IP Library Granted Patent US 10,044,525
Granted Patent B2
US 10,044,525 · App. 15/859,247 · Granted Aug 7, 2018

Scalable tenant networks

Inventors: Poornananda R. Gaddehosur (Redmond, WA); Benjamin M. Schultz (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L12/4675G06F9/45537H04L41/0893H04L41/12H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,525
App. No.
15/859,247
Granted
Aug 7, 2018
Kind
B2
Abstract

Template-driven locally calculated policy updates for virtualized machines in a datacenter environment are described. A central control and monitoring node calculates and pushes down policy templates to local control and monitoring nodes. The templates provide boundaries and/or a pool of networking resources, from which the local control and monitoring node is enabled to calculate policy updates for locally instantiated virtual machines and containers.

Claims (42)

1. A system comprising:

a local controller configured to:

monitor resource utilization of the system;

receive a policy template that includes one or more configurable network policy elements from a central controller;

calculate a network virtualization policy for at least one virtualized computing resource implemented within one or more nodes associated with the local controller, the network virtualization policy being based at least on the received policy template and the monitored resource utilization; and

distribute the network virtualization policy to one or more network infrastructure elements and/or to the one or more nodes; and

a local store configured to store the monitored resource utilization, the policy template, and the calculated network virtualization policy.

2. The system of claim 1 , wherein the local controller is further configured to request, based at least on the monitored resource utilization and from the central controller, an updated policy template that indicates a change in the configurable network policy elements, the change providing additional networking resources.

3. The system of claim 1 , wherein the at least one virtualized computing resource includes a first virtual machine and/or a container executing within a second virtual machine.

4. The system of claim 3 , wherein the one or more configurable network policy elements includes a plurality of sets of network addresses that are associated with each other based on a policy relationship between the first virtual machine and the second virtual machine, the local controller configured to allocate at least one network address selected from the plurality of sets of network addresses to the at least one virtualized computing resource.

5. The system of claim 3 , wherein the one or more configurable network policy elements includes a plurality of sets of security policies that are associated with each other based on a policy relationship between the first virtual machine and the second virtual machine, the local controller configured to allocate at least one security policy selected from the plurality of sets of security policies to the at least one virtualized computing resource.

6. The system of claim 3 , wherein the one or more network infrastructure elements includes at least one virtualized network function instantiated within the first virtual machine, the local controller configured to monitor and update a policy that is tailored to the virtualized network function.

7. The system of claim 3 , wherein the local controller is configured to use one or more IP anchors to ensure connectivity to at least one virtualized network function instantiated within the first virtual machine, the local controller configured to monitor and update a policy that is tailored to the at least one virtualized network function and that is associated with the one or more IP anchors.

8. The system of claim 1 , wherein the local controller is configured to use one or more IP anchors to ensure connectivity to at least one node of the one or more nodes that has received a policy update from the local controller.

9. The system of claim 1 , wherein the local controller is configured to provide discoverability services for a virtual machine, a container, or a virtualized network function that has migrated to another system.

10. A method comprising:

monitoring, by a local controller, resource utilization of a system;

receiving, at the local controller and from a central controller, a policy template that includes one or more configurable network policy elements;

calculating, based at least on the received policy template and the monitored resource utilization, a network virtualization policy for at least one virtualized computing resource implemented within one or more nodes associated with the local controller; and

distributing, by the local controller, the network virtualization policy to one or more network infrastructure elements and/or to the one or more nodes.

11. The method of claim 10 , further comprising requesting, based at least on the monitored resource utilization and from the central controller, an updated policy template that indicates a change in the configurable network policy elements, the change providing additional networking resources.

12. The method of claim 10 , wherein the at least one virtualized computing resource includes a first virtual machine and/or a container executing within a second virtual machine.

13. The method of claim 12 , wherein the one or more configurable network policy elements includes a plurality of sets of network addresses that are associated with each other based on a relationship between the first virtual machine and the second virtual machine and wherein the method further comprises distributing, by the local controller at least one network address selected from the plurality of sets of network addresses to the one or more nodes.

14. The method of claim 12 , wherein the one or more configurable network policy elements includes at least a plurality of sets of security policies that are associated with each other based on a routing relationship between the first virtual machine and the second virtual machine, the method further comprising allocating at least one security policy selected from the plurality of sets of security policies to the at least one virtualized computing resource.

15. The method of claim 12 , wherein the one or more network infrastructure elements includes at least one virtualized network function instantiated within the first virtual machine, the method further comprising monitoring and updating a policy that is tailored to the virtualized network function.

16. The method of claim 12 , further comprising:

using one or more IP anchors to ensure connectivity to at least one virtualized network function instantiated within the first virtual machine; and

monitoring and updating a policy that is tailored to the at least one virtualized network function and that is associated with the one or more IP anchors.

17. The method of claim 10 , further comprising using one or more IP anchors to ensure connectivity to at least one node of the one or more nodes that has received a policy update from the local controller.

18. The method of claim 10 , further comprising providing discoverability services for a virtual machine, a container, or a virtualized network function that has migrated to another system.

19. A system comprising:

one or more processors;

computer-readable media;

programming instructions stored on the computer-readable media and executable by the one or more processors to:

receive a policy template for a local environment that includes one or more nodes, the policy template indicating one or more configurable network policy elements allocated to one or more virtualized computing resources instantiated within the one or more nodes;

determine, based at least in part on the policy template, a network virtualization policy for at least one virtualized computing resource instantiated within the one or more nodes;

distribute the network virtualization policy to one or more network infrastructure elements and/or to the one or more nodes;

monitor network resource utilization within the one or more nodes; and

request an updated policy template that indicates a change in the one or more configurable network policy elements to provide additional network resources allocated to the one or more virtualized computing resources instantiated within the one or more nodes or to one or more new virtualized computing resources instantiated within the one or more nodes.

20. The system of claim 19 , wherein the programming instructions are further executable by the one or more processors to:

receive the updated policy template responsive to the requesting the updated policy template; and

determine an updated network virtualization policy for one or more of the at least one virtualized computing resource or a new virtualized computing resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2017
From: GADDEHOSUR, POORNANANDA R.; SCHULTZ, BENJAMIN M.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 044509/0193 →
Continuity (3)
Continuation 15075049 · Mar 18, 2016
Provisional Application 62267664 · Dec 15, 2015
Related Publication 20180123830A1 · May 3, 2018