IPSEC Authentication Pipeline for Mutable Field Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which can lead to bottlenecks in data throughput.

Innovation Solution

A network interface system with a security system that includes a pipeline to mask mutable fields from incoming data prior to authentication, offloading processing tasks and reducing computational load on the host system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host system performs authentication processing for incoming IPSEC packets, then security verification is achieved, but host processing overhead increases and data throughput is reduced

Engineering Contradiction:
Improvesecurity verificationVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the authentication processing function from the host system and relocates it to a dedicated security system within the network interface card. This separation allows the host to focus on data processing while the security system handles authentication, thereby improving both security verification reliability and overall data throughput by eliminating the host processing bottleneck

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a pipeline as an intermediary component between the network interface and the security system. This pipeline pre-processes incoming packets by identifying and masking mutable fields before authentication, enabling the security system to work more efficiently and further enhancing throughput while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If host system performs segmentation and checksumming tasks, then protocol compliance is ensured, but computational load on host increases

Engineering Contradiction:
Improveprotocol complianceVSAvoidcomputational load
Core Design Contradiction:
Manufacturing precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts segmentation and checksumming functions from the host system and implements them within the network interface card's security system. This offloading ensures protocol compliance is maintained while significantly reducing the computational load and energy consumption of the host system

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If pipeline masks mutable fields prior to authentication, then authentication accuracy is improved, but processing complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the pipeline mask mutable fields before the authentication process begins. This pre-processing step ensures that only immutable fields are authenticated, improving authentication accuracy while the modular pipeline architecture keeps the added complexity manageable and organized

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7512787B1Receive IPSEC in-line processing of mutable fields for AH algorithm
Publication Date: 2009.03.31 GLOBALFOUNDRIES US INC
  • US7512787B1 patent drawing
  • US7512787B1 patent drawing
  • US7512787B1 patent drawing

AI summary

The invention relates to a network interface system for interfacing a host system with a network. The network interface system includes a bus interface system, a media access control system, and a security system. The security system is operative to selectively authenticate incoming and outgoing data. The security system includes a pipeline that masks mutable fields from incoming data prior to authentication.