SmartNIC Offloads Encryption to Reduce Host Resource Utilization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure communication systems between network nodes and devices face challenges due to disparate configurations and resource burdens, leading to increased costs and potential congestion or denial of service.
Innovation Solution
A SmartNIC-based inline secure communication service that offloads encryption, decryption, and other security tasks from host hardware to a separate SmartNIC, centralizing services and minimizing configuration disparities and resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security services (encryption, decryption) are implemented on host devices, then secure communication is achieved, but resource utilization increases and congestion may occur
Solution Approach 1:
The patent extracts security services (encryption, decryption, authentication) from host devices and relocates them to dedicated Security Gateway devices. This separation removes the resource burden from hosts while maintaining secure communication capabilities, directly resolving the contradiction between reliability and productivity.
Solution Approach 2:
The Security Gateway acts as an intermediary device between hosts and the network, handling all security-related operations. This mediator approach allows hosts to communicate securely without directly performing resource-intensive security functions, thus improving productivity while maintaining reliability.
2Reliability
If multiple vendors implement their own security configurations, then security coverage is comprehensive, but configuration disparities increase and complexity rises
Solution Approach 1:
The Security Gateway provides universal security services that can handle multiple protocols and communication types (unicast, multicast, broadcast) through a single unified configuration interface. This eliminates the need for each vendor to implement separate security configurations, reducing complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The patent merges disparate security configurations from multiple vendors into a single centralized Security Gateway that handles all security operations. By combining multiple security functions into one unified device with standardized configuration, the system reduces configuration disparities and complexity while maintaining comprehensive security.
3Reliability
If security services are distributed across multiple host devices, then security is decentralized, but service consistency decreases and management becomes difficult
Solution Approach 1:
The system segments security functions by separating them into two distinct layers: decentralized Security Gateways that provide localized security services, and a centralized configuration management system that ensures service consistency. This segmentation allows both decentralization for reliability and centralized control for consistency.
Solution Approach 2:
The Security Gateway implements feedback mechanisms where configuration changes are propagated from the centralized management system to all distributed gateways, ensuring service consistency. The feedback loop maintains uniform security policies across all decentralized nodes while preserving their autonomous operation capabilities.
Data Source
AI summary
A method, a device, and a non-transitory storage medium are described in which a SmartNIC-based inline secure communication service is provided. The service is provided by a SmartNIC. The SmartNIC-based inline secure communication service includes encryption and decryption of traffic originating from and destined to virtual devices of a device.


