InfiniBand Fabric Data Services for Transparent Firewall Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The performance and administrative bottlenecks associated with traditional networks and storage in large cloud computing architectures, particularly in middleware machine environments, are significant, as they hinder efficient data service delivery and security.
Innovation Solution
A system and method that provide a data service component in a network environment using a native packet forwarding mechanism, allowing for transparent software firewall or traffic routing services within the InfiniBand fabric, with support for high availability and scalability through intermediate nodes and host channel adaptors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional network and storage architectures are used in large cloud computing environments, then system compatibility and ease of deployment are maintained, but performance bottlenecks and administrative overhead increase significantly
Solution Approach 1:
The patent introduces an intermediate network layer (InfiniBand fabric) that acts as a mediator between traditional network/storage systems and application workloads. This intermediate layer provides high-performance data services while maintaining compatibility with existing systems, thus improving productivity without proportionally increasing complexity.
Solution Approach 2:
The system segments network functions into distinct components: traditional network interfaces for compatibility, InfiniBand fabric for high-performance data services, and separate management planes. This segmentation allows each component to be optimized independently, improving overall performance while managing complexity through modular architecture.
2Reliability
If software firewall services are implemented in traditional network environments, then security functionality is provided, but administrative overhead and processing delays increase
Solution Approach 1:
The patent replaces traditional software-based firewall processing with hardware-accelerated filtering capabilities in the InfiniBand Host Channel Adaptors (HCAs). This substitution moves security functions from the software layer to the hardware layer, maintaining security reliability while dramatically reducing packet processing time through parallel hardware operations.
Solution Approach 2:
The HCA implements self-service security filtering by performing packet inspection and filtering operations autonomously at the network interface level, without requiring centralized software firewall processing for every packet. This reduces administrative overhead and processing delays while maintaining security policies.
3Ease of operation
If data services are provided through intermediate nodes in InfiniBand fabric, then service transparency and network integrity are maintained, but addressing complexity and routing overhead increase
Solution Approach 1:
The patent implements address translation copying mechanisms where global addresses are translated to local addresses through cached mappings in HCAs. This copying approach maintains service transparency by presenting a simplified address space to applications while handling complex routing translations in the background through pre-computed address mappings.
Solution Approach 2:
The system performs preliminary address resolution by pre-computing and caching global-to-local address translations in HCA memory before data transmission occurs. This preliminary action eliminates the need for real-time address translation during data flow, maintaining transparency while reducing routing overhead during actual operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method can provide a data service in a network environment. The system can provide a data service component on a node in the network environment, wherein the network environment includes a plurality of nodes interconnected via a network fabric. Furthermore, the system can use a native packet forwarding mechanism to direct a data flow in the network fabric to said data service component on the node. Then, the system can use said data service component to process one or more data packets in the data flow in the network fabric.