In-line Security Processor for Network Data Path Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic processing systems for secure data transmission over data networks are inefficient due to additional round trips on the host bus, high costs, and difficulty in integration with TCP offload engines, leading to a need for improved data security processing techniques that support faster data transfers while being cost-effective and adaptable.
Innovation Solution
An in-line security processor is integrated into the data path to perform encryption, decryption, and authentication operations, operating transparently with host processing components and network controllers, reducing the need for external cryptographic engines and minimizing bus traffic, and allowing configuration via the packet network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional PCI-resident cryptographic engines are used, then data security processing is provided, but additional round trips over the host bus are required and system cost increases
Solution Approach 1:
The patent combines the cryptographic engine with the network interface controller into a single integrated device. This merging eliminates the need for separate PCI-resident cryptographic engines and their associated host bus round trips, as cryptographic operations can now be performed locally at the network interface without requiring data to be transferred back and forth between the network card and the host processor via the PCI bus.
Solution Approach 2:
The patent extracts the cryptographic processing function from the host processor and PCI bus system, placing it directly within the network interface controller. This extraction removes the cryptographic engine from the conventional PCI-resident architecture, eliminating the harmful host bus round trips while maintaining security processing capabilities.
2Reliability
If conventional PCI-resident cryptographic engines are used, then data security processing is provided, but system cost increases significantly
Solution Approach 1:
The patent merges the cryptographic engine with the network interface controller into a single integrated device. This consolidation eliminates the need for separate cryptographic hardware components, reducing overall system cost while maintaining security processing capabilities. The integration allows cryptographic functions to be implemented as part of the standard network interface controller rather than requiring additional expensive dedicated cryptographic hardware.
3Productivity
If dedicated cryptographic devices are used, then encryption/decryption operations are offloaded, but integration with TCP offload engines becomes difficult
Solution Approach 1:
The patent combines the cryptographic engine with the network interface controller, which can work in conjunction with TCP offload engines. This integration allows cryptographic processing to be seamlessly incorporated into the data path without creating conflicts with TCP offload functionality, as the cryptographic operations are performed at the network interface level rather than requiring separate dedicated devices that would sit in the midst of the TCP offload engine.
4Productivity
If cryptographic operations are performed by separate devices, then processing is offloaded, but bus traffic increases
Solution Approach 1:
The patent merges the cryptographic engine with the network interface controller, allowing cryptographic operations to be performed locally at the network interface without requiring data to be transferred over the host bus. This integration eliminates the additional bus traffic that would result from using separate cryptographic devices, as the processing occurs in-place within the same device that handles network data transmission.
Data Source
AI summary
Methods and associated systems provide secured data transmission over a data network. A security device provides security processing in the data path of a packet network. The device may include at least one network interface to send packets to and receive packets from a data network and at least one cryptographic engine for performing encryption, decryption and/or authentication operations. The device may be configured as an in-line security processor that processes packets that pass through the device as the packets are routed to/from the data network.


