Programmable Systolic Cryptographic Modules for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT network security solutions are inadequate in detecting and preventing new, unknown attacks and malware, as they are designed to protect data in transit but not data at rest, leaving stored data vulnerable to intrusions and breaches, resulting in significant financial losses.

Innovation Solution

A security device with programmable systolic-matrix cryptographic modules and interfaces that encrypt incoming data packets using FPGAs, allowing for scalable, flexible, and high-speed encryption and decryption, capable of supporting various protocols and interfaces, thereby enhancing data security at rest and in transit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deterministic search and analytics engines (firewalls, IDS/IPS, malware products) are used to detect known attacks, then detection accuracy for known threats is improved, but the ability to detect new attacks, malware or virus variants deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic security system that transitions from static deterministic pattern matching to adaptive machine learning-based detection. The system continuously learns from new attack patterns and updates its detection models, enabling it to adapt to emerging threats while maintaining detection accuracy for known attacks through ensemble methods that combine traditional signatures with learned behaviors.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the fundamental detection parameters from fixed signatures and patterns to dynamic, learned representations of attack behaviors. By using machine learning models that can adjust their parameters based on training data, the system achieves both high detection accuracy for known threats and adaptability to new attack variants through continuous model updates and retraining.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If layering security products (firewalls, IDS/IPS, security analytics, malware software, access controls) is used to protect data in transit, then security coverage for network traffic is improved, but protection for data at rest deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidprotection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security platform that can protect both data in transit and data at rest through a unified architecture. The machine learning-based detection system and encryption capabilities are designed to operate across multiple data states and transmission mediums, providing comprehensive security coverage without requiring separate specialized systems for each protection scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional security products are used to prevent known attacks and general access denial attacks, then protection against deterministic threats is improved, but ability to stop new attacks and malware variants deteriorates

Engineering Contradiction:
Improveprotection effectivenessVSAvoidthreat response capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by continuously training machine learning models on emerging threat patterns before these attacks fully manifest in the network. The proactive model updating and anomaly detection capabilities allow the system to prepare defenses against new attack variants before they cause damage, maintaining protection effectiveness while gaining adaptability to evolving threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240311516A1Security device with programmable systolic-matrix cryptographic module and programmable input/output interface
Publication Date: 2024.09.19 SECTURION SYST
  • US20240311516A1 patent drawing
  • US20240311516A1 patent drawing
  • US20240311516A1 patent drawing

AI summary

A system includes programmable systolic cryptographic modules for security processing of packets from a data source. A first programmable input/output interface routes each incoming packet to one of the systolic cryptographic modules for encryption processing. A second programmable input/output interface routes the encrypted packets from the one systolic cryptographic module to a common data storage. In one embodiment, the first programmable input/output interface is coupled to an interchangeable physical interface that receives the incoming packets from the data source. In another embodiment, each cryptographic module includes a programmable systolic packet input engine, a programmable cryptographic engine, and a programmable systolic packet output engine, each configured as a systolic array (e.g., using FPGAs) for data processing.