Network Device Security Inspection Using Accelerators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security challenges persist in preventing devices from receiving or transmitting malicious or unauthorized data, as existing solutions struggle to effectively enforce security policies in real-time across communications networks.

Innovation Solution

A network device equipped with processors, accelerators, and integrated circuitry for real-time inspection of data, utilizing machine learning models and specialized accelerators like RegEx and SHA accelerators to identify policy violations, and generating responses to prevent data transmission or reception if policies are breached.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time data inspection is performed using processors and accelerators, then security policy enforcement capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity policy enforcement capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device divides security inspection functions into separate specialized accelerators (SHA accelerator for hash calculations, RegEx accelerator for pattern matching) and general processors. This segmentation allows each component to handle specific inspection tasks independently, improving overall security enforcement capability while managing complexity through functional specialization rather than monolithic processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network device integrates multiple inspection functions (hash calculation, regular expression matching, machine learning model evaluation) into a single unified security inspection system. The accelerators and processors work together to provide comprehensive security policy enforcement, making the device multi-functional in its security capabilities while presenting a cohesive system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If machine learning models and accelerators are used for policy violation identification, then inspection speed is improved, but device complexity increases

Engineering Contradiction:
Improveinspection speedVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces traditional software-based inspection methods with hardware accelerators (SHA accelerator for cryptographic hash calculations, RegEx accelerator for pattern matching) and integrated machine learning models. This substitution of mechanical/software processes with specialized hardware and AI algorithms significantly improves inspection speed while the modular architecture manages complexity through hardware acceleration rather than purely software-based solutions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive security inspection is performed on all network data, then security coverage is improved, but processing time increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network device performs preliminary security inspections using accelerators and machine learning models to quickly identify and filter out malicious or policy-violating data before it reaches the main processing queue. This preliminary action using specialized hardware and AI algorithms enables comprehensive security coverage while reducing the processing time burden on the main inspection system by pre-filtering problematic data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The inspection system applies different inspection depths and methods to different data types and threat levels. Critical data receives comprehensive inspection using all accelerators and models, while less critical data receives streamlined inspection. This local quality approach ensures comprehensive security coverage for high-risk items while reducing overall processing time through differentiated inspection strategies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20220400123A1Secure network access device
Publication Date: 2022.12.15 MELLANOX TECHNOLOGIES LTD(IL)
  • US20220400123A1 patent drawing
  • US20220400123A1 patent drawing
  • US20220400123A1 patent drawing

AI summary

Systems and techniques for securing network communications are described. A network device comprises a network interface and at least one accelerator. The network device inspects obtained data using the accelerator. The network device determines, based on the inspection, that the data is indicative of a violation of a security policy, and generates a response to the violation.