Context-Aware Middlebox Services at Datacenter Edges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional hardware middlebox appliances do not leverage the flexibility and contextual data provided by software-defined networking (SDN) and network virtualization, limiting their ability to effectively utilize rich contextual information for data message flows.

Innovation Solution

A novel architecture that captures contextual attributes on host computers, using context engines and software forwarding elements to generate context headers for data messages, which are then processed by middlebox service engines at the edge of a physical datacenter, enabling context-aware services such as firewall operations, load-balancing, encryption, and WAN optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional hardware middlebox appliances are used, then device stability and reliability are maintained, but the ability to leverage flexibility and contextual data from SDN and network virtualization is lost

Engineering Contradiction:
Improveability to leverage contextual dataVSAvoidarchitecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a context header insertion processor as an intermediary component that bridges the gap between existing hardware middlebox appliances and SDN contextual data. This processor captures contextual attributes from virtualized network functions and encapsulates them in headers that can be processed by traditional middlebox services, allowing legacy hardware to leverage modern contextual data without requiring complete architectural replacement

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The context header insertion processor serves multiple functions: it captures contextual attributes from diverse sources (virtual machines, containers, network flows), encapsulates this data in a standardized header format, and makes it accessible to various middlebox services. This multi-functional component enables both traditional hardware appliances and virtualized services to utilize contextual data within a unified architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If middlebox services are migrated to virtualized hosts, then flexibility and access to contextual data improve, but integration with external networks and routing services becomes more complex

Engineering Contradiction:
Improveflexibility and contextual data accessVSAvoidnetwork integration complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the middlebox service functionality into distinct modular components: context capture modules that collect attributes from virtualized environments, context header insertion processors that encapsulate this data, and service engine interfaces that communicate with external networks. This segmentation allows each component to be optimized independently while maintaining seamless integration between virtualized services and external network infrastructure

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If contextual attributes are captured and processed for each data message flow, then service rule enforcement accuracy improves, but processing overhead and latency increase

Engineering Contradiction:
Improveservice rule enforcement accuracyVSAvoidmessage processing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The context header insertion processor performs preliminary action by capturing and encapsulating contextual attributes early in the message flow path, before messages reach middlebox service engines. This advance preparation ensures that when messages are processed by service rules, the contextual data is already available in a ready-to-use format, eliminating the need for time-consuming queries during critical message processing stages

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11184327B2Context aware middlebox services at datacenter edges
Publication Date: 2021.11.23 VMWARE INC
  • US11184327B2 patent drawing
  • US11184327B2 patent drawing
  • US11184327B2 patent drawing

AI summary

Some embodiments of the invention provide a novel architecture for providing context-aware middlebox services at the edge of a physical datacenter. In some embodiments, the middlebox service engines run in an edge host (e.g., an NSX Edge) that provides routing services and connectivity to external networks (e.g., networks external to an NSX-T deployment). Some embodiments use a novel architecture for capturing contextual attributes on host computers that execute one or more machines and providing the captured contextual attributes to context-aware middlebox service engines providing the context-aware middlebox services. In some embodiments, a context header insertion processor uses contextual attributes to generate a header including data regarding the contextual attributes (a “context header”) that is used to encapsulate a data message that is processed by the SFE and sent to the context-aware middlebox service engine.