Two-way encryption / decryption device for load and overlay operations
By introducing programmable path selection circuits and security ICs into network devices, the challenges of encryption/decryption functions in overlay networks are solved, enabling flexible encryption/decryption processing under different network modes and supporting effective processing of L3 routing and overlay traffic.
Patent Information
- Application Number
- CN202211541345.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-01-04
- Filing Date
- 2022-12-02
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-12-02
AI Technical Summary
Existing technologies struggle to simultaneously implement encryption/decryption functions during both carry-over and overlay operations, especially in scenarios requiring L3 routing, where MACsec/IPsec-enabled devices cannot effectively carry overlay traffic.
Employing a programmable path selection circuit, combined with a security IC (such as a MACsec device or an IPsec IC device), it operates in two modes to achieve flexible encryption/decryption of incoming and outgoing packets, supporting standard cryptographic operations for both native and overlay networks.
It enables flexible handling of incoming and outgoing packets under different network modes, supports L3 routing and encryption/decryption of superimposed traffic, and improves the flexibility and security of network devices.
Smart Images

Figure CN116405235B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] At least one embodiment relates to processing resources for performing and facilitating network communications. For example, at least one embodiment relates to bidirectional encryption / decryption techniques for underlay operations and overlay operations. BACKGROUND
[0002] Network devices (e.g., switches, routers, hubs, endpoints, network interface cards (NICs), data processing units (DPUs), etc.) can have encryption / decryption functionality (e.g., media access control security (MACsec) or Internet Protocol security (IPsec)) to encrypt / decrypt starting from the relevant layer of the network stack, such as Layer 2 (L2) or Layer 3 (L3). These encryption / decryption functionalities can be used as examples when the devices are connected point-to-point over fiber, or when there are switches in the middle for L2 encryption and routers in the middle for L3 encryption.
[0003] Overlay networking can be used to create network abstraction layers that can be used to run multiple independent, discrete virtualized network layers on top of a physical network. Overlay networking uses an overlay encapsulation protocol. The overlay encapsulation protocol can create a virtual network that overlays an existing physical network infrastructure. It uses an underlay IP network and builds flexible Layer 2 overlay logical networks on top of it. With overlay, any connection running on Layer 2 can span a Layer 3 network.
[0004] Using encryption / decryption functionality with overlay network technology can present some challenges. For example, a device that supports MACsec / IPsec cannot support the following: the need to carry overlay traffic while assuming that the underlay device should be able to locally route traffic using L3 routing, including reading the L4 header when needed. BRIEF DESCRIPTION OF DRAWINGS
[0005] Various embodiments according to the present disclosure will be described with reference to the drawings, in which:
[0006] Figure 1A An example communication system is shown in accordance with at least some embodiments.
[0007] Figure 1B is a block diagram of a network device in accordance with at least some embodiments.
[0008] Figure 2A is a block diagram of a network device with a programmable path selection circuit operating in a first mode in accordance with at least some embodiments.
[0009] Figure 2Bis a block diagram of a network device operating in a second mode according to at least some embodiments.
[0010] Figure 3A is a block diagram of a network device with a path through encryption and decryption circuits in a first mode according to at least some embodiments.
[0011] Figure 3B is a block diagram of a network device with a path to encryption and decryption circuits in a second mode using programmable multiplexers according to at least some embodiments.
[0012] Figure 4 is a block diagram of a network device according to at least some embodiments.
[0013] Figure 5 is a flowchart of a method for routing an incoming packet to be encrypted and encapsulated in a network device according to at least some embodiments.
[0014] Figure 6 is a flowchart of a method for operating a network device in a first mode or a second mode to route an incoming packet in the network device according to at least some embodiments.
[0015] Figure 7 shows an example computer system including programmable path selection circuitry according to at least some embodiments. DETAILED DESCRIPTION
[0016] Bidirectional encryption and decryption techniques for bearer operations and overlay operations are described. Media Access Control Security (MACsec) functionality (e.g., in the form of circuitry, integrated chips (ICs), and devices) has been added to many network devices (or circuitry) in order to provide end-to-end network security in different types of networks. For example, MACsec is a network security standard that operates at the Media Access Control layer and defines data confidentiality and integrity for media access independent protocols. Thus, MACsec can provide point-to-point security over an Ethernet link (generally referred to herein as a network link) and is defined by the Institute of Electrical and Electronics Engineers (IEEE) standard 802.11AE. Moreover, MACsec can be used in conjunction with other security protocols, such as Internet Protocol Security (IPsec) and Secure Sockets Layer (SSL), to provide this end-to-end network security.
[0017] MACsec can identify and prevent most security threats, including denial of service, intrusion, man-in-the-middle, spoofing, passive eavesdropping, and replay attacks. To do so, MACsec secures the Ethernet link for almost all traffic, including frames from Link Layer Discovery Protocol (LLDP), Link Aggregation Control Protocol (LACP), Dynamic Host Configuration Protocol (DHCP), Address Resolution Protocol (ARP), and other protocols that are typically unprotected on Ethernet links due to limitations of other security solutions. As a result, MACsec circuits are expected to grow with the expansion of the Internet of Things (IoT) and other network-enabled devices. One of the main use cases for MACsec is to secure local area networks (LANs) with multiple machines, particularly to secure Ethernet traffic on Layer 2 LAN networks. To implement the MACsec functionality between a switch and connected endpoints (e.g., PC clients, IoT devices, etc.), the devices can use a standardized negotiation protocol called the MACsec Key Agreement (IEEE 802. IX-2010).
[0018] While MACsec circuits can be integrated within network devices (e.g., coupled to network circuits within a network device), it is advantageous to keep the MACsec circuits separate from the network devices. For example, MACsec circuits are specialized and can be efficiently manufactured as ICs or MACec devices individually, and some legacy network devices can not yet include MACsec circuits. In these embodiments, the MACsec circuits or devices (hereinafter collectively referred to as “devices”) can be coupled between a network device and a source of network connectivity or other network devices. As a result, each MACsec device provides end-to-end security for the network device to which the MACsec device is coupled, and the network device does not need to be redesigned or remanufactured to include MACsec circuits.
[0019] As noted above, using encryption / decryption functionality with overlay network technology can present some challenges. For example, devices that support MACsec / IPsec cannot support cases that require carrying overlay traffic, while assuming that the carrying device should be able to locally route traffic using L3 routing, including reading L4 headers when needed.
[0020] Aspects and embodiments of the present disclosure address these and other challenges by providing bidirectional encryption / decryption for bearer operations and overlay operations. Aspects and embodiments of the present disclosure can provide programmable path selection circuitry for different modes of operation. Network devices can operate in two modes and implement standard cryptographic operations for local networks and overlay networks while having the flexibility to operate in both modes using programmable path selection circuitry. The programmable path selection circuitry is coupled to a security IC (e.g., a MACsec device or an IPsec IC device). The programmable path selection circuitry can change connectivity within or outside of the cryptographic device to provide greater flexibility. The programmable path selection circuitry enables both sides of the cryptographic device to encrypt or decrypt, allowing incoming data in the clear to be encrypted before being processed by the network processing element.
[0021] Figure 1A An example communication system 100 according to at least one example embodiment is shown. The system 100 includes a device 110, a communication network 108 including a communication channel 109, and a device 112. In at least one example embodiment, the devices 110 and 112 correspond to one or more of a personal computer (PC), a laptop, a tablet, a smartphone, a server, a collection of servers, and the like. In some embodiments, the devices 110 and 112 can correspond to any suitable type of device that communicates with other devices connected to a common type of communication network 108. According to embodiments, a receiver 104 of the device 110 or 112 can correspond to a graphics processing unit (GPU), a switch (e.g., a high-speed network switch), a network adapter, a central processing unit (CPU), and the like. As another specific, but non-limiting, example, the devices 110 and 112 can correspond to a server that provides information resources, services, and / or application programs to user devices, client devices, or other hosts in the system 100.
[0022] Examples of the communication network 108 that can be used to connect the devices 110 and 112 include an Internet Protocol (IP) network, an Ethernet network, an InfiniBand (IB) network, a Fibre Channel network, the Internet, a cellular communication network, a wireless communication network, combinations thereof (e.g., Fibre Channel over Ethernet), variations thereof, and the like. In one specific, but non-limiting, example, the communication network 108 is a network capable of data transmission between the devices 110 and 112 using data signals (e.g., digital signals, optical signals, wireless signals).
[0023] The device 110 includes a transceiver 116 for transmitting and receiving signals, such as data signals. The data signals can be digital or optical signals modulated with data, or other suitable signals for carrying data.
[0024] Transceiver 116 can include digital data source 120, transmitter 102, receiver 104, and processing circuitry 132 that controls transceiver 114. Digital data source 120 can include appropriate hardware and / or software for outputting data in a digital format, such as binary code and / or thermometer code. The digital data output by digital data source 120 can be retrieved from memory (not shown) or generated from input, such as user input.
[0025] Transmitter 102 includes appropriate software and / or hardware for receiving digital data from digital data source 120 and outputting a data signal from the digital data for transmission to receiver 104 of device 112 over communication network 108. Additional details of the structure of transmitter 102 are discussed in greater detail below with reference to the accompanying drawings.
[0026] Receiver 104 of device 110 (and device 112) can include appropriate hardware and / or software for receiving signals, such as data signals from communication network 108. For example, receiver 104 can include components for receiving and processing signals to extract data for storage in memory.
[0027] Processing circuitry 132 can include software, hardware, or a combination thereof. For example, processing circuitry 132 can include a memory that includes executable instructions and a processor (e.g., a microprocessor) that executes the instructions on the memory. The memory can correspond to any appropriate type or set of memory devices configured to store instructions. Non-limiting examples of suitable memory devices that can be used include flash memory, random access memory (RAM), read only memory (ROM), variations thereof, combinations thereof, and the like. In some embodiments, the memory and the processor can be integrated into a common device (e.g., the microprocessor can include integrated memory).
[0028] Processing circuitry 132 can send and / or receive signals to and / or from other elements of transceiver 116 to control the overall operation of transceiver 114. Additionally or alternatively, processing circuitry 132 can include hardware, such as an application specific integrated circuit (ASIC). Other non-limiting examples of processing circuitry 132 include an integrated circuit (IC) chip, a central processing unit (CPU), a general purpose processing unit (GPU), a microprocessor, a field programmable gate array (FPGA), a collection of logic gates, transistors, resistors, capacitors, inductors, diodes, etc. Some or all of processing circuitry 132 can be disposed on a printed circuit board (PCB) or set of PCBs. It should be understood that any appropriate type or set of electrical components can be suitable for inclusion in processing circuitry 132.
[0029] Selected elements of transceiver 116 or transceiver 114 can take the form of a pluggable card or controller of device 110. For example, selected elements of transceiver 118 or transceiver 116 can be implemented on a network interface card (NIC).
[0030] Device 112 can include a transceiver 136 for transmitting and receiving signals, e.g., data signals, over a channel 109 of communication network 108. The same or similar structure of transceiver 116 can apply to transceiver 134, and therefore, the structure of transceiver 138 is not described separately.
[0031] Although not explicitly shown, it is understood that devices 110 and 112, and transceivers 116 and 136, can include other processing devices, storage devices, and / or communication interfaces typically associated with computing tasks, e.g., transmitting and receiving data.
[0032] In at least one embodiment, devices 110 and 112 each include a MACsec device. Communications can flow in both directions between devices 110 and 112, with the first MACsec device being an intermediary network device for securing communications between device 110 and device 112. Communication network 108 can also include network links (whether wired or wireless) between MACsec devices, which in some embodiments can be over a relatively large distance. The network links can typically be implemented with twisted pair cable or fiber optic cable.
[0033] Device 110 is a network device, e.g., a switch, that includes a plurality of ports and a network processing element (e.g., processing circuitry 132). As described herein, device 110 can operate in two modes and can implement standard cryptographic operations for native networks and overlay networks, while having the flexibility of operating in both modes using programmable path selection circuitry 140 coupled to a security IC 142 (e.g., a MACsec device or an IPsec IC device). Programmable path selection circuitry 140 can change connectivity within or outside of the cryptographic device to provide greater flexibility. Programmable path selection circuitry 140 enables both sides of the cryptographic device to encrypt or decrypt, allowing for encryption of clear incoming data before processing by the network processing element. Additional details of programmable path selection circuitry 140 and security IC 142 are described below with reference to Figure 1B Additional details of programmable path selection circuitry 140 and security IC 142 are described below with reference to
[0034] Figure 1Bis a block diagram of a network device 150 according to at least some embodiments. The network device 150 includes a plurality of ports 152, a network processing element 154, e.g., a switch ASIC (similar to the processing circuitry 132 described above), a programmable path selection circuit 140, and a security IC 142, e.g., a MACsec device or an IPsec IC device. In at least one embodiment, the programmable path selection circuit 140 is configured to operate in a first mode or a second mode. In the first mode, the programmable path selection circuit 140 routes a first outgoing packet to the security IC 142 for encryption before transmission on one of the plurality of ports 152. Further, in the first mode, the programmable path selection circuit 140 routes a first incoming packet received on one of the plurality of ports 152 to the security IC 142 for decryption. In the second mode, the programmable path selection circuit 140 routes a second incoming packet to the security IC 142 for encryption before processing by the network processing element 154.
[0035] In another embodiment, in the second mode, the programmable path selection circuit 140 routes a second outgoing packet to the security IC 142 for decryption by the network processing element 154 afterwards.
[0036] In another embodiment, in the first mode, the programmable path selection circuit 140 routes a first outgoing packet to the security IC 142 to obtain an encrypted packet. The programmable path selection circuit 140 transmits the encrypted packet on a first port of the plurality of ports 152. In at least one embodiment, the first port is a protected port. In another implementation, in the first mode, the programmable path selection circuit 140 receives a first incoming packet on a second port of the plurality of ports 152. In at least one embodiment, the second port is a protected port. The programmable path selection circuit 140 routes the first incoming packet to the security IC 142 to obtain a decrypted packet and routes the decrypted packet to the network processing element 154.
[0037] In at least one embodiment, in the second mode, the programmable path selection circuit 140 receives a first incoming packet on a first port of the plurality of ports 152 and routes a first outgoing packet to the security IC 142 to obtain an encrypted packet. The programmable path selection circuit 140 routes the encrypted packet to the network processing element 154 to obtain an encapsulated packet. The encapsulated packet is transmitted on a second port of the plurality of ports 152. The second port can be a protected port.
[0038] In at least one embodiment, in the second mode, the programmable path selection circuit 140 routes the first outgoing packet to the secure IC 142 to obtain a decrypted packet and sends the decrypted packet on a second port of the plurality of ports 152. In at least one embodiment, the second port is a non-protected port.
[0039] As described above, the programmable path selection circuit 140 can be coupled to the secure IC 142 and provide routing to the secure IC 140 in two modes (e.g., a first mode and a second mode) as shown and described in the example paths. Figures 2A-2B
[0040] Figure 2A is a block diagram of a network device 200 in which the programmable path selection circuit 140 is operating in a first mode in accordance with at least some embodiments. The network device 200 includes a set of ports 202, a set of secure ICs 242 (also referred to as cryptographic circuits), and a network processing element 204. During operation in the first mode, the network device 200 receives a first incoming packet 201 on a first port 202(1). In one embodiment, the first incoming packet 201 includes a MACsec encrypted packet. The programmable path selection circuit 140 routes the first incoming packet 201 to a first secure IC 242(1) for decryption. After the first secure IC 242(1) decrypts the first incoming packet 201, the programmable path selection circuit 140 routes the decrypted packet 203 to the network processing element 204. The decrypted packet 204 can be a clear Vxlan packet. Alternatively, the decrypted packet 230 can not be encapsulated. The network processing element 204 can process the Vxlan packet. For example, the network processing element 204 can determine where to route the packet, whether to encapsulate the packet or decapsulate the packet, etc. The network processing element 204 can send an outgoing packet 205 to a second port 202(2). In at least one embodiment, the programmable path selection circuit 140 can route the outgoing packet 205 to a second secure IC 242(3) for encryption as an encrypted packet 207 before sending via the second port 202(2). The encrypted packet 207 is sent out on the second port 202(2). In at least one embodiment, the first port 202(1) and the second port 202(2) are protected ports. In another embodiment, the first port 202(1) is a protected port, the second port 202(2) is not a protected port, and the outgoing packet is not encrypted.
[0041] Figure 2B is a block diagram of a network device 200 in which the programmable path selection circuit 140 is operating in a second mode in accordance with at least some embodiments.
[0042] During operation in the second mode, network device 200 receives a first incoming packet 251 on first port 202(1). In one embodiment, first incoming packet 251 comprises a MACsec encrypted packet. Programmable path selection circuit 140 routes first incoming packet 251 to network processing element 204 for processing (e.g., decapsulating) instead of decryption by first security IC 242(1). This can be necessary in order to enable security IC 242(2) to decrypt the packet. Network processing element 204 can process the overlay information in first incoming packet 251 to obtain an outgoing packet 253. It should be noted that network processing element 204 can process the MAC header from the overlay information and only process the payload. This is because in this case the rest of the overlay header is still encrypted. Outgoing packet 253 can comprise a MACsec encrypted packet. Programmable path selection circuit 140 can route outgoing packet 253 to second security IC 242(2) for decryption to obtain a decrypted packet 255 prior to transmission via second port 202(2). Decrypted packet 255 is transmitted out on second port 202(2). In at least one embodiment, first port 202(1) is a protected port and second port 202(2) is an unprotected port.
[0043] In another embodiment, network device 200 can receive an incoming packet on an unprotected port. Programmable path selection circuit 140 can route the incoming packet to a security IC for encryption prior to processing by network processing element 204. Network processing element 204 can add overlay or payload information to the packet and transmit an outgoing packet as an overlay encrypted packet, where another receiving device can process the overlay information prior to decrypting the packet as described above with respect to Figure 2B As described above, network processing element 204 can process the payload and unencrypted portions of the overlay.
[0044] Programmable path selection circuit 140 can be used to allow network processing element 204 to process overlay or payload information in a packet. Programmable path selection circuit 140 provides flexibility in routing incoming and outgoing packets to cryptographic circuits in either direction based on mode (as shown in Figures 3A-3B
[0045] Figure 3A is a block diagram of network device 300 with a path through encryption circuit and decryption circuit in a first mode according to at least some embodiments. Network device 300 includes first port 302, second port 304, encryption circuit 306, and decryption circuit 308. Programmable path selection circuit 140 provides a path between first port 302 and second port 304 through encryption circuit 306 and decryption circuit 308 in the first mode. In the first mode, second port 304 receives a first packet, programmable path selection circuit 140 routes the first packet to encryption circuit 306 for encryption, and routes the encrypted packet to first port 302. Programmable path selection circuit 140 routes the first packet in a first path 301 between second port 304 and first port 302 through encryption circuit 306. In the first mode, first port 302 receives a second packet, programmable path selection circuit 140 routes the second packet to decryption circuit 308 for decryption. Programmable path selection circuit 140 routes the decrypted packet to second port 304. Programmable path selection circuit 140 routes the second packet in a second path 303 between first port 302 and second port 304 through decryption circuit 308. For simplicity, Figure 3A Network processing elements that process incoming and outgoing packets are not shown.
[0046] Figure 3B is a block diagram of network device 300 with a path to encryption circuit and decryption circuit in a second mode using programmable multiplexers according to at least some embodiments. Programmable path selection circuit 140 provides a path between first port 302 and second port 304 and through encryption circuit 306 and decryption circuit 308 in the second mode. In the second mode, second port 304 receives a first packet, programmable path selection circuit 140 routes the first packet to encryption circuit 306 or decryption circuit 308 using programmable multiplexer 310, and routes the encrypted or decrypted packet to first port 302 using programmable multiplexer 310. Programmable path selection circuit 140 routes the first packet in a first path 351 between second port 304 and first port 302 through encryption circuit 306 or decryption circuit 308. In the second mode, first port 302 receives a second packet, programmable path selection circuit 140 routes the second packet to encryption circuit 306 or decryption circuit 308 using programmable multiplexer 310, and routes the encrypted or decrypted packet to second port 304 using programmable multiplexer 310. Programmable path selection circuit 140 routes the second packet in a second path 303 between first port 302 and second port 304 through encryption circuit 306 or decryption circuit 308. For simplicity, Figure 3B Network processing elements that process incoming and outgoing packets are not shown.
[0047] In at least one embodiment, in a first mode, programmable path selection circuitry 140 using programmable multiplexer 310 can route a first outgoing packet to a cryptographic circuit, such as a security IC (e.g., a MACsec device or an IPsec device), to obtain an encrypted packet and send the encrypted packet on an outgoing protected port. Programmable path selection circuitry 140 using programmable multiplexer 310 can receive a first incoming packet on an incoming protected port, route the first incoming packet to the security IC to obtain a decrypted packet, and route the decrypted packet to a network processing element.
[0048] In at least one embodiment, in a second mode, programmable path selection circuitry 140 using programmable multiplexer 310 can receive a first incoming packet on an incoming port. To obtain an encrypted packet, programmable multiplexer 310 routes the first incoming packet to a cryptographic circuit, such as a security IC (e.g., a MACsec device or an IPsec device). Programmable multiplexer 310 routes the encrypted packet to a network processing element to obtain an encapsulated packet. In addition to including the encrypted packet, the encapsulated packet can include overlay information. Programmable multiplexer 310 routes the encapsulated packet on an outgoing protected port. In another embodiment, in the second mode, programmable path selection circuitry 140 can route a first outgoing packet to a security integrated circuit to obtain a decrypted packet and send the decrypted packet on an outgoing port.
[0049] In at least one embodiment, an operator can select which paths 351 and 353 packets should take to reach encryption circuit 306 and decryption circuit 308. For the second mode, incoming packets from “unprotected” ports can be routed to encryption circuit 306, while incoming packets from protected ports can be routed out with or without being routed to encryption circuit 306 or decryption circuit 308. Outgoing packets to “unprotected” ports can be routed to decryption circuit 308, while outgoing packets from protected ports can be routed out with or without being routed to encryption circuit 306 or decryption circuit 308.
[0050] Figure 4is a block diagram of a network device 400 having a path selection circuit 140 according to at least some embodiments. In at least some embodiments, the network device 400 includes an input interface 404, a MACsec circuit 412, a network processing element 426, and an output interface 413. The input interface 404 can be coupled to an incoming network link 401 through which the network device 400 receives network packets. The input interface 404 is further coupled to the path selection circuit 140. The path selection circuit 140 can be coupled to at least two different paths to which the path selection circuit 140 can route incoming data packets 405 to the MACsec circuit 412, the network processing element 426, or both. Once the packets are processed, the path selection circuit 140 can send outgoing data packets 407 to the output interface 413, for example, to a destination network device through an outgoing network link 421.
[0051] More specifically, in at least some embodiments, the path selection circuit 140 is coupled between the input interface 404 and the output interface 413 to route the incoming data packets 405 to the MACsec circuit 412 before or after processing by the network processing element 426 depending on the mode of the network device 400.
[0052] In at least one embodiment, the MACsec circuit 412 can perform authentication, integrity checks, and optional encryption or decryption on the incoming data packets 405 or the outgoing data packets 407 as described herein. In at least some embodiments, the MACsec circuit 412 includes a MACsec encryptor 414, a MACsec decryptor 418, a set of counters 422, and a replay protector 424, all of which can be hardware. In one embodiment, the MACsec encryptor 414 and the MACsec decryptor 418 are combined into a single encryption / decryption engine. The MACsec encryptor 414 and the MACsec decryptor 418 can be used to generate a tag for integrity checks, and the replay protector 424 can add to the security tag to provide replay protection. The MACsec encryptor 414 can optionally encrypt the packets before sending the secure packets to the output interface 413 or after sending the secure packets to the network processing element 426 as described herein. If the packets have been encrypted, the MACsec decryptor 418 can decrypt the secure packets to generate unencrypted packets before sending the unencrypted packets to the output interface 413 or before sending the secure packets to the network processing element 426 as described herein. As previously noted, encryption or decryption is optional. Thus, the MACsec circuit 412 can encrypt or decrypt the packets to provide point-to-point encryption of the packets between a first network circuit and a second network circuit. The MACsec circuit 412 can include additional components and functionality, but is shown in simplified form for purposes of explanation.
[0053] In at least one embodiment, network processing element 426 can perform encapsulation of packets. In at least some embodiments, network processing element 426 includes encapsulator 428 and decapsulator 430, both of which can be hardware.
[0054] In one embodiment, encapsulator 428 and decapsulator 430 are combined into a single encapsulation engine. Encapsulator 428 and decapsulator 430 can be used to encapsulate packets with overlay or bearer information, or extract overlay or bearer information from packets. As described herein, encapsulator 428 can selectively encapsulate packets prior to sending the secure packets to output interface 413.
[0055] Figure 5 is a flowchart of a method 500 for routing an incoming packet to be encrypted and encapsulated in a network device, in accordance with at least some embodiments. Method 500 can be performed by processing logic that comprises hardware, software, firmware, or any combination thereof. In at least one embodiment, method 500 is performed by any of devices 110 or 112 of FIG. 1, or Figure 1B network devices 150 of FIG. 1. In at least one embodiment, method 500 is performed by any of network device 200 of FIG. 2, network device 300 of FIG. 3, and Figure 4 network device 400 of FIG. 4.
[0056] Consider Figure 5 Method 500 begins by the processing logic receiving an incoming packet at a first port of a network device (block 502). The processing logic routes the incoming packet to an encryption circuit to be encrypted as an encrypted packet (block 504). The processing logic routes the encrypted packet to a network processing element to be encapsulated as an encapsulated packet (block 506). The processing logic routes the encapsulated packet to a second port of the network device (block 508).
[0057] In another embodiment, the processing logic receives an outgoing packet from the network processing element. The processing logic routes the outgoing packet to a decryption circuit to be decrypted as a decrypted packet. The processing logic routes the decrypted packet to the second port.
[0058] In another embodiment, the processing logic receives a second incoming packet at the first port. The processing logic routes the second incoming packet to a decryption circuit to be decrypted as a second decrypted packet. The processing logic routes the second decrypted packet to the network processing element.
[0059] In another embodiment, the processing logic receives a second outgoing packet from the network processing element. The processing logic routes the second outgoing packet to an encryption circuit to be encrypted as a second encrypted packet. The processing logic routes the second encrypted packet to the second port.
[0060] In another embodiment, the processing logic receives a second incoming packet at a third port of the network device. In at least one embodiment, the third port is a protected port. The processing logic routes the second incoming packet to a network processing element for encapsulation as a second encapsulated packet. The processing logic routes the second encapsulated packet to a fourth port of the network device. In at least one embodiment, the fourth port is a protected port.
[0061] Figure 6 is a flowchart of a method 600 for operating a network device in a first mode or a second mode to route incoming packets in the network device, according to at least some embodiments. The method 600 can be performed by processing logic that can comprise hardware, software, firmware, or any combination thereof. In at least one embodiment, the method 600 is performed by any of the network devices 150 of FIG. 1 or the devices 112 of FIG. 1, or the network device 200 of FIG. 2, the network device 300 of FIG. 3, and the network device 400 of FIG. 4. Figure 1B is a flowchart of a method 600 for operating a network device in a first mode or a second mode to route incoming packets in the network device, according to at least some embodiments. The method 600 can be performed by processing logic that can comprise hardware, software, firmware, or any combination thereof. In at least one embodiment, the method 600 is performed by any of the network devices 150 of FIG. 1 or the devices 112 of FIG. 1, or the network device 200 of FIG. 2, the network device 300 of FIG. 3, and the network device 400 of FIG. 4. Figure 4 is a flowchart of a method 600 for operating a network device in a first mode or a second mode to route incoming packets in the network device, according to at least some embodiments. The method 600 can be performed by processing logic that can comprise hardware, software, firmware, or any combination thereof. In at least one embodiment, the method 600 is performed by any of the network devices 150 of FIG. 1 or the devices 112 of FIG. 1, or the network device 200 of FIG. 2, the network device 300 of FIG. 3, and the network device 400 of FIG. 4.
[0062] Referring to Figure 6 , the method 600 begins with the processing logic receiving an incoming packet at a first port of the network device (block 602). The processing logic determines whether the network device is operating in a first mode (block 603). If the processing logic determines at block 603 that the network device is operating in the first mode, the processing logic routes the incoming packet to a decryption circuit for decryption as a decrypted packet (block 614). The processing logic routes the decrypted packet to a network processing element for processing (block 616). The network processing element can process superimposed information or carried information contained in the packet. The processing logic routes the decrypted packet to a second port of the network device (block 618).
[0063] If the processing logic determines at block 603 that the network device is not operating in the first mode, the processing logic routes the incoming packet to an encryption circuit for encryption as an encrypted packet (block 604). The processing logic routes the encrypted packet to a network processing element for encapsulation as an encapsulated packet (block 606). The processing logic routes the encapsulated packet to a second port of the network device (block 608).
[0064] In another embodiment of the first mode, the processing logic receives a decrypted packet on the second port of the network device. The processing logic routes the decrypted packet to the network processing element to process the decrypted packet. The processing logic routes the decrypted packet to the encryption circuit to encrypt the decrypted packet as an encrypted packet. The processing logic routes the encrypted packet to the first port. In another embodiment of the second mode (i.e., not in the first mode), the processing logic receives an encapsulated packet on the second port of the network device. The processing logic routes the encapsulated packet to the network processing element to process the packet. The processing logic routes the processed packet to the encryption circuit to encrypt as an encrypted packet and routes the encrypted packet to the first port.
[0065] Figure 7 A computer system 700 including programmable path selection circuit 140 is shown, in accordance with at least one embodiment. In at least one embodiment, computer system 700 can be a system with interconnected devices and components, a SOC, or some combination. In at least one embodiment, computer system 700 is formed by a processor 702 that can include execution units to execute an instruction. In at least one embodiment, computer system 700 can include, without limitation, components such as processor 702 to employ execution units including logic to execute an algorithm for processing data. In at least one embodiment, computer system 700 can include processors such as Intel® Core® i7™, Xeon™, XScale™, and / or StrongARM™, which can be obtained from Intel Corporation of Santa Clara, California, ARM® Cortex™, Core TM or Nervana TM processors, although other systems (including PCs, workstations, set-top boxes, etc. with other microprocessors) can also be used. In at least one embodiment, computer system 700 can execute a version of the WINDOWS operating system available from Microsoft Corporation of Redmond, Washington. Other
[0066] In at least one embodiment, the computer system 700 can be used with other devices, such as handheld devices and embedded applications. Some examples of handheld devices include cellular phones, Internet Protocol devices, digital cameras, personal digital assistants (“PDAs”), and handheld PCs. In at least one embodiment, embedded applications may include microcontrollers, digital signal processors (DSPs), SoCs, network computers (“NetPCs”), set-top boxes, network hubs, wide area network (“WAN”) switches, or any other system capable of executing one or more instructions. In one embodiment, the computer system 700 can be used with devices such as graphics processing units (GPUs), network adapters, central processing units, and network devices such as switches (e.g., high-speed direct GPU-to-GPU interconnects, such as NVIDIA GH100 NVLINK or NVIDIA Quantum 2 64-port InfiniBand NDR switches).
[0067] In at least one embodiment, the computer system 700 may include, but is not limited to, a processor 702, which may include, but is not limited to, one or more execution units 707 configured to execute a Computational Unified Device Architecture (“CUDA”). (Developed by NVIDIA Corporation, Santa Clara, California) In at least one embodiment, the CUDA program is at least a part of a software application written in the CUDA programming language. In at least one embodiment, the computer system 700 is a single-processor desktop or server system. In at least one embodiment, the computer system 700 may be a multiprocessor system. In at least one embodiment, the processor 702 may include, but is not limited to, a CISC microprocessor, a RISC microprocessor, a VLIW microprocessor, a processor implementing instruction set combinations, or any other processor device, such as a digital signal processor. In at least one embodiment, the processor 702 may be coupled to a processor bus 710, which allows data signals to be transmitted between the processor 702 and other components in the computer system 700.
[0068] In at least one embodiment, processor 702 can include, without limitation, a level 1 (“L1”) internal cache memory (“cache”) 704. In at least one embodiment, processor 702 can have a single internal cache or multiple levels of internal caches. In at least one embodiment, cache memory can reside in processor 702 external to processor 702. In at least one embodiment, processor 702 can also include a combination of internal caches and external caches that reside in processor 702. In at least one embodiment, a register file 706 can store different types of data, including, without limitation, integer registers, floating point registers, status registers, and instruction pointer registers.
[0069] In at least one embodiment, execution unit 707, including, without limitation, logic to perform integer and floating point operations, also resides in processor 702. Processor 702 can also include a microcode (“ucode”) read only memory (“ROM”). In at least one embodiment, execution unit 707 can include logic to handle a compressed instruction set 709. In at least one embodiment, by using a compressed instruction set 709 in a general-purpose processor 702, along with associated circuitry to execute the instructions, many multimedia applications can be accelerated by using compact data representations. In at least one embodiment, by using a full width of a processor’s data bus to operate on packed data, many multimedia applications can be executed more efficiently and with less power than on processors lacking such data buses.
[0070] In at least one embodiment, execution unit 708 can also be used to implement a microcontroller, embedded processor, graphics device, DSP, and other types of logic device. In at least one embodiment, computer system 700 can include, without limitation, a memory 720. In at least one embodiment, memory 720 can be implemented using DRAM, SRAM, Flash, or other type of storage technology. Memory 720 can store instructions 719 and / or data 721 that can be executed by processor 702.
[0071] In at least one embodiment, a system logic chip can be coupled to processor bus 710 and memory 720. In at least one embodiment, system logic chip can include, without limitation, a memory controller hub (“MCH”) 716 with which processor 702 can communicate over processor bus 712. In at least one embodiment, MCH 716 can provide a high bandwidth memory path 718 to memory 720 for instruction and data storage and for storage of graphics commands, data, and textures for processing by graphics processor unit 712. In at least one embodiment, MCH 716 can direct data signals between processor 702, memory 720, and other components in computer system 700 and can bridge data signals between processor bus 710, memory 720, and system I / O 722. In at least one embodiment, system logic chip can provide a graphics port, which is a sub- set of the high bandwidth memory path 718, dedicated to providing graphics commands, data, and textures to graphics processor unit 712. In at least one embodiment, MCH 716 can be coupled to memory 720 through high bandwidth memory path 718, and graphics / video card 712 can be coupled to MCH 716 through an Accelerated Graphics Port (“AGP”) interconnect 714.
[0072] In at least one embodiment, computer system 700 can use system I / O 722, which is a specialized hub interface bus, to couple MCH 716 to I / O controller hub (“ICH”) 730. In at least one embodiment, ICH 730 can provide a direct connection to some I / O devices and can be used as a bridge to other I / O devices. In at least one embodiment, the local I / O bus can include, without limitation, a high-speed I / O bus for connecting peripherals to memory 720, chipset, and processor 702. Examples can include, without limitation, a data storage device 724, a graphics processor unit 712, a digital signal processor (“DSP”) 715, a crypto processor 716, a keyboard and mouse controller 723, a wireless transceiver 726, and a network controller 734. In at least one embodiment, data storage device 724 can include a hard disk drive, a floppy disk drive, a CD-ROM device, a flash memory device, or other mass storage device.
[0073] In at least one embodiment, Figure 7 A system including interconnected hardware devices or “chips” is shown. In at least one embodiment, Figure 7 An exemplary SoC can be shown. In at least one embodiment, Figure 7 Devices shown can be interconnected with proprietary interconnects, standardized interconnects (e.g., PCIe), or some combination thereof. In at least one embodiment, one or more components of system 700 are interconnected using Compute Express Link (“CXL”) interconnects.
[0074] Other variations are within the spirit of the present disclosure. Thus, while the disclosed technology is susceptible to various modifications and alternative constructions, certain illustrated embodiments thereof are shown in the drawings and have been described above in detail. It should be understood, however, that there is no intention to limit the disclosure to the specific form or forms disclosed, but on the contrary, the intention is to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the disclosure, as defined in the appended claims.
[0075] The use of the terms "a" and "an" and "the" and similar referents in the context of describing the disclosed embodiments (especially in the context of the following claims) are to be construed to cover both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context. The terms "comprising," "having," "including," and "containing" are to be construed as open-ended terms (meaning "including, but not limited to,") unless otherwise noted. The term "connected" (as used in the context of the "connected") is to be construed as partly or fully encompassed in, attached to, or joined together with, even if there are some intervening materials. Unless specifically stated otherwise, reference herein to a numerical range is intended to use as a shorthand method of referring individually to each separate value falling within the range, and each separate value is incorporated in the specification as if it were individually recited herein. In at least one embodiment, the use of the term "set" (e.g., "set of items") or "subset" is to be construed as a non-empty set of one or more members, unless otherwise indicated or contradicted by context. Furthermore, the term "subset" of a corresponding set does not necessarily denote a proper subset of the corresponding set, but rather the subset and the corresponding set can be equal, unless otherwise indicated or contradicted by context.
[0076] Unless explicitly stated otherwise or apparent from context, a phrase such as "at least one of A, B, and C" or "at least one of A, B, or C" shall indicate that the group is inclusive of any of the items, elements, etc. individually or any combination of the items, elements, etc. For example, the phrases "at least one of A, B and C" and "at least one of A, B, or C" shall cover: (a) A alone, (b) B alone, (c) C alone, (d) at least one of A and B together, (e) at least one of A and C together, (f) at least one of B and C together, and (g) all of A, B, and C together. In other words, the phrase "at least one of A, B, and C" or "at least one of A, B, or C" shall mean that the group is an inclusive- or group. In addition, unless otherwise stated or clear from context, the term "plurality" shall indicate a state of more than one (e.g., a plurality of items shall indicate more than one item). In at least one embodiment, a plurality of items shall indicate at least two items, but if explicitly indicated or otherwise clear from context, a plurality of items can indicate more than two items. Further, unless otherwise stated or clear from context, the phrase "based on" is intended to refer to the established fact that something is based on a combination of more than one thing. For example, "based on" is intended to mean "based, at least in part, on" unless explicitly stated otherwise or clear from context.
[0077] Unless otherwise indicated herein, or otherwise clearly contradicted by context, the operations of a process described herein can be performed in any suitable order. In at least one embodiment, processes such as those described herein (or variations and / or combinations thereof) are performed under the control of one or more computer systems configured with executable instructions, and are implemented as code (e.g., executable instructions, one or more computer programs or one or more applications) executing collectively on one or more processing units, by hardware or combinations thereof. In at least one embodiment, the code is stored on a computer-readable storage medium, such as a computer program product, which is readable by a computer system in the computing device. In at least one embodiment, the code product has instructions executable by one or more processors, and thus the code product, when executed by the one or more processors, causes the computer system to carry out operations described herein. In at least one embodiment, a computer-readable storage medium is a non-transitory computer-readable storage medium, which excludes transitory signals (e.g., a propagating transient electric or electromagnetic transmission) but includes non-transitory data storage circuitry (e.g., buffers, cache, and queues). In at least one embodiment, code (e.g., executable or source code) is stored on a set of one or more non-transitory computer-readable storage media (or other memory for storing executable instructions) having executable instructions stored thereon that, when executed by one or more processors of a computer system (i.e., as a result of being executed), cause the computer system to perform operations described herein. In at least one embodiment, a set of non-transitory computer-readable storage media includes multiple non-transitory computer-readable storage media, and one or more of the individual non-transitory storage media in the multiple non-transitory computer-readable storage media lack all of the code, with the multiple non-transitory computer-readable storage media collectively storing the entire code. In at least one embodiment, executable instructions are executed so that different instructions are executed by different processors.
[0078] Accordingly, in at least one embodiment, a computer system is configured to implement one or more services that individually or collectively perform operations of processes described herein, and such a computer system is configured with applicable hardware and / or software that enables implementation of operations. Moreover, a computer system implementing at least one embodiment of the present disclosure is a single device, and in another embodiment is a distributed computer system that includes multiple devices operating in different manners such that the distributed computer system performs operations described herein, and such that a single device does not perform all operations.
[0079] The use of any and all examples, or exemplary language (e.g., "such as") provided herein is intended merely to better illuminate embodiments of the disclosure and does not pose a limitation on the scope of the disclosure unless otherwise claimed. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0080] All references cited herein, including publications, patent applications, and patents, are hereby incorporated by reference to the same extent as if each reference were individually and specifically incorporated by reference and were specifically stated to be incorporated by reference herein in its entirety.
[0081] In the description and claims, the terms“coupled” and“connected,” along with their derivatives, can be used. It should be understood that these terms are not intended as synonyms for each other. Rather, in particular embodiments, “connected” or“coupled” can be used to indicate that two or more elements are in direct or indirect physical or electrical contact with each other. “Coupled” can also mean that two or more elements are not in direct contact with each other, but yet still co-operate or interact with each other.
[0082] Unless specifically stated otherwise, it can be appreciated that throughout the specification terms such as“processing,”“computing,”“calculating,”“determining,” or the like, refer to the action and / or processes of a computer or computing system, or similar electronic
[0083] In a similar manner, the term“processor” can refer to any device or portion of a device that processes electronic data from registers and / or memory to transform that electronic data into other electronic data that can be stored in registers and / or memory. As a non-limiting example, a“processor” can be a network device or a MACsec device. A“computing platform” can include one or more processors. As used herein,“software” processes can include, for example, software and / or hardware entities that perform work over time, such as tasks, threads, and intelligent agents. Likewise, each process can refer to multiple processes to sequentially or concurrently execute instructions, either continuously or intermittently. In at least one embodiment, the terms“system” and“method” can be used interchangeably herein, as long as the system can embody one or more methods, and the method can be considered a system.
[0084] In this document, obtaining, acquiring, receiving, or importing analog or digital data into a subsystem, computer system, or computer-implemented machine can be referenced. In at least one embodiment, the process of obtaining, acquiring, receiving, or importing analog and digital data can be accomplished in a variety of ways such as, for example, by receiving data as a parameter to a function call or call to an application programming interface. In at least one embodiment, the process of obtaining, acquiring, receiving, or importing analog or digital data can be accomplished by transferring data via a serial or parallel interface. In at least one embodiment, the process of obtaining, acquiring, receiving, or importing analog or digital data can be accomplished by transferring data from a providing entity to an acquiring entity via a computer network. In at least one embodiment, providing, outputting, transferring, sending, or presenting analog or digital data can also be referenced. In various examples, the process of providing, outputting, transferring, sending, or presenting analog or digital data can be accomplished by transferring data as an input or output parameter to a function call, a parameter to an application programming interface, or an interprocess communication mechanism.
[0085] Although the description herein sets forth example embodiments of the described technology, other architectures can be used to implement the described functionality, and it is intended that the appended claims cover all such architectures. Moreover, although specific allocations of roles can be defined above for the purpose of description, various functions and roles can be distributed and divided among various embodiments depending on circumstances.
[0086] Moreover, although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described. Rather, the specific features and acts are disclosed as example forms of implementing the claims.
Claims
1. A network device, comprising: Multiple ports; Network processing components; A programmable path selection circuit coupled to the plurality of ports and the network processing element; as well as A secure integrated circuit coupled to the programmable path selection circuit, wherein the programmable path selection circuit is configured to operate in a first mode and a second mode, wherein: i) In the first mode, the first outgoing packet is routed to the security integrated circuit for encryption before being sent on one of the plurality of ports, and the first incoming packet received on one of the plurality of ports is routed to the security integrated circuit for decryption; and ii) In the second mode, the second incoming packet is routed to the security integrated circuit for encryption before being processed by the network processing element.
2. The network device as described in claim 1, wherein, In the second mode, the programmable path selection circuit is used to route the second outgoing packet to the secure integrated circuit for decryption after processing by the network processing element.
3. The network device as described in claim 1, wherein, In the first mode, the programmable path selection circuit is used for: The first outgoing packet is routed to the secure integrated circuit to obtain an encrypted packet; The encrypted packet is sent on a first port of the plurality of ports, wherein the first port is a protected port; A first incoming packet is received on a second port of the plurality of ports, wherein the second port is a protected port; The first incoming packet is routed to the secure integrated circuit to obtain the decrypted packet; as well as The decrypted packets are routed to the network processing element.
4. The network device as described in claim 1, wherein, In the second mode, the programmable path selection circuit is used for: Receive the first incoming packet on the first port of the plurality of ports; The first incoming packet is routed to the secure integrated circuit to obtain an encrypted packet; as well as The encrypted packets are routed to the network processing element to obtain encapsulated packets, wherein the encapsulated packets are sent on a second port of the plurality of ports, wherein the second port is a protected port.
5. The network device as described in claim 4, wherein, In the second mode, the programmable path selection circuit is used for: The first outgoing packet is routed to the secure integrated circuit to obtain the decrypted packet; as well as The decrypted packet is sent to the second port among the plurality of ports.
6. The network device of claim 5, wherein the second port is an unprotected port.
7. The network device of claim 1, wherein the security integrated circuit is a Media Access Control Security (MACsec) device.
8. The network device of claim 1, wherein the security integrated circuit is an Internet Protocol Security (IPsec) device.
9. An apparatus comprising: First port; Second port; Third port; Fourth port; A path selection circuit coupled to the first port, the second port, the third port, and the fourth port; A decryption circuit coupled to the path selection circuit; An encryption circuit coupled to the path selection circuit; as well as Network processing elements coupled to the path selection circuit, wherein the path selection circuit is used for: In the first mode, the first incoming packet received on the first port is routed to the decryption circuit so that the first incoming packet is decrypted before being routed to the network processing element to obtain the first outgoing packet; In the first mode, the first outgoing packet is routed to the encryption circuit so that the first outgoing packet is encrypted before being sent on the second port; as well as In the second mode, the second incoming packet received on the third port is routed to the encryption circuit so that the second incoming packet is encrypted before being routed to the network processing element.
10. The apparatus of claim 9, wherein the network processing circuitry is configured to receive the second incoming packet and generate a second outgoing packet, wherein the path selection circuitry is configured to route the second outgoing packet to the decryption circuitry to decrypt the second outgoing packet before sending it to the fourth port, wherein the second outgoing packet received at the decryption circuitry is an encapsulated packet.
11. The apparatus of claim 10, further comprising: A Media Access Control Security (MACsec) device including the encryption circuit and the decryption circuit.
12. The apparatus of claim 10, further comprising: An Internet Protocol Security (IPsec) device including the encryption circuit and the decryption circuit.
13. The apparatus of claim 10, wherein the path selection circuit is used for: In the first mode, the first outgoing packet is routed to the encryption circuit; and In the second mode, the second outgoing packet is routed to the decryption circuit.
14. The apparatus of claim 10, wherein the encapsulation grouping includes overlay information.
15. A method comprising: Receive the first incoming packet at the first port of the network device; In the first mode, the first incoming packet is routed to the decryption circuitry of the network device for decryption before being routed to the network processing element to obtain the first outgoing packet; In the first mode, the first outgoing packet is routed to the encryption circuitry of the network device so that the first outgoing packet is encrypted before being sent to the second port of the network device; The second incoming packet is received at the third port of the network device; as well as In the second mode, the second incoming packet is routed to the encryption circuit so that the second incoming packet is encrypted before being routed to the network processing element to obtain an encrypted packet.
16. The method of claim 15, further comprising: Receive outgoing packets from the network processing element, the outgoing packets corresponding to the encrypted packets; The outgoing packets are routed to the decryption circuit for decryption into decrypted packets; as well as The decrypted packet is routed to the fourth port of the network device.
17. The method of claim 15, further comprising: Receive outgoing packets from the network processing element, the outgoing packets corresponding to the encrypted packets; as well as The outgoing packets are routed to the fourth port of the network device.
18. The method of claim 15, further comprising: Receive a second outgoing packet from the network processing element, the second outgoing packet corresponding to the second incoming packet; The second outgoing packet is routed to the encryption circuit to be encrypted into a second encrypted packet; as well as The second encrypted packet is routed to the fourth port.
19. The method of claim 17, wherein the first port is a protected port; and The fourth port mentioned above is a protected port.
Citation Information
Patent Citations
System and method for authentication and security in a communication system
US20040255037A1
Connection setting of tone processing module
US20170124998A1
Non-random flowlet-based routing
US20190052567A1