VPN Encryption Switch for Server CPU Offload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of a central processing unit (CPU) in a server for encryption and decryption in a virtual private network (VPN) can affect the execution of other applications.

Innovation Solution

A switch configured to relay data between VPN peers, utilizing an application-specific integrated circuit (ASIC) or field-programmable gate array (FPGA) to perform encryption and decryption, thereby offloading these tasks from the CPU.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CPU of server is used for encryption and decryption in VPN, then VPN security is ensured, but execution of other applications is affected

Engineering Contradiction:
ImproveVPN encryption securityVSAvoidapplication execution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the encryption and decryption functions from the server CPU and relocates them to dedicated hardware encryption devices at the network edge (customer premises equipment). This separation allows the server CPU to focus on application execution while VPN encryption/decryption is handled independently by specialized hardware, thus resolving the conflict between security and productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces network switches as intermediary devices that relay encrypted data between VPN peers without requiring the server CPU to perform encryption/decryption operations. The switches forward traffic while the actual cryptographic operations are performed by hardware encryption devices at the customer premises, acting as mediators between the server and end devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If CPU resources are allocated for VPN encryption, then encryption functionality is provided, but server processing capacity for other tasks is reduced

Engineering Contradiction:
Improveencryption capabilityVSAvoidserver processing capacity
Core Design Contradiction:
Adaptability or versatilityVSPower

Solution Approach 1:

The patent implements self-service encryption where customer premises equipment performs its own encryption and decryption operations locally, without requiring server CPU resources. Each VPN peer encrypts data before transmission and decrypts received data independently, making the encryption capability self-sufficient and eliminating the need to consume server processing capacity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the software-based encryption mechanism (requiring CPU computational power) with hardware-based encryption devices that perform cryptographic operations in dedicated encryption circuits. This substitution of mechanical/hardware systems for software processing eliminates the trade-off between encryption capability and server processing capacity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250286862A1switch
Publication Date: 2025.09.11 NIPPON TELEGRAPH & TELEPHONE CORP
  • US20250286862A1 patent drawing
  • US20250286862A1 patent drawing
  • US20250286862A1 patent drawing

AI summary

A switch is a switch configured to relay data transmitted and received between virtual private network (VPN) peers. The switch includes a first circuit that encrypts a packet from any one of computers as one of the VPN peers and transmits the packet after the encryption to any one of computers as the other of the VPN peers via a network to transmit the packet by a VPN. With such a configuration, encryption in a VPN is implemented without use of CPU resources of a server.