IP Library Granted Patent US 11,552,782
Granted Patent B2
US 11,552,782 · App. 16/915,021 · Granted Jan 10, 2023

Securing system-on-chip (SoC) using incremental cryptography

Inventors: Prabhat Kumar Mishra (Gainesville, FL); Thelijjagoda S N Charles (Gainesville, FL); Yangdi Lyu (Gainesville, FL)
Assignee: UNIVERSITY OF FLORIDA RESEARCH FOUNDATION, INCORPORATED
H04L9/0618G06F21/606H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,782
App. No.
16/915,021
Granted
Jan 10, 2023
Kind
B2
Abstract

Various examples are provided related to software and hardware architectures that enable a lightweight incremental encryption scheme that is implemented on a System-on-chip (SoC) resource such as a network interface. In one example, among others, a method for incremental encryption includes obtaining, by a network interface (NI) of a sender intellectual property (IP) core in a network-on-chip (NoC) based system-on-chip (SoC) architecture, a payload for communication to a receiver intellectual property (IP) core; identifying, by the NI, one or more different blocks between the payload and a payload of a previous packet communicated between the sender IP core and the receiver IP core; and encrypting, by the NI, the one or more different blocks to create encrypted blocks of an encrypted payload.

Claims (34)

1. A method for incremental encryption of intellectual property (IP) core communications, comprising:

obtaining, by a network interface (NI) of a sender intellectual property (IP) core in a network-on-chip (NoC) based system-on-chip (SoC) architecture, a payload for communication to a receiver intellectual property (IP) core;

identifying, by the NI, one or more different blocks between the payload and a payload of a previous packet communicated between the sender IP core and the receiver IP core, each different block of the one or more different blocks comprising bitwise differences between a block of the payload and a corresponding block of the payload of the previous packet;

encrypting, by the NI, the one or more different blocks to create encrypted blocks of an encrypted payload; and

constructing, by the NI, a ciphertext from the encrypted blocks and the one or more different blocks to create the encrypted payload.

2. The method of claim 1 , further comprising:

generating, by the NI, helper data that indicates the one or more different blocks.

3. The method of claim 2 , further comprising:

generating a final packet for communication to the receiver IP core by combining at least the helper data and the encrypted payload.

4. The method of claim 3 , further comprising:

adding at least one filler to create the final packet.

5. The method of claim 3 , wherein the final packet is a same packet size as the previous packet.

6. The method of claim 1 , wherein encrypting the one or more different blocks to create encrypted blocks comprises:

splitting the payload into the one or more different blocks and encrypting the one or more different blocks.

7. The method of claim 1 , wherein the previous packet comprises a most recent one of a plurality of packets communicated between the sender IP core and the receiver IP core.

8. A method for decryption of intellectual property (IP) core communications, comprising:

identifying, by a network interface (NI) of a receiver intellectual property (IP) core in a network-on-chip (NoC) based system-on-chip (SoC) architecture, a packet comprising an encrypted payload received from a sender intellectual property (IP) core; and

decrypting, by the NI, the encrypted payload based at least in part on applying at least one parameter to create one or more different blocks corresponding to a payload of a previous packet identified by the receiver IP core communicated between the sender IP core and the receiver IP core, each different block of the one or more different blocks comprising bitwise differences between a block of the payload of the previous packet and a corresponding block of an unencrypted payload associated with the encrypted payload.

9. The method of claim 8 , wherein a plaintext header of the packet comprises helper data that indicates at least one location for the one or more different blocks associated with the previous packet.

10. The method of claim 9 , further comprising:

constructing, by the NI, a new payload based at least in part on combining the one or more different blocks with at least a portion of the payload of the previous packet based at least in part on the location.

11. The method of claim 8 , wherein the at least one parameter is stored in a register of the NI, and wherein the at least one parameter comprises a key or an initialization vector.

12. The method of claim 8 , wherein the packet comprises helper data that indicates at least one location for the one or more different blocks associated with the previous packet.

13. A method for incremental cryptography of intellectual property (IP) core communications in a network-on-chip (NoC) based system-on-chip (SoC) architecture, comprising:

obtaining, by a network interface (NI) of a sender intellectual property (IP) core, a payload for communication to a receiver intellectual property (IP) core;

splitting, by the NI, the payload into one or more different blocks, each different block of the one or more different blocks comprising bitwise differences between a block of the payload and a corresponding block of a payload stored in a register of the NI of the sender IP core, where the payload stored in the register is associated with the receiver IP core;

encrypting, by the NI, individual ones of the one or more different blocks to create encrypted blocks of an encrypted payload; and

constructing, by the NI, a ciphertext from the encrypted blocks and the one or more different blocks to create the encrypted payload.

14. The method of claim 13 , further comprising:

transmitting the encrypted payload comprising the ciphertext to the receiver IP core.

15. The method of claim 13 , wherein encrypting individual ones of the one or more different blocks occurs in parallel.

16. The method of claim 13 , further comprising transmitting helper data to the receiver IP core that indicates at least one location for the one or more different blocks.

17. The method of claim 13 , wherein encrypting individual ones of the one or more different blocks comprises storing or retrieving an initialization vector or a key.

18. The method of claim 17 , wherein the key comprises a 128-bit secret key, and the initialization vector comprises a 64-bit initialization vector for initializing a 128-bit internal state.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: MISHRA, PRABHAT KUMAR; CHARLES, THELIJJAGODA S N; LYU, YANGDI
To: UNIVERSITY OF FLORIDA RESEARCH FOUNDATION, INCORPORATED
Reel/Frame 057335/0595 →
CONFIRMATORY LICENSE Recorded Aug 18, 2020
From: UNIVERSITY OF FLORIDA
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 053532/0605 →
Continuity (2)
Provisional Application 62874187 · Jul 15, 2019
Related Publication 20210021404A1 · Jan 21, 2021
Cited By (1)
US 12,381,711