RoCE Adapter TCP Credential Inheritance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing separate IPSec security credentials for RoCE connections consumes processing time and resources, and applying a blanket security policy that encrypts all connections may over-protect non-sensitive data streams, wasting valuable resources.
Innovation Solution
A method and system that forward IPSec Security Associations (SAs) and related keys from a host device to a RoCE adapter, enabling secure data communication over RoCE connections using the established TCP connection, allowing for customizable cryptographic protection levels based on data sensitivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate IPSec security credentials are established for RoCE connections, then security protection is improved, but processing time and system resources are consumed
Solution Approach 1:
The patent merges the security credential establishment process by allowing RoCE connections to inherit and reuse IPSec SAs and cryptographic keys that were already established for TCP connections. The RoCE adapter forwards these existing credentials, eliminating the need to create separate security associations for RoCE traffic, thus reducing processing time while maintaining security protection.
Solution Approach 2:
The patent implements universality by enabling a single established IPSec SA to serve multiple connection types (both TCP and RoCE). The security infrastructure is designed so that one set of credentials can protect multiple data streams, making the security system multi-functional and reducing the overhead of establishing separate credentials for each connection type.
2Reliability
If separate IPSec security credentials are established for RoCE connections, then security protection is improved, but system resources are consumed
Solution Approach 1:
The patent merges the security credential establishment process by allowing RoCE connections to inherit and reuse IPSec SAs and cryptographic keys that were already established for TCP connections. The RoCE adapter forwards these existing credentials, eliminating the need to create separate security associations for RoCE traffic, thus reducing processing time while maintaining security protection.
Solution Approach 2:
The patent applies the principle of discarding and recovering by having the RoCE adapter discard the need to create new security credentials and instead recover/reuse the existing IPSec SAs and keys from the TCP connection. This recovery mechanism reduces the quantity of system resources required for security credential management.
3Reliability
If a blanket security policy encrypts all RoCE connections, then security coverage is improved, but valuable resources are wasted
Solution Approach 1:
The patent applies local quality by enabling selective encryption based on the specific requirements of each data stream. Instead of a blanket policy that encrypts everything, the system allows granular control where only specific RoCE connections that require security protection will use IPSec credentials. This reduces unnecessary bandwidth consumption for encryption while maintaining security coverage where needed.
Solution Approach 2:
The patent implements partial action by allowing security protection to be applied only to the extent necessary for each specific connection requirement. The system can establish IPSec credentials only when needed for particular RoCE connections rather than applying encryption universally, avoiding excessive action on data streams that do not require security protection.
Data Source
AI summary
A system for establishing a secure connection is described. The system includes a remote direct memory access over converged Ethernet (RoCE) adapter and host device. The host device includes a processor configured to establish a Transmission Control Protocol (TCP) connection between the host device and a client device via the host device network adapter. The host device forwards Internet Protocol Security (IPSec) Security Associations (SAs) and related keys to a host device Remote Direct Memory Access over Converged Ethernet (RoCE) adapter operatively connected with the host device for remote direct memory access. The RoCE adapter communicates protected data to and from the client device over an RoCE connection using the IPSec SAs and related keys.


