Inline Logic Circuit for Secure Data Packet Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial controllers face processing overhead and latency due to traditional methods of authentication and decryption of secure data packets, which limit data transfer rates and critical control functions.
Innovation Solution
An inline logic circuit is introduced to perform authentication and/or decryption of data packets as they are transferred from a network interface to a shared memory location, using an alternate completion bit to synchronize with the MAC, thereby reducing overall latency and processing burden on the SPP module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication and decryption methods are used for secure data packets, then security is maintained, but processing overhead and latency increase
Solution Approach 1:
The patent performs authentication and decryption operations in advance during the data transfer process itself, rather than waiting for complete packet reception. The inline logic circuit begins processing the data packet while it is still being transferred from network interface to shared memory, completing security operations before the data transfer concludes. This preliminary action eliminates post-transfer processing delays and reduces overall latency while maintaining security.
2Reliability
If traditional authentication and decryption methods are used for secure data packets, then security is maintained, but data transfer rate decreases
Solution Approach 1:
The patent performs authentication and decryption operations in advance during the data transfer process itself, rather than waiting for complete packet reception. The inline logic circuit begins processing the data packet while it is still being transferred from network interface to shared memory, completing security operations before the data transfer concludes. This preliminary action eliminates post-transfer processing delays and reduces overall latency while maintaining security.
Solution Approach 2:
The patent introduces an inline logic circuit as an intermediary component between the network interface and shared memory. This logic circuit intercepts data packets during transfer and performs authentication/decryption operations independently, acting as a mediator that handles security processing without blocking the main data transfer path. The MAC can continue transferring packets while the inline circuit processes them in parallel.
3Reliability
If authentication and decryption are performed after data transfer completes, then processing is thorough, but additional processing time and CPU cycles are required
Solution Approach 1:
The patent extracts the authentication and decryption operations from the main software processing path and implements them in dedicated hardware (inline logic circuit). This separation removes the processing burden from the CPU and SPP module, allowing them to focus on higher-level control functions while the hardware circuit handles security processing independently and in parallel with data transfer.
Solution Approach 2:
The patent introduces an inline logic circuit as an intermediary component between the network interface and shared memory. This logic circuit intercepts data packets during transfer and performs authentication/decryption operations independently, acting as a mediator that handles security processing without blocking the main data transfer path. The MAC can continue transferring packets while the inline circuit processes them in parallel.
Data Source
AI summary
A logic circuit for managing reception of secure data packets in an industrial controller snoops data being transferred by a Media Access Controller (MAC) between a network port and a shared memory location within the industrial controller. The logic circuit is configured to perform authentication and/or decryption on the data packet as the data packet is being transferred between the port and the shared memory location. The logic circuit performs authentication as the data is being transferred and completes authentication shortly after the MAC has completed transferring the data to the shared memory. The logic circuit coordinates operation with the MAC and signals a Software Packet Processing (SPP) module when authentication is complete. The logic circuit is further configured to decrypt the data packet, if necessary, and to similarly coordinate operation with the MAC and delay signaling the SPP module that data is ready until decryption is complete.


