EP1158728A2

Packet processor with multi-level policing logic

Abstract

A switch includes a backplane and multiple packet processors. One or more packet processors include multi-level policing logic. The packet processor receives a packet and classifies the packet into multiple policeable groups. The packet is compared against bandwidth contracts defined for the policeable groups. Nested lookups are performed for the packet in a policing database to identify the multiple groups and to retrieve policing data for the multiple policeable groups. The policing results, which may be combined into a single policing result by taking the worst case policing result, are applied to disposition logic as recommendations, and are combined with other disposition recommendations to make a disposition decision for the packet.

EP1158728A2, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Projected expiry passed 23 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

46 claims: 11 independent, 35 dependent

  1. 1
    A packet switching controller comprising:an input for receiving a packet;a policing element for classifying the packet into a plurality of policeable groups,    wherein the packet is compared against one or more bandwidth contracts defined for the policeable groups to produce one or more policing results.
  2. 5
    A method of processing a packet using a policing element, the method comprising the steps of:receiving the packet;classifying the packet into a plurality of policeable groups;and comparing the packet against one or more bandwidth contracts defined for the policeable groups to produce one or more policing results.
  3. 9
    A method for policing a data packet received by a data communication switch, the method comprising:classifying the data packet into a plurality of policeable groups;identifying policing data associated with one or more policeable groups;applying the policing data to produce one or more policing results for the policeable groups;and recommending a disposition of the data packet from the policing results.
  4. 18
    A method for policing a data packet received by a data communication switch, the method comprising the steps of:creating a policing database including a plurality of policing data entries specifying policing data for a plurality of policeable groups;applying a first identifier for retrieving a first policing data associated with a first policeable group and a second identifier identifying a second policeable group;applying the first policing data to produce a first policing result;applying the second identifier for retrieving a second policing data;applying the second policing data to produce a second policing result;and recommending a disposition of the data packet from the first and second policing results.
  5. 27
    A policing engine for a data communication node, wherein the policing engine classifies a packet into a plurality of policeable groups, and wherein the packet is compared for the respective ones of the policeable groups against respective ones of bandwidth contracts to produce respective ones of policing results.
  6. 28
    A policing engine for a data communication node, wherein a first policeable group identifier is applied to a policing database to retrieve first policing data and a second policeable group identifier, wherein the first policing data is applied to produce a first policing result, and the second policeable group identifier is applied to the policing database to retrieve second policing data, wherein the second policing data is applied to produce a second policing result.
  7. 29
    A packet processor comprising:an input for receiving a packet;policing means for classifying the packet into a plurality of policeable groups,    wherein the packet is compared against one or more bandwidth contracts defined for the policeable groups to produce one or more policing results.
  8. 41
    A data policing method, the method comprising the steps of:receiving a packet;adding a time credit to a first token count to generate a second token count;applying the second token count to generate a policing result for the packet;applying the policing result to determine whether to subtract a size debit from the second token count to generate a third token count or not;and subtracting the size debit from the second token count to generate a third token count if such subtraction has been determined through applying the policing result.
  9. 43
    A data policing method, the method comprising the steps of:receiving a packet;adding a time credit to a first token count to generate a second token count;applying the second token count to generate a policing result for the packet;applying the policing result to generate a disposition result for the packet;applying the disposition result to determine whether to subtract a size debit from the second token count to generate a third token count or not;and subtracting the size debit from the second token count to generate the third token count if such subtraction has been determined through applying the disposition result.
  10. 45
    A data policing method, the method comprising the steps of:receiving a packet;adding a time credit to ones of token counts to generate respective ones of second token counts;applying the ones of second token counts to generate a policing result for the packet;applying the policing result to determine whether to subtract size debit from at least one of the second token counts to generate at least one third token count or not;and subtracting the size debit from at least one of the second token counts to generate at least one third token count if such subtraction has been determined through applying the policing result.
  11. 46
    A data policing method, the method comprising the steps of:receiving a packet;adding a time credit to ones of token counts to generate respective ones of second token counts;applying the ones of second token counts to generate a policing result for the packet;applying the policing result to generate a disposition result for the packet;applying the disposition result to determine whether to subtract or not a size debit from at least one of the second token counts to generate at least one third token count;and subtracting the size debit from at least one of the second token counts to generate at least one third token count if such subtraction has been determined through applying the disposition result.