Flexible Inline Cryptographic Pipeline for Network Packet Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices rely heavily on software processing for cryptographic operations, leading to performance degradation and reduced throughput due to excessive CPU resource consumption.

Innovation Solution

Offloading cryptographic processing to a block cipher circuit coupled inline within a hardware pipeline, utilizing hardware engines such as ASICs and FPGAs, to perform cryptographic operations at line rate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic operations are performed using software processing, then flexibility and ease of implementation are improved, but system performance and throughput deteriorate due to excessive CPU resource consumption

Engineering Contradiction:
Improveease of implementationVSAvoidsystem throughput
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces software-based cryptographic processing with dedicated hardware cryptographic circuits. This substitution moves the cryptographic operations from the software domain (CPU execution) to the hardware domain (dedicated circuits), thereby eliminating the performance bottleneck while maintaining cryptographic functionality. The hardware circuits are designed to perform encryption and decryption operations in parallel with network packet processing, achieving line-rate throughput without CPU intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If cryptographic operations are offloaded to hardware circuits, then processing speed and throughput are improved, but device complexity increases

Engineering Contradiction:
Improveprocessing speedVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the cryptographic circuit with the network interface card (NIC) hardware pipeline, integrating encryption and decryption functions directly into the packet processing path. This consolidation allows cryptographic operations to be performed inline with network packet processing without requiring separate hardware components or additional processing stages, thereby achieving high throughput while minimizing the increase in device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic circuit is designed to support multiple cryptographic algorithms and protocols (e.g., AES, DES, 3DES, RC4, IPsec, MACsec) within a single hardware component. This multi-functionality allows the same hardware circuit to handle various cryptographic operations across different network protocols and security requirements, reducing the need for multiple specialized circuits and thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If cryptographic processing is performed in hardware pipeline, then network packet speed is improved, but flexibility in protocol adaptation deteriorates

Engineering Contradiction:
Improvenetwork packet speedVSAvoidprotocol adaptability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The cryptographic circuit incorporates programmable or configurable elements that allow it to adapt to different cryptographic protocols and algorithms dynamically. The circuit can be reconfigured via firmware or control logic to support various encryption standards (AES, DES, 3DES, RC4) and protocols (IPsec, MACsec, TLS), enabling the hardware to maintain high processing speeds while accommodating changing protocol requirements without sacrificing flexibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12438859B2Flexible cryptographic architecture in a network device
Publication Date: 2025.10.07 MELLANOX TECHNOLOGIES LTD(IL)
  • US12438859B2 patent drawing
  • US12438859B2 patent drawing
  • US12438859B2 patent drawing

AI summary

A network device includes a hardware pipeline to process a network packet to be encrypted. A portion of the hardware pipeline retrieves information from the network packet and generates a command based on the information. A block cipher circuit is coupled inline within the hardware pipeline. The hardware pipeline includes hardware engines coupled between the portion of the hardware pipeline and the block cipher circuit. The hardware engines parse and execute the command to determine a set of inputs and input the set of inputs and portions of the network packet to the block cipher circuit. The block cipher circuit encrypts a payload data of the network packet based on the set of inputs.