Network Interface Card Hardware Decryption and Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic processing systems face inefficiencies in handling encrypted data packets, as they often rely on software for decryption and classification, which can hinder performance and direct encrypted traffic to default locations without proper routing.
Innovation Solution
A network interface card equipped with hardware decryption and classification capabilities, allowing encrypted data packets to be decrypted and routed to appropriate receive rings based on classification, thereby bypassing software dependence and enhancing processing efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If software-based decryption and classification is used, then implementation flexibility is maintained, but processing performance deteriorates
Solution Approach 1:
The patent replaces software-based decryption and classification mechanisms with dedicated hardware circuits. The decryption circuit performs cryptographic operations hardware-level, and the classification circuit analyzes packet headers and directs traffic to appropriate receive rings without software intervention, thereby achieving high processing performance while maintaining manageable hardware complexity through modular circuit design
Solution Approach 2:
The network interface card performs decryption and classification autonomously through hardware circuits without requiring host system software processing. The decryption circuit self-manages cryptographic operations using stored keys, and the classification circuit self-routes packets based on header analysis, enabling the hardware to serve itself and eliminate software dependency for these functions
2Reliability
If software processing is used for encrypted traffic, then routing flexibility is maintained, but traffic routing accuracy deteriorates
Solution Approach 1:
The classification circuit performs preliminary analysis of packet headers (such as IP addresses, ports, and protocol information) before decryption to determine the appropriate receive ring. This preliminary classification action ensures accurate routing decisions are made based on visible header data, while the subsequent hardware decryption occurs in parallel without delaying the routing decision, thereby achieving both high routing accuracy and processing efficiency
3Productivity
If hardware decryption is implemented, then processing efficiency is improved, but device complexity increases
Solution Approach 1:
The hardware decryption function is segmented into distinct modular circuits: a decryption circuit that handles cryptographic operations, a classification circuit that analyzes packet headers and determines routing, and multiple receive rings for traffic distribution. This segmentation allows each component to be optimized independently, improving processing efficiency while keeping overall hardware complexity manageable through modular architecture
Data Source
AI summary
Encrypted data packets are received by a network interface card. The network interface card, upon determining that the received data packets are encrypted, directs the encrypted data packets to decryption hardware in the network interface card. The decryption hardware decrypts the encrypted data packets and forwards the decrypted data packets to a hardware classifier that classifies the decrypted data packets and directs the classified decrypted data packets to the appropriate receive resource(s) of the network interface card.


