IP Library Granted Patent US 12,261,941
Granted Patent B2
US 12,261,941 · App. 18/040,245 · Granted Mar 25, 2025

Creating, using, and managing protected cryptography keys

Inventors: Jason W. Brandt (Austin, TX); Steven L. Grobman (Flower Mound, TX); Vedvyas Shanbhogue (Austin, TX)
Assignee: Intel Corporation
H04L9/0822H04L9/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,941
App. No.
18/040,245
Granted
Mar 25, 2025
Kind
B2
Abstract

System, method, and apparatus embodiments for creating, using, and managing protected cryptography keys are described. In an embodiment, an apparatus includes a decoder, an execution unit, and a cache. The decoder is to decode a single instruction into a decoded single instruction, the single instruction having a first source operand to specify encrypted data and a second source operand to specify a handle including a first including ciphertext of an encryption key, an integrity tag, and additional authentication data. The execution unit is to execute the decoded single instruction to perform a first check of the integrity tag against the ciphertext and the additional authentication data for any modification to the ciphertext or the additional authentication data, perform a second check of a current request against one or more restrictions specified by the additional authentication data of the handle, decrypt the ciphertext to generate an encryption key only when the first check indicates no modification to the ciphertext or the additional authentication data and the second check indicates the one or more restrictions are not violated, decrypt the encrypted data with the encryption key to generate unencrypted data, and provide the unencrypted data as a result of the single instruction. The cache is to store the handle, wherein only a portion of the integrity tag is to be used in a lookup of the handle.

Claims (49)

1. An apparatus comprising:

decoder circuitry to decode a single instruction into a decoded single instruction, the single instruction having a first source operand to specify encrypted data and a second source operand to specify a handle including a first including ciphertext of an encryption key, an integrity tag, and additional authentication data;

execution circuitry to execute the decoded single instruction to:

perform a first check of the integrity tag against the ciphertext and the additional authentication data for any modification to the ciphertext or the additional authentication data,

perform a second check of a current request against one or more restrictions specified by the additional authentication data of the handle,

decrypt the ciphertext to generate an encryption key only when the first check indicates no modification to the ciphertext or the additional authentication data and the second check indicates the one or more restrictions are not violated,

decrypt the encrypted data with the encryption key to generate unencrypted data, and

provide the unencrypted data as a result of the single instruction; and

a cache to store the handle, wherein only a portion of the integrity tag is to be used in a lookup of the handle.

2. The apparatus of claim 1 , wherein the portion of the integrity tag is half of the integrity tag.

3. The apparatus of claim 1 , wherein the integrity tag is 128 bits and the portion of the integrity tag is 64 bits.

4. The apparatus of claim 1 , wherein the integrity tag is bits 128 to 256 of the handle.

5. The apparatus of claim 4 , wherein the additional authentication data is bits 0 to 127 of the handle.

6. The apparatus of claim 5 , wherein the ciphertext is bits 256 to 383 of the handle.

7. The apparatus of claim 5 , wherein the ciphertext is bits 256 to 511 of the handle.

8. The apparatus of claim 5 , wherein the additional authentication data includes a field to indicate whether the handle is usable for encryption.

9. The apparatus of claim 5 , wherein the additional authentication data includes a field to indicate whether the handle is usable for decryption.

10. The apparatus of claim 5 , wherein the additional authentication data includes a field to indicate whether the handle is usable at a privilege level.

11. The apparatus of claim 5 , wherein the additional authentication data includes a field to indicate a size of the ciphertext.

12. The apparatus of claim 11 , wherein the additional authentication data includes a field to indicate whether the ciphertext is 128 bits or 256 bits.

13. A method comprising:

decoding a single instruction into a decoded single instruction with a decoder of a hardware processor, the single instruction having a first source operand to specify encrypted data and a second source operand to specify a handle including a first including ciphertext of an encryption key, an integrity tag, and additional authentication data;

executing the decoded single instruction with an execution unit of the processor to:

perform a first check of the integrity tag against the ciphertext and the additional authentication data for any modification to the ciphertext or the additional authentication data,

perform a second check of a current request against one or more restrictions specified by the additional authentication data of the handle,

decrypt the ciphertext to generate an encryption key only when the first check indicates no modification to the ciphertext or the additional authentication data and the second check indicates the one or more restrictions are not violated,

decrypt the encrypted data with the encryption key to generate unencrypted data,

provide the unencrypted data as a result of the single instruction, and

store the handle in the cache; and

looking up the handle from the cache based on a portion of the integrity tag.

14. The method of claim 13 , wherein the subset of the integrity tag is half of the integrity tag.

15. The method of claim 14 , wherein the integrity tag is 128 bits and the subset of the integrity is 64 bits.

16. The method of claim 13 , wherein the integrity tag is bits 128 to 256 of the handle.

17. The method of claim 16 , wherein the additional authentication data is bits 0 to 127 of the handle.

18. The method of claim 17 , wherein the additional authentication data includes a field to indicate whether the ciphertext is bits 256 to 383 or bits 256 to 511 of the handle.

19. A system comprising:

a memory to store a handle; and

a processor including:

a cache;

decoder circuitry to decode a single instruction into a decoded single instruction, the single instruction having a first source operand to specify encrypted data and a second source operand to specify a handle including a first including ciphertext of an encryption key, an integrity tag, and additional authentication data;

execution circuitry to execute the decoded single instruction to:

read the handle from the memory,

perform a first check of the integrity tag against the ciphertext and the additional authentication data for any modification to the ciphertext or the additional authentication data,

perform a second check of a current request against one or more restrictions specified by the additional authentication data of the handle,

decrypt the ciphertext to generate an encryption key only when the first check indicates no modification to the ciphertext or the additional authentication data and the second check indicates the one or more restrictions are not violated,

decrypt the encrypted data with the encryption key to generate unencrypted data, and

provide the unencrypted data as a result of the single instruction; and

store the handle in the cache, wherein only a portion of the integrity tag is to be used in a lookup of the handle.

20. The system of claim 19 , wherein the portion of the integrity tag is half of the integrity tag.

Continuity (2)
Provisional Application 63073366 · Sep 1, 2020
Related Publication 20230269076A1 · Aug 24, 2023
References Cited (15)
US 8510569B2 · Smith · 2013 [cited by examiner]
US 8914648B1 · Pierson · 2014 [cited by examiner]
US 20060015753A1 · Drehmel · 2006 [cited by examiner]
US 20120096282A1 · Henry et al. · 2012 [cited by applicant]
US 20150271144A1 · Ronca · 2015 [cited by applicant]
US 20180247082A1 · Durham · 2018 [cited by examiner]
US 20190080096A1 · Savry · 2019 [cited by applicant]
US 20190087354A1 · Chhabra · 2019 [cited by examiner]
US 20190132120A1 · Zhang · 2019 [cited by examiner]
US 20200125742A1 · Kounavis · 2020 [cited by examiner]
US 20200134234A1 · LeMay · 2020 [cited by examiner]
Hasarfaty, Shai, and Yanai Moyal. “Behind the Scenes of Intel Security and Manageability Engine.” BlackHat US 2019. (Year: 2019). [cited by examiner]
International Preliminary Report on Patentability, PCT App. No. PCT/US2021/048039, Mar. 16, 2023, 8 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2021/048039, Dec. 13, 2021, 11 pages. [cited by applicant]
Office Action, TW App. No. 110132120, Nov. 4, 2024, 42 pages (17 pages of English Translation and 25 pages of Original Document). [cited by applicant]