Microcode State Machine Network Traffic Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security and monitoring systems, including firewalls and antivirus software, are inadequate in detecting new types of attacks and reacting to threats effectively, as they rely on off-the-shelf components with non-deterministic performance and lack flexibility, leading to inefficiencies and high costs in high-speed networks.

Innovation Solution

An apparatus utilizing microcode controlled state machines and a distribution circuit to process network traffic according to provisioned rules and policies, enabling prioritized matching, categorization, and biased sampling, which allows for advanced network security and monitoring features such as deep packet inspection and granular traffic modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If advanced security systems use off-the-shelf computer system components (CPUs, memory, operating systems), then the system is easier to manufacture and maintain, but the performance is non-deterministic and inefficient for high-speed networks

Engineering Contradiction:
Improveease of manufactureVSAvoidprocessing speed
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent replaces general-purpose CPU-based processing with specialized hardware architectures including network processors (NPs), content addressable memories (CAMs), and application-specific integrated circuits (ASICs). This substitution of mechanical/computational systems enables deterministic high-speed packet processing while maintaining manufacturability through standardized hardware components.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the operational parameters of the system by implementing custom instruction sets, optimized data path widths, and tailored clock frequencies in the hardware architecture. These parameter changes enable the system to achieve wire-speed processing and predictable performance characteristics that off-the-shelf components cannot provide.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If additional co-processors (network processors and content addressable memories) are added to enhance monitoring and detection capabilities, then the detection capability is improved, but the cost increases substantially

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions (packet classification, deep packet inspection, intrusion detection, traffic monitoring) into a single integrated hardware architecture. By combining classification engines, inspection modules, and detection mechanisms into one unified system, the patent achieves enhanced detection capability without proportionally increasing device complexity or cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent designs a universal security processing platform that can perform multiple functions including firewall filtering, intrusion detection, virus scanning, and traffic analysis using the same hardware resources. This multi-functionality reduces the need for separate specialized components, thereby controlling device complexity while maintaining high detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If hardware architectures are not customized to the application, then the ease of manufacture is improved, but the performance is non-deterministic and validation is difficult

Engineering Contradiction:
Improveease of manufactureVSAvoidperformance predictability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the security processing function into distinct hardware modules with well-defined interfaces: packet classification module, deep packet inspection module, intrusion detection module, and traffic monitoring module. Each module is designed and validated independently, then integrated into a complete system. This segmentation enables both ease of manufacture through modular design and performance predictability through controlled integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary design and validation of hardware modules using formal verification methods and simulation before final integration. By validating each module's performance characteristics in advance, the patent ensures deterministic behavior in the complete system while maintaining manufacturability through standardized design processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2452466B1Apparatus and method for enhancing forwarding, classification, and monitoring of network traffic
Publication Date: 2021.01.06 CPACKET NETWORKS
  • EP2452466B1 patent drawingFigure 1
  • EP2452466B1 patent drawingFigure 2
  • EP2452466B1 patent drawingFigure 3

AI summary

An apparatus is described that performs prioritized matching through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a plurality of microcode controlled state machines, and a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that the plurality of microcode controlled state machines apply rules to the input data to determine matches and produce priority indicators, wherein each match has an associated priority indicator. At least one of the matches is selected based on the priority indicators. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of flexible, advanced network security and monitoring features and network traffic analysis.