Multi-lane Encryption Circuitry for Arbitrary Channel Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Building encryption circuitry for unknown encryption applications, such as programmable integrated circuit devices, is challenging due to the difficulty in mapping the number of channels to lanes, especially when data rates exceed device speeds or when channels and lanes are mismatched, leading to complications in delivering correct encryption keys and completing operations within clock cycles.
Innovation Solution
The development of multi-lane encryption circuitry with a fixed size, including encryption and authentication portions, where each lane can select encryption keys and manage partial hash states, allowing for flexible channel support and efficient operation even when the number of channels exceeds lanes, using key and hash channel selection circuitry to synchronize keys and hash values across stages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the number of lanes is fixed, then device complexity is reduced, but adaptability to different channel configurations deteriorates
Solution Approach 1:
The patent implements dynamic channel-to-lane mapping where the association between channels and lanes can be reconfigured based on the number of active channels. The system dynamically adjusts which lane processes which channel's data, allowing the fixed physical lane structure to adapt to varying channel configurations through programmable routing and key selection logic.
Solution Approach 2:
The encryption circuitry is designed with universal lane structures that can handle multiple channel configurations. Each lane is equipped with key selection circuitry and hash state management that enables it to process data from different channels depending on configuration, making the lane structure multi-functional rather than dedicated to specific channels.
2Productivity
If data rate exceeds device speed, then throughput is improved, but the number of required lanes increases
Solution Approach 1:
The patent implements preliminary hashing operations where hash states are computed in advance during idle cycles or parallel processing windows. By pre-computing authentication tags and maintaining hash state in registers, the system reduces the critical path delay and enables higher data rates without proportionally increasing the number of lanes, as computations are performed ahead of time rather than in the critical encryption path.
Solution Approach 2:
The system maintains continuous encryption and authentication operations across multiple lanes with pipelined processing. By keeping all lanes actively processing different channels simultaneously and using overlap techniques where hash computation for one channel occurs while encryption for another channel is being performed, the system maximizes throughput utilization of the fixed lane resources.
3Device complexity
If multiple channels are multiplexed onto fewer lanes, then device complexity is reduced, but key delivery accuracy deteriorates
Solution Approach 1:
The patent introduces channel identification signals and key selection circuitry as intermediary elements between the multiplexed data stream and the encryption lanes. Each lane receives channel ID information that acts as a mediator to select the appropriate encryption key from a key storage structure, ensuring that even though multiple channels share the same physical lane, the correct key is delivered to the correct lane at the correct time through the intermediary key selection logic.
Solution Approach 2:
The system pre-loads encryption keys into lane-specific key registers before the actual encryption operation begins. By preparing the correct key in advance in the target lane's key storage, the system ensures that when multiplexed data arrives, the key is already positioned and ready, eliminating timing errors and ensuring accurate key-to-channel matching without requiring complex real-time key switching during the encryption critical path.
Data Source
AI summary
Encryption/authentication circuitry includes an encryption portion having a first number of encryption lanes, each encryption lane including a plurality of encryption stages, and keyspace circuitry including a plurality of key lanes corresponding to a predetermined maximum number of channels. Each key lane has key storage stages corresponding to the encryption stages, and includes key memories for the predetermined maximum number of channels. Key channel selection circuitry for each stage selects a key from among the key memories at that stage. An authentication portion includes a second number of authentication lanes, hash key storage for the predetermined maximum number of channels, partial hash state storage for the predetermined number of channels, and hash channel selection circuitry. Based on the channel being processed, the hash selection circuitry selects, in each respective lane, respective hash key data from the hash key storage and respective partial hash state data from the partial hash state storage.


