VPN Gateway Throughput via Multi-Core SA Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing VPN technologies are limited by the restriction of a single VPN connection being bound to a single processing core, which leads to reduced throughput due to the intensive processing work required for IKE-SA operations.
Innovation Solution
The VPN gateway is configured to create multiple outbound and/or inbound Security Associations (SAs) for a single VPN connection, distributing the encryption and decryption tasks across multiple processing cores using a Security Parameter Index (SPI) identifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single SA is bound to a single processing core to ensure correct order processing of data packets, then processing reliability is improved, but throughput is reduced due to intensive IKE-SA processing work concentrated on one core
Solution Approach 1:
The patent divides the processing workload by creating multiple SAs (first SA, second SA, third SA, fourth SA) bound to different processing cores (first processing core, second processing core, third processing core, fourth processing core). This segmentation distributes the intensive IKE-SA processing work across multiple cores, preventing any single core from becoming a bottleneck while maintaining reliable ordered processing within each core-SA pair.
2Productivity
If multiple SAs are created and distributed across multiple processing cores, then throughput is improved by parallel processing, but device complexity increases due to multiple SA-processing core mappings
Solution Approach 1:
The patent establishes a universal mapping pattern where each SA is bound to a specific processing core through a consistent rule (first SA to first core, second SA to second core, etc.). This universal binding approach simplifies the management of multiple SAs and cores by providing a predictable, systematic relationship, reducing the operational complexity despite having multiple mappings.
3Productivity
If all available processing cores are allocated to a single VPN connection for maximum throughput, then productivity is improved, but reliability decreases due to increased likelihood of processing core failure from overuse
Solution Approach 1:
The patent segments the processing workload across multiple cores (first through fourth processing cores) for a single VPN connection, distributing the intensive encryption and decryption tasks. This segmentation prevents any single core from being overused to the point of failure while maintaining high aggregate throughput through parallel processing across all allocated cores.
Data Source
AI summary
The techniques described herein increase the throughput of a single VPN connection by creating multiple outbound and/or inbound Security Associations (SAs). For instance, two or more different SAs can encrypt outbound data packets to be sent over the VPN connection to a remote device. Moreover, two or more different SAs can decrypt inbound data packets received over the VPN connection from the remote device. Each of the SAs can be bound to a different processing core via the use of a Security Parameter Index (SPI) identifier. Consequently, inbound data packets communicated over a single VPN connection from a remote device to a physical host in a VPN gateway can be distributed amongst multiple processing cores for decryption purposes. Further, outbound data packets to be communicated over the single VPN connection from the physical host to the remote device can be distributed amongst multiple processing cores for encryption purposes.


