Hardware Packet Flow Processing Offload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud architectures face limitations in processing data flows due to the need for software-based identification and processing of initial data flows, porting information, and policies, which leads to increased latency and reduced network throughput.

Innovation Solution

Hardware-based network devices are enabled to perform the initial identification of data flows, maintain cache states, apply applicable policies, and process subsequent packets without invoking software-based processing, using standardized formats and programming interfaces to offload processing to hardware elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based processing is used for initial data flow identification and policy application, then processing flexibility and policy management are improved, but network throughput and connection processing speed deteriorate

Engineering Contradiction:
Improveprocessing flexibilityVSAvoidnetwork throughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments packet processing into two distinct paths: a control plane that handles initial data flow identification and policy determination using software, and a data plane that processes subsequent packets using hardware-based flow tables. This segmentation allows flexible policy management in software while achieving high-speed processing in hardware, resolving the contradiction between adaptability and productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control plane performs preliminary actions by identifying data flows and determining applicable policies before packets enter the high-speed processing path. Flow table entries are pre-configured with policy information, enabling subsequent packets to be processed rapidly without repeated software intervention. This preliminary action preserves processing flexibility while achieving high throughput.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If hardware-based processing is used for packet processing, then network throughput and processing speed are improved, but ability to handle initial data flow identification and policy updates deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidpolicy management capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces flow tables as an intermediary data structure that bridges software-based control plane and hardware-based data plane. The control plane populates flow tables with policy information, and the data plane uses these tables for high-speed packet processing. This intermediary enables policy updates in software to be efficiently transferred to hardware, maintaining adaptability while achieving high processing speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Once flow table entries are created, the hardware-based data plane autonomously processes subsequent packets using these pre-configured entries without requiring continuous software intervention. The system serves itself by maintaining flow state information in hardware, enabling high-speed processing while the control plane retains the ability to update policies when needed.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If CPU resources are used for packet processing, then policy application accuracy is improved, but latency and resource availability for cloud services worsen

Engineering Contradiction:
Improvepolicy application accuracyVSAvoidnetwork latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of software-based packet processing with a hardware-based processing system using specialized network interface cards and field-programmable gate arrays. This substitution maintains policy application accuracy through precise hardware implementation while dramatically reducing processing latency and freeing CPU resources for cloud services, directly resolving the contradiction between precision and time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If more CPU cores are allocated to packet processing, then connection processing capacity is improved, but resources available for cloud services deteriorate

Engineering Contradiction:
Improveconnection processing capacityVSAvoidCPU resource availability
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts packet processing functionality from the general-purpose CPU and relocates it to specialized hardware components including network interface cards and FPGAs. This extraction enables high connection processing capacity in hardware while preserving CPU cores for cloud service execution, directly resolving the resource allocation contradiction between networking and computing workloads.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11799785B2Hardware-based packet flow processing
Publication Date: 2023.10.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11799785B2 patent drawing
  • US11799785B2 patent drawing
  • US11799785B2 patent drawing

AI summary

Techniques are disclosed for processing data packets by a hardware-based networking device configured to disaggregate processing of data packets from hosts of a virtualized computing environment. The hardware-based networking device includes a hardware-based component implementing a plurality of behavioral models indicative of packet processing graphs for data flows in the virtualized computing environment. A data packet having a source from or destination to an endpoint in a virtual network of the virtualized computing environment is received. Based on determining that the data packet is a first packet of a data flow to or from the endpoint, one of the behavioral models is mapped to the data flow. The packet is modified in accordance with the mapped behavioral model. A state of the data flow is stored. Subsequent data packets of the data flow are processed based on the stored state.