Cryptographic Card Allocation in Multi-Core Packet Engines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems face inefficiencies in distributing and managing cryptographic cards, such as SSL cards, across multiple packet processing engines in a multi-core system, leading to suboptimal encryption and decryption processes.

Innovation Solution

A multi-cryptographic-card/multi-core system is implemented, where a card distribution manager allocates cryptographic cards to packet processing engines, allowing for unique allocation and shared usage, establishing queues for residual cards to optimize card utilization across multiple cores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic cards are distributed across multiple packet processing engines in a multi-core system, then encryption and decryption throughput is improved, but resource utilization efficiency deteriorates due to idle cryptographic cards

Engineering Contradiction:
Improveencryption and decryption throughputVSAvoidresource utilization efficiency
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements dynamic allocation of cryptographic cards to packet processing engines based on real-time workload demands. The system monitors the state of cryptographic cards and packet engines, dynamically assigning idle cryptographic cards to engines that need encryption/decryption capacity, thereby maintaining high resource utilization while supporting high throughput

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal cryptographic card pool that can be shared across multiple packet processing engines. Instead of dedicating specific cryptographic cards to specific engines, the system makes cryptographic cards universally accessible to any engine that needs them, improving overall system utilization while maintaining the ability to serve multiple functions and engines

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If cryptographic cards are dedicated to specific packet processing engines, then resource allocation simplicity is improved, but system adaptability deteriorates when workload changes

Engineering Contradiction:
Improveresource allocation simplicityVSAvoidsystem adaptability to workload changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into cryptographic card owners (packet processing engines) and a central allocation manager. Each engine is assigned specific cryptographic cards it owns, maintaining simple local resource management. The allocation manager segments the overall allocation task into monitoring individual engine states and individually assigning idle cards from any owner to any needing engine, achieving both simplicity and adaptability

Inventive Principle:
Principle #1Segmentation

3Productivity

If the number of packet processing engines exceeds the number of cryptographic cards, then processing parallelism is improved, but resource contention increases

Engineering Contradiction:
Improveprocessing parallelismVSAvoidresource contention management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a central cryptographic card allocation manager as an intermediary between multiple packet processing engines and the cryptographic card pool. This mediator monitors the state of all engines and cards, automatically assigning idle cryptographic cards to engines that need them. This intermediary layer simplifies contention management by centralizing the allocation logic, allowing multiple engines to efficiently share limited cryptographic cards without complex peer-to-peer coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9378381B2Systems and methods for queue level SSL card mapping to multi-core packet engine
Publication Date: 2016.06.28 CITRIX SYSTEMS INC
  • US9378381B2 patent drawing
  • US9378381B2 patent drawing
  • US9378381B2 patent drawing

AI summary

The present invention is directed towards systems and methods for distributed operation of a plurality of cryptographic cards in a multi-core system. In various embodiments, a plurality of cryptographic cards providing encryption/decryption resources are assigned to a plurality of packet processing engines in operation on a multi-core processing system. One or more cryptographic cards can be configured with a plurality of hardware or software queues. The plurality of queues can be assigned to plural packet processing engines so that the plural packet processing engines share cryptographic services of a cryptographic card having multiple queues. In some embodiments, all cryptographic cards are configured with multiple queues which are assigned to the plurality of packet processing engines configured for encryption operation.