Architecture of an encryption circuit implementing various types of encryption algorithms simultaneously without a loss of performance
Abstract
An encryption circuit for simultaneously processing various encryption algorithms, the circuit being capable of being coupled with a host system hosted by a computing machine. The circuit comprises an input/output module responsible for the data exchanges between the host system and the circuit via a dedicated bus. An encryption module coupled with the input/output module is in charge of the encryption and decryption operations. Isolation means between the input/output module and the encryption module makes the sensitive information stored in the encryption module inaccessible to the host system and ensures the parallelism of the operations performed by the input/output module and the encryption module. The circuit is supported on a peripheral component interconnect card. The circuit is specifically adapted to provide “hardware” protection of computer servers or stations.
Claims
exact text as granted — not AI-modified1 - 14 . (canceled)
15 . An encryption circuit for simultaneously processing various encryption algorithms, the encryption circuit adapted to be coupled to a host computer system, the encryption circuit comprising:
an input/output module coupled to the host computer system via a dedicated bus, the input/output module handling data exchanges between the host computer system and the encryption circuit via the input/output module and the input/output module comprising a microcontroller and a memory; an encryption module coupled to the input/output module, said encryption module controlling encryption and decryption operations, as well as storage of all sensitive information of the encryption circuit; and isolation means operatively connected between the input/output module and the encryption module, the isolation means configured to make the sensitive information stored in the encryption module inaccessible to the host computer system.
16 . An encryption circuit according to claim 15 , wherein the isolation means comprises a dual-port memory.
17 . An encryption circuit according to claim 15 , wherein the isolation means comprises a dual-port memory coupled between the input/output module and the encryption module, the dual-port memory is coupled to a first bus and simultaneously handles the exchange of data, commands and statuses between the input/output and encryption modules, and isolation between the input/output and encryption modules.
18 . An encryption circuit as set forth in claim 16 , wherein the encryption module comprises:
a first encryption sub-module, dedicated to the processing of symmetric encryption algorithms, and being coupled with a first bus of the dual-port memory; a second encryption sub-module, dedicated to the processing of asymmetric encryption algorithms and being coupled with the first bus of the dual-port memory and including a separate internal second bus isolated from the first bus of the dual-port memory; and a CMOS memory, coupled with the dual-port memory via the first bus of the dual-port memory, containing the encryption keys.
19 . An encryption circuit as set forth in claim 17 , wherein the encryption module comprises:
a first encryption sub-module, dedicated to the processing of symmetric encryption algorithms, and being coupled with the first bus of the dual port memory; a second encryption sub-module, dedicated to the processing of asymmetric encryption algorithms and being coupled with the first bus of the dual-port memory and including a separate internal second bus isolated from the first bus of the dual-port memory; and a CMOS memory, coupled with the dual-port memory via the first bus of the dual-port memory, containing the encryption keys.
20 . An encryption circuit according to claim 18 , wherein the first encryption sub-module comprises an encryption component coupled with the dual-port memory via the first bus of the memory, comprising various encryption automata, respectively dedicated to the processing of symmetric encryption algorithms, and in that the second encryption sub-module comprises at least two encryption processors, respectively dedicated to the processing of asymmetric encryption algorithms, coupled with the encryption module via the internal second bus of the second sub-module and a bus isolator that isolates the second bus from the first bus of the dual-port memory.
21 . An encryption circuit according to claim 20 , wherein the encryption processors of the encryption module are of the CIP configuration.
22 . An encryption circuit according to claim 20 , wherein one of the two encryption processors is of the CIP type, and in that the other of the two encryption processors is of the ACE configuration.
23 . An encryption circuit according to claim 20 , wherein one of the two encryption processors is of the ACE configuration comprising a field programmable gate array (FPGA).
24 . An encryption circuit according to claim 23 , wherein the encryption component is of the SCE configuration.
25 . An encryption circuit according to claim 24 , wherein the encryption component comprises a field programmable array (FPGA).
26 . An encryption circuit according to claim 25 , wherein the second encryption sub-module comprises a flash memory PROM and an SRAM memory coupled with the second internal bus of the sub-module.
27 . An encryption circuit according to claim 20 , further comprising a CMOS memory containing security keys and security mechanisms that trigger a reset mechanism of the CMOS memory in case of an alarm.
28 . An encryption circuit according to claim 15 , wherein the microcontroller comprises:
an input/output processor and a PCI interface integrating DMA channels responsible for executing the data transfers between the host computer system and the circuit; and the memory comprises the flash memory containing the code of the input/output processor and a PCI interface integrating DMA channels responsible for executing the data transfers between the host computer system and the circuit; the flash memory containing the code of the input/output processor; and the static random access memory that receives a copy of the contents of the flash memory upon startup of the input/output processor.
29 . An encryption circuit according to claim 15 , comprising a serial link connected to input basic keys through a secure path independent of the dedicated PCI bus, said link controlled by the encryption module.
30 . An encryption circuit according to claim 29 , wherein the serial link (SL) allows downloading of proprietary algorithms into the first encryption sub-module.
31 . An encryption circuit as set forth in claim 15 , further including a card supporting the circuit.
32 . An encryption circuit as set forth in claim 18 , further including a card supporting the circuit.
33 . An encryption circuit as set forth in claim 20 , further including a card supporting the circuit.Join the waitlist — get patent alerts
Track US2007223688A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.