SmartNIC TCP Offload for CPU Cycle Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems face challenges in providing flexible network interfaces to adapt to changes in device structures, protocols, operating systems, and applications, leading to increased CPU resource consumption due to complex networking tasks like encryption and packet processing, which hampers performance and scalability.

Innovation Solution

A transparent proxy system deployed on a smartNIC with P4-based ASICs performs TCP/TLS termination and congestion control in hardware, offloading CPU tasks and providing programmable IO devices with ARM cores to manage network connections dynamically, reducing CPU cycles and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network processing tasks (encryption, packet processing, deep packet inspection) are performed by CPU, then network security and control are improved, but CPU resource consumption increases and productivity decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidCPU resource availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts network processing tasks (TCP/TLS termination, encryption, decryption, packet processing) from the CPU and implements them in dedicated hardware accelerators. The hardware accelerator includes a TCP stack, TLS stack, and encryption/decryption units that operate independently of the host CPU, thereby reducing CPU resource consumption while maintaining network security functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a hardware accelerator as an intermediary component between the network interface and the host CPU. This hardware accelerator acts as a mediator that handles network processing tasks, reducing the burden on the CPU while ensuring secure and controlled network traffic management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network processing is done in software on CPU, then flexibility and adaptability are maintained, but processing speed decreases and latency increases

Engineering Contradiction:
Improveprotocol flexibilityVSAvoidnetwork processing speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent implements a dynamic configuration mechanism where the hardware accelerator can be programmed with different TCP congestion control algorithms and network processing policies. The system can adapt to different network conditions and protocols dynamically, allowing high-speed processing while maintaining flexibility through programmable configuration rather than fixed hardware logic.

Inventive Principle:
Principle #15Dynamics

3Reliability

If TCP/TLS termination and encryption are performed by host CPU, then application security is improved, but CPU cycles are consumed and throughput is reduced

Engineering Contradiction:
Improveapplication securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts TCP/TLS termination, encryption, and decryption functions from the host CPU and implements them in the hardware accelerator. The hardware accelerator includes dedicated TLS stack and encryption units that handle these security functions independently, thereby maintaining application security while significantly reducing CPU cycle consumption and increasing network throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11431681B2Application aware TCP performance tuning on hardware accelerated TCP proxy services
Publication Date: 2022.08.30 PENSANDO SYSTEMS INC
  • US11431681B2 patent drawing
  • US11431681B2 patent drawing
  • US11431681B2 patent drawing

AI summary

Described are platforms, systems, and methods for actuating transmission control protocol/Internet protocol (TCP/IP) through a method comprises: identifying a computer workload during a handshake process for establishing a network connection with a remote host; configuring, based on the computer workload, one or more TCP/IP parameters of the network connection; and completing the handshake process to establish the network connection with the remote host.