Runtime Adaptable Protocol Processor for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current TCP/IP protocol stacks in software form consume significant host processor cycles, leading to performance bottlenecks in high-speed networks, especially at line rates above 1 Gbps, and lack efficient security processing capabilities, making them inadequate for modern network security demands.
Innovation Solution
A high-performance, run-time adaptable hardware processor architecture that reduces TCP/IP protocol stack overhead and integrates advanced security features, enabling acceleration of network data processing, security operations, and application-layer services without the need for dedicated accelerators, by dynamically reconfiguring computational elements and interconnections to handle various network protocols and security tasks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If TCP/IP protocol stack is implemented in software on host processor, then protocol processing functionality is achieved, but processor cycle consumption increases significantly
Solution Approach 1:
The patent replaces the software-based TCP/IP protocol stack (mechanical system in terms of execution overhead) with a hardware-based protocol processor that implements protocol processing functions in dedicated circuitry. This substitution eliminates the need for host processor to execute protocol processing instructions, thereby freeing processor cycles for application workloads while maintaining full protocol processing capability.
2Reliability
If dedicated security accelerators are added to enhance security processing, then security capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent merges security processing functions (encryption, decryption, authentication) directly into the protocol processor fabric. Instead of adding separate dedicated security accelerator cards or modules, the security functions are integrated as programmable logic within the same hardware platform that handles protocol processing, thereby enhancing security capability without proportionally increasing system complexity.
Solution Approach 2:
The protocol processor is designed with programmable logic that can perform multiple functions including both protocol processing and security operations. This multi-functionality allows a single hardware platform to replace what would traditionally require separate dedicated accelerators, reducing overall system complexity while providing comprehensive security capabilities.
3Productivity
If hardware protocol processor is implemented to reduce processor overhead, then processing speed is improved, but adaptability to different protocols decreases
Solution Approach 1:
The patent implements a dynamically reconfigurable protocol processor where the logic fabric can be programmatically configured to handle different protocol requirements. This dynamic adaptability allows the same hardware platform to be reconfigured for various protocols (TCP, UDP, SCTP, application-layer protocols) while maintaining high-speed hardware processing, thus resolving the contradiction between processing speed and protocol flexibility.
Solution Approach 2:
The protocol processor utilizes programmable logic that can change its operational parameters and behavior based on the required protocol. By modifying the configuration of the hardware logic rather than the physical structure, the system achieves high-speed processing for any supported protocol, effectively decoupling throughput performance from protocol-specific design constraints.
4Adaptability or versatility
If multiple dedicated accelerators are deployed for different network services, then service capability is improved, but loss of substance (hardware resources) increases
Solution Approach 1:
The patent creates a universal hardware platform where a single protocol processor can perform multiple network services including protocol processing, security functions, and application-layer processing. This consolidation means that instead of deploying separate physical accelerators for each service, one reconfigurable processor handles all services sequentially or concurrently through logical configuration, thereby reducing overall hardware resource consumption.
Solution Approach 2:
The reconfigurable nature of the protocol processor allows it to dynamically adapt its logic fabric to provide different network services as needed. This dynamic service provisioning capability enables the system to deliver multiple specialized functions using a single shared hardware resource pool, effectively reducing the total quantity of hardware substances required compared to having dedicated accelerators for each service.
Data Source
AI summary
A runtime adaptable protocol processor is disclosed. The processor architecture provides capabilities to transport and process Internet Protocol (IP) packets from Layer 2 through transport protocol layer and may also provide packet inspection through Layer 7. Further, a runtime adaptable processor is coupled to the protocol processing hardware and may be dynamically adapted to perform hardware tasks as per the needs of the network traffic being sent or received and/or the policies programmed or services or applications being supported. A set of engines may perform pass-through packet classification, policy processing and/or security processing enabling packet streaming through the architecture at nearly the full line rate. A scheduler schedules packets to packet processors for processing. An internal memory or local session database cache stores a session information database for a certain number of active sessions. The session information that is not in the internal memory is stored and retrieved to/from an additional memory. An application running on an initiator or target can in certain instantiations register a region of memory, which is made available to its peer(s) for access directly without substantial host intervention through RDMA data transfer. A security system is also disclosed that enables a new way of implementing security capabilities inside enterprise networks in a distributed manner using a protocol processing hardware with appropriate security features.


