EP2569902B1

Interconnecting members of a virtual network

Abstract

This record has no abstract on file.

EP2569902B1, drawing sheet 1
Sheet 1 of 6

Term

4.6 yearsleft in the term

Expires 27 April 2031.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 3 independent, 10 dependent

  1. 1
    One or more computer-readable media having computer-executable instructions embodied thereon that, when executed, perform a method for managing distribution of data packets between a plurality of members of a virtual network ,V-net, that are isolated from other machines on a network, the method comprising:providing (702) a first V-net that comprises the plurality of members running, in part, within at least one data center, wherein the plurality of members include an originating network adapter and a destination network adapter;detecting (704) the originating network adapter attempting to transmit one or more data packets to the destination network adapter, wherein the one or more data packets are structured with a header that includes a target identifier of the destination network adapter;performing (706) a resolution process that comprises: (a) accessing (708) a forwarding table that is associated with the first V-net, wherein the forwarding table represents a mapping between the plurality of members of the first V-net and VM switches that are each located on respective nodes within the at least one data center, wherein the mapping is designed according to communication policies that govern data-packet traffic between the plurality of members, and wherein the forwarding table is maintained within a directory server;and (b) discovering (710) routing information associated with a destination-side VM switch, listed in the forwarding table, that corresponds to the target identifier;modifying (712) the one or more data packets to include the routing information;transmitting (714) the one or more modified data packets from a source-side VM switch to the destination-side VM-switch;and sending, by the destination-side switch, the target identifier to the directory server to verify that delivery was approved by the communication policies and corresponds with the forwarding table.
  2. 12
    A computer system for supporting and isolating communications between network adapters that are allocated to a service application, the computer system comprising:an originating network adapter (250) that generates one or more data packets (260) structured with headers that include a target identifier, wherein the target identifier points to a destination network adapter (240);the destination network adapter that resides on a first node of at least one data center, wherein the destination network adapter and the originating network adapter are members of a virtual network, V-net, allocated to a service application running, in part, in the at least one data center;a directory server (220) that maintains a forwarding table associated with the V-net, wherein the forwarding table is populated with identifiers of the members of the V-net that are mapped to respective VM switches and wherein the mapping is designed according to communication policies that govern data-packet traffic between the members;a destination-side VM switch (221) that resides on the first node of the at least one data center;and a source-side VM switch (223) that resides with the originating network adapter on a second node of the at least one data center, wherein the source-side VM switch reads the headers of the one or more data packets and conveys the target identifier to the directory server, wherein the directory server compares the target identifier against the forwarding table and determines whether the destination-side VM switch is mapped to the target identifier, wherein, when the destination-side VM switch is mapped to the target identifier, the source-side VM switch appends a frame to the headers of the one or more data packets that includes a locator of the destination-side VM switch, and wherein, incident to appending a frame to the headers, the source-side VM switch forwards the one or more data packets to the destination-side VM switch, wherein the destination-side VM switch receives the one or more data packets, restores the headers by removing the frame and sends the target identifier to the directory server to verify that delivery was approved by the communication policies and corresponds with the forwarding table.
  3. 13
    A computerized method for managing distribution of data packets between a plurality of members of a virtual network, V-net, that are isolated from other machines on a network, the method comprising:providing (702) a first V-net that comprises the plurality of members running, in part, within at least one data center, wherein the plurality of members include an originating network adapter and a destination network adapter;detecting (704) the originating network adapter attempting to transmit one or more data packets to the destination network adapter, wherein the one or more data packets are structured with a header that includes a target identifier of the destination network adapter;performing (706) a resolution process that comprises: (a) accessing (708) a forwarding table that is associated with the first V-net, wherein the forwarding table represents a mapping between the plurality of members of the first V-net and VM switches that are each located on respective nodes within the at least one data center, wherein the mapping is designed according to communication policies that govern data-packet traffic between the plurality of members, and wherein the forwarding table is maintained within a directory server;and (b) discovering (710) routing information associated with a destination-side VM switch, listed in the forwarding table, that corresponds to the target identifier;modifying (712) the one or more data packets to include the routing information;transmitting (714) the one or more modified data packets from a source-side VM switch to the destination-side VM-switch;and sending, by the destination-side switch, the target identifier to the directory server to verify that delivery was approved by the communication policies and corresponds with the forwarding table.