Trusted Cryptographic Processor Redundancy and Arbitration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems are inflexible and expensive to design, requiring separate devices for different security levels and interfaces, and struggle with asynchronous operations in high-assurance applications, leading to potential mismatches and operational suspensions due to independent microprocessors processing data out of order.

Innovation Solution

A cryptographic processor with multiple input and output ports, shared redundant processing elements, and arbitration logic that ensures consistent processing by comparing outputs and arbitrating port usage, allowing for reconfiguration and error detection in a scalable architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple separate cryptographic devices are used to support multiple interfaces and classification levels, then cryptographic processing capability and versatility are improved, but device complexity and system integration complexity increase linearly

Engineering Contradiction:
Improvecryptographic processing capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple cryptographic processing paths and interfaces into a single integrated cryptographic device. The device includes multiple input ports for different interfaces (e.g., HIPERLAN/2, Bluetooth, Wi-Fi) and multiple output ports, with a shared cryptographic processing core that can handle multiple algorithms and protocols simultaneously, eliminating the need for separate cryptographic devices for each interface.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic device is designed with universal processing capability to handle multiple cryptographic algorithms (AES, DES, 3DES, RC4, SHA-1, MD5), multiple interfaces, and different classification levels within a single device. The processing elements can be dynamically configured to support various cryptographic operations across different ports, providing multi-functionality without requiring separate dedicated devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If redundant microprocessors operate independently with asynchronous clocks, then processing speed and reliability are improved, but synchronization difficulty increases causing operational suspensions

Engineering Contradiction:
Improveprocessing reliabilityVSAvoidsynchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces shared resources including a common bus interface, shared memory, and unified control logic as intermediaries between redundant processing elements. These shared resources act as mediators that coordinate the operation of multiple processing elements, ensuring they process data in the same order and produce consistent results, thereby maintaining synchronization without requiring complex inter-processor communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The device is segmented into multiple independent processing elements that can operate in parallel, each handling specific cryptographic operations. These segmented processing elements are coordinated through shared resources to ensure consistent output, allowing the system to maintain both parallel processing capability and synchronization.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If data path reconfiguration is performed by redundant decision making logic, then operational flexibility is improved, but monitoring complexity increases due to asynchronous requests

Engineering Contradiction:
Improvedata path reconfiguration capabilityVSAvoidmonitoring logic complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the decision-making logic for data path reconfiguration into a unified control mechanism that is shared across all processing elements. This centralized control logic coordinates reconfiguration requests from different interfaces and classification levels, ensuring that path changes are monitored and executed consistently without requiring separate monitoring logic for each processing path.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3447675B1Trusted cryptographic processor
Publication Date: 2022.03.16 VIASAT INC
  • EP3447675B1 patent drawingFigure 1
  • EP3447675B1 patent drawingFigure 2
  • EP3447675B1 patent drawingFigure 3

AI summary

A cryptographic processor for redundantly-processing cryptographic operations is disclosed. The cryptographic processor includes a number of input ports, a first and second cryptographic engines, comparison logic and a plurality of output ports. The number of input ports is configured to accept both plaintext and ciphertext. Each of the number of input ports is coupled to both the first and second cryptographic engines. The comparison logic is configured to determine if the first and second cryptographic engines produce a result that is different. The number of output ports is configured to produce both plaintext and ciphertext.