Data path security processing
    1.
    发明授权
    Data path security processing 有权
    数据路径安全处理

    公开(公告)号:US08055895B2

    公开(公告)日:2011-11-08

    申请号:US12551381

    申请日:2009-08-31

    IPC分类号: H04L29/08 H04L9/00

    摘要: Methods and associated systems provide secured data transmission over a data network. A security device provides security processing in the data path of a packet network. The device may include at least one network interface to send packets to and receive packets from a data network and at least one cryptographic engine for performing encryption, decryption and/or authentication operations. The device may be configured as an in-line security processor that processes packets that pass through the device as the packets are routed to/from the data network.

    摘要翻译: 方法和相关系统通过数据网络提供安全的数据传输。 安全设备在分组网络的数据路径中提供安全处理。 该设备可以包括至少一个网络接口,用于向数据网络发送分组并从数据网络接收分组,并且至少一个密码引擎用于执行加密,解密和/或认证操作。 该设备可以被配置为一个在线安全处理器,其处理在数据包被路由到/从数据网络时通过设备的分组。

    Data path security processing
    2.
    发明授权
    Data path security processing 有权
    数据路径安全处理

    公开(公告)号:US07587587B2

    公开(公告)日:2009-09-08

    申请号:US10727430

    申请日:2003-12-04

    IPC分类号: H04L29/08 H04L9/00

    摘要: Methods and associated systems provide secured data transmission over a data network. A security device provides security processing in the data path of a packet network. The device may include at least one network interface to send packets to and receive packets from a data network and at least one cryptographic engine for performing encryption, decryption and/or authentication operations. The device may be configured as an in-line security processor that processes packets that pass through the device as the packets are routed to/from the data network.

    摘要翻译: 方法和相关系统通过数据网络提供安全的数据传输。 安全设备在分组网络的数据路径中提供安全处理。 该设备可以包括至少一个网络接口,用于向数据网络发送分组并从数据网络接收分组,并且至少一个密码引擎用于执行加密,解密和/或认证操作。 该设备可以被配置为一个在线安全处理器,其处理在数据包被路由到/从数据网络时通过设备的分组。

    Data Path Security Processing
    3.
    发明申请
    Data Path Security Processing 有权
    数据路径安全处理

    公开(公告)号:US20090319775A1

    公开(公告)日:2009-12-24

    申请号:US12551381

    申请日:2009-08-31

    IPC分类号: H04L29/08 H04L9/00

    摘要: Methods and associated systems provide secured data transmission over a data network. A security device provides security processing in the data path of a packet network. The device may include at least one network interface to send packets to and receive packets from a data network and at least one cryptographic engine for performing encryption, decryption and/or authentication operations. The device may be configured as an in-line security processor that processes packets that pass through the device as the packets are routed to/from the data network.

    摘要翻译: 方法和相关系统通过数据网络提供安全的数据传输。 安全设备在分组网络的数据路径中提供安全处理。 该设备可以包括至少一个网络接口,用于向数据网络发送分组并从数据网络接收分组,并且至少一个密码引擎用于执行加密,解密和/或认证操作。 该设备可以被配置为一个在线安全处理器,其处理在数据包被路由到/从数据网络时通过设备的分组。

    System and method for network interfacing
    4.
    发明授权
    System and method for network interfacing 有权
    网络接口的系统和方法

    公开(公告)号:US07934021B2

    公开(公告)日:2011-04-26

    申请号:US12480637

    申请日:2009-06-08

    IPC分类号: G06F15/16

    CPC分类号: H04L67/1097

    摘要: Systems and methods for network interfacing may include a communication data center with a first tier, a second tier and a third tier. The first tier may include a first server with a first single integrated convergent network controller chip. The second server may include a second server with a second single integrated convergent network controller chip. The third tier may include a third server with a third single integrated convergent network controller chip. The second server may be coupled to the first server via a single fabric with a single connector. The third server may be coupled to the second server via the single fabric with the single connector. The respective first, second and third server, each processes a plurality of different traffic types concurrently via the respective first, second and third single integrated convergent network chip over the single fabric that is coupled to the single connector.

    摘要翻译: 用于网络接口的系统和方法可以包括具有第一层,第二层和第三层的通信数据中心。 第一层可以包括具有第一单一集成收敛网络控制器芯片的第一服务器。 第二服务器可以包括具有第二单一集成收敛网络控制器芯片的第二服务器。 第三层可以包括具有第三单一集成收敛网络控制器芯片的第三服务器。 第二服务器可以经由具有单个连接器的单个结构耦合到第一服务器。 第三服务器可以通过具有单个连接器的单个结构耦合到第二服务器。 相应的第一,第二和第三服务器各自通过耦合到单个连接器的单个结构上的相应的第一,第二和第三单个集成收敛网络芯片同时处理多个不同的业务类型。

    System and method for TCP offload
    5.
    发明授权
    System and method for TCP offload 有权
    TCP卸载的系统和方法

    公开(公告)号:US07849208B2

    公开(公告)日:2010-12-07

    申请号:US12032953

    申请日:2008-02-18

    IPC分类号: H04L12/56 G06F15/16

    摘要: A system for processing packets is disclosed and may including a network interface card (NIC). The NIC may include a TCP enabled Ethernet controller (TEEC). The TEEC may include an internal elastic buffer. The TEEC may process received incoming TCP packets once and may temporarily buffer at least a portion of the incoming TCP packets in the internal elastic buffer. The processing may occur without reassembly or retransmission. The internal elastic buffer may include a receive internal elastic buffer and a transmit internal elastic buffer. The receive internal elastic buffer may temporarily buffer at least a portion of the received incoming TCP packets. The transmit internal elastic buffer may temporarily buffer at least a portion of TCP packets to be transmitted. The TEEC may place at least a portion of the received incoming TCP packets data into at least a portion of a host memory.

    摘要翻译: 公开了一种用于处理分组的系统,并且可以包括网络接口卡(NIC)。 NIC可以包括TCP启用的以太网控制器(TEEC)。 TEEC可以包括内部弹性缓冲器。 TEEC可以处理接收到的TCP分组一次,并且可以临时缓冲内部弹性缓冲器中的传入TCP分组的至少一部分。 该处理可以在没有重新组装或重传的情况下进行。 内部弹性缓冲器可以包括接收内部弹性缓冲器和传输内部弹性缓冲器。 接收内部弹性缓冲器可以临时缓冲所接收的进入TCP分组的至少一部分。 发送内部弹性缓冲器可以临时缓冲要发送的TCP分组的至少一部分。 TEEC可以将接收到的进入的TCP分组数据的至少一部分置于主机存储器的至少一部分中。

    System and method for TCP offload
    6.
    发明授权
    System and method for TCP offload 有权
    TCP卸载的系统和方法

    公开(公告)号:US08677010B2

    公开(公告)日:2014-03-18

    申请号:US13115274

    申请日:2011-05-25

    IPC分类号: G06F15/16 H04L12/56

    摘要: Aspects of the invention may comprise receiving an incoming TCP packet at a TEEC and processing at least a portion of the incoming packet once by the TEEC without having to do any reassembly and/or retransmission by the TEEC. At least a portion of the incoming TCP packet may be buffered in at least one internal elastic buffer of the TEEC. The internal elastic buffer may comprise a receive internal elastic buffer and/or a transmit internal elastic buffer. Accordingly, at least a portion of the incoming TCP packet may be buffered in the receive internal elastic buffer. At least a portion of the processed incoming packet may be placed in a portion of a host memory for processing by a host processor or CPU. Furthermore, at least a portion of the processed incoming TCP packet may be DMA transferred to a portion of the host memory.

    摘要翻译: 本发明的方面可以包括在TEEC处接收进入的TCP分组,并且由TEEC处理进入分组的至少一部分一次,而不必由TEEC进行任何重新组合和/或重传。 进入的TCP分组的至少一部分可以缓冲在TEEC的至少一个内部弹性缓冲器中。 内部弹性缓冲器可以包括接收内部弹性缓冲器和/或发送内部弹性缓冲器。 因此,进入的TCP分组的至少一部分可以缓冲在接收内部弹性缓冲器中。 处理的输入分组的至少一部分可以被放置在主机存储器的一部分中,以供主机处理器或CPU处理。 此外,处理的输入TCP分组的至少一部分可以被DMA传送到主机存储器的一部分。

    System and method for TCP/IP offload independent of bandwidth delay product
    8.
    发明授权
    System and method for TCP/IP offload independent of bandwidth delay product 有权
    TCP / IP卸载的系统和方法独立于带宽延迟产品

    公开(公告)号:US08402142B2

    公开(公告)日:2013-03-19

    申请号:US11963105

    申请日:2007-12-21

    IPC分类号: G06F15/16

    摘要: A method for providing TCP/IP offload may include receiving control of at least a portion of Transmission Control Protocol (TCP) connection variables by a TCP/IP Offload Engine operatively coupled to a host. The at least a portion of the TCP/IP Offload Engine connection variables may be updated and provided to the host. The TCP/IP Offload Engine may receive control of segment-variant TCP connection variables. The TCP/IP Offload Engine may update the received TCP segment-variant TCP connection variables, and communicate the updated TCP segment-variant TCP connection variables to the host. A system for providing connection offload may include a TCP/IP Offload Engine that receives control of state information for a particular connection offloaded to a network interface card (NIC). Control of the state information for the particular connection may be split between the NIC and a host.

    摘要翻译: 提供TCP / IP卸载的方法可以包括通过可操作地耦合到主机的TCP / IP卸载引擎来接收至少一部分传输控制协议(TCP)连接变量的控制。 TCP / IP卸载引擎连接变量的至少一部分可能被更新并提供给主机。 TCP / IP卸载引擎可以接收段变式TCP连接变量的控制。 TCP / IP卸载引擎可以更新所接收的TCP段变体TCP连接变量,并将更新的TCP段变体TCP连接变量传送给主机。 用于提供连接卸载的系统可以包括TCP / IP卸载引擎,其接收卸载到网络接口卡(NIC)的特定连接的状态信息的控制。 控制特定连接的状态信息可能会在NIC和主机之间分配。

    System and method for network interfacing
    9.
    发明授权
    System and method for network interfacing 有权
    网络接口的系统和方法

    公开(公告)号:US08010707B2

    公开(公告)日:2011-08-30

    申请号:US10652330

    申请日:2003-08-29

    IPC分类号: G06F15/16

    摘要: Systems and methods that network interface are provided. In one embodiment, a data center may be provided that may include, for example, a first tier, a second tier and a third tier. The first tier may include, for example, a first server. The second tier may include, for example, a second server. The third tier may include, for example, a third server. At least one of the first server, the second server and the third server may handle a plurality of different traffic types over a single fabric.

    摘要翻译: 提供网络接口的系统和方法。 在一个实施例中,可以提供可以包括例如第一层,第二层和第三层的数据中心。 第一层可以包括例如第一服务器。 第二层可以包括例如第二服务器。 第三层可以包括例如第三服务器。 第一服务器,第二服务器和第三服务器中的至少一个可以通过单个结构处理多个不同的业务类型。