In-line Security Processor for Network Data Path Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic processing systems for secure data transmission over data networks are inefficient due to additional round trips on the host bus, high costs, and difficulty in integration with TCP offload engines, leading to a need for improved data security processing techniques that support faster data transfers while being cost-effective and adaptable.

Innovation Solution

An in-line security processor is integrated into the data path to perform encryption, decryption, and authentication operations, operating transparently with host processing components and network controllers, reducing the need for external cryptographic engines and minimizing bus traffic, and allowing configuration via the packet network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PCI-resident cryptographic engines are used, then data security processing is provided, but additional round trips over the host bus are required and system cost increases

Engineering Contradiction:
Improvedata security processingVSAvoidadditional round trips
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the cryptographic engine with the network interface controller into a single integrated device. This merging eliminates the need for separate PCI-resident cryptographic engines and their associated host bus round trips, as cryptographic operations can now be performed locally at the network interface without requiring data to be transferred back and forth between the network card and the host processor via the PCI bus.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the cryptographic processing function from the host processor and PCI bus system, placing it directly within the network interface controller. This extraction removes the cryptographic engine from the conventional PCI-resident architecture, eliminating the harmful host bus round trips while maintaining security processing capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional PCI-resident cryptographic engines are used, then data security processing is provided, but system cost increases significantly

Engineering Contradiction:
Improvedata security processingVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the cryptographic engine with the network interface controller into a single integrated device. This consolidation eliminates the need for separate cryptographic hardware components, reducing overall system cost while maintaining security processing capabilities. The integration allows cryptographic functions to be implemented as part of the standard network interface controller rather than requiring additional expensive dedicated cryptographic hardware.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If dedicated cryptographic devices are used, then encryption/decryption operations are offloaded, but integration with TCP offload engines becomes difficult

Engineering Contradiction:
Improveprocessing offloadVSAvoidintegration capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent combines the cryptographic engine with the network interface controller, which can work in conjunction with TCP offload engines. This integration allows cryptographic processing to be seamlessly incorporated into the data path without creating conflicts with TCP offload functionality, as the cryptographic operations are performed at the network interface level rather than requiring separate dedicated devices that would sit in the midst of the TCP offload engine.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If cryptographic operations are performed by separate devices, then processing is offloaded, but bus traffic increases

Engineering Contradiction:
Improveprocessing offloadVSAvoidbus traffic
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent merges the cryptographic engine with the network interface controller, allowing cryptographic operations to be performed locally at the network interface without requiring data to be transferred over the host bus. This integration eliminates the additional bus traffic that would result from using separate cryptographic devices, as the processing occurs in-place within the same device that handles network data transmission.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7587587B2Data path security processing
Publication Date: 2009.09.08 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US7587587B2 patent drawing
  • US7587587B2 patent drawing
  • US7587587B2 patent drawing

AI summary

Methods and associated systems provide secured data transmission over a data network. A security device provides security processing in the data path of a packet network. The device may include at least one network interface to send packets to and receive packets from a data network and at least one cryptographic engine for performing encryption, decryption and/or authentication operations. The device may be configured as an in-line security processor that processes packets that pass through the device as the packets are routed to/from the data network.