Flexible Cryptographic System Architecture for Customer-Specific Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic products have inflexible hardware architectures that are difficult to modify or upgrade, limiting their ability to adapt to new functions and customer-specific requirements, particularly for domestic and international customers.

Innovation Solution

A cryptographic system with a flexible architecture utilizing a base general-purpose processor and channel processors, along with a software-defined approach that includes abstract layers and field programmable gate arrays (FPGAs) for customizable plug-ins and anti-tamper configurations, allowing for easy configuration and upgrade.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If custom-designed hardware with customer-specific integrated circuits and processors is used, then cryptographic security and customer-specific functionality are improved, but hardware flexibility and ease of modification are worsened

Engineering Contradiction:
Improvecryptographic securityVSAvoidhardware flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent employs field-programmable gate arrays (FPGAs) that can be dynamically reconfigured through partial reconfiguration mechanisms, allowing the hardware to adapt its functionality without physical modification. This dynamic reconfigurability enables the same hardware platform to serve multiple customers with different cryptographic requirements while maintaining security through customer-specific configuration loading.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The cryptographic system is designed with a universal hardware architecture that can host multiple customer-specific cryptographic subsystems simultaneously. The base processor and channel processors can load different customer-specific integrated circuit configurations and algorithms, allowing one physical device to function as multiple customer-specific systems, thereby achieving both security customization and hardware flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If inflexible hardware architecture is used, then manufacturing simplicity is improved, but ease of upgrade and modification is worsened

Engineering Contradiction:
Improvemanufacturing simplicityVSAvoidease of upgrade
Core Design Contradiction:
Ease of manufactureVSEase of repair

Solution Approach 1:

The cryptographic system is segmented into modular components including a base processor, multiple channel processors, and separable customer-specific integrated circuit configurations. This segmentation allows the core hardware architecture to be manufactured once in a standardized form, while customer-specific functionality is added through loadable configuration files rather than custom manufacturing, greatly simplifying production while enabling easy upgrades.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables modification of cryptographic functionality by changing software parameters and configuration data rather than altering hardware manufacturing. Customer-specific algorithms and anti-tamper configurations are implemented through loaded configuration files that modify the operational parameters of the universal hardware, allowing easy upgrades without re-manufacturing.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If customer-specific processors are used, then cryptographic functionality is improved, but device complexity and cost are worsened

Engineering Contradiction:
Improvecryptographic functionalityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of manufacturing separate physical processors for each customer, the system creates virtual copies of customer-specific processing functionality through loaded configuration files and software-defined cryptographic subsystems. The universal hardware platform replicates the functionality of customer-specific processors through software interpretation, eliminating the need for complex custom hardware while maintaining full cryptographic functionality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9806885B1Dual use cryptographic system and method
Publication Date: 2017.10.31 ROCKWELL COLLINS INC
  • US9806885B1 patent drawing
  • US9806885B1 patent drawing
  • US9806885B1 patent drawing

AI summary

Cryptographic communication systems and methods can utilize a base interface and a channel interface. Plug-ins can be utilized to provide cryptographic functions configured for either a first customer or a second customer. The first customer can be a United States domestic customer and the second customer can be an international customer.