Method and architecture for a scalable application and security switch using multi-level load balancing
Abstract
A switch architecture and method provides scaling through multi-level load balancing of flows across data and application processing planes. An input/output module receives a communication session flow (forward) from a client device and selects one of a plurality of data processors to process the flow. The selected data processor determines the level of processing for the forward flow and selects an application processor from a plurality of such application processors. The application processor generates a session structure identifying actions to be performed on the forward flow and transfers the session structure to the selected data processor to perform the actions on the forward flow. The application processor also predictively generates and offloads a session structure for the associated reverse flow. If the reverse session structure is offloaded to a different data processor, either the forward or reverse flow redirects packets, or is redirected, to the data processor hosting the other flow.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of operating an application switch, the method comprising:
at an I/O interface: receiving packets in a forward flow at the I/O interface; selecting one of a plurality of data processors to process the forward flow in accordance with a data processor load balancing algorithm; and transferring the forward flow to the data processor selected to process the forward flow; at the selected data processor: determining from the forward flow a level of application processing needed for the forward flow; selecting one of a plurality of application processors to process the forward flow in accordance with an application processor load balancing algorithm; and transferring the forward flow to the application processor selected for processing the forward flow; at the selected application processor: generating a forward session structure for the forward flow that identifies one or more actions to be performed on the forward flow; and providing the forward session structure to the selected data processor; and at the selected data processor, processing the forward flow in accordance with the forward session structure.
2 . The method of claim 1 , wherein selecting one of a plurality of data processors to process the forward flow according to a data processor load balancing algorithm comprises selecting one of the plurality of data processors based at least in part on source/destination information in the forward flow.
3 . The method of claim 1 , comprising:
the at least one I/O interface selecting one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm; the selected application processor generating a reverse session structure for the reverse flow that identifies one or more actions to be performed on the reverse flow, and providing the reverse session structure to the data processor selected to process the reverse flow; and the selected data processor processing the reverse flow in accordance with the reverse session structure.
4 . The method of claim 3 , wherein selecting one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm comprises selecting the data processor based at least in part on source/destination information related to the forward flow.
5 . The method of claim 1 , wherein:
at least one I/O interface redirecting the reverse flow to the data processor selected to process the forward flow; and the selected data processor processing the reverse flow in accordance with the forward session structure.
6 . The method of claim 1 , comprising the at least one I/O interface predictively providing a reverse flow associated with the forward flow to one of the plurality of data processors for processing.
7 . An application switch comprising:
at least one I/O interface configured to receive packets in a forward flow; a plurality of data processors communicatively coupled to the at least one I/O interface and configured for processing packets received from the I/O interface; and a plurality of application processors communicatively coupled to the plurality of data processors and configured for processing packets received from the data processors; the at least one I/O processor being further configured:
to select one of the plurality of data processors to process the forward flow in accordance with a data processor load balancing algorithm; and
to transfer the forward flow to the data processor selected to process the forward flow;
the selected data processor being further configured:
to determine from the forward flow a level of application processing needed for the forward flow;
to select one of a plurality of application processors to process the forward flow in accordance with an application processor load balancing algorithm and based at least in part on level of application processing needed for the forward flow; and
to transfer the forward flow to the application processor selected for processing the forward flow;
the selected application processor being further configured:
to generate a forward session structure for the forward flow that identifies one or more actions to be performed on the forward flow; and
to provide the forward session structure to the selected data processor; and
the selected data processor being further configured to process the forward flow in accordance with the forward session structure.
8 . The application switch of claim 7 , wherein the I/O interface is configured to select one of a plurality of data processors to process the forward flow according to a data processor load balancing algorithm by selecting one of the plurality of data processors based at least in part on source/destination information in the forward flow.
9 . The application switch of claim 7 , wherein:
the at least one I/O interface is configured to select one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm; the selected application processor is configured to generate a reverse session structure for the reverse flow that identifies one or more actions to be performed on the reverse flow, and to providing the reverse session structure to the data processor selected to process the reverse flow; and the selected data processor is configured to process the reverse flow in accordance with the reverse session structure.
10 . The application switch of claim 9 , wherein the the at least one I/O interface is configured to select one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm by selecting one of the data processors based at least in part on source/destination information related to the forward flow.
11 . The application switch of claim 7 , wherein:
the at least one I/O interface is configured to redirect the reverse flow to the data processor selected to process the forward flow; and the selected data processor is configured to process the reverse flow in accordance with the forward session structure.
12 . The application switch of claim 7 , wherein the at least one I/O interface is configured to predictively providing a reverse flow associated with the forward flow to one of the plurality of data processors for processing.
13 . A computer program embodied on a non-transitory computer readable medium and configured to be executed by a processor, the computer program comprising computer readable program code for:
receiving a forward flow of a communication session from a source device; selecting one of a plurality of data processors to process the forward flow according to a data processor load balancing algorithm; transferring the forward flow to the data processor selected to process the forward flow; determining from the forward flow a level of application processing needed for the forward flow; selecting one of a plurality of application processors to process the forward flow in accordance with an application processor load balancing algorithm and based at least in part on level of application processing needed for the forward flow; transferring the forward flow to the application processor selected for processing the forward flow; generating a forward session structure for the forward flow that identifies one or more actions to be performed on the forward flow; and providing the forward session structure to the selected data processor and processing the forward flow in accordance therewith.
14 . The computer program of claim 13 , wherein the program code for selecting one of a plurality of data processors to process the forward flow according to a data processor load balancing algorithm comprises program code for selecting one of the plurality of data processors based at least in part on source/destination information in the forward flow.
15 . The computer program of claim 13 , further comprising computer readable program code for:
selecting one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm; generating a reverse session structure for the reverse flow that identifies one or more actions to be performed on the reverse flow; and providing the reverse session structure to the data processor selected to process the reverse flow and processing the reverse flow in accordance therewith.
16 . The computer program of claim 13 wherein the computer program code for selecting one of the plurality of data processors to process a reverse flow in accordance with the data processor load balancing algorithm comprises computer program code for selecting one of the plurality of data processors based at least in part on source/destination information related to the forward flow.
17 . The computer program of claim 13 , further comprising computer readable program code for redirecting the reverse flow to the data processor selected to process the forward flow and processing the reverse flow in accordance with the forward session structure.
18 . The computer program of claim 13 , further comprising computer readable program code for predictively providing a reverse flow associated with the forward flow to one of the plurality of data processors for processing.Join the waitlist — get patent alerts
Track US2014016465A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.