Lightweight Block Cipher for Secure Processor-Accelerator MMIO
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud and high-volume data analytics computing environments, existing encryption methods like AES-GCM require large circuit area and power, limiting their use for secure processor-accelerator communication, which is crucial for preventing information leakage and ensuring privacy and integrity without performance overhead.
Innovation Solution
A lightweight block-cipher based Galois counter authentication technique is used, specifically employing a 64-bit block cipher like PRINCE, which reduces circuit area and power consumption, enabling secure in-line data protection during processor-accelerator communication with low latency and high throughput, and preventing attacks like spoofing and denial of service without stalling data transfers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AES-GCM encryption is used for processor-accelerator communication, then security and privacy are improved, but circuit area and power consumption increase significantly
Solution Approach 1:
The patent changes the cryptographic algorithm parameter from AES-GCM to a lightweight block cipher, fundamentally altering the encryption approach to reduce circuit area while maintaining security. This parameter change enables the system to achieve security requirements with significantly reduced hardware footprint suitable for accelerator integration.
Solution Approach 2:
The patent employs a lightweight block cipher that consumes fewer resources and can be implemented with simpler, more compact circuitry compared to AES-GCM. This approach uses a more efficient cryptographic primitive that provides adequate security for the specific processor-accelerator communication context while being less resource-intensive.
2Reliability
If AES-GCM encryption is used for processor-accelerator communication, then security and privacy are improved, but power consumption increases
Solution Approach 1:
The patent changes the cryptographic algorithm parameter from AES-GCM to a lightweight block cipher, fundamentally altering the encryption approach to reduce power consumption while maintaining security. This parameter change enables the system to achieve security requirements with significantly reduced power budget suitable for accelerator integration.
Solution Approach 2:
The patent employs a lightweight block cipher that consumes fewer power resources compared to AES-GCM. This approach uses a more efficient cryptographic primitive that provides adequate security for the specific processor-accelerator communication context while being less power-intensive.
3Reliability
If encryption is added to processor-accelerator communication, then security is improved, but performance overhead increases
Solution Approach 1:
The patent employs a lightweight block cipher that provides security with minimal performance overhead. The simplified cryptographic operations enable faster encryption/decryption processing compared to AES-GCM, reducing the impact on data transfer performance between processor and accelerator.
Solution Approach 2:
The patent changes the cryptographic approach to use a lightweight block cipher with optimized performance characteristics for the target hardware platform. This parameter change reduces computational complexity and enables the security function to be integrated without significantly impacting the overall system performance.
Data Source
AI summary
Technologies for secure data transfer of MMIO data between a processor and an accelerator. A MIMO security engine includes a first block cipher pipeline to encrypt a count using a key; a first exclusive-OR (XOR) to generate a first XOR result of the encrypted count and a length multiplied by an authentication key; a second block cipher pipeline to encrypt (count+1) using the key; a second XOR to generate a second XOR result of plaintext data and the encrypted (count+1); a plurality of Galois field multipliers (GFMs) to perform Galois field multiplication on additional authenticated data (AAD), powers of the authentication key, and ciphertext data; and a plurality of exclusive-ORs (XORs) to combine results of the GFMs and the first XOR result to generate an authentication tag. Other embodiments are described and claimed.


