Distributed vPlane State Analysis for Scalable Packet Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized network environments, existing technologies face challenges in efficiently managing stateful packet flows, particularly in determining the state analysis owner for peer-to-peer transmission, which is crucial for maintaining consistent state processing across packets in stateful flows like firewall traffic and NAT, but often requires centralized databases that struggle to scale with large deployments.
Innovation Solution
A distributed methodology is implemented where vPlanes are assigned query subsets, allowing them to autonomously determine and manage state analysis owners, with helper vPlanes assisting in resolving unknown state analysis owners and distributing the processing load across the network fabric, eliminating the need for centralized databases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized databases are used to manage state analysis owners, then state processing consistency is maintained, but scalability deteriorates in large deployments
Solution Approach 1:
The patent segments the centralized state analysis owner determination into distributed vPlane components. Each vPlane maintains local state information and can independently determine state analysis owners for its associated virtual machines, eliminating the need for a single centralized database while maintaining consistency through coordinated state tracking across multiple vPlanes.
Solution Approach 2:
The patent introduces vPlanes as intermediary components between virtual machines and the physical network infrastructure. These vPlanes act as state analysis owners that mediate packet flow state tracking, distributing the previously centralized function across multiple intelligent intermediaries that can autonomously manage state information.
2Productivity
If distributed methodology is implemented, then scalability is improved, but system complexity increases
Solution Approach 1:
The patent makes vPlanes universal components that can perform multiple functions: acting as state analysis owners for their local virtual machines, serving as helpers for other vPlanes, and participating in the distributed state determination process. This multi-functionality reduces the need for specialized components and simplifies the overall distributed architecture.
Solution Approach 2:
The patent enables vPlanes to autonomously determine state analysis owners using local information and predefined algorithms. Each vPlane can independently resolve state ownership questions without requiring centralized coordination, allowing the system to self-organize and scale automatically as virtual machines are added or removed.
3Productivity
If vPlanes autonomously determine state analysis owners, then processing efficiency is improved, but state management consistency becomes more difficult to maintain
Solution Approach 1:
The patent implements feedback mechanisms where vPlanes exchange state information and acknowledgments with each other. When a vPlane determines a state analysis owner, it communicates this determination to relevant parties, and state information is propagated throughout the distributed system, ensuring all vPlanes have consistent views of flow state ownership.
Solution Approach 2:
The patent establishes predetermined algorithms and criteria that vPlanes use to autonomously determine state analysis owners before packets arrive. These preliminary rules, based on virtual machine associations and vPlane capabilities, enable consistent state ownership determination without requiring real-time coordination for each packet, thus maintaining both efficiency and consistency.
Data Source
AI summary
Techniques for enabling peer-to-peer transmission of stateful packet flows in a network environment are provided. In certain embodiments, a computer system receives a packet belonging to a stateful flow, determines a query subset from a plurality of query subsets based on information from the packet, determines a first forwarding plane from a plurality of forwarding planes as an owner of the query subset, sends the packet to the first forwarding plane that owns the query subset, receives from the first forwarding plane information indicating that a second forwarding plane from the plurality of forwarding planes is a state analysis owner for the packet, and transmits the packet to the second forwarding plane. Examples of stateful flow include firewall traffic, network address translation traffic, or application layer classification for Quality of Service. In certain embodiments, the state analysis owner for the stateful flow may perform routing functions for the packet.


