Encryption Accelerator and System and Method for Encryption

By introducing input buffers and data components into the encryption accelerator, the problem of virtual data in the AEAD encryption scheme is automatically removed, and the effect of improving system bus throughput and encryption operation efficiency is achieved.

CN114329508BActive Publication Date: 2025-06-17INFINEON TECHNOLOGIES AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111153795.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-09-29
Filing Date
2021-09-29
Publication Date
2025-06-17
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

In AEAD encryption scheme, when using the maximum transmission size of the bus, it may cause virtual data to be moved into the encryption accelerator, affecting the efficiency and flexibility of encryption operations.

Method used

By introducing input buffers and data components into the encryption accelerator, the lengths of each part of the message are determined and valid data is read from the address range based on these lengths, and virtual data is automatically removed, thereby improving the throughput of the system bus.

Benefits of technology

It realizes automatic removal of virtual data without configuring the length of each part of the message, improves the efficiency and flexibility of the encryption accelerator, and enhances the system bus throughput when transmitting data using DMA.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329508B_ABST
    Figure CN114329508B_ABST
Patent Text Reader

Abstract

An encryption accelerator and a system and method for encryption are disclosed. The encryption accelerator may include an input buffer that stores first data including a first portion of a message in a first address range and second data including a second portion of the message in a second address range. The encryption accelerator may include one or more components that determine the lengths of the first portion and the second portion, read the first portion from the first address range, discard any virtual data in the first address range based on an indication of an endpoint of the first data in the first address range, read the second portion from the second address range, and discard any virtual data in the second address range based on an indication of an endpoint of the second data in the second address range. The encryption accelerator may include an encryption engine that performs an encryption operation using the first portion and the second portion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptography and, in particular, to virtual data removal in authenticated encryption using related data encryption schemes. Background Art

[0002] In some cases, a message in a secure communication scenario includes at least two parts - an additional authenticated data part (AAD) that is only authenticated and a plaintext part that is both authenticated and encrypted. The encryption operation that performs this authenticated encryption is called authenticated encryption with associated data (AEAD). AEAD can be used to ensure both the confidentiality and authenticity of data. Typically, the AAD part includes message header information, while the plaintext part includes the message payload. Summary of the Invention

[0003] In some implementations, an encryption accelerator includes: an input buffer for storing first data in a first address range, where the first data includes a first part of a message, and for storing second data in a second address range, where the second data includes a second part of the message; one or more components for determining the lengths of the first part and the second part, reading the first part from the first address range based on the length of the first part, discarding any virtual data in the first address range based on the length of the first part and an indication of an endpoint of the first data in the first address range, reading the second part from the second address range based on the length of the second part, and discarding any virtual data in the second address range based on the length of the second part and an indication of an endpoint of the second data in the second address range; and an encryption engine for performing an encryption operation using the first part and the second part.

[0004] In some implementations, a system includes: a memory for storing a first part of a message and a second part of the message; a direct memory access component for providing first data, which includes the first part of the message, to the encryption accelerator and for providing second data, which includes the second part of the message, to the encryption accelerator; and an encryption accelerator for storing the first data in a first address range of an input buffer; storing the second data in a second address range of the input buffer; determining the lengths of the first part and the second part after the first data is stored in the first address range and after the second data is stored in the second address range; discarding any virtual data included in the first data based on the length of the first part and an indication of an endpoint of the first data; and discarding any virtual data included in the second data based on the length of the second part and an indication of an endpoint of the second data.

[0005] In some implementations, a method includes: storing first data in a first address range of an input buffer of an encryption accelerator, the first data including a first part of a message; storing second data in a second address range of the input buffer of the encryption accelerator, the second data including a second part of the message; determining a length of the first part and a length of the second part; obtaining a first part of the first data from the first address range based on the length of the first part and the length of the first data, obtaining a second part of the second data from the second address range based on the length of the second part and the length of the second data; and performing an encryption operation using the first part obtained from the first address range and the second part obtained from the second address range. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] Figures 1A to 1C is a diagram illustrating an example of virtual data removal in an AEAD encryption scheme according to various aspects of the present disclosure.

[0007] Figure 2 is a diagram of an example system in which the encryption accelerator described herein can be implemented.

[0008] Figure 3 is a flowchart of an example process related to virtual data removal in an AEAD encryption scheme according to various aspects of the present disclosure. DETAILED DESCRIPTION

[0009] The following detailed description of example implementations refers to the accompanying drawings. Like reference numerals in different drawings may identify the same or similar elements.

[0010] In an AEAD encryption scheme, the AAD part of a message and the plaintext part of the message are independent. Thus, the AAD part and the plaintext part are typically processed / generated by different software tasks and stored at different locations in the random access memory (RAM) of a microcontroller. That is, the parts of the message are not concatenated within the RAM. To move these two types of data to an encryption accelerator (e.g., an Advanced Encryption Standard (AES) engine), direct memory access (DMA) can be used.

[0011] Typically, to increase the throughput on the system bus, the maximum transfer size of the bus (e.g., burst access) can be used. However, in cases where the size of the AAD part or the size of the plaintext part is not a multiple of the transfer size of the bus, using the maximum transfer size of the bus can cause so-called virtual data to be moved into the encryption accelerator. Similarly, when allocating a specific buffer size for generating a header (e.g., the AAD part of a message), a given header may have a different size per frame. Thus, software can generate headers that may be smaller than the buffer size. Here, if the DMA is configured to transfer the entire allocated buffer size, virtual data (independent of the bus transfer size) may appear between the AAD part and the plaintext part. This can be a problem for an encryption accelerator that uses a first-in-first-out (FIFO) input buffer because virtual data must not be included in the encryption operation.

[0012] Conventionally, to prevent virtual data from being included in the encryption operation, word or byte access is needed to enable the transfer of only valid data. However, using word or byte access reduces the throughput of the system bus. Another technique for solving the virtual data problem is to make the encryption accelerator aware of the size of the AAD part and the size of the plaintext part before the start of data transfer (i.e., before the AAD part or the plaintext part is provided to the encryption accelerator). However, this increases the latency and is less flexible for software processing.

[0013] Some implementations described herein implement virtual data removal in an AEAD encryption scheme. In some implementations, the encryption accelerator includes an input buffer for storing first data in a first address range, where the first data includes a first part of a message (e.g., the AAD part of the message), and for storing second data in a second address range, where the second data includes a second part of the message (e.g., the plaintext part of the message). The encryption accelerator further includes one or more components for determining the length of the first part and the length of the second part. Then, the one or more components read the first part from the first address range based on the length of the first part and discard any virtual data in the first address range based on the length of the first part and an indication of the endpoints of the first data in the first address range. The one or more components also read the second part from the second address range based on the length of the second part and discard any virtual data in the second address range based on the length of the second part and an indication of the endpoints of the second data in the second address range. The encryption accelerator further includes an encryption engine for performing an encryption operation using the first part and the second part.

[0014] In this way, the encryption accelerator is improved such that the encryption accelerator can distinguish valid data from virtual data for a given part of a message, and thus can (automatically) remove virtual data even without knowing the size of the part of the message before the message data is transmitted to / received by the encryption accelerator. In other words, the improved encryption accelerator enables automatic removal of virtual data even when the length values of the parts of the message are not configured at the start of data transmission. As a result, the maximum transmission size of the bus can be used, thereby increasing the throughput of the system bus, which improves flexibility and latency when transferring data using, for example, DMA.

[0015] Figures 1A to 1C FIG. is a diagram illustrating Example 100 of virtual data removal in an AEAD encryption scheme according to various aspects of the present disclosure.

[0016] As Figures 1A to 1C shown, Example 100 includes an encryption accelerator 102. In some implementations, the encryption accelerator 102 may be a component in a system, such as a system on a chip (SoC). As Figure 1A shown, the encryption accelerator 102 may include an input buffer 104, a data component 106, an encryption engine 108, and an output buffer 110. A description of the encryption accelerator 102 and the components of the encryption accelerator 102 is provided below, followed by a description of an example operation of the encryption accelerator 102.

[0017] The encryption accelerator 102 is a component of the system for performing encryption operations. In some implementations, the encryption accelerator 102 may be a coprocessor of the system. In some implementations, the encryption accelerator 102 improves the performance of the system by providing hardware for performing encryption operations (instead of performing encryption operations by software and / or the general central processing unit (CPU) of the system).

[0018] The input buffer 104 is a component of the encryption accelerator 102 that holds data received by the encryption accelerator 102 before the data received by the encryption accelerator 102 is processed by one or more other components of the encryption accelerator 102. In some implementations, the input buffer 104 may be a FIFO-based buffer. In some implementations, data is stored in a specific address range of the input buffer 104 in association with implementing virtual data removal, as described herein. In some implementations, the data stored in the input buffer 104 includes a part of a message (e.g., an AAD part, a plaintext part, a random number, etc.), as described below.

[0019] The data component 106 includes one or more components of the encryption accelerator 102 for performing one or more operations associated with virtual data removal, as described herein. For example, the data component 106 may include a component for determining the length of a portion of a message, a component for reading a portion of the message from an address range of the input buffer 104, and a component for discarding any virtual data from the address range of the input buffer 104, as described in further detail below. In some implementations, the data component 106 may also be referred to as a data part, a frame component, or a frame part.

[0020] The encryption engine 108 is a component of the encryption accelerator 102 that is used to perform encryption operations using portions of the data read by the data component 106. For example, the encryption engine 108 may include an AES engine.

[0021] The output buffer 110 is a component of the encryption accelerator 102 that holds data to be transmitted by the encryption accelerator 102 after the data to be transmitted by the encryption accelerator 102 has been processed by one or more other components of the encryption accelerator 102. In some implementations, the output buffer 110 may be a FIFO-based buffer.

[0022] In an exemplary operation, starting from reference numeral 150, the input buffer 104 may store first data in a first address range (address range 1), where the first data includes a first portion (M1) of a message. For example, the encryption accelerator 102 may receive the first data via a DMA component (not shown) of the system, and the input buffer 104 may store the first data in the first address range (e.g., 0x000 to 0x7FF). The first portion of the message is the portion of the message on which one or more encryption operations are performed. For example, the first portion of the message may include the AAD portion of the message, the plaintext portion of the message, the nonce portion of the message, etc. In some implementations, in addition to the first portion of the message, the first data may also include one bit or more of virtual data (DD1). For example, when the maximum transfer size of the bus is used to transfer the first data to the encryption accelerator 102 and the size of the first portion of the message is less than the maximum transfer size of the bus, the first data may be padded with one bit or more of virtual data.

[0023] As indicated by reference numeral 152, the input buffer 104 may store second data in a second address range (address range 2), where the second data includes a second part (M2) of the message. For example, the encryption accelerator 102 may receive the second data through a DMA component (not shown) of the system, and the input buffer 104 may store the second data in a second address range (e.g., 0x800 to 0xFFF). The second part of the message is another part of the message (i.e., the part of the message that is different from the first part): one or more encryption operations will be performed based on this other part. For example, the second part of the message may include the AAD part of the message, the plaintext part of the message, the random number part of the message, etc. In some implementations, in addition to the second part of the message, the second data may further include one or more bits of dummy data (DD2). For example, when the maximum transfer size of the bus is used to transfer the second data to the encryption accelerator 102 and the size of the second part of the message is less than the maximum transfer size of the bus, the second data may be padded with one or more bits of dummy data. Here, the boundary between address range 1 and address range 2 in the memory of the input buffer 104 is dynamic. For example, in Figure 1A the context of, based on the size of the first part M1 of the message plus the size of one or more bits of dummy data DD1, the position where one or more bits of dummy data DD1 end and the second part M2 of the message begins in the memory of the input buffer 104 is dynamic.

[0024] As indicated by reference numeral 154, the data component 106 determines the length of the first part of the message and the length of the second part of the message. In some implementations, after the first data is stored in the first address range and after the second data is stored in the second address range, the data component 106 determines the length of the first part of the message and the length of the second part of the message. That is, after the first data and the second data are transferred to the encryption accelerator 102 and stored by the encryption accelerator 102, the data component 106 may determine the lengths of the first part and the second part of the message.

[0025] In some implementations, data component 106 determines the length of the first part of the message and the length of the second part of the message from a first software-accessible length register and a second software-accessible length register, respectively. For example, software associated with encryption accelerator 102 may configure encryption accelerator 102 with a set of parameters to be used in association with performing an encryption operation on the first data and the second data. In some implementations, this configuration is performed after (or simultaneously with) the first data and / or the second data being transferred to encryption accelerator 102. In some implementations, the set of parameters includes an indication of the length of the first part of the message that may be stored in the first software-accessible length register, and an indication of the length of the second part of the message that may be stored in the second software-accessible length register. The set of parameters may also include one or more other parameters associated with performing the encryption operation, such as an indication of the type of cipher to be used, an indication of the key to be used, and the like. Here, data component 106 determines the lengths of the first part and the second part of the message based on the length configured in the first software-accessible length register and the length configured in the second software-accessible length register, respectively.

[0026] As indicated by reference numeral 156, data component 106 then reads the first part of the message from a first address range based on the length of the first part of the message determined in the manner described above. Next, as indicated by reference numeral 158, data component 106 discards any virtual data in the first address range based on the length of the first part and an indication of the endpoint of the first data in the first address range. For example, data component 106 may determine the position at which the first part of the data in the first address range ends based on the length of the first part of the message. Here, data component 106 may discard any virtual data between the position at which the first part of the message ends and the indicated endpoint of the first data in the first address range (since there will be virtual data between the end of the first part of the message and the endpoint of the first data).

[0027] In some implementations, the indication of the endpoint of the first data in the first address range is based on a byte counter associated with the first data. For example, data component 106 may utilize a byte counter that counts the number of bytes stored in association with storing the first data. Here, the number of bytes counted by the byte counter indicates the endpoint of the first data based on the byte counter. Alternatively, in some implementations, the indication of the endpoint of the first data in the first address range is based on the stored write pointer position associated with storing the first data. For example, when input buffer 104 is implemented as a circular buffer, a write pointer value may be stored after storing the first data in the first address range. Here, the endpoint of the first data in the first address range may be determined by evaluating the difference between the stored write pointer and the current value of the read pointer.

[0028] In some implementations, in association with discarding any virtual data in the first address range, data component 106 may identify one or more bits of virtual data in the first address range based on the length of the first part and an indication of the endpoints of the first data in the first address range. The data component 106 may then discard one or more bits of virtual data by reading one or more bits of virtual data from the input buffer 104 without processing the one or more bits of virtual data or by setting the read pointer associated with reading data from the input buffer 104 to the stored write pointer position associated with storing the first data.

[0029] As Figure 1B shown by reference numeral 160 in the figure, the data component 106 also reads the second part of the message from the second address range based on the length of the second part of the message determined in the above manner. Next, as shown by reference numeral 162, the data component 106 discards any virtual data in the second address range based on the length of the second part and an indication of the endpoints of the second data in the second address range. For example, the data component 106 may determine the position at which the second part of the data in the second address range ends based on the length of the second part of the message. Here, the data component 106 may discard any virtual data between the position at which the second part of the message ends and the indicated endpoints of the second data in the second address range (since there will be virtual data between the end of the second part of the message and the endpoints of the second data). In some implementations, the indication of the endpoints of the second data in the second address range is based on a byte counter associated with the second data or the stored write pointer position associated with storing the second data, similar to the manner described above in association with the first data.

[0030] In some implementations, in association with discarding any virtual data in the second address range, data component 106 may identify one or more bits of virtual data based on the length of the second part and an indication of the endpoints of the second data in the second address range. The data component 106 may then discard one or more bits of virtual data by reading one or more bits of virtual data from the input buffer 104 without processing the one or more bits of virtual data or by setting the read pointer associated with reading data from the input buffer 104 to the stored write pointer position associated with storing the second data.

[0031] As Figure 1CAs indicated by reference numeral 164, data component 106 may forward the first part of the message and the second part of the message (without virtual data) to encryption engine 108 or otherwise provide them to encryption engine 108. As indicated by reference numeral 166, encryption engine 108 may use the first part of the message and the second part of the message to perform an encryption operation. As indicated by reference numeral 168, encryption engine 108 may provide the output of the encryption operation (e.g., a secure communication message generated from the first part of the message and the second part of the message) to output buffer 110, and output buffer 110 may convey the output accordingly (e.g., convey it to a communication component (not shown) of the system).

[0032] It should be noted that the message described in example 100 includes a first part and a second part. However, in some implementations, the message may include one or more additional parts. For example, the message may include a first part (e.g., a random number part), a second part (e.g., an AAD part), and a third part (e.g., a plaintext part). In such a case, input buffer 104 may also be configured to store the third data in a specific address range, where the third data includes the third part of the message. Here, data component 106 may determine the length of the third part of the message, read the third part from the specific address range based on the length of the third part, and discard any virtual data in the specific address range based on the length of the third part and an indication of the endpoints of the third data in the specific address range in the manner described herein. Additionally, encryption engine 108 may use the third part of the message (in addition to the first part and the second part of the message) to perform an encryption operation.

[0033] In some implementations, the specific address range for storing the third data is a third address range (e.g., an address range in addition to the first address range and the second address range). Generally, in some implementations, N (N≥1) address ranges may be used, where each of the N address ranges is used to store a corresponding data item of N data items, and each data item includes one part of the N parts of the message.

[0034] Alternatively, in some implementations, the specific address range storing the third data is the first address range. For example, rather than requiring a given piece of data (e.g., including a given part of a message) to be stored in a dedicated address range, it is only required that the given data be written to an address range different from the address range where the last data was stored. This is necessary for the data component 106 to maintain knowledge of the position of the stored circular buffer pointer. As a result, it is possible to alternate writes between two or more address ranges. For example, a message may include a first part, a second part, and a third part as described above. Here, the first data including the first part of the message may be stored in the first address range, then the second data including the second part of the message may be stored in the second address range, and then the third data including the third part of the message may be stored in the first address range. Additional data may be alternately stored between the first address range and the second address range in a similar manner. Generally, in some implementations, M (M > 1) address ranges may be used, where N data items are alternately stored between the M address ranges, and each data item includes one of the N parts of the message (e.g., such that the address ranges are not used to store consecutively received data items).

[0035] As described above, provided Figures 1A to 1C as an example. Other examples may be different from the examples regarding Figures 1A to 1C described. Provided Figures 1A to 1C the number and arrangement of the components shown as an example. In practice, compared to the components shown Figures 1A to 1C there may be additional components, fewer components, different components, or components with a different arrangement. Additionally, Figures 1A to 1C two or more of the components shown may be implemented within a single component, or Figures 1A to 1C a single component shown may be implemented as multiple distributed components. Additionally or alternatively, Figures 1A to 1C a set of components shown (e.g., one or more components) may perform one or more functions described as being performed by Figures 1A to 1C another set of components shown.

[0036] Figure 2 FIG. 23 is a diagram of an example system 200 in which the encryption accelerator 102 may be implemented. In some implementations, the system 200 may be a SoC. As Figure 2 shown, the system 200 may include an encryption accelerator 102, as well as a bus 112, a memory 114, a DMA 116, a CPU 118, and a communication component 120.

[0037] The encryption accelerator 102 is a component for performing encryption operations associated with the system 200 as described herein. Additional details regarding the encryption accelerator 102 were provided above regarding Figures 1A to 1C FIG. 28.

[0038] Bus 112 is a component that enables communication between components of system 200. For example, bus 112 can enable encryption accelerator 102 to receive data from memory 114 and / or DMA 116. As another example, bus 112 can enable encryption accelerator 102 to transfer data to communication component 120.

[0039] Memory 114 is a component for storing and providing portions of messages to be processed by encryption accelerator 102. For example, memory 114 can store a first portion of a message and a second portion of the message, and based on the first portion and the second portion of the message, encryption accelerator 102 will perform an encryption operation. In some implementations, memory 114 can include RAM, read-only memory (ROM), and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory).

[0040] DMA 116 is a component for providing data stored by memory 114 to encryption accelerator 102 (e.g., data including a portion of a message stored by memory 114). In some implementations, DMA 116 provides data stored by memory 114 to encryption accelerator 102 independent of CPU 118 (i.e., DMA 116 provides direct memory access). For example, independent of CPU 118, DMA 116 is capable of providing first data including a first portion of a message to encryption accelerator 102, and providing second data including a second portion of the message to encryption accelerator 102, as described herein.

[0041] CPU 118 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field programmable gate array, an application specific integrated circuit, and / or other types of processing components. In some implementations, CPU 118 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, CPU 118 includes one or more processors that can be programmed to perform functions.

[0042] Communication component 120 includes components that enable system 200 to communicate with other devices, for example, via a wired connection and / or a wireless connection. For example, communication component 120 can include a receiver, a transmitter, a transceiver, a modem, a network interface card, an antenna, etc.

[0043] Provide Figure 2 The number and arrangement of the components shown are for example purposes. In practice, there may be additional components, fewer components, different components, or components with a different arrangement compared to Figure 2 those shown. Additionally, Figure 2 two or more of the components shown can be implemented within a single component, or Figure 2The individual components shown in the figure may be implemented as multiple distributed components. Additionally or alternatively, a set of components (e.g., one or more components) of system 200 may perform one or more functions described as being performed by another set of components of system 200.

[0044] Figure 3 is a flowchart of an example process 300 associated with virtual data removal in an AEAD encryption scheme. In some implementations, Figure 3 one or more process blocks of may be performed by an encryption accelerator (e.g., encryption accelerator 102).

[0045] As Figure 3 shown, process 300 may include storing first data in a first address range of an input buffer of the encryption accelerator, the first data including a first portion of a message (block 310). For example, the encryption accelerator may (e.g., using input buffer 104) store the first data in the first address range of the input buffer of the encryption accelerator, the first data including the first portion of the message, as described above.

[0046] As Figure 3 further shown, process 300 may include storing second data in a second address range of the input buffer of the encryption accelerator, the second data including a second portion of the message (block 320). For example, the encryption accelerator may (e.g., using input buffer 104) store the second data in the second address range of the input buffer of the encryption accelerator, the second data including the second portion of the message, as described above.

[0047] As Figure 3 further shown, process 300 may include determining the length of the first portion and the length of the second portion (block 330). For example, the encryption accelerator may (e.g., using data component 106) determine the length of the first portion and the length of the second portion, as described above.

[0048] As Figure 3 further shown, process 300 may include obtaining a first portion of the first data from the first address range based on the length of the first portion and the length of the first data (block 340). For example, the encryption accelerator may (e.g., using data component 106) obtain the first portion of the first data from the first address range based on the length of the first portion and the length of the first data, as described above.

[0049] As Figure 3As further shown, process 300 may include obtaining a second portion of the second data from a second address range based on the length of the second portion and the length of the second data (block 350). For example, an encryption accelerator may (e.g., using data component 106) obtain a second portion of the second data from a second address range based on the length of the second portion and the length of the second data, as described above.

[0050] As Figure 3 As further shown, process 300 may include performing an encryption operation using the first portion obtained from the first address range and the second portion obtained from the second address range (block 360). For example, an encryption accelerator may (e.g., using encryption engine 108) perform an encryption operation using the first portion obtained from the first address range and the second portion obtained from the second address range, as described above.

[0051] Process 300 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in combination with one or more other processes described elsewhere herein.

[0052] In a first implementation, after storing the first data in the first address range and after storing the second data in the second address range, the lengths of the first portion and the second portion are determined.

[0053] In a second implementation, alone or in combination with the first implementation, obtaining a first portion of the first data from the first address range includes: reading the first portion from the first address range based on the length of the first portion, and discarding any virtual data in the first address range based on the length of the first portion and an indication of the endpoints of the first data.

[0054] In a third implementation, alone or in combination with one or more of the first implementation and the second implementation, obtaining a second portion of the second data from the second address range includes: reading the second portion from the second address range based on the length of the second portion, and discarding any virtual data in the second address range based on the length of the second portion and an indication of the endpoints of the second data in the second address range.

[0055] Although Figure 3 example blocks of process 300 are shown, in some implementations, process 300 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks compared to those depicted Figure 3 herein. Additionally or alternatively, two or more blocks of process 300 may be executed in parallel.

[0056] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise forms disclosed. Modifications and variations may be made in light of the above disclosure, or may be acquired from the practice of the implementations.

[0057] As used herein, the term “component” is intended to be broadly construed as hardware, firmware, and / or a combination of hardware and software.

[0058] It will be apparent that the systems and / or methods described herein may be implemented in different forms of hardware, firmware, or a combination of hardware and software. The actual special control hardware or software code used to implement these systems and / or methods does not limit the implementations. Accordingly, the operations and behavior of the systems and / or methods are described herein without reference to specific software code—it being understood that software and hardware may be designed to implement the systems and / or methods based on the description herein.

[0059] Although specific combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or not specifically disclosed in the specification. Although each dependent claim listed below may directly depend only on one claim, the disclosure of each implementation includes each dependent claim combined with every other claim in the claim set.

[0060] Any element, act, or instruction used herein should not be construed as critical or essential unless explicitly described as such. Further, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more.” Further, as used herein, the article “the” is intended to include one or more items referenced in conjunction with the article “the” and may be used interchangeably with “one or more.” Further, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, combinations of related and unrelated items, etc.) and may be used interchangeably with “one or more.” The phrase “only one” or similar language is used where only one item is intended. Further, as used herein, the terms “having,” “including,” “containing,” etc. are intended to be open-ended terms. Further, unless otherwise expressly stated, the phrase “based on” is intended to mean “at least partially based on.” Further, as used herein, unless otherwise expressly stated (e.g., if used in conjunction with “any” or “only one of”), the term “or” when used in series is intended to be inclusive and may be used interchangeably with “and / or.”

Claims

1. An encryption accelerator, comprising: An input buffer for: Storing first data in a first address range, the first data including a first part of a message, and Storing second data in a second address range, the second data including a second part of the message; One or more components for: Determining the length of the first part and the length of the second part, Reading the first part from the first address range based on the length of the first part, Identifying one or more bits of virtual data in the first address range based on the length of the first part and an indication of an endpoint of the first data in the first address range, Discarding the one or more bits of virtual data by at least one of: Reading the one or more bits of virtual data from the input buffer without processing the one or more bits of virtual data, and Setting a read pointer associated with reading data from the input buffer to a stored write pointer position associated with storing the first data, Reading the second part from the second address range based on the length of the second part, Discarding virtual data in the second address range based on the length of the second part and an indication of an endpoint of the second data in the second address range; And An encryption engine for performing an encryption operation using the first part and the second part.

2. The encryption accelerator according to claim 1, wherein, The first part of the message is an additional authentication data part of the message, and the second part of the message is a plaintext part of the message.

3. The encryption accelerator according to claim 1, wherein, After the first data is stored in the first address range and after the second data is stored in the second address range, determining the length of the first part and the length of the second part.

4. The encryption accelerator according to claim 1, wherein, The length of the first part and the length of the second part are determined from respective software-accessible length registers.

5. The encryption accelerator according to claim 1, wherein, The indication of the endpoint of the first data in the first address range is based on a byte counter associated with the first data or a stored write pointer position associated with storing the first data.

6. The encryption accelerator according to claim 1, wherein, The indication of the endpoint of the second data in the second address range is based on a byte counter associated with the second data or a stored write pointer position associated with storing the second data.

7. The encryption accelerator according to claim 1, wherein, The one or more bits of virtual data are one or more bits of first virtual data, and wherein, When discarding second one or more bits of second virtual data in the second address range, the one or more components are for: Identifying the second one or more bits of second virtual data in the second address range based on the length of the second part and an indication of an endpoint of the second data in the second address range, and Discarding the second one or more bits of second virtual data by at least one of: Reading the second one or more bits of second virtual data from the input buffer without processing the second one or more bits of second virtual data, and Setting the read pointer to a stored write pointer position associated with storing the second data.

8. The encryption accelerator according to claim 1, wherein, The input buffer is further configured to store third data in a specific address range, the third data including a third part of the message, wherein the specific address range is a third address range or the first address range, wherein the one or more bits of virtual data are one or more bits of first virtual data, and wherein the one or more components are further configured to: determine the length of the third part, read the third part from the specific address range based on the length of the third part, discard a second one or more bits of second virtual data in the specific address range based on the length of the third part and an indication of an endpoint of the third data in the specific address range, and wherein the encryption engine is further configured to perform the encryption operation using the third part.

9. A system for encryption, comprising: A memory for storing a first part of a message and a second part of the message; A direct memory access component configured to: provide first data to an encryption accelerator, the first data including the first part of the message, and provide second data to the encryption accelerator, the second data including the second part of the message; and The encryption accelerator configured to: store the first data in a first address range of an input buffer; store the second data in a second address range of the input buffer; after the first data is stored in the first address range and after the second data is stored in the second address range, determine the length of the first part and the length of the second part; identify one or more bits of virtual data in the first address range based on the length of the first part and an indication of an endpoint of the first data in the first address range, discard the one or more bits of virtual data by at least one of: reading the one or more bits of virtual data from the input buffer without processing the one or more bits of virtual data, and setting a read pointer associated with reading data from the input buffer to a stored write pointer position associated with storing the first data; and discard virtual data included in the second data based on the length of the second part and an indication of an endpoint of the second data.

10. The system according to claim 9, wherein, The encryption accelerator is further configured to: read the first part from the first address range based on the length of the first part, read the second part from the second address range based on the length of the second part, and perform an encryption operation using the first part and the second part.

11. The system according to claim 9, wherein, The lengths of the first part and the second part are determined from respective software-accessible length registers.

12. The system according to claim 9, wherein, The indication of the endpoint of the first data in the first address range is based on a byte counter associated with the first data or a stored write pointer position associated with storing the first data.

13. The system according to claim 9, wherein, The indication of the endpoint of the second data in the second address range is based on a byte counter associated with the second data or a stored write pointer position associated with storing the second data.

14. The system according to claim 9, wherein, The one or more bits of virtual data are the first one or more bits of first virtual data, and wherein, when discarding the second one or more bits of second virtual data in the second address range, the encryption accelerator is configured to: identify the second one or more bits of second virtual data in the second address range based on the length of the second part and an indication of an endpoint of the second data in the second address range, and discard the second one or more bits of second virtual data by at least one of: reading the second one or more bits of second virtual data from the input buffer without processing the second one or more bits of second virtual data, and setting the read pointer to the stored write pointer position associated with storing the second data.

15. A method for encryption, comprising: Store first data in a first address range of an input buffer of an encryption accelerator, the first data including a first part of a message; Store second data in a second address range of the input buffer of the encryption accelerator, the second data including a second part of the message; Determine the lengths of the first part and the second part; Obtain the first part of the first data from the first address range based on the length of the first part and the length of the first data; Identify one or more bits of virtual data in the first address range based on the length of the first part and an indication of an endpoint of the first data in the first address range; Discard the one or more bits of virtual data by at least one of: reading the one or more bits of virtual data from the input buffer without processing the one or more bits of virtual data, and setting the read pointer associated with reading data from the input buffer to the stored write pointer position associated with storing the first data; Obtain the second part of the second data from the second address range based on the length of the second part and the length of the second data; and perform an encryption operation using the first part obtained from the first address range and the second part obtained from the second address range.

16. According to the method of claim 15, wherein, After storing the first data in the first address range and after storing the second data in the second address range, determine the lengths of the first part and the second part.

17. According to the method of claim 15, wherein, Obtaining the first part of the first data from the first address range includes: reading the first part from the first address range based on the length of the first part, and discarding one or more bits of virtual data in the first address range based on the length of the first part and an indication of an endpoint of the first data.

18. According to the method of claim 15, wherein, The one or more bits of virtual data are the first one or more bits of first virtual data, and wherein, obtaining the second part of the second data from the second address range includes: reading the second part from the second address range based on the length of the second part, and Discard one or more second virtual data bits in the second address range based on an indication of an endpoint of the second data in the second address range and the length of the second portion.

19. According to the method of claim 15, wherein, After the first data is stored in the first address range and after the second data is stored in the second address range, determine the length of the first portion and the length of the second portion.

20. According to the method of claim 15, wherein, The indication of the endpoint of the first data in the first address range is based on a byte counter associated with the first data or a stored write pointer position associated with storing the first data.

Citation Information

Patent Citations

  • Data Processing Device And Method For Cryptographic Processing Of Data

    CN108011706A

  • Communication device, cryptographic communication system, cryptographic communication method, and computer program product

    US20170222803A1