Encryption Accelerator for Full-Volume Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to data encryption in information handling systems are limited by their hardware-based constraints, which restrict the use of specific encryption algorithms and do not allow for true full-volume encryption, and require secure storage of encryption keys and authentication objects.

Innovation Solution

An information handling system with an encryption accelerator that can perform a variety of cryptographic functions, allowing for encryption and decryption of data during input/output operations based on designated cryptographic functions and keys, and includes logic for pre-operating system encryption and decryption, as well as recovery from interrupted operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware-based encryption is used, then data security is improved, but encryption algorithm flexibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidencryption algorithm flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption accelerator is designed to support multiple cryptographic algorithms (AES, DES, 3DES, RC4, RC2, Blowfish, CAST, Serpent, Twofish, RIPEMD, MD5, SHA-1, SHA-256) within a single hardware device. This multi-functional capability allows the system to maintain strong security while providing flexibility to choose different algorithms based on specific requirements, resolving the contradiction between security reliability and algorithm flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If traditional encryption approaches are used, then system-specific data can be accessed, but full-volume encryption capability deteriorates

Engineering Contradiction:
Improvesystem startup accessVSAvoidfull-volume encryption capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system implements pre-boot authentication and encryption key establishment before the operating system loads. The encryption accelerator is initialized early in the boot process, and authentication credentials are verified before full-volume encryption is activated. This preliminary action enables the system to maintain both ease of operation (through automated authentication) and full-volume encryption capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure storage locations with specific security protocols are used, then key security is improved, but system complexity deteriorates

Engineering Contradiction:
Improvekey securityVSAvoidsecure storage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the encryption accelerator, secure key storage, and authentication mechanisms into a single integrated hardware component. The encryption accelerator includes internal secure storage for cryptographic keys and authentication objects, eliminating the need for separate secure storage locations and reducing system complexity while maintaining strong key security through hardware-based protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9658969B2System and method for general purpose encryption of data
Publication Date: 2017.05.23 DELL PROD LP
  • US9658969B2 patent drawing
  • US9658969B2 patent drawing

AI summary

Systems and methods for reducing problems and disadvantages associated with traditional approaches to encryption and decryption of data are provided. An information handling system may include a processor, a memory communicatively coupled to the processor, and an encryption accelerator communicatively coupled to the processor. The encryption accelerator may be configured to encrypt and decrypt information in accordance with a plurality of cryptographic functions, receive a command from the processor to perform an encryption or decryption task upon data associated with an input/output operation, and in response to receiving the command, encrypt or decrypt the data associated with the input/output operation based on a particular one of the plurality of cryptographic functions.