Financial network

The use of multi-core processors and dedicated routing devices in network elements addresses data transmission delays by optimizing routing and translation processes, resulting in improved network efficiency and consistent performance.

JP2025157363APending Publication Date: 2025-10-15CFPH LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025117687
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2014-06-30
Filing Date
2025-07-14
Publication Date
2025-10-15

AI Technical Summary

Technical Problem

Significant delays are introduced when data travels between servers in communication networks, particularly due to network/port translation functions, leading to inconsistent delays across different routers.

Method used

A network element with multi-core processors is used, where each processor core is dedicated to specific routing tasks, and includes a routing device that maps local and remote addresses, performs load balancing, and fails over to secondary sockets when primary sockets fail, while also supporting high-speed data transmission and network translation functions.

Benefits of technology

This configuration reduces data transmission delays and ensures consistent performance by optimizing routing and translation processes, enhancing network efficiency and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025157363000002
    Figure 2025157363000002
  • Figure 2025157363000003
    Figure 2025157363000003
  • Figure 2025157363000004
    Figure 2025157363000004
Patent Text Reader

Abstract

To provide a communication network component.SOLUTION: A method load balances a pair of local network address and a port on a first network 103 between a first destination using a first socket and a second destination using a second socket, with a first processing device opening the first socket to the first destination of the second remote network and opening the second socket to the second destination of the second remote network. The traffic sent to the local network address and the port pair is routed to a second destination using the second socket. A second processing device accesses a portion of a memory space shared with a first processing core, and at least one packet header or an entire packet is sent to an analytics engine while the first processing device routes the entire packet.SELECTED DRAWING: None
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 62 / 019,366, filed June 30, 2014, which is incorporated herein by reference.

[0002] Some embodiments relate to a communication network element. [Background technology]

[0003] A communication network may include one or more network components to facilitate data communication (eg, between computing devices). [Brief explanation of the drawings]

[0004] [Figure 1A] FIG. 1 illustrates an example system according to some embodiments. [Figure 1B] FIG. 1B is a diagram illustrating an example of the configuration of the system in FIG. 1A. [Figure 2] FIG. 1 illustrates another example system according to some embodiments. [Figure 3] FIG. 1 illustrates an example network element according to some embodiments. [Figure 4] FIG. 1 illustrates an example SDN in accordance with some embodiments. [Figure 5] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 6] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 7] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 8] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 9] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 10] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 11] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 12] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 13] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 14] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 15] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 16] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 17] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. [Figure 18] FIG. 1 illustrates an aspect of an example SDN, according to some embodiments. Summary of the Invention [Problem to be solved by the invention]

[0005] The present invention is directed to solving the problems of the background art. [Means for solving the problem]

[0006] The following should be understood as embodiments rather than claims.

[0007] A. An apparatus including a first routing device configured to map local address and port pairs of a first network to destinations on a second network and to map local address and port pairs of a third network to destinations on the second network, wherein the first routing device is configured such that a first core of a first processor is configured to perform routing to the first network and a second core of the first processor is configured to perform routing to the second network. To facilitate, the routing device is configured to open a first socket to the destination and a second socket to a second destination, and to fail over routing to the second socket in response to determining that the first socket has failed; and a third core of the routing device is configured to execute a process configured to access a portion of a memory space shared with the first core, copy at least one of a packet header and an entire packet from the portion of the memory space, and transmit the at least one of the packet header and the entire packet to an analytics engine coupled to the first routing device.

[0008] A.1. The apparatus of Claim A, wherein the first routing device is configured to load balance traffic such that traffic sent to a local address and port pair is divided between a destination using a first socket and a second destination using a second socket. A.1.1. The apparatus of Claim A.1, wherein load balancing is performed in at least one of a round-robin and a least-connection manner. A.2. The apparatus of Claim A, wherein the routing device includes multiple multi-core processors. A.3. The apparatus of Claim A, wherein the routing device is configured to route data at gigabit speeds.

[0009] A.4. The apparatus of claim A, including a second routing device configured to map address and port pairs to a first network and map second address and port pairs to a second network, wherein the second routing device is configured such that a first core of a second processor is configured to perform routing from a destination to the first network and a second core of the second processor is configured to perform routing from the destination to the second network. A.4.1. The apparatus of claim A.4, wherein the first routing device is configured to compress data blocks to be routed to the destination according to a dictionary scheme, and the second routing device is configured to decompress the data blocks according to a dictionary scheme for transmission to the destination. A.4.2. The apparatus of claim A.4, wherein mapping from the first network and the second network through the first routing device enables services from the first network and the second network to the software defined network. A.4.3. The apparatus of Claim A.4, wherein the second routing device enables a destination to subscribe to services provided by the first network and the second network to the software-defined network. A.4.4. The apparatus of Claim A.4, wherein the first routing device and the second routing device define a software-defined network spanning multiple data centers. A.4.5. The apparatus of Claim A.4, wherein the destination includes a customer conducting a transaction and the first network includes a network in which an electronic exchange resides. DETAILED DESCRIPTION OF THE INVENTION

[0010] Referring to FIG. 1A , an example system 100 is shown. System 100 may include multiple entities, including entity 110 and multiple entities 130a-n (one of which is shown in detail in FIG. 1A ), one or more of which may be interconnected via network 103. Entity 110 may be, for example, a service provider that provides services, and each entity 130 may be, for example, a customer / user of the services provided by service provider 110 (e.g., a corporation, bank, investment fund, trader, etc.). For convenience of explanation, entity 110 will be referred to as a service provider and entity 130 will be referred to as a user / customer. However, these terms are not limiting, and other example entities are possible. Also, while entity 110 may be a service provider that provides a service to entity 130, other relationships between entity 110 and entity 130 are possible.

[0011] As an example, service provider 110 may offer one or more electronic marketplaces for trading / buying / matching items (e.g., financial instruments, real estate, wagers / stakes, tangible goods, services, etc.) and thus may offer one or more electronic matching / trading engines. Similarly, customers 130 may seek to trade one or more items on electronic marketplaces offered by service provider 130. According to this example, one or more of customers 130 may electronically transmit data / messages to, for example, service provider 110, including, for example, orders to buy and / or sell items at specified prices and / or quantities (e.g., bids, offers, hits, takes). Similarly, service provider 110 may electronically receive and execute such orders and transmit data / messages to customers 130, including, for example, prices and quantities of pending and executed orders. As will be appreciated by those skilled in the art, this is merely one example, and other and / or additional services may be provided by service provider 110, and additional and / or other messages / data may be transmitted between service provider 110 and customers 130. For example, one or more of customers 130 may electronically transmit data / messages to, for example, service provider 110, including, for example, orders to bet on teams, events, etc., at specified odds and / or stakes. Similarly, service provider 110 may electronically receive and execute / match such orders and transmit data / messages to customers 130, including, for example, specified odds and / or stakes for pending and / or executed orders.

[0012] Service provider 110 may include one or more network components 112 and one or more computing systems 114 (which may include or be connected to one or more database systems) that provide services, for example, to customers 130. As will be appreciated by those skilled in the art, service provider 110 may include additional and / or other computing systems and / or network components. Computing systems 114 may be referred to herein as servers for convenience of description. However, it should be understood that the use of the term server is non-limiting and other types of computing systems may be used. One or more of servers 114 may include one or more processors and one or more memories. One or more of servers 114 may also include one or more network hardware / software / firmware-based interfaces / ports that enable the server to connect to network components 112 and thereby to network 103. Such interfaces may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, may be configured to support one or more different types of protocols, such as Ethernet, and may be configured to operate at any speed, such as Gb rates. As will be appreciated by those skilled in the art, the servers 114 may have additional and / or other configurations. The service provider 110 may also include one or more software- and / or firmware- and / or hardware-based applications, which may be stored on one or more database systems and / or servers 114 and configured to execute on one or more of the servers 114. Each server may execute the same or different applications. As an example, the applications may be configured to provide one or more electronic matching / trading engines for trading / matching one or more items as described herein.

[0013] The network elements 112 may include, for example, one or more routers and / or switches, including, for example, core and / or edge routers and / or core and / or edge switches. Each of the network elements 112 may include one or more network hardware / software / firmware-based interfaces / ports that enable the network elements to connect to each other, to one or more of the servers 114, and / or to the network 103. Such interfaces may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, to support one or more different types of protocols, such as Ethernet, and to operate at any speed, such as Gb rates. As will be appreciated by those skilled in the art, the network elements 112 may have additional and / or other configurations. One or more of the network elements 112 may include one or more physical connections (wired / wireless) to other network elements 112, servers 114, and / or the network 103. Network component 112 and one or more of servers 114 may be further configured such that one or more of servers 114 have private network addresses, thereby residing on the private network of service provider 110, and / or have public addresses, thereby residing on the public network. In this manner, network component 112 may be configured such that servers 114 can communicate with each other and / or with network 103, thereby communicating with one or more other computing systems (e.g., connected to network 103), such as computing system 138 of customer 130. As will also be appreciated by those skilled in the art, network component 112 may include additional and / or other components as described herein and may provide additional and / or other types of functionality to that described herein.

[0014] An example of a customer 130 (illustrated as customer 130a) may include one or more network components 132, 134, and 136 and one or more computing systems 138 (which may include or be connected to one or more database systems). Those skilled in the art will appreciate that customer 130 may include additional and / or other computing systems and / or network components. Those skilled in the art will appreciate that other customers 130 may include configurations similar to and / or different from the configuration of customer 130a shown in FIG. 1A. Computing systems 138 may be referred to herein as servers for ease of explanation. However, it should be understood that the use of the term server is non-limiting and other types of computing systems may be used. One or more of servers 138 may include one or more processors and one or more memories. One or more of the servers 138 may also include one or more network hardware / software / firmware-based interfaces / ports that enable the server to connect to one or more of the network components 132-136 and thereby to the network 103. Such interfaces may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, may be configured to support one or more different types of protocols, such as Ethernet, and may be configured to operate at any speed, such as Gb rates. As will be appreciated by those skilled in the art, the servers 138 may have additional and / or other configurations. The customer 130 may also include one or more software- and / or firmware- and / or hardware-based applications, which may be stored in one or more database systems and / or servers 138 and configured to execute on one or more of the servers 138.As one example, an application may be configured to use services provided by the server 114 of the service provider 110, and in particular, to trade one or more items with one or more other customers 130, e.g., by using an electronic matching / trading engine provided by the server 114 of the service provider 110. According to this example, one or more of the servers 138 of the customers 130 may communicate data / messages electronically, e.g., to the server 114 of the service provider 110, over the network 103, where such data / messages include, e.g., buy and / or sell orders (e.g., bids, offers, hits, take orders) for items at specified prices and / or quantities. Similarly, the server 114 of the service provider 110 may electronically receive and execute such orders and communicate data / messages to the server 138 of the customer 130, where such data / messages include, e.g., prices and quantities of pending and executed orders. Those skilled in the art will appreciate that this is merely one example and that other and / or additional services may be provided by service provider 110 and additional and / or other messages / data may be transferred between service provider 110 and customer 130 as described herein.

[0015] The network elements 132-136 of customer 130 may include, for example, one or more routers and / or switches, including, for example, core and / or edge routers and / or core and / or edge switches. Each of the network elements may include one or more network hardware / software / firmware-based interfaces / ports that enable the network elements to connect to each other, to one or more of servers 138, and / or to network 103. Such interfaces may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, to support one or more different types of protocols, such as Ethernet, and to operate at any speed, such as Gb rates. As will be appreciated by those skilled in the art, the network elements 132-136 may have additional and / or other configurations. One or more of the network components 132-136 may include one or more physical connections (wired / wireless) to other network components 132-136, one or more of the servers 138, and / or the network 103. The network components 132-136 may further be configured such that one or more of the servers 138 have private network addresses and thereby reside on the private network of their respective customers 130, and / or have public addresses and thereby reside on the public network. In this manner, the network components 132-136 may be configured such that the servers 114 can communicate with each other and / or such that the servers 114 can communicate with the network 103 and thereby communicate with one or more other computing systems (e.g., connected to the network 103), such as the servers 114. As will also be appreciated by those skilled in the art, the network components 132-136 may include additional and / or other components as described herein and may provide additional and / or other types of functionality to that described herein.

[0016] Network 103 may include one or more network components, including, for example, one or more routers and / or switches. Such network components may include one or more network hardware / software / firmware-based interfaces / ports that may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, one or more different types of protocols, such as Ethernet, and may be configured to operate at any speed, such as Gb rates. One or more components of network 103 may include one or more physical connections (wired / wireless) with other components and with each of entities 110 and 130. In this manner, network 103 may be configured such that computing system 114 of entity 110 and computing system 138 of entity 130 are at least capable of communicating with each other. Those skilled in the art will also appreciate that network 103 may include additional and / or other network components as described herein and may be configured in additional and / or other ways than those described herein.

[0017] 1B, where like reference numerals refer to like components as described herein, system 200 is shown, which may be one configuration example of system 100 of FIG. 1A. According to this example, network element 112 of service provider 110 may include a switch, e.g., a core switch, that includes one or more connections to each of servers 114. By way of example, network element 112 may be an Arista 7124 application switch, although other and / or additional network elements may be used. Network element 112 and one or more of servers 114 may be further configured such that one or more of servers 114 have network addresses on network 103, which may be considered “public” addresses (although these addresses may not actually be public). According to one illustrative aspect of example system 200, network 103 may be a private network (possibly owned or leased) of service provider 110. According to this example, network element 112 and one or more of servers 114 are part of network 103. In other words, the network interfaces of network component 112 that interface with server 114 and also with customer 130 may be in the same address space.

[0018] 1B , network element 136 of example customer 130 (shown as customer 130a) may include a switch such as a core switch, network element 134 may be a switch such as an edge switch, and network element 132 may be a router. Switch 136 may include one or more connections to each of servers 138 and one or more connections to switch 134. Switch 134 may then include one or more connections to router 136. Network elements 132-136 and one or more of servers 138 may be further configured such that one or more of servers 138 have private network addresses (i.e., addresses that are not on network 103) and thereby reside on a private network separate from network 103. Other customers 130n may have similar configurations.

[0019] 1B , each customer 130 may have one (or possibly more) addresses on network 103, which may be considered “public” addresses (although these addresses may not actually be public). Accordingly, each router 132 may be configured as a network address translator, and possibly a port address translator (NAT / PAT), which, for example, maps between one or more private addresses of server 138 on customer 130's network and the public address assigned to each customer 130 on network 103. Thus, when server 138 is communicating a message / data (which may be encapsulated, for example, in the form of a packet including an address and / or port) to server 114, router 136 may translate the private address of server 138 in the packet to the public address assigned to customer 130 on network 103. Again, such translation may include translating a port number used by an application on server 138 to a different port number. Similarly, when server 114 is communicating a message / data (which may be encapsulated, for example, in the form of a packet containing an address and / or port) to server 138, router 136 may translate the public address assigned to customer 130 in the packet to the private address of server 138. Again, router 136 may also perform port translation as part of the address translation.

[0020] 1B , network 103 may include point-to-point connections 113a-n between switch 112 of service provider 110 and each of routers 132 (e.g., of customer 130) (although again, non-point-to-point connections are possible). For example, each connection between switch 112 of service provider 110 and router 132 (e.g., of customer 130) may be a fiber connection, such as a single-mode fiber connection operating at 1 Gb, 10 Gb, 100 Gb, etc. (although other connection types and rates may be used). According to even further aspects of this example configuration, server 114 and network element 112 of service provider 110 and one or more of network elements 132-136 and server 138 of each customer 130 may be co-located, e.g., in the same room. For example, one or more of the servers 114 and the network elements 112 may be housed in one rack. Similarly, one or more of the network elements 132-136 and the servers 138 of a first respective customer 130 may be housed in another respective rack, etc. Those skilled in the art will also appreciate that the system 200 may include additional and / or other components and may include additional and / or other configurations than those described herein.

[0021] 1A and 1B, one potential problem is that a significant delay may be introduced when data travels between server 114 and server 138. As a specific example, router 132 may introduce a delay (e.g., greater than 100 microseconds), which may be the result of, for example, network / port translation functions. Similarly, different routers 132 for different customers 130 may experience different delays.

[0022] 2, where like reference numerals refer to like components as described herein, an example system 300 similar to the example system 200 of FIG. 1B is shown. According to this example, system 300 includes a network element 202. Network element 202 may be part of service provider 110 and therefore owned and / or operated by service provider 110. Network element 202 may be co-located with, and housed in the same rack as, one or more network elements of service provider 110, including server 114 and / or network element 112 of service provider 110. As will be appreciated by those skilled in the art, network element 202 need not be owned and / or operated by service provider 110 or co-located with the network elements and / or servers of service provider 110.

[0023] Network element 202 may include one or more network hardware / software / firmware-based interfaces / ports 204a...204n, which allow the network element to connect with server 114, possibly via network element 112, for example. Network element 202 may also include one or more network hardware / software / firmware-based interfaces / ports 206a...206n, which allow the network element to connect with server 138 (e.g., for each customer 130a-n). Network interfaces 204a-n and 206a-n of network element 202 may be configured to support one or more different types of physical network connections, such as copper, fiber optic, and / or wireless, may be configured to support one or more different types of protocols, such as Ethernet, and may be configured to operate at any speed, such as Gb rates. Furthermore, different network interfaces 204a-n and 206a-n may have different configurations. Those skilled in the art will appreciate that network component 202 may have additional and / or other configurations.

[0024] 2, one or more of the network interfaces 204a-n of the network element 202 may be physically (wired / wirelessly) connected (e.g., by connections 210a-n) to the network element 112, which may be a switch. According to another and / or additional example, each of one or more of the network interfaces 204a-n of the network element 202 may be physically connected directly to a respective server 114 of the service provider 110 by one or more connections 210a-n. According to a further aspect of the example system 300, each customer 130a-n may be assigned one or more respective network interfaces 206a-n of the network element 202. Accordingly, each network interface 206a-n of network element 202 may be physically (wired / wirelessly) connected (e.g., by connections 212a-n) to a respective server 138 of a respective customer 130a-n, directly and / or through one or more network elements (e.g., network element 136, which may be, for example, a switch) of the respective customer. For example, each connection 212a-n may be a fiber connection, such as, for example, a single-mode fiber connection operating at 1 Gb, 10 Gb, 100 Gb, etc. (although other types of connections and rates may also be used). As will be appreciated by those skilled in the art, additional and / or other configurations of network element 202 and system 300 are possible.

[0025] According to further aspects of example system 300, one or more of network interfaces 204a-n, connections 210a-n, network elements 112, and servers 114 of network element 202 may reside on network 214, which may be a private network of service provider 110 and may have a network address space. Accordingly, network element 112 and one or more of servers 114 may be configured such that one or more of servers 114 have a network address on network 214 within the network address space. According to further aspects of this example configuration, for example, one or more of network interface 206a, connections 212a, network elements 136 of each customer 130a, and servers 138 of each customer 130a may reside on network 216a of customer 130a, which may be a private network of customer 130a and may have a network address space. Accordingly, the network components 136 of customer 130 a, as well as one or more of the servers 138, may be configured such that one or more of the servers 138 have network addresses on network 216 a within the respective network address spaces. Similarly, for example, network interface 206 n, connection 212 n, network components 136 of customer 130 n, and one or more of the servers 138 of customer 130 n may reside on network 216 n of customer 130 n, which may be a private network for customer 130 n and may have its own network address space. Accordingly, the network components 136 of customer 130 n, as well as one or more of the servers 138, may be configured such that one or more of the servers 138 of customer 130 n have network addresses on network 216 n within the respective network address spaces. Other customers 130 not shown in FIG. 2 may have similar configurations.

[0026] According to further aspects of this example system, network component 202 may be, for example, a two-way network address translator and possibly a port address translator (NAT / PAT). More specifically, according to this example, each customer 130 a-n may have one (or possibly more) addresses on network 214 within the network address space of network 214. Thus, for each customer 130 a-n, network component 202 may be configured as a NAT / PAT that maps between one or more addresses of server 138 on respective customer networks 216 a-n (i.e., within the network address space of the respective network) and addresses assigned to the respective customer 130 a-n on network 214 (e.g., within the network address space of network 214). Thus, when server 138 is communicating a message / data (which may be encapsulated, for example, in a packet containing an address and / or a port) to server 114, network component 202 may translate the address of server 138 on network 216 a-n in the packet to an address assigned to customer 130 a-n on network 214. Again, such translation may include translating a port number in the packet used by an application on server 138 to a different port number. Similarly, when server 110 is communicating a message / data (which may be encapsulated, for example, in a packet containing an address and / or a port) to server 138, network component 202 may translate the address assigned to customer 130 a-n on network 214 in the packet to an address of server 138 on network 216 a-n. Again, network component 202 may perform port translation as part of the address translation.

[0027] Referring to FIG. 3 , where like reference numerals refer to like components as described herein, an example architecture of network element 202 is shown. Network element 202 may include multiple computing processors, including one or more of processors 301 a...301 n and one or more of processors 302 a, 302 b,..., 302 n. Processors 301 a-n may be referred to herein as scheduling processors, and processors 302 a-n may be referred to herein as network processors. The terms "scheduling" and "network" are intended to be non-limiting and are used herein for ease of description only. Each of processors 301 a-n and 302 a-n may or may not be similarly configured (e.g., with respect to memory, processing speed, etc.). As will be appreciated by those skilled in the art, network element 202 may include more and / or fewer processors. According to further aspects of the example network element 202, any one or more of the scheduling processors 301 a-n and the network processors 302 a-n may be interconnected with one another via a communications architecture, such as a bus architecture, which may include, for example, a shared memory architecture. Those skilled in the art will appreciate that other and / or additional communications architectures are possible. The communications architecture may be such that any of the scheduling processors 301 a-n may be configured to communicate with any of the network processors 302 a-n. Those skilled in the art will appreciate that other configurations are possible.

[0028] The network element 202 may also include one or more network interfaces 204a-n and one or more network interfaces 206a-n, as described herein, where one or more of the network interfaces 204a-n may be configured to interface, for example, directly or indirectly, with the server 114, and one or more of the network interfaces 206a-n may be configured to interface, for example, with respective customers 130a-n. The network interfaces 204a-n and 206a-n may have the same configuration and / or one or more different configurations. For example, the interfaces 204a-n and 206a-n may be any combination of long-range or short-range, single-mode or multi-mode fiber interfaces operating at rates such as 1 Gb, 10 Gb, 100 Gb, etc. One or more of the network interfaces 204a-n and 206a-n may be physically located on their own network interface card, and / or some of the network interfaces 204a-n and 206a-n may be physically located on one or more common network interface cards. As will be appreciated by those skilled in the art, other configurations are possible.

[0029] As previously described herein, each network interface 206a-n may be assigned to and interface with a respective customer 130a-n. Those skilled in the art will appreciate that multiple network interfaces may be assigned to a given customer (e.g., for load balancing purposes, backups, etc.). According to a further aspect of the example network element 202, each network interface 206a-n may be assigned to a respective network processor 302a-n such that all data transmitted through the respective network interface is processed exclusively by the respective network processor. However, those skilled in the art will appreciate that additional and / or other configurations are possible, such as assigning more than one network interface 206a-n to a given network processor 302a-n and / or assigning more than one network processor 302a-n to a given network interface 206a-n. According to further aspects of the example network element 202, a given network interface 206a-n may be interconnected with its respective network processor 302a-n via a communications architecture, such as a bus architecture (e.g., a PCIe bus architecture). As will be appreciated by those skilled in the art, other and / or additional communications architectures are possible, such that any network interface 206a-n may be configured to communicate with any one or more of the network processors 302a-n, and any network processor 302a-n may be configured to communicate with any one or more of the network interfaces 206a-n. According to further aspects of the network element 202, each network processor 302a-n may be isolated from all interrupts other than those from its associated network interface 206a-n, for example. As will be appreciated by those skilled in the art, other configurations are possible.

[0030] As further shown in FIG. 3, the example network element 202 may include one or more network applications 303a-n. The applications 303a-n may be software-based applications, although other and / or additional configurations are possible, including firmware- and / or hardware-based applications. The network element 202 may include one or more memory devices on which the applications 303a-n may be stored and / or executed from. Such memory devices may be electronically coupled to one or more of the processors 301a-n and 302a-n. According to one aspect of the network element 202, each network processor may execute an application 303a-n. According to a further aspect of the network element 202, each application 303a-n may execute only on its respective processor. Thus, application 303a may execute only on processor 302a, application 303b may execute only on processor 302b, and so on. This is sometimes referred to as processor affinity. However, those skilled in the art will appreciate that additional and / or other configurations are possible, such as running multiple applications 303 a-n on a single processor 302 a-n and / or running one or more of the applications 303 a-n on multiple processors. For example, in some embodiments, routing devices may be assigned l-flow level core affinity or processor affinity.

[0031] Thus, according to one example configuration of network element 202, a given network application 303 a-n may be assigned to and executed on a respective network processor 302 a-n, each network processor 302 a-n may be assigned to a respective network interface 206 a-n, and each network interface 206 a-n may be assigned to a respective customer 130 a-n. According to a further aspect of this example configuration, each network application 302 a-n may be configured as a NAT and possibly a PAT, and may perform network / port translation of messages / data passing between network 214 and each network 216 a-n of each customer 130 a-n. Thus, the network element 202 may be configured (e.g., by a network administrator) to assign a given network interface 206 a-n to a given network processor 302 a-n, and the network applications 303 a-n on each network processor may be further configured to perform NAT / PAT functions based on the customer 130 a-n to which the assigned interface is connected. Depending on the physical hardware configuration / layout of the network processors 302 a-n and network interfaces 206 a-n and / or the amount of data generated by and / or transmitted to each customer 130 a-n, a particular assignment of network interfaces 206 a-n to network processors 302 a-n may be more advantageous than other assignments in terms of the total data throughput of the network element 202, and may be so assigned, e.g., by an administrator. For example, it may be advantageous to assign a given network interface 206 a-n to a nearby network processor 302 a-n.As will be appreciated by those skilled in the art, the network applications 302a-n may not be configured as NAT / PAT, one network application may be configured to perform different functions than another network application, etc.

[0032] According to further aspects of the example network element 202, each network interface 204a-n may be assigned to a respective scheduling processor 301a-n such that all data transmitted via the respective network interface is processed exclusively by the respective scheduling processor. However, as will be appreciated by those skilled in the art, additional and / or other configurations are possible. For example, every network interface 204a-n may be assigned to one of the scheduling processors 301a-n, and / or each scheduling processor may be configured to communicate with any one or more of the network interfaces 204a-n. According to further aspects of the example network element 202, a given network interface 204a-n may be interconnected with a respective scheduling processor 301a-n via a communications architecture, such as a bus architecture (e.g., a PCIe bus architecture). As will be appreciated by those skilled in the art, other and / or additional communications architectures are possible. The communications architecture may be such that any network interface 204 a-n may be configured to communicate with any one or more of the scheduling processors 301 a-n, and any scheduling processor 301 a-n may be configured to communicate with any one or more of the network interfaces 204 a-n. According to further aspects of the network component 202, one or more of the scheduling processors 301 a-n may be isolated from all interrupts other than, for example, interrupts from one or more of the network interfaces 204 a-n. As will be appreciated by those skilled in the art, other configurations are possible.

[0033] As further shown in FIG. 3, network element 202 may include one or more scheduling applications and / or one or more management applications, which are collectively shown in FIG. 3 as applications 304a-n. The applications 304a-n may be software-based applications, although other configurations are possible, including firmware- and / or hardware-based applications. As previously mentioned, network element 202 may include one or more memory devices on which applications 304a-n may be stored and / or executed from. According to one example of network element 202, each scheduling processor 301a-n may execute one or more scheduling applications, one or more management applications, or a combination thereof. As another example, scheduling applications and / or management applications may execute on multiple processors. As another example, one scheduling application may run on one scheduling processor 301 a-n and be responsible for a subset of the network processors 302 a-n (as described further herein), while another scheduling application may run on the scheduling processors 301 a-n and be responsible for a different subset of the network processors 302 a-n. As another example, one scheduling application may run on one scheduling processor 301 a-n and be responsible for all of the network processors 302 a-n. As a further example, one scheduling application may run on multiple scheduling processors 301 a-n and be responsible for all of the network processors 302 a-n. As will be appreciated by those skilled in the art, other variations are possible. For ease of explanation, the network element 202 is described herein as having one scheduling application and one management application.Those skilled in the art will appreciate that network component 202 may include other types of applications than those described herein.

[0034] According to further aspects of the example network element 202, the scheduling application 304 may be configured to pass messages / data between the network interfaces 206a-n and the network interfaces 204a-n as follows. a. For messages / data received at network interfaces 206a-n, after each network application 303a-n performs NAT / PAT translation on each packet, for example, scheduling application 304 may retrieve / obtain the translated packet and forward / communicate the translated packet to one of network interfaces 204a-n. b. For messages / data received at network interfaces 204a-n, the scheduling application 304 may obtain the message / data and, for each packet, determine which of the respective network applications 303a-n performs the NAT / PAT translation, and forward / communicate the packet to that network application, where the packet may be translated (NAT / PAT) and forwarded / communicated to the respective network interface 206a-n.

[0035] Thus, according to one example operation of network element 202, a given server 138 of a given customer 130a-n may send a message / data (which may be encapsulated in the form of a packet including, for example, an address and / or port) to server 114 of service provider 110. The message / data / packet may be received at a given network interface 206a-n of network element 202. A given network application 303a-n of a network processor 302a-n assigned to that network interface 206a-n may then retrieve / receive and / or be forwarded the message / data / packet (or a portion thereof) from network interface 206a-n and perform NAT / PAT translation on the respective packet. The network application 303a-n may then forward and / or make available the converted message / data / packet to the scheduling application 304, which may then retrieve and / or receive the converted message / data / packet and then forward and / or make available the converted message / data / packet to its respective network interface 204a-n, from which it may be communicated to the server 114. Similarly, a given server 114 of the service provider 110 may send a message / data (which may be encapsulated in the form of a packet, for example) to the server 138 of the customer 130a-n. The message / data / packet may be received at a given network interface 204a-n of the network element 202.The scheduling application 304 may then retrieve / receive and / or be forwarded the message / data / packet (or a portion thereof) from the network interfaces 204a-n, determine which of the respective network applications 303a-n / network processors 302a-n will perform NAT / PAT translation on the message / data / packet, and forward and / or make the message / data / packet available to the respective network application 303a-n. (By way of example, and although other implementations are possible, the scheduling application may maintain a table (which may be configured by an administrator) that maps network addresses associated with customers 130 to respective network processors 302a-n so that the scheduling application can forward the message / data to the appropriate network processor 302a-n.) The network applications 303 a-n may then retrieve and / or receive the messages / data / packets, perform NAT / PAT translations on the respective packets, and forward and / or make the translated messages / data / packets available to the respective network interfaces 206 a-n assigned to the network processors 302 a-n on which the network applications 303 a-n are executing. The network interfaces 206 may then communicate the messages / data / packets to the servers 138 of the customers 130 a-n. Those skilled in the art will appreciate that this is merely one example, and that other and / or additional operational examples of the network elements 202 are possible. Those skilled in the art will also appreciate that the operations performed by the scheduling application 304 as described herein and the operations performed by the network applications 303 a-n as described herein may be performed in whole or in part by others.

[0036] Regarding communication between the scheduling application 304 and any given network application 303a-n, as an example, the two applications may communicate via one or more (e.g., two) shared memory circular queues. For example, the network application 303 may place a converted message from the network interface 206 into a first memory queue and update, e.g., an index / pointer for the queue to reflect that the new message has been added to the queue. Similarly, the scheduling application 304 may monitor the index / pointer for the queue, recognize a new message in the queue, read the message, and update the index / pointer, e.g., to reflect that the message has been read. Similarly, the scheduling application 304 may place a message from the network interface 204 into a second memory queue and update the index / pointer for the queue to reflect that the new message has been added to the second queue. Similarly, the network application 303 may monitor the index / pointer for the second queue, recognize a new message in the queue, read the message, and update the index / pointer, e.g., to reflect that the message has been read. A similar process may be used when other network applications 303 (each of which may have its own set of queues) communicate with the scheduling application 304. Those skilled in the art will appreciate that this is only one example and other communication techniques / processes may be used.

[0037] As previously mentioned, the network element 202 may include a management application 304, which may execute, for example, on the scheduling processors 301 a-n. Such an application may be used by an administrator to monitor the status of the network element 202 and configure the network element. For example, the network element 202 may include, for example, one or more input / output devices, such as a display interface, a mouse, a keyboard, a touch screen, a network interface (for remote access), etc. Using such interfaces and the management application 304, for example, an administrator may monitor the status of the network element 202 and configure the network element. For example, an administrator may assign and / or reassign a given network interface 206 a-n to a given network processor 302 a-n. An administrator may further configure the network applications 303 a-n of a given network processor 302 (e.g., with respect to the addresses and / or ports between which the network application 303 is to translate) according to the customers 130 a-n on whose behalf the network application 303 is to perform NAT / PAT translations. Those skilled in the art will appreciate that network applications may be configured in other manners. For example, one advantage of hardware / software configuration of network element 202 is that it allows an administrator to, for example, reconfigure a given customer 130a-n (e.g., reconfiguring its NAT / PAT configuration, reconfiguring which network processors 302a-n are assigned to that customer, and / or reconfiguring which network interfaces 206a-n are assigned to that network processor 302a-n and / or customer) without temporarily disconnecting other customers. Management application 304 may, for example, include an IPMI subsystem to allow an administrator to monitor the status of network element 202. Such a subsystem may be separate from management application 304.Those skilled in the art will appreciate that these are only examples of management functions and that other / additional functions are possible.

[0038] According to further aspects of network element 202, the network element may include one or more memory devices, e.g., solid-state drives, and may include one or more logging applications that capture all (or a portion) of the data moving through the network element and log the data on the drives. According to further aspects, the logging applications may filter the data, store only a portion of the data, and / or perform analysis of the data (e.g., calculating latency) and store the results of such analysis. According to even further aspects, the logging applications may filter the data (e.g., searching for market data prices, completed transactions, etc.) and / or analyze the data and forward the filtered data and / or analysis results to another network interface (e.g., a network interface different from network interfaces 204a-n and / or 206a-n). Other systems and users (such as customer 130) external to network element 202 may receive such data and / or analysis results, e.g., data and / or analysis results related to prices. As will be appreciated by those skilled in the art, these are merely example logging functions and other / additional logging functions are possible.

[0039] According to an embodiment of network element 202, an Intel Sandy Bridge processor incorporating multiple (e.g., eight) cores may be used to implement one or more of processors 301a-n and 302a-n. For example, in a given Sandy Bridge processor, one or more cores may be assigned as scheduling processors 302a-n and one or more cores may be assigned as network processors 303a-n. Such cores may be configured and operate as described herein with respect to processors 301a-n and 302a-n. Network element 202 may include multiple Sandy Bridge processors, where for each Sandy Bridge processor, one or more cores may be assigned as network processors 302a-n and one or more cores may be assigned as scheduling processors 301a-n (which may only work with that chip's network processor, e.g., to move messages between network interfaces 204a-n and 206a-n). In such a configuration, any of the network interfaces 206a-n may be assigned to any of the network processors (cores) of a Sandy Bridge processor. Alternatively, only certain network interfaces 206a-n may be assigned to one Sandy Bridge processor, with another set of network interfaces 206a-n assigned to another Sandy Bridge processor, etc. Similarly, any of the network interfaces 204a-n may be assigned to any of the scheduling processors (cores) of a Sandy Bridge processor. Alternatively, only certain network interfaces 204a-n may be assigned to one Sandy Bridge processor, with another set of network interfaces 206a-n assigned to another Sandy Bridge processor, etc. Those skilled in the art will appreciate that these are merely examples and that other configurations and other chipsets may be used.

[0040] According to a further embodiment of network component 202, network interfaces 204a-n and 206a-n may be implemented by one or more network interface cards manufactured by Hotlava, including any one or more of the following: Tambora 120G6, Tambora 64G6, Tambora 80G4, Tambora 64G4, and Bosavi 12G6. Those skilled in the art will appreciate that these are examples only and that other network interface cards, including network interface cards from other suppliers, may also be used.

[0041] According to a further embodiment of network component 202, a Sandy Bridge processor and a HotLab network interface card may be plugged into a single motherboard, and such a system may run the Linux operating system. Again, those skilled in the art will appreciate that these are examples only and other configurations are possible.

[0042] As will be appreciated by those skilled in the art, network component 202 may be configured in the reverse direction (e.g., as described herein in FIGS. 2 and 3). For example, a given server 114 on network 214 may have one (or possibly more) addresses on another network (e.g., network 216a), but several other networks may also interface with network interface 206. Thus, for a given server 114, network component 202 may be configured as a NAT / PAT (as described herein), e.g., a NAT / PAT that maps between one or more addresses of server 114 on customer network 214 and addresses assigned to the server on network 216a.

[0043] While the present disclosure has been described with respect to specific embodiments and generally associated methods, modifications and substitutions to these embodiments and methods will be apparent to those skilled in the art. Accordingly, the description of the exemplary embodiments above is not intended to limit the present disclosure. Other changes, substitutions, and alterations are possible without departing from the spirit and scope of the present disclosure. In various embodiments, routing devices that define and / or enable software-defined networks may reside in data centers and / or at customers and / or service providers, as appropriate. For example, an edge routing device in an SDN may provide l-flow routing, a customer or service provider switch or edge routing device may provide such functionality, and so forth.

[0044] In some embodiments, a software-defined network may be included. Such a network may use high-speed networking devices (e.g., devices such as device 202) as disclosed herein. Such a network may enable cloud and / or decentralized financial networks with a high degree of flexibility and speed. In some embodiments, the software-defined network may include a carrier-grade network transformation system.

[0045] For SDN endpoints, the SDN may perform NAT (with headers) of packets and / or support port-level redirection (port address translation) as needed, acting as a proxy between one or more external networks and one or more internal SDN IP zones. This design can help reduce routing and ensure that changes to external networks do not require any downstream routing changes. In some embodiments, there may be one internal SDN IP zone per data center that the SDN spans. An l-flow may be defined as an IP and port pair accessible from a source. The SDN can provide services such as routing, analytics, load balancing, and failover to the service provider identified by a particular l-flow.

[0046] The SDN may appear to the customer network as a simple server connection with static routes. For example, a customer connection to the SDN may look similar to the customer connection described above with respect to connections through network device 202. If other endpoints (e.g., FIX endpoints, market data endpoints, and / or internal services) are enabled, the customer facing SDN endpoints may present these services (e.g., as l-flows) to various ports or IPs defined by the customer network.

[0047] Failover and load balancing can be handled at the application layer and can be defined per set of IPs and ports, called a logical flow (l-flow), which allows for fine-grained control of application-level failover and load balancing by lifting network failover up to the application level.

[0048] SDN can act as a unique connectivity layer used to power the global network. Unlike traditional network systems, such an SDN can interact with systems at both the network and application levels. Endpoints can connect with each other over standard IPv4 TCP / IP configurations, similar to traditional servers. Once connected, the SDN can be configured to provide a myriad of forwarding, analytics, load balancing, and failover options for each IP and port pair, called an l-flow.

[0049] In some embodiments, the SDN may use 1 Gb / s, 10 Gb / s single-mode fiber (SMF) connections per endpoint. Of course, as noted above, any type of connection may be used in various embodiments, and these examples are non-limiting. SDN endpoints (on the SDN side) may be configured with one or many IP addresses in any address space compatible with external networks. In some embodiments, SDN endpoints may have requirements such as each SDN endpoint must be assigned (at least) one static IPv4 address and each SDN endpoint must be provided with (at least) one default gateway. While examples are given for IPv4 and TCP, of course, other examples may use any desired technology, such as IPv6 and UDP.

[0050] Connectivity to and / or from the SDN may terminate and originate at IP addresses assigned to external connections, with full network address translation of the l-flow IP and port pairs by the SDN.

[0051] SDN endpoints may be directly connected to the external primary and / or secondary switches or other components of the connected user / service provider. This configuration can help reduce some forms of latency. Figure 5 shows an example of a LUCERA SDN endpoint connection to an external switch of an external LAN. In some embodiments, there is no additional routing layer between the application server and the SDN. In this configuration, each endpoint may be assigned an IP address from an external IP pool, and the SDN endpoints may be configured similarly to a traditional server network interface.

[0052] In some embodiments, the SDN endpoints may be connected to an external firewall or router. This configuration is similar to the configuration described above, except that IP addresses are assigned from the transit network. Figure 6 shows an example of such a connection. This topology may be deployed to create a DMZ or to allow for VLAN consolidation. If additional source routes are needed (if the external transit does not perform full NAT), they may also be added to the SDN endpoints.

[0053] If an SDN needs to connect to multiple VLANs, some embodiments may employ the direct-connect topology described above and add an endpoint for each VLAN. Figure 7 shows an example of an SDN endpoint configured to connect to three separate 802.1Q tagged VLANs. In some embodiments, this endpoint may support, for example, up to 1024 VLAN endpoints per physical connection. The SDN endpoint allows for this flexibility to adapt to external networks and may appear as either a single gateway or a collection of gateways within the network.

[0054] In some embodiments, the SDN can operate as a carrier-grade network address translation system. Each physical endpoint on the SDN can be mapped to a physical network interface, and each logical IP address can be attached to that interface. Figure 8 illustrates SDN nodes, their external interfaces, and corresponding internal fabric connections. In some embodiments, the components in Figure 8 can correspond to network components such as component 202 described above.

[0055] In some embodiments, SDN endpoints may perform full (header rewriting) network address translation to connect to the core fabric. One process (and / or core and / or processor) may be allocated for implementing and managing NAT and / or PAT services per l-flow. Each external connection may be directly connected to one interface, and the NAT layer may prevent the traffic from being visible on the external network.

[0056] In some embodiments, by default, an interface may be reachable via PING (ICMP echo) but not via other ports. Ports on external interfaces may be enabled when applications are made available to the SDN (as l-flows). Figure 9 illustrates an example scenario in which a customer endpoint has access to two services from ExchangeCo: a market data feed on port 9999 and a FIX session on port 9998. These two services each have a separate l-flow, defined by an IP and port pair. The SDN performs full NAT of the ExchangeCO network and exposes these services to local endpoints on ports 9999 and 9998. These ports may be changed as needed. For example, the SDN may expose ExchangeCO services on ports 9000 and 9001 as needed. Internally, the SDN may employ a non-blocking, congestion-free fabric, and internal communications may occur in private fabric IP zones. In some embodiments, cross-datacenter connections (eg, including redundant transcontinental lines) may act as edge node points and support internal l-flows.

[0057] In some embodiments, an SDN endpoint may allow access to any number of l-flows. For a given service (which may be identified as a set of IPs, ports, and / or protocols), the SDN defines l-flows to manage access, failover, and / or quality of service. The SDN can manage these operational aspects transparently to users accessing the l-flows. An l-flow may be defined as being ingress or egress. An ingress l-flow may be a service that is external to the SDN and offered within the SDN. An egress l-flow may be a service that is internal to the SDN and offered to an external endpoint.

[0058] Figure 10 shows an example in which an ingress i-flow is enabled. In this example, a FIX engine in ExchangeCo's network wants to provide SDN customers with access to their markets. ExchangeCO defines this i-flow as follows: Market Data: IP: 192.168.1.1, Port: 9999, Protocol: TCP; Order Session: IP: 192.168.1.2, Port: 9998, Protocol: TCP.

[0059] Figure 11 shows a customer with an egress l-flow to access an ExchangeCo service. When CustomerCo attempts to access an ExchangeCO service, negotiates with ExchangeCo regarding entitlements, and is granted access by ExchangeCo, the SDN activates an l-flow for the service to that customer. The ExchangeCO service appears (source IP) on the local CustomerCO LAN (or VLAN), and CustomerCO does not need to know the details of the actual ExchangeCO endpoints. This abstraction may allow ExchangeCO to change its network design without forcing downstream routing updates, failovers, and load balancing to occur, as long as there is no interruption to customer connections to ExchangeCo, etc.

[0060] In some embodiments, l-flows may change ports (port address translation). In some embodiments, l-flows may traverse a cross-data center fabric. For example, in the example of FIG. 12, CustomerCO attempts to access two FX matching sources as a liquidity receiver (egress l-flows) and two FX matching sources as a liquidity provider (ingress l-flows).

[0061] As a further example, Figure 13 shows a liquidity aggregator that needs to connect through an SDN with six liquidity providers in NY4 (which may identify specific data centers) and five liquidity providers in LD4 (which may identify geographically disparate data centers). To simplify connectivity on the aggregator side, all destinations are reachable through a single IP address (shown here as 10.2.1.1). Outbound ports for each destination may be defined consecutively, so that all 10 endpoints appear at a single IP, and each port is mapped to a logical endpoint.

[0062] SDN can act like a traditional network appliance in that it can detect failures at the link level and IP level. For example, we define the following ingress l-flow, shown in Figure 14: [Table 1] I-flows can operate in active / passive scenarios and failover for link (physical) or IP failures. A socket may be opened to establish each of these I-flows. If the socket becomes unavailable, a failure condition can occur for any of the I-flows. If the primary socket becomes unavailable, a secondary I-flow may be used instead. Because the secondary socket is opened before the failure condition occurs, there is no delay in establishing a new connection after a failure is detected.

[0063] Customers using this l-flow as an egress can transparently fail over to the secondary path, with no networking changes apparent to the customer. In this example scenario, a failure of the link to the primary will cause the primary session to fail and the l-flow to start routing to the secondary link (a new session instance may be started if this is a FIX engine). In particular, the failure detection logic resides with the egress l-flow. In the event of a downstream (primary) failure, the egress l-flow receives an IP layer error, tears down the session, and re-establishes the connection (stateful service) using the secondary. In some embodiments, the failover method assumes stateful endpoints and registers TCP reconnection upon failure.

[0064] Failover and load balancing may be handled similarly by SDN. Failover and / or load balancing may be applied at ingress and / or egress l-flows. Load-balanced services can be implemented in a variety of ways. Two non-limiting examples are round-robin (weighted or unweighted) and least connected.

[0065] When round-robin distribution is employed, each server may be used in turn according to its weight. This is the simplest and most commonly implemented load balancing method. Applying round-robin weights can direct traffic to the more computationally robust servers. In some embodiments, the number of endpoints in a pool may be limited to, for example, 1024, meaning that there are a maximum of 1024 possible "servers" for distributing l-flows end-to-end. Figure 15 shows an example of two-server load balancing using weighted round-robin. According to the round-robin weighting algorithm implemented by the SDN endpoint, packets entering the illustrated egress l-flow are routed between two ingress l-flows to either the primary or secondary FIX engine.

[0066] An example of least-connection load balancing is selecting the server with the fewest currently connected sessions. This load balancing method may be optimal for services with non-uniform computational loads and variable connection lengths (e.g., database services or web services).

[0067] In some embodiments, compression may be applied to the ingress and / or egress l-flows. Such compression may be in any desired form. One example of compression that may be used is dictionary-based compression. One example of such dictionary-based compression that may be used is a compression algorithm related to the deflate algorithm, such as the zlib library compression algorithm. As will be appreciated by those skilled in the art, other types of compression algorithms may also be used in various embodiments.

[0068] Compression can be useful in some situations to reduce latency and / or improve bandwidth by reducing and / or minimizing packet size and / or eliminating the transmission of redundant data. This can be especially true for large message updates and / or text-based l-flows (e.g., FIX messaging l-flows).

[0069] In some embodiments, compression and / or decompression may occur at the SDN level. The dictionary may be shared / established among multiple processes / processors / cores. An API or other method for establishing control of the l-flow may be used to instruct the process on the style and method of compression. For example, when an SDN connection between a new l-flow and an SDN endpoint is established, a compression dictionary matching the desired compression routine may be established. The dictionary may be shared with SDN endpoints that have access to the l-flow. Data entering one endpoint of the l-flow may be compressed according to the compression routine. Data leaving the l-flow may be decompressed according to the compression routine. The process at the endpoint may perform the compression and / or decompression according to the established routine (e.g., by executing instructions in a processor / core such as in component 202).

[0070] FIG. 16 illustrates an example instance of end-to-end compression of an l-flow. In this example, for each chunk of data (e.g., 2048 bytes, or some other amount of data), a dictionary entry is created at both the sending and receiving endpoints of the l-flow. The dictionary creation is done in a concurrent manner, rather than in a pre-prepared or pre-shared manner. The method for establishing dictionary entries may be predefined across endpoints, so that both endpoints generate the same dictionary entries. Other implementations may use a pre-prepared dictionary or a pre-shared dictionary instead of a concurrent dictionary.

[0071] Upon the first transmission of a particular data chunk, a dictionary entry corresponding to that chunk is created at the sending end. Creating the entry can incur a performance hit because it may require additional processing compared to simply sending the data without creating a dictionary entry. In this example, at the receiving endpoint, the first chunk may be ABC. The dictionary entry created establishes ABC as the first entry. The second data chunk may be DEF. The dictionary entry created establishes DEF as the second entry. The data is sent to the other endpoint as ABCDEF, where the dictionary entry is matched.

[0072] On subsequent transmissions, that particular data chunk may be compressed to a smaller size. For example, a 2048-byte data chunk may be compressed into a 10-byte reference that identifies a dictionary entry. In this example, when a new data string containing two chunks, DEF and HIJ, is received, the receiving l-flow converts the DEF chunk into a reference to a second dictionary entry and creates a new dictionary entry corresponding to the HIJ chunk as the third entry. The data sent to the other l-flow endpoint is a reference pointer to the second dictionary entry and the HIJ chunk. Upon receipt at the other endpoint, this endpoint looks up the second dictionary entry and recreates the DEF chunk, creating the complete DEFHIJ string. The other endpoint also creates a new dictionary entry corresponding to the HIJ chunk.

[0073] Of course, the size of the example data is given as a non-limiting example, and dictionary lookups and / or chunks of any size may be used as desired.

[0074] In some embodiments, encryption may be applied to ingress and / or egress l-flows. Such encryption may be in any desired form. Encryption may be applied inline. For example, encryption may include SSL encryption. Encryption may include TLS encryption. A process / processor / core may apply the same or different keys (e.g., private and / or public keys) for each l-flow. For example, data entering one endpoint of an l-flow may be encrypted (e.g., using a public key). In some embodiments, data may exit the l-flow in encrypted form and may be decrypted (e.g., using a private key) by the destination. In some embodiments, data may be decrypted (e.g., using a private key) by the other endpoint of the l-flow as it exits that endpoint. Different l-flows may be encrypted and decrypted similarly using different keys and / or keys. Some examples of encryption algorithms and / or keys that may be supported include AES128-SHA, AES256-SHA, RC4-MD5, etc. In the case of AES-based keys, the endpoints may implement Intel's AES-NI instruction set for low-latency and high-throughput transmission. Offloading the encryption burden to the SDN may enable analytical applications (e.g., packet capture, analytics, etc.) to operate on the traffic. Other embodiments may include encryption by the source and / or destination instead of offloading the encryption burden to the SDN. In such embodiments, the content of the data may be unknown to the SDN and therefore unavailable to some analytical applications. Additionally, some analytical applications may be able to operate on encrypted data without intervention and / or may use a post-delivery reporting system to enable operation.

[0075] In some embodiments, analytics applications may be applied to ingress and / or egress l-flows. In some embodiments, l-flow analytics may operate only on packet headers. Such analytics may allow analysis to be performed regardless of whether encryption and / or compression burdens are delegated to the SDN. In some embodiments, analytics applications may also include payload analytics, such as packet capture mechanisms. Processing may operate inline and therefore not interfere with data packets traversing the SDN. Such processing may be performed by buffering or queuing packet headers in an analytics processor, core, or process. The buffer may be a shared memory space with the process, processor, or core performing the routing and / or transmission processing. For example, after a header / data packet has been processed through an SDN endpoint or other node in the SDN, the packet header may be placed in a ring buffer or other queuing memory portion for processing by an analytics process. Analytics processing may occur separately from the SDN routing process itself. This structure may ensure that post-transmission analysis occurs without interfering with the flow of SDN packets.

[0076] The analytics information may be stored and may be available for historical query. Such queries may be performed from devices connected to the SDN to a processor or database operated by a non-routing system, e.g., a computing system not involved in routing data through the SDN. Different levels of granularity may be maintained for queries of different time lengths. Different metrics may be maintained for queries of different time lengths. Example metrics that may be proposed for analytics on l-flows may include bandwidth, error, and / or latency information, such as bandwidth (bits), throughput (number of packets), TCP retransmissions (percentage of total packets), TCP retransmissions (number of packets), TCP out-of-order packets (percentage of total packets), TCP out-of-order packets (number of packets), TCP active flows, application round trip time, TCP handshake latency, etc. Analytics information may be streamed via web sockets and / or delivered in any desired manner.

[0077] In some embodiments, additional analytics regarding the performance of the SDN and / or l-flows may be available. To calculate analytics data regarding data transmitted through the SDN, the SDN may provide hundreds, thousands, tens of thousands, etc. of telemetry points. For example, each hop or node along any path through the SDN can act as a telemetry point. Custom metrics may be defined by the customer from any information that can be collected by such telemetry points. Examples of additional metrics may include SNMP metrics, Statsd metrics, Kstats metrics, etc.

[0078] In some embodiments, rather than analyzing only the header, the entire data packet may be analyzed. The operations for capturing and / or analyzing the header and capturing and / or analyzing the packet may be similar.

[0079] 17 and 18 illustrate example structures for packet and / or header capture and / or analysis configurations that may be used in some embodiments. Such configurations may enable analysis of captured packets and / or packet headers. The capture mechanism is organized as a virtual tap within an l-flow. The virtual tap implements a network packet broker that streams packet information as needed.

[0080] A memory space, such as a ring buffer, may be shared between two processes / processors / cores, as shown in FIG. 17. For example, one process / processor / core may handle routing related to l-flows. Another process / processor / core may handle packet capture and / or other analytics or functions of the SDN. Packets may be placed in a buffer and processed by both processes / processors / cores. In some embodiments, both cores may access any component of the buffer to process packets in the buffer. In some embodiments, the routing or l-flow process / processor / core may access a first set of space, and the packet capture process / processor / core may access another set of space. The first set of space may have a higher priority than the second set of space. For example, in one embodiment, the packet capture process / processor / core may access the last space in the ring buffer before it is overwritten by new data, which becomes the first space in the ring buffer. In such embodiments, a routing or l-flow process / processor / core may be given first priority to process a packet before a packet capture process / processor / core is allowed to act on the packet. In some embodiments, a packet capture process / processor / core may be limited to interrupting routing or l-flow accesses to buffers, while a routing or l-flow process / processor / core may be allowed to interrupt a packet capture process / processor / core. In this way, routing is always given the highest priority, and latency or data transfer is minimized.

[0081] In some embodiments, the packet capture process / processor / core may copy data from the shared memory to a writer buffer (e.g., another ring buffer). Such a buffer may be of any size. An example size may be a 4MB buffer. The buffer may store data that is queued to be written to disk or otherwise acted upon by an analysis tool. In some embodiments, the packet capture process / processor / core may send the captured packets to a collector agent or collector process, or otherwise queue the packets for transmission by a low-priority sending process.

[0082] In some embodiments, post-capture processing of captured packets may occur away from the core routing components of the SDN. For example, this may be done by a processor that does not have any functionality related to data transmission and / or routing. For example, a collector agent may run on such a non-routing processor. Figure 18 illustrates the operation and post-processing of such a collector agent away from the routing of the SDN. Copying information from one location to another in a reliable manner can maintain data integrity. For example, the RAFT consensus algorithm may be used to ensure reliable replication.

[0083] To allow analytics to properly recreate or analyze information about a packet, the packet may be time-stamped by a trusted time source. This time-stamping may be part of the header. A GPS or CDMA clock source may be used for time-stamping. This time-stamping may also be used to determine order priority (e.g., price-time priority at an SDN exchange service provider).

[0084] In some embodiments, captured packets may be broadcast to a message queue, which allows all applications that subscribe to the queue to act on the captured packets. For example, a collector agent may push received packets into the message queue. Each l-flow may be assigned a channel in the memory queue. Thus, packets captured from a particular l-flow (e.g., at an endpoint, a node in the SDN, etc.) may be broadcast on the assigned channel. Applications may listen to data on a particular channel and act on the data as needed.

[0085] An initial post-processing task may subscribe to the published l-flow raw file output in a message queue. The initial post-processing task may publish back queue data, which is reformatted from the raw packet capture into a desired format. An example format is PCAP format. Such formatted data may be consumed by a PCAP analysis application (e.g., Wireshark, TCPFlow) as needed. An example format is: <date><l-flow uuid> <gmtsecond> <data>The initial post-processing task may run before other tasks. The operation of the initial post-processing task may assign data to channels (e.g., by using the l-flow uuid tag in the formatted republished data).

[0086] In response to the formatted data being published in the message queue, a post-processing engine may act on the data, if necessary. For example, a post-processing engine may be assigned (e.g., through an API) to provide analytics on packets from a particular l-flow. When a packet tagged with that l-flow's uuid, or otherwise in that l-flow channel in the message queue, appears, the post-processing engine may operate to analyze the packet.

[0087] In some embodiments, the post-processing engine may operate to store files. Such storage may be, for example, long-term or short-term storage, as needed. The data may be gzip compressed, indexed, and stored in any desired storage medium. The post-processing engine may operate to provide l-flow replay activity. Packets may be reordered based on packet timestamps during post-processing to provide accurate information even if they are received out of order. Post-processing may be performed to perform any desired analytics analysis on the captured packets and / or headers.

[0088] There are many examples of possible SDN functionality, such as l-flow compression, encryption, packet capture, analytics, etc., which may be provided in various combinations depending on the embodiment. Of course, examples of such functionality are not limiting.

[0089] FIG. 4 illustrates another example of an SDN that can be implemented in some embodiments. In this example, four SDN endpoints 401, 403, 405, and 407 (which may or may not correspond to customer 130 in the previous figure) are shown connected to the SDN through two SDN network devices 202A and 202B. Each network device serves a separate data center, SDN data centers 411 and 413. These data centers may be connected through an SDN fabric, which is illustrated as internal networking components and devices 415. Each data center is illustrated as having internal SDN endpoints and / or other service providers, indicated at 417 and 419 (e.g., these may or may not correspond to components such as 114 in the previous figure). Of course, this example is provided as a non-limiting example of some possible functionality and / or configurations in some embodiments. Some embodiments may have other configurations, components, functionality, etc.

[0090] In a cloud-based and / or distributed high-speed trading network, various endpoints and / or participants may provide services to other endpoints and / or participants to facilitate trading through the SDN. For example, as a non-limiting example setup, endpoints 405 and 407 may provide market data services to SDN participants, endpoint 401 may provide exchange data services to SDN participants, and endpoint 403 may be a trading entity that utilizes the distributed services of the SDN.

[0091] A customer of endpoint 403 may access market data l-flows to each of endpoints 405 and 407 by accessing the IP address and port combination assigned by the SDN to those services for endpoint 403. Market data information may be provided by the services of endpoints 405 and 407 back to the customer of endpoint 403 through the SDN. Similarly, endpoint 403 may provide trading commands (e.g., bids, offers) by communicating with endpoint 401 through the SDN.

[0092] An internal service, such as endpoint 417, may provide a service similar to an external endpoint. For example, the internal service may provide exchange functionality. The internal service may be accessed similarly to an external service (e.g., by a port and IP pair). In some embodiments, access to an internal endpoint and an external endpoint may be identical, so that the endpoint does not know which one is being accessed (e.g., even though the port and / or IP address and / or API command may be different).

[0093] Any network changes at any of these endpoints may be attributed to the SDN. Components connected to the SDN may appear as one network space to other components connected to the SDN. However, these components may actually be heterogeneously connected and physically separate. The SDN may abstract these physical differences, allowing the endpoints to logically view each other as connected devices. This configuration may allow market data to be communicated from these SDN-connected services to SDN-connected trading entities at high speeds and / or low latency.

[0094] To facilitate SDN functionality, one component of the SDN, such as component 419, may exercise control over each component of the SDN. For example, controller 419 may instruct the components of the SDN on how to route and / or process packets recovered by the SDN. For example, core 302 and / or application 303 may be controlled to respond to data (e.g., route according to the architecture of the SDN, ignore appropriately, encrypt or compress if necessary, analyze and / or capture if necessary) as needed by the SDN.

[0095] For example, for customer 403, the SDN may control network applications running in a core dedicated to customer 403 in network device 202A to enable routes to each of endpoints 401, 405, and 407. Routes to other endpoints may be disabled for that customer by the SDN controller. Those routes may be opened later, and / or open routes may be closed later. For example, if a new switching system is connected to the SDN, a new route to that system may be established at an IP and port pair that is accessible to the customer. As another example, if a customer does not pay for a market data subscription, the market data endpoint may become inaccessible, and the route may no longer be open for customer 403. Control component 419 may receive various inputs regarding such route changes and control applications such as 303A on core 302A to process packets according to such network changes.

[0096] As another example, a customer may request data encryption, data compression, data analytics, packet capture, etc. for access to a service. Such a request may be made through the controller 419 and / or directly through an API accessible by a network application (e.g., 303A), which may then process and / or be controlled to process the packets according to the request.

[0097] Control and / or application of services such as encryption, compression, load balancing, etc. may occur in various locations and / or by various entities. For example, a customer may instruct an API of the SDN (e.g., the SDN control component 419 and / or the core / application component 220) to compress communications with a market data source in a particular l-flow. The SDN may control components of the SDN (e.g., through communication between APIs of the SDN (e.g., the core / application component at each end of the l-flow)) to apply the requested compression to the data as it passes through the SDN. In some embodiments, such compression may be applied from endpoint to endpoint of the l-flow. In other embodiments, such compression may be applied across hops of the l-flow (e.g., within the SDN fabric). Of course, encryption functionality may operate similarly with the endpoint identifying the encryption to be used for the l-flow and one or more components of the SDN operating to apply the identified encryption.

[0098] As another example, load balancing on an l-flow may be controlled by instructions from a service provider. For example, an egress l-flow providing an exchange service may identify (e.g., by using an SDN API to an SDN controller or other component of the SDN (e.g., a core or application that controls routing in a device such as component 220)) that load balancing should be performed in a round-robin manner. One or more components of the SDN may be controlled to facilitate the identified load balancing. For example, a core connected to the exchange may be controlled to route any other packets arriving at that core to a different destination according to the load balancing formula. Because the load balancing is handled by the SDN, users of the service, and even the service itself, may not be aware of the actual adjustments to network routing.

[0099] As another example, analytics and / or packet capture may similarly be applied and / or controlled at the l-flow level. An endpoint may identify that a desired analysis and / or capture is to be applied to a particular l-flow. The SDN may determine how and / or where to apply the desired capture and / or analysis. For example, a core connecting a service to the SDN may operate to capture packets and / or apply analysis to packets. As another example, a core at an endpoint using a service may operate to apply analytics and / or capture packets of a user of the service to packets. The SDN may determine where and how to apply the capture and / or analysis (e.g., by instructing a core / application to perform an action on packets with certain characteristics as the packets traverse the SDN) and control the core to apply it in response to a request from the endpoint.

[0100] Again, it should be understood that these examples, structures and functionality are given as non-limiting examples only.

[0101] The following sections provide a guide to interpreting this application. I. Terminology

[0102] The term "product" means any machine, article of manufacture, and / or composition of matter, unless expressly specified otherwise.

[0103] The term "process" means any process, algorithm, method, etc., unless expressly specified otherwise.

[0104] Each process (whether called a method, algorithm, or otherwise) inherently includes one or more steps, and thus any reference to a "step or steps" of a process has inherent antecedent in the mere recitation of the term "process" or similar term. Accordingly, any reference in a claim to a "step or steps" of a process has sufficient antecedent.

[0105] The term "invention" and the like means "one or more inventions disclosed in this application" unless expressly specified otherwise.

[0106] The terms "one embodiment," "embodiment," "embodiments," "the embodiment," "the embodiment," "one or more embodiments," "some embodiments," "particular embodiments," "an embodiment," "another embodiment," etc. mean "one or more (but not all) embodiments of the invention," unless expressly specified otherwise.

[0107] The term "modification" of an invention means one embodiment of the invention unless expressly stated otherwise.

[0108] The term "indication" is used in a very broad sense: a "indication" of an object should be understood to include anything that can be used to identify that object.

[0109] A representation of an object may include an electronic message for identifying the object (e.g., identifying a widget by its serial number or identifying a widget by one or more characteristics of the widget). A representation of an object may include information that can be used to compute or reference the object (e.g., information that identifies the machine of which the widget is a part and can be used to identify the widget). A representation of an object may identify other objects related to the object (e.g., characteristics of the object, the object's name, names of objects related to the object). A representation of an object may not identify other objects related to the object (e.g., in a computer system configured to interpret the English article "a" to identify a widget, the article "a" may be used to identify the widget in the computer system). A representation of an object may be a sign, phenomenon, and / or symbol of the object. A representation of an object may include, for example, a code, a reference, an example, a link, a signal, and / or an identifier. A representation of an object may include information that indicates, describes, and / or relates to the object.

[0110] A transformation of a representation of an item may be a representation of the item (e.g., an encrypted representation of an item may be a representation of the item). A representation of an item may include the item itself, a copy of the item, and / or a portion of the item. A representation of an item may be meaningless to an item not constructed to understand the representation (e.g., a human may not understand the article "a" representing a widget, but a computer system may still be able to identify the widget from the article "a," and thus be a representation of the widget). It should be understood that the fact that a representation of an item can be used to identify the item does not imply that the item or other items are identified. A representation of an item may include any numerical representation unless otherwise specified. A representation of an item may include representations of other items (e.g., an electronic message representing many items) (representation can be used as a very broad claim phrase, e.g., "receive a representation of a financial instrument").

[0111] The word "indicate" means (1) to designate, identify, represent, or display, as by a word, symbol, or other thing; (2) to designate or identify by some word, feature, symbol, or other thing; (3) to depict, picture, or indicate the likeness, as in a picture; or (4) to function as a sign or symbol.

[0112] Reference to "another embodiment" when describing an embodiment does not indicate that the referenced embodiment is mutually exclusive of the other embodiment (e.g., an embodiment described before the referenced embodiment) unless expressly stated otherwise. Similarly, the mere fact that two (or more) embodiments are referenced does not imply that those embodiments are mutually exclusive.

[0113] One embodiment of an invention may include, encompass, or subsume one or more other embodiments of the invention. For example, a first embodiment comprising elements a, b, and c may include a second embodiment comprising elements a, b, c, and d, and a third embodiment comprising elements a, b, c, and e. Similarly, each of these first, second, and third embodiments may include a fourth embodiment comprising elements a, b, c, d, and e.

[0114] The terms "include," "comprise," and variations thereof mean "including, but not necessarily limited to," unless expressly specified otherwise. Thus, for example, the statement "the machine includes a red widget and a blue widget" means that the machine may include a red widget and a blue widget, but may also include one or more other items.

[0115] The term "consisting of" and variations thereof means "including and limited to," unless expressly specified otherwise. So, for example, the statement "This machine consists of red widgets and blue widgets" means that the machine includes red widgets and blue widgets, but nothing else.

[0116] The term "comprise" and variations thereof mean "to be a constituent part, component, or member" unless expressly specified otherwise. Thus, for example, the statement "The red widget and the blue widget comprise a machine" means that the machine includes a red widget and a blue widget.

[0117] The term "consist exclusively of" and variations thereof means "to be exclusively a part, the only component, or the only member," unless expressly specified otherwise. Thus, for example, the statement "The red widget and the blue widget exclusively constitute a machine" means that the machine consists of red widgets and blue widgets (i.e., contains nothing else).

[0118] The terms "a," "an," and "the" refer to "one or more" unless expressly specified otherwise. Thus, for example, the phrase "widget" means one or more widgets unless expressly specified otherwise. Similarly, the phrase "said widget" after the phrase "widget" means "one or more said widgets." Thus, the phrase "said" may refer to a specific phrase with an antecedent. For example, when the phrase "a specific single feature" is followed by the phrase "said feature," the phrase "said feature" should be understood to refer to the aforementioned "specific single feature" (the article "a" in "a specific single feature" refers to "one" specific single feature, not more than one specific single feature).

[0119] The term "plurality" means "two or more" unless expressly specified otherwise.

[0120] The term "herein" means "in this application, including anything that may be incorporated by reference," unless expressly stated otherwise.

[0121] When modifying a plurality of items (such as an enumerated list), the phrase "at least one of" means any combination of one or more of those items, unless expressly specified otherwise. For example, the phrase "at least one of a widget, a car, and a wheel" means either (i) a widget, (ii) a car, (iii) a wheel, (iv) a widget and a car, (v) a widget and a wheel, (vi) a car and a wheel, or (vii) a widget, a car, and a wheel. When modifying a plurality of items, the phrase "at least one of" does not mean "one of each of" the plurality of items. For example, the phrase "at least one widget, a car, and a wheel" does not mean "one widget, one car, and one wheel."

[0122] When used as a cardinal number to indicate a quantity of something (e.g., 1 widget, 2 widgets), numerical terms such as "1," "2," etc., mean the quantity indicated by the numerical term, and not more than the quantity indicated by the numerical term. For example, the phrase "1 widget" does not mean "at least 1 widget," and thus the phrase "1 widget" does not include, for example, 2 widgets.

[0123] The phrase "based on" does not mean "based only on" unless expressly specified otherwise. That is, the phrase "based on" includes both "based only on" and "based at least on." The phrase "based at least on" is equivalent to the phrase "based at least in part on." For example, the phrase "factor A" is calculated based on factor B and factor C includes embodiments in which factor A is calculated as the product of C times B (i.e., A=B×C), in which factor A is calculated by the sum of B and C (i.e., A=B+C), in which factor A is calculated by D times C times B, in which factor A is calculated by the square root of B plus the sum of C and D, etc.

[0124] The term "corresponds to" and similar terms are not exclusive unless expressly specified otherwise. For example, the term "corresponds to" does not mean "corresponds only to" unless expressly specified otherwise. For example, the phrase "this data corresponds to a credit card number" includes both "this data corresponds only to a credit card number" and "this data corresponds to a credit card number and also to something else."

[0125] The term "whereby" is used exclusively in this specification to precede a clause or set of other words that express solely the intended result, purpose, or outcome of something that is expressly described before the term "whereby." Thus, when the term "whereby" is used in a claim, the clause or other word that it modifies does not impose any further specific limitations on that claim or otherwise limit the meaning or scope of that claim.

[0126] The terms "eg," "such as," and similar terms mean "for example," and thus do not limit the term or phrase they describe. For example, in the sentence "a computer sends data (e.g., instructions, data structures) over the Internet," the term "for example" explains that "instructions" are an example of "data" that a computer can send over the Internet, and also explains that "data structures" are an example of "data" that a computer can send over the Internet. However, both "instructions" and "data structures" are merely examples of "data," and things other than "instructions" and "data structures" can also be "data."

[0127] The term "respective" and similar terms mean "viewed individually." Thus, when two or more things have "respective" properties, each such thing has its own unique property, and those properties can be different from one another or the same. For example, the phrase "two machines each have a respective function" means that a first of the two machines has a function and a second of the two machines likewise has a function. The function of the first machine may or may not be the same as the function of the second machine.

[0128] The term "ie" and similar terms mean "that is," and thus qualify the term or phrase it describes. For example, in the sentence "a computer sends data (i.e., instructions) over the Internet," the term "ie" describes that the "data" that a computer sends over the Internet are "instructions."

[0129] Numerical ranges are intended to include integer and non-integer numbers within the range unless expressly stated otherwise. For example, a range "1 to 10" should be interpreted to explicitly include integers between 1 and 10 (e.g., 1, 2, 3, 4, ..., 9, 10) and non-integer numbers (e.g., 1.0031415926, 1.1, 1.2, ..., 1.9).

[0130] Where two or more terms or phrases are synonymous (e.g., by expressly stating that the terms or phrases are synonymous), one such instance of a term or phrase does not mean that another instance of such a term or phrase must have a different meaning. For example, if a statement makes the meaning of "including" synonymous with "including but not limited to," simply using the phrase "including but not limited to" does not mean that the term "including" means anything other than "including but not limited to."

[0131] II.Decision The term "determine" and its grammatical variations (e.g., determining a price, determining a value, determining objects that meet certain criteria) are used in a very broad sense. The term "determine" encompasses a wide variety of actions, and thus "determine" can include calculating, computing, processing, deriving, investigating, searching (e.g., searching a table, database, or other data structure), representing in an electronic format or digital display, ascertaining, etc. "Determine" can also include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. "Determine" can also include resolving, selecting, choosing, establishing, etc.

[0132] The term "determining" does not imply certainty or absolute precision; thus, "determining" can include estimating, inferring, predicting, guessing, averaging, and the like.

[0133] The term "determining" does not imply that a mathematical operation must be performed, that a numerical method must be used, or that an algorithm must be employed.

[0134] The term "determine" does not imply that a particular widget must be used, for example, a computer does not necessarily have to make the decision.

[0135] The term "determining" may include "calculating." The term "calculating" should be understood to include performing one or more calculations. Calculations may include computation, arithmetic processing, and / or inference. Calculations may be performed by a computing device. For example, calculating something may include applying an algorithm to data by a computer processor and generating something as an output of the processor.

[0136] The term "determining" may include "referencing." It should be understood that the term "referencing" may include, for example, making one or more references to something. Referencing may include inquiring, accessing, selecting, choosing, reading, and / or searching. The act of referencing may be performed by a computing device. For example, referencing something may include reading, by a processor, a memory location where the something is stored.

[0137] The term "determining" can include "receiving." For example, receiving something can include incorporating something. In some embodiments, receiving can include an act performed to incorporate something, such as operating a network interface to incorporate something. In some embodiments, receiving can be performed without an act performed to incorporate something, such as a direct memory write or an act performed to incorporate something into hardwired circuitry. Receiving something can include receiving something from a remote resource capable of computing something.

[0138] III. Sentence Form If a limitation of a first claim covers one feature as well as a plurality of features (e.g., a limitation such as "at least one widget" covers not only one widget but also a plurality of widgets), and in a second claim that depends from the first claim, the second claim uses the definite article "the" to refer to its limitation (e.g., "the widget"), this mere use does not mean that the first claim covers only one feature, nor does it mean that the second claim covers only one feature (e.g., "the widget" can cover both one widget and a plurality of widgets).

[0139] When an ordinal number (such as "first," "second," or "third") is used as an adjective before a term, the ordinal number (unless expressly stated otherwise) is used merely to indicate a particular feature, such as to distinguish that feature from another feature described by the same or a similar term, but the ordinal number has no other meaning or limiting effect and is merely a convenient name. For example, a "first widget" may be so named simply to distinguish it from, e.g., a "second widget." Thus, the mere use of the ordinal numbers "first" and "second" before the term "widget" does not indicate any other relationship between the two widgets, nor does it indicate any other characteristics of either or both widgets. For example, the mere use of the ordinal numbers "first" and "second" before the term "widget" does not (1) mean that either widget comes before or after the other widget in terms of order or position, (2) mean that either widget occurs or operates before or after the other widget in terms of time, or (3) mean that either widget ranks above or below the other widget in terms of importance or quality. The mere use of ordinal numbers does not impose a numerical limitation on the feature that the ordinal number identifies. For example, the mere use of the ordinal numbers "first" and "second" before the term "widget" does not mean that there are exactly two widgets.

[0140] Where a single device, object, or other product is described herein, in other embodiments, two or more devices or objects (whether or not operating together) may alternatively be used in place of the single device or object described. Thus, functionality described as possessed by a device may in other embodiments be alternatively possessed by two or more devices or objects (whether or not operating together).

[0141] Similarly, where this specification describes two or more devices, objects, or other products (whether or not operating together), in other embodiments, a single device or object may be substituted for the two or more described devices or objects. For example, multiple computer-based devices may be replaced with a single computer-based device. In other embodiments, such multiple computer-based devices may collaborate to perform a single step of a process, as occurs in a grid computing system. In other embodiments, such multiple computer-based devices may provide additional functionality, such as performing multiple steps of a process, as occurs in a cloud computing system. (Conversely, a single computer-based device may be replaced with multiple computer-based devices working together. For example, a single computer device may be replaced with a server and a workstation working together via the Internet.) Thus, various functionality described as being possessed by two or more devices or objects may alternatively be possessed by a single device or object.

[0142] The functionality and / or features of a single described device may, in other embodiments, be alternatively performed by one or more other devices that are described but are not explicitly described as having such functionality / features. Thus, other embodiments need not include the described device itself, but instead may include one or more other devices that have such functionality or features in those other embodiments.

[0143] IV. Disclosed Examples and Terminology Are Non-Limiting Neither the Title (which is at the very bottom of the application and should not be used to interpret the meaning of any claim, nor should it be used to interpret the scope of any claim at the beginning of the first page) nor the Abstract (which is at the end of the application) should be construed as limiting in any way the scope of the disclosed invention. The Abstract is included herein solely because required under 37 C.F.R. § 1.72(b).

[0144] The titles and section headings provided herein are for convenience only and should not be construed as limiting the disclosure in any way.

[0145] Numerous embodiments have been described herein and are shown solely for illustrative purposes. The described embodiments are not, and are not intended to be, limiting in any sense. As is readily apparent from this disclosure, the invention disclosed herein is broadly applicable to numerous embodiments. Those skilled in the art will appreciate that the disclosed invention can be implemented with various modifications and alterations, including structural, logical, software, and electrical modifications. Although particular features of the disclosed invention may be described with reference to one or more specific embodiments and / or drawings, it should be understood that, unless expressly stated otherwise, such features are not limited to use with the particular embodiment or drawings for which such features are described.

[0146] While an embodiment may be disclosed as including several features, other embodiments of the invention may include fewer than all such features. Thus, for example, a claim may be directed to less than all features of a disclosed embodiment, and such a claim should not be construed as requiring more features than are expressly recited in the claim.

[0147] No embodiment of a method step or product element described herein constitutes or is essential to or refers to the same subject matter as the invention claimed herein, unless expressly stated to be such herein or (with respect to a claim and the invention defined by that claim) expressly recited in the claim.

[0148] Any preamble to a claim that refers to matter other than a statutory classification should be construed as describing the purposes, benefits, and possible uses of the claimed invention, and such preamble should not be construed as limiting the claimed invention.

[0149] This disclosure is not a literal description of all embodiments of the invention, nor is this disclosure a listing of features of the invention that must be present in all embodiments.

[0150] Not all disclosed embodiments are necessarily protected by the scope of a claim (even if all pending, amended, issued, and cancelled claims are included). Moreover, an embodiment may (but need not) be protected by several claims. Thus, if a claim (whether pending, amended, issued, or cancelled) is directed to a particular embodiment, that is not evidence that the scope of other claims does not similarly protect that embodiment.

[0151] Devices described as communicating with each other need not communicate with each other continuously unless expressly specified otherwise. Rather, such devices need only transmit to each other as needed or desired and may in fact refrain from exchanging data most of the time. For example, a machine communicating with other machines over the Internet may not transmit data to other machines for extended periods of time (e.g., weeks at a time). Furthermore, devices that communicate with each other may communicate directly or indirectly through one or more intermediaries. Multiple devices communicate with each other if they are capable of at least one-way communication. For example, a first device communicates with a second device if it can send information to the second device. Similarly, a second device communicates with a first device if it can receive information from the first device.

[0152] The description of an embodiment with several components or features does not imply that all or any of such components or features are required. On the contrary, various optional components are described to illustrate the wide variety of possible embodiments of the invention. Unless expressly specified otherwise, no component or feature is essential or required.

[0153] Although process steps, algorithms, or the like may be described or claimed in a particular order, such processes can be configured to function in different orders. That is, any order or sequence of steps that may be explicitly described or claimed does not necessarily indicate a requirement that the steps be performed in that order. Steps of processes described herein can be performed in any order possible. Furthermore, some steps can be performed simultaneously, even though they are described or implied as occurring non-concurrently (e.g., because one step is described after another). Furthermore, illustration of a process by drawing depictions does not imply that the illustrated process excludes other variations and modifications to the process, nor does it imply that the illustrated process or any of its steps are required for the invention, or that the illustrated process is preferred.

[0154] Although a process may be described as including multiple steps, this does not imply that all or any of those steps are preferred, essential, or required. Various other embodiments within the scope of the described invention(s) include other processes that omit some or all of the described steps. Unless expressly specified otherwise, no step is essential or required.

[0155] Although a process may be described in isolation or without reference to other products or methods, in an embodiment, the process may interact with other products or methods. For example, such interactions may include linking one business model to another. Such interactions may be provided to increase the flexibility or desirability of the process.

[0156] Although a product may be described as including multiple components, aspects, qualities, properties, and / or characteristics, this does not indicate that any or all of those multiples are preferred, essential, or required. Various other embodiments within the scope of the described invention(s) include other products that omit some or all of the multiples described.

[0157] Unless expressly stated otherwise, an enumerated list of items (which may be numbered or unnumbered) does not imply that any or all of the items are mutually exclusive. Similarly, unless expressly stated otherwise, an enumerated list of items (which may be numbered or unnumbered) does not imply that any or all of the items are exhaustive of any category. For example, the enumerated list "computers, laptops, and PDAs" does not imply that any or all of the three items in the list are mutually exclusive, nor does it imply that any or all of the three items in the list are exhaustive of any category.

[0158] The listing of items as enumerated (which may or may not be numbered) does not imply that any or all of the items are equivalent to each other or readily substituted for each other.

[0159] All embodiments are illustrative and do not imply that the invention or any embodiment has been made or performed as applicable.

[0160] V. Computing It will be readily apparent to those skilled in the art that the various processes described herein can be implemented, for example, by appropriately programmed general-purpose computers, special-purpose computers, and computing devices. Typically, a processor (e.g., one or more microprocessors, one or more microcontrollers, one or more digital signal processors) receives instructions (e.g., from a device such as a memory) and executes those instructions, thereby performing one or more processes defined by the instructions. The instructions may be embodied, for example, as one or more computer programs or one or more scripts.

[0161] The term "computer" refers to a means that determines the use of a processor according to a software algorithm.

[0162] "Processor" means one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, graphics processing units (GPUs) or such devices, or any combination thereof, regardless of their architecture (e.g., chip-level multiprocessing or multicore, RISC, CISC, microprocessors with non-interlocked pipeline stages, pipelined, simultaneous multithreading, microprocessors with embedded graphics processing units, GPGPU).

[0163] "Computer device" means one or more microprocessors, central processing units (CPUs), computer devices, microcontrollers, digital signal processors, graphics cards, mobile gaming devices, or any combination of such devices, regardless of their architecture (e.g., chip-level multiprocessing or multicore, RISC, CISC, microprocessors with non-interlocked pipeline stages, pipelined architecture, simultaneous multithreading).

[0164] Thus, a description of a process is also a description of an apparatus for performing that process. An apparatus for performing a process may include, for example, a processor, and input and output devices suitable for performing the process. For example, a description of a process describes an apparatus that includes a processor and a memory that stores a program containing instructions that, when executed by the processor, direct the processor to perform the method.

[0165] An apparatus for executing a process may include multiple computing devices that cooperatively execute the process. Some of these computing devices may cooperate to execute steps of the process, and some may operate individually on steps of the process and provide underlying services to other computing devices that may facilitate execution of the process. Such computing devices may operate under the direction of a centralized authority. In other embodiments, such computing devices may operate without the direction of a centralized authority. Some examples of apparatuses that may operate in some or all of these ways may include grid computing systems, cloud computing systems, peer-to-peer computing systems, computing systems that can provide software as a service, and the like. For example, an apparatus may include a computing system that executes much of the processing load on a remote server but outputs display information and receives user input information from a local user computer, such as a computing system running VMware software.

[0166] Furthermore, programs (as well as other types of data) implementing such methods can be stored and transmitted in numerous ways using a variety of media (e.g., computer-readable media). In some embodiments, hardwired circuitry or custom hardware can be used in place of, or in combination with, some or all of the software instructions capable of implementing the processes of various embodiments. Thus, various combinations of hardware and software, as well as software, can be used.

[0167] The term "computer-readable medium" refers to any non-transitory medium, media, or combination of various media that participate in providing data (e.g., instructions, data structures) that may be read by a computer, a processor, or a similar device. Such media may take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks and other persistent memory. Volatile media include dynamic random access memory (DRAM), which typically constitutes main memory. Transmission media include coaxial cables, copper wire, and fiber optics, including the wires that constitute a system bus coupled to the processor. Transmission media may include or convey acoustic waves, light waves, and electromagnetic radiation, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer readable media include, for example, a floppy disk, a flexible disk, a hard disk, magnetic tape, any other magnetic medium, a CD-ROM, a DVD, any other optical medium, punch cards, paper tape, any other physical medium with a pattern of holes, a RAM, a PROM, an EPROM, a Flash EEPROM, any other memory chip or cartridge, a carrier wave as described below, or any other medium from which a computer can read.

[0168] The term "tangible computer-readable medium" refers to a "computer-readable medium" that includes a hardware element such as an optical or magnetic disk.

[0169] Data (e.g., a sequence of instructions) can be carried to a processor using various forms of computer-readable media. For example, data can (i) be sent to the processor from RAM, (ii) be carried over a wireless transmission medium, (iii) be formatted and / or transmitted in accordance with numerous forms, standards, or protocols, such as Ethernet (or IEEE 802.3), wireless local area network communications defined by the IEEE 802.11 standard whether or not approved by the WiFi Alliance, SAP, ATP, Bluetooth, TCP / IP, TDMA, CDMA, 3G, etc., and / or (iv) be encrypted to protect privacy or prevent fraud in any of a variety of ways well known in the art.

[0170] The term "database" refers to a collection of electronic records of data stored in a readable format.

[0171] The term "data structure" refers to a database of a hardware machine such as a computer.

[0172] The term "network" refers to a series of points or nodes interconnected by communication paths. For example, a network may include multiple computers or communication devices interconnected by one or more wired and / or wireless communication paths. A network may interconnect with other networks and may include sub-networks.

[0173] The term "predetermined" refers to having been previously determined, i.e., prior to the present time or action. For example, the phrase "displaying a predetermined value" means displaying a value that was determined prior to the display action.

[0174] The term "condition" indicates either (1) a prerequisite for the fulfillment of a dependent agreement, or (2) something necessary for something else to occur or occur.

[0175] The term "transformation" means (1) the exchange or transfer of goods, services, or funds, or (2) any act or action of communication involving two parties or things that repeatedly affect one another.

[0176] Thus, a description of a process is also a description of a computer-readable medium storing a program for performing that process. The computer-readable medium can store (in any suitable format) those program elements suitable for performing the method. For example, a description of a process is a description of a computer-readable memory storing a program including instructions that, when executed by a processor, direct the processor to perform the method.

[0177] Just as the description of various steps in a process does not indicate that all steps described are required, apparatus embodiments include computers or computing devices operable to perform some, but not necessarily all, of the described processes.

[0178] Similarly, just as the description of various steps in a process does not indicate that all steps described are required, embodiments of a computer-readable medium storing a program or data structure include computer-readable media that store a program that, when executed, can cause a processor to perform some (if not necessarily all) of the described process.

[0179] When describing a database, those skilled in the art will understand that (i) alternative database structures to the described database can be readily used, and (ii) other memory structures other than a database can be readily used. Any illustrations or descriptions of any sample databases shown herein are exemplary configurations for stored information representation. For example, any number of other configurations other than those suggested in the tables shown in the drawings or elsewhere can be used. Similarly, the entries in any illustrated databases represent only exemplary information, and those skilled in the art will understand that the number and content of entries may differ from the number and content described herein. Furthermore, despite any description of a database as a table, other formats (including relational databases, object-based models, and / or distributed databases) can be used to store and manipulate the types of data described herein. Similarly, object methods or database operations can be used to implement various processes, such as those described herein. Furthermore, databases can be stored in known manner, either locally or remotely from devices that access data in such databases.

[0180] Various embodiments can be configured to function within a network environment, including a computer in communication with one or more devices (e.g., via a communications network). The computer can communicate with those devices directly or indirectly through any wired or wireless medium (e.g., the Internet, a LAN, a WAN, or Ethernet, token ring, telephone lines, cable lines, radio channels, optical communications lines, commercial online service providers, bulletin board systems, satellite communications lines, or any combination of the above). Each of the devices can itself comprise a computer or other computing device, such as one based on an Intel®, Pentium®, or Centrino™, Atom™, or Core™ processor, adapted to communicate with the computer. Any number and type of devices can communicate with the computer.

[0181] In one embodiment, a server computer or centralized authority may not be necessary or desirable. For example, the present invention may, in one embodiment, be practiced on one or more devices without a centralized authority. In such an embodiment, any functions described herein as being performed by a server computer, and any data described as being stored on a server computer, may instead be performed by or stored on one or more such devices.

[0182] When describing a process, in one embodiment the process can function without any human intervention, while in another embodiment the process includes some human intervention (e.g., a step is performed by or with the assistance of a human).

[0183] As used herein, the term "encryption" refers to the process of obfuscating or concealing information so that it is not readily understandable without special knowledge. The process of encryption may involve converting raw information, called plaintext, into encrypted information. The encrypted information may be called ciphertext, and the algorithm that converts plaintext to ciphertext may be called encryption. Encryption may be used to perform the operation of converting ciphertext back to plaintext. Examples of encryption include substitution ciphers, transposition ciphers, and encryption performed using rotor machines.

[0184] In various cryptographic methods, encryption requires a supporting piece of information called a key. A key may consist, for example, of a string of bits. A key may be used for encryption to encrypt plaintext. A key may be used for encryption to decrypt ciphertext. In a category of encryption called symmetric key algorithms (i.e., secret key cryptography), the same key is used for encryption and decryption. Therefore, the strength of the encrypted information depends on keeping the key secret. Examples of symmetric key cryptography include DES and AES. In a category of encryption called asymmetric key algorithms (i.e., public key cryptography), different keys are used for encryption and decryption. In asymmetric key algorithms, any member of the public can use one key (i.e., the public key) to encrypt plaintext into ciphertext. However, only the holder of the second key (i.e., the private key) can decrypt the ciphertext back into plaintext. An example of an asymmetric key cryptography is RSA.

[0185] VI. Continuing Applications This disclosure provides one of ordinary skill in the art with an enabling description of several embodiments and / or inventions, some of which may not be claimed in this application, but may be claimed in one or more continuing applications claiming benefit of priority to this application.

[0186] Applicant intends to file further applications to pursue subject matter disclosed and enabled but not claimed in this application.

[0187] VII. Waiver Numerous references to a particular embodiment do not imply a waiver or negation of additional, different embodiments, and similarly, references to a description of an embodiment including all of a particular feature do not imply a waiver or negation of embodiments that do not include that particular feature. Any explicit waiver or negation in this application will be preceded by the words "does not include" or "cannot perform."

[0188] VIII. Examination Process In interpreting this application (including the claims), persons of ordinary skill in the art will refer to the prosecution history of this application, rather than to any other patents or patent applications, regardless of whether there are other patent applications that may be considered related to this application and whether there are other patent applications that share a claim of priority with this application.

[0189] [Appendix 1] A first routing device configured to map local address and port pairs of a first network to destinations on a second network and to map local address and port pairs of a third network to the destinations on the second network, wherein the first routing device is configured such that a first core of a first processor is configured to perform routing to the first network and a second core of the first processor is configured to perform routing to the second network. An apparatus comprising: to facilitate mapping the local address and port pair of the first network to the destination, the routing device is configured to open a first socket to the destination and a second socket to a second destination, and to fail over routing to the second socket in response to determining that the first socket has failed; a third core of the routing device is configured to execute a process configured to access a portion of a memory space shared with the first core, copy at least one of a packet header and an entire packet from the portion of the memory space, and facilitate transmitting the at least one of the packet header and the entire packet to an analytics engine coupled to the first routing device. Device. [Appendix 2] 10. The apparatus of claim 1, wherein the first routing device is configured to load balance the traffic sent to the local address and port pair such that traffic is split between the destination using the first socket and the second destination using the second socket. [Appendix 3] 3. The apparatus of claim 2, wherein the load balancing is performed using at least one of a round-robin method and a least-connection method. [Appendix 4] 10. The device of claim 1, wherein the routing device includes a plurality of multi-core processors. [Appendix 5] 10. The apparatus of claim 1, wherein the routing device is configured to route data at gigabit speeds. [Appendix 6] a second routing device configured to map an address and port pair to the first network and to map a second address and port pair to the second network, wherein the second routing device is configured such that a first core of a second processor is configured to perform routing from the destination to the first network and a second core of the second processor is configured to perform routing from the destination to the second network. 2. The apparatus of claim 1, comprising: [Appendix 7] 7. The apparatus of claim 6, wherein the first routing device is configured to compress data blocks to be routed to the destination according to a dictionary scheme, and the second routing device is configured to decompress the data blocks according to the dictionary scheme for transmission to the destination. [Appendix 8] 7. The apparatus of claim 6, wherein services are enabled from the first network and the second network to the software-defined network by mapping from the first network and the second network through the first routing device. [Appendix 9] 7. The apparatus of claim 6, wherein the second routing device enables the destination to subscribe to services provided by the first network and the second network to the software-defined network. [Appendix 10] 7. The apparatus of claim 6, wherein the first routing device and the second routing device define a software-defined network spanning multiple data centers. [Appendix 11] 7. The apparatus of claim 6, wherein the destination includes a customer conducting a transaction and the first network includes a network on which an electronic exchange resides.< / data> < / gmtsecond> < / date>

Claims

1. a first processing device configured to map local network address and port pairs on a first network to services on a second, remote network; opening a first socket to a first destination on a second remote network and opening a second socket to a second destination on the second remote network; load balancing traffic sent to the local network address and port pair between the first destination using the first socket and the second destination using the second socket; In response to determining that the first destination has failed, routing traffic sent to the local network address and port pair to the second destination using the second socket; The second processing device accessing a portion of a memory space shared with the first processing core, copying at least one packet header or an entire packet from the portion of the memory space, and facilitating sending the at least one packet header or the entire packet to an analytics engine while the first processing unit routes the entire packet; A method comprising:

2. by the third processing device, mapping a second local network address and port pair of a third network to the service on the second remote network; The method of claim 1 , comprising:

3. The method of claim 1 , wherein the load balancing is performed in at least one of a round robin or least connection fashion.

4. By the routing device, mapping an address and port pair to the first network and a second address and port pair to the second network, wherein the routing device is configured such that a third processing device is configured to perform routing from the destination to the first network and a fourth processing device is configured to perform routing from the destination to the second network; The method of claim 1 , comprising:

5. 5. The method of claim 4, wherein the first processing device is configured to compress data blocks to be routed to the service according to a dictionary scheme, and the routing device is configured to decompress the data blocks according to the dictionary scheme for transmission to the service.

6. The method of claim 4 , wherein the first processing device and the first routing device define a software-defined network spanning multiple remote data centers.

7. The method of claim 1 , wherein mapping enables a plurality of services from the first network and the second network over a software-defined network.

8. The method of claim 1 , wherein the first processing device enables multiple devices on the first network to subscribe to multiple services offered on a software-defined network.

9. 10. The method of claim 1, wherein the service includes a customer conducting a transaction and the first network includes a network on which an electronic exchange resides.

Citation Information

Patent Citations

  • Communication control device, communication control system, virtual server management device, switch device and communication control method

    JP2013183440A

  • Communication system, control device, packet collection method and program

    JP2013223191A