Quadrant NFV Platform Packet Processing Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network function virtualization (NFV) systems fail to concurrently satisfy requirements such as stateful network function support, third-party compatibility, service level objective (SLO) adherence, and failure resilience, leading to operational complexities and inefficiencies, particularly due to differences between cloud computing and NFV architectures.

Innovation Solution

The Quadrant NFV platform leverages cloud computing infrastructure, extending the Function as a Service (FaaS) model to support packet processing and remote state access, achieving isolation through NIC virtualization and cooperative scheduling, and using Kubernetes for dynamic scaling, thereby enabling efficient execution of network function chains that meet SLO targets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network functions are virtualized to replace hardware middleboxes, then ease of management and scalability improve, but performance and isolation deteriorate

Engineering Contradiction:
Improveease of managementVSAvoidperformance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces traditional hardware middleboxes with software-based network functions running on commodity cloud infrastructure. Network functions are implemented as containerized applications that can be deployed, managed, and scaled using standard cloud orchestration tools, eliminating the need for specialized hardware while maintaining or improving performance through virtualization techniques.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal network function execution platform that can host multiple different network functions (firewall, load balancer, IDS/IPS, etc.) on the same infrastructure. This multi-functional approach allows operators to manage diverse network services through a single standardized interface while leveraging shared resources for improved efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple network functions are chained together to achieve operator objectives, then functionality improves, but latency and throughput performance deteriorate

Engineering Contradiction:
ImprovefunctionalityVSAvoidthroughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges multiple network functions into unified service chains where functions are orchestrated to process packets in sequence with minimal handoff overhead. By combining related network functions into integrated service chains and using shared data planes, the system reduces the performance penalty typically associated with function chaining while maintaining full functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent ensures continuous packet processing through network function chains by implementing efficient inter-function communication mechanisms. Packets flow continuously through the chain with minimal buffering or context switching, maintaining high throughput even as multiple functions are composed together to achieve complex operator objectives.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If network functions are isolated to ensure security between untrusted third-party functions, then security improves, but device complexity and operational overhead increase

Engineering Contradiction:
ImproveisolationVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtualization layer with virtual network functions and virtual switching fabric that acts as an intermediary between untrusted third-party network functions. This intermediary layer provides automatic isolation and security boundaries without requiring complex manual configuration, managing security policies centrally while allowing functions to operate independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If cloud computing infrastructure is used to achieve scalability and ease of management, then operational efficiency improves, but NFV-specific requirements such as packet processing performance and isolation are not met

Engineering Contradiction:
Improveoperational efficiencyVSAvoidisolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different quality levels to different parts of the cloud infrastructure: using standardized cloud abstractions for management and orchestration layers while implementing NFV-optimized data planes with dedicated packet processing paths. This allows the system to leverage cloud efficiency for operations while maintaining high-performance isolated packet processing where it matters most.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20230198907A1Methods and systems for efficient and secure network function execution
Publication Date: 2023.06.22 UNIV OF SOUTHERN CALIFORNIA
  • US20230198907A1 patent drawing
  • US20230198907A1 patent drawing
  • US20230198907A1 patent drawing

AI summary

A network function virtualization platform for providing network functions for traffic flow of a network is disclosed. The platform may be added to a Function as a Service (FaaS) network infrastructure. A worker node includes a core executing network functions, a scheduler, and an agent. A first network function includes code for executing the network function and a runtime. An ingress module receives network traffic flow and separates packets for performance of the first network function. A controller is coupled to the ingress module and the agent. The controller controls the ingress module to route the separated packets to the worker node. The scheduler schedules execution of the first network function on the packets. The agent assigns execution of the first network function to the core of the worker node.