Method and device for data flow processing
Abstract
Methods and systems for managing data exchange in a network environment are disclosed. A flow tag is assigned to a data packet at the source device 112-1. The flow tag includes a port ID corresponding to a port (port 2) in the aggregation device 200 . The destination device 112-2 is communicating with a port at the aggregation device. The data packet is authenticated at the aggregation device. The data packet is output from the source device to the destination device through the aggregation device according to the port ID in the flow tag of the authenticated data packet.

Term
7.1 yearsleft in the term
Expires 12 November 2033.
- Priority
- Filed
- Granted
- Today
- Expires
31 claims: 6 independent, 25 dependent
- 1네트워크 환경에서 데이터 교환을 관리하기 위한 방법으로서, 취합 디바이스로부터 소스 디바이스로 플로우태그(flowtag)를 송신하는 단계, 상기 플로우태그는 상기 취합 디바이스에서의 포트를 식별하는 포트 아이디(port identification)를 포함하고, 상기 포트는 MAC(Media Access Control) 어드레스를 갖는 수신지 디바이스에 통신가능하게 접속되며;상기 취합 디바이스에서 데이터 패킷 및 상기 플로우태그를 상기 소스 디바이스로부터 수신하는 단계;상기 취합 디바이스에서 상기 데이터 패킷을 인증하는 단계;및 상기 데이터 패킷을 인증하면, 상기 플로우태그 내의 상기 포트 아이디에 따라 상기 데이터 패킷을 상기 취합 디바이스로부터 상기 수신지 디바이스로 출력하는 단계를 포함하는 방법.
- 2제1항에 있어서, 상기 포트 아이디는 상기 MAC 어드레스에 대하여 상기 취합 디바이스 내의 매핑 테이블에 매핑되는 것인 방법.
- 3제1항에 있어서, 상기 소스 디바이스는 서버 노드를 포함하는 것인 방법.
- 4제1항에 있어서, 상기 소스 디바이스로부터 상기 취합 디바이스로 상기 포트 아이디에 대한 요청을 보내는 단계, 상기 요청은 상기MAC 어드레스를 포함하며;상기 MAC 어드레스를 상기 포트 아이디와 연관시키는 상기 취합 디바이스에서의 매핑 테이블 엔트리에 따라, 상기 포트를 식별하는 포트 아이디를 포함하는 상기 플로우태그를 상기 취합 디바이스로부터 상기 소스 디바이스로 보내는 단계를 더 포함하는 방법.
- 5제4항에 있어서, 상기 취합 디바이스에서 상기 플로우태그를 발생시키는 단계를 더 포함하는 방법.
- 6제1항에 있어서, 상기 취합 디바이스에서 구성 변경을 검출하는 단계;상기 구성 변경과 관련된 데이터를 포함하는 요청을 상기 취합 디바이스로부터 상기 소스 디바이스로 보내는 단계;및 상기 구성 변경과 관련된 상기 데이터를 포함하도록 상기 요청에 응답하여 상기 소스 디바이스에서 상기 플로우태그를 업데이트하는 단계를 더 포함하는 방법.
- 7제1항에 있어서, 상기 데이터 패킷을 인증하는 단계는, 라우팅 요청 메시지(routing request message)를 상기 소스 디바이스로부터 상기 취합 디바이스로 보내는 단계;상기 플로우태그를 봉인(seal)하는 크리덴셜(credential)을 상기 취합 디바이스로부터 상기 소스 디바이스에서 수신하는 단계;상기 플로우태그와 상기 데이터 패킷을 상기 소스 디바이스로부터 상기 취합 디바이스로 송신하는 단계, 상기 플로우태그는 상기 크리덴셜을 포함하고;그리고 상기 취합 디바이스에서 상기 크리덴셜을 타당성 검증함으로써 상기 데이터 패킷을 인증하는 단계를 포함하는 것인 방법.
- 8제7항에 있어서, 상기 플로우태그는 상기 취합 디바이스에서 발생된 복수의 크리덴셜 중에서 상기 크리덴셜에 대응하는 세대 ID(generation ID)를 포함하는 것인 방법.
- 9제7항에 있어서, 상기 크리덴셜을 타당성 검증하는 것은, 상기 취합 디바이스에서 제 2 크리덴셜을 발생시키는 단계;상기 소스 디바이스로부터 보내진 상기 크리덴셜과 상기 제 2 크리덴셜을 상기 취합 디바이스에서 비교하는 단계;및 상기 소스 디바이스로부터 보내진 상기 크리덴셜이 상기 제 2 크리덴셜과 매칭되면 상기 소스 디바이스로부터 보내진 상기 크리덴셜을 유효라고 결정하고 또는 상기 소스 디바이스로부터 보내진 상기 크리덴셜이 상기 제 2 크리덴셜과 매칭되지 않으면 상기 소스 디바이스로부터 보내진 상기 크리덴셜을 무효라고 결정하는 단계를 포함하는 것인 방법.
- 10제9항에 있어서, 상기 소스 디바이스로부터 보내진 상기 크리덴셜이 무효라는 결정에 응답하여 상기 데이터 패킷을 폐기하고 타당성 검증 결과의 로그를 생성하는 단계를 더 포함하는 방법.
- 11제7항에 있어서, 상기 취합 디바이스에서 순환 키 선택기로부터 키를 제공하는 단계;및 상기 취합 디바이스에서 복수의 발생된 크리덴셜로부터 상기 크리덴셜을 선택하도록 상기 키를 사용하는 단계를 더 포함하는 방법.
- 12제1항에 있어서, 상기 소스 디바이스에서 플로우태그 캐시를 유지하는 단계를 더 포함하며, 상기 플로우태그 캐시는 하나 이상의 플로우태그들을 저장하도록 구성되는 것인 방법.
- 13데이터 패킷을 처리하기 위한 방법으로서, 취합 디바이스에서 발생된 플로우태그를, 상기 취합 디바이스로부터 소스 디바이스에서 수신하는 단계, 상기 플로우태그는 라우팅 데이터 및 크리덴셜을 포함하고, 상기 라우팅 데이터는 상기 취합 디바이스에서의 포트에 대응하는 포트 아이디를 포함하며, 상기 포트는 MAC 어드레스를 갖는 수신지 디바이스에 통신가능하게 접속되며;그리고 상기 플로우태그를 포함하는 데이터 패킷 및 대응하는 데이터 유닛을 상기 소스 디바이스로부터 상기 취합 디바이스로 보내는 단계를 포함하는 방법.
- 14삭제
- 15제13항에 있어서, 상기 플로우태그는 상기 취합 디바이스에서 발생된 복수의 크리덴셜 중에서 상기 크리덴셜에 대응하는 세대 ID를 포함하는 것인 방법.
- 16제13항에 있어서, 상기 소스 디바이스로부터 보내진 상기 크리덴셜이 무효라는 결정에 응답하여 타당성 검증 결과의 로그를 상기 취합 디바이스에서 생성하는 단계를 더 포함하는 방법.
- 17제13항에 있어서, 상기 취합 디바이스에서 순환 키 선택기로부터 키를 제공하는 단계;및 상기 취합 디바이스에서 복수의 발생된 크리덴셜로부터 상기 크리덴셜을 선택하도록 상기 키를 사용하는 단계를 더 포함하는 방법.
- 18제13항에 있어서, 상기 취합 디바이스에서 상기 크리덴셜을 타당성 검증함으로써 상기 데이터 패킷을 인증하는 단계;및 상기 크리덴셜을 타당성 검증하는 것에 응답하여 상기 플로우태그 내 상기 라우팅 데이터에 따라 상기 데이터 유닛을 처리하는 단계를 더 포함하는 방법.
- 19데이터 네트워크로서, 데이터 전송 연산에서 플로우태그를 데이터 패킷에 할당하는 소스 디바이스;상기 데이터 전송 연산에서 상기 데이터 패킷을 수신하는 수신지 디바이스;및 상기 소스 디바이스가 통신하고 있는 제 1 포트 및 상기 수신지 디바이스가 통신하고 있는 제 2 포트를 갖는 취합 디바이스를 포함하며, 상기 취합 디바이스는 상기 플로우태그 내의 라우팅 데이터를 처리하고 상기 플로우태그를 봉인하는 크리덴셜을 타당성 검증하는 패킷 관리 디바이스를 포함하고, 상기 플로우태그 내의 상기 라우팅 데이터는 상기 제 2 포트에 대응하는 포트 아이디를 포함하고, 상기 취합 디바이스는 상기 데이터 패킷 및 상기 플로우태그를 상기 소스 디바이스로부터 수신하고 그리고 상기 플로우태그 내의 상기 포트 아이디에 기초하여 상기 데이터 패킷을 상기 수신지 디바이스로 포워딩하도록 구성되는 것을 특징으로 하는 데이터 네트워크.
- 20제19항에 있어서, 상기 소스 디바이스는 복수의 엔트리, 상기 소스 디바이스의 MAC 어드레스와 상기 제 1 포트에 대응하는 포트 아이디 간 매핑을 포함하는 제 1 엔트리, 및 상기 수신지 디바이스의 MAC 어드레스와 상기 제 2 포트에 대응하는 상기 포트 아이디 간 매핑을 포함하는 제 2 엔트리를 포함하는 플로우태그 캐시를 포함하는 것인 데이터 네트워크.
- 21제20항에 있어서, 상기 패킷 관리 디바이스는 상기 소스 디바이스로부터 보내진 요청에 응답하여 상기 수신지 디바이스의 상기 MAC 어드레스와 상기 제2 포트에 대응하는 상기 포트 아이디 간 매핑을 제공하는 매핑 테이블을 포함하는 것인 데이터 네트워크.
- 22제21항에 있어서, 상기 패킷 관리 디바이스는 포트 구성 변경을 검출하는 구성 관리 모듈을 포함하고, 상기 매핑 테이블은 상기 포트 구성 변경에 응답하여 업데이트되는 것인 데이터 네트워크.
- 23제19항에 있어서, 상기 패킷 관리 디바이스는 상기 크리덴셜을 발생시키는 크리덴셜 처리 엔진을 포함하는 것인 데이터 네트워크.
- 24제23항에 있어서, 상기 패킷 관리 디바이스는 상기 소스 디바이스로부터 수신된 상기 크리덴셜을 타당성 검증하는 크리덴셜 타당성 검증 모듈을 포함하는 것인 데이터 네트워크.
- 25제23항에 있어서, 상기 패킷 관리 디바이스는 복수의 크리덴셜로부터 상기 크리덴셜을 선택하기 위한 키를 제공하는 순환 키 선택기를 포함하는 것인 데이터 네트워크.
- 26취합 디바이스로서, 소스 디바이스와 통신하는 제 1 포트;MAC 어드레스를 갖는 수신지 디바이스와 통신하는 제 2 포트;및 매핑 테이블을 포함하는 패킷 관리 디바이스를 포함하며, 상기 매핑 테이블은 상기 제 1 포트와 상기 소스 디바이스 사이의 제 1 매핑 및 상기 제 2 포트와 상기 수신지 디바이스 사이의 제 2 매핑을 포함하며, 상기 패킷 관리 디바이스는 상기 소스 디바이스로부터 데이터 유닛을 수신하고 상기 데이터 유닛과 함께 제공되는 상기 제 2 포트와 관련된 정보에 따라 상기 데이터 유닛을 상기 수신지 디바이스로 라우팅하며, 상기 제 2 포트와 관련된 상기 정보는 상기 데이터 유닛과 함께 수신되는 플로우태그 내에 포함된 상기 제 2 포트에 대한 아이디(identification)인 것을 특징으로 하는 취합 디바이스.
- 27제26항에 있어서, 상기 패킷 관리 디바이스는 포트 구성 변경을 검출하는 구성 관리 모듈을 포함하고, 상기 매핑 테이블은 상기 포트 구성 변경에 응답하여 업데이트되는 것인 취합 디바이스.
- 28제27항에 있어서, 상기 패킷 관리 디바이스는 상기 데이터 유닛을 인증하기 위한 크리덴셜을 발생시키는 크리덴셜 처리 엔진을 포함하는 것인 취합 디바이스.
- 29제28항에 있어서, 상기 패킷 관리 디바이스는 발생된 상기 크리덴셜을 사용하여 상기 소스 디바이스로부터 상기 플로우태그와 수신된 크리덴셜을 타당성 검증하는 크리덴셜 타당성 검증 모듈을 포함하는 것인 취합 디바이스.
- 30제28항에 있어서, 상기 패킷 관리 디바이스는 상기 크리덴셜을 발생시키기 위한 키를 제공하는 순환 키 선택기를 포함하는 것인 취합 디바이스.
- 31컴퓨터 판독가능 프로그램 코드가 내장되어 있는 컴퓨터 판독가능 저장 매체로서, 상기 컴퓨터 판독가능 프로그램 코드는, 플로우태그를 소스 디바이스에서의 데이터 패킷에 할당하도록 구성된 컴퓨터 판독가능 프로그램 코드, 상기 플로우태그는 취합 디바이스에서의 포트를 식별하는 포트 아이디 및 크리덴셜을 포함하고, 상기 포트는 MAC 어드레스를 갖는 수신지 디바이스에 통신가능하게 접속되며;상기 소스 디바이스로부터 상기 취합 디바이스로 상기 데이터 패킷 및 상기 플로우태그를 전송하도록 구성된 컴퓨터 판독가능 프로그램 코드;상기 크리덴셜에 기초하여 상기 취합 디바이스에서 상기 데이터 패킷을 인증하도록 구성된 컴퓨터 판독가능 프로그램 코드;및 상기 플로우태그 내의 상기 포트 아이디에 기초하여, 상기 포트로부터 상기 데이터 패킷을 상기 취합 디바이스로부터 상기 수신지 디바이스로 출력하도록 구성된 컴퓨터 판독가능 프로그램 코드 를 포함하는 것인 컴퓨터 판독가능 저장 매체.
Independent claims31
69 paragraphs in 1 section, as filed
METHOD AND DEVICE FOR DATA FLOW PROCESSING
FIELD OF THE INVENTION The present invention relates generally to data networks, and more particularly to methods and systems for controlling data flow between data network devices.
Large network environments, such as data centers, can provide Internet and intranet services to support businesses and organizations. A typical data center may house various types of electronic equipment such as computers, domain name system (DNS) servers, network switches, routers, data storage devices, and the like. A data center may have hundreds or thousands of interconnected host devices, eg, server nodes, that communicate with each other and with external devices via a switching architecture that includes switches, routers, and the like. In data exchange between a host device and a network switch, the host device sends a data payload and a destination MAC address to the switch in, for example, an Ethernet frame. The switch in turn decodes the MAC address to determine the intended destination of the data payload. Idiomatic network switches typically consist of a content addressable memory (CAM) table containing frames that forward information such as destination device MAC addresses and switch port information to output data to destination devices.
According to one aspect, a method for managing data exchange in a network environment is provided. A flowtag is transmitted to the source device. The flow tag contains a port identification corresponding to a port in the aggregation device. A data packet including a flowtag is received from a source device. The data packet is authenticated at the aggregation device. The authenticated data packet is output according to the port ID in the flow tag of the authenticated data packet.
According to another aspect, a method for processing a data packet is provided. The source device receives the flowtag and credential generated by the aggregation device. The flow tag includes routing data. A data packet including a flow tag and a corresponding data unit are output from the source device to the aggregation device.
According to another aspect, there is provided a data network comprising a source device, a destination device, and an aggregation device. The source device assigns a flowtag to the data packet in a data transfer operation. The destination device receives the data packet in a data transfer operation. The aggregation device has a first port with which the source device is communicating and a second port with which the destination device is communicating. The aggregation device includes a packet management device that processes routing data in the flowtag and validates the credentials sealing the flowtag. The routing data in the flow tag includes a port ID corresponding to the second port. The aggregation device transmits the data packet from the source device to the destination device according to the port ID in the flow tag.
According to another aspect, there is provided an aggregation device comprising a packet management device comprising a first port in communication with a source device, a second port in communication with a destination device, and a mapping table. The mapping table includes a first mapping between the first port and the source device and a second mapping between the second port and the destination device. The packet management device receives the data unit from the source device and routes the data to the destination device according to information related to the second port through which the data unit is provided.
According to another aspect, there is provided a computer program product comprising a computer readable storage medium having computer readable program code embedded therein. The computer readable program code comprises computer readable program code configured to assign a flowtag to a data packet at a source device. The flow tag includes a port ID corresponding to a port in the aggregation device. The destination device communicates with the port at the aggregation device. The computer readable program code is computer readable configured to output the data packet from the source device to the destination device via the aggregation device according to the computer readable program code configured to authenticate the data packet at the aggregation device and a port ID in the authenticated data packet. It further includes program code.
BRIEF DESCRIPTION OF THE DRAWINGS The above and further advantages of the present invention may be better understood by reference to the following description taken in conjunction with the accompanying drawings in which like reference numerals indicate like structural elements and features in the various drawings. The drawings are not necessarily to scale, emphasis instead being placed on illustrating the principles of the invention. 1 is a block diagram of a computing environment in which embodiments of the inventive concepts may be practiced; FIG. 2 is a block diagram of a packet management device of the aggregation system of FIG. 1 , in accordance with one embodiment; 3 is a flowchart of a method for managing data exchange in a network environment, according to one embodiment; 4 is a flowchart of a method for managing data exchange in a network environment, according to another embodiment; 5 is a flowchart of a method for authenticating a packet, according to one embodiment; 6 is a diagram illustrating the content of a packet output from a server node to an aggregation device, according to an embodiment; and 7 is a detailed block diagram illustrating a validation process, according to one embodiment.
Although specific details are set forth in the following description, it should be appreciated by those skilled in the art that the systems and methods may be practiced without at least some of the details. In some instances, well-known features and processes have not been described in detail so as not to obscure the present invention.
The idiomatic server node sends a data packet to a network switch, which forwards the data packet to its destination device according to the source and destination MAC addresses from which the data packet is provided. However, management of the CAM table of the switch requires a certain set of logic-intensive steps, including MAC address lookup or related decoding functions, MAC address-to-port mapping, and the like. This costly process can be extended in virtual network configurations where a virtual machine (VM) is provided for each connection to a network switch and where each VM requires one or more MAC addresses.
Some aspects of the inventive concept are for efficiently controlling the routing of data packets, frames, cells, or other fixed or variable amounts of data exchanged between one or more server nodes in communication with an aggregation device in a network environment such as a data center. and security-related attributes related to the transmission of data, such as source MAC address validation, virtual LAN (VLAN) membership, and an approach to enforce destination MAC address filtering. The aggregation device receives a request from the source device to route the data packet to the destination device via the aggregation device. The aggregation device generates a flowtag that includes a port identifier and the like that is mapped to the MAC address of the destination device. The aggregation device can also generate a credential that can be used to seal the flowtag. The flowtag is received by the source device and stored in the flowtag cache. In addition to the credentials, the flowtag may contain a switch port number or other routing information used by the aggregation device instead of the MAC address to route data to the destination device. During subsequent data exchanges, the aggregation device directs packets received from the source device to the port corresponding to the port number or associated identifier in the flowtag. The aggregation device uses the port number or the like from the received flowtag to route the data instead of the MAC address. Therefore, no MAC address lookup is necessary. This enables decoding functions and the like to be performed in software in the aggregation device instead of hardware-intensive CAM tables, thus reducing the hardware effort normally required when processing MAC addresses.
A related, additional or alternative feature of the inventive concept may also reduce the risk of exposure of a MAC address to spoofing or the like, particularly in virtualization applications. This may be accomplished by an aggregation device that validates the flowtag and received credentials, sealing the flowtag content, prior to routing the packet to the destination device. The credential may be validated by recalculating the credential at the aggregation device and comparing it to the received credential.
1 is a block diagram of a computing environment 10 in which embodiments of the inventive concepts may be practiced. Computing environment 10 may include a data network in which data is exchanged between components of the network. Computing environment 10 includes a plurality of server nodes 112-1 through 112-N (typically 112), where N is an integer greater than zero. The server nodes 112 are each coupled to the aggregation device 200 by a Peripheral Component Interconnect Express (PCIe) connector or the like to establish a communication path 116 with the aggregation device 200 . Server node 112 may include a single socket server or associated microprocessor device attached to aggregation device 200 by a PCIe interface or the like. Other low-power host devices may be configured and arranged to communicate with the aggregation device 200 . The server node 112 may be configured and arranged as a processor cluster or other well-known arrangement. One or more server nodes 112 may be virtualized or non-virtualized.
Server node 112 includes one or more network interfaces, eg, NICs. The virtualized server node and/or aggregation device 200 may include multiple virtual network interface cards (vNICs).
Server node 112 includes processor 102, which includes one or more microprocessors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), application specific integrated circuits (ASICs), memory controllers, multi-core processors, or other types of data processing devices, or some and combinations of these and other devices.
Server node 112 also includes memory (not shown). The memory may be non-volatile or volatile memory, for example DRAM or static RAM (SRAM). Memory 104 stores and includes program code for an operating system, one or more applications, or other software programs executed by processor 102 . In addition, the memory 104 may include and store some or all of the node interface 122 , the device driver 124 , the flow tag cache 126 , and the network stack 128 .
The node interface 122 may include a PCIe port or associated network connector and may communicate with the device driver 124 to establish a communication path 116 with the aggregation device 200 .
Flowtag cache 126 stores MAC address-to-routing information map data. The routing information may include an egress port or other identifier corresponding to the destination device. In one embodiment, the flowtag cache 126 maps a tuple, eg, {destination MAC address, VLAN tag (if present)} to a variable length flowtag. For example, the flowtag cache 126 may map port 2 in the aggregation device 200 to the MAC address of the server node 112 - 2 . The flow tag may be inserted into a header that is transmitted to the aggregation device 200 in an Ethernet frame or other data unit, eg, a cell, packet, or the like.
A driver 124 , also referred to as a host driver, may manage the flow tag cache 126 . In one embodiment, the driver 124 includes a virtual queue interface 132 that communicates with a virtual queue 218 , or a virtual queue supported by a vNIC in the aggregation device 200 .
The network stack 128 may include a multi-layer software stack for network communication. Network stack 128 may include Transmission Control Protocol (TCP), User Datagram Protocol (UDP), or related protocols included in the Internet Protocol (IP) suite. Network stack 128 may include, for example, other network, transport, and/or link layers that conform to the Open Systems Interconnection (OSI) model, or other abstraction layers. For example, the link layer of the network stack 128 may assign source and destination MAC addresses such that data packets are directed to a particular network interface on the server node 112-1, e.g., interface 122. make it possible
As described above, the server node 112-1 may be virtualized. The virtualized server node 112-1 may include one or more virtual machines (not shown) or guests, hypervisors, and/or other virtualization components, such that the server node 112-1 may include an aggregation device ( 200) and/or share hardware, such as a BIOS, HBA, or other hardware device, and/or a physical NIC 242 in communication with it.
The aggregation device 200 is interposed between the server node 112 and one or more network interface cards (NICs) 242 or associated network adapters such that the server node 112 can communicate with one or more remote electronic devices 152 . can be combined. The aggregation device 200 may be used as a connection fabric to the server nodes 112 , which may be organized within a cluster, replacing some or all of the traditional Ethernet switching requirements used in conventional server racks.
The aggregation device 200 includes a switch fabric 202 , an input/output (I/O) processor 204 , a packet management device 210 , a plurality of ports 1-N, and a corresponding plurality of port processors 216 - 1 to 216-N), wherein N is an integer greater than 1.
Ports 1-N may be input ports and/or output ports. The port processor 216 may provide a PCIe link or the like that forms a communication path 116 with the server node 112 . Port processor 216 may include transmit and/or receive control logic and decoding logic to process incoming packets from server node 112 .
The switch fabric 202 provides data plane interconnection between the server nodes 112 , such that one or more remote electronic devices 152 and/or the server nodes are in communication with the aggregation system 200 via one or more NICs 242 . (112) to exchange data.
I/O processor 204 processes data transferred between aggregation system 200 and server node 112 and/or remote computing device 252 . The I/O processor 204 may monitor the transmission of data packets between the server node 112 and/or one or more remote computing devices 152 . In one embodiment, I/O processor 204 includes a network processor for exchanging data between server node 112 and/or remote electronic device 152 . In another embodiment, the I/O processor 204 is configured to perform data transfers into and out of the switch fabric 202 according to, for example, a control plane processor (not shown) that may be provided with a plurality of vNICs. It contains multiplexers and other logic. Here, the I/O processor 204 transmits data to and from the aggregation device 200 , for example, between two or more server nodes 112 , or between a server node 112 and a remote computing device 152 . It can serve as a staging area for
FIG. 2 is a block diagram of a packet management device 210 of the aggregation system of FIG. 1 , according to one embodiment. The packet management device 210 includes a mapping table 222 , a configuration management module 224 , a credential processing engine 226 , a credential validation module 228 and a circular key selector 232 .
The mapping table 222 includes a set of mappings between the aggregation system ports 1-N and the MAC addresses of the source server nodes in communication with the aggregation device 200 . The mapping table 222 is a software application that tracks and manages the MAC address of the server node 112 and/or other device communicating with the aggregation device 200 and the port on which the server node 112 and/or other device is hanging. may be part of For example, referring to Figure 2, each MAC address assigned to the server nodes 212A, 212B may be associated with any of the switch ports 1-N, respectively, resulting in less processing than a hardware-intensive CAM table. demand
The configuration management module 224 may detect a configuration change related to the MAC address. For example, the configuration management module 224 may detect when a device is changed to a different port in the aggregation device 200 . Here, a management device such as an external controller may update the mapping table 222 with a mapping between the MAC address of the device and a new port.
Credential processing engine 226 generates credentials that can be used to protect routing information, such as port numbers, in exchanges between aggregation device 200 and server node 112 . This may be achieved, for example, by a credential that seals components of the data packet such as header information and flow tags such as MAC addresses. The credential processing engine 226 may generate credentials on a per-virtual machine or per-port basis. A cache of credentials may be maintained by the host driver 124 . Credentials may be constructed by credential processing engine 226 by computing a one-way hash of the flowtag and associated header information, for example: {seed per port, port number, link number, virtual queue tag}. The credential processing engine 226 provides a port seed or rotation value of the credential, or virtual queue (VQ) tag, VLAN membership, and/or used to cycle the credential so that the credential can be used more than once. Alternatively, one or more credentials may be assigned based on the currently active key.
The credential validation module 228 authenticating the flowtag data may validate the flowtag and the received credential against the generated or recomputed copy at the ingress port at the aggregation device 200 . Once the credentials have been validated, the flowtag content can be used to route the packet to the appropriate destination virtual queue 218 .
As described herein, the credentials may be recycled in the aggregation device 200 . The circular key selector 232 may recycle the credential based on a predetermined criterion, and may maintain the state of the credential. This may be accomplished by a key, e.g., a per-VQ key, that is periodically rotated by the cyclic key selector 232 to prevent or otherwise reduce the risk of an unauthorized host or other snooping device from subverting the credential. can
3 is a flow diagram of a method 300 for managing data exchange in a network environment, according to one embodiment. In describing the method 300, reference is made to the components of FIGS. 1 and 2 .
At block 302, a flowtag cache map is generated. The flowtag cache map may include a mapping between a server node MAC address and a device port in the aggregation device 200 . For example, referring to FIG. 1 , the flow tag cache map in the cache 126 is a first mapping between the MAC address of the server node 112-1 and port 1 of the aggregation device 200 and the server node 112- 2) may include a second mapping between the MAC address of the aggregation device and port 2 of the aggregation device. The flowtag cache map may be populated by data collected from the aggregation device 200 associated with the MAC address-to-port mapping, eg, a new device coupled to the aggregation device 200 .
In decision diamond 304 , the source node driver, e.g., the driver 124 of the server node 112-1, matches the destination MAC address, e.g., the MAC address of the destination server node 112-2, and It is determined whether an exit port ID (ID), for example, a mapping between ports 2 with which the destination server 112-2 is communicating, can be identified. When the source driver 124 determines the mapping between the MAC address of the destination server node 112-2 and the port in the aggregation device 200 communicating with the destination server node 112-2, that is, port 2, , then the method 300 proceeds to block 312 , where the aggregation device 200 according to the port ID of the destination server node 112-2, ie, port 2, instead of the destination MAC address. The packet sent from the source server node 112-1 to the destination server node 112-2 is processed.
If the source driver 124 does not identify the mapping between the destination port, ie, port 2, of the MAC address of the destination server node 112-2, then the method 300 proceeds to block 306, where The destination MAC address is forwarded to the packet management device 210 .
At block 308 , the packet management device 210 may send a port number or associated identifier corresponding to the received destination MAC address to the source server node 112-1. The port number is preferably associated with the egress port with which the destination server node 112-2, having the destination MAC address, is communicating. The port number or associated identifier may be part of a flowtag generated at the packet management device that is sent to the source server node 112-1 in response to the request. The flow tag may be stored in the flow tag cache 126 .
At block 310 , the source server node 112-1 outputs the data packet including the flowtag to the aggregation device 200 for routing to its destination. The data packet may be an Ethernet packet or the like.
In block 312 , the aggregation device 200 sends the destination server node 112 - 2) Processes the packets sent to Since routing occurs according to port number, less processing is required than configuring routing where routing occurs according to MAC address.
4 is a flowchart of a method 400 for managing data exchange in an electronic communication environment, according to another embodiment. In describing the method 400, reference is made to the components of FIGS.
At block 402, a configuration change is detected. A configuration change may include a change to a different port by the server node 112 . The server node 112 or external device 152 may be reconfigured with a different MAC address, or the MAC address may be reassigned to another server node 112 or external device 152 . Here, the cache 126 at the source server node 112-1 may have an entry pointing to the MAC address mapped to port 2 of the aggregation device 200 . However, the configuration manager 228 of the aggregation device 200 , and more specifically the packet management device 210 , indicates that a different MAC address is communicating with port 2 , or that the MAC address stored in the cache 126 is a different MAC address. change can be detected. In another example, the aggregation device 200 detects that a different MAC address is assigned to a virtual machine at the server node 112 .
At block 404 , the packet management device 210 sends a request to the source server node 112-1. The request may include an invalidation request indicating to the source server node 112-1 that the previous mapping of the destination MAC address to port 2 is no longer valid. In another embodiment, the request includes an update request to the source server node 112-1. The source server node 112-1 deletes the old mapping information from the flow tag cache 126 and processes the new mapping information. Accordingly, a request to invalidate a previous mapping in the flowtag cache 126 may be sent by the packet management device 210 or, alternatively, an indicator performing invalidation of the mapping and subsequent updates to the source server node 112 - 1)) can be sent.
At block 406 , the flowtag cache 126 is updated to include MAC address-to-port mapping information reflecting the configuration change detected at block 402 . The MAC address-to-port mapping information is provided from the mapping table 222 of the packet management device 210 .
5 is a flow diagram of a method 500 for validating packet data, according to one embodiment. In describing the method 500, reference is made to the components of FIGS. Method 500 applies, for example, to address security-related issues where routing information, such as a MAC address in a guest driver of a virtualized server node, may be obtained for spoofing or susceptible to other unauthorized or illegal use. Thus, for example, it is possible to prevent others from obtaining data by avoiding access to the server node.
At block 502 , the source server node 112-1 may send a routing request message to the aggregation device 200 . The routing request message may include a request for a destination MAC address or other routing data.
At block 504 , the packet management device 210 of the aggregation device 200 may send routing data in response to the request made at block 502 . In one embodiment, the aggregation device 200 sends the credential with the flowtag instead of the requested destination MAC address according to the mapping information in the mapping table 222 .
The aggregation device 200 may also send credentials and/or other information, such as routing data and VLAN membership data, to the requesting source server node 112-1. The credential may be generated by the credential processing engine 226 . A credential is a packet and/or flowtag data such as a per-port seed, port number, link number, virtual queue identifier or tag, and/or generation ID, which may be used to recycle the credential as described below. It can be constructed by computing a one-way hash of the header information. In one embodiment, a credential is generated for each virtual machine of the server node 112 . In another embodiment, a credential is generated for each port 1-N to which the server node 112 or other electronic device is coupled. The credential processing engine 226 may assign the credential based on the virtual queue tag, VLAN membership for the source, and/or the current active key, described below with reference to FIG. 7 .
At block 506, the server node 112 transmits a packet or associated data unit that includes a flowtag. Flowtags may include data related to, for example, destination ports, VLAN data, and/or other routing data described herein. The flowtag may include a generation ID or phase ID and/or credentials provided by the aggregation device 200 described in block 504 . The packet provided with the flow tag may be an Ethernet packet or the like.
At block 508, the packet management device 210 validates the flowtag and the received credential. The credential validation module 228 may validate the received credential against a copy generated at the ingress port, eg, by recalculating the credential, eg, by performing a one-way hash. . In one embodiment, the credential validation module 228 allows the guest to publish a descriptor pointing to the data buffer to the server node 112, and the server node 112 writes the descriptor back to the guest for reuse. It communicates with one or more virtual queues in the aggregation device 200 that allow it to be released. Here, the NIC and flow path of the requesting server node virtual machine may be established to move the flow tag and packet through the aggregation device 200 .
At block 510, once validation is complete, the flowtag content, such as the aggregation device egress port number, may be used to route the packet to its destination. The packet may be routed to the destination virtual queue 218 at the aggregation device 200 for data buffering, for example. In another embodiment, packets are routed directly to egress ports 1-N for output to destination server node 112 or a remote device.
6 is a diagram illustrating the content of a packet 600 output from a server node 112 to an aggregation device 200 , according to an embodiment .
The data unit 600 may be a packet, frame, cell, or the like. The data unit 600 includes a flow tag 602 , a header 604 , and a data payload 606 . The flow tag 602 may be the same as or similar to those described in accordance with embodiments herein. The header 604 may be an Ethernet header or the like, and may include preamble, source MAC address, destination MAC address, VLAN ID, and/or Ethernet type fields.
The flowtag 602 may include a port ID field, a credential field, and/or a generation ID field. The port ID field may include a destination port number. The port number in the Port ID field may be used to route the network packet 604 to the destination device. The credential field may include, for example, a credential generated by the aggregation device 200 according to the methods described herein and provided to the server node 112-1 during data exchange.
The generation ID field may contain a generation ID or port seed, which can be used to prevent snoopers from gathering information over time that would otherwise have weakened the hash. The generation ID allows the aggregation device 200 to maintain the state of the generated credential and allows the credential to be periodically recycled, for example by tracking the credential.
7 is a detailed block diagram illustrating a packet validation flow, according to one embodiment. In describing the packet validation flow, reference is made to the components of FIGS. 1 to 6 , in particular, the credential validation step described in block 508 of FIG. 5 .
The server node 112 transmits the packet 702 or the like to the aggregation device 200 . Packet 702 includes a flow tag 712 , an Ethernet header 714 , and a payload 716 . The flow tag 712 may be similar to the flow tag 602 described in FIG. 6 . In another embodiment, as shown in FIG. 7 , the flow tag 712 includes a key selection field 722 , a credential field 724 , and a VQ_DestTag field 726 .
The key selection field 722 contains a key selection value used by the circular key selector 704, also referred to as a generation ID (ID), to select a valid encryption key (key 0, key 1). The selected encryption key 734 may be used when a credential is generated that is compared to the credential 724 in the flowtag 712 during the validation process. The keys (key 0, key 1) may be stored in the aggregation device 200 and may be yes on a predetermined basis, to reduce the risk that an unauthorized party, such as a snooper, will subvert the mechanism for generating and validating credentials. For example, it may be cycled by the credential processing engine 226 every 4 seconds.
Credentials 724 may be generated and inserted into flowtag 712 according to embodiments described herein, eg, may be generated by credential processing engine 226 . Credentials 724 are in part used by credential processing engine 226 with data 740 received from incoming packet 702 , such as VLAN membership ID (VLAN_ID) 730 in Ethernet header 714 . Then, the validity is verified by the credential validity verification module 228 by re-calculating the credentials.
VQ_DestTag 726 relates to a virtual queue that identifies a destination device to receive packet data. The VQ_DestTag 726 may be generated by decoding the MMIO mailbox write address and data associated with storage of packet data in a buffer or the like at the aggregation device 200 for reception by the destination device.
Ethernet header 714 may include one or more fields known to those of skill in the art, such as preamble, source MAC address, destination MAC address, VLAN ID, and Ethernet type fields.
During a packet validation operation, credential validation module 228 generates a credential that is compared to credentials 724 of packet 702 . VQ_DestTag 726 and VLAN ID in Ethernet header 714 are cyclic key selector 232 to generate a credential that can be compared to credential 724 in received flow tag 702 to yield a validation result. ) outputted from VQ_SrcTag and key (key 0, key 1). If validation fails, then packets may be dropped, and a log of the results may be generated. If the validation passes, the packet processor may process the received data.
As will be appreciated by those skilled in the art, aspects of the invention may be embodied as a system, method, or computer program product. Accordingly, aspects of the present invention may be entirely hardware embodiments, entirely software embodiments (including firmware, resident software, micro-code, etc.) or otherwise generally referred to herein as "circuits," "modules," or "systems." It may take the form of an embodiment combining possible hardware and software aspects. Moreover, aspects of the invention may take the form of a computer program product embodied in one or more computer readable medium(s) embodied in computer readable program code.
Any combination of one or more computer readable medium(s) may be used. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus or device, or any suitable combination of the above. More specific examples (not an exhaustive list) of computer readable storage media will include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, RAM, ROM, IP. ROM (EPROM or flash memory), optical fiber, portable compact disk ROM (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above. In the context of this document, a computer-readable storage medium can be any tangible medium that can contain or store a program for use by or associated with an instruction execution system, apparatus, or device.
A computer readable signal medium may include a propagated data signal having computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take a variety of forms including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium that can communicate, propagate, or transmit a program for use by or associated with an instruction execution system, apparatus, or device. The program code embodied on a computer readable medium may be transmitted using any suitable medium including, but not limited to, wireless, wireline, fiber optic cable, RF, etc., or any suitable combination of the above.
The computer program code for performing the operations of aspects of the present invention may be implemented in an object-oriented programming language such as Java, Smalltalk, C++, or the like, and an idiomatic procedural programming language such as a "C" programming language or similar programming language. It may be written in any combination of one or more programming languages, including The program code may run entirely on the user's computer, partly on the user's computer, as a standalone software package, partly on the user's computer and partly on a remote computer or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be It can be done on an external computer (via the Internet you are using).
Aspects of the invention are described herein with reference to exemplary flowchart and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention. It will be understood that each block of the exemplary flowcharts and/or block diagrams, and combinations of blocks in the exemplary flowcharts and/or block diagrams, may be implemented by computer program instructions. These computer program instructions are such that the instructions, executable by the processor of a computer or other programmable data processing device, produce means for implementing the function/acts specified in the flowchart and/or block diagram block or blocks, such that the general purpose computer , a special purpose computer, or other programmable data processing device that produces the machine.
These computer program instructions are also capable of instructing a computer, such that the instructions stored on the computer readable medium produce an article of manufacture comprising instructions that implement the functions/acts specified in the flowchart and/or block diagram block or blocks. It may be stored on a computer readable medium, other programmable data processing apparatus, or other device that functions in a particular manner. These computer program instructions may also include a series of computational steps comprising: a computer; It may be loaded onto a computer, other programmable data processing apparatus, or other device for execution on another programmable apparatus or other device.
The flowchart and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products in accordance with various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of code comprising one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions recited in the blocks may occur out of the order recited in the figures. For example, two blocks shown in series may actually be executed substantially concurrently, and blocks may sometimes be executed in reverse order, depending on the functionality involved. Each block in the exemplary flowcharts and/or block diagrams, and combinations of blocks in the exemplary flowcharts and/or block diagrams, is a special-purpose hardware-based system, or combination of special-purpose hardware and computer instructions, that performs the specified function or action. can be implemented by
While the present invention has been shown and described with reference to specific embodiments, it should be understood by those skilled in the art that various changes in form and detail may be made therein without departing from the spirit and scope of the invention.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2023038387A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| KR1020090089456A | Cites | Republic of Korea | – |
| US20040258062A1 | Cites | United States of America | – |
10 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 13675401 | United States of America | – | |
| 201213675401 | United States of America | A | |
| 2013069572 | United States of America | W |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2014137215A1 | United States of America | A1 | |
| WO2014078271A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US8875256B2 | United States of America | B2 | |
| CN104769912A | China | A | |
| KR20150082282A | Republic of Korea | A | |
| EP2920940A1 | European Patent Office (EPO) | A1 | |
| JP2016502795A | Japan | A | |
| KR101688984B1This record | Republic of Korea | B1 | |
| CN104769912B | China | B | |
| EP2920940B1 | European Patent Office (EPO) | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-1688984
- Application
- 1020157011759
Titles4
- Korean
- 데이터 플로우 처리를 위한 방법 및 디바이스
- English
- METHOD AND DEVICE FOR DATA FLOW PROCESSING
- Unlabeled
- 데이터 플로우 처리를 위한 방법 및 디바이스{METHOD AND DEVICE FOR DATA FLOW PROCESSING}
- Unlabeled
- METHOD AND DEVICE FOR DATA FLOW PROCESSING
Classification
- CPC, 8
- H04L63/08
- H04L12/4641
- G06F13/4022
- H04L45/38
- H04L63/1466
- H04L63/06
- H04L63/123
- G06F2213/0026
- IPC, 5
- H04L29 06
- G06F13 40
- H04L12 46
- H04L12 721
- H04L45 50