Parallel IPsec Processors for Network Interface Offload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which leads to a bottleneck and increased processing time, especially for small data packets.

Innovation Solution

A network interface system with two transmit IPsec processors operating in parallel to perform encryption and authentication simultaneously, offloading security processing from the host processor and reducing the processing load by accelerating IPsec processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processing is performed on the host processor, then security functions can be implemented, but processing time increases and host processor load increases

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts security processing functions from the host processor and implements them in dedicated hardware (network interface card). This separates the security processing workload from the host processor, allowing simultaneous execution of security operations and host computations, thereby reducing processing time and host processor load while maintaining security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a dedicated network interface card as an intermediary device between the host processor and the network. This intermediary contains specialized security processing units that handle encryption and authentication operations, acting as a mediator that offloads these time-consuming tasks from the host processor while ensuring secure data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If single processor is used for IPsec processing, then device complexity is low, but processing speed is insufficient for high throughput

Engineering Contradiction:
Improveprocessing speedVSAvoidprocessor configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the IPsec processing workload by implementing separate encryption and authentication processing units within the network interface card. This segmentation allows parallel processing of different security operations, increasing overall processing speed while keeping each individual processing unit relatively simple and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple security processing functions (encryption, authentication, packet handling) into a single integrated network interface card. This consolidation provides high processing speed through dedicated hardware while managing complexity by integrating all functions into one device rather than requiring multiple separate processors.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If security processing is performed sequentially, then processing is simpler to implement, but bottleneck occurs and throughput decreases

Engineering Contradiction:
ImprovethroughputVSAvoidprocessing architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments security processing into distinct parallel operations by implementing separate encryption and authentication processing units. This allows different packets to undergo encryption and authentication simultaneously in different processing units, eliminating sequential bottlenecks and increasing throughput while maintaining relatively simple individual processing paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables continuous security processing by implementing parallel processing units that can operate simultaneously without waiting for sequential completion. Multiple packets can be encrypted and authenticated in overlapping time periods, maintaining continuous useful action and maximizing throughput without requiring complex coordination between processing stages.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9106625B2Two parallel engines for high speed transmit IPSEC processing
Publication Date: 2015.08.11 ADVANCED MICRO DEVICES INC
  • US9106625B2 patent drawing
  • US9106625B2 patent drawing
  • US9106625B2 patent drawing

AI summary

The invention relates to a network interface system for interfacing a host system with a network. The network interface system includes a bus interface system, a media access control system, and a security system. The network interface offloads IPsec processing from the host processor. According to the invention, the security system includes two processors for encrypting and authenticating the outgoing data. Outgoing data packets are sent alternately to one or the other processor, whereby transmission processing can be accelerated relative to receive processing.