US2023041056A1PendingUtilityA1

Stateful network slice selection using slice selector as connection termination proxy

Assignee: VMWARE INCPriority: Feb 22, 2019Filed: Oct 22, 2022Published: Feb 9, 2023
Est. expiryFeb 22, 2039(~12.6 yrs left)· nominal 20-yr term from priority
G06F 2009/45595H04W 64/003H04L 41/5054H04L 41/0895H04L 41/046G06F 9/45558G06F 2009/4557H04L 41/40H04L 41/0806H04L 41/048H04W 48/18H04W 76/12
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments provide a method for establishing multiple virtual service networks over multiple datacenters. The method configures, for each virtual service network of the plurality of virtual service networks, a set of machines distributed across the datacenters to implement an ordered set of network services for the virtual service network. The method configures multiple service network selectors executing within the datacenters to receive a data message, select one of the virtual service networks for the data message based on analysis of contents of the data message, determine a location within the datacenters for a machine implementing a first network service of the ordered set of network services for the selected virtual service network, and transmit the data message to the machine implementing the first network service.

Claims

exact text as granted — not AI-modified
1 - 23 . (canceled) 
     
     
         24 . For a network slice selector, a method comprising:
 from an electronic device, receiving a connection initiation message for a connection between the electronic device and a network domain;   exchanging a set of connection initiation messages with the electronic device to set up the connection;   receiving a data message belonging to the connection from the electronic device;   selecting one of a plurality of network slices to which the electronic device has access as the network slice for the connection based on analysis of the received data message; and   forwarding the data message and subsequent data messages belonging to the connection onto the selected network slice to be delivered to the network domain.   
     
     
         25 . The method of  claim 24 , wherein:
 the connection initiation message comprises a transmission control protocol (TCP) SYN message; and   exchanging the set of connection initiation messages comprises sending a SYN-ACK message from the network slice selector to the electronic device and receiving an ACK message from the electronic device.   
     
     
         26 . The method of  claim 25  further comprising, after selecting the network slice and prior to forwarding the data message, forwarding the SYN message and the ACK message onto the selected network slice to be delivered to the network domain. 
     
     
         27 . The method of  claim 24 , wherein the selected network slice comprises a set of network services to be applied to data messages forwarded onto the selected network slice. 
     
     
         28 . The method of  claim 27 , wherein the selected network slice is a first network slice and the set of network services is a first set of network services, wherein the plurality of network slices comprises at least a second network slice that comprises a second set of network services to be applied to data messages forwarded onto the second network slice. 
     
     
         29 . The method of  claim 27 , wherein at least a subset of the network services are implemented as virtualized network functions (VNFs) that execute in at least two different datacenters. 
     
     
         30 . The method of  claim 24 , wherein forwarding the data message onto the selected network slice comprises:
 forwarding the data message to a first network service of the selected network slice;   receiving the data message from the first network service after the first network service processes the data message; and   forwarding the data message to a second network service of the selected network slice.   
     
     
         31 . The method of  claim 24 , wherein the network slice selector executes in a first datacenter, wherein forwarding the data message onto the selected network slice comprises:
 forwarding the data message to a first network service of the selected network slice that executes in the first datacenter;   receiving the data message from the first network service after the first network service processes the data message; and   forwarding the data message to a service chaining module that executes in a second datacenter, wherein the service chaining module forwards the data message to a second network service that executes in the second datacenter.   
     
     
         32 . The method of  claim 24 , wherein the network slice selector is a flow-based forwarding element executing in a virtual machine. 
     
     
         33 . The method of  claim 24 , wherein the network slice selector executes in a container. 
     
     
         34 . A non-transitory machine readable medium storing a network slice selector for execution by at least one processing unit, the network slice selector comprising sets of instructions for:
 receiving, from an electronic device, a connection initiation message for a connection between the electronic device and a network domain;   exchanging a set of connection initiation messages with the electronic device to set up the connection;   receiving a data message belonging to the connection from the electronic device;   selecting one of a plurality of network slices to which the electronic device has access as the network slice for the connection based on analysis of the received data message; and   forwarding the data message and subsequent data messages belonging to the connection onto the selected network slice to be delivered to the network domain.   
     
     
         35 . The non-transitory machine readable medium of  claim 34 , wherein:
 the connection initiation message comprises a transmission control protocol (TCP) SYN message; and   the set of instructions for exchanging the set of connection initiation messages comprises a set of instructions for sending a SYN-ACK message from the network slice selector to the electronic device and receiving an ACK message from the electronic device.   
     
     
         36 . The non-transitory machine readable medium of  claim 35 , wherein the network slice selector further comprises a set of instructions for forwarding the SYN message and the ACK message onto the selected network slice to be delivered to the network domain, after selecting the network slice and prior to forwarding the data message. 
     
     
         37 . The non-transitory machine readable medium of  claim 34 , wherein the selected network slice comprises a set of network services to be applied to data messages forwarded onto the selected network slice. 
     
     
         38 . The non-transitory machine readable medium of  claim 37 , wherein the selected network slice is a first network slice and the set of network services is a first set of network services, wherein the plurality of network slices comprises at least a second network slice that comprises a second set of network services to be applied to data messages forwarded onto the second network slice. 
     
     
         39 . The non-transitory machine readable medium of  claim 37 , wherein at least a subset of the network services are implemented as virtualized network functions (VNFs) that execute in at least two different datacenters. 
     
     
         40 . The non-transitory machine readable medium of  claim 34 , wherein the set of instructions for forwarding the data message onto the selected network slice comprises sets of instructions for:
 forwarding the data message to a first network service of the selected network slice;   receiving the data message from the first network service after the first network service processes the data message; and   forwarding the data message to a second network service of the selected network slice.   
     
     
         41 . The non-transitory machine readable medium of  claim 34 , wherein the network slice selector executes in a first datacenter, wherein the set of instructions for forwarding the data message onto the selected network slice comprises sets of instructions for:
 forwarding the data message to a first network service of the selected network slice that executes in the first datacenter;   receiving the data message from the first network service after the first network service processes the data message; and   forwarding the data message to a service chaining module that executes in a second datacenter, wherein the service chaining module forwards the data message to a second network service that executes in the second datacenter.   
     
     
         42 . A system comprising:
 a set of host computers executing network services for a plurality of network slices; and   a computing device executing a network slice selector that:
 receives, from an electronic device, a connection initiation message for a connection between the electronic device and a network domain; 
 exchanges a set of connection initiation messages with the electronic device to set up the connection; 
 receives a data message belonging to the connection from the electronic device; 
 selects one of the plurality of network slices to which the electronic device has access as the network slice for the connection based on analysis of the received data message; and 
 forwards the data message and subsequent data messages belonging to the connection to the selected network slice to be delivered to the network domain. 
   
     
     
         43 . The system of  claim 42 , wherein the network slice selector forwards the data message onto the selected network slice by:
 forwarding the data message to a first network service of the selected network slice;   receiving the data message from the first network service after the first network service processes the data message; and   forwarding the data message to a second network service of the selected network slice.

Join the waitlist — get patent alerts

Track US2023041056A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.