Tunnel Acceleration for Wireless Access Points
Abstract
A method and system for network offloading includes receiving a packet at a communication interface of a wireless access point and processing the packet at a flow acceleration processor prior to processing the packet at a host processor. The flow acceleration processor may process the packet for header checking or security processing. The flow acceleration processor may provide the packet to a security coprocessor for security processing. The flow acceleration processor may generate a result code indicating whether the processing at the flow acceleration processor was successful. If the processing was unsuccessful, the packet is provided to the host processor for exception processing.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
flow acceleration circuity configured to:
receive a packet for flow acceleration processing;
when the packet fails to meet a recognition criterion, assign a processing result code to the packet, the result code configured to indicate that exception processing applies for the packet; and
host circuitry, coupled to the flow acceleration circuitry, the host circuitry configured to:
receive the result code and the packet from the flow acceleration circuitry;
responsive to the result code, perform the exception processing on the packet; and
resubmit the packet to the flow acceleration circuitry after the exception processing.
2 . The system of claim 1 , where the flow acceleration circuitry is further configured to extract a flow key from the packet to determine that the packet fails to meet the recognition criterion.
3 . The system of claim 2 , where the flow key comprises an identifier of an endpoint of a network tunnel.
4 . The system of claim 2 , where the flow acceleration circuitry is further configured to access a record in a flow descriptor table responsive to the flow key.
5 . The system of claim 4 , where the flow acceleration circuitry is configured to determine that the packet fails to meet the recognition criterion when the record in the flow descriptor table is unrecognized.
6 . The system of claim 4 , where the record in the flow descriptor table is configured to identify an encapsulation format of the packet.
7 . The system of claim 1 , where the host circuitry is configured to resubmit the packet with a transmit descriptor, the transmit descriptor comprising a processing instruction for the flow acceleration circuitry.
8 . The system of claim 7 , where:
the processing instruction comprises a bypass indicator; and the flow acceleration circuitry is configured to pass the packet, responsive to the bypass indicator, to switching circuitry.
9 . The system of claim 7 , where:
the processing instruction comprises a transmission unit size; and the flow acceleration circuitry is configured to divide the packet into fragments based on the transmission unit size.
10 . The system of claim 1 , where the exception processing comprises a removal of an encapsulation form the packet.
11 . The system of claim 1 , where the exception processing comprises a reformat of an encapsulation of the packet.
12 . The system of claim 1 , where the flow acceleration circuitry is configured to send the packet to a security co-processor to determine when the packet fails to meet the recognition criterion.
13 . The system of claim 12 , where the flow acceleration circuitry is configured to determine that the packet failed to meet the recognition criterion when the security co-processor fails to de-crypt the packet.
14 . The system of claim 1 , where:
the host circuitry is further configured to send a command to the flow acceleration circuitry to perform exception processing, the command configured to add an entry to a flow descriptor table; and the entry is configured to cause the packet to meet the recognition criterion after the packet is resubmitted to the flow acceleration circuitry.
15 . A device comprising:
flow acceleration circuitry in data communication with host circuitry, the flow acceleration circuitry configured to:
receive a network packet from the network interface circuitry;
when the network packet fails to meet a recognition criterion, assign a processing result code to the network packet, the result code indicates exception processing for the network packet;
send the network packet and the result code to the host circuitry; and
responsive to the result code, receive a resubmission of the network packet from the host circuitry after exception processing at the host circuitry.
16 . The device of claim 15 , where the network packet comprises a flow key that identifies a network tunnel.
17 . The device of claim 16 , where the flow acceleration circuitry is configured to reference an entry for the flow key in a descriptor table to determine an encapsulation format for the network tunnel.
18 . A product comprising:
a machine-readable medium other than a transitory signal; and instructions stored on the machine-readable medium, the instructions configured to, when executed by a machine:
access a flow key within a packet received at flow acceleration circuitry, the flow key comprising an identifier of an endpoint of a network tunnel;
reference a descriptor table to determine an encapsulation format for the network tunnel;
when the encapsulation format is unrecognized by the flow acceleration circuitry, determine that the packet has failed to meet a recognition criterion;
generate a result code indicating that the packet has failed to meet the recognition criterion;
send the result code and the packet to host circuitry for exception processing; and
receive a resubmission of the packet from the host circuitry after exception processing.
19 . The product of claim 18 , where the resubmission of the packet comprises a re-encapsulation of the packet.
20 . The product of claim 18 , where the instructions are further configured to reference the descriptor table a second time after resubmission of the packet to access an updated entry.Join the waitlist — get patent alerts
Track US2015131447A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.