SmartNIC Flow Template Creation for Cloud Data Center Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud data centers face challenges in efficiently monitoring and managing network and application layers due to the distributed nature of cloud native applications, leading to underutilization of network capabilities and increased costs, with existing solutions limited in their ability to enforce policies within the datacenter and respond to real-time issues.
Innovation Solution
A closed-loop framework utilizing SmartNICs (Data Processing Units) for application-aware network services, which includes edge services platforms for orchestration, API-driven service deployment, monitoring, and dynamic policy enforcement, enabling real-time monitoring and remediation of security and performance issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional NICs with host CPU-based datapath processing are used, then basic packet forwarding functionality is achieved, but CPU resources are consumed by datapath processing reducing availability for applications
Solution Approach 1:
The patent extracts the datapath processing functionality from the host CPU and relocates it to a dedicated network processor within the NIC. This separation allows the host CPU to focus exclusively on application processing while the network processor handles packet forwarding, filtering, and security functions, thereby resolving the resource contention issue.
Solution Approach 2:
The patent introduces a network processor as an intermediary component between the NIC and the host CPU. This intermediary handles the complex datapath processing tasks, acting as a buffer that prevents direct resource consumption by the host CPU while maintaining full network processing capabilities.
2Productivity
If SmartNICs with augmented datapath processing are used, then network processing capability is improved, but device complexity increases
Solution Approach 1:
The patent designs the network processor to perform multiple functions including packet forwarding, security filtering, traffic monitoring, and policy enforcement within a single integrated component. This multi-functionality approach increases capability while managing complexity by consolidating functions rather than adding separate components for each function.
3Adaptability or versatility
If distributed monitoring tools are used for cloud native applications, then monitoring coverage is expanded, but system complexity and cost increase
Solution Approach 1:
The patent combines network layer monitoring and application layer monitoring into a unified monitoring architecture implemented at the SmartNIC. This integration allows simultaneous monitoring of both network traffic patterns and application performance metrics without requiring separate distributed toolsets, thereby expanding coverage while managing complexity through consolidation.
Solution Approach 2:
The monitoring system is designed to automatically collect, analyze, and respond to performance and security events without requiring external intervention. The SmartNIC autonomously monitors traffic patterns, detects anomalies, and enforces policies, reducing the complexity of manual monitoring architecture while expanding monitoring capabilities.
4Reliability
If real-time policy enforcement is implemented, then security response time is improved, but processing overhead increases
Solution Approach 1:
The patent implements flow template matching that pre-defines expected traffic patterns and policies. When traffic arrives, the system quickly matches it against pre-established templates rather than performing full policy evaluation, enabling real-time enforcement with reduced processing overhead. The flow templates are created in advance based on historical traffic analysis.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Example systems, methods, and storage media are described. An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which, when executed by the processing circuitry, cause the network system to obtain telemetry data, the telemetry data comprising indications of creations of instances of a flow. The instructions cause the network system to, based on the indications of the creations of the instances of the flow, determine a pattern of creation of the instances of the flow. The instructions cause the network system to, based on the pattern of creation of the instances of the flow, generate an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.