IP Library Granted Patent US 11,706,019
Granted Patent B2
US 11,706,019 · App. 17/347,049 · Granted Jul 18, 2023

Systems for providing secure communications using a protocol engine

Inventors: Anantha P. Chandrakasan (Belmont, MA); Chiraag Juvekar (Cambridge, MA); Utsav Banerjee (Cambridge, MA)
Assignee: Massachusetts Institute of Technology
H04L9/0643G06F21/602H04L9/0816H04L9/3239H04L9/3268H04L63/0428H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,706,019
App. No.
17/347,049
Granted
Jul 18, 2023
Kind
B2
Abstract

Systems and methods for implementing confidential communications between nodes of a network provide reduced power consumption, require less memory, and provide improved security, relative to previously-known systems and method. Preferred embodiments implement protocol functions in hardware, as opposed to software, to yield some or all of the foregoing improvements. Some embodiments use a hashing circuit for multiple purposes, while maintaining its ability to compute successive intermediate hash values. Some embodiments improve security of systems using circuits configured to leverage a favorable data format.

Claims (53)

1. A system for providing secure communications between a client and a server on a network, the system comprising:

a hashing circuit;

a memory circuit;

a fixed-logic protocol controller in data communication with the hashing circuit and the memory circuit, the fixed-logic protocol controller configured to execute a client-side handshake protocol;

a cryptographic accelerator in data communication with the hashing circuit and the fixed-logic protocol controller, the cryptographic accelerator configured to encrypt outbound messages and to decrypt inbound messages; and

a communications interface in operable communication with the network to transmit messages from the client to the server, and to receive messages from the server, wherein the cryptographic accelerator comprises a fixed-logic elliptic curve cryptography accelerator configured to operate on data in a zero-less signed digit format.

2. The system of claim 1 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator is a fixed-logic cryptographic accelerator.

3. The system of claim 1 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator comprises a programmable microprocessor.

4. The system of claim 1 , further comprising a programmable microprocessor separate from the fixed-logic protocol controller.

5. The system of claim 4 , further comprising a clock gate circuit configured to controllably disable a clock signal to the programmable microprocessor when the fixed-logic protocol controller is executing a handshake with the server.

6. The system of claim 1 , wherein the hashing circuit is a fixed-logic circuit configured to execute a SHA2-256 hash protocol and the fixed-logic protocol controller is configured to:

(a) use the hashing circuit to generate an intermediate hash value of a session hash from a set of messages;

(b) store hash state data from the hashing circuit to the memory circuit, the hash state data representing the state of the hashing circuit at a first time and including at least the intermediate hash value;

(c) use the hashing circuit for a secondary purpose, such secondary purpose leaving the hashing circuit in a second state; and subsequently

(d) read the hash state data from the memory circuit; and

(e) restore the hashing circuit to the state of the hashing circuit at the first time, so that the hashing circuit is configured to generate a subsequent hash value by operating on the intermediate hash value.

7. The system of claim 6 , wherein the hashing circuit is further configured to discard a message from the set of messages after using such message to generate an intermediate hash value and prior to generating the subsequent hash value.

8. A system for providing secure communications between a client and a server on a network, the system comprising:

a hashing circuit;

a memory circuit;

a fixed-logic protocol controller in data communication with the hashing circuit and the memory circuit, the fixed-logic protocol controller configured to execute a client-side handshake protocol;

a cryptographic accelerator in data communication with the hashing circuit and the fixed-logic protocol controller, the cryptographic accelerator configured to encrypt outbound messages and to decrypt inbound messages;

a communications interface in operable communication with the network to transmit messages from the client to the server, and to receive messages from the server;

a programmable microprocessor separate from the fixed-logic protocol controller; and

a clock gate circuit configured to controllably disable a clock signal to the programmable microprocessor when the fixed-logic protocol controller is executing a handshake with the server.

9. The system of claim 8 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator is a fixed-logic cryptographic accelerator.

10. The system of claim 8 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator comprises a programmable microprocessor.

11. The system of claim 8 , wherein the hashing circuit is a fixed-logic circuit configured to execute a SHA2-256 hash protocol and the fixed-logic protocol controller is configured to:

(a) use the hashing circuit to generate an intermediate hash value of a session hash from a set of messages;

(b) store hash state data from the hashing circuit to the memory circuit, the hash state data representing the state of the hashing circuit at a first time and including at least the intermediate hash value;

(c) use the hashing circuit for a secondary purpose, such secondary purpose leaving the hashing circuit in a second state; and subsequently

(d) read the hash state data from the memory circuit; and

(e) restore the hashing circuit to the state of the hashing circuit at the first time, so that the hashing circuit is configured to generate a subsequent hash value by operating on the intermediate hash value.

12. The system of claim 11 , wherein the hashing circuit is further configured to discard a message from the set of messages after using such message to generate an intermediate hash value and prior to generating the subsequent hash value.

13. The system of claim 8 , wherein the cryptographic accelerator comprises a fixed-logic elliptic curve cryptography accelerator configured to operate on data in a zero-less signed digit format.

14. A system for providing secure communications between a client and a server on a network, the system comprising:

a hashing circuit;

a memory circuit;

a fixed-logic protocol controller in data communication with the hashing circuit and the memory circuit, the fixed-logic protocol controller configured to execute a client-side handshake protocol;

a cryptographic accelerator in data communication with the hashing circuit and the fixed-logic protocol controller, the cryptographic accelerator configured to encrypt outbound messages and to decrypt inbound messages; and

a communications interface in operable communication with the network to transmit messages from the client to the server, and to receive messages from the server,

wherein the hashing circuit is a fixed-logic circuit configured to execute a SHA2-256 hash protocol and the fixed-logic protocol controller is configured to:

(a) use the hashing circuit to generate an intermediate hash value of a session hash from a set of messages;

(b) store hash state data from the hashing circuit to the memory circuit, the hash state data representing the state of the hashing circuit at a first time and including at least the intermediate hash value;

(c) use the hashing circuit for a secondary purpose, such secondary purpose leaving the hashing circuit in a second state; and subsequently

(d) read the hash state data from the memory circuit; and

(e) restore the hashing circuit to the state of the hashing circuit at the first time, so that the hashing circuit is configured to generate a subsequent hash value by operating on the intermediate hash value.

15. The system of claim 14 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator is a fixed-logic cryptographic accelerator.

16. The system of claim 14 , wherein the hashing circuit is a fixed-logic hashing circuit, and the cryptographic accelerator comprises a programmable microprocessor.

17. The system of claim 14 , further comprising a programmable microprocessor separate from the fixed-logic protocol controller.

18. The system of claim 17 , further comprising a clock gate circuit configured to controllably disable a clock signal to the programmable microprocessor when the fixed-logic protocol controller is executing a handshake with the server.

19. The system of claim 14 , wherein the hashing circuit is further configured to discard a message from the set of messages after using such message to generate an intermediate hash value and prior to generating the subsequent hash value.

20. The system of claim 14 , wherein the cryptographic accelerator comprises a fixed-logic elliptic curve cryptography accelerator configured to operate on data in a zero-less signed digit format.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2021
From: CHANDRAKASAN, ANANTHA; JUVEKAR, CHIRAAG; BANERJEE, UTSAV
To: MASSACHUSETTS INSTITUTE OF TECHNOLOGY
Reel/Frame 056664/0728 →
Continuity (3)
Division 16273813 · Feb 12, 2019
Provisional Application 62629527 · Feb 12, 2018
Related Publication 20210306138A1 · Sep 30, 2021
Cited By (1)
US 12,341,889