Microcode State Machine Network Traffic Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and monitoring systems, including firewalls and antivirus software, are inadequate in detecting new types of attacks and reacting to threats effectively, as they rely on off-the-shelf components with non-deterministic performance and lack flexibility, leading to inefficiencies and high costs in high-speed networks.
Innovation Solution
An apparatus utilizing microcode controlled state machines and a distribution circuit to process network traffic according to provisioned rules and policies, enabling prioritized matching, categorization, and biased sampling, which allows for advanced network security and monitoring features such as deep packet inspection and granular traffic modifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If advanced security systems use off-the-shelf computer system components (CPUs, memory, operating systems), then the system is easier to manufacture and maintain, but the performance is non-deterministic and inefficient for high-speed networks
Solution Approach 1:
The patent replaces general-purpose CPU-based processing with specialized hardware architectures including network processors (NPs), content addressable memories (CAMs), and application-specific integrated circuits (ASICs). This substitution of mechanical/computational systems enables deterministic high-speed packet processing while maintaining manufacturability through standardized hardware components.
Solution Approach 2:
The patent changes the operational parameters of the system by implementing custom instruction sets, optimized data path widths, and tailored clock frequencies in the hardware architecture. These parameter changes enable the system to achieve wire-speed processing and predictable performance characteristics that off-the-shelf components cannot provide.
2Reliability
If additional co-processors (network processors and content addressable memories) are added to enhance monitoring and detection capabilities, then the detection capability is improved, but the cost increases substantially
Solution Approach 1:
The patent merges multiple security functions (packet classification, deep packet inspection, intrusion detection, traffic monitoring) into a single integrated hardware architecture. By combining classification engines, inspection modules, and detection mechanisms into one unified system, the patent achieves enhanced detection capability without proportionally increasing device complexity or cost.
Solution Approach 2:
The patent designs a universal security processing platform that can perform multiple functions including firewall filtering, intrusion detection, virus scanning, and traffic analysis using the same hardware resources. This multi-functionality reduces the need for separate specialized components, thereby controlling device complexity while maintaining high detection capability.
3Ease of manufacture
If hardware architectures are not customized to the application, then the ease of manufacture is improved, but the performance is non-deterministic and validation is difficult
Solution Approach 1:
The patent segments the security processing function into distinct hardware modules with well-defined interfaces: packet classification module, deep packet inspection module, intrusion detection module, and traffic monitoring module. Each module is designed and validated independently, then integrated into a complete system. This segmentation enables both ease of manufacture through modular design and performance predictability through controlled integration.
Solution Approach 2:
The patent performs preliminary design and validation of hardware modules using formal verification methods and simulation before final integration. By validating each module's performance characteristics in advance, the patent ensures deterministic behavior in the complete system while maintaining manufacturability through standardized design processes.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An apparatus is described that performs prioritized matching through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a plurality of microcode controlled state machines, and a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that the plurality of microcode controlled state machines apply rules to the input data to determine matches and produce priority indicators, wherein each match has an associated priority indicator. At least one of the matches is selected based on the priority indicators. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of flexible, advanced network security and monitoring features and network traffic analysis.