IP Library › Granted Patent US 11,941,427
Granted Patent B2
US 11,941,427 · App. 18/311,693 · Granted Mar 26, 2024

Frameworks and interfaces for offload device-based packet processing

Inventors: Pradeep Vincent (Kenmore, WA); Matthew David Klein (Seattle, WA); Samuel James McKelvie (Seattle, WA)
Assignee: Amazon Technologies, Inc.
G06F9/45558H04L12/4633H04L41/082H04L45/74H04L63/0272H04L63/20G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,941,427
App. No.
18/311,693
Granted
Mar 26, 2024
Kind
B2
Abstract

A network device can include packet processing circuitry to provide support for virtual functions. The packet processing circuitry can perform operations such as receiving data traffic associated with a physical address, determining that the data traffic is associated with a guest of a host system by matching the data traffic with an ingress rule associated with a virtual function, and forwarding the data traffic to the virtual function.

Claims (28)

1. A peripheral device comprising:

processing circuitry; and

a memory storing instructions that, when executed by the processing circuitry, cause the peripheral device to perform operations including:

receiving data traffic associated with a physical address;

determining that the data traffic is associated with a guest of a host system by matching the data traffic with an ingress rule associated with a virtual function; and

forwarding the data traffic to the virtual function.

2. The peripheral device of claim 1 , wherein the ingress rule includes matching an opaque field in packet headers of the data traffic.

3. The peripheral device of claim 2 , wherein the opaque field contains a flow identifier.

4. The peripheral device of claim 1 , wherein matching the data traffic includes performing a 6-tuple comparison.

5. The peripheral device of claim 1 , wherein packets of the data traffic associated with the guest include a virtual internet protocol (IP) address in a virtual machine address space of the guest.

6. The peripheral device of claim 5 , wherein the virtual IP address is provided as encoded information in a subset of the packets.

7. The peripheral device of claim 6 , wherein the operations include reconstructing the virtual IP address from the encoded information provided in the subset of the packets.

8. The peripheral device of claim 6 , wherein the packets are segmented packets, and the encoded information is provided adjacent to segmentation boundaries of a subset of the segmented packets.

9. The peripheral device of claim 8 , wherein the operations include performing a de-segmentation process to form a larger packet from multiple segmented packets.

10. The peripheral device of claim 5 , wherein the virtual IP address is provided in a transmission control protocol (TCP) options field.

11. The peripheral device of claim 1 , wherein the operations further include maintaining a packet count and a byte count for packets matching the ingress rule.

12. The peripheral device of claim 1 , wherein the ingress rule is maintained by a trusted domain.

13. The peripheral device of claim 10 , wherein the peripheral device provides a debug mode that forces packets matching the ingress rule to be sent to a trusted domain.

14. The peripheral device of claim 10 , wherein the operations further include:

receiving egress packets;

determining that the egress packets match an egress rule; and

encapsulating the egress packets according to the egress rule.

15. The peripheral device of claim 14 , wherein the egress rule includes matching a source media access control (MAC) address assigned to a virtual machine.

16. The peripheral device of claim 14 , wherein the egress rule includes matching a source IP address.

17. The peripheral device of claim 14 , wherein the egress rule includes matching a destination MAC address against a list of allowable destination MAC addresses.

18. The peripheral device of claim 14 , wherein the operations further include segmenting the egress packets.

19. The peripheral device of claim 18 , wherein the operations further include inserting an opaque field into each of the segmented egress packets.

20. The peripheral device of claim 1 , wherein the peripheral device is controlled by a trusted domain that enforces a maximum transmission unit set by the trusted domain over a maximum transmission unit setting configured by the guest.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2023
From: VINCENT, PRADEEP; KLEIN, MATTHEW DAVID; MCKELVIE, SAMUEL JAMES
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 063524/0811 →
Continuity (7)
Continuation 17445080 · Aug 13, 2021
Continuation 16789337 · Feb 12, 2020
Continuation 15904236 · Feb 23, 2018
Continuation 14923276 · Oct 26, 2015
Continuation 14321492 · Jul 1, 2014
Continuation 13076347 · Mar 30, 2011
Related Publication 20230273809A1 · Aug 31, 2023
Cited By (1)
US 12,210,896