Slice-Aggregated Cryptographic System for Secure Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems for data transfer over communication networks are costly due to redundant engines and suffer from latency and power inefficiencies, as well as lack of physical isolation in time division multiplexing approaches.
Innovation Solution
A slice-aggregated cryptographic system comprising multiple low-processing-rate slices that can be configured and aggregated to form higher processing rate units, achieving cost efficiency, power efficiency, and physical isolation for secure data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple cryptographic engines of different processing rates are included in the system, then the system can support various data transfer rates, but the system cost increases due to redundant engines
Solution Approach 1:
The cryptographic system is divided into multiple identical cryptographic engines, each capable of operating at a base processing rate. These engines can be aggregated in parallel to achieve higher processing rates, eliminating the need for redundant engines of different capabilities and reducing system cost while maintaining adaptability.
Solution Approach 2:
Each cryptographic engine is designed to be universal and multi-functional, capable of handling data transfers at its base rate and contributing to higher rate transfers when aggregated with other engines. This universality allows a single engine design to serve multiple purposes across different data transfer rate requirements.
2Adaptability or versatility
If time division multiplexing is used on a single cryptographic engine with ingress and egress buffers, then configurability is achieved, but latency and power consumption increase
Solution Approach 1:
Instead of using a single cryptographic engine with time division multiplexing, the system segments functionality across multiple identical engines operating in parallel. Each engine handles its own data flow without requiring complex buffer rearrangement and switching, thereby reducing latency while maintaining configurability through selective engine aggregation.
3Adaptability or versatility
If time division multiplexing is used on a single cryptographic engine, then resource sharing is achieved, but power efficiency decreases due to inability to gate unused portions
Solution Approach 1:
The system dynamically activates or deactivates specific cryptographic engines based on the current data transfer requirements. When lower processing rates are needed, fewer engines are activated, allowing power gating of unused engines and improving power efficiency while maintaining resource sharing capabilities through selective aggregation.
4Productivity
If multiple cryptographic engines are used to achieve higher processing rates, then processing capacity increases, but physical isolation is lost compromising security
Solution Approach 1:
The system processes different data transfers through separate cryptographic engines that are physically isolated from each other. Each engine maintains its own processing pipeline without sharing internal state or buffers with other engines, ensuring physical isolation and security while achieving higher aggregate processing rates through parallel engine operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system comprises one or more slice-aggregated cryptographic slices each configured to perform a plurality of operations on an incoming data transfer at a first processing rate by aggregating one or more individual cryptographic slices each configured to perform the plurality of operations on a portion of the incoming data transfer at a second processing rate. Each of the individual cryptographic slices comprises in a serial connection an ingress block configured to take the portion of the incoming data transfer at the second processing rate, a cryptographic engine configured to perform the operations on the portion of the incoming data transfer, an egress block configured to process a signature of the portion and output the portion of the incoming data transfer once the operations have completed. The first processing rate of each slice-aggregated cryptographic slices equals aggregated second processing rates of the individual cryptographic slices in the slice- aggregated cryptographic slice.