Network Interface Security Pipelines for IPsec Processing Bottlenecks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which can lead to increased processing load and inefficiencies.

Innovation Solution

A network interface system with a security system that includes encryption and authentication pipelines, allowing for offloading of security processing from the host system, utilizing two sets of authentication pipelines to alternate frames and maintain continuous encryption processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processing is performed on the host system, then security functions can be implemented, but processing load and overhead increase

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidhost processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security processing functions (encryption and authentication pipelines) from the host system and implements them in the network interface card. This allows the host to offload computationally intensive security operations, reducing processing load while maintaining security capabilities in the NIC hardware.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If authentication processing uses a single pipeline, then device complexity is reduced, but processing speed and throughput decrease

Engineering Contradiction:
Improveauthentication processing speedVSAvoidnumber of authentication pipelines
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments authentication processing into multiple parallel pipelines (first and second authentication pipelines) that can simultaneously process different data packets. This segmentation increases throughput and processing speed while distributing the computational load across multiple dedicated hardware units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements continuous processing by having multiple authentication pipelines operate in parallel, ensuring that the authentication function continues without interruption. While one pipeline processes a packet, another can simultaneously handle the next packet, eliminating idle time and maintaining continuous useful action.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If encryption pipelines are interrupted for authentication processing, then resource utilization is optimized, but processing continuity and speed suffer

Engineering Contradiction:
Improveencryption processing continuityVSAvoidpipeline coordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides authentication processing into separate dedicated pipelines that are independent of the encryption pipeline. This segmentation allows encryption to proceed continuously in its own pipeline while authentication occurs in parallel in separate pipelines, eliminating the need to interrupt encryption for authentication operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7818563B1Method to maximize hardware utilization in flow-thru IPsec processing
Publication Date: 2010.10.19 ADVANCED MICRO DEVICES INC
  • US7818563B1 patent drawing
  • US7818563B1 patent drawing
  • US7818563B1 patent drawing

AI summary

The invention relates to a network interface system for interfacing a host system with a network. The network interface system includes a bus interface system, a media access control system, a memory system, and a security system. The security system is coupled to the memory system and is adapted to selectively perform security processing on incoming and outgoing data. For at least one of receive or transmit processing, the security system comprises one or more encryption pipelines and at least two sets of one or more authentication pipelines. The encryption pipelines are adapted to perform one or more encryption or decryption algorithms. The authentication pipelines are adapted to perform one or more authentication algorithms. The security system is configured to selectively process frames through the encryption pipelines and then through the two sets of authentication pipelines. The system toggles whereby successive frames alternate between the two sets of authentication pipelines.