IP Library › Granted Patent US 12,323,308
Granted Patent B2
US 12,323,308 · App. 18/478,166 · Granted Jun 3, 2025

Service level enforcement in distributed system using data package injection

Inventors: Dharmesh M. Patel (Round Rock, TX); John A. Lockman, III (Granite Shoals, TX)
Assignee: Dell Products L.P.
H04L41/5025H04L41/04H04L41/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,308
App. No.
18/478,166
Granted
Jun 3, 2025
Kind
B2
Abstract

Methods and systems for managing the operation of a deployment are provided. The deployment may be managed in accordance with a subscription model. The subscription model may use subscriptions to define the extent and limits on use of services provided by the deployment. The subscription services and limits may be enforced by management controllers of network devices of the deployment. The management controllers may operate independently from control planes and data planes of the network devices. If a plane is suspected of being compromised, the management controllers may take action to confirm the suspicions. If confirmed, then remedial activity may be initiated to address the compromised control plane.

Claims (62)

1. A method of managing operation of a distributed system, the method comprising:

making, by a management controller of a first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

measuring, by the management controller and based on the subscription, a level of network service provided by the first network device that is governed by the subscription;

making a first determination regarding whether the level of network service is commensurate with the subscription;

in a first instance of the first determination where the level of network service is not commensurate with the subscription:

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of extra network data units based on the network data package to obtain an updated data plane; and

providing, by the first network device, network data unit processing services using the updated data plane.

2. The method of claim 1 , further comprising:

making a second determination regarding whether the level of network service provided by the updated data plane is commensurate with the subscription; and

in a first instance of the second determination where the level of network service provided by the updated data plane is commensurate with the subscription:

while providing the network data unit processing services:

dynamically adjusting, by the management controller, the network data package to retain the level of network service provided by the updated data plane.

3. The method of claim 1 , wherein the extra network data units are transmitted, at least in part, while the network data unit processing services are provided.

4. The method of claim 3 , wherein providing the network data unit processing services comprises:

obtaining, by the data plane, inbound network data units from other network devices of the distributed system; and

forwarding, by the data plane, the inbound network data units toward destinations.

5. The method of claim 4 , wherein the subscription specifies a network data units processing rate for the first network device, and content of the network data package is selected to consume a quantity of network data unit processing capacity of the data plane to prevent the data plane from processing the inbound network data units at a rate that exceeds the network data unit processing rate specified by the subscription.

6. The method of claim 4 , wherein the subscription specifies a network data units processing latency for the first network device, and content of the network data package is selected to consume a quantity of network data unit processing capacity of the data plane to prevent the data plane from processing the inbound network data units at a latency that is superior to the latency specified by the subscription.

7. The method of claim 1 , wherein the management controller comprises a data processing system, the control plane is hosted by computing resources of the first network device, and the data processing system operates independently from the computing resources.

8. The method of claim 7 , wherein the management controller is operably connected to the computing resources via a first management channel, and the first management channel being usable by the management controller to configure the computing resources.

9. The method of claim 8 , wherein the data plane is hosted by a special purposes hardware device operably connected to in-band links through which network traffic is obtained and forwarded on to other devices, and the management controller is operably connected to at least one other device via an out-of-band link.

10. The method of claim 9 , wherein the management controller is operably connected to the special purpose hardware device via a second management channel, and the second management channel being usable by the management controller to configure the special purpose hardware device.

11. The method of claim 10 , wherein the special purpose hardware device comprises a switch application specific integrated circuit adapted to forward network traffic.

12. The method of claim 1 , wherein the subscription is for a level of service to be provided by the first network device to a subscribing entity.

13. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause a network device to perform operations for managing operation of a distributed system, the operations comprising:

making, by a management controller of a first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

measuring, by the management controller and based on the subscription, a level of network service provided by the first network device that is governed by the subscription;

making a first determination regarding whether the level of network service is commensurate with the subscription;

in a first instance of the first determination where the level of network service is not commensurate with the subscription:

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of extra network data units based on the network data package to obtain an updated data plane; and

providing, by the first network device, network data unit processing services using the updated data plane.

14. The non-transitory machine-readable medium of claim 13 , wherein the operations further comprise

making a second determination regarding whether the level of network service provided by the updated data plane is commensurate with the subscription; and

in a first instance of the second determination where the level of network service provided by the updated data plane is commensurate with the subscription:

while providing the network data unit processing services:

dynamically adjusting, by the management controller, the network data package to retain the level of network service provided by the updated data plane.

15. The non-transitory machine-readable medium of claim 13 , wherein the extra network data units are transmitted, at least in part, while the network data unit processing services are provided.

16. The non-transitory machine-readable medium of claim 14 , wherein providing the network data unit processing services comprises:

obtaining, by the data plane, inbound network data units from other network devices of the distributed system; and

forwarding, by the data plane, the inbound network data units toward destinations.

17. The non-transitory machine-readable medium of claim 16 , wherein the subscription specifies a network data units processing rate for the first network device, and content of the network data package is selected to consume a quantity of network data unit processing capacity of the data plane to prevent the data plane from processing the inbound network data units at a rate that exceeds the network data unit processing rate specified by the subscription.

18. The non-transitory machine-readable medium of claim 16 , wherein the subscription specifies a network data units processing latency for the first network device, and content of the network data package is selected to consume a quantity of network data unit processing capacity of the data plane to prevent the data plane from processing the inbound network data units at a latency that is superior to the latency specified by the subscription.

19. A first network device, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the first network device to perform operations for managing operation of a distributed system, the operations comprising:

making, by a management controller of a first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

measuring, by the management controller and based on the subscription, a level of network service provided by the first network device that is governed by the subscription;

making a first determination regarding whether the level of network service is commensurate with the subscription;

in a first instance of the first determination where the level of network service is not commensurate with the subscription:

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of extra network data units based on the network data package to obtain an updated data plane; and

providing, by the first network device, network data unit processing services using the updated data plane.

20. The first network device of claim 19 , wherein the operations further comprise

making a second determination regarding whether the level of network service provided by the updated data plane is commensurate with the subscription;

in a first instance of the second determination where the level of network service provided by the updated data plane is commensurate with the subscription:

while providing the network data unit processing services:

dynamically adjusting, by the management controller, the network data package to retain the level of network service provided by the updated data plane.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2023
From: PATEL, DHARMESH M.; LOCKMAN, JOHN A., III
To: DELL PRODUCTS L.P.
Reel/Frame 065134/0394 →
Continuity (1)
Related Publication 20250112838A1 · Apr 3, 2025
References Cited (24)
US 7890612B2 · Todd · 2011 [cited by examiner]
US 8189486B2 · Krishnaswamy · 2012 [cited by applicant]
US 8696765B2 · Mendez · 2014 [cited by examiner]
US 8850507B2 · Reisman · 2014 [cited by applicant]
US 9294386B2 · Narad · 2016 [cited by applicant]
US 9354126B2 · Chainer et al. · 2016 [cited by applicant]
US 9534967B2 · Chainer et al. · 2017 [cited by applicant]
US 10652038B2 · Juneau · 2020 [cited by examiner]
US 11095558B2 · Cheng et al. · 2021 [cited by applicant]
US 11630747B1 · Deboy · 2023 [cited by applicant]
US 11962506B2 · Rangel Augusto · 2024 [cited by applicant]
US 20070143827A1 · Nicodemus · 2007 [cited by applicant]
US 20120114331A1 · Kamijo et al. · 2012 [cited by applicant]
US 20160328349A1 · Kunnathur Ragupathi · 2016 [cited by applicant]
US 20180359134A1 · Pech · 2018 [cited by examiner]
US 20200014583A1 · Dang · 2020 [cited by applicant]
US 20200403889A1 · Nguyen · 2020 [cited by examiner]
US 20210117249A1 · Doshi et al. · 2021 [cited by applicant]
US 20230267198A1 · Karpovsky · 2023 [cited by examiner]
US 20240205226A1 · Lukyanov · 2024 [cited by applicant]
“Management vs. Control vs. Data Planes in a Network Device,” Codilime, Dec. 22, 2022, Web Page <https://codilime.com/blog/management-plane-vs-control-plane-vs-data-plane/> accessed on Sep. 28, 2023 (8 Pages). [cited by applicant]
“Control Plane Policing,” Cisco Systems, Inc., Nov. 2006 (36 Pages). [cited by applicant]
Strickx, Tom, “ASICs at the Edge,” The Cloudflare Blog, Nov. 27, 2020, web page <https://blog.cloudflare.com/asics-at-the-edge/> accessed on Sep. 28, 2023 (22 Pages). [cited by applicant]
Cotroneo, Domenico, et al., “Overload control for virtual network functions under CPU contention,” Future Generation Computer Systems 99 (2019): 164-176 (13 Pages). [cited by applicant]