Inline Logic Circuit for Secure Data Packet Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial controllers face processing overhead and latency due to traditional methods of generating secure signatures and performing encryption for data packets, which limits data transfer rates and critical control functions.

Innovation Solution

An inline logic circuit is used to generate secure signatures and perform encryption in tandem with data packet transfer from shared memory to a network interface, reducing the processing burden on the Software Packet Processing module and optimizing data packet management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods of generating secure signatures and performing encryption are used, then data security is maintained, but processing overhead increases and data transfer rates decrease

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the encryption and signature generation functions from the main Software Packet Processing module by implementing them as a dedicated hardware logic circuit. This separation allows security operations to execute in parallel with data packet transfer, eliminating the processing bottleneck while maintaining security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hardware logic circuit as an intermediary component between the Software Packet Processing module and the Network Interface. This intermediary handles the computationally intensive encryption and signature generation tasks, freeing the software module to focus on packet management and allowing simultaneous data transfer without security processing delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional methods of generating secure signatures and performing encryption are used, then data security is maintained, but latency increases

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The hardware logic circuit is pre-configured with encryption algorithms and signature generation capabilities, allowing it to immediately process data packets as they arrive without requiring software intervention or setup. This preliminary preparation of the processing path eliminates latency associated with software-based security operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous data packet transfer by implementing security operations in parallel with the transfer process itself. The hardware logic circuit processes encryption and signature generation simultaneously with data movement through the system, eliminating idle time and maintaining continuous useful action throughout the data transmission pipeline.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If the Software Packet Processing module handles security operations, then processing is flexible, but the processing burden increases

Engineering Contradiction:
Improveprocessing flexibilityVSAvoidprocessing burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the computationally intensive security operations from the Software Packet Processing module and places them in a dedicated hardware logic circuit. This extraction reduces the processing burden on the software module while maintaining the flexibility to handle different packet types through configurable hardware parameters and control signals.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11599649B2Method and apparatus for managing transmission of secure data packets
Publication Date: 2023.03.07 ROCKWELL AUTOMATION TECH INC
  • US11599649B2 patent drawing
  • US11599649B2 patent drawing
  • US11599649B2 patent drawing

AI summary

A logic circuit for generation of data signatures and/or encryption of data packets to be transferred from an industrial controller snoops data as it is written to an output buffer within the industrial controller. The logic circuit generates a secure signature and/or coordinates encryption of the data packet being transferred between the shared memory location and the output buffer. If encryption of the data is required, an encryption module may both encrypt the data and generate a secure signature. If encryption is not required, the logic circuit generates the secure signature. In either case, the logic circuit controls ownership of the memory address in which the secure signature is to be written to coordinate with the MAC transferring the secure signature to the output buffer, providing a uniform interface between the SPP module and the MAC.