US2010174770A1PendingUtilityA1

Runtime adaptable search processor

Individually held — no corporate assignee on recordPriority: Dec 30, 2005Filed: Jan 26, 2010Published: Jul 8, 2010
Est. expiryDec 30, 2025(expired)· nominal 20-yr term from priority
G06F 16/951H04L 69/32G06F 16/90344H04L 69/12H04L 69/16H04L 69/161H04L 67/10H04L 63/20H04L 63/145H04L 67/1097G06F 9/30029
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A runtime adaptable search processor is disclosed. The search processor provides high speed content search capability to meet the performance need of network line rates growing to 1 Gbps, 10 Gbps and higher. The search processor provides a unique combination of NFA and DFA based search engines that can process incoming data in parallel to perform the search against the specific rules programmed in the search engines. The processor architecture also provides capabilities to transport and process Internet Protocol (IP) packets from Layer 2 through transport protocol layer and may also provide packet inspection thrugh Layer 7. Further, a runtime adaptable processor is coupled to the protocol processing hardware and may be dynamically adapted to perform hardware tasks as per the needs of the network traffic being sent or received and/or the policies programmed or services or applications being supported. A set of engines may perform pass-through packet classification, policy processing and/or security processing enabling packet streaming through the architecture at nearly the full line rate. A high performance content search and rules processing security processor is disclosed which may be used for application layer and network layer security. Scheduler schedules packets to packet processors for processing. An internal memory or local session database cache stores a session information database for a certain number of active sessions. The session information that is not in the internal memory is stored and retrieved to/from an additional memory. An application running on an initiator or target can in certain instantiations register a region of memory, which is made available to its peer(s) for access directly without substantial host intervention through RDMA data transfer. A security system is also disclosed that enables a new way of implementing security capabilities inside enterprise networks in a distributed manner using a protocol processing hardware with appropriate security features.

Claims

exact text as granted — not AI-modified
1 . A system for operating on network packets or on local content, said system capable of being coupled to a network, said system comprising a runtime adaptable search processor to process content embedded within said network packets or within said local content. 
   
   
       2 . The system of  claim 1  wherein said runtime adaptable search processor further provides runtime adaptable search processor array hardware to dynamically select hardware configurations within said runtime adaptable search processor to support application or service processing needs of said network packets or said local content. 
   
   
       3 . The system of  claim 1  comprising a content search API to enable applications to utilize the runtime adaptable search processor hardware to accelerate content search; wherein the content search API comprises one or more of the following:
 means to initialize said runtime adaptable search processor;   means to communicate content search rules to said runtime adaptable search processor;   means to communicate the content to be searched by said runtime adaptable search processor;   means to communicate the results of said content search by said runtime adaptable search processor to said applications; and   means to start and stop said runtime adaptable search processor to start and stop content search.   
   
   
       4 . The system of  claim 1  wherein said runtime adaptable search processor enables one or more of the following:
 email security applications comprising one or more of the following:   anti-spam, anti-virus, anti-spyware, anti-phishing, confidential leak prevention, and regulatory compliance; and   web security applications comprising one or more of the following:   firewall, intrusion detection and prevention, application layer security, anti-spam, anti-virus, anti-spyware, anti-phishing, confidential leak prevention, and regulatory compliance,   wherein said applications can be performed at network line rates, wherein said network line rates lie within a range of line rates from below 100 Mbps to 10 Gbps and higher.   
   
   
       5 . The system of  claim 1  wherein said runtime adaptable search processor receives data packets from a network and sends data packets to a network, and further provides capability to select one or more of the following:
 a. policy based services, applications, or policies, or a combination thereof, on one or more of the following: the data packets received from said network, and the data packets sent to said network;   b. user selected services, applications, or policies, or a combination thereof, on one or more of the following: the data packets received from said network, and the data packets sent to said network;   c. user defined services, applications, or policies, or a combination thereof, on one or more of the following: the data packets received from said network, and the data packets sent to said network; and   d. user configured services, applications, or policies, or a combination thereof, on one or more of the following: the data packets received from said network, and the data packets sent to said network.   
   
   
       6 . An apparatus comprising a runtime adaptable finite state automaton (FSA) architecture for implementing at least one regular expression, said FSA architecture having a plurality of states, said FSA architecture comprising:
 a. at least one interconnection between any two of said plurality of states;   b. a state dependent vector (SDV) for each of said plurality of states that is used to enable or disable said at least one interconnection between said two states and other states of said plurality of states;   c. a current state vector (CSV) for each of said plurality of states representing the current state of some of said plurality of states which the state of said plurality of states depends on for its next state evaluation;   d. at least one symbol associated with each of said plurality of states for controlling the transition into or out of said each of said plurality of states;   e. at least one symbol detection logic for receiving symbols, detecting the value of said symbols and generating a received symbol vector (RSV);   f. at least one application state memory for storing a plurality of application state contexts that use said finite state automaton, each of said plurality of application state contexts corresponding to a regular expression; and   g. a state transition logic for each of said plurality of states that uses at least said state dependent vector, said current state vector, and said received symbol vector to generate the next state for each of said plurality of states.   
   
   
       7 . The apparatus of  claim 6 , wherein said FSA architecture further comprises one or more of the following:
 a. a programmable storage for said SDV for enabling runtime configuration of said SDV;   b. a programmable storage for a left-biased (LB) or right-biased (RB) signal for enabling runtime configuration of the realized FSA type;   c. a programmable storage for storing a start flag to indicate if said state is a start state of said FSA;   d. a programmable storage for storing an accept flag to indicate if said state is an accept state of said FSA;   e. a programmable storage for storing an action field to indicate the action that should be taken when said state is activated or reached during said FSA evaluation; and   f. a programmable storage for storing a tag field to indicate a tag that is issued when said state is activated or reached during said FSA evaluation.

Join the waitlist — get patent alerts

Track US2010174770A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.