Encryption Accelerator for Full-Volume Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to data encryption in information handling systems are limited by their hardware-based constraints, which restrict the use of specific encryption algorithms and do not allow for true full-volume encryption, and require secure storage of encryption keys and authentication objects.

Innovation Solution

An information handling system equipped with an encryption accelerator that can perform a variety of cryptographic functions, allowing for encryption and decryption of data during input/output operations based on designated cryptographic functions and keys, and includes logic for pre-operating system encryption and decryption, as well as recovery from interrupted operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware-based encryption is used, then data security is improved, but encryption algorithm flexibility deteriorates and full-volume encryption becomes impossible

Engineering Contradiction:
Improvedata securityVSAvoidencryption algorithm flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption accelerator is designed to support multiple cryptographic algorithms (AES, DES, 3DES, RC4, MD5, SHA-1, RIPEMD-160) within a single hardware device. The system can dynamically select and execute different algorithms based on the encryption requirements, transforming a specialized hardware component into a universal encryption platform that maintains security while providing algorithmic flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The encryption system transitions from static hardware-based encryption to a dynamic architecture where the encryption algorithm and key can be changed at runtime. The processor can issue different encryption commands to the accelerator, and the system can adapt encryption parameters based on data type, security requirements, and operational context, enabling both full-volume and selective encryption.

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional hardware-based encryption is used, then data security is improved, but full-volume encryption capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidfull-volume encryption capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The encryption system divides the storage volume into multiple segments or blocks that can be encrypted independently. The processor can issue encryption commands to specific data regions while leaving other regions accessible for system operations. This segmentation enables progressive full-volume encryption without requiring complete system shutdown or compromising system functionality during the encryption process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary encryption setup by establishing encryption keys and algorithms before actual data encryption begins. The encryption accelerator is pre-configured with cryptographic functions, and the system can prepare encryption parameters in advance, allowing full-volume encryption to proceed efficiently without interrupting normal system operations or requiring post-encryption system reconfiguration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption keys are stored in secure storage locations, then data security is improved, but system complexity and authentication requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidsecure storage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption key storage functionality is merged with the existing processor and encryption accelerator components. Rather than requiring a separate secure storage device with independent authentication mechanisms, the system integrates key management within the processor-encryptor architecture. The processor can directly access and manage encryption keys through the accelerator, reducing system complexity while maintaining security through hardware-based key protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9135471B2System and method for encryption and decryption of data
Publication Date: 2015.09.15 DELL PROD LP
  • US9135471B2 patent drawing
  • US9135471B2 patent drawing

AI summary

Systems and methods for reducing problems and disadvantages associated with traditional approaches to encryption and decryption of data are provided. A method for encryption and decryption of data, may include encrypting or decrypting data associated with an input/output operation based on at least one of an encryption key and a cryptographic function, wherein at least one of the encryption key and the cryptographic function are selected based on one or more characteristics associated with the data to be encrypted or decrypted. Another method may include encrypting an item of data based on at least one of a first-layer encryption key and a first-layer cryptographic function to produce first-layer encrypted data and encrypting the first-layer encrypted data based on at least one of a second-layer encryption key and a second-layer cryptographic function to produce second-layer encrypted data.