EFFICIENT PACKET HANDLING, REDIRECTION, AND INSPECTION USING OFFLOAD PROCESSORS
Method for handling packets are disclosed that can include providing at least one main processor connected to a plurality of offload processors by a memory bus; providing an arbiter connected to each of the plurality of offload processors, the arbiter capable of scheduling resource priority for instructions or data received from the memory bus; configuring the offload processors to provide security related services on packets prior to redirection to the main processor; operating a virtual switch respectively connected to the main processor and the plurality of offload processors using the memory bus, with the virtual switch capable of receiving memory read/write data over the memory bus; and directing at least some memory read/write data to the arbiter from the virtual switch.
1 . A method for handling packets, comprising the steps of:
providing at least one main processor connected to a plurality of offload processors by a memory bus;
providing an arbiter connected to each of the plurality of offload processors, the arbiter capable of scheduling resource priority for instructions or data received from the memory bus;
configuring the offload processors to provide security related services on packets prior to redirection to the main processor;
operating a virtual switch respectively connected to the main processor and the plurality of offload processors using the memory bus, with the virtual switch capable of receiving memory read/write data over the memory bus; and
directing at least some memory read/write data to the arbiter from the virtual switch.
2 . The method for handling packets of claim 1 , wherein the offload processors provide support for signature detection by an intrusion prevention system.
3 . The method for handling packets of claim 1 , wherein the offload processors provide support for encryption/decryption.
4 . The method for handling packets of claim 1 , further comprising a network interface card with single root IO virtualization (SR-IOV), to receive the packets and direct packets to one of the offload processors acting as a virtual switch, with packets being passed to the offload processor by the virtual switch and an input-out memory management unit (IOMMU).
5 . The method for handling packets of claim 1 , wherein the offload processors are connected to memory, and further include a snoop control unit for coherent read out and write in to memory.
6 . The method for handling packets of claim 1 , wherein the offload processors are connected to memory to permit zero-overhead context switching between threads of a networked application.
7 . The method for handling packets of claim 1 , wherein the offload processors are connected to memory and a computational FPGA, all being mounted together on XIMM module configured for insertion into a DIMM socket.