Netflow Offload to Network Silicon for High-Speed Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Netflow technologies are limited in collecting fine-grained network traffic data, especially in environments with non-Cisco network switches, leading to performance degradation due to the need for software-based packet inspection in high-speed networks, and inability to monitor individual NIC ports or VM-to-VM traffic effectively.

Innovation Solution

Offloading Netflow data collection and export functions to network silicon, such as chipset, SoC, or NIC levels, enabling detailed flow data collection and export at the Physical Function (PF) and Virtual Function (VF) layers, allowing for monitoring of individual queues and VM-to-VM traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If software-based packet inspection is used to collect Netflow data, then Netflow data can be collected, but system performance degrades significantly in high-speed networks

Engineering Contradiction:
ImproveNetflow data collection capabilityVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts the Netflow data collection function from the software layer and implements it in hardware (network silicon/chipset). This separation allows the software to focus on higher-level processing while the hardware handles packet inspection, resolving the performance degradation issue.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary hardware component (network silicon with embedded Netflow collection agent) that sits between the physical network interface and the software processing layer. This intermediary performs packet inspection in hardware, preventing software performance degradation while maintaining Netflow collection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If Netflow data is collected at aggregated platform level, then network traffic monitoring is simplified, but fine-grained traffic data on individual ports and VMs cannot be captured

Engineering Contradiction:
Improvemonitoring complexityVSAvoidtraffic data granularity
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the monitoring capability by enabling Netflow collection at multiple hierarchical levels: platform level, individual NIC port level, and even virtual function level. This segmentation allows simultaneous aggregation for simplicity and detail for granular analysis where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of monitoring granularity by collecting Netflow data not just at the platform level but also at individual virtual function and port levels. This multi-dimensional approach enables both aggregated and fine-grained views of network traffic.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If only Cisco network switches are used for Netflow, then Netflow data collection is enabled, but compatibility with non-Cisco network equipment is lost

Engineering Contradiction:
ImproveNetflow data collectionVSAvoidnetwork equipment compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements Netflow collection capability in the network silicon/chipset itself, making it independent of the network switch vendor. This universal implementation allows Netflow data collection on any network equipment regardless of manufacturer, eliminating Cisco-specific limitations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If Netflow collection is performed in software, then implementation flexibility is maintained, but processing overhead increases significantly

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidprocessing overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces the software-based Netflow collection mechanism with a hardware-based implementation in network silicon. This substitution eliminates the processing overhead and CPU cycles required for software packet inspection while maintaining implementation flexibility through configurable hardware rules.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10063446B2Netflow collection and export offload using network silicon
Publication Date: 2018.08.28 INTEL CORP
  • US10063446B2 patent drawing
  • US10063446B2 patent drawing
  • US10063446B2 patent drawing

AI summary

Methods and apparatus for collection of Netflow data and export offload using network silicon. In accordance with aspects of the embodiments, the Netflow export and collection functions are offloaded to the network silicon in the chipset, System on a Chip (SoC), backplane switch, disaggregated switch, virtual switch (vSwitch) accelerator, and Network Interface Card/Controller (NIC) level. For apparatus implementing virtualized environments, one or both of the collection and export functions are implemented at the Physical Function (PF) and/or Virtual Function (VF) layers of the apparatus.