Encryption of data exchanged between components in link layer with auto-lock between transmitting component and receiving component

By sending unencrypted training frames between server nodes and encrypting data using encrypted counter blocks generated by counters, the problem of easy leakage of node connections and delayed traditional encryption methods is solved, and security enhancement and authentication mechanisms are simplified.

CN120380718APending Publication Date: 2025-07-25INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380089381.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-29
Filing Date
2023-12-13
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the connection between server nodes is easily accessed by third parties, resulting in leakage of sensitive information. Traditional encryption methods increase data transmission waiting time and lack an authentication mechanism.

Method used

Unencrypted training frames are sent to the receiver through the transmitter and scrambled before transmission, encrypting the frames using the encrypted counter block generated by the counter, including error detection information, simplifying the link retraining process.

Benefits of technology

It realizes enhanced data transmission security between nodes, reduces data transmission delay, simplifies the link retraining process, and provides a data authentication mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120380718A_ABST
    Figure CN120380718A_ABST
Patent Text Reader

Abstract

A method for encrypting a frame transmitted from a transmitter to a receiver includes transmitting a set of unencrypted training frames from the transmitter to the receiver, where each training frame is scrambled and the training frame prior to transmission on an output of a counter of the transmitter, where each scrambled training frame is unencrypted. A control signal from a transmitter is transmitted from the transmitter to a receiver after a training frame. After the control signal is transmitted to the receiver, a frame modified to include error detection information is encrypted using an encryption counter block generated from an output of the counter. The encrypted modified frame is transmitted from the transmitter to the receiver.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The field of the present invention is data processing, or more specifically, methods, apparatuses, and products for encrypting data exchanged between processing cores. Background Art

[0002] The development of the EDVAC computer system in 1948 is generally considered to be the beginning of the computer era. Since then, computer systems have evolved into extremely complex devices. Today's computers are much more complex than earlier systems such as EDVAC. A computer system typically includes a combination of hardware and software components, applications, an operating system, processors, buses, memories, input / output devices, and the like. As semiconductor processing and computer architecture advancements have driven computer performance higher and higher, more complex computer software has been developed to take advantage of the higher performance of the hardware, resulting in today's computer systems being much more powerful than those of just a few years ago.

[0003] Many computing system configurations include one or more servers. A server includes a plurality of nodes connected to each other by links. For example, some nodes of a server are processing cores, other nodes are storage devices, and other nodes provide other functions. Different nodes are typically located in different physical locations and are connected to each other. For example, a node is connected to another node via a network cable or other wired connector. Other types of connections between nodes can be implemented in different configurations.

[0004] However, the connections between the nodes of a server are relatively accessible to third parties to probe or penetrate the computing system. For example, the network cables between nodes are relatively accessible to third parties and provide an entry point for third parties to obtain data from the computing system. The data transmitted through the connection typically includes sensitive information, such as customer or user information, making the connection between nodes a potential vulnerability of the computing system.

[0005] To protect the data communicated through the connections between nodes, the data exchanged through the connections is encrypted in various configurations. However, traditional methods for encrypting data increase the latency of data transmission through the connection by introducing additional time for performing the encryption. In addition, conventional encryption methods involve a retraining counter used for scrambling the data transmitted through the link each time the link is re-established or retrained, and lack an authentication mechanism for the exchanged data. Summary of the Invention

[0006] A method and system for encrypting frames transmitted from a transmitter to a receiver includes transmitting a set of unencrypted training frames from the transmitter to the receiver, where each training frame is scrambled and trained before being transmitted on the output of a counter of the transmitter, and where each scrambled training frame is unencrypted. A control signal from the transmitter is transmitted from the transmitter to the receiver after the training frames. After transmitting the control signal to the receiver, a frame modified to include error detection information is encrypted using an encrypted counter block generated from the output of the counter. The encrypted modified frame is transmitted from the transmitter to the receiver.

[0007] The foregoing and other objects, features, and advantages of the present invention will become apparent from the following more particular description of exemplary embodiments of the invention as illustrated in the accompanying drawings, wherein like reference numerals generally represent like parts of the exemplary embodiments of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 is a block diagram of an example computing environment in accordance with some embodiments of the present invention.

[0009] Figure 2 is a block diagram of an example interconnect architecture in accordance with some embodiments of the present invention.

[0010] Figure 3 is a block diagram of a transmitter of a security implementation module in accordance with some embodiments of the present invention.

[0011] Figure 4 is a block diagram of a scrambler of a transmitter including encryption in accordance with some embodiments of the present invention.

[0012] Figure 5 is a block diagram of a receiver of a security implementation module in accordance with some embodiments of the present invention.

[0013] Figure 6 is a block diagram of a descrambler including decryption of a transmitter in accordance with some embodiments of the present invention.

[0014] Figure 7 is a flowchart of a method for transmitting encrypted frames using a counter used by a transmitter in accordance with some embodiments of the present invention.

[0015] Figure 8 is a flowchart of a method for decrypting received frames after locking a counter in a receiver to a counter in a transmitter in accordance with some embodiments of the present invention. DETAILED DESCRIPTION

[0016] Aspects of the present invention are described by narrative text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in embodiments of a computer program product (CPP). With respect to any flowchart, depending on the technology involved, operations may be performed in an order different from the order shown in a given flowchart. For example, again depending on the technology involved, two operations shown in consecutive flowchart blocks may be performed in reverse order, as a single integrated step, simultaneously, or in a manner that at least partially overlaps in time.

[0017] An embodiment of a computer program product (“CPP embodiment” or “CPP”) is a term used in this disclosure to describe any collection of one or more storage media (also referred to as “media”) jointly included in a set of one or more storage devices, the set of one or more storage devices jointly including machine-readable code corresponding to instructions and / or data for performing the computer operations specified in a given CPP claim. A “storage device” is any tangible device that can retain and store instructions used by a computer processor. By way of non-limitation, computer-readable storage media can be electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, mechanical storage media, or any suitable combination of the foregoing. Some known types of storage devices that include these media include: magnetic disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or pits / lands formed in the main surface of a disc, or any suitable combination of the foregoing. As used in this disclosure, the term computer-readable storage media should not be construed to store in the form of a transient signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, optical pulses passing through an optical fiber cable, or electrical signals transmitted through wires and / or other transmission media. As will be understood by those skilled in the art, during the normal operation of a storage device, such as during access, defragmentation, or garbage collection, data typically moves at some occasional points in time, but this does not make the storage device transient because the data is not transient when it is stored.

[0018] Figure 1The computing environment 100 shown in [figure] includes examples of environments for executing at least some of the computer code involved in performing the methods of the present invention, such as the security implementation module 127. In addition to the security implementation module 127, the computing environment 100 also includes, for example, a computer 101, a wide area network (WAN) 102, an end-user device (EUD) 103, a remote server 104, a public cloud 105, and a private cloud 106. In this embodiment, the computer 101 includes a set of processors 110 (including processing circuitry 120 and a cache 121), a communication fabric 111, volatile memory 112, persistent storage 113 (including an operating system 122 and the security implementation module 127, as described above), a set of peripheral devices 114 (including a set of user interface (UI) devices 123, a storage device 124, and a set of Internet of Things (IoT) sensors 125), and a network module 115. The remote server 104 includes a remote database 130. The public cloud 105 includes a gateway 140, a cloud orchestration module 141, a set of host physical machines 142, a set of virtual machines 143, and a set of containers 144. The computing environment 100 includes examples of environments for executing at least some of the computer code involved in performing the methods of the present invention, such as the security implementation module 127. The security implementation module 127 includes instructions and data for encrypting data transmitted to another device or component and for decrypting data received from another device or component. The security implementation module 127 also includes instructions for synchronizing counters used by the computer 101 and another device (e.g., another computer 101, a processor) to encrypt and decrypt data. In addition to the security implementation module 127, the computing environment 100 also includes, for example, a computer 101, a wide area network (WAN) 102, an end-user device (EUD) 103, a remote server 104, a public cloud 105, and a private cloud 106. In this embodiment, the computer 101 includes a set of processors 110 (including processing circuitry 120 and a cache 121), a communication fabric 111, volatile memory 112, persistent storage 113 (including an operating system 122 and the test module 127, as described above), a set of peripheral devices 114 (including a set of user interface (UI) devices 123, a storage device 124, and a set of Internet of Things (IoT) sensors 125), and a network module 115. The remote server 104 includes a remote database 130. The public cloud 105 includes a gateway 140, a cloud orchestration module 141, a set of host physical machines 142, a set of virtual machines 143, and a set of containers 144.

[0019] The computer 101 may take the form of a desktop computer, a laptop computer, a tablet computer, a smart phone, a smart watch or other wearable computer, a mainframe computer, a quantum computer, or any other form of computer or mobile device now known or developed in the future that is capable of running a program, accessing a network, or querying a database (such as the remote database 130). As is well understood in the field of computer technology and depending on the technology, the execution of a computer-implemented method may be distributed among multiple computers and / or among multiple locations. On the other hand, in this presentation of the computing environment 100, the discussion focuses on a single computer, specifically the computer 101, to keep the presentation as simple as possible. The computer 101 may be located in the cloud, even if it is not shown in the Figure 1 cloud in the figure. On the other hand, the computer 101 is not required to be in the cloud to any degree other than what may be affirmatively indicated.

[0020] The processor set 110 includes one or more computer processors of any type now known or developed in the future. The processing circuit 120 may be distributed across multiple packages, e.g., multiple coordinated integrated circuit chips. The processing circuit 120 may implement multiple processor threads and / or multiple processor cores. The cache 121 is a memory located within the (one or more) processor chip packages and is generally used for data or code that should be made available for rapid access by threads or cores running on the processor set 110. Cache memory is typically organized into multiple levels based on its relative proximity to the processing circuit. Alternatively, some or all of the cache for the processor group may be located "off-chip". In some computing environments, the processor set 110 may be designed to work with qubits and perform quantum computing.

[0021] Computer-readable program instructions are generally loaded onto the computer 101 to cause the processor set 110 of the computer 101 to execute a series of operational steps to implement a computer-implemented method such that the instructions so executed will instantiate the method specified in the flowchart and / or the narrative description of the computer-implemented method included in this document (collectively referred to as "the method of the present invention"). These computer-readable program instructions are stored in various types of computer-readable storage media, such as the cache 121 and other storage media discussed below. The program instructions and associated data are accessed by the processor set 110 to control and direct the execution of the method of the present invention. In the computing environment 100, at least some of the instructions for executing the method of the present invention may be stored in the secure implementation module 127 in the persistent storage device 113.

[0022] The communication structure 111 is a signal conduction path that allows various components of the computer 101 to communicate with each other. Generally, this structure is made up of switches and conductive paths, such as those that make up a bus, a bridge, a physical input / output port, etc. Other types of signal communication paths can be used, such as fiber optic communication paths and / or wireless communication paths.

[0023] The volatile memory 112 is any type of volatile memory known now or developed in the future. Examples include dynamic type random access memory (RAM) or static type RAM. Generally, the volatile memory 112 is characterized by random access, but this is not required unless affirmatively indicated. In the computer 101, the volatile memory 112 is located in a single package and inside the computer 101, but alternatively or additionally, the volatile memory can be distributed over multiple packages and / or be located external to the computer 101.

[0024] The persistent storage device 113 is any form of non-volatile storage device for a computer known now or developed in the future. The non-volatility of this storage device means that the stored data is retained whether or not power is supplied to the computer 101 and / or directly to the persistent storage device 113. The persistent storage device 113 can be a read-only memory (ROM), but generally at least a portion of the persistent storage device allows data to be written, deleted, and rewritten. Some familiar forms of the persistent storage device include magnetic disks and solid state storage devices. The operating system 122 can take several forms, such as various known proprietary operating systems or open source portable operating system interface type operating systems that employ a kernel. The code included in the security implementation module 127 generally includes at least some of the computer code involved in performing the method of the present invention.

[0025] The peripheral device set 114 includes a collection of the peripheral devices of the computer 101. The data communication connections between the peripheral devices and the other components of the computer 101 can be implemented in various ways, such as a Bluetooth connection, a Near Field Communication (NFC) connection, a connection by a cable (such as a Universal Serial Bus (USB) type cable), a plug-in connection (e.g., a Secure Digital (SD) card), a connection through a local communication network, and even a connection through a wide area network (such as the Internet). In various embodiments, the UI device set 123 may include components such as a display screen, a speaker, a microphone, wearable devices (such as goggles and smart watches), a keyboard, a mouse, a printer, a touchpad, a game controller, and a haptic device. The storage device 124 is an external storage device, such as an external hard disk drive, or a pluggable storage device, such as an SD card. The storage device 124 can be persistent and / or volatile. In some embodiments, the storage device 124 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where the computer 101 needs to have a large amount of storage (e.g., in the case where the computer 101 locally stores and manages a large database), the storage may be provided by a peripheral storage device designed to store a very large amount of data, such as a Storage Area Network (SAN) shared by multiple geographically distributed computers. The IoT sensor set 125 consists of sensors that can be used in Internet of Things applications. For example, one sensor can be a thermometer, while another sensor can be a motion detector.

[0026] The network module 115 is a collection of computer software, hardware, and firmware that allows the computer 101 to communicate with other computers via the WAN 102. The network module 115 may include hardware (such as a modem or a Wi-Fi signal transceiver), software for packetizing and / or depacketizing data for communication network transmission, and / or web browser software for transmitting data over the Internet. In some embodiments, the network control function and the network forwarding function of the network module 115 are executed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software Defined Network (SDN)), the control function and the forwarding function of the network module 115 are executed on physically separate devices, such that the control function manages several different network hardware devices. The computer-readable program instructions for performing the methods of the present invention can generally be downloaded to the computer 101 from an external computer or an external storage device through a network adapter card or a network interface included in the network module 115.

[0027] Wide area network (WAN) 102 is any wide area network (e.g., the Internet) capable of transmitting computer data over non-local distances by any technology now known or later developed for transmitting computer data. In some embodiments, WAN 102 may be replaced and / or supplemented by a local area network (LAN) (such as a Wi-Fi network) designed to transmit data between devices located in a local area. A WAN and / or a LAN typically includes computer hardware such as copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.

[0028] End user device (EUD) 103 is any computer system used and controlled by an end user (e.g., a customer of an enterprise operating computer 101), and may take any form discussed above in connection with computer 101. EUD 103 typically receives helpful and useful data from the operation of computer 101. For example, in the hypothetical case where computer 101 is designed to provide recommendations to an end user, the recommendation will typically be transmitted from network module 115 of computer 101 to EUD 103 via WAN 102. In this way, EUD 103 can display or otherwise present the recommendation to the end user. In some embodiments, EUD 103 may be a client device such as a thin client, a heavy client, a mainframe computer, a desktop computer, etc.

[0029] Remote server 104 is any computer system that provides at least some data and / or functionality to computer 101. Remote server 104 may be controlled and used by the same entity operating computer 101. Remote server 104 represents a machine that collects and stores useful and helpful data for use by other computers such as computer 101. For example, in the hypothetical case where computer 101 is designed and programmed to provide recommendations based on historical data, the historical data may be provided to computer 101 from remote database 130 of remote server 104.

[0030] A public cloud 105 is any computer system available for use by multiple entities that provides on-demand availability of computer system resources and / or other computing capabilities, particularly data storage (cloud storage) and computing power, without direct active management by the user. Cloud computing typically exploits resource sharing to achieve consistency and economies of scale. The direct and active management of the computing resources of the public cloud 105 is performed by the computer hardware and / or software of the cloud orchestration module 141. The computing resources provided by the public cloud 105 are typically implemented by virtual computing environments running on various computers of a set of host physical machines 142, which is the totality of the physical computers in and / or available for the public cloud 105. The virtual computing environment (VCE) typically takes the form of virtual machines from a set of virtual machines 143 and / or containers from a set of containers 144. It should be understood that these VCEs can be stored as images and can be transferred among and between various physical machine hosts either as images or after instantiation of the VCE. The cloud orchestration module 141 manages the transfer and storage of the images, deploys new instantiations of the VCE, and manages the active instantiations of the VCE deployments. The gateway 140 is a collection of computer software, hardware, and firmware that allows the public cloud 105 to communicate via the WAN 102.

[0031] Some further explanations of the virtual computing environment (VCE) will now be provided. A VCE can be stored as an "image". New active instances of a VCE can be instantiated from the image. Two common types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature where the kernel allows for the existence of multiple isolated user space instances (called containers). From the perspective of the programs running within them, these isolated user space instances typically appear as real computers. A computer program running on a normal operating system can utilize all the resources of that computer, such as connected devices, files and folders, network shares, CPU capabilities, and quantifiable hardware capabilities. However, a program running within a container can only use the contents of the container and the devices allocated to the container, which is a characteristic known as containerization.

[0032] The private cloud 106 is similar to the public cloud 105, except that the computing resources are only available to a single enterprise. Although the private cloud 106 is depicted as communicating with the WAN 102, in other embodiments, the private cloud can be completely disconnected from the Internet and only accessible through a local / private network. A hybrid cloud is a combination of multiple clouds of different types (e.g., private cloud, community cloud, or public cloud type) that are typically implemented by different providers. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is bound together by standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the multiple constituent clouds. In this embodiment, both the public cloud 105 and the private cloud 106 are part of a larger hybrid cloud.

[0033] For further illustration, Figure 2 An example of a layered protocol stack used by one or more computers (such as computer 101) to send and receive data is shown. Examples of layered protocol stacks include a Peripheral Component Interconnect Express (PCIe) stack, a QuickPath Interconnect (QPI) stack, or other types of layered protocol stacks. In Figure 2 the example shown, the layered protocol stack includes a transaction layer 205, a link layer 210, and a physical layer 215. In other embodiments, additional layers may be included in the layered protocol stack. An interface for a computer 101 or for a processing core of a computer 101 (e.g., a processor in the processor set 110) to exchange data with another device (e.g., another computer 101, another processing core) may be represented as a layered protocol stack, such as Figure 2 shown.

[0034] Data packets carrying information from a sending device to a receiving device are formed by the transaction layer 205 and the link layer 210. Different layers add different information to the data packets. After being formed in the transaction layer 205 and the link layer 210, the data packets are sent from the sending device to the receiving device using the physical layer 215. The receiving device receives the data packets from the physical layer 215, where the layers after the physical layer 215 modify the data packets based on the information in the data packets until the data packets reach the transaction layer 205. Then, the transaction layer 205 of the receiving device processes the data packets.

[0035] The transaction layer 205 provides an interface between the processing core of a device (e.g., the processor set 110 of computer 101) and an interconnect architecture that includes the link layer 210 and the transaction layer 215. The transaction layer 215 assembles packets for transmitting data and disassembles the packets of the received data. For example, the transaction layer 215 assembles the packet headers and packet payloads of the data. In some embodiments, the transaction layer 215 assembles the packets based on a specification that describes the content and structure of the packets. An example specification for assembling packets is the PCIe specification.

[0036] The link layer 210 is between the transaction layer 205 and the physical layer 215. The link layer 210 provides a mechanism for exchanging packets between different components over a link. In various embodiments, the mechanism provided by the link layer 210 has at least a threshold reliability. As described below in connection with Figure 3 As further described, a portion of the link layer receives data packets from the transaction layer 205, applies information identifying the packet sequence to the packets, generates error correction information and includes it in the packets, and transmits the packets including the sequence information and the error correction information to the physical layer 215.

[0037] The physical layer 215 sends packets across a physical medium from the link layer 210 to another component or device. The physical layer 215 prepares outgoing packets for transmission and identifies and prepares incoming packets before routing the incoming packets to the link layer 210. Thus, the physical layer 215 provides a transmitter and a receiver. The transmitter of the physical layer 215 serializes data packets from the link layer 210 and sends the serialized packets to another device or component. For example, the physical layer 215 transmits serialized packets from a processing core to another processing core via a network cable or another type of physical connection. Additionally, the physical layer 215 includes a receiver that receives packets from a physical connection (e.g., from another device or component via a physical connection), where the packets are then deserialized and assigned to frames provided to the link layer 210.

[0038] Thus, in various embodiments, the layered protocol stack described in connection with Figure 2 includes a layer (the transaction layer 205) that assembles packets from data received from a processor core. Another layer (the link layer 210) sorts the assembled packets. An additional layer (the physical layer 215) uses a physical connection to send a sequence of the assembled packets to another processor core or other device. As described below in connection with Figures 3 to 7 As further described, encrypting data in the link layer 210 allows the data to be protected when it is transmitted through the physical layer 215.

[0039] The security implementation module 127 includes a transmitter and a receiver. The transmitter allows the security implementation module 127 to send data from a processor core (such as a processor from the processor set 110), and the receiver allows the security implementation module 127 to receive data from a device or component. As described below in connection with Figure 3 As further described, the transmitter encrypts data from the transaction layer 205 to prevent unauthorized access to the data when it is sent via a physical connection. As described below in connection with Figure 4 As further described, the receiver decrypts data from the physical layer 215 and routes the decrypted data to the transport layer 205.

[0040] Refer to Figure 3, a block diagram showing an example transmitter of the security implementation module 127. Figure 3 The transmitter shown in Figure 3 includes a frame buffer 305, an error detection module 310, and one or more channel transmission modules 315. The channel configuration module 315 includes a scrambler 320 and a synchronization module 325. In other embodiments, the transmitter includes modules that are different from or additional to the modules described in connection with

[0041] For illustrative purposes, Figure 3 the transmitter shown in

[0042] receives data from a processing core (e.g., a processor). However, in other embodiments, the transmitter receives data from another component. The data received by the transmitter is received by the frame buffer 305, which generates a queue of packets received by the transmitter. This allows the transmitter to form frames including the data packets received by the transmitter. In different embodiments, the frame buffer 305 includes a different number of data packets in the frame.

[0043] The output of the frame buffer 305, which is a frame of packets (e.g., a group), is received by the error detection module 310. The error detection module 310 generates error detection information for the frame included in the frame. The error detection information is included in the frame together with the data from the packet to allow detection of changes in the data included in the frame during transmission. In various embodiments, the error detection information is a cyclic redundancy check (CRC) code, where the error detection module 310 appends the CRC code to the frame. In other embodiments, the error detection module 310 generates other types of error detection information that allow a receiving device to identify errors in the frame and appends the error detection information to the frame.

[0044] The channel configuration module 315 includes a scrambler 320 and a synchronization module 325. The scrambler 320 receives a frame including error detection information from the error detection module 310. The scrambler 320 modifies the frame before transmission to simplify the receiving device to recover timing information and data from the frame. In various embodiments, the scrambler increases the number of transitions from a logical high value to a logical low value or from a logical low value to a logical high value in the frame. The increased number of transitions between values allows the receiver to better recover data and clock information from the frame. For example, the scrambler 320 is an additive scrambler, where a linear feedback shift register generates a pseudo-random binary sequence as a seed value. The scrambler performs a serial XOR operation with the seed value output from the linear feedback shift register and the frame including error detection information.

[0045] Compared with traditional scramblers, Figure 3 the scrambler 320 encrypts data. In various embodiments, the scrambler 320 encrypts data using the Advanced Encryption Standard (AES). In other embodiments, other block cipher encryption methods or other encryption methods are used to encrypt data. In various embodiments, the scrambler uses block cipher encryption in counter mode, where a counter generates a key stream that is combined with the unencrypted data from the frame to encrypt the frame. For example, the counter is a linear feedback shift register. In various embodiments, a reversible operation (e.g., XOR, concatenation, addition) is used to combine the counter with a starting value to generate a unique counter block. The counter block is encrypted with a key using AES or another block cipher encryption method, where the encrypted counter block is used to encrypt the frame. For example, an XOR operation is used to combine the encrypted counter block with the frame to generate an encrypted frame.

[0046] Reference Figure 4 , a block diagram of an embodiment of the scrambler 320 is shown. In Figure 4 the example, the scrambler 320 includes a linear feedback shift register (LFSR) 405, an encryption module 410, a selector 415, and an XOR module 425. However, in other embodiments, the scrambler includes components different from or additional to those described in conjunction with Figure 4 description.

[0047] In various embodiments, the scrambler 320 uses block cipher encryption to encrypt data, such as a frame. For example, the scrambler 320 encrypts data using the Advanced Encryption Standard (AES). In other embodiments, other block cipher encryption methods or other encryption methods are used to encrypt data. Figure 4 The scrambler 320 shown in Figure 4Examples include LFSR 405 as a counter. The LFSR 405 of the scrambler 320 runs freely, so the LFSR 405 continuously increments, providing new values for encryption, where the number of possible values is based on the bit width of the LFSR 405. In other embodiments, other types of counters may be used, where the counter continuously increments.

[0048] The output of the LFSR 405 (or other counter) is received by the encryption module 410, which combines the output of the LFSR 405 with the starting value using reversible operations (e.g., XOR, concatenation, addition) to produce a unique counter block. The encryption module 410 encrypts the counter block using a key with AES or another block cipher encryption method. The encrypted counter block is output from the encryption module 410 and used to encrypt frames, as described further below.

[0049] The LFSR 405 and the encryption module 410 are coupled to the selector 415. Based on the control signal 420, the selector 415 selects the output of the LFSR 405 or the encryption module 410, which is received as an input to the XOR module 425. In response to the control signal 420 having a first value, the selector 415 couples the output of the LFSR 405 to the XOR module 425, while in response to the control signal 420 having a second value, the selector 415 couples the output of the encryption module 410 to the XOR module 425. In various embodiments, when the scrambler 320 operates in the training mode, the control signal 420 has the first value, in which the frame data is sent without encryption (i.e., in plain text). In the training mode, the scrambler 320 does not encrypt the frames, and the frames sent during the training mode are from a set of training frames. Instead, during the training mode, the output of the LFSR 405 is combined with the frame using the XOR module 425, which performs an exclusive OR operation on the bits of the LFSR 405 output and the bits of the frame to increase the number of transitions between logical high and logical low values in the frame before transmission, thus simplifying the recovery of timing information and data from the frame by the receiving device. The set of training frames is sent in a specific sequence determined by the order of the training frames in the set, which, in various embodiments, allows the receiving device to maintain the expected values of different frames. As described further below, sending training frames with expected values to the receiving device allows the counter (e.g., LFSR) of the receiving device to synchronize or lock with the LFSR 405 during the training mode. This allows the training mode to simplify the synchronization of the LFSR 405 and the counter of the receiving device.

[0050] When a counter is used to encrypt frames and the counter of the transmitter and the counter of the receiver are not synchronized, the receiver cannot accurately decrypt the encrypted frames. This synchronization of the transmitter's counter and the receiver's counter is referred to as "locking" the transmitter's counter and the receiver's counter. In a conventional embodiment, when retraining the link between the transmitter and the receiver, the transmitter's counter and the receiver's counter are renegotiated or refreshed, thus introducing additional complexity and computational resources. The training mode described above allows the training frames to be sent in plaintext while being scrambled using the output of the LFSR 405, thus allowing the receiver to determine the value of the receiver's counter synchronized with the LFSR 405 of the scrambler based on the received training frames and the expected values of the frames.

[0051] In response to the control signal 420 having a second value, the selector 415 couples the output of the encryption module 410 to the XOR module 425, and the XOR module 425 combines the output of the encryption module 410 with the frame using an exclusive OR operation on the bits of the frame and the bits of the output of the encryption module 410. This combines the encrypted counter block output by the encryption module 410 with the frame using the XOR module 425 to generate an encrypted frame. The encrypted frame is then output from the scrambler 320 and sent via the physical layer 215 to a receiving device or component, as described above in connection with Figure 2 further described.

[0052] Using the output of the LFSR 405 (or another counter) as the input to the encryption module 410 allows the frames to be encrypted before transmission while simplifying the retraining of the link between the transmitter and the receiver by using the output of the LFSR 405 instead of the output of the encryption module 410 to modify the training mode of the frames. Additionally, using a continuously incrementing (or "free-running") LFSR 405 prevents the encryption module 410 from receiving duplicate inputs. Additionally, making the LFSR 405 input the input to the encryption module 410 allows the frame data to be encrypted without introducing additional latency for encryption.

[0053] Return reference Figure 3 , the frame output by the scrambler 320 is input to the synchronization module 325. The synchronization module 325 appends a synchronization header to the frame. Additionally, in various embodiments, the synchronization module 325 encodes information identifying the boundaries between packets in the frame to simplify the identification of the packets including the frame. When the scrambler 320 operates in the training mode, the synchronization module 325 receives an unencrypted frame including error detection information from the scrambler 320. However, when the scrambler 320 does not operate in the training mode, the synchronization module 325 receives an encrypted frame including error detection information. The output of the synchronization module 325 is sent via the physical layer 215 to a receiving device, such as a processor core.

[0054] Although Figure 3 andFigure 4 Describes a transmitter of the security implementation module 127 for sending data from the security implementation module 127, but the security implementation module 127 also includes a receiver for receiving data from another device. Figure 5 Is a block diagram of the receiver of the security implementation module 127. In Figure 5 The illustrated example, the receiver includes a set of channel receivers 500, an error detection module 515, and a layer preparation module 505. However, in other embodiments, the receiver includes modules different from or additional to the Figure 5 modules shown therein.

[0055] In various embodiments, the receiver includes a channel receiver 500 for each channel including a physical layer. This allows the receiver to receive multiple data frames in parallel from different channels. One or more channels may not include frames. In Figure 5 the illustrated example, the channel receiver 500 includes a synchronization module 505 and a descrambler 510. In other embodiments, the channel receiver includes components additional to or different from the Figure 5 components shown therein. The descrambler 510 receives data frames from the physical layer.

[0056] The synchronization module 505 aligns the frames received from the transmitter. In various embodiments, the synchronization module 505 of the transmitter extracts the synchronization header appended to the frame by the synchronization module 325 of the transmitter. The synchronization module 505 of the transmitter uses the information from the synchronization header to identify the boundaries between packets and to identify the packets including the frames.

[0057] In addition, the synchronization module 505 offsets the propagation delay when receiving frames. The propagation delay can be introduced from different path lengths of different channels of the communication channel from which the receiver receives the frames, or from control signals added by the receiver to the received frames. These delays introduce skew into the received frames, and the synchronization module 505 includes one or more skew correction methods applied to the received frames. The one or more skew correction methods align the received frames to cancel the propagation delay from the reception of the frames. Different skew correction methods can be used in different embodiments, where one or more skew correction methods are applied to the frames before the frames are sent to the descrambler 510.

[0058] Refer to Figure 6 , a block diagram of one embodiment of the descrambler 510 is shown. In Figure 6 the example of, the descrambler 510 includes an XOR module 605, a linear feedback shift register (LFSR) 615, an encryption module 620, and a selector 625. In other embodiments, the descrambler 510 includes components different from or additional to the Figure 5 components described in connection with

[0059] The XOR module 605 receives the frame from the physical layer and the output of the selector 625. The XOR module 605 performs an exclusive - OR operation on the bits of the received frame and the bits of the output of the selector 625. The output of the XOR module 605 is the output of the descrambler 510 and is routed to the error detection module 515 through the synchronization module 520.

[0060] The selector 625 selects the output of the LFSR 615 or the output of the encryption module 620 based on the encryption status signal 610. The encryption status signal 610 is received by the receiver from the transmitter. The first value of the encryption status signal 610 indicates that the receiver is receiving an unencrypted or plain - text frame, while the second value of the encryption status signal 610 indicates that the receiver is receiving an encrypted frame. When the encryption status signal has the first value indicating that the transmitter is sending encrypted data. In various embodiments, the first value indicating the reception of an unencrypted frame is the default value of the encryption status signal 610, and in response to receiving a control packet from the transmitter, the encryption status signal 610 changes to the second value indicating the reception of encrypted data. In some embodiments, the transmitter sends control data packets on all channels between the transmitter and the receiver, and the receiver determines that the control data packet is received in response to at least a threshold number of channels receiving the control data packet. For example, the receiver sets the encryption status signal 610 to the second value indicating the reception of encrypted data in response to a majority of channels receiving the control packet. When the encryption status signal 610 has the second value, the descrambler 510 determines that the received frame is encrypted and couples the output of the encryption module 620 to the XOR module 605.

[0061] When the encryption status signal 610 has the first value indicating that the frame is not encrypted, the descrambler 510 operates in a training mode for receiving unencrypted frames. As described above in connection with Figure 5Further described, the frame data is sent without encryption in the training mode. Thus, the descrambler 510 receives the unencrypted training frames from the set of training frames. The transmitter and the receiver store the set of training frames and the order in which the training frames are sent, thereby allowing the receiver to maintain the expected value of each training frame of the set. During the training mode, the descrambler performs an exclusive OR (XOR) operation on the bits of the received initial training frame and the bits of the expected value of the initial training frame. The result of the XOR operation of the received initial training frame and the expected value of the initial training frame is provided to the LFSR 615 (or other counter) to provide the initial value of the LFSR 615. The LFSR continuously increments from the initial value. For the training frames subsequently received while in the training mode, the descrambler 510 provides the output of the LFSR 615 to the XOR module 605, and the XOR module 605 performs an XOR operation on the output of the LFSR 615 and the received training frame. The descrambler 510 compares the output of the XOR module 605, which is the descrambled received training frame, with the expected value of the received training frame. In response to a threshold number of training frames received after the initial training frame matching the corresponding expected value of the training frame after being descrambled, the descrambler 510 determines that the LFSR 615 of the descrambler 510 is locked with the LFSR 405 of the scrambler 320. In the case where the LFSR 615 of the descrambler 510 is locked with the LFSR 405 of the scrambler 320, the descrambler 510 is able to decrypt the frames subsequently received from the physical layer. When the training mode ends, the scrambler 320 uses multiple channels to send a control packet to the descrambler 510, where receiving the control packet sets the encryption status signal 610 to a value indicating that encrypted frames are being received (e.g., the second value in the above example).

[0062] The LFSR 615 is also coupled to an encryption module 620, and the encryption module 620 is also coupled to a selector 625. The encryption module 620 combines the output of the LFSR 615 with a starting value using reversible operations (e.g., XOR, concatenation, addition) to produce a unique counter block. The encryption module 620 encrypts the counter block using a key with AES or another block cipher encryption method. The encrypted counter block is output from the encryption module 620 and is used to decrypt the received frames. To decrypt the received frames, the selector 625 couples the output of the encryption module 620 (the encrypted counter block) to the XOR module 605, and the XOR module 605 performs an XOR operation on the received frame and the encrypted counter block. When the received frame is encrypted, the XOR operation with the encrypted counter block decrypts the received frame. As described above in connection with Figure 3 and Figure 4 Further described, the received frame includes error detection information. Thus, decrypting the received frame results in decrypted data from the frame and error detection information from the frame. The decrypted frame including error correction information is output from the XOR module 605 to the error detection module 515.

[0063] Return reference Figure 5 The error detection module 515 receives the decrypted frame from the descrambler, where the decrypted frame includes error detection information. The error detection module 515 applies one or more error detection methods to the error detection information to determine whether the decrypted frame includes an error. For example, the error detection module 515 generates a check value from the decrypted frame and compares the check value with the error detection information included in the frame. If the check value is different from the error detection information included in the frame, the error detection module 515 determines that the frame includes one or more errors from the transmission. Conversely, if the check value matches the error detection information included in the frame, the error detection module 515 determines that the frame was received without errors from the transmission. In other embodiments, the error detection module 515 determines whether the remainder from dividing the frame containing the error detection information by the divisor used by the error detection module 310 of the transmitter is zero. If the remainder is zero, the error detection module 515 determines that the frame does not include an error, and if the remainder is not zero, the error detection module 515 determines that the frame includes an error. In some embodiments, the error detection module 515 performs one or more error correction processes on the frame in which an error is detected, or in other embodiments, the error detection module 515 initiates a request to the transmitter to retransmit the frame including the error.

[0064] The frame determined to not include an error is sent from the error detection module 515 to the layer preparation module 520. The layer preparation module 520.

[0065] Check the integrity of the packets included in the frame from the layer preparation module 520 and send the packets and the description of the packets to the transaction layer 205 for routing to the processing core or another receiving device.

[0066] For further illustration, Figure 7 A flowchart depicting an example method for transmitting an encrypted frame using a counter used by a transmitter is shown. Figure 7 The method shown in includes a training mode that synchronizes the counter of the transmitter and the counter of the receiver. Compared to the conventional method in which the counter of the receiver and the counter of the receiver are refreshed to a common value for synchronization when refreshing the link between the transmitter and the receiver, Figure 7 the method allows for automatic synchronization of the counter of the receiver and the counter of the transmitter when retraining the link. Additionally, Figure 7 the method encrypts the data after adding the error detection information, thus providing increased security against active attacks, where the active attack modifies the data transmitted between the transmitter and the receiver, since such modifications introduce errors into the data introduced by the modification.

[0067] A transmitter (such as in conjunction with Figure 3The described transmitter) sends 705 an initial training frame to the receiver when in a training mode. The initial training frame is unencrypted and is included in a set of training frames, where the training frames have values known to the transmitter and the receiver. The training frames are also transmitted in an order specified by the set, allowing the receiver to determine the expected values of the training frames. The transmitter scrambles the initial training frame before transmission, as described above in connection with Figure 3 and Figure 4 further described. For example, the transmitter combines the training frame with the output of a counter, such as a linear feedback shift register (LFSR), to increase the number of transitions between the values of the initial training frame. The counter is free-running, so the counter continuously increments. For example, the transmitter performs an exclusive OR operation on the initial training frame and the output of the counter, and the result of the exclusive OR operation is sent 705 from the transmitter to the receiver.

[0068] As described below in connection with Figure 8 further described, the receiver uses the initial training frame to determine the initial value of the receiver's counter. Subsequently, the transmitter sends 710 additional training frames from the set after scrambling each of the additional training frames. When the additional training frames of the set are unencrypted, each of the additional training frames is scrambled based on the output of the transmitter's counter. As the transmitter's counter continuously increments, different values of the transmitter's counter are used to scramble different additional training frames sent 710 at different times. In various embodiments, the initial training frame and the additional training frames each include error detection information that is added to the initial training frame and one or more additional training frames before scrambling the training frames.

[0069] After transmitting the set of training frames, or after transmitting at least a threshold amount of the set of training frames, the transmitter sends 715 a control signal to the receiver. The control signal identifies the time point at which the transmitter begins to send encrypted frames to the receiver. As described below in connection with Figure 8 further described, in response to receiving the control signal, the receiver configures itself to decrypt the frames received after receiving the control signal. In various embodiments, the transmitter sends 715 the control signal across multiple channels that form a communication link between the transmitter and the receiver. Sending 715 the control signal across multiple channels provides redundancy against bit errors of the control signal that occur during transmission, thereby increasing the likelihood that the receiver receives the control signal.

[0070] The transmitter modifies 720 the frame to include error detection information. For example, the transmitter appends the error detection information to the data included in the frame. In various embodiments, the error detection information includes a cyclic redundancy check code appended to the frame, thereby creating a modified frame that includes the data comprising the frame and the error detection information.

[0071] After transmitting the control signal, the transmitter uses the output of a counter, such as an LFSR output, to encrypt a modified frame that includes error detection information. As described above in connection with Figure 3 and Figure 4 The transmitter uses a reversible operation (e.g., XOR, concatenation, addition) to combine the output of the counter with a starting value to produce a unique counter block. The counter block is encrypted using a key with AES or another block cipher encryption method, where the encrypted counter block is combined with the modified frame to generate a modified encrypted frame. For example, after transmitting the control signal 715 to the receiver, the transmitter decouples the output of the counter from the XOR operation and couples the output of an encryption block (such as Figure 4 the encryption module 410 in

[0072] Figure 8 is a flowchart of an embodiment of a method for decrypting a received frame after locking a counter in the receiver to a counter in the transmitter. Similar to the method described in connection with Figure 7 The method described in connection with Figure 8 includes a training mode that synchronizes the counter in the receiver with the counter in the transmitter. Compared to the conventional method where the counter in the receiver and the counter in the receiver are refreshed to a common value for synchronization when the link between the transmitter and the receiver is refreshed, Figure 8 the method of

[0073] During a training mode, a receiver receives 805 an initial training frame. The initial training frame is unencrypted and is included in a set of training frames, where the training frames have values known to a transmitter and a receiver. The training frames are also transmitted in an order specified by the set, allowing the receiver to determine the expected values of the training frames. In various embodiments, the initial training frame is scrambled by the transmitter based on the output of a counter, such as a linear feedback shift register (LFSR) of the transmitter, before transmission. The receiver uses the initial training frame and the expected value of the initial training frame to determine 810 the output of the transmitter's counter used to scramble the initial training frame, which is used as the initial value of the receiver's counter, such as the receiver's LFSR.

[0074] To determine 810 the initial value of the receiver's counter from the initial training frame, the receiver determines the difference between the initial training frame and the expected value of the initial training frame. For example, the receiver determines the difference between the initial training frame and the expected value of the initial training frame by performing an exclusive OR on the initial training frame and the expected value of the initial training frame, where the output of the exclusive OR identifies the difference between the initial training frame and the expected value of the initial training frame, and the expected value of the initial training frame is the initial value of the receiver's counter. In other embodiments, the receiver performs a different operation to determine the difference between the initial training frame and the expected value of the initial training frame to be used as the initial value of the receiver's counter. The receiver sets 815 the receiver's counter to the determined initial value, allowing the receiver to infer the value of the transmitter's counter when the initial training frame is sent and set the receiver's counter to an initial value that matches the inferred value of the transmitter's counter.

[0075] When the counter setting 815 is such that the initial value of 810 is determined based on the difference between the initial training frame and the expected value of the initial training frame, the counter of the receiver increments continuously (i.e., the counter is free-running). As the counter increments, the receiver receives 820 training frames from the set of training frames. Each training frame in the set is unencrypted but scrambled by the transmitter before transmission. Using the value from the counter and based on incrementing the counter from the initial value, the receiver descrambles 825 the training frame and determines whether the training frame matches the expected value of the training frame. For example, the receiver descrambles 825 the training frame by performing an exclusive OR on the output of the receiver's counter and the training frame when the training frame is received, and the result is the descrambled training frame. As further described above, the receiver determines the expected value of the training frame based on its position within the set of training frames. In response to determining that a threshold number of training frames received from the transmitter match the corresponding expected values of the training frames after the receiver descrambles 825 them, the receiver determines that the counter of the receiver is locked or synchronized with the counter of the transmitter. For example, in response to a threshold number of consecutive training frames matching the corresponding expected values of the training frames after the receiver descrambles 825 them, the receiver determines that the counters of the receiver and the transmitter are synchronized. In various embodiments, the above synchronization of the counter of the transmitter and the counter of the receiver is performed for each of a plurality of channels of the communication link between the transmitter and the receiver, thereby allowing synchronization of the counters of the transmitter and the receiver for the respective channels.

[0076] The receiver then receives 830 from the transmitter a control signal indicating that the training mode has ended. In response to receiving 830 the control signal, the receiver modifies one or more configuration settings to decrypt the frames received subsequently. For example, in response to receiving 830 the control signal, the receiver decouples the output of the counter of the receiver from the exclusive OR operation and couples the output of an encryption module (such as Figure 6 the encryption module 620 in Figure 6 as further described above) to the exclusive OR operation. This enables the receiver to determine the exclusive OR between the output of the encryption module and the frames received after the control signal, and the output of the encryption module is an encrypted counter block, as described above in connection with

[0077] Thus, the receiver decrypts the frames received after receiving 830 the control signal. Figure 3 、 Figure 4 and Figure 7is further described. The receiver decrypts the received frame 840 using an encrypted counter block generated from the output of a counter of the receiver. As further described above, in various embodiments, the receiver decrypts the received frame 840 by performing an XOR operation on the received frame and the encrypted counter block generated from the output of the counter of the receiver. The result of the XOR operation is the decrypted frame from the transmitter that includes error detection information.

[0078] In various embodiments, the communication link between the transmitter and the receiver includes a plurality of channels, and frames are sent on different channels. Thus, in some embodiments, the transmitter uses the plurality of channels of the communication link to send encrypted modified frames. The receiver receives the encrypted modified frames from the plurality of channels and decrypts the encrypted modified frames, as described above in connection with Figure 5 , Figure 6 and Figure 8 is further described. In various embodiments, the transmitter modifies the number of channels used to send frames to the receiver. For example, the transmitter uses a subset of channels less than the plurality of frames to send frames after a particular frame. When an error or performance issue occurs on one or more of the channels, this reduction in the number of channels used for transmission can save power used for transmission or remove channels from being used for transmission. This reduction in the channels used to send data can occur without resynchronization of the transmitter's counter and the receiver's counter because the synchronization of the transmitter's counter and the receiver's counter, as described above in connection with Figures 2 to 8 is performed for different channels of the communication link, which allows for the synchronization of the transmitter's and receiver's counters for each individual channel. This allows for the dynamic modification (e.g., reduction) of the number of channels used by the transmitter to send data without renegotiating the synchronization of the transmitter's counter and the receiver's counter.

[0079] Encrypting a data frame allows protecting the data during transmission when the frame is scrambled before being transmitted over a communication link. To provide additional protection, error detection information is appended to the frame before transmission, so the frame includes the error detection information when encrypted. Including the error detection information when encrypting the frame allows the receiver to detect errors caused by modifying the data during transmission. To simplify encryption, the transmitter encrypts the frame using a counter that is used to scramble the frame before transmission. The output of the counter is provided to an encryption module that outputs encrypted data for encrypting the frame. The receiver similarly provides the output of the counter used to descramble the frame to the encryption module, which outputs the encrypted data for decrypting the frame. A training mode, during which unencrypted training frames are transmitted between the transmitter and the receiver, where the receiver uses the known values of the training frames to determine an initial value of the receiver's counter. The initial value infers the value of the transmitter's counter used for encryption, allowing synchronization of the transmitter's counter and the receiver's counter without having to specifically negotiate the starting values of both the transmitter's counter and the receiver's counter. Additionally, using the outputs of the transmitter's counter and the receiver's counter to encrypt and decrypt the frame allows performing encryption and decryption without increasing the latency of data transmission between the transmitter and the receiver.

[0080] Exemplary embodiments of the present invention are mainly described in the context of a full-featured computer system for performing context switching by replacing the address translation context used by a computer processor. However, those skilled in the art will recognize that the present invention can also be embodied in a computer program product disposed on a computer-readable storage medium for use with any suitable data processing system. Such a computer-readable storage medium can be any storage medium for machine-readable information, including magnetic media, optical media, or other suitable media. Examples of such media include disks in a hard disk drive or disk, optical disks in an optical disk drive, magnetic tape, and other media that will occur to those skilled in the art. Those skilled in the art will immediately recognize that any computer system with suitable programming means will be able to execute the steps of the method of the present invention included in the computer program product. Those skilled in the art will also recognize that although some exemplary embodiments described in this specification are directed to software installed and executed on computer hardware, alternative embodiments implemented as firmware or hardware are also within the scope of the present invention.

[0081] From the foregoing description, it will be understood that modifications and changes can be made in the various embodiments of the present invention without departing from the true scope of the present invention. The description in this specification is for illustrative purposes only and should not be construed in a limiting sense. The scope of the present invention is limited only by the language of the appended claims.

Claims

1. A method for encrypting frames, the method comprising: Scrambling each training frame in a set for transmission from a transmitter to a receiver, each training frame in the set being scrambled based on an output of a counter of the transmitter and the training frame, wherein each scrambled training frame is unencrypted; Sending a control signal from the transmitter to the receiver; Modifying the frame to include error detection information; After sending the control signal to the receiver, encrypting the modified frame including the error detection information using an encrypted counter block generated from the output of the counter; And Sending the encrypted modified frame from the transmitter to the receiver.

2. The method according to claim 1, wherein The counter is incremented continuously.

3. The method according to claim 1, wherein, Scrambling each training frame in the set based on the output of the counter and the training frame includes: Performing an exclusive OR operation on the training frame and the output of the counter.

4. The method according to claim 1, wherein Sending the control signal to the receiver includes: Sending the control signal on each of a plurality of channels including a connection between the transmitter and the receiver.

5. The method according to claim 1, wherein, Using the encrypted counter block generated from the output of the counter to encrypt the modified frame including the error detection information includes: Combining the output of the counter with a starting value; Generating the encrypted counter block according to a key and the combination of the output of the counter and the starting value; and Combining the encrypted counter block with the modified frame including the error detection information to generate the encrypted modified frame.

6. The method according to claim 5, wherein, Combining the encrypted counter block with the modified frame including the error detection information to generate the encrypted modified frame includes: Performing an exclusive OR operation on the encrypted counter block and the modified frame including the error detection information.

7. The method according to claim 1, wherein The counter includes a linear feedback shift register.

8. The method according to claim 1, wherein Sending the encrypted modified frame from the transmitter to the receiver includes: Sending the encrypted modified frame from the transmitter to the receiver using a plurality of channels including a connection between the transmitter and the receiver; and Sending subsequent encrypted modified frames from the transmitter to the receiver using a subset of channels less than the plurality of channels.

9. A method for decrypting frames, comprising: Receiving an initial training frame at a receiver from a transmitter, wherein the initial training frame is unencrypted; Determining an initial value of a counter based on a difference between the initial training frame and an expected value of the initial training frame; Setting the counter to the initial value; Receiving a set of training frames while the counter is incremented continuously from the initial value, wherein each training frame is unencrypted; Descrambling each of the set of training frames using an output of the counter; Receiving a control signal from the transmitter, the control signal indicating a subsequent transmission of an encrypted frame including error detection information; Receiving a frame including error detection information after receiving the control signal; And Decrypting the frame including the error detection information using an encrypted counter block generated from the output of the counter.

10. The method according to claim 9, wherein Determining the initial value of the counter based on the difference between the initial training frame and the expected value of the initial training frame includes: Performing an exclusive OR operation on the initial training frame and the expected value of the initial training frame.

11. The method according to claim 9, wherein, Receiving, at the receiver, the control signal indicating a subsequent transmission of an encrypted frame including error detection information includes: Receiving the control signal on each of a plurality of channels including the connection between the transmitter and the receiver.

12. The method according to claim 11, wherein, Receiving, at the receiver, the control signal indicating a subsequent transmission of an encrypted frame including error detection information further includes: Determining that the control signal is received in response to the receiver determining that the control signal is received from at least a threshold number of the plurality of channels.

13. The method according to claim 12, wherein, The threshold number of the plurality of channels includes a majority of the plurality of channels.

14. The method according to claim 9, wherein Decrypting the frame including error detection information using the encrypted counter block generated from the output of the counter includes: Combining the output of the counter with a starting value; Generating the encrypted counter block based on a key and the combination of the output of the counter and the starting value; and Combining the encrypted counter block with the frame including error detection information to generate a decrypted frame including error detection information.

15. The method according to claim 14, wherein, Combining the encrypted counter block with the frame including error detection information to generate a decrypted frame including error detection information includes: Performing an exclusive OR operation on the encrypted counter block and the frame including error detection information.

16. The method according to claim 9, wherein Receiving the frame including error detection information after receiving the control signal includes: Receiving the frame including error detection information using a plurality of channels including the connection between the transmitter and the receiver; and Receiving subsequent frames from the receiver using a subset of channels less than the plurality of channels.

17. An apparatus for decrypting data, comprising a computer processor, a computer memory operably coupled to the computer processor, the computer memory having computer program instructions stored therein, the computer program instructions, when executed by the computer processor, causing the apparatus to perform the following steps: Receiving, at a receiver, an initial training frame from a transmitter, wherein the initial training frame is unencrypted; Determining an initial value of a counter of the receiver based on a difference between the initial training frame and an expected value of the initial training frame; Setting the counter to the initial value; Receiving a set of training frames while the counter of the receiver is incremented continuously from the initial value, wherein each training frame is unencrypted; Descrambling each of the set of training frames using an output of the counter of the receiver; Receiving a control signal from the transmitter, the control signal indicating a subsequent transmission of an encrypted frame including error detection information; Receiving a frame including error detection information after receiving the control signal; And Decrypting the frame including error detection information using an encrypted counter block generated from the output of the counter of the receiver.

18. The apparatus according to claim 17, wherein, Decrypting the frame including error detection information using the encrypted counter block generated from the output of the counter of the receiver includes: Combine the output of the counter with the starting value; Generate an encrypted counter block based on the key and the combination of the output of the counter of the receiver and the starting value; and Combine the encrypted counter block with the frame including error detection information to generate a decrypted frame including error detection information.

19. The apparatus according to claim 17, wherein, The frame including error detection information includes a frame encrypted by the transmitter based on a value determined from the output of the counter of the transmitter.

20. The apparatus according to claim 18, wherein The value determined from the output of the counter of the transmitter includes an encrypted counter block generated from the output of the counter of the transmitter.