Layer 2 NPU Offloading Layer 3 Traffic Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network devices lack the capability to offload communication sessions from virtual or physical layer 3 devices to NPUs, leading to performance and operational limitations in maintaining traffic throughput.

Innovation Solution

A layer 2 network device with multiple NPUs is configured to receive session information from layer 3 devices, assign sessions to these NPUs, and process packets associated with those sessions, thereby enabling layer 3 offloading functionality for lower performance devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If layer 3 devices process all packets themselves, then routing and traffic control functionality is maintained, but device performance and throughput are reduced due to processing overload

Engineering Contradiction:
Improvetraffic throughputVSAvoidprocessing load
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the packet processing function from the layer 3 device and relocates it to a separate layer 2 network device with NPU. The layer 3 device retains only session management and routing decisions, while the NPU handles actual packet forwarding, thereby reducing the processing load on the layer 3 device and improving overall throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a layer 2 network device with NPU as an intermediary between the layer 3 device and the network traffic. This intermediary handles the computationally intensive packet processing tasks, allowing the layer 3 device to maintain complex routing logic without being bottlenecked by processing speed requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If NPUs are integrated only within physical layer 3 devices, then offloading capability is provided, but virtual firewalls and other layer 3 devices cannot utilize offloading functionality

Engineering Contradiction:
Improveoffloading capabilityVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the layer 2 network device with NPU a universal offloading resource that can serve multiple different layer 3 devices including physical firewalls, virtual firewalls, and routers. Instead of embedding NPUs in each layer 3 device, the system creates a shared NPU resource that can be dynamically allocated to different layer 3 devices based on their offloading needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If layer 3 devices handle all communication sessions, then routing control is maintained, but operational performance and traffic handling speed are limited

Engineering Contradiction:
Improvepacket processing speedVSAvoidtraffic throughput
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The patent replaces the general-purpose CPU-based processing in layer 3 devices with specialized NPU hardware in layer 2 devices. The NPU is specifically designed for high-speed packet processing and can handle multiple sessions in parallel, providing both faster packet processing speed and higher overall productivity compared to traditional CPU-based approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10148576B2Network processing unit (NPU) integrated layer 2 network device for layer 3 offloading
Publication Date: 2018.12.04 FORTINET INC
  • US10148576B2 patent drawing
  • US10148576B2 patent drawing
  • US10148576B2 patent drawing

AI summary

Systems and methods for facilitating offloading of communication sessions from layer 3 network devices are provided. According to one embodiment, session information pertaining to a session capable of being offloaded is received from a layer 3 network device by a layer 2 network device that includes multiple network processing units (NPUs). The session is assigned to one of the NPUs. Subsequently, responsive to receiving, by the layer 2 network device, a packet associated with the session, the packet is processed by the assigned NPU and forwarded on behalf of the layer 3 network device to a destination specified by the processed packet.