US2003023846A1PendingUtilityA1

Classification engine in a cryptography acceleration chip

Assignee: BROADCOM CORPPriority: Jul 8, 1999Filed: Aug 12, 2002Published: Jan 30, 2003
Est. expiryJul 8, 2019(expired)· nominal 20-yr term from priority
G06F 21/72H04L 63/0428G06F 21/604G06F 2207/7219H04L 63/0485H04L 63/164G06F 9/3879
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Provided is an architecture for a cryptography accelerator chip that allows significant performance improvements over previous prior art designs. In various embodiments, the architecture enables parallel processing of packets through a plurality of cryptography engines and includes a classification engine configured to efficiently process encryption/decryption of data packets. Cryptography acceleration chips in accordance may be incorporated on network line cards or service modules and used in applications as diverse as connecting a single computer to a WAN, to large corporate networks, to networks servicing wide geographic areas (e.g., cities). The present invention provides improved performance over the prior art designs, with much reduced local memory requirements, in some cases requiring no additional external memory. In some embodiments, the present invention enables sustained full duplex Gigabit rate security processing of IPSec protocol data packets.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A cryptography accelerator, comprising: 
 a plurality of cryptography processing engines;    classification circuitry configured to receive header information associated with a packet and determine state and security association information associated with the packet, the state and security association information comprising a key, a sequence number, and a byte count, wherein the state and security association information is determined by identifying a flow to which the packet belongs; and    packet distribution circuitry coupled to the plurality of cryptography processing engines and the classification circuitry, the packet distribution circuitry configured to receive data, state, and security association information associated with the packet and forward the data associated with the packet to one of the plurality of cryptography processing engines for cryptographic processing of the data.    
     
     
         2 . The cryptography accelerator of  claim 1 , wherein the classification circuitry is further configured to determine whether the packet should be dropped.  
     
     
         3 . The cryptography accelerator of  claim 1 , wherein the classification circuitry is further configured to determine whether the packet should be processed.  
     
     
         4 . The cryptography accelerator of  claim 1 , wherein the byte count is used to determine how much more data associated with the flow can be processed using the state and security association information.  
     
     
         5 . The cryptography accelerator of  claim 1 , wherein header information comprises source and destination identifiers.  
     
     
         6 . The cryptography accelerator of  claim 5 , wherein header information further comprises source and destination port numbers.  
     
     
         7 . The cryptography accelerator of  claim 1 , wherein the data associated with the packet forwarded to one of the plurality of cryptography processing engines is the payload of the packet.  
     
     
         8 . The cryptography accelerator of  claim 1 , wherein the data associated with the packet forwarded to one of the plurality of cryptography processing engines is a portion of the packet.  
     
     
         9 . A network device comprising the cryptography accelerator of  claim 1 .  
     
     
         10 . A method for performing cryptography processing, comprising: 
 receiving header information associated with a packet at a classification engine in a cryptography accelerator; and    determining state and security association information at the classification engine, the state and security association information comprising a key, a sequence number, and a byte count, wherein the state and security association information is determined by identifying a flow to which the packet belongs.    
     
     
         11 . The method of  claim 10 , further comprising: 
 forwarding the state and security association information along with the data associated with the packet to a packet distribution unit.    
     
     
         12 . The method of  claim 11 , wherein the packet distribution unit is coupled to a plurality of cryptography processing engines.  
     
     
         13 . The method of  claim 12 , wherein the data associated with the packet is distributed to one of the plurality of cryptography processing engines.  
     
     
         14 . The method of  claim 10 , wherein the classification engine determines whether the packet should be dropped.  
     
     
         15 . The method of  claim 10 , wherein the classification engine determines whether the packet should be processed.  
     
     
         16 . The method of  claim 10 , wherein the byte count is used to determine how much more data associated with the flow can be processed using the state and security association information.  
     
     
         17 . The method of  claim 10 , wherein header information comprises source and destination identifiers.  
     
     
         18 . The method of  claim 17 , wherein header information further comprises source and destination port numbers.  
     
     
         19 . A cryptography accelerator, comprising: 
 means for receiving header information associated with a packet at a classification engine in a cryptography accelerator; and    means for determining state and security association information at the classification engine, the state and security association information comprising a key, a sequence number, and a byte count, wherein the state and security association information is determined by identifying a flow to which the packet belongs.    
     
     
         20 . The cryptography accelerator of  claim 19 , further comprising: 
 means for forwarding the state and security association information along with the data associated with the packet to a packet distribution unit.    
     
     
         21 . A computer readable medium comprising microcode for configuring an integrated circuit, the computer readable medium comprising: 
 microcode for receiving header information associated with a packet at a classification engine in a cryptography accelerator; and    microcode for determining state and security association information at the classification engine, the state and security association information comprising a key, a sequence number, and a byte count, wherein the state and security association information is determined by identifying a flow to which the packet belongs.    
     
     
         22 . The computer readable medium of  claim 21 , further comprising: 
 microcode for forwarding the state and security association information along with the data associated with the packet to a packet distribution unit.

Join the waitlist — get patent alerts

Track US2003023846A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.