Crypto Cloudlet Security Wrapper for Adaptive Cryptographic Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic solutions rely heavily on specialized hardware, requiring platform-specific device drivers and software, which is burdensome for supporting multiple operating systems and laborious to maintain, especially in scaled environments.

Innovation Solution

The implementation of a crypto cloudlet with a security wrapper, adaptive service, and Ethernet interface that provides secure cryptographic services with minimal hardware needs, dynamically adjusting to hardware characteristics and resources, and enabling secure input/output exchanges through a single channel, thus decoupling from platform dependencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware is used for cryptographic operations, then security and performance are improved, but platform dependency and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidplatform dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a crypto cloudlet as an intermediary component that sits between the host system and hardware resources. This cloudlet virtualizes cryptographic operations, allowing the system to leverage hardware capabilities while maintaining software-based portability. The cloudlet acts as a mediator that abstracts hardware-specific details, thus improving security through controlled hardware access while reducing platform dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the cryptographic system into distinct functional components: the host system, the crypto cloudlet, and the hardware resources. This segmentation allows each component to be optimized independently - the host system maintains portability, the cloudlet provides security management, and hardware delivers performance. By dividing the system this way, the patent achieves both security improvements and reduced platform coupling.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If platform-specific device drivers are installed for each operating system, then hardware compatibility is improved, but maintenance burden and operational complexity increase

Engineering Contradiction:
Improvehardware compatibilityVSAvoidmaintenance burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The crypto cloudlet is designed as a universal software layer that can operate across multiple operating systems without requiring platform-specific device drivers. It provides a unified interface for cryptographic operations that works consistently across different OS environments, thereby maintaining hardware compatibility while dramatically reducing maintenance burden and operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of installing separate device drivers for each operating system, the patent uses the crypto cloudlet to create a virtualized copy of the hardware interface. This software-based copy provides the same cryptographic functionality across different platforms without requiring actual hardware driver installations, thus improving ease of operation while maintaining adaptability.

Inventive Principle:
Principle #26Copying

3Productivity

If hardware resources are directly accessed by multiple clients, then resource utilization is improved, but security risks and access control complexity increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The crypto cloudlet serves as a security intermediary that manages all client access to hardware resources. It implements access control policies, authentication mechanisms, and secure communication channels between clients and hardware. This intermediary layer enables multiple clients to utilize hardware resources efficiently while maintaining strong security controls and reducing access control complexity through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the crypto cloudlet continuously monitors hardware resource usage, client authentication status, and security events. Based on this feedback, it dynamically adjusts resource allocation and access control decisions, thereby optimizing resource utilization while maintaining security. The feedback loop enables real-time security adjustments without compromising resource efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11115396B1Scaling of adaptive crypto services within the cloud
Publication Date: 2021.09.07 THALES DIS CPL USA INC
  • US11115396B1 patent drawing
  • US11115396B1 patent drawing
  • US11115396B1 patent drawing

AI summary

In one embodiment, a crypto cloudlet is provided that includes a security wrapper to a virtual machine to guarantee secure Input/Output exchange between a client and one or more cryptographic adaptive services powered by a set of virtual CPUs through a single well defined channel, an adaptive service running in the virtual machine that identifies hardware resources necessary to satisfy a cryptographic demand or request, and an Ethernet interface communicatively coupled to the security wrapper providing network channel services for exchange of cryptographic data and commands. The security wrapper presents to the adaptive services the hardware accelerators exposed by the virtual machine. Other embodiments are disclosed.