SDN Appliance FPGA Offloading for Bare-Metal Server Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Custom hardware in cloud computing environments, such as bare-metal servers, often lack the capability to execute software-defined networking (SDN) policies, leading to limitations in scalability and performance, particularly when integrating with virtual machines, which can disrupt resource deployment and throughput.
Innovation Solution
Implementing an SDN appliance that separates SDN policy enforcement from the host and moves it onto a strategically placed appliance, utilizing FPGA for enhanced processing capabilities, allowing for flexible policy application and high availability, while leveraging transient state management to maintain connectivity during failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SDN policy enforcement is implemented on custom hardware (bare-metal servers), then security and networking capabilities are improved, but device complexity and scalability are worsened due to hardware limitations
Solution Approach 1:
The patent extracts the SDN policy enforcement functionality from the host system and places it on a separate network device (gateway or router). This allows custom hardware to benefit from SDN capabilities without needing to execute the full host networking stack, thereby improving security while reducing device complexity requirements.
Solution Approach 2:
The patent introduces an intermediary network device that acts as a bridge between custom hardware and the SDN controller. This intermediary handles policy enforcement and networking functions, allowing bare-metal servers to access cloud services with improved security without requiring complex hardware modifications.
2Adaptability or versatility
If the host networking stack is executed on every host, then SDN policy enforcement capability is improved, but scalability and resource utilization are worsened
Solution Approach 1:
The patent makes the network device (gateway/router) universal by enabling it to serve multiple functions: acting as a border router, SDN agent, and policy enforcement point simultaneously. This eliminates the need for every host to run the full networking stack, improving resource utilization while maintaining SDN capabilities across the network.
Solution Approach 2:
The patent extracts the networking stack execution requirement from individual hosts and consolidates it on shared network devices. This allows SDN policy enforcement capability to be maintained while significantly improving resource utilization efficiency by avoiding redundant stack executions on each host.
3Adaptability or versatility
If traffic is sent through multiple software hops for additional SDN policies, then policy flexibility is improved, but performance and throughput are worsened
Solution Approach 1:
The patent introduces a border router as an intermediary that consolidates multiple SDN policy enforcement points into a single location. Traffic requires only one software hop at the border router instead of multiple hops through various hosts, maintaining policy flexibility while improving network throughput by reducing processing latency.
4Productivity
If custom hardware is integrated into virtual networks, then hardware capability utilization is improved, but fault tolerance and availability are worsened
Solution Approach 1:
The patent introduces a border router as an intermediary between custom hardware and the virtual network. This intermediary handles fault isolation and failure scenarios, allowing custom hardware to be integrated into virtual networks with improved hardware utilization while maintaining fault tolerance through the protective layer provided by the border router.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A virtual network comprising virtual machines executing at a computing environment is implemented. A software defined networking (SDN) appliance is configured to provide a connection to computing resources via a virtual network of a virtual computing environment. The SDN appliance includes a network interface card that are operable to interact with multiple field-programmable gate array (FPGA) devices are configured to be a hardware acceleration device for processing data traffic, and the FPGA device is configured to ingress a packet to a dataflow on one port and egress the packet from a different port associated with a different dataflow.