FPGA Encryption Device for High-Speed Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption/decryption devices for secure communications between protected and unprotected networks are limited by software-based architectures, which cannot handle data rates beyond a few million bits per second, making them inefficient for high-speed processing.

Innovation Solution

The use of programmable logic devices (PLDs) such as FPGAs and ASICs to create an encryption/decryption device with separate plaintext and ciphertext units, along with a cryptographic unit, performing encapsulation and decryption operations at high speeds, adhering to the High Assurance Internet Protocol Interoperability Specification (HAIPIS).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If software-based architectures are used for encryption/decryption devices, then ease of manufacture and implementation are improved, but data processing speed deteriorates and cannot handle rates beyond a few million bits per second

Engineering Contradiction:
Improveease of implementationVSAvoiddata processing speed
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent replaces software-based encryption/decryption processing with hardware-based Field Programmable Gate Arrays (FPGAs). This substitution transitions from a software mechanical system to a hardware-based system that can process data at speeds exceeding several hundred million bits per second, directly resolving the speed limitation while maintaining implementation flexibility through programmability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If hardware-based systems like FPGAs are used to increase data processing speed, then productivity is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improvedata processing speedVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The encryption/decryption device is segmented into distinct functional modules implemented on separate FPGAs: a first FPGA for encapsulation/decapsulation operations and a second FPGA for encryption/decryption operations. This segmentation allows each module to be optimized independently while maintaining overall system functionality, reducing the complexity burden on any single component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a memory interface as an intermediary between the first and second FPGAs, facilitating efficient data transfer and coordination. This intermediary layer simplifies the interaction between the encapsulation/decapsulation module and the encryption/decryption module, making the overall complex system more manageable and easier to implement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption operations are performed on all IP packets, then security is improved, but processing time and system overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs encapsulation operations before encryption, preparing the data structure in advance. By pre-processing the IP packets through encapsulation/decapsulation in the first FPGA before passing them to the second FPGA for encryption, the system optimizes the workflow and reduces overall processing time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1953954B1Encryption/decryption device for secure communications between a protected network and an unprotected network and associated methods
Publication Date: 2016.01.27 HARRIS CORP
  • EP1953954B1 patent drawingFigure 1
  • EP1953954B1 patent drawingFigure 2
  • EP1953954B1 patent drawingFigure 3

AI summary

The encryption/decryption device includes a plaintext unit, a ciphertext unit and a cryptographic unit connected therebetween. The plaintext unit may include a logic device such as a first programmable logic device (PLD), e.g., a field programmable gate array (FPGA), for interfacing with the protected network to perform encapsulation of data from the protected network to define outgoing datagrams, and to perform decapsulation of incoming datagrams from the cytographic unit. The ciphertext unit may include a second logic device such as a PLD or FPGA for interfacing with the unprotected network to perform routing of incoming encrypted datagrams from the unprotected network to the cryptographic unit, and to perform routing of outgoing encrypted datagrams from the cryptographic unit to the unprotected network. The cryptographic unit may also be a PLD or FPGA and performs encryption of outgoing datagrams from the plaintext unit, and to perform decryption of incoming encrypted datagrams from the ciphertext unit to define the incoming datagrams.