Adapter Overlapping Protection Domain for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods for network devices, such as adapters, fail to effectively protect data during transmission and reception by removing initial error protection codes and adding new ones without ensuring protocol-specific protection, leading to potential data corruption and insecurity.

Innovation Solution

Implementing a security module with encryption and decryption capabilities in adapters to generate and transmit encrypted frames with protocol-specific protection codes, including a third type of error protection code generated without using frame header fields, ensuring secure data transmission across network links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data security methods remove initial error protection codes and add new ones without protocol-specific protection, then data transmission can proceed, but data security and protection against corruption deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidprotection code management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of error protection by implementing multiple layers of protection codes (first type from host, second type added by adapter, third type in encryption domain) with different characteristics and scopes. Each protection code operates at different stages and provides different types of protection, transforming the single-layer protection approach into a multi-layered parameter system that enhances security while managing complexity through structured organization

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the data protection process into distinct stages with dedicated protection codes: first type protection at host memory stage, second type protection added by adapter before encryption, and third type protection within encryption domain. This segmentation allows each protection layer to operate independently and effectively, preventing data corruption at different points in the transmission chain

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is applied to data and protection codes, then data security improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by adding the second type of error protection code to the data payload before encryption occurs. This preliminary protection ensures that even if encryption introduces processing delays or errors, the data already has a layer of error protection in place. The third type of protection code is also generated within the encryption domain, creating overlapping protection that reduces the need for reprocessing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements beforehand cushioning by creating overlapping protection domains where multiple error protection codes coexist. The first type protection from host, second type from adapter, and third type within encryption domain provide cushioning layers that protect against various failure modes. This cushioning approach ensures that time losses from encryption processing are compensated by having multiple validation layers already in place

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If multiple error protection codes are added to data, then data protection improves, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidprotection code management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different types of error protection codes to different local domains of data processing. The first type protection operates at host memory level, the second type at adapter processing level, and the third type within the encryption domain. Each protection code is optimized for its specific local context and scope, allowing complex multi-layer protection without requiring uniform management across the entire system

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the protection code management into distinct responsibilities: host system manages first type protection, adapter manages second type protection, and encryption module generates third type protection. This segmentation distributes the complexity across different components rather than concentrating it in one device, making the overall system more manageable despite the multiple protection layers

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10419481B1Methods and systems for overlapping protection domain in network devices
Publication Date: 2019.09.17 MARVELL ASIA PTE LTD
  • US10419481B1 patent drawing
  • US10419481B1 patent drawing
  • US10419481B1 patent drawing

AI summary

Methods and systems for securing data are provided. For example, one method includes receiving at an adapter, data with a first type of error protection code from a host memory of a computing device; adding by the adapter a second type of error protection code to the data before removing the first type of error protection code; generating by the adapter, a frame header for the data with a protocol specific protection code and a third type of error protection code, where the third type of error protection code is generated without using any frame header field; encrypting by the adapter, the data, the protocol specific protection code and the third type of error protection code; and transmitting by the adapter, the encrypted data with encrypted protocol specific protection code and encrypted third type of error protection code to a receiving adapter coupled to the adapter by a network link.