IP Library › Granted Patent US 11,470,071
Granted Patent B2
US 11,470,071 · App. 16/852,553 · Granted Oct 11, 2022

Authentication for logical overlay network traffic

Inventors: Ye Luo (Beijing, CN); Jinjun Gao (Beijing, CN); Qi Wu (Beijing, CN); Donghai Han (Beijing, CN)
Assignee: VMWARE, INC.
H04L63/08G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,470,071
App. No.
16/852,553
Granted
Oct 11, 2022
Kind
B2
Abstract

Example methods and systems for authentication for logical overlay network traffic are described. In one example, a first computer system may detect an inner packet and generate authentication information associated with the inner packet based on control information from a management entity. The authentication information may indicate that the inner packet originates from a trusted zone. The first computer system may further generate an encapsulated packet by encapsulating the inner packet with an outer header that specifies the authentication information, and send the encapsulated packet towards the second virtualized computing instance to cause a second computer system to verify that the inner packet originates from the trusted zone based on the authentication information.

Claims (62)

1. A method for a first computer system to perform authentication for logical overlay network traffic, the method comprising:

detecting an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance;

based on control information from a manager, generating authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone;

generating an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and

sending the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance.

2. The method of claim 1 , wherein sending the encapsulated packet comprises:

sending the encapsulated packet via a first virtual tunnel endpoint (VTEP) supported by the first computer system to a second VTEP supported by the second computer system, wherein the first VTEP is an open interface that is accessible by a source from a non-trusted zone.

3. The method of claim 2 , wherein generating the authentication information comprises:

identifying, by a managed bridge supported by the first computer system, authentication key information from the control information; and

generating, by the managed bridge, the authentication information based on the authentication key information and the inner packet, wherein the second computer system is configured to verify the authentication information based on the same authentication key.

4. The method of claim 2 , wherein generating the encapsulated packet comprises:

generating the encapsulated packet using a transport bridge that is supported by the first computer system but not managed by the manager.

5. The method of claim 1 , wherein generating the encapsulated packet comprises:

configuring an option field in the outer header of the encapsulated packet to include the authentication information.

6. The method of claim 1 , further comprising:

receiving, from the second computer system or a third computer system, an ingress encapsulated packet that includes an ingress inner packet and an ingress outer header;

extracting ingress authentication information from the ingress outer header; and

based on the ingress authentication information and the control information from the manager, determining whether the ingress inner packet originates from the trusted zone.

7. The method of claim 6 , further comprising:

in response to determination that the ingress inner packet does not originate from the trusted zone, dropping the ingress inner packet.

8. A non-transitory computer-readable storage medium that includes a set of instructions which, in response to execution by a processor of a first computer system, cause the processor to perform authentication for logical overlay network traffic, wherein the method comprises:

detecting an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance;

based on control information from a manager, generating authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone;

generating an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and

sending the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance.

9. The non-transitory computer-readable storage medium of claim 8 , wherein sending the encapsulated packet comprises:

sending the encapsulated packet via a first virtual tunnel endpoint (VTEP) supported by the first computer system to a second VTEP supported by the second computer system, wherein the first VTEP is an open interface that is accessible by a source from a non-trusted zone.

10. The non-transitory computer-readable storage medium of claim 9 , wherein generating the authentication information comprises:

identifying, by a managed bridge supported by the first computer system, authentication key information from the control information; and

generating, by the managed bridge, the authentication information based on the authentication key information and the inner packet, wherein the second computer system is configured to verify the authentication information based on the same authentication key.

11. The non-transitory computer-readable storage medium of claim 9 , wherein generating the encapsulated packet comprises:

generating the encapsulated packet using a transport bridge that is supported by the first computer system but not managed by the manager.

12. The non-transitory computer-readable storage medium of claim 8 , wherein generating the encapsulated packet comprises:

configuring an option field in the outer header of the encapsulated packet to include the authentication information.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

receiving, from the second computer system or a third computer system, an ingress encapsulated packet that includes an ingress inner packet and an ingress outer header;

extracting ingress authentication information from the ingress outer header; and

based on the ingress authentication information and the control information from the manager, determining whether the ingress inner packet originates from the trusted zone.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the method further comprises:

in response to determination that the ingress inner packet does not originate from the trusted zone, dropping the ingress inner packet.

15. A computer system, being a first computer system, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, in response to execution by the processor, cause the processor to:

detect an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance;

based on control information from a manager, generate authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone;

generate an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and

send the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance.

16. The computer system of claim 15 , wherein the instructions that cause the processor to send the encapsulated packet cause the processor to:

send the encapsulated packet via a first virtual tunnel endpoint (VTEP) supported by the first computer system to a second VTEP supported by the second computer system, wherein the first VTEP is an open interface that is accessible by a source from a non-trusted zone.

17. The computer system of claim 16 , wherein the instructions that cause the processor to generate the authentication information cause the processor to:

identify, by a managed bridge supported by the first computer system, authentication key information from the control information; and

generate, by the managed bridge, the authentication information based on the authentication key information and the inner packet, wherein the second computer system is configured to verify the authentication information based on the same authentication key.

18. The computer system of claim 16 , wherein the instructions that cause the processor to generate the encapsulated packet cause the processor to:

generate the encapsulated packet using a transport bridge that is supported by the first computer system but not managed by the manager.

19. The computer system of claim 15 , wherein the instructions that cause the processor to generate the encapsulated packet cause the processor to:

configure an option field in the outer header of the encapsulated packet to include the authentication information.

20. The computer system of claim 15 , wherein the instructions further cause the processor to:

receive, from the second computer system or a third computer system, an ingress encapsulated packet that includes an ingress inner packet and an ingress outer header;

extract ingress authentication information from the ingress outer header; and

based on the ingress authentication information and the control information from the manager, determine whether the ingress inner packet originates from the trusted zone.

21. The computer system of claim 20 , wherein the instructions further cause the processor to:

in response to determination that the ingress inner packet does not originate from the trusted zone, drop the ingress inner packet.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2020
From: LUO, YE; GAO, JINJUN; WU, QI; HAN, DONGHAI
To: VMWARE, INC.
Reel/Frame 052436/0348 →
Continuity (1)
Related Publication 20210328977A1 · Oct 21, 2021