IP Library › Granted Patent US 11,308,225
Granted Patent B2
US 11,308,225 · App. 16/723,927 · Granted Apr 19, 2022

Management of keys for use in cryptographic computing

Inventors: Michael E. Kounavis (Portland, OR); Santosh Ghosh (Hillsboro, OR); Sergej Deutsch (Hillsboro, OR); David M. Durham (Beaverton, OR)
Assignee: Intel Corporation
G06F21/602G06F9/30043G06F9/30101G06F9/30178G06F9/321G06F9/45558G06F9/48G06F9/5016G06F12/0207G06F12/0646G06F12/0811G06F12/0875G06F12/0897G06F12/1408G06F12/1458G06F12/1466G06F21/12G06F21/6227G06F21/72G06F21/79H04L9/0637H04L9/0822H04L9/0861H04L9/0869H04L9/0894H04L9/14G06F2009/45587G06F2212/1052H04L2209/125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,308,225
App. No.
16/723,927
Granted
Apr 19, 2022
Kind
B2
Abstract

A method comprising executing, by a core of a processor, a first instruction requesting access to a parameter associated with data for storage in a main memory coupled to the processor, the first instruction including a reference to the parameter, a reference to a wrapping key, and a reference to an encrypted encryption key, wherein execution of the first instruction comprises decrypting the encrypted encryption key using the wrapping key to generate a decrypted encryption key; requesting transfer of the data between the main memory and the processor core; and performing a cryptographic operation on the parameter using the decrypted encryption key.

Claims (36)

1. A processor comprising:

a plurality of registers; and

a processor core comprising circuitry, the processor core to execute a first instruction requesting access to a parameter associated with data for storage in a main memory coupled to the processor, the first instruction including a reference to the parameter, a reference to a wrapping key, and a reference to an encrypted encryption key, wherein execution of the first instruction comprises:

decrypting the encrypted encryption key using the wrapping key to generate a decrypted encryption key;

requesting transfer of the data between the main memory and the processor core; and

performing a cryptographic operation on the parameter using the decrypted encryption key.

2. The processor of claim 1 , wherein the parameter comprises at least one of the data, a linear address of the data, a physical address of the data, a software object identifier, and a software object type.

3. The processor of claim 1 , wherein the first instruction comprises a cryptographic store instruction, the parameter comprises plaintext data, the cryptographic operation comprises encryption of the plaintext data to generate the data for storage in the main memory, and requesting transfer of the data comprises requesting transfer, from the processor core to the main memory, of the data for storage in the main memory.

4. The processor of claim 1 , wherein the first instruction comprises a cryptographic load instruction, the parameter comprises encrypted data stored in the main memory, requesting transfer of the data comprises requesting transfer of the encrypted data from the main memory to the processor core, and the cryptographic operation comprises decryption of the encrypted data.

5. The processor of claim 1 , wherein the parameter comprises the data for storage in the main memory and execution of the first instruction further comprises placing the parameter into a register of the plurality of registers.

6. The processor of claim 1 , wherein the parameter comprises an encrypted pointer referencing the data for storage in the main memory.

7. The processor of claim 1 , wherein the plurality of registers comprise a plurality of data registers and a plurality of registers dedicated to storing cryptographic keys, and wherein the reference to the wrapping key comprises an identifier of a register of the plurality of registers dedicated to storing cryptographic keys.

8. The processor of claim 7 , wherein the reference to the encrypted encryption key comprises an identifier of a second register of the plurality of registers dedicated to storing cryptographic keys.

9. The processor of claim 1 , wherein the parameter comprises an object identifier of a plurality of object identifiers, the object identifier is associated with the data for storage in the main memory, and the wrapping key comprises a master key used by a parent function to encrypt the plurality of object identifiers to generate a plurality of derived keys to be distributed to a plurality of child functions.

10. The processor of claim 9 , wherein the processor is further to execute an instruction issued by a child function of the plurality of child functions, wherein the instruction issued by the child function includes a reference to a derived key of the plurality of derived keys and a reference to data encrypted by the derived key.

11. The processor of claim 1 , wherein the processor is to implement a hierarchy of encryption keys, wherein a first function having access to a first wrapping key that is a root of a second wrapping key obtains access to data encrypted using an encryption key wrapped by the first wrapping key and data encrypted using a second encryption key wrapped by the second wrapping key and wherein a second function having access to the second wrapping key but not the first wrapping key obtains access to data encrypted using the second encryption key but not data encrypted using the first encryption key.

12. The processor of claim 1 , wherein the processor core is to execute a second instruction, the second instruction including a reference to the wrapping key and a reference to the encryption key, wherein execution of the second instruction comprises:

encrypting the encryption key using the wrapping key to generate the encrypted encryption key; and

outputting the encrypted encryption key.

13. The processor of claim 1 , further comprising one or more of: a battery communicatively coupled to the processor, a display communicatively coupled to the processor, or a network interface communicatively coupled to the processor.

14. The processor of claim 1 , wherein the processor core to execute the first instruction is a first core of a multi-core central processing unit.

15. A method comprising:

executing, by a core of a processor, a first instruction requesting access to a parameter associated with data for storage in a main memory coupled to the processor, the first instruction including a reference to the parameter, a reference to a wrapping key, and a reference to an encrypted encryption key, wherein execution of the first instruction comprises:

decrypting the encrypted encryption key using the wrapping key to generate a decrypted encryption key;

requesting transfer of the data between the main memory and the processor core; and

performing a cryptographic operation on the parameter using the decrypted encryption key.

16. The method of claim 15 , wherein the parameter comprises at least one of the data, a linear address of the data, a physical address of the data, a software object identifier, and a software object type.

17. The method of claim 15 , wherein the first instruction comprises a cryptographic store instruction, the parameter comprises plaintext data, the cryptographic operation comprises encryption of the plaintext data to generate the data for storage in the main memory, and requesting transfer of the data comprises requesting transfer, from the processor core to the main memory, of the data for storage in the main memory.

18. The method of claim 15 , wherein the first instruction comprises a cryptographic load instruction, the parameter comprises encrypted data stored in the main memory, requesting transfer of the data comprises requesting transfer of the encrypted data from the main memory to the processor core, and the cryptographic operation comprises decryption of the encrypted data.

19. One or more non-transitory computer-readable media with code stored thereon, wherein the code is executable to cause a processor to:

execute a first instruction requesting access to a parameter associated with data for storage in a main memory coupled to the processor, the first instruction including a reference to the parameter, a reference to a wrapping key, and a reference to an encrypted encryption key, wherein execution of the first instruction comprises:

decrypting the encrypted encryption key using the wrapping key to generate a decrypted encryption key;

requesting transfer of the data between the main memory and the processor core; and

performing a cryptographic operation on the parameter using the decrypted encryption key.

20. The one or more computer-readable media of claim 19 , wherein the first instruction comprises a cryptographic store instruction, the parameter comprises plaintext data, the cryptographic operation comprises encryption of the plaintext data to generate the data for storage in the main memory, and requesting transfer of the data comprises requesting transfer, from the processor core to the main memory, of the data for storage in the main memory.

21. The one or more computer-readable media of claim 19 , wherein the first instruction comprises a cryptographic load instruction, the parameter comprises encrypted data stored in the main memory, requesting transfer of the data comprises requesting transfer of the encrypted data from the main memory to the processor core, and the cryptographic operation comprises decryption of the encrypted data.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 051852 FRAME: 0913. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 8, 2021
From: KOUNAVIS, MICHAEL E.; GHOSH, SANTOSH; DEUTSCH, SERGEJ; DURHAM, DAVID M.
To: INTEL CORPORATION
Reel/Frame 058392/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2020
From: KOUNAVIS, MICHAEL E.; GHOSH, SANTOSH; DEUTSCH, SERGEJ; DURHAM, DAVID M.
To: INTEL CORPORATION
Reel/Frame 051852/0913 →
Continuity (2)
Provisional Application 62868884 · Jun 29, 2019
Related Publication 20200145199A1 · May 7, 2020
Cited By (4)
US 12,282,567 US 12,306,998 US 12,321,467 US 12,346,463