Encryption Accelerator for Full-Volume Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional approaches to data encryption in information handling systems are limited by their hardware-based constraints, which restrict the use of specific encryption algorithms and do not allow for true full-volume encryption, and require secure storage of encryption keys and authentication objects.
Innovation Solution
An information handling system equipped with an encryption accelerator that can perform a variety of cryptographic functions, allowing for encryption and decryption of data during input/output operations based on designated cryptographic functions and keys, and includes logic for pre-operating system encryption and decryption, as well as recovery from interrupted operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional hardware-based encryption is used, then data security is improved, but encryption algorithm flexibility deteriorates and full-volume encryption becomes impossible
Solution Approach 1:
The encryption accelerator is designed to support multiple cryptographic algorithms (AES, DES, 3DES, RC4, MD5, SHA-1, RIPEMD-160) within a single hardware device. The system can dynamically select and execute different algorithms based on the encryption requirements, transforming a specialized hardware component into a universal encryption platform that maintains security while providing algorithmic flexibility.
Solution Approach 2:
The encryption system transitions from static hardware-based encryption to a dynamic architecture where the encryption algorithm and key can be changed at runtime. The processor can issue different encryption commands to the accelerator, and the system can adapt encryption parameters based on data type, security requirements, and operational context, enabling both full-volume and selective encryption.
2Reliability
If traditional hardware-based encryption is used, then data security is improved, but full-volume encryption capability deteriorates
Solution Approach 1:
The encryption system divides the storage volume into multiple segments or blocks that can be encrypted independently. The processor can issue encryption commands to specific data regions while leaving other regions accessible for system operations. This segmentation enables progressive full-volume encryption without requiring complete system shutdown or compromising system functionality during the encryption process.
Solution Approach 2:
The system performs preliminary encryption setup by establishing encryption keys and algorithms before actual data encryption begins. The encryption accelerator is pre-configured with cryptographic functions, and the system can prepare encryption parameters in advance, allowing full-volume encryption to proceed efficiently without interrupting normal system operations or requiring post-encryption system reconfiguration.
3Reliability
If encryption keys are stored in secure storage locations, then data security is improved, but system complexity and authentication requirements increase
Solution Approach 1:
The encryption key storage functionality is merged with the existing processor and encryption accelerator components. Rather than requiring a separate secure storage device with independent authentication mechanisms, the system integrates key management within the processor-encryptor architecture. The processor can directly access and manage encryption keys through the accelerator, reducing system complexity while maintaining security through hardware-based key protection.
Data Source
AI summary
Systems and methods for reducing problems and disadvantages associated with traditional approaches to encryption and decryption of data are provided. A method for encryption and decryption of data, may include encrypting or decrypting data associated with an input/output operation based on at least one of an encryption key and a cryptographic function, wherein at least one of the encryption key and the cryptographic function are selected based on one or more characteristics associated with the data to be encrypted or decrypted. Another method may include encrypting an item of data based on at least one of a first-layer encryption key and a first-layer cryptographic function to produce first-layer encrypted data and encrypting the first-layer encrypted data based on at least one of a second-layer encryption key and a second-layer cryptographic function to produce second-layer encrypted data.

