Secure I/O Interface System for Network Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication systems face bottlenecks in processing speed and security due to the use of multiple systems for network and security processing, which increases the risk of unauthorized access and requires larger chip and system sizes, especially in broadband networks and portable devices.

Innovation Solution

A secure I/O interface system that consolidates all or most network and security processing functions onto a single NIC, performing tasks like encryption, decryption, and VPN processing at high speeds, reducing the need for multiple systems and minimizing backplane bus bottlenecks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple systems are used for network and security processing, then security functionality is enhanced, but processing speed is reduced and system complexity increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines network processing functions and security processing functions into a single integrated network processor. This consolidation eliminates the need for separate systems, reduces the number of interfaces and coordination requirements, and minimizes data transfer bottlenecks while maintaining comprehensive security functionality including firewall, VPN, and intrusion detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network processor is designed as a universal device that performs multiple functions simultaneously - network packet processing, security processing, and data transfer. This multi-functional approach allows the single system to handle diverse operations that previously required separate dedicated systems, thereby improving processing speed without compromising security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple systems are used for network and security processing, then security functionality is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges previously separate network processing systems and security processing systems into a single integrated network processor. This consolidation reduces the number of system components, eliminates multiple interfaces between different systems, and simplifies coordination requirements while maintaining all necessary security functions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts and consolidates security processing capabilities directly into the network processor, removing the need for separate security systems. This extraction of security functions from independent systems and integration into the network processing path reduces overall system complexity while preserving security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If security processing is handled by host processor, then flexibility is improved, but security against snooping is reduced

Engineering Contradiction:
ImproveflexibilityVSAvoidsnooping risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments processing functions by implementing a dedicated network processor that is physically separated from the host processor. This segmentation isolates security-critical operations from the host system, preventing snooping while maintaining flexibility through programmable security processing capabilities in the dedicated processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dedicated network processor acts as an intermediary between the host processor and the network interface. It mediates all network traffic and security processing operations, providing a secure boundary that prevents unauthorized access to host processor memory and data while still allowing flexible configuration through software programming of the network processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple systems are used for secure processing, then security coverage is improved, but communication speed is limited

Engineering Contradiction:
Improvesecurity coverageVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent combines network processing and security processing into a single integrated processor that handles both functions simultaneously in one data path. This eliminates the sequential processing and multiple data transfers required when separate systems are used, thereby improving communication speed while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated network processor enables continuous processing of network packets through security functions without interruption or transfer delays. The single-system architecture allows uninterrupted data flow from network interface through processing functions to host, maintaining high communication speeds while providing complete security coverage.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7685436B2System and method for a secure I/O interface
Publication Date: 2010.03.23 LIONRA TECH LTD
  • US7685436B2 patent drawing
  • US7685436B2 patent drawing
  • US7685436B2 patent drawing

AI summary

A security processor performs all or substantially all security and network processing to provide a secure I/O interface system to protect computing hardware from unauthorized access or attack. The security processor sends and receives all incoming and outgoing data packets for a host device and includes a packet engine, coupled to a local data bus, to process the incoming and outgoing packets. The processor further comprises a cryptographic core coupled to the packet engine to provide encryption and decryption processing for packets processed by the packet engine. The packet engine also handles classification processing for the incoming and outgoing packets. A modulo engine may be coupled to the local data bus.