IP Library Granted Patent US 12,189,792
Granted Patent B2
US 12,189,792 · App. 17/033,748 · Granted Jan 7, 2025

Scalable multi-key memory encryption

Inventors: Barry E. Huntley (Hillsboro, OR); Hormuzd M. Khosravi (Portland, OR); Thomas Toll (Portland, OR); Ramya Jayaram Masti (Hillsboro, OR); Siddhartha Chhabra (Portland, OR); Vincent Von Bokern (Rescue, CA)
Assignee: Intel Corporation
G06F21/602G06F12/06H04L9/14G06F2212/1008G06F2212/402
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,792
App. No.
17/033,748
Granted
Jan 7, 2025
Kind
B2
Abstract

Embodiments of apparatuses, methods, and systems for scalable multi-key memory encryption are disclosed. In an embodiment, an apparatus includes a core, an encryption unit, and key identification hardware. The core is to write data to and read data from memory regions, each to be identified by a corresponding address. The encryption unit to encrypt data to be written and decrypt data to be read. The key identification hardware is to use a portion of the corresponding address to look up a corresponding key identifier in a key information data structure. The corresponding key identifier is one multiple key identifiers. The corresponding key identifier is to identify which one of multiple encryption keys is to be used to encrypt and decrypt the data.

Claims (34)

1. An apparatus comprising:

a core to write data to and read data from a plurality of memory regions, each of the plurality of memory regions to be identified by a corresponding address;

an encryption unit to encrypt data to be written and decrypt data to be read, wherein the encryption unit is to use a plurality of encryption keys;

key identification hardware to use a portion of the corresponding address to look up a corresponding key identifier in a key information data structure, wherein, the corresponding key identifier is one of a plurality of key identifiers, and the corresponding key identifier is to identify one of the plurality of encryption keys to be used to encrypt and decrypt the data; and

an instruction decoder to decode a first instruction to write to the key information data structure, wherein the first instruction is the only way for software to write to the key information data structure and is to write only to the key information structure;

wherein the key information data structure is to include a first indicator corresponding to the corresponding key identifier, the first indicator to indicate whether a memory location identified by the corresponding address is private, the first indicator to be compared to a second indicator provided with the corresponding address for the look up.

2. The apparatus of claim 1 , wherein the portion of the corresponding address is an address of one of the plurality of memory region to be protected by encryption with the one of the plurality of encryption keys identified by the corresponding key identifier.

3. The apparatus of claim 2 , wherein the one of the plurality of memory regions is a page.

4. The apparatus of claim 3 , wherein the portion of the corresponding address is a page frame number.

5. The apparatus of claim 4 , wherein the corresponding address is an address of a memory location within the page.

6. The apparatus of claim 5 , wherein the key information data structure is to include an entry per page, wherein each entry is to include a key identifier field.

7. The apparatus of claim 6 , wherein each entry is to include an indicator to indicate whether data to be stored at the corresponding address is private.

8. The apparatus of claim 6 , wherein each entry is to include an indicator to indicate that the entry is one of a group of entries in which the key identifier field is storing a first key identifier, wherein the first key identifier is the same for each entry.

9. The apparatus of claim 1 , wherein the key information data structure is to be stored in a system memory, further comprising a key information cache to cache entries from the key information data structure.

10. The apparatus of claim 1 , wherein the instruction decoder is also to decode a second instruction to read from the key information data structure, wherein the second instruction is the only way for software to read from the key information data structure and is to read only from the key information structure.

11. The apparatus of claim 10 , wherein the second instruction has a format including a first field for an opcode and a second field for an operand, wherein the operand is to specify at least one of the plurality of memory regions.

12. The apparatus of claim 11 , wherein execution of the decoded second instruction includes reading the corresponding key identifier from the key information data structure, wherein the corresponding key identifier corresponds to the at least one of the plurality of memory regions.

13. The apparatus of claim 1 , wherein the first instruction has a format including a first field for an opcode, a second field for a first operand, and a third field for a second operand, wherein the first operand is to specify at least one of the plurality of memory regions and the second operand is to specify the corresponding key identifier.

14. The apparatus of claim 13 , wherein execution of the decoded first instruction includes writing the corresponding key identifier to the key information data structure, wherein the corresponding key identifier corresponds to the at least one of the plurality of memory regions.

15. A method comprising:

requesting data to be written from a core to one of a plurality of memory regions, each of the plurality of memory regions to be identified by a corresponding address;

looking up, using a portion of the corresponding address and key identification hardware, a corresponding key identifier in a key information data structure, wherein the corresponding key identifier is one of a plurality of key identifiers, and the corresponding key identifier is to identify one of a plurality of encryption keys;

comparing a first indicator to a second indicator, the first indicator corresponding to the corresponding key identifier in the key information data structure to indicate whether a memory location identified by the corresponding address is private, the second indicator provided with the corresponding address for the looking up;

if the first indicator indicates the memory location is private and matches the second indicator, encrypting the data using the one of the plurality of encryption keys; and

if the first indicator indicates the memory location is private and matches the second indicator, writing the corresponding key identifier to the key information data structure using a first instruction, wherein the first instruction is the only way for software to write to the key information data structure and is to write only to the key information structure.

16. The method of claim 15 , further comprising reading the corresponding key identifier from the key information data structure using a second instruction, wherein the second instruction is the only way for software to read from the key information data structure and is to read only to the key information structure.

17. A system comprising:

a memory;

a core to write data to and read data from a plurality of memory regions, each of the plurality of memory regions to be identified by a corresponding address;

an encryption unit to encrypt data to be written and decrypt data to be read, wherein the encryption unit is to use a plurality of encryption keys;

key identification hardware to use a portion of the corresponding address to look up a corresponding key identifier in a key information data structure, wherein the corresponding key identifier is one of a plurality of key identifiers, and the corresponding key identifier is to identify one of the plurality of encryption keys to be used to encrypt and decrypt the data; and

an instruction decoder to decode a first instruction to write to the key information data structure, wherein the first instruction is the only way for software to write to the key information data structure and is to write only to the key information structure;

wherein the key information data structure is to include a first indicator corresponding to the corresponding key identifier, the first indicator to indicate whether a memory location identified by the corresponding address is private, the first indicator to be compared to a second indicator provided with the corresponding address for the look up.

18. The system of claim 17 , wherein the core is to access the memory through a plurality of memory channels and at least a portion of the key information data structure is to be copied for more than one of the plurality of memory channels.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2020
From: HUNTLEY, BARRY E.; KHOSRAVI, HORMUZD M.; TOLL, THOMAS; JAYARAM MASTI, RAMYA; CHHABRA, SIDDHARTHA; VON BOKERN, VINCENT
To: INTEL CORPORATION
Reel/Frame 054429/0694 →
Continuity (1)
Related Publication 20220100871A1 · Mar 31, 2022
References Cited (101)
US 6804766B1 · Noel · 2004 [cited by examiner]
US 6950517B2 · Hawkes et al. · 2005 [cited by applicant]
US 7340602B2 · Serret-Avila · 2008 [cited by applicant]
US 7836387B1 · Wong et al. · 2010 [cited by applicant]
US 9882720B1 · Levy et al. · 2018 [cited by applicant]
US 10102151B2 · Axnix et al. · 2018 [cited by applicant]
US 10255202B2 · Khosravi et al. · 2019 [cited by applicant]
US 10521618B1 · Zhang et al. · 2019 [cited by applicant]
US 10540198B2 · Durham · 2020 [cited by examiner]
US 10705976B2 · Sahita · 2020 [cited by examiner]
US 10965474B1 · Benson · 2021 [cited by examiner]
US 11841806B1 · Chhabra · 2023 [cited by examiner]
US 11991276B2 · Pilozzi · 2024 [cited by examiner]
US 20040019783A1 · Hawkes et al. · 2004 [cited by applicant]
US 20070140477A1 · Wise · 2007 [cited by examiner]
US 20080044012A1 · Ekberg et al. · 2008 [cited by applicant]
US 20080084996A1 · Chen et al. · 2008 [cited by applicant]
US 20110167273A1 · Maas et al. · 2011 [cited by applicant]
US 20110296206A1 · Henry et al. · 2011 [cited by applicant]
US 20110314303A1 · Shevchenko et al. · 2011 [cited by applicant]
US 20120047580A1 · Smith et al. · 2012 [cited by applicant]
US 20120110336A1 · Frey et al. · 2012 [cited by applicant]
US 20130067245A1 · Horovitz et al. · 2013 [cited by applicant]
US 20130121488A1 · Kang · 2013 [cited by examiner]
US 20130238907A1 · Debout et al. · 2013 [cited by applicant]
US 20150161059A1 · Durham et al. · 2015 [cited by applicant]
US 20160057118A1 · Lee et al. · 2016 [cited by applicant]
US 20170075628A1 · Ji · 2017 [cited by examiner]
US 20170075820A1 · Hartley et al. · 2017 [cited by applicant]
US 20170201503A1 · Jayasena et al. · 2017 [cited by applicant]
US 20170262306A1 · Wang · 2017 [cited by examiner]
US 20170277869A1 · Liu · 2017 [cited by applicant]
US 20170351737A1 · Curewitz et al. · 2017 [cited by applicant]
US 20180129756A1 · Nishizawa et al. · 2018 [cited by applicant]
US 20180165224A1 · Ng et al. · 2018 [cited by applicant]
US 20180205576A1 · Morita et al. · 2018 [cited by applicant]
US 20190042463A1 · Shanbhogue et al. · 2019 [cited by applicant]
US 20190042759A1 · Smith et al. · 2019 [cited by applicant]
US 20190042765A1 · Chung et al. · 2019 [cited by applicant]
US 20190042795A1 · Bolotov et al. · 2019 [cited by applicant]
US 20190050283A1 · Durham et al. · 2019 [cited by applicant]
US 20190087354A1 · Chhabra · 2019 [cited by examiner]
US 20190095350A1 · Durham et al. · 2019 [cited by applicant]
US 20190116046A1 · Hoyer · 2019 [cited by examiner]
US 20190147192A1 · Khosravi · 2019 [cited by examiner]
US 20190197259A1 · Debande et al. · 2019 [cited by applicant]
US 20190251275A1 · Ramrakhyani et al. · 2019 [cited by applicant]
US 20190319789A1 · Chhabra et al. · 2019 [cited by applicant]
US 20190347432A1 · Boivie · 2019 [cited by applicant]
US 20190386815A1 · Satpathy et al. · 2019 [cited by applicant]
US 20200042442A1 · Wang · 2020 [cited by examiner]
US 20200057664A1 · Durham · 2020 [cited by examiner]
US 20200082070A1 · Semeria et al. · 2020 [cited by applicant]
US 20200145419A1 · Yitbarek et al. · 2020 [cited by applicant]
US 20200159677A1 · Evans et al. · 2020 [cited by applicant]
US 20200159969A1 · Shanbhogue et al. · 2020 [cited by applicant]
US 20200201786A1 · Ouziel et al. · 2020 [cited by applicant]
US 20200201787A1 · Shanbhogue et al. · 2020 [cited by applicant]
US 20200201789A1 · Durham · 2020 [cited by examiner]
US 20200202012A1 · Shanbhogue · 2020 [cited by examiner]
US 20200202013A1 · Caspi et al. · 2020 [cited by applicant]
US 20200310972A1 · Shanbhogue et al. · 2020 [cited by applicant]
US 20210064546A1 · Zmudzinski et al. · 2021 [cited by applicant]
US 20210067334A1 · Angel · 2021 [cited by applicant]
US 20210216476A1 · Sawan · 2021 [cited by examiner]
US 20220019698A1 · Durham et al. · 2022 [cited by applicant]
US 20230101226A1 · Feghali · 2023 [cited by examiner]
US 20230409492A1 · Lasko · 2023 [cited by examiner]
US 20240169099A1 · Khosravi · 2024 [cited by examiner]
CN 102726028A · 2012 [cited by applicant]
EP 2608044A1 · 2013 [cited by applicant]
EP 3614284A1 · 2020 [cited by applicant]
EP 3671473A1 · 2020 [cited by applicant]
TW 201608864A · 2016 [cited by applicant]
TW 201642138A · 2016 [cited by applicant]
TW 201734875A · 2017 [cited by applicant]
TW 201810088A · 2018 [cited by applicant]
No stated author; Intel Architecture Memory Encryption Technologies Specification; 2019; retrieved from the Internet kib.kiev.ua/x86docs/Intel/MemEncryption/336907-002.pdf; pp. 1-30, as printed. (Year: 2019). [cited by examiner]
No stated author; § 5.2 Page Translation—Intel 80386 Reference Programmer's Manual; Retrieved from the Internet https://pdos.csail.mit.edu/6.828/2011/readings/i386/toc.htm; pp. 1-4 as printed. (Year: 2011). [cited by examiner]
European Search Report and Search Opinion, EP App. No. 21197466.2, dated Mar. 2, 2022, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/727,608, dated Apr. 13, 2022, 13 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 20198333.5, dated Mar. 9, 2021, 8 pages. [cited by applicant]
Examination Report, IN App. No. 202044041215, dated Feb. 25, 2022, 6 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2021/047587, dated Dec. 20, 2021, 11 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/728,712, dated Aug. 26, 2022, 20 pages. [cited by applicant]
Gueron, Shay, “A Memory Encryption Engine Suitable for General Purpose Processors” IACR Cryptol. ePrint Arch., Feb. 2016, pp. 1-14. [cited by applicant]
Kounavis et al., “Cryptographic Constructions Supporting Implicit Data Integrity”, Available Online at <https://eprint.iacr.org/2018/534.pdf>, May 2018, pp. 1-56. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/023,683, dated Apr. 29, 2020, 23 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/023,683, dated Oct. 20, 2020, 22 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/728,712, dated Mar. 1, 2022, 20 pages. [cited by applicant]
Search Report and Written Opinion, NL App. No. 2029047, dated Mar. 28, 2022, 7 pages of Original Document Only. [cited by applicant]
Shi et al., “Architectural Support of Multiple Hypervisors over Single Platform for Enhancing Cloud Computing Security”, ACM, 2012, 10 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/727,608, dated Apr. 29, 2022, 2 pages. [cited by applicant]
Notice of Allowance, NL App. No. 2029047, dated Jul. 27, 2022, 5 pages of Original Document Only. [cited by applicant]
Intention to Grant, EP App. No. 20198333.5, dated Jan. 9, 2023, 6 pages. [cited by applicant]
International Preliminary Report on Patentability, PCT App. No. PCT/US2021/047587, dated Apr. 6, 2023, 7 pages. [cited by applicant]
Office Action, TW App. No. 109132349, dated Nov. 29, 2023, 34 pages (14 pages of English Translation and 20 pages of Original Document). [cited by applicant]
Intention to Grant, EP App. No. 21197466.2, dated Jan. 17, 2024, 7 pages. [cited by applicant]
Decision to Grant, EP App. No. 21197466.2, May 16, 2024, 2 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/134,052, Feb. 15, 2024, 20 pages. [cited by applicant]
Notice of Allowance, TW App. No. 109132349, Mar. 8, 2024, 03 pages (01 page of English Translation and 02 pages of Original Document). [cited by applicant]