IP Library Patent Application 16236074
Patent Application
App. No. 16/236,074

TECHNOLOGIES FOR SECURE I/O WITH MEMORY ENCRYPTION ENGINES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/236,074
Abstract

Technologies for secure I/O data transfer include a computing device having a processor and an accelerator. Each of the processor and the accelerator includes a memory encryption engine. The computing device configures both memory encryption engines with a shared encryption key and transfers encrypted data from a source component to a destination component via an I/O link. The source may be processor and the destination may be the accelerator or vice versa. The computing device may perform a cryptographic operation with one of the memory encryption engines and bypass the other memory encryption engine. The computing device may read encrypted data from a memory of the source, bypass the source memory encryption engine, and transfer the encrypted data to the destination. The destination may receive encrypted data, bypass the destination memory encryption engine, and store the encrypted data in a memory of the destination. Other embodiments are described and claimed.

Claims (124)

1 . A computing device for secure data transfer, the computing device comprising:

a first memory encryption engine and a second encryption engine;

a transfer manager to (i) configure the first memory encryption engine and the second memory encryption engine with a first encryption key and (ii) transfer encrypted data from a source component to a destination component via an I/O link between the source component and the destination component, wherein the encrypted data is encrypted with the first encryption key; and

bypass control logic to bypass the second memory encryption engine;

wherein the first memory encryption engine is to perform a cryptographic operation related to the encrypted data using the first encryption key.

2 . The computing device of claim 1 , wherein:

the source component comprises the first memory encryption engine;

the destination component comprises the second memory encryption engine;

to transfer the encrypted data comprises to transfer the encrypted data in response to performance of the cryptographic operation; and

to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to transfer of the encrypted data.

3 . The computing device of claim 2 , wherein:

the first memory encryption engine is further to read cleartext data from a cleartext memory of the source component;

the bypass control logic is further to store the encrypted data in an encrypted memory coupled to the destination component in response to bypass of the second memory encryption engine; and

to perform the cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component in response to a read of the cleartext data.

4 . The computing device of claim 2 , wherein:

the first memory encryption engine is further to (i) read the encrypted data from an encrypted memory coupled to the source component and (ii) perform a second cryptographic operation related to the encrypted data using the first encryption key in response to performance of the cryptographic operation;

the bypass control logic is further to store the encrypted data in an encrypted memory coupled to the destination component in response to bypass of the second memory encryption engine;

to perform the cryptographic operation comprises to decrypt the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component in response to a read of the encrypted data;

to perform the second cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component; and

to transfer the encrypted data comprises to transfer the encrypted data in response to performance of the second cryptographic operation.

5 . The computing device of claim 1 , wherein:

the source component comprises the second memory encryption engine;

the destination component comprises the first memory encryption engine;

to transfer the encrypted data comprises to transfer the encrypted data in response to bypass of the second memory encryption engine; and

to perform the cryptographic operation comprises to perform the cryptographic operation in response to transfer of the encrypted data.

6 . The computing device of claim 5 , wherein:

the bypass control logic is to read the encrypted data from an encrypted memory coupled to the source component;

the first memory encryption engine is further to store cleartext data in a cleartext memory of the destination component in response to performance of the cryptographic operation;

to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to a read of the encrypted data; and

to perform the cryptographic operation comprises to decrypt the encrypted data to recover the cleartext data using the first encryption key and a tweak associated with the source component.

7 . The computing device of claim 5 , wherein:

the bypass control logic is to read the encrypted data from an encrypted memory coupled to the source component;

the first memory encryption engine is to (i) perform a second cryptographic operation related to the encrypted data using the first encryption key in response to performance of the cryptographic operation, and (ii) store the encrypted data in an encrypted memory coupled to the destination component in response to performance of the second cryptographic operation;

to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to a read of the encrypted data;

to perform the cryptographic operation comprises to decrypt the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component; and

to perform the second cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component.

8 . The computing device of claim 1 , wherein:

the bypass control logic is to determine whether to bypass the second memory encryption engine; and

the second memory encryption engine is to perform a second cryptographic operation related to the encrypted data using the first encryption key in response to a determination not to bypass the second memory encryption engine;

the source component comprises the first memory encryption engine;

the destination component comprises the second memory encryption engine; and

to transfer the encrypted data comprises to transfer the encrypted data in response to performance of the cryptographic operation.

9 . The computing device of claim 8 , wherein:

the first memory encryption engine is further to read cleartext data from a cleartext memory of the source component;

the second memory encryption engine is further to store the cleartext data in a cleartext memory of the destination component in response to performance of the second cryptographic operation;

to perform the cryptographic operation comprises to encrypt the cleartext data using the first encryption key in response to a read of the cleartext data; and

to perform the second cryptographic operation comprises to decrypt the encrypted data to recover the cleartext data using the first encryption key.

10 . The computing device of claim 1 , wherein:

the bypass control logic is further to determine whether to bypass the second memory encryption engine; and

to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to a determination to bypass the second memory encryption engine.

11 . The computing device of claim 10 , wherein to determine whether to bypass the second memory encryption engine comprises to determine whether to bypass the second memory encryption engine based on a memory address associated with the encrypted data.

12 . The computing device of claim 10 , wherein to determine whether to bypass the second memory encryption engine comprises to determine whether a tweak associated with the encrypted data is available to the first memory encryption engine.

13 . The computing device of claim 1 , wherein:

the computing device comprises a processor and an accelerator, wherein the I/O link is coupled between the processor and the accelerator;

the source component comprises the processor or the accelerator;

the destination component comprises the processor or the accelerator;

the first memory encryption engine comprises a memory encryption engine of the processor or a memory encryption engine of the accelerator; and

the second memory encryption engine comprises the memory encryption engine of the processor or the memory encryption engine of the accelerator other than the first memory encryption engine.

14 . A method for secure data transfer, the method comprising:

configuring, by the computing device, a first memory encryption engine of the computing device and a second memory encryption engine of the computing device with a first encryption key;

transferring, by the computing device, encrypted data from a source component to a destination component via an I/O link between the source component and the destination component, wherein the encrypted data is encrypted with the first encryption key;

performing, by the first memory encryption engine, a cryptographic operation related to the encrypted data using the first encryption key; and

bypassing, by the computing device, the second memory encryption engine.

15 . The method of claim 14 , wherein:

the source component comprises the first memory encryption engine;

the destination component comprises the second memory encryption engine;

transferring the encrypted data comprises transferring the encrypted data in response to performing the cryptographic operation; and

bypassing the second memory encryption engine comprises bypassing the second memory encryption engine in response to transferring the encrypted data.

16 . The method of claim 15 , further comprising:

reading, by the computing device, cleartext data from a cleartext memory of the source component; and

storing, by the computing device, the encrypted data in an encrypted memory coupled to the destination component in response to bypassing the second memory encryption engine;

wherein performing the cryptographic operation comprises encrypting the cleartext data using the first encryption key and a tweak associated with the destination component in response to reading the cleartext data.

17 . The method of claim 15 , further comprising:

reading, by the computing device, the encrypted data from an encrypted memory coupled to the source component;

performing, by the first memory encryption engine, a second cryptographic operation related to the encrypted data using the first encryption key in response to performing the cryptographic operation; and

storing, by the computing device, the encrypted data in an encrypted memory coupled to the destination component in response to bypassing the second memory encryption engine;

wherein performing the cryptographic operation comprises decrypting the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component in response to reading the encrypted data;

wherein performing the second cryptographic operation comprises encrypting the cleartext data using the first encryption key and a tweak associated with the destination component; and

wherein transferring the encrypted data comprises transferring the encrypted data in response to performing the second cryptographic operation.

18 . The method of claim 14 , wherein:

the source component comprises the second memory encryption engine;

the destination component comprises the first memory encryption engine;

transferring the encrypted data comprises transferring the encrypted data in response to bypassing the second memory encryption engine; and

performing the cryptographic operation comprises performing the cryptographic operation in response to transferring the encrypted data.

19 . The method of claim 18 , further comprising:

reading, by the computing device, the encrypted data from an encrypted memory coupled to the source component;

performing, by the first memory encryption engine, a second cryptographic operation related to the encrypted data using the first encryption key in response to performing the cryptographic operation; and

storing, by the computing device, the encrypted data in an encrypted memory coupled to the destination component in response to performing the second cryptographic operation;

wherein bypassing the second memory encryption engine comprises bypassing the second memory encryption engine in response to reading the encrypted data;

wherein performing the cryptographic operation comprises decrypting the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component; and

wherein performing the second cryptographic operation comprises encrypting the cleartext data using the first encryption key and a tweak associated with the destination component.

20 . One or more computer-readable storage media comprising a plurality of instructions stored thereon that, in response to being executed, cause a computing device to:

configure a first memory encryption engine of the computing device and a second memory encryption engine of the computing device with a first encryption key;

transfer encrypted data from a source component to a destination component via an I/O link between the source component and the destination component, wherein the encrypted data is encrypted with the first encryption key;

perform, by the first memory encryption engine, a cryptographic operation related to the encrypted data using the first encryption key; and

bypass the second memory encryption engine.

21 . The one or more computer-readable storage media of claim 20 , wherein:

the source component comprises the first memory encryption engine;

the destination component comprises the second memory encryption engine;

to transfer the encrypted data comprises to transfer the encrypted data in response to performing the cryptographic operation; and

to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to transferring the encrypted data.

22 . The one or more computer-readable storage media of claim 21 , further comprising a plurality of instructions stored thereon that, in response to being executed, cause the computing device to:

read cleartext data from a cleartext memory of the source component; and

store the encrypted data in an encrypted memory coupled to the destination component in response to bypassing the second memory encryption engine;

wherein to perform the cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component in response to reading the cleartext data.

23 . The one or more computer-readable storage media of claim 21 , further comprising a plurality of instructions stored thereon that, in response to being executed, cause the computing device to:

read the encrypted data from an encrypted memory coupled to the source component;

perform, by the first memory encryption engine, a second cryptographic operation related to the encrypted data using the first encryption key in response to performing the cryptographic operation; and

store the encrypted data in an encrypted memory coupled to the destination component in response to bypassing the second memory encryption engine;

wherein to perform the cryptographic operation comprises to decrypt the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component in response to reading the encrypted data;

wherein to perform the second cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component; and

wherein to transfer the encrypted data comprises to transfer the encrypted data in response to performing the second cryptographic operation.

24 . The one or more computer-readable storage media of claim 20 , wherein:

the source component comprises the second memory encryption engine;

the destination component comprises the first memory encryption engine;

to transfer the encrypted data comprises to transfer the encrypted data in response to bypassing the second memory encryption engine; and

to perform the cryptographic operation comprises to perform the cryptographic operation in response to transferring the encrypted data.

25 . The one or more computer-readable storage media of claim 24 , further comprising a plurality of instructions stored thereon that, in response to being executed, cause the computing device to:

read the encrypted data from an encrypted memory coupled to the source component;

perform, by the first memory encryption engine, a second cryptographic operation related to the encrypted data using the first encryption key in response to performing the cryptographic operation; and

store the encrypted data in an encrypted memory coupled to the destination component in response to performing the second cryptographic operation;

wherein to bypass the second memory encryption engine comprises to bypass the second memory encryption engine in response to reading the encrypted data;

wherein to perform the cryptographic operation comprises to decrypt the encrypted data to recover cleartext data using the first encryption key and a tweak associated with the source component; and

wherein to perform the second cryptographic operation comprises to encrypt the cleartext data using the first encryption key and a tweak associated with the destination component.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2019
From: KIDA, LUIS; CHHABRA, SIDDHARTHA; LAL, RESHMA; PAPPACHAN, PRADEEP M.
To: INTEL CORPORATION
Reel/Frame 047964/0336 →