XIMMs Offload Packet Decryption from x86 Processors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

x86 architecture processors are inefficient in handling high-volume packet handling and security applications due to high power consumption, limited parallelism, and security implications, making them unsuitable for enterprise or cloud data security systems.

Innovation Solution

The use of Xocket In-line Memory Modules (XIMMs) with 'wimpy' cores connected to a memory bus for offloading lightweight packet handling tasks, enabling high parallelism, low power consumption, and efficient context switching, thereby handling high network bandwidth traffic with low latency and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If x86 processors are used for packet handling and security applications, then processing capability is provided, but power consumption is high and parallelism is limited

Engineering Contradiction:
Improvepower consumptionVSAvoidprocessing capability
Core Design Contradiction:
PowerVSProductivity

Solution Approach 1:

The system segments processing tasks by separating packet handling and security operations from main x86 processors to dedicated network processors (NPs) inserted into memory slots. This segmentation allows x86 processors to focus on high-level applications while NPs handle network-specific tasks, reducing overall power consumption while maintaining processing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network processors act as intermediary components between network interfaces and x86 processors. These NPs handle packet processing, encryption/decryption, and security operations, serving as a mediator that reduces the computational burden on power-hungry x86 processors while enabling parallel processing through multiple NP instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If x86 processors handle high-volume packet processing, then processing power is available, but context switching overhead and security implications increase

Engineering Contradiction:
ImprovesecurityVSAvoidcontext switching overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security-critical operations from general-purpose x86 processors by dedicating specific network processors to handling encrypted traffic, VPN operations, and intrusion detection. This segmentation isolates security functions, reducing context switching overhead and potential security implications while improving reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network processors are designed to autonomously handle packet processing, decryption, and security operations without requiring frequent context switches to x86 processors. Each NP maintains its own execution context and can independently process security operations, reducing overall system complexity and improving reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11080209B2Server systems and methods for decrypting data packets with computation modules insertable into servers that operate independent of server processors
Publication Date: 2021.08.03 XOCKETS INC
  • US11080209B2 patent drawing
  • US11080209B2 patent drawing
  • US11080209B2 patent drawing

AI summary

A server system can include a plurality of servers interconnected by a network. Each server can include a server processor, a socket configured to receive a module, and at least one removable computation module configured for insertion into the socket. Each computation module can include first processing circuits mounted on the computation module and configured to at least decrypt data packets received by the server independent of the server processor and second processing circuits mounted on the computation module and configured to form a virtual switch for switching the data packets.