Security Association Table Lookup Architecture for Network Interface Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems require significant host processing overhead for tasks like segmentation, checksumming, and security processing, which can lead to reduced resources available for other applications.

Innovation Solution

A network interface device that offloads security processing by storing a portion of the security association database and obtaining security associations to perform encryption and decryption on incoming and outgoing frames, reducing the need for host system intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processing is performed on the host system processor, then security processing can be completed, but the processing load on the host system increases and resources for other applications are reduced

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidhost system resource availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security processing functionality from the host system processor and relocates it to a network interface card (NIC). The NIC includes dedicated security processing circuits and a local security association table (SAT) cache, allowing security operations to be performed independently of the host processor, thereby maintaining security capabilities while preserving host system resources for other applications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary SAT cache structure located in the NIC that mediates between the host system's security requirements and the network processing needs. This intermediate cache stores frequently accessed security association data, allowing the NIC to perform security processing locally without continuously querying the host system, thus reducing host processor involvement while maintaining security processing reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If the entire security association database is stored in the network interface device, then security processing speed increases, but the device complexity and memory requirements increase

Engineering Contradiction:
Improvesecurity processing speedVSAvoidnetwork interface device structure
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the security association database into two parts: a complete database stored in the host system and a cached portion (SAT cache) stored in the network interface card. This segmentation allows the NIC to access frequently used security data locally for fast processing while the host system maintains the complete database, thereby achieving high processing speed without excessive device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing the NIC with a localized cache of security association data specifically tailored for rapid access during network processing. This local SAT cache contains only the portion of security data needed for immediate processing, optimizing the NIC's local resources while maintaining connection to the complete database in the host system when needed.

Inventive Principle:
Principle #3Local quality

3Loss of time

If security association data is cached in the network interface component, then access speed improves, but the component's memory usage increases

Engineering Contradiction:
Improvesecurity association access timeVSAvoidmemory resources in network interface
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

The patent implements partial action by caching only a portion of the security association database in the network interface card's SAT cache, rather than the entire database. This selective caching of frequently accessed security data reduces the memory burden on the NIC while still achieving significant improvements in access speed for the most critical security operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7624263B1Security association table lookup architecture and method of operation
Publication Date: 2009.11.24 ADVANCED MICRO DEVICES INC
  • US7624263B1 patent drawing
  • US7624263B1 patent drawing
  • US7624263B1 patent drawing

AI summary

A security association architecture system of the present invention facilitates network data transfer by providing an internal portion of a security association database that can be quickly accessed to obtain security associations as well as an external component that stores the complete security association database. As a result, at least some security associations for incoming received frames and outgoing transmitted frames can be obtained from the internal portion located on a network interface device without accessing system memory, a host computer, and the like in order to obtain the security associations to perform security processing.