A method and system for unloading virtual switch rules on smart network card
By dynamically perceiving traffic patterns and rule characteristics, and adaptively adjusting the offloading solution of virtual switch rules, solving the problem of limited resources of intelligent network card and ignoring rule characteristics of solid offload, achieving more efficient packet processing and system performance improvement.
Patent Information
- Application Number
- CN202311496200.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-10
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2043-11-10
AI Technical Summary
The existing solution to offload the data paths in virtual switches into smart network cards, without differentiating the uninstallation of all the rules supported by hardware, resulting in limited resources of smart network cards, frequent rule replacements affect system stability and performance, and solid offloading ignores the characteristics of the rules, resulting in a degradation of data packet matching performance.
A dynamic unloading solution is proposed. By perceiving the characteristics of traffic patterns and rules, the unloading solution is adaptively adjusted, dynamically unloading and removing rules in the smart network card, retaining large traffic rules, and deleting small traffic rules to ensure that large traffic is processed in the smart network card, and improving the overall performance of the system.
By dynamically adjusting the virtual switch rules stored by smart network card, we ensure that the flow hits and forwards in the smart network card, reduce the resource occupancy of small streams, improve the overall performance of the system, and avoid the impact of frequent rule replacement on system stability.
Smart Images

Figure CN117544583B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to a software and hardware collaborative processing technology for virtual switches in cloud computing, and specifically to a method and system for unloading virtual switch rules on a smart network card. Background Art
[0002] Cloud data centers connect a large number of computing and storage devices through some network devices to form an organic whole to provide services to the outside world. With the rapid development and widespread deployment of technologies such as software-defined networks, network function virtualization, and distributed computing, the network, computing, and storage of data centers are moving towards integration. In particular, the processing of network transmission and switching has penetrated deep into the end system with virtual switches as the carrier, making the end system based on the general-purpose processor platform the "last mile" of data transmission. Virtual switches can implement switch components in physical servers based on virtualization technology through software, and the communication between virtual hosts and their external networks, as well as the scheduling of local or remote resources, will ultimately be implemented in the form of data packet switching through virtual network switches on the end system, such as Figure 1 shown.
[0003] Virtual switches are usually deployed in cloud, software defined networking (SDN) and network function virtualization (NFV) environments, which usually have high requirements for data communication performance. When a data packet is processed in a virtual switch, it needs to be searched and matched based on a pre-set rule set. After matching the corresponding table entry, it is processed based on the corresponding action in the table entry. Therefore, the search performance of the data packet directly affects the processing capacity of the virtual switch. With the rapid development of Internet technology, the demand for large bandwidth and low latency networks has become mainstream. The processing performance of virtual switches in this scenario faces the following three challenges. First, the efficiency of general processors in executing network packet processing is low. For example, under the x86 architecture, the traditional data packet processing method is CPU interrupt, that is, the network card driver notifies the CPU to process through an interrupt after receiving the data packet, and then the CPU copies the data and hands it over to the protocol stack. When the amount of data is large, this method will generate a large number of CPU interrupts, resulting in the CPU being unable to run other programs, low efficiency, increased system latency, reduced throughput, and reduced overall efficiency of the infrastructure. Secondly, the I / O efficiency is low. Virtual switches can achieve a speed of about 500,000 packets per second (pps) on a 10Gbps link, and the theoretical maximum packet rate can reach 15 million per second. However, after deploying a large number of virtual network functions (VNFs), most of the flows are small flows (such as voice packets), and mainstream virtual switches can only achieve 1 / 80 of the I / O performance on a 10Gbps interface. Finally, service quality assurance. Many cloud services need to guarantee a certain bandwidth or latency to provide stable services, but the processing performance of virtual switches is limited. After a surge in business traffic, a large number of packets will be lost, which directly affects the experience of cloud services.
[0004] To optimize performance, it has become a mainstream trend to offload virtual switch rules based on SmartNICs. Compared with traditional NICs, SmartNICs embed a device with computing and storage functions between the traditional Ethernet interface and the hardware bus, such as a network processor (NP) or a field programmable gate array (FPGA), making it highly programmable and customizable, and also having stronger computing and storage capabilities. SmartNICs offload the virtual switch data plane by offloading part or all of the functions of the virtual switch data path to the SmartNIC. By maintaining a fast forwarding path on the NIC, when a message is received, it first checks whether the processing rules for this type of message have been cached in the fast path. If found, the corresponding rules are directly executed, otherwise it is sent to the virtual switch for processing. By offloading with SmartNICs, the overall processing performance of the system is improved, while the corresponding resources of the host are released.
[0005] The existing solution of offloading the data path in the virtual switch to the smart network card is to indiscriminately offload all the rules supported by the hardware, and the offloading solution is solidified. However, the storage resources of the hardware on the smart network card are limited. When the rules that have been offloaded occupy all the network card resources, the newly added rules will choose to replace the rules in the smart network card. Frequent rule replacement will affect the stability of the system and reduce system performance. In addition, due to the characteristics of the smart network card hardware design itself, its ability to process rules with different characteristics is different. Rules with certain characteristics may reduce the average performance of data packet matching in the hardware, and the use of solidified offloading ignores the characteristics of the rules. Summary of the invention
[0006] The purpose of the present invention is to solve the above-mentioned problems existing in the existing solution of offloading the data path in the virtual switch to the smart network card.
[0007] To achieve the above objectives, the present invention proposes a dynamic offloading scheme, which can adaptively and dynamically adjust the offloading scheme by sensing the characteristics of traffic patterns and rules, making full use of hardware advantages, so that more data packets hit and forward in the network card, and improving the overall performance of the system.
[0008] Specifically, on one hand, the present invention provides a system for unloading virtual switch rules on a smart network card, the system comprising: a smart management layer and a smart network card, the smart management layer mainly comprising: a flow and rule feature recognition module and a rule dynamic unloading module; wherein,
[0009] The traffic and rule feature recognition module is used to obtain the rules and corresponding traffic information in the smart network card at a certain time interval, extract and analyze the features, design the corresponding dynamic unloading strategy according to the features, and pass the strategy to the rule dynamic unloading module;
[0010] The rule dynamic unloading module is used to store the corresponding relationship between the hardware and software after the rules are unloaded, as well as the dynamic unloading strategy designed based on the traffic and rule feature recognition module to remove the rules that have been unloaded to the smart network card.
[0011] On the other hand, the present invention provides a method for unloading virtual switch rules on a smart network card, which is applied to the above system, and the steps include:
[0012] When the traffic and rule feature recognition module obtains the hash table and flow information from the smart network card, it determines whether coarse-grained dynamic unloading based on the hash table can be performed, and when the total number of rules unloaded in the hardware exceeds the preset threshold, fine-grained dynamic unloading based on the rules is performed; finally, the corresponding information of the rules that need to be removed from the hardware is obtained and passed to the rule dynamic unloading module;
[0013] The step of coarse-grained dynamic unloading based on the hash table includes: the traffic and rule feature recognition module monitors the number of unloading rules in each hash table that has been sent to the smart network card, counts the proportion of traffic hitting each hash table to the total traffic, and obtains the average value p of the traffic proportion of all hash tables; when the number of rules in a hash table is less than n, and the percentage of traffic hitting the hash table to the total traffic is less than the average value p, the hash table and the rules contained therein are deleted;
[0014] The step of fine-grained dynamic unloading based on rules includes: by counting the information of the flow unloaded on the smart network card, statistically analyzing the number of data packets matched by the rules, and removing a preset number of rules with relatively low hit times from the smart network card.
[0015] The method and system for unloading virtual switch rules to a smart network card provided by the present invention can dynamically adjust the virtual switch rules stored in the smart network card, retain the virtual switch rules corresponding to large flows, and delete the virtual switch rules corresponding to small flows, thereby ensuring that large flows are processed in the smart network card, and the removed small flows are no longer unloaded to the smart network card, so that more data packets are hit and forwarded in the smart network card, thereby improving the overall performance of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the multiple embodiments disclosed in this specification, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only the multiple embodiments disclosed in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 A schematic diagram of the existing system structure for offloading virtual switch rules to a smart network card;
[0018] Figure 2 A schematic diagram of a system structure for dynamically unloading virtual switch rules on a smart network card provided by an embodiment of the present invention;
[0019] Figure 3 Schematic diagram of image distance measurement based on perceptual hashing. DETAILED DESCRIPTION
[0020] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. The described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of this application.
[0021] Figure 2 A schematic diagram of a system structure for dynamically unloading virtual switch rules on a smart network card provided by an embodiment of the present invention. Figure 2 As shown, the system architecture is divided into three parts from top to bottom, namely, a software module 100 based on a virtual switch, an intelligent management layer 200 and an intelligent network card 300.
[0022] The software module 100 based on the virtual switch is provided with a control plane 110, which is used to correspond to the control logic of the virtual switch, that is, to determine the method and strategy of how to forward the data packet and guide the work of the data plane; the data plane is responsible for the search and forwarding of the data, and stores the search and forwarding rule table. In the embodiment of the present invention, the rules frequently hit in the data plane are stored in the smart network card 300, which is a subset of the rules contained in the data plane. The intelligent management layer 200 mainly includes a traffic and rule feature identification module 210 and a rule dynamic unloading module 220. Among them, the traffic and rule feature identification module 210 is used to obtain the rules and corresponding traffic information in the smart network card 300 at a certain time interval, extract and analyze the features, and design the corresponding dynamic unloading strategy according to the features, and pass the strategy to the rule dynamic unloading module 220. The rule dynamic unloading module 220 maintains a hash table, which maintains the corresponding relationship between the rule ID and its unloading structure in the hardware. In the hash table, the rule ID is identified by ufid, and ufid corresponds to the unique identifier of each rule in the rule set. The structure of the rule unloaded to the hardware is represented by the structure hd_offloaded_entry. The main functions of the rule dynamic unloading module 220 include two parts. On the one hand, it stores the corresponding relationship between the hardware and software after the rule is unloaded. On the other hand, based on the dynamic unloading strategy designed by the traffic and rule feature recognition module 210, it removes the rules that have been unloaded to the smart network card 300.
[0023] To realize the dynamic unloading of virtual switch rules, if the information and hit status of the unloading rules in the hardware are frequently counted, the unloading scheme is updated and the existing rules in the hardware are replaced, the overall performance of the system will fluctuate greatly and the stability will be poor; however, the rules and traffic distribution change over time. If the unloading strategy is not updated for a long time, the system performance cannot be guaranteed. The specific reasons are as follows. First, since the ultimate goal of dynamic unloading is to forward and process large flows in the smart network card 300 as much as possible, but due to the limited resources of the smart network card 300, if the small flows in the smart network card 300 occupy a large amount of space, the large flows cannot be processed in the smart network card 300 in time, but are sent to the virtual switch, the overall performance of the system will decrease. In addition, rules with different characteristics have different effects on the processing power of the chip. Rules with certain characteristics may seriously reduce the average matching speed of data packets in the smart network card 300. Although the unloaded rules do not occupy all hardware resources, when the rules with such characteristics correspond to small flows, if they are not removed from the smart network card 300 in time, the overall performance of the system will be affected. Therefore, the traffic and rule feature identification module 210 needs to select a suitable time granularity as much as possible to extract and monitor the traffic and rule features in the smart network card 300, and this time interval is called a "time window".
[0024] Based on the above system, an embodiment of the present invention provides a slow-start network traffic monitoring strategy based on perceptual hashing. First, a perceptual hash algorithm is used to count the matching of data packets on a rule set within a period of time. Perceptual hash algorithm is a general term for a class of hash algorithms, which can generate a "fingerprint" string for each image, and judge the similarity of images by comparing the fingerprint information of different images. The closer the results are, the more similar the corresponding images are. Perceptual hash algorithms include mean hashing (aHash), perceptual hashing (pHash) and difference hashing (dHash). aHash is faster but less accurate; pHash is more accurate but slower; dHash takes both into account, with higher accuracy and faster speed. Therefore, an embodiment of the present invention uses dHash. The traffic and rule feature identification module 210 reads the rule information and the corresponding packet hit number in the smart network card 300 at the beginning. According to the combination of the source IP and the destination IP of the rule, one dimension is used to represent the length of the source IP address prefix, and the other dimension is used to represent the length of the destination IP address prefix. A 33×33 matrix is obtained, in which each element corresponds to a prefix combination (i.e., a hash table), and the value of each element corresponds to the number of data packets that hit the hash table within a period of time. After obtaining the matrix, the elements therein are normalized to obtain the corresponding image. After obtaining the image, the perceptual hashing technology is used to obtain its fingerprint and store it. The fingerprint acquisition method of the image is as follows: Figure 3As shown below. That is, it includes the following steps: First, scale down the regular set prefix combination distribution image to 8×8 by the nearest neighbor interpolation method; Second, compare two adjacent pixels and convert each row of pixels into differences; Third, encode the differences in sequence. In the same row, if the pixel value P[x] in the x-th column is less than the pixel value P[x + 1] in the (x + 1)-th column, that is, P[x] < P[x + 1], then the difference is set to "1", otherwise it is set to "0". The obtained string is used as the fingerprint of the image. After obtaining the first fingerprint, the second fingerprint is obtained in the next time window according to the above method, and the Hamming distance between the two fingerprints is calculated. The Hamming distance, that is, the number of different characters at the corresponding positions of two equal-length strings, is used to calculate the number of different bits between the two fingerprints, so as to measure the similarity between different distributions. If the Hamming distance is less than a certain threshold, it is considered that the two images belong to the same type; otherwise, the two images belong to different types. Therefore, in the embodiment of the present invention, after obtaining the first fingerprint at the initial moment, the second fingerprint is obtained after t0. If the Hamming distance between the two fingerprints is less than the threshold, the third fingerprint is obtained after 2t0; otherwise, the third fingerprint is obtained after t0. If in the first case, the distance between the third fingerprint obtained after 2t0 and the fingerprint obtained at t0 is still less than the threshold, the fourth fingerprint is obtained after 4t0; otherwise, the fourth fingerprint is obtained after t0. The time interval for obtaining fingerprints is 2 times that of the previous time, that is, t0, 2t0, 4t0, 8t0, 16t0 (corresponding to 2t in the pseudocode of Algorithm 1). The longest time interval for obtaining fingerprints is 16t0. When the interval increases to 16t0, if the distance between the current fingerprint and the previous fingerprint is less than the threshold, it will always stay at 16t0; if the distance between the current fingerprint and the previous fingerprint is greater than the threshold, regardless of the previous time interval, it will return to the interval of t0. As shown in Algorithm 1.
[0025] Algorithm 1. Slow-Start Traffic Monitoring Algorithm Based on Perceptual Hashing
[0026] Input: Fingerprint F1 of the hit distribution of data packets in the hash table in the previous period, fingerprint F2 of the hit distribution of data packets in the hash table in the current time period, threshold thre, time window t' calculated last time
[0027] Output: Time window size t
[0028]
[0029] Based on the above strategy, statistics are collected on the information of rules and traffic in the hardware, and the rules of the hardware in the smart network card 300 are dynamically adjusted, so as to maximize the system performance. In practice, the actual changes in rules and traffic in different scenarios are different, so the embodiment of the present invention aims to select a suitable time granularity to obtain the information of rules and traffic in the hardware, and the size of the specific parameter value is not fixed and should be determined according to the actual situation.
[0030] The time window obtained by the slow start monitoring strategy of the perceptual hash is used to count the traffic and rule distribution, and a rule dynamic unloading strategy is designed based on the statistical information. The unloading strategy will be updated in each time window, so as to ensure that the unloading strategy can be dynamically updated with the change of time and traffic. The rule smart network card unloading strategy mainly includes two parts: one part is to select which rules to unload to the smart network card 300, and the other part is to remove the rules that have been unloaded to the hardware. In the dynamic unloading strategy proposed in the embodiment of the present invention, by analyzing the rules and traffic characteristics, some rules are selected to be swapped out from the hardware within a time window, and the rules that hit in the virtual switch are always unloaded to the smart network card 300. The advantage of this solution is that the most recently hit rule can be selected to try to process the data packet in the hardware. As for rule removal, it includes two aspects, namely, the characteristics of the rules and the number of rules, which are respectively called "coarse-grained dynamic unloading based on hash tables" and "fine-grained dynamic unloading based on rules".
[0031] Based on the coarse-grained dynamic unloading of the hash table, a rule in the virtual switch will be disassembled into multiple rules and sent to the smart network card 300, so the smart network card 300 has different processing capabilities for rules with different features. Through experiments, it is found that as the number of hash tables unloaded to the smart network card 300 increases, the forwarding performance of the data packet is significantly reduced. When the load of some hash tables in the smart network card 300 is low, that is, the hash table only stores a small number of rules and the rule corresponds to a small flow, the hash table should be deleted, and the data packet corresponding to the rule should be sent to the virtual switch for processing. Therefore, the traffic and rule feature identification module 210 first monitors the number of unloaded rules that have been sent to each hash table in the smart network card 300, counts the proportion of traffic hitting each hash table to the total traffic, and obtains the average value p of the traffic proportion of all hash tables. When the number of rules in a hash table is less than n, and the percentage of traffic hitting the hash table to the total traffic is less than the average value p, the hash table and the rules contained therein are deleted.
[0032] Based on the rule-based fine-grained dynamic unloading, it can be seen that based on the fact that the traffic distribution obeys Zipf's law, although the number of large flows accounts for a small part of the total number of flows, it generates the vast majority of the total traffic. Therefore, when the number of rules in each hash table is large, and the total number of unloaded rules reaches 90% of the maximum number of rules n that the hardware can store, the embodiment of the present invention adopts "rule-based fine-grained dynamic unloading", by counting the information of the flow unloaded on the smart network card, and statistically analyzing the number of data packets matched by the rules, 20%×n rules with relatively low hit times are removed from the smart network card 300. By using this method, 10%×n free space can always be reserved for the smart network card 300, thereby ensuring that the newly arrived traffic can always be unloaded to the hardware. In addition, by updating the dynamic unloading strategy in each time window, it is ensured that the large flow is processed in the smart network card 300, thereby improving the overall performance of the system. Before the next update of the unloading strategy, the removed small flow is no longer unloaded to the smart network card.
[0033] In summary, after the traffic and rule feature recognition module 210 obtains the hash table and flow information from the smart network card 300, it first determines whether "coarse-grained dynamic unloading based on the hash table" can be performed. On this basis, when the total number of rules unloaded in the hardware exceeds the threshold we set in advance, "fine-grained dynamic unloading based on rules" is performed. Finally, the corresponding information of the rules that need to be removed from the hardware is obtained and passed to the rule dynamic unloading module.
[0034] The embodiment of the present invention uses a time window obtained by a slow-start network traffic monitoring strategy based on perceptual hashing to count traffic and rule distribution, and designs a rule-based dynamic unloading strategy based on statistical information. The unloading strategy is updated in each time window, thereby ensuring that the unloading strategy can be dynamically updated with changes in time and traffic.
[0035] The specific implementation methods described above further illustrate in detail the purposes, technical solutions and beneficial effects of the multiple embodiments disclosed in this specification. It should be understood that the above description is only the specific implementation methods of the multiple embodiments disclosed in this specification, and is not used to limit the protection scope of the multiple embodiments disclosed in this specification. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solutions of the multiple embodiments disclosed in this specification should be included in the protection scope of the multiple embodiments disclosed in this specification.
Claims
1. A method for offloading virtual switch rules on a smart network card, characterized in that: After the traffic and rule feature recognition module obtains the hash table and flow information from the smart network card, it determines whether coarse-grained dynamic offloading based on the hash table can be performed, and when the total number of rules offloaded in the hardware exceeds a preset threshold, fine-grained dynamic offloading based on rules is performed; Finally, the corresponding information of the rules that need to be removed from the hardware is obtained and passed to the rule dynamic offloading module; by reading the information of the rules in the smart network card and the corresponding packet hit counts, according to the combination of the source IP and destination IP of the rules, using one dimension to represent the length of the source IP address prefix and the other dimension to represent the length of the destination IP address prefix, the corresponding matrix is obtained, where each element corresponds to a prefix combination, that is, a hash table, and the value of each element corresponds to the number of data packets hitting the hash table within a period of time; The steps of the coarse-grained dynamic offloading based on the hash table include: the traffic and rule feature recognition module monitors the number of offloaded rules in each hash table that has been issued to the smart network card, calculates the proportion of the traffic hitting each hash table in the total traffic and obtains the average value p of the traffic proportions of all hash tables; when the number of rules in a certain hash table is less than n and the percentage of the traffic hitting the hash table in the total traffic is less than the average value p, then the hash table and the rules it contains are deleted; The steps of the fine-grained dynamic offloading based on rules include: by statistically analyzing the information of the flows offloaded on the smart network card and the number of data packets matched by the rules, a preset number of rules with relatively low hit counts are removed from the smart network card.
2. The method according to claim 1, characterized in that By updating the dynamic offloading policy within each time window.
3. The method according to claim 1, characterized in that The steps of the traffic and rule feature recognition module extracting and monitoring the traffic and rule features in the smart network card include: After obtaining the matrix, the elements in it are normalized to obtain the corresponding image; After obtaining the image, the fingerprint is obtained using the perceptual hash technology and stored; after obtaining the first fingerprint, the second fingerprint is obtained in the next time window according to the above method, and the Hamming distance between the two fingerprints is calculated to measure the similarity between different distributions; if the Hamming distance is less than the threshold, it is considered that the two images belong to the same type, otherwise, the two images belong to different types.
4. The method according to claim 3, characterized in that The steps of obtaining the fingerprint of the image include: reducing the rule set prefix combination distribution image to 8×8 by the nearest neighbor interpolation method; comparing two adjacent pixels and converting each row of pixels into differences; encoding the differences in turn. In the same row, if the pixel value P[x] in the x-th column is less than the pixel value P[x + 1] in the x + 1-th column, that is, P[x]<P[x + 1], then the difference is set to "1", otherwise it is set to "0", and the obtained string is used as the fingerprint of the image.
5. The method according to claim 3, characterized in that: After the first fingerprint is obtained at the initial moment, the second fingerprint is obtained after t0; if the Hamming distance between the two fingerprints is less than the threshold, the third fingerprint is obtained after 2t0, otherwise the third fingerprint is obtained after t0; if in the first case, the distance between the third fingerprint obtained after 2t0 and the fingerprint obtained at t0 is still less than the threshold, the fourth fingerprint is obtained after 4t0, otherwise the fourth fingerprint is obtained after t0; the time interval for obtaining fingerprints is twice the previous time; the longest time interval for obtaining fingerprints is 16t0, when the interval increases to 16t0, if the distance between the current fingerprint and the previous fingerprint is less than the threshold, it always stays at 16t0; and if the distance between the current fingerprint and the previous fingerprint is greater than the threshold, no matter what the previous time interval is, it will fall back to the interval of t0.
6. The method according to claim 1, characterized in that The preset number of rules is 20%×n.
Citation Information
Patent Citations
Flow table aging time adjusting method and device and storage medium
CN112134806A