SmartNIC Flow Template Creation for Cloud Data Center Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud data centers face challenges in efficiently monitoring and managing network and application layers due to the distributed nature of cloud native applications, leading to underutilization of network capabilities and increased costs, with existing solutions limited in their ability to enforce policies within the datacenter and respond to real-time issues.

Innovation Solution

A closed-loop framework utilizing SmartNICs (Data Processing Units) for application-aware network services, which includes edge services platforms for orchestration, API-driven service deployment, monitoring, and dynamic policy enforcement, enabling real-time monitoring and remediation of security and performance issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional NICs with host CPU-based datapath processing are used, then basic packet forwarding functionality is achieved, but CPU resources are consumed by datapath processing reducing availability for applications

Engineering Contradiction:
Improveapplication processing capacityVSAvoidCPU resource consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent extracts the datapath processing functionality from the host CPU and relocates it to a dedicated network processor within the NIC. This separation allows the host CPU to focus exclusively on application processing while the network processor handles packet forwarding, filtering, and security functions, thereby resolving the resource contention issue.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a network processor as an intermediary component between the NIC and the host CPU. This intermediary handles the complex datapath processing tasks, acting as a buffer that prevents direct resource consumption by the host CPU while maintaining full network processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If SmartNICs with augmented datapath processing are used, then network processing capability is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork processing capabilityVSAvoidNIC structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent designs the network processor to perform multiple functions including packet forwarding, security filtering, traffic monitoring, and policy enforcement within a single integrated component. This multi-functionality approach increases capability while managing complexity by consolidating functions rather than adding separate components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If distributed monitoring tools are used for cloud native applications, then monitoring coverage is expanded, but system complexity and cost increase

Engineering Contradiction:
Improvemonitoring coverageVSAvoidmonitoring architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines network layer monitoring and application layer monitoring into a unified monitoring architecture implemented at the SmartNIC. This integration allows simultaneous monitoring of both network traffic patterns and application performance metrics without requiring separate distributed toolsets, thereby expanding coverage while managing complexity through consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring system is designed to automatically collect, analyze, and respond to performance and security events without requiring external intervention. The SmartNIC autonomously monitors traffic patterns, detects anomalies, and enforces policies, reducing the complexity of manual monitoring architecture while expanding monitoring capabilities.

Inventive Principle:
Principle #25Self-service

4Reliability

If real-time policy enforcement is implemented, then security response time is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity enforcementVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements flow template matching that pre-defines expected traffic patterns and policies. When traffic arrives, the system quickly matches it against pre-established templates rather than performing full policy evaluation, enabling real-time enforcement with reduced processing overhead. The flow templates are created in advance based on historical traffic analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4380126A1Intelligent firewall flow creator
Publication Date: 2024.06.05 JUNIPER NETWORKS INC
  • EP4380126A1 patent drawingFigure 1
  • EP4380126A1 patent drawingFigure 2
  • EP4380126A1 patent drawingFigure 3

AI summary

Example systems, methods, and storage media are described. An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which, when executed by the processing circuitry, cause the network system to obtain telemetry data, the telemetry data comprising indications of creations of instances of a flow. The instructions cause the network system to, based on the indications of the creations of the instances of the flow, determine a pattern of creation of the instances of the flow. The instructions cause the network system to, based on the pattern of creation of the instances of the flow, generate an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.