Inline Cryptographic Engine for Peripheral Interface Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Peripheral interface data is vulnerable to observation and unauthorized access, and existing technologies lack effective encryption solutions that do not increase latency or require awareness from connected devices.
Innovation Solution
Incorporating an inline cryptographic engine within a peripheral interface controller to transparently encrypt data transmitted over peripheral interfaces and decrypt data received, while maintaining encryption keys secure within a system-on-a-chip (SOC) or attached memory, supporting both encryption and address translation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transmitted over peripheral interfaces, then communication between components is enabled, but data becomes vulnerable to observation and unauthorized access
Solution Approach 1:
The patent introduces an intermediary encryption layer between the data source and peripheral interface. The encryption engine acts as a mediator that transforms readable data into encrypted form before transmission, and decrypts incoming data. This intermediary mechanism protects data security while maintaining communication functionality, as the encryption/decryption process occurs transparently within the controller without affecting the communication capability.
2Object-affected harmful factors
If encryption is implemented for data transmission, then data security is improved, but latency increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring the encryption engine with encryption keys and algorithms before data transmission begins. The encryption context is established in advance, allowing data to be encrypted immediately upon arrival without setup delays. This preliminary preparation minimizes latency while maintaining security.
Solution Approach 2:
The encryption engine operates continuously during data transmission, processing data in real-time as it flows through the peripheral interface controller. Rather than batching or pausing for encryption operations, the system maintains continuous encryption/decryption action, ensuring that the security function does not interrupt the data flow and minimizing latency.
3Object-affected harmful factors
If encryption is implemented for data transmission, then data security is improved, but device complexity increases
Solution Approach 1:
The peripheral interface controller is designed with multi-functionality, integrating both encryption/decryption capabilities and address translation functions within a single device. The encryption engine is embedded within the existing controller architecture, allowing it to perform multiple functions (data security and address management) rather than requiring separate dedicated hardware for each function. This reduces overall system complexity while maintaining security.
4Adaptability or versatility
If encryption keys are stored externally, then key management flexibility is improved, but security is worsened
Solution Approach 1:
The patent implements a nested structure where encryption keys are stored within the secure memory space of the peripheral interface controller, which itself is part of the broader system architecture. The keys are nested within the controller's protected memory region, accessible only through controlled interfaces. This nesting provides security by placing keys within a protected environment while maintaining flexibility through the controller's interface management capabilities.
Data Source
AI summary
In an embodiment, a peripheral interface controller may include an inline cryptographic engine which may encrypt data being sent over a peripheral interface and decrypt data received from the peripheral interface. The encryption may be transparent to the device connected to the peripheral interface that is receiving/supplying the data. In an embodiment, the peripheral interface controller is included in a system on a chip (SOC) that also includes a memory controller configured to couple to a memory. The memory may be mounted on the SOC in a chip-on-chip or package-on-package configuration. The unencrypted data may be stored in the memory for use by other parts of the SOC (e.g. processors, on-chip peripherals, etc.). The keys used for the encryption/decryption of data may remain within the SOC.


