On-the-fly WLAN Encryption Eliminates Buffering Delays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional WLAN systems experience processing delays, inefficient data throughput, and high buffer loads due to multiple buffering stages during encryption and decryption processes, leading to potential data loss and increased CPU load.
Innovation Solution
Implementing an on-the-fly encryption and decryption process within a security enhancement unit and MAC unit, which eliminates buffering of encrypted data frames after encryption or before decryption, allowing for direct transmission and reception without order discrepancies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple buffering stages are used during encryption and decryption processes, then data security is improved, but processing delays increase and data throughput decreases
Solution Approach 1:
The patent implements a continuous encryption pipeline where plaintext data frames are encrypted on-the-fly without being buffered after encryption. The security enhancement unit processes data frames continuously as they arrive from the MAC unit, eliminating the interruption caused by traditional multi-stage buffering. This continuous processing maintains data security through proper encryption while eliminating the processing delays and throughput reduction caused by multiple buffering stages.
Solution Approach 2:
The patent performs encryption as a preliminary action immediately when data frames arrive from the MAC unit, before they would otherwise be buffered. By encrypting data frames on-the-fly in the security enhancement unit and immediately forwarding the encrypted frames back to the MAC unit, the system eliminates the need for subsequent buffering stages while maintaining security requirements.
2Reliability
If multiple buffering stages are used during encryption and decryption processes, then data security is improved, but processing time increases
Solution Approach 1:
The patent eliminates time-consuming buffering stages by implementing continuous on-the-fly encryption. Data frames are encrypted immediately upon arrival from the MAC unit and are forwarded without delay, removing the time loss associated with multiple buffering and re-reading operations while maintaining the security benefits of structured encryption processing.
3Reliability
If multiple buffering stages are used during encryption and decryption processes, then encryption security is maintained, but CPU processing load increases
Solution Approach 1:
The patent segments the encryption function from the MAC functionality by introducing a dedicated security enhancement unit. This separate unit handles all encryption and decryption operations, freeing the CPU from these processing tasks. The MAC unit focuses on medium access control while the security enhancement unit independently handles cryptographic operations, reducing overall CPU processing load while maintaining encryption security.
Solution Approach 2:
The security enhancement unit acts as an intermediary between the MAC unit and the encryption/decryption processes. It receives plaintext data frames from the MAC unit, performs the cryptographic operations, and returns encrypted frames to the MAC unit without involving the CPU in the detailed encryption processing, thereby reducing CPU processing load while maintaining security.
4Reliability
If data frames are buffered between transmission stages, then transmission reliability is improved, but data faults increase due to out of order frames
Solution Approach 1:
The patent eliminates the data fault problem by removing the buffering stage that causes out-of-order frame issues. Data frames are encrypted on-the-fly and immediately forwarded without being stored and re-read, ensuring that frames maintain their original sequence. This continuous processing preserves transmission reliability while eliminating the information loss caused by out-of-order buffering.
Data Source
AI summary
A communication device for performing cryptographically secured communication in a WLAN (Wireless Local Area Network) network is provided that comprises a security enhancement unit and a MAC (Medium Access Control) unit. The security enhancement unit is for encrypting plaintext data frames into encrypted data frames and/or decrypting encrypted data frames into plaintext data frames. The MAC unit is for managing communication between communication devices within the WLAN network by coordinating access to a shared wireless communication medium through which communication signals are transmitted. The security enhancement unit and the MAC unit are adapted to perform an on-the-fly encryption process and/or on-the-fly decryption process thereby exchanging the encrypted data frames without buffering the encrypted data frames after encryption or prior to decryption, respectively. The embodiments may provide an improved encryption/decryption architecture including an on-chip memory for performing on-the-fly encryption and/or on-the-fly decryption in the framework of 802.11i security enhancement.


