IP Library Granted Patent US 12,294,471
Granted Patent B2
US 12,294,471 · App. 18/434,031 · Granted May 6, 2025

Network layer performance and security provided by a distributed cloud computing network

Inventors: Nicholas Alexander Wondra (Savoy, IL); Achiel Paul van der Mandele (Austin, TX); Alexander Forster (Austin, TX); Eric Reeves (Austin, TX); Joaquin Madruga (Austin, TX); Rustam Xing Lalkaka (San Francisco, CA); Marek Przemyslaw Majkowski (Warsaw, PL)
Assignee: CLOUDFLARE, INC.
H04L12/4633H04L2101/618
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,294,471
App. No.
18/434,031
Granted
May 6, 2025
Kind
B2
Abstract

A first computing device of a distributed cloud computing network receives an IP packet that is destined to an origin server of an origin network. The first computing device processes the received IP packet and encapsulates the IP packet inside an outer packet to generate an encapsulated packet, where the outer packet has a source IP address that is advertised as an anycast IP address at the distributed cloud computing network, and a destination IP address of an origin router of the origin network. The encapsulated packet is transmitted to the origin router.

Claims (107)

1. A method in a distributed cloud computing network that includes a plurality of computing devices, the method comprising:

receiving a first IP packet at a first one of the plurality of computing devices of the distributed cloud computing network, wherein the received first IP packet is destined to a first origin server of a first origin network;

processing the received first IP packet at the first computing device;

encapsulating the processed first IP packet inside a first outer packet to generate a first encapsulated packet, wherein the first outer packet has a source IP address that is advertised as a first anycast IP address at the distributed cloud computing network, and wherein the first outer packet has a first destination IP address of a first origin router of the first origin network; and

transmitting the first encapsulated packet to the destination IP address of the first origin router.

2. The method of claim 1 , wherein processing the received first IP packet at the first computing device includes performing a distributed denial of service (DDoS) mitigation on the first IP packet.

3. The method of claim 1 , wherein the received first IP packet has a second destination IP address that is a second anycast IP address that is advertised at the distributed cloud computing network.

4. The method of claim 3 , further comprising:

wherein the first IP packet is received from a first client device;

wherein the second anycast IP address is advertised by each of the plurality of computing devices of the distributed cloud computing network;

receiving, at a second one of the plurality of computing devices, a second encapsulated packet from the first origin router in response to the transmitted first encapsulated packet, the second encapsulated packet having been directed to the second anycast IP address;

processing, at the second computing device, the second encapsulated packet including decapsulating the second encapsulated packet to reveal a second IP packet; and

transmitting, by the second computing device, the second IP packet to the first client device.

5. The method of claim 3 , further comprising:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

encapsulating the processed second IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a third IP packet; and

determining, using a probability map based on an IP address of the second client device, that an ingress for a packet flow of the third IP packet is the first computing device, and responsive to this determining, transmitting the third IP packet from the second computing device to the first computing device;

processing, at the first computing device, the third IP packet; and

transmitting, by the first computing device, the third IP packet to the second client device.

6. The method of claim 3 , further comprising:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

modifying the processed second IP packet by changing its source IP address to an IP address of the first computing device to create a modified third IP packet;

encapsulating the modified third IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a fourth IP packet;

transmitting the fourth IP packet from the second computing device to the first computing device;

processing, at the first computing device, the fourth IP packet; and

transmitting, by the first computing device, the fourth IP packet to the second client device.

7. The method of claim 6 , wherein processing the received second IP packet and processing the fourth IP packet include performing layer 4 and/or layer 7 processing.

8. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving a first IP packet at a first one of a plurality of computing devices of a distributed cloud computing network, wherein the received first IP packet is destined to a first origin server of a first origin network;

processing the received first IP packet at the first computing device;

encapsulating the processed first IP packet inside a first outer packet to generate a first encapsulated packet, wherein the first outer packet has a source IP address that is advertised as a first anycast IP address at the distributed cloud computing network, and wherein the first outer packet has a first destination IP address of a first origin router of the first origin network; and

transmitting the first encapsulated packet to the destination IP address of the first origin router.

9. The non-transitory machine-readable storage medium of claim 8 , wherein processing the received first IP packet at the first computing device includes performing a distributed denial of service (DDoS) mitigation on the first IP packet.

10. The non-transitory machine-readable storage medium of claim 8 , wherein the received first IP packet has a second destination IP address that is a second anycast IP address that is advertised at the distributed cloud computing network.

11. The non-transitory machine-readable storage medium of claim 10 , wherein the operations further comprise:

wherein the first IP packet is received from a first client device;

wherein the second anycast IP address is advertised by each of the plurality of computing devices of the distributed cloud computing network;

receiving, at a second one of the plurality of computing devices, a second encapsulated packet from the first origin router in response to the transmitted first encapsulated packet, the second encapsulated packet having been directed to the second anycast IP address;

processing, at the second computing device, the second encapsulated packet including decapsulating the second encapsulated packet to reveal a second IP packet; and

transmitting, by the second computing device, the second IP packet to the first client device.

12. The non-transitory machine-readable storage medium of claim 10 , wherein the operations further comprise:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

encapsulating the processed second IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a third IP packet; and

determining, using a probability map based on an IP address of the second client device, that an ingress for a packet flow of the third IP packet is the first computing device, and responsive to this determining, transmitting the third IP packet from the second computing device to the first computing device;

processing, at the first computing device, the third IP packet; and

transmitting, by the first computing device, the third IP packet to the second client device.

13. The non-transitory machine-readable storage medium of claim 10 , wherein the operations further comprise:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

modifying the processed second IP packet by changing its source IP address to an IP address of the first computing device to create a modified third IP packet;

encapsulating the modified third IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a fourth IP packet;

transmitting the fourth IP packet from the second computing device to the first computing device;

processing, at the first computing device, the fourth IP packet; and

transmitting, by the first computing device, the fourth IP packet to the second client device.

14. The non-transitory machine-readable storage medium of claim 13 , wherein processing the received second IP packet and processing the fourth IP packet include performing layer 4 and/or layer 7 processing.

15. A first computing device of a plurality of computing devices of a distributed cloud computing network, the first computing device comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the processor, causes the first computing device to perform operations comprising:

receiving a first IP packet at first computing device, wherein the received first IP packet is destined to a first origin server of a first origin network;

processing the received first IP packet at the first computing device,

encapsulating the processed first IP packet inside a first outer packet to generate a first encapsulated packet, wherein the first outer packet has a source IP address that is advertised as a first anycast IP address at the distributed cloud computing network, and wherein the first outer packet has a first destination IP address of a first origin router of the first origin network, and

transmitting the first encapsulated packet to the destination IP address of the first origin router.

16. The first computing device of claim 15 , wherein processing the received first IP packet at the first computing device includes performing a distributed denial of service (DDoS) mitigation on the first IP packet.

17. The first computing device of claim 15 , wherein the received first IP packet has a second destination IP address that is a second anycast IP address that is advertised at the distributed cloud computing network.

18. The first computing device of claim 17 , wherein the operations further comprise:

wherein the first IP packet is received from a first client device;

wherein the second anycast IP address is advertised by each of the computing devices of the distributed cloud computing network;

receiving, at a second one of the plurality of computing devices, a second encapsulated packet from the first origin router in response to the transmitted first encapsulated packet, the second encapsulated packet having been directed to the second anycast IP address;

processing, at the second computing device, the second encapsulated packet including decapsulating the second encapsulated packet to reveal a second IP packet; and

transmitting, by the second computing device, the second IP packet to the first client device.

19. The first computing device of claim 17 , wherein the operations further comprise:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

encapsulating the processed second IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a third IP packet; and

determining, using a probability map based on an IP address of the second client device, that an ingress for a packet flow of the third IP packet is the first computing device, and responsive to this determining, transmitting the third IP packet from the second computing device to the first computing device;

processing, at the first computing device, the third IP packet; and

transmitting, by the first computing device, the third IP packet to the second client device.

20. The first computing device of claim 17 , wherein the operations further comprise:

receiving, from a second client device, a second IP packet at the first computing device, wherein the received second IP packet is destined to a second origin server of a second origin network;

processing the received second IP packet at the first computing device;

modifying the processed second IP packet by changing its source IP address to an IP address of the first computing device to create a modified third IP packet;

encapsulating the modified third IP packet inside a second outer packet to generate a second encapsulated packet, wherein the second outer packet has a source IP address that is advertised as a third anycast IP address at the distributed cloud computing network, and wherein the second outer packet has a third destination IP address of a second origin router of the second origin network;

transmitting the second encapsulated packet to the destination IP address of the second origin router for the second origin network;

receiving, at a second one of the plurality of computing devices, a third encapsulated packet from the second origin router in response to the transmitted second encapsulated packet, the third encapsulated packet being directed to the third anycast IP address;

processing, at the second computing device, the third encapsulated packet including decapsulating the third encapsulated packet to reveal a fourth IP packet;

transmitting the fourth IP packet from the second computing device to the first computing device;

processing, at the first computing device, the fourth IP packet; and

transmitting, by the first computing device, the fourth IP packet to the second client device.

21. The first computing device of claim 20 , wherein processing the received second IP packet and processing the fourth IP packet include performing layer 4 and/or layer 7 processing.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: WONDRA, NICHOLAS ALEXANDER; VAN DER MANDELE, ACHIEL PAUL; FORSTER, ALEXANDER; REEVES, ERIC; MADRUGA, JOAQUIN; LALKAKA, RUSTAM XING; MAJKOWSKI, MAREK PRZEMYSLAW
To: CLOUDFLARE, INC.
Reel/Frame 066432/0780 →
Continuity (5)
Continuation 18067713 · Dec 18, 2022
Continuation 17481177 · Sep 21, 2021
Continuation 16993181 · Aug 13, 2020
Provisional Application 62886314 · Aug 13, 2019
Related Publication 20240179026A1 · May 30, 2024
References Cited (31)
US 6779051B1 · Basil et al. · 2004 [cited by applicant]
US 8259571B1 · Raphel · 2012 [cited by examiner]
US 8955112B2 · Nguyen et al. · 2015 [cited by applicant]
US 9450981B2 · Doron et al. · 2016 [cited by applicant]
US 10341379B2 · George et al. · 2019 [cited by applicant]
US 10574691B2 · Shapira et al. · 2020 [cited by applicant]
US 10979402B1 · Hartley · 2021 [cited by examiner]
US 20070153782A1 · Fletcher et al. · 2007 [cited by applicant]
US 20150350069A1 · Padgett et al. · 2015 [cited by applicant]
US 20160094621A1 · Wolfe · 2016 [cited by examiner]
US 20160127148A1 · Xue et al. · 2016 [cited by applicant]
US 20170019428A1 · Cohn · 2017 [cited by examiner]
US 20170366577A1 · Shapira · 2017 [cited by examiner]
US 20180159723A1 · Rao · 2018 [cited by applicant]
US 20180375760A1 · Saavedra · 2018 [cited by applicant]
US 20190132150A1 · Ramachandran · 2019 [cited by examiner]
US 20190173860A1 · Sankaran · 2019 [cited by examiner]
US 20190268247A1 · Bristow · 2019 [cited by examiner]
US 20190288941A1 · Filsfils et al. · 2019 [cited by applicant]
US 20190319871A1 · Indiresan · 2019 [cited by examiner]
US 20200036624A1 · Michael et al. · 2020 [cited by applicant]
US 20200344147A1 · Pianigiani et al. · 2020 [cited by applicant]
US 20200344205A1 · Majkowski · 2020 [cited by examiner]
US 20200412576A1 · Kondapavuluru · 2020 [cited by examiner]
WO 2015003391A1 · 2015 [cited by applicant]
WO WO2015003348A1 · 2015 [cited by examiner]
Non-Final Office Action, U.S. App. No. 17/481,177, Apr. 4, 2022, 19 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/067,713, Jul. 24, 2023, 32 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/993,181, May 18, 2021, 24 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/481,177, Aug. 17, 2022, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/067,713, Nov. 9, 2023, 9 pages. [cited by applicant]