Techniques and devices for configurable memory encryption and authentication
Disclosed systems and techniques involve flexible encryption, decryption, retrieval, and authentication of data. The systems may include a cryptographic processor that, in a first selectable mode of operation is configured to identify plaintext blocks, generate encrypted ciphertext blocks, process sequentially the ciphertext blocks to obtain an authentication value, encrypt the authentication value, and store the ciphertext blocks and an authentication tag, obtained based on the encrypted authentication value. In a second selectable mode, the cryptographic processor may perform ciphertext block encryption but forgo obtaining the authentication value.
1 . A method to store a parcel of data in a memory device at a memory address jointly associated with the parcel of data and an error correction (EC) space for the parcel of data, the method comprising:
encrypting, by a processing device, a plurality of plaintext blocks of the parcel of data to generate a plurality of ciphertext blocks, wherein each of the plurality of ciphertext blocks is generated by encrypting a respective block of the plurality of plaintext blocks;
processing sequentially, by the processing device, the plurality of ciphertext blocks to obtain an authentication value;
encrypting, by the processing device, the authentication value to obtain an encrypted authentication value; and
storing, in the memory device, the plurality of ciphertext blocks and a target number of bits of an authentication tag for the plurality of ciphertext blocks, wherein the authentication tag is based on the encrypted authentication value, and wherein the target number of bits is determined by a size of the EC space for the parcel of data.
2 . The method of claim 1 , wherein the plurality of ciphertext blocks are generated using one or more cipher circuits, wherein the one or more cipher circuits implement at least one of AES encryption or SM4 encryption.
3 . The method of claim 1 , wherein generating the plurality of ciphertext blocks comprises processing the plurality of plaintext blocks in view of an additional input, wherein the additional input comprises a cryptographic key and at least one of a version number associated with the plurality of plaintext blocks, the memory address, or a session-specific information.
4 . The method of claim 3 , wherein processing sequentially the plurality of ciphertext blocks to obtain the authentication value comprises:
using a plurality of addition operations and a plurality of multiplication operations, to obtain the authentication value starting from a seed authentication value, wherein at least a sub-plurality of the plurality of addition operations updates the authentication value by adding, to the authentication value, a respective ciphertext block of the plurality of ciphertext blocks, and wherein the plurality of multiplication operations updates the authentication value by multiplying the authentication value by an auxiliary value.
5 . The method of claim 4 , wherein the seed authentication value comprises at least one of a version number associated with the plurality of plaintext blocks or a memory address of a memory location allocated to storing the plurality of ciphertext blocks.
6 . The method of claim 1 , wherein the authentication tag comprises the encrypted authentication value.
7 . The method of claim 1 , wherein the encrypted authentication value is obtained by processing the authentication value using a cipher circuit.
8 . The method of claim 1 , wherein the authentication tag is obtained using the encrypted authentication value and a tweak value, wherein the tweak value is obtained by using an encrypted, by a cipher circuit, authentication data, wherein the authentication data comprises the memory address.
9 . A system comprising:
a processing device; and
a memory device communicatively coupled to the processing device, wherein the processing device is configured to:
encrypt a plurality of plaintext blocks of a parcel of data to generate a plurality of ciphertext blocks, wherein each of the plurality of ciphertext blocks is generated by encrypting a respective block of the plurality of plaintext blocks;
process sequentially the plurality of ciphertext blocks to obtain an authentication value;
encrypt the authentication value to obtain an encrypted authentication value; and
store, in the memory device at a memory address jointly associated with the parcel of data and an error correction (EC) space for the parcel of data, the plurality of ciphertext blocks and a target number of bits of an authentication tag for the plurality of ciphertext blocks, wherein the authentication tag is based on the encrypted authentication value, and wherein the target number of bits is determined by a size of the EC space for the parcel of data.
10 . The system of claim 9 , wherein the plurality of ciphertext blocks are generated using one or more cipher circuits, wherein the one or more cipher circuits implement at least one of AES encryption or SM4 encryption.
11 . The system of claim 9 , wherein to generate the plurality of ciphertext blocks the processing device is configured to process the plurality of plaintext blocks in view of an additional input, wherein the additional input comprises a cryptographic key and at least one of a version number associated with the plurality of plaintext blocks or the memory address.
12 . The system of claim 11 , wherein to process sequentially the plurality of ciphertext blocks to obtain the authentication value, the processing device is configured to:
use a plurality of addition operations and a plurality of multiplication operations, to obtain the authentication value starting from a seed authentication value, wherein at least a sub-plurality of the plurality of addition operations updates the authentication value by adding, to the authentication value, a respective ciphertext block of the plurality of ciphertext blocks, and wherein the plurality of multiplication operations updates the authentication value by multiplying the authentication value by an auxiliary value.
13 . The system of claim 12 , wherein the seed authentication value comprises at least one of a version number associated with the plurality of plaintext blocks or a memory address of a memory location allocated to storing the plurality of ciphertext blocks.
14 . The system of claim 9 , wherein the authentication tag comprises the encrypted authentication value.
15 . The system of claim 9 , wherein the encrypted authentication value is obtained by processing the authentication value using a cipher circuit.
16 . The system of claim 9 , wherein the authentication tag is obtained using the encrypted authentication value and a tweak value, wherein the tweak value is obtained by using an encrypted, by a cipher circuit, authentication data, wherein the authentication data comprises the memory address.
17 . A non-transitory computer-readable memory comprising instructions that, when executed by a processing device, cause the processing device to:
encrypt a plurality of plaintext blocks of a parcel of data to generate a plurality of ciphertext blocks, wherein each of the plurality of ciphertext blocks is generated by encrypting a respective block of the plurality of plaintext blocks;
process sequentially the plurality of ciphertext blocks to obtain an authentication value;
encrypt the authentication value to obtain an encrypted authentication value; and
store, in a memory device at a memory address jointly associated with the parcel of data and an error correction (EC) space for the parcel of data, the plurality of ciphertext blocks and a target number of bits of an authentication tag for the plurality of ciphertext blocks, wherein the authentication tag is based on the encrypted authentication value, and wherein the target number of bits is determined by a size of the EC space for the parcel of data.
18 . The non-transitory computer-readable memory of claim 17 , wherein the authentication tag comprises the encrypted authentication value.
19 . The non-transitory computer-readable memory of claim 17 , wherein the encrypted authentication value is obtained by processing the authentication value using a cipher circuit.
20 . The non-transitory computer-readable memory of claim 17 , wherein the authentication tag is obtained using the encrypted authentication value and a tweak value, wherein the tweak value is obtained by using an encrypted, by a cipher circuit, authentication data, wherein the authentication data comprises the memory address.