IP Library Granted Patent US 11,316,661
Granted Patent B2
US 11,316,661 · App. 16/733,685 · Granted Apr 26, 2022

Encryption interface

Inventors: Eugene M. Kishinevsky (Hillsboro, OR); Uday R. Savagaonkar (Portland, OR); Alpa T. Narendra Trivedi (Hillsboro, OR); Siddhartha Chhabra (Hillsboro, OR); Baiju V. Patel (Portland, OR); Men Long (Beaverton, OR); Kirk S. Yap (Westborough, MA); David M. Durham (Beaverton, OR)
Assignee: Intel Corporation
H04L9/0631G06F12/1408G06F12/1425G06F21/602G06F21/85G09C1/00G06F2212/1052G06F2212/402H04L2209/125Y02D10/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,316,661
App. No.
16/733,685
Granted
Apr 26, 2022
Kind
B2
Abstract

Encryption interface technologies are described. A processor can include a system agent, an encryption interface, and a memory controller. The system agent can communicate data with a hardware functional block. The encryption interface can be coupled between the system agent and a memory controller. The encryption interface can receive a plaintext request from the system agent, encrypt the plaintext request to obtain an encrypted request, and communicate the encrypted request to the memory controller. The memory controller can communicate the encrypted request to a main memory of the computing device.

Claims (32)

1. An apparatus comprising:

a central processor unit (CPU) core to generate unencrypted data to be stored in memory;

cryptographic circuitry, external to the CPU core, to:

determine the unencrypted data is to be encrypted,

encrypt the unencrypted data using an encryption key,

change the encryption key to a new encryption key based on time or memory region,

compare a re-keying urgency value against other memory traffic, and

in response to determining that re-keying urgency exceeds a threshold, update the encrypted data with the new encryption key; and

memory controller circuitry to store the encrypted data in the memory.

2. The apparatus of claim 1 , wherein the cryptographic circuitry, external to the CPU core, is to encrypt the unencrypted data according to an Advanced Encryption Standard.

3. The apparatus of claim 1 , wherein the cryptographic circuitry, external to the CPU core, is to:

receive encrypted data from the memory,

decrypt the encrypted data, and

provide the decrypted data to the CPU core.

4. The apparatus of claim 1 , wherein the cryptographic circuitry, external to the CPU core, is to:

receive data from the memory, and

upon determining the data received from the memory is unencrypted, provide the data to the CPU core without performing decryption.

5. The apparatus of claim 1 , wherein the memory is dynamic random-access memory.

6. An apparatus comprising:

a central processor unit (CPU) core to generate unencrypted data to be stored at an address in memory;

cryptographic circuitry, external to the CPU core, to encrypt the unencrypted data using an encryption key, to change the encryption key to a new encryption key based on time or memory region, compare a re-keying urgency value against other memory traffic, and in response to determining that re-keying urgency exceeds a threshold, update the encrypted data with the new encryption key;

bypass circuitry, external to the CPU, to select data from an output of the cryptographic circuitry and the unencrypted data; and

memory controller circuitry to store the selected data in the memory.

7. The apparatus of claim 6 , wherein the cryptographic circuitry, external to the CPU core, is to encrypt the unencrypted data according to an Advanced Encryption Standard.

8. The apparatus of claim 6 , wherein the cryptographic circuitry, external to the CPU core, is to:

receive encrypted data from the memory,

decrypt the encrypted data, and

provide the decrypted data to the CPU core.

9. The apparatus of claim 6 , wherein the cryptographic circuitry, external to the CPU core, is to:

receive data from the memory, and

upon determining the data received from the memory is unencrypted, provide the data to the CPU core without performing decryption.

10. The apparatus of claim 6 , wherein the memory is dynamic random-access memory.

Continuity (3)
Continuation 15457004 · Mar 13, 2017
Division 14581946 · Dec 23, 2014
Related Publication 20200259632A1 · Aug 13, 2020