IP Library Granted Patent US 11,243,893
Granted Patent B2
US 11,243,893 · App. 15/977,353 · Granted Feb 8, 2022

Preventing unauthorized access to encrypted memory

Inventors: Jonathan Lutz (Cornelius, OR); Reouven Elbaz (Hillsboro, OR); Jason W. Brandt (Austin, TX); Hisham Shafi (Akko, IL); Ittai Anati (Ramat Hasharon, IL); Vedvyas Shanbhogue (Austin, TX)
Assignee: Intel Corporation
G06F12/1408G06F11/3656G06F21/602G06F21/78H04L9/0861G06F9/384G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,243,893
App. No.
15/977,353
Granted
Feb 8, 2022
Kind
B2
Abstract

A processor or system includes a processor core to execute a set of instructions to determine that a memory encryption mode is enabled. The memory encryption mode is to cause data stored to memory to be encrypted and data retrieved from the memory to be decrypted. The processor core is further to determine that a debug mode has been enabled and, responsive to a determination that the debug mode has been enabled, generate a second encryption key different than a first encryption key employed before reboot of a computing system. The processor core is further to transmit the second encryption key to a cryptographic engine for use in encryption and decryption of the data according to the memory encryption mode.

Claims (38)

1. A processor comprising:

a cryptographic engine;

a processor core coupled to the cryptographic engine, the processor core to:

upon reboot of a computing system, determine that a memory encryption mode is enabled based on a value of a bit in a first register, wherein the memory encryption mode is to cause data stored to memory to be encrypted and data retrieved from the memory to be decrypted; and

responsive to a determination that a non-privileged memory debug mode has been enabled:

generate a second encryption key different than a first encryption key employed before the reboot of the computing system, wherein use of the first encryption key will fail to access data stored in memory, wherein to generate the second encryption key comprises to cause a deterministic tweak in key generation, and

provide the second encryption key to the cryptographic engine for use in encryption and decryption of the data according to the memory encryption mode.

2. The processor of claim 1 , wherein to determine that the non-privileged memory debug mode is enabled comprises to read a bit from a debug interface register.

3. The processor of claim 1 , wherein the memory comprises one of dynamic random access memory (DRAM) or non-volatile random access memory (NVRAM).

4. The processor of claim 1 , wherein the cryptographic engine comprises a total memory encryption (TME) engine.

5. The processor of claim 1 , wherein the cryptographic engine comprises, in part, a memory encryption engine (MEE).

6. A system comprising:

memory;

a processor core coupled to the memory, the processor core to execute an extensible firmware interface to:

set a first bit in a first register to indicate that a memory encryption mode has been enabled; and

set a second bit in a second register to indicate that a non-privileged memory debug mode has been enabled; and

a cryptographic engine coupled to the processor core and to the memory, the cryptographic engine to:

responsive to the second bit being set and a reboot of the system:

generate a second encryption key different than a first encryption key employed before the reboot of the system, wherein the first encryption key will fail to access data stored in memory, wherein to generate the second encryption key comprises causing a deterministic tweak in key generation,

responsive to the first bit being set and generation of the second encryption key, encrypt, using the second encryption key, data to be written to the memory and decrypt data to be retrieved from the memory.

7. The system of claim 6 , wherein to generate the second encryption key, the cryptographic engine is to execute key derivation logic.

8. The system of claim 6 , wherein the processor core is further to:

execute microcode to generate the second encryption key; and

transmit the second encryption key to the cryptographic engine.

9. The system of claim 6 , wherein the first register comprises an encryption activate register.

10. The system of claim 6 , wherein the second register comprises a debug interface register.

11. The system of claim 6 , wherein the cryptographic engine comprises a total memory encryption (TME).

12. The system of claim 6 , wherein the cryptographic engine comprises, in part, a memory encryption engine (MEE).

13. A method comprising:

upon reboot of a computing system, determining, by a processor core, that a memory encryption mode is enabled, wherein the memory encryption mode causes data stored to memory to be encrypted and data retrieved from the memory to be decrypted;

determining, by the processor core, that a non-privileged memory debug mode has been enabled; and

responsive to determining that the non-privileged memory debug mode has been enabled:

generating, by the processor core, a second encryption key different than a first encryption key employed before the reboot of the computing system, wherein use of the first encryption key will fail to access data stored in memory, wherein to generate the second encryption key, the processor core is to cause a deterministic tweak in key generation, and

providing, by the processor core, the second encryption key to a cryptographic engine for use in encrypting and decrypting the data according to the memory encryption mode.

14. The method of claim 13 , wherein generating the second encryption key comprises the processor core executing a set of microinstructions.

15. The method of claim 13 , wherein determining that the memory encryption mode is enabled comprises reading a bit stored in an encryption activate register.

16. The method of claim 13 , wherein determining that the non-privileged memory debug mode is enabled comprises reading a bit from a debug interface register.

17. The method of claim 13 , wherein the cryptographic engine comprises one of a total memory encryption (TME) engine or a memory encryption engine (MEE).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2018
From: LUTZ, JONATHAN; ELBAZ, REOUVEN; BRANDT, JASON W.; SHAFI, HISHAM; ANATI, ITTAI; SHANBHOGUE, VEDVYAS
To: INTEL CORPORATION
Reel/Frame 046303/0680 →
Continuity (1)
Related Publication 20190347213A1 · Nov 14, 2019
Cited By (3)
US 12,579,307 US 12,627,480 US 12,712,724