Encryption Accelerator for Full-Volume Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional approaches to data encryption in information handling systems are limited by their hardware-based constraints, which restrict the use of specific encryption algorithms and do not allow for true full-volume encryption, and require secure storage of encryption keys and authentication objects.
Innovation Solution
An information handling system with an encryption accelerator that can perform a variety of cryptographic functions, allowing for encryption and decryption of data during input/output operations based on designated cryptographic functions and keys, and includes logic for pre-operating system encryption and decryption, as well as recovery from interrupted operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional hardware-based encryption is used, then data security is improved, but encryption algorithm flexibility deteriorates
Solution Approach 1:
The encryption accelerator is designed to support multiple cryptographic algorithms (AES, DES, 3DES, RC4, RC2, Blowfish, CAST, Serpent, Twofish, RIPEMD, MD5, SHA-1, SHA-256) within a single hardware device. This multi-functional capability allows the system to maintain strong security while providing flexibility to choose different algorithms based on specific requirements, resolving the contradiction between security reliability and algorithm flexibility.
2Ease of operation
If traditional encryption approaches are used, then system-specific data can be accessed, but full-volume encryption capability deteriorates
Solution Approach 1:
The system implements pre-boot authentication and encryption key establishment before the operating system loads. The encryption accelerator is initialized early in the boot process, and authentication credentials are verified before full-volume encryption is activated. This preliminary action enables the system to maintain both ease of operation (through automated authentication) and full-volume encryption capability.
3Reliability
If secure storage locations with specific security protocols are used, then key security is improved, but system complexity deteriorates
Solution Approach 1:
The patent combines the encryption accelerator, secure key storage, and authentication mechanisms into a single integrated hardware component. The encryption accelerator includes internal secure storage for cryptographic keys and authentication objects, eliminating the need for separate secure storage locations and reducing system complexity while maintaining strong key security through hardware-based protection.
Data Source
AI summary
Systems and methods for reducing problems and disadvantages associated with traditional approaches to encryption and decryption of data are provided. An information handling system may include a processor, a memory communicatively coupled to the processor, and an encryption accelerator communicatively coupled to the processor. The encryption accelerator may be configured to encrypt and decrypt information in accordance with a plurality of cryptographic functions, receive a command from the processor to perform an encryption or decryption task upon data associated with an input/output operation, and in response to receiving the command, encrypt or decrypt the data associated with the input/output operation based on a particular one of the plurality of cryptographic functions.

