Processing system and corresponding method of operation
By introducing dual incomplete FIFO registers into the memory cryptographic engine, the data channel of the slave device is dynamically managed, solving the bus inconsistency problem during mode switching, realizing efficient data transmission on the AXI bus, and improving the stability and performance of the system.
Patent Information
- Application Number
- CN202210538235.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-05-05
- Filing Date
- 2022-05-17
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2042-05-17
AI Technical Summary
In the processing system, when the memory cryptographic engine switches between block cryptography operation mode and stream cryptography operation mode, it is easy to cause inconsistencies and protocol violations on the bus, affecting the stability and efficiency of data transmission.
By introducing a dual incomplete FIFO register in the memory cryptographic engine, the data channel of the slave device is dynamically deferred until the master device completes the processing of the current burst, ensuring the consistency of data transmission on the bus during mode switching, and responding to the master device's processing completion signal by reactivating the read data channel.
It enables dynamic switching between block cipher and stream cipher operation modes, maintains compliance with bus communication protocols, improves the stability and efficiency of data transmission, and saves silicon area and cost.
Smart Images

Figure CN115378593B_ABST
Abstract
Description
Technical Field
[0001] This description relates to the instantaneous decryption of data retrieved from memory devices in a processing system.
[0002] One or more embodiments may be applied to a cryptographic engine that performs data decryption on an AXI (Advanced Extensible Interface) bus. Background Technology
[0003] In a microcontroller unit (MCU) or microprocessor unit (MPU), a master device (e.g., a processing core) can access slave devices (e.g., memory or an interface to external memory) to retrieve data from them via an interconnect such as an AXI bus. The AMBA AXI protocol specification is in... The document "AMBA SYSTEM AXI" is published online. TM and ACE TM The protocol specification is given in "ARMIHI 0022E (ID 033013)".
[0004] For security reasons, data retrieved from a memory device can be encrypted. Therefore, a memory cryptographic engine (MCE) can be coupled to the AXI bus to decrypt (e.g., ciphertext) the data retrieved from memory before forwarding it as plaintext to the master device.
[0005] In some applications, the memory cryptographic engine can operate according to multiple decryption modes (e.g., block cipher mode and stream cipher mode), resulting in different types of data transactions on the AXI bus. The selection of the operating mode can be dynamic, allowing the type of data transaction on the AXI bus to change from time to time, which carries the risk of inconsistency and / or protocol violation. Summary of the Invention
[0006] In one embodiment, the processing system includes: a master device that issues a memory burst transaction request during operation; a slave device that generates data in response to the memory burst transaction request during operation; a cryptographic engine that outputs plaintext data during operation; and an interconnect bus coupled to the master device, the slave device, and the cryptographic engine, wherein the cryptographic engine selectively operates in one of a plurality of operating modes, the plurality of operating modes including a stream cipher operating mode, wherein the data stream generated by the slave device is processed in combinational circuitry of the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus; And a block cipher operation mode, wherein data blocks generated by the slave device are stored in the buffer memory of the cryptographic engine and processed in the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein in response to an indication of a change from the block cipher operation mode to the stream cipher operation mode, the cryptographic engine: suspends the read data channel on the interconnect bus between the slave and master devices; and responds to an indication that the master device has received the last beat of a read burst of plaintext data associated with data blocks stored in the buffer memory by reactivating the read data channel.
[0007] In one embodiment, a method includes: issuing a memory burst transaction request via a master device; generating data by a slave device in response to the memory burst transaction request; processing the data by a cryptographic engine to output plaintext data; and coupling the master device, the slave device, and the cryptographic engine together using an interconnect bus, wherein the cryptographic engine operates selectively according to one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein decrypting the data includes using combinational circuitry of the cryptographic engine to decrypt the data stream generated by the slave device to generate plaintext data provided by the cryptographic engine to the master device via the interconnect bus; and A block cipher operation mode, wherein decrypting the data includes storing a data block generated by the slave device in a buffer memory of the cryptographic engine and processing the data stored in the buffer memory in the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein the method includes: suspending a read data channel on the interconnect bus between the slave device and the master device in response to an indication to change from a stream cipher operation mode to a block cipher operation mode; and reactivating the read data channel in response to an indication that the master device has received the last beat of a read burst of plaintext data associated with a data block stored in the buffer memory.
[0008] In one embodiment, a device includes: an interface; and a cryptographic engine coupled to the interface, wherein the cryptographic engine outputs plaintext data via the interface in operation in response to a memory burst transaction request, wherein the cryptographic engine operates selectively according to one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein the cryptographic engine applies combinational logic to a data stream in operation to produce plaintext data; and a block cipher operating mode, wherein the cryptographic engine applies block processing operations to stored data blocks in operation to produce plaintext data, wherein in response to an indication of a change from the block cipher operating mode to the stream cipher operating mode, the cryptographic engine: suspends a read data channel of the interface; and responds to an indication of receiving the last beat of a read burst of plaintext data associated with a data block processed in the block cipher operating mode by reactivating the read data channel.
[0009] In one embodiment, the content of a non-transitory computer-readable medium causes a cryptographic device to perform a method comprising: selectively operating a cryptographic engine in one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein the cryptographic engine applies combinational logic to a data stream to produce plaintext data; a block cipher operating mode, wherein the cryptographic engine applies block processing operations to stored data blocks to produce plaintext data; and responding to an indication of a change from the block cipher operating mode to the stream cipher operating mode by: suspending a read data channel; and responding to an indication of receiving the last beat of a read burst of plaintext data associated with a data block processed in the block cipher operating mode by reactivating the read data channel.
[0010] Therefore, one or more embodiments can facilitate the dynamic switching of the memory cryptographic engine in the processing system between block cryptographic operation mode and stream cryptographic operation mode, while conforming to the communication protocol requirements of the interconnect bus of the processing system. Attached Figure Description
[0011] One or more embodiments will now be described by way of example only with reference to the accompanying drawings, in which:
[0012] Figure 1 It is an exemplary circuit block diagram of a processing system including a dynamic memory cryptographic engine operating in stream cipher mode;
[0013] Figure 2 This is an exemplary circuit block diagram of a dynamic memory cryptographic engine processing system for processing cryptographic operation modes of the system.
[0014] Figure 3This is an exemplary circuit block diagram of a processing system including a dynamic memory cryptographic engine that can switch between stream cipher operation mode and block cipher operation mode, according to one or more embodiments of this specification.
[0015] Figure 4 This is an exemplary circuit block diagram illustrating the implementation details of a dynamic memory cryptographic engine in a processing system according to one or more embodiments of this specification; and
[0016] Figure 5 This is an example diagram illustrating the time evolution of a signal in a processing system according to one or more embodiments of this specification. Detailed Implementation
[0017] In the following description, one or more specific details are shown to provide a thorough understanding of examples of embodiments described herein. Embodiments may be obtained without one or more specific details, or by utilizing other methods, components, materials, etc. In other instances, known structures, materials, or operations have not been shown or described in detail so as not to obscure certain aspects of the embodiments.
[0018] References to "an embodiment" or "one embodiment" within the framework of this specification are intended to indicate that a particular configuration, structure, or feature described with respect to that embodiment is included in at least one embodiment. Therefore, phrases such as "in an embodiment" or "in one embodiment" that may appear at one or more points in this specification do not necessarily refer to the same embodiment. Furthermore, in one or more embodiments, a particular configuration, structure, or feature may be combined in any suitable manner.
[0019] The title / reference numerals used herein are provided for convenience only and are not intended to limit the scope of protection or the scope of the embodiments.
[0020] In the accompanying drawings, unless the context otherwise requires, the same parts or elements are indicated by the same reference numerals / numbers, and for the sake of brevity, the corresponding descriptions will not be repeated.
[0021] As previously mentioned, in processing systems such as microcontroller units (MCUs) or microprocessor units (MPUs), a cryptographic engine can be used to encrypt (e.g., encrypt and / or decrypt) data provided by slave devices (e.g., external memory controllers) on a communication bus (e.g., an AXI bus) in a dual manner. A first operating mode, known as stream encryption (e.g., counter (CTR) encryption mode), can be used for high-speed communication and general data transmission. A second operating mode, known as block encryption (e.g., electronic codebook (ECB) encryption mode), can be used for secure data transmission. Therefore, depending on the choice of the cryptographic engine's operating mode, data transactions on the bus can be of different types.
[0022] Figure 1 This is an exemplary block diagram of a processing system including a dynamic memory cryptographic engine (MCE) operating in a first operating mode. For example... Figure 1 As shown, the processing system 1 (e.g., an MCU or MPU) may include a master device 10 (e.g., a processing core) and a slave device 20 (e.g., a memory or memory interface) coupled via an interconnect bus 30 (e.g., an AXI bus). The interconnect bus 30 may include an address channel 31 and data channels 32a, 32b. The processing system 1 may include a memory cryptographic engine 40, which is coupled to the interconnect bus 30 and configured to apply Advanced Encryption Standard (AES) encryption (e.g., AES encryption and / or decryption) to data on the bus 30 via an AES engine 41.
[0023] like Figure 1 As shown, the memory cryptographic engine 40 can operate in a first operating mode, such as a stream cipher mode like the counter (CTR) mode. In this operating mode, the master device 10 issues an AXI request on address channel 31, which includes the address of data to be retrieved from slave device 20. The AXI request is propagated to slave device 20 and the AES engine 41 of cryptographic engine 40. AES engine 41 calculates the corresponding keystream based on the data address and applies an XOR operation 42 to the encrypted data retrieved from slave device 20 via data channel 32a and the keystream calculated by AES engine 41. The corresponding plaintext data is returned to master device 10 via data channel 32b. Thus, the encrypted data is XORed (e.g., in a combined manner) with a pre-computed keystream generated based on the data address, while the burst request is propagated to slave device 20 without modification.
[0024] When address channel 31 and data channel 32 are running in parallel Figure 1 The streaming encryption operation mode illustrated here relies on simple and direct data transfer on the AXI bus 30. However, this operation mode may be vulnerable to brute-force attacks on the data bus.
[0025] Figure 2 yes Figure 1An exemplary block diagram of the processing system 1 is provided, wherein the dynamic memory cryptographic engine 40 operates in a second operating mode, such as block cipher mode, or electronic codebook (ECB) mode. In this operating mode, the master device 10 issues an AXI request on address channel 31a, the AXI request including the address of data to be retrieved from the slave device 20. The AXI request is processed in processing block 43 of the memory cryptographic engine 40 to format the request to the block size of the cryptographic engine (e.g., AES engine 41). The formatted AXI request (e.g., address MOD(AES_size)) is propagated to the slave device 20 via address channel 31b. The corresponding data retrieved from the slave device 20 via data channel 32a is stored in a buffer (e.g., register) 44 of the memory cryptographic engine 40. Buffer 44 may have a size equal to AES_size. AES engine 41 decrypts the data stored in buffer 44 and returns the corresponding plaintext data to the master device 10 via data channel 32b.
[0026] Figure 2 The block encryption operation mode illustrated in the example is less susceptible to side-channel attacks (SCA) or brute-force attacks on the data bus, but it is slower than the stream encryption mode because the AES engine introduces additional waiting time for operations on buffered data.
[0027] In such Figure 3 In one or more of the illustrated embodiments, the memory cryptographic engine 40 can dynamically switch between a first operating mode (e.g., stream cipher) and a second operating mode (e.g., block cipher), for example, based on the data address requested by AXI. This approach can be advantageous, for example, when both general-purpose data with a low security level (which can be retrieved from the cryptographic engine with low latency) and secure data with a higher computational latency (which can be retrieved from the cryptographic engine with higher latency) are stored from device 20 (e.g., an interface to external memory). Since the cryptographic engine involves a high gate count (e.g., approximately 16,000 logic gates), using the same engine for both operating modes is particularly advantageous in terms of silicon area.
[0028] Therefore, as Figure 3 As shown, the memory cryptographic engine 40 can switch between a first operating mode and a second operating mode by setting one or more multiplexers to implement stream cipher topology or block cipher topology. As an example, in Figure 3 The gray arrows indicate stream cipher topologies, while the black arrows indicate block cipher topologies.
[0029] Specifically, the memory cryptographic engine 40 may include a first multiplexer 51, which propagates an AXI request (stream cipher topology) issued by the master device 10 or an AXI request (block cipher topology) formatted by the processing block 43 to the slave device 20 via address channel 31b. The memory cryptographic engine 40 may also include a second multiplexer 52, which propagates an AXI request (stream cipher topology) issued by the master device 10 or data retrieved from the slave device 20 and stored in buffer 44 (block cipher topology) to the AES engine 41. Depending on the currently selected operating mode of the memory cryptographic engine 40, the data output by the AES engine 41 may be stored in a first register (which is filled with the key stream generated by the AES engine 41, in...) Figure 3 (not visible in the middle) or the second register (which is filled with plaintext data generated by AES engine 41, in Figure 3 (Not visible in the image). Therefore, the memory cryptographic engine 40 may further include a demultiplexer 53, which propagates the output data from the AES engine 41 to a first register (stream cipher topology) or to a second register (block cipher topology). The first register may feed the XOR processing block 42. The memory cryptographic engine 40 may further include a third multiplexer 54, which propagates the data output from the XOR processing block 42 (stream cipher topology) or the data decrypted by the AES engine 41 and stored in the second register (block cipher topology) to the master device 10 via data channel 32b.
[0030] Note that dynamic switching between the first and second operating modes may introduce inconsistencies and / or protocol violations on bus 30, particularly when switching from block cipher mode to stream cipher mode. This inconsistency may be due to two factors:
[0031] In cases where the data retrieved from slave device 20 in stream cipher mode is streaming and unbufferable, memory cryptography engine 40 may require additional computation time to provide plaintext to master device 10 before slave device 20 accepts the data in stream cipher mode; and / or
[0032] When operating in block cipher mode, the amount of data transmitted from slave device 20 to master device 10 is different when receiving data blocks (e.g., bytes) from AES engine 41, even if the master device only needs one data block.
[0033] Several solutions to the above problems can be considered. One solution might be to restrict the application to using a static selection between stream cipher mode and block cipher mode, but this is not a solution for dynamic traffic management. Another solution might rely on using two separate buses, but this would require additional interconnects and a dedicated AES manager to distribute the cipher engine. Another solution might rely on replicating the cipher engine, as well as replicating the silicon region. Another solution might rely on using the internal buffer 44 also during operation in stream cipher mode. Another solution might rely on pausing the master device 10 when switching from block cipher mode to stream cipher mode to "clear" the read channel for remaining block cipher data transactions. This last solution would impact performance if the slave device had strobed access to external memory.
[0034] In order to improve the management of mixed data transactions on bus 30 when switching the data bus from read buffer 44 to read directly from the slave data channel 32a (e.g., when switching the operation of memory cryptographic engine 40 from block cryptography mode to stream cryptography mode), one or more embodiments may rely on suspending the data channel 32a of slave device 20 until master device 10 has completed reading from slave buffer 44.
[0035] Therefore, one or more embodiments may involve, as Figure 4 The illustrated processing system 1, Figure 4 This is a block diagram example of certain components of the processing system, particularly certain components of the memory cryptographic engine, which is configured to manage mixed data transactions on bus 30 when the memory cryptographic engine switches between block cryptographic operation mode and stream cryptographic operation mode.
[0036] It should be noted that, Figure 4 In this specification, some signals of bus 30 are based on those referenced at the beginning of this specification. The AXI protocol is specified in the references.
[0037] The read address channel signal ARADDR[31:0] originates from master device 10 and represents "read address"; the read address gives the address of the first transmission in a read burst transaction. The read address channel signal ARVALID originates from master device 10 and represents "read address valid"; this signal indicates that the channel is sending a valid read address and control information. The read address channel signal ARREADY originates from slave device 20 and represents "read address ready"; this signal indicates that the slave device is ready to receive the address and associated control signals.
[0038] The RVALIDS signal for reading the data channel originates from slave device 20 and represents "read valid"; this signal, issued by the slave device, indicates that the channel is signaling the need to read data. The RVALIDS signal is the same as the RVALIDS signal received by master device 10. The RDATAS signal for reading the data channel originates from slave device 20 and represents "read data"; this signal, issued by the slave device, carries the data retrieved from slave device 20. The RDATAS signal is the same as the RVALIDS signal received by master device 10 (e.g., provided at the output of multiplexer circuit 54). The RREADY signal for reading the data channel originates from master device 10 and represents "read ready"; this signal, issued by the master device, indicates that the master device can accept read data and a response. The RREADYS signal is the same as the RREADY signal, as received by slave device 20, and may be generated by the memory as discussed below.
[0039] In one or more embodiments, in order to notify (e.g., know) the read channel of bus 30 about the desired management type (e.g., depending on whether MCE40 is expected to operate in stream encryption mode or block encryption mode), information about the desired encryption mode (e.g., stream (CTR) or block (ECB) encryption) can be stored in register 61, specifically in FIFO register 61, also known as the "incomplete FIFO" (incomplete burst). Figure 4 As illustrated, information can be pushed (e.g., enqueued) into FIFO register 61 according to a PUSH signal corresponding to an authorized request (e.g., PUSH = ARVALID and ARREADY). Therefore, information from signal DIN1 = ECB, indicating the desired block encryption mode for the next burst, can be pushed into FIFO register 61 when authorization is requested on the address channel. Information stored in FIFO register 61 can be popped (e.g., dequeued) from FIFO register 61 via signal DOUT1 = ECB according to signal POP1, which indicates that the last data tick has been transmitted to the master device (e.g., POP1 = RLAST and RVALID and RREADY). Signal DOUT1 can be used to control multiplexer circuit 54 such that, depending on the value of signal DOUT1, data transmitted to master device 10 via signal RDATA is data from XOR gate 42 (if the memory cryptographic engine operates in stream cipher mode) or data from AES engine 41 (if the memory cryptographic engine operates in block cipher mode).
[0040] However, in cases where a block cipher (e.g., ECB) burst is followed by a stream cipher (e.g., CTR) burst, storing information about the encryption mode in FIFO register 61 may be insufficient.
[0041] therefore, Figure 4 One or more embodiments illustrated may rely on dynamically pausing stream (e.g., CTR) data from slave device 20 until master device 10 has completed (e.g., fully received) a block burst. To this end, in one or more embodiments, the memory cryptographic engine may include a second register 62, also referred to as the "ECB2STR" register, specifically the FIFO register 62. Information containing the stream cryptographic tag (e.g., CTR tag) for the next burst may be stored in register 62. Figure 4 As illustrated, information can be pushed (e.g., enqueued) into FIFO register 62 according to the same PUSH signal controlling the first FIFO register 61. Therefore, information from the signal DIN2 = CTR, indicating the desired stream encryption mode for the next burst, can be pushed into FIFO register 62 when authorization is requested on the address channel. Information stored in FIFO register 62 can be popped (e.g., dequeued) from FIFO register 62 via the signal DOUT2 = CTR, which depends on the signal POP2 (e.g., POP2 = RLASTS, RVALIDS, and RREADYS) generated at the end of the burst from the slave side at the slave end of the burst. Memory cryptographic engine 40 may include AND gate 63, which receives signals DOUT1 and DOUT2 as input signals and generates corresponding output signals. Memory cryptographic engine 40 may include AND gate 64, which receives an inverted copy of the signal generated by AND gate 63 as a first input, and the RREADY signal from master device 10 as a second input, to generate the RREADYS signal for slave device 20.
[0042] like Figure 4 As shown, Figure 1 - Figure 4 The master device 10, slave device 20, and cryptographic engine 40 may include one or more processors P, one or more memories M, and one or more interfaces I. The one or more processors P and one or more memories M can implement one or more functions associated with the respective devices in operation. For example, the processor P can execute instructions stored in one or more memories M. The interface I can, for example, couple the respective device to an interconnect bus 30.
[0043] Figure 5 These are signals ACLK (e.g., the global clock signal of interconnect bus 30) in one or more embodiments, RVALID, RREADY, RLAST, POP1 (in... Figure 5 In the text, it is represented as "OUTSTANDING_FIFO_POP", DOUT2 (in... Figure 5In the code, it is represented as "ECB2STR_INFO"), RVALIDS, RREADYS, RLASTS, POP2 (in Figure 5 The following is an exemplary timing diagram of the possible behaviors of ECB (represented as "ECB2STR_INFO_POP").
[0044] exist Figure 5 In the process, a new block cipher burst (e.g., an ECB burst) begins at time M1. At time M2, the block cipher burst has been used up by the slave device, not the master device, and the information DOUT2 is popped from FIFO register 62 (e.g., dequeued) to check the encryption type of the next burst. Since the encryption type of the next burst is stream encryption (e.g., CTR), the slave device 20 is deferred (RREADYS = 0) until the master device 10 finishes processing the current block cipher burst. At time M3, the master device 10 receives the last data of the block cipher burst; from this time onwards, the signal RREADYS is no longer deferred (RREADYS == RREADY), and the stream cipher burst can be driven by the slave device 20.
[0045] It should be noted that one or more embodiments can be applied in any situation where the reading channel must switch from reading buffered information to reading the data stream, and therefore it can also be applied when switching to plaintext transactions (e.g., in the case where unencrypted information is stored from device 20, for example, plaintext is stored directly from the device).
[0046] It should also be noted that one or more embodiments can operate with the slave device 20 relying on the use of the AXIID transaction identifier to disable the "out-of-order" feature (a feature of the AXI bus that allows the master device to issue transactions without waiting for earlier transactions to complete).
[0047] Therefore, one or more embodiments may involve an instantaneous decryption engine including "double" incomplete FIFO registers (61, 62), which are also updated based on bursts generated by the slave device to know the encryption type of the next burst before the master device completes the current burst. One or more embodiments may rely on strobing the AXI read channel to allow sufficient time for the master device 10 to complete buffered data transfer. In one or more embodiments, the AES engine 41 may be used alternatively to generate keystream or block encryption; depending on the encryption mode, the output from the memory cryptographic engine may be transmitted to the master device 10, dynamically driven from an internal buffer or the slave device 20.
[0048] One or more embodiments may therefore provide one or more of the following advantages:
[0049] A single IP address and cryptographic engine (e.g., AES engine 41 in memory cryptographic engine 40) can be reused to generate mixed stream-oriented and block-oriented traffic;
[0050] Saves space and costs;
[0051] Easy to configure; and
[0052] Improved performance is achieved by implementing a read channel that only affects bus 30.
[0053] Without violating the basic principles and without departing from the scope of protection, the details and embodiments may vary significantly from what has been described by example only.
[0054] In one or more embodiments, a processing system includes a master device and a slave device coupled via an interconnect bus. The master device is configured to issue a memory burst transaction request via the interconnect bus to retrieve data from the slave device. The processing system includes a cryptographic engine coupled to the interconnect bus and configured to decrypt data retrieved from the slave device to produce plaintext data for the master device. The cryptographic engine operates selectively according to a stream cipher operation mode or a block cipher operation mode, in which a data stream is retrieved from the slave device and processed in combinational circuitry to produce plaintext data, and in a block cipher operation mode, a data block is retrieved from the slave device, stored in a buffer memory of the cryptographic engine, and processed in an encryption engine to produce plaintext data. The cryptographic engine is configured to pause a read data channel on the interconnect bus between the slave device and the master device in response to the cryptographic engine switching from the block cipher operation mode to the stream cipher operation mode. The cryptographic engine is configured to respond to the last beat of a read burst of plaintext data generated by the cryptographic engine and corresponding to a data block received by the master device and stored in the buffer memory by reactivating the read data channel.
[0055] In one or more embodiments, the cryptographic engine may include a first register configured to store information regarding whether a memory transaction request will be processed in a block cipher operation mode for each memory transaction request. The cryptographic engine may switch between the stream cipher operation mode and the block cipher operation mode based on data retrieved from the first register in response to the master device having received all data from a previous memory transaction request.
[0056] In one or more embodiments, the cryptographic engine may include a second register configured to store information about whether the memory transaction request will be processed in stream cipher mode for each memory transaction request. The cryptographic engine may postpone reading the data channel based on data retrieved from the second register in response to the slave device having returned all data from a previous memory transaction request.
[0057] In one or more embodiments, the slave device may include memory and / or an interface to memory outside the processing system.
[0058] In one or more embodiments, the stream cipher operation mode may include a counter operation mode and / or the block cipher operation mode may include an electronic codebook operation mode.
[0059] In one or more embodiments, the cryptographic engine can switch between stream cipher operation mode and block cipher operation mode based on the data address included in the memory transaction request.
[0060] In one or more embodiments, the interconnect bus may operate according to the Advanced Extensible Interface (AXI) protocol.
[0061] In one or more embodiments, a method of operating a processing system according to one or more embodiments may include issuing a memory burst transaction request at a master device via an interconnect bus to retrieve data from a slave device. The method may include decrypting the data retrieved from the slave device to produce plaintext data for the master device. Decrypting the data may include selectively operating a cryptographic engine according to a stream cipher operation mode or a block cipher operation mode. In the stream cipher operation mode, a data stream is retrieved from the slave device and processed in combinational circuitry to produce plaintext data; in the block cipher operation mode, a data block is retrieved from the slave device, stored in a buffer memory of the cryptographic engine, and processed in an encryption engine to produce plaintext data. The method may include suspending a read data channel on the interconnect bus between the slave device and the master device in response to the cryptographic engine switching from the block cipher operation mode to the stream cipher operation mode. The method may include reactivating the read data channel in response to the last beat of a read burst of plaintext data generated by the cryptographic engine and corresponding to a data block received by the master device and stored in the buffer memory.
[0062] In one embodiment, a processing system includes: a master device that issues a memory burst transaction request during operation; a slave device that generates data in response to the memory burst transaction request during operation; a cryptographic engine that outputs plaintext data during operation; and an interconnect bus coupled to the master device, the slave device, and the cryptographic engine, wherein the cryptographic engine selectively operates in one of a plurality of operating modes, the plurality of operating modes including a stream cipher operating mode, wherein the data stream generated by the slave device is processed in combinational circuitry of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master device via the interconnect bus; And a block cipher operation mode, wherein data blocks generated by the slave device are stored in the buffer memory of the cryptographic engine and processed in the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein in response to an indication of a change from the block cipher operation mode to the stream cipher operation mode, the cryptographic engine: suspends the read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received the last beat of a read burst of plaintext data associated with the data blocks stored in the buffer memory by reactivating the read data channel.
[0063] In one embodiment, the cryptographic engine includes a first register that, in operation, stores information regarding whether the memory burst transaction request will be processed in the block cipher operation mode for each of the memory burst transaction requests, and wherein the cryptographic engine switches between the stream cipher operation mode and the block cipher operation mode based on data obtained from the first register in response to an indication that the master device has received all data associated with a previous memory burst transaction request. In another embodiment, the cryptographic engine includes a second register that, in operation, stores information regarding whether the memory transaction request will be processed in the stream cipher operation mode for each of the memory burst transaction requests, and wherein the cryptographic engine postpones the read data channel based on data obtained from the second register in response to a slave device having returned all data from a previous memory burst transaction request.
[0064] In one embodiment, the device includes a memory or an interface to a memory external to the processing system. In one embodiment, the stream cipher operation mode includes a counter operation mode. In one embodiment, the block cipher operation mode includes an electronic codebook operation mode.
[0065] In one embodiment, the cryptographic engine switches between multiple operating modes during operation based on the data address included in the memory burst transaction request. In another embodiment, the interconnect bus operates according to the Advanced Extensible Interface (AXI) protocol.
[0066] In one embodiment, the cryptographic engine's multiple operating modes include a bypass operating mode, wherein a plaintext data stream generated by the slave device is provided to the master device via an interconnect bus. In one embodiment, in response to an indication of a change from block cryptography operating mode to bypass operating mode, the cryptographic engine: suspends the read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received the last tick of a read burst of plaintext data associated with a data block stored in the buffer memory by reactivating the read data channel.
[0067] In one embodiment, a method includes: issuing a memory burst transaction request via a master device; generating data by a slave device in response to the memory burst transaction request; processing the data by a cryptographic engine to output plaintext data; and coupling the master device, the slave device, and the cryptographic engine together using an interconnect bus, wherein the cryptographic engine operates selectively according to one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein decrypting the data includes: decrypting the data stream generated by the slave device using combinational circuitry of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master device via the interconnect bus; and block A cryptographic operation mode, wherein decrypting the data includes: storing a data block generated by the slave device in a buffer memory of the cryptographic engine, and processing the data stored in the buffer memory in the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein the method includes: suspending a read data channel on the interconnect bus between the slave device and the master device in response to an indication to change from a stream cryptographic operation mode to a block cryptographic operation mode; and reactivating the read data channel in response to an indication that the master device has received the last beat of a read burst of plaintext data associated with a data block stored in the buffer memory. In an embodiment, the method includes: for each memory burst transaction request, storing information indicating whether the memory burst transaction request will be processed in the block cryptographic operation mode in a first register; and switching between the stream cryptographic operation mode and the block cryptographic operation mode based on data retrieved from the first register in response to an indication that the master device has received all data associated with a previous memory burst transaction request. In one embodiment, the method includes: for each memory burst transaction request, storing information indicating whether the memory transaction request will be processed in the stream cipher operation mode in a second register; and, in response to the slave device having returned all data from a previous memory burst transaction request, suspending the read data channel based on data obtained from the second register. In one embodiment, the stream cipher operation mode includes a counter operation mode; the block cipher operation mode includes an electronic codebook operation mode; or the stream cipher operation mode includes a counter operation mode, and the block cipher operation mode includes an electronic codebook operation mode. In another embodiment, the method includes: switching the cryptographic engine among multiple operation modes based on a data address included in the memory burst transaction request. In one embodiment, the multiple operation modes of the cryptographic engine include a bypass operation mode, wherein a plaintext data stream generated by the slave device is provided to the master device via an interconnect bus.In one embodiment, the method includes: suspending a read data channel on the interconnect bus in response to an indication of a change from a block cipher operation mode to a bypass operation mode; and reactivating the read data channel in response to an indication that the master device has received the last tick of a read burst of plaintext data associated with a data block stored in the buffer memory.
[0068] In one embodiment, a device includes: an interface; and a cryptographic engine coupled to the interface, wherein the cryptographic engine outputs plaintext data via the interface in response to a memory burst transaction request, wherein the cryptographic engine operates selectively according to one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein the cryptographic engine applies combinational logic to a data stream in operation to produce plaintext data; and a block cipher operating mode, wherein the cryptographic engine applies block processing operations to a stored data block in operation to produce plaintext data, wherein in response to an indication of a change from the block cipher operating mode to the stream cipher operating mode, the cryptographic engine: suspends a read data channel of the interface; and responds to an indication of receiving the last beat of a read burst of plaintext data associated with a data block processed in the block cipher operating mode by reactivating the read data channel. In one embodiment, the cryptographic engine includes a first register that, in operation, stores information regarding whether a memory burst transaction request will be processed in the block cipher operation mode for each of the memory burst transaction requests, and wherein the cryptographic engine switches between the stream cipher operation mode and the block cipher operation mode based on data retrieved from the first register in response to an indication that all data associated with a previous memory burst transaction request has been received. In one embodiment, the cryptographic engine includes a second register that, in operation, stores information regarding whether a memory transaction request will be processed in the stream cipher operation mode for each of the memory burst transaction requests. In one embodiment, the interface couples the cryptographic engine to an interconnect bus in operation. In one embodiment, the interface is an interconnect bus that couples the cryptographic engine to a master device and a slave device in operation. In one embodiment, the multiple operating modes of the cryptographic engine include a bypass operating mode, wherein a plaintext data stream generated by the slave device is provided by the cryptographic engine to the master device via the interconnect bus.
[0069] In one embodiment, the content of a non-transitory computer-readable medium causes a cryptographic device to perform a method comprising: selectively operating a cryptographic engine in one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode, wherein the cryptographic engine applies combinational logic to a data stream to produce plaintext data; a block cipher operating mode, wherein the cryptographic engine performs block processing operations on stored data blocks to produce plaintext data; and responding to an indication of a change from the block cipher operating mode to the stream cipher operating mode by: suspending a read data channel; and responding to an indication of receiving the last beat of a read burst of plaintext data associated with a data block processed in the block cipher operating mode by reactivating the read data channel. In one embodiment, the plurality of operating modes of the cryptographic engine includes a bypass operating mode, wherein the plaintext data stream passes through the cryptographic engine without applying cryptographic processing to the data stream. In one embodiment, the content includes instructions executed by the cryptographic engine.
[0070] Some embodiments may take the form of or include a computer program product. For example, according to one embodiment, a computer-readable medium is provided that includes a computer program adapted to perform one or more of the methods or functions described above. The medium may be a physical storage medium, such as a read-only memory (ROM) chip, or a disk, such as a digital multifunction disc (DVD-ROM), optical disc (CD-ROM), hard disk, memory, network, or a portable media article readable by a suitable drive or via a suitable connection, including one or more barcodes or other related codes encoded on one or more such computer-readable media and readable by a suitable reader device.
[0071] Furthermore, in some embodiments, some or all of these methods and / or functions may be implemented or provided in other ways, such as at least in part in firmware and / or hardware, including but not limited to one or more application-specific integrated circuits (ASICs), digital signal processors, discrete circuits, logic gates, standard integrated circuits, controllers (e.g., by executing appropriate instructions, and including microcontrollers and / or embedded controllers), field-programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), and devices employing RFID technology and various combinations thereof.
[0072] The various embodiments described above can be combined to provide further embodiments. These and other changes can be made to the embodiments based on the detailed description above. Generally, the terminology used in the following claims should not be construed as limiting the claims to the specific embodiments disclosed in the specification and claims, but should be interpreted to include all possible embodiments and the full scope of the authorized equivalents of these claims. Therefore, the claims are not limited to this disclosure.
Claims
1. A processing system comprising: a master device that in operation issues memory burst transaction requests; a slave device that in operation generates data in response to memory burst transaction requests; a cryptographic engine that in operation outputs plaintext data; and an interconnect bus coupled to the master device, the slave device, and the cryptographic engine, wherein the cryptographic engine selectively operates in one of a plurality of operational modes, the plurality of operational modes comprising: a stream cipher operational mode in which a stream of data generated by the slave device is processed in a combinational circuit of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master device via the interconnect bus; and a block cipher operational mode in which a block of data generated by the slave device is stored in a buffer memory of the cryptographic engine and processed in an encryption engine of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein in response to an indication of a change from the block cipher operational mode to the stream cipher operational mode, the cryptographic engine: suspends a read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received a last beat of a read burst of plaintext data associated with a block of data stored in the buffer memory by reactivating the read data channel; wherein the cryptographic engine includes a first register that in operation stores, for each of the memory burst transaction requests, information of whether the memory burst transaction request is to be processed in the block cipher operational mode, and wherein the cryptographic engine switches between the stream cipher operational mode and the block cipher operational mode in accordance with data retrieved from the first register in response to an indication that the master device has received all data associated with a previous memory burst transaction request; and wherein the cryptographic engine includes a second register that in operation stores, for each of the memory burst transaction requests, information of whether the memory transaction request is to be processed in the stream cipher operational mode, and wherein the cryptographic engine suspends the read data channel in accordance with data retrieved from the second register in response to the slave device having returned all data of a previous memory burst transaction request.
2. The processing system of claim 1, wherein the slave device comprises a memory or an interface to a memory external to the processing system.
3. The processing system of claim 1, wherein the stream cipher operational mode comprises a counter operational mode.
4. The processing system of claim 1, wherein the block cipher operational mode comprises a electronic codebook operational mode.
5. The processing system of claim 1, wherein the cryptographic engine in operation switches between operational modes of the plurality of operational modes in accordance with a data address included in the memory burst transaction request. 6. The processing system of claim 1, wherein the interconnect bus operates according to an Advanced eXtensible Interface (AXI) protocol.
7. The processing system of claim 1, wherein the plurality of operating modes of the cryptographic engine includes a bypass operating mode in which a stream of plaintext data produced by the slave device is provided to the master device via the interconnect bus.
8. A processing system comprising: a master device that, in operation, issues memory burst transaction requests; a slave device that, in operation, produces data in response to memory burst transaction requests; a cryptographic engine that, in operation, outputs plaintext data; and an interconnect bus coupled to the master device, the slave device, and the cryptographic engine, wherein the cryptographic engine selectively operates in one of a plurality of operating modes, the plurality of operating modes including: a stream cipher operating mode in which a stream of data produced by the slave device is processed in combinational circuitry of the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus; and a block cipher operating mode in which blocks of data produced by the slave device are stored in buffer memory of the cryptographic engine and processed in an encryption engine of the cryptographic engine to produce plaintext data provided by the cryptographic engine to the master device via the interconnect bus, wherein in response to an indication of a change from the block cipher operating mode to the stream cipher operating mode, the cryptographic engine: suspends a read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received a last beat of a read burst of plaintext data associated with a block of data stored in the buffer memory by reactivating the read data channel; wherein the plurality of operating modes of the cryptographic engine includes a bypass operating mode in which a stream of plaintext data produced by the slave device is provided to the master device via the interconnect bus; wherein in response to an indication of a change from the block cipher operating mode to the bypass operating mode, the cryptographic engine: suspends the read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received a last beat of a read burst of plaintext data associated with a block of data stored in the buffer memory by reactivating the read data channel.
9. A method comprising: issuing, by a master device, memory burst transaction requests; producing, by a slave device, data in response to memory burst transaction requests; processing, by a cryptographic engine, data, outputting plaintext data; and coupling together, using an interconnect bus, the master device, the slave device, and the cryptographic engine, wherein the cryptographic engine selectively operates in one of a plurality of operating modes, the plurality of operating modes including: a stream cipher mode of operation in which decrypting the data comprises decrypting a stream of data generated by the slave using a combinatorial circuit of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master via the interconnect bus; and a block cipher mode of operation in which decrypting the data comprises storing a block of data generated by the slave in a buffer memory of the cryptographic engine and processing the data stored in the buffer memory in an encryption engine to generate plaintext data provided by the cryptographic engine to the master via the interconnect bus; wherein the method comprises: suspending a read data channel of the interconnect bus between the slave and the master in response to an indication to change from the stream cipher mode of operation to the block cipher mode of operation; and reactivating the read data channel in response to an indication that the master has received a last beat of a read burst of plaintext data associated with a block of data stored in the buffer memory; storing, in a first register, information indicating whether the memory burst transaction request is to be processed in the block cipher mode of operation for each memory burst transaction request; switching between the stream cipher mode of operation and the block cipher mode of operation in response to an indication that the master has received all data associated with a previous memory burst transaction request according to data retrieved from the first register; storing, in a second register, information indicating whether the memory transaction request is to be processed in the stream cipher mode of operation for each memory burst transaction request; suspending the read data channel in response to an indication that the slave has returned all data of a previous memory burst transaction request according to data retrieved from the second register.
10. The method of claim 9, wherein: the stream cipher mode of operation comprises a counter mode of operation; the block cipher mode of operation comprises an electronic codebook mode of operation; or the stream cipher mode of operation comprises a counter mode of operation and the block cipher mode of operation comprises an electronic codebook mode of operation.
11. The method of claim 9, comprising: switching the cryptographic engine between modes of operation in the plurality of modes of operation according to a data address included in the memory burst transaction request.
12. The method of claim 9, wherein the plurality of modes of operation of the cryptographic engine comprises a bypass mode of operation in which a stream of plaintext data generated by the slave is provided to the master via the interconnect bus.
13. A method, comprising: issuing a memory burst transaction request by a master; generating data by a slave in response to a memory burst transaction request; processing data by a cryptographic engine, outputting plaintext data; and coupling the master, the slave, and the cryptographic engine together using an interconnect bus, wherein the cryptographic engine selectively operates according to one of a plurality of modes of operation, the plurality of modes of operation comprising: a stream cipher mode of operation in which decrypting the data comprises decrypting a stream of data generated by the slave using a combinatorial circuit of the cryptographic engine to generate plaintext data provided by the cryptographic engine to the master via the interconnect bus; and a block cipher mode of operation in which decrypting the data comprises storing a block of data generated by the slave in a buffer memory of the cryptographic engine and processing the data stored in the buffer memory in an encryption engine to generate plaintext data provided by the cryptographic engine to the master via the interconnect bus. a stream cipher mode of operation in which decrypting the data includes using combinational circuitry of the cryptographic engine to decrypt a data stream generated by the slave to produce plaintext data provided by the cryptographic engine to the master via the interconnect bus; and a block cipher mode of operation in which decrypting the data includes storing a data block generated by the slave in a buffer memory of the cryptographic engine and processing the data stored in the buffer memory in an encryption engine to produce plaintext data provided by the cryptographic engine to the master via the interconnect bus; a bypass mode of operation in which plaintext data stream generated by the slave is provided to the master via the interconnect bus; wherein the method includes: suspending a read data channel of the interconnect bus between the slave and the master in response to an indication of a change from the stream cipher mode of operation to the block cipher mode of operation; suspending the read data channel of the interconnect bus in response to an indication of a change from the block cipher mode of operation to the bypass mode of operation; and reactivating the read data channel in response to an indication that the master has received a last beat of a read burst of plaintext data associated with a data block stored in the buffer memory.
14. An apparatus comprising: an interface; and a cryptographic engine coupled to the interface, wherein the cryptographic engine in operation outputs plaintext data via the interface in response to a memory burst transaction request, wherein the cryptographic engine selectively operates according to one of a plurality of modes of operation, the plurality of modes of operation including: a stream cipher mode of operation in which the cryptographic engine in operation applies combinational logic to a data stream to produce plaintext data; and a block cipher mode of operation in which the cryptographic engine in operation applies a processing operation to a stored data block to produce plaintext data, wherein in response to an indication of a change from the block cipher mode of operation to the stream cipher mode of operation, the cryptographic engine: suspends a read data channel of the interface; and reactivates the read data channel in response to receiving an indication of a last beat of a read burst of plaintext data associated with a data block processed in the block cipher mode of operation; wherein the cryptographic engine includes a first register that in operation stores, for each of the memory burst transaction requests, information whether the memory burst transaction request is to be processed in the block cipher mode of operation, and wherein the cryptographic engine switches between the stream cipher mode of operation and the block cipher mode of operation according to data retrieved from the first register in response to having received an indication of all data associated with a previous memory burst transaction request; wherein the cryptographic engine includes a second register that in operation stores, for each of the memory burst transaction requests, information whether the memory transaction request is to be processed in the stream cipher mode of operation.
15. The device of claim 14, wherein the interface, in operation, couples the cryptographic engine to an interconnect bus.
16. The device of claim 14, wherein the interface is an interconnect bus, the interconnect bus, in operation, coupling the cryptographic engine to a master device and a slave device.
17. A device comprising: an interface; and a cryptographic engine coupled to the interface, wherein the cryptographic engine, in operation, outputs plaintext data via the interface in response to a memory burst transaction request, wherein the cryptographic engine selectively operates according to one of a plurality of operating modes, the plurality of operating modes comprising: a stream cipher operating mode, wherein the cryptographic engine, in operation, applies combinatorial logic to a stream of data to produce plaintext data; and a block cipher operating mode, wherein the cryptographic engine, in operation, applies a processing operation to a stored block of data to produce plaintext data, a bypass operating mode, wherein a stream of plaintext data produced by a slave device is provided by the cryptographic engine to a master device via an interconnect bus, wherein in response to an indication of a change from the block cipher operating mode to the stream cipher operating mode, the cryptographic engine: suspends a read data channel of the interface; and responds to an indication of receipt of a last beat of a read burst of plaintext data associated with a block of data processed in the block cipher operating mode by reactivating the read data channel; wherein in response to an indication of a change from the block cipher operating mode to the bypass operating mode, the cryptographic engine: suspends the read data channel of the interconnect bus between the slave device and the master device; and responds to an indication that the master device has received a last beat of a read burst of plaintext data associated with a block of data stored in a buffer memory by reactivating the read data channel.
18. A non-transitory computer readable medium having contents to cause a cryptographic device to perform a method comprising: selectively operating a cryptographic engine according to one of a plurality of operating modes in response to receiving a memory burst transaction request from a master device, the plurality of operating modes comprising: a stream cipher operating mode, wherein the cryptographic engine applies combinatorial logic to a stream of data produced by a slave device to produce plaintext data; and a block cipher operating mode, wherein the cryptographic engine applies a block processing operation to a stored block of data produced by the slave device to produce plaintext data; and responding to an indication of a change from the block cipher operating mode to the stream cipher operating mode by: suspending a read data channel; and responding to an indication that the master device has received a last beat of a read burst of plaintext data associated with a block of data processed in the block cipher operating mode by reactivating the read data channel, the method comprising: storing, in a first register, information indicating whether the memory burst transaction request is to be processed in the block cipher operating mode for each memory burst transaction request; switching between the stream cipher mode of operation and the block cipher mode of operation according to data retrieved from the first register in response to an indication that the master device has received all data associated with a previous memory burst transaction request; storing, in a second register, information indicating whether the memory transaction request is to be processed in the stream cipher mode of operation for each memory burst transaction request; suspending the read data channel according to data retrieved from the second register in response to the slave device having returned all data of a previous memory burst transaction request.
19. The non-transitory computer readable medium of claim 18, wherein the plurality of modes of operation of the cryptographic engine includes a bypass mode of operation in which a stream of plaintext data passes through the cryptographic engine without cryptographic processing being applied to the stream of data.
20. The non-transitory computer readable medium of claim 18, wherein the content includes instructions for execution by the cryptographic engine.
Citation Information
Patent Citations
Swap circuit for common key block cipher and encryption / decryption circuit including the same
US20100111295A1
Cryptography method and circuit, corresponding device
US20190386816A1
A hardware multiple cipher engine
US20200313860A1
Stream / block cipher crytographic system
US4316055A