Network protocol reassembly accelaration
Abstract
Methods and systems are provided for network protocol reassembly acceleration. According to one embodiment, an incoming packet is received at a network interface. Payload data from the packet is written by a memory interface to a physical page within a system memory on behalf of the network interface based on a sequence number associated with the incoming packet and by obtaining a physical address from a virtual memory map corresponding to an incoming session with which the packet is associated. After the physical page is full, the physical page is made accessible to a user process being executed by a processor associated with the system memory by remapping the physical page through a paging table used by the user process.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving an incoming packet at a network interface; a memory interface writing payload data from the packet to a physical page within a system memory on behalf of the network interface based on a sequence number associated with the incoming packet and by obtaining a physical address from a virtual memory map corresponding to an incoming session with which the packet is associated; and after the physical page is full, making the physical page accessible to a user process being executed by a processor associated with the system memory by remapping the physical page through a paging table used by the user process.
2 . The method of claim 1 , wherein the incoming packet comprises a TCP packet and the incoming session comprises an incoming TCP session.
3 . The method of claim 2 , further comprising a network interface driver being executed by the processor allocating one or more physical pages of the system memory for each of a plurality of incoming TCP sessions, including the incoming TCP session.
4 . The method of claim 3 , further comprising the network interface driver building virtual memory maps, including the virtual memory map, corresponding to the plurality of incoming TCP sessions.
5 . The method of claim 4 , further comprising the network interface driver building a session table including information regarding a page directory base address for each of the plurality of incoming TCP sessions and information regarding an offset to adjust a start address of the payload data with respect to a boundary of the physical page.
6 . The method of claim 5 , further comprising:
calculating an adjusted sequence number based on the sequence number and the offset; and using the adjusted sequence number as a virtual address input to the virtual memory map.
7 . The method of claim 2 , further comprising, prior to the memory interface writing payload data from the TCP packet to the physical page, determining whether the physical page has been allocated.
8 . A network device comprising:
a processor configured to execute one or more user processes and a network interface driver; a system memory, coupled to the processor, having stored therein (i) a paging table used by the processor to translate virtual memory addresses into corresponding physical memory addresses and (ii) a plurality of virtual memory maps containing information for use in connection with translating a virtual address input based on a sequence number of an incoming Transmission Control Protocol (TCP) packet to a physical address; a network interface operable to receive incoming TCP packets; an interconnect bus coupled to the processor and the system memory; and a bus/memory interface, coupled to the network interface and the interconnect bus, adapted to write payload data from the incoming TCP packet to a physical page within the system memory on behalf of the network interface based on the sequence number and a virtual memory map of the plurality of virtual memory maps corresponding to an incoming TCP session with which the TCP packet is associated; and wherein the network interface driver makes the physical page accessible to a user process of the one or more user processes by remapping the physical page through the paging table.
9 . The network device of claim 8 , wherein the network interface driver is further configured to allocate one or more physical pages of the system memory for each of the plurality of incoming TCP sessions.
10 . The network device of claim 9 , wherein the network interface driver is further configured to create and maintain the plurality of virtual memory maps.
11 . The network device of claim 10 , wherein the network interface driver is further configured to build a session table within the system memory including information regarding a page directory base address for each of the plurality of incoming TCP sessions and information regarding an offset to adjust a start address of the payload data with respect to a boundary of the physical page.
12 . The network device of claim 11 , wherein the virtual address is determined by calculating an adjusted sequence number based on the sequence number and the offset.
13 . The network device of claim 8 , wherein the network device comprises a network security platform.
14 . The network device of claim 8 , wherein the user process performs one or more security functions.
15 . The network device of claim 14 , wherein the one or more security functions include one or more of antivirus scanning, spam detection, web filtering, firewalling, intrusion detection, intrusion prevention and virtual private network (VPN) services.
16 . A program storage device readable by one or more processors of a network device, tangibly embodying a program of instructions executable by the one or more processors to perform method steps for performing Transmission Control Protocol (TCP) reassembly, the method comprising:
receiving an incoming TCP packet at a network interface of the network device; writing payload data from the TCP packet to a physical page within a system memory based on a sequence number associated with the incoming TCP packet and by obtaining a physical address from a virtual memory map corresponding to an incoming TCP session with which the TCP packet is associated; and after the physical page is full, making the physical page accessible to a user process being executed by a processor associated with the system memory by remapping the physical page through a paging table used by the processor.
17 . The program storage device of claim 16 , wherein the user process performs one or more security functions.
18 . The program storage device of claim 17 , wherein the one or more security functions include one or more of antivirus scanning, spam detection, web filtering, firewalling, intrusion detection, intrusion prevention and virtual private network (VPN) services.Join the waitlist — get patent alerts
Track US2009307363A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.