Context-Aware Middlebox Services via Context Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional hardware middlebox appliances do not leverage the flexibility and contextual data provided by software-defined networking (SDN) and network virtualization, limiting their ability to effectively utilize rich contextual information for data message flows.

Innovation Solution

A novel architecture that captures contextual attributes on host computers, using context engines and software forwarding elements to generate context headers for data messages, which are then processed by middlebox service engines at the edge of a physical datacenter, enabling context-aware services such as firewall operations, load-balancing, encryption, and WAN optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If middlebox services are implemented as traditional hardware appliances, then device stability and reliability are maintained, but flexibility and ability to utilize contextual data from SDN are limited

Engineering Contradiction:
ImproveflexibilityVSAvoidservice stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a context header insertion processor as an intermediary component that bridges the software-based context collection mechanism and the middlebox service engines. This processor captures contextual attributes from data messages, generates context headers, and inserts them into message flows, enabling middlebox services to access rich contextual information while maintaining system stability through a structured intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the middlebox service functionality into modular components: context collection modules on individual hosts, context header insertion processors, and middlebox service engines at the datacenter edge. This segmentation allows each component to be independently optimized and managed, providing flexibility while maintaining overall system reliability through distributed architecture

Inventive Principle:
Principle #1Segmentation

2Loss of information

If middlebox services run on hosts with access to contextual data, then service intelligence and context-awareness are improved, but system complexity increases

Engineering Contradiction:
Improvecontextual data utilizationVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts contextual attributes from data messages and places them into dedicated context headers. This extraction separates the contextual information from the original message payload, allowing middlebox services to access contextual data efficiently without processing the entire message content, thereby reducing computational complexity while improving contextual awareness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The context header insertion processor performs preliminary actions by capturing and generating context headers before data messages reach the middlebox service engines. This preliminary processing of contextual information simplifies the workload of middlebox services, as they receive pre-processed messages with contextual attributes already organized in structured headers

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If context headers are generated and inserted for all data messages, then middlebox service capability is enhanced, but processing overhead and time increase

Engineering Contradiction:
Improvecontext-aware service capabilityVSAvoidmessage processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The context header insertion processor implements partial action by selectively processing context headers based on message characteristics and service requirements. Rather than generating context headers for every single data message without discrimination, the system applies context header insertion selectively to messages that require middlebox processing, reducing overall processing overhead while maintaining enhanced service capability for relevant traffic

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10999220B2Context aware middlebox services at datacenter edge
Publication Date: 2021.05.04 VMWARE INC
  • US10999220B2 patent drawing
  • US10999220B2 patent drawing
  • US10999220B2 patent drawing

AI summary

Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines and providing the captured contextual attributes to middlebox service engines executing at the edge of a physical datacenter. In some embodiments, the middlebox service engines run in an edge host (e.g., an NSX Edge) that provides routing services and connectivity to external networks (e.g., networks external to an NSX-T deployment). Some embodiments execute a context header insertion processor that receives contextual attributes relating to network events and/or process events on the machines collected using a guest-introspection (GI) agent on each machine. In some embodiments, the context header insertion processor uses these contextual attributes to generate a header including data regarding the contextual attributes (a “context header”) that is used to encapsulate a data message that is processed by the SFE.