IP Library Granted Patent US 11,394,786
Granted Patent B2
US 11,394,786 · App. 16/686,362 · Granted Jul 19, 2022

Zero-copy forwarding for network function virtualization

Inventors: Amnon Ilan (Raanana, IL); Michael Tsirkin (Lexington, MA)
Assignee: Red Hat, Inc.
H04L67/141G06F9/45558H04L45/72H04L61/2007H04L67/28G06F2009/45595H04L61/6022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,394,786
App. No.
16/686,362
Granted
Jul 19, 2022
Kind
B2
Abstract

Systems and methods for zero-copy forwarding for network function virtualization (NFV). An example method comprises: receiving, by a hypervisor of a host computer system, a definition of a packet filter originated by a virtual machine running on the host computer system; responsive to validating the packet filter, associating the packet filter with a vNIC of the virtual machine; receiving, by the hypervisor, a network packet originated by the vNIC; and responsive to matching the network packet to a network connection specified by the packet filter, causing the packet filter to forward the network packet via the network connection.

Claims (52)

1. A method, comprising:

receiving, by a hypervisor of a host computer system, a definition of a packet filter originated by a virtual machine running on the host computer system;

responsive to validating the packet filter, associating the packet filter with a virtual network interface card (vNIC) of the virtual machine;

receiving, by the hypervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application running on the host computer system, causing the packet filter to bypass the proxy application by forwarding the first network packet via the network connection;

receiving, by the hypervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, causing the proxy application to create a new network connection to a destination specified by the second network packet.

2. The method of claim 1 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

3. The method of claim 1 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

4. The method of claim 3 , wherein the link layer parameter is at least one of: a protocol, a destination address, or a port.

5. The method of claim 1 , wherein the packet filter is a Berkley Packet filter (BPF).

6. The method of claim 1 , further comprising:

responsive to receiving an incoming network packet via the network connection, forwarding the incoming network packet to the vNIC.

7. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter are not mutually-exclusive.

8. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter do not specify an infinite loop.

9. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter do not specify an infinite recursion.

10. A computer system, comprising:

a memory; and

a processing device, coupled to the memory, to:

receive, by a hypervisor, a definition of a packet filter originated by a virtual machine running on the computer system;

responsive to validating the packet filter, associate the packet filter with a virtual network interface card (vNIC) of the virtual machine;

receive, by the hypervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application running on the computer system, cause the packet filter to bypass the proxy application by forwarding the first network packet via the network connection;

receive, by the hypervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, cause a proxy application running on the computer system to create a new network connection to a destination specified by the second network packet.

11. The computer system of claim 10 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

12. The computer system of claim 10 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

13. The computer system of claim 12 , wherein the link layer parameter is at least one of: a protocol, a destination address, or a port.

14. The computer system of claim 10 , wherein the packet filter is a Berkley Packet filter (BPF).

15. The computer system of claim 10 , wherein the processing device is further to:

responsive to receiving an incoming network packet via the network connection, forward the incoming network packet to the vNIC.

16. A non-transitory computer-readable storage medium comprising executable instructions that, when executed by a host computer system, cause the host computer system to:

receive, by a hypervisor, a definition of a packet filter originated by a virtual machine running on the host computer system;

responsive to validating the packet filter, associate the packet filter with a virtual network interface card (vNIC) of the virtual machine;

receive, by the hypervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application running on the host computer system, cause the packet filter to bypass the proxy application by forwarding the first network packet via the network connection;

receive, by the hypervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, cause a proxy application running on the host computer system to create a new network connection to a destination specified by the second network packet.

17. The non-transitory computer-readable storage medium of claim 16 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

18. The non-transitory computer-readable storage medium of claim 16 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the link layer parameter is at least one of: a protocol, a destination address, or a port.

20. The non-transitory computer-readable storage medium of claim 16 , further comprising executable instructions that, when executed by the host computer system, cause the host computer system to:

responsive to receiving an incoming network packet via the network connection, forwarding the incoming network packet to the vNIC.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2019
From: ILAN, AMNON; TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 051040/0116 →
Continuity (1)
Related Publication 20210152642A1 · May 20, 2021