Nova Patents
CA2634812C

Cryptographic co-processor

Abstract

A secure communication platform on an integrated circuit is a highly integrated security processor which incorporates a general purpose digital signal processor (DSP) (62), along with a number of high performance cryptographic function elements, as well as a PCI and PCMCIA (14) interface. The secure communications platform is integrated with an off- the-shelf DSP so that a vendor who is interested in digital signal processing could also receive built-in security functions which cooperate with the DSP. The integrated circuit includes a callable library of cryptographic commands and encryption algorithms. An encryption processor is included to perform key and data encryption, as well as a high performance hash processor and a public key accelerator (28).

CA2634812C, drawing sheet 1
Sheet 1 of 55

Term

Term ended

Expired 16 September 2018, 8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

27 claims: 21 independent, 6 dependent

  1. 1
    CA 02634812 2008-07-18 CLAIMS:1. A method of implementing parallel Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of: initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing plaintext data in an encrypt memory and in a hash memory;loading the fetched context data stored in the registers into an encryption circuit and into a hash circuit;loading the plaintext data into the encryption circuit and into the hash circuit;encrypting the plaintext data in the encryption circuit to generate ciphertext data;hashing the plaintext data in the hash circuit to generate a hash digest;and storing the ciphertext data in the encrypt memory and the hash digest in a register.
  2. 2
    A method as defined in Claim 1, further comprising the step of:padding the plaintext data stored in the encrypt memory and the plaintext data stored in the hash memory to generate padded plaintext data, wherein the plaintext data used in the steps of loading the plaintext data, encrypting the plaintext data and hashing the plaintext data includes a padded portion of data.
  3. 4
    A method as defined in Claim 3, wherein the ciphertext data stored in the encrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the ciphertext data.
  4. 5
    A method of implementing parallel Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of:331 CA 02634812 2009-06-01 initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing ciphertext data in a decrypt memory and in a hash memory;loading the fetched context data stored in the registers into a decryption circuit and into a hash circuit;loading the ciphertext data into the decryption circuit and into the hash circuit;decrypting the ciphertext data in the decryption circuit to generate plaintext data;hashing the ciphertext data in the hash circuit to generate a hash digest;and storing the plaintext data in the decrypt memory and the hash digest in a register.
  5. 6
    A method as defined in Claim 5, further comprising the steps of:verifying pad bytes for correct pad properties;and discarding a padded portion of data from the plaintext data.
  6. 8
    A method as defined in Claim 7, wherein the plaintext data stored in the decrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the plaintext data.
  7. 9
    A method of implementing pipeline Internet Protocol Security (IPsec) operations simultaneously within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing plaintext data in an encrypt memory;loading the fetched context data stored in the registers into an encryption circuit and into a hash circuit;332 CA 02634812 2008-07-18 loading the plaintext data into the encryption circuit;encrypting the plaintext data in the encryption circuit to generate ciphertext data;storing the ciphertext data in the encrypt memory and in the hash memory;loading the ciphertext data stored in the hash memory into the hash circuit;hashing the ciphertext data in the hash circuit into a hash digest;and storing the hash digest in a register.
  8. 10
    A method as defined in Claim 9, further comprising the step of:padding the plaintext data stored in the encrypt memory to generate padded plaintext data, wherein the plaintext data used in the steps of loading the plaintext data and encrypting the plaintext data includes a padded portion of data.
  9. 12
    A method as defined in Claim 11, wherein the ciphertext data stored in the encrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the ciphertext data.
  10. 13
    A method of implementing pipeline Internet Protocol Security (IPsec) operations simultaneously within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing ciphertext data in a decrypt memory;loading the fetched context data stored in the registers into a decryption circuit and into a hash circuit;loading the ciphertext data into the decryption circuit;decrypting the ciphertext data in the decryption circuit to generate plaintext data;333 CA 02634812 2008-07-18 storing the plaintext data in the decrypt memory and in the hash memory;loading the plaintext data into the hash circuit;hashing the plaintext data in the hash circuit to generate a hash digest;and storing the hash digest in a register.
  11. 14
    A method as defined in Claim 13, further comprising the steps of:verifying pad bytes for correct pad properties;and discarding a padded portion of data from the plaintext data.
  12. 16
    A method as defined in Claim 15, wherein the plaintext data stored in the decrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the plaintext data.
  13. 17
    A method of implementing Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing ciphertext data in a decrypt memory;loading the fetched context data stored in the registers into a decryption circuit;loading the ciphertext data into the decryption circuit;decrypting the ciphertext data in the decryption circuit to generate plaintext data;and storing the plaintext data in the decrypt memory.
  14. 18
    A method as defined in Claim 17, further comprising the steps of:verifying pad bytes for correct pad properties;and 334 CA 02634812 2008-07-18 discarding a padded portion of data from the plaintext data.
  15. 20
    A method as defined in Claim 19, wherein the plaintext data stored in the decrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the plaintext data.
  16. 21
    A method of implementing Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing plaintext data in an encrypt memory;loading the fetched context data stored in the registers into an encryption circuit;loading the plaintext data into the encryption circuit;encrypting the plaintext data in the encryption circuit to generate ciphertext data;and storing the ciphertext data in the encrypt memory.
  17. 22
    A method as defined in Claim 21, further comprising the step of:padding the plaintext data stored in the encrypt memory to generate padded plaintext data, wherein the plaintext data used in the steps of loading the plaintext data and encrypting the plaintext data includes a padded portion of data.
  18. 24
    A method as defined in Claim 23, wherein the ciphertext data stored in the encrypt memory includes a last portion having eight bytes, and wherein the initialization vector includes the eight bytes of the last portion of the ciphertext data.
  19. 25
    A method of implementing Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing ciphertext data in a hash memory;loading the fetched context data stored in the registers into a hash circuit;loading the ciphertext data into the hash circuit;hashing the ciphertext data in the hash circuit to generate a hash digest;and storing the hash digest in a register.
  20. 26
    A method of implementing Internet Protocol Security (IPsec) operations within an integrated circuit comprising the steps of:initializing configuration and status registers;fetching context data from memory containing security associations;storing the fetched context data in registers;storing plaintext data in a hash memory;loading the fetched context data stored in the registers into a hash circuit;loading the plaintext data into the hash circuit;hashing the plaintext data in the hash circuit to generate a hash digest;and storing the hash digest in a register.
  21. 27
    A method as defined in Claim 26, further comprising the step of:padding the plaintext data stored in the hash memory to generate padded plaintext data, wherein the plaintext data used in the steps of loading the plaintext data and hashing the plaintext data includes a padded portion of data. 336
Independent claims21