Configurable Routing Block for Secure Cryptographic Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The evaluation of trusted Secure Operating Systems in embedded programmable cryptographic solutions is difficult, time-consuming, and expensive, making it challenging to implement secure communication of cryptographic data effectively.
Innovation Solution
A circuit and method utilizing a routing block with configurable logic in integrated circuits to selectively route data between secure and non-secure interfaces, incorporating partial reconfiguration modules and interconnect elements configured on different metal layers for improved isolation, allowing secure and non-secure data paths to be managed efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted Secure Operating System is used to provide preemptive time and space partitioning for controlling information flow between portions of circuit having different security levels, then security control is improved, but evaluation becomes difficult, time-consuming, and expensive
Solution Approach 1:
The patent replaces the software-based Secure Operating System with a hardware-based routing block implemented in reconfigurable logic. This routing block provides time and space partitioning through configurable logic that can be programmed to route data from different security levels to appropriate cryptographic applications, eliminating the need for complex SOS evaluation while maintaining security control
Solution Approach 2:
The routing block uses configurable parameters and control signals to dynamically change routing behavior based on security requirements. The reconfigurable logic allows the system to adapt routing paths according to different security contexts, providing flexible security control without the overhead of a trusted operating system
2Reliability
If a trusted Secure Operating System is used to control information flow between security levels, then security control is improved, but cost increases due to difficult and time-consuming evaluation
Solution Approach 1:
The patent substitutes the expensive software evaluation process with a hardware implementation using reconfigurable logic. The routing block provides verifiable security control through its configurable nature, allowing standard hardware verification methods to be used instead of costly and time-consuming trusted operating system evaluation
Solution Approach 2:
The routing block serves multiple functions: it routes data from different security levels, implements time and space partitioning, and provides configurable access control to cryptographic applications. This multi-functionality consolidates what would otherwise require a complex trusted operating system into a single hardware component
3Adaptability or versatility
If reconfigurable logic is used to implement routing block for selective data routing, then flexibility and adaptability are improved, but device complexity increases
Solution Approach 1:
The patent divides the cryptographic system into distinct security domains with a routing block that segments data flow paths. The reconfigurable logic is organized into configurable routing entries that can be independently programmed, allowing flexible data routing while maintaining a structured and manageable circuit architecture
Solution Approach 2:
The routing block acts as an intermediary component between interfaces receiving data from different security levels and cryptographic applications. This mediator approach centralizes the complexity in a single controllable component rather than distributing it throughout the entire system
Data Source
AI summary
A circuit for enabling communication of cryptographic data in an integrated circuit is disclosed. The circuit comprises a first interface coupled to receive data having a first security level; a second interface coupled to receive data having a second security level; a cryptographic application; and a routing block coupled between the first and second interfaces and the cryptographic application, the routing block comprising configurable logic, wherein the routing block is configurable to selectively route the data having the first security level by way of the first interface and to route data having the second security level by way of the second interface. A method of enabling communication of cryptographic data in an integrated circuit is also disclosed.


