Hardware Circuit for Sequestered Encryption in Cloud Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing and IoT systems are vulnerable to software hacks and side-channel attacks, as they rely on software for data processing, which can compromise user data security and integrity.

Innovation Solution

An electronic circuit system that performs operations solely on hardware, using sequestered encryption to prevent access to unencrypted secret data and data keys, ensuring latency independence and control-independent decision-making to protect against side-channel attacks, while utilizing data identifiers for integrity and authenticity validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software is used for data processing in cloud computing and IoT systems, then operational flexibility and ease of implementation are improved, but security against software hacks and side-channel attacks deteriorates

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based data processing with hardware-based processing. Specifically, it uses an electronic circuit with dedicated hardware components (decryptor, processor, encryptor, data identifier generator) to perform cryptographic operations, eliminating the security vulnerabilities inherent in software implementations while maintaining operational functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If traditional encryption methods are used, then data confidentiality is improved, but vulnerability to side-channel attacks worsens due to software-based implementation

Engineering Contradiction:
Improvedata confidentialityVSAvoidside-channel attacks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes software-based cryptographic operations with hardware-based operations. The electronic circuit performs decryption, processing, and re-encryption entirely in hardware, preventing attackers from exploiting software vulnerabilities and side-channel information leaks that arise from software execution patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the cryptographic processing into distinct hardware components: a decryptor for decryption, a processor for data manipulation, an encryptor for re-encryption, and a data identifier generator for integrity verification. This segmentation isolates sensitive operations within dedicated hardware modules, reducing the attack surface for side-channel attacks.

Inventive Principle:
Principle #1Segmentation

3Reliability

If hardware-based processing is implemented, then security against software hacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against software hacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple cryptographic functions (decryption, processing, encryption, data identifier generation) into a single integrated electronic circuit. This consolidation reduces device complexity compared to implementing separate hardware modules for each function, while still providing security against software hacks through hardware-based operation.

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If data identifiers are generated for each operation, then data integrity verification is improved, but processing time increases

Engineering Contradiction:
Improveintegrity verificationVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent generates data identifiers continuously as part of the normal processing flow within the hardware circuit. The data identifier generator operates in tandem with the processor and encryptor, producing identifiers without interrupting or pausing the main data processing operations, thus minimizing time overhead while maintaining integrity verification capability.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12105855B2Privacy-enhanced computation via sequestered encryption
Publication Date: 2024.10.01 AGITA LABS INC
  • US12105855B2 patent drawing
  • US12105855B2 patent drawing
  • US12105855B2 patent drawing

AI summary

A system includes an electronic circuit that performs operations on encrypted data. The electronic circuit includes electronic circuit elements electrically coupled to receive an encrypted first secret data block including a first data identifier and to decrypt the encrypted first secret data block. The electronic circuit further includes electronic circuit elements electrically coupled to combine the data identifier and an operation identifier of an operation to be executed to generate an intermediate value; apply a one-way hash function to the intermediate value to generate a second data identifier; and encrypt the second data identifier for outputting.