STREAM PROCESSING FOR ENCRYPTED, INTEGRITY AND REPLAY-PROTECTED MEMORY
A processing system may include a memory device including a destination memory in communication with a memory encryption processing unit, wherein the memory encryption processing unit is configured to establish an authenticated-encrypted data stream with a host encryption processing unit via a communications channel by executing a mutual authentication protocol to establish a symmetric session key.
1 . A processing system comprising:
a memory device including a destination memory in communication with a memory encryption processing unit,
wherein the memory encryption processing unit is configured to establish an authenticated-encrypted data stream with a host encryption processing unit via a communications channel by executing a mutual authentication protocol to establish a symmetric session key.
2 . The processing system of claim 1 , further comprising:
a host computing device including the host encryption processing unit, the host encryption processing unit being in communication with the memory encryption processing unit,
wherein the host encryption processing unit is configured to establish the authenticated-encrypted data stream in conjunction with the memory encryption processing unit.
3 . The processing system of claim 2 , wherein the host encryption processing unit comprises a first root of trust and the memory encryption processing unit comprises a second root of trust.
4 . The processing system of claim 2 , wherein the memory encryption processing unit comprises a data parallel processor.
5 . The processing system of claim 4 , wherein the data parallel processor includes a first processing element operable to send and receive data using the authenticated-encrypted data stream to the host encryption processing unit and a second processing element.
6 . The processing system of claim 5 , wherein the second processing element is operable to execute the mutual authentication protocol over a sideband channel.
7 . The processing system of claim 1 , wherein the authenticated-encrypted data stream uses AES-GCM encryption, and the memory encryption processing unit comprises an AES-GCM endpoint.
8 . The processing system of claim 1 , wherein the destination memory is a dual in-line memory module.
9 . The processing system of claim 1 , wherein the memory device further comprises a high bandwidth memory in communication with the memory encryption processing unit.
10 . (canceled)
11 . The processing system of claim 1 , wherein the symmetric session key is a first symmetric session key and, wherein the memory encryption processing unit is configured to, upon determining that a predetermined number of transactions have executed after the first symmetric session key was established, execute the mutual authentication protocol to establish a second symmetric session key, wherein the predetermined number of transactions is less than three hundred million transactions and a transaction comprises a send operation or a receive operation over the authenticated-encrypted data stream.
12 . The processing system of claim 1 , wherein the memory encryption processing unit is further configured to read data from the destination memory and send the data via the authenticated-encrypted data stream to the host encryption processing unit.
13 . The processing system of claim 12 , wherein the data comprises trusted compute encrypted data and the memory encryption processing unit is further configured to decrypt the data read from the destination memory before the data is sent to the host encryption processing unit via the authenticated-encrypted data stream.
14 . The processing system of claim 1 , wherein the memory encryption processing unit is further configured to: receive data from the host encryption processing unit via the authenticated-encrypted data stream, decrypt the data received from the host encryption processing unit using the symmetric session key, and save the data in the destination memory.
15 . The processing system of claim 14 , wherein the memory encryption processing unit includes a hardware private key, and wherein saving the data in the destination memory further comprises encrypting the data using a trusted compute function and the hardware private key before the data is saved to the destination memory.
16 . The processing system of claim 1 , wherein the memory encryption processing unit is further configured to:
receive a math command from the host encryption processing unit via the authenticated-encrypted data stream, the math command being associated with a math operation and destination memory data,
read destination memory data from the destination memory,
decrypt the destination memory data using a trusted compute function and a hardware private key to generate decrypted destination memory data, and
execute the math operation on the decrypted destination memory data to generate a math operation output.
17 . The processing system of claim 16 , wherein the memory encryption processing unit is further configured to:
send the math operation output to the host encryption processing unit via the authenticated-encrypted data stream.
18 . The processing system of claim 1 , wherein the memory encryption processing unit is connected to the destination memory via a memory link, and the memory link includes a housing enclosing a circuitry with tamper-resistant features, the tamper-resistant features being operable to destroy the circuitry if the housing is removed to expose the circuitry.
19 . A method comprising:
establishing, via a memory encryption processing unit, an authenticated-encrypted data stream via a communications channel with a host encryption processing unit by executing a mutual authentication protocol to establish a symmetric session key, wherein the memory encryption processing unit is part of a memory device including a destination memory in communication with the memory encryption processing unit.
20 . (canceled)
21 . (canceled)
22 . (canceled)
23 . (canceled)
24 . (canceled)
25 . (canceled)
26 . (canceled)
27 . (canceled)
28 . (canceled)
29 . (canceled)
30 . The method of claim 19 , further comprising:
reading, via the memory encryption processing unit, data from the destination memory; and
sending the data via the authenticated-encrypted data stream to the host encryption processing unit.
31 . (canceled)
32 . The method of claim 19 , wherein the memory encryption processing unit includes a hardware private key:
receiving, via the memory encryption processing unit, data from the host encryption processing unit via the authenticated-encrypted data stream;
decrypting the data received from the host encryption processing unit using the symmetric session key; and
saving the data in the destination memory.
33 . (canceled)
34 . (canceled)
35 . (canceled)
36 . (canceled)