Virtual Function Data Center Bridging via Priority Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data Center Bridging features assigned to physical network interface controllers are not accessible to Virtual Functions, limiting their ability to manage bandwidth and prioritize traffic classes, which is crucial for secure and efficient data transmission in multi-tenant cloud environments.
Innovation Solution
Implementing a virtualization approach that hides Data Center Bridging features by mapping virtual user priorities to physical user priorities and traffic classes, allowing Virtual Functions to access necessary resources while preventing malicious behavior through rate-limiting and secure configuration, using a Physical Function driver to manage and communicate these mappings to Virtual Function drivers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Data Center Bridging features are assigned to physical network interface controllers, then network management and traffic prioritization capabilities are improved, but accessibility to Virtual Functions is limited
Solution Approach 1:
The patent segments Data Center Bridging features into physical and virtual components. Physical functions (PF) handle hardware-level operations while virtual functions (VF) manage logical traffic control. This segmentation allows VF drivers to access DCB features through virtualized interfaces without direct hardware access, resolving the contradiction between feature accessibility and system complexity.
Solution Approach 2:
The PF driver acts as an intermediary between VF drivers and the physical network interface controller. It translates virtual traffic class priorities into physical user priorities, enabling VF drivers to indirectly access DCB features while the PF driver maintains control over the physical hardware interface, thus improving accessibility without exposing full system complexity.
2Productivity
If Virtual Functions can access Data Center Bridging features directly, then bandwidth management and traffic prioritization are improved, but security risks increase
Solution Approach 1:
The patent implements local quality by giving each Virtual Function driver access only to its own allocated traffic classes and bandwidth resources. The PF driver enforces isolation by mapping each VF's virtual user priority to specific physical user priorities, ensuring that bandwidth management efficiency is improved for each tenant while preventing malicious behavior through enforced resource boundaries.
Solution Approach 2:
The system changes the parameter of priority mapping dynamically. Virtual user priorities (0-7) are mapped to physical user priorities through configurable lookup tables in the PF driver. This parameter transformation allows VF drivers to efficiently manage bandwidth within their allocated ranges while the PF driver maintains security by controlling the mapping relationships and preventing unauthorized access to physical resources.
3Productivity
If multiple tenants share physical network resources, then resource utilization is improved, but tenant isolation and security are compromised
Solution Approach 1:
The patent adds a virtualization dimension to physical network resources. Multiple tenants share physical NIC resources through virtual functions that operate in a virtual dimension. The PF driver manages the mapping between virtual traffic classes and physical user priorities, enabling high resource utilization while maintaining tenant isolation through virtual-to-physical priority mapping that prevents cross-tenant interference.
Data Source
AI summary
Tenant support is provided in a multi-tenant configuration in a data center by a Physical Function driver communicating a virtual User Priority to a virtual traffic class mapper to a Virtual Function driver. The Physical Function driver configures the Network Interface Controller to map virtual User Priorities to Physical User Priorities and to enforce the Virtual Function's limited access to Traffic Classes. Data Center Bridging features assigned to the physical network interface controller are hidden by virtualizing user priorities and traffic classes. A virtual Data Center Bridging configuration is enabled for a Virtual Function, to provide access to the user priorities and traffic classes that are not visible to the Virtual Function that the Virtual Function may need.


