...
首页> 外文期刊>Bell Labs technical journal >A Novel Network Processor for Security Applications in High-Speed Data Networks
【24h】

A Novel Network Processor for Security Applications in High-Speed Data Networks

机译:适用于高速数据网络中安全应用的新型网络处理器

获取原文
获取原文并翻译 | 示例
           

摘要

This paper describes the programmable protocol processor (PRO3) architecture, which is capable of supporting advanced security services over high-speed networks. Security services include such things as a firewall, packet and flow classification, connection-state handling (i.e., stateful inspection), higher-layer protocol data unit (PDU) reassembly (i.e., application-level firewalls), and packet encryption and decryption. The PRO3, which is integrated with a high-speed line card, attempts to accelerate the performance of the firewall by implementing key functionality in hardware and by optimizing the balance between hardware and software functions. In this way, significant performance enhancements can be achieved, such as making transport control protocol (TCP) and Internet protocol (IP) data transactions secure, and protecting and separating virtual private networks (VPNs) from the external public network. The PRO3 incorporates an innovative scheme―a reduced instruction set computing (RlSC)-based pipelined module with line-rate throughput―that makes it possible to process high- and low-level streaming operations efficiently. Using microcode profiling and simulation, we give performance results for a stateful-inspection firewall application with network address translation (NAT) support.
机译:本文介绍了可编程协议处理器(PRO3)架构,该架构能够支持高速网络上的高级安全服务。安全服务包括防火墙,数据包和流分类,连接状态处理(即状态检查),高层协议数据单元(PDU)重组(即应用程序级防火墙)以及数据包加密和解密等内容。与高速线卡集成的PRO3试图通过在硬件中实现关键功能并优化硬件和软件功能之间的平衡来提高防火墙的性能。这样,可以实现显着的性能增强,例如确保传输控制协议(TCP)和Internet协议(IP)数据事务的安全,以及保护虚拟专用网(VPN)与外部公用网络并将其分离。 PRO3结合了创新方案-具有线速吞吐量的基于精简指令集计算(RlSC)的流水线模块-使高效处理高层和低层流操作成为可能。使用微代码分析和仿真,我们为具有网络地址转换(NAT)支持的状态检查防火墙应用程序提供了性能结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号