Network Interface Card Offloading Checksum and Security Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which can lead to increased computational load and inefficiency.

Innovation Solution

A network interface system that offloads security processing, checksumming, and segmentation from the host system by incorporating a bus interface, media access control, memory, security, and checksum systems, allowing for selective encryption, decryption, and checksum generation within a single integrated circuit, thereby reducing the computational burden on the host.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security processing, checksumming, and segmentation are performed by the host system processor, then processing capabilities are sufficient, but computational load and processing time increase significantly

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent extracts security processing, checksumming, and segmentation functions from the host system processor and relocates them to dedicated hardware components within the network interface card. This extraction removes the computational burden from the host processor, allowing it to focus on higher-level tasks while the offloaded functions handle data preparation and security operations independently, thereby reducing processing time and improving overall data transfer efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network interface card serves as an intermediary device between the host system and the network. By incorporating dedicated security processing units, checksumming engines, and segmentation logic within the NIC, it mediates the data transfer process by handling time-consuming operations locally before data leaves or enters the host system. This intermediary approach prevents the host processor from being bottlenecked by these routine but computationally intensive tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If host system performs all network processing functions, then system simplicity is maintained, but computational overhead increases

Engineering Contradiction:
Improvesystem complexityVSAvoidcomputational overhead
Core Design Contradiction:
Device complexityVSUse of energy by moving object

Solution Approach 1:

The patent segments the network processing functions by dividing them into distinct operational components: security processing unit, checksumming engine, and segmentation logic. Each component is implemented as separate hardware modules within the network interface card, allowing independent operation and optimization. This segmentation distributes the computational workload across specialized units rather than concentrating it all in the host processor, reducing overall computational overhead while maintaining manageable system architecture.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If security processing is performed in software on the host, then flexibility is maintained, but processing speed decreases

Engineering Contradiction:
Improveprocessing flexibilityVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent replaces the software-based security processing mechanism with hardware-based security processing units implemented in electronic circuitry on the network interface card. This substitution transitions from software execution (which is inherently slower due to interpretation and context switching) to direct hardware execution (which operates at native clock speeds). The hardware security units can process encryption, decryption, and authentication operations simultaneously with data transfer, dramatically increasing processing speed while maintaining the same security功能的 flexibility through configurable hardware logic.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8351445B1Network interface systems and methods for offloading segmentation and/or checksumming with security processing
Publication Date: 2013.01.08 GLOBALFOUNDRIES US INC
  • US8351445B1 patent drawing
  • US8351445B1 patent drawing
  • US8351445B1 patent drawing

AI summary

Network interface systems are disclosed comprising a bus interface system, a media access control system, a memory system, a security system for selectively encrypting outgoing data and decrypting incoming data, a checksum system for generating and verifying checksum values, and a segmentation system for selectively segmenting outgoing data, where the network interface system may be fabricated as a single integrated circuit chip. Methods are also provided for interfacing a host system with a network, in which checksum information is obtained from the host system, which is used to generate checksum values for outgoing data while the data is being stored in a network interface memory system.