Security Association Table Lookup Architecture for Network Interface Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which can lead to reduced resources available for other applications.
Innovation Solution
A network interface device that offloads security processing by storing a portion of the security association database and obtaining security associations to perform encryption and decryption on incoming and outgoing frames, reducing the need for host system intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security processing is performed on the host system processor, then security processing can be completed, but the processing load on the host system increases and resources for other applications are reduced
Solution Approach 1:
The patent extracts security processing functionality from the host system processor and relocates it to a network interface card (NIC). The NIC includes dedicated security processing circuits and a local security association table (SAT) cache, allowing security operations to be performed independently of the host processor, thereby maintaining security capabilities while preserving host system resources for other applications.
Solution Approach 2:
The patent introduces an intermediary SAT cache structure located in the NIC that mediates between the host system's security requirements and the network processing needs. This intermediate cache stores frequently accessed security association data, allowing the NIC to perform security processing locally without continuously querying the host system, thus reducing host processor involvement while maintaining security processing reliability.
2Speed
If the entire security association database is stored in the network interface device, then security processing speed increases, but the device complexity and memory requirements increase
Solution Approach 1:
The patent segments the security association database into two parts: a complete database stored in the host system and a cached portion (SAT cache) stored in the network interface card. This segmentation allows the NIC to access frequently used security data locally for fast processing while the host system maintains the complete database, thereby achieving high processing speed without excessive device complexity.
Solution Approach 2:
The patent applies local quality by providing the NIC with a localized cache of security association data specifically tailored for rapid access during network processing. This local SAT cache contains only the portion of security data needed for immediate processing, optimizing the NIC's local resources while maintaining connection to the complete database in the host system when needed.
3Loss of time
If security association data is cached in the network interface component, then access speed improves, but the component's memory usage increases
Solution Approach 1:
The patent implements partial action by caching only a portion of the security association database in the network interface card's SAT cache, rather than the entire database. This selective caching of frequently accessed security data reduces the memory burden on the NIC while still achieving significant improvements in access speed for the most critical security operations.
Data Source
AI summary
A security association architecture system of the present invention facilitates network data transfer by providing an internal portion of a security association database that can be quickly accessed to obtain security associations as well as an external component that stores the complete security association database. As a result, at least some security associations for incoming received frames and outgoing transmitted frames can be obtained from the internal portion located on a network interface device without accessing system memory, a host computer, and the like in order to obtain the security associations to perform security processing.


