Network Security Apparatus Using Microcode State Machines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and monitoring systems, including firewalls and anti-virus software, are inadequate in detecting new types of attacks and reacting to threats effectively, as they lack comprehensive monitoring capabilities and flexibility, especially in high-speed networks, and are often inefficient due to non-deterministic performance and inflexibility in hardware architectures.
Innovation Solution
An apparatus that processes network traffic using microcode-controlled state machines and a distribution circuit to apply rules for traffic modification, enabling advanced network security and monitoring features, including signature-based and behavioral rule evaluation, deep packet inspection, and granular traffic modifications, without relying on general-purpose CPUs, thus providing a low-cost, high-speed, and flexible solution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If general-purpose CPUs are used for network traffic processing, then flexibility and adaptability are improved, but processing speed and productivity deteriorate
Solution Approach 1:
The patent replaces general-purpose CPU processing with specialized hardware components including network processors (NPs), content addressable memories (CAMs), and application-specific integrated circuits (ASICs). This substitution enables deterministic high-speed packet processing while maintaining flexibility through programmable state machines and microcode, directly resolving the contradiction between CPU flexibility and processing speed.
Solution Approach 2:
The patent changes the operational parameters of processing elements by using parallel processing architectures where multiple NPs and CAMs operate simultaneously on different packet streams. This parallelism increases overall throughput while each individual processor maintains its flexible programmability, thus achieving both high speed and adaptability.
2Measurement precision
If specialized hardware components (NPs, CAMs) are added to enhance monitoring and detection capabilities, then detection precision and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The patent segments the network security processing function into distinct specialized components: NPs for packet processing, CAMs for signature matching, and ASICs for specific security functions. Each component is optimized for its specific task, improving detection precision while the modular architecture manages complexity through clear functional separation.
Solution Approach 2:
The patent designs the specialized hardware components to be multi-functional. The NPs can execute different microcode programs for various security protocols, CAMs can store multiple types of signatures and rules, and the system can handle different packet types and security threats, thereby reducing the need for separate dedicated hardware for each function.
3Ease of manufacture
If hardware architectures are not customized for network security applications, then ease of manufacture is improved, but performance reliability and productivity deteriorate due to non-deterministic behavior
Solution Approach 1:
The patent replaces general-purpose CPU architectures with customized hardware designs including NPs, CAMs, and ASICs that are specifically engineered for network security processing. These customized components provide deterministic performance characteristics and predictable timing behavior, ensuring reliability while remaining manufacturable through standard semiconductor fabrication processes.
4Productivity
If complex memory hierarchies and queuing structures are added to support high bandwidth networks, then productivity is improved, but device complexity increases
Solution Approach 1:
The patent segments the memory and queuing functions into distributed caches within each NP and CAM module, rather than using a complex centralized memory hierarchy. Each processing element has its own local memory, reducing the need for complex interconnection and memory management structures while maintaining high bandwidth capability through parallel access.
Data Source
AI summary
An apparatus that facilitates network security for input network traffic includes microcode controlled state machines, each of which includes a computation kernel. Rules applied to a network traffic segment are distributed across the computation kernels. At least two of the computation kernels include condition logic configured by microcode stored in an associated control store to evaluate a unique configured rule in microcode to produce modification instructions. A distribution circuit routes the network traffic segment to each of the microcode controlled state machines. A circuit generates a modification command by combining the modification instructions from each of the at least two computation kernels, and performs a modification of the input network traffic based on the modification command to produce modified output network traffic that facilitates network security.


