Embedded Firmware Cipher Accelerator for ASIC Cryptographic Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic systems struggle to meet the increasing processing speed demands of modern cryptographic algorithms, particularly in secure Internet communication, due to the need for extensive code writing and long processing times, and are often unable to be quickly updated to support new ciphers.
Innovation Solution
A configurable data processing system with a processor and hardware accelerators that execute cryptographic protocols using custom instructions, allowing for efficient processing of multiple cipher algorithms and the ability to reconfigure without halting the system, embedding a firmware cipher within an ASIC to accelerate operations beyond software or firmware solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional firmware systems are used to perform cryptographic calculations, then the system can support multiple cipher algorithms, but the processing time increases significantly and requires extensive code writing and testing
Solution Approach 1:
The cryptographic processing system is segmented into two distinct parts: a configurable processor that executes custom instructions for control and coordination, and dedicated hardware cipher data accelerators that perform actual cryptographic calculations. This segmentation allows the system to support multiple cipher algorithms through software configuration while maintaining fast hardware-based processing, thereby reducing processing time while preserving versatility.
Solution Approach 2:
A configurable processor acts as an intermediary between the software layer and hardware accelerators. The processor executes custom instructions that configure and control the hardware cipher data accelerators, enabling flexible support for multiple cipher algorithms while delegating the computationally intensive cryptographic operations to the hardware layer, thus balancing adaptability and processing speed.
2Speed
If conventional hardware cryptographic devices are designed to support specific ciphers, then processing speed is improved, but the device cannot be quickly updated to support new ciphers
Solution Approach 1:
The hardware cryptographic device incorporates configurable hardware cipher data accelerators that can be dynamically reconfigured through custom instructions executed by a configurable processor. This dynamic configuration capability allows the hardware to maintain fast processing speeds for current ciphers while being easily adaptable to support new cipher algorithms, resolving the contradiction between speed and upgradability.
Solution Approach 2:
The hardware cipher data accelerators are designed with universal functionality to support multiple cipher algorithms through configuration rather than dedicated hardware for each cipher. The configurable processor with custom instructions provides a universal control interface that can program the hardware accelerators to implement different cipher algorithms, enabling both high processing speed and ease of updating for new ciphers.
3Reliability
If more cryptographic processing is performed to meet security demands, then security is improved, but the processing demand consumes ever increasing proportions of available central processing capability
Solution Approach 1:
The system replaces general-purpose software-based cryptographic processing with specialized hardware cipher data accelerators that perform cryptographic calculations in hardware. This substitution offloads the computationally intensive cryptographic operations from the central processor, maintaining high security through robust cryptographic processing while preserving central processing capability for other tasks, thus improving security without proportionally increasing overall system processing demands.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A firmware cipher component is provided which can be configured and programmed to efficiently implement a broad range of cryptographic ciphers while accelerating their processing. This firmware cipher component allows an ASIC to support multiple cipher algorithms while accelerating the operations beyond speeds conventionally achieved by software or firmware only solutions. This system combines cryptographic specific custom instructions with hardware based data manipulation accelerators. The cryptographic specific custom instructions and hardware accelerators may support both block and stream ciphers. Thus, the system may be reconfigured, allowing the cipher algorithm to change without halting the system. Further, embedding the Firmware Programmable Cipher within an ASIC may allow future capabilities to be supported in secure applications.