Embedded encryption and / or decryption using address tags

By encoding the embedded address tag in the PCIe address, the problems of encryption and decryption operation delay and memory bandwidth load in the prior art are solved, and more efficient data access is achieved.

CN120548531APending Publication Date: 2025-08-26QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480008360.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-27
Filing Date
2024-01-23
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

Prior art There are problems with encryption and decryption operation delays and increased memory bandwidth load when protecting data, especially when using software-based encryption or standalone encryption hardware.

Method used

Embedded address tag technology is adopted to encode part of the PCIe address into embedded address tags, which are used to find metadata for encryption and decryption during data access, reducing modifications to existing protocols.

Benefits of technology

Through embedded address tag technology, the latency of accessing storage devices and the use of memory bandwidth are reduced, and the efficiency of data access is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120548531A_ABST
    Figure CN120548531A_ABST
Patent Text Reader

Abstract

Techniques and systems for data access are provided. For example, a process may include determining a storage device address for a storage device, determining a tag for obtaining encrypted metadata for data for the storage device, generating a return address, the return address including a host memory address and the tag, and accessing the storage device based on the return address and the storage device address.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to techniques for protecting information (eg, an encrypted file system). For example, aspects of the present disclosure relate to systems and techniques for inline encryption using address tags. Background Art

[0002] Computing devices often employ various techniques to protect data. For example, data may be subjected to encryption and decryption techniques in various scenarios, such as writing data to a storage device, reading data from a storage device, writing data to or reading data from a memory device, encrypting and decrypting data blocks and / or volumes, encrypting and decrypting digital content, performing embedded cryptographic operations, and the like. Such encryption and decryption operations are often performed, at least in part, using secure information assets (such as cryptographic keys, derived cryptographic keys, and the like). Certain scenarios exist in which attacks are performed in an attempt to obtain such secure information assets. Therefore, it would be generally advantageous to implement systems and techniques for protecting such secure information assets. Summary of the Invention

[0003] This document describes systems and techniques for protecting against malicious attacks in images. A brief overview of one or more aspects disclosed herein is provided below. Therefore, the following summary should not be considered an extensive overview of all contemplated aspects, nor should it be considered to identify key or important elements related to all contemplated aspects or to delineate the scope associated with any particular aspect. Accordingly, the following summary provides, in simplified form, certain concepts related to one or more aspects of the mechanisms disclosed herein as a prelude to the detailed description provided below.

[0004] Systems and techniques for accessing data, such as for accessing an encrypted data storage device, are described. In one illustrative example, a method for accessing data is provided. The method includes determining a storage device address for a storage device, determining a tag for obtaining encrypted metadata for data on the storage device, generating a return address comprising a host memory address and the tag, and accessing the storage device based on the return address and the storage device address.

[0005] As another example, an apparatus for data access is provided. The apparatus includes at least one memory, a storage device, and at least one processor coupled to the at least one memory. The at least one processor is configured to determine a storage device address for the storage device, determine a tag for obtaining encrypted metadata for data on the storage device, generate a return address comprising a host memory address and the tag, and access the storage device based on the return address and the storage device address.

[0006] In another example, a non-transitory computer-readable medium is provided having instructions stored thereon that, when executed by at least one processor, cause the at least one processor to perform the following operations: determine a storage device address for a storage device, determine a tag for obtaining encrypted metadata for data of the storage device, generate a return address, the return address comprising a host memory address and the tag, and access the storage device based on the return address and the storage device address.

[0007] In another example, an apparatus for data access is provided. The apparatus includes: means for determining a storage device address for a storage device, means for determining a tag for obtaining encrypted metadata for data of the storage device, means for generating a return address, the return address including a host memory address and the tag, and means for accessing the storage device based on the return address and the storage device address.

[0008] In some aspects, one or more apparatuses described herein are, are part of, and / or include a mobile or wireless communication device (e.g., a mobile phone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a connected watch or other wearable device), a vehicle or computing device or a component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device (such as a mobile phone acting as a server device), an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system on a chip (SoC), any combination thereof, and / or other types of devices. In some aspects, the apparatus includes a display for displaying one or more images, notifications, and / or other displayable data. In some aspects, the apparatus includes one or more sensors (e.g., one or more RF sensors) such as one or more gyroscopes, one or more gyroscopes, one or more accelerometers, any combination thereof, and / or other sensors.

[0009] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used alone to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.

[0010] The foregoing and other features and examples will become more apparent after reference to the following description, claims, and accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Illustrative examples of the present application are described in detail below with reference to the following drawings:

[0012] Figure 1 is a block diagram illustrating certain components of a computing device according to some examples;

[0013] Figure 2 shows an example PCIe transaction layer packet format configured to perform inline encryption / decryption using address tags in accordance with aspects of the present disclosure;

[0014] Figure 3 is a flowchart illustrating an example process for data access according to some examples;

[0015] Figure 4 is a schematic diagram illustrating an example of a system for implementing certain aspects of the present technology. DETAILED DESCRIPTION

[0016] Provided below are certain aspects and examples of the present disclosure. As will be apparent to those skilled in the art, some of these aspects and examples can be applied independently, and some of them can be applied in combination. In the following description, for the purpose of explanation, specific details are set forth in order to provide a comprehensive understanding of the examples of the present application. However, it will be apparent that each example can be implemented without these specific details. The accompanying drawings and description are not intended to be restrictive. In addition, certain details known to those of ordinary skill in the art can be omitted to avoid ambiguous descriptions.

[0017] In the following description of the drawings, in the various examples described herein, any component described with respect to a drawing may be equivalent to one or more similarly named (or numbered) components described with respect to any other drawing. For the sake of brevity, the description of these components may not be repeated in full with respect to each drawing. Therefore, each example of a component of each figure is incorporated by reference and is assumed to be optionally present in each other figure with one or more similarly named components. In addition, according to the various examples described herein, any description of a component of a drawing will be interpreted as an optional example, which can be implemented in addition to, in conjunction with, or in place of the example described with respect to the corresponding similarly named component in any other drawing.

[0018] The following description only provides illustrative examples and is not intended to limit the scope, applicability or configuration of the present disclosure. On the contrary, the following description of the illustrative examples will provide a description of the implementation for realizing the exemplary examples for those skilled in the art. It should be understood that various changes can be made to the function and arrangement of elements without departing from the spirit and scope of the present application as set forth in the appended claims.

[0019] As used herein, the phrase "operably connected" or "operably connected" (or any variation thereof) means that there is a direct or indirect connection between elements / components / devices, etc. that allows the elements to interact with each other in some way. For example, the phrase "operably connected" can refer to any direct (e.g., a direct wired connection between two devices or components) or indirect (e.g., a wired and / or wireless connection between any number of devices or components that connect an operably connected device). Therefore, any path through which information can travel can be considered to be an operational connection. In addition, operably connected devices and / or components can exchange things, and / or can unintentionally share things other than information, such as, for example, electric current, radio frequency signals, power supply interference, interference due to proximity, interference due to reuse of the same wires and / or physical media, interference due to reuse of the same registers and / or other logical media, etc.

[0020] In some cases, storage devices such as hard disks, solid-state drives, flash drives, etc. can be protected using disk encryption such as full disk encryption. In some cases, in order to access the storage device (e.g., read data from / write data to the storage device), an encryption operation can be performed. The encryption operation can be based on certain metadata, such as a key and / or an adjustment value. The key and / or adjustment can be based on a logical block address (LBA), so that each encrypted sector has an associated key and a unique 128-bit adjustment including the LBA. Therefore, a portion of the address of the data can be used to look up the metadata to access the storage device. Software-based encryption or independent encryption hardware (e.g., encryption hardware that does not directly read from / write to the storage device, the memory is used to read from / write to the storage device) can be used to encrypt / decrypt data for disk encryption, but such solutions may increase latency and bandwidth load on the storage device. Other approaches may involve modifications to existing protocols.

[0021] This document describes systems, apparatuses, electronic devices, methods (also referred to as processes), and computer-readable media (collectively referred to herein as "systems and techniques") for performing inline encryption and / or decryption using address tags. For example, the inline address tag can use a portion of an address (e.g., a Peripheral Component Interconnect Express (PCIe) address) as an inline address tag to look up metadata used to encrypt / decrypt data from / to a storage device. In some cases, the inline address tag can be used as an index for looking up in a data segment table (DST). In some cases, the DST can be an in-memory table that includes information for determining metadata used to encrypt / decrypt data. The inline cryptography can refer to transparently encrypting / decrypting data from a storage device as part of a read / write process to an existing PCIe / NVMe storage device. For example, a storage device can retrieve encrypted data from the storage device and write the data to a memory location. As part of the write operation, the encrypted data stream can be automatically decrypted and written to the memory location. This can be performed without having to, for example, copy the entire encrypted data to another memory to perform the decoding.

[0022] In some cases, including metadata for encrypting / decrypting data in the PCIe address (e.g., return address) used to access the storage device allows a single request to obtain both the data to be encrypted / decrypted and the metadata used to perform the encryption / decryption. This solution can help reduce latency in accessing the storage device and reduce memory bandwidth usage compared to software-based encryption or standalone encryption / decryption hardware. Encoding the embedded address tag in the PCIe address helps avoid having to change the underlying protocol.

[0023] Various aspects of the technology described herein are discussed below with respect to the accompanying figures. Figure 1 1 is a block diagram illustrating an example of a computing device 100 configured to perform inline encryption / decryption using inline address tags according to aspects of the present disclosure. As shown, the computing device 100 includes a processor 102, a non-volatile memory express (NVMe) device 104, a bus 106, a memory device 108, an attached storage device 110, an inline cryptographic engine 112, and a peripheral component interconnect express (PCIe) interface 114. In some cases, the memory device 108 may include a data segmentation table (DST) 118. Alternatively, the DST 118 may be part of the inline cryptographic engine 112 or other hardware component.

[0024] Computing device 100 is any device, portion of a device, or any collection of devices capable of processing instructions electronically, and may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuits, memory, input and output devices (not shown), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and / or any combination thereof). Examples of computing devices include, but are not limited to, mobile devices (e.g., laptops, smartphones, personal digital assistants, tablet computers, automotive computing systems, and / or any other mobile computing devices), Internet of Things (IoT) devices, servers (e.g., blade servers in blade server chassis, rack servers in racks, etc.), desktop computers, storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash storage arrays, network attached storage devices, etc.), network devices (e.g., switches, routers, multilayer switches, etc.), wearable devices (e.g., connected watches or smart watches or other wearable devices), robotic devices, smart TVs, smart appliances, extended reality (XR) devices (e.g., augmented reality, virtual reality, etc.), any device including one or more SoCs, and / or any other type of computing device having the above requirements. In one or more examples, any or all of the foregoing examples can be combined to create a system of such devices, which can be collectively referred to as a computing device. Other types of computing devices can be used without departing from the scope of the examples described herein.

[0025] In some examples, processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program). As an example, this circuitry may be an integrated circuit implemented at least in part using transistors that implement components such as an arithmetic logic unit, a control unit, logic gates, registers, a first-in-first-out (FIFO) buffer, a data and control buffer, and the like. In some examples, the processor retrieves and decodes instructions and then executes them. Execution of instructions may include performing operations on data, which may include reading and / or writing data. In some examples, the instructions and data used by the processor are stored in a memory (e.g., memory device 108) of computing device 100. The processor may perform various operations for executing software, such as an operating system, an application, and the like. Processor 102 may write data from memory to a storage device of computing device 100 and / or read data from a storage device via memory. Examples of processors include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), a neural processing unit, a tensor processing unit, a display processing unit, a digital signal processor (DSP), a finite state machine, and the like. In some cases, processor 102 may be integrated into a system on a chip (SoC) 116. In some examples, the SoC 116 may also incorporate the bus 106, the memory device 108, the embedded cryptographic engine 112, and the PCIe interface 114. In some cases, the NVMe device 104 and the attached storage device 110 may be coupled to the SoC 116, but separate from the SoC 116.

[0026] The processor 102 may be operatively connected to the memory device 108, any storage means of the computing device 100 (e.g., the NVMe device 104, the attached storage device 110), and / or the embedded cryptographic engine 112 via the bus 106. Figure 1 Computing device 100 is shown with a single processor 102 , but a computing device may include any number of processors without departing from the scope of the examples described herein.

[0027] In some examples, the computing device 100 includes an NVMe device 104. In some examples, the NVMe device 104 is a flash storage device that complies with the NVMe specification, which defines a protocol that can be overlaid on the PCIe interface 114 (e.g., extending the functionality of the PCIe interface 114). The NVMe device 104 can be used to store any type of data. Data can be written to and / or read from the NVMe device 104. As an example, the NVMe device can store an operating system image, a software image, application data, etc. The NVMe device 104 can store any other type of data without departing from the scope of the examples described herein. In some examples, the NVMe device 104 includes a NAND flash storage device. The NVMe device 104 can use any other type of storage technology without departing from the scope of the examples described herein. In some examples, the NVMe device 104 can have a relatively faster data rate than other storage devices of the computing device 100 (e.g., the additional storage device 110). The NVMe device 104 may be operatively connected to the processor 102, the memory device 108, and / or the attached storage device 110. Figure 1 A computing device 100 is shown with a single NVMe device 104, but a computing device may include any number of NVMe devices without departing from the scope of the examples described herein. Figure 1 An NVMe device 104 is shown, but the computing device 100 may include any other type of flash storage device without departing from the scope of the examples described herein.

[0028] In some cases, the NVMe device 104 can be coupled to a PCIe interface 114. The PCIe interface 114 can be a physical input / output (I / O) interface for connecting various components or peripherals that can be used by the computing device 100. In some cases, multiple devices can be coupled via the PCIe interface 114, such as an NVMe device and an attached storage device 110. In some cases, different communication protocols can be used on the PCIe interface 114 to communicate with devices coupled via the PCIe interface 114. For example, the NVMe protocol can be used to communicate with the NVMe device 104 through the PCIe interface 114. Other communication protocols can also be used. It is worth noting that although discussed in the context of PCIe and NVMe, it should be understood that the concepts discussed herein are not limited to PCIe and NVMe, but can be applied to other component interfaces.

[0029] In some cases, a host (such as a processor 102) of the PCIe interface 114 can access the NVMe device 104 by providing commands and / or data to the NVMe device 104. For example, the processor 102 can queue an NVMe command set (e.g., a request), an address, and / or data for the NVMe device 104 in a buffer (such as a memory device 108). The buffer can be used for the NVMe device 104 to write data from the buffer to the NVMe device 104 and / or read data from the NVMe device 104 into the buffer, and the address can indicate where to perform the read / write on the NVMe device 104 and / or the buffer. The NVMe command for performing the read / write can include an NVMe command identifier for identifying the NVMe command. In some cases, the size of the NVMe command can be 64 bits. In some cases, placing the NVMe command in the buffer can trigger a doorbell signal that is configured to indicate to the NVMe device 104 that the NVMe command in the buffer is ready for execution. In some cases, the NVMe device 104 can respond to queued NVMe commands in the buffer in any order (e.g., in order, out of order, etc.). In some cases, there can be multiple NVMe command queues. In response to an NVMe command, the NVMe device 104 can read data from the buffer to be written to the NVMe device 104 (e.g., for a write command), or the NVMe device 104 can write data retrieved from the NVMe device 104 to the buffer (e.g., in response to a read command).

[0030] In some examples, computing device 100 includes additional storage device 110. In some examples, additional storage device is a non-volatile storage device. Additional storage device 110 may be, for example, a persistent memory device. In some examples, additional storage device 110 may be any type of computer storage device. Examples of types of computer storage devices include, but are not limited to, hard drives, solid-state drives, flash memory devices, tape drives, removable disk drives, universal serial bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, and the like. Although Figure 1 The additional storage device 110 is shown as part of the computing device 100, but the additional storage device can be separate from the computing device 100 and operably connected to the computing device 100 (e.g., an external drive array, cloud storage, etc.). In some examples, the additional storage device 110 operates at a relatively slower data rate than the NVMe device 104. In some examples, the additional storage device 110 is also an NVMe storage device. In some examples, the additional storage device 110 is operably connected to the processor 102, the NVMe device 104, the embedded cryptographic engine 112, and / or the memory device 108. Although Figure 1Computing device 100 is shown with a single additional storage device 110 , but computing device 100 may have any number of additional storage devices without departing from the scope of the examples described herein.

[0031] In some examples, the computing device 100 includes a memory device 108. The memory device can be any type of computer memory. In some examples, the memory device 108 is a volatile memory device. As an example, the memory device 108 can be a random access memory (RAM). In one or more examples, data stored in the memory device 108 is located at a memory address and is therefore accessible by the processor 102 and / or the embedded cryptographic engine 112 using the memory address. Similarly, the processor 102 and / or the secure execution environment (or components therein) can use the memory address to write data to the memory device 108 and / or read data from the memory device 108. The memory device 108 can be used to store any type of data, such as computer programs, calculation results, etc. In some examples, the memory device 108 is operably connected to the processor 102, the NVMe device 104, the attached storage device 110, and the inline cryptographic engine 112. Although Figure 1 The computing device 100 is shown with a single memory device 108 , but the computing device 100 may have any number of memory devices without departing from the scope of the examples described herein.

[0032] In some examples, computing device 100 includes any number of security components (e.g., multiple embedded cryptographic engines 112). A security component can be any component capable of performing various cryptographic services, and thus can be any hardware (e.g., circuitry), software, firmware, or any combination thereof. In some examples, a security component is a sub-chip hardware component of a system on a chip (SoC), which can include Figure 1Other components shown, such as processor 102. Any other components of the computing device 100 may also be included as part of the SoC without departing from the scope of the examples described herein. In some examples, the security component exists in the data path between the storage device (e.g., NVMe storage device 104, additional storage device 110) and the memory device 108, and / or in the data path between the processor 102 and the memory device 108 or any storage device (e.g., 104, 110). In some examples, all or any portion of the security component can be considered to be an "embedded" cryptographic engine. In some examples, the security component is configured to perform any number of cryptographic service types on data read from or written to the storage device (e.g., NVMe device 104, additional storage device 110) and / or memory device 108 of the computing device 100. In some examples, all or any portion of data passed from memory to storage, from storage to memory, or to or from processor 102 of computing device 100 passes through a security component.

[0033] Examples of the types of cryptographic services that can be performed include, but are not limited to, encrypting data, decrypting data, key derivation, performing data integrity verification, and performing authenticated encryption and decryption. In some examples, the security component is configured to perform various types of cryptographic services by being configured to execute one or more cryptographic algorithms. As an example, in order to perform encryption and decryption, one or more security components can be configured to execute one or more of the Advanced Encryption Standard XOR-encryption-XOR Adjustable Block Ciphertext Stealing (AES-XTS) algorithm, the AES-Cipher Block Chaining (AES-CBC) algorithm, the AES-Electronic Codebook (AES-EBC) algorithm, the Encryption Salt Sector Initialization Vector AES-CBC (ESSIV-AES-CBC) algorithm, etc. (including any variants of such algorithms (e.g., 128 bits, 192 bits, 256 bits, etc.)). As another example, in order to perform integrity verification, the security component can be configured to execute a hash algorithm, such as, for example, one or more members of the SHA hash algorithm family. As another example, in order to perform authenticated encryption, the security component can be configured to execute the AES-Galois / Counter Mode (GCM) algorithm. The security component may be configured to perform any other encryption algorithm without departing from the scope of the examples described herein.

[0034] In some examples, the embedded cryptographic engine 112 is a hardware component (e.g., including circuitry) that can execute software and / or firmware and is configured to perform various operations or services to protect the computing device 100. For example, as described in more detail herein, the embedded cryptographic engine 112 can use embedded address tags to perform embedded encryption and / or decryption.

[0035] Although Figure 1 A particular number of components in a particular configuration is shown, but one of ordinary skill in the art will understand that the computing device 100 may include more or fewer components, and / or components arranged in any number of alternative configurations, without departing from the scope of the examples described herein. Figure 1 Although not shown, it will be understood by those skilled in the art that the computing device 100 can execute any number or type of software or firmware (e.g., boot loaders, operating systems, hypervisors, virtual machines, computer applications, mobile device applications, etc.). Therefore, the examples disclosed herein should not be limited to Figure 1 Configuration of components shown. Figure 1 The components shown may or may not be discrete components. In some aspects, one or more of the components may be combined into different hardware elements, implemented in software, and / or otherwise implemented using software and / or hardware. As used herein, the term device may be a discrete component or device, or may not be a discrete component. In some aspects, other devices may exist within the device, be part of the device, and / or utilize the same hardware components as the device.

[0036] In some cases, a processor (such as Figure 1 The processor 102 of the embodiment of the present invention can access the storage device (such as the processor 102) via the memory space (such as the SoC memory space or the processor memory space). Figure 1 NVMe device 104 or attached storage device 110). As an example, a processor may access a non-volatile memory express (NVMe) storage device (e.g., a portion of attached storage device 110) via a read or write command, and the read or write command may have associated SoC memory space available for (e.g., allocated for) data to be read / written. In some cases, the NVMe storage device may be a storage device accessible via an NVMe interface. The NVMe interface may operate over an interface such as PCIe interface 114. For example, NVMe may include protocol commands and structures that may be transmitted by PCIe. Thus, an NVMe storage device may be accessed using NVMe via PCIe interface 114.

[0037] In some cases, an NVMe device (such as NVMe device 104) operating through PCIe interface 114 can directly access host memory (e.g., SoC memory, processor I / O memory, etc.) space, such as space on memory device 108. The memory space can be logically organized into one or more groups of data segments. In some cases, a data segment can be a continuous portion of the SoC memory, and there can be one DST entry for each data segment. Data segments that can be continuous in the memory space can be stored in continuous data segments on the memory. In some cases, each data segment is a continuous non-overlapping portion of the SoC memory.

[0038] In some cases, to support embedded encryption / decryption, the embedded cryptographic engine 112 can use a DST 118 configured by software (e.g., a driver, a system process, etc.) that defines the location and size of each data segment, which data segments have encryption enabled, and metadata required for encryption / decryption operations. In some cases, the encryption-enabled data segments contain I / O data stored in consecutive sectors on the NVMe device 104.

[0039] In some cases, a storage device may be divided into sectors. In some cases, a sector may be specified by its logical block address (LBA). In some cases, the number and size of sectors of a storage device may be fixed. In some cases, the sector size and number may be statically configured, for example, by software, before encryption of the storage device is implemented.

[0040] In some cases, full disk encryption can be used to encrypt a storage device, such as a non-volatile, non-transitory computer-readable memory device, such as a hard drive, a flash drive, or other type of computer-readable medium that can store data accessible by a computer. Full disk encryption can refer to a storage device on which the data on the storage device is encrypted. In some cases, metadata (such as a master boot record) for accessing (e.g., reading / writing) the storage device can also be encrypted. In some cases, full disk encryption can be performed based on an encryption scheme such as Advanced Encryption Standard XOR Encryption XOR Adjustable Block Ciphertext Stealing (AES-XTS). AES-XTS is an adjustable encryption scheme that uses an AES encryption password and an adjustment value. In an adjustable encryption scheme, no two sectors should be treated the same way. The adjustment attempts to simulate a random permutation of the password. In some cases, the adjustment can be based on the sector address and the index of the block within the sector.

[0041] In some cases, AES-XTS uses a key and a non-secret adjustment value to perform encryption or decryption operations to read data from / write data to a storage device. The key and adjustment can be based on the LBA (or other storage device address) so that each encrypted sector has an associated key and a unique 128-bit adjustment that includes the LBA (or other storage device address). In some cases, the storage device can be accessed using an NVMe interface or other peripheral interface. In some cases, the peripheral interface may not directly provide a way to provide metadata for encryption / decryption operations for a storage device with full disk encryption. For example, the NVMe / PCIe protocol stack itself does not provide a way to specify an embedded address tag, where a portion of a PCIe address can be used as an embedded address tag to look up information used to encrypt / decrypt data on the storage device. In some cases, a PCIe address (e.g., a return address) can be an address used by a storage device (e.g., a storage device accessible via a PCIe bus) to access SoC memory (e.g., host memory). The SoC memory may be a memory space accessible to components of the SoC (eg, a processor) to which a storage device may write return information or data (eg, a return code or data requested by a storage read operation).

[0042] Figure 2 An example PCIe transaction layer packet format 200 configured to perform inline encryption / decryption using inline address tags in accordance with aspects of the present disclosure is shown. The example packet format 200 may use 64-bit addressing and include four double words (DW0 202, DW1 204, DW2 206, and DW3 208). In some cases, DW0 202 and DW1 204 may include a header, status, length, escrow information, completer information, and / or other PCIe configuration information for establishing a PCIe transaction. For clarity, details of the bit fields in DW0 202 and DW1 204 have been omitted. For conventional PCIe transactions, the packet format 200 may include a 64-bit return address in DW2 206 and DW3 208. In some cases, a reserved field (e.g., having a shorter return address) may also be included after the return address. The return address may identify a device, and an addressed PCIe device (e.g., a storage device) may return data or return information (e.g., a return code) to it. As an example, a PCIe device may have a return address space (e.g., a PCIe address) that the PCIe device may access (e.g., by performing an I / O operation) to return data or return information (e.g., a return code) from the storage device.

[0043] For embedded encryption / decryption with embedded address tags, to help allow embedded address tags to be provided without modifying existing protocols (e.g., PCIe / NVMe), a portion of the return address (e.g., in DW2 206) can be used for cryptographic operations. For example, the upper 16 bits of the PCIe address can be used as the embedded address tag 212. The embedded address tag 212 can be used as a reference to the DST (e.g., Figure 1 The information in the DST table (e.g., metadata) can provide sufficient information to determine the adjustments and keys used to encrypt / decrypt data for the storage device. Encryption / decryption of the data using the adjustments and keys can then be performed in memory in a manner similar to current full disk encryption technology. In some cases, the DST can be stored in memory (e.g., an in-memory table), such as the memory device 108. The remaining lower 48-bit portion of the I / O address space, the PCIe host memory address (e.g., SoC address) space 214 can be used for PCIe access to the storage device (e.g., NVMe protocol structure, address information data for a given external drive and its associated PCIe interface, etc.). The PCIe address format can be as follows: pcie_addr[63:48] = dst_index[15:0]

[0044] pcie_addr[47:0]=soc_addr[47:0]

[0045] In some cases, a different embedded address tag 212 for NVMe PCIe access may be used for each NVMe embedded cryptographic engine instance (e.g., using Figure 1 In some cases, when drive encryption is enabled, the software may allocate and configure an entry in the DST for each NVMe storage command (e.g., read / write command) data segment before submitting the command to the command queue (e.g., for execution). Each entry in the DST may be 16 bytes long. In some cases, there may be two DST entry formats, one for enabling encrypted segments and a second for disabling already encrypted segments. For entries in the DST that allow encryption, the following fields may be included:

[0046] base_addr[47:2] = base address in SoC memory reserved[1:0] = reserved

[0047] base_lba[47:0] = Base LBA

[0048] num_sector[15:0] = number of sectors

[0049] key_index[7:0]=key_index(key 0-255)

[0050] encrypt_mode[0] = encryption mode (AES-XTS-128, AES-XTS-256)

[0051] reserved[4:0]=Reserved

[0052] encrypt_en[0]=1

[0053] valid[0] = Entry is valid

[0054] For entries in DST where encryption is disabled, the following fields may be included:

[0055] base_addr[47:2] = base address in SoC memory reserved[1:0] = reserved

[0056] length[47:0] = length in bytes

[0057] reserved[29:0]=Reserved

[0058] encrypt_en[0]=0

[0059] valid[0] = Entry is valid

[0060] In some cases, the embedded address tag 212 for NVMe PCIe access can be statically configured by software for each interface (e.g., each drive interface). The lower 48 bits of PCIe host memory address (e.g., SoC address) space 214 do not have to be used exclusively by a drive or for NVMe data. Therefore, the lower 48 bits of the PCIe host memory address space 214 (e.g., return address) can be used as an SoC memory address (e.g., a host memory address of a component (e.g., a processor) that can access the SoC, where the storage device can write return data and information), and the upper 16 bits can be used as the embedded address tag 212 for accessing the DST.

[0061] In some cases, when drive encryption is enabled, PCIe transactions associated with NVMe storage command data segments of a storage device may be processed according to the DST entry selected by the embedded address tag 212. In some cases, when drive encryption is enabled, software allocates and configures entries in the DST for data segments associated with the NVMe interface. In some examples, the SoC memory accessed by the NVMe device may fall within the data segments listed in the DST. In some cases, the embedded cryptographic engine may validate transactions against selected entries in the DST. In some cases, validating storage commands (e.g., via Figure 1 The embedded cryptographic engine 112 of the embodiment of the present invention is configured such that the associated I / O transfer falls within the segment address range selected based on the base_addr and length fields. Appropriate errors can be generated for transfers that fall outside the selected data segment, and the transaction is handled in the same manner as other access control violations. In some cases, drive reads of encryption-enabled data segments are encrypted on the fly. Similarly, drive writes are decrypted on the fly. It is worth noting that while the upper 16 bits of the PCIe address are used for the tag in this example, other implementations may use any number of bits of the PCIe address for the tag.

[0062] return Figure 1 In some cases, the DST 118 is stored in memory and can have up to 64,000 entries (and in some cases more). The RAM that can support a 64,000 entry table can be 1 megabyte (MB). In some examples, a smaller table may be sufficient. The hardware can be configured for a smaller local RAM. In some aspects, the keys (e.g., indexes) of the data (e.g., all data) associated with read and write commands can (and in some cases must) be preloaded into the embedded cryptographic engine by software before the commands are issued. In some cases, the DST 118 can be managed (e.g., adding and / or removing entries in the DST 118) by software executed, for example, on a processor such as the processor 102 or as part of the embedded cryptographic engine 112. In other cases, the DST 118 can be managed by hardware, for example, in the embedded cryptographic engine 112.

[0063] In some cases, the embedded cryptographic engine 112 may include a small, fully associative cache that stores recently accessed DST entries. The cache may include the ability for software to invalidate entries when they are deallocated in the DST 118. In some cases, the DST 118 may be stored in memory (e.g., memory device 108) on the processor and / or SOC, such as a cache. In some cases, the DST 118 may be stored in RAM (such as system memory) separate from the processor and / or SOC.

[0064] As an example, a storage write for storing data in a full disk encrypted NVMe device 104 may be performed by the processor 102. The processor 102 may write the data, along with the appropriate command and header for the storage write, to an appropriate mapped memory location in, for example, the memory device 108 for the storage write. In some cases, the appropriate mapped memory location may be a location accessible by the embedded cryptographic engine 112. The processor 102 may also write an LBA address (e.g., an address of a storage device or other storage device address) to an appropriate mapped memory location that indicates where on the NVMe device 104 the data should be written. The processor 102 may also write a return address (e.g., a PCIe address) for the NVMe device 104 to an appropriate mapped memory location, for example, for use in a return code. As described above with respect to Figure 2 As described, the return address may include a 48-bit portion that includes the host memory address (e.g., the SoC address) and a 16-bit (e.g., upper 16 bits) embedded address tag (e.g., as described above with respect to Figure 2 In some cases, the lower 48 bits may be sufficient for the return SoC address, and the information to be returned may be written based on the 48-bit return address.

[0065] The processor 102 may also write metadata for handling PCIe transactions for storage writes to a portion (e.g., a row) of the DST 118 (or to the embedded cryptographic engine 112 to write to the DST 118). By way of example, the metadata may include information for encrypting / decrypting data (e.g., to determine adjustments and keys), as well as addresses where the data may be accessed / written (e.g., start / end addresses, size), command submission queue identifiers, sector information, etc. In some cases, the embedded cryptographic engine 112 may return an index (e.g., a pointer) indicating which portion (e.g., row) of the DST 118 the metadata is stored in. The index may be included in an embedded address tag. In some cases, multiple segments (e.g., of the DST 118) may be referenced by embedded address tags or by metadata stored in the DST 118.

[0066] For example, the embedded cryptographic engine 112 may use the embedded address tag and the LBA address to encrypt / decrypt data transferred to / from the NVMe device 104. For example, the embedded address tag may include an index (e.g., a pointer) indicating a portion (e.g., a row) of a DST 118 (e.g., a table, array, linked list, graph, etc.) in the embedded cryptographic engine 112 that includes metadata for processing PCIe transactions.

[0067] The processor 102 may indicate to the NVMe device 104 (e.g., via a doorbell signal such as an interrupt) that there is data for the NVMe device 104. The NVMe device 104 may then, based on the indication, access the appropriate mapped memory location in the memory device 108 to obtain the LBA address, data, return address, and appropriate command and header. As part of sending the information from the mapped memory location to the NVMe device 104, the embedded cryptographic engine 112 may encode the data based on the LBA address and tag. The NVMe device 104 may then write the encoded data to the LBA address and send an appropriate return code to the return address. In some cases, the NVMe device 104 does not process the tag of the return address and may simply ignore the tag. In some cases, the processor 102 may, for example, remove the entry in the DST 118 after receiving the appropriate return code.

[0068] In some cases, a storage read may be performed in a manner similar to a storage write. For example, processor 102 may write the appropriate command and header for a storage read, along with LBA information and a return address for the requested data. Figure 2 As discussed in

[15] , the upper 16 bits of the return address may also include an ICE tag, and the lower 48 bits may include a return SoC address (e.g., or other memory location) for a memory read of a mapped memory location in the memory device 108. The processor 102 may also write metadata for processing a PCIe transaction for a memory read to a portion (e.g., a row) of the DST 118 (or to the embedded cryptographic engine 112 to write to the DST 118). The NVMe device 104 may then access the mapped memory location in the memory device 108 based on the indication to obtain the LBA address, the return address, and the appropriate command and header. The NVMe device 104 may access the LBA address to obtain the requested data and send the requested data to be stored at the return address along with the LBA address information and the return address information. The embedded cryptographic engine 112 may decode the requested data based on the LBA address and the embedded address tag in the return address. For example, the embedded cryptographic engine 112 may access the embedded address tag to obtain an index into the DST 118 to retrieve metadata about the PCIe transaction. The metadata and LBA address may be used to decode the requested data.The decoded information may be stored based on the return address (eg, in the lower 48 bits).

[0069] Figure 33 is a flow chart illustrating operations 300 for image processing according to aspects of the present disclosure. Process 300 can be performed by a computing device (or apparatus) or a component of a computing device (e.g., a chipset, a codec, etc.). The computing device can be a mobile device (e.g., a mobile phone), a network-connected wearable device (such as a watch), an extended reality (XR) device (such as a virtual reality (VR) device or an augmented reality (AR) device), a vehicle or a component or system of a vehicle, or other types of computing devices. Process 300 can be implemented as a software component that executes and runs on one or more processors.

[0070] At block 302, a computing device (or a component thereof) may determine a storage device address of a storage device. In some cases, the storage device address includes a logical block address (LBA), and the memory table includes LBA information for the storage device. The computing device (or a component thereof) may generate an adjustment for data encryption based on the LBA information.

[0071] At block 304, the computing device (or a component thereof) may determine a tag for obtaining encrypted metadata for the data on the storage device. In some cases, the encryption of the data includes encrypting or decrypting the data. In some cases, the tag comprises 16 bits. In some cases, the storage device is encrypted using full disk encryption. In some cases, the storage device is encrypted using Advanced Encryption Standard XOR Encryption with Adjustable Block Ciphertext Stealing (AES-XTS).

[0072] At block 306, the computing device (or a component thereof) may generate a return address. In some cases, the return address includes a host memory address and a tag. In some cases, the tag includes an index to a memory table of keys used for data encryption (e.g., a key). In some cases, the storage device includes a Peripheral Component Interconnect Express (PCIe) bus device. In some cases, the return address includes a PCIe address. In some cases, the tag is included in the upper 16 bits of the PCIe address. In some cases, the storage device is accessed via the PCIe bus using a Non-Volatile Memory Express (NVMe) interface.

[0073] The computing device (or a component thereof) may access the storage device based on the return address and the storage device address at block 308. The computing device (or a component thereof) may access the storage device by storing at least the return address and the storage device address in a memory location accessible to the storage device to read from or write to the storage device.

[0074] In some examples, the techniques or processes described herein can be performed by a computing device, apparatus, and / or any other computing device. In some cases, the computing device or apparatus may include a processor, microprocessor, microcomputer, or other component of a device configured to perform the steps of the processes described herein. In some examples, the computing device or apparatus may include a camera configured to capture video data (e.g., a video sequence) comprising video frames. For example, the computing device may include a camera device, which may or may not include a video codec. As another example, the computing device may include a mobile device with a camera (e.g., a camera device such as a digital camera, an IP camera, a mobile phone or tablet computer including a camera, or other type of device with a camera). In some cases, the computing device may include a display for displaying images. In some examples, the camera or other capture device that captures video data is separate from the computing device, in which case the computing device receives the captured video data. The computing device may further include a network interface, a transceiver, and / or a transmitter configured to transmit video data. The network interface, transceiver, and / or transmitter may be configured to transmit data based on the Internet Protocol (IP) or other network data.

[0075] The processes described herein can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, an operation represents computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform specific functions or implement specific data types. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations can be combined in any order and / or in parallel to implement the described processes.

[0076] In some cases, a device or apparatus configured to perform the operations of process 300 and / or other processes described herein may include a processor, a microprocessor, a microcomputer, or other components of a device configured to perform the steps of process 300 and / or other processes. In some instances, such a device or apparatus may include one or more sensors configured to capture image data and / or other sensor measurements. In some examples, such a computing device or apparatus may include one or more sensors and / or cameras configured to capture one or more images or videos. In some cases, such a device or apparatus may include a display for displaying images. In some examples, one or more sensors and / or cameras are separated from the device or apparatus, in which case the device or apparatus receives the sensed data. Such a device or apparatus may further include a network interface configured to transmit data.

[0077] Components of devices or apparatuses configured to perform one or more operations of process 300 and / or other processes described herein may be implemented in circuits. For example, the components may include electronic circuits or other electronic hardware, and / or may be implemented using electronic circuits or other electronic hardware, which may include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and / or other suitable electronic circuits), and / or the components may include computer software, firmware, or a combination thereof for performing the various operations described herein and / or may be implemented using computer software, firmware, or a combination thereof for performing the various operations described herein. The computing device may also include a display (as an example of an output device or in addition to an output device), a network interface configured to communicate and / or receive data, any combination thereof, and / or other components. The network interface may be configured to transmit and / or receive data based on an Internet Protocol (IP) or other types of data.

[0078] Process 300 is illustrated as a logical flow diagram, the operations of which represent a sequence of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, an operation represents computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform specific functions or implement specific data types. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations can be combined in any order and / or in parallel to implement the process.

[0079] In addition, the processes described herein (e.g., process 300 and / or other processes) can be performed under the control of one or more computer systems configured with executable instructions, and can be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that executes together on one or more processors, implemented by hardware, or a combination thereof. As noted above, the code can be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions that can be executed by one or more processors. The computer-readable or machine-readable storage medium can be non-transitory.

[0080] In addition, the processes described herein can be performed under the control of one or more computer systems configured with executable instructions and can be implemented in hardware as code (e.g., executable instructions, one or more computer programs, or one or more applications) that is executed together on one or more processors, or a combination thereof. As noted above, the code can be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising multiple instructions that can be executed by one or more processors. The computer-readable or machine-readable storage medium can be non-transitory.

[0081] Figure 4 is a schematic diagram illustrating an example of a system for implementing certain aspects of the present technology. Specifically, Figure 4 An example of a computing system 400 is shown, which can be any computing device, for example, constituting an internal computing system, a remote computing system, a camera, or any component thereof, wherein the components of the system communicate with each other using a connection 405. Connection 405 can be a physical connection using a bus or a direct connection within processor 410 (e.g., in a chipset architecture). Connection 405 can also be a virtual connection, a networked connection, or a logical connection.

[0082] In some examples, computing system 400 is a distributed system in which the functionality described in this disclosure can be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some examples, one or more of the described system components represent a number of such components that each perform some or all of the functionality described for that component. In some examples, a component can be a physical device or a virtual device.

[0083] The example system 400 includes at least one processing unit (CPU or processor) 410 and connections 405 that couple various system components including system memory 415, such as read-only memory (ROM) 420 and random access memory (RAM) 425, to the processor 410. The computing system 400 may include a cache 412 of high-speed memory that is directly connected to the processor 410, close to the processor 1510, or integrated as part of the processor 1510.

[0084] Processor 410 may include any general-purpose processor and hardware or software services, such as services 432, 434, and 436 stored in storage device 430, configured to control processor 410, as well as specialized processors in which software instructions are incorporated into the actual processor design. Processor 410 may essentially be a completely self-contained computing system, including multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.

[0085] To enable user interaction, the computing system 400 includes an input device 445, which can represent any number of input mechanisms or sensors, such as a microphone for voice (e.g., user speaking), a touch-sensitive screen for gesture or graphical input (e.g., user performing sign language symbols, user shaking the phone, etc.), a keyboard (e.g., user pressing keys), a mouse, motion input, determining that the user is at a location indicated by a positioning system or modem subsystem, etc., which can be used to activate the counters described in the previous section and enable / disable the asset transfer chain at any stage described previously. The computing system 400 can also include an output device 435, which can be one or more of a variety of output mechanisms. In some instances, a multimodal system can enable a user to provide multiple types of input / output to communicate with the computing system 400. The computing system 400 can include a communication interface 440, which can generally control and manage user input and system output. The communication interface can use wired and / or wireless transceivers to perform or facilitate the reception and / or transmission of wired or wireless communications, including the use of audio jacks / plugs, microphone jacks / plugs, universal serial bus (USB) ports / plugs, Ports / plugs, Ethernet ports / plugs, fiber optic ports / plugs, proprietary wired ports / plugs, Wireless signal transmission, Low energy (BLE) wireless signal transmission, The communication interface 440 may also include one or more global navigation satellite system (GNSS) receivers or transceivers for determining the location of the computing system 400 based on one or more signals received from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the United States-based Global Positioning System (GPS), the Russian-based Global Navigation Satellite System (GLONASS), the Chinese-based BeiDou Navigation Satellite System (BDS), and the European-based Galileo GNSS. There is no restriction on operation with any particular hardware arrangement, so the basic features herein may be readily replaced with improved hardware or firmware arrangements as they are developed.

[0086] The storage device 430 may be a non-volatile and / or non-transitory and / or computer-readable memory device, and may be a hard disk, or other type of computer-readable medium that can store data accessible by a computer, such as a magnetic cassette, a flash memory card, a solid-state storage device, a digital versatile disk, a magnetic cassette, a floppy disk, a floppy disk, a hard disk, a magnetic tape, a magnetic stripe / strip, any other magnetic storage medium, flash memory, memristor memory, any other solid-state memory, a compact disc read-only memory (CD-ROM) disc, a rewritable compact disc (CD) disc, a digital video disc (DVD) disc, a Blu-ray disc (BDD) disc, a holographic disc, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, The memory device 430 may include a card, a smart card chip, an EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, a random access memory (RAM), a static RAM (SRAM), a dynamic RAM (DRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash EPROM (FLASH EPROM), a cache memory (L1 / L2 / L3 / L4 / L5 / L#), a resistive random access memory (RRAM / ReRAM), a phase change memory (PCM), a spin-transfer torque RAM (STT-RAM), another memory chip or cartridge, and / or a combination thereof. The memory device 430 may include software instructions or code that can be executed by the processor 410 to enable the system 400 to perform functions.

[0087] As used herein, the term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying (a plurality of) instructions and / or data. Computer-readable media may include non-transitory media that can store data, but does not include carrier waves and / or temporary electronic signals transmitted wirelessly or via a wired connection. Examples of non-transitory media may include, but are not limited to, disks or tapes, optical storage media (e.g., compact discs (CDs) or digital versatile discs (DVDs)), flash memory, memory, or storage devices. Computer-readable media may store code and / or machine-executable instructions that may represent any combination of procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. A code segment may be coupled to another code segment or hardware circuit by passing and / or receiving information, data, independent variables, parameters, or memory contents. Information, independent variables, parameters, data, etc. may be passed, forwarded, or sent using any suitable means including memory sharing, message passing, token passing, network transmission, etc.

[0088] In some examples, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and signals themselves.

[0089] Specific details are provided in the above description to provide a thorough understanding of the examples provided herein. However, it will be understood by those skilled in the art that examples can be implemented without these specific details. For clarity of explanation, in some cases, the technology herein can be presented as a separate functional block comprising the following functional blocks, which include devices, device components, operations in the method embodied in software or hardware, steps or routines, or a combination of hardware and software. Additional components other than those shown in the accompanying drawings and / or described herein can be used. For example, circuits, systems, networks, processes, and other components can be shown as components in block diagram form, so as not to obscure examples in unnecessary details. In other cases, known circuits, processes, algorithms, structures, and techniques may be shown as not having unnecessary details, so as to avoid blurring these examples.

[0090] The various examples above may be described as processes or methods, which may be depicted as flow charts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. Although a flow chart is used to describe the operations as a sequential process, many operations may be performed in parallel or simultaneously. Additionally, the order of these operations may be rearranged. When these operations are completed, the process terminates, but it may have other operations not included in the accompanying drawings. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, its termination may correspond to the function returning to the calling function or main function.

[0091] The process and method according to the above examples can be implemented using computer-executable instructions stored in a computer-readable medium or otherwise obtainable from a computer-readable medium. For example, such instructions can include instructions and data that cause or configure a general-purpose computer, a special-purpose computer, or a processing device to perform a specific function or function group. The computer resource portion used can be accessed through a network. Computer-executable instructions can be, for example, binary files, intermediate format instructions (such as assembly language, firmware, source code, etc.). Examples of computer-readable media that can be used for storing instructions, information used, and / or information created during the method according to the described examples include disks or optical disks, flash memory, USB devices with non-volatile memory, networked storage devices, etc.

[0092] The equipment implementing the process and method according to these disclosures can include hardware, software, firmware, middleware, microcode, hardware description language or any combination thereof, and can adopt any of a variety of form factors.When implemented in software, firmware, middleware or microcode, the program code or code segment (e.g., computer program product) for performing the necessary tasks can be stored in a computer-readable or machine-readable medium. One (or more) processors can perform the necessary tasks. Typical examples of form factors include personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc. of laptop computers, smart phones, mobile phones, tablet devices or other small form factors. The functions described herein can also be embodied in peripheral devices or add-on cards. By further example, such functions can also be implemented on a circuit board between different chips or different processes performed in a single device.

[0093] The instructions, the media for transmitting such instructions, the computing resources for executing them, and other structures for supporting such computing resources are exemplary means for providing the functionality described in this disclosure.

[0094] In the foregoing description, various aspects of the present application have been described with reference to specific examples of the present application, but it will be appreciated by those skilled in the art that the present application is not limited thereto. Therefore, although the illustrative examples of the present application have been described in detail herein, it should be understood that these inventive concepts may be embodied and adopted differently in other ways, and the appended claims are intended to be interpreted as including such variations, except as limited by the prior art. The various features and aspects of the above-mentioned applications may be used individually or in combination. Further, without departing from the broader spirit and scope of this specification, the examples described herein may be utilized in any number of environments and applications other than those described herein. Therefore, the description and drawings should be considered to be illustrative rather than restrictive. For illustration purposes, the method is described in a particular order. It should be understood that, in alternative examples, the method may be performed in an order different from the order described.

[0095] A person of ordinary skill in the art will understand that the less than ("<") and greater than (">") symbols or terms used herein may be replaced by less than or equal to ("≤") and greater than or equal to ("≥") symbols, respectively, without departing from the scope of this specification.

[0096] Where a component is described as being “configured to” perform certain operations, such configuration may be achieved, for example, by designing electronic circuits or other hardware to perform the operations, by programming programmable electronic circuits (e.g., a microprocessor or other suitable electronic circuits) to perform the operations, or any combination thereof.

[0097] The phrase "coupled to" refers to any component that is directly or indirectly physically connected to another component and / or any component that is directly or indirectly in communication with another component (e.g., connected to another component through a wired or wireless connection and / or other appropriate communication interface).

[0098] Claim language or other language that refers to “at least one of” a set and / or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfies the claim. For example, claim language that recites “at least one of A and B” or “at least one of A or B” means A, B, or A and B. In another example, claim language that recites “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any repeating information or data (e.g., A and A, B and B, C and C, A and A and B, etc.), or any other ordering, repetition, or combination of A, B, and C. The language “at least one of” a set and / or “one or more” of a set does not limit the set to the items listed in the set. For example, claim language that recites “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B. The phrases "at least one" and "one or more" are used interchangeably herein.

[0099] Claim language or other language that recites "at least one processor is configured to," "at least one processor is configured to," "one or more processors are configured to," "one or more processors are configured to," etc., indicates that one processor or multiple processors (in any combination) can perform the associated operations. For example, claim language reciting "at least one processor is configured to: X, Y, and Z" means that a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each responsible for some subset of operations X, Y, and Z, such that the multiple processors together perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z. In another example, claim language reciting "at least one processor is configured to: X, Y, and Z" can mean that any single processor can only perform at least a subset of operations X, Y, and Z.

[0100] Where reference is made to one or more elements that perform a function (e.g., steps of a method), one element may perform all of the functions, or more than one element may collectively perform the functions. When more than one element collectively performs a function, each function need not be performed by each of those elements (e.g., different functions may be performed by different elements) and / or each function need not be performed by only one element as a whole (e.g., different elements may perform different sub-functions of a function). Similarly, where reference is made to one or more elements that are configured to cause another element (e.g., a device) to perform a function, one element may be configured to cause the other element to perform all of the functions, or more than one element may be collectively configured to cause the other element to perform a function.

[0101] In the case of an entity (e.g., any entity or device described herein) that performs a function or is configured to perform a function (e.g., a step of a method), the entity may be configured to cause one or more elements to perform a function (individually or collectively). The one or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) functions of the function, and / or any combination thereof. In the case of referring to an entity performing a function, the entity may be configured to cause one component to perform all functions, or to cause more than one component to perform a function together. When an entity is configured to cause more than one component to perform a function together, each function does not need to be performed by each of those components (e.g., different functions can be performed by different components) and / or each function does not need to be performed by only one component as a whole (e.g., different components can perform different sub-functions of a function).

[0102] The various illustrative logic blocks, modules, circuits, and algorithmic operations described in conjunction with the examples disclosed herein can be implemented as electronic hardware, computer software, firmware, or a combination thereof. In order to clearly illustrate this interchangeability of hardware and software, the above has been generally described around the functionality of various illustrative components, blocks, modules, circuits, and operations. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. Technicians can implement the described functions in different ways for each specific application, but such implementation decisions should not be interpreted as resulting in a departure from the scope of this application.

[0103] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as general-purpose computers, wireless communication devices, handheld devices, or integrated circuit devices with multiple uses, including applications in wireless communication devices, handheld devices, and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be implemented at least in part by a computer-readable data storage medium comprising program code that, when executed, includes instructions for performing one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) (e.g., synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media, and the like. Additionally or alternatively, the techniques may be implemented at least in part by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures, such as a propagated signal or wave, and that can be accessed, read, and / or executed by a computer.

[0104] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated logic circuits or discrete logic circuits. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; however, in an alternative embodiment, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration. Therefore, the term "processor" as used herein may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or device suitable for implementing the techniques described herein.

[0105] Illustrative aspects of the disclosure include:

[0106] Aspect 1. A method for data access, comprising: determining a storage device address for a storage device; determining a tag for obtaining encrypted metadata for data used in the storage device; generating a return address, the return address comprising a host memory address and the tag; and accessing the storage device based on the return address and the storage device address.

[0107] Aspect 2. The method according to aspect 1, wherein the encryption of the data comprises encrypting or decrypting the data.

[0108] Aspect 3. A method according to any one of Aspects 1 or 2, wherein accessing the storage device includes storing at least the return address and the storage device address to a memory location accessible to the storage device for reading from or writing to the storage device.

[0109] Aspect 4. The method according to any one of aspects 1-3, wherein the tag comprises an index to a memory table.

[0110] Aspect 5. The method according to aspect 4, wherein the memory table includes a key for data encryption.

[0111] Aspect 6. A method according to any one of Aspects 4 or 5, wherein the storage device address includes a logical block address (LBA), and wherein the memory table includes LBA information of the storage device.

[0112] Aspect 7. The method according to aspect 6 further includes generating adjustments for data encryption based on the LBA information.

[0113] Aspect 8. The method of any one of aspects 1-7, wherein the storage device comprises a Peripheral Component Interconnect Express (PCIe) bus device, and wherein the return address comprises a PCIe address.

[0114] Aspect 9. The method according to aspect 8, wherein the tag comprises 16 bits.

[0115] Aspect 10. The method of aspect 9, wherein the tag is included in the upper 16 bits of the PCIe address.

[0116] Aspect 11. A method according to any one of Aspects 8-10, wherein the storage device is accessed using a non-volatile memory express (NVMe) interface through a PCIe bus.

[0117] Aspect 12. The method according to any one of aspects 1-11, wherein the storage device is encrypted using full disk encryption.

[0118] Aspect 13. The method according to any one of aspects 1-12, wherein the storage device is encrypted using Advanced Encryption Standard XOR Encryption XOR Adjustable Block Ciphertext Stealing (AES-XTS).

[0119] Aspect 14. An apparatus for data access, the apparatus comprising: at least one memory; a storage device; and at least one processor coupled to the at least one memory, the at least one processor being configured to: determine a storage device address for the storage device; determine a tag for obtaining encrypted metadata for data of the storage device; generate a return address, the return address comprising a host memory address and the tag; and access the storage device based on the return address and the storage device address.

[0120] Aspect 15. The apparatus according to aspect 14, wherein the encryption of the data comprises encrypting or decrypting the data.

[0121] Aspect 16. An apparatus according to any one of Aspects 14 or 15, wherein, in order to access the storage device, the at least one processor is configured to store at least the return address and the storage device address to a memory location accessible to the storage device for reading from or writing to the storage device.

[0122] Aspect 17. The apparatus according to any one of aspects 14-16, wherein the tag comprises an index to a memory table.

[0123] Aspect 18. The apparatus of aspect 17, wherein the memory table includes a key for data encryption.

[0124] Aspect 19. An apparatus according to any one of aspects 17 or 18, wherein the storage device address comprises a logical block address (LBA), and wherein the memory table comprises LBA information for the storage device.

[0125] Aspect 20. The apparatus of aspect 19, wherein the at least one processor is further configured to generate adjustments for data encryption based on the LBA information.

[0126] Aspect 21. The apparatus of any one of aspects 14 to 20, wherein the storage device comprises a Peripheral Component Interconnect Express (PCIe) bus device, and wherein the return address comprises a PCIe address.

[0127] Aspect 22. The apparatus according to aspect 21, wherein the tag comprises 16 bits.

[0128] Aspect 23. The apparatus of aspect 22, wherein the tag is included in the upper 16 bits of the PCIe address.

[0129] Aspect 24. An apparatus according to any one of Aspects 21-23, wherein the storage device is accessed using a non-volatile memory express (NVMe) interface through a PCIe bus.

[0130] Aspect 25. The apparatus of any one of aspects 14 to 24, wherein the storage device is encrypted using full disk encryption.

[0131] Aspect 26. The apparatus of any one of aspects 14 to 25, wherein the storage device is encrypted using Advanced Encryption Standard XOR Encryption XOR Adjustable Block Ciphertext Stealing (AES-XTS).

[0132] Aspect 27. A non-transitory computer-readable medium having instructions stored thereon, which, when executed by at least one processor, causes the at least one processor to perform the following operations: determine a storage device address for a storage device; determine a tag for obtaining encrypted metadata for data of the storage device; generate a return address, the return address comprising a host memory address and the tag; and access the storage device based on the return address and the storage device address.

[0133] Aspect 28. The non-transitory computer-readable medium of aspect 27, wherein the encryption of the data comprises encrypting or decrypting the data.

[0134] Aspect 29. A non-transitory computer-readable medium according to any one of Aspects 27 or 28, wherein, in order to access the storage device, the instructions further cause the at least one processor to store at least the return address and the storage device address to a memory location accessible to the storage device for reading from or writing to the storage device.

[0135] Aspect 30. The non-transitory computer-readable medium of any one of aspects 27-29, wherein the tag comprises an index to a memory table.

[0136] Aspect 31. The non-transitory computer-readable medium of aspect 30, wherein the memory table includes a key for data encryption.

[0137] Aspect 32. A non-transitory computer-readable medium according to any one of Aspects 30 or 31, wherein the storage device address comprises a logical block address (LBA), and wherein the memory table comprises LBA information for the storage device.

[0138] Aspect 33. The non-transitory computer-readable medium of aspect 32, wherein the instructions further cause the at least one processor to generate an adjustment for data encryption based on the LBA information.

[0139] Aspect 34. The non-transitory computer-readable medium of any one of aspects 27-33, wherein the storage device comprises a Peripheral Component Interconnect Express (PCIe) bus device, and wherein the return address comprises a PCIe address.

[0140] Aspect 35. The non-transitory computer-readable medium of aspect 34, wherein the tag comprises 16 bits.

[0141] Aspect 36. The non-transitory computer-readable medium of aspect 35, wherein the tag is included in the upper 16 bits of the PCIe address.

[0142] Aspect 37. The non-transitory computer-readable medium of any one of aspects 34-36, wherein the storage device is accessed using a non-volatile memory express (NVMe) interface via a PCIe bus.

[0143] Aspect 38. The non-transitory computer-readable medium of any one of aspects 27-37, wherein the storage device is encrypted using full disk encryption.

[0144] Aspect 39. The non-transitory computer-readable medium of any one of aspects 27-38, wherein the storage device is encrypted using Advanced Encryption Standard XOR Encryption XOR Adjustable Block Ciphertext Stealing (AES-XTS).

[0145] Aspect 40. An apparatus for data access, comprising means for performing one or more of the operations according to any one of aspects 1 to 13.

Claims

1. A device for data access, comprising: at least one memory; Storage devices; as well as at least one processor coupled to the at least one memory, the at least one processor configured to: determining a storage device address for the storage device; determining a tag for obtaining encrypted metadata for data on the storage device; generating a return address, the return address including a host memory address and the tag; as well as The storage device is accessed based on the return address and the storage device address.

2. The device according to claim 1, wherein The encryption of the data includes encrypting or decrypting the data.

3. The device according to claim 1, wherein To access the storage device, the at least one processor is configured to store at least the return address and the storage device address to a memory location accessible to the storage device for reading from or writing to the storage device.

4. The device according to claim 1, wherein The tag comprises an index to a memory table.

5. The device according to claim 4, wherein The memory table includes a key used for encryption of the data.

6. The device according to claim 4, wherein The storage device address comprises a logical block address (LBA), and wherein the memory table comprises LBA information for the storage device.

7. The device according to claim 6, wherein The at least one processor is further configured to generate an adjustment to encryption of the data based on the LBA information.

8. The device according to claim 4, wherein The storage device comprises a Peripheral Component Interconnect Express (PCIe) bus device, and wherein the return address comprises a PCIe address.

9. The device according to claim 8, wherein The tag consists of 16 bits.

10. The device according to claim 9, wherein The tag is included in the upper 16 bits of the PCIe address.

11. The device according to claim 8, wherein The storage device is accessed using a Non-Volatile Memory Express (NVMe) interface over the PCIe bus.

12. The device according to claim 1, wherein The storage device is encrypted using full disk encryption.

13. The device according to claim 1, wherein The storage device is encrypted using Advanced Encryption Standard XOR Encryption XOR Adjustable Block Ciphertext Stealing (AES-XTS).

14. A method for data access, comprising: determining a storage device address for the storage device; determining a tag for obtaining encrypted metadata for data on the storage device; generating a return address, the return address including a host memory address and the tag; as well as The storage device is accessed based on the return address and the storage device address.

15. The method according to claim 14, wherein The encryption of the data includes encrypting or decrypting the data.

16. The method according to claim 14, wherein Accessing the storage device includes storing at least the return address and the storage device address to a memory location accessible to the storage device for reading from or writing to the storage device.

17. The method according to claim 14, wherein: The tag comprises an index to a memory table.

18. The method according to claim 17, wherein The memory table includes a key used for encryption of the data.

19. The method according to claim 17, wherein The storage device address comprises a logical block address (LBA), and wherein the memory table comprises LBA information for the storage device.

20. The method of claim 19, further comprising generating an adjustment for encryption of the data based on the LBA information.