IP Library › Granted Patent US 11,763,008
Granted Patent B2
US 11,763,008 · App. 16/742,972 · Granted Sep 19, 2023

Encrypting data using an encryption path and a bypass path

Inventors: Tony Sawan (Round Rock, TX); Adam Samuel Hale (Austin, TX)
Assignee: International Business Machines Corporation
G06F21/602H04L9/0866G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,763,008
App. No.
16/742,972
Granted
Sep 19, 2023
Kind
B2
Abstract

Embodiments herein describe a memory controller that has an encryption path and a bypass path. Using an indicator (e.g., a dedicated address range), an outside entity can inform the memory controller whether to use the encryption path or the bypass path. For example, using the encryption path when performing a write request means the memory controller encrypts the data before it was stored, while using the bypass path means the data is written into memory without be encrypted. Similarly, using the encryption path when performing a read request means the controller decrypts the data before it is delivered to the requesting entity, while using the bypass path means the data is delivered without being decrypted.

Claims (38)

1. A system, comprising:

a processor core; and

a memory controller comprising an encryption path and a bypass path, wherein the encryption path comprises an encryption engine for encrypting and decrypting data, wherein the bypass path bypasses the encryption engine, and wherein the memory controller is configured to:

receive a first write request to write first data into a memory, the first write request comprising a first indicator indicating that the encryption path should be used;

encrypt the first data using the encryption engine before storing the first data in the memory, wherein the encryption engine uses an encryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on a current physical address of the first data;

receive a first read request to read the first data from the memory, the first read request comprising a second indicator indicating that the bypass path should be used;

retrieve the first data from the memory using the bypass path, wherein the first data remains encrypted;

receive a second write request to write the first data to the memory, the second write request comprising the second indicator indicating that the bypass path should be used, wherein the first data remains encrypted;

store the first data in the memory using the bypass path;

receive a second read request to read the first data from the memory, the first read request comprising the first indicator indicating that the encryption path should be used; and

decrypt the first data using the encryption engine in the encryption path, wherein the encryption engine uses a decryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on the current physical address of the first data.

2. The system of claim 1 , wherein, when performing the first and second write requests, the first data is written into the memory using a same physical address as specified in the first and second write requests.

3. The system of claim 1 , wherein the static portion is an ID assigned to the processor core or the memory controller during manufacturing.

4. The system of claim 1 , wherein the static portion is stored in the processor core or the memory controller, and wherein the static portion is unreadable by any entity external to the processor core or the memory controller.

5. A method, comprising:

receiving a first write request at a memory controller to write first data into a memory, the first write request comprising a first indicator indicating that an encryption path in the memory controller should be used;

encrypting the first data using an encryption engine in the encryption path before storing the first data in the memory, wherein the encryption engine uses an encryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on a current physical address of the first data;

receiving a first read request at the memory controller to read the first data from the memory, the first read request comprising a second indicator indicating that a bypass path should be used, wherein the bypass path bypasses the encryption engine;

retrieving the first data from the memory using the bypass path, wherein the first data remains encrypted;

receiving a second write request at the memory controller to write the first data to the memory, the second write request comprising the second indicator indicating that the bypass path should be used, wherein the first data remains encrypted;

storing the first data in the memory using the bypass path;

receiving a second read request at the memory controller to read the first data from the memory, the second read request comprising the first indicator indicating that the encryption path should be used; and

decrypting the first data using the encryption engine in the encryption path, wherein the encryption engine uses a decryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on the current physical address of the first data.

6. The method of claim 5 , wherein, when performing the first and second write requests, the first data is written into the memory using a same physical address as specified in the first and second write requests.

7. A memory controller in an integrated circuit, comprising:

an encryption path comprising an encryption engine; and

a bypass path configured to bypass the encryption engine,

wherein the memory controller is configured to:

receive a first write request to write first data into a memory, the first write request comprising a first indicator indicating that the encryption path should be used;

encrypt the first data using the encryption engine before storing the first data in the memory, wherein the encryption engine uses an encryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on a current physical address of the first data;

receive a first read request to read the first data from the memory, the first read request comprising a second indicator indicating that the bypass path should be used;

retrieve the first data from the memory using the bypass path, wherein the first data remains encrypted;

receive a second write request to write the first data to the memory, the second write request comprising the second indicator indicating that the bypass path should be used, wherein the first data remains encrypted;

store the first data in the memory using the bypass path;

receive a second read request to read the first data from the memory, the first read request comprising the first indicator indicating that the encryption path should be used; and

decrypt the first data using the encryption engine in the encryption path, wherein the encryption engine uses a decryption key comprising a static portion and a dynamic portion, and wherein the dynamic portion is generated based on the current physical address of the first data.

8. The memory controller of claim 7 , wherein, when performing the first and second write requests, the first data is written into the memory using a same physical address as specified in the first and second write requests.

9. The memory controller of claim 7 , wherein the first indicator and the second indicator correspond to different base address registers (BARs).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: SAWAN, TONY; HALE, ADAM SAMUEL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 051517/0910 →
Continuity (1)
Related Publication 20210216645A1 · Jul 15, 2021
Cited By (1)
US 12,572,702