Seamless Packet Workload Migration Between Exception Path Node Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization-based services face challenges in managing large-scale packet processing workloads across hundreds of thousands of virtual or physical machines, as ad-hoc solutions for network packet address manipulation do not scale effectively, leading to potential disruptions and performance issues in large provider networks.

Innovation Solution

A multi-layer packet processing service that migrates packet processing workloads between isolated node groups without disrupting application flows, using a fast-path and exception-path layer architecture to efficiently rewrite network packets and maintain state information, ensuring seamless transitions and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ad-hoc solutions for network packet address manipulation are used, then flexibility in packet processing is improved, but scalability to large provider networks deteriorates

Engineering Contradiction:
Improveflexibility in packet processingVSAvoidscalability to large provider networks
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments packet processing into two distinct paths: fast-path nodes for high-volume standard packet processing and exception-path node groups for specialized packet manipulation. This segmentation allows the fast-path to handle bulk traffic efficiently while exception-path nodes provide flexible ad-hoc processing only when needed, resolving the contradiction between flexibility and scalability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If packet processing workloads are migrated between isolated node groups, then system maintenance and load balancing are improved, but connection continuity may be disrupted

Engineering Contradiction:
Improvesystem maintenance and load balancingVSAvoidconnection continuity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-establishing state synchronization mechanisms and maintaining flow state information at both source and destination exception-path node groups before migration occurs. This allows seamless workload transfer without disrupting active connections, as the destination group is already prepared to handle the migrated packets immediately.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If fast-path and exception-path layer architecture is used, then packet processing efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvepacket processing efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The fast-path nodes serve as intermediaries between the network traffic and exception-path node groups. They handle the majority of packet processing efficiently and only involve exception-path nodes when specialized manipulation is required. This intermediary architecture improves overall efficiency while containing complexity by isolating it to specific components rather than distributing it throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11799950B1Seamless migration of packet processing workloads between exception path node groups
Publication Date: 2023.10.24 AMAZON TECH INC
  • US11799950B1 patent drawing
  • US11799950B1 patent drawing
  • US11799950B1 patent drawing

AI summary

A control plane server of a packet processing service assigns a first node group comprising exception-path nodes of the service to a network interface of a first application. Nodes of the assigned node group provide packet rewriting rules used by fast-path nodes of the service to direct requests of the application. In response to detecting that a workload migration criterion has been met, the control plane server initiates a migration workflow of the interface, during which flow state information of a packet flow is replicated at respective subsets of nodes of the first node group and a second node group, and connections used for the application requests remain operational. After the migration workflow completes, nodes of the second node group provide packet rewriting rules for directing requests of the application.