High performance architecture for converged security systems and devices
By introducing network processing and security processing subsystems into communication equipment and utilizing a high-performance architecture with multiple interconnected engines, the problems of system complexity and poor flexibility in existing technologies are solved, and high-throughput network and security processing is achieved.
Patent Information
- Application Number
- CN202211540686.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-01-28
- Filing Date
- 2022-12-02
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2042-12-02
AI Technical Summary
Existing communication equipment in high-throughput networks is complex, expensive, and inflexible due to the use of multiple discrete components, making it unable to efficiently achieve networking and security functions.
It adopts a high-performance architecture that combines a network processing subsystem and a security processing subsystem. It utilizes multiple interconnected network processing engines and security processing engines to execute network and security functions in a single pipeline, operating asynchronously to improve throughput.
It achieves high-throughput network and security processing, avoids performance bottlenecks, and provides a flexible and efficient networking and security solution.
Smart Images

Figure CN116527295B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates generally to systems and methods for network communications. In particular, the present disclosure relates to systems and methods to provide a high performance architecture for converged security systems and appliances. BACKGROUND
[0002] Communications appliances provide various networking and security features, including switching and routing, traffic management, cryptographic features (e.g., encryption and decryption, authentication, etc.), filtering, and other such functions. As network throughput exceeds terabits per second, implementations of these complex systems utilizing many discrete components encounter bottlenecks. While some manufacturers have attempted configurations with fewer specialized components to increase throughput, this sacrifices flexibility and adds substantial expense as the system cannot perform all individual functions individually. SUMMARY
[0003] In one aspect, the present application relates to a system for high throughput network and security processing, comprising: a network processing subsystem comprising a plurality of interconnected network processing engines configured in a single pipeline; and a security processing subsystem coupled to and external to the network processing subsystem, the security processing subsystem comprising a plurality of interconnected security processing engines.
[0004] In another aspect, the present application relates to an appliance, comprising: a chassis; one or more physical communication interfaces positioned on a portion of the chassis; a network processing subsystem positioned within the chassis and coupled to the one or more physical communication interfaces, the network processing subsystem comprising a plurality of interconnected network processing engines configured in a single pipeline; and a security processing subsystem positioned within the chassis, coupled to and external to the network processing subsystem, the security processing subsystem comprising a plurality of interconnected security processing engines. BRIEF DESCRIPTION OF DRAWINGS
[0005] Various objects, aspects, features, and advantages of the present disclosure will become more fully apparent and better understood from the following detailed description, taken in conjunction with the accompanying drawings, in which like reference numerals designate identical, functionally similar, and / or structurally similar elements throughout the several views. In the drawings, like reference numerals refer to like elements throughout.
[0006] Figure 1 is a block diagram of an embodiment of an architecture for converged security systems and appliances;
[0007] Figure 2 is a block diagram of another embodiment of an architecture for converged security systems and appliances;
[0008] Figures 3A to 3Eis a block diagram of a deployment configuration of an embodiment of an architecture for converged security systems and devices;
[0009] Figure 4A is a block diagram depicting an embodiment of a network environment including one or more access points in communication with one or more devices or stations; and
[0010] Figure 4B and 4C is a block diagram depicting an embodiment of a computing device useful in connection with the methods and systems described herein.
[0011] The details of various embodiments of the methods and systems are set forth in the accompanying drawings and description below. DETAILED DESCRIPTION
[0012] The following IEEE standards, including any draft versions of this standard(s), are hereby incorporated by reference in their entirety and made part of this disclosure for all purposes: IEEE P802.11n TM ; and IEEE P802.11ac TM . While the disclosure can refer to aspects of these standards, the disclosure is in no way limited by these standards.
[0013] For the purpose of reading the descriptions of various embodiments below, the following descriptions of sections of the specification and their respective contents can be helpful:
[0014] Section A describes embodiments of systems and methods to provide a high performance architecture for converged security systems and devices; and
[0015] Section B describes network and computing environments that can be used to implement the embodiments described herein.
[0016] A. High performance architecture for secure systems and devices for fusion
[0017] Communications devices provide various networking and security features, including switching and routing, traffic management, cryptographic features, filtering, and other such functions. As network throughput exceeds terabits per second, embodiments of these complex systems utilizing many discrete components encounter bottlenecks. While some manufacturers have attempted configurations with fewer specialized components to increase throughput, this sacrifices flexibility and adds substantial expense as the system cannot perform all individual functions individually.
[0018] For example, a system providing networking and security features can be built from a wide variety of components, including:
[0019] • a switch / router component (e.g., ASIC) to perform networking and traffic management at high data rates;
[0020] • Cryptographic accelerator components to perform public key and symmetric encryption offload;
[0021] • Regular expression search (REGEX) acceleration components to perform pattern searches at high rates;
[0022] • General purpose central processing units (CPUs) for management, data processing, and other functions;
[0023] • Network interface cards (NICs) to allow traffic to traverse between the networking domain and the general purpose CPU domain; and
[0024] • Field programmable gate arrays (FPGAs) to implement many of the above functions, as well as specialized logic / control functions that allow the system to operate as a coherent whole.
[0025] The use of so many different types of components makes such systems complex, expensive, and susceptible to performance limitations. The overall performance of a given system is often constrained by bottlenecks in particular components. Very few, if any, of these components are built specifically for this type of system. From a business perspective, there is a lack of commercially available silicon solutions that are specifically targeted for this use case. Thus, given the widespread popularity of Internet connectivity and network-based applications, there is a strong need for systems and devices that support the fusion of data networking and data security functions at high data rates.
[0026] The present disclosure relates to systems and methods to provide an architecture for building high performance silicon components that support a rich set of networking and security features. The architecture is highly scalable, addressing the bottleneck issues discussed above and providing very high throughput. In addition, the architecture utilizes replaceable blocks or functional elements that can be programmed to perform various functions without sacrificing flexibility or performance. Where appropriate, many functions are hardware accelerated, while other functions are under the control of general purpose processors. In particular, in many embodiments, the architecture splits network and security functions into two functional and logical blocks, which in some embodiments can be physically located on the same die or integrated circuit, or can be split across separate integrated circuits. Network functions can be performed via an integrated NIC and accelerator subsystem with high throughput execution pipelines (e.g., 2 Tbp or higher in many embodiments). In many embodiments, network functions can be processed using a single clock (e.g., distributed among multiple functional network processing blocks). In many embodiments, security functions can be performed via the same or a separate clock. For example, in many embodiments, security functions can be performed asynchronously from network processing functions.
[0027] Figure 1is a block diagram of an embodiment of an architecture for a converged security system and device, which includes a network processing subsystem 100 (sometimes referred to as a network processor or network processor subsystem) and a security processing subsystem 110 (sometimes referred to as a security processor or security processor subsystem). Although sometimes referred to as a processor, in many embodiments each of the network processor 100 and the security processor 110 can comprise multiple sub- or co-processors, as well as function-specific hardware circuitry, such as FPGAs or ASICs, sometimes referred to as network processing engines or security processing engines. As shown, incoming data packets from an input (e.g., a receive port) can be processed by the network processor 100, which has high-throughput network components including serializers / deserializers / Ethernet MAC / port blocks; a programmable packet parser or filter including a parser capable of classifying packet headers or header portions at any layer of the network stack (e.g., layer 2, layer 3, layer 4, etc.); a programmable packet lookup engine to implement layer 2 and layer 3 features such as IP fragmentation and assembly, network address translation, access control lists, etc.; a programmable packet editor for packet modification (e.g., modifying header fields including type-length-value (TLV) encoded headers, modifying addresses or sequence numbers, or otherwise modifying packets); large-scale stateful flow and ACL processing (with large storage arrays for managing or maintaining a large number of flow states simultaneously); a deep buffer traffic manager supporting hierarchical QoS; and an integrated fabric interface for building distributed, chassis-based systems (discussed in more detail below).
[0028] In many embodiments, each functional block of the network processing 100 can comprise hardware, software, or a combination of hardware and software, and as discussed above, can be executed in an isochronous manner on a single distributed clock (which in various embodiments can be on-die or off-die). This network processing pipeline can be very high throughput, capable in many embodiments of handling 2Tbp or more, as well as millions or hundreds of millions of simultaneous network flows (maintaining state as needed for network address translation, load balancing, TCP connection tracking, etc.).
[0029] In many embodiments, the security processor 110 can operate asynchronously from the network processing 100, and often has lower throughput. Thus, the security processor 110 can also include a second distributed clock (which in various embodiments can be on-die or off-die), and / or can operate at a different clock rate than the network processor 100. However, since not all packets require additional security processing features, offloading these functions to a parallel die can allow the host pipeline to not be blocked, increasing overall system throughput. Additionally, in many embodiments, the network processor 100 and security processor 110 can have different fabrication parameters: for example, in some embodiments, the network processor 100 and security processor 110 can have different fabrication scales (e.g., 5nm or 7nm processes, for example, in some embodiments).
[0030] The security processor 110 can include multiple sub- or co-processors, as well as function-specific hardware circuits (e.g., FPGAs or ASICs) including multiple sub- or co-processors, for example, for security acceleration, and function-specific hardware circuits (e.g., FPGAs or ASICs) for: IPSEC symmetric encryption and decryption; MACsec symmetric encryption and decryption; DTLS symmetric encryption and decryption; TLS symmetric encryption and decryption; TLS public key encryption and decryption; regular expression search (REGEX) accelerators; machine learning / artificial intelligence inference engines; integrated network interface controllers for packets to / from the CPU; and integrated and / or external CPUs. For example, in some embodiments, the security processor 110 can include a back-up engine for matching encryption or decryption keys, performing hashes or other calculations. Since these processes can be resource-intensive and time-consuming, offloading their functionality to the security processor 110 allows packet streams that do not require additional security features to flow through the network processor 100 at full speed. The components of the security processor 110 and network processor 100 can exchange data via any suitable means, such as a shared memory bus or storage (e.g., RAM or flash memory), and / or via Ethernet, fabric, or PCI switches or bridges. For example, in some embodiments, packets can be forwarded by the network processor 100 to an internal or virtual address of the security processor 110 for processing.
[0031] In many embodiments, the network processing subsystem 100 and security processing subsystem 110 can be deployed on or supported by a single card (e.g., a PCIe card or similar interface) for installation in a server or other data backplane. In other embodiments, the network processing subsystem 100 and security processing subsystem 110 can be divided between separate cards (including a parent card and child card, in some embodiments), allowing for separate deployment (discussed in greater detail below).
[0032] AsFigure 1 As shown, the architecture implementation deploys these individual components in an integrated manner to enable the efficient implementation of high-performance networking and security systems. The operational sequences, as well as the capacity and performance of each component, are tuned to result in consistent yet differentiated performance across various use cases. Therefore, this type of implementation provides a scalable architecture that can handle multiple throughput / performance points using programmable, replaceable components without sacrificing flexibility for performance.
[0033] Figure 2 This is a block diagram of another implementation scheme for the architecture of converged security systems and devices. (And...) Figure 1 Similarly, network processor 100' and security processor 110' are separate. However, as shown, in some implementations, decryption and sidechain information obtained from RegEx or machine learning engines in network processor 100' can be provided to security processor 110', potentially reducing the processing requirements of security processor 110'. For example, network flows classified by RegEx of network processor 100' (e.g., application-layer classification for QoS or malicious packet detection) can have their classification information passed to security processor 110' for further processing (e.g., decryption for deep packet inspection, filter configuration, etc.).
[0034] Figures 3A to 3E This is a block diagram illustrating the deployment and configuration of an implementation scheme for a converged security system and its devices. For example, first refer to... Figure 3A An integrated network / security processor 310 (sometimes referred to as a network / security processing system or engine, and including one or more network processors 100 and one or more security processors 110) may be coupled to one or more physical interfaces 300 (e.g., Ethernet, WiFi hardware, fiber optic interfaces, etc.) and one or more central processing units 320 (e.g., via PCIe interfaces). The network / security processor 310 provides an integrated solution with high I / O capacity, high throughput, and cryptographic processing capabilities that can be offloaded from the CPU 320. In some embodiments, the integrated network / security processor 310 may be deployed in a chassis, such as a 1U or 2U rackmount server chassis (or any other suitable form factor). In such embodiments, the chassis may house or support additional components, such as power supplies, front or rear panel ports (e.g., Ethernet or fiber optic ports for physical interfaces 300), or other such features. In some embodiments, the chassis may include a PCIe backplane or similar interface through which the network / security processor 310 can be connected.
[0035] In some implementations, multiple integrated network / security processors 310 can be deployed in a single device or chassis, such as Figure 3BAs illustrated in the block diagram. For example, multiple integrated network / security processors 310 (310A, 310B) may be coupled to corresponding multiple physical interfaces 300 (e.g., individual physical ports in many embodiments) and CPUs (320A, 320B), and coupled via interconnect architecture interface 305 (e.g., as individual cards or blades in a server or device chassis). In some embodiments, the boot flow to each integrated network / security processor 310 may be balanced among the integrated network / security processors 310 (e.g., such that each processor 310 performs stream processing for half of the physical interfaces). In some embodiments, security processing functions may be shared among the network processors of each integrated network / security processor 310, such that the security processor of the first integrated network / security processor 310A can perform cryptographic processing for the network processor of the second integrated network / security processor 310, wherein packet data is passed between each processor 310 via interconnect architecture 305. This is particularly helpful for balancing the processing load among each security processor of the integrated network / security processor 310.
[0036] Figure 3C The illustration shows a similar implementation in which the integrated network / security processor 310 is divided into corresponding network processing cards 312A, 312B and security or data processing cards 315A, 315B. In some implementations, as shown, each network processing card 312A, 312B may include the integrated network / security processor 310A, 310B. Security functions (including fallback offloading, machine learning analytics, etc.) may be provided by the security processor 110 of each integrated network / security processor 310, and / or may be provided individually by independent security processors 314A, 314B (each of which may include the security processor 110). A configuration switch and / or load balancer 330 may provide load balancing among the data processing cards 315A, 315B.
[0037] Figure 3D Demonstrates expansion using individual line cards 311A, 311B (or more). Figure 3A In one implementation, each line card includes an integrated network / security processor 310 for data processing and one or more CPUs 320, wherein an external switch 302 distributes traffic to each card. This implementation can be manufactured relatively inexpensively (where each card is identical), allows for high scalability, and provides higher reliability (e.g., utilizing "hot" backup cards in some implementations).
[0038] Similarly, Figure 3EThe illustration showcases an implementation with individual devices 330A and 330B connected via an external switch 302 (e.g., a top-of-rack switch or a ToR switch) and an internal switch 332 providing load balancing among multiple integrated network / security processors 310. Processed packet streams can be provided to an external server CPU 320' (e.g., an application server, data server, or other computing device), thereby allowing the integrated network / security processor 310 to be easily deployed as an intermediate device in a network rack or similar environment.
[0039] In some aspects, this disclosure relates to a system for high-throughput networking and security processing. The system includes: a network processing subsystem comprising a plurality of interconnected network processing engines configured in a single pipeline; and a security processing subsystem coupled to and external to the network processing subsystem, the security processing subsystem comprising a plurality of interconnected security processing engines.
[0040] In some embodiments, the network processing subsystem includes a first clock, and the security processing subsystem includes a second clock. In some embodiments, the network processing subsystem operates at the first clock rate, and the security processing subsystem operates at the second clock rate. In some embodiments, the system includes a memory bus shared by at least one network processing engine of the network processing subsystem and at least one security processing engine of the security processing subsystem.
[0041] In some embodiments, the network processing subsystem and the security processing subsystem are coupled via an Ethernet interface. In further embodiments, the system includes an Ethernet switch that manages packet flows between the network processing subsystem and the security processing subsystem. In some embodiments, the system includes a structural interconnect interface coupled to at least one of the network processing subsystem and the security processing subsystem.
[0042] In some implementations, the system includes a single card supporting the network processing subsystem and the security processing subsystem. In some implementations, the system includes a second network processing subsystem, a second security processing subsystem, and a network switch coupled to each of the first network processing subsystem, the first security processing subsystem, the second network processing subsystem, and the second security processing subsystem, the network switch being configured to load balance the security processing of each of the first network processing subsystem and the second security processing subsystem between the first security processing subsystem and the second security processing subsystem.
[0043] In some implementations, the plurality of interconnected security processing engines are configured in corresponding plurality of parallel processing pipelines.
[0044] On the other hand, the present invention relates to a device comprising: a chassis; one or more physical communication interfaces located on a portion of the chassis; a network processing subsystem located within the chassis and coupled to the one or more physical communication interfaces, the network processing subsystem including a plurality of interconnected network processing engines configured in a single pipeline; and a security processing subsystem located within the chassis, coupled to the network processing subsystem and external to the network processing subsystem, the security processing subsystem including a plurality of interconnected security processing engines.
[0045] In some embodiments, the device includes a communication backplane located within the chassis, and the network processing subsystem is coupled to the one or more physical communication interfaces via the communication backplane. In a further embodiment, the network processing subsystem and the security processing subsystem are supported on a single card. In yet another embodiment, the device includes a second network processing subsystem and a second security processing subsystem supported on a second single card and coupled to the one or more physical communication interfaces via the communication backplane. In still a further embodiment, the device includes a modular switch located within the chassis, the modular switch managing packet flows across the communication backplane.
[0046] In some embodiments, the network processing subsystem operates at a first clock rate, and the security processing subsystem operates at a second clock rate. In some embodiments, the device includes a memory bus shared by at least one network processing engine of the network processing subsystem and at least one security processing engine of the security processing subsystem. In some embodiments, the network processing subsystem and the security processing subsystem are coupled via Ethernet or a modular interface.
[0047] B. Computing and network environment
[0048] After discussing specific embodiments of this solution, it may be helpful to describe the operating environment and associated system components (e.g., hardware elements) in conjunction with the methods and systems described herein. References Figure 4A This describes an embodiment of a network environment. Briefly, the network environment includes a wireless communication system comprising one or more access points 406, one or more wireless communication devices 402, and network hardware components 492. Wireless communication devices 402 may, for example, include laptop computers 402, tablet computers 402, personal computers 402, and / or cellular telephone devices 402. (See reference...) Figure 4B and 4C The embodiments of each wireless communication device and / or access point are described in more detail. In one embodiment, the network environment may be a self-organizing network environment, an infrastructure wireless network environment, a subnet environment, etc.
[0049] Access points (APs) 406 are operatively coupled to network hardware 492 via a local area network (LAN) connection. Network hardware 492, which may include routers, gateways, switches, bridges, modems, system controllers, devices, etc., provides LAN connectivity for the communication system. Each of the access points 406 may have an associated antenna or antenna array to communicate with wireless communication devices 402 in its area. Wireless communication devices 402 may register with a specific access point 406 to receive services from the communication system (e.g., via SU-MIMO or MU-MIMO configuration). For direct connections (e.g., point-to-point communication), some wireless communication devices 402 may communicate directly via allocated channels and communication protocols. Some of the wireless communication devices 402 may be mobile or relatively stationary relative to the access point 406.
[0050] In some embodiments, access point 406 includes means or modules (combining hardware and software) that allow wireless communication devices 402 to connect to a wired network using Wi-Fi or other standards. Access point 406 may sometimes be referred to as a wireless access point (WAP). Access point 406 may be configured, designed, and / or constructed for operation in a wireless local area network (WLAN). In some embodiments, access point 406 may be connected as a standalone device to a router (e.g., via a wired network). In other embodiments, the access point may be a component of a router. Access point 406 may provide network access to multiple devices 402. Access point 406 may, for example, be connected to a wired Ethernet connection and use a radio frequency link to provide wireless connectivity for other devices 402 to utilize that wired connection. Access point 406 may be constructed and / or configured to support standards for transmitting and receiving data using one or more radio frequencies. Those standards and the frequencies they use may be defined by IEEE (e.g., the IEEE 802.11 standard). Access points can be configured and / or used to support public Internet hotspots, and / or to extend the Wi-Fi signal range of an internal network.
[0051] In some embodiments, access point 406 may be used (e.g., in a home or building) for wireless networks (e.g., IEEE 802.11, Bluetooth, ZigBee, any other type of radio frequency-based network protocol and / or variations thereof). Each of the wireless communication devices 402 may include a built-in radio and / or be coupled to a radio. Such wireless communication devices 402 and / or access points 406 may operate according to various aspects of this disclosure as presented herein to enhance performance, reduce cost and / or size, and / or enhance broadband applications. Each wireless communication device 402 may have the ability to act as a client node seeking access to resources (e.g., data and connections to networked nodes such as servers) via one or more access points 406.
[0052] The network connection may include any type and / or form of network and may include any of the following: point-to-point network, broadcast network, telecommunications network, data communication network, computer network. The network topology may be a bus, star, or ring network topology. The network may be any network topology known to those skilled in the art capable of supporting the operations described herein. In some embodiments, different types of data may be transmitted via different protocols. In other embodiments, the same type of data may be transmitted via different protocols.
[0053] The communication devices 402 and access points 406 may be deployed as any type and form of computing device and / or executed thereon, such computing device as a computer, network device or equipment capable of communicating on any type and form of network and performing the operations described herein. Figure 4B and 4C A block diagram depicting a computing device 400 that can be used to implement embodiments of wireless communication device 402 or access point 406. (See diagram for reference.) Figure 4B and 4C As shown, each computing device 400 includes a central processing unit 421 and a main memory unit 422. Figure 4B As shown, computing device 400 may include storage device 428, mounting device 416, network interface 418, I / O controller 423, display devices 424a to 424n, keyboard 426, and pointing device 427, such as a mouse. Storage device 428 may include, but is not limited to, operating system and / or software. Figure 4C As shown, each computing device 400 may also include additional optional elements such as memory port 403, bridge 470, one or more input / output devices 430a to 430n (generally referred to by reference numeral 430), and cache memory 440 that communicates with central processing unit 421.
[0054] Central processing unit 421 is any logic circuit system that responds to and processes instructions fetched from main memory unit 422. In many embodiments, central processing unit 421 is provided by a microprocessor unit, such as: a microprocessor unit manufactured by Intel Corporation of Mountain View, California; a microprocessor unit manufactured by International Business Machines Corporation of White Plains, New York; or a microprocessor unit manufactured by Advanced Micro Devices Inc. of Sunnyvale, California. Computing device 400 may be based on any of these processors, or any other processor capable of operating as described herein.
[0055] Main memory unit 422 may be one or more memory chips capable of storing data and allowing microprocessor 421 to directly access any memory location, such as any type or variant of static random access memory (SRAM), dynamic random access memory (DRAM), ferroelectric RAM (FRAM), NAND flash memory, NOR flash memory, and solid-state drive (SSD). Main memory 422 may be based on any of the aforementioned memory chips, or any other available memory chip capable of operating as described herein. Figure 4B In the embodiment shown, the processor 421 communicates with the main memory 422 via the system bus 450 (described in more detail below). Figure 4C An embodiment of a computing device 400 is depicted, wherein the processor communicates directly with the main memory 422 via a memory port 403. For example, in Figure 4C In this context, the main memory 422 can be DRDRAM.
[0056] Figure 4C An embodiment is depicted in which the main processor 421 communicates directly with the cache memory 440 via a secondary bus (sometimes referred to as the back-side bus). In other embodiments, the main processor 421 communicates with the cache memory 440 using a system bus 450. The cache memory 440 typically has a faster response time than the main memory 422 and is provided by, for example, SRAM, BSRAM, or EDRAM. Figure 4C In the embodiment shown, processor 421 communicates with various I / O devices 430 via a local system bus 450. Various buses can be used to connect central processing unit 421 to any of the I / O devices 430, such as VESA VL bus, ISA bus, EISA bus, Micro Channel Architecture (MCA) bus, PCI bus, PCI-X bus, PCI-Express bus, or NuBus. For an embodiment where the I / O device is a video display 424, processor 421 may use an Advanced Graphics Port (AGP) to communicate with display 424. Figure 4C An embodiment of computer 400 is depicted, wherein the main processor 421 may, for example, communicate directly with the I / O device 430b via HYPERTRANSPORT, RAPIDIO, or INFINIBAND communication technologies. Figure 4C An embodiment in which a hybrid local bus and direct communication is also depicted: the processor 421 communicates with the I / O device 430a using the local interconnect bus, while simultaneously communicating directly with the I / O device 430b.
[0057] A wide variety of I / O devices 430a to 430n may be present in the computing device 400. Input devices include keyboards, mice, trackpads, trackballs, microphones, dial pads, touchpads, touch screens, and drawing tablets. Output devices include video displays, speakers, inkjet printers, laser printers, projectors, and dye-to-sublimation printers. The I / O devices can be controlled by an I / O controller 423, such as... Figure 4B As shown in the diagram. The I / O controller can control one or more I / O devices, such as a keyboard 426 and a pointing device 427, such as a mouse or light pen. Additionally, the I / O devices can provide storage and / or mounting media 416 for the computing device 400. In yet another embodiment, the computing device 400 can provide USB connectivity (not shown) to receive handheld USB storage devices, such as the USB flash drive series manufactured by Twintech Industry, Inc. in Los Aramis, California.
[0058] Refer again Figure 4B The computing device 400 may support any suitable installation device 416, such as a disk drive, CD-ROM drive, CD-R / RW drive, DVD-ROM drive, flash memory drive, tape drive of various formats, USB device, hard disk drive, network interface, or any other device suitable for installing software and programs. The computing device 400 may further include a storage device, such as one or more hard disk drives or a redundant array of independent disks, for storing the operating system and other related software, and for storing application software programs, such as any program or software 420 for implementing (e.g., configured and / or designed for) the systems and methods described herein. Optionally, any of the installation devices 416 may also be used as a storage device. Additionally, the operating system and software may be run from a bootable medium.
[0059] Furthermore, the computing device 400 may include a network interface 418 for interfacing with the network 404 via various connections, including but not limited to standard telephone lines, LAN or WAN links (e.g., 802.11, T1, T3, 56kb, X.25, SNA, DECNET), broadband connections (e.g., ISDN, Frame Relay, ATM, Gigabit Ethernet, Ethernet over SONET), wireless connections, or any combination thereof. Connections may be established using various communication protocols (e.g., TCP / IP, IPX, SPX, NetBIOS, Ethernet, ARCNET, SONET, SDH, Fiber Distributed Data Interface (FDDI), RS232, IEEE 802.11, IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.11n, IEEE 802.11ac, IEEE 802.11ad, CDMA, GSM, WiMax, and direct asynchronous connections). In one embodiment, computing device 400 communicates with other computing devices 400' via any type and / or form of gateway or tunneling protocol, such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS). Network interface 418 may include a built-in network adapter, network interface card, PCMCIA network card, card bus network adapter, wireless network adapter, USB network adapter, modem, or any other device suitable for interfacing computing device 400 with any type of network capable of communicating and performing the operations described herein.
[0060] In some embodiments, computing device 400 may include or be connected to one or more display devices 424a to 424n. Therefore, any of the I / O devices 430a to 430n and / or I / O controller 423 may include any type and / or form of suitable hardware, software, or a combination of hardware and software for supporting, enabling, or providing the computing device 400 with connection to and use of the display devices 424a to 424n. For example, computing device 400 may include any type and / or form of video adapter, video card, driver, and / or library for docking, communicating, connecting, or otherwise using the display devices 424a to 424n. In one embodiment, a video adapter may include multiple connectors for docking with the display devices 424a to 424n. In other embodiments, computing device 400 may include multiple video adapters, each of which is connected to the display devices 424a to 424n. In some embodiments, any part of the operating system of the computing device 400 may be configured to use multiple displays 424a to 424n. Those skilled in the art will recognize and understand that the computing device 400 may be configured in various ways and embodiments to have one or more display devices 424a to 424n.
[0061] In a further embodiment, the I / O device 430 may be a bridge between the system bus 450 and an external communication bus, such as a USB bus, Apple desktop bus, RS-232 serial connection, SCSI bus, FireWire bus, FireWire 800 bus, Ethernet bus, AppleTalk bus, gigabit Ethernet bus, asynchronous transfer mode bus, Fibre Channel bus, serial attachment small computer system interface bus, USB connection, or HDMI bus.
[0062] Figure 4B and 4CThe computing device 400 of the type described herein can operate under the control of an operating system that controls task scheduling and access to system resources. The computing device 400 can run any operating system, such as any version of the Microsoft Windows operating system, different versions of Unix and Linux operating systems, any version of MAC OS for Macintosh computers, any embedded operating system, any real-time operating system, any open-source operating system, any proprietary operating system, any operating system for mobile computing devices, or any other operating system capable of running on a computing device and performing the operations described herein. Typical operating systems include, but are not limited to: Android produced by Google; Windows 7 and 8 produced by Microsoft Corporation of Redmond, Washington; MAC OS produced by Apple Computer Inc. of Cupertino, California; WebOS produced by Dynamic Research Incorporated (RIM); OS / 2 produced by International Business Machines Corporation of Armonk, New York; and Linux, a free operating system distributed by Crater Company of Salt Lake City, Utah, or any type and / or form of Unix operating system, etc.
[0063] Computer system 400 may be any workstation, telephone, desktop computer, laptop or notebook computer, server, handheld computer, mobile phone or other portable telecommunications device, media playback device, gaming system, mobile computing device, or any other type and / or form of computing, telecommunications, or media device capable of communication. Computer system 400 has sufficient processor power and memory capacity to perform the operations described herein.
[0064] In some embodiments, computing device 400 may have a different processor, operating system, and input device consistent with the device described herein. For example, in one embodiment, computing device 400 is a smartphone, mobile device, tablet computer, or personal digital assistant. In yet other embodiments, computing device 400 is an Android-based mobile device, an iPhone smartphone manufactured by Apple Computer, Cupertino, California, or a Blackberry or WebOS-based handheld device or smartphone, such as a device manufactured by Dynamics Research, Inc. Furthermore, computing device 400 may be any workstation, desktop computer, laptop or notebook computer, server, handheld computer, mobile phone, any other computer, or other form of computing or telecommunications device capable of communication and having sufficient processor power and memory capacity to perform the operations described herein.
[0065] Although this disclosure may refer to one or more “users”, such “user” may refer to a device or station (STA) associated with a user, for example consistent with the terms “user” and “multi-user” as commonly used in the context of a multi-user multiple-input multiple-output (MU-MIMO) environment.
[0066] While examples of the communication systems described above may include devices and access points (APs) operating according to the 802.11 standard, it should be understood that embodiments of the described systems and methods may operate according to other standards and use wireless communication devices other than those configured as devices and APs. For example, multi-cell communication interfaces associated with cellular networks, satellite communications, vehicular communication networks, and other non-802.11 wireless networks can utilize the systems and methods described herein to achieve improved overall capacity and / or link quality without departing from the scope of the systems and methods described herein.
[0067] It should be noted that certain paragraphs of this disclosure may use terms such as "first" and "second" in connection with devices, operating modes, transmission chains, antennas, etc., for the purpose of identifying or distinguishing one from another or others. These terms are not intended to relate entities merely temporally or sequentially (e.g., first device and second device), although in some cases such a relationship may be present. These terms also do not limit the number of possible entities (e.g., devices) that can operate within a system or environment.
[0068] It should be understood that the system described above may provide any or more of those components, and these components may be located on a standalone machine or, in some embodiments, on multiple machines in a distributed system. Furthermore, the system and method described above may be provided as one or more computer-readable programs or executable instructions embodied in or on one or more articles of art. The articles of art may be floppy disks, hard disks, CD-ROMs, flash memory cards, PROMs, RAMs, ROMs, or magnetic tapes. Generally, the computer-readable program may be implemented in any programming language, such as LISP, PERL, C, C++, C#, PROLOG, or in any bytecode language, such as JAVA. The software program or executable instructions may be stored as object code on or in one or more articles of art.
[0069] While the foregoing written description of the methods and systems enables those skilled in the art to make and use what is currently considered the best mode, those skilled in the art will understand and appreciate that variations, combinations, and equivalents of the particular embodiments, methods, and examples present herein exist. Therefore, the methods and systems should not be limited to the foregoing embodiments, methods, and examples, but rather to all embodiments and methods within the scope and spirit of this disclosure.
Claims
1. A system for high-throughput network and security processing, comprising: The first network processing subsystem includes multiple interconnected network processing engines configured in a single pipeline and executed by hardware circuitry for processing acceleration. A first security processing subsystem is coupled to and physically located outside the first network processing subsystem, the first security processing subsystem comprising a plurality of interconnected security processing engines executed by hardware circuitry for security acceleration. Second network processing subsystem; Second security processing subsystem; A network switch coupled to each of the first network processing subsystem, the first security processing subsystem, the second network processing subsystem, and the second security processing subsystem; as well as The network switch is configured to load balance the security processing of each of the first network processing subsystem and the second network processing subsystem between the first security processing subsystem and the second security processing subsystem.
2. The system according to claim 1, wherein the first network processing subsystem includes a first clock, and wherein the first security processing subsystem includes a second clock.
3. The system according to claim 1, wherein the first network processing subsystem operates at a first clock rate, and wherein the first security processing subsystem operates at a second clock rate.
4. The system of claim 1, further comprising a memory bus shared by at least one network processing engine of the first network processing subsystem and at least one security processing engine of the first security processing subsystem.
5. The system according to claim 1, wherein the first network processing subsystem and the first security processing subsystem are coupled via an Ethernet interface.
6. The system of claim 5, further comprising an Ethernet switch for managing packet flows between the first network processing subsystem and the first security processing subsystem.
7. The system of claim 1, further comprising a structural interconnect interface coupled to at least one of the first network processing subsystem and the first security processing subsystem.
8. The system of claim 1, further comprising a single card supporting the first network processing subsystem and the first security processing subsystem.
9. The system of claim 1, wherein the plurality of interconnected security processing engines are configured in corresponding plurality of parallel processing pipelines.
10. An apparatus comprising: Chassis; One or more physical communication interfaces are located on a portion of the chassis; A first network processing subsystem, located within the chassis and coupled to the one or more physical communication interfaces, includes multiple interconnected network processing engines configured in a single pipeline and executed by hardware circuitry for processing acceleration. A first security processing subsystem is located within the chassis, coupled to the first network processing subsystem, and physically located outside the first network processing subsystem. The first security processing subsystem includes a plurality of interconnected security processing engines executed by hardware circuitry for security acceleration. and The first network processing subsystem and the first security processing subsystem are supported on a single card; A second network processing subsystem and a second security processing subsystem are supported on a second single card and coupled to the one or more physical communication interfaces via a communication backplane. as well as A modular switch is located within the chassis and configured to load balance the security processing of each of the first and second network processing subsystems between the first and second security processing subsystems.
11. The device of claim 10, further comprising a communication backplane located within the chassis, wherein the first network processing subsystem is coupled to the one or more physical communication interfaces via the communication backplane.
12. The apparatus of claim 10, wherein the first network processing subsystem operates at a first clock rate, and wherein the first security processing subsystem operates at a second clock rate.
13. The device of claim 10, further comprising a memory bus shared by at least one network processing engine of the first network processing subsystem and at least one security processing engine of the first security processing subsystem.
14. The device of claim 10, wherein the first network processing subsystem and the first security processing subsystem are coupled via Ethernet or a modular interface.
Citation Information
Patent Citations
Virtualization security network element data processing method and system, medium and cloud platform
CN112437023A