IP Library › Granted Patent US 11,909,712
Granted Patent B2
US 11,909,712 · App. 17/092,192 · Granted Feb 20, 2024

Network address translation for virtual machines

Inventor: Evan K. Anderson (Seattle, WA)
Assignee: Google LLC
H04L61/256G06F9/45558H04L49/3009H04L61/2503H04L61/255H04L61/2517H04L61/2535H04L67/1001H04L69/16H04L69/22G06F2009/45595H04L2101/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,909,712
App. No.
17/092,192
Granted
Feb 20, 2024
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for receiving a packet from a client, the packet having header information including a destination Internet Protocol (IP) address, a destination port, a source IP address, and a source port, and wherein the source IP address and source port are associated with the client; selecting a destination virtual machine based on the destination port; modifying the packet by replacing the destination IP address in the header information with an IP address of the selected destination virtual machine; and sending the modified packet to the destination virtual machine.

Claims (80)

1. A method comprising:

receiving, at data processing hardware of a gateway associated with a virtual private network, a packet from a first virtual machine executing on a host machine of the virtual private network, the packet comprising:

a source internet protocol (IP) address assigned to the first virtual machine;

a source port of the host machine assigned to the first virtual machine;

a destination IP address; and

a destination port;

determining, by the data processing hardware, that the packet is intended for a client external to the virtual private network, the client associated with the destination IP address and the destination port;

based on the determination that the packet is intended for the client external to the virtual private network, modifying, by the data processing hardware:

the source IP address of the packet from the source IP address assigned to the first virtual machine to a respective IP address assigned to the gateway; and

the source port of the packet from the source port of the host machine to a different port assigned to the first virtual machine; and

communicating, by the data processing hardware, the packet to the destination IP address of the client external to the virtual private network,

wherein:

the client comprises a second virtual machine; and

the packet is a User Datagram Protocol (UDP) packet comprising a return virtual network pair token for unidirectional communication from the second virtual machine to the first virtual machine.

2. The method of claim 1 , further comprising, prior to the data processing hardware of the gateway receiving the packet, encapsulating a data portion of the packet.

3. The method of claim 2 , wherein encapsulating the packet comprises encrypting at least a portion of the data portion of the packet using a Diffie-Hellman protocol.

4. The method of claim 1 , further comprising, requesting a token from a registry service, the token used to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine.

5. The method of claim 4 , wherein the token comprises a validity period defining a time when the token expires.

6. The method of claim 5 , wherein prior to communicating the packet to the destination IP address of the client external to the virtual private network, determining that the validity period for the token is satisfied.

7. The method of claim 6 , wherein determining that the validity period for the token is satisfied occurs at the data processing hardware of the gateway.

8. The method of claim 1 , further comprising:

prior to the data processing hardware of the gateway receiving the packet, encapsulating a data portion of the packet;

prior to the data processing hardware of the gateway communicating the packet to the destination IP address of the client external to the virtual private network, determining, by the data processing hardware, that a validity period of a token associated with the packet is satisfied, the token configured to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine;

determining, by the data processing hardware, that the validity period for the token is satisfied; and

in response to determining that the validity period for the token is satisfied, de-encapsulating, by the data processing hardware, the encapsulated data portion of the packet.

9. A method comprising:

receiving, at data processing hardware of a gateway associated with a virtual private network, a packet from a first virtual machine executing on a host machine of the virtual private network, the packet comprising:

a source internet protocol (IP) address assigned to the first virtual machine;

a source port of the host machine assigned to the first virtual machine;

a destination IP address; and

a destination port;

determining, by the data processing hardware, that the packet is intended for a client external to the virtual private network, the client associated with the destination IP address and the destination port;

based on the determination that the packet is intended for the client external to the virtual private network, modifying, by the data processing hardware, the source IP address of the packet from the source IP address assigned to the first virtual machine to a respective IP address assigned to the gateway; and

communicating, by the data processing hardware, the packet to the destination IP address of the client external to the virtual private network,

wherein:

the client comprises a second virtual machine;

the method further comprises requesting a token from a registry service, the token used to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine; and

the packet is a User Datagram Protocol (UDP) packet comprising a return virtual network pair token for unidirectional communication from the second virtual machine to the first virtual machine.

10. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

receiving, at a gateway associated with a virtual private network, a packet from a first virtual machine executing on a host machine of the virtual private network, the packet comprising:

a source internet protocol (IP) address assigned to the first virtual machine;

a source port of the host machine assigned to the first virtual machine;

a destination IP address; and

a destination port;

determining that the packet is intended for a client external to the virtual private network, the client associated with the destination IP address and the destination port;

based on the determination that the packet is intended for the client external to the virtual private network:

modifying the source IP address of the packet from the source IP address assigned to the first virtual machine to a respective IP address assigned to the gateway; and

modifying the source port of the packet from the source port of the host machine to a different port assigned to the first virtual machine; and

communicating the packet to the destination IP address of the client external to the virtual private network,

wherein:

the client comprises a second virtual machine; and

the packet is a User Datagram Protocol (UDP) packet comprising a return virtual network pair token for unidirectional communication from the second virtual machine to the first virtual machine.

11. The system of claim 10 , wherein the operations further comprise, prior to the gateway receiving the packet, encapsulating a data portion of the packet.

12. The system of claim 11 , wherein encapsulating the packet comprises encrypting at least a portion of the data portion of the packet using a Diffie-Hellman protocol.

13. The system of claim 10 , wherein the operations further comprise, requesting a token from a registry service, the token used to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine.

14. The system of claim 13 , wherein the token comprises a validity period defining a time when the token expires.

15. The system of claim 14 , wherein prior to communicating the packet to the destination IP address of the client external to the virtual private network, determining that the validity period for the token is satisfied.

16. The system of claim 15 , wherein determining that the validity period for the token is satisfied occurs at the data processing hardware of the gateway.

17. The system of claim 10 , wherein the operations further comprise:

prior to the gateway receiving the packet, encapsulating a data portion of the packet;

prior to communicating the packet to the destination IP address of the client external to the virtual private network, determining that a validity period of a token associated with the packet is satisfied, the token configured to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine;

determining that the validity period for the token is satisfied; and

in response to determining that the validity period for the token is satisfied, de-encapsulating the encapsulated data portion of the packet.

18. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

receiving, at a gateway associated with a virtual private network, a packet from a first virtual machine executing on a host machine of the virtual private network, the packet comprising:

a source internet protocol (IP) address assigned to the first virtual machine;

a source port of the host machine assigned to the first virtual machine;

a destination IP address; and

a destination port;

determining that the packet is intended for a client external to the virtual private network, the client associated with the destination IP address and the destination port;

based on the determination that the packet is intended for the client external to the virtual private network, modifying the source IP address of the packet from the source IP address assigned to the first virtual machine to a respective IP address assigned to the gateway; and

communicating the packet to the destination IP address of the client external to the virtual private network;

wherein:

the client comprises a second virtual machine;

the operations further comprise, requesting a token from a registry service, the token used to establish a unidirectional virtual network pair from the first virtual machine to the second virtual machine; and

the packet is a User Datagram Protocol (UDP) packet comprising a return virtual network pair token for unidirectional communication from the second virtual machine to the first virtual machine.

Assignments (2)
CONVERSION Recorded Apr 30, 2021
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 056105/0551 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2021
From: ANDERSON, EVAN K.
To: GOOGLE INC.
Reel/Frame 056106/0683 →
Continuity (5)
Continuation 16158534 · Oct 12, 2018
Continuation 15001471 · Jan 20, 2016
Continuation 13350398 · Jan 13, 2012
Provisional Application 61432561 · Jan 13, 2011
Related Publication 20210243155A1 · Aug 5, 2021
Cited By (1)
US 12,284,115