Bridge Security Engine Offloads CPU Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital content protection schemes, such as DTCP, are inadequate as they leave clear text data susceptible to theft at internal data buses and impose a significant burden on CPUs due to encryption and decryption processes, especially when handling high-definition video.
Innovation Solution
A security engine is integrated into a bridge to offload cryptographic services from the central processing unit, enabling encryption and decryption operations to be performed at insecure interfaces, thereby reducing CPU load and enhancing security by maintaining data in cipher text form.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital content protection schemes (such as DTCP) are used to encrypt content on inter-device system buses, then content transmission security is improved, but clear text data becomes susceptible to theft at internal data buses and CPU burden increases significantly
Solution Approach 1:
The patent extracts the cryptographic service functions from the CPU and places them in a dedicated security engine within the bridge. This separation removes the burden of encryption/decryption operations from the CPU while preventing clear text exposure on internal buses, as the security engine handles all cryptographic operations independently.
Solution Approach 2:
The security engine acts as an intermediary between the CPU and other system components. It receives encrypted data from the CPU, performs decryption using secure key management, and outputs decrypted data only to authorized destinations, thereby preventing unauthorized access to clear text on internal buses while maintaining efficient data flow.
2Reliability
If CPU performs encryption and decryption of high definition video, then digital content protection is provided, but CPU clock cycles are significantly consumed (approximately 800 MHz for one HDTV stream)
Solution Approach 1:
The patent extracts cryptographic service functions from the CPU and implements them in a dedicated security engine within the bridge. This hardware-based approach offloads all encryption and decryption operations from the CPU, freeing up significant clock cycles while maintaining robust digital content protection for high definition video streams.
Solution Approach 2:
The patent replaces the software-based cryptographic operations in the CPU with hardware-based cryptographic operations in the security engine. This substitution provides the same digital content protection functionality but with significantly lower computational overhead, as the security engine is specifically designed for cryptographic operations in hardware.
3Reliability
If CPU performs decryption and re-encryption operations, then digital content is protected, but clear text data must be written to system memory where it is susceptible to theft
Solution Approach 1:
The security engine serves as a secure intermediary that performs all decryption and re-encryption operations without exposing clear text to the system memory bus. Decrypted data remains confined within the security engine's secure boundaries and is only output to authorized destinations, eliminating the security vulnerability of clear text exposure on memory buses.
Solution Approach 2:
The patent implements localized security processing within the bridge's security engine, where cryptographic operations occur in a secure, isolated environment. This local processing ensures that clear text data never leaves the secure boundary of the security engine, providing targeted protection at the specific location where cryptographic operations occur.
Data Source
AI summary
A bridge is disclosed having a security engine to protect digital content at insecure interfaces of the bridge. The bridge permits cryptographic services to he offloaded from a central processing unit to the bridge. The bridge receives a clear text input from a central processing unit. The bridge encrypts the clear text input as cipher text for storage in a memory. The bridge provided the cipher text to a graphics processing unit.


