Shared Security Engine Packet Routing for Latency Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking systems face increased costs, complexity, and time latency due to the use of dedicated security engines per communication channel, which is burdensome and inefficient for maintaining data confidentiality and integrity.

Innovation Solution

Implementing a shared security engine across multiple communication channels or links, which selectively processes data packets for encryption and decryption, reducing the number of security components and preventing time latency by routing packets to the shared engine based on sensitivity and available secure associations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated security engine is used per communication channel, then data confidentiality and integrity are maintained, but system costs and complexity increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple dedicated security engines into a single shared security engine that serves multiple communication channels. The shared security engine includes a receive interface coupled to a receive link, a transmit interface coupled to a transmit link, and a shared buffer memory that is shared between the receive and transmit interfaces, thereby reducing system complexity while maintaining security functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared security engine is designed to perform multiple functions: it can receive encrypted data packets from multiple receive links, decrypt them using shared buffer memory, route decrypted packets to transmit links, and encrypt outbound packets. This multi-functional design eliminates the need for separate dedicated engines for each channel.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a dedicated security engine is used per communication channel, then security processing is available, but hardware costs increase

Engineering Contradiction:
Improvedata integrityVSAvoidhardware components
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple dedicated security engines into one shared security engine that handles security processing for multiple communication channels. This consolidation reduces the total quantity of hardware components while maintaining the same security processing capability through shared resources including the security engine itself, buffer memory, and routing logic.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If data packets are processed serially in a queue, then security processing is maintained, but time latency increases

Engineering Contradiction:
Improvesecurity processingVSAvoidtime latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic packet routing where the shared security engine can selectively route encrypted data packets from multiple receive links to transmit links based on available buffer space and processing capacity. This dynamic approach allows parallel processing of packets from different channels rather than serial queueing, reducing time latency while maintaining security processing.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The shared buffer memory is designed to maintain continuous security processing by pre-allocating buffer spaces for multiple channels and enabling the security engine to switch between processing packets from different receive links without idle wait time. This continuity eliminates the stop-start nature of serial queueing and reduces overall processing latency.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10230698B2Routing a data packet to a shared security engine
Publication Date: 2019.03.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10230698B2 patent drawing
  • US10230698B2 patent drawing
  • US10230698B2 patent drawing

AI summary

Examples disclose a system comprising an integrated circuit to determine whether a data packet should be processed by a shared security engine associated with a secure link. Additionally, the examples disclose a first media access control (MAC), associated with the shared security engine, to receive the data packet for transmission on the secure link based on the determination the data packet should be processed by the shared security engine.