RoCE Adapter TCP Credential Inheritance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing separate IPSec security credentials for RoCE connections consumes processing time and resources, and applying a blanket security policy that encrypts all connections may over-protect non-sensitive data streams, wasting valuable resources.

Innovation Solution

A method and system that forward IPSec Security Associations (SAs) and related keys from a host device to a RoCE adapter, enabling secure data communication over RoCE connections using the established TCP connection, allowing for customizable cryptographic protection levels based on data sensitivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate IPSec security credentials are established for RoCE connections, then security protection is improved, but processing time and system resources are consumed

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the security credential establishment process by allowing RoCE connections to inherit and reuse IPSec SAs and cryptographic keys that were already established for TCP connections. The RoCE adapter forwards these existing credentials, eliminating the need to create separate security associations for RoCE traffic, thus reducing processing time while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universality by enabling a single established IPSec SA to serve multiple connection types (both TCP and RoCE). The security infrastructure is designed so that one set of credentials can protect multiple data streams, making the security system multi-functional and reducing the overhead of establishing separate credentials for each connection type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate IPSec security credentials are established for RoCE connections, then security protection is improved, but system resources are consumed

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security credential establishment process by allowing RoCE connections to inherit and reuse IPSec SAs and cryptographic keys that were already established for TCP connections. The RoCE adapter forwards these existing credentials, eliminating the need to create separate security associations for RoCE traffic, thus reducing processing time while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies the principle of discarding and recovering by having the RoCE adapter discard the need to create new security credentials and instead recover/reuse the existing IPSec SAs and keys from the TCP connection. This recovery mechanism reduces the quantity of system resources required for security credential management.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If a blanket security policy encrypts all RoCE connections, then security coverage is improved, but valuable resources are wasted

Engineering Contradiction:
Improvesecurity coverageVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by enabling selective encryption based on the specific requirements of each data stream. Instead of a blanket policy that encrypts everything, the system allows granular control where only specific RoCE connections that require security protection will use IPSec credentials. This reduces unnecessary bandwidth consumption for encryption while maintaining security coverage where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by allowing security protection to be applied only to the extent necessary for each specific connection requirement. The system can establish IPSec credentials only when needed for particular RoCE connections rather than applying encryption universally, avoiding excessive action on data streams that do not require security protection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10567373B2Establishing security over converged Ethernet with TCP credential appropriation
Publication Date: 2020.02.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10567373B2 patent drawing
  • US10567373B2 patent drawing
  • US10567373B2 patent drawing

AI summary

A system for establishing a secure connection is described. The system includes a remote direct memory access over converged Ethernet (RoCE) adapter and host device. The host device includes a processor configured to establish a Transmission Control Protocol (TCP) connection between the host device and a client device via the host device network adapter. The host device forwards Internet Protocol Security (IPSec) Security Associations (SAs) and related keys to a host device Remote Direct Memory Access over Converged Ethernet (RoCE) adapter operatively connected with the host device for remote direct memory access. The RoCE adapter communicates protected data to and from the client device over an RoCE connection using the IPSec SAs and related keys.