SmartNIC Firewall Policy Processor for Microservices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring tools are not fully integrated with the rest of the infrastructure, leading to under-utilization of network capabilities and increased costs due to the need for separate tools for network and application monitoring.

Innovation Solution

A closed-loop framework using SmartNICs (Data Processing Units) to perform application-aware network services, including continuous monitoring of application performance metrics and real-time remediation of security or performance issues, through the integration of machine learning models and edge services platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate network monitoring tools are used, then network monitoring capability is provided, but system complexity and cost increase

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines network monitoring and application monitoring into a single integrated system using SmartNICs. The SmartNIC consolidates multiple monitoring functions that previously required separate tools, reducing system complexity while maintaining comprehensive monitoring capability. The NIC processes both network traffic and application performance metrics through unified hardware resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SmartNIC is designed to perform multiple functions including network packet processing, application performance monitoring, and security enforcement. This multi-functional approach eliminates the need for separate specialized tools, reducing overall system complexity while providing comprehensive monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If host CPU performs datapath processing, then basic network functionality is achieved, but CPU resources are consumed by non-application tasks

Engineering Contradiction:
Improvenetwork functionalityVSAvoidapplication processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts datapath processing functions from the host CPU and relocates them to the SmartNIC. The SmartNIC handles packet forwarding, filtering, and other network datapath tasks independently, freeing the host CPU cores to dedicate full capacity to application processing and business logic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SmartNIC acts as an intermediary between the network and the host CPU. It offloads network processing tasks from the CPU while maintaining the necessary network functionality, allowing the CPU to focus on application-level operations without being burdened by low-level network processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If SmartNIC performs application-aware network services, then network utilization improves, but device complexity increases

Engineering Contradiction:
Improvenetwork utilizationVSAvoidSmartNIC complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The SmartNIC performs self-configuration and self-management for application-aware network services. It automatically monitors application performance metrics and adjusts network processing accordingly without requiring external control, reducing the operational complexity despite increased functional capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The SmartNIC dynamically adapts its behavior based on real-time application performance data. It adjusts network processing priorities and resource allocation dynamically to optimize network utilization for different application workloads, managing complexity through adaptive rather than static configurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12267300B2Intelligent firewall policy processor
Publication Date: 2025.04.01 JUNIPER NETWORKS INC
  • US12267300B2 patent drawing
  • US12267300B2 patent drawing
  • US12267300B2 patent drawing

AI summary

An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which cause the system to obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts. The instructions cause the system to, based on the telemetry data, determine a subset of applications of the plurality of applications that run on a first host of the plurality of hosts. The instructions cause the system to determine a subset of firewall policies of a plurality of firewall polices, each of the subset of firewall policies applying to at least one respective application of the subset of applications. The instructions cause the system to generate an indication of the subset of firewall policies and send the indication to a management plane of a distributed firewall.