IP Library Granted Patent US 10,491,521
Granted Patent B2
US 10,491,521 · App. 15/469,530 · Granted Nov 26, 2019

Field checking based caching of ACL lookups to ease ACL lookup search

Inventors: Gil Levy (Hod Hasharon, IL); Pedro Reviriego (Madrid, ES); Salvatore Pontarelli (Rome, IT); Aviv Kfir (Nili, IL)
Assignee: Mellanox Technologies TLV Ltd.
H04L45/7453H04L45/748H04L45/7457
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,491,521
App. No.
15/469,530
Granted
Nov 26, 2019
Kind
B2
Abstract

In a network element cache operation is enhanced by extracting a set of fields from a packet, constructing a hash key from the extracted fields, and identifying a subset of the fields, wherein the field values thereof fail to exist in a set of classification rules. The hash key by is modified by masking the subset of the extracted fields. A hash lookup is performed using the modified hash key in a cache memory that stores a portion of the classification rules. The packet is processed responsively to the lookup.

Claims (36)

1. A method, comprising the steps of:

storing a plurality of classification rules

storing a hash table in a cache memory, the hash table having entries comprising rule patterns that correspond to a portion of the classification rules;

extracting a set of fields from a packet received via a data network, the fields having respective field values;

constructing a hash key from the extracted fields; and

identifying a subset of the extracted fields, wherein when the field values of the subset of the extracted fields fail to exist in the classification rules performing the steps of:

modifying the hash key by masking the subset of the extracted fields;

identifying one of the entries using the modified hash key to perform a hash lookup to the hash table; and

transmitting the packet in accordance with the classification rule that corresponds to the rule pattern of the identified entry.

2. The method according to claim 1 , wherein constructing a hash key comprises generating a concatenation of the extracted fields.

3. The method according to claim 1 , wherein constructing a hash key further comprises:

adding a bit to each of the extracted fields; and

setting the bit to a predetermined value only in the extracted fields of the subset.

4. The method according to claim 1 , wherein one of the fields and at least a portion of the classification rules comprise respective internet protocol addresses, and identifying a subset comprises finding a longest prefix match between the internet protocol address of the one field and the internet protocol address of one of the classification rules.

5. The method according to claim 4 , wherein finding a longest prefix match is performed using a ternary content addressable memory (TCAM) that returns a length of a mask that can be used for caching.

6. The method according to claim 1 , wherein identifying a subset is performed using a Bloom filter.

7. An apparatus, comprising:

a network element, operative for receiving packets via a data network;

a processor in the network element;

a main memory storing a plurality of classification rules; and

a cache memory accessible to the processor, the cache memory storing a hash table, the hash table having entries comprising rule patterns that correspond to a portion of the classification rules, wherein the processor is operative for performing the steps of:

extracting a set of fields from a packet received via the data network, the fields having respective field values;

constructing a hash key from the extracted fields; and

identifying a subset of the extracted fields, wherein when the field values of the subset of the extracted fields fail to exist in the classification rules performing the steps of:

modifying the hash key by masking the subset of the extracted fields; and

identifying one of the entries using the modified hash key to perform a hash lookup to the hash table; and

transmitting the packet from the network element in accordance with the classification rule that corresponds to the rule pattern of the identified entry.

8. The apparatus according to claim 7 , wherein constructing a hash key comprises generating a concatenation of the extracted fields.

9. The apparatus according to claim 7 , wherein constructing a hash key further comprises:

adding a bit to each of the extracted fields; and

setting the bit to a predetermined value only in the extracted fields of the subset.

10. The apparatus according to claim 7 , wherein one of the fields and at least a portion of the classification rules comprise respective internet protocol addresses, and identifying a subset comprises finding a longest prefix match between the internet protocol address of the one field and the internet protocol address of one of the classification rules.

11. The apparatus according to claim 10 , wherein finding a longest prefix match is performed using a ternary content addressable memory (TCAM) that returns a length of a mask that can be used for caching.

12. The apparatus according to claim 7 , wherein identifying a subset is performed using a Bloom filter.

13. The method according to claim 1 , wherein identifying one of the entries is by performing a single hash lookup.

14. The apparatus according to claim 7 , wherein identifying one of the entries is by performing a single hash lookup.

Assignments (2)
MERGER Recorded Dec 15, 2021
From: MELLANOX TECHNOLOGIES TLV LTD.
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 058517/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2017
From: LEVY, GIL; REVIRIEGO, PEDRO; PONTARELLI, SALVATORE; KFIR, AVIV
To: MELLANOX TECHNOLOGIES TLV LTD.
Reel/Frame 041745/0829 →