Inline Logic Circuit for Secure Data Packet Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial controllers face processing overhead and latency due to traditional methods of authentication and decryption of secure data packets, which limit data transfer rates and critical control functions.

Innovation Solution

An inline logic circuit is introduced to perform authentication and/or decryption of data packets as they are transferred from a network interface to a shared memory location, using an alternate completion bit to synchronize with the MAC, thereby reducing overall latency and processing burden on the SPP module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and decryption methods are used for secure data packets, then security is maintained, but processing overhead and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and decryption operations in advance during the data transfer process itself, rather than waiting for complete packet reception. The inline logic circuit begins processing the data packet while it is still being transferred from network interface to shared memory, completing security operations before the data transfer concludes. This preliminary action eliminates post-transfer processing delays and reduces overall latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional authentication and decryption methods are used for secure data packets, then security is maintained, but data transfer rate decreases

Engineering Contradiction:
ImprovesecurityVSAvoiddata transfer rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs authentication and decryption operations in advance during the data transfer process itself, rather than waiting for complete packet reception. The inline logic circuit begins processing the data packet while it is still being transferred from network interface to shared memory, completing security operations before the data transfer concludes. This preliminary action eliminates post-transfer processing delays and reduces overall latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an inline logic circuit as an intermediary component between the network interface and shared memory. This logic circuit intercepts data packets during transfer and performs authentication/decryption operations independently, acting as a mediator that handles security processing without blocking the main data transfer path. The MAC can continue transferring packets while the inline circuit processes them in parallel.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication and decryption are performed after data transfer completes, then processing is thorough, but additional processing time and CPU cycles are required

Engineering Contradiction:
Improveprocessing thoroughnessVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and decryption operations from the main software processing path and implements them in dedicated hardware (inline logic circuit). This separation removes the processing burden from the CPU and SPP module, allowing them to focus on higher-level control functions while the hardware circuit handles security processing independently and in parallel with data transfer.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an inline logic circuit as an intermediary component between the network interface and shared memory. This logic circuit intercepts data packets during transfer and performs authentication/decryption operations independently, acting as a mediator that handles security processing without blocking the main data transfer path. The MAC can continue transferring packets while the inline circuit processes them in parallel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12052231B2Method and apparatus for managing reception of secure data packets
Publication Date: 2024.07.30 ROCKWELL AUTOMATION TECH INC
  • US12052231B2 patent drawing
  • US12052231B2 patent drawing
  • US12052231B2 patent drawing

AI summary

A logic circuit for managing reception of secure data packets in an industrial controller snoops data being transferred by a Media Access Controller (MAC) between a network port and a shared memory location within the industrial controller. The logic circuit is configured to perform authentication and/or decryption on the data packet as the data packet is being transferred between the port and the shared memory location. The logic circuit performs authentication as the data is being transferred and completes authentication shortly after the MAC has completed transferring the data to the shared memory. The logic circuit coordinates operation with the MAC and signals a Software Packet Processing (SPP) module when authentication is complete. The logic circuit is further configured to decrypt the data packet, if necessary, and to similarly coordinate operation with the MAC and delay signaling the SPP module that data is ready until decryption is complete.