Network Port Encryption for Scalable Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for encrypting data-at-rest in network devices are limited by low throughput and high costs, particularly in multi-gigabit Storage Area Networks (SANs), as they either rely on hardware-accelerated network appliances or software-based encryption at source or destination devices, which do not scale for pervasive protection.

Innovation Solution

Performing encryption and decryption of data at rest at the port of a network device, such as a switch, before data is written to or read from a storage medium, using dedicated logic and protocols like Fibre Channel or Ethernet, allowing for per-port processing to match the switch's capacity and enabling scalable, economical wire-speed protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If encryption is performed at a network appliance with hardware acceleration, then encryption throughput is improved, but the solution does not scale to service numerous storage devices in a multi-gigabit SAN

Engineering Contradiction:
Improveencryption throughputVSAvoidscalability to numerous storage devices
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The encryption function is segmented from the central network appliance and distributed to individual network ports. Each port has its own encryption capability, allowing independent processing of data streams to multiple storage devices. This segmentation enables the system to scale to numerous storage devices simultaneously without bottlenecking at a single encryption point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption capability is moved from a centralized single-point architecture to a distributed multi-point architecture across network ports. This dimensional change from one encryption engine to many enables wire-speed protection across entire SANs with multiple gigabit interfaces, solving the scalability limitation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If encryption is performed at source or destination devices in software, then device cost is reduced, but encryption throughput is limited and cannot provide wire-speed protection

Engineering Contradiction:
Improvedevice costVSAvoidencryption throughput
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The network port acts as an intermediary between source devices and storage media, performing hardware-accelerated encryption. This intermediary approach allows standard source and destination devices to maintain lower costs while still achieving wire-speed encryption throughput through the port's dedicated encryption capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Software-based encryption is replaced with hardware-accelerated encryption at the network port. This substitution provides wire-speed protection capability while keeping source and destination devices economically feasible, as the encryption hardware resides in the network infrastructure rather than expensive end devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a single hardware-accelerated encryptor services numerous sources, then encryption capability is improved, but the performance of the network appliance is limited

Engineering Contradiction:
Improveencryption capabilityVSAvoidnetwork appliance performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The single encryptor architecture is segmented into multiple port-based encryption engines. Each network port has dedicated encryption capability, eliminating the bottleneck of a single encryptor servicing numerous sources. This allows the network appliance to maintain high performance while providing encryption capability across all ports simultaneously.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8266431B2Method and apparatus for performing encryption of data at rest at a port of a network device
Publication Date: 2012.09.11 CISCO TECHNOLOGY INC
  • US8266431B2 patent drawing
  • US8266431B2 patent drawing
  • US8266431B2 patent drawing

AI summary

Methods and apparatus for performing encryption for data at rest at a port of a network device such as a switch are disclosed. Specifically, when data is received from a host during a write to a storage medium such as a disk, the data is encrypted by the port prior to transmitting the encrypted data to the storage medium. Similarly, when a host attempts to read data from the storage medium, the port of the network device receives the encrypted data from the storage medium, decrypts the data, and transmits the decrypted data to the host. In this manner, encryption and decryption of data at rest are supported by the port of the network device.