Programmable Systolic Cryptographic Modules for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IT network security solutions are inadequate in detecting and preventing new, unknown attacks and malware, as they are designed to protect data in transit but not data at rest, leaving stored data vulnerable to intrusions and breaches, resulting in significant financial losses.
Innovation Solution
A security device with programmable systolic-matrix cryptographic modules and interfaces that encrypt incoming data packets using FPGAs, allowing for scalable, flexible, and high-speed encryption and decryption, capable of supporting various protocols and interfaces, thereby enhancing data security at rest and in transit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deterministic search and analytics engines (firewalls, IDS/IPS, malware products) are used to detect known attacks, then detection accuracy for known threats is improved, but the ability to detect new attacks, malware or virus variants deteriorates
Solution Approach 1:
The patent implements a dynamic security system that transitions from static deterministic pattern matching to adaptive machine learning-based detection. The system continuously learns from new attack patterns and updates its detection models, enabling it to adapt to emerging threats while maintaining detection accuracy for known attacks through ensemble methods that combine traditional signatures with learned behaviors.
Solution Approach 2:
The system changes the fundamental detection parameters from fixed signatures and patterns to dynamic, learned representations of attack behaviors. By using machine learning models that can adjust their parameters based on training data, the system achieves both high detection accuracy for known threats and adaptability to new attack variants through continuous model updates and retraining.
2Reliability
If layering security products (firewalls, IDS/IPS, security analytics, malware software, access controls) is used to protect data in transit, then security coverage for network traffic is improved, but protection for data at rest deteriorates
Solution Approach 1:
The patent creates a universal security platform that can protect both data in transit and data at rest through a unified architecture. The machine learning-based detection system and encryption capabilities are designed to operate across multiple data states and transmission mediums, providing comprehensive security coverage without requiring separate specialized systems for each protection scenario.
3Reliability
If traditional security products are used to prevent known attacks and general access denial attacks, then protection against deterministic threats is improved, but ability to stop new attacks and malware variants deteriorates
Solution Approach 1:
The system performs preliminary actions by continuously training machine learning models on emerging threat patterns before these attacks fully manifest in the network. The proactive model updating and anomaly detection capabilities allow the system to prepare defenses against new attack variants before they cause damage, maintaining protection effectiveness while gaining adaptability to evolving threats.
Data Source
AI summary
A system includes programmable systolic cryptographic modules for security processing of packets from a data source. A first programmable input/output interface routes each incoming packet to one of the systolic cryptographic modules for encryption processing. A second programmable input/output interface routes the encrypted packets from the one systolic cryptographic module to a common data storage. In one embodiment, the first programmable input/output interface is coupled to an interchangeable physical interface that receives the incoming packets from the data source. In another embodiment, each cryptographic module includes a programmable systolic packet input engine, a programmable cryptographic engine, and a programmable systolic packet output engine, each configured as a systolic array (e.g., using FPGAs) for data processing.


