IP Library › Granted Patent US 12,261,936
Granted Patent B2
US 12,261,936 · App. 17/213,465 · Granted Mar 25, 2025

Technologies for real-time updating of encryption keys

Inventors: Vinit Mathew Abraham (Hillsboro, OR); Raghunandan Makaram (Northborough, MA); Kirk S. Yap (Westborough, MA); Siva Prasad Gadey (Portland, OR); Tanmoy Kar (Bengaluru, IN)
Assignee: Intel Corporation
H04L9/0631H04L9/0643H04L9/0872
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,936
App. No.
17/213,465
Granted
Mar 25, 2025
Kind
B2
Abstract

Techniques for real-time updating of encryption keys are disclosed. In the illustrative embodiment, an encrypted link is established between a local and remote processor over a point-to-point interconnect. The encrypted link is operated for some time until the encryption key should be updated. The local processor sends a key update message to the remote processor notifying the remote processor of the change. The remote processor prepares for the change and sends a key update confirmation message to the local processor. The local processor then sends a key switch message to the remote processor. The local processor pauses transmission of encrypted message while the remote processor completes use of the encrypted message. After a pause, the local processor continues sending encrypted messages with the updated encryption key.

Claims (78)

1. An apparatus comprising:

point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to:

establish an encrypted point-to-point link between the point-to-point interface circuitry and a processor, wherein the processor is a CPU of the apparatus, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;

determine an updated encryption key;

transmit, on a channel of the point-to-point link corresponding to the updated encryption key, a key switch message to the processor to instruct the processor to use the updated encryption key;

perform, after transmission of the key switch message and without sending encrypted messages on the channel, one or more stages of a pipeline of the cryptographic engine to encrypt one or more messages with the updated encryption key; and

send the one or more messages encrypted with the updated encryption key on the channel.

2. The apparatus of claim 1 , wherein the point-to-point interface circuitry is further to:

transmit a key update message to the processor to instruct the processor to prepare to use the updated encryption key; and

receive a key update confirmation message from the processor indicating that the processor is prepared to use the updated encryption key,

wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the processor.

3. The apparatus of claim 1 , wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time to allow the processor to decrypt messages in a pipeline of a cryptographic engine of the processor with the first encryption key.

4. The apparatus of claim 3 , wherein the point-to-point interface circuitry is to automatically resume transmission of encrypted messages after the predetermined amount of time.

5. The apparatus of claim 1 , wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel,

wherein the first encryption key is associated with the first channel,

wherein the point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.

6. The apparatus of claim 1 , wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.

7. The apparatus of claim 1 , wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of time since the first encryption key was first used.

8. The apparatus of claim 1 ,

wherein to establish the encrypted point-to-point link comprises to:

establish a transmit link to transmit messages to the processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and

establish a receive link to receive messages from the processor with use of a first receive encryption key,

wherein the point-to-point interface circuitry is further to:

decrypt messages received from the processor in the cryptographic engine with use of the first receive encryption key and with use of a receive pipeline of the cryptographic engine;

determine an updated receive encryption key;

receive, from the processor, a key switch message to instruct the apparatus to use the updated receive encryption key; and

clear, in response to the key switch message, the receive pipeline of the cryptographic engine with use of the first receive encryption key by completing decryption of messages in the receive pipeline; and

switch the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key in response to the receive pipeline being cleared.

9. The apparatus of claim 8 , wherein to determine the updated receive encryption key comprises to determine the updated receive encryption key based on communication with the processor.

10. The apparatus of claim 1 , wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with integrity protection with use of Advanced Encryption Standard-Galois/Counter Mode (AES-GCM).

11. The apparatus of claim 1 , wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with use of Advanced Encryption Standard in Counter mode (AES-CTR) and an integrity key to integrity protect messages with use of AES-Galois message authentication code (AES-GMAC).

12. The apparatus of claim 1 , the point-to-point interface circuitry is in a second CPU of the apparatus, wherein the CPU is mounted on a motherboard, wherein the second CPU is mounted on the motherboard.

13. A system comprising:

a plurality of processors comprising a first processor and a second processor, wherein the first processor comprises first point-to-point interface circuitry and the second processor comprises second point-to-point interface circuitry,

wherein the first point-to-point interface circuitry is to:

establish an encrypted point-to-point link between the first point-to-point interface circuitry and the second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to use a first encryption key to encrypt messages for the encrypted point-to-point link;

determine an updated encryption key; and

transmit a key switch message to the second processor to instruct the second processor to use the updated encryption key,

wherein the second point-to-point interface circuitry is to:

receive, from the first processor, the key switch message to instruct the second processor to use the updated encryption key; and

clear, in response to the key switch message, a pipeline of a cryptographic engine of the second point-to-point interface circuitry with use of the first encryption key by completing processing of messages in the pipeline; and

switch, in response to the key switch message, the cryptographic engine to use the updated encryption key in place of the first encryption key in response to the pipeline being cleared.

14. The system of claim 13 , wherein the point-to-point interface circuitry is further to:

transmit a key update message to the second processor to instruct the second processor to prepare to use the updated encryption key; and

receive a key update confirmation message from the second processor indicating that the second processor is prepared to use the updated encryption key,

wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the second processor.

15. The system of claim 13 , wherein transmission of encrypted messages by the first point-to-point interface circuitry is to be paused after transmission of the key switch message for a predetermined amount of time to allow the second point-to-point interface circuitry to decrypt messages in a pipeline of a cryptographic engine of the second processor with the first encryption key.

16. The system of claim 13 , wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel,

wherein the first encryption key is associated with the first channel,

wherein the first point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.

17. The system of claim 13 , wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.

18. An apparatus comprising:

point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to:

establish an encrypted point-to-point link between the point-to-point interface circuitry and a processor, wherein the processor is a CPU of the apparatus, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;

determine an updated encryption key;

transmit a key switch message to the processor to instruct the processor to use the updated encryption key; and

transmit, after transmission of the key switch message and without a reset of the encrypted point-to-point link, encrypted messages with use of the updated encryption key.

19. The apparatus of claim 18 , wherein the point-to-point interface circuitry is further to:

transmit a key update message to the processor to instruct the processor to prepare to use the updated encryption key; and

receive a key update confirmation message from the processor indicating that the processor is prepared to use the updated encryption key,

wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the processor.

20. The apparatus of claim 18 , wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time to allow the processor to decrypt messages in a pipeline of a cryptographic engine of the processor with the first encryption key.

21. The apparatus of claim 18 , wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein transmit the key switch message comprises to transmit the key switch message over the first channel,

wherein the first encryption key is associated with the first channel,

wherein the point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.

22. The apparatus of claim 18 , wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.

23. The apparatus of claim 18 , wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of time since the first encryption key was first used.

24. The apparatus of claim 18 ,

wherein to establish the encrypted point-to-point link comprises to:

establish a transmit link to transmit messages to the processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and

establish a receive link to receive messages from the processor with use of a first receive encryption key,

wherein the point-to-point interface circuitry is further to:

decrypt messages received from the processor in the cryptographic engine with use of the first receive encryption key and with use of a pipeline of the cryptographic engine;

determine an updated receive encryption key;

receive, from the processor, a key switch message to instruct the apparatus to use the updated receive encryption key; and

clear, in response to the key switch message, the pipeline of the cryptographic engine with use of the first receive encryption key by completing decryption of messages in the receive pipeline; and

switch the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key in response to the receive pipeline being cleared.

25. The apparatus of claim 24 , wherein to determine the updated receive encryption key comprises to determine the updated receive encryption key based on communication with the processor.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE FILING DATE OF THE APPLICATION PREVIOUSLY RECORDED ON REEL 055733 FRAME 0455. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 7, 2023
From: ABRAHAM, VINIT MATHEW; YAP, KIRK S.; MAKARAM, RAGHUNANDAN; GADEY, SIVA PRASAD; KAR, TANMOY
To: INTEL CORPORATION
Reel/Frame 063908/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2021
From: ABRAHAM, VINIT MATHEW; YAP, KIRK S.; MAKARAM, RAGHUNANDAN; GADEY, SIVA PRASAD; KAR, TANMOY
To: INTEL CORPORATION
Reel/Frame 055733/0455 →
Continuity (1)
Related Publication 20210218548A1 · Jul 15, 2021
References Cited (14)
US 6957329B1 · Aleksic · 2005 [cited by examiner]
US 7818563B1 · Dwork · 2010 [cited by examiner]
US 11265301B1 · Gupta · 2022 [cited by examiner]
US 11582195B1 · Karppanen · 2023 [cited by examiner]
US 20100151822A1 · Medvinsky · 2010 [cited by examiner]
US 20110055558A1 · Liu · 2011 [cited by examiner]
US 20150156181A1 · kerberg · 2015 [cited by examiner]
US 20160249210A1 · Chang · 2016 [cited by examiner]
US 20170272408A1 · Li · 2017 [cited by examiner]
US 20190220721A1 · Chhabra · 2019 [cited by examiner]
US 20190288842A1 · Weis · 2019 [cited by examiner]
US 20200245401A1 · Ingale · 2020 [cited by examiner]
US 20210075587A1 · Alwen · 2021 [cited by examiner]
Compute Express Link Consortium, Inc., “Compute Express Link (CSL) Specification, Revision 2.0,” Oct. 2020 (628 pages). [cited by applicant]