SEQUENTIAL EVENT TRACKER WITH LOOSE ATOMARITY OF ACCESSES
A cyclic sequential array with a sliding window and control values optimizes event tracking by minimizing cache line updates, addressing performance issues in event tracking systems and enhancing system efficiency.
Patent Information
- Application Number
- DE102025106544
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-26
- Filing Date
- 2025-02-20
- Publication Date
- 2025-08-28
AI Technical Summary
Existing event tracking systems in computing environments face performance degradation due to the need to access multiple cache lines for updating event arrays, especially when tracking a large number of events, which reduces bandwidth and throughput.
Implementing a cyclic sequential array with a sliding window mechanism that tracks events within a limited number of cache lines, updating at most two cache lines at a time, and using control values to manage cache line initialization, thereby optimizing event tracking efficiency.
This approach enhances system performance by reducing cache line accesses, freeing resources, and improving bandwidth and throughput in communication devices.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
CLAIM TO FOREIGN PRIORITY
[0001] This application claims the benefits under 35 USC §119(ad) of Israeli patent application No. 311,073, filed February 25, 2024, which is incorporated herein by reference. TECHNICAL FIELD
[0002] At least one embodiment relates generally to event tracking and in particular, but not exclusively, to a sequential event tracker with loose atomicity of accesses. BACKGROUND
[0003] In certain computing environments, an array is used to manage the tracking of events associated with a system or device in the computing environment. While many types of events are conceivable, one example used here is tracking when individual network packets are received and whether that individual network packet has been received previously. This type of event tracking is performed with Internet Protocol Security (IPsec) for anti-replay protection, which tracks whether certain encrypted packets have themselves already been received and does not process those packets to provide anti-replay protection.
[0004] Such an array can be instantiated in memory, where sequential cells of the array contain one or more bits that specify information associated with the tracked events. In some systems, the order of the cells may correspond to an expected temporal sequence of events, even though the events may arrive out of order, allowing tracking to still occur in the expected order. Furthermore, the total number of events may be larger than the array, in which case only a certain number of the most recent events are tracked, while older events are not.In this way, a specific chronological order of events can be tracked in order to take specific actions, such as whether to forward received network packets, flush certain data from the cache to memory, separate grouped memory sections, perform a technical update, or the like, based on the status of the event(s) while the event(s) are being tracked.
[0005] In some systems or devices, events are cached to provide fast access and improve the performance of the tracing process. If the array size is large enough to effectively track a sufficient number of events, multiple cache lines may need to be accessed each time the array is updated, reducing the effectiveness and performance of event tracing. Tracing multiple event types in parallel tends to degrade performance even further. SUMMARY
[0006] The invention is defined by the claims. To illustrate the invention, aspects and embodiments are described herein, which may or may not be within the scope of the claims.
[0007] A device includes a cache for storing an array that tracks the occurrence of events, and a processing device coupled to the cache. The processing device tracks control values associated with a state of cache lines of the array. The processing device tracks, within the cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window. In response to detecting an event, the processing device updates a first value of a particular cache line of the cache lines based on a control value corresponding to the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window.
[0008] Any feature of one aspect or embodiment may be applied to other aspects or embodiments in any suitable combination. In particular, any feature of a method aspect or embodiment may be applied to a device aspect or embodiment, and vice versa. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Various embodiments in accordance with the present disclosure will be described with reference to the drawings, in which: Fig. 1 is a block diagram of an example distributed system including a computing system and one or more network devices, according to various embodiments; Fig. 2A, Fig. 2B and Fig.2C are graphical representations of an exemplary set of cache lines forming a window of cell index values of an array used to track IPSec-related events according to various embodiments; Fig. 3 is a flow diagram of an exemplary method for efficiently using control values and multiple cache lines of an array in the cache to track events, according to at least one embodiment; Fig. 4A, Fig. 4B and Fig. 4C are flow diagrams of an example method for efficiently using control values and multiple cache lines of an array in the cache to track events, according to at least one embodiment; Fig.5A is a diagram illustrating a current array active window and current cache control values when certain new packets are received, as tracked over time using identifier values (or sequence numbers) of the new packets, according to some embodiments; Fig. 5B with the diagram of Fig. 5A is a coherent diagram illustrating, according to some embodiments, the updates associated with both the control values and the cell values located at various cell index values of the active window of the array based on the identifiers (or sequence numbers) of the new packets; and Fig. 6 is a block diagram illustrating an example computing device according to implementations of the present disclosure. DETAILED DESCRIPTION
[0010] As described above, current event tracing techniques use a cacheable array (e.g., a cache array) that is sequentially tracked by cache cells. In some event tracing applications, events within cache cells are sequentially tracked according to an expected order and sometimes need to be updated atomically to adequately execute an expected action that might be triggered by the trace (as is the case with IPsec). For this reason, if the hardware offloads sequential tracing of multiple event types (each type is tracked independently in a separate array) to the hardware, and the hardware size is limited, the hardware can cache numerous arrays.
[0011] Additionally, if the cache array size must be larger than a cache line to track a sufficient number of events, then multiple cache lines must be accessed, read, and updated. Sometimes such updates can lead to a trickle-down effect (e.g., shifting of events across cache lines), where many sequentially arranged cache lines must be read and updated to accurately (e.g., chronologically and / or atomically) track the events stored in the array. Such repeated access, reading, and updating of cache lines negatively impacts the performance of a computing system or device in which too much cache is tied up and / or too many processing resources are devoted to updating the cache array solely to track events.In networked communication devices, event tracking in such an array may, for example, reduce bandwidth or throughput capacity.
[0012] Aspects and embodiments of the present disclosure address the above deficiencies and others by using a cyclic sequential array in the cache that tracks a certain number of events within a limited number of cache lines and can do so by updating no more than two cache lines at a time. More specifically, a sliding window can be tracked through the cache array so that only a limited number of cache lines need be considered for updating at any one time. Furthermore, control values corresponding to a state of the array's cache lines can be updated. In some embodiments, the control values are stored in a control cache line, which can be a second of the at most two cache lines being updated.In some embodiments, each value (or state) of the control values may indicate whether a particular cache line should be initialized (or reset) before proceeding with further updates to the event trace within that cache line. This allows tracing to continue without slowing down to update specific cache lines that may be initialized or reset at a later time.
[0013] In some embodiments, a cache stores an array that tracks the occurrence of multiple events, and a processing device is coupled to the cache. In some embodiments, the processing device tracks, within a control cache line of the cache or within other memory (as discussed below), multiple control values corresponding to a state of multiple cache lines of the array, e.g., a cache array that implements event tracking. The processing device may track, within the multiple cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window. In some embodiments, a sequence number of the event is greater than the largest sequence number within the current window and is therefore outside the window.
[0014] In response to detecting an event, the processing device may update a value of a particular cache line of the plurality of cache lines based on a control value corresponding to the particular cache line and whether the value is within a range of cell index values currently defined by the window. In some embodiments, values within the plurality of cache lines include indicators corresponding to unique network packets received over a network, as is done by providing anti-replay protection in IPSec. In some embodiments, in response to receiving any event or network packet, at most the control values and a single cache line of the array are accessed (e.g., a total of two cache lines, or a single cache line and any other memory location storing the control values).
[0015] Therefore, advantages of systems, devices, and methods implemented in accordance with some embodiments of the present disclosure include, among other things, providing an efficient mechanism for managing sequential event tracing with a size larger than a single cache line of a system or device in which the event tracing array is implemented. Additional advantages include the ability to increase available bandwidth and resources in communication devices by releasing the resources consumed by the event tracing. Further advantages will be apparent to those skilled in the art of this hardware event tracing, as explained below.
[0016] Fig.1 is a block diagram of an example distributed system 100 including a computing system and one or more network devices, according to various embodiments. In some embodiments, the system 100 includes the computing system 102 communicating with a plurality of additional network devices over a network 115. In some embodiments, the network devices include a first network device 105A, a second network device 105B, and so on up to an Nth network device 105N. The network 115 may be a wireless network, a wired network, or a combination of a wired and a wireless network.
[0017] In various embodiments, computing system 102 includes a processing device 110 including and / or coupled to a cache 112 and optionally including hardware registers 114, memory 130 (such as volatile memory), storage 140 (such as non-volatile memory), and a network interface 120. In some embodiments, memory 130 and / or storage 140 store instructions (e.g., program code) that, when executed by processing device 110, perform the operations disclosed herein. In some embodiments, network interface 120 is configured to communicate with the additional network devices and forward packets to processing device 110 for processing.In at least some embodiments, the processing device 110 stores, accesses, and updates metadata to update the event trace as stored in a cache array of the cache 112, referred to herein as an “array” for convenience.
[0018] In some embodiments, the array stores a cyclic sequential array that tracks multiple events (W) over time, where a cell c S(in [0, ..., W-1] in the array) contains information about the most recently processed event, and each event in the array is stored with a specific number of bits (e.g., E bits). The remaining tracked events can be arranged in cyclic order in the remaining cells of the array. When tracking events that arrive out of order, a unique and ascending event identifier (e.g., T) can be used to indicate the order of an event over time (e.g., the actual time, the sequence number, and the like).
[0019] In at least some embodiments, tracking and updating the array may occur within a window of cell index values that shifts cyclically with the occurrence of any event outside the window.
[0020] Table 1 lists a number of variables that can be used in an algorithm that can be executed by processing device 110 to track incoming events, regardless of whether the events arrive out of sequence, update a cell associated with an incoming event, and decide whether to cyclically shift the window based on whether the cell is outside the window, e.g., has an event identifier greater than the largest event identifier value of the current window. When the window is shifted, various variables can be reset to then continue tracking a newly defined window of cell index values. The sequence numbers can be thought of as event identifiers.Furthermore, if each cell of the array stores a single bit per event, the number of bits describing the cache line size is the same as the number of tracked events per cache line, e.g., P = L. . Table 1 variable definition W Number of events in the active window that are tracked in the array T S Value of a highest sequence number / identifier from events already received T N Value of a sequence number / identifier of a new event c S Cell index position within a specific cache line, the T S corresponds c N Cell index position within a specific cache line, the T N corresponds P Number of bits to describe the size of a cache line E Number of bits used to express a single event M Number of cache lines required for the array = ceil(W*E / P) L Number of tracked events per cache line = floor(P / E)
[0021] Thus, using Table 1, the processing device 110 may execute the algorithm to determine a value for the event identifier T N of the new event (e.g. the “event”) upon arrival and T N with a value for the event identifier T S to compare with c S and the total number of tracked events in the window (or W). In some embodiments, if the event identifier T N for the event is less than the event identifier T S minus W plus one (e.g. T N <T S-W+1), the new event is treated as an out-of-array event because it is too old for the array. Otherwise, if the event identifier is T N for the event less than or equal to Ts (e.g. T N <=T S ), the event is then processed as an event within the array (in-array event) and its associated information is stored in any cell c N updated with the parameters T N , T S , c S , W, L, as will be explained in more detail. In addition, if T N >T S is, the cells between c S and c N cyclically initialized. By treating the event tracker as a cyclic array of events stored in cache 112, expensive shift operations can be avoided in the disclosed embodiments.
[0022] For example, the purpose of anti-replay protection in IPSec is to ignore (e.g., discard) incoming old packets and incoming duplicate packets that are within a certain distance (measured by the difference in the IPSec packet sequence number) from the highest sequence number of an incoming and successfully processed (e.g., decrypted and authenticated) packet. To this end, the disclosed cyclic algorithm associated with anti-replay protection in IPSec may include an array of size W containing a single bit per packet sufficient to indicate whether a packet with the corresponding sequence number has already been processed. In this example, the values within the array's multiple cache lines may include indicators corresponding to unique network packets received over network 115 from other network devices. The identifier T Scan be the highest sequence number (event identifier) of a packet that was successfully processed. The position of the identifier T S in the array (of cache 112) can be defined as c S =T S %L, e.g. T S Modulo L, the number of tracked packets in a cache line can be determined. If L is a power of two, the calculation of c S can be easily performed in hardware. The sequence number of the other cells in the array can be implicitly determined by the distance of these respective cells in the array of c S be determined.
[0023] Fig. 2A, Fig. 2B and Fig. 2C are graphical representations illustrating an exemplary set of cache lines that form a window of cell index values of an array used to track IPSec-related events, such as an array located in cache 112, according to various embodiments. For example, if Ts =82 (in Fig. 2A marked by a capital “S”) and W=16, then c S =2, cell index one ("1") contains the indication "processed" at sequence number 81, cell index zero ("0") contains this indication at sequence number 80, and cell index 15 contains this indication for a packet with sequence number 79, and so on. In this embodiment, an indication "N" (or not processed) may be stored as zero ("0"), while an indication "Y" (or yes, processed) may be stored as one ("1").
[0024] To complete the example, we consider the state of the array in Fig. 2A, if a new packet with sequence number T N is received, then the packet would, if T N <67, be discarded because T N <T S -W+1. However, if T N =75, then the packet would be processed and the value of the array at c N=11 would change to Y. If T N =68, then the packet would be discarded because the array indicates that it has already been processed, since the value of c N =4 “Y”. However, if T N =88, then T S be updated to contain the value 88 and the array would be updated to indicate the new state as indicated by the position of the “S” in Fig. 2B.
[0025] In cases where the size of the array times the number of bits per tracked event (e.g., W*E) is larger than the size of a cache line (e.g., P), maintaining the array goes beyond a single cache line and requires additional resources, so a total of M=ceil(W*E / P) cache lines with L=floor(P / E) tracked events (cells) are required per cache line. Here, the term "ceil" refers to a ceiling function that maps its argument to the smallest integer greater than or equal to its argument, while the term "floor" refers to a floor function that maps its argument to the largest integer less than or equal to its argument. Note that there may be additional control bits for the array, such as log2(T S) to store the largest event identifier associated with the array. In various embodiments, the handling of these resources is performed carefully and atomically to ensure consistency.
[0026] For example, if a network security protocol such as IPSec is offloaded, where processing device 110 performs replay protection to prevent the processing of duplicate packets, a sliding window can be implemented sequentially within the array. In this case, atomicity prevents false positives and false negatives, e.g., dropping a packet that hasn't been received yet or forwarding a packet that has already been processed.
[0027] In systems that support out-of-order packet reception, where latency can result in a large gap (in sequence numbers) between received packets, a small sliding window can result in dropped packets and reduce overall bandwidth because retransmission is required for reliable connections. Furthermore, if the system 100 must support a large number of connections, accessing cache lines results in limited bandwidth. Reducing accesses to such cache lines frees up computational resources and optimizes system performance.
[0028] In systems that support a sequential event tracker where W*E is larger than the cache line size (e.g., P), the processing device 110 may need to allocate more than a single cache line to contain the array. A simple approach may be to allocate the required cache lines and maintain the same simple algorithm, and furthermore, to maintain a flow that updates all cache lines atomically so that no misses occur. As previously described, atomicity is fundamental to avoid consistency errors. However, in some cases, such an approach would require accessing all cache lines for each event, which would significantly impact system performance. For example, when processing an event where T N -T Sis approximately W, then all cache lines must be updated, which is undoubtedly inefficient.
[0029] To see the example array implementation of Fig. To simplify 2A-2B, assume that a cache line can contain 4 bits (P=4). In the situation where the received IPSec packet has a sequence number T S =88, three cache lines would have been updated because the algorithm updates cells 3-8 of the array.
[0030] The present disclosure describes an alternative approach in which processing device 110 stores additional control indicators in a separate memory location so that, for each processed event, processing device 110 sequentially updates at most the control values and only one cache line, rather than accessing multiple cache lines. In some embodiments, the control values are stored in a control cache line of cache 112, in hardware registers 114, in software registers, or other locations of memory 130, or the like. Accessing so few cache lines may be possible because, rather than explicitly initializing cache lines, processing device 110 stores a one-bit indication per cache line (e.g., as a control value) of whether the cache line is already initialized or not, to avoid fetching that cache line(s) if the cache line(s) should be initialized.
[0031] For this purpose, it is assumed that the additional control bits and an event trace array are stored in separate cache lines, although a separate cache line is not mandatory, as the control values or bits can be stored in registers or other memory locations. In this way, the number of cache lines accessed per packet can be limited to the control values stored in the cache or other memory location and a single cache line containing part of the array. The explanation with reference to Fig. 4A-4C will present such an example, which will be Fig.3 with a specific set of operations. In at least some embodiments, access to the control values and the cache line of the event trace array is performed atomically, or at least to ensure that the order of access to each cache line follows the order of the received events. Thus, in at least some embodiments, two general phases of the disclosed algorithm include first accessing the control indicators or control values and, if appropriate, updating the control indicator or value. Second, based on the control value update, an individual cache line from the array is accessed and the array is updated according to the original values of the control indicators.
[0032] Fig.3 is a flowchart of an example method for efficiently using control values and multiple cache lines of an array in cache to track events, according to at least one embodiment. The method 300 may be performed by processing logic including hardware, firmware, software, or any combination thereof. In some embodiments, the method 300 is performed by the computing system 102 to include execution by the processing device 110 of instructions stored in the storage 140 and executed from the memory 130. Although illustrated in a particular sequence or order, the order of the processes may be changed unless otherwise noted.Therefore, the illustrated embodiments are intended only as examples, and the illustrated processes may be performed in a different order, and some processes may be performed in parallel. Furthermore, one or more processes may be omitted in various embodiments. Thus, not all processes are required in every embodiment. Other process sequences are possible.
[0033] In operation 310, the processing logic stores an array in a cache that tracks multiple events. In some situations, the number of these tracked events may be in the dozens, hundreds, thousands, or hundreds of thousands.
[0034] In operation 320, the processing device tracks, within a memory location, a plurality of control values corresponding to a state of a plurality of cache lines of the array.
[0035] In operation 330, the processing device tracks a window of cell index values (e.g., corresponding to an event identifier value of various events) within the plurality of cache lines with a window size that cyclically shifts with the occurrence of any event that is outside the window.
[0036] In operation 340, in response to detecting an event, the processing device updates a value of a particular cache line of the plurality of cache lines based on a control value in the control cache line corresponding to the particular cache line and whether the value is within a range of cell index values currently defined by the window. For example, the value may be stored in a cell of the particular cache line that corresponds to a cell index value of the event.
[0037] Fig. 4A, Fig. 4B and Fig.4C are flow diagrams of an example method 400 for efficiently using control values and multiple cache lines of an array in cache to track events, according to at least some embodiments. The method 400 may be performed by processing logic including hardware, firmware, software, or any combination thereof. In some embodiments, the method 400 is performed by the computing system 102 to include execution by the processing device 110 of instructions stored in the memory 140 and executed from the memory 130. Although illustrated in a particular sequence or order, the order of the processes may be changed unless otherwise noted.Therefore, the illustrated embodiments are intended only as examples, and the illustrated processes may be performed in a different order, and some processes may be performed in parallel. Furthermore, one or more processes may be omitted in various embodiments. Thus, not all processes are required in every embodiment. Other process sequences are possible.
[0038] In some embodiments, method 400 can be understood as implementing a large sequential event tracker, where event identifiers start at zero and increase by one for each subsequent proper event in the sequence. Other configuration values can also be initialized first, including a largest identifier of an event that is in log2(T MAX ) bits are processed (as T S In some cases, T Sbe optimized to be stored in fewer bits, for example, if an assumption about the maximum permissible disorder of the system, or in other words, the maximum difference between packet identifier values (T S -T N ), so that only a portion of the most significant bits are stored. Another configuration value may include a per-cache-line zero indication (referred to as WZ), e.g., M bits for a single bit per cache line, indicating whether or not the cache line should be zeroed before any cell therein is accessed and / or updated. In some embodiments, these WZ (or control) values are stored in the control cache line of cache 112, or in registers or other memory locations.
[0039] In operation 402, the processing logic initializes certain values and parameters to be used for event tracking. For example, the processing logic negates an initial control value (e.g., associated with a particular cache line) and asserts a set of remaining control values from the plurality of control values (WZ(i)). The processing logic may then initialize a first event identifier value (T S), which is a maximum value for received events, to an initial value, e.g., zero, before tracking all received events begins. In some embodiments, the control values indicate whether corresponding cache lines to which the control values refer should be initialized. The processing logic may also initialize cells of the cache line associated with the initial control value and initialize cells of the particular cache line in response to the control value associated with the particular cache line being asserted.
[0040] In operation 404, the processing logic continues in an idle state by detecting a new event that initiates any number of different event-related update flows through the flowchart of Fig. 4A-4C should trigger.
[0041] In operation 406, the processing logic determines the first event identifier value, which is a maximum value for events already processed (tracked as T S ), determines a second event identifier value for the event (tracked as T N) and compares the first event identifier value with the second event identifier value. For example, the processing logic may determine whether the second event identifier value is less than a difference between the first event identifier value and a window size plus one. Thus, in operation 406, new events are assumed to be received, while in operation 404, the remaining time is idle. In general, unless otherwise noted, the remainder of the following discussion of the method flow refers to a single new "event" to keep the discussion concise, but many different events may take different paths through the operations of method 400, as best described with reference to Fig. 5A-5B, in which certain events received one after the other are shown as examples.
[0042] In operation 408, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size (e.g., less than a difference between the first event identifier value and a window size plus one), the processing logic performs out-of-array event handling for the event. This out-of-array event handling may be algorithm-dependent, such as dropping a packet in IPSec, maintaining a limited list of recent events that were outside the array, and the like. Operation 408 can also be understood to perform out-of-array event handling for the event in response to the second event identifier value being too small to be tracked by the window.
[0043] In operation 410, the processing logic determines a first cell index value (c S) as a combination of the first event identifier value (T S ) and a number of possible tracked events (L) for each of the plurality of cache lines. In some embodiments, the first cell index value is T S Modulo L (T S %L) or any other operation between T S and L. The processing logic may also provide an initial cache line value (i S ) of the plurality of cache lines associated with the first event identifier value, e.g., floor(T S / L). The processing logic can also use a second cell index value (c N ) as a combination of the second event identifier value (T N ) and the number of possible tracked events (L) for each of the plurality of cache lines. In some embodiments, the second cell index value T N Modulo L (T N %L) or any other operation between T Nand L. The processing logic may further determine a second cache line value i N of the plurality of cache lines associated with the second event identifier value, e.g., floor(T N / L).
[0044] In operation 412, the processing logic determines whether the second event identifier value T S less than or equal to the first event identifier value T N , such as whether the event is outside the window.
[0045] In operation 414, in response to the second event identifier value being outside the window (e.g., being greater than the first event identifier value), the processing logic further determines whether a second cache line value (i N) of the array for the event satisfies a condition based on a first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array. For example, the processing logic may determine whether the second cache line value is greater than the addition of a first cache line value (i S ) corresponding to the first event identifier value (T S) and a number of the plurality of cache lines of the array (M). In other words, the processing logic determines whether the second event identifier value is so large that there is no overlap between the events currently tracked by the window and the events that will be tracked by the window after the event has been processed. If the answer in operation 414 is no, e.g., by determining that a second cache line value of the array for the event is less than or equal to the addition of a first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array, then the method 400 proceeds to the operations of Fig.4B. Otherwise, method 400 proceeds to operations 416 and 418 to reset the array for a new window. In some embodiments, after certain conditions are met, operations are performed in two parts, first in connection with updating the value of T S and / or the value(s) of WZ(i) or the control values, and secondly in connection with the updating of cache lines in the array constituting the particular event trace operation.
[0046] In operation 416, the processing logic sets the first event identifier value (T S ) the second event identifier value (T N) and asserts control values from the control cache line, except for the control value associated with the current event. Furthermore, the processing logic negates the control value in the control cache line for the specific event, for example, by setting the control value to a predefined value such as zero.
[0047] In operation 418, the processing logic accesses (e.g., retrieves) a particular cache line with a cell index value corresponding to the event, which, for example, in some embodiments, is designated as i N%M can be determined. The processing logic may also initialize the cells of the particular cache line and, within the particular cache line, perform in-array manipulation for the second cell index value (cN) associated with the second event identifier value of the event. In some embodiments, the in-array manipulation is algorithm-dependent. For example, the in-array manipulation may include checking whether a packet with sequence number T N is a duplicate (like the anti-replay protection algorithm in IPsec), counting how many times an event has occurred, and the like.
[0048] In operation 420, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size (e.g., the second event identifier value being less than or equal to the first event identifier value) in operation 412, the processing logic determines whether the control value for the event (WZ(I N %M)) is asserted. While "asserted" could mean "has a value of zero or one," for the purpose of explaining method 400, "asserted" means "set to one ("1"). If the control value is asserted, method 400 proceeds to operation 424, and if the control value is not asserted (e.g., is unasserted), method 400 proceeds to operation 422.
[0049] In operation 422, in response to the control value being unconfirmed, the processing logic accesses the particular cache line and performs in-array event processing for a cell index value of the particular cache line (c N ) corresponding to the second event identifier value.
[0050] In operation 424, the processing logic determines whether a first cache line value associated with the event identifier value matches that of the particular cache line, e.g., whether i N equal to i SFor example, in operation 424, the processing logic may determine whether the first and second event identifier values are tracked in the same particular cache line of the plurality of cache lines of the array. If the answer is yes, the method 400 proceeds to operations 426 and 428; otherwise, the method 400 proceeds to operations 430 and 432 if the first and second event identifier values are tracked in different cache lines of the plurality of cache lines.
[0051] In operation 426, the processing logic negates the control value in the control cache line, for example, setting the control value to zero.
[0052] In operation 428, the processing logic accesses the cache line (e.g., at i N %M) and initializes cells of the specific cache line from zero to a first cell index value associated with the first event identifier value (e.g., 0:c S). The processing logic further performs an in-array operation on the first cell index value (c S ), followed by performing an in-array operation within the specific cache line for a second cell index value (c N ) associated with the second event identifier value.
[0053] In operation 430, the processing logic negates the control value in the control cache line, for example, setting the control value to zero.
[0054] In operation 432, the processing logic accesses the cache line (e.g., at i N %M) and initializes the cells of the specific cache line. The processing logic further performs an in-array operation within the specific cache line for a second cell index value (c N ) associated with the second event identifier value.
[0055] With additional reference to Fig.4B, as explained, if the determination in operation 414 is "no," the method 400 proceeds to operation 434. In operation 434, the processing logic determines whether it is still in the early stages of tracing events, for example, if the first event identifier value (TS) is less than the size of the event trace window (W). If the answer in operation 434 is "no," the method 400 proceeds to the operations of Fig. 4C. However, if the answer in operation 434 is "yes," the method 400 proceeds to operation 436, where the processing logic determines whether the second event identifier value (T N) is smaller than the size of the event trace window (W). Thus, between operations 434 and 436, processing logic may determine whether both the first event identifier value and the second event identifier value satisfy a condition based on the window size. If the answer in operation 436 is "no," method 400 proceeds to operations 440 and 442.
[0056] In operation 440, in response to determining that the second event identifier value is greater than or equal to the size of the event trace window (W), the processing logic sets the first event identifier value (T S )with the second event identifier value (T N ). The processing logic can then set the control values for the plurality of cache lines from zero to a value less than the specific cache line, e.g., up to i N %M minus one, confirm.
[0057] In operation 442, the processing logic accesses the cache line associated with the event, e.g., at i N %M. The processing logic may initialize the cells of a given cache line from zero to a second cell index value associated with the second event identifier value, for example, 0:c N . The processing logic can then perform an in-array operation on the second cell index value (c N ) associated with the second event identifier value of the event.
[0058] If the answer in operation 436 is "yes," the method proceeds to operation 444, where the processing logic determines whether the control value of the particular cache line is asserted (e.g., WZ(I N%M) is equal to one). If the control value is asserted, the method 400 proceeds to operations 446 and 448, and if the control value is unasserted, the method 400 proceeds to operations 450 and 452.
[0059] In operation 446, the processing logic sets the first event identifier value equal to the second event identifier value and negates the control value for the particular cache line.
[0060] In operation 448, the processing logic accesses the specific cache line (e.g., at i N %M) and initializes the cells of the specific cache line. The processing logic then performs an in-array operation within the specific cache line for a second cell index value (c N ) associated with the second event identifier value of the event.
[0061] In operation 450, the processing logic sets the first event identifier value equal to the second event identifier value.
[0062] In operation 452, the processing logic accesses the particular cache line (e.g., at i N %M) and initializes the cells of the specific cache line. The processing logic then performs an in-array operation within the specific cache line for a second cell index value (c N ) associated with the second event identifier value of the event.
[0063] With additional reference to Fig. 4C, as previously explained, if the answer in operation 434 is "no," the method 400 proceeds to operation 454, where the processing logic determines whether a first cache line value (i S ) associated with the first event identifier, with that of the specific cache line (i N). For example, in operation 454, the processing logic may determine whether the first and second event identifier values are tracked in the same particular cache line of the plurality of cache lines of the array. If the answer in operation 454 is "yes," the method 400 proceeds to operation 456; otherwise, if the first and second event identifier values are tracked in different cache lines of the plurality of cache lines, the method 400 proceeds to operation 470.
[0064] In operation 456, the processing logic determines whether the control value for the particular cache line is negated, e.g., has a zero value. In operation 456 and the operations derived from operation 456, the particular cache line is the same as the first cache line.
[0065] In operation 458, in response to the control value for the particular cache line being asserted (in operation 456), the processing logic sets the first event identifier value equal to the second event identifier value and negates the control value for the particular cache line.
[0066] In operation 460, the processing logic accesses the particular cache line (e.g., at i S %M) and initializes the cells of the particular cache line. The processing logic may then perform an in-array operation within the particular cache line for a first cell index value associated with the first event identifier value, followed by performing an in-array operation within the particular cache line for a second cell index value associated with the second event identifier value.
[0067] In operation 462, in response to negating the control value for the particular cache line (in operation 456), the processing logic sets the first event identifier value equal to the second event identifier value.
[0068] In operation 464, the processing logic accesses the specific cache line (e.g., at i S %M) and initializes the cells of the particular cache line from a first cell index value associated with the first event identifier value plus one to a second cell index value associated with the second event identifier value, e.g., c S+ 1:c N. In other words, the processing logic may initialize cells within an initial cache line associated with the initial cache line value, beyond a first cell index value associated with the first event identifier value, up to a last cell of the initial cache line. The processing logic may further perform in-array event processing within the particular cache line for the second cell index value associated with the second event identifier value of the event.
[0069] In operation 470 (resulting from a negative determination in operation 454), the processing logic determines whether the control value for the particular cache line is asserted. In operation 470 and the operations derived from operation 470, the particular cache line is different from the first cache line.
[0070] In operation 474, in response to the particular cache line being asserted (in operation 470), the processing logic sets the first event identifier value equal to the second event identifier value. The processing logic may further cyclically assert the control values within the control cache line corresponding to a value greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event, e.g., (i S +1)%M:(i N %M).
[0071] In operation 478, the processing logic accesses the particular cache line (e.g., at i S%M) and initializes the cells for an initial cache line corresponding to the initial cache line value. The processing logic performs an in-array operation within the initial cache line for a first cell index value associated with the first event identifier value.
[0072] In operation 480, in response to the particular cache line being negated (in operation 470), the processing logic sets the first event identifier value equal to the second event identifier value. The processing logic may further cyclically assert the control values within the control cache line corresponding to a value greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event, e.g., (i S +1)%M:(i N %M).
[0073] In operation 484, the processing logic accesses the specific cache line, e.g., at i S %M, and initializes cells within an initial cache line corresponding to the initial cache line value, starting from a value greater than a first cell index value associated with the first event identifier value, to an end of the initial cache line, e.g., c S +1:L-1.
[0074] Fig. 5A is a diagram illustrating a current array active window and current cache control values when certain new packets are received, as tracked over time using identifier values (or sequence numbers) of the new packets, according to some embodiments. Fig. 5B is a diagram of Fig.5A is a coherent diagram illustrating, according to some embodiments, the updates associated with both the control values and the cell values located at various cell index values of the active window of the array based on the identifiers (or sequence numbers) of the new packets. While the example of Fig. 5A-5B are representations for packets, e.g., for use in the IPsec implementation of anti-replay protection, which requires a single bit per cell in the array, a sufficiently knowledgeable person in the art would recognize the extension of the application of this cyclic array tracking to other applications and areas.
[0075] As can be seen, the example of Fig.5A-5B illustrate an array of four cache lines, where each cache line contains four cell positions that can be updated to track events. Actual implementations may be much larger, but this size is used for explanatory purposes in this disclosure and is therefore merely exemplary. Table 1 may again be helpful in understanding which variables are referenced and how they are defined.
[0076] In various embodiments, each new packet is assigned a sequence number or identifier (T N ) in relation to a current T S -value (initialized to zero) in Fig. 5A shows the values in the current array and in the current control cache line before each new packet arrives. Fig.Figure 5B, on the other hand, shows how the array changes based on the changes generated by the algorithm based on the new packet (e.g., into a “new array”). The new array becomes the “Current Array” in Fig. 5A before the next new packet arrives, which in turn causes additional updates as the flow moves between Fig. 5A and Fig. 5B. The term “Expiration”, which is shown on the right side of the diagram in Fig. 5A, indicates the relative values of many of the variables used by the algorithm of method 400 of Fig. 4A-4C, and is therefore helpful in determining how the method 400 applies to the specific example of Fig. 5A-5B applies.
[0077] In the illustrative embodiment, the first incoming new packet has a sequence number (T N) three (“3”), the control values are initialized to one (“1”), and the current array values are initialized to “X”, which means that the algorithm does not care what the values are at this point, since these values are updated based on the sequence numbers of incoming packets. Note that for T S <W die Zellen rechts von der Position von T S Information for sequence numbers higher than T S Cell indices generally do not change with events, as the cell indices in each cache line remain between 0 and L-1. Since this happens early in the array update, the relative values of T S , T N , i N , i S , the process in the operations of Fig. 4B. As in Fig.As shown in Figure 5B, the cell index values are initialized (since WZ(0) is equal to one) and the third cell (index 2) of the first cache line is updated to "Y" for "Yes" to confirm receipt. In addition, the control value for WZ(0) is updated to zero, e.g., negated, to indicate that the first cache line contains current / valid data and does not need to be initialized. Finally, the first event identifier value (T S ) is set to three, the incoming sequence number of the new packet. These are the current values before the next new packet is received. In some embodiments, the "N" value may be represented by a zero and a "Y" value by a one, but these values may also be reversed.
[0078] The second packet to be received has a sequence number of six (“6”), which is generally processed in the same way as the packet with sequence number three, as just explained. However, the sequence number coincides with a cell index value in the second cache line, so the second cache line now has “N” values, except for the third cell in the second cache line (index 2), which has a “Y” value (see Fig. 5B). The control value for WZ(1) is updated to zero, similar to what happened with the control value corresponding to the first cache line.
[0079] The third packet to be received has a sequence number of one ("1"), which is located in the first cache line. Since the control value WZ(0) for the first cache line is zero, the second cell (index 1), which corresponds to the sequence number, is updated to "Y", as shown in Fig.5B. This third new package may not require any further updates.
[0080] The fourth new packet has a sequence number eight (“8”), which is located in the third cache line. As in Fig. 5B, similar updates are made to the array and control values as in response to receiving the packet with sequence number six, except for the third cache line. Specifically, the third cache line is initialized to "N" values, except that the first cell (index 0) matching the sequence number for the new event is updated to "Y." In addition, the control value for WZ(2) associated with the second cache line is also set to zero.
[0081] The fifth next packet has a sequence number of 23, which sets the high sequence number so that the current Ts is lower than W, e.g., T S<W. Außerdem wird das neue Fenster so verschoben, dass es die Sequenznummer 23 umfasst, und T N is greater than W, e.g. T N >W. Thus, the decision-making in this situation is based on operations 440 and 442 of Fig. 4B. As in Fig. As shown in Figure 5B, the window of cells has expanded to cell index values 8-23, and sequence number 23 inserts updates into the second cache line. Since the first cache line has invalid (stale) values for cells 16-19, the control value WZ(0) is reset to one, which means that the first cache line must be initialized during the next update. Note that the cells to the right of T S were not set to zero because T S <W ist. Von nun an enthalten die Zellen rechts von T S Information for smaller sequence numbers.
[0082] The sixth packet has a sequence number of 50, which means that TS <T N is, I N >i S + M, which divides the decision flow into operations 416 and 418 in Fig. 4A. As in Fig. 5B, the window shifts cyclically to higher sequence numbers to capture sequence number 50, which is now defined by values from 35 to 50. The value of T S becomes the value of T N and all control values are set to one (e.g. initialized), except for WZ(0) for the cache line containing T N of 50, which is set to zero. The values of the first cache line are initialized to "N," and the bit value in the third cell (index 2) of the first cache line, corresponding to the sequence number value 50, is set to "Y."
[0083] The seventh packet has a sequence number 53, which is higher than the previous sequence number 50. This means that T S <T N is, i N <=i S+M is and T S >=W, which divides the decision flow into operations 474 and 478 in Fig. 4C shifted. Since T S >W, the algorithm causes an update of the cache line containing T S (e.g., the first cache line), and cyclically shifts W to a higher range to capture sequence number 53, which is now defined by cell index values 38-53 (see Fig. 5B). In this case, the algorithm sets the third cell in the first cache line to zero, because cell number three changes its sequence number from 35 to 51, which had not yet been received. Cell index three already had the value "N," but the algorithm could not know this, so it accesses cell index three and sets its value to "N." To avoid accessing a second cache line in the array, the algorithm sets WZ(1) to one ("1"), even though WZ(1) already has that value.
[0084] The eighth (and last) packet for this example has a sequence number 55, which is a higher sequence number than the previous sequence number 53. In addition, i N equal to i S , so that the algorithm can access the second cache line of the previous Ts and the operations 458 and 460 of Fig. 4C can follow. As in Fig. 5B, the algorithm can then search the second cache line up to cell c N , which is the fourth cell (index 3) of the second cache line, to "N" (or zero) values and update the second cell (index 1 for sequence number 53) and then the fourth cell (index 3 for sequence number 55), e.g., in-array editing for both c S as well as c NThis minimizes cache line accesses, and allows updates for multiple incoming packets to be performed simultaneously on a single cache line. Furthermore, the WZ(1) control value for the second cache line can be set to zero, indicating that the data is valid and no initialization is required before accessing the second cache line.
[0085] Fig. 6 is a block diagram illustrating an example computing device 600 according to implementations of the present disclosure. Computing device 600 may be associated with computing system 102 of distributed system 100 ( Fig.1). The example computing device 600 may be connected to other computing devices on a LAN, an intranet, an extranet, and / or the Internet. The computing device 600 may operate as a server in a client-server network environment. The computing device 600 may be a personal computer (PC), a set-top box (STB), a server, a network router, a switch, or a bridge, or any device capable of executing a series of instructions (sequential or otherwise) that specify the actions to be performed by that device. Although only a single computing device is illustrated, the term "computer" is intended to include any collection of computers that individually or collectively execute a set (or sets) of instructions to perform one or more of the methods discussed herein.
[0086] The example computing device 600 may include a processing device 602 (also referred to as a processor, CPU, or GPU), a volatile memory 604 (or main memory, e.g., read-only memory (ROM), flash memory, dynamic random access memory (DRAM) such as synchronous DRAM (SDRAM), etc.), a non-volatile memory 606 (e.g., flash memory, static random access memory (SRAM), etc.), and secondary storage (e.g., a data storage device 616), which may communicate with each other via a bus 630.
[0087] Processing device 602 (which may include processing logic 622) represents one or more general-purpose processing devices, such as a microprocessor, a central processing unit, or the like. In particular, processing device 602 may be a complex instruction set computing (CISC) microprocessor, a reduced instruction set computing (RISC) microprocessor, a very long instruction word (VLIW) microprocessor, a processor implementing other instruction sets, or a processor implementing a combination of instruction sets. Processing device 602 may also be one or more special-purpose processing devices, such as an ASIC, an FPGA, a digital signal processor (DSP), a network processor, or the like.According to one or more aspects of the present disclosure, the processing device 602 may be configured to execute instructions that implement the method 300 for implementing out-of-band threat prevention.
[0088] The example computing device 600 may further include a network interface 608 communicatively connectable to a network 620. The example computing device 600 may further include a video display 610 (e.g., a liquid crystal display (LCD), a touch screen, or a cathode ray tube (CRT)), an alphanumeric input device 612 (e.g., a keyboard), a cursor control device 614 (e.g., a mouse), and an audible signal generating device 618 (e.g., a speaker).
[0089] The data storage device 616 may include a computer-readable storage medium (or more specifically, a non-transitory computer-readable storage medium) 624 having one or more sets of executable instructions 626 stored thereon. According to one or more aspects of the present disclosure, the executable instructions 626 may include executable instructions that perform the method 300 for implementing out-of-band threat prevention.
[0090] The executable instructions 626 may also be located entirely or at least partially in the volatile memory 604 and / or the processing device 602 while being executed by the example computing device 600, where the volatile memory 604 and the processing device 602 also represent computer-readable storage media. The executable instructions 626 may further be transmitted or received over a network via the network interface 608.
[0091] While the computer-readable storage medium 624 in Fig.6 as a single medium, the term "computer-readable storage medium" or "non-transitory computer-readable storage medium storing instructions" should be understood to include a single medium or multiple media (e.g., a centralized or distributed database and / or associated caches and servers) that store the one or more sets of operating instructions. The term "computer-readable storage medium" is also intended to include any medium capable of storing or encoding a set of instructions for execution by the machine that causes the machine to perform one or more of the methods described herein. The term "computer-readable storage medium" is accordingly intended to include, but is not limited to, solid-state storage, optical, and magnetic media.
[0092] Some parts of the above detailed descriptions are presented in terms of algorithms and symbolic representations of operations on bits of data in a computer memory. These algorithmic descriptions and representations are the means employed by those skilled in the data processing field to most effectively communicate the content of their work to other professionals. An algorithm is understood here and generally as a self-consistent sequence of steps that leads to a desired result. The steps are those that require physical manipulation of physical quantities. Usually, but not necessarily, these quantities take the form of electrical or magnetic signals that can be stored, transmitted, combined, compared, and otherwise manipulated.It has sometimes proved convenient, particularly for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like.
[0093] It should be borne in mind, however, that all these and similar terms are to be associated with the corresponding physical quantities and are merely convenient labels applied to those quantities. Unless expressly stated otherwise, as will be apparent from the following discussion, it is understood that throughout this specification discussions using terms such as "identify," "determine," "store," "set," "cause," "return," "compare," "create," "stop," "load," "copy," "throw," "replace," "occur," or the like refer to the operations and processes of a computer system or similar electronic computing device.manipulates the data represented as physical (electronic) quantities in the registers and memories of the computer system and converts it into other data that are similarly represented as physical quantities in the memories or registers of the computer system or other devices for information storage, transmission or display.
[0094] Examples of the present disclosure also relate to an apparatus for performing the methods described herein. This apparatus may be specially constructed for the required purposes, or it may be a general-purpose computer system that is selectively programmed by a computer program stored in the computer system. Such a computer program may be stored in a computer-readable storage medium, such as, but not limited to, any type of drive, including optical drives, CD-ROMs and magnetic-optical drives, read-only memories (ROMs), random access memories (RAMs), EPROMs, EEPROMs, magnetic disk storage media, optical storage media, flash memory devices, other types of machine-accessible storage media, or any type of media suitable for storing electronic instructions, each coupled to a computer system bus.
[0095] The methods and displays presented herein are inherently tied to a particular computer or other device. Various general systems may be used with programs according to the teachings presented herein, or it may prove useful to construct a more specialized device to perform the required method steps. The required structure for a variety of these systems is presented in the following description. Furthermore, the scope of the present disclosure is not limited to any particular programming language. It is contemplated that a variety of programming languages may be used to implement the teachings of the present disclosure.
[0096] It should be understood that the above description is illustrative only and not restrictive. Many other implementation examples will become apparent to those skilled in the art upon reading and understanding the above description. Although the present disclosure describes specific examples, it will be appreciated that the systems and methods of the present disclosure are not limited to the examples described herein, but may be practiced with modifications within the scope of the appended claims. Accordingly, the description and drawings are to be regarded in an illustrative rather than a restrictive sense. The scope of the present disclosure should, therefore, be determined by reference to the appended claims, as well as to the full extent of equivalents to which such claims are entitled.
[0097] Other variations are within the scope of the present disclosure. Thus, while the disclosed techniques are susceptible to various modifications and alternative constructions, certain illustrative embodiments thereof are shown in the drawings and have been described in detail above. It should be understood, however, that the disclosure is not intended to limit the disclosure to any particular disclosed form or forms, but, on the contrary, is intended to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the disclosure as defined by the appended claims.
[0098] The use of the terms "a," "an," "the," "the," and "the," and similar designations in connection with the description of disclosed embodiments (particularly in connection with the following claims) is to be construed to include both the singular and the plural, unless otherwise stated herein or clearly contradicted by context, and not as a definition of any term. The terms "comprising," "with," "including," and "containing" are to be construed as open-ended terms (i.e., "including, but not limited to") unless otherwise specified. The term "connected," when left unchanged and referring to physical connections, is to be construed as "partially or wholly contained, attached to, or connected to," even if something in between.The specification of ranges of values is intended herein merely as a shorthand method to refer individually to each value falling within the range, unless otherwise noted herein, and each value is included in the description as if listed individually herein. In at least one embodiment, use of the term "set" (e.g., "a set of items") or "subset" is to be understood, unless otherwise noted or contradicted by context, to refer to a non-empty collection comprising one or more items. Unless otherwise noted or contradicted by context, the term "subset" of a corresponding set does not necessarily denote a proper subset of the corresponding set; rather, the subset and the corresponding set may be the same.
[0099] Conjunctive phrases such as sentences in the form "at least one of A, B, and C" or "at least one of A, B, and C," unless explicitly stated otherwise or clearly contradicted by the context, are generally understood to mean that an element, term, etc., can be either A or B or C, or any non-empty subset of the set A and B and C. In an illustrative example for a sentence with three elements, the conjunctive phrases "at least one of A, B, and C" and "at least one of A, B, and C" refer to one of the following sentences: {A}, {B}, {C}, {A, B}, {A, C}, {B, C}, {A, B, C}. Thus, such conjunctive phrases are not intended to generally imply that at least one of A, at least one of B, and at least one of C must be present in certain embodiments. Unless otherwise noted or contradicted by the context, the term “multiplicity” refers to a state of plurality (e.g."a plurality of elements" means multiple elements. In at least one embodiment, the number of items in a plurality is at least two, but may be more if indicated either explicitly or by context. Unless otherwise stated or clear from context, the phrase "based on" means "at least partially based on" and not "solely based on."
[0100] The operations of the processes described herein may be performed in any suitable order, unless otherwise specified herein or the context clearly dictates otherwise. In at least one embodiment, a process such as the processes described herein (or variations and / or combinations thereof) is performed under the control of one or more computer systems configured with executable instructions and implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that are collectively executed on one or more processors, by hardware, or combinations thereof. In at least one embodiment, code is stored on a computer-readable storage medium, e.g., in the form of a computer program comprising a plurality of instructions executable by one or more processors.In at least one embodiment, a computer-readable storage medium is a non-transitory computer-readable storage medium that excludes volatile signals (e.g., propagating transient electrical or electromagnetic transmission) but includes non-transitory data storage circuitry (e.g., buffers, cache, and queues) within transceivers for volatile signals. In at least one embodiment, code (e.g., executable code or source code) is stored on a set of one or more non-transitory computer-readable storage media that store executable instructions (or other memory for storing executable instructions) that, when executed by one or more processors of a computer system (i.e., as a result of execution), cause a computer system to perform operations described herein.In at least one embodiment, a set of non-transitory computer-readable storage media comprises a plurality of non-transitory computer-readable storage media, and one or more of the individual non-transitory storage media of the plurality of non-transitory computer-readable storage media lack all code, while the plurality of non-transitory computer-readable storage media collectively store all code. In at least one embodiment, the executable instructions are executed such that different instructions are executed by different processors.
[0101] Accordingly, in at least one embodiment, computer systems are configured to implement one or more services that individually or collectively perform operations of the processes described herein, and such computer systems are configured with suitable hardware and / or software that enable operations to be performed. Further, a computer system implementing at least one embodiment of the present disclosure is a single device, and in another embodiment, a distributed computer system that includes multiple devices that operate differently, such that a distributed computer system performs the operations described herein and a single device does not perform all operations.
[0102] The use of any and all examples or exemplary language (e.g., "such as") is intended only to better illustrate embodiments of the disclosure and does not limit the scope of the disclosure unless otherwise claimed. No language in the specification should be construed to infer any unclaimed element as essential to the practice of the disclosure.
[0103] All references cited herein, including publications, patent applications, and patents, are hereby incorporated by reference to the same extent as if each reference were individually and expressly indicated to be incorporated by reference and reproduced herein in its entirety.
[0104] The terms "coupled" and "connected," and their derivatives, may be used in the description and claims. These terms are not synonymous. Rather, in certain examples, "connected" or "coupled" may be used to indicate that two or more elements are in direct or indirect physical or electrical contact with each other. "Coupled" can also mean that two or more elements are not in direct contact with each other, but still cooperate or interact with each other.
[0105] Unless expressly stated otherwise, terms such as "processing", "computing", "calculating", "determining", etc. throughout the specification refer to actions and / or processes of a computer or computer system or similar electronic computing device that manipulate and / or convert data represented as physical, such as electronic, quantities in the registers and / or memories of the computer system into other data similarly represented as physical quantities in the memories, registers, or other information storage, transmission, or display devices of the computer system.
[0106] Similarly, the term "processor" can refer to any device or part of a device that processes electronic data from registers and / or memory and converts that electronic data into other electronic data that can be stored in registers and / or memory. As non-limiting examples, "processor" can be a network device or a MACsec device. A "computing platform" can include one or more processors. As used herein, the term "software" processes can include, for example, software and / or hardware units that perform work over time, such as tasks, threads, and intelligent programs. Each process can also refer to multiple processes for executing instructions sequentially or in parallel, continuously or intermittently.In at least one embodiment, the terms "system" and "method" are used interchangeably herein, as the system may include one or more methods and the methods may be considered a system.
[0107] In this document, reference may be made to obtaining, acquiring, receiving, or inputting analog or digital data to a subsystem, computer system, or computer-implemented machine. In at least one embodiment, the process of obtaining, acquiring, receiving, or inputting analog and digital data may be performed in various ways, such as by receiving data as a parameter of a function call or an application programming interface call. In at least one embodiment, processes for obtaining, acquiring, receiving, or inputting analog or digital data may be performed by transmitting data over a serial or parallel interface.In at least one embodiment, processes for acquiring, capturing, receiving, or inputting analog or digital data may be performed by transmitting data over a computer network from the providing entity to the capturing entity. In at least one embodiment, reference may also be made to providing, outputting, communicating, transmitting, or presenting analog or digital data. In various examples, processes for providing, outputting, communicating, transmitting, or presenting analog or digital data may be performed by transmitting data as an input or output parameter of a function call, as a parameter of an application programming interface, or as an interprocess communication mechanism.
[0108] Although the present descriptions set forth embodiments of the described techniques, other architectures may be used to implement the described functions, which are intended to be within the scope of this disclosure. While certain distributions of responsibilities may be defined above for descriptive purposes, various functions and responsibilities may be distributed and allocated in different ways depending on the circumstances.
[0109] Although the subject matter has been described in language referring to structural features and / or methodological acts, it is to be understood that the subject matter claimed in the appended claims is not necessarily limited to the specific features or acts described. Rather, certain features and acts are disclosed as exemplary forms of implementing the claims.
[0110] It is to be understood that aspects and embodiments described above are by way of example only and that changes in detail may be made within the scope of the claims.
[0111] Each device, method, and feature disclosed in the description and (where appropriate) in the claims and drawings may be provided independently or in any suitable combination.
[0112] The reference signs contained in the claims are for illustrative purposes only and are not intended to limit the scope of the claims.
[0113] The disclosure of this application also includes the following numbered clauses: Clause 1. Device comprising: a cache for storing an array that tracks the occurrence of a plurality of events; and a processing device connected to the cache, the processing device being operable to: track a plurality of control values associated with a state of a plurality of cache lines of the array; track, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and in response to detecting an event, update a first value of a particular cache line of the plurality of cache lines based on a control value corresponding to the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window. Clause 2. The apparatus of clause 1, wherein in response to receiving any event, at most the plurality of control values and a single cache line of the array are accessed. Clause 3. The apparatus of clause 1, wherein values within the plurality of cache lines comprise indicators corresponding to unique network packets received over a network, and wherein at most the plurality of control values and a single cache line of the array are accessed in response to receipt of any network packet. Clause 4. Apparatus according to Clause 3, wherein the window size is determined based on an expected maximum difference between packet identifier values of incoming packets. Clause 5. Apparatus according to clause 1, wherein the processing means for tracking the window of cell index values is further to cyclically shift the window in response to any event having a cell index value that is outside the window. Clause 6. The apparatus of clause 1, wherein the plurality of control values indicate whether corresponding cache lines are to be initialized, and wherein the processing apparatus is further operable to: to negate an initial tax value; to confirm a set of remaining tax values from the plurality of tax values; setting a first event identifier value, which is a maximum value for received events, to an initial value before tracking all received events begins; initialize cells of the cache line associated with the initial control value; and Initialize cells of the particular cache line in response to the control value associated with the particular cache line being asserted. Clause 7. The device according to Clause 1, wherein the processing device further serves to: determine a first event identifier value that is a maximum value for received events; determine a second event identifier value for the event; and to perform a comparison based on the first event identifier value and the second event identifier value. Clause 8. The apparatus of clause 7, wherein the processing device is further operable to perform out-of-array event processing for the event in response to the second event identifier value being too small to be tracked by the window. Clause 9. The apparatus of clause 7, wherein the processing device is further operable to perform out-of-array event processing for the event in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size. Clause 10. Device according to Clause 7, wherein the processing device further serves to: determine a first cell index value as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines; determine a first cache line value of the plurality of cache lines as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines associated with the first event identifier value; determine a second cell index value as a combination of the second event identifier value and the number of possible tracked events for each of the plurality of cache lines; and determine a second cache line value of the plurality of cache lines as a combination of the second event identifier and the number of possible tracked events for each of the plurality of cache lines associated with the second event identifier value. Clause 11. Apparatus according to clause 7, wherein the processing device is further operable, in response to the second event identifier value being within the window: to determine a state of the tax value; and to initialize some cells of the specific cache line depending on the state; and perform an in-array operation on a cell index value associated with at least one of the first event identifier value and the second event identifier value within the particular cache line. Clause 12. The apparatus of clause 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: determine that the control value associated with the particular cache line is negated; and perform in-array event processing for a second cell index value of the particular cache line associated with the second event identifier value. Clause 13. The apparatus of clause 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: to determine that the tax value is confirmed; determine that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; negate the control value associated with the specific cache line; initialize cells of the particular cache line from a first cell up to and including a first cell index value associated with the first event identifier value; perform an in-array operation on the first cell index value associated with the first event identifier value within the particular cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value within the particular cache line. Clause 14. The apparatus of clause 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: to determine that the tax value is confirmed; determine that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; to negate the tax value; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value within the particular cache line. Clause 15. Apparatus according to clause 7, wherein the processing device is further operable, in response to the second event identifier value being large enough such that there is no overlap between the events currently tracked by the window and the events that will be tracked by the window after the event has been processed: set the first event identifier value equal to the second event identifier value; to assert control values, except for the control value associated with the particular cache line; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 16. The apparatus of clause 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; set the first event identifier value equal to the second event identifier value; to assert control values, except for the control value associated with the particular cache line; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 17. The apparatus of clause 7, wherein the processing device is further operable, in response to the second event identifier value of the event being outside the window and still at an early stage of tracking the events, the first event identifier value satisfying a condition based on the window size: determine that a second cache line value of the array for the event satisfies a condition based on a first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; set the first event identifier value equal to the second event identifier value; to determine a state for some of the control values; to initialize some cells of the specific cache line depending on the state; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 18. The apparatus of Clause 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that both the first event identifier value and the second event identifier value satisfy a condition based on the window size; determine that the control value associated with the particular cache line is negated; set the first event identifier value equal to the second event identifier value; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 19. The apparatus of Clause 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that both the first event identifier value and the second event identifier value satisfy a condition based on the window size; determine that the control value associated with the particular cache line is asserted; set the first event identifier value equal to the second event identifier value; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 20. The apparatus of clause 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that the first event identifier value satisfies a condition based on the window size; determine that the second event identifier value satisfies a condition based on the window size; set the first event identifier value equal to the second event identifier value; assert the control values for the plurality of cache lines from a control value associated with a first cache line of the array and up to a value less than a control value associated with the particular cache line; initialize the cells of the particular cache line from a first cell of the particular cache line and up to a second cell index value associated with the second event identifier value; and perform an in-array operation on the second cell index value associated with the second event identifier value of the event within the particular cache line. Clause 21. Procedure which includes: Storing, by a processing device, an array tracking a plurality of events in a cache; tracking a plurality of control values associated with a state of a plurality of cache lines of the array; Tracking, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and Updating, in response to detecting an event, a first value of a particular cache line of the plurality of cache lines based on a control value associated with the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window. Clause 22. The method of Clause 21, wherein updating the first value of the particular cache line in response to receiving any event accesses at most the plurality of control values and a single cache line of the array. Clause 23. The method of Clause 21, wherein values within the plurality of cache lines comprise indicators corresponding to unique network packets received over a network, and wherein at most the plurality of control values and a single cache line of the array are accessed in response to receipt of any network packet. Clause 24. The method of Clause 21, wherein tracking the window of cell index values further comprises cyclically shifting the window in response to any event outside the window. Clause 25. The method of Clause 21, wherein the control values indicate whether corresponding cache lines should be initialized, further comprising: Confirming the plurality of control values and setting a first event identifier value, which is a maximum value for received events, to an initial value before tracking all received events; and Initializing cells of the particular cache line in response to the control value associated with the particular cache line being asserted. Clause 26. Procedure under Clause 21, which further includes: Determining a first event identifier value that is a maximum value for received events; Determining a second event identifier value for the event; and Comparing the first event ID value with the second event ID value. Clause 27. The method of Clause 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size, performing out-of-array event processing for the event. Clause 28. Procedure under Clause 26, which further includes: Determining a first cell index value as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines; Determining a first cache line value of the plurality of cache lines associated with the first event identifier value; Determining a second cell index value as a combination of the second event identifier value and the number of possible tracked events for each of the plurality of cache lines; and Determining a second cache line value of the plurality of cache lines associated with the second event identifier value. Clause 29. The method of clause 26, wherein the processing device is further operable, in response to the second event identifier value being outside the window: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that the first event identifier value satisfies a condition based on the window size; determine that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; set the first event identifier value equal to the second event identifier value; to determine a state of the tax value; to initialize some of the cells of a first cache line; and perform an in-array operation within the first cache line on a cell index value that corresponds to at least one of the first event identifier value or the second event identifier value. Clause 30. The method of Clause 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; determining that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; determining that the control value associated with the particular cache line is negated; Setting the first event identifier value equal to the second event identifier value; Initializing the cells of an initial cache line from a first cell index value associated with the first event identifier value plus one to a second cell index value associated with the second event identifier value; and Performing an in-array operation on the second cell index value associated with the second event identifier value of the event within the initial cache line. Clause 31. The method of Clause 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; Determining that the control value associated with the particular cache line is asserted; Setting the first event identifier value equal to the second event identifier value; negating the control value associated with the specific cache line; Initializing the cells for an initial cache line from a first cell of the initial cache line up to a second cell index value associated with the second event identifier value; performing an in-array operation on a first cell index value associated with the first event identifier value within the initial cache line; and Performing an in-array operation on a second cell index value associated with the second event identifier value within the initial cache line. Clause 32. The method of Clause 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; determining that the control value associated with the particular cache line is negated; Setting the first event identifier value equal to the second event identifier value; Asserting the control values associated with those that are greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event; and Initializing cells within an initial cache line associated with the initial cache line value from outside a first cell index value associated with the first event identifier value to a last cell of the initial cache line. Clause 33. The method of Clause 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; Determining that the control value associated with the particular cache line is asserted; Setting the first event identifier value equal to the second event identifier value; Asserting the control values associated with those greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event; Initializing the cells for a cache line associated with the initial cache line value; and Performing an in-array operation on a first cell index value associated with the first event identifier value within the initial cache line. Clause 34. Non-transitory computer-readable storage medium storing instructions that, when executed by a processing device connected to a cache, cause the processing device to perform operations that include: Storing an array tracking a plurality of events in the cache; tracking a plurality of control values associated with a state of a plurality of cache lines of the array; Tracking, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and Updating, in response to detecting an event, a first value of a particular cache line of the plurality of cache lines based on control values corresponding to the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window. QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] US 311,073
[0001]
Claims
[1] Device comprising: a cache for storing an array that tracks the occurrence of a plurality of events; and a processing device connected to the cache, the processing device being operable to: track a plurality of control values associated with a state of a plurality of cache lines of the array; track, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and in response to detecting an event, update a first value of a particular cache line of the plurality of cache lines based on a control value corresponding to the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window. [2] The apparatus of claim 1, wherein in response to receiving any event, at most the plurality of control values and a single cache line of the array are accessed. [3] The apparatus of claim 1 or 2, wherein values within the plurality of cache lines comprise indicators corresponding to unique network packets received over a network, and wherein at most the plurality of control values and a single cache line of the array are accessed in response to receipt of any network packet. [4] The apparatus of claim 3, wherein the window size is determined based on an expected maximum difference between packet identifier values of incoming packets. [5] Apparatus according to any preceding claim, wherein the processing means for tracking the window of cell index values is further to cyclically shift the window in response to any event having a cell index value that is outside the window. [6] Apparatus according to any one of the preceding claims, wherein the plurality of control values indicate whether corresponding cache lines are to be initialized, and wherein the processing device is further arranged to: to negate an initial tax value; to confirm a set of remaining tax values from the plurality of tax values; setting a first event identifier value, which is a maximum value for received events, to an initial value before tracking all received events begins; initialize cells of the cache line associated with the initial control value; and Initialize cells of the particular cache line in response to the control value associated with the particular cache line being asserted. [7] Apparatus according to any one of the preceding claims, wherein the processing device further serves to: determine a first event identifier value that is a maximum value for received events; determine a second event identifier value for the event; and to perform a comparison based on the first event identifier value and the second event identifier value. [8] The apparatus of claim 7, wherein the processing device is further operable to perform out-of-array event processing for the event in response to the second event identifier value being too small to be tracked by the window. [9] The apparatus of claim 7, wherein the processing device is further operable to perform out-of-array event processing for the event in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size. [10] The apparatus of claim 7, wherein the processing device further serves to: determine a first cell index value as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines; determine a first cache line value of the plurality of cache lines as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines associated with the first event identifier value; determine a second cell index value as a combination of the second event identifier value and the number of possible tracked events for each of the plurality of cache lines; and determine a second cache line value of the plurality of cache lines as a combination of the second event identifier and the number of possible tracked events for each of the plurality of cache lines associated with the second event identifier value. [11] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value being within the window: to determine a state of the tax value; and to initialize some cells of the specific cache line depending on the state; and perform an in-array operation on a cell index value associated with at least one of the first event identifier value and the second event identifier value within the particular cache line. [12] The apparatus of claim 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: determine that the control value associated with the particular cache line is negated; and perform in-array event processing for a second cell index value of the particular cache line associated with the second event identifier value. [13] The apparatus of claim 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: to determine that the tax value is confirmed; determine that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; negate the control value associated with the specific cache line; initialize cells of the particular cache line from a first cell up to and including a first cell index value associated with the first event identifier value; perform an in-array operation on the first cell index value associated with the first event identifier value within the particular cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value within the particular cache line. [14] The apparatus of claim 11, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size: to determine that the tax value is confirmed; determine that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; to negate the tax value; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value within the particular cache line. [15] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value being large enough such that there is no overlap between the events currently tracked by the window and the events that will be tracked by the window after the event has been processed: set the first event identifier value equal to the second event identifier value; to assert control values, except for the control value associated with the particular cache line; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. [16] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; set the first event identifier value equal to the second event identifier value; to assert control values, except for the control value associated with the particular cache line; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. [17] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value of the event being outside the window and still at an early stage of tracking the events, the first event identifier value satisfying a condition based on the window size: determine that a second cache line value of the array for the event satisfies a condition based on a first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; set the first event identifier value equal to the second event identifier value; to determine a state for some of the control values; to initialize some cells of the specific cache line depending on the state; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. [18] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that both the first event identifier value and the second event identifier value satisfy a condition based on the window size; determine that the control value associated with the particular cache line is negated; set the first event identifier value equal to the second event identifier value; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. [19] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that both the first event identifier value and the second event identifier value satisfy a condition based on the window size; determine that the control value associated with the particular cache line is asserted; set the first event identifier value equal to the second event identifier value; negate the control value associated with the specific cache line; to initialize the cells of the specific cache line; and perform an in-array operation on a second cell index value associated with the second event identifier value of the event within the particular cache line. [20] The apparatus of claim 7, wherein the processing device is further operable, in response to the second event identifier value satisfying a condition based on the first event identifier value: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that the first event identifier value satisfies a condition based on the window size; determine that the second event identifier value satisfies a condition based on the window size; set the first event identifier value equal to the second event identifier value; assert the control values for the plurality of cache lines from a control value associated with a first cache line of the array and up to a value less than a control value associated with the particular cache line; initialize the cells of the particular cache line from a first cell of the particular cache line and up to a second cell index value associated with the second event identifier value; and perform an in-array operation on the second cell index value associated with the second event identifier value of the event within the particular cache line. [21] Procedure comprising: Storing, by a processing device, an array tracking a plurality of events in a cache; tracking a plurality of control values associated with a state of a plurality of cache lines of the array; Tracking, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and Updating, in response to detecting an event, a first value of a particular cache line of the plurality of cache lines based on a control value associated with the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window. [22] The method of claim 21, wherein updating the first value of the particular cache line in response to receiving any event accesses at most the plurality of control values and a single cache line of the array. [23] The method of claim 21 or 22, wherein values within the plurality of cache lines comprise indicators corresponding to unique network packets received over a network, and wherein at most the plurality of control values and a single cache line of the array are accessed in response to receipt of any network packet. [24] The method of claim 21, 22 or 23, wherein tracking the window of cell index values further comprises cyclically shifting the window in response to any event outside the window. [25] The method of claims 21 to 24, wherein the control values indicate whether corresponding cache lines should be initialized, further comprising: Confirming the plurality of control values and setting a first event identifier value, which is a maximum value for received events, to an initial value before tracking all received events; and Initializing cells of the particular cache line in response to the control value associated with the particular cache line being asserted. [26] A method according to any one of claims 21 to 25, further comprising: Determining a first event identifier value that is a maximum value for received events; Determining a second event identifier value for the event; and Comparing the first event ID value with the second event ID value. [27] The method of claim 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value and the window size, performing out-of-array event processing for the event. [28] The method of claim 26, further comprising: Determining a first cell index value as a combination of the first event identifier value and a number of possible tracked events for each of the plurality of cache lines; Determining a first cache line value of the plurality of cache lines associated with the first event identifier value; Determining a second cell index value as a combination of the second event identifier value and the number of possible tracked events for each of the plurality of cache lines; and Determining a second cache line value of the plurality of cache lines associated with the second event identifier value. [29] The method of claim 26, wherein the processing device is further operable, in response to the second event identifier value being outside the window: determine that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determine that the first event identifier value satisfies a condition based on the window size; determine that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; set the first event identifier value equal to the second event identifier value; to determine a state of the tax value; to initialize some of the cells of a first cache line; and perform an in-array operation within the first cache line on a cell index value that corresponds to at least one of the first event identifier value or the second event identifier value. [30] The method of claim 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; determining that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; determining that the control value associated with the particular cache line is negated; Setting the first event identifier value equal to the second event identifier value; Initializing the cells of an initial cache line from a first cell index value associated with the first event identifier value plus one to a second cell index value associated with the second event identifier value; and Performing an in-array operation on the second cell index value associated with the second event identifier value of the event within the initial cache line. [31] The method of claim 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in the particular cache line of the plurality of cache lines; Determining that the control value associated with the particular cache line is asserted; Setting the first event identifier value equal to the second event identifier value; negating the control value associated with the specific cache line; Initializing the cells for an initial cache line from a first cell of the initial cache line up to a second cell index value associated with the second event identifier value; performing an in-array operation on a first cell index value associated with the first event identifier value within the initial cache line; and Performing an in-array operation on a second cell index value associated with the second event identifier value within the initial cache line. [32] The method of claim 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; determining that the control value associated with the particular cache line is negated; Setting the first event identifier value equal to the second event identifier value; Asserting the control values associated with those that are greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event; and Initializing cells within an initial cache line associated with the initial cache line value from outside a first cell index value associated with the first event identifier value to a last cell of the initial cache line. [33] The method of claim 26, further comprising, in response to the second event identifier value satisfying a condition based on the first event identifier value: determining that a second cache line value of the array for the event satisfies a condition based on the first cache line value associated with the first event identifier value and a number of the plurality of cache lines of the array; Determining that the first event identifier value satisfies a condition based on the window size; determining that the first and second event identifier values are tracked in different cache lines of the plurality of cache lines; Determining that the control value associated with the particular cache line is asserted; Setting the first event identifier value equal to the second event identifier value; Asserting the control values associated with those greater than an initial cache line value associated with the first event identifier value and sequential cache line values of the plurality of cache lines up to a final cache line value associated with the second event identifier value of the event; Initializing the cells for a cache line associated with the initial cache line value; and Performing an in-array operation on a first cell index value associated with the first event identifier value within the initial cache line. [34] A non-transitory computer-readable storage medium storing instructions that, when executed by a processing device connected to a cache, cause the processing device to perform operations that include: Storing an array tracking a plurality of events in the cache; tracking a plurality of control values associated with a state of a plurality of cache lines of the array; Tracking, within the plurality of cache lines, a window of cell index values corresponding to event identifier values and having a window size that shifts with an occurrence of any event that is outside the window; and Updating, in response to detecting an event, a first value of a particular cache line of the plurality of cache lines based on control values corresponding to the particular cache line and based on whether the first value is within a range of cell index values currently defined by the window.
Citation Information
Patent Citations
311,073