IP Library › Granted Patent US 11,934,542
Granted Patent B2
US 11,934,542 · App. 18/079,863 · Granted Mar 19, 2024

Methods and apparatus for offloading encryption

Inventor: Sumanth Jannyavula Venkata (Fremont, CA)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F21/602G06F13/4027H04L9/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,934,542
App. No.
18/079,863
Granted
Mar 19, 2024
Kind
B2
Abstract

A method may include transferring data from a host to an encryption offload engine through an interconnect fabric, encrypting the data from the host at the encryption offload engine, and transferring the encrypted data from the encryption offload engine to a storage device through a peer-to-peer connection in the interconnect fabric. The method may further include transferring the encrypted data from the storage device to the encryption offload engine through a peer-to-peer connection in the interconnect fabric, decrypting the encrypted data from the storage device at the encryption offload engine, and transferring the decrypted data to the host through the interconnect fabric. The method may further include transferring the encrypted data from the storage device to the host, and verifying the encryption of the encrypted data at the host.

Claims (69)

1. A method comprising:

receiving, at a data transformation engine, using a first connection in a communication fabric, data;

transforming the data using the data transformation engine to generate transformed data; and

transferring the transformed data from the data transformation engine to a storage device using a second connection in the communication fabric;

wherein the communication fabric comprises a switch connected to the data transformation engine and the storage device; and

wherein the second connection uses the switch.

2. The method of claim 1 , further comprising:

transferring the transformed data from the storage device to the data transformation engine using a second connection in the communication fabric;

modifying the transformed data from the storage device at the data transformation engine to generate modified data; and

transferring the modified data using the communication fabric.

3. The method of claim 1 , further comprising:

transferring the transformed data from the storage device to a host; and

verifying, at the host, the transformed data.

4. The method of claim 1 , wherein:

the data comprises a source address; and

the method further comprises mapping the source address to the data transformation engine.

5. The method of claim 4 , wherein:

the data transformation engine is configured to fetch the data using a mapping table; and

the storage device is configured to:

receive a write command; and

transfer the transformed data from the data transformation engine to the storage device based on the write command.

6. The method of claim 2 , wherein:

the modified data is associated with a destination address; and

the method further comprises mapping the destination address to the data transformation engine.

7. The method of claim 6 , wherein:

the storage device is configured to:

receive a read command; and

transfer the transformed data from the data transformation engine to the storage device based on the read command; and

the data transformation engine is configured to transfer the modified data using a mapping table.

8. A system comprising:

a host;

a data transformation engine; and

a communication fabric arranged to connect the host, the data transformation engine, and one or more storage devices, wherein the communication fabric comprises a switch connected to the data transformation engine and at least one of the one or more storage devices;

wherein the data transformation engine is configured to:

receive data from the host using a first connection;

transform the data to generate transformed data; and

send the transformed data to the at least one of the storage devices using a second connection in the communication fabric, wherein the second connection uses the switch.

9. The system of claim 8 , wherein the host is configured to:

read the transformed data from the at least one of the one or more storage devices; and

verify the transformed data.

10. The system of claim 9 , wherein the host is configured to:

map a destination address to the host; and

read, based on the destination address, the transformed data from the at least one of the one or more storage devices.

11. The system of claim 8 , wherein:

the system further comprises a submission queue configured to receive a write command from the host; and

the write command comprises a source address for the transformed data.

12. The system of claim 11 , wherein the host is configured to map the source address to the data transformation engine.

13. The system of claim 8 , wherein the data transformation engine is configured to send the transformed data to the at least one of the storage devices based on a mapping.

14. The system of claim 13 , wherein the data transformation engine is configured to receive the data from the host based on the mapping.

15. The system of claim 14 , wherein the at least one of the storage devices is configured to receive the transformed data from the data transformation engine based on a write command.

16. The system of claim 8 , wherein the data transformation engine is further configured to:

receive transformed data from at least one of the storage devices using the second connection;

modify the transformed data to generate modified data; and

send the modified data to the host.

17. The system of claim 16 , wherein:

the system further comprises a queue configured to hold a read command; and

the read command is associated with a destination address for the modified data.

18. The system of claim 17 , wherein the host is configured to map the destination address to the data transformation engine.

19. An apparatus comprising:

a computational device comprising:

an interface configured to couple the computational device to a communication fabric, wherein the communication fabric comprises a switch connected to the computational device and a storage device; and

a controller coupled to the interface and configured to:

receive, using a first connection, data using the interface;

transform the data to generate transformed data; and

send, using a connection, the transformed data to the storage device using the interface, wherein the connection uses the switch.

20. The apparatus of claim 19 , wherein the controller is further configured to:

receive transformed data from the storage device using the interface;

modify the transformed data to generate modified data; and

send the modified data using the interface.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2023
From: JANNYAVULA VENKATA, SUMANTH
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 063916/0085 →
Continuity (3)
Continuation 16856003 · Apr 22, 2020
Provisional Application 62967571 · Jan 29, 2020
Related Publication 20230110633A1 · Apr 13, 2023