System and method for flow table management

By using a hardware-configured flow management system with high-speed caching and precise matching engine, the high computational resource and complexity issues of network switches in flow tracing and security management are solved, achieving efficient flow table management and high-scale flow processing, and improving communication efficiency and consistency.

CN116866284BActive Publication Date: 2025-11-11AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211721605.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-01-31
Filing Date
2022-12-30
Publication Date
2025-11-11
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

Existing network switches face challenges in flow tracing and security management, including high computational resource requirements, complexity, and communication bandwidth limitations. In particular, when handling large volumes of flows, efficient flow table management is difficult to achieve.

Method used

The flow management system employs a hardware configuration, including memory and processor, and utilizes a cache and precise matching engine to manage flow tables. It supports large flow table sizes, high-speed flow learning and aging, and combines distributed systems and complex flow lifecycles to achieve efficient flow management.

Benefits of technology

It improves the efficiency and scalability of flow table management, supports the processing of hundreds of millions of flows, reduces computing resource requirements, and enhances communication bandwidth and operational consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116866284B_ABST
    Figure CN116866284B_ABST
Patent Text Reader

Abstract

This application relates to systems and methods for flow table management. A switch includes a memory containing flow tables. The flow tables contain a flow key database and a flow policy database for flows in a network associated with the switch. The switch includes a security processor containing an exact matching engine. The exact matching engine manages the flow tables in the memory. The exact matching engine includes a learning cache configured to store key entries stored in the flow key database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to systems and methods for transmitting data in a network environment. More specifically, this disclosure relates to systems and methods for flow management in a network. Background Technology

[0002] The communications industry is rapidly evolving to adapt to emerging technologies and growing customer demands. New network applications and the need for higher performance require communications networks to operate at faster speeds (e.g., higher bandwidth). Many communications providers are using packet switching technology to achieve these goals. Storage, communications, entertainment, and computer systems utilize switches, such as routers, packet switching systems, and other network data processing devices, to transmit packets, frames, or other data units.

[0003] A switch is a network component that controls the distribution of messages or data packets, frames, or other data units based on the address information contained within each data packet. As used herein, the term "data packet" is not limited to a specific protocol or format of a data unit or frame. The term "data packet" includes, but is not limited to, cells, frames, datagrams, bridging protocol data unit packets, packet data, and other data structures used in network communications. Computer and network security are seriously threatened by security attacks based on software vulnerabilities and other issues. Flow tracing in a network can be used to detect a wide variety of security attacks. Secure switches in a network use large flow tables to perform flow tracing, which work in conjunction with various device components such as processors, external memory, and central processing unit (CPU) subsystems. Flow tracing can be complex, require computational / networking resources, and may impact communication bandwidth. Summary of the Invention

[0004] In one aspect, this application relates to a switch comprising: a memory including flow tables, the flow tables including a flow key database and a flow policy database for flows in a network associated with the switch; and a processor including an engine, wherein the engine is a hardware component configured to manage the flow tables in the memory, wherein the engine includes a cache configured to store key entries stored in the flow key database.

[0005] On the other hand, this application relates to a flow management method, the method comprising: receiving a packet at a switch; determining a working processor identification for the packet; performing flow table entry learning using the working processor identification of a flow associated with the packet to obtain data of entries for the flow; and writing the entries of the flow into a learning cache integrated with the switch.

[0006] On the other hand, this application relates to an apparatus comprising: a memory configured to store flow tables; and a processor configured for packet processing and separate from the memory, the processor including a cache and an engine configured to manage the flow tables, the cache for placing entries of new flows into the flow tables, the engine being a hardware unit. Attached Figure Description

[0007] The various objects, aspects, features, and advantages of some embodiments of this specification will become more apparent and better understood through a detailed description taken in conjunction with the accompanying drawings, wherein the same reference characters identify corresponding elements throughout. In the drawings, the same reference numerals generally indicate the same, functionally similar, and / or structurally similar elements.

[0008] Figure 1 This is a general block diagram depicting a network device within a network according to some embodiments;

[0009] Figure 2 It is possible according to some embodiments to Figure 1 A block diagram of the security switch used in the network described herein;

[0010] Figure 3 This is a block diagram of a system comprising a set of network security switches according to some embodiments, each network security switch being similar to... Figure 2 The security switch described in the document;

[0011] Figure 4 According to some embodiments Figure 3 A block diagram of the flow table of the ingress security switch in the system described;

[0012] Figure 5 According to some embodiments Figure 3 A block diagram of the flow table of the egress security switch in the system described herein;

[0013] Figure 6 This is a demonstration based on some embodiments. Figure 2 The flowchart of the temporary learning operation of the security switch is described in the document;

[0014] Figure 7 According to some embodiments Figure 2 The block diagram of the cache of the security switch described in the document;

[0015] Figure 8 It is included according to some embodiments Figure 2 The block diagram of the packet processor for the bitmap memory of the security switch described herein; and

[0016] Figure 9 It is included according to some embodiments Figure 2 The block diagram of the compressed FIFO packet processor of the security switch described herein.

[0017] Details of various embodiments of the method and system are set forth in the accompanying drawings and the description below. Detailed Implementation

[0018] Secure switches or other network devices may perform flow tracing in association with various device components, such as packet processors, external memory, and CPU subsystems. In some embodiments, flow tracing may be performed separately from forwarding lookup operations (e.g., Ethernet Layer 2 / Layer 3) and may be performed before allowing flows into the network. In some embodiments, the system and method support very high-volume flows (e.g., hundreds of millions of flows). In some embodiments, memory external to the processor of the secure switch is provided in the package along with the processor. The memory may be dynamic random access memory (DRAM), such as double data rate synchronous dynamic random access memory (DDR SDRAM) or high bandwidth (HB) memory.

[0019] In some embodiments, the switch is configured to perform complex flow management. Flow management systems and methods can achieve larger flow table sizes, higher flow learning / aging rates, distributed system support, complex flow lifecycles, and operational consistency at a scale greater than conventional flow management techniques. In some embodiments, the systems and methods utilize flow tables (also known as flow key tables or hash tables) with hundreds of millions of entries (e.g., one entry per flow, where the flow is a unidirectional communication flow identified by source and destination identifiers). In some embodiments, each entry is a few hundred bits wide and includes a key and a short policy.

[0020] In some embodiments, the flow table utilizes techniques and cohesion engines to implement flow management with high-performance metrics (e.g., more than 100 million flow entries, more than 100 million block key lookups per second, more than 10 million learning and aging events per second, and more than 100,000 CPU update operations per second). In some embodiments, the system and method are used in a distributed system with multiple working central processing units having multiple flow processing nodes and a management security switch.

[0021] In some embodiments, the switch includes a memory and a security processor. The security processor includes a memory controller, a cache coherency management unit, a precise matching engine, and a packet processor. The security processor is configured to perform hardware-based reordering of entries in flow tables stored in the memory.

[0022] In some embodiments, the switch includes a memory containing flow tables. The flow tables contain a flow key database and a flow policy database for flows in the network associated with the switch. The switch includes a security processor containing an exact match engine. The exact match engine manages the flow tables in the memory. The exact match engine includes a learning cache configured to store key entries stored in the flow key database.

[0023] In some embodiments, the switch includes memory and a security processor. The security processor includes an exact match engine. The exact match engine manages flow tables in memory. The flow tables are configured to have a flow key database separate from the flow policy database, and the exact match engine includes a learning cache configured to store key entries.

[0024] In some embodiments, the security processor is configured to provide sophisticated flow management that enables higher flow table scalability, higher flow learning / aging rates, distributed system support, complex flow lifecycles, and / or operational consistency. In some embodiments, the security processor is configured to provide enhanced learning rates, enhanced aging rates, and / or table indirection (or indirect references) to achieve scalability while performing sophisticated flow management. Enhanced learning rates refer to identifying new flows and placing entries for them into the flow table faster than conventional flow management techniques. Enhanced aging rates refer to identifying no-longer-used flows and removing entries from the flow table faster than conventional flow management techniques. Providing table indirection refers to providing a table configuration where references or data containers in the flow table are used to obtain the values ​​of the flows.

[0025] In some embodiments, the security processor is disposed on a single integrated circuit (IC) substrate. In some embodiments, the memory is disposed on a separate IC device. In some embodiments, the security processor and memory are in a single package (e.g., contained in a housing, such as a single housing containing multiple ICs and an interposer and having pins, solder balls, contacts, or other leads or conductors for electrical connection with other devices). In some embodiments, the security processor and memory are disposed on an interposer.

[0026] In some embodiments, the security processor is configured to pipeline simple cases (e.g., cases that do not require reordering) and serialize reordered cases. In some embodiments, the security processor includes a hardware-based reordering engine.

[0027] In some embodiments, the flow management method includes receiving packets at a switch, determining a work processor identifier, performing flow table learning for entries using the work processor identifier, and writing entries to a learning cache integrated with the switch.

[0028] In some embodiments, the method further includes determining whether the learning cache is full before writing the entry. In some embodiments, the method further includes performing a bucket read after writing the entry to the learning cache. In some embodiments, the bucket is a storage carrier in the flow table of the stream and can store parameters of the entry. In some embodiments, the method further includes initiating a reordering operation if the bucket is full. In some embodiments, the method further includes determining whether an empty bucket exists, and if an empty bucket exists, inserting the entry into the flow table.

[0029] In some embodiments, an apparatus includes memory configured to store flow tables and a processor separate from the memory and configured for packet processing. The processor includes a cache, an engine, and a packet processor. The engine is configured to manage the flow tables. The cache is learned to store entries for new flows placed in the flow tables.

[0030] In some embodiments, the processor is configured for hardware reordering, learning rate enhancement, aging rate enhancement, and table indirect retrieval to achieve scaling, while performing complex flow management. In some embodiments, the flow table includes key entries and policy index entries. In some embodiments, the key entries and policy index entries are decoupled from each other. In some embodiments, for bidirectional flows, two key entries point to or link to a single policy entry.

[0031] Network devices

[0032] refer to Figure 1 An exemplary configuration of network 8 includes network device 10. Network device 10 may be a hardware-based and / or software-based device, such as a network switch for moving data packets within network 8 based on address information contained within the packets themselves. In some embodiments, network device 10 additionally and / or alternatively performs router operations. Network device 10 may be any device configured to communicate data within or across the network. Additionally, although this disclosure may sometimes refer to "switch" and "switching" for the purposes of this description, the terms "switch" and "switching" may include both switching and routing. The term hardware refers to circuitry configured for a specific operation that does not have an instruction set loaded onto a general-purpose processor to perform that specific operation. The circuitry may be configured with data in registers, memory, or other storage devices and may work with a software-instructed processor to perform network operations. Examples of hardware include special-purpose circuitry, ASICs, programmable logic devices, non-programmable logic devices, arithmetic logic units, counters, caches, memory or cache management units, matching engines, combinations thereof, etc.

[0033] In some embodiments, network device 10 is a network switch functionally connected to CPU 12 and other external devices 14. External devices 14 may be other external processors, external memory, other network devices (e.g., servers, routers, or computers), and / or other network switches, access points, and routers. External devices 14 can expand the switching capacity in network 8. CPU 12 can be used to program network device 10 based on desired rules or protocols for packet processing. Network device 10 may also include other components not shown. For example, network device 10 may include an Ethernet port interface controller, a Gigabit port interface controller, an Internet port interface controller, and additional buffers.

[0034] Data received at port 24 from external devices(s) 16, 18, 20, and 22 may be processed by network device 10 independently of CPU 12 based on programmed instructions or packet processing rules. Based on the programmed instructions or packet processing rules, the processed data is redistributed across port 24 to the appropriate external devices(s) 16, 18, 20, and 22. Network device 10 may be an integrated, modular, single-chip solution. In some embodiments, network device 10 includes an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a communication processor, or any other type and form of dedicated silicon logic or processing circuitry capable of processing and exchanging packets or other data units according to packet processing rules. Additionally and / or alternatively, network device 10 may be several individual components on a circuit board or interposer, or may be implemented on one or more general-purpose devices configured via software.

[0035] Packet processing may include reading, modifying, and classifying packets; altering packet forwarding behavior; removing and / or appending information to packets; mirroring packets to another port; storing packets in a buffer; reordering packets within a series of packets; sending packets to a service queue; recirculating or looping back packets; or changing the type of packets. Any of devices 10, 16, 18, 20, and 22 may be configured as a switch configured to perform flow management.

[0036] refer to Figure 2 System 200 includes a host processor 202 and a security switch 204. The security switch 204 can be used as a network 8 ( Figure 1The secure switch 204 may be any of the network device 10 or external devices 16, 18, and 20 in the network, or may be an additional device that communicates with devices 10, 16, 18, 20, and 22. In some embodiments, the secure switch 204 is provided as a system in an integrated circuit (IC) package having a secure processor 206, external memory 212, and external memory 214. In some embodiments, the secure processor 206, external memory 212, and external memory 214 are each separate ICs disposed on an interposer layer in the integrated circuit (IC) package. The secure switch 204 may be embodied as a 2 / 3x HBM2E 4 / 8 stacked device. In some embodiments, the secure switch 204 is a non-secure network switch.

[0037] External memories 212 and 214 are any type of storage device and communicate with the security switch 204 via an intermediary layer. In some embodiments, external memories 212 and 214 are high-bandwidth (HB) memory devices. In some embodiments, external memories 212 and 214 are dynamic random access memory (DRAM) ICs. Although in Figure 2 The image shows two memory devices (external memory 212 and external memory 214), but a single memory device or three or more memory devices may be used.

[0038] External memories 212 and 214 each have a large storage capacity and are capable of storing flow table 207 with hundreds of millions of entries. In some embodiments, each entry is several hundred bits wide and includes a key and a short policy. Each key contains a set of grouping fields that uniquely identify the flow. Each short policy contains inherent rules / actions applicable to the flow.

[0039] According to some embodiments, the security processor 206 of the security switch 204 is provided as a hardware unit for processing packets and performing flow management as described below. In some embodiments, the security processor 206 of the security switch 204 includes an external memory controller 220 communicating with external memories 212 and 214, a cache and consistency management controller 226, a packetization control interface 228, a precise matching engine 230, an internal processor 222, a packet processor (PP) 234, and a service management unit 232.

[0040] Internal processor 222 includes an Advanced Reduced Instruction Set Computer (RISC) machine (ARM) 224. In some embodiments, cache and coherence management controller 226 communicates with external memory controller 220 and exact match engine 230. Cache and coherence management controller 226 uses read and write caches (e.g., ... Figure 7The read cache 712 and write cache 714 in the memory manage external memory transactions with the memory 212 and 214. The service management unit 232 uses network monitoring tools and management technologies, such as bandwidth monitoring, deep packet inspection, and application-based routing, to ensure optimal network operation.

[0041] External memory controller 220 communicates with cache and coherence management controller 226 and external memories 212 and 214. External memory controller 220 handles the physical interface from security switch 204 to external memories 212 and 214. The combination of controller 220, cache and coherence management controller 226, and external memories 212 and 214 constitutes an HBM subsystem (e.g., in some embodiments, HBM subsystem 840). Figure 8 In some embodiments, the external memory controller 220 and the cache and coherence management controller 226 are hardware units.

[0042] The exact matching engine 230 manages the flow table 207 (e.g., a flow key table or hash table) maintained in one or two external memories 212 and 214. The exact matching engine 230 uses a matching and caching mechanism (e.g., a learning cache 704). Figure 7 The hardware unit of flow table 207 is used to appropriately write entries into the flow table. The learning cache 704 is a cache for storing entries of recently learned flows (e.g., the learning cache is a cache for storing entries of flows that will be written into flow table 207). In some embodiments, flow table 207 includes a flow logical database. For example, flow table 207 includes the following databases (DBs): Flow-{Key + Policy}-DB (Hash, 200M), Flow-Policy-DB (Index, 200M), Short Flow-Status-DB (Index, 200M), and Flow-Status-DB (Index, 200M Ingress + 200M Egress). Flow table 207 is used in the flow learning and flow aging operations implemented in the hardware, as explained below.

[0043] The internal processor 222 is a local CPU and may be housed on a different line card in the chassis system (e.g., a host CPU line card) or integrated with the security switch 204 (e.g., integrated with processor 206). In some embodiments, the line card is connected via a peripheral component interconnect e (PCIe) subsystem. In some embodiments, the local CPU is embedded within the internal processor 222 (e.g., as an advanced RISC machine (ARM) processor 224). The internal processor 222 is coupled to the precise matching engine 230 and the host processor 202.

[0044] In some embodiments, the host processor 202 is a worker CPU (WCPU). In some embodiments, the WCPU is located on a line card in the chassis system, different from the security switch 204. In some embodiments, the host processor 202 includes 64 CPUs, each with 32 cores.

[0045] The packet control interface 228 is coupled to the precise matching engine 230. In some embodiments, the packet control interface 228 reads the flow table 207 and reliably delivers the flow records to the WCPU (e.g., host processor 202) or a backup network switch (e.g., backup security switch 308). In some embodiments, the packet control interface 228 is a hardware unit. In some embodiments, the packet control interface 228 is a highly reliable delivery engine.

[0046] In some embodiments, the security switch 204 supports up to hundreds of millions of flows. Each flow is uniquely identified using a 5-tuple and a Zone_ID, where the Zone_ID is similar to a class_ID in some embodiments. As part of flow tracing, the security switch 204 tracks flow state and flow statistics (ingress and egress). Multiple logical databases are maintained in the HBM subsystem, such as flow key, flow policy, flow state, and flow statistics databases (e.g., associated with external memories 212 and 214). Collectively, this data may be referred to as the flow database.

[0047] Security switch 204 maintains flow table 207. In some embodiments, hardware units (e.g., exact match engine 230) identify new flows and use a flow learning process to insert the flow key, flow policy, flow state, and flow statistics of the new flow into the flow database. In some embodiments, hardware units (e.g., exact match engine 230) use a flow aging process to identify inactive flows. In some embodiments, security switch 204 removes identified inactive flows from flow table 207.

[0048] refer to Figure 3 System 300 includes an ingress security switch 304, a backup security switch 308, a switch structure 310, a WCPU 312, and an egress security switch 314. In some embodiments, the ingress security switch 304, the backup security switch 308, and the egress security switch 314 may be similar to security switch 204 ( Figure 2 WCPU 312 is similar to host processor 202. In some embodiments, switch architecture 310 is any network topology and may include network nodes interconnected via one or more network switches, such as crossover switches and other switches.

[0049] Ingress security switch 304 provides an ingress point for packets entering system 300. Egress security switch 314 provides an egress point for packets leaving system 300. Backup security switch 308 provides redundancy and support for ingress security switch 304 and / or egress security switch 314. Packets transmitted in system 300 contain one or more flow records and are transmitted between ingress security switch 304, backup security switch 308, egress security switch 314, and WCPU 312. Each flow record contains a 5-tuple, zone ID, local flow ID (LFID), egress LFID (E-LFID), and a new flow policy (e.g., {flow key (5-tuple + ZONE_ID), I-LFID, E-LFID, new flow policy}). Switches 304, 314, and 308 update the flow table 207 of the flow accordingly. After this update, all packets of the flow are forwarded according to the updated policy, and the flow entry is marked as final. A flow policy is a software installation strategy applied to the grouping of flows, and in some embodiments may include a short policy (also known as a short flow policy).

[0050] In some embodiments, switches 304, 314, and 308 update the flow ID (FID). Each of switches 304, 314, and 308 can communicate with WCPU 312 using the FID as an identifier for a flow. In some embodiments, the local flow ID (LFID) is a flow key database in flow table 207 (e.g., database 402). Figure 4 )) and flow strategy / status / statistics databases (e.g., databases 406, 408, and 410) Figure 4 The indirect values ​​between )) provide a logical flow identifier with a unique index. In some embodiments, the LFID is a unique free pointer assigned by switch 304 to the first packet of a new flow.

[0051] In ingress operations, the LFID (also known as the ingress LFID) can be used as the flow table 207 of switch 304. Figure 2 The flow policy / state / ingress statistics database is indexed in the flow statistics database. Flow state contains identifiers representing the state of the flow and is updated by hardware on each packet in some embodiments. In some embodiments, flow statistics include counters associated with the flow and are maintained by hardware units of switch 304.

[0052] The Egress LFID (E-LFID) is a unique free pointer assigned to a flow leaving switch 314. This parameter is used for flow egress statistics in switch 314 (e.g., database 502). Figure 5The Global Flow ID (GFID) is an index for the flow. It can contain ingress and egress identifiers (e.g., ingress_switch_ID, ingress LFID, egress switch ID, egress LFID) and is a system-wide unique identifier for the flow. The association between the flow and the GFID is maintained by WCPU 312.

[0053] In some embodiments, switches 304, 314, and 308 are configured to manage the flow lifecycle. For example, the flow lifecycle may have phases such as Temporary Flow Learning (TFL), Final Flow Learning (FFL), and Post-Final Flow Learning (PFFL). In some embodiments, TFL may be used to ensure that all initial packets of a flow are sent to the same WCPU 312. In some embodiments, FFL may be used to apply a policy specified by the WCPU to all remaining packets of a flow. In some embodiments, PFFL may be used to clean up flow table 207 and for standby operations.

[0054] TFL may involve the following exemplary operations:

[0055] 1. Stream miss: A new stream has been received, but the stream lookup failed.

[0056] 2. TFL Startup: TFL is powered by hardware (e.g., processor 206). Figure 2 Start up to register the new flow in flow table 207.

[0057] 3. Obtain WCPU_ID: Group processor (e.g., processor 206 ( Figure 2 Perform load balancing to obtain a unique WCPU_ID, so that all packets of a given flow are sent to a WCPU 312.

[0058] 4. Obtain LF_ID: Flow table 207 generates LF_ID to store flow policies / states / status in the later stages of the flow lifecycle.

[0059] 5. Obtain timestamp: Group processor (e.g., processor 206) Figure 2 Provides a timestamp to identify the current time of the learning stream.

[0060] 6. Update stream entries: Use {WCPU_ID, LF_ID, timestamp}.

[0061] FFL may involve the following exemplary operations:

[0062] 1. The WCPU 312 processes the first few packets of the stream and establishes policies / states / statistics for subsequent packets of the stream.

[0063] 2. Apply the policy specified by WCPU to all subsequent packets of the flow in flow table 207.

[0064] 3. Also update the status / status of all subsequent groups of the flow in flow table 207.

[0065] PFFL may involve the following exemplary operations:

[0066] 1. Packetized interface: Flow table 207 provides a packet-based interface to WCPU 312 to support periodic standby.

[0067] 2. Aging: Streams eventually end, some taking a few milliseconds, others a few seconds or even longer. Once a stream ends, the stream entry is aged to make room for a new stream entry.

[0068] In some embodiments, switches 304, 314, and 308 are configured to provide complex flow management that enables higher flow table scalability, higher flow learning / aging rates, distributed system support, complex flow lifecycles, and operational consistency. In some embodiments, system 300 using switches 304, 314, and 308 provides operations such as hardware reordering, learning caching, learning rate enhancement, aging rate enhancement, and table indirection to achieve scalability while performing complex flow management.

[0069] In some embodiments, a reordering algorithm (e.g., cuckoo hashing, cuckoo filtering, or other algorithms) is used to perform flow key lookup. Switches 304, 314, and 308 are configured to use hardware for reordering. If flow table 207 (e.g., a hash table implemented using the cuckoo hashing algorithm) has no space in any hash storage area, the table is reordered (e.g., entries need to be moved) to create space for new learning entries. The hardware of switches 304, 314, and 308 is configured to support higher learning rate requirements by supporting multi-level reordering to support higher flow sizes. The hardware of switches 304, 314, and 308 includes a hardware-based reordering engine. In some embodiments, the hardware reordering engine is configured to determine whether the storage area in flow table 207 for new entries is full and reorder the entries in flow table 207 according to the cuckoo algorithm. Hash table organization (number of parallel accesses and number of entries per access) may be designed to provide high memory utilization (e.g., 80%). In some embodiments, the reordering algorithm may be depth-first, breadth-first, or another algorithm of user choice. In some embodiments, a linear hash algorithm is utilized. In some embodiments, the hardware supports a mixture of full-width and half-width entries, which can be used for various types of protocols (e.g., Internet Protocol (IP)v4 and IPv6).

[0070] There is a time window between command issuance and command completion because external memory latency is significant and variable. To ensure operational consistency during this period (e.g., as if the time gap did not exist), switches 304, 314, and 308 are configured to use a learning cache (e.g., cache 707). Figure 7 This prevents duplicate learning operations and packets from going to different PP identifiers (e.g., WCPU ID), even if packet processor 234 has not yet been assigned an identifier. In some embodiments, the learning cache is on-chip or integrated with switches 304, 314, and 308. To ensure minimal use of the learning cache, control from flow group policies is provided to enable / disable the cache. For example, control for enabling or disabling Transmission Control Protocol (TCP) synchronization packets can be enabled or disabled by switches 304, 314, and 308. In some embodiments, the learning cache size is several thousand entries, a trade-off between chip cost and learning burst absorption time (a few milliseconds). In some embodiments, switches 304, 314, and 308 are configured such that learning cache results have priority over external memory results when entries are moved from the learning cache to external memory in the background. In some embodiments, increasing the size parameter increases the learning burst absorption time of the device, while decreasing the size parameter reduces system cost. In some embodiments, key update and WCPU_ID update operations are combined into a single external memory access to reduce access bandwidth. In some embodiments, key update and WCPU_ID update operations may be kept separate to minimize the learning cache size and increase the device's learning burst absorption time.

[0071] In some embodiments, switches 304, 314, and 308 are configured to employ a learning scheme that does not serialize all learning operations. In some embodiments, switches 304, 314, and 308 are configured to pipelining simple (e.g., non-reordered) cases while being configured to serialize reordered cases (e.g., processing non-reordered learning operations before processing learning operations that include reordering operations). In some embodiments, switches 304, 314, and 308 are configured to support separate caches / queues for simple and reordered cases, thereby ensuring that simple cases do not unacceptably stop due to reordered cases. In some embodiments, flow table 207 ( Figure 2 The components are divided into groups or blocks, and the hardware reordering controller is copied.

[0072] In some embodiments, switches 304, 314, and 308 are configured not to update the hit / timestamp table for each packet. In some embodiments, switches 304, 314, and 308 are configured to update the first packet of a flow (i.e., when the flow is learned). In some embodiments, the current timestamp is stored as part of a short policy (e.g., 128 bits of data associated with 384 bits of key data form a flow table entry).

[0073] In some embodiments, switches 304, 314, and 308 are configured to provide inline-executable aging instructions. In some embodiments, the inline aging operation is carried out on a packet lookup, and aging outdated entries in storage areas already read for packet management operations is performed. This technique prioritizes aging entries in storage areas that already have entries and helps proactively free up space in relatively full storage areas. In some embodiments, an aging event queue is maintained and pushed every clock cycle. In some embodiments, switches 304, 314, and 308 are configured to support timer-based aging, wherein a background timer sequentially iterates through all entries in flow table 207, checks whether the flow duration exceeds a configured threshold, and ages (i.e., deletes) the entry if it does. Timer-based aging can be slower than inline aging. In some embodiments, the timestamp can be a full 64-byte (b) / 48-byte timestamp, a quantized approximately 8-byte timestamp, or a 1-byte hit bit.

[0074] In some embodiments, switches 304, 314, and 308 are configured to decouple the policy / state / statistics database from the key table database to support multiple use cases. In some embodiments, key table entries are moved to improve hash table utilization so that ingress policy / state / statistics entries do not need to be moved when hash table entries are sorted. In some embodiments, for bidirectional flows, two key entries point to one policy / state / statistics entry. In some embodiments, the LF_ID (logical flow ID) is a redirection pointer that enables this decoupling. Packet processor 234 implements a free address pool scheme to support ingress LFID generation. This free address pool can be queried by WCPU 312, and the resulting LFID can be passed to the flow table manager as part of the FFL. In some embodiments, switches 304, 314, and 308 are configured to support separate LF_IDs for ingress and egress switches 304 and 314. Instead of the free address pool scheme, in some embodiments a compressed FIFO with background scanning (e.g., memory 908) is utilized. Figure 9 )).

[0075] The following describes an exemplary flow learning operation. A new flow is received at switch 304. During TFL, switch 308 accesses flow table 207 ( Figure 2The external memory (212 and 214) is used to allocate I-LFID and send packets to WCPU 312 via structure 310. WCPU processes the first few packets of the stream and determines the egress switch 314 of the stream by performing an E-LFID query.

[0076] After or at the end of the TFL (e.g., during or just before the FFL), WCPU 312 provides an LFID link and provides the flow's E-LFID and updated policy to switch 304 for storage in flow table 207. After the FFL, packets from the flow are forwarded to egress security switch 314 via structure 310. Egress security switch 314 receives packets and updates statistics using the E-LFID. Egress security switch 314 then delivers the packets to the destination port.

[0077] refer to Figure 4 Similar to flow table 207 ( Figure 2 The flow table 400 of the ingress security switch 304 includes a flow key database 402, a flow shortening policy database 404, a flow policy database 406, a flow state database 408, and a flow ingress statistics database 410. An example of the content of the flow table 400 after the FFL is shown. (Reference) Figure 5 Similar to flow table 207 ( Figure 2 The flow table 500 of the egress security switch 314 contains the flow egress statistics database 502. An exemplary content of the flow table 500 is shown after the FFL. In some embodiments, flow table components are linked via I-LFID in the ingress security switch 304 and E-LFID in the egress security switch 314.

[0078] refer to Figure 6 In some embodiments, system 300 may perform TFL according to operation flow 600. TFL begins at operation 602. At operation 604, ingress security switch 304 performs equal-cost multipath resolution to obtain identification of WCPU 312. At operation 606, hash table entry learning or flow table entry learning is performed to obtain flow table data (e.g., LFID, key, identification of WCPU 312, and timestamp) of the flow's entries. At operation 608, the learning cache is checked to determine if the learning cache is full. If so, then an exception is executed at operation 610 and flow 600 is dropped. If not, then operation 614 is executed. In operation 614, pending learning is written to the learning cache, and a memory read is initiated.

[0079] In operation 616, flow table 207 is checked to determine if the storage area is full. If so, a reordering operation (e.g., cuckoo hash reordering) is performed in operation 620, and flow 600 proceeds to operation 622. If not, operation 626 is executed. In operation 626, entries are written to flow table 207.

[0080] In operation 622, the storage area is checked to determine if it is empty. If it is, then flow 600 proceeds to operation 620. If not, then operation 628 is executed. In operation 628, an aging entry is searched in flow table 207. If an aging entry is found, then aging operation 640 is executed to delete or remove the expired entry, and flow 600 proceeds to operation 626. If no aging entry is found, then operation 630 is executed. In operation 630, the entry is left in the learning cache, and operation 620 is executed at a later time.

[0081] refer to Figure 7 In some embodiments, processor 206 ( Figure 2 The system includes a cache and consistency management controller 226 with a read cache 712 and a write cache 714, an exact matching engine 230 with a cache 704, and a packet processor 234 with a cache 706. Caches 712, 714, 704, and 706 are used as cache points for stream learning operations. In some embodiments, the size of the cache depends on the desired or acceptable external memory latency.

[0082] Read cache 712 and write cache 714 are configured to retain data before it is sent to external memory (e.g., external memory 212 and 214). Caches 712 and 714 can handle multiple accesses to the same entry. The depth of caches 712 and 714 can be selected based on the system parameters and design considerations described above.

[0083] In some embodiments, cache 704 is a multi-purpose structure within the exact match engine 230. Cache 704 is used as an overflow ternary content-addressable memory and provides key and short policy storage until the learning operation is initiated. Cache 704 stores the key, short policy, and WCPU identification (e.g., {key + short policy containing WCPU_ID}). In some embodiments, a partial write is completed once a cache miss is detected (at which point only the key is known). In some embodiments, a full write (for short policy data) is available after WCPU resolution. In some embodiments, cache 704 has a depth of 16. At a learning rate of 16M / s, a learning time of 62.5ns is achieved per learning session. In some embodiments, if the external memory access time = 4us, then the depth of cache 704 is 64 (4us / 62.5ns equals 64).

[0084] Cache 706 is an ingress pipeline cache and, in some embodiments, is part of packet processor 234. Cache 706 is configured to handle consistent WCPU allocation of packets from the same stream. WCPU resolution hardware 736 is configured for, for example, stream 600 (… Figure 6 The parsing operation used in the stream learning operation. Cache 706 stores the exact match cache index and WCPU identification (e.g., {EM cache index, WCPU_ID}), which is written after WCPU parsing and released once cache 704 has been updated for the stream. Cache 706 has a depth of N to cover the latency from the start of a cache miss (e.g., MISS -> WCPU_ID determination) (e.g., N = 50).

[0085] refer to Figure 8 Each loop generates a unique LFID (Free Pointer) for use during the learning process. In some embodiments, a memory free address pooling M-FAP method (which maintains a set of available free addresses) is used to construct a list of free LFIDs for use in the background process of scanning flow table 207 to populate the list of free LFIDs. In some embodiments, packet processor 234 includes TFL process engine 816, bitmap state memory 812, and free LFID first-in-first-out (FIFO) memory 814. Engine 816 manages, for example, flow 600 ( Figure 6 The TFL operation in ) . Bit status memory 812 is used to track non-zero rows of memory 842.

[0086] Packet processor 234 and HBM subsystem 840 (e.g., Figure 2The HBM subsystem 840 is coupled to controller 220, cache and consistency management controller 226, and external memories 212 and 214. Memory 842 includes memory 842. Memory 842 stores the list of free LFIDs as a bitmap of 200M streams (e.g., a 25600x8192 b bitmap memory). In some embodiments, memory 842 is part of external memories 214 or 216.

[0087] HBM subsystem 840 maintains on-chip state to read memory 242 and populate free LFID FIFO memory 814 in packet processor 234. In some embodiments, a 16Kx32-bit LFID-FIFO memory stores a list of LFIDs. Data read from memory 842 is fed into the FIFO memory (e.g., memory 814). In some embodiments, if a row has 25600x1 bits of free LFIDs, then a 1-bit indication is stored for each row. The indication is updated when a specific row in memory 842 used for LFID reclamation is updated. Assuming a TFL rate of approximately 5 M / s, then in some embodiments, 16K indices are processed every approximately 3.2 ms. According to some embodiments, initiating a read to memory 842 every 1 to 2 ms allows a learning rate to be achieved at a low bandwidth (approximately 1 kilobyte / s) on the interface of external memories 212 and 214.

[0088] refer to Figure 9 A background method is used to construct a list of free LFIDs for use by the background process of scanning flow table 207 to populate the list. In some embodiments, packet processor 234 includes TFL processing engine 816, first-in-first-out (FIFO) memory 902, and free LFID FIFO memory 814. Memory 902 is a compressed FIFO configured to pick up indices of consecutive ranges from free LFID FIFO memory 814 and store them as ranges, thereby improving index storage efficiency (e.g., probabilistic storage expansion).

[0089] In some embodiments, the exact matching engine 230 is configured to read multiple storage areas for reordering. During this operation, the exact matching engine 230 is configured to locate expired temporary flow entries and delete them, and reclaim LFIDs. In some embodiments, the grouping control interface 228 is configured to perform a continuous background scan of the flow table 207 (taking several seconds or minutes) to export statistics in some embodiments. The grouping control interface 228 also discovers expired entries and reclaims expired LFIDs. The grouping control interface 228 is aware of WCPU-based deletions.

[0090] The FIFO memory 814 is optimized in the pipeline to store the indexes provided by the operations described above. If memory 814 is full, the last read address in flow table 207 is stored, and adding indexes to memory 814 stops. In the next scan cycle, the reclaimed indexes come only from the last read address. Advantageously, this technique does not require additional memory / access to external memories 212 and 214.

[0091] Switch 204 can perform an aging process (e.g. Figure 6 Operation 640 in the process removes entries from flow table 207. According to an LCPU-based aging technique, the LCPU or internal processor 222 responds to a temporary learning notification and periodically reads flow table 207 (via exact matching engine 230). If the recorded current time is greater than the recorded period, the entry is aged. In some embodiments, to prevent errors when the LCPU decides to age an entry while the WCPU updates the entry, a long period (e.g., 500 round-trip times) and a 64-bit timestamp can be used to reduce the chance of this error. According to the exact matching engine-based aging technique, exact matching engine 230 searches the hash table, retrieves storage areas, and checks for vacancies. If no vacancies are found, reordering begins. Exact matching engine 230 may check if the storage area has temporary entries, and if the recorded current time is greater than the recorded period, the entry is used as a vacancies.

[0092] Configuration of exemplary embodiments

[0093] The construction and arrangement of the systems and methods shown in the various exemplary embodiments are merely illustrative. Although only a few embodiments have been described in detail in this disclosure, many modifications are possible (e.g., changes in the number of ports or destinations, data types, methods of re-insertion, reintroduction, etc., parameter values, arrangements, etc.). For example, the positions of elements may be reversed or otherwise changed, the connections between elements may be direct or indirect, such that one or more intermediate elements may exist connecting them, and the nature or number of discrete elements or locations may be altered or changed. Therefore, all such modifications are intended to be included within the scope of this disclosure. According to alternative embodiments, the order or sequence of any process or method steps may be changed or reordered. Other substitutions, modifications, changes, and omissions may be made in terms of the design, operating conditions, and arrangement of the exemplary embodiments without departing from the scope of this disclosure. For example, embodiments of this disclosure may be implemented by a single device and / or system, or by a combination of separate devices and / or systems.

[0094] This disclosure contemplates methods, systems, and program products for performing various operations on any machine-readable medium. Embodiments of this disclosure may be implemented using existing computer processors, or by a dedicated computer processor for a suitable system incorporated for this or another purpose, or by a hardwired system. Embodiments within the scope of this disclosure include program products comprising machine-readable media for carrying or having machine-executable instructions or data structures stored thereon. Such machine-readable media may be any available media accessible by a general-purpose or special-purpose computer or other machine having a processor. For example, such machine-readable media may include RAM, ROM, EPROM, EEPROM, NAND, NOR, CD-ROM or other optical disk storage devices, magnetic disk storage devices or other magnetic storage devices, or any other media that can be used to carry or store desired program code in the form of machine-executable instructions or data structures and is accessible by a general-purpose or special-purpose computer (i.e., ASIC or FPGA) or any other machine having a processor. Combinations of the above are also included within the scope of machine-readable media. Machine-executable instructions comprise, for example, instructions and data that cause a general-purpose computer, special-purpose computer, or special-purpose processing machine to perform a function or set of functions.

[0095] Although the diagrams illustrate a specific order of method steps, the order of steps may differ from that depicted. Furthermore, two or more steps may be performed simultaneously or partially simultaneously. This variation will depend on the chosen software and hardware system and the designer's choices. All such variations are within the scope of this disclosure. Similarly, software implementations can utilize rule-based logic and other logic with standard programming techniques to accomplish various connection steps, processing steps, comparison steps, and decision steps.

Claims

1. A switch, comprising: The memory includes flow tables, which include a flow key database and a flow policy database for flows in the network associated with the switch; and A processor includes an exact matching engine and a packet processor engine, wherein the exact matching engine is a hardware component configured to manage the flow tables in the memory, wherein the exact matching engine includes a learning cache configured to store key entries, wherein the exact matching engine is configured to write entries associated with flow misses to the learning cache, and wherein the packet processor engine is configured to determine the existence of empty storage areas in the flow key database, wherein the entries associated with the flow misses are stored in the empty storage areas of the flow key database, wherein if the empty storage areas for the entries associated with the flow misses do not exist, then The packet processor engine is configured to perform a reordering operation, wherein if the reordering operation finds an uncovered storage area, the entry associated with the stream miss is stored in the uncovered storage area of ​​the stream key database; if no uncovered storage area exists after the reordering operation, the packet processor engine is configured to perform an aging operation, wherein if the aging operation finds an aged storage area, the entry associated with the stream miss is stored in the aged storage area of ​​the stream key database; and if the aging operation does not find an aged entry, the entry remains stored in the learning cache.

2. The switch of claim 1, wherein the flow table is configured to have a flow key database separate from the flow policy database, and wherein the processor is a security processor and the switch is a security switch.

3. The switch of claim 2, wherein the security processor is configured to provide learning rate enhancement, aging rate enhancement, and table indirect value scalability, while performing complex flow management.

4. The switch of claim 2, wherein the security processor is disposed on a single integrated circuit substrate.

5. The switch of claim 4, wherein the memory is housed on a separate integrated circuit device, and the security processor is configured to perform hardware-based reordering, wherein entries in the flow policy database do not need to be moved when the entries in the flow key database are reordered.

6. The switch of claim 5, wherein the security processor and the memory are in a single package.

7. The switch according to claim 5, wherein the security processor and the memory are mounted on an interposer board.

8. The switch of claim 5, wherein the learning cache is configured to store a short policy database linked to the flow key database.

9. The switch of claim 2, wherein the security processor is configured to process non-reordering learning operations before processing learning operations that include the reordering operation.

10. The switch of claim 2, wherein the security processor includes a hardware-based reordering engine configured to reorder the flow table as it fills a storage area in the flow table with key entries of the key entries in the cache.

11. A flow management method, the method comprising: Receive packets at the switch; Determine the working processor identification of the group; The worker processors of the streams associated with the groups are used to perform flow table entry learning to obtain data for the entries of the streams; The entry of the stream is written to a learning cache integrated with the switch using an exact matching engine, which is configured to write the entry to the learning cache. The group processor engine is used to determine the existence of an empty storage area in the stream key database of the stream table, wherein the entries are stored in the empty storage area of ​​the stream key database; If no empty storage area exists for the entry, a reordering operation is performed, wherein if the reordering operation finds an uncovered storage area, the entry is stored in the uncovered storage area of ​​the stream key database. If no uncovered storage area is found after the reordering operation, an aging operation is performed, wherein if the aging operation finds an aging storage area, the entry is stored in the aging storage area of ​​the stream key database, and if the aging operation does not find the aging storage area, the entry remains stored in the learning cache.

12. The method of claim 11, further comprising: After the entry is written, a memory read is performed.

13. The method of claim 12, further comprising: If the storage area is full, the reordering operation is initiated.

14. The method of claim 13, further comprising: Determine if the storage area is empty; and If the storage area is empty, then the entry is inserted into the flow table.

15. The method of claim 11, further comprising: Insert the entry into the flow table.

16. An apparatus comprising: A memory configured to store flow tables, including a flow key database; and A processor configured for packet processing and separate from the memory includes a packet processor engine and an exact matching engine. The exact matching engine includes a learning cache and is configured to manage the flow table. The learning cache is used to place entries for new flows into the flow table. The exact matching engine is a hardware unit. The exact matching engine is configured to write entries associated with flow misses to the learning cache. The packet processor engine is configured to determine the existence of an empty storage area in the flow key database, wherein the entries associated with the flow misses are stored in the empty storage area of ​​the flow key database. If the empty storage area for the entries associated with the flow misses does not exist, the packet processor engine is configured to... The packet processor engine is configured to perform a reordering operation, wherein if the reordering operation finds an uncovered storage area, the entry associated with the stream miss is stored in the uncovered storage area of ​​the stream key database; if no uncovered storage area exists after the reordering operation, the packet processor engine is configured to perform an aging operation, wherein if the aging operation finds an aging storage area, the entry associated with the stream miss is stored in the aging storage area of ​​the stream key database; if the aging operation does not find the aging entry, the entry remains stored in the learning cache; and if no aging storage area is found, the packet processor engine is configured to perform the reordering operation at a later time.

17. The device of claim 16, wherein the processor is configured for hardware reordering, learning rate control, aging rate control, and table indirect value retrieval to achieve scaling, while performing stream management.

18. The device of claim 16, wherein the flow table includes key entries and policy index entries.

19. The apparatus of claim 18, wherein the key entries and policy index entries are decoupled from each other, and wherein for a bidirectional stream, two key entries point to one policy entry.

20. The device of claim 16, wherein the processor and the memory are disposed on an interposer in an integrated circuit package.

Citation Information

Patent Citations

  • Flow classification apparatus, methods, and systems

    CN110301120A

  • Flow cache management

    US20220006737A1