Security Processor Isolates Network Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data centers, the use of local host processors for managing security and networking settings is insecure, as they can be compromised by malware, and remote management scenarios like 'bare metal provisioning' pose a security risk, allowing tenants to control network interface cards and inject packets into data networks.

Innovation Solution

A network connection device with a security processor isolates security and network configuration functions from the host processor, using a management network connectivity port inaccessible to data traffic, enabling secure remote control and monitoring, and performing encryption, decryption, and access control list management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the local host processor is used to manage security and networking settings, then the device complexity is reduced and ease of operation is improved, but the security reliability deteriorates as the processor can be compromised by malware

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the processor functions by introducing a separate security processor that handles security-related tasks independently from the host processor. This segmentation isolates security-critical operations from potential malware compromises on the host processor, thereby improving security reliability while maintaining manageable device complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security processor as an intermediary component between the host processor and security-sensitive operations. This intermediary handles authentication, encryption, and security policy enforcement, protecting the system even when the host processor is compromised, thus resolving the contradiction between security reliability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the host processor controls network interface card configuration, then the ease of operation is improved, but the security reliability deteriorates allowing packet injection attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments control authority by giving the security processor exclusive control over network interface card configuration and security settings. This segmentation prevents malware on the host processor from injecting packets or modifying network settings, improving security reliability while maintaining ease of operation through centralized security management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts security control functions from the host processor and places them in a dedicated security processor. This extraction removes the vulnerability where host processor malware could control NIC configuration, thereby improving security reliability while keeping the system easy to operate through automated security policies.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a separate security processor is introduced to isolate security functions, then the security reliability is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by creating a separate security processor for security functions. While this increases device complexity through additional hardware components, it significantly improves security reliability by isolating security-critical operations from potential compromises on the host processor, representing an acceptable trade-off for critical infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security processor is designed with multi-functionality, handling authentication, encryption, decryption, and security policy enforcement. This universality consolidates multiple security functions into a single component, improving security reliability without proportionally increasing device complexity, as one versatile processor replaces what would otherwise require multiple specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3343838B1Utilizing management network for secured configuration and platform management
Publication Date: 2020.02.12 MELLANOX TECHNOLOGIES LTD(IL)
  • EP3343838B1 patent drawingFigure 1
  • EP3343838B1 patent drawingFigure 2

AI summary

A network connection device (12) having a security processor (30) exchanges data traffic between a data network (26) and a host computer (16) via a network port (28). Security management data is exchanged exclusively between the security processor and a management network (36) via a management network connectivity port (34) that is inaccessible to the data traffic.