Flexible Inline Cryptographic Pipeline for Network Packet Throughput
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network devices rely heavily on software processing for cryptographic operations, leading to performance degradation and reduced throughput due to excessive CPU resource consumption.
Innovation Solution
Offloading cryptographic processing to a block cipher circuit coupled inline within a hardware pipeline, utilizing hardware engines such as ASICs and FPGAs, to perform cryptographic operations at line rate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cryptographic operations are performed using software processing, then flexibility and ease of implementation are improved, but system performance and throughput deteriorate due to excessive CPU resource consumption
Solution Approach 1:
The patent replaces software-based cryptographic processing with dedicated hardware cryptographic circuits. This substitution moves the cryptographic operations from the software domain (CPU execution) to the hardware domain (dedicated circuits), thereby eliminating the performance bottleneck while maintaining cryptographic functionality. The hardware circuits are designed to perform encryption and decryption operations in parallel with network packet processing, achieving line-rate throughput without CPU intervention.
2Productivity
If cryptographic operations are offloaded to hardware circuits, then processing speed and throughput are improved, but device complexity increases
Solution Approach 1:
The patent merges the cryptographic circuit with the network interface card (NIC) hardware pipeline, integrating encryption and decryption functions directly into the packet processing path. This consolidation allows cryptographic operations to be performed inline with network packet processing without requiring separate hardware components or additional processing stages, thereby achieving high throughput while minimizing the increase in device complexity.
Solution Approach 2:
The cryptographic circuit is designed to support multiple cryptographic algorithms and protocols (e.g., AES, DES, 3DES, RC4, IPsec, MACsec) within a single hardware component. This multi-functionality allows the same hardware circuit to handle various cryptographic operations across different network protocols and security requirements, reducing the need for multiple specialized circuits and thereby limiting the increase in device complexity.
3Speed
If cryptographic processing is performed in hardware pipeline, then network packet speed is improved, but flexibility in protocol adaptation deteriorates
Solution Approach 1:
The cryptographic circuit incorporates programmable or configurable elements that allow it to adapt to different cryptographic protocols and algorithms dynamically. The circuit can be reconfigured via firmware or control logic to support various encryption standards (AES, DES, 3DES, RC4) and protocols (IPsec, MACsec, TLS), enabling the hardware to maintain high processing speeds while accommodating changing protocol requirements without sacrificing flexibility.
Data Source
AI summary
A network device includes a hardware pipeline to process a network packet to be encrypted. A portion of the hardware pipeline retrieves information from the network packet and generates a command based on the information. A block cipher circuit is coupled inline within the hardware pipeline. The hardware pipeline includes hardware engines coupled between the portion of the hardware pipeline and the block cipher circuit. The hardware engines parse and execute the command to determine a set of inputs and input the set of inputs and portions of the network packet to the block cipher circuit. The block cipher circuit encrypts a payload data of the network packet based on the set of inputs.


