Security Chip and CPU Traffic Routing for DDoS Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing protection devices, such as firewalls, rely on dedicated security chips with fixed logic, which limits their effectiveness and integrity in defending against network attacks, particularly in scenarios involving complex or high-traffic attacks like DDoS.

Innovation Solution

A method combining a central processing unit (CPU) with a dedicated security chip to collaboratively defend against attacks, where the chip handles traffic related to low-risk IP addresses and forwards high-risk traffic to the CPU for further defense, while sampling and updating IP address lists to enhance detection and defense capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a dedicated security chip with fixed logic is used, then device complexity is reduced and forwarding speed is improved, but defense effectiveness and integrity deteriorate due to limited capability

Engineering Contradiction:
Improvetraffic forwarding speedVSAvoiddefense effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the traffic processing function into two parts: the dedicated security chip handles high-speed forwarding of normal traffic, while the CPU handles complex attack detection and high-risk traffic processing. This segmentation allows each component to operate at its optimal performance level, resolving the contradiction between forwarding speed and defense effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the dedicated security chip forwards high-risk traffic to the CPU for further processing. This intermediary approach enables the system to leverage both the speed of the security chip and the intelligence of the CPU, achieving both fast forwarding and effective defense.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If only a dedicated security chip is used for attack defense, then device complexity is reduced, but comprehensive attack detection capability deteriorates

Engineering Contradiction:
Improvesystem structureVSAvoidattack detection capability
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges the dedicated security chip with the CPU to form a collaborative defense system. The security chip maintains simple traffic forwarding functionality while the CPU provides comprehensive attack detection. This merging combines the advantages of both components, achieving both reduced complexity and enhanced detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the CPU serve multiple functions: it handles complex attack detection, processes high-risk traffic, and updates the destination IP table. This multi-functionality allows the system to maintain comprehensive attack detection while avoiding the need for additional dedicated hardware, thus managing device complexity effectively.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the CPU processes all traffic, then comprehensive attack detection is achieved, but CPU load increases and forwarding performance deteriorates

Engineering Contradiction:
Improveattack detection completenessVSAvoidforwarding performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts normal traffic processing from the CPU and assigns it to the dedicated security chip. By taking out the routine forwarding function from the CPU, the system reduces CPU load while maintaining comprehensive attack detection capability for high-risk traffic that requires CPU processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by having the CPU process only the necessary high-risk traffic rather than all traffic. This selective approach maintains adequate attack detection completeness for critical threats while significantly improving overall forwarding performance by avoiding unnecessary CPU processing of normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12488102B2Method for processing traffic in protection device, and protection device
Publication Date: 2025.12.02 HUAWEI TECH CO LTD
  • US12488102B2 patent drawing
  • US12488102B2 patent drawing
  • US12488102B2 patent drawing

AI summary

In accordance with an embodiment, a method includes: receiving, by a dedicated security chip, first traffic from a first network interface of the protection device, where the first network interface is configured to receive traffic sent by a first network device, and a destination internet protocol (IP) address of the first traffic comprises a first IP address; determining, by the dedicated security chip, whether the first IP address exists in a first destination IP table stored on the dedicated security chip, wherein the first destination IP table comprises at least one IP address having a risk of being attacked; and in response to a determination that the first IP address exists in the first destination IP table, sending, by the dedicated security chip, the first traffic to the CPU.