Scalable HAIPE Architecture Using Segmented FPGA Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current commercial and government network security solutions, particularly IPSec, do not adequately address vulnerabilities such as flow analysis, routing spoofs, and key management spoofs, and there is a need for a scalable hardware architecture that supports High Assurance Internet Protocol Encryption (HAIPE) with enhanced features like Over the Network Key Management and guaranteed interoperability.

Innovation Solution

A scalable hardware architecture featuring Field Programmable Gate Arrays (FPGAs) for cryptographic processing, with separate data processing and management subsystems, and an integrated control and data processor, enabling efficient packet encryption, decryption, authentication, and routing while supporting layered IP protocol stacks and future upgrades.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware platform is designed to provide required computational support for HAIPE, then security and performance are improved, but cost, size, and weight increase

Engineering Contradiction:
ImprovesecurityVSAvoidweight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The system is divided into separate processing units (first processing unit for red side, second processing unit for black side) and a cryptographic unit, allowing independent optimization of each component's weight and performance characteristics while maintaining overall security requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs Field Programmable Gate Arrays (FPGAs) that allow computational parameters to be changed and optimized based on specific application requirements, enabling the platform to provide required computational support while adjusting weight and cost parameters through reconfiguration rather than hardware changes

Inventive Principle:
Principle #35Parameter changes

2Reliability

If HAIPE protocol features are added to address vulnerabilities, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The HAIPE protocol implementation is segmented into distinct functional units: data processing subsystems handled by separate processing units and cryptographic functions handled by a dedicated cryptographic unit, reducing the complexity burden on any single component while maintaining comprehensive security features

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic unit serves as an intermediary between the first and second processing units, managing the complex cryptographic operations and key management functions required by HAIPE, thereby simplifying the overall system architecture by centralizing complexity in a dedicated mediator component

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If data processing and management functions are integrated, then device simplicity is improved, but security and control separation deteriorate

Engineering Contradiction:
ImprovesimplicityVSAvoidcontrol separation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system explicitly segments control functions (management subsystem) from data processing functions (data processing subsystems), with each having dedicated processing units that communicate through defined interfaces, ensuring that even though the physical device may be integrated, the functional separation maintains security and control integrity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic unit acts as an intermediary that enforces separation between management and data processing functions, requiring all communication between these subsystems to pass through controlled cryptographic interfaces, thereby maintaining security boundaries while allowing integrated operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7904711B2Scaleable architecture to support high assurance internet protocol encryption (HAIPE)
Publication Date: 2011.03.08 CROGA INNOVATIONS LTD
  • US7904711B2 patent drawing
  • US7904711B2 patent drawing
  • US7904711B2 patent drawing

AI summary

A scalable internet protocol (IP) encryption system includes a cryptographic unit that processes sensitive data for packet encryption/decryption and data authentication. A first processing unit with an optional IP Layer hardware accelerator includes a data processing subsystem that processes sensitive data and forwards the data to the cryptographic unit for encryption and data authentication. A management subsystem is operative with the cryptographic unit for configuring IP networking functions and distributing network configuration information to the data processing subsystem through the cryptographic unit. Data processing is separated from management and control functions at the data processing and management subsystems. A second processing unit with an optional IP Layer hardware accelerator receives the encrypted data from the cryptographic unit and processes the encrypted data for IP packet routing, fragmentation and reassembly and receives network configuration information from the management subsystem via the cryptographic unit.