IP Library Granted Patent US 11,637,770
Granted Patent B2
US 11,637,770 · App. 17/237,750 · Granted Apr 25, 2023

Invalidating cached flow information in a cloud infrastructure

Inventors: Leonard Thomas Tracy (Bothell, WA); Lucas Michael Kreger-Stickles (Seattle, WA); Jagwinder Singh Brar (Bellevue, WA); Bryce Eugene Bockman (Seattle, WA)
Assignee: Oracle International Corporation
H04L45/38H04L12/4641H04L41/0813H04L41/0853H04L45/02H04L45/742
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,637,770
App. No.
17/237,750
Granted
Apr 25, 2023
Kind
B2
Abstract

Techniques for managing the distribution of configuration information that supports the flow of packets in a cloud environment are described. In an example, a virtual network interface card (VNIC) hosted on a network virtualization device NVD receives a first packet from a compute instance associated with the VNIC. The VNIC determines that flow information to send the first packet on a virtual network is unavailable from a memory of the NVD. The VNIC sends, via the NVD, the first packet to a network interface service, where the network interface service maintains configuration information to send packets on the substrate network and is configured to send the first packet on the substrate network based on the configuration information. The NVD receives the flow information from the network interface service, where the flow information is a subset of the configuration information. The NVD stores the flow information in the memory.

Claims (59)

1. A system comprising:

a set of servers connected with a substrate network and hosting a network interface service;

a network virtualization device hosting a virtual network interface card, connected with the substrate network, and storing flow information usable by the virtual network interface card for traffic associated with a virtual network; and

a host machine connected with the network virtualization device and hosting a compute instance from the virtual network,

wherein the network interface service hosted on the set of servers is configured to:

store configuration information about a configuration of the virtual network;

store version information about the configuration information;

determine that the virtual network interface card is associated with the flow information;

determine, based on the version information, that the flow information on the network virtualization device is outdated;

generate, based on the configuration information and the version information, an update to the flow information; and

send, to the network virtualization device, the update.

2. The system of claim 1 , wherein the configuration information comprises security policies, overlay-to-substrate internet protocol (IP) address mappings, and route rules for one or more packet flows, and wherein the flow information comprises at least one of a security policy, an overlay-to-substrate IP address mapping, or a route rule included in the configuration information.

3. The system of claim 1 , wherein the configuration information comprises a plurality of portions, the flow information corresponding to a portion of the plurality of portions of the configuration information, and wherein the network interface service is further configured to:

store, for each portion of the plurality of portions, an indicator of a version of the portion; and

determine that a version of the flow information is outdated based on the stored indicator of the version for the corresponding portion of the configuration information.

4. The system of claim 3 , wherein the network interface service is further configured to:

send, to the network virtualization device, an indicator of the update to be stored on the network virtualization device.

5. The system of claim 3 , wherein the network interface service is further configured to:

receive, from the network virtualization device, a request for the update of the flow information, wherein the stored indicator informs the network virtualization device that the updated versionupdate is available; and

send, to the network virtualization device, the update in response to the request.

6. The system of claim 3 , wherein the network interface service is further configured to:

send, to a control plane, the version information; and

receive, from the control plane, the update of the flow information and an indicator of the update.

7. The system of claim 6 , wherein sending the version information comprises sending a vector clock populated with an indicator of a version of each portion of the plurality of portions that form the configuration information.

8. A method comprising:

storing, by a network virtualization device, flow information usable by a virtual network interface card for traffic associated with a virtual network, the network virtualization device hosting the virtual network interface card and connected with a substrate network, the virtual network interface card associated with a compute instance;

storing, by the network virtualization device, version information about the flow information;

determining, by the network virtualization device, that the flow information is outdated based on communication with a control plane about the version information;

receiving, by the network virtualization device from the control plane or a network interface service, an update of the flow information, the network interface service hosted on a set of servers connected with the substrate network, the network interface service storing configuration information about a configuration of the virtual network and version information about the configuration information, the update based on the configuration information and version information; and

updating, by the network virtualization device, the flow information based on the update.

9. The method of claim 8 , further comprising:

sending, by the network virtualization device to the control plane, the version information; and

receiving, by the network virtualization device from the control plane, an indication that the flow information is outdated.

10. The method of claim 9 , wherein sending the version information comprises sending a vector clock that comprises one or more version indicators of the flow information, and wherein receiving the indication comprises receiving an indicator of the update to the flow information.

11. The method of claim 8 , further comprising:

sending, by the network virtualization device to the network interface service, a request to receive the update;

receiving, by the network virtualization device from the network interface service, the update based on the request; and

sending, by the network virtualization device, a packet based on the update.

12. The method of claim 11 , wherein the request is sent to the network interface service in response to receiving an indication from the control plane that the flow information is outdated and prior to receiving the packet from the compute instance.

13. The method of claim 8 , further comprising:

receiving, by the network virtualization device from a host machine of the compute instance, a packet;

sending, by the network virtualization device to the network interface service, the packet based on the flow information being outdated; and

receiving, by the network virtualization device from the network interface service, the update based on the packet.

14. One or more non-transitory computer-readable instructions that, upon execution on a network virtualization device, cause the network virtualization device to perform operations comprising:

storing flow information usable by a virtual network interface card for traffic associated with a virtual network, the network virtualization device hosting the virtual network interface card and connected with a substrate network, the virtual network interface card associated with a compute instance;

storing version information about the flow information;

determining that the flow information is outdated based on communication with a control plane about the version information;

receiving, from the control plane or-a network interface service, update of the flow information, the network interface service hosted on a set of servers connected with the substrate network, the network interface service storing configuration information about a configuration of the virtual network and version information about the configuration information, the update based on the configuration information and version information; and

updating the flow information based on the update.

15. The one or more non-transitory computer-readable instructions of claim 14 , wherein the operations further comprise receiving, from the network interface service, the flow information and the version information, wherein the flow information and the version information are stored in a cache associated with the virtual network interface card.

16. The one or more non-transitory computer-readable instructions of claim 14 , wherein the configuration information comprises a plurality of portions, and wherein the operations further comprise receiving, from the network interface service, and storing each portion of the plurality of portions and a corresponding version indicator.

17. The one or more non-transitory computer-readable instructions of claim 16 , wherein the operations further comprise:

receiving, from a host machine of the compute instance, a packet;

determining that the flow information comprises at least one outdated portion based on the communication with the control plane; and

sending the packet to the network interface service based on the flow information comprising at least one outdated portion.

18. The one or more non-transitory computer-readable instructions of claim 17 , wherein the operations further comprise:

receiving, from the network interface service, an updated version of the at least one outdated portion in response to sending the packet.

19. The one or more non-transitory computer-readable instructions of claim 16 , wherein the configuration information comprises security policies, overlay-to-substrate internet protocol (IP) address mappings, and route rules for one or more packet flows, and wherein the flow information comprises at least one of a security policy, an overlay-to-substrate IP address mapping, or a route rule included in the configuration information.

20. The system of claim 5 , wherein the request for the update is based on an indication from a control plane that the flow information is outdated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2021
From: TRACY, LEONARD THOMAS; KREGER-STICKLES, LUCAS MICHAEL; BRAR, JAGWINDER SINGH; BOCKMAN, BRYCE EUGENE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 056059/0610 →
Continuity (2)
Provisional Application 63149276 · Feb 13, 2021
Related Publication 20220263713A1 · Aug 18, 2022
Cited By (8)
US 12,284,113 US 12,289,284 US 12,328,257 US 12,341,689 US 12,341,690 US 12,562,984 US 12,592,877 US 12,706,840