L2 Concentrator Appliance CPU Flow Affinity for IPsec Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hybrid cloud computing systems face challenges in maintaining high throughput and accessibility for virtual machines (VMs) across stretched networks, particularly due to overhead from network stretching and encryption, which can lead to performance issues like latency and bottlenecks in processing network traffic.

Innovation Solution

The implementation of CPU flow affinity by pinning multiple IPsec tunnels to respective CPUs or cores, and using an L2 concentrator appliance to distribute packets across receive queues based on hash values, allowing parallel processing and increasing throughput in stretched networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network stretching and encryption are implemented for secure VM communication across hybrid cloud environments, then security and accessibility are improved, but throughput and processing speed deteriorate due to overhead

Engineering Contradiction:
ImprovesecurityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments network traffic into multiple receive queues (e.g., 8 queues) and processes them in parallel across multiple CPU cores. Each queue handles a portion of the encrypted traffic, allowing simultaneous processing that overcomes the throughput limitations imposed by encryption overhead while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from single-threaded sequential processing to multi-dimensional parallel processing by distributing traffic across multiple CPU cores and queues. This dimensional expansion from 1D to 2D/3D processing space enables the system to handle encrypted traffic at higher speeds without compromising security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If multiple IPsec tunnels are established for parallel processing, then throughput is improved, but device complexity increases

Engineering Contradiction:
ImprovethroughputVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple IPsec tunnels into a unified L2 extension network architecture. Instead of managing separate complex tunnel configurations, the system combines them under a single L2 bridging framework that automatically distributes traffic across queues and cores, reducing operational complexity while maintaining the throughput benefits of parallel tunnels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The L2 concentrator appliance is designed with multi-functionality, serving as both an L2 bridge and an IPsec tunnel endpoint. This universal design consolidates multiple functions into a single device, reducing the number of separate components needed and simplifying the overall system architecture while enabling parallel tunnel processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11012507B2High throughput layer 2 extension leveraging CPU flow affinity
Publication Date: 2021.05.18 VMWARE INC
  • US11012507B2 patent drawing
  • US11012507B2 patent drawing
  • US11012507B2 patent drawing

AI summary

Techniques leveraging CPU flow affinity to increase throughput of a layer 2 (L2) extension network are disclosed. In one embodiment, an L2 concentrator appliance, which bridges a local area network (LAN) and a wide area network (WAN) in a stretched network, is configured such that multiple Internet Protocol Security (IPsec) tunnels are pinned to respective CPUs or cores, which each process traffic flows for one of the IPsec tunnels. Such parallelism can increase the throughput of the stretched network. Further, an L2 concentrator appliance that receives FOU packets is configured to distribute the received FOU packets across receive queues based a deeper inspection of inner headers of such packets.