Nova Patents
EP1908210B1

Trusted cryptographic processor

Abstract

This record has no abstract on file.

EP1908210B1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 5 July 2026, 0.2 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

9 claims: 1 independent, 8 dependent

  1. 1
    A cryptographic processor (500) for redundantly-processing cryptographic operations, the cryptographic processor comprising:a bi-directional plaintext interface;a bi-directional ciphertext interface;at least one additional bi-directional plaintext interface or bi-directional ciphertext interface, wherein each of the interfaces is bi-directional to include an input port (428) and an output port (424), wherein at least one of the input ports is configured to receive a first plaintext data packet and a first ciphertext data packet, wherein at least one of the output ports is configured to send out a second ciphertext data packet and a second plaintext data packet;a first cryptographic engine (404-1) coupled to the input ports of the interfaces;a second cryptographic engine (404-2) coupled to the input ports of the interfaces, the first cryptographic engine (404-1) and the second cryptographic engine (404-2) being each configured to perform encryption of the first plaintext data packet to produce the second ciphertext data packet as an output and decryption of the first ciphertext data packet to produce the second plaintext data packet as an output;a first arbitration logic (312) and a second arbitration logic (314) configured to: receive a request to open the appropriate input port (428) when one of the interfaces has a data packet to be routed through the first cryptographic engine (404-1) and the second cryptographic engine (404-2), and open the appropriate input port (428 according to the request;receive a request to open the appropriate output port (424) when the first cryptographic engine (404-1) and the second cryptographic engine (404-2) receive the data packet, and open the appropriate output port (424) according to the request;and ensure that only one input port (428) is opened at a time, and that only one output port (424) is opened at a time, the first arbitration logic (312) and the second arbitration logic (314) being configured to be instructed to close all of the output ports (424) when an entire data packet has been sent out of the output port (424), wherein a port (428-1, 428-2, 428-3, 428-4, 424-1, 424-3) is only opened if the first arbitration logic (312) and the second arbitration logic (314) are in agreement as to which port (428-1, 428-2, 428-3, 428-4, 424-1, 424-3) to open;and comparison logic (208, 210) configured to compare the redundant data packets as the packets leave the first cryptographic engine (404-1) and the second cryptographic engine (404-2), to ensure that the first cryptographic engine (404-1) and the second cryptographic engine (404-2) produce a same output.