IP Library › Granted Patent US 11,757,782
Granted Patent B2
US 11,757,782 · App. 17/334,999 · Granted Sep 12, 2023

Architectures for disaggregating SDN from the host

Inventors: Gerald Roy Degrace (Atalnta, GA); Deepak Bansal (Bellevue, WA); Rishabh Tewari (Sammamish, WA); Michal Czeslaw Zygmunt (Bellevue, WA); Deven Jagasia (Kirkland, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L47/20G06F9/45558H04L41/046H04L45/12H04L45/38H04L45/586H04L47/2483H04L49/70H04L67/1097G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,782
App. No.
17/334,999
Granted
Sep 12, 2023
Kind
B2
Abstract

Techniques are disclosed for processing data packets and implementing policies in a software defined network (SDN) of a virtual computing environment. At least one SDN appliance is configured to disaggregate enforcement of policies of the SDN from hosts of the virtual computing environment. The servers are communicatively coupled to network interfaces of the SDN appliance. The servers host a plurality of virtual machines The SDN appliance comprises a plurality of smart network interface cards (sNICs) configured to implement functionality of the SDN appliance.

Claims (42)

1. A method for processing data packets and implementing policies in a software defined network (SDN) of a virtual computing environment, the method performed by a SDN appliance configured to disaggregate enforcement of policies of the SDN from hosts of the virtual computing environment, the hosts implemented on servers communicatively coupled to network interfaces of the SDN appliance, the servers hosting a plurality of virtual machines, the method comprising:

receiving, at the SDN appliance from a device that is remote from the virtual computing environment, a data packet addressed to an endpoint in a virtual network hosted by one of the virtual machines, the data packet comprising an identifier indicative of the remote device, wherein the SDN appliance comprises a plurality of smart network interface cards (sNICs) configured to implement functionality of the SDN appliance;

based on the identifier:

determining, by an sNIC of the SDN appliance, that the data packet is associated with the virtual network; and

mapping, by the sNIC of the SDN appliance, one of a plurality of policies to a data flow of the virtual network;

modifying, by the sNIC of the SDN appliance, the packet in accordance with the mapped policy; wherein the mapped policy is dynamically adjustable based on the data flow; and

forwarding, by the sNIC of the SDN appliance, the modified packet to the endpoint in the virtual network.

2. The method of claim 1 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among the servers.

3. The method of claim 1 , wherein the SDN appliance is implemented as two physical devices that are communicatively coupled to at least two top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the physical devices.

4. The method of claim 3 , wherein storage traffic bypasses the sNICs.

5. The method of claim 1 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among one or more top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the top-of-rack switches.

6. The method of claim 2 , wherein at least two top-of-rack switches are configured with SDN agents configured to manage functionality of the SDN appliance.

7. A system comprising:

a plurality of servers communicatively coupled to at least one software defined network (SDN) appliance configured to disaggregate enforcement of policies of a SDN of a virtual computing environment from hosts of the virtual computing environment, the hosts implemented on servers communicatively coupled to network interfaces of the SDN appliance, the servers hosting a plurality of virtual machines;

the system configured to:

receive, from a device that is remote from the virtual computing environment, a data packet addressed to an endpoint in a virtual network hosted by one of the virtual machines, the data packet comprising an identifier indicative of the remote device, the SDN appliance comprising a plurality of smart network interface cards (sNICs) configured to implement functionality of the SDN appliance;

based on the identifier:

determine, by one of the sNICs of the SDN appliance, that the data packet is associated with the virtual network; and

map, by the one sNIC of the SDN appliance, one of a plurality of policies to a data flow of the virtual network;

modify, by the one sNIC of the SDN appliance, the packet in accordance with the mapped policy; wherein the mapped policy is dynamically adjustable based on the data flow; and

forward, by the one sNIC of the SDN appliance, the modified packet to the endpoint in the virtual network.

8. The system of claim 7 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among the plurality of servers.

9. The system of claim 7 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among one or more top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the top-of-rack switches.

10. The system of claim 7 , wherein the policy is applied at selectively placed network hops in the virtual network.

11. The system of claim 7 , wherein the SDN appliance is configured to apply policies of the virtual computing environment to data traffic on the virtual network after the data traffic leaves its source and before the data traffic reaches its destination.

12. The system of claim 7 , wherein the SDN appliance is implemented as two physical devices that are communicatively coupled to at least two top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the physical devices.

13. The system of claim 12 , wherein storage traffic bypasses the sNICs.

14. The system of claim 12 , wherein at least two top-of-rack switches are configured with SDN agents configured to manage functionality of the SDN appliance.

15. A data center rack comprising:

a plurality of servers; the servers communicatively coupled to at least one software defined network (SDN) appliance configured to disaggregate enforcement of policies of a SDN of a virtual computing environment from hosts of the virtual computing environment, the hosts implemented on servers communicatively coupled to network interfaces of the SDN appliance, the servers hosting a plurality of virtual machines;

the data center rack configured to:

receive, from a device that is remote from a software defined network (SDN) of a virtual computing environment, a data packet addressed to an endpoint in a virtual network hosted by one of the virtual machines, the data packet comprising an identifier indicative of the remote device, the SDN appliance comprising a plurality of smart network interface cards (sNICs) configured to implement functionality of the SDN appliance;

based on the identifier:

determine, by an sNIC of the SDN appliance, that the data packet is associated with the virtual network; and

map, by the sNIC of the SDN appliance, one of a plurality of policies to a data flow of the virtual network;

modify, by the sNIC of the SDN appliance, the packet in accordance with the mapped policy; wherein the mapped policy is dynamically adjustable based on the data flow; and

forward, by the sNIC of the SDN appliance, the modified packet to the endpoint in the virtual network.

16. The data center rack of claim 15 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among the plurality of servers.

17. The data center rack of claim 15 , wherein the SDN appliance is implemented as a distributed appliance where the sNICs are physically distributed among one or more top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the top-of-rack switches.

18. The data center rack of claim 15 , wherein the SDN appliance is implemented as two physical devices that are communicatively coupled to at least two top-of-rack switches, the servers communicatively coupled to network interfaces of the top-of-rack switches so that each of the servers have a switchable communications path to each sNIC of the physical devices.

19. The data center rack of claim 18 , wherein storage traffic bypasses the sNICs.

20. The data center rack of claim 18 , wherein at least two top-of-rack switches are configured with SDN agents configured to manage functionality of the SDN appliance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2021
From: DEGRACE, GERALD ROY; BANSAL, DEEPAK; TEWARI, RISHABH; ZYGMUNT, MICHAL CZESLAW; JAGASIA, DEVEN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057845/0282 →
Continuity (5)
Provisional Application 63173336 · Apr 9, 2021
Provisional Application 63173334 · Apr 9, 2021
Provisional Application 63173352 · Apr 9, 2021
Provisional Application 63173348 · Apr 9, 2021
Related Publication 20220329527A1 · Oct 13, 2022
Cited By (1)
US 12,739,164