IP Library Granted Patent US 11,095,626
Granted Patent B2
US 11,095,626 · App. 16/142,923 · Granted Aug 17, 2021

Secure in-line received network packet processing

Inventors: Richard E. Kessler (Shrewsbury, MA); Shahe H. Krakirian (Palo Alto, CA)
Assignee: MARVELL ASIA PTE, LTD.
H04L63/0485G06F9/4881
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,095,626
App. No.
16/142,923
Granted
Aug 17, 2021
Kind
B2
Abstract

A network processor provides for in-line encryption and decryption of received and transmitted packets. For packet transmittal, a processor core generates packet data for encryption and forwards an encryption instruction to a cryptographic unit. The cryptographic unit generates an encrypted packet, and enqueues a send descriptor to a network interface controller, which, in turn, constructs and transmits an outgoing packet. For received encrypted packets, the network interface controller communicates with the cryptographic unit to decrypt the packet prior to enqueuing work to the processor core, thereby providing the processor core with a decrypted packet.

Claims (18)

1. A circuit, comprising:

a network parser configured to determine an encryption status from a packet header of a packet, the encryption status indicating whether the packet is a candidate for decryption;

a network interface controller configured to create a queue entry indicating that packet processing is required for the packet, the network interface controller configured to selectively forward a decryption command based on the encryption status;

a decryption engine configured to decrypt the packet in response to the decryption command and generate a decrypted packet;

a queue configured to store the queue entry in order with a plurality of queue entries corresponding to a plurality of packets received by the network parser, the plurality of packets including the packet and unencrypted packets that the network parser determined not to be a candidate for decryption; and

a packet processor configured to process the plurality of packets based on the plurality of queue entries and regardless of communication with the decryption engine, the packet processor accessing one of the packet and the decrypted packet as a function of the encryption status.

2. The circuit of claim 1 , wherein the decryption engine is further configured to selectively generate a portion of the queue entry as a function of the encryption status, the portion including a decryption result indicating a location of the decrypted packet.

3. The circuit of claim 2 , wherein the packet processor is further configured to locate the packet in a memory based on the queue entry, the processor locating either 1) the decrypted packet based on the decryption result, or 2) the packet.

4. The circuit of claim 1 , wherein the packet processor is further configured to locate the packet by reading the queue entry in a manner independent of the encryption status.

5. The circuit of claim 1 , wherein the network parser is further configured to determine a flow from the packet header, the flow identifying a work group to which the packet belongs.

6. The circuit of claim 5 , wherein the queue entry identifies the flow.

7. The circuit of claim 1 , wherein the network interface controller, in response to the encryption status indicating that the packet is not a candidate for decryption, is further configured to generate the queue entry to indicate a location of the packet.

8. The circuit of claim 1 , wherein the packet processor is further configured to communicate with the encryption engine to decrypt the packet.

9. The circuit of claim 1 , wherein the network interface controller is further configured to manage entries of the queue.

10. The circuit of claim 1 , wherein the network interface controller is further configured to selectively forward the decryption command based on a status of a queue of decryption requests to the decryption engine.

11. The circuit of claim 1 , further comprising a scheduler configured to schedule work for the packet processor, the scheduler further configured to schedule the packet for processing by the packet processor.

12. The circuit of claim 11 , wherein the scheduler is further configured to receive a decryption result from the decryption engine, the scheduler scheduling the work based on the decryption result.

13. The circuit of claim 1 , wherein the queue entry further indicates instructions for processing the packet.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2020
From: CAVIUM INTERNATIONAL
To: MARVELL ASIA PTE, LTD.
Reel/Frame 053475/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2020
From: MARVELL INTERNATIONAL LTD.
To: CAVIUM INTERNATIONAL
Reel/Frame 052918/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: MARVELL WORLD TRADE LTD.
To: MARVELL INTERNATIONAL LTD.
Reel/Frame 051778/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2019
From: CAVIUM, LLC
To: MARVELL INTERNATIONAL LTD.
Reel/Frame 050226/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2019
From: MARVELL INTERNATIONAL LTD.
To: MARVELL WORLD TRADE LTD.
Reel/Frame 050226/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2018
From: KESSLER, RICHARD E.; KRAKIRIAN, SHAHE H.
To: CAVIUM, LLC
Reel/Frame 047371/0610 →
Continuity (1)
Related Publication 20200099670A1 · Mar 26, 2020