![面向數(shù)據(jù)中心的巨大突破NVIDIADPU集數(shù)據(jù)中心于芯片(中英)_第1頁](http://file4.renrendoc.com/view/46247c0a0331d9f6d661f6fc0f25e2e4/46247c0a0331d9f6d661f6fc0f25e2e41.gif)
![面向數(shù)據(jù)中心的巨大突破NVIDIADPU集數(shù)據(jù)中心于芯片(中英)_第2頁](http://file4.renrendoc.com/view/46247c0a0331d9f6d661f6fc0f25e2e4/46247c0a0331d9f6d661f6fc0f25e2e42.gif)
![面向數(shù)據(jù)中心的巨大突破NVIDIADPU集數(shù)據(jù)中心于芯片(中英)_第3頁](http://file4.renrendoc.com/view/46247c0a0331d9f6d661f6fc0f25e2e4/46247c0a0331d9f6d661f6fc0f25e2e43.gif)
![面向數(shù)據(jù)中心的巨大突破NVIDIADPU集數(shù)據(jù)中心于芯片(中英)_第4頁](http://file4.renrendoc.com/view/46247c0a0331d9f6d661f6fc0f25e2e4/46247c0a0331d9f6d661f6fc0f25e2e44.gif)
![面向數(shù)據(jù)中心的巨大突破NVIDIADPU集數(shù)據(jù)中心于芯片(中英)_第5頁](http://file4.renrendoc.com/view/46247c0a0331d9f6d661f6fc0f25e2e4/46247c0a0331d9f6d661f6fc0f25e2e45.gif)
版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報或認(rèn)領(lǐng)
文檔簡介
1、2數(shù)據(jù)中心的處理器 演進(jìn)與挑戰(zhàn)數(shù)據(jù)中心的變革 以數(shù)據(jù)為中心21st Century Unit of ComputingDPUGPUCPU3Accelerated Disaggregated Infrastructure (ADI)數(shù)據(jù)中心變成了新的計(jì)算單元NVIDIA NetworkingSoftware defined, Hardware-accelerated DPU (data processing unit)DPU essential to disaggregate resources & make composable ADIAccelerated ComputingGPU: AI
2、& machine learningGPU critical for AI & machine learning Every workload will become AI Accelerated4軟件定義和硬件加速成為數(shù)據(jù)中心的核心Software Defined SecurityDistributed IDS/IPS NG FirewallSoftware Defined StoragevRoutervSwitchVMs & ContainersSoftware Defined NetworkingNVMe-oFData Storage Direct EncryptionMicroDDOS
3、 Segmentation PreventionTelco/NFVElastic StorageRoot of TrustCompression DeDupNAT/Load Balancer5DPU 成為大勢所趨Software Defined Data Center Infrastructure-on-a-Chip軟件定義的數(shù)據(jù)中心架構(gòu)級芯片To Software Defined Infrastructure on CPUTo Software Defined Infrastructure on DPUFrom Hardware AppliancesManagementStorageSecu
4、rityNetworkingNVIDIA NICSoftware-defined SecuritySoftware-defined NetworkingSoftware-defined StorageInfrastructure ManagementAcceleration EnginesNVIDIA DPU with Arm Cores & AcceleratorsSoftware-defined NetworkingSoftware-defined SecuritySoftware-defined StorageInfrastructure ManagementAcceleration E
5、ngines67NVIDIA DPU數(shù)據(jù)中心級處理器架構(gòu)總覽8BLUEFIELD-2 DPU數(shù)據(jù)處理單元Data Center Infrastructure-on-a-Chip數(shù)據(jù)中心架構(gòu)級芯片69 億 Transistors8 個 64-bit Arm CPUs Cores 雙 16-way VLIW Engine 100 Gbps 的 IPsec 性能50 Gbps 的 RegEx 性能 100 Gbps Video Streaming 5 百萬 NVMe IOPs相當(dāng)于 125 個 x86 CPU Cores 的工作BLUEFIELD-2 DPU 功能示意圖200 Gbps Ethern
6、et & InfiniBand, NRZ & PAM4 modulationPowered by ConnectX-6 Dx8 ARM A72 CPUs subsystem in a Tile architecture8MB L2 cache, 6MB L3 cache in 4 TilesARM Frequency up-to 2.5GHzFully integrated PCIe switch, 16 bi-furcated Gen4.0Root Complex or End Point modes1GbE Out-of-Band management port16 lanes PCIe
7、Gen3/49BLUEFIELD-2 全面提升應(yīng)用效率單一 DPU 硬件加速和 CPU 軟件執(zhí)行效率對照一覽10X15X30X50XMALWARE PATTERN MATCHINGVIDEO STREAMINGIPSEC ENCRYPTIONELASTIC BLOCK STORAGE2.5XCLOUD OVERLAY NETWORKING150X10NG STATEFUL FIREWALL11DPU 在安全、存儲和云 場景的應(yīng)用12SECURED HARDWARESecure FW upgrade Root-of-Trust Arm trust zoneDPU 數(shù)據(jù)中心的安全保障Integra
8、ted Security for modern data center needsADVANCED L4-L7 SECURITYCRYPTO ACCELERATIONPROGRAMMABILTY & ISOLATIONNG stateful firewall Deep Packet Inspection Host introspectionData-in-motion enc.Data-at-rest enc.Public Key AccelerationHardened Isolation Micro-Segmentation Programmable algo.13數(shù)據(jù)中心的安全防護(hù)正在由
9、外圍向內(nèi)部轉(zhuǎn)移Software Defined Networking (SDN)Encryption (Software)L4-L7 InspectionWorkloadSoftwaredefinedStorage (SDS)WorkloadFirewall / Micro-segmentationNICOptionalDPUL4-L7 InspectionU-SegmentationNGFW / CryptoSDN & SDSIDSNGFWAnti- Malware核心數(shù)據(jù)中心邊緣 IsolationIT OpsCloud ServerCloud ServerDevOpsWITHOUT DP
10、UWITH DPUIT OpsDevOpsWorkloadWorkloadWorkloadWorkloadWorkloadWorkload最安全的 DPU - BLUEFIELD-2Trust Shifts to the DPURoot-of-TrustStateful FirewallInline Crypto AcceleratorsDeep Packet InspectionIsolated Security Control PlaneFull Isolation from the HostCPUGPUNetwork TrafficDistributed NG FirewallIDS/I
11、PSDDOSPreventionMicro SegmentationRoot of Trust14Better SecuritySmaller attack surfaceReal-time reaction to threats Security in every host & workload Transparent cryptography在云上提升安全性能 讓云更安全Shifting the trust to NVIDIA DPUBetter TCOOpex savings Capex savingsBetter PerformanceHardware acceleratedInlin
12、e networking & storage acceleration Seamless integrative securityFull visibility15UNPARALLELED PERFORMANCESTORAGE SECURITYSECRET SAUCEDual 100Gbps or single 200Gbps Up to 5.4M IOPs 4KBLowest latency NVMe-oF accelerationDPU 讓存儲更安全高效Storage Agility Meets Best-in-Class Hardware AccelerationData-at-rest
13、 AES-XTS encryption Authentication services Protection between usersNVMe SNAP / Virtio-blk SNAP Integrated data & control planes Data (De)Compression Deduplication16BLUEFIELD 面向彈性塊存儲的 SNAP 技術(shù)支持各種存儲應(yīng)用場景 : DAS, Scale-UP, Scale-OUT, Hyperconverged 等Remote Storage Access NVMe-oF & RDMA offload iSCSI, iS
14、ER, NFS, CEPHHyperconverged Local Storage Access Direct/IndirectIndirectDirectNVME SNAPEmulated Interfaces on PCIeNVMe SNAP / virtio-blk SNAP1718DPU 讓存儲更靈活、易重構(gòu)Emulates remote storage to appear as local to the host OSDynamically assigned storage, not bound by physical capacityVirtualized or Bare Meta
15、l CloudOver-provisioning, scaled to rack/cluster Inbox standard driversOS agnostic - supports legacy OSs重塑企業(yè)云的效益Compute PlatformsHOST OSRemote StorageVirtio-blkDPU SNAP FrameworkNVMe19越來越多的應(yīng)用需要更先進(jìn)的網(wǎng)絡(luò)技術(shù)Kubernetes typically runs modern workloads: data-driven, real-time and highly distributedMicroservi
16、ces run on multiple, arbitrary serversEach microservice runs multiple timesMicroservices generate intensive east-west data movements High-throughput, low-latency is imperativeMonolithic ArchitectureMicroservice ArchitectureLimited CommunicationUIData Access Layer Business LogicUIMicroserviceMicroser
17、viceMicroserviceMicroserviceMassive Communication20Accelerating all pod-to-pod, ClusterIP service communicationFull upstream solution, integrated into Linux kernel, OVS and OVN communitiesFlexible solution for accelerating the primary network (Kubernetes API) or secondary network with meta CNI (Mult
18、us)Leverage advanced offloads including overlay network encap/decap, connection tracking and NATDPU 賦能 OVN SDNOVS 操作和 OVN 控制被卸載到 BlueField-2 DPUsHostHostPodPodOVS PipelineOVN ControllerOVN K8S CNINICOVN K8S CNIDPUOVN ControllerOVS Pipeline從數(shù)據(jù)平面和控制平面加速 GPUDIRECT RDMAAccelerating GPU-to-GPU communicat
19、ions by employing RDMA to offload the CPU and host memory Highest throughput and lowest communication latency for GPUs commsGPUMemoryPCIeNode 1NetworkCPUGPUCPUMemoryGPUMemoryPCIeNode 2CPUGPUCPUMemoryDPUDPU21將管理云一樣管理 BARE-METAL 系統(tǒng)Software-defined NetworkingBare-Metal Cloud SecurityStorage-Defined Sto
20、rageFull-featured SDN capabilitiesFull orchestration through upstream OpenStack Neutron APIsComplete host isolation for the tenants workloadNo security agents running on servers with impact on performanceVirtualized storage flexibility with local storage performance Dynamically allocates cloud stora
21、ge and back-ups in the storage cloud22Limited to network security with ACLsNo visibility to the hosts workloads, failing to implement effective security strategiesIncreased surface for east-west attacksSecurity Policy in TOR SwitchTenants DomainProviders DomainNICBare-Metal HostSecurity Policy BlueF
22、ield-2 DPUComplete isolation of the security enforcement from the tenants workloadEnabling diverse cyber security solutions, enhancing data-center securityNo need to install agents on serversNo impact on server performanceBLUEFIELD 保障 BARE-METAL KUBERNETES 的安全Applying Security Policies on BlueField-
23、2 Arm, Fully Isolated from the Hosts CPU and OSTOR SwitchApplying Security Policies on TOR SwitchCPUGPUTOR SwitchCPUBare-Metal Host23Limited to no SDN capabilitiesOrchestration through proprietary TOR switch vendor pluginsMandates proprietary network driver installation in bare-metal hostNetworking
24、in TOR SwitchTenants DomainProviders DomainNICBare-Metal HostSDN Integration with BlueField-2 DPUFull-featured SDN hardware-accelerated capabilitiesFull orchestration through upstream OpenStackNo installation of network driver in bare-metal hostBLUEFIELD 在 BARE-METAL 云上實(shí)現(xiàn)了 SDNApplying Neutron OVS L2
25、 Agent on BlueField-2 ArmTOR SwitchOpenStack Policies on TOR SwitchCPUGPUTOR SwitchCPUBare-Metal Host24Bound by physical storage capacityNo backup service or limited local RAID No option to manage storage resources No migration of resourcesLocal Physical Drive in BM HostTenants DomainProviders Domai
26、nNICBare-Metal HostNVMe SNAP on BlueField-2 DPUSame flexibility as virtualized storageBacked-up in the storage cloudDynamically allocated cloud storageOS agnostic, only NVMe driver neededTOR SwitchBare-Metal HostBLUEFIELD 在 BARE-METAL 云上實(shí)現(xiàn)了 SDSRemote StorageTOR SwitchOpenStack Policies on TOR Switch
27、CPUCPU2526DPU 的應(yīng)用案例分享27云 :NVIDIA & VMWARE 在混合云上強(qiáng)強(qiáng)聯(lián)手Run Modern Workloads Efficiently Over New Composable, Disaggregated InfrastructureBare Metal Linux &WindowsIsolationNetwork and Security: NSX SvcsCompute HypervisorStorage: VSAN DataESXiHost ManagementDPUProject Monterey28Todays EnvironmentNetwork &
28、 Security: NSX SvcsCompute HypervisorStorage: VSAN DataESXiHost Management新一代的 VMware cloud foundation 架構(gòu)Bare Metal Linux & WindowsIsolation LayerCompute HypervisorESXiToPdraoyjescEt nMvoirnotnemreeyntORNICDPUNetwork & Security NSXStorage VSAN DataHost Management云:構(gòu)建新一代的 VMWARE CLOUD FOUNDATION 架構(gòu)存儲
29、:全自動運(yùn)維、橫向可擴(kuò)展的 NVME-OF 存儲Automated provisioning of networked storage to servers without using any host resourcesData analytics, ML/AI on any OS or hypervisor can now take advantage of scale-out NVMe storageInstantly attach/detach data sets and storage, and replace failed components in secondsHigh per
30、formance, continuously adaptable infrastructure for data-intensive applicationsDriveScale Blog29安全:主機(jī)無需安全代理的 (AGENTLESS) SEGMENTATIONGuardicore introduces complete network level visibility. Tracks connections and reports network events and their verdictGuardicore enforcement policy is accelerate by
31、the DPU hardware by offloading the segmentation rulesGuardicore agents running on BlueField cores in a separated trusted domain, enforce policies even on a compromised hostGuardicore CentraBlueField-2 DPULINUX OSGUARDICORE AGENTBare-Metal HostOVSBare-Metal ServerGuardicore Blog30安全: DPU 加速 CHECK POI
32、NT INFINITY CLOUDCheck Point Infinity Nano-agents are deployed on the NVIDIA DPU to protect, isolate and accelerate the cloud and edgeThe DPU & the Nano-agents enforce the distributed security policy created by the Infinity centralized managementCheckPoint Tech & Nvidia are working together to accel
33、erate security services with AI on every compute nodeProtect, isolate and accelerate the cloud and edgeHostWorkloadWorkloadNano-Agent31WorkloadDPUCheckPoint Blog32基于 DOCA SDK 的應(yīng)用 開發(fā)指南33SDK for BlueField DPUsOpen source APIs DPDK, SPDK, P4Certified reference apps & 3rd party solutionsSupport for mult
34、iple OSNVIDIA DOCA 介紹Data Center Infrastructure-on-a-Chip Architecture 數(shù)據(jù)中心級架構(gòu)芯片的 軟件架構(gòu)StorageSPDKSecurityDPDKNetworkingDPDK / P4DOCA SDKINFRASTRUCTURE APPLICATIONSASAP2CRYPTORoTRDMASNAPManagementTelemetryInfrastructure ManagementSoftware-defined StorageSoftware-defined SecuritySoftware-defined Netwo
35、rking一個 DPU 方案滿足所有客戶的需求Open PlatformVMWare based SolutionFull Solution & EcosystemToday20212021BlueField-2 DPUDOCA SDKCustomer AppsVMwareDOCA SDK3rd Party AppsBlueField-2 DPUBlueField-2 DPU34與合作伙伴共建 DPU 生態(tài)系統(tǒng)Storage ISVs | Security ISVs | Infrastructure35完善的 NVIDIA 認(rèn)證體系Servers Designed and Optimized for Accelerated ComputingPerformance OptimizedAccelerated Compute and I/O
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 丁二烯法合成氯丁橡膠生產(chǎn)裝置項(xiàng)目可行性研究報告模板-備案拿地
- 2024-2025學(xué)年河北省尚義縣第一中學(xué)等校高二上學(xué)期12月月考?xì)v史試卷
- 2025年債務(wù)轉(zhuǎn)股權(quán)協(xié)議標(biāo)準(zhǔn)格式
- 2025年古園林保護(hù)性維護(hù)協(xié)議
- 2025年農(nóng)產(chǎn)品交易市場租賃合同模板
- 2025年功能性棚模新材料及各種助劑項(xiàng)目提案報告
- 2025年企業(yè)與個人租車合同模板及規(guī)定
- 2025年長租公寓項(xiàng)目立項(xiàng)申請報告范文
- 2025年家居用品商貿(mào)公司采購協(xié)議書
- 2025年綠色共享汽車合作投資與發(fā)展策劃協(xié)議
- 2025陜西省建筑安全員B證考試題庫及答案
- 益普索X空中云匯-2024年B2B外貿(mào)企業(yè)出海白皮書 -全球支付及金融平臺 賦能B2B外貿(mào)企業(yè)競爭力
- 2025牢牢堅(jiān)守廉潔底線嚴(yán)守廉政職業(yè)底線主題課件
- DB31-T 451-2021 凈水廠用煤質(zhì)顆?;钚蕴窟x擇、使用及更換技術(shù)規(guī)范
- ADA糖尿病醫(yī)學(xué)診療標(biāo)準(zhǔn)指南修訂要點(diǎn)解讀(2025)課件
- 2024成人動脈血?dú)夥治雠R床操作實(shí)踐標(biāo)準(zhǔn)(第二版)課件
- 高一古詩詞鑒賞課模板
- 年產(chǎn)珍珠棉7000噸紙箱包裝3000噸生產(chǎn)項(xiàng)目環(huán)評報告表
- 健康管理-理論知識復(fù)習(xí)測試卷含答案
- 崩漏病(異常子宮出血)中西醫(yī)診療方案
- 2024年甘肅省公務(wù)員考試《行測》真題及答案解析
評論
0/150
提交評論