Hybrid Hardware Software Cryptographic Processor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic implementations in embedded devices lack flexibility, which hampers their ability to adapt to new attacks and optimize hardware resources for various cryptographic algorithms, leading to performance issues and inadequate security.

Innovation Solution

A device with a central processing unit and RAM memory that incorporates hardware-specific elementary operations, allowing software instructions to manage and mask data, enabling flexible implementation of cryptographic algorithms by mixing dedicated hardware and software processes, and allowing control over randomization principles to adapt security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic algorithms are implemented fully in hardware, then security and performance are improved, but flexibility and adaptability to new attacks deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cryptographic algorithm is divided into multiple elementary operations that can be selectively implemented in hardware. The processor includes a set of hardware-accelerated elementary operations that can be configured through software to implement different cryptographic algorithms and security measures, allowing both high performance and flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system allows dynamic configuration of the cryptographic implementation through software control. The processor can adapt its hardware-accelerated operations to implement different cryptographic algorithms and security countermeasures based on threat models and performance requirements, rather than being fixed in hardware.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If cryptographic algorithms are implemented fully in software, then flexibility is improved, but performance deteriorates

Engineering Contradiction:
ImproveflexibilityVSAvoidperformance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

A set of hardware-accelerated elementary operations serves as an intermediary between the software cryptographic implementation and the physical hardware. These operations provide speedup for critical cryptographic functions while maintaining software control over the overall algorithm selection and security parameter configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If hardware resources are optimized for specific cryptographic algorithms, then performance for those algorithms is improved, but adaptability to other algorithms deteriorates

Engineering Contradiction:
ImproveperformanceVSAvoidalgorithm support
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The processor implements a universal set of elementary operations that can be configured through software to support multiple cryptographic algorithms including AES, DES, SHA-1, SHA-2, and others. The same hardware-accelerated operations can be reused across different algorithms by changing the software configuration, providing both performance and algorithm diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11232213B2Mixed hardware and software instructions for cryptographic functionalities implementation
Publication Date: 2022.01.25 THALES DIS FRANCE SA
  • US11232213B2 patent drawing

AI summary

The present invention relates to a device having a central processing unit, RAM memory and at least two hardware elementary operations, using registers of greater size than the one of the central processing unit, said device being such that construction of at least one part of RAM memory is managed only by the hardware elementary operations, hardware elementary operations themselves and masking of inputs/outputs/intermediary data are monitored by software instructions, said software instructions being able to address different cryptographic functionalities using said hardware elementary operations according to several ways depending on each concerned functionality, said software instructions being further able to address several levels of security in the execution of the different functionalities.