Process-Variation Encryption for Photonic Network-on-Chip Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern chip-multiprocessor devices, including photonic communication devices, face security risks due to third-party hardware designs that can introduce hardware trojans, particularly in broadcast and multicast communication, leading to data leakage and snooping attacks, which existing technologies have not adequately addressed.

Innovation Solution

The implementation of hardware-circuit-level encryption using process variation-based authentication signatures and an architecture-level reservation operation to secure photonic communication devices, specifically photonic network-on-chip (PNoC) architectures, which generates unique encryption keys based on process variation profiles and separates data and reservation signals to prevent snooping and manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If third-party hardware designs are used to reduce design time, then hardware design efficiency is improved, but security risks increase due to potential hardware trojans

Engineering Contradiction:
Improvehardware design efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements process-variation-based authentication that is established during fabrication before the hardware is deployed. Unique process variation profiles are captured and stored as authentication signatures, enabling security verification to be performed in advance rather than requiring continuous external security checks during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces process variation profiles as an intermediary authentication mechanism between the hardware design and the system. These profiles serve as a trusted intermediary that verifies the authenticity of hardware components without requiring direct inspection of the third-party design sources, thus enabling security verification while maintaining design efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If photonic communication is used for high-speed data transfer, then bandwidth and speed are improved, but vulnerability to snooping attacks increases

Engineering Contradiction:
Improvedata transfer speedVSAvoidsnooping attacks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies encryption to photonic data streams before transmission, proactively preventing snooping attacks rather than detecting them after the fact. The encryption process transforms the data into an unreadable format that cannot be intercepted or analyzed by external attackers, thus counteracting the inherent vulnerability of photonic signals to eavesdropping.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the inherent process variations, which are typically considered manufacturing defects or sources of signal instability in photonic devices, into a beneficial authentication mechanism. These variations create unique process variation profiles that serve as unclonable authentication signatures, transforming what was previously a harmful factor into a security asset.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If process variation-based authentication is implemented, then security against snooping is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where each photonic device automatically generates and stores its own process variation profile during fabrication, and uses this profile for authentication without requiring external verification infrastructure. The device independently performs authentication operations using its embedded process variation characteristics, eliminating the need for complex centralized authentication systems.

Inventive Principle:
Principle #25Self-service

4Reliability

If encryption is applied to photonic data streams, then security is improved, but power consumption and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and utilizes the naturally occurring process variations in photonic devices as the basis for authentication and encryption keys. By leveraging these pre-existing physical characteristics rather than generating artificial cryptographic keys through computationally intensive processes, the system achieves strong security with minimal additional power consumption and computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11645380B2Process-variability-based encryption for photonic communication architectures
Publication Date: 2023.05.09 COLORADO STATE UNIV RES FOUND
  • US11645380B2 patent drawing
  • US11645380B2 patent drawing
  • US11645380B2 patent drawing

AI summary

The exemplified methods and systems provide hardware-circuit-level encryption for inter-core communication of photonic communication devices such as photonic network-on-chip devices. In some embodiments, the hardware-circuit level encryption uses authentication signatures that are based on process variation that inherently occur during the fabrication of the photonic communication device. The hardware level encryption can facilitate high bandwidth on-chip data transfers while preventing hardware-based trojans embedded in components of the photonic communication device such as PNoC devices or preventing external snooping devices from snooping data from the neighboring photonic signal transmission medium in a shared photonic signal transmission medium. In some embodiments, the hardware-circuit-level encryption is used for unicast/multicast traffic.