Hardware Data Filtering Device for High Throughput and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software-based data filtering devices in communication networks suffer from low throughput, high latency, and security integrity issues, failing to provide satisfactory performance in filtering data between computer networks of different sensitivity levels.
Innovation Solution
An electronic data filtering device utilizing FPGA or ASIC circuits for its extraction, verification, and action modules, equipped with configuration, extraction, verification, and action instruction sets, ensures configurability, low latency, and enhanced security by implementing a filtering block with a conformity control block and operational memory for effective data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software-based filtering devices are used, then configurability is improved, but throughput deteriorates and latency increases
Solution Approach 1:
The patent segments the filtering device into a hardware core (FPGA/ASIC) for high-speed packet processing and a software component for configurable rule management. This segmentation allows the hardware to handle high throughput while software provides adaptability through instruction set configuration, resolving the contradiction between performance and configurability.
Solution Approach 2:
The patent introduces an intermediary instruction set architecture that bridges hardware capabilities and software configurability. The extraction, verification, and action instruction sets act as intermediaries that translate high-level filtering rules into efficient hardware operations, enabling both high throughput and adaptability.
2Adaptability or versatility
If software-based filtering devices are used, then configurability is improved, but security integrity deteriorates
Solution Approach 1:
The patent segments security-critical functions into dedicated hardware modules (extraction, verification, action) that operate with fixed, verified logic, while configurability is maintained through a controlled instruction set interface. This segmentation isolates security risks in the hardware core while allowing flexible configuration through standardized instructions.
Solution Approach 2:
The patent replaces software-based filtering logic with hardware implementations (FPGA/ASIC) for critical security functions. This substitution eliminates vulnerabilities associated with software execution while maintaining configurability through hardware-programmable instruction sets, thereby improving security integrity.
3Ease of operation
If software-based filtering devices are used, then ease of operation is improved, but latency increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring hardware resources and instruction sets before data processing begins. The extraction and verification modules are pre-loaded with optimized hardware logic, allowing immediate high-speed processing once configuration is complete, thus reducing operational latency while maintaining ease of configuration.
Solution Approach 2:
The patent substitutes software processing with hardware acceleration for time-sensitive filtering operations. By implementing extraction, verification, and action modules in FPGA/ASIC, the system achieves low latency while maintaining ease of operation through configurable instruction sets that guide hardware behavior.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This electronic data filtering device (10) is configured to filter data (14) and includes a first filtering unit (16) comprising a filtering block (22). The filtering block (22) includes: - a configuration module (26), configured to store a set of extraction instructions, a set of evaluation instructions, and a set of action instructions; - a first extraction module (28) to initialize a set of filtering operands based on the frame (T); - a first verification module (30) to verify filtering rules based on the initialized filtering operands; and - a first action module (32) to perform an action on the frame (T) based on the verification of the filtering rules. The first extraction (28), verification (30), and action (32) modules are implemented as an FPGA or an ASIC.