IP Library Granted Patent US 8,191,134
Granted Patent B1
US 8,191,134 · App. 12/240,784 · Granted May 29, 2012

Lockless distributed IPsec processing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,191,134
App. No.
12/240,784
Granted
May 29, 2012
Kind
B1
Abstract

According to one embodiment of the invention, a plurality of IPsec packets belonging to a single IPsec tunnel are received. Different ones of the plurality of IPseck packets are distributed to different ones of a plurality of processing cores of a network element. At least some of those IPsec packets are processed in parallel and without taking a lock on a Security Association (SA) data structure storing a SA associated with the plurality of IPsec packets. The SA is atomically accessed and atomically updated.

Claims (43)

1. A method for lockless Internet Protocol Security (IPsec) processing performed on a network element, comprising:

receiving a plurality of IPsec packets each belonging to a single IPsec tunnel;

distributing different ones of the plurality of IPsec packets to different ones of a plurality of processing cores of the network element for processing; and

processing at least some of those IPsec packets in parallel and without taking a lock on a Security Association (SA) data structure storing a SA associated with each of the plurality of IPsec packets, wherein the processing includes:

for each processing core that is processing one of the plurality of IPsec packets,

atomically accessing the SA associated with that IPsec packet, wherein the atomically accessing the SA includes accessing a SA pointer structure, which stores a pointer to the SA, with an atomic read operation,

atomically read a sequence map and a last sequence number for that IPsec packet, wherein if the sequence number of that IPSec packet is not within the range of the sequence map, the processing core to drop that IPSec packet,

using values of the SA during processing of that IPsec packet, and

atomically updating at least certain values of that SA.

2. The method of claim 1 , further comprising for each of the plurality of IPsec packets received, if the sequence number of the packet is not within the range of the sequence map, issuing an exception.

3. The method of claim 2 , further comprising updating the sequence map and the last sequence number based on values derived from processing that IPsec packet.

4. The method of claim 1 , further comprising upon the SA expiring, nullifying the pointer to the SA and delaying removal of the SA until each processing core has finished accessing the SA.

5. The method of claim 1 , further comprising creating a SA for the plurality of IPsec packets upon determining that a SA is not associated with those IPsec packets.

6. The method of claim 5 , wherein the creating the SA further includes atomically adding a pointer to the created SA in the SA pointer structure with an atomic write operation.

7. A network element to process Internet Protocol Security (IPsec) packets in a distributed processing environment, comprising:

one or more interfaces to receive a plurality of IPsec packets belonging to a single IPsec tunnel;

a packet work distribution unit to distribute the plurality of IPsec packets to different ones of a plurality of processing cores;

a Security Association (SA) data structure to store one or more SAs, wherein each of the plurality of IPsec packets is associated with the same SA;

a SA pointer structure which includes one or more pointers referencing the SA data structure, wherein each of the processing core is to access the SA pointer structure with an atomic read operation to determine the location of the SA associated with the IPSec tunnel;

the plurality of processing cores to process the IPsec packets in parallel and without taking a lock on the SA data structure, wherein each processing core that receives one of the IPsec packets to process is to:

atomically access a SA associated with that IPsec packet, wherein each of the processing core is to access the SA pointer structure with an atomic read operation to determine the location of the SA associated with the IPSec tunnel,

atomically read a sequence map and a last sequence number for that IPsec packet, wherein if the sequence number of that IPSec packet is not within the range of the sequence map, the processing core to drop that IPSec packet,

use values of that SA during the processing, and

atomically update a sequence number of that SA.

8. The network element of claim 7 , further comprising an ingress queue to store the plurality of IPsec packets according to arrival order, wherein the packet work distribution unit is to distribute the IPsec packets based on the arrival order of those IPsec packets.

9. The network element of claim 7 , further comprising each of the processing cores to update the sequence map and the last sequence number based on values derived from processing an IPsec packet.

10. The network element of claim 7 , further comprising the processing cores to nullify the pointer to the SA associated with the IPsec tunnel upon the SA expiring and to delay removal of the SA until each processing core has finished using that SA.

11. The network element of claim 10 , wherein each of the processing cores is further to create a SA for the plurality of IPsec packets upon determining that a SA is not associated with the plurality of IPsec packets.

12. The network element of claim 11 , wherein the create the SA includes the processing core to atomically add a pointer to the created SA in the SA pointer structure with an atomic write operation.

13. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations for lockless Internet Protocol Security (IPsec) processing, the operations comprising:

receiving a plurality of IPsec packets each belonging to a single IPsec tunnel;

distributing different ones of the plurality of IPsec packets to different ones of a plurality of processing cores of the network element for processing; and

processing at least some of those IPsec packets in parallel and without taking a lock on a Security Association (SA) data structure storing a SA associated with each of the plurality of IPsec packets, wherein the processing includes:

for each processing core that is processing one of the plurality of IPsec packets,

atomically accessing the SA associated with that IPsec packet, wherein atomically accessing the SA includes accessing a SA pointer structure, which stores a pointer to the SA, with an atomic read operation,

atomically read a sequence map and a last sequence number for that IPsec packet, wherein if the sequence number of that IPSec packet is not within the range of the sequence map, the processing core to drop that IPSec packet,

using values of the SA during processing of that IPsec packet, and

atomically updating at least certain values of the SA.

14. The non-transitory machine-readable storage medium of claim 13 , further comprising for each of the plurality of IPsec packets received, if the sequence number of the packet is not within the range of the sequence map, issuing an exception.

15. The non-transitory machine-readable storage medium of claim 14 , further comprising updating the sequence map and the last sequence number based on values derived from processing that IPsec packet.

16. The non-transitory machine-readable storage medium of claim 13 , further comprising upon the SA expiring, nullifying the pointer to the SA and delaying removal of the SA until each processing core has finished accessing the SA.

17. The non-transitory machine-readable storage medium of claim 13 , further comprising creating a SA for the plurality of IPsec packets upon determining that a SA is not associated with those IPsec packets.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the creating the SA further includes atomically adding a pointer to the created SA in the SA pointer structure with an atomic write operation.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 30, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046040/0277 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
CONVERSION AND NAME CHANGE Recorded Dec 14, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037289/0593 →
MERGER Recorded Dec 14, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037287/0098 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2008
From: THANGAVELU, ARAVIND
To: SONICWALL, INC.
Reel/Frame 021618/0553 →