MACSec Power Domain Segmentation for Mobile Die Size Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current MACSec designs face challenges in reducing power consumption while maintaining efficient packet processing, particularly in mobile environments where die size and power dissipation are critical concerns.
Innovation Solution
The MACSec entity is partitioned into multiple independently controlled power domains that can enter a reduced power consumption state when not in use, utilizing clock gating and buffering to manage power efficiently, and employing high-Vt cells and pipelining to minimize dynamic power dissipation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACSec security processing is implemented using traditional integrated circuit designs, then security protection functionality is achieved, but power consumption and die size become excessively large
Solution Approach 1:
The MACSec security processing circuit is divided into multiple independent processing elements (PEs), each capable of handling specific security operations. This segmentation allows the system to activate only the necessary PEs for current traffic requirements, significantly reducing overall power consumption while maintaining security functionality. Each PE can be independently controlled and powered down when not needed.
Solution Approach 2:
The patent implements dynamic power management where processing elements can transition between active and low-power states based on real-time traffic conditions. The system dynamically allocates processing resources to match actual security needs, avoiding continuous full-power operation and thereby reducing average power consumption while maintaining reliable security protection.
2Reliability
If MACSec security processing elements are integrated into the chip, then security functionality is provided, but the chip die size increases significantly
Solution Approach 1:
By segmenting the security processing into multiple specialized processing elements rather than implementing a monolithic security processor, the patent achieves efficient resource utilization. Each PE is optimized for specific operations, allowing compact design while providing comprehensive security functionality across the chip.
Solution Approach 2:
The processing elements are designed to handle multiple security operations and can be dynamically allocated to different security tasks. This multi-functionality allows a smaller number of PEs to provide comprehensive security protection, reducing the overall die area required compared to dedicated hardware for each security function.
3Reliability
If traditional security processing architectures are used, then comprehensive security coverage is achieved, but processing speed and efficiency are reduced
Solution Approach 1:
The segmentation of security processing into parallel processing elements enables simultaneous handling of multiple security operations on different packets or packet segments. This parallel processing capability significantly increases throughput and processing speed while maintaining comprehensive security coverage across all traffic.
Solution Approach 2:
The dynamic resource allocation allows the system to adapt processing capacity to actual traffic demands, activating additional processing elements only when needed. This dynamic approach maintains high processing speeds during peak security requirements while conserving resources during lower-traffic periods, overall improving productivity.
Data Source
AI summary
A media access control (MAC) security apparatus for a local area network interface includes a parser, an encryption engine, an authentication engine, and a first buffer. The parser is configured to output packets. The encryption engine is configured to receive the packets from the parser and generate encrypted data based on the packets received from the parser and cryptographic primitives. The encryption engine includes an advanced encryption standard engine configured to form the cryptographic primitives. The authentication engine is configured to perform authentication operations of the local area network interface based on the encrypted data from the encryption engine. The first buffer is configured to interface the encryption engine to the parser. The parser and the encryption engine process data at different rates. The first buffer is configured to compensate for the different rates.


