IP Library › Granted Patent US 12,526,352
Granted Patent B2
US 12,526,352 · App. 18/176,207 · Granted Jan 13, 2026

Granular and efficient policy-based routing in software-defined edge networks

Inventors: Ahmed Khalid (Carrigtwohill, IE); Seán Ahearne (Ballinglanna, IE)
Assignee: Dell Products L.P.
H04L69/22H04L45/74H04L47/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,352
App. No.
18/176,207
Granted
Jan 13, 2026
Kind
B2
Abstract

Policy based routing in networks including software-based networks is disclosed. Packets ingested into a software defined network are altered to include a label header that identifies a source and destination of a packet. If the packets leave or egress the network, the packets are converted back to regular packets by removing the label header. Adding the label header reduces overhead. Further routing can be performed while enforcing policies.

Claims (66)

1 . A method comprising:

receiving packets, at a controller, wherein the packets are generated at a first pod and is destined for a target pod, and wherein the pod is included in a software defined network;

determining, by the controller, a type of communication for the packets and a path for the packets to the target pod;

configuring flow entries, by the controller, for the packets based on the type of communication for each switch in the path controlled by the controller; and

configuring the packets at a gateway switch, by the gateway switch according to the flow entries, and forwarding the packets according to the flow entries associated with the gateway switch,

wherein, when the type of communication is intracluster:

applying any existing policies; and

setting forwarding entries at the gateway switch that include:

adding a label header to packets at the gateway switch coming from the first pod and destined for the target pod, wherein the first pod and the target pod are identified by their MAC addresses, wherein the label header includes a first identifier for the first pod and a second identifier for the target pod;

changing an ethernet type to the packets at the gateway switch; and

forwarding the packets to a next switch in the path.

2 . The method of claim 1 , further comprising:

receiving the packets at the gateway switch, wherein the gateway switch is configured to forward the packets to the controller when no flow entries are present at the gateway switch and wherein the gateway switch is an ingress switch.

3 . The method of claim 2 , wherein the gateway switch comprises: a programmable switch, a virtual programmable switch, or a SmartNIC (Smart Network Interface Card).

4 . The method of claim 1 , where the type of communication is intranode when the controller determines that the first pod and the target pod are on a same node, further comprising, when the type of communication is intranode:

applying any existing policies;

setting the forwarding entries at the gateway switch that include forwarding the packets coming from the first pod to the target pod without changing the packets.

5 . The method of claim 4 , further comprising:

dropping the packets when a policy restricts communications between the first pod and the target pod.

6 . The method of claim 1 , wherein the type of communication is intracluster when the controller determines that the first pod and the target pod are on different nodes in a same cluster.

7 . The method of claim 6 , further comprising: setting the forwarding entries at the next switch that include forwarding the packets of the ethernet type and having the first and second identifiers to a next hop in the path.

8 . The method of claim 6 , wherein the next switch is an egress switch, further comprising: setting the forwarding entries that include removing the label header for the packets of the ethernet frame type and including the first and second identifiers, changing the ethernet frame type and forwarding the packets to the target pod.

9 . The method of claim 8 , further comprising: adding a meter for the forwarding entries.

10 . The method of claim 1 , wherein when the path includes an external network and the type of communication is external, further comprising: setting the forwarding entries by:

at the gateway switch:

adding a label header to the packets coming from the first pod and destined for the target pod, wherein the label includes the first identifier of the pod and the second identifier of the target pod, and changing an ethernet type in the packets; and

forwarding the packets according to the path;

at an egress switch:

removing the label header and changing the ethernet type;

setting IP addresses for the first pod and the target pod;

at a second ingress switch:

adding a new label header, changing the ethernet type, and forwarding the packets to a final switch; and

at the final switch:

removing the label header and changing the ethernet type.

11 . The method of claim 1 , further comprising: removing unnecessary header information while the packets are in transit in the software defined network, wherein the unnecessary header information is re-inserted at an egress switch.

12 . A non-transitory storage medium storing therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving packets, at a controller, wherein the packets are generated at a first pod and is destined for a target pod, and wherein the first pod is included in a software defined network;

determining, by the controller, a type of communication for the packets and a path for the packets to the target pod;

configuring flow entries, by the controller, for the packets based on the type of communication for each switch in the path controlled by the controller; and

configuring the packets at a gateway switch, by the gateway switch according to the flow entries, and forwarding the packets according to the flow entries associated with the gateway switch,

wherein, when the type of communication is intracluster:

applying any existing policies; and

setting forwarding entries at the gateway switch that include:

adding a label header to the packets at the gateway switch coming from the first pod and destined for the target pod, wherein the first pod and the target pod are identified by their MAC addresses, wherein the label header includes a first identifier for the first pod and a second identifier for the target pod;

changing an ethernet type to the packets at the gateway switch; and

forwarding the packets to a next switch in the path.

13 . The non-transitory storage medium of claim 12 , further comprising receiving the packets at the gateway switch, wherein the gateway switch is configured to forward the packets to the controller when no flow entries are present at the gateway switch and wherein the gateway switch is an ingress switch.

14 . The non-transitory storage medium of claim 13 , wherein the gateway switch comprises: a programmable switch, a virtual programmable switch, or a SmartNIC (Smart Network Interface Card).

15 . The non-transitory storage medium of claim 12 , where the type of communication is intranode when the controller determines that the first pod and the target pod are on a same node, further comprising when the type of communication is intranode:

applying any existing policies;

setting forwarding entries at the gateway switch that include forwarding the packets coming from the first pod to the target pod without changing the packets.

16 . The non-transitory storage medium of claim 15 , further comprising: dropping the packets when a policy restricts communications between the first pod and the target pod.

17 . The non-transitory storage medium of claim 12 , wherein the type of communication is intracluster when the controller determines that the first pod and the target pod are on different nodes in a same cluster.

18 . The non-transitory storage medium of claim 17 , further comprising: setting forwarding entries at the next switch that include forwarding the packets of the ethernet type and having the first and second identifiers to a next hop in the path.

19 . The non-transitory storage medium of claim 17 , wherein the next switch is an egress switch, further comprising: setting forwarding entries that include removing the label header for the packets of the ethernet frame type and including the first and second identifiers, changing the ethernet frame type, reinserting headers removed at an ingress switch and forwarding the packets to the target pod.

20 . The non-transitory storage medium of claim 12 , wherein when the path includes an external network and the type of communication is external, further comprising setting forwarding entries by:

at the gateway switch:

adding a label header to the packets coming from the first pod and destined for the target pod, wherein the label includes the first identifier of the first pod and the second identifier of the target pod, and adding an ethernet type; and

forwarding the packets according to the path;

at an egress switch:

removing the label header and changing the ethernet type;

setting IP addresses for the first pod and the target pod;

at a second ingress switch:

adding a new label header, changing the ethernet type, and forwarding the packets to a final switch; and

at the final switch:

removing the label header and changing the ethernet type.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2023
From: KHALID, AHMED; AHEARNE, SEÁN
To: DELL PRODUCTS L.P.
Reel/Frame 062831/0519 →
Continuity (1)
Related Publication 20240291910A1 · Aug 29, 2024
References Cited (6)
US 20080137686A1 · Agarwal · 2008 [cited by examiner]
US 20100188976A1 · Rahman · 2010 [cited by examiner]
US 20160205015A1 · Halligan · 2016 [cited by examiner]
US 20180307522A1 · Wu · 2018 [cited by examiner]
US 20190166020A1 · Mommileti · 2019 [cited by examiner]
US 20190222538A1 · Yang · 2019 [cited by examiner]