DPU Hardware-Accelerated PBR Over Service Function Chains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SFC architectures lack support for flexible steering rules, configurable and dynamic interface mappings, and network acceleration in a single accelerated data plane, which hinders scalability and efficiency in modern, cloud-centric networks.
Innovation Solution
Implementing a DPU with hardware-accelerated flexible steering rules, configurable and dynamic SFC interfaces, and a network pipeline abstraction layer (NPAL) to enable virtual bridges and support multiple network protocols and functions in a single accelerated data plane, facilitating fast link recovery and policy-based routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional middleboxes (firewalls, load balancers, IDS) are used to provide security and network functions, then network security and performance are improved, but device complexity, capital investment, and operational complexity increase significantly
Solution Approach 1:
The patent combines multiple middlebox functions (firewall, load balancer, IDS, DLP, VPN, WAN optimization) into a single integrated network fabric using service function chaining. This consolidation reduces the number of separate hardware devices from multiple specialized middleboxes to a unified infrastructure, directly addressing the contradiction by maintaining security functions while reducing overall system complexity
Solution Approach 2:
The network fabric infrastructure is designed to provide multiple network functions (security, load balancing, intrusion detection, data loss prevention, VPN, WAN optimization) through a single universal platform. This multi-functional approach allows the system to replace multiple specialized middleboxes with one versatile infrastructure, reducing capital investment and operational complexity while maintaining all necessary security and performance functions
2Adaptability or versatility
If multiple specialized hardware middleboxes are deployed to provide diverse network functions, then network functionality and performance are improved, but capital investment and space requirements increase
Solution Approach 1:
The patent merges multiple specialized hardware middleboxes into a single network fabric infrastructure that supports diverse network functions through service function chaining. This consolidation reduces the quantity of hardware resources from multiple separate devices to one integrated platform, directly addressing the contradiction by maintaining functional versatility while reducing hardware footprint
Solution Approach 2:
The network fabric is designed as a universal platform capable of providing multiple network functions (firewall, load balancing, IDS, DLP, VPN, WAN optimization) through a single infrastructure. This multi-functionality allows the system to replace multiple specialized hardware devices with one versatile platform, reducing space requirements and capital investment while maintaining all necessary network functionalities
3Productivity
If traditional SFC architectures are used without hardware acceleration, then implementation simplicity is maintained, but network acceleration and scalability are limited
Solution Approach 1:
The patent introduces a service function chaining infrastructure as an intermediary layer between traditional networking and hardware acceleration. This SFC architecture acts as a mediator that enables hardware-accelerated policy-based routing while maintaining compatibility with existing network functions, resolving the contradiction by providing network acceleration without requiring complete architectural overhaul
Solution Approach 2:
The patent changes the operational parameters of the network architecture by implementing hardware-accelerated policy-based routing within the service function chaining framework. This parameter change enables line-rate packet processing and enhanced scalability while keeping the overall architecture manageable through the existing SFC abstraction layer, thus improving productivity without proportionally increasing complexity
Data Source
AI summary
Technologies for creating an optimized and accelerated network pipeline using a network pipeline abstraction layer (NPAL) for policy-based routing (PBR) over Service Function Chaining (SFC) are described. A DPU includes acceleration hardware engine to provide a single accelerated data plane. A processing device can generate a first virtual bridge and a second virtual bridge, the first virtual bridge to be controlled by a first network service hosted on the DPU and having a set of one or more network rules, and the second virtual bridge having a policy-based routing policy (PBR policy). The processing device can add the virtual port between the first virtual bridge and the second virtual bridge. The acceleration hardware engine, in the single accelerated data plane, can route network traffic data using the PBR policy and process the network traffic data using the set of one or more network rules.


