Network Security Apparatus Using Microcode State Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security and monitoring systems, including firewalls and anti-virus software, are inadequate in detecting new types of attacks and reacting to threats effectively, as they lack comprehensive monitoring capabilities and flexibility, especially in high-speed networks, and are often inefficient due to non-deterministic performance and inflexibility in hardware architectures.

Innovation Solution

An apparatus that processes network traffic using microcode-controlled state machines and a distribution circuit to apply rules for traffic modification, enabling advanced network security and monitoring features, including signature-based and behavioral rule evaluation, deep packet inspection, and granular traffic modifications, without relying on general-purpose CPUs, thus providing a low-cost, high-speed, and flexible solution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If general-purpose CPUs are used for network traffic processing, then flexibility and adaptability are improved, but processing speed and productivity deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent replaces general-purpose CPU processing with specialized hardware components including network processors (NPs), content addressable memories (CAMs), and application-specific integrated circuits (ASICs). This substitution enables deterministic high-speed packet processing while maintaining flexibility through programmable state machines and microcode, directly resolving the contradiction between CPU flexibility and processing speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the operational parameters of processing elements by using parallel processing architectures where multiple NPs and CAMs operate simultaneously on different packet streams. This parallelism increases overall throughput while each individual processor maintains its flexible programmability, thus achieving both high speed and adaptability.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If specialized hardware components (NPs, CAMs) are added to enhance monitoring and detection capabilities, then detection precision and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network security processing function into distinct specialized components: NPs for packet processing, CAMs for signature matching, and ASICs for specific security functions. Each component is optimized for its specific task, improving detection precision while the modular architecture manages complexity through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the specialized hardware components to be multi-functional. The NPs can execute different microcode programs for various security protocols, CAMs can store multiple types of signatures and rules, and the system can handle different packet types and security threats, thereby reducing the need for separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If hardware architectures are not customized for network security applications, then ease of manufacture is improved, but performance reliability and productivity deteriorate due to non-deterministic behavior

Engineering Contradiction:
Improveease of manufactureVSAvoidperformance reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces general-purpose CPU architectures with customized hardware designs including NPs, CAMs, and ASICs that are specifically engineered for network security processing. These customized components provide deterministic performance characteristics and predictable timing behavior, ensuring reliability while remaining manufacturable through standard semiconductor fabrication processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If complex memory hierarchies and queuing structures are added to support high bandwidth networks, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvebandwidth handling capabilityVSAvoidmemory hierarchy complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the memory and queuing functions into distributed caches within each NP and CAM module, rather than using a complex centralized memory hierarchy. Each processing element has its own local memory, reducing the need for complex interconnection and memory management structures while maintaining high bandwidth capability through parallel access.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8024799B2Apparatus and method for facilitating network security with granular traffic modifications
Publication Date: 2011.09.20 CPACKET NETWORKS
  • US8024799B2 patent drawing
  • US8024799B2 patent drawing
  • US8024799B2 patent drawing

AI summary

An apparatus that facilitates network security for input network traffic includes microcode controlled state machines, each of which includes a computation kernel. Rules applied to a network traffic segment are distributed across the computation kernels. At least two of the computation kernels include condition logic configured by microcode stored in an associated control store to evaluate a unique configured rule in microcode to produce modification instructions. A distribution circuit routes the network traffic segment to each of the microcode controlled state machines. A circuit generates a modification command by combining the modification instructions from each of the at least two computation kernels, and performs a modification of the input network traffic based on the modification command to produce modified output network traffic that facilitates network security.