Link IDE MAC Circuit for Silent Data Corruption Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches for providing data integrity and encryption for link communications suffer from performance/latency penalties, increased duplication of encryption circuitry, and power consumption concerns, while also being vulnerable to silent data corruption and physical attacks.
Innovation Solution
The implementation of a system that combines error detection/correction with link integrity and encryption (IDE) message authentication code (MAC) to ensure data integrity, using a transmitter to generate protection bits, encrypt them, and compute a link IDE MAC, while the receiver regenerates the protection bits to verify the MAC, thereby achieving high levels of silent data corruption protection at low cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but performance/latency penalty increases
Solution Approach 1:
The system generates protection bits (such as CRC or ECC codes) on the plaintext data before encryption occurs. This preliminary generation allows the protection information to be prepared in advance, avoiding the need to generate it after encryption, thereby reducing latency and performance penalty while maintaining data protection integrity.
2Reliability
If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but duplication of encryption circuitry increases
Solution Approach 1:
The system combines error detection/correction protection with cryptographic protection into a unified approach. By merging these functions and using a single encryption circuitry that processes both the plaintext data and the pre-generated protection bits together, the patent eliminates the need for separate duplicated encryption circuits, thereby reducing device complexity while maintaining comprehensive data protection.
3Reliability
If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but power consumption increases
Solution Approach 1:
By generating protection bits on plaintext before encryption, the system avoids the need for redundant encryption operations on protection data. This preliminary action reduces the total computational workload and minimizes the operation of power-intensive encryption circuitry, thereby reducing overall power consumption while maintaining data protection integrity.
Solution Approach 2:
The combined error detection/correction and cryptographic protection approach processes both data and protection bits through a single encryption operation. This merging eliminates the need for separate encryption passes, reducing the cumulative power consumption that would result from multiple independent encryption operations while maintaining comprehensive data protection.
4Reliability
If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but bandwidth overhead increases
Solution Approach 1:
The system generates protection bits on plaintext before encryption and processes them together with the data through a single encryption operation. This approach avoids generating separate protection data after encryption, thereby minimizing additional bandwidth overhead while maintaining data protection integrity through the combined protection mechanism.
Data Source
AI summary
In one embodiment, an apparatus includes: an integrity circuit to receive data and generate a protection code based at least in part on the data; a cryptographic circuit coupled to the integrity circuit to encrypt the data into encrypted data and encrypt the protection code into an encrypted protection code; a message authentication code (MAC) circuit coupled to the cryptographic circuit to compute a MAC comprising a tag using header information, the encrypted data, and the encrypted protection code; and an output circuit to send the header information, the encrypted data, and the tag to a receiver via a link. Other embodiments are described and claimed.


