Converged Cryptographic Engine Consolidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The presence of multiple cryptographic engines on a platform leads to unnecessary power consumption, increased area usage, and design complexity, along with duplication of Intellectual Property blocks and maintenance costs due to differing design teams and requirements for side channel resistance and post-quantum resistance.
Innovation Solution
A Converged Cryptographic Engine (CCE) is introduced, which combines all cryptographic engines into a single engine on the memory interface, utilizing a special instruction for encryption/decryption of data between storage devices and main memory, and supports advanced encryption standards like AES-XTS, reducing the number of engines and simplifying design and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple cryptographic engines are present at different locations on a platform, then security coverage is improved, but power consumption increases
Solution Approach 1:
The patent consolidates multiple cryptographic engines into a single Converged Cryptographic Engine (CCE) located at the memory interface. This single engine handles encryption and decryption for both main memory and storage devices, eliminating the need for separate cryptographic engines at different platform locations while maintaining comprehensive security coverage.
Solution Approach 2:
The CCE is designed as a universal cryptographic engine that can serve multiple functions: protecting main memory, protecting storage devices, and handling data transfers between them. This multi-functional design allows one engine to replace multiple specialized engines, reducing overall power consumption while maintaining security across all data locations.
2Reliability
If multiple cryptographic engines are present at different locations on a platform, then security coverage is improved, but area usage increases
Solution Approach 1:
The patent merges multiple cryptographic engines into a single CCE instance at the memory interface. This consolidation physically reduces the silicon area required by eliminating redundant cryptographic engine implementations across different platform components, while the single engine maintains security coverage for all data paths.
3Reliability
If multiple cryptographic engines are present at different locations on a platform, then security coverage is improved, but design complexity increases
Solution Approach 1:
The patent combines multiple cryptographic engines into a single CCE, which dramatically simplifies the design architecture. Instead of coordinating multiple separate engines with different design requirements, the system now manages one unified engine with consistent design standards, reducing overall design complexity.
Solution Approach 2:
The CCE is designed as a universal engine that handles multiple security functions (main memory protection, storage device protection, data transfer encryption) through a single standardized interface and control mechanism. This universality eliminates the need to design and integrate multiple specialized engines with different requirements.
4Reliability
If multiple cryptographic engines are present at different locations on a platform, then security coverage is improved, but maintenance costs increase
Solution Approach 1:
The patent consolidates multiple cryptographic engines into a single CCE, which reduces maintenance costs by eliminating the need to maintain separate engine instances. With only one engine to update, patch, and troubleshoot, maintenance efforts and associated costs are significantly reduced while security coverage remains comprehensive.
Data Source
Figure 1A
Figure 1B
Figure 2~5
AI summary
Methods and apparatus relating to a Converged Cryptographic Engine (CCE) for storage encryption are described. In an embodiment, decode circuitry decodes an instruction to determine whether Converged Cryptographic Engine (CCE) circuitry is enabled. Execution circuitry executes the instruction to program a plurality of keys in response to the CCE circuitry being enabled. The CCE circuitry performs all encryption and all decryption of data to be transferred between a memory and a storage device based at least in part on at least one of the plurality of keys. Other embodiments are also disclosed and claimed.