Link IDE MAC Circuit for Silent Data Corruption Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for providing data integrity and encryption for link communications suffer from performance/latency penalties, increased duplication of encryption circuitry, and power consumption concerns, while also being vulnerable to silent data corruption and physical attacks.

Innovation Solution

The implementation of a system that combines error detection/correction with link integrity and encryption (IDE) message authentication code (MAC) to ensure data integrity, using a transmitter to generate protection bits, encrypt them, and compute a link IDE MAC, while the receiver regenerates the protection bits to verify the MAC, thereby achieving high levels of silent data corruption protection at low cost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but performance/latency penalty increases

Engineering Contradiction:
Improvedata protectionVSAvoidperformance/latency penalty
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system generates protection bits (such as CRC or ECC codes) on the plaintext data before encryption occurs. This preliminary generation allows the protection information to be prepared in advance, avoiding the need to generate it after encryption, thereby reducing latency and performance penalty while maintaining data protection integrity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but duplication of encryption circuitry increases

Engineering Contradiction:
Improvedata protectionVSAvoidduplication of encryption circuitry
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system combines error detection/correction protection with cryptographic protection into a unified approach. By merging these functions and using a single encryption circuitry that processes both the plaintext data and the pre-generated protection bits together, the patent eliminates the need for separate duplicated encryption circuits, thereby reducing device complexity while maintaining comprehensive data protection.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but power consumption increases

Engineering Contradiction:
Improvedata protectionVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

By generating protection bits on plaintext before encryption, the system avoids the need for redundant encryption operations on protection data. This preliminary action reduces the total computational workload and minimizes the operation of power-intensive encryption circuitry, thereby reducing overall power consumption while maintaining data protection integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The combined error detection/correction and cryptographic protection approach processes both data and protection bits through a single encryption operation. This merging eliminates the need for separate encryption passes, reducing the cumulative power consumption that would result from multiple independent encryption operations while maintaining comprehensive data protection.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If current approaches for providing data integrity and encryption are implemented, then data protection is improved, but bandwidth overhead increases

Engineering Contradiction:
Improvedata protectionVSAvoidbandwidth overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system generates protection bits on plaintext before encryption and processes them together with the data through a single encryption operation. This approach avoids generating separate protection data after encryption, thereby minimizing additional bandwidth overhead while maintaining data protection integrity through the combined protection mechanism.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250117285A1System, Apparatus And Method For Providing Protection Against Silent Data Corruption In A Link
Publication Date: 2025.04.10 INTEL CORP
  • US20250117285A1 patent drawing
  • US20250117285A1 patent drawing
  • US20250117285A1 patent drawing

AI summary

In one embodiment, an apparatus includes: an integrity circuit to receive data and generate a protection code based at least in part on the data; a cryptographic circuit coupled to the integrity circuit to encrypt the data into encrypted data and encrypt the protection code into an encrypted protection code; a message authentication code (MAC) circuit coupled to the cryptographic circuit to compute a MAC comprising a tag using header information, the encrypted data, and the encrypted protection code; and an output circuit to send the header information, the encrypted data, and the tag to a receiver via a link. Other embodiments are described and claimed.