 12, 2023, 13 pages. [cited by applicant]
International Application No. PCT/US2023/062060, International Search Report and the Written Opinion mailed on Apr. 28, 2023, 10 pages. [cited by applicant]