Authentication for logical overlay network traffic

US11470071B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11470071-B2
Application numberUS-202016852553-A
CountryUS
Kind codeB2
Filing dateApr 20, 2020
Priority dateApr 20, 2020
Publication dateOct 11, 2022
Grant dateOct 11, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Example methods and systems for authentication for logical overlay network traffic are described. In one example, a first computer system may detect an inner packet and generate authentication information associated with the inner packet based on control information from a management entity. The authentication information may indicate that the inner packet originates from a trusted zone. The first computer system may further generate an encapsulated packet by encapsulating the inner packet with an outer header that specifies the authentication information, and send the encapsulated packet towards the second virtualized computing instance to cause a second computer system to verify that the inner packet originates from the trusted zone based on the authentication information.

First claim

Opening claim text (preview).

We claim: 1. A method for a first computer system to perform authentication for logical overlay network traffic, the method comprising: detecting an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance; based on control information from a manager, generating authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone; generating an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and sending the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance. 2. The method of claim 1 , wherein sending the encapsulated packet comprises: sending the encapsulated packet via a first virtual tunnel endpoint (VTEP) supported by the first computer system to a second VTEP supported by the second computer system, wherein the first VTEP is an open interface that is accessible by a source from a non-trusted zone. 3. The method of claim 2 , wherein generating the authentication information comprises: identifying, by a managed bridge supported by the first computer system, authentication key information from the control information; and generating, by the managed bridge, the authentication information based on the authentication key information and the inner packet, wherein the second computer system is configured to verify the authentication information based on the same authentication key. 4. The method of claim 2 , wherein generating the encapsulated packet comprises: generating the encapsulated packet using a transport bridge that is supported by the first computer system but not managed by the manager. 5. The method of claim 1 , wherein generating the encapsulated packet comprises: configuring an option field in the outer header of the encapsulated packet to include the authentication information. 6. The method of claim 1 , further comprising: receiving, from the second computer system or a third computer system, an ingress encapsulated packet that includes an ingress inner packet and an ingress outer header; extracting ingress authentication information from the ingress outer header; and based on the ingress authentication information and the control information from the manager, determining whether the ingress inner packet originates from the trusted zone. 7. The method of claim 6 , further comprising: in response to determination that the ingress inner packet does not originate from the trusted zone, dropping the ingress inner packet. 8. A non-transitory computer-readable storage medium that includes a set of instructions which, in response to execution by a processor of a first computer system, cause the processor to perform authentication for logical overlay network traffic, wherein the method comprises: detecting an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance; based on control information from a manager, generating authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone; generating an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and sending the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance. 9. The non-transitory computer-readable storage medium of claim 8 , wherein sending the encapsulated packet comprises: sending the encapsulated packet via a first virtual tunnel endpoint (VTEP) supported by the first computer system to a second VTEP supported by the second computer system, wherein the first VTEP is an open interface that is accessible by a source from a non-trusted zone. 10. The non-transitory computer-readable storage medium of claim 9 , wherein generating the authentication information comprises: identifying, by a managed bridge supported by the first computer system, authentication key information from the control information; and generating, by the managed bridge, the authentication information based on the authentication key information and the inner packet, wherein the second computer system is configured to verify the authentication information based on the same authentication key. 11. The non-transitory computer-readable storage medium of claim 9 , wherein generating the encapsulated packet comprises: generating the encapsulated packet using a transport bridge that is supported by the first computer system but not managed by the manager. 12. The non-transitory computer-readable storage medium of claim 8 , wherein generating the encapsulated packet comprises: configuring an option field in the outer header of the encapsulated packet to include the authentication information. 13. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises: receiving, from the second computer system or a third computer system, an ingress encapsulated packet that includes an ingress inner packet and an ingress outer header; extracting ingress authentication information from the ingress outer header; and based on the ingress authentication information and the control information from the manager, determining whether the ingress inner packet originates from the trusted zone. 14. The non-transitory computer-readable storage medium of claim 13 , wherein the method further comprises: in response to determination that the ingress inner packet does not originate from the trusted zone, dropping the ingress inner packet. 15. A computer system, being a first computer system, comprising: a processor; and a non-transitory computer-readable medium having stored thereon instructions that, in response to execution by the processor, cause the processor to: detect an inner packet having an inner header that is addressed from a first virtualized computing instance to a second virtualized computing instance; based on control information from a manager, generate authentication information associated with the inner packet, wherein the authentication information indicates that the inner packet originates from a trusted zone; generate an encapsulated packet by encapsulating the inner packet with an outer header specifying the authentication information, wherein the outer header is addressed from the first computer system to a second computer system; and send the encapsulated packet towards the second virtualized computing instance to cause the second computer system to verify that the inner packet originates from the trusted zone based on the authentication information and to forward the inner packet towards the second virtualized computing instance. 16. The computer system of claim 15 , wherein the instructions that cause the processor to send the encapsul

Assignees

Inventors

Classifications

  • the source of the received data · CPC title

  • Isolation or security of virtual machine instances · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Hypervisor-specific management and integration aspects · CPC title

  • Virtual private networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11470071B2 cover?
Example methods and systems for authentication for logical overlay network traffic are described. In one example, a first computer system may detect an inner packet and generate authentication information associated with the inner packet based on control information from a management entity. The authentication information may indicate that the inner packet originates from a trusted zone. The fi…
Who is the assignee on this patent?
Vmware Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 11 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).