Isolated Cell Packet Processing Service for Scalable Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large provider networks face scalability issues with ad-hoc solutions for network packet transformation, leading to inefficiencies in managing traffic between hundreds of thousands of virtual or physical machines, particularly in implementing customized policy-based packet processing for virtualization-based services.
Innovation Solution
A multi-layer packet processing service utilizing isolated cells with control plane and data plane resources, where each cell comprises action implementation nodes, decision master nodes, and administration nodes, enabling customized packet processing and isolation to manage traffic efficiently across virtualized computing environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ad-hoc solutions for packet transformation are used, then customized packet processing can be implemented, but scalability deteriorates in large provider networks with hundreds of thousands of virtual or physical machines
Solution Approach 1:
The system segments packet processing into isolated cells, each handling specific traffic workloads. This segmentation enables customized packet processing for different applications while maintaining scalability by allowing cells to be independently scaled or replaced without affecting the entire network infrastructure.
Solution Approach 2:
The patent employs copying by instantiating multiple identical or similar cells that can be replicated across the network. These cells can be copied and distributed to handle different traffic streams, enabling scalable customized processing without requiring unique complex infrastructure for each application.
2Productivity
If resources are shared among multiple customers, then hardware utilization increases, but security and isolation between customers deteriorates
Solution Approach 1:
The system divides the shared hardware resources into logically isolated cells, each dedicated to specific customers or applications. This segmentation allows multiple customers to share physical hardware while maintaining strict logical isolation and security boundaries between them.
Solution Approach 2:
The patent implements nested virtualization where virtual machines are hosted within isolated cells that run on shared physical hardware. This nesting structure enables multiple layers of isolation and virtualization, allowing secure multi-tenancy while maximizing hardware utilization through efficient resource sharing.
3Productivity
If more virtual machines are instantiated on the same host, then hardware utilization increases, but system complexity and failure impact deteriorates
Solution Approach 1:
The system segments the host into isolated cells that encapsulate virtual machine workloads. This segmentation simplifies system management by creating clear boundaries between different virtual machine instances, making it easier to monitor, maintain, and isolate failures even as the number of virtual machines increases.
4Adaptability or versatility
If customized policy-based packet processing is implemented for specific traffic, then application requirements are met, but processing overhead and CPU efficiency deteriorates
Solution Approach 1:
The system performs preliminary actions by pre-configuring cells with customized packet processing policies and forwarding information bases before traffic needs to be processed. This allows traffic to be handled efficiently using pre-established rules rather than requiring complex real-time decision-making, improving CPU efficiency while maintaining customized processing capabilities.
Data Source
AI summary
An isolated packet processing cell of a packet processing service, comprising an action implementation node and a decision master node, is assigned to an application. An indication of processing rules of the application is transmitted to the decision master node. In response to receiving a particular packet, the action implementation node obtains a representation of an action (which is based on the processing rules) from the decision master node and executes the action.


