DPU Hardware-Accelerated PBR Over Service Function Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SFC architectures lack support for flexible steering rules, configurable and dynamic interface mappings, and network acceleration in a single accelerated data plane, which hinders scalability and efficiency in modern, cloud-centric networks.

Innovation Solution

Implementing a DPU with hardware-accelerated flexible steering rules, configurable and dynamic SFC interfaces, and a network pipeline abstraction layer (NPAL) to enable virtual bridges and support multiple network protocols and functions in a single accelerated data plane, facilitating fast link recovery and policy-based routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional middleboxes (firewalls, load balancers, IDS) are used to provide security and network functions, then network security and performance are improved, but device complexity, capital investment, and operational complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple middlebox functions (firewall, load balancer, IDS, DLP, VPN, WAN optimization) into a single integrated network fabric using service function chaining. This consolidation reduces the number of separate hardware devices from multiple specialized middleboxes to a unified infrastructure, directly addressing the contradiction by maintaining security functions while reducing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network fabric infrastructure is designed to provide multiple network functions (security, load balancing, intrusion detection, data loss prevention, VPN, WAN optimization) through a single universal platform. This multi-functional approach allows the system to replace multiple specialized middleboxes with one versatile infrastructure, reducing capital investment and operational complexity while maintaining all necessary security and performance functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple specialized hardware middleboxes are deployed to provide diverse network functions, then network functionality and performance are improved, but capital investment and space requirements increase

Engineering Contradiction:
Improvenetwork functionalityVSAvoidhardware resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple specialized hardware middleboxes into a single network fabric infrastructure that supports diverse network functions through service function chaining. This consolidation reduces the quantity of hardware resources from multiple separate devices to one integrated platform, directly addressing the contradiction by maintaining functional versatility while reducing hardware footprint

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network fabric is designed as a universal platform capable of providing multiple network functions (firewall, load balancing, IDS, DLP, VPN, WAN optimization) through a single infrastructure. This multi-functionality allows the system to replace multiple specialized hardware devices with one versatile platform, reducing space requirements and capital investment while maintaining all necessary network functionalities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If traditional SFC architectures are used without hardware acceleration, then implementation simplicity is maintained, but network acceleration and scalability are limited

Engineering Contradiction:
Improvenetwork accelerationVSAvoidarchitecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a service function chaining infrastructure as an intermediary layer between traditional networking and hardware acceleration. This SFC architecture acts as a mediator that enables hardware-accelerated policy-based routing while maintaining compatibility with existing network functions, resolving the contradiction by providing network acceleration without requiring complete architectural overhaul

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the operational parameters of the network architecture by implementing hardware-accelerated policy-based routing within the service function chaining framework. This parameter change enables line-rate packet processing and enhanced scalability while keeping the overall architecture manageable through the existing SFC abstraction layer, thus improving productivity without proportionally increasing complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250337688A1Hardware-accelerated policy-based routing (PBR) over service function chaining (SFC)
Publication Date: 2025.10.30 MELLANOX TECHNOLOGIES LTD(IL)
  • US20250337688A1 patent drawing
  • US20250337688A1 patent drawing
  • US20250337688A1 patent drawing

AI summary

Technologies for creating an optimized and accelerated network pipeline using a network pipeline abstraction layer (NPAL) for policy-based routing (PBR) over Service Function Chaining (SFC) are described. A DPU includes acceleration hardware engine to provide a single accelerated data plane. A processing device can generate a first virtual bridge and a second virtual bridge, the first virtual bridge to be controlled by a first network service hosted on the DPU and having a set of one or more network rules, and the second virtual bridge having a policy-based routing policy (PBR policy). The processing device can add the virtual port between the first virtual bridge and the second virtual bridge. The acceleration hardware engine, in the single accelerated data plane, can route network traffic data using the PBR policy and process the network traffic data using the set of one or more network rules.