Infiniband Port Community Separation Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Infiniband networks face challenges in effectively managing community separation, leading to data insecurities and underutilization of network capabilities due to inadequate partitioning mechanisms.
Innovation Solution
An Infiniband device with an input port that includes a packet interrogator for extracting group membership identifiers and a membership confirmation unit using a content-addressable memory with programmable bit masks to manage multiple partitions within the network, enabling efficient community separation enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional Infiniband networks use traditional switching or routing components to manage partitions, then community separation can be enforced, but the cost and complexity of the system increases significantly
Solution Approach 1:
The patent extracts the community separation enforcement function from complex switching/routing components and implements it directly at the Infiniband port level using simple hardware logic. The port-level partition key table and matching circuitry eliminate the need for expensive middle-layer switching components while maintaining secure data isolation between communities.
Solution Approach 2:
The Infiniband port automatically enforces community separation by locally comparing incoming packet partition keys against its own partition key table. This self-service mechanism at each port eliminates the need for centralized switching/routing control, reducing overall system complexity while maintaining reliable data isolation.
2Adaptability or versatility
If the number of partitions is increased to manage more communities, then network capability utilization improves, but the cost of switching or routing components increases
Solution Approach 1:
The patent segments the partition key table into multiple entries that can be stored in standard memory at each port, rather than requiring a monolithic switching/routing component. This segmentation allows the system to manage thousands of partitions by distributing the partition key tables across many ports, each with its own small memory structure, eliminating the need for expensive centralized switching components.
Solution Approach 2:
The patent moves from a centralized dimension of partition management (requiring expensive switching/routing components) to a distributed dimension where each port maintains its own partition key table. This dimensional shift from centralization to distribution allows scalability to thousands of partitions without proportionally increasing component cost.
3Reliability
If traditional community separation mechanisms are used, then data isolation is achieved, but network capabilities are underutilized
Solution Approach 1:
The patent implements a universal port-level enforcement mechanism that handles multiple functions: data isolation between communities, high-speed packet filtering, and scalable partition management. This multi-functional approach at the Infiniband port level eliminates the need for separate specialized components, thereby utilizing network capabilities more effectively while maintaining secure data isolation.
Data Source
AI summary
Embodiments of the present invention provide an Infiniband device having an input port for receiving a data packet. The input port is operable to extract a partition membership identifier from the packet; and to compare the extracted partition membership identifier to a partition membership table of the port to determine whether the packet breaches a partition group membership requirement. In some embodiments, the partition membership table is implemented as a content addressable memory storing a plurality of programmable bit masks.


