IPSec Offload Using XFRM and PL Hardware Collaboration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The process of Internet Protocol Security (IPSec) protection consumes a large amount of processor resources and occupies significant resource overhead.
Innovation Solution
Implementing a secure communication method with software and hardware collaborative encryption, utilizing an extended framework for routing and management (XFRM) module and a programmable logic (PL) hardware module, where the XFRM module handles message identification and security association information, while the PL hardware module performs IPSec protection, thereby offloading processor-intensive tasks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software-based IPSec protection is implemented, then implementation flexibility is maintained, but processor resource consumption increases significantly
Solution Approach 1:
The patent replaces the software-based mechanical processing system with a hardware acceleration system. Specifically, it uses a cryptographic processing unit (CPU) dedicated to hardware acceleration that performs IPSec protection operations through hardware circuits, substituting the traditional software processing mechanism. This substitution dramatically reduces the processor resource consumption while maintaining implementation flexibility through the software-hardware collaboration framework.
Solution Approach 2:
The patent introduces an intermediary hardware acceleration interface between the software processing layer and the hardware execution layer. This intermediary mechanism, represented by the hardware acceleration capability exposed through standard programming interfaces, allows software to leverage hardware acceleration without direct hardware access complexity. The intermediary layer manages the coordination between software IPSec processing and hardware acceleration, resolving the contradiction between flexibility and resource consumption.
2Use of energy by moving object
If hardware acceleration is introduced, then processor resource consumption is reduced, but system complexity increases
Solution Approach 1:
The patent implements universality by designing the hardware acceleration interface to support multiple cryptographic algorithms and IPSec modes through a unified hardware acceleration framework. The hardware acceleration capability is designed to handle various encryption types (AES, DES, 3DES) and modes (ECB, CBC, CFB, OFB, CTR) through a single integrated interface, eliminating the need for separate hardware modules for each function. This multi-functionality reduces system complexity despite the introduction of hardware acceleration.
Solution Approach 2:
The patent segments the IPSec processing function into distinct software and hardware components. The software layer handles high-level coordination, policy management, and interface communication, while the hardware layer handles low-level cryptographic operations. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by clearly defining boundaries and interfaces between software and hardware, reducing the complexity burden of hardware acceleration integration.
3Device complexity
If software-only processing is used, then system simplicity is maintained, but processing speed and efficiency are insufficient
Solution Approach 1:
The patent merges software and hardware processing capabilities into a hybrid system that leverages the advantages of both. The software layer provides high-level processing, policy enforcement, and interface management, while the hardware layer provides high-speed cryptographic operations. By merging these capabilities through a coordinated software-hardware collaboration framework, the system achieves both processing speed improvement and operational simplicity, avoiding the complexity of pure hardware solutions while eliminating the speed limitations of software-only processing.
Data Source
AI summary
The present disclosure provides a secure communication implementation method with software and hardware collaborative encryption. The method includes: after receiving a first network packet, querying, by an extended framework for routing and management (XFRM) module, a first mapping table through message identification information of the first network packet to obtain SA information corresponding to the message identification information; encapsulating the SA information in the first network packet and sending an encapsulated first network packet to a programmable logic (PL) hardware module; after receiving the encapsulated first network packet, parsing, by the PL hardware module, the SA information from the encapsulated first network packet, performing Internet protocol security (IPSec) protection on the first network packet based on the SA information to obtain a secured first network packet.


