Selective Data Encryption in Monolithic Semiconductor Circuits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure systems, such as pay-television systems, inefficiently encrypt all data regardless of its privilege status or the security of the devices handling it, making privileged data vulnerable to hacking during temporary storage in insecure external memory.
Innovation Solution
A monolithic semiconductor integrated circuit with two series of data pathways, one passing through a cryptographic circuit for selective encryption and decryption based on the security status of the devices, ensuring only privileged data is encrypted and decrypted accordingly, thereby reducing processing overhead and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all data is encrypted regardless of privilege status, then security is improved, but processing overhead increases
Solution Approach 1:
The patent applies different encryption treatments to different data based on their privilege status. Privileged data is encrypted while non-privileged data is not, creating local quality differentiation in the data protection approach. This resolves the contradiction by encrypting only where necessary rather than uniformly across all data.
Solution Approach 2:
Instead of applying encryption to all data (excessive action), the patent applies encryption only to privileged data (partial action). The system selectively encrypts based on privilege identification, avoiding the unnecessary processing overhead of encrypting non-privileged data while maintaining security for sensitive information.
2Adaptability or versatility
If privileged data is stored in insecure external memory, then storage flexibility is improved, but data vulnerability increases
Solution Approach 1:
The patent applies preliminary encryption to privileged data before storing it in insecure external memory. By encrypting the data in advance (preliminary action), the system enables flexible storage in insecure locations while protecting against vulnerability. The encryption is performed before the harmful factor (insecure storage environment) takes effect.
Solution Approach 2:
Encryption acts as an intermediary mechanism between privileged data and insecure external memory. The encryption layer mediates the interaction, allowing the data to be stored in flexible external memory locations while the encryption protects it from vulnerability. This intermediary protection resolves the contradiction between storage flexibility and security.
3Adaptability or versatility
If two series of data pathways are provided, then selective encryption capability is improved, but device complexity increases
Solution Approach 1:
The patent segments the data pathway into two series: one for encrypted data transmission and one for unencrypted data transmission. This segmentation enables selective encryption capability by routing privileged data through the encrypted pathway and non-privileged data through the unencrypted pathway. The segmentation resolves the contradiction by creating distinct paths for different data types.
Solution Approach 2:
The system dynamically selects which data pathway to use based on the privilege status of the data being transmitted. The routing is not fixed but adapts dynamically to the data characteristics. This dynamic behavior provides selective encryption capability while managing complexity through intelligent routing decisions rather than static complex architecture.
Data Source
AI summary
A monolithic semiconductor integrated circuit is provided for selectively encrypting or decrypting data transmitted between one of a plurality of devices on the circuit and an external memory. Two series of data pathways connect the devices and the external memory. The first series of data pathways passes through a cryptographic circuit causing data to be encrypted or decrypted, and the other series of data pathways provides an unhindered route. When a data access request is made by a device, the data is selectively routed along one of the two series of data pathways according to the identification of the device making the data access request. In one example, if data is transmitted from a device to the external memory, the data is selectively encrypted before being stored in the external memory if the device transmitting the data is identified as secure. Then, when that data is retrieved from the external memory by a second device, the data is selectively decrypted only if the second device is identified as secure.


