L2 Concentrator Appliance CPU Flow Affinity for IPsec Throughput
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hybrid cloud computing systems face challenges in maintaining high throughput and accessibility for virtual machines (VMs) across stretched networks, particularly due to overhead from network stretching and encryption, which can lead to performance issues like latency and bottlenecks in processing network traffic.
Innovation Solution
The implementation of CPU flow affinity by pinning multiple IPsec tunnels to respective CPUs or cores, and using an L2 concentrator appliance to distribute packets across receive queues based on hash values, allowing parallel processing and increasing throughput in stretched networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network stretching and encryption are implemented for secure VM communication across hybrid cloud environments, then security and accessibility are improved, but throughput and processing speed deteriorate due to overhead
Solution Approach 1:
The system segments network traffic into multiple receive queues (e.g., 8 queues) and processes them in parallel across multiple CPU cores. Each queue handles a portion of the encrypted traffic, allowing simultaneous processing that overcomes the throughput limitations imposed by encryption overhead while maintaining security.
Solution Approach 2:
The patent transitions from single-threaded sequential processing to multi-dimensional parallel processing by distributing traffic across multiple CPU cores and queues. This dimensional expansion from 1D to 2D/3D processing space enables the system to handle encrypted traffic at higher speeds without compromising security.
2Productivity
If multiple IPsec tunnels are established for parallel processing, then throughput is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple IPsec tunnels into a unified L2 extension network architecture. Instead of managing separate complex tunnel configurations, the system combines them under a single L2 bridging framework that automatically distributes traffic across queues and cores, reducing operational complexity while maintaining the throughput benefits of parallel tunnels.
Solution Approach 2:
The L2 concentrator appliance is designed with multi-functionality, serving as both an L2 bridge and an IPsec tunnel endpoint. This universal design consolidates multiple functions into a single device, reducing the number of separate components needed and simplifying the overall system architecture while enabling parallel tunnel processing.
Data Source
AI summary
Techniques leveraging CPU flow affinity to increase throughput of a layer 2 (L2) extension network are disclosed. In one embodiment, an L2 concentrator appliance, which bridges a local area network (LAN) and a wide area network (WAN) in a stretched network, is configured such that multiple Internet Protocol Security (IPsec) tunnels are pinned to respective CPUs or cores, which each process traffic flows for one of the IPsec tunnels. Such parallelism can increase the throughput of the stretched network. Further, an L2 concentrator appliance that receives FOU packets is configured to distribute the received FOU packets across receive queues based a deeper inspection of inner headers of such packets.


