FPGA Classification-Based Configuration in Network Security Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for dynamically configuring Field Programmable Gate Arrays (FPGAs) in network security devices are inefficient, as they require the Central Processing Unit (CPU) to perform addressing and generate multiple configuration entries, leading to high CPU resource occupation and reduced system performance, especially during high configuration frequencies.

Innovation Solution

The method involves the CPU generating a configuration entry with a classification number for each FPGA, which autonomously compares and stores the configuration content when the classification numbers match, allowing the FPGA to receive and process the configuration independently, reducing CPU involvement and channel bandwidth occupation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the CPU performs addressing and generates multiple configuration entries for each FPGA, then the configuration can be precisely delivered to the target FPGA, but the CPU resource occupation increases and system performance decreases

Engineering Contradiction:
Improveconfiguration delivery precisionVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent divides the configuration delivery process into two parts: the CPU generates a single configuration entry with a classification number, and the FPGA autonomously performs the matching and configuration application. This segmentation reduces CPU workload while maintaining precise configuration delivery through the classification number matching mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The FPGA is empowered to autonomously obtain its classification number, compare it with the configuration entry's classification number, and independently apply the configuration when they match. This self-service capability eliminates the need for CPU-mediated addressing, significantly reducing CPU resource occupation while ensuring accurate configuration delivery.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If the CPU generates multiple configuration entries for each FPGA, then the correct configuration can be assigned to the target FPGA, but the channel bandwidth occupation increases

Engineering Contradiction:
Improveconfiguration assignment accuracyVSAvoidchannel bandwidth occupation
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent merges multiple configuration entries into a single configuration entry that contains a classification number. This single entry can be used by multiple FPGAs with the same classification number, reducing the number of configuration entries transmitted over the channel and thereby reducing bandwidth occupation while maintaining accurate configuration assignment through classification matching.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If the CPU is heavily involved in FPGA configuration process, then precise configuration control can be achieved, but the configuration frequency is limited

Engineering Contradiction:
Improveconfiguration control precisionVSAvoidconfiguration frequency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The FPGA autonomously obtains its classification number, compares it with the configuration entry's classification number, and independently applies the configuration when they match. This self-service mechanism eliminates the need for CPU intervention in each configuration operation, allowing configurations to be applied at high frequency without CPU bottleneck, while precision is maintained through the classification number matching mechanism.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11568092B2Method of dynamically configuring FPGA and network security device
Publication Date: 2023.01.31 HANGZHOU DPTECH TECH
  • US11568092B2 patent drawing
  • US11568092B2 patent drawing
  • US11568092B2 patent drawing

AI summary

Provided are a method of dynamically configuring a FPGA and a network security device. The network security device includes a CPU and at least one FPGA coupled with the CPU. The CPU generates a configuration entry for a target FPGA in response to a user instruction. The configuration entry includes a classification number and a configuration content for the target FPGA. The CPU sends the configuration entry to each FPGA coupled with the CPU, Each FPGA obtains its own classification number, compares its own classification number with the classification number in the configuration entry, and stores the configuration content when the own classification number the same with the classification number in the configuration entry.