Virtual Function Data Center Bridging via Priority Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data Center Bridging features assigned to physical network interface controllers are not accessible to Virtual Functions, limiting their ability to manage bandwidth and prioritize traffic classes, which is crucial for secure and efficient data transmission in multi-tenant cloud environments.

Innovation Solution

Implementing a virtualization approach that hides Data Center Bridging features by mapping virtual user priorities to physical user priorities and traffic classes, allowing Virtual Functions to access necessary resources while preventing malicious behavior through rate-limiting and secure configuration, using a Physical Function driver to manage and communicate these mappings to Virtual Function drivers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Data Center Bridging features are assigned to physical network interface controllers, then network management and traffic prioritization capabilities are improved, but accessibility to Virtual Functions is limited

Engineering Contradiction:
ImproveData Center Bridging feature accessibilityVSAvoidnetwork interface controller configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments Data Center Bridging features into physical and virtual components. Physical functions (PF) handle hardware-level operations while virtual functions (VF) manage logical traffic control. This segmentation allows VF drivers to access DCB features through virtualized interfaces without direct hardware access, resolving the contradiction between feature accessibility and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The PF driver acts as an intermediary between VF drivers and the physical network interface controller. It translates virtual traffic class priorities into physical user priorities, enabling VF drivers to indirectly access DCB features while the PF driver maintains control over the physical hardware interface, thus improving accessibility without exposing full system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If Virtual Functions can access Data Center Bridging features directly, then bandwidth management and traffic prioritization are improved, but security risks increase

Engineering Contradiction:
Improvebandwidth management efficiencyVSAvoidmalicious behavior potential
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by giving each Virtual Function driver access only to its own allocated traffic classes and bandwidth resources. The PF driver enforces isolation by mapping each VF's virtual user priority to specific physical user priorities, ensuring that bandwidth management efficiency is improved for each tenant while preventing malicious behavior through enforced resource boundaries.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of priority mapping dynamically. Virtual user priorities (0-7) are mapped to physical user priorities through configurable lookup tables in the PF driver. This parameter transformation allows VF drivers to efficiently manage bandwidth within their allocated ranges while the PF driver maintains security by controlling the mapping relationships and preventing unauthorized access to physical resources.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If multiple tenants share physical network resources, then resource utilization is improved, but tenant isolation and security are compromised

Engineering Contradiction:
Improveresource utilizationVSAvoidtenant isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent adds a virtualization dimension to physical network resources. Multiple tenants share physical NIC resources through virtual functions that operate in a virtual dimension. The PF driver manages the mapping between virtual traffic classes and physical user priorities, enabling high resource utilization while maintaining tenant isolation through virtual-to-physical priority mapping that prevents cross-tenant interference.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11403137B2Method and apparatus for secure data center bridging in a multi-tenant system
Publication Date: 2022.08.02 INTEL CORP
  • US11403137B2 patent drawing
  • US11403137B2 patent drawing
  • US11403137B2 patent drawing

AI summary

Tenant support is provided in a multi-tenant configuration in a data center by a Physical Function driver communicating a virtual User Priority to a virtual traffic class mapper to a Virtual Function driver. The Physical Function driver configures the Network Interface Controller to map virtual User Priorities to Physical User Priorities and to enforce the Virtual Function's limited access to Traffic Classes. Data Center Bridging features assigned to the physical network interface controller are hidden by virtualizing user priorities and traffic classes. A virtual Data Center Bridging configuration is enabled for a Virtual Function, to provide access to the user priorities and traffic classes that are not visible to the Virtual Function that the Virtual Function may need.