Embedded Firmware Cipher Accelerator for ASIC Cryptographic Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic systems struggle to meet the increasing processing speed demands of modern cryptographic algorithms, particularly in secure Internet communication, due to the need for extensive code writing and long processing times, and are often unable to be quickly updated to support new ciphers.

Innovation Solution

A configurable data processing system with a processor and hardware accelerators that execute cryptographic protocols using custom instructions, allowing for efficient processing of multiple cipher algorithms and the ability to reconfigure without halting the system, embedding a firmware cipher within an ASIC to accelerate operations beyond software or firmware solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional firmware systems are used to perform cryptographic calculations, then the system can support multiple cipher algorithms, but the processing time increases significantly and requires extensive code writing and testing

Engineering Contradiction:
Improvesupport for multiple cipher algorithmsVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The cryptographic processing system is segmented into two distinct parts: a configurable processor that executes custom instructions for control and coordination, and dedicated hardware cipher data accelerators that perform actual cryptographic calculations. This segmentation allows the system to support multiple cipher algorithms through software configuration while maintaining fast hardware-based processing, thereby reducing processing time while preserving versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A configurable processor acts as an intermediary between the software layer and hardware accelerators. The processor executes custom instructions that configure and control the hardware cipher data accelerators, enabling flexible support for multiple cipher algorithms while delegating the computationally intensive cryptographic operations to the hardware layer, thus balancing adaptability and processing speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If conventional hardware cryptographic devices are designed to support specific ciphers, then processing speed is improved, but the device cannot be quickly updated to support new ciphers

Engineering Contradiction:
Improveprocessing speedVSAvoidability to update for new ciphers
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The hardware cryptographic device incorporates configurable hardware cipher data accelerators that can be dynamically reconfigured through custom instructions executed by a configurable processor. This dynamic configuration capability allows the hardware to maintain fast processing speeds for current ciphers while being easily adaptable to support new cipher algorithms, resolving the contradiction between speed and upgradability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The hardware cipher data accelerators are designed with universal functionality to support multiple cipher algorithms through configuration rather than dedicated hardware for each cipher. The configurable processor with custom instructions provides a universal control interface that can program the hardware accelerators to implement different cipher algorithms, enabling both high processing speed and ease of updating for new ciphers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If more cryptographic processing is performed to meet security demands, then security is improved, but the processing demand consumes ever increasing proportions of available central processing capability

Engineering Contradiction:
ImprovesecurityVSAvoidcentral processing capability consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system replaces general-purpose software-based cryptographic processing with specialized hardware cipher data accelerators that perform cryptographic calculations in hardware. This substitution offloads the computationally intensive cryptographic operations from the central processor, maintaining high security through robust cryptographic processing while preserving central processing capability for other tasks, thus improving security without proportionally increasing overall system processing demands.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2715544B1Method and system for embedded high performance reconfigurable firmware cipher
Publication Date: 2022.12.21 EXELIS INC
  • EP2715544B1 patent drawingFigure 1
  • EP2715544B1 patent drawingFigure 2
  • EP2715544B1 patent drawingFigure 3

AI summary

A firmware cipher component is provided which can be configured and programmed to efficiently implement a broad range of cryptographic ciphers while accelerating their processing. This firmware cipher component allows an ASIC to support multiple cipher algorithms while accelerating the operations beyond speeds conventionally achieved by software or firmware only solutions. This system combines cryptographic specific custom instructions with hardware based data manipulation accelerators. The cryptographic specific custom instructions and hardware accelerators may support both block and stream ciphers. Thus, the system may be reconfigured, allowing the cipher algorithm to change without halting the system. Further, embedding the Firmware Programmable Cipher within an ASIC may allow future capabilities to be supported in secure applications.