Hardware Circuit for Sequestered Encryption in Cloud Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing and IoT systems are vulnerable to software hacks and side-channel attacks, as they rely on software for data processing, which can compromise user data security and integrity.
Innovation Solution
An electronic circuit system that performs operations solely on hardware, using sequestered encryption to prevent access to unencrypted secret data and data keys, ensuring latency independence and control-independent decision-making to protect against side-channel attacks, while utilizing data identifiers for integrity and authenticity validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software is used for data processing in cloud computing and IoT systems, then operational flexibility and ease of implementation are improved, but security against software hacks and side-channel attacks deteriorates
Solution Approach 1:
The patent replaces software-based data processing with hardware-based processing. Specifically, it uses an electronic circuit with dedicated hardware components (decryptor, processor, encryptor, data identifier generator) to perform cryptographic operations, eliminating the security vulnerabilities inherent in software implementations while maintaining operational functionality.
2Loss of information
If traditional encryption methods are used, then data confidentiality is improved, but vulnerability to side-channel attacks worsens due to software-based implementation
Solution Approach 1:
The patent substitutes software-based cryptographic operations with hardware-based operations. The electronic circuit performs decryption, processing, and re-encryption entirely in hardware, preventing attackers from exploiting software vulnerabilities and side-channel information leaks that arise from software execution patterns.
Solution Approach 2:
The patent segments the cryptographic processing into distinct hardware components: a decryptor for decryption, a processor for data manipulation, an encryptor for re-encryption, and a data identifier generator for integrity verification. This segmentation isolates sensitive operations within dedicated hardware modules, reducing the attack surface for side-channel attacks.
3Reliability
If hardware-based processing is implemented, then security against software hacks is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple cryptographic functions (decryption, processing, encryption, data identifier generation) into a single integrated electronic circuit. This consolidation reduces device complexity compared to implementing separate hardware modules for each function, while still providing security against software hacks through hardware-based operation.
4Measurement precision
If data identifiers are generated for each operation, then data integrity verification is improved, but processing time increases
Solution Approach 1:
The patent generates data identifiers continuously as part of the normal processing flow within the hardware circuit. The data identifier generator operates in tandem with the processor and encryptor, producing identifiers without interrupting or pausing the main data processing operations, thus minimizing time overhead while maintaining integrity verification capability.
Data Source
AI summary
A system includes an electronic circuit that performs operations on encrypted data. The electronic circuit includes electronic circuit elements electrically coupled to receive an encrypted first secret data block including a first data identifier and to decrypt the encrypted first secret data block. The electronic circuit further includes electronic circuit elements electrically coupled to combine the data identifier and an operation identifier of an operation to be executed to generate an intermediate value; apply a one-way hash function to the intermediate value to generate a second data identifier; and encrypt the second data identifier for outputting.


