Networking and High-Performance Systems

ProtocolForge - Modular High-Performance Protocol Processing Data Plane

A modular C, Assembly, and DPDK preprocessing service validated at approximately 1 Tbps, decapsulating QinQ, MPLS, VNTag, GRE, and GTP traffic before forwarding normalized IP to PacketLens or other systems.

ContextConfidential network operator
PeriodOne-year specialized data-plane program
RelationshipSpecialized data-plane subsystem
Team footprintEight engineers contributed over one year.
DPDKC and AssemblyProtocol decapsulationModular data planes

The system

ProtocolForge handles network traffic whose useful IP payload is wrapped in additional encapsulation or tunnel layers that PacketLens or another analysis tool cannot consume directly. The service identifies supported outer protocols, strips or decapsulates the required layers, recovers the underlying IP traffic, and forwards that normalized output downstream.

Verified protocol support includes QinQ, MPLS, VNTag, GRE, and GTP. The public case describes the supported boundaries without exposing parser implementation, private packet formats, or customer routing policy.

The customer intentionally wanted the preprocessing layer separated from PacketLens. ProtocolForge therefore runs as an independent service on a separate server, can scale independently, can be placed in a different data center, and can feed PacketLens or another customer analysis system.

Engineering relationship

Across a one-year specialized program, OPTIME engineered the DPDK packet-I/O path, C and selected Assembly processing, protocol identification and decapsulation, normalized raw-IP output, independent deployment model, downstream integration, and approximately 1 Tbps local data-center validation.

ProtocolForge is the generalized encapsulation-normalization layer in a related modular architecture. MobileScope specializes in mobile-core GTP-U/GTP-C processing, while PacketLens consumes raw IP for classification, selected protocol analysis, filtering, and traffic steering.

Engineering constraints

  • Process layered encapsulations at high traffic rates without exposing proprietary parser internals.
  • Support only the verified QinQ, MPLS, VNTag, GRE, and GTP protocol set in the public description.
  • Recover normalized raw IP suitable for PacketLens and other customer tools.
  • Keep decapsulation independent from downstream analysis so each responsibility can scale separately.
  • Support deployment on a separate server and, when required, in a different data center from PacketLens.
  • Use Assembly only for selected performance-critical routines rather than implying an all-Assembly implementation.
  • Describe approximately 1 Tbps as validated local data-center performance, not continuous throughput in every deployment.

What OPTIME engineered

  • A DPDK-based high-throughput packet capture and distribution path.
  • A C data plane for encapsulation identification, protocol processing, and decapsulation.
  • Selected Assembly routines for performance-critical packet-processing work.
  • QinQ VLAN encapsulation processing.
  • MPLS label-stack processing and payload recovery.
  • VNTag encapsulation processing.
  • GRE tunnel processing and decapsulation.
  • GTP tunnel processing where required by the monitored traffic.
  • Normalized raw-IP output for PacketLens or another customer analysis tool.
  • An independently deployable service/server boundary with separate scaling and placement.
  • Performance validation at approximately 1 Tbps in the customer’s local data-center environment.

Architecture

  1. Encapsulated network traffic

    Monitored QinQ, MPLS, VNTag, GRE, or GTP traffic enters the preprocessing service.

  2. Independent ProtocolForge service

    The service runs separately from PacketLens and can scale or deploy in a different data center.

  3. DPDK capture

    High-throughput packet I/O feeds the native data plane with reduced operating-system overhead.

  4. C / Assembly data plane

    C implements the processing core, with Assembly reserved for selected performance-critical routines.

  5. Encapsulation identification

    The data plane identifies the supported outer protocol layers that must be removed.

  6. Protocol processing

    QinQ, MPLS, VNTag, GRE, and GTP layers are processed at a public conceptual boundary.

  7. Normalized raw IP

    The underlying IP payload is recovered without exposing proprietary parser or customer-rule details.

  8. PacketLens output

    Normalized traffic can feed PacketLens for deeper IP classification and selective analysis.

  9. Alternative tool output

    The same normalized output can be directed toward another customer analysis system.

Key engineering decisions

Deploy preprocessing independently

Rather than embedding every decapsulation function inside PacketLens, OPTIME created a separate service/server so normalization and IP analysis can scale, operate, and deploy independently.

Normalize to raw IP at a stable boundary

ProtocolForge removes only the required outer layers and emits underlying IP, allowing PacketLens and other tools to consume a consistent downstream format.

Reserve Assembly for selected hot paths

The implementation uses C for the data-plane core and selected Assembly only where performance-critical processing justified lower-level optimization.

Keep outputs tool-independent

PacketLens is the primary verified downstream consumer, but the modular output can feed other customer analysis systems without combining them into one monolithic deployment.

Related engineering platform

Other encapsulated traffic flows through ProtocolForge for QinQ, MPLS, VNTag, GRE, or GTP processing before normalized raw IP reaches PacketLens or another downstream tool.

MobileScope is the related specialized mobile-core preprocessing layer, separating high-rate GTP-U decapsulation from GTP-C control/session analysis. PacketLens remains the raw-IP analysis and traffic-steering layer.

Verified capability

ProtocolForge provides an independently deployable normalization boundary for high-rate encapsulated traffic. It was validated at approximately 1 Tbps in the customer’s local data-center environment; that figure does not imply every deployment continuously processes 1 Tbps.

Verified result

The modular data plane recovered normalized IP from the verified encapsulation set at approximately 1 Tbps in customer-local validation while preserving independent deployment and scaling from PacketLens.

Verified metrics

Validated preprocessing throughput

Approximately 1 Tbps

Validated in the customer’s local data-center environment; not a universal continuous-throughput claim.

Technology & Engineering Role

C
High-performance packet-processing and protocol-decapsulation logic.
Assembly
Selected performance-critical packet-processing routines.
DPDK
High-throughput packet I/O for the independent data-plane service.
QinQ
VLAN encapsulation processing and payload recovery.
MPLS
Label-stack processing and underlying payload extraction.
VNTag
Encapsulation processing for supported monitored traffic.
GRE
Tunnel processing and decapsulation.
GTP
Mobile and network tunnel processing where required.
Raw IP output
Normalized traffic delivered to PacketLens or another customer system.
Modular service architecture
Independent deployment, scaling, and data-center placement.

Related engineering

CONTACT US

Tell us about your project, and let’s create something together

Austin, Texas

Distributed engineering teams across North America, Europe, the Caucasus, and Latin America.

[email protected]

We use the information you submit to respond to your inquiry and process it through the service providers required to operate this form.