Secure Metadata Sharing Among VNFs via RDMA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud native microservice infrastructure, there is no mechanism for secure metadata sharing across different hosts and tenants in a network, limiting the ability of virtualized network functions (VNFs) to improve performance by sharing metadata.

Innovation Solution

A distributed forwarding and metadata sharing (DFMS) framework using remote direct memory access (RDMA) enables secure metadata sharing among VNFs located on different hosts within a cluster, with a DFMS controller registering VNFs into groups and assigning access rights, allowing RDMA requests for metadata access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VNFs are distributed across different hosts and tenants in cloud native infrastructure, then system scalability and security are improved, but metadata sharing capability deteriorates due to lack of secure sharing mechanism

Engineering Contradiction:
Improvesystem scalabilityVSAvoidmetadata sharing capability
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a metadata server as an intermediary component that mediates metadata sharing between VNFs on different hosts. The metadata server stores metadata centrally and provides controlled access to authorized VNFs through standardized interfaces, enabling secure metadata sharing across distributed multi-tenant environments without requiring direct peer-to-peer access between VNFs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional metadata sharing approaches are used without RDMA, then system complexity is reduced, but metadata access speed and efficiency deteriorate

Engineering Contradiction:
Improvemetadata access speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces traditional network-based metadata access mechanisms with Remote Direct Memory Access (RDMA) technology. RDMA enables direct memory-to-memory data transfer between hosts bypassing the operating system and network stack, achieving high-speed metadata access with low latency. The system manages this complexity through standardized RDMA interfaces and a metadata server that abstracts the underlying hardware complexity from VNFs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12058136B2Secured metadata sharing among VNFs
Publication Date: 2024.08.06 HUAWEI TECH CO LTD
  • US12058136B2 patent drawing
  • US12058136B2 patent drawing
  • US12058136B2 patent drawing

AI summary

A system and method for securely sharing metadata among virtualized network functions (VNFs) disposed within a cluster of host computers includes a distributed forwarding and metadata sharing (DFMS) framework that forwards received data packets and provides remote direct memory access (RDMA) enabled sharing of secured metadata among the VNFs from more than one host computer in the cluster of host computers, and a DFMS controller that resides in the cluster of host computers as a VNF and registers VNFs in the cluster to at least one group of VNFs in the cluster and assigns access rights to the metadata of VNFs within respective groups of VNFs in the cluster. In operation, each registered VNF in a group in the cluster uses RDMA requests to access the metadata for other registered VNFs in the group in the cluster to which the each registered VNF in the group has access rights.