IP Library Granted Patent US 11,625,337
Granted Patent B2
US 11,625,337 · App. 17/134,355 · Granted Apr 11, 2023

Encoded pointer based data encryption

Inventor: David M. Durham (Beaverton, OR)
Assignee: Intel Corporation
G06F12/1408G06F12/1441G06F21/79G06F2221/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,337
App. No.
17/134,355
Granted
Apr 11, 2023
Kind
B2
Abstract

Technologies disclosed herein provide cryptographic computing. An example method comprises storing, in a register, an encoded pointer to a memory location, wherein the encoded pointer comprises first context information and a slice of a memory address of the memory location, wherein the first context information includes an identification of a data key; decoding the encoded pointer to obtain the memory address of the memory location; using the memory address obtained by decoding the encoded pointer to access encrypted data at the memory location; and decrypting the encrypted data based on the data key.

Claims (33)

1. A processor unit, comprising:

a first memory element to store an encoded pointer to a memory location, wherein the encoded pointer comprises first context information and a slice of a memory address of the memory location, wherein the first context information includes an identification of an address key that is a secret key used to encrypt and decrypt slices of encoded pointers; and

circuitry to:

use the address key to cryptographically decode a portion of the encoded pointer during a determination of the memory address of the memory location;

use the determined memory address to access encrypted data at the memory location; and

decrypt the encrypted data based on a data key.

2. The processor unit of claim 1 , wherein the encoded pointer has a length of at least 128 bits.

3. The processor unit of claim 1 , wherein the first context information is plaintext within the encoded pointer and the encoded pointer further comprises encrypted second context information.

4. The processor unit of claim 3 , wherein the encrypted second context information is encrypted in a block of the encoded pointer that further comprises an encrypted portion of the memory address.

5. The processor unit of claim 3 , the circuitry to decrypt the encrypted data based further on a first tweak, the first tweak including one or more bits derived, at least in part, from the first context information and the second context information.

6. The processor unit of claim 1 , wherein the first context information comprises a message authentication code calculated based on at least a portion of the memory address.

7. The processor unit of claim 1 , wherein the first context information comprises permission bits indicating a level of access authorized for the memory location.

8. The processor unit of claim 1 , wherein the first context information comprises type bits indicating a class of the encrypted data in the memory location.

9. The processor unit of claim 1 , wherein the first context information comprises version bits representing a deterministically different value associated with the encoded pointer.

10. The processor unit of claim 1 , wherein the first context information comprises a lookup tag to index to an entry of a table, wherein the entry comprises second context information.

11. A method, comprising:

storing, in a register, an encoded pointer to a memory location, wherein the encoded pointer comprises first context information and a slice of a memory address of the memory location, wherein the first context information includes an identification of an address key that is a secret key used to encrypt and decrypt slices of encoded pointers;

cryptographically decoding a portion of the encoded pointer using the address key in order to obtain the memory address of the memory location;

using the memory address to access encrypted data at the memory location; and

decrypting the encrypted data based on a data key.

12. The method of claim 11 , wherein the encoded pointer has a length of at least 128 bits.

13. The method of claim 11 , wherein the first context information is plaintext within the encoded pointer and the encoded pointer further comprises encrypted second context information.

14. The method of claim 13 , wherein the encrypted second context information is encrypted in a block of the encoded pointer that further comprises an encrypted portion of the memory address.

15. The method of claim 13 , further comprising decrypting the encrypted data based further on a first tweak, the first tweak including one or more bits derived, at least in part, from the first context information and the second context information.

16. One or more non-transitory computer-readable media with code stored thereon, wherein the code is executable to cause a machine to:

store, in a register, an encoded pointer to a memory location, wherein the encoded pointer comprises first context information and a slice of a memory address of the memory location, wherein the first context information includes an identification of an address key that is a secret key used to encrypt and decrypt slices of encoded pointers;

use the address key during cryptographic decoding of a portion of the encoded pointer in order to obtain the memory address of the memory location;

use the memory address to access encrypted data at the memory location; and

decrypt the encrypted data based on a data key.

17. The one or more computer-readable media of claim 16 , wherein the encoded pointer has a length of at least 128 bits.

18. The one or more computer-readable media of claim 16 , wherein the first context information is plaintext within the encoded pointer and the encoded pointer further comprises encrypted second context information.

19. The one or more computer-readable media of claim 18 , wherein the encrypted second context information is encrypted in a block of the encoded pointer that further comprises an encrypted portion of the memory address.

20. The one or more computer-readable media of claim 18 , wherein the code is executable to cause the machine to decrypt the encrypted data based further on a first tweak, the first tweak including one or more bits derived, at least in part, from the first context information and the second context information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2021
From: DURHAM, DAVID M.
To: INTEL CORPORATION
Reel/Frame 054843/0855 →
Continuity (1)
Related Publication 20210117342A1 · Apr 22, 2021