Encrypted Data Integrity Detection Using Shared Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods require significant hardware expansion and increased current consumption to detect data changes and correct errors, especially in mobile devices, where memory space is limited and additional hardware is costly.

Innovation Solution

A method that encrypts redundancy information with data words before storage, allowing for partial storage of the encrypted redundancy data word, enabling error detection using existing encryption hardware with minimal additional hardware, and adaptable error code lengths to match security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If error correction code is applied after encryption by MED, then data change detection capability is improved, but device complexity and current consumption increase due to additional dedicated hardware

Engineering Contradiction:
Improvedata change detection capabilityVSAvoidhardware extent
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the error detection function with the existing encryption hardware (MED) by integrating an error detection unit that works in conjunction with the encryption unit. Instead of adding completely separate dedicated error correction hardware after encryption, the system merges error detection capabilities into the encryption workflow, allowing the same hardware infrastructure to serve dual purposes of encryption and error detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encryption unit (MED) is designed to perform multiple functions: it not only encrypts data but also generates and processes error detection codes. The error detection unit leverages the encrypted data and associated error detection data already present in the system, making the encryption hardware multi-functional by enabling it to handle both security encryption and error detection tasks without requiring entirely separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If error correction code is applied after encryption by MED, then data change detection capability is improved, but current consumption increases due to additional dedicated hardware

Engineering Contradiction:
Improvedata change detection capabilityVSAvoidcurrent consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines the error detection function with the existing encryption hardware (MED) by integrating an error detection unit that works in conjunction with the encryption unit. Instead of adding completely separate dedicated error correction hardware after encryption, the system merges error detection capabilities into the encryption workflow, allowing the same hardware infrastructure to serve dual purposes of encryption and error detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encryption unit (MED) is designed to perform multiple functions: it not only encrypts data but also generates and processes error detection codes. The error detection unit leverages the encrypted data and associated error detection data already present in the system, making the encryption hardware multi-functional by enabling it to handle both security encryption and error detection tasks without requiring entirely separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If error code word length is reduced below data width, then memory requirements decrease, but hardware changes are required at the encryption unit

Engineering Contradiction:
Improvememory requirementsVSAvoidhardware modification requirement
Core Design Contradiction:
Quantity of substanceVSEase of manufacture

Solution Approach 1:

The patent segments the error detection process into distinct components: the encryption unit (MED) that generates encrypted data and associated error detection data, and a separate error detection unit that processes this data. This segmentation allows the error code word length to be independently configured below the data width without requiring changes to the encryption unit's fundamental architecture, as the error detection unit is designed to handle variable-length error codes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary error detection unit that acts as a mediator between the encryption unit and the storage system. This intermediary component receives encrypted data and error detection data from the encryption unit, processes them according to the desired error code length, and manages the storage requirements. This intermediary layer allows flexible error code sizing without requiring direct modifications to the encryption unit's hardware architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If actual superfluous bits of error code are stored, then error code length can be reduced, but memory space consumption increases

Engineering Contradiction:
Improveerror code structureVSAvoidmemory space
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by implementing error detection with error code words that are shorter than the full data width. Instead of using complete-length error codes that would consume excessive memory, the system uses precisely the minimum necessary error detection bits required to detect the intended level of data corruption. This partial approach avoids storing unnecessary error code bits while maintaining adequate error detection capability for the application's needs.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8199914B2Detection of a change of the data of a dataset
Publication Date: 2012.06.12 INFINEON TECHNOLOGIES AG
  • US8199914B2 patent drawing
  • US8199914B2 patent drawing
  • US8199914B2 patent drawing

AI summary

An undesired change of encrypted data words of a stored encrypted dataset may be concluded from the fact that redundancy information is associated with the data words of a dataset prior to encryption, wherein the redundancy information is also encrypted and stored at least partially together with the encrypted data words of the encrypted dataset as an encrypted redundancy data word. The change of the stored encrypted data words may be concluded from the fact that the decrypted data words resulting from decrypting the encrypted data words are used to form a new redundancy data word which is encrypted into a new encrypted redundancy data word. A comparison of the new encrypted redundancy data word to the encrypted redundancy data word enables to examine whether the encrypted data was changed.