IP Library Granted Patent US 12,375,372
Granted Patent B2
US 12,375,372 · App. 17/842,626 · Granted Jul 29, 2025

Zero-copy forwarding for network function virtualization

Inventors: Amnon Ilan (Raanana, IL); Michael Tsirkin (Yokneam Illit, IL)
Assignee: Red Hat, Inc.
H04L43/028H04L43/04H04L63/0236H04L63/0263H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,372
App. No.
17/842,626
Granted
Jul 29, 2025
Kind
B2
Abstract

Systems and methods for zero-copy forwarding for network function virtualization (NFV). An example method comprises: receiving, by a supervisor of a host computer system, a definition of a packet filter originated by a virtual execution environment running on the host computer system; responsive to validating the packet filter, associating the packet filter with a vNIC of the virtual execution environment; receiving, by the supervisor, a network packet originated by the vNIC; and responsive to matching the network packet to a network connection specified by the packet filter, causing the packet filter to forward the network packet via the network connection.

Claims (49)

1. A method, comprising:

receiving, by a supervisor of a virtual execution environment running on a host computer system, a definition of a packet filter originated by the virtual execution environment running on the host computer system;

responsive to validating the packet filter, associating the packet filter with a virtual network interface card (vNIC) of the virtual execution environment;

receiving, by the supervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application, causing the packet filter to bypass the proxy application by forwarding the first network packet via the network connection, wherein the proxy application runs within one of: the virtual execution environment running on the host computer system, a privileged execution environment running on the host computer system, or a non-privileged execution environment running on the host computer system, or the proxy application runs on another host computer system;

receiving, by the supervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, causing the proxy application to create a new network connection to a destination specified by the second network packet.

2. The method of claim 1 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

3. The method of claim 1 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

4. The method of claim 3 , wherein the link layer parameter is at least one of: a protocol, a destination address, or a port.

5. The method of claim 1 , wherein the packet filter is a Berkley Packet filter (BPF).

6. The method of claim 1 , further comprising:

responsive to receiving an incoming network packet via the network connection, forwarding the incoming network packet to the vNIC.

7. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter are not mutually-exclusive.

8. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter do not specify an infinite loop.

9. The method of claim 1 , wherein validating the packet filter further comprises:

ascertaining that two or more rules encoded by the definition of the packet filter do not specify an infinite recursion.

10. A computer system, comprising:

a memory; and

a processing device, coupled to the memory, to:

receive, by a supervisor of a virtual execution environment running on the computer system, a definition of a packet filter originated by a virtual execution environment running on the computer system;

responsive to validating the packet filter, associate the packet filter with the virtual network interface card (vNIC) of the virtual execution environment;

receive, by the supervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application, cause the packet filter to bypass the proxy application by forwarding the first network packet via the network connection, wherein the proxy application runs within one of: the virtual execution environment running on the host computer system, a privileged execution environment running on the host computer system, or a non-privileged execution environment running on the host computer system, or the proxy application runs on another host computer system;

receive, by the supervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, cause a proxy application to create a new network connection to a destination specified by the second network packet.

11. The computer system of claim 10 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

12. The computer system of claim 10 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

13. The computer system of claim 12 , wherein the packet filter is a Berkley Packet filter (BPF).

14. A non-transitory computer-readable storage medium comprising executable instructions that, when executed by a host computer system, cause the host computer system to:

receive, by a supervisor of a virtual execution environment running on the host computer system, a definition of a packet filter originated by a virtual execution environment running on the host computer system;

responsive to validating the packet filter, associate the packet filter with the virtual network interface card (vNIC) of the virtual execution environment;

receive, by the supervisor, a first network packet originated by the vNIC;

responsive to matching, by the packet filter, the first network packet to a network connection maintained by a proxy application, cause the packet filter to bypass the proxy application by forwarding the first network packet via the network connection, wherein the proxy application runs within one of: the virtual execution environment running on the host computer system, a privileged execution environment running on the host computer system, or a non-privileged execution environment running on the host computer system, or the proxy application runs on another host computer system;

receive, by the supervisor, a second network packet originated by the vNIC; and

responsive to failing to match the second network packet to the packet filter, cause a proxy application to create a new network connection to a destination specified by the second network packet.

15. The non-transitory computer-readable storage medium of claim 14 , wherein forwarding the first network packet further comprises:

substituting a source address of the first network packet with a source address of a network interface card (NIC) associated with the network connection.

16. The non-transitory computer-readable storage medium of claim 14 , wherein matching the first network packet to the network connection specified by the packet filter further comprises:

matching a link layer parameter specified by the first network packet to a corresponding network link layer parameter associated with the network connection.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the link layer parameter is at least one of: a protocol, a destination address, or a port.

18. The non-transitory computer-readable storage medium of claim 14 , further comprising executable instructions that, when executed by the host computer system, cause the host computer system to:

responsive to receiving an incoming network packet via the network connection, forwarding the incoming network packet to the vNIC.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2022
From: ILAN, AMNON; TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 060234/0191 →
Continuity (2)
Continuation In Part 16686362 · Nov 18, 2019
Related Publication 20220321433A1 · Oct 6, 2022
References Cited (24)
US 6801927B1 · Smith et al. · 2004 [cited by applicant]
US 7792021B1 · Pankajakshan · 2010 [cited by applicant]
US 8893113B1 · Nguyen · 2014 [cited by applicant]
US 9043811B2 · Radhakrishnan et al. · 2015 [cited by applicant]
US 10230608B2 · Tsirkin · 2019 [cited by applicant]
US 10248447B2 · Leitner · 2019 [cited by applicant]
US 10331468B2 · Gray · 2019 [cited by applicant]
US 10397044B2 · Chu et al. · 2019 [cited by applicant]
US 20070204337A1 · Schnackenberg et al. · 2007 [cited by applicant]
US 20100280999A1 · Atluri et al. · 2010 [cited by applicant]
US 20130111474A1 · Agarwal · 2013 [cited by examiner]
US 20170126797A1 · Frid · 2017 [cited by applicant]
US 20180063000A1 · Wu · 2018 [cited by examiner]
US 20180239715A1 · Tsirkin et al. · 2018 [cited by applicant]
US 20200053050A1 · Malysh · 2020 [cited by examiner]
US 20200092790A1 · Salkintzis · 2020 [cited by examiner]
US 20200319907A1 · Jain · 2020 [cited by applicant]
US 20210029083A1 · Li et al. · 2021 [cited by applicant]
Sun, Chen et al, Tsinghua University; Clemson University, “NFP: Enabling Network Function Parallelism in NFV”, hittps://par.nsf.gov/servlets/purl/10073026, Aug. 21-25, 2017, 14 pages. [cited by applicant]
Kawashima, Ryota, Matsuo, Hiroshi, Department of Computer Science and Engineering Nagoya Institute of Technology; Japan, “OVTee: A Fast and Pragmatic Software-based Zero-copy/Pass-through Mechanism for NFV-nodes”, https… [cited by applicant]
USPTO, Office Action for U.S. Appl. No. 16/686,362, mailed Aug. 4, 2021. [cited by applicant]
USPTO, Final Office Action for U.S. Appl. No. 16/686,362, mailed Nov. 26, 2021. [cited by applicant]
USPTO, Advisory Action for U.S. Appl. No. 16/686,362, mailed Feb. 4, 2022. [cited by applicant]
UPTO, Notice of Allowance for U.S. Appl. No. 16/686,362, mailed Mar. 8, 2022. [cited by applicant]