IP Library Granted Patent US 12,695,701
Granted Patent B2
US 12,695,701 · App. 18/478,515 · Granted Jul 28, 2026

Configuring service load balancers with specified backend virtual networks

Inventors: Yuvaraja Mariappan (San Jose, CA); Sachchidanand Vaidya (Santa Clara, CA); Pragash Vijayaragavan (Sunnyvale, CA); Prasanna D. Mucharikar (Fremont, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L47/125G06F9/45558G06F9/5077H04L61/5007G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,701
App. No.
18/478,515
Granted
Jul 28, 2026
Kind
B2
Abstract

Techniques are described for specifying a backend virtual network for a service load balancer. An example orchestrator of this disclosure is configured to receive a service definition for a service implemented by load balancing service traffic for the service among a plurality of backend virtual execution elements, wherein the service definition specifies a first virtual network to use as a backend virtual network for the service, to instantiate, in a selected one of the computing devices, a backend virtual execution element for the service, and to configure, based on the service definition specifying the first virtual network to use as the backend virtual network for the service, a network controller for the virtualized computing infrastructure to configure a load balancer to load balance service traffic to a first virtual network interface, of the backend virtual element, for the first virtual network.

Claims (60)

1 . A system comprising processing circuitry having access to memory, the system configured to:

receive a service definition for a service that implements a load balancer for load balancing service traffic among a plurality of backend virtual execution elements, wherein the service definition includes an identifier of a backend virtual network, the backend virtual network comprising one of a plurality of virtual networks implemented on a physical network;

identify, based on the identifier of the backend virtual network, a virtual network interface of a virtual execution element; and

expose, based on the virtual network interface of the virtual execution element, the virtual execution element to the service that implements the load balancer for load balancing the service traffic to cause the load balancer to load balance the service traffic in part to the virtual network interface of the virtual execution element.

2 . The system of claim 1 , wherein the system is configured to:

create a load balancer member object, of the load balancer, the load balancer member object corresponding to the virtual execution element; and

annotate the load balancer member object with an annotation to specify the virtual network interface of the virtual execution element.

3 . The system of claim 2 , wherein, to expose the virtual execution element, the system is configured to:

generate a configuration update by linking a service Internet Protocol (IP) address for the service with the annotation specifying the virtual network interface of the virtual execution element; and

send the configuration update to configure a virtual router with next-hop information to cause the virtual router to load balance the service traffic, sent to the service IP address, in part to the virtual network interface of the virtual execution element.

4 . The system of claim 2 , wherein, the system is configured to, based on the annotation specifying the virtual network interface, configure the load balancer to load balance the service traffic in part to the identified virtual network interface for the backend virtual network.

5 . The system of claim 1 ,

wherein the system is configured to:

allocate a unique Internet Protocol (IP) address for the virtual execution element;

allocate a service IP address for the service; and

configure the virtual network interface of the virtual execution element with the unique IP address,

wherein to expose the virtual execution element to the service the system is configured to configure a virtual router with the service IP address and the unique IP address to cause the virtual router to load balance the service traffic, sent to the service IP address, in part to the virtual execution element.

6 . The system of claim 1 , wherein the system is configured to:

annotate configuration data for the virtual execution element to specify the backend virtual network, and

based on the annotated configuration data for the virtual execution element, send interface configuration data to a computing device that hosts the virtual execution element to configure the virtual execution element of the plurality of backend virtual execution elements with the virtual network interface to enable the virtual execution element to receive service traffic from the load balancer via the backend virtual network.

7 . The system of claim 1 , wherein the system is configured to:

receive a virtual network address for the virtual network interface of the virtual execution element for the backend virtual network; and

configure the load balancer to load balance the service traffic in part to the virtual network address.

8 . The system of claim 1 , wherein the system is configured to:

receive a virtual network address for the virtual network interface of the virtual execution element for the backend virtual network in association with a service Internet Protocol (IP) address for the service; and

configure the load balancer to load balance the service traffic, sent to the service IP address, in part to the virtual network address.

9 . The system of claim 1 ,

wherein the virtual network interface of the virtual execution element for the backend virtual network is a primary interface of the virtual execution element.

10 . The system of claim 1 , wherein the virtual execution element comprises a Kubernetes pod.

11 . The system of claim 10 , wherein the service comprises a Kubernetes service that provides access to the Kubernetes pod via a service Internet Protocol (IP) address assigned to the Kubernetes service.

12 . A method comprising:

receiving, by an orchestrator for a virtualized computing infrastructure, a service definition for a service that implements a load balancer for load balancing service traffic among a plurality of backend virtual execution elements, wherein the service definition includes an identifier of a backend virtual network, the backend virtual network comprising one of a plurality of virtual networks implemented on a physical network;

identifying, by a network controller for the virtualized computing infrastructure and based on the identifier of the backend virtual network, a virtual network interface of a virtual execution element; and

exposing, based on the virtual network interface of the virtual execution element, the virtual execution element to the service that implements the load balancer for load balancing the service traffic to cause the load balancer to load balance the service traffic in part to the virtual network interface of the virtual execution element.

13 . The method of claim 12 , further comprising:

creating, by the orchestrator, a load balancer member object, of the load balancer, the load balancer member object corresponding to the virtual execution element; and

annotating, by the orchestrator, the load balancer member object with an annotation to specify the virtual network interface of the virtual execution element.

14 . The method of claim 13 , wherein exposing the virtual execution element comprises:

generating, by the network controller, a configuration update by linking a service Internet Protocol (IP) address for the service with the annotation specifying the virtual network interface of the virtual execution element; and

sending, by the network controller, the configuration update to configure a virtual router with next-hop information to cause the virtual router to load balance the service traffic, sent to the service IP address, in part to the virtual network interface of the virtual execution element.

15 . The method of claim 12 , further comprising:

allocating a unique Internet Protocol (IP) address for the virtual execution element allocating a service IP address for the service; and

configuring the virtual network interface of the virtual execution element with the unique IP address,

wherein exposing the virtual execution element to the service comprises configuring a virtual router with the service IP address and the unique IP address to cause the virtual router to load balance the service traffic, sent to the service IP address, in part to the virtual execution element.

16 . The method of claim 12 , further comprising:

annotating, by the orchestrator, configuration data for the virtual execution element to specify the backend virtual network; and

sending, based on the annotated configuration data for the virtual execution element, the interface configuration data to a computing device that hosts the virtual execution element to configure the virtual execution element to configure the virtual execution element of the plurality of backend virtual execution elements with the virtual network interface to enable the virtual execution element to receive service traffic from the load balancer via the backend virtual network.

17 . The method of claim 12 , further comprising:

receiving a virtual network address for the virtual network interface of the virtual execution element for the backend virtual network; and

configuring the load balancer to load balance the service traffic in part to the virtual network address.

18 . Non-transitory computer-readable media comprising instructions for causing one or more programmable processors to:

receive a service definition for a service that implements a load balancer for load balancing service traffic among a plurality of backend virtual execution elements, wherein the service definition includes an identifier of a backend virtual network, the backend virtual network comprising one of a plurality of virtual networks implemented on a physical network;

identify, based on the identifier of the backend virtual network, a virtual network interface of a virtual execution element; and

expose, based on the virtual network interface of the virtual execution element, the virtual execution element to the service that implements the load balancer for load balancing the service traffic to cause the load balancer to load balance the service traffic in part to the virtual network interface of the virtual execution element.

19 . The non-transitory computer-readable medium of claim 18 , wherein the instructions further cause the one or more programmable processors to:

create a load balancer member object, of the load balancer, the load balancer member object corresponding to the virtual execution element; and

annotate the load balancer member object with an annotation to specify the virtual network interface of the virtual execution element.

20 . The non-transitory computer-readable medium of claim 19 , wherein, to expose the virtual execution element, the instructions cause the one or more programmable processors to:

generate a configuration update by linking a service Internet Protocol (IP) address for the service with the annotation specifying the virtual network interface of the virtual execution element; and

send the configuration update to configure a virtual router with next-hop information to cause the virtual router to load balance the service traffic, sent to the service IP address, in part to the virtual network interface of the virtual execution element.

Assignments (1)
NUNC PRO TUNC ASSIGNMENT Recorded May 6, 2026
From: JUNIPER NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 075513/0034 →
Continuity (3)
Continuation 16949684 · Nov 10, 2020
Continuation 16369169 · Mar 29, 2019
Related Publication 20240048492A1 · Feb 8, 2024
References Cited (176)
US 6115715A · Traversat et al. · 2000 [cited by applicant]
US 6351751B1 · Traversat et al. · 2002 [cited by applicant]
US 7227838B1 · O'Riordan · 2007 [cited by applicant]
US 7436840B1 · Hoffman et al. · 2008 [cited by applicant]
US 7460526B1 · Hoffman et al. · 2008 [cited by applicant]
US 7539135B1 · Hoffman et al. · 2009 [cited by applicant]
US 8427943B2 · Gahm · 2013 [cited by examiner]
US 8442048B2 · Aybay et al. · 2013 [cited by applicant]
US 9043792B1 · Xu · 2015 [cited by applicant]
US 9276816B1 · Conte · 2016 [cited by examiner]
US 9571394B1 · Sivaramakrishnan et al. · 2017 [cited by applicant]
US 9602422B2 · Yip et al. · 2017 [cited by applicant]
US 9686158B1 · Krueger · 2017 [cited by examiner]
US 9712436B2 · Tsirkin et al. · 2017 [cited by applicant]
US 9722877B2 · Uberoy et al. · 2017 [cited by applicant]
US 9736231B1 · Abrams · 2017 [cited by examiner]
US 9792141B1 · Sethuramalingam et al. · 2017 [cited by applicant]
US 9935829B1 · Miller et al. · 2018 [cited by applicant]
US 9979602B1 · Chinnakannan et al. · 2018 [cited by applicant]
US 10021196B1 · Akers · 2018 [cited by examiner]
US 10121009B2 · Kuhr et al. · 2018 [cited by applicant]
US 10148493B1 · Ennis, Jr. et al. · 2018 [cited by applicant]
US 10203972B2 · Koganty et al. · 2019 [cited by applicant]
US 10237176B2 · Mutnuru et al. · 2019 [cited by applicant]
US 10243919B1 · Suresh et al. · 2019 [cited by applicant]
US 10250677B1 · Aizikovich · 2019 [cited by applicant]
US 10263789B1 · Popoveniuc · 2019 [cited by examiner]
US 10326762B2 · Fitzgerald · 2019 [cited by examiner]
US 10355989B1 · Panchal et al. · 2019 [cited by applicant]
US 10419361B2 · Zhu et al. · 2019 [cited by applicant]
US 10530845B1 · Golden · 2020 [cited by examiner]
US 10608881B2 · Teng · 2020 [cited by examiner]
US 10728145B2 · Rao et al. · 2020 [cited by applicant]
US 10812366B1 · Berenberg · 2020 [cited by examiner]
US 10841226B2 · Mariappan et al. · 2020 [cited by applicant]
US 10951651B1 · Golan · 2021 [cited by examiner]
US 11055273B1 · Meduri · 2021 [cited by examiner]
US 11113090B1 · Wilkinson · 2021 [cited by examiner]
US 11159366B1 · Gawade · 2021 [cited by examiner]
US 11223565B2 · Buddhikot · 2022 [cited by examiner]
US 11467881B2 · Thyagarajan · 2022 [cited by examiner]
US 11513828B1 · Zelenov · 2022 [cited by examiner]
US 11792126B2 · Mariappan · 2023 [cited by examiner]
US 11928514B2 · Mestery · 2024 [cited by examiner]
US 12034740B1 · Carmack · 2024 [cited by examiner]
US 20040165581A1 · Oogushi · 2004 [cited by applicant]
US 20040210623A1 · Hydrie et al. · 2004 [cited by applicant]
US 20070288921A1 · King et al. · 2007 [cited by applicant]
US 20080151893A1 · Nordmark et al. · 2008 [cited by applicant]
US 20110051689A1 · Premec et al. · 2011 [cited by applicant]
US 20110067107A1 · Weeks et al. · 2011 [cited by applicant]
US 20110228787A1 · Tamura · 2011 [cited by applicant]
US 20120042054A1 · Kotha et al. · 2012 [cited by applicant]
US 20120170462A1 · Sinha · 2012 [cited by applicant]
US 20120170477A1 · Hieda · 2012 [cited by applicant]
US 20120246637A1 · Kreeger et al. · 2012 [cited by applicant]
US 20120287931A1 · Kidambi et al. · 2012 [cited by applicant]
US 20130263118A1 · Kannan et al. · 2013 [cited by applicant]
US 20140177518A1 · Akisada et al. · 2014 [cited by applicant]
US 20140254565A1 · Pitchaiah et al. · 2014 [cited by applicant]
US 20150067674A1 · Melander et al. · 2015 [cited by applicant]
US 20150222480A1 · Gan et al. · 2015 [cited by applicant]
US 20150244617A1 · Nakil et al. · 2015 [cited by applicant]
US 20150281128A1 · Sindhu · 2015 [cited by applicant]
US 20150339216A1 · Wade · 2015 [cited by applicant]
US 20160092254A1 · Borra · 2016 [cited by examiner]
US 20160094389A1 · Jain et al. · 2016 [cited by applicant]
US 20160182279A1 · Gong et al. · 2016 [cited by applicant]
US 20160261505A1 · Saniee · 2016 [cited by examiner]
US 20160285769A1 · Qiang · 2016 [cited by applicant]
US 20160294643A1 · Kim · 2016 [cited by applicant]
US 20160359955A1 · Gill et al. · 2016 [cited by applicant]
US 20170034050A1 · Sunavala et al. · 2017 [cited by applicant]
US 20170041288A1 · Stotski et al. · 2017 [cited by applicant]
US 20170171145A1 · Hirai · 2017 [cited by examiner]
US 20170244787A1 · Rangasamy et al. · 2017 [cited by applicant]
US 20170289065A1 · Zhu et al. · 2017 [cited by applicant]
US 20180048716A1 · Madhayyan et al. · 2018 [cited by applicant]
US 20180062923A1 · Katrekar et al. · 2018 [cited by applicant]
US 20180063087A1 · Hira et al. · 2018 [cited by applicant]
US 20180063193A1 · Chandrashekhar et al. · 2018 [cited by applicant]
US 20180063201A1 · Zhang et al. · 2018 [cited by applicant]
US 20180063233A1 · Park · 2018 [cited by examiner]
US 20180173569A1 · Yamagami · 2018 [cited by examiner]
US 20180176289A1 · Watanabe · 2018 [cited by examiner]
US 20180191607A1 · Kanakarajan · 2018 [cited by applicant]
US 20180191840A1 · Yamamoto · 2018 [cited by examiner]
US 20180239647A1 · Tsai et al. · 2018 [cited by applicant]
US 20180285169A1 · Noguchi · 2018 [cited by examiner]
US 20180302490A1 · Surcouf et al. · 2018 [cited by applicant]
US 20180324280A1 · Solis et al. · 2018 [cited by applicant]
US 20180375728A1 · Gangil et al. · 2018 [cited by applicant]
US 20190007366A1 · Voegele · 2019 [cited by examiner]
US 20190081955A1 · Chugtu · 2019 [cited by examiner]
US 20190087244A1 · Turner · 2019 [cited by applicant]
US 20190097838A1 · Sahoo et al. · 2019 [cited by applicant]
US 20190102226A1 · Caldato · 2019 [cited by examiner]
US 20190297011A1 · Nainar et al. · 2019 [cited by applicant]
US 20190335004A1 · Yang · 2019 [cited by examiner]
US 20190342266A1 · Ramachandran et al. · 2019 [cited by applicant]
US 20190377604A1 · Cybulski · 2019 [cited by examiner]
US 20200073692A1 · Rao et al. · 2020 [cited by applicant]
US 20200099610A1 · Heron · 2020 [cited by examiner]
US 20200120112A1 · Cybulski · 2020 [cited by examiner]
US 20200153897A1 · Mestery · 2020 [cited by examiner]
US 20200186422A1 · Fildebrandt · 2020 [cited by examiner]
US 20200186600A1 · Dawani · 2020 [cited by examiner]
US 20200241903A1 · Wang · 2020 [cited by applicant]
US 20200250006A1 · Parekh · 2020 [cited by applicant]
US 20200252335A1 · Kelam · 2020 [cited by applicant]
US 20200252376A1 · Feng et al. · 2020 [cited by applicant]
US 20200314015A1 · Mariappan · 2020 [cited by examiner]
US 20200336384A1 · Jha · 2020 [cited by examiner]
US 20210058327A1 · Mariappan et al. · 2021 [cited by applicant]
US 20220116285A1 · Abdollahi Vayghan · 2022 [cited by examiner]
US 20240048492A1 · Mariappan · 2024 [cited by examiner]
US 20250097821A1 · Akkipeddi · 2025 [cited by examiner]
CN 102055667A · 2011 [cited by applicant]
CN 102790716A · 2012 [cited by applicant]
CN 102891868A · 2013 [cited by examiner]
CN 104718723A · 2015 [cited by applicant]
CN 105208053A · 2015 [cited by applicant]
CN 105791147A · 2016 [cited by examiner]
CN 105915583A · 2016 [cited by examiner]
CN 105981330A · 2016 [cited by applicant]
CN 107566440A · 2018 [cited by applicant]
CN 108243055A · 2018 [cited by examiner]
CN 108259216A · 2018 [cited by applicant]
CN 108924268A · 2018 [cited by examiner]
CN 110704155A · 2020 [cited by examiner]
CN 111131414A · 2020 [cited by examiner]
CN 112187671A · 2021 [cited by examiner]
CN 116319711A · 2023 [cited by examiner]
EP 3316532A1 · 2018 [cited by applicant]
EP 3716533A1 · 2020 [cited by examiner]
EP 3367638B1 · 2023 [cited by examiner]
EP 4320843B1 · 2025 [cited by examiner]
KR 20170085072A · 2017 [cited by examiner]
KR 20180024063A · 2018 [cited by applicant]
WO 2013184846A1 · 2013 [cited by applicant]
WO WO2015031866A1 · 2015 [cited by examiner]
WO WO2016101639A1 · 2016 [cited by examiner]
WO WO2018003031A1 · 2018 [cited by examiner]
WO 2018063332A1 · 2018 [cited by applicant]
WO WO2019128240A1 · 2019 [cited by examiner]
WO WO2020152503A1 · 2020 [cited by examiner]
“Configuration of a Virtual Router on a FireSIGHT System,” Cisco, accessed from https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118021-technote-firesight-00.pdf, Jul. 21, 2014, 4 pp. [cited by applicant]
“Kubernetes Network Custom Resource Definition De-facto Standard v1 Support,” OpenStack Docs: Kubernetes Network Custom Resource Definition De-facto Standard v1 Support, https://docs.openstack.org/kuryr-kubernetes/lates… [cited by applicant]
“Kubernetes networking with OpenContrail,” OpenContrail Blog, http://www.opencontrail.org/kubernetes-networking-with-opencontrail/, Jul. 26, 2015, 6 pp. [cited by applicant]
“Multiple Network Interfaces in Kubernetes,” Application Note, Intel Corp., Software Defined Datacenter Solutions Group, Apr. 2018, 15pp. [cited by applicant]
“PCI-SIG SR-IOV Primer: An Introduction to SR-IOV Technology,” Rev. 2.5, Intel Corp., Jan. 2011, 28 pp. [cited by applicant]
Anonymous et al., “Enabling New Features in Kubernetes for NFV”, Jul. 2017, 2 pp., Retrieved from the Internet on Jan. 26, 2023 from URL: https://networkbuilders.intel.com/solutionslibrary/enabling-new-features-in-kuber… [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 19181700.6 dated Apr. 7, 2022, 5 pp. [cited by applicant]
Docker, Inc., “Docker Overview”, Docker Docs, 5 pp., Retrieved from the Internet on Jun. 7, 2022 from URL: https://docs.docker.com/get-started/overview/. [cited by applicant]
Extended Search Report from counterpart European Application No. 19181700.6, dated Jan. 2, 2020, 7 pp. [cited by applicant]
First Office Action and Search Report, and translation thereof, from counterpart Chinese Application No. 201910905709.9, dated May 8, 2021, 11 pp. [cited by applicant]
Lowe, “Introducing Linux Network Namespaces,” Scott's Weblog the weblog of an IT pro focusing on cloud computing, Kubernetes, Linux, containers, and networking, Sep. 4, 2013, 4 pp. [cited by applicant]
Mackie et. al., “BGP-Signaled End-System IP/VPNs,” draft-ietf-l3vpn-end-system-06, Network Working Group, Dec. 15, 2016, 32pp. [cited by applicant]
Manco et al., “My VM is Lighter (and Safer) than Your Container”, Proceedings of the 26th Symposium on Operating Systems Principles, SOSP '17, Oct. 28, 2017, 16 pp., XP055436727, New York, New York, USA, DOI: 10.1145/31… [cited by applicant]
Prosecution History from U.S. Appl. No. 16/369,169, now issued U.S. Pat. No. 10,841,226, dated Jul. 6, 2020 through Oct. 23, 2020, 18 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 16/949,684, dated May 23, 2022 through Jun. 12, 2023, 141 pp. [cited by applicant]
Response to Communication pursuant to Article 94(3) EPC dated Apr. 7, 2022, from counterpart European Application No. 19181700.6 filed Aug. 8, 2022, 13 pp. [cited by applicant]
Response to Extended Search Report dated Jan. 2, 2020 from counterpart European Application No. 19181700.6, filed Mar. 22, 2021, 85 pp. [cited by applicant]
Rosen, “BGP/MPLS IP Virtual Private Networks (VPNs),” Request for Comments 4364, Internet Engineering Task Force Network Working Group, Feb. 2006, 48 pp. [cited by applicant]
Siddiqui et al., “Enabling New Features with Kubernetes for NFV,” Intel Corporation, Data Center Solution Networking Group, White Paper, Jun. 1, 2017, 14 pp. [cited by applicant]
Tao, “The Work of Containerized NFV Infrastructure on Arm Platform,” Open Source Summit Japan & Automotive Linux Summit, Jun. 21, 2018, 34 pp. [cited by applicant]
Zhou et al., “NFV Reference Design for a Containerized vEPC Application”, Solution Summary, Jun. 12, 2017, 34 pp., Retrieved from the Internet on Jan. 26, 2023 from URL: https://sdnfv.zte.com.cn/downloads/85. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 19181700.6 dated Feb. 14, 2024, 5 pp. [cited by applicant]
First Office Action and Search Report, and translation thereof, from counterpart Chinese Application No. 202210092742.6 dated Feb. 23, 2024, 27 pp. [cited by applicant]
Chen et al., “Security Service Access Method for Virtual Network”, Journal of Huazhong University of Science and Technology, vol. 44, No. 3, Mar. 23, 2016, pp. 49-54, Translation provided for only the Abstract. [cited by applicant]
Guan et al., “Research and Implementation of an Enhanced Virtua1 Router Redundancy Protocol with Dynamic Load Balancing”, Computer Engineering and Science, vol. 32, No. 1, Jan. 15, 2010, pp. 13-17, Translation provided … [cited by applicant]
Notice of Intent to Grant, and translation thereof, from counterpart Chinese Application No. 202210092742.6 dated Jul. 2, 2024, 5 pp. [cited by applicant]
Response to Communication pursuant to Article 94(3) EPC dated Feb. 14, 2024, from counterpart European Application No. 19181700.6 filed Jun. 12, 2024, 9 pp. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 19181700.6 dated Oct. 2, 2025, 61 pp. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 16/369,169, dated Jul. 6, 2020, 7 pp. [cited by applicant]
U.S. Appl. No. 16/118,107, by Juniper Networks, Inc. (Inventor: Vinay Chandrakant Rao), filed Aug. 30, 2018. [cited by applicant]