Offloading Virtual Service Endpoint to Network Interface Card
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing trend of virtualizing network functions in data networks introduces complexity in forwarding decisions due to varying overhead requirements for different virtualized network functions, necessitating a method to efficiently steer network packets through chains of virtualized services without requiring dedicated hardware appliances.
Innovation Solution
The system offloads a portion of packet forwarding decisions from network switches to a virtual service endpoint on a network interface card, using an out-of-band tag to identify packets that need to be processed by subsequent virtual network functions, thereby freeing up processing cycles for other tasks and simplifying forwarding decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If network functions are virtualized and consolidated into network servers, then hardware costs are reduced and flexibility is improved, but processing overhead and complexity increase
Solution Approach 1:
The patent segments the virtual network function chain into multiple individual virtualized network functions, each capable of being independently instantiated and configured. This segmentation allows the system to process different packet types through different function chains, reducing the processing overhead for packets that don't require complex multi-function processing while maintaining the flexibility of virtualization.
Solution Approach 2:
The patent introduces a service function chain (SFC) mediator that manages and orchestrates the chain of virtualized network functions. This intermediary component handles the complexity of forwarding decisions and function instantiation, shielding the underlying processing complexity from the actual network traffic flow and enabling efficient packet processing.
2Adaptability or versatility
If multiple virtualized network functions are chained together to provide tailored services, then service flexibility is improved, but forwarding decision complexity increases
Solution Approach 1:
The patent implements dynamic service function chains where the sequence and composition of virtualized network functions can be adjusted based on customer workload requirements and packet characteristics. This dynamic configuration allows the system to optimize forwarding decisions by creating simplified function chains for common traffic types while maintaining complex chains for specialized services when needed.
Solution Approach 2:
The patent changes the parameters of virtual network function processing by introducing packet tagging mechanisms and flow-based routing parameters. These parameter changes enable the system to make simpler forwarding decisions by matching packet characteristics against predefined chain configurations, reducing the complexity of real-time forwarding decisions while maintaining service flexibility.
3Reliability
If deep packet inspection is performed by virtualized network functions, then security detection capability is improved, but per-packet overhead increases
Solution Approach 1:
The patent applies partial action by implementing selective deep packet inspection only for packets that require security analysis, rather than processing every packet through the same inspection chain. The service function chain architecture allows packets to be routed through inspection functions only when necessary, reducing per-packet overhead for traffic that doesn't require intensive security processing while maintaining high security detection capability for relevant traffic.
Data Source
AI summary
Technologies for offloading virtual service endpoint capabilities include a compute node and network controller. A device driver of a compute device may discover offloaded virtual service endpoint capability of a network interface card of the compute device. The device driver may advertise the offloaded virtual service endpoint capability to a network agent and virtual network functions provided by the compute device. An out-of-band tag may be associated with the offloaded virtual service endpoint to identify network packets to be processed by the offloaded virtual service endpoint. The network agent may add a flow entry to a forwarding table of a network switch of the compute device based on network flow information received from the network controller. The network agent may also associate the added flow entry with the offloaded virtual service endpoint based on the out-of-band tag and configure the offloaded virtual service endpoint based on the network flow information.


