Hardware Encryption Modules for Side-Channel-Resistant Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-only encryption solutions, such as AES 256, are vulnerable to hacks and side-channel attacks, and older systems lack the computational power to implement advanced encryption protocols, necessitating a hardware/software approach for secure data transmission.

Innovation Solution

A hardware-based encryption system using Smart Terminator Modules (STMs) with a Symmetric Encryption-Asymmetric Solution (SEAS) that employs key hopping, random number generation, and secure logging to protect networks from unauthorized access and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-only encryption (AES 256) is used, then encryption can be implemented on modern systems, but it is vulnerable to hacks and side-channel attacks

Engineering Contradiction:
Improveencryption securityVSAvoidvulnerability to hacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The encryption system is divided into separate hardware and software components. The patent implements a dedicated encryption hardware device that operates independently from the main software system, isolating the cryptographic functions from software-based vulnerabilities. This segmentation prevents software hacks from compromising the encryption keys and algorithms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware intermediary device is introduced between the network and the encryption software. This hardware module acts as a mediator that handles sensitive cryptographic operations, protecting them from software-based side-channel attacks while maintaining compatibility with existing software encryption protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If advanced software encryption protocols are implemented, then security is improved, but older systems lack the computational power to support them

Engineering Contradiction:
Improveencryption securityVSAvoidcomputational power requirement
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent replaces software-based cryptographic processing with dedicated hardware encryption circuitry. This substitution moves the computational burden from general-purpose software processors to specialized hardware components, enabling strong encryption on older systems with limited computational resources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The encryption hardware device changes the operational parameters by providing fixed, pre-configured encryption capabilities that do not require high computational power. The hardware is designed to perform specific cryptographic functions efficiently, regardless of the host system's processing capabilities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If hardware-based encryption is implemented, then resistance to side-channel attacks is improved, but device complexity increases

Engineering Contradiction:
Improveresistance to side-channel attacksVSAvoidhardware/software integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption hardware device is designed with universal interfaces and protocols that work with multiple operating systems and network configurations. This multi-functionality reduces the need for system-specific customizations, thereby lowering overall device complexity despite the hardware addition.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The hardware encryption device operates autonomously with self-contained cryptographic processing. It manages its own keys, performs self-diagnosis, and requires minimal external control, reducing the complexity of integration with existing systems while maintaining high security against side-channel attacks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12506717B2Network security devices and method
Publication Date: 2025.12.23 WATTRE INC
  • US12506717B2 patent drawing
  • US12506717B2 patent drawing
  • US12506717B2 patent drawing

AI summary

A communication system including a first and second module. A first network member is coupled to the first module, and a second network member is coupled to the second module. The modules being in communication with each other thereby allowing communication between the first network member and the second network member. The modules being configured to: encrypt a message, beginning with the encrypting of the message using a key and a salt, the salt being an entropy sourced random number produced using a one-way hash function producing hashes of an arbitrary length; stop the encrypting when the message is encrypted resulting in an encrypted message; encrypt the salt with the key resulting in an encrypted salt; assemble the encrypted salt, a demark character, the encrypted message and padding to form a data set; and securely communicate the data set from one of the modules to another of the modules.