Network Function Accelerator Isolation via Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in efficiently managing and optimizing the resources and workload distribution for radio-based applications in 5G networks, particularly in reducing computational and power consumption while maintaining low latency and scalability.
Innovation Solution
The implementation of virtualization servers equipped with offloading cards that include network function accelerators (NFAs) and virtualization management components, which offload certain tasks from primary processors, enabling faster execution of network functions and simplifying network slicing through virtualized representations of NFAs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network functions are executed on primary processors, then processing capability is sufficient, but computational consumption and latency increase
Solution Approach 1:
The system segments network function execution by introducing separate network function accelerator (NFA) units that handle specific network functions independently from the primary processor. This segmentation allows the primary processor to focus on core control plane functions while NFAs handle data plane network functions, reducing overall computational consumption and improving execution speed for network-specific tasks.
Solution Approach 2:
The patent introduces an intermediary NFA component that acts as a mediator between the primary processor and network traffic. The NFA receives network function requests from the primary processor and executes them in hardware, serving as an intermediate processing layer that reduces the computational burden on the primary processor while maintaining fast network function execution.
2Adaptability or versatility
If more virtualization components are added to manage NFAs, then resource sharing and workload distribution improve, but device complexity increases
Solution Approach 1:
The virtualization manager is designed as a universal component that handles multiple functions including NFA provisioning, configuration, monitoring, and workload distribution through a single integrated interface. This multi-functional approach allows diverse resource sharing and workload management tasks to be performed through one standardized management layer, improving adaptability without proportionally increasing complexity.
Solution Approach 2:
The system creates virtualized representations (copies) of NFA resources that can be managed and allocated independently from the physical hardware. These virtual copies allow multiple virtual network functions to share physical NFA resources through virtualization, enabling flexible resource sharing while the virtualization manager handles the complexity of mapping virtual requests to physical resources.
3Quantity of substance
If NFAs are virtualized and shared across multiple tenants, then resource utilization improves, but isolation and security configuration become more difficult
Solution Approach 1:
The system applies local quality by providing tenant-specific isolation configurations and security policies tailored to each individual tenant's requirements. The virtualization manager maintains separate configuration contexts for different tenants, allowing each to have customized isolation levels and security settings while sharing the same physical NFA resources, thus enabling fine-grained control over multi-tenant environments.
Solution Approach 2:
The virtualization manager serves as an intermediary layer that handles isolation and security configuration between multiple tenants and the shared NFA resources. It translates high-level tenant isolation requirements into low-level hardware configuration settings, automatically managing the complexity of multi-tenant isolation while allowing tenants to simply specify their security and isolation needs through standardized interfaces.
Data Source
AI summary
A first security rule set for traffic of a compute instance run at a virtualization server is stored in response to a programmatic request. A second security rule set for traffic of a network function accelerator of the virtualization server is stored in response to another programmatic request. Prior to delivery of network messages to the compute instance or from the accelerator, compliance with the applicable security rule set is verified.


