IP Library › Granted Patent US 11,861,020
Granted Patent B2
US 11,861,020 · App. 16/913,283 · Granted Jan 2, 2024

Generating keys for persistent memory

Inventors: Siddhartha Chhabra (Portland, OR); Hormuzd M. Khosravi (Portland, OR)
Assignee: Intel Corporation
G06F21/602G06F3/0623G06F3/0659G06F3/0679G06F9/3885G06F9/4403G06F21/6281G06F21/78H04L9/0869H04L9/0877H04L9/0891H04L9/3239
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,861,020
App. No.
16/913,283
Granted
Jan 2, 2024
Kind
B2
Abstract

An apparatus includes a processor, persistent memory coupled to the processor, and a memory protection logic. The processor may include multiple processing engines. The persistent memory may include a persistent storage portion and a memory expansion portion. The memory protection logic is to: obtain a first ephemeral component associated with the persistent storage portion; generate a persistent key using the first ephemeral component; obtain a second ephemeral component associated with the memory expansion portion; and generate a non-persistent key using the second ephemeral component. Other embodiments are described and claimed.

Claims (99)

1. An apparatus comprising:

a processor including a plurality of processing engines;

persistent memory coupled to the processor, wherein the persistent memory includes a persistent storage portion and a memory expansion portion; and

a memory protection logic to:

obtain a first ephemeral component associated with the persistent storage portion;

generate a persistent key based on a hash function of the first ephemeral component and a static component;

obtain a second ephemeral component associated with the memory expansion portion; and

generate a non-persistent key using the second ephemeral component.

2. The apparatus of claim 1 , further comprising a memory controller to:

handle requests for the persistent storage portion using the persistent key; and

handle requests for the memory expansion portion using the non-volatile key.

3. The apparatus of claim 1 , further comprising a memory storing firmware instructions, the firmware instructions executable to:

in response to a detection of an initial boot of the apparatus:

cause the memory protection logic to generate the first ephemeral component, store the first ephemeral component in a storage, and store the first ephemeral component in a first register of the processor;

obtain the static component from the processor; and

cause the memory protection logic to generate the persistent key using the static component and the first ephemeral component generated by the memory protection logic.

4. The apparatus of claim 3 , the firmware instructions executable to:

in response to a detection of another boot of the apparatus that is subsequent to the initial boot:

read the first ephemeral component from the storage;

obtain the static component from the processor; and

cause the memory protection logic to regenerate the persistent key using the static component and the first ephemeral component read from the storage.

5. The apparatus of claim 4 , the firmware instructions executable to:

in response to the detection of the another boot:

cause the memory protection logic to generate a new second ephemeral component, store the new second ephemeral component in the storage, and store the new second ephemeral component in a second register of the processor; and

cause the memory protection logic to generate a new non-persistent key using the new second ephemeral component generated by the memory protection logic.

6. The apparatus of claim 5 , the firmware instructions executable to:

in response to a detection of an exit of the apparatus from a standby state, wherein the standby state is subsequent to the another boot:

read the first ephemeral component from the first register of the processor;

cause the memory protection logic to regenerate the persistent key using the static component and the first ephemeral component read from the first register;

read the new second ephemeral component from the second register of the processor; and

cause the memory protection logic to regenerate the new non-persistent key using the new second ephemeral component read from the second register.

7. The apparatus of claim 3 , wherein the static component is obtained from one or more in fuses written into the processor during manufacture, and wherein the static component is a hidden value that is only accessible with a valid privilege.

8. A method comprising:

detecting an initialization of a computing system comprising a processor and persistent memory, wherein the persistent memory includes a persistent storage portion and a memory expansion portion;

in response to a detection of the initialization, obtaining a first ephemeral component associated with the persistent storage portion;

generating a persistent key based on a hash function of the first ephemeral component and a static component;

obtaining a second ephemeral component associated with the memory expansion portion;

generating a non-persistent key using the second ephemeral component; and

handling memory requests using the persistent key and the non-persistent key.

9. The method of claim 8 , further comprising:

obtaining the static component from the processor.

10. The method of claim 8 , further comprising:

detecting an initial boot of the computing device;

in response to a detection of the initial boot of the computing device:

generating, by a memory protection logic of the processor, the first ephemeral component;

storing the first ephemeral component in a storage and in a first register of the processor;

obtaining the static component from the processor; and

generating, by the memory protection logic, the persistent key using the static component and the first ephemeral component generated by the memory protection logic.

11. The method of claim 10 , further comprising:

detecting another boot of the computing device that is subsequent to the initial boot;

in response to a detection of the another boot:

reading the first ephemeral component from the storage;

obtaining the static component from the processor; and

regenerating, by the memory protection logic, the persistent key using the static component and the first ephemeral component read from the storage.

12. The method of claim 11 , further comprising:

in response to the detection of the another boot:

generating, by the memory protection logic, a new second ephemeral component;

storing the new second ephemeral component in the storage and in a second register of the processor; and

generating, by the memory protection logic, a new non-persistent key using the new second ephemeral component generated by the memory protection logic.

13. The method of claim 12 , further comprising:

detecting an exit of the computing device from a standby state, wherein the standby state is subsequent to the another boot;

in response to the detection of the exit:

reading the first ephemeral component from the first register of the processor;

regenerating, by the memory protection logic, the persistent key using the static component and the first ephemeral component read from the first register;

reading the new second ephemeral component from the second register of the processor; and

regenerating, by the memory protection logic, the new non-persistent key using the new second ephemeral component read from the second register.

14. The method of claim 8 , further comprising:

detecting a request for the persistent memory;

obtaining a key identifier in the request;

determining whether a value of key identifier is greater than zero;

in response to a determination that the value of the key identifier is greater than zero, handling the request using a particular key associated with the key identifier; and

in response to a determination that the value of the key identifier is not greater than zero, handling the request using the persistent key instead of the particular key associated with the key identifier.

15. A non-transitory machine-readable medium storing instructions, the instructions executable to:

detect an initialization of a computing system comprising a processor and persistent memory, wherein the persistent memory includes a persistent storage portion and a memory expansion portion, and wherein the processor includes a memory protection logic;

in response to a detection of the initialization:

obtain a first ephemeral component associated with the persistent storage portion;

cause the memory protection logic to generate a persistent key based on a hash function of the first ephemeral component and a static component;

obtain a second ephemeral component associated with the memory expansion portion; and

cause the memory protection logic to generate a non-persistent key using the second ephemeral component.

16. The medium of claim 15 , the instructions executable to:

in response to a determination that the initialization is an initial boot of the computing system:

cause the memory protection logic to generate the first ephemeral component, store the first ephemeral component in a storage, and store the first ephemeral component in a first register of the processor;

obtain the static component from the processor; and

cause the memory protection logic to generate the persistent key based on a hash function of the static component and the first ephemeral component generated by the memory protection logic.

17. The medium of claim 16 , the instructions executable to:

in response to a determination that the initialization is another boot of the computing system that is subsequent to the initial boot:

read the first ephemeral component from the storage;

obtain the static component from the processor; and

cause the memory protection logic to regenerate the persistent key using the static component and the first ephemeral component read from the storage.

18. The medium of claim 17 , the instructions executable to:

in response to the determination that the initialization is the another boot of the computing system:

cause the memory protection logic to generate a new second ephemeral component, store the new second ephemeral component in the storage, and store the new second ephemeral component in a second register of the processor; and

cause the memory protection logic to generate a new non-persistent key using the new second ephemeral component generated by the memory protection logic.

19. The medium of claim 18 , the instructions executable to:

in response to a detection of an exit of the computing system from a standby state, wherein the standby state is subsequent to the another boot:

read the first ephemeral component from the first register of the processor;

cause the memory protection logic to regenerate the persistent key using the static component and the first ephemeral component read from the first register;

read the new second ephemeral component from the second register of the processor; and

cause the memory protection logic to regenerate the new non-persistent key using the new second ephemeral component read from the second register.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2020
From: CHHABRA, SIDDHARTHA; KHOSRAVI, HORMUZD M.
To: INTEL CORPORATION
Reel/Frame 053548/0794 →
Continuity (1)
Related Publication 20210409209A1 · Dec 30, 2021