IP Library › Granted Patent US 8,539,252
Granted Patent B2
US 8,539,252 · App. 13/493,158 · Granted Sep 17, 2013

Method and system for protecting data

Inventor: Andrew Dellow (Minchinhampton, GB)
Assignee: Broadcom Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,539,252
App. No.
13/493,158
Granted
Sep 17, 2013
Kind
B2
Abstract

Methods and systems for protecting data may include controlling encryption and/or decryption, utilizing an encryption/decryption algorithm, rights related to the source and destination addresses, and encryption/decryption keys. The source location and/or destination of the data may comprise protected or unprotected memory. One or more of a plurality of algorithms may be utilized for the encryption and/or decryption. The rights may be stored in a key table, which may be stored on-chip, and may be reprogrammable. One or more keys for the encryption and/or decryption may be received from an external source or generated within the chip. The encryption/decryption algorithm may be selected based on two or more encryption/decryption algorithms, and additionally based on the source address, destination address, source rights, and destination rights.

Claims (40)

1. A method for data communication, comprising:

storing a descriptor in a memory, wherein the descriptor comprises a source address, a destination address, a first encryption/decryption algorithm, and a key pointer;

storing a key slot in a key table, wherein the key slot comprises source rights, destination rights, a second encryption/decryption algorithm, and a key;

encrypting or decrypting data located at the source address using the first encryption/decryption algorithm, the second encryption/decryption algorithm, and the key; and

storing the encrypted or decrypted data to the destination address.

2. A method for data communication according to claim 1 , further comprising:

receiving the key from an external source.

3. A method for data communication according to claim 1 , further comprising generating the key using the key table.

4. A method for data communication according to claim 1 , wherein the key pointer points to the key slot in the key table.

5. A method for data communication according to claim 1 , further comprising:

determining if the first encryption/decryption algorithm matches the second encryption/decryption algorithm.

6. A method for data communication according to claim 5 , wherein the determining compares the source address and source rights.

7. A method for data communication according to claim 5 , wherein the determining compares the destination address and destination rights.

8. A method for data communication according to claim 1 , further comprising:

determining if encryption is requested, and, if so, encrypting the data using the first encryption/decryption algorithm and the key.

9. A method for data communication according to claim 1 , further comprising:

determining if decryption is requested, and, if so, decrypting the data using the first encryption/decryption algorithm and the key.

10. A method for data communication according to claim 1 , further comprising:

determining the source rights based on a location of the source address in memory.

11. A method for data communication according to claim 1 , further comprising determining the destination rights based on a location of the destination address in memory.

12. A system for data communication, comprising:

a memory configured to store a descriptor;

a key table configured to store a key slot connected to the memory;

a security logic block, connected to both the memory and the key table, configured to select a final encryption/decryption algorithm; and

an encryption/decryption block, connected to the security logic block, the memory, and the key table, configured to generate an output data by encrypting/decrypting an input data using the final encryption/decryption algorithm;

wherein:

the descriptor includes a source address, a destination address, a first encryption/decryption algorithm, and a key pointer;

the key slot includes source rights, destination rights, a second encryption/decryption algorithm, and a key;

the input data used by the encryption/decryption block is read from the source address; and

the output data is stored in the destination address.

13. A system for data communication according to claim 12 , wherein the key table is configured to receive the key from an external source.

14. A system for data communication according to claim 12 , wherein the key table is configured to generate the key.

15. A system for data communication according to claim 12 , wherein the key pointer is configured to point to the key slot in the key table.

16. A system for data communication according to claim 12 , wherein the security logic block is configured to compare the first and second encryption/decryption algorithms to select the final encryption/decryption algorithm.

17. A system for data communication according to claim 16 , wherein the security logic is further configured to compare the source address and source rights to select the final encryption/decryption algorithm.

18. A system for data communication according to claim 16 , wherein the security logic is further configured to compare the destination address and destination rights to select the final encryption/decryption algorithm.

19. A system for data communication according to claim 12 , further comprising:

a security system connected to the encryption/decryption block and configured to indicate if encryption or decryption has been requested.

20. A system for data communication according to claim 12 , wherein the key table is configured to determine the source rights based on the source address.

21. A system for data communication according to claim 12 , wherein the key table is configured to determine the destination rights based on the destination address.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE ERROR IN RECORDING THE MERGER IN THE INCORRECT US PATENT NO. 8,876,094 PREVIOUSLY RECORDED ON REEL 047351 FRAME 0384. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 8, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 049248/0558 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE MERGER PREVIOUSLY RECORDED AT REEL: 047230 FRAME: 0910. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047351/0384 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047230/0910 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2012
From: DELLOW, ANDREW
To: BROADCOM CORPORATION
Reel/Frame 028353/0777 →
Continuity (2)
Continuation 11858530 · Sep 20, 2007
Related Publication 20120254627A1 · Oct 4, 2012