Network Port Encryption for Scalable Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for encrypting data-at-rest in network devices are limited by low throughput and high costs, particularly in multi-gigabit Storage Area Networks (SANs), as they either rely on hardware-accelerated network appliances or software-based encryption at source or destination devices, which do not scale for pervasive protection.
Innovation Solution
Performing encryption and decryption of data at rest at the port of a network device, such as a switch, before data is written to or read from a storage medium, using dedicated logic and protocols like Fibre Channel or Ethernet, allowing for per-port processing to match the switch's capacity and enabling scalable, economical wire-speed protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If encryption is performed at a network appliance with hardware acceleration, then encryption throughput is improved, but the solution does not scale to service numerous storage devices in a multi-gigabit SAN
Solution Approach 1:
The encryption function is segmented from the central network appliance and distributed to individual network ports. Each port has its own encryption capability, allowing independent processing of data streams to multiple storage devices. This segmentation enables the system to scale to numerous storage devices simultaneously without bottlenecking at a single encryption point.
Solution Approach 2:
The encryption capability is moved from a centralized single-point architecture to a distributed multi-point architecture across network ports. This dimensional change from one encryption engine to many enables wire-speed protection across entire SANs with multiple gigabit interfaces, solving the scalability limitation.
2Ease of manufacture
If encryption is performed at source or destination devices in software, then device cost is reduced, but encryption throughput is limited and cannot provide wire-speed protection
Solution Approach 1:
The network port acts as an intermediary between source devices and storage media, performing hardware-accelerated encryption. This intermediary approach allows standard source and destination devices to maintain lower costs while still achieving wire-speed encryption throughput through the port's dedicated encryption capability.
Solution Approach 2:
Software-based encryption is replaced with hardware-accelerated encryption at the network port. This substitution provides wire-speed protection capability while keeping source and destination devices economically feasible, as the encryption hardware resides in the network infrastructure rather than expensive end devices.
3Reliability
If a single hardware-accelerated encryptor services numerous sources, then encryption capability is improved, but the performance of the network appliance is limited
Solution Approach 1:
The single encryptor architecture is segmented into multiple port-based encryption engines. Each network port has dedicated encryption capability, eliminating the bottleneck of a single encryptor servicing numerous sources. This allows the network appliance to maintain high performance while providing encryption capability across all ports simultaneously.
Data Source
AI summary
Methods and apparatus for performing encryption for data at rest at a port of a network device such as a switch are disclosed. Specifically, when data is received from a host during a write to a storage medium such as a disk, the data is encrypted by the port prior to transmitting the encrypted data to the storage medium. Similarly, when a host attempts to read data from the storage medium, the port of the network device receives the encrypted data from the storage medium, decrypts the data, and transmits the decrypted data to the host. In this manner, encryption and decryption of data at rest are supported by the port of the network device.


