IP Library Granted Patent US 12,401,579
Granted Patent B2
US 12,401,579 · App. 18/478,124 · Granted Aug 26, 2025

Service level verification in distributed system using data package injection

Inventors: Dharmesh M. Patel (Round Rock, TX); John A. Lockman, III (Granite Shoals, TX)
Assignee: Dell Products L.P.
H04L41/5009H04L41/5032H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,579
App. No.
18/478,124
Granted
Aug 26, 2025
Kind
B2
Abstract

Methods and systems for managing the operation of a deployment are provided. The deployment may be managed in accordance with a subscription model. The subscription model may use subscriptions to define the extent and limits on use of services provided by the deployment. The subscription services and limits may be enforced by management controllers of network devices of the deployment. The management controllers may operate independently from control planes and data planes of the network devices. If a plane is suspected of being compromised, the management controllers may take action to confirm the suspicions. If confirmed, then remedial activity may be initiated to address the compromised plane.

Claims (60)

1. A method of managing operation of a distributed system, the method comprising:

making, by a management controller of a first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of network data units based on the network data package;

monitoring, by the management controller, processing of the network data units by the data plane to obtain at least one metric indicating a level of network service provided by the first network device;

making a determination, by the management controller, regarding whether the level of the network service is commensurate with the subscription;

in a first instance of the determination where the level of network service is not commensurate with the subscription:

performing, by the management controller, a control plane independent enforcement action to conform operation of the first network device to be commensurate with the subscription to obtain an updated data plane; and

providing, by the updated data plane, network management services to manage network traffic flowing through the distributed system.

2. The method of claim 1 , wherein injecting the network data package comprises:

sending, by the management controller and via a management link, the network data package to a switch application specific integrated circuit of the data plane to initiate processing of the network data units by the data plane.

3. The method of claim 2 , wherein monitoring the processing comprises:

measuring, by the management controller, a duration of time for processing the network data units by the data plane.

4. The method of claim 2 , wherein monitoring the processing comprises:

obtaining, by the management controller, a measurement of a rate at which the network data units are processed by the data plane, the measurement being performed by a second network device.

5. The method of claim 4 , wherein making the determination comprises comparing the measurement to a limit of the subscription corresponding to the rate at which the network data units are processed by the data plane.

6. The method of claim 1 , wherein identifying that the control plane of the first network device is suspected of being compromised comprises:

deploying, by the management controller, a network policy to the control plane; and

monitoring, by the management controller, updates to the data plane to identify whether the data plane is updated by the control plane based on the network policy.

7. The method of claim 6 , wherein the control plane independent enforcement action comprises:

quarantining, by the management controller, the data plane from the control plane; and

updating, by the management controller, operation of the data plane based on the network policy.

8. The method of claim 1 , wherein the management controller comprises a data processing system, the control plane is hosted by computing resources of the first network device, and the data processing system operates independently from the computing resources of the first network device.

9. The method of claim 8 , wherein the management controller is operably connected to the computing resources of the first network device via a first management channel, and the first management channel being usable by the management controller to configure the computing resources of the first network device.

10. The method of claim 9 , wherein the data plane is hosted by a special purpose hardware device operably connected to in-band links through which the network traffic is obtained and forwarded on to other devices, and the management controller is operably connected to at least one other device via an out-of-band link.

11. The method of claim 10 , wherein the management controller is operably connected to the special purpose hardware device via a second management channel, and the second management channel being usable by the management controller to configure the special purpose hardware device.

12. The method of claim 11 , wherein the special purpose hardware device comprises a switch application specific integrated circuit adapted to forward network traffic.

13. The method of claim 1 , wherein the subscription is for a level of service to be provided by the first network device to a subscribing entity.

14. The method of claim 13 , wherein the level of service is a latency level for processing of network data units.

15. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause a network device to perform operations for managing operation of a distributed system, the operations comprising:

making, by a management controller of a first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of network data units based on the network data package;

monitoring, by the management controller, processing of the network data units by the data plane to obtain at least one metric indicating a level of network service provided by the first network device;

making a determination, by the management controller, regarding whether the level of the network service is commensurate with the subscription;

in a first instance of the determination where the level of network service is not commensurate with the subscription:

performing, by the management controller, a control plane independent enforcement action to conform operation of the first network device to be commensurate with the subscription to obtain an updated data plane; and

providing, by the updated data plane, network management services to manage network traffic flowing through the distributed system.

16. The non-transitory machine-readable medium of claim 15 , wherein injecting the network data package comprises:

sending, by the management controller and via a management link, the network data package to a switch application specific integrated circuit of the data plane to initiate processing of the network data units by the data plane.

17. The non-transitory machine-readable medium of claim 16 , wherein monitoring the processing comprises:

measuring, by the management controller, a duration of time for processing the network data units by the data plane.

18. The non-transitory machine-readable medium of claim 16 , wherein monitoring the processing comprises:

obtaining, by the management controller, a measurement of a rate at which the network data units are processed by the data plane, the measurement being performed by a second network device.

19. A first network device, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the first network device to perform operations for managing operation of a distributed system, the operations comprising:

making, by a management controller of the first network device, an identification that a control plane of the first network device is suspected of being compromised;

identifying, by the management controller and based on the identification, a subscription for services provided by the first network device;

obtaining, by the management controller and based on the subscription, a network data package;

injecting, by the management controller, the network data package into a data plane of the first network device to initiate transmission of network data units based on the network data package;

monitoring, by the management controller, processing of the network data units by the data plane to obtain at least one metric indicating a level of network service provided by the first network device;

making a determination, by the management controller, regarding whether the level of the network service is commensurate with the subscription;

in a first instance of the determination where the level of network service is not commensurate with the subscription:

performing, by the management controller, a control plane independent enforcement action to conform operation of the first network device to be commensurate with the subscription to obtain an updated data plane; and

providing, by the updated data plane, network management services to manage network traffic flowing through the distributed system.

20. The first network device of claim 19 , wherein injecting the network data package comprises:

sending, by the management controller and via a management link, the network data package to a switch application specific integrated circuit of the data plane to initiate processing of the network data units by the data plane.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2023
From: PATEL, DHARMESH M.; LOCKMAN, JOHN A., III
To: DELL PRODUCTS L.P.
Reel/Frame 065134/0188 →
Continuity (1)
Related Publication 20250112943A1 · Apr 3, 2025
References Cited (39)
US 6192402B1 · Iwase · 2001 [cited by applicant]
US 7890612B2 · Todd · 2011 [cited by applicant]
US 8189486B2 · Krishnaswamy · 2012 [cited by applicant]
US 8696765B2 · Mendez · 2014 [cited by applicant]
US 8850507B2 · Reisman · 2014 [cited by applicant]
US 9294386B2 · Narad · 2016 [cited by applicant]
US 9354126B2 · Chainer et al. · 2016 [cited by applicant]
US 9534967B2 · Chainer et al. · 2017 [cited by applicant]
US 10652038B2 · Juneau · 2020 [cited by applicant]
US 10885191B1 · Gupta · 2021 [cited by applicant]
US 11095558B2 · Cheng et al. · 2021 [cited by applicant]
US 11630747B1 · Deboy et al. · 2023 [cited by applicant]
US 11962506B2 · Rangel Augusto et al. · 2024 [cited by applicant]
US 12113669B1 · Patel · 2024 [cited by applicant]
US 20070143827A1 · Nicodemus · 2007 [cited by applicant]
US 20100188975A1 · Raleigh · 2010 [cited by applicant]
US 20110128844A1 · Sun · 2011 [cited by applicant]
US 20110275377A1 · Wu · 2011 [cited by applicant]
US 20120114331A1 · Kamijo et al. · 2012 [cited by applicant]
US 20150311961A1 · Li · 2015 [cited by applicant]
US 20160328349A1 · Kunnathur Ragupathi · 2016 [cited by applicant]
US 20180359134A1 · Pech · 2018 [cited by applicant]
US 20200014583A1 · Dang · 2020 [cited by applicant]
US 20200403889A1 · Nguyen · 2020 [cited by applicant]
US 20210117249A1 · Doshi et al. · 2021 [cited by applicant]
US 20210263836A1 · Singh · 2021 [cited by applicant]
US 20210368395A1 · Prabhakar · 2021 [cited by applicant]
US 20230164567A1 · Fellows · 2023 [cited by examiner]
US 20230267198A1 · Karpovsky et al. · 2023 [cited by applicant]
US 20240205226A1 · Lukyanov et al. · 2024 [cited by applicant]
US 20240380767A1 · Davraev · 2024 [cited by examiner]
US 20240414574A1 · Alworth · 2024 [cited by applicant]
US 20250112942A1 · Patel · 2025 [cited by applicant]
US 20250112943A1 · Patel · 2025 [cited by applicant]
US 20250112951A1 · Patel · 2025 [cited by applicant]
“Management vs. Control vs. Data Planes in a Network Device,” Codilime, Dec. 22, 2022, Web Page <https://codilime.com/blog/management-plane-vs-control-plane-vs-data-plane/> accessed on Sep. 28, 2023 (8 Pages). [cited by applicant]
“Control Plane Policing,” Cisco Systems, Inc., Nov. 2006 (36 Pages). [cited by applicant]
Strickx, Tom, “ASICs at the Edge,” The Cloudflare Blog, Nov. 27, 2020, web page <https://blog.cloudflare.com/asics-at-the-edge/> accessed on Sep. 28, 2023 (22 Pages). [cited by applicant]
Cotroneo, Domenico, et al., “Overload control for virtual network functions under CPU contention,” Future Generation Computer Systems 99 (2019): 164-176 (13 Pages). [cited by applicant]
Cited By (2)
US 12,609,874 US 12,719,897