Network Interface Card Hardware Decryption and Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic processing systems face inefficiencies in handling encrypted data packets, as they often rely on software for decryption and classification, which can hinder performance and direct encrypted traffic to default locations without proper routing.

Innovation Solution

A network interface card equipped with hardware decryption and classification capabilities, allowing encrypted data packets to be decrypted and routed to appropriate receive rings based on classification, thereby bypassing software dependence and enhancing processing efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If software-based decryption and classification is used, then implementation flexibility is maintained, but processing performance deteriorates

Engineering Contradiction:
Improveprocessing performanceVSAvoidhardware complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces software-based decryption and classification mechanisms with dedicated hardware circuits. The decryption circuit performs cryptographic operations hardware-level, and the classification circuit analyzes packet headers and directs traffic to appropriate receive rings without software intervention, thereby achieving high processing performance while maintaining manageable hardware complexity through modular circuit design

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The network interface card performs decryption and classification autonomously through hardware circuits without requiring host system software processing. The decryption circuit self-manages cryptographic operations using stored keys, and the classification circuit self-routes packets based on header analysis, enabling the hardware to serve itself and eliminate software dependency for these functions

Inventive Principle:
Principle #25Self-service

2Reliability

If software processing is used for encrypted traffic, then routing flexibility is maintained, but traffic routing accuracy deteriorates

Engineering Contradiction:
Improverouting accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The classification circuit performs preliminary analysis of packet headers (such as IP addresses, ports, and protocol information) before decryption to determine the appropriate receive ring. This preliminary classification action ensures accurate routing decisions are made based on visible header data, while the subsequent hardware decryption occurs in parallel without delaying the routing decision, thereby achieving both high routing accuracy and processing efficiency

Inventive Principle:
Principle #10Preliminary action

3Productivity

If hardware decryption is implemented, then processing efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidhardware complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The hardware decryption function is segmented into distinct modular circuits: a decryption circuit that handles cryptographic operations, a classification circuit that analyzes packet headers and determines routing, and multiple receive rings for traffic distribution. This segmentation allows each component to be optimized independently, improving processing efficiency while keeping overall hardware complexity manageable through modular architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7607168B1Network interface decryption and classification technique
Publication Date: 2009.10.20 ORACLE AMERICAN INC
  • US7607168B1 patent drawing
  • US7607168B1 patent drawing
  • US7607168B1 patent drawing

AI summary

Encrypted data packets are received by a network interface card. The network interface card, upon determining that the received data packets are encrypted, directs the encrypted data packets to decryption hardware in the network interface card. The decryption hardware decrypts the encrypted data packets and forwards the decrypted data packets to a hardware classifier that classifies the decrypted data packets and directs the classified decrypted data packets to the appropriate receive resource(s) of the network interface card.