Hardware Policy Engine Circuitry for Cloud Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional policy enforcement mechanisms in distributed computing systems face challenges such as excessive CPU overhead, inconsistent performance, difficulty in scaling, lack of real-time quality of service adjustments, and inadequate integration of security processes, leading to inefficiencies and increased complexity.

Innovation Solution

The implementation of a policy engine circuitry with application programming interfaces (APIs) and protected compute entities that enforce platform resource management policies, allowing for isolated computing environments and efficient resource allocation, while integrating security at the hardware level to reduce CPU overhead and enhance scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software processes (e.g., vSwitch) are used to control virtual machine interactions with infrastructure components, then policy enforcement capability is provided, but CPU overhead increases excessively and performance becomes inconsistent

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidCPU overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based policy enforcement mechanisms (vSwitch processes) with hardware-based enforcement in the virtualization layer. This substitution moves policy enforcement from the software domain to the hardware domain, eliminating the CPU overhead associated with software processing while maintaining enforcement capability. The hardware enforcement point intercepts and enforces policies directly at the virtualization layer without requiring software intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent extracts policy enforcement functionality from the software layer (vSwitch) and places it in the hardware layer (virtualization layer). This extraction separates the enforcement function from the software processes that were previously handling it, allowing the software to focus on other tasks while hardware handles enforcement, thereby reducing overall CPU overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional software mechanisms are used for policy enforcement, then basic control is achieved, but scalability becomes difficult as system size increases

Engineering Contradiction:
Improvepolicy controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

By replacing software-based control mechanisms with hardware-based enforcement in the virtualization layer, the system achieves scalability that software alone cannot provide. The hardware enforcement point processes policies at line rate without being constrained by software processing capabilities, allowing the system to scale to larger numbers of virtual machines and higher traffic volumes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the policy enforcement function from the software control plane and places it in the hardware data plane. This segmentation allows independent scaling of enforcement capabilities without being tied to software architecture constraints, enabling the system to handle larger scales more efficiently.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If software processes are used for policy enforcement, then flexibility in control is maintained, but processing latency increases significantly

Engineering Contradiction:
Improvecontrol flexibilityVSAvoidprocessing latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent substitutes software-based policy enforcement with hardware-based enforcement in the virtualization layer. This substitution dramatically reduces processing latency because hardware can enforce policies at line rate without the overhead of software context switching, interpretation, and execution that plagues software-based approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If low level programming is used to program node behaviors for policy compliance, then policy implementation is achieved, but system complexity increases significantly

Engineering Contradiction:
Improvepolicy implementationVSAvoidprogramming complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex policy enforcement logic from the software layer and places it in the hardware layer. This extraction removes the burden of complex programming from the software domain, as hardware enforcement points handle policy compliance automatically through dedicated logic, simplifying the overall system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware enforcement point in the virtualization layer performs policy enforcement autonomously without requiring complex software programming. The hardware structure itself embodies the enforcement logic, making the system self-sufficient for policy compliance and reducing the need for sophisticated software control mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9282119B2Policy enforcement in computing environment
Publication Date: 2016.03.08 INTEL CORP
  • US9282119B2 patent drawing
  • US9282119B2 patent drawing
  • US9282119B2 patent drawing

AI summary

An embodiment may include policy engine circuitry that may enforce, at least in part, one or more platform resource management policies in a cloud computing environment. The one or more policies may be based, at least in part, upon service arrangements of the cloud computing environment. The one or more policies may establish respective isolated computing environments in the cloud computing environment that may be used by respective users. The enforcement of the one or more policies may result in the respective isolated computing environments being virtually isolated from each other and prevented from interfering with each other in derogation of the one or more policies. The one or more policies may be established, at least in part, via interaction of at least one management process with one or more application program interfaces of the circuitry. Many modifications are possible.