Encrypted Data Integrity Detection Using Shared Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods require significant hardware expansion and increased current consumption to detect data changes and correct errors, especially in mobile devices, where memory space is limited and additional hardware is costly.
Innovation Solution
A method that encrypts redundancy information with data words before storage, allowing for partial storage of the encrypted redundancy data word, enabling error detection using existing encryption hardware with minimal additional hardware, and adaptable error code lengths to match security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If error correction code is applied after encryption by MED, then data change detection capability is improved, but device complexity and current consumption increase due to additional dedicated hardware
Solution Approach 1:
The patent combines the error detection function with the existing encryption hardware (MED) by integrating an error detection unit that works in conjunction with the encryption unit. Instead of adding completely separate dedicated error correction hardware after encryption, the system merges error detection capabilities into the encryption workflow, allowing the same hardware infrastructure to serve dual purposes of encryption and error detection.
Solution Approach 2:
The encryption unit (MED) is designed to perform multiple functions: it not only encrypts data but also generates and processes error detection codes. The error detection unit leverages the encrypted data and associated error detection data already present in the system, making the encryption hardware multi-functional by enabling it to handle both security encryption and error detection tasks without requiring entirely separate dedicated hardware for each function.
2Reliability
If error correction code is applied after encryption by MED, then data change detection capability is improved, but current consumption increases due to additional dedicated hardware
Solution Approach 1:
The patent combines the error detection function with the existing encryption hardware (MED) by integrating an error detection unit that works in conjunction with the encryption unit. Instead of adding completely separate dedicated error correction hardware after encryption, the system merges error detection capabilities into the encryption workflow, allowing the same hardware infrastructure to serve dual purposes of encryption and error detection.
Solution Approach 2:
The encryption unit (MED) is designed to perform multiple functions: it not only encrypts data but also generates and processes error detection codes. The error detection unit leverages the encrypted data and associated error detection data already present in the system, making the encryption hardware multi-functional by enabling it to handle both security encryption and error detection tasks without requiring entirely separate dedicated hardware for each function.
3Quantity of substance
If error code word length is reduced below data width, then memory requirements decrease, but hardware changes are required at the encryption unit
Solution Approach 1:
The patent segments the error detection process into distinct components: the encryption unit (MED) that generates encrypted data and associated error detection data, and a separate error detection unit that processes this data. This segmentation allows the error code word length to be independently configured below the data width without requiring changes to the encryption unit's fundamental architecture, as the error detection unit is designed to handle variable-length error codes.
Solution Approach 2:
The patent introduces an intermediary error detection unit that acts as a mediator between the encryption unit and the storage system. This intermediary component receives encrypted data and error detection data from the encryption unit, processes them according to the desired error code length, and manages the storage requirements. This intermediary layer allows flexible error code sizing without requiring direct modifications to the encryption unit's hardware architecture.
4Device complexity
If actual superfluous bits of error code are stored, then error code length can be reduced, but memory space consumption increases
Solution Approach 1:
The patent applies partial action by implementing error detection with error code words that are shorter than the full data width. Instead of using complete-length error codes that would consume excessive memory, the system uses precisely the minimum necessary error detection bits required to detect the intended level of data corruption. This partial approach avoids storing unnecessary error code bits while maintaining adequate error detection capability for the application's needs.
Data Source
AI summary
An undesired change of encrypted data words of a stored encrypted dataset may be concluded from the fact that redundancy information is associated with the data words of a dataset prior to encryption, wherein the redundancy information is also encrypted and stored at least partially together with the encrypted data words of the encrypted dataset as an encrypted redundancy data word. The change of the stored encrypted data words may be concluded from the fact that the decrypted data words resulting from decrypting the encrypted data words are used to form a new redundancy data word which is encrypted into a new encrypted redundancy data word. A comparison of the new encrypted redundancy data word to the encrypted redundancy data word enables to examine whether the encrypted data was changed.


