IP Library Granted Patent US 12,273,264
Granted Patent B1
US 12,273,264 · App. 18/434,618 · Granted Apr 8, 2025

Maintaining processing core affinity for fragmented packets in network devices

Inventors: Dipankar Barman (Bangalore, IN); Chin Man Kim (Cupertino, CA)
Assignee: Juniper Networks, Inc.
H04L45/38H04L45/02H04L45/566H04L45/60H04L67/1023H04L2101/663
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,264
App. No.
18/434,618
Granted
Apr 8, 2025
Kind
B1
Abstract

Techniques are disclosed for maintaining processing unit core affinity for fragmented packets. In one example, a service physical interface card (PIC) implementing a service plane of a network device receives fragmented and/or non-fragmented packet data for a traffic flow. The service PIC comprises at least one processing unit comprising multiple cores. A routing engine operating in a control plane of the network device defines one or more core groups comprising a subset of the cores. The routing engine assigns the traffic flow to a core group and a forwarding engine operating in a forwarding plane of the network device forwards the packet data for the traffic flow to the assigned core group. A core of the assigned core group applies a network service to the fragmented and/or non-fragmented packet data for the traffic flow, and the forwarding engine forwards the packet data for the traffic flow toward a destination.

Claims (92)

1. A network device comprising:

processing circuitry in communication with storage media;

at least one service physical interface card (PIC) comprising at least one processing unit, wherein the at least one processing unit comprises a plurality of cores;

a forwarding engine executing on the processing circuitry, wherein the forwarding engine is configured to:

partially assemble fragmented packet data for traffic flows to obtain 5-tuple information for each of the respective traffic flows;

generate, from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

modify the fragmented packet data for the traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loopback the modified fragmented packet data for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows; and

a routing engine executing on the processing circuitry, wherein the routing engine is configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of the plurality of cores of the at least one processing unit of the at least one service PIC, the subset comprising at least the first core,

wherein, for each of the traffic flows, the first core of the core group to which the respective traffic flow is assigned is configured to apply a network service to the packets for the respective traffic flow, and

wherein, for each of the traffic flows, the forwarding engine is further configured to forward, after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

2. The network device of claim 1 ,

wherein the routing engine is configured to assign each of the respective traffic flows to the respective core group of the one or more core groups based at least in part on the 5-tuple information of the respective traffic flow.

3. The network device of claim 2 , wherein the 5-tuple information for each of the respective traffic flows comprises:

a source address;

a destination address;

one of a source port and destination port or a security port index (SPI); and

a protocol for the traffic flow.

4. The network device of claim 1 , wherein the first core of the core group comprises a 5-tuple core.

5. The network device of claim 1 ,

wherein the forwarding engine is configured to obtain, from an initial fragment of the fragmented packet data for the traffic flows, a core identifier for each of the corresponding traffic flows, and

wherein the routing engine is configured to assign each of the traffic flows to the respective core group of the one or more core groups based at least in part on the core identifier obtained for the corresponding traffic flow of the traffic flows.

6. The network device of claim 1 ,

wherein the forwarding engine is configured to obtain, for the fragmented packet data for the traffic flows, a non-fragmented route for each of the corresponding traffic flows, and

wherein the routing engine is configured to assign each of the traffic flows to the respective core group of the one or more core groups based at least in part on the non-fragmented route for the corresponding traffic flow of the traffic flows.

7. The network device of claim 1 , wherein the service PIC is configured to implement a service plane for the network device.

8. A network device comprising:

processing circuitry in communication with storage media;

at least one service physical interface card (PIC) comprising at least one processing unit, wherein the at least one processing unit comprises a plurality of cores;

a forwarding engine executing on the processing circuitry, wherein the forwarding engine is configured to:

obtain, from fragmented packet data for traffic flows, 5-tuple information for each of the respective traffic flows;

generate, from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

fully assemble the fragmented packet data for the traffic flows to obtain packets for each of the respective traffic flows;

modify the packets for each of the respective traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loopback the modified packets for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows; and

a routing engine executing on the processing circuitry, wherein the routing engine is configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of the plurality of cores of the at least one processing unit of the at least one service PIC, the subset comprising at least the first core,

wherein, for each of the traffic flows, the first core of the core group to which the respective traffic flow is assigned is configured to apply a network service to the packets for the respective traffic flow, and

wherein, for each of the traffic flows, the forwarding engine is further configured to forward, after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

9. The network device of claim 8 , wherein the routing engine is configured to assign each of the respective traffic flows to the respective core group of the one or more core groups based at least in part on 5-tuple information for each of the respective traffic flows.

10. A method comprising:

executing, by processing circuitry of a network device, a forwarding engine configured to:

partially assemble fragmented packet data for traffic flows to obtain 5-tuple information for each of the respective traffic flows;

generate, from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

modify the fragmented packet data for the traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loopback the modified fragmented packet data for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows;

executing, by the processing circuitry of the network device, a routing engine configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of a plurality of cores of at least one processing unit of at least one service physical interface card (PIC) of the network device, the subset comprising at least the first core;

applying, for each of the traffic flows and by the first core of the core group to which the respective traffic flow is assigned, a network service to the packets for the respective traffic flow, and

forwarding, for each of the traffic flows, by the forwarding engine, and after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

11. The method of claim 10 ,

wherein assigning each of the respective traffic flows to the respective core group of the one or more core groups is based at least in part on the 5-tuple information of the respective traffic flow.

12. The method of claim 11 , wherein the 5-tuple information for each of the respective traffic flows comprises:

a source address;

a destination address;

one of a source port and destination port or a security port index (SPI); and

a protocol for the traffic flow.

13. The method of claim 10 , wherein the first core of the core group comprises a 5-tuple core.

14. The method of claim 10 ,

wherein the method further comprises obtaining, by the forwarding engine, from an initial fragment of the fragmented packet data for the traffic flows, a core identifier for each of the corresponding traffic flows, and

wherein assigning each of the traffic flows to the respective core group of the one or more core groups is based at least in part on the core identifier obtained for the corresponding traffic flow of the traffic flows.

15. The method of claim 10 ,

wherein the method further comprises obtaining, by the forwarding engine and for the fragmented packet data for the traffic flows, a non-fragmented route for each of the corresponding traffic flows, and

wherein assigning each of the traffic flows to the respective core group of the one or more core groups is based at least in part on the non-fragmented route for the corresponding traffic flow of the traffic flows.

16. A method comprising:

executing, by processing circuitry of a network device, a forwarding engine configured to:

obtain, from fragmented packet data for traffic flows, 5-tuple information for each of the respective traffic flows;

generate from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

fully assemble the fragmented packet data for the traffic flows to obtain packets for each of the respective traffic flows;

modify the packets for each of the respective traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loop back the modified packets for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows;

executing, by the processing circuitry of the network device, a routing engine configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of a plurality of cores of at least one processing unit of at least one service physical interface card (PIC) of the network device, the subset comprising at least the first core;

applying, for each of the traffic flows and by the first core of the core group to which the respective traffic flow is assigned, a network service to the packets for the respective traffic flow, and

forwarding, for each of the traffic flows, by the forwarding engine, and after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

17. The method of claim 16 , wherein assigning each of the respective traffic flows to the respective core group of the one or more core groups is based at least in part on 5-tuple information for each of the respective traffic flows.

18. Non-transitory computer-readable media comprising instructions that, when executed, are configured to cause processing circuitry to:

execute a forwarding engine configured to:

partially assemble fragmented packet data for traffic flows to obtain 5-tuple information for each of the respective traffic flows;

generate, from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

modify the fragmented packet data for the traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loopback the modified fragmented packet data for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows; and

execute a routing engine configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of a plurality of cores of at least one processing unit of at least one service physical interface card (PIC) of a network device, the subset comprising at least the first core;

wherein the instructions are further configured to cause, for each of the traffic flows, the first core of the core group to which the respective traffic flow is assigned to apply a network service to the packets for the respective traffic flow, and

wherein, for each of the traffic flows, the forwarding engine is further configured to forward, after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

19. Non-transitory computer-readable media comprising instructions that, when executed, are configured to cause processing circuitry to:

execute a forwarding engine configured to:

obtain, from fragmented packet data for traffic flows, 5-tuple information for each of the respective traffic flows;

generate, from the 5-tuple information for each of the respective traffic flows, a 5-tuple hash for each of the respective traffic flows;

fully assemble the fragmented packet data for the traffic flows to obtain packets for each of the respective traffic flows;

modify the packets for each of the respective traffic flows to include metadata specifying the 5-tuple information and the 5-tuple hash for each of the respective traffic flows; and

loopback the modified packets for the traffic flows to the forwarding engine for forwarding to a first core of a core group, of one or more core groups, to which the respective traffic flow is assigned to obtain packets for the respective traffic flows;

execute a routing engine configured to assign each of the traffic flows to a respective core group of the one or more core groups, wherein each of the one or more core groups comprises a subset of a plurality of cores of at least one processing unit of at least one service physical interface card (PIC) of a network device, the subset comprising at least the first core;

wherein the instructions are further configured to cause, for each of the traffic flows, the first core of the core group to which the respective traffic flow is assigned to apply a network service to the packets for the respective traffic flow, and

wherein, for each of the traffic flows, the forwarding engine is further configured to forward, after application of the network service, the packets for the respective traffic flow toward a destination of the traffic flow.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded May 6, 2026
From: JUNIPER NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 075513/0034 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2025
From: BARMAN, DIPANKAR; KIM, CHIN MAN
To: JUNIPER NETWORKS, INC.
Reel/Frame 072889/0038 →
Continuity (2)
Continuation 18169696 · Feb 15, 2023
Continuation 17105008 · Nov 25, 2020
References Cited (16)
US 8743907B1 · Kadosh · 2014 [cited by examiner]
US 11621914B2 · Barman et al. · 2023 [cited by applicant]
US 20040243718A1 · Fujiyoshi · 2004 [cited by applicant]
US 20050038793A1 · Romano et al. · 2005 [cited by applicant]
US 20050053054A1 · Das et al. · 2005 [cited by applicant]
US 20060198375A1 · Baik · 2006 [cited by applicant]
US 20080216150A1 · Brabson · 2008 [cited by applicant]
US 20100284404A1 · Gopinath et al. · 2010 [cited by applicant]
US 20120266181A1 · Carney · 2012 [cited by applicant]
US 20140126577A1 · Post et al. · 2014 [cited by applicant]
US 20220166709A1 · Barman et al. · 2022 [cited by applicant]
Kent et al., “Security Architecture for the Internet Protocol,” RFC 4301, Network Working Group, Dec. 2005, 101 pp. [cited by applicant]
O-Heung Chung, Jae-Deok Lirn, Seung-Ho Ryu, Young-Ho Kirn and Ki-Young Kirn, “Fragment packet partial re-assembly method for intrusion detection,” 2006 8th International Conference Advanced Communication Technology, Pho… [cited by applicant]
Prosecution History from U.S. Appl. No. 17/105,008, dated Aug. 2, 2022 through Nov. 30, 2022, 50 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 18/169,696, dated Apr. 11, 2023 through Nov. 14, 2023, 58 pp. [cited by applicant]
U.S. Appl. No. 18/169,696, filed Feb. 15, 2023, by Barman et al. [cited by applicant]