Parallel Encryption Hardware Architecture for High Speed Data Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption and decryption algorithms, such as AES-ECB, face challenges in achieving high data rates required for SAS/SATA interfaces, particularly when using a single engine, which results in data transmission rates lower than desired, especially when encrypting or decrypting data at 300 MHz clock frequency.
Innovation Solution
A hardware architecture that employs parallel processing and pipeline operations using multiple encryption/decryption units, sharing key expansion units, and tweaking value managers to generate and apply tweaking values, enabling simultaneous encryption/decryption of data blocks with common keys, and handling partial codewords through feedback mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a single encryption/decryption engine is used, then device complexity is reduced, but data transmission rate becomes insufficient for SAS/SATA interfaces
Solution Approach 1:
The encryption device is divided into multiple independent encryption units (first encryption unit, second encryption unit, etc.), each capable of processing data blocks independently. This segmentation allows parallel processing of multiple data blocks simultaneously, thereby increasing the overall data transmission rate while maintaining manageable complexity through modular design
Solution Approach 2:
Multiple encryption units share common hardware components including the key expansion unit, tweakable block cipher engine, and round key storage. By merging these resources, the system achieves high throughput through parallel processing without proportionally increasing device complexity, as the shared components serve multiple units simultaneously
2Productivity
If multiple encryption units operate in parallel, then encryption speed increases, but hardware footprint increases
Solution Approach 1:
Multiple encryption units share common hardware resources including the key expansion unit, tweakable block cipher engine, and round key storage memory. This resource sharing allows the system to achieve parallel processing capability with multiple encryption units while avoiding the proportional increase in hardware footprint that would result from completely independent units
Solution Approach 2:
The key expansion unit and block cipher engine are designed as universal components that can serve multiple encryption units. The key expansion unit can generate round keys for different units, and the block cipher engine can process data from multiple units sequentially or in parallel, making these components multi-functional and reducing overall hardware requirements
Data Source
AI summary
The disclosure provides a hardware architecture for encryption and decryption device. The hardware architecture can improve the encryption and decryption data rate by using parallel processing, and pipeline operation. Further, the hardware architecture can save footprint by sharing hardware components. Additionally, the hardware architecture can be associated with a memory to protect the information stored at the memory. The encryption device can include a tweaking value manager that is configured to generate an array of tweaking values corresponding to the array of data blocks based on a tweaking encryption key, a first encryption unit that is configured to encrypt a first portion of the array of data blocks into a first portion of encrypted data blocks based on corresponding tweaking values and a data encryption key, a second encryption unit that is configured to encrypt a second portion of the array of data blocks into a second portion of encrypted data blocks based on corresponding tweaking values and the data encryption key, and a data block combiner that is configured to combine the first portion of encrypted data blocks and the second portion of encrypted data blocks into an array of encrypted data blocks.


