IP Library Granted Patent US 12,413,469
Granted Patent B2
US 12,413,469 · App. 18/393,476 · Granted Sep 9, 2025

Secure bi-directional network connectivity system between private networks

Inventors: Shruti Nitin Shetye (Pleasanton, CA); Soumya Kailasa (Fremont, CA); Jesus Velazquez Reyes (Lake Forest Park, WA); Lucas Michael Kreger-Stickles (Seattle, WA); Abhiman Yashpala Karkera (San Jose, CA); Dhwanish Pramthesh Shah (Sunnyvale, CA); Guanhong Pei (Everett, WA); Clayton Matthew Magouyrk (Seattle, WA); Paul James Cainkar (Seattle, WA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L41/0803H04L61/5007H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,469
App. No.
18/393,476
Granted
Sep 9, 2025
Kind
B2
Abstract

A secure private network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) is described that provides secure private network connectivity between external resources residing in a customer's on-premise environment and the customer's resources residing in the cloud. The SNCS provides secure private bi-directional network connectivity between external resources residing in a customer's external site representation and resources and services residing in the customer's VCN in the cloud without a user (e.g., an administrator) of the enterprise having to explicitly configure the external resources, advertise routes or set up site-to-site network connectivity. The SNCS provides a high performant, scalable, and highly available site-to-site network connection for processing network traffic between a customer's on-premise environment and the CSPI by implementing a robust infrastructure of network elements and computing nodes that are used to provide the secure site to site network connectivity.

Claims (34)

1. A method comprising:

creating a connection between an external resource residing in an on-premise network and at least one intermediate container, the on-premise network comprising a user wallet and the intermediate container comprising a VCN wallet, wherein creating the connection includes authentication with the user wallet and the VCN wallet, and wherein the external resource is registered as an external endpoint in a virtual cloud network (VCN);

transmitting a request from an external resource representation residing in the VCN via a virtual network interface card (VNIC) to the external resource;

receiving at the at least one intermediate container a result corresponding to the request via the created connection; and

transmitting, by the at least one intermediate container, the result to the external resource representation via the VNIC using the created connection.

2. The method of claim 1 , further comprising creating a second connection between the at least one intermediate container and the external resource representation.

3. The method of claim 2 , wherein the VCN wallet comprises a VCN client wallet, and wherein the at least one intermediate container comprises a VCN server wallet.

4. The method of claim 3 , wherein creating the second connection includes authentication with the VCN client wallet and the VCN server wallet.

5. The method of claim 4 , further comprising creating each of the VCN client wallet and the VCN server wallet based on the user wallet.

6. The method of claim 4 , wherein the request is transmitted from the external resource to the external resource representation via the intermediate container.

7. The method of claim 6 , wherein the intermediate container resides on a data plane.

8. The method of claim 6 , wherein the intermediate container comprises a proxy server.

9. The method of claim 7 , wherein the intermediate container comprises a first container and a second container.

10. The method of claim 9 , wherein the first container is configured for communicative coupling with the on-premise network via a first tunnel shard.

11. The method of claim 10 , wherein the first container is configured for communicative coupling with the on-premise network via the first tunnel shard and a public communication network.

12. The method of claim 10 , wherein the at least one intermediate container comprises a second container configured for communicative coupling with the VCN.

13. The method of claim 12 , wherein the second container comprises a connection manager (“CMAN”) container configured to serve as a proxy server to redirect packets received by the CMAN container from the VCN to the on-premise network.

14. The method of claim 12 , wherein the first container is communicatively coupled with the second container.

15. The method of claim 14 , further comprising registering the external resource residing as the external endpoint in the VCN.

16. The method of claim 15 , further comprising creating the external resource representation for the external endpoint in the VCN, the creating of the external resource representation comprising creating the VNIC.

17. The method of claim 16 , further comprising creating a private endpoint in the VCN.

18. The method of claim 17 , wherein the private endpoint is communicatively coupled with the external resource via the external resource representation.

19. A system comprising:

memory comprising processor-executable stored instructions; and

a processor configured to execute the stored instructions to:

create a connection between an external resource residing in an on-premise network and at least one intermediate container, the on-premise network comprising a user wallet and the intermediate container comprising a VCN wallet, wherein creating the connection includes authentication with the user wallet and the VCN wallet, and wherein the external resource is registered as an external endpoint in a virtual cloud network (VCN);

transmit a request from an external resource representation residing in the VCN via a virtual network interface card (VNIC) to the external resource;

receive at the at least one intermediate container a result corresponding to the request via the created connection; and

transmit, by the at least one intermediate container, the result to the external resource representation via the VNIC using the created connection.

20. A non-transitory computer-readable storage medium storing a plurality of instructions executable by one or more processors, the plurality of instructions when executed by the one or more processors cause the one or more processors to:

create a connection between an external resource residing in an on-premise network and at least one intermediate container, the on-premise network comprising a user wallet and the intermediate container comprising a VCN wallet, wherein creating the connection includes authentication with the user wallet and the VCN wallet, and wherein the external resource is registered as an external endpoint in a virtual cloud network (VCN);

transmit a request from an external resource representation residing in the VCN via a virtual network interface card (VNIC) to the external resource;

receive at the at least one intermediate container a result corresponding to the request via the created connection; and

transmit, by the at least one intermediate container, the result to the external resource representation via the VNIC using the created connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2024
From: SHETYE, SHRUTI NITIN; KAILASA, SOUMYA; REYES, JESUS VELAZQUEZ; KREGER-STICKLES, LUCAS MICHAEL; KARKERA, ABHIMAN YASHPALA; SHAH, DHWANISH PRAMTHESH; PEI, GUANHONG; MAGOUYRK, CLAYTON MATTHEW; CAINKAR, PAUL JAMES
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067393/0343 →
Continuity (8)
Continuation In Part 18373698 · Sep 27, 2023
Continuation 18078897 · Dec 9, 2022
Continuation 17515093 · Oct 29, 2021
Provisional Application 63457695 · Apr 6, 2023
Provisional Application 63457700 · Apr 6, 2023
Provisional Application 63434879 · Dec 22, 2022
Provisional Application 63434846 · Dec 22, 2022
Related Publication 20240195681A1 · Jun 13, 2024
References Cited (89)
US 6304974B1 · Samar · 2001 [cited by applicant]
US 10469461B1 · Singh et al. · 2019 [cited by applicant]
US 10777505B2 · Chang et al. · 2020 [cited by applicant]
US 10785158B1 · Chen · 2020 [cited by examiner]
US 11372689B1 · Allen · 2022 [cited by applicant]
US 11558245B1 · Kreger-Stickles et al. · 2023 [cited by applicant]
US 11736558B2 · Kreger-Stickles et al. · 2023 [cited by applicant]
US 11777848B2 · Tracy et al. · 2023 [cited by applicant]
US 11811593B2 · Kreger-Stickles et al. · 2023 [cited by applicant]
US 11968078B2 · Tessmer et al. · 2024 [cited by applicant]
US 12355664B2 · Tracy et al. · 2025 [cited by applicant]
US 20120005521A1 · Droux et al. · 2012 [cited by applicant]
US 20120124660A1 · Wang · 2012 [cited by examiner]
US 20140168453A1 · Shoemake · 2014 [cited by examiner]
US 20140207930A1 · Benny · 2014 [cited by applicant]
US 20150301844A1 · Droux et al. · 2015 [cited by applicant]
US 20180006877A1 · Raman · 2018 [cited by examiner]
US 20180062920A1 · Srinivasan et al. · 2018 [cited by applicant]
US 20180183756A1 · Bangalore Krishnamurthy · 2018 [cited by applicant]
US 20180284985A1 · Bansal et al. · 2018 [cited by applicant]
US 20180287938A1 · Han · 2018 [cited by applicant]
US 20180349163A1 · Gao et al. · 2018 [cited by applicant]
US 20190036868A1 · Chandrashekhar et al. · 2019 [cited by applicant]
US 20190102384A1 · Hung et al. · 2019 [cited by applicant]
US 20190265996A1 · Shevade et al. · 2019 [cited by applicant]
US 20190347406A1 · Lev-Ran · 2019 [cited by applicant]
US 20190392150A1 · Shevade et al. · 2019 [cited by applicant]
US 20200167175A1 · Tsirkin · 2020 [cited by applicant]
US 20200334241A1 · Muralidhar · 2020 [cited by examiner]
US 20200334242A1 · Muralidhar · 2020 [cited by examiner]
US 20200382471A1 · Janakiraman · 2020 [cited by examiner]
US 20200409873A1 · Kamath et al. · 2020 [cited by applicant]
US 20200410820A1 · Ellis et al. · 2020 [cited by applicant]
US 20210374693A1 · La Salle · 2021 [cited by applicant]
US 20220263793A1 · Baker et al. · 2022 [cited by applicant]
US 20220335764A1 · Imanuel · 2022 [cited by examiner]
US 20220342718A1 · Iqbal et al. · 2022 [cited by applicant]
US 20240020373A1 · Ivanov et al. · 2024 [cited by applicant]
U.S. Appl. No. 18/373,698 , “Non-Final Office Action”, May 8, 2024, 16 pages. [cited by applicant]
International Application No. PCT/US2023/085686 , “International Search Report and Written Opinion”, May 27, 2024, 14 pages. [cited by applicant]
International Application No. PCT/US2023/085695 , “International Search Report and Written Opinion”, May 8, 2024, 14 pages. [cited by applicant]
International Application No. PCT/US2023/034751 , “International Preliminary Report on Patentability”, Feb. 2, 2024, 11 pages. [cited by applicant]
International Application No. PCT/US2023/034753, “International Preliminary Report on Patentability”, Feb. 2, 2024, 12 pages. [cited by applicant]
U.S. Appl. No. 18/051,088, Non-Final Office Action dated Jul. 31, 2024, 15 pages. [cited by applicant]
U.S. Appl. No. 18/373,698, Notice of Allowance dated Aug. 7, 2024, 8 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Advisory Action”, Aug. 4, 2022, 4 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Final Office Action”, Apr. 15, 2022, 22 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Non-Final Office Action”, Sep. 15, 2022, 24 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Non-Final Office Action”, Sep. 27, 2021, 21 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Notice of Allowance”, May 17, 2023, 6 pages. [cited by applicant]
U.S. Appl. No. 17/175,569 , “Supplemental Notice of Allowability”, Aug. 17, 2023, 3 pages. [cited by applicant]
U.S. Appl. No. 17/175,573 , “Corrected Notice of Allowability”, Jul. 26, 2022, 2 pages. [cited by applicant]
U.S. Appl. No. 17/175,573 , “Corrected Notice of Allowability”, Sep. 2, 2022, 2 pages. [cited by applicant]
U.S. Appl. No. 17/175,573 , “Non-Final Office Action”, Mar. 15, 2022, 19 pages. [cited by applicant]
U.S. Appl. No. 17/175,573 , “Notice of Allowance”, Jul. 14, 2022, 9 pages. [cited by applicant]
U.S. Appl. No. 17/515,087 , “Corrected Notice of Allowability”, Jul. 14, 2023, 5 pages. [cited by applicant]
U.S. Appl. No. 17/515,087 , “Final Office Action”, Sep. 19, 2022, 12 pages. [cited by applicant]
U.S. Appl. No. 17/515,087 , “Non-Final Office Action”, Mar. 24, 2022, 10 pages. [cited by applicant]
U.S. Appl. No. 17/515,087 , “Notice of Allowance”, Mar. 17, 2023, 8 pages. [cited by applicant]
U.S. Appl. No. 17/515,093 , “Corrected Notice of Allowability”, Nov. 10, 2022, 4 pages. [cited by applicant]
U.S. Appl. No. 17/515,093 , “Non-Final Office Action”, May 25, 2022, 21 pages. [cited by applicant]
U.S. Appl. No. 17/515,093 , “Notice of Allowance”, Sep. 21, 2022, 7 pages. [cited by applicant]
U.S. Appl. No. 18/051,088 , “Final Office Action”, Jan. 17, 2024, 18 pages. [cited by applicant]
U.S. Appl. No. 18/051,088 , “Non-Final Office Action”, Sep. 20, 2023, 16 pages. [cited by applicant]
U.S. Appl. No. 18/078,897 , “Corrected Notice of Allowability”, Aug. 10, 2023, 6 pages. [cited by applicant]
U.S. Appl. No. 18/078,897 , “Non-Final Office Action”, Apr. 11, 2023, 12 pages. [cited by applicant]
U.S. Appl. No. 18/078,897 , “Notice of Allowance”, Jul. 26, 2023, 7 pages. [cited by applicant]
Bari , et al., “Data Center Network Virtualization: A Survey”, Institute of Electrical and Electronics Engineers Communications Surveys & Tutorials, vol. 15, No. 2, Jan. 2013, pp. 909-928. [cited by applicant]
Eisenbud , et al., “Maglev: A Fast and Reliable Software Network Load Balancer”, 13th USENIX Symposium on Networked Systems Design and Implementation, Mar. 2016, 13 pages. [cited by applicant]
Firestone , et al., “Azure Accelerated Networking: SmartNICs in the Public Cloud”, 15th USENIX Symposium on Networked Systems Design and Implementation, Apr. 2018, 14 pages. [cited by applicant]
Li , et al., “A Novel Hardware-Assisted Virtualization Approach for Network Interface Card”, International Conference on Research Challenges in Computer Science, Dec. 28, 2009, pp. 225-228. [cited by applicant]
Liebeherr , et al., “Experimental Evaluation of Address Binding Dissemination in Multi-Substrate Overlay Networks”, Business, Computer Science, Sep. 2011, 8 pages. [cited by applicant]
Luo , et al., “Accelerated Virtual Switching with Programmable NICs for Scalable Data Center Networking”, Proceedings of the Second Association for Computing Machinery SIGCOMM Workshop on Virtualized Infrastructure Syst… [cited by applicant]
Nakajima , et al., “High-Performance vNIC Framework for Hypervisor-Based NFV with Userspace vSwitch”, Fourth European Workshop on Software Defined Networks, IEEE, 2015, pp. 43-48. [cited by applicant]
International Application No. PCT/US2022/034751 , “International Search Report and Written Opinion”, Sep. 23, 2022, 13 pages. [cited by applicant]
International Application No. PCT/US2022/034751 , “Written Opinion”, Aug. 8, 2023, 10 pages. [cited by applicant]
International Application No. PCT/US2022/034753 , “International Search Report and Written Opinion”, Sep. 23, 2022, 13 pages. [cited by applicant]
International Application No. PCT/US2022/034753 , “Written Opinion”, Aug. 30, 2023, 22 pages. [cited by applicant]
Wang , et al., “Expeditus: Congestion-Aware Load Balancing in Clos Data Center Networks”, Institute of Electrical and Electronics Engineers/Association for Computing Machinery Transactions on Networking, vol. 25, No. 5,… [cited by applicant]
U.S. Appl. No. 18/051,088, Notice of Allowance, Mailed On Mar. 14, 2025, 9 pages. [cited by applicant]
U.S. Appl. No. 18/233,779, Non-Final Office Action, Mailed On Feb. 12, 2025, 19 pages. [cited by applicant]
U.S. Appl. No. 18/393,454, Non-Final Office Action, Mailed On Dec. 2, 2024, 35 pages. [cited by applicant]
U.S. Appl. No. 18/051,088, “Corrected Notice of Allowability”, May 28, 2025, 2 pages. [cited by applicant]
U.S. Appl. No. 18/233,779, Non-Final Office Action, Mailed On May 28, 2025, 23 pages. [cited by applicant]
U.S. Appl. No. 18/393,454, Final Office Action mailed Jul. 1, 2025, 9 pages. [cited by applicant]
International Application No. PCT/US2023/085686, International Preliminary Report on Patentability mailed Jul. 3, 2025, 11 pages. [cited by applicant]
International Application No. PCT/US2023/085695, International Preliminary Report on Patentability mailed Jul. 3, 2025, 11 pages. [cited by applicant]
Indian Application No. 202447022236, First Examination Report mailed Jul. 9, 2025, 11 pages. [cited by applicant]
Indian Application No. 202447024560, First Examination Report mailed Jul. 9, 2025, 9 pages. [cited by applicant]
Cited By (1)
US 12,500,811