SmartNIC Firewall Policy Processing for Application-Aware Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud data centers face challenges in efficiently monitoring and managing network and application layers due to the distributed nature of cloud-native applications, leading to underutilization of network capabilities and increased costs in monitoring, with existing solutions focusing on network edges and lacking real-time application-aware policy enforcement.

Innovation Solution

A closed-loop framework utilizing SmartNICs (Data Processing Units) for integrated network and application monitoring, enabling real-time application-aware services such as threat detection and SLA enforcement by offloading datapath processing to SmartNICs, which include a hybrid architecture of programmable ARM processors and ASICs for dynamic policy generation and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If datapath processing is performed by host CPU, then basic packet forwarding functionality is achieved, but CPU resources are shared by applications and datapath processing reducing application performance

Engineering Contradiction:
ImproveCPU resource availability for applicationsVSAvoiddatapath processing architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts datapath processing functionality from the host CPU and relocates it to a separate SmartNIC device. This extraction resolves the resource contention by isolating packet processing tasks from application workloads, allowing the host CPU to dedicate full resources to applications while the SmartNIC handles network packet processing independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SmartNIC acts as an intermediary device between the network and the host system. It mediates packet processing tasks by performing L2/L3/L4 packet processing, policing, and security functions before packets reach the host CPU, thereby reducing the burden on host resources while maintaining network connectivity and processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network monitoring is performed at network edges with existing solutions, then network layer monitoring is achieved, but application-aware monitoring is lacking and costs increase

Engineering Contradiction:
Improveapplication-aware monitoring capabilityVSAvoidmonitoring architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges network layer monitoring and application layer monitoring into a unified monitoring architecture implemented on the SmartNIC. This combination enables simultaneous observation of both network traffic patterns and application-level behaviors, providing comprehensive application-aware monitoring capabilities without requiring separate monitoring systems and reducing overall complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SmartNIC is designed with multi-functional capabilities that include both traditional network processing and advanced monitoring functions. It can perform packet processing, security enforcement, and application-aware monitoring simultaneously, making it a universal device that handles multiple networking and observability tasks without requiring additional specialized hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If SmartNICs are used for offloading datapath processing, then CPU resources are freed for applications, but policy enforcement complexity increases

Engineering Contradiction:
Improveapplication processing capacityVSAvoidpolicy management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring security policies and packet processing rules on the SmartNIC before actual network traffic arrives. The control plane communicates policy requirements in advance, allowing the SmartNIC to prepare processing pipelines and rule sets beforehand, which simplifies real-time enforcement and reduces the complexity of dynamic policy management during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the SmartNIC reports status, performance metrics, and policy enforcement results back to the control plane. This feedback loop enables automated policy adjustments and optimization, reducing the manual complexity of policy management while maintaining high application processing capacity through intelligent, adaptive policy enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250211575A1Intelligent firewall policy processor
Publication Date: 2025.06.26 JUNIPER NETWORKS INC
  • US20250211575A1 patent drawing
  • US20250211575A1 patent drawing
  • US20250211575A1 patent drawing

AI summary

An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which cause the system to obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts. The instructions cause the system to, based on the telemetry data, determine a subset of applications of the plurality of applications that run on a first host of the plurality of hosts. The instructions cause the system to determine a subset of firewall policies of a plurality of firewall polices, each of the subset of firewall policies applying to at least one respective application of the subset of applications. The instructions cause the system to generate an indication of the subset of firewall policies and send the indication to a management plane of a distributed firewall.