SDN Appliance Disaggregates Policy Enforcement for Custom Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Custom computing or storage assets in cloud environments often lack the capability to apply security policies, disrupting resource deployment and limiting scalability due to hardware restrictions, especially when using bare-metal servers or non-VM workloads, which can impact performance and hinder migration of high-throughput workloads to the cloud.
Innovation Solution
Implementing an SDN appliance that disaggregates policy processing from the host, using an FPGA to move SDN policy enforcement off the host and provide high availability and fault tolerance, allowing for flexible SDN policy application and scalable networking, enabling seamless integration of custom hardware into cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are implemented on a customer's virtual network, then security is improved, but management plane connectivity to injected compute instances is disrupted
Solution Approach 1:
The patent segments network connectivity into two separate planes: a management plane for controlling injected compute instances and a data plane for customer traffic. This segmentation allows security policies to be applied to the data plane while preserving management plane connectivity, resolving the contradiction between security and operational access.
Solution Approach 2:
The patent introduces a dedicated data plane as an intermediary component that sits between the customer's virtual network and the injected compute instances. This intermediary enables security policies to be enforced on customer traffic while allowing the management plane to maintain direct connectivity to instances for provisioning and control operations.
2Adaptability or versatility
If SDN policy stack is loaded on a network device, then SDN policy application capability is improved, but hardware restrictions and limitations prevent implementation
Solution Approach 1:
The patent introduces an SDN appliance as an intermediary device that runs the full SDN policy stack. This appliance acts as a mediator between the network devices and the control plane, enabling sophisticated SDN policy application without requiring modifications to hardware-restricted network devices or switches.
Solution Approach 2:
The SDN appliance provides universal SDN policy application capability that can work with various network device types and hardware configurations. By centralizing the SDN stack in a universal appliance rather than requiring it on every network device, the system achieves policy versatility without being constrained by individual hardware limitations.
3Reliability
If traffic is sent through several software hops for additional SDN policies, then policy enforcement is improved, but networking service performance drops
Solution Approach 1:
The patent extracts SDN policy enforcement from the host system and moves it to a dedicated SDN appliance. This extraction eliminates the performance penalty of multiple software hops on the host by consolidating policy processing in a specialized appliance, thereby maintaining policy enforcement while improving networking service performance.
Solution Approach 2:
The patent implements a virtual network interface card (vNIC) that copies network traffic to the SDN appliance for policy processing. This copying mechanism allows the main network path to continue efficiently while a copy of the traffic is processed for policy enforcement, minimizing performance impact on the primary networking services.
4Power
If custom hardware is integrated into cloud environments, then hardware capability and performance are improved, but capability to apply policies is lost
Solution Approach 1:
The patent introduces an SDN appliance as an intermediary that bridges custom hardware and the policy management system. The appliance receives traffic from custom hardware endpoints and applies SDN policies, thereby enabling policy application capability on custom hardware that lacks native policy enforcement capabilities while preserving the hardware's performance advantages.
Data Source
AI summary
A virtual network comprising virtual machines executing at a computing environment is implemented. A flexibly extensible NIC (eNIC) is executed at a software defined networking (SDN) appliance. A data packet is received that is addressed to a host that is connected to the virtual network. Based on a layer 2 address and a network identifier, the virtual switch identifies the host represented by the eNIC that is associated with the data packet. A policy associated with the host is determined and applied to the data packet. The policy is dynamically adjustable based on the host.


