Context-Aware Adaptive AES-CTR Hardware Accelerator for IoT and Embedded Systems
Abstract
Internet of Things (IoT) developments and emerging resource-constrained edge devices have increased the need for hardware cryptographic accelerators that provide dynamic balancing between security and power. Traditional AES hardware implementations are static with respect to changing encryption parameters, requiring full system reconfiguration. Therefore, these systems are not ideal for environments experiencing fluctuations in both threat levels and available energy budgets. This work discusses a context-aware adaptive AES hardware accelerator implemented on a Xilinx Artix-7 FPGA that allows runtime switching between AES-128 and AES-256 encryption modes while operating in Counter (CTR) mode. The proposed design features a dual-datapath architecture, including a 128-bit parallel path for high throughput and a 32-bit serialized path for power-constrained applications, under the control of a single finite-state machine (FSM). The system utilizes UART communication for runtime configuration command transmission to support transitions between encryption modes without stopping the encryption pipeline or resetting the CTR-mode keystream. Both implementations (AES-128 Parallel Core and 32-bit Serial Core) achieve a maximum physical clock frequency of 135.1 MHz while utilizing 535 LUTs and consuming 16 mW of dynamic power. Both designs completely meet timing closure requirements at the 50 MHz operating frequency, with a worst negative slack (WNS) of +5.655 ns. Hardware-in-the-loop testing demonstrated that both designs operate correctly using NIST Known Answer Test (KAT) vectors during runtime mode switching.