IPSec Offload Using XFRM and PL Hardware Collaboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of Internet Protocol Security (IPSec) protection consumes a large amount of processor resources and occupies significant resource overhead.

Innovation Solution

Implementing a secure communication method with software and hardware collaborative encryption, utilizing an extended framework for routing and management (XFRM) module and a programmable logic (PL) hardware module, where the XFRM module handles message identification and security association information, while the PL hardware module performs IPSec protection, thereby offloading processor-intensive tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based IPSec protection is implemented, then implementation flexibility is maintained, but processor resource consumption increases significantly

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidprocessor resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces the software-based mechanical processing system with a hardware acceleration system. Specifically, it uses a cryptographic processing unit (CPU) dedicated to hardware acceleration that performs IPSec protection operations through hardware circuits, substituting the traditional software processing mechanism. This substitution dramatically reduces the processor resource consumption while maintaining implementation flexibility through the software-hardware collaboration framework.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary hardware acceleration interface between the software processing layer and the hardware execution layer. This intermediary mechanism, represented by the hardware acceleration capability exposed through standard programming interfaces, allows software to leverage hardware acceleration without direct hardware access complexity. The intermediary layer manages the coordination between software IPSec processing and hardware acceleration, resolving the contradiction between flexibility and resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If hardware acceleration is introduced, then processor resource consumption is reduced, but system complexity increases

Engineering Contradiction:
Improveprocessor resource consumptionVSAvoidsystem complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent implements universality by designing the hardware acceleration interface to support multiple cryptographic algorithms and IPSec modes through a unified hardware acceleration framework. The hardware acceleration capability is designed to handle various encryption types (AES, DES, 3DES) and modes (ECB, CBC, CFB, OFB, CTR) through a single integrated interface, eliminating the need for separate hardware modules for each function. This multi-functionality reduces system complexity despite the introduction of hardware acceleration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the IPSec processing function into distinct software and hardware components. The software layer handles high-level coordination, policy management, and interface communication, while the hardware layer handles low-level cryptographic operations. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by clearly defining boundaries and interfaces between software and hardware, reducing the complexity burden of hardware acceleration integration.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If software-only processing is used, then system simplicity is maintained, but processing speed and efficiency are insufficient

Engineering Contradiction:
Improvesystem simplicityVSAvoidprocessing speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent merges software and hardware processing capabilities into a hybrid system that leverages the advantages of both. The software layer provides high-level processing, policy enforcement, and interface management, while the hardware layer provides high-speed cryptographic operations. By merging these capabilities through a coordinated software-hardware collaboration framework, the system achieves both processing speed improvement and operational simplicity, avoiding the complexity of pure hardware solutions while eliminating the speed limitations of software-only processing.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12603870B2Secure communication implementation method with software and hardware collaborative encryption and network device
Publication Date: 2026.04.14 HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD
  • US12603870B2 patent drawing
  • US12603870B2 patent drawing
  • US12603870B2 patent drawing

AI summary

The present disclosure provides a secure communication implementation method with software and hardware collaborative encryption. The method includes: after receiving a first network packet, querying, by an extended framework for routing and management (XFRM) module, a first mapping table through message identification information of the first network packet to obtain SA information corresponding to the message identification information; encapsulating the SA information in the first network packet and sending an encapsulated first network packet to a programmable logic (PL) hardware module; after receiving the encapsulated first network packet, parsing, by the PL hardware module, the SA information from the encapsulated first network packet, performing Internet protocol security (IPSec) protection on the first network packet based on the SA information to obtain a secured first network packet.