Cryptographic Module FPGA Self-Test Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic apparatuses face challenges in obtaining FIPS 140 certification due to the lack of self-test functionality in devices executing different software, which prevents setting the apparatus as a cryptographic boundary, especially when part of the devices do not have the necessary verification capabilities.

Innovation Solution

Incorporating a cryptographic module with a field-programmable gate array (FPGA) that executes verification of image data for software not originally verified by the device, allowing the entire apparatus to be set as a cryptographic boundary even if not all devices have self-test functionality, by using CRC codes for error detection and verification of boot and main images.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a cryptographic apparatus includes devices from different vendors executing different software, then the adaptability and versatility of the apparatus is improved, but the ability to perform FIPS self-test on all devices is lost, preventing certification

Engineering Contradiction:
Improveability to integrate devices from different vendorsVSAvoidFIPS self-test capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cryptographic module as an intermediary that performs FIPS self-tests on devices lacking this capability. The cryptographic module executes verification of image data for devices such as PCIe switches that cannot perform self-tests, thereby maintaining overall system certification while allowing integration of diverse vendor devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic module is designed to perform multiple functions: it executes software for cryptographic operations and simultaneously performs FIPS self-tests on other devices in the cryptographic boundary. This multi-functionality allows a single device to ensure compliance for the entire apparatus.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Area of stationary object

If the cryptographic boundary is expanded to include more devices, then the security coverage is improved, but the complexity of ensuring all devices have self-test functionality increases

Engineering Contradiction:
Improvesize of cryptographic boundaryVSAvoidcomplexity of self-test verification
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The cryptographic module serves as a central intermediary that consolidates self-test responsibilities. Instead of requiring each device to have self-test capability, the cryptographic module centrally manages verification of image data for all devices in the expanded cryptographic boundary, simplifying the overall verification architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If existing devices without self-test functionality are integrated into the cryptographic apparatus, then the ease of manufacture and device selection is improved, but the ability to obtain FIPS 140 certification is lost

Engineering Contradiction:
Improveease of integrating existing devicesVSAvoidFIPS 140 certification capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The cryptographic module acts as a mediator that enables existing devices without self-test functionality to be integrated into FIPS 140 certified systems. By performing verification of image data for these devices, the cryptographic module bridges the gap between device capabilities and certification requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic module performs self-service by conducting FIPS self-tests on itself and other devices. This self-verification capability allows the system to maintain certification compliance without requiring external verification infrastructure.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables the cryptographic apparatus to satisfy FIPS 140 certification requirements, including Level 2, by efficiently verifying software images and reducing the cryptographic boundary size, thereby enhancing security and compliance.

Implementation Method 1

using CRC codes for error detection and verification of boot and main images

Methodology Applied
Scientific EffectCRC error detection:

Data Source

PatentUS11263350B2Cryptographic apparatus and self-test method of cryptographic apparatus
Publication Date: 2022.03.01 HITACHI VANTARA LTD
  • US11263350B2 patent drawing
  • US11263350B2 patent drawing
  • US11263350B2 patent drawing

AI summary

In a cryptographic apparatus, a cryptographic module executes first assurance check processing, which is processing for satisfying a predetermined certification requirement on image data of first software, and also executes second assurance check processing, which is processing for satisfying the above predetermined certification requirement on a verification target, which is at least part of image data of second software, and on which verification for satisfying the predetermined certification requirement is not performed by a device.