FPGA Encryption Device for High-Speed Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption/decryption devices for secure communications between protected and unprotected networks are limited by software-based architectures, which cannot handle data rates beyond a few million bits per second, making them inefficient for high-speed processing.
Innovation Solution
The use of programmable logic devices (PLDs) such as FPGAs and ASICs to create an encryption/decryption device with separate plaintext and ciphertext units, along with a cryptographic unit, performing encapsulation and decryption operations at high speeds, adhering to the High Assurance Internet Protocol Interoperability Specification (HAIPIS).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If software-based architectures are used for encryption/decryption devices, then ease of manufacture and implementation are improved, but data processing speed deteriorates and cannot handle rates beyond a few million bits per second
Solution Approach 1:
The patent replaces software-based encryption/decryption processing with hardware-based Field Programmable Gate Arrays (FPGAs). This substitution transitions from a software mechanical system to a hardware-based system that can process data at speeds exceeding several hundred million bits per second, directly resolving the speed limitation while maintaining implementation flexibility through programmability.
2Productivity
If hardware-based systems like FPGAs are used to increase data processing speed, then productivity is improved, but device complexity and manufacturing difficulty increase
Solution Approach 1:
The encryption/decryption device is segmented into distinct functional modules implemented on separate FPGAs: a first FPGA for encapsulation/decapsulation operations and a second FPGA for encryption/decryption operations. This segmentation allows each module to be optimized independently while maintaining overall system functionality, reducing the complexity burden on any single component.
Solution Approach 2:
The patent introduces a memory interface as an intermediary between the first and second FPGAs, facilitating efficient data transfer and coordination. This intermediary layer simplifies the interaction between the encapsulation/decapsulation module and the encryption/decryption module, making the overall complex system more manageable and easier to implement.
3Reliability
If encryption operations are performed on all IP packets, then security is improved, but processing time and system overhead increase
Solution Approach 1:
The patent performs encapsulation operations before encryption, preparing the data structure in advance. By pre-processing the IP packets through encapsulation/decapsulation in the first FPGA before passing them to the second FPGA for encryption, the system optimizes the workflow and reduces overall processing time while maintaining comprehensive security coverage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The encryption/decryption device includes a plaintext unit, a ciphertext unit and a cryptographic unit connected therebetween. The plaintext unit may include a logic device such as a first programmable logic device (PLD), e.g., a field programmable gate array (FPGA), for interfacing with the protected network to perform encapsulation of data from the protected network to define outgoing datagrams, and to perform decapsulation of incoming datagrams from the cytographic unit. The ciphertext unit may include a second logic device such as a PLD or FPGA for interfacing with the unprotected network to perform routing of incoming encrypted datagrams from the unprotected network to the cryptographic unit, and to perform routing of outgoing encrypted datagrams from the cryptographic unit to the unprotected network. The cryptographic unit may also be a PLD or FPGA and performs encryption of outgoing datagrams from the plaintext unit, and to perform decryption of incoming encrypted datagrams from the ciphertext unit to define the incoming datagrams.