Single DES Engine for Triple DES Gigabit Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems require significant host processing overhead, real estate, and power consumption for implementing layer 3 and layer 4 functions such as frame creation, segmentation, checksumming, and security processing, which is computation intensive and inefficient.
Innovation Solution
A 3DES IPsec circuit utilizing a single DES engine for gigabit/s IPsec security processing, which selectively processes input data through three stages of DES operations with intermediate result feedback, reducing hardware and power requirements while maintaining high processing speeds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional host processing is used for layer 3 and layer 4 functions, then processing capability is maintained, but host processing overhead, real estate, and power consumption increase significantly
Solution Approach 1:
The patent extracts security processing functions from the host system and implements them in a dedicated network peripheral device. The peripheral handles encryption/decryption operations independently, removing the computational burden from the host processor and reducing overall system power consumption while maintaining processing capability.
Solution Approach 2:
The network peripheral acts as an intermediary between the host system and the network. It offloads security processing tasks to this intermediate device, allowing the host to maintain processing capability without directly performing computation-intensive cryptographic operations.
2Productivity
If conventional host processing is used for layer 3 and layer 4 functions, then processing capability is maintained, but host processing overhead and real estate increase significantly
Solution Approach 1:
The patent extracts security processing functions from the host system and implements them in a dedicated network peripheral device. The peripheral handles encryption/decryption operations independently, removing the computational burden from the host processor and reducing overall system power consumption while maintaining processing capability.
Solution Approach 2:
The network peripheral acts as an intermediary between the host system and the network. It offloads security processing tasks to this intermediate device, allowing the host to maintain processing capability without directly performing computation-intensive cryptographic operations.
3Use of energy by stationary object
If Triple DES encryption is implemented using a single DES engine, then hardware real estate and power consumption are reduced, but processing speed may be compromised
Solution Approach 1:
The patent implements dynamic timing control where the single DES engine processes three 64-bit data blocks sequentially with optimized timing. The engine completes the first block in one clock cycle and uses feedback paths to prepare subsequent blocks, achieving gigabit/s processing speeds despite using a single engine rather than three parallel engines.
Data Source
AI summary
Security processing circuits are discussed which may be used alone or as part of a network interface device of a host system using a single DES engine to accomplish 3DES processing. The security processing circuit is adapted for selectively encrypting outgoing data and decrypting incoming data, where the network interface device may be fabricated as a single integrated circuit chip. Methods are also provided for performing 3DES encryption and decryption services between the host system and a network, in which security information is obtained from the host system, which is used together with a set of secret keys for 3DES processing data utilizing a single DES engine and an intermediate result fed back to the single DES engine of the 3DES IPsec circuit.


