IP Library › Granted Patent US 10,671,546
Granted Patent B2
US 10,671,546 · App. 15/573,597 · Granted Jun 2, 2020

Cryptographic-based initialization of memory content

Inventors: Amro J. Awad (Princeton, NJ); Pratyusa K. Manadhata (Piscataway, NJ); Stuart Haber (New York, NY); William G. Horne (Lawrenceville, NJ)
Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
G06F12/1408G06F3/0604G06F3/0632G06F3/0685G06F12/0802G06F21/602G06F21/62G06F21/79G06F2221/2107G06F2221/2113G06F2221/2125G06F2221/2143G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,671,546
App. No.
15/573,597
Granted
Jun 2, 2020
Kind
B2
Abstract

A technique includes receiving a request to initialize a region of a memory. Content that is stored in the region is encrypted based at least in part on a stored nonce value and a key. The technique includes, in response to the request, performing cryptographic-based initialization of the memory, including altering the stored nonce value to initialize the region of the memory.

Claims (45)

1. A method performed by a controller, comprising:

storing a plurality of nonce values in a first memory region, wherein the plurality of nonce values are for encrypting data in respective different memory regions;

in response to a read request, retrieving a stored nonce value of the plurality of nonce values in the first memory region, the stored nonce value associated with content in a second memory region of a memory;

decrypting encrypted data in the second memory region using the stored nonce value and a key;

receiving a request to initialize the second memory region of the memory to render the content in the second memory region of the memory unrecoverable; and

in response to the request to initialize the second memory region of the memory to render the content in the second memory region of the memory unrecoverable, performing a cryptographic-based initialization of the second memory region, including altering the stored nonce value in the first memory region to render the content in the second memory region of the memory unrecoverable.

2. The method of claim 1 , wherein the stored nonce value comprises a counter value, and altering the stored nonce value comprises altering the counter value.

3. The method of claim 1 , wherein the second memory region is associated with a cache line, and altering the stored nonce value comprises changing a count value associated with the cache line.

4. The method of claim 1 , wherein the second memory region is associated with a plurality of cache lines and the stored nonce value is one of a plurality of stored nonce values, the method further comprising:

altering the plurality of stored nonce values to shred the content in the second memory region to render the content in the second memory region unrecoverable.

5. The method of claim 1 , further comprising:

prior to receiving the request to initialize the second memory region, encrypting the content in the second memory region based at least in part on the stored nonce value, the key, and a cache line address to provide the encrypted data.

6. The method of claim 1 , wherein the request to initialize the second memory region is a zero fill request to store all zeros in the second memory region, and the altering of the stored nonce value is performed in response to the zero fill request in lieu of writing zeroes to the second memory region.

7. The method of claim 1 , wherein the altering of the stored nonce value in response to the request to initialize the second memory region renders the content in the second memory region into garbage content.

8. The method of claim 1 , wherein the controller is a memory controller, the stored nonce value is stored in the first memory region of a local memory of the memory controller, and the key is associated with the memory controller.

9. An apparatus comprising:

a first memory to store a plurality of initialization vectors associated with a plurality of cache lines, wherein the plurality of initialization vectors are for encrypting data in respective different memory regions of a second memory; and

a memory controller to:

in response to a read request, retrieve stored initialization vectors of the plurality of initialization vectors in the first memory, the stored initialization vectors associated with content in a corresponding memory region of the second memory;

decrypt encrypted data in the corresponding memory region using the stored initialization vectors and a key;

receive a request to shred the corresponding memory region to render the content in the corresponding memory region unrecoverable, the corresponding memory region associated with a group of cache lines of the plurality of cache lines; and

in response to the request to shred the corresponding memory region, alter the stored initialization vectors associated with the group of cache lines to shred the corresponding memory region that renders the content in the corresponding memory region unrecoverable.

10. The apparatus of claim 9 , wherein the corresponding memory region comprises a page of the second memory.

11. The apparatus of claim 9 , wherein the first memory comprises a volatile memory, and the memory controller is to back up content of the first memory to a non-volatile memory.

12. The apparatus of claim 9 , wherein the memory controller is to decrypt the encrypted data further based at least in part on an address of the encrypted data.

13. The apparatus of claim 9 , wherein the request to shred the corresponding memory region is a zero fill request to store all zeros in the corresponding memory region.

14. The apparatus of claim 9 , wherein the memory controller is to invalidate the group of cache lines in response to the request to shred the corresponding memory region.

15. The apparatus of claim 9 , wherein the memory controller is to, in response to a request to write data to a given cache line of the plurality of cache lines:

change a given initialization vector of the plurality of initialization vectors;

encrypt data of the given cache line using the changed given initialization vector,

wherein the request to shred is different from a request to write data.

16. The apparatus of claim 9 , wherein the altering of the stored initialization vectors in response to the request to shred renders the content of the corresponding memory region into garbage content.

17. A system comprising:

a first memory to store a plurality of nonce values, wherein the plurality of nonce values are for encrypting data in respective different memory regions of a second memory; and

a memory controller to:

in response to a read request, retrieve a stored nonce value of the plurality of nonce values in the first memory, the stored nonce value associated with content in a corresponding memory region of the second memory;

decrypt encrypted data in the corresponding memory region using the stored nonce value and a key;

receive an initialization request to initialize the corresponding memory region of the second memory to render the content in the corresponding memory region of the second memory unrecoverable; and

in response to the initialization request, perform a cryptographic-based initialization of the corresponding memory region, including altering the stored nonce value to render the content in the corresponding memory region of the second memory unrecoverable.

18. The system of claim 17 , wherein:

the corresponding memory region comprises a page;

the page comprises a plurality of cache line regions;

the stored nonce value is associated with a given cache line region of the plurality of cache line regions; and

the encrypted data is stored in the given cache line region.

19. The system of claim 18 , wherein the memory controller is to, in response to the initialization request, change other nonce values associated with one or more cache line regions other than the given cache line region.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE 2ND INVENTOR'S NAME FROM PRATYUSA MANADHATA PREVIOUSLY RECORDED ON REEL 044427 FRAME 0989. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECTION OF THE 2ND INVENTOR'S NAME TO PRATYUSA K. MANADHATA. Recorded Apr 2, 2020
From: MANADHATA, PRATYUSA K.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 052311/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2018
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 046311/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2017
From: AWAD, AMRO J.; MANADHATA, PRATYUSA; HABER, STUART; HORNE, WILLIAM G.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 044427/0989 →
Continuity (1)
Related Publication 20180137062A1 · May 17, 2018