Offload Controller Programmable Switch Bypass Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud service provider infrastructure faces challenges in handling increased bandwidth and port density requirements for remote VPC access, leading to higher latency, decreased per connection consistency, and high management costs due to the need for extensive routing tables and expensive routers.
Innovation Solution
Implementing an offload controller and a programmable switch ASIC that bypasses the gateway by using a VPC controller and virtual route controller to configure routes directly between customer premises equipment and virtual machine hosts, reducing reliance on x86 systems and virtual routing and forwarding protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all packets in and out of the overlay network are handled at the gateway, then routing control is centralized, but network latency increases and per connection consistency decreases
Solution Approach 1:
The patent segments the routing function by dividing the routing table into multiple distributed routing tables across different network devices (gateways and edge devices). Each device maintains a portion of the routing information, allowing packets to be routed locally without always passing through the gateway. This segmentation reduces network latency while maintaining routing control through coordinated updates of the distributed routing tables.
2Adaptability or versatility
If x86 systems are used for network function virtualization, then flexibility and rapid feature deployment are improved, but management costs and power consumption increase
Solution Approach 1:
The patent replaces traditional x86-based virtualized network functions with specialized hardware accelerators or ASICs (application-specific integrated circuits) that are optimized for networking tasks. This substitution maintains the flexibility of software-defined networking while dramatically reducing power consumption and management overhead by using purpose-built hardware instead of general-purpose processors running virtualization software.
3Reliability
If VRF is deployed for each VM host to isolate tenant traffic, then tenant isolation is improved, but the number of routing tables proliferates consuming space and open connections
Solution Approach 1:
The patent implements a universal routing table structure that serves multiple tenants simultaneously through the use of tenant identification fields and conditional routing rules. Instead of creating separate VRF instances for each tenant, a single routing table infrastructure handles traffic isolation by matching packets against tenant-specific criteria (such as VLAN tags, IP prefixes, or metadata) and applying appropriate routing actions. This multi-functional approach maintains tenant isolation while avoiding the proliferation of separate routing tables.
4Productivity
If routers that handle thousands and millions of connections are deployed, then connection handling capacity is improved, but device cost increases to over $1 million each
Solution Approach 1:
The patent segments the connection handling function across multiple low-cost devices rather than relying on a single expensive high-capacity router. By distributing routing state and forwarding decisions across edge devices, gateways, and potentially overlay network nodes, the system achieves aggregate connection handling capacity comparable to expensive routers while using inexpensive commodity hardware. Each device handles a portion of the connections, and the distributed architecture provides scalability without requiring million-dollar appliances.
Data Source
AI summary
A method and system that include techniques for an offload controller that controls functionality of a programmable switch. The offload controller may handle hash management and/or hash collision resolution for the programmable switch. The offload controller may additionally or alternatively configure the programmable switch to forward packets directly to a virtual private cloud (VPC) and/or virtual machine (VM), bypassing a gateway in some instances.


