Slice-Aggregated Cryptographic System for Secure Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems for data transfer over communication networks are costly due to redundant engines and suffer from latency and power inefficiencies, as well as lack of physical isolation in time division multiplexing approaches.

Innovation Solution

A slice-aggregated cryptographic system comprising multiple low-processing-rate slices that can be configured and aggregated to form higher processing rate units, achieving cost efficiency, power efficiency, and physical isolation for secure data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple cryptographic engines of different processing rates are included in the system, then the system can support various data transfer rates, but the system cost increases due to redundant engines

Engineering Contradiction:
Improvesupport for various data transfer ratesVSAvoidsystem cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cryptographic system is divided into multiple identical cryptographic engines, each capable of operating at a base processing rate. These engines can be aggregated in parallel to achieve higher processing rates, eliminating the need for redundant engines of different capabilities and reducing system cost while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each cryptographic engine is designed to be universal and multi-functional, capable of handling data transfers at its base rate and contributing to higher rate transfers when aggregated with other engines. This universality allows a single engine design to serve multiple purposes across different data transfer rate requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If time division multiplexing is used on a single cryptographic engine with ingress and egress buffers, then configurability is achieved, but latency and power consumption increase

Engineering Contradiction:
ImproveconfigurabilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Instead of using a single cryptographic engine with time division multiplexing, the system segments functionality across multiple identical engines operating in parallel. Each engine handles its own data flow without requiring complex buffer rearrangement and switching, thereby reducing latency while maintaining configurability through selective engine aggregation.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If time division multiplexing is used on a single cryptographic engine, then resource sharing is achieved, but power efficiency decreases due to inability to gate unused portions

Engineering Contradiction:
Improveresource sharingVSAvoidpower consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically activates or deactivates specific cryptographic engines based on the current data transfer requirements. When lower processing rates are needed, fewer engines are activated, allowing power gating of unused engines and improving power efficiency while maintaining resource sharing capabilities through selective aggregation.

Inventive Principle:
Principle #15Dynamics

4Productivity

If multiple cryptographic engines are used to achieve higher processing rates, then processing capacity increases, but physical isolation is lost compromising security

Engineering Contradiction:
Improveprocessing rateVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system processes different data transfers through separate cryptographic engines that are physically isolated from each other. Each engine maintains its own processing pipeline without sharing internal state or buffers with other engines, ensuring physical isolation and security while achieving higher aggregate processing rates through parallel engine operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3999991B1Slice-aggregated cryptographic system and method
Publication Date: 2025.06.18 XILINX INC
  • EP3999991B1 patent drawingFigure 1
  • EP3999991B1 patent drawingFigure 2
  • EP3999991B1 patent drawingFigure 3

AI summary

A system comprises one or more slice-aggregated cryptographic slices each configured to perform a plurality of operations on an incoming data transfer at a first processing rate by aggregating one or more individual cryptographic slices each configured to perform the plurality of operations on a portion of the incoming data transfer at a second processing rate. Each of the individual cryptographic slices comprises in a serial connection an ingress block configured to take the portion of the incoming data transfer at the second processing rate, a cryptographic engine configured to perform the operations on the portion of the incoming data transfer, an egress block configured to process a signature of the portion and output the portion of the incoming data transfer once the operations have completed. The first processing rate of each slice-aggregated cryptographic slices equals aggregated second processing rates of the individual cryptographic slices in the slice- aggregated cryptographic slice.