Layout-Optimized Random Mask Distribution for Cryptographic Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing systems face challenges in generating and distributing large, high-quality random masks for cryptographic operations, which are essential for thwarting unauthorized access attempts, due to the need for extensive and complex circuitry that leads to routing and timing issues, particularly when multiple cryptographic processors share a common random number generator.
Innovation Solution
A layout-optimized random mask distribution system and method that minimizes the distance and size of busses between random number sources, mask generators, and cryptographic accelerators, reduces the need for buffers, and addresses signal integrity and routing congestion by using a FIPS-certified random number generator and multiple mask generators to provide frequent, large random masks to cryptographic processors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a common random number generator is shared by multiple cryptographic processors, then device complexity is reduced, but routing and timing issues arise due to extensive circuitry requirements
Solution Approach 1:
The patent divides the random mask distribution system into multiple dedicated mask generators, each serving specific cryptographic processors. This segmentation eliminates routing congestion and timing issues by creating localized distribution paths, while each mask generator remains relatively simple in structure.
Solution Approach 2:
The patent implements layout-optimized distribution where mask generators are strategically placed close to their target cryptographic processors. This local optimization minimizes bus length and routing complexity for each specific connection, improving signal integrity without requiring a completely complex system-wide rearchitecture.
2Reliability
If large random masks are generated and distributed to multiple cryptographic processors, then data security is enhanced, but routing congestion and timing issues increase
Solution Approach 1:
The system segments the distribution of large random masks by assigning dedicated mask generators to specific cryptographic processors. Each generator handles large mask generation locally, avoiding the need for complex system-wide routing of large data blocks across the entire chip.
Solution Approach 2:
The patent optimizes the physical layout arrangement of mask generators and cryptographic processors on the chip, using spatial optimization to minimize bus length and routing complexity. This dimensional optimization allows efficient distribution of large masks without increasing logical routing complexity.
3Reliability
If the distance between random number sources and cryptographic processors is minimized, then signal integrity is improved, but layout real estate requirements are constrained
Solution Approach 1:
The chip layout is segmented into multiple localized zones, each containing a mask generator and its associated cryptographic processors. This segmentation allows each zone to be compact, maintaining short distances for signal integrity while the overall chip area is efficiently utilized through modular organization.
Solution Approach 2:
The patent employs a nested layout structure where mask generators are positioned within or adjacent to clusters of cryptographic processors they serve. This nesting minimizes the distance between components while efficiently packing the layout to conserve overall chip real estate.
Data Source
AI summary
A data processing system includes a module for generating and distributing random masks to a number of cryptographic accelerators while providing for fewer total interconnects among the components generating the random masks. The module segments the tasks associated with generating random masks across a number of modules and blocks such that routing and timing problems can be minimized and layout can be optimized. A method for generating and distributing random masks to a number of cryptographic accelerators is also provided. The random masks are utilized by cryptographic accelerators to protect secret keys, and data associated with those keys, from discovery by unauthorized users.


