Rules Offload Engine (ROE): Accelerating Host SDN Policy Evaluation
- Anshuman Verma ,
- Tian Tan ,
- Ahmed Abdelsalam ,
- Milan Dasgupta ,
- Jonathan Hunter ,
- Zach Libby ,
- Narayanan Ravichandran ,
- Harish Srinivasan ,
- Matt Reat ,
- Nadeen Gebara ,
- Vishal Gondaliya ,
- Ezz Hamed ,
- Rahul Garlapati ,
- Lok Chand Koppaka ,
- Abdullah Mughrabi ,
- Dev Desai ,
- Alexander Malysh ,
- Shwetha Bhat ,
- Rohan Kandi ,
- Megan Sng ,
- Tushar Garg ,
- Muluken Hailesellasie ,
- Andrew Putnam ,
- Derek Chiou ,
- Osman Ertugay ,
- Alireza Dabagh ,
- Vivek Bhanu ,
- Daniel Firestone
Published by ACM
Software Defined Networking (SDN) policy evaluation analyzes and verifies network rules to enable accurate packet routing, manage access controls, and ensure security and privacy. Therefore, SDN policy evaluation is a mandatory step that each network packet must go through in virtual machines hosted on public cloud services, such as Azure. Evaluating SDN policies requires up to several hundred microseconds, which severely limits performance. The problem exacerbates at cloud scale where more connections per second (CPS) are desirable across millions of virtual machines.
In this paper, we present Rules Offload Engine (ROE), a hardware software co-designed solution that accelerates SDN policy evaluation through FPGA-based SmartNICs. We propose the ROE Instruction Set Architecture (RISA) that features dedicated networking friendly instructions. RISA fuses control policy data and operation directly into the instructions to facilitate an efficient FPGA implementation. We develop an ROE compiler that translates SDN rules into RISA instructions. We also design the ROE-Core that implements RISA and other components for seamless integration with existing hardware and software stacks. Overall, ROE enables up to 400K CPS, achieving 10x higher throughput compared to prior software-centric approaches. ROE is deployed in Azure and was featured as a part of the second-generation Azure Boost.