Cryptosystem Memory Management
By using password-safe MAC or HMAC technology and logical operations in the memory, the problem of difficulty in effectively detecting and correcting errors in the memory in the prior art is solved, and high performance protection and cost reduction of memory data are achieved.
Patent Information
- Application Number
- CN201811209775.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-11-17
- Filing Date
- 2018-10-17
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2038-10-17
AI Technical Summary
The prior art is difficult to effectively detect and correct errors in the memory when managing encrypted data stored in the memory, and the ECC memory technology does not have password security, which increases system costs.
Password-safe message authentication code (MAC) or HMAC technology is used to replace the ECC detection mechanism through statistical tests and error methods, and logical operations such as XOR operations are used to identify and correct errors in the memory, and data decryption is carried out when necessary.
High performance protection of memory data is achieved, random bit errors, integrated circuit failures, and malicious opponent attacks are detected and corrected, and memory costs are reduced.
Smart Images

Figure CN109800103B_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application is a partial continuation of U.S. Patent Application No. 14 / 998,054, titled "Memory Integrity with Error Detection and Correction," filed on December 24, 2015, the content of which is incorporated by reference as if fully set forth herein. Technical Field
[0003] The present disclosure generally relates to managing data stored in a memory, and more particularly but not exclusively, to managing encrypted data stored in a memory. Background Art
[0004] A computing device can store data in a hierarchical manner, where data is transferred between a larger storage device and a smaller cache memory device. In some examples, data can be stored in an encrypted format in the storage device and in an unencrypted format in a smaller on - chip cache device. In some examples, error - correcting code (ECC) memory technology can be used to detect errors in data stored in a memory device. ECC memory technology can be deterministic and reversible, but not cryptographic. Brief Description of the Drawings
[0005] The following detailed description can be better understood by reference to the accompanying drawings, which include specific examples of many features of the disclosed subject matter.
[0006] Figure 1 A block diagram of a computing device that can manage encrypted data is shown;
[0007] Figure 2 A block diagram of a dual in - line memory module is shown;
[0008] Figure 3 A process flow diagram for managing encrypted data is shown;
[0009] Figure 4 A process flow diagram for managing encrypted data is shown;
[0010] Figure 5A And Figure 5B An example of a data structure for storing encrypted data is shown;
[0011] Figure 6 is a process flow diagram for managing encrypted data based on the level of entropy of the data;
[0012] Figure 7 is an example pipeline for managing encrypted data;
[0013] Figure 8 is a process flow diagram for managing encrypted data;
[0014] Figure 9 is a process flow diagram for managing encrypted data based on a correction value as a second MAC value;
[0015] Figure 10A and Figure 10B is an example of a technique for managing encrypted data using a block correction value as a second MAC;
[0016] Figure 11 is an example of a tangible, non - transitory computer - readable medium for managing encrypted data.
[0017] In some cases, the same numbers are used throughout the disclosure and the figures to refer to similar components and features. Numbers in the 100 series refer to features initially found in Figure 1 ; numbers in the 200 series refer to features initially found in Figure 2 ; and so on. Detailed Description
[0018] Error - correcting code (ECC) memory may include integrated circuits or devices or chips that use additional physical memory to correct corrupted data, which may increase system cost. Additionally, ECC memory technology may not be cryptographic. The techniques described herein provide cryptographic - secure ECC methods while maintaining error - correction capabilities to provide high - performance memory that can mitigate random bit errors, memory - based integrated - circuit failures, and malicious adversaries. A memory - based integrated circuit (also referred to herein as a device) may include any suitable hardware or logic chip for storing a predetermined number of bits in a storage device. The techniques described herein are cryptographically secure and perform both the tasks of error - correction and providing memory integrity, including supporting multiple encryption keys / MKTME (Multi - Key Total Memory Encryption), replay prevention, and cryptographically strong data corruption detection, even by a physical adversary. Additionally, the techniques described herein may not require the use of additional ECC memory and thus reduce memory cost.
[0019] The techniques described herein include using a cryptographically strong Message Authentication Code (MAC) or HMAC (Hash Message Authentication Code) to replace the ECC detection mechanism with a statistical trial-and-error method. In some examples, the device unraveling code targets one device of the memory for the secure hash test at a time, which can identify the memory device containing the error and which bits are flipped (up to a completely damaged device). The unraveling as mentioned herein can include performing an XOR operation or any other suitable logical operation on the data in the integrated circuit stored in the memory device. In some examples, when combined with Total Memory Encryption (TME / multi-key TME), the heuristic can help identify potentially damaged plaintext blocks given the entropy of the plaintext block, as an error that changes the ciphertext stored in the memory will result in random plaintext upon decryption. Alternatively, compression can be used to encode the detection code (e.g., Reed-Solomon) within the data cache line to identify / locate the damaged memory locations and reduce the cost / amount of physical memory required to store these codes.
[0020] In some embodiments, a computing device can store a first Message Authentication Code (MAC) based on data stored in the system memory in response to a write operation to the system memory. The MAC as mentioned herein can include any suitable message authentication code involving a cryptographic hash function and a secret cryptographic key. In some embodiments, the computing device can also detect a read operation corresponding to the data stored in the system memory and calculate a second MAC based on the data stored in the system memory. The computing device can also determine that the second MAC does not match the first stored MAC and recalculate the second MAC after a correction operation, where the correction operation includes an XOR operation based on the data stored in the system memory and an alternative value for the device of the system memory. Additionally, the computing device can decrypt the data stored in the system memory and send the decrypted data to the cache in response to detecting that the recalculated second MAC matches the first MAC.
[0021] In some embodiments, the computing device may also store an encrypted first block correction value based on the plaintext data to be stored in the system memory in response to a write operation to the system memory. Additionally, the computing device may detect a read operation corresponding to the data stored in the system memory and calculate a second block correction value based on the data stored in the system memory, the second block correction value being calculated based on an XOR operation including the plaintext of the encrypted data stored in the system memory. In some embodiments, the computing device may determine that the second block correction value does not match the decrypted first block correction value and recalculate the second block correction value after a correction operation, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and an alternative value of the device data for the system memory. Additionally, the computing device may decrypt the data stored in the system memory and send the decrypted data to the cache in response to detecting that the recalculated second block correction value matches the first block correction value.
[0022] The techniques described herein can prevent the reconstruction of data stored in memory to produce a correct ECC code and provide memory protection against random errors and faults. Additionally, the techniques described herein enable detection of attempts to corrupt memory by injecting data from one tenant into another in a cross-key domain attack, or by flipping physical memory bits in a row-hammer attack, or by otherwise physically manipulating the memory device. Because the techniques described herein are cryptographically non-deterministic to an adversary, the adversary cannot deterministically manipulate the memory data, e.g., detect.
[0023] References in the specification to "one embodiment" or "an embodiment" of the disclosed subject matter mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the disclosed subject matter. Thus, the phrase "in one embodiment" may appear throughout the specification, but the phrase may not necessarily refer to the same embodiment.
[0024] Figure 1 is a block diagram of an example of a host computing device that can manage encrypted data. The host computing device 100 can be, for example, a mobile phone, a laptop computer, a desktop computer, or a tablet computer, among others. The host computing device 100 can include a processor 102 adapted to execute stored instructions and a memory device 104 that stores instructions executable by the processor 102. The processor 102 can be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. The memory device 104 can include random access memory, read-only memory, flash memory, or any other suitable memory system. The instructions executed by the processor 102 can be used to implement a method that can transmit encrypted image data.
[0025] The processor 102 may also be linked via the system interconnect 106 (e.g., Fast NuBus, etc.) to a display interface 108 adapted to connect the host computing device 100 to a display device 110. The display device 110 may include a display screen, which is a built-in component of the host computing device 100. The display device 110 may also include a computer monitor, a television, or a projector externally connected to the host computing device 100, and others. The display device 110 may include light-emitting diodes (LEDs) and micro-LEDs, and others.
[0026] Additionally, a network interface controller (also referred to herein as NIC) 112 may be adapted to connect the host computing device 100 to a network (not depicted) via the system interconnect 106. The network (not depicted) may be a cellular network, a radio network, a wide area network (WAN), a local area network (LAN), or the Internet, and others.
[0027] The processor 102 may be connected via the system interconnect 106 to an input / output (I / O) device interface 114 adapted to connect the computing host device 100 to one or more I / O devices 116. The I / O devices 116 may include, for example, a keyboard and a pointing device, where the pointing device may include a touchpad or a touch screen, and others. The I / O devices 116 may be built-in components of the host computing device 100 or may be devices externally connected to the host computing device 100.
[0028] In some embodiments, the processor 102 may also be linked via the system interconnect 106 to any storage device 118, which may include a hard disk drive, an optical disc drive, a USB flash drive, a solid-state drive, or other non-volatile memories, a drive array, or any combination thereof. In some embodiments, the storage device 118 may include any suitable application programs and stored data.
[0029] In some embodiments, processor 102 may include any suitable number of logic modules executable by memory controller 119. In some examples, memory controller 119 (or memory management unit) is the logic on processor 102 that interacts with external system memory device 104. Memory controller 119 may interact with external memory 104 for read / write operations, send or receive data, calculate / manage MAC, error correction code, encryption / decryption, etc. In some examples, MAC manager 120 may store a first message authentication code (MAC) based on data stored in system memory in response to a write operation to the system memory. The MAC as mentioned herein may include any suitable message authentication code involving a cryptographic hash function and a secret cryptographic key. In some embodiments, MAC manager 120 may also detect a read operation corresponding to data stored in system memory and calculate a second MAC based on the data stored in system memory. MAC manager 120 may also determine that the second MAC does not match the first MAC and recalculate the second MAC after a correction operation, where the correction operation includes an XOR operation based on the data stored in system memory and an alternative value for the device of the system memory. Additionally, decryption manager 122 may decrypt data stored in system memory in response to detecting that the recalculated second MAC matches the first MAC. In some embodiments, data transmitter 124 may send the decrypted data to cache 126 residing on processor 102 or any other suitable cache or memory device. In some examples, cache 126 (or cache hierarchy) is located between processor 102 and memory controller 119. In some embodiments, processor 102, cache 126, and memory controller 119 may be on the same physical chip / die or package.
[0030] Alternatively, in some embodiments, the MAC manager 120 may store an encrypted first correction value based on data stored in the system memory in response to a write operation to the system memory. Additionally, the MAC manager 120 may also detect a read operation corresponding to the data stored in the system memory and calculate a second block correction value based on the data stored in the system memory, where the second block correction value is calculated based on an XOR operation including the plaintext data stored in the system memory. In some embodiments, the MAC manager 120 may determine that the second block correction value does not match the decrypted first block correction value and recalculate the second block correction value using a correction operation, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and an alternative value for the device of the system memory. Further, the decryption manager 122 may decrypt the data stored in the system memory in response to detecting that the recalculated second block correction value matches the first block correction value, and the data transmitter 124 may transmit the decrypted data to the cache.
[0031] It should be understood that Figure 1 the block diagram of Figure 1 is not intended to indicate that the host computing device 100 will include Figure 1 all of the components shown in
[0032] Figure 2 shows a block diagram of a dual in-line memory module (DIMM). In Figure 2Among them, DIMM 200 can be a SIMM, SO-DIMM, NVDIMM, VLPDIMM, DDR DIMM, DDR2 DIMM, DDR3 DIMM, DDR4 DIMM, or DDR5 DIMM, and others. DIMM 200 can include any number of devices or integrated circuits or chips. For example, eight devices for storing data are depicted in two memory banks 202 and 204 of DIMM 200. In some examples, error-related device 206 can reside near memory banks 202 and 204, and error-related device 206 can store MAC values. In some examples, DIMM 200 can also include additional devices on the back side (not depicted) of DIMM 200. The back side of DIMM 200 can also include memory banks and error-related devices for storing device correction values. Error-related device 206 and the error-related device behind DIMM 200 can provide additional memory for storing detection and correction codes.
[0033] It should be understood that Figure 2 the block diagram of Figure 2 is not intended to indicate that DIMM 200 will include Figure 2 all the components shown in
[0034] Figure 3 A process flow diagram for managing encrypted data is shown. Figure 3 The method 300 shown in Figure 1 can be implemented using any suitable computing component or device, such as,
[0035] at block 302, the MAC manager 120 can calculate and store a first MAC based on the data stored in the system memory in response to a write operation to the system memory. For example, the MAC manager 120 can detect a write operation to the system memory and use any suitable cryptographic MAC function with a second key, and others, to generate a MAC value based on the data stored in the memory. In some embodiments, the data stored in the memory can include any suitable ciphertext encrypted using any suitable encryption technique. The result of the logical operation of a block of cross-device data can be stored as a device data block correction value.
[0036] at block 304, the MAC manager 120 can detect a read operation corresponding to the data stored in the system memory. For example, the MAC manager 120 can detect an attempt to execute an instruction based on the encrypted data stored in the system memory.
[0037] At block 306, the MAC manager 120 may calculate a second MAC based on the encrypted data retrieved from the system memory. The MAC manager 120 may apply the same MAC function used for the write operation and use the same key in order to produce a matching MAC.
[0038] At block 308, the MAC manager 120 may determine that the second MAC does not match the first MAC. For example, the MAC manager 120 may detect whether bits of the data stored in the memory have flipped since the data was stored in the memory as part of a write operation. In some examples, the flipped bits in the memory may represent data corrupted by a malicious attempt to manipulate the data stored in the memory.
[0039] At block 310, the MAC manager 120 may recompute the second MAC with a correction operation, where the correction operation includes an XOR operation based on the device data blocks retrieved from the system memory and alternative values for the excluded device data blocks for the system memory. In one example, the alternative values (also referred to herein as the expanded correction values) may repair the corrupted data stored in the devices of the memory. For a simplified example, an assumed 16-bit cache line may consist of four 4-bit integrated circuits or device data blocks and a 4-bit MAC, e.g., 1010 (block 1), 0100 (block 2), 1101 (block 3), 1011 (block 4), and 0010 (MAC). The MAC value may be calculated based on a keyed secure hash operation on device data blocks 1-4. The correction value may be a combination of devices 1-4 based on a logical XOR operation, which produces the value 1000. The MAC value may also be included in the XOR operation, resulting in a 1010 device block correction value (BC). In some examples, the correction value may be used to reconstruct any of the missing device data blocks, including the MAC device with the XOR operation, assuming no errors in the other devices. For example, the replacement data block for the faulty device 1 may be calculated based on a logical XOR operation on the correction value, the MAC value, and the values of device data blocks 2-4. Additionally, a second MAC value may be calculated based on a keyed secure hash operation that combines the alternative correction value for device 1 with the values of device data blocks 2-4 and the first stored MAC value. If the faulty device data is repaired by replacing it with the alternative value, the second calculated MAC value should match the first stored MAC value. Then the alternative value should be used instead of the faulty device data block. Otherwise, the calculated second MAC value will likely not match the first stored MAC value.
[0040] At block 312, the decryption manager 122 may decrypt data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC. At block 314, the data transmitter 124 may send the decrypted data to the cache.
[0041] In some embodiments, Figure 3 the process flow diagram is not intended to indicate that the operations of method 300 will be performed in any particular order or that all operations of method 300 will be included in every case. Additionally, method 300 may include any suitable number of additional operations. For example, the techniques herein may be applied to correct any suitable sized block or integrated circuit. In some examples, there may be a trade-off between the block correction value size and the number of correction attempts for correcting one erroneous data block. As shown below, a cache line may be represented as a set of N device data blocks B[0],..., B[N-1] of size S. In some embodiments, any suitable cryptographic secure hash function may be used as the MAC function, e.g., an SHA-3 based MAC, among others. In some examples, the MAC function accepts any suitable secret key and multiple data blocks as input, as shown in Equation 1 below:
[0042] MAC = SHA3(key, B[0]||…||B[N-1]) Equation 1
[0043] In some embodiments, the key may be selected based on metadata or a key identifier that is part of the memory address. In some examples, an alternative MAC function may include the memory address of a data row in memory, which is part of the hashed data. Additionally, in some examples, the MAC function may be computed using any suitable alternative cryptographic secure hash function such as SHA-1 or SHA-2, among others.
[0044] In some examples, the device block correction value (BC) may be computed according to an XOR operation:
[0045]
[0046] In some examples, the data returned from a memory read is B′[0]…B′[N-1], which may be equal to B[0]...B[N-1] if there are no errors. If the MAC does not match, a repair value (RV) may be computed using an XOR operation, where one of the device data blocks B'[i] from the set of B'[0] to B'[N-1] is omitted from the following equation:
[0047]
[0048] As discussed above, attempts to repair each device and verify the MAC during a correction operation can include, for each device data:
[0049] MAC′ = SHA3(key, B′[0]||…||(B′[i] replacing RV)||…||B′[N - 1]) Equation 4
[0050] In some examples, the MAC function can be computed using any suitable alternative cryptographically secure hash function such as SHA-1 or SHA-2 and others. If MAC′ matches the MAC, the repaired value can be returned in place of the faulty device data block. Otherwise, an error can be returned.
[0051] Alternatively, a repair value RV can be computed for each device without XORing the device's data block with the data blocks of other devices. In this example, RV can replace the device data block during a repair attempt. In some examples, S = 32 and N = 16. However, S and N can be any suitable values. In one example, if S = 1 and N = 512, each bit can be flipped and the MAC can be verified after each bit flip. In this example, BC may not be stored.
[0052] Figure 4 A process flow diagram for managing encrypted data is shown. Figure 4 The method 400 shown can be implemented using any suitable computing component or device, e.g., Figure 1 the computing device 100.
[0053] At block 402, the MAC manager 120 can compute the MAC. In some examples, the MAC is computed in response to a read operation as discussed above. The MAC manager 120 can compute the MAC using a keyed secure hash operation based on the encrypted data stored in any suitable number of integrated circuits or devices including the cache line containing the data.
[0054] At block 404, the MAC manager 120 can determine whether the computed MAC matches the stored MAC. If the computed MAC matches the stored MAC, the process flow continues at block 406, where the error is corrected (or was never present), the data is decrypted and sent to the cache device. If the computed MAC does not match the stored MAC, the process flow continues at block 408, where each of the integrated circuits or memory devices is tested.
[0055] If each of the integrated circuits or devices including the cache line with data has been tested, but the first MAC and the second MAC never match, the process proceeds to block 410, where an uncorrectable error is reported. If not all of the integrated circuits or devices including the cache line with data have been tested, the process flow continues at block 412. At block 412, the MAC manager 120 may skip the next integrated circuit or device data block in the XOR calculation and substitute the unrolled or XORed repair value (RV) to calculate the MAC value. The process flow returns to block 402.
[0056] In some examples, the techniques herein may be used with a MAC size of any suitable length. For example, if the MAC value is 64 bits, two spare integrated circuits or memory devices may be used to store two 32-bit values. The two 32-bit MAC values may be combined with a logical OR operation. In some embodiments, two MAC values may be calculated in response to a read operation, and the results of the two MAC values may be concatenated to generate a 64-bit MAC value.
[0057] In some embodiments, the techniques herein may attempt to correct single-bit errors or multi-bit errors within a single device or integrated circuit using each integrated circuit or device of a memory DIMM including a cache line with data once. In some examples, the technique may also correct multiple single-bit errors across multiple devices or integrated circuits. For example, if there is one-bit error in each of two separate devices, the fully unrolled or XORed correction value may show that two bits have flipped. In some embodiments, the MAC may be tested by flipping various bit combinations in each device data block. For example, for 8 DDR5 devices, two bit sites in each device data block may be flipped across n devices. Thus, sixty-four MAC tests may identify two devices containing a single single-bit error.
[0058] In some examples, if the fully unrolled or XORed correction value has a large number of flipped bits, the error may be a complete device failure. The device failure may persist across multiple memory reads but with fewer correction attempts. For example, for DDR5 memory, adding only 22 * 8 extra clocks for SHA3 encryption may be the worst case, and these operations may be performed in parallel. In some examples, SHA3 encryption takes fewer clock cycles than AES-XTS decryption, so when calculating the MAC through the ciphertext and calculating it in parallel with the decryption of the memory read operation, integrity does not add any performance overhead to the memory read other than the encryption.
[0059] Figure 4The process flow diagram is not intended to indicate that the operations of method 400 will be performed in any particular order or that all operations of method 400 will be included in every case. Additionally, method 400 may include any suitable number of additional operations.
[0060] Figure 5A and Figure 5B illustrates an example of a data structure for storing encrypted data. In some examples, each device 502A may include any suitable number of bits. For example, each device 502A may include a 16-bit value, a 32-bit value, or a 64-bit value, among others. In some embodiments, any number of devices may be equal in size to the encryption key or the encryption block. For example, if the size is 32 bits, devices 502A, 504A, 506A, and 508A may be equal to the block size of data encrypted using AES. In some embodiments, a correction value 510A is generated by calculating the result of an XOR operation based on a previously stored MAC value 512A and the encrypted data values stored in device data blocks 502A, 504A, 506A, 508A, and similarly, all the remaining devices shown in 514A have an impact on the cache line of the data.
[0061] In Figure 5B device data blocks 502B, 504B, 506B, 508B, and 510B may store encrypted data in a memory. In some examples, an alternative value 512B is generated for device data block 504B based on an XOR operation on device data blocks 502B, 506B, 508B, and all other device data blocks shown as 510B, MAC 514B, and correction value 516B. For example, if the stored MAC 514B fails to match the MAC 518B (combined device data blocks) of the calculated data row, an alternative value 512B may be generated using an XOR operation based on MAC value 514B, correction value 516B, and each device data block in the device data blocks excluding the one device data block being tested (also referred to herein as unwinding). For example, device data block 504B may be excluded from the XOR sequence to determine whether device data block 504B includes an erroneous bit, since the second MAC recalculated using the generated alternative value in place of device data block 504B matches the stored first MAC.
[0062] Figure 6 shows a process flow diagram for managing encrypted data based on the entropy level of the data. Figure 6 The method 600 shown in Figure 1computing device 102. Method 600 can utilize heuristics to locate which device or portion of a memory device may be faulty. For example, if a decrypted AES block shows random plaintext, then one of the device data blocks in the device data blocks that may affect the AES block is faulty.
[0063] At block 602, the MAC manager 120 may detect that the computed MAC does not match the stored MAC value. At block 604, the MAC manager 120 may decrypt multiple data blocks in the stored memory. In some embodiments, the number of decrypted device data blocks is equal to the length of the encryption key. For example, four device data blocks each storing thirty-two bits may be decrypted for a one-hundred-twenty-eight-bit encryption block. In some examples, the size of the block corresponds to the size of the input or output of the block cipher. For example, a block cipher such as AES 128 may use a 128-bit key to encrypt / decrypt data of 128-bit block size. Alternatively, a block cipher such as AES 256 may use a 256-bit key to encrypt / decrypt data blocks of the same 128-bit size.
[0064] At block 606, the MAC manager 120 may determine whether the plaintext of the decrypted data block has an entropy below a threshold value. For example, if the number of zero bits and one bits in the plaintext is approximately equal or has an equal distribution, then the entropy is higher than the threshold due to the random nature of the data. Thus, method 600 may include ignoring the plaintext data with low entropy, or first selecting the block with the highest entropy for replacement testing. In one example, a decrypted block with multiple 8-bit zeros at byte alignment sites may not be considered random or corrupted, and thus those devices including that block may be eliminated from the process of identifying corrupted data blocks with errors. In other examples, the decrypted plaintext with repeated values or values similar to other decrypted blocks is considered to have a lower entropy and may be skipped first in the replacement value test because these plaintexts are unlikely to be the source of memory corruption.
[0065] If the plaintext of the decrypted data has an entropy higher than the threshold value, the process flow continues at block 608. At block 608, the MAC manager 120 may determine whether correcting each data block by replacing the device data block with a correction value as discussed above Figure 3 corrects the data. If the plaintext of the decrypted data has an entropy lower than the threshold value, the process flow continues at block 610 by testing subsequent amounts of data blocks before returning to block 602 of the process flow diagram. The MAC manager may also recompute the second MAC after replacing each device data block with the replacement value of the decrypted block with the highest entropy.
[0066] In some embodiments, compression can also be used on the data to fit Reed-Solomon codes or similar ECC error detection codes within a data cache line. If these codes are repeated across multiple blocks, these codes can also be used to precisely identify bit error locations without requiring trial and error. Similarly, compression of the data rows can allow MAC values to be stored in the space freed up by the compression, thus reducing the need for additional memory to store the MAC values. Additionally, if there is a device failure or a stuck-at fault, it may be multiple memory reads across aligned memory locations corresponding to the same device. This means that multiple adjacent reads will experience the same fault location. This will help error correction focus on the most likely device for the stuck-at fault, again reducing trial and error.
[0067] Figure 6 The process flow diagram is not intended to indicate that the operations of method 600 will be performed in any particular order or that method 600 will include all the operations in every case. Additionally, method 500 can include any suitable number of additional operations.
[0068] Figure 7 Illustrates a pipelining technique for computing the MAC. In some embodiments, the pipeline for MAC computation can be used for speculative repair of device data blocks instead of sequential MAC computation for each repair attempt. For example, in a fully pipelined design (1 stage / clock cycle), at each clock cycle, for i = 0...15, the cache line can be submitted to the MAC generation pipeline along with the "repaired" device i such that the MAC values are computed in parallel. In one example, assuming a SHA-3 encryption pipeline has a 22-cycle latency, the total latency result in the best case can be 22 cycles, 47 cycles in the worst case, and 29 cycles on average. In some examples, the SHA-3 pipeline can be partially pipelined to match the throughput, i.e., accept one cache line every four cycles. In some embodiments, repairing the device storing the MAC value does not require recomputing the MAC value on the cache line data since the data has not changed during the repair attempt. Instead, the process can include performing an XOR operation to generate a "repaired" MAC and attempting to match the repaired MAC with the MAC generated on the original read data. In some examples, this repair attempt can be performed first before attempting to repair any device data block, which may have a latency of at least 22 cycles due to MAC recomputation.
[0069] In Figure 7In example 700, the fully pipelined SHA-3 engine consists of 22 identical cascaded stages, each of which has a set of state registers and combinational logic for the Keccak function. Inputs can be provided to each stage, and the last stage provides the output. To increase the utilization of the pipeline, the loop of pipeline stage K 702 can feed the input 702 to any one of the pipeline stages through inputs in0...in21 704. The output of the specific input data is retrieved from the corresponding outputs out0...out21 706 after 22 cycles.
[0070] This loop design allows multiple input cache lines to be loaded and processed in parallel in the same cycle instead of skewing by one cycle. This is useful when calculating MACs to repair device data blocks. In the best case, if the pipeline is empty, "repaired" cache lines can be loaded in parallel to determine which device is faulty, thus reducing latency. In some examples, unused inputs can be used to calculate the MACs of other data responses arriving from memory. This improves the latency and throughput of memory-intensive workloads with frequent DRAM errors. A hardware arbiter can be used to keep track of ongoing MAC calculations and multiplex the input data to the appropriate stage. This approach can also be applied to partially pipelined designs, where each stage applies multiple rounds of the Keccak function to the current state until it is transferred to the next stage. Each of these stages can have external inputs and outputs as described above to maximize the utilization of each stage.
[0071] Figure 8 A process flow diagram for managing encrypted data is shown. Figure 8 The method 800 shown in can be implemented using any suitable computing component or device, for example, Figure 1 computing device 102.
[0072] At block 802, the MAC manager 120 can store an encrypted first block correction value and a first MAC value based on data stored in the system memory in response to a write operation to the system memory. The first block correction value includes the XOR of the plaintext of each block of data in the data row written to the memory. Additionally, the MAC manager can calculate an additional MAC value for the encrypted data in the data row and store the additional MAC value in the memory. At block 804, the MAC manager 120 can detect a read operation corresponding to the data stored in the system memory.
[0073] At block 806, the MAC manager 120 may calculate a second block correction value based on data stored in the system memory. In some examples, the second block correction value may be calculated based on an XOR operation of the plaintext data or decrypted data of each block including the data row stored in the system memory. In some examples, the second block correction value may be generated in response to a read operation.
[0074] At block 808, the MAC manager 120 may determine that the second block correction value does not match the decrypted first stored block correction value. In such a case, the MAC manager 120 may retrieve an additional stored MAC value from the memory and calculate a second MAC for the data row stored in the memory. If the stored MAC matches the second calculated MAC, it is determined that the block correction code is in error, and the data may be decrypted and sent to the cache. If, at block 810, the stored MAC does not match the second calculated MAC, the MAC manager 120 may recalculate the second block correction value with a correction operation at block 812. In some embodiments, the correction operation includes an XOR operation based on the decrypted data blocks stored in the system memory and determines an alternative value for the device data block or integrated circuit for the system memory by omitting the device data block and using the remaining block correction values in place of the decrypted device data block plaintext. The alternative value is then encrypted using the secret key (used to encrypt the device data block), and the second MAC is recalculated using the remaining encrypted blocks and the encrypted alternative value.
[0075] At block 814, the decryption manager 122 may decrypt the data stored in the system memory including the cache line in response to detecting that the recalculated second MAC value matches the first stored MAC value. At block 816, the data transmitter 124 may send the decrypted data to the cache.
[0076] Figure 8The process flow diagram of does not intend to indicate that the operations of method 800 will be performed in any particular order or include all the operations of method 800 in every case. Additionally, method 800 may include any suitable number of additional operations. In method 800, the block correction code itself can safely (in a non-forgeable manner) detect that the data has at least one error. An additional MAC value can be used to determine when any error is corrected or fixed. If there is no error, the additional stored MAC value is not retrieved. In some embodiments, the additional MAC value can be stored in a separate memory location, thus removing the need for an additional device on the memory device (e.g., DIMM) for the MAC. Some embodiments can completely eliminate the additional stored MAC value by using the entropy of each decrypted data block to determine which device / block has an error and using a substitute value in place of the decrypted data block with the highest entropy, as Figure 6 shown. Similarly, data compression techniques can be used to fit the MAC within the space freed up by compressing the data rows.
[0077] Figure 9 is a process flow diagram for managing encrypted data. In some embodiments, method 900 may include transforming each device data block before calculating the error correction code. One transformation is to use a small block size cipher (e.g., SIMON, SPECK, PRINCE, and others), where the block size matches the device size, to encrypt each device individually with a secret key before XORing each resulting ciphertext. Some embodiments may include a tweak, e.g., using XTS (XEX-based Tweaked Codebook Mode with Ciphertext Stealing) or other tweakable modes, where the tweak includes the address of the device data block to create a ciphertext that depends on the memory site / location. Which key to use for encrypting / decrypting a data row can also be selected by appending address bits or other cacheable metadata indicating which key in a set of keys to use.
[0078] Thus, even the correction code is secure. For example, the encryption of each device with a small block size cipher can be used as an input to the XOR function to calculate the XORed correction code. An attacker would need to know the output of that secret function to make all the device data blocks expand to zero. Thus, both the MAC and the correction code work together to enhance the security of the block.
[0079] At block 902, the MAC manager 120 can calculate the MAC, confidentialize the data, and decrypt the block correction value in response to a read operation. In some examples, the block correction value is stored in an encrypted format from a previous write operation. In some embodiments, the MAC can be calculated based on the encrypted data stored in the memory before decryption.
[0080] At block 904, the MAC manager 120 may determine whether the decrypted block correction value matches the XOR result based on the plaintext data or the decrypted data. If the block correction value matches the XORed plaintext data block, the process flow continues at block 906 and the decrypted data is sent to the cache. If the block correction value does not match the XORed plaintext data block, the process flow continues at block 908.
[0081] At block 908, the MAC manager 120 may determine whether the calculated MAC matches the stored MAC. If the calculated MAC matches the stored MAC, the process flow continues at block 906 by sending the decrypted data to the cache device. If the calculated MAC does not match the stored MAC, the process flow continues to block 910. At block 910, the MAC manager 120 may skip to the next device data block in the XOR calculation, replace the decrypted block correction value for the decrypted device data block, re-encrypt the replacement value, and recalculate the MAC and the encrypted replacement value on the remaining encrypted device data blocks before returning to block 908. Thus, in order for a corrupted cache line to pass the integrity check, an attacker has to forge not only the MAC, but also the block correction value generated using the secret key. Thus, this effectively becomes a two-MAC solution, especially when a stronger (larger) MAC than can fit in the device data block of the error detection code is required. As DRAM device density increases, the above solution is also efficient in reducing the cost of ECC memory because the MAC can be stored separately in isolated (e.g., software-allocated) memory or as a table structure in memory (a table indexed by the memory address associated with each table entry). Thus, additional ECC chips / devices for ECC error detection codes and / or MACs on the DIMM can be eliminated. At the same time, when device correction fails to match, isolated memory for the MAC can be used. The MAC is used to determine which of the correction values in the correction value is successful, or whether the correcting device is a faulty part because the MAC will match the uncorrected data row value. Finally, techniques such as compression can be used to embed the MAC within the data row (when compressible), and only MAC lookups are used for data cache lines that are not compressed. This can further reduce the amount of isolated memory required and reduce the number of memory lookups when correcting memory errors.
[0082] Figure 10A and Figure 10B depicts techniques for managing encrypted data using block correction values and a second MAC. In Figure 10AIn this case, during memory write, the encrypted data 1002A can be used to calculate the separately stored MAC 1004A. Additionally, the decrypted version of the data or the plaintext data 1006A can be combined with an XOR operation to generate the XORed plaintext 1008A as the correction value 1010A. The correction value 1010A can be stored as the encrypted block correction value in the encrypted format 1012A.
[0083] In Figure 10B this case, during memory read, all device data blocks of the memory row are decrypted. Then the plaintexts of each device block are XORed together and compared with the decrypted block correction value 1010B. Each device data 1002B can be decrypted before performing the XOR operation on the plaintext 1004B to generate the XORed plaintext 1006B. In some examples, the encrypted block correction value 1008B can be decrypted to generate the decrypted block correction value 1010B, and the decrypted block correction value 1010B is compared with the XORed plaintext 1006B. In some examples, when the decrypted value of 1010B and 1006B do not match, the XORed plaintext 1006B can be XORed with the decrypted block correction value 1010B while omitting one device / block at a time from the 1006B calculation. Then the resulting block correction value is encrypted to generate the initial encrypted data block value of the faulty device. Then this value is used to replace the omitted device data block, and the MAC is recalculated and compared with the separately stored MAC until the faulty device data block is identified and corrected. In some examples, even when the MAC passes, when the block / device is transformed and XORed with the initial block correction value, the block correction value should expand or generate a zero value due to the XOR operation.
[0084] In some embodiments, the techniques described herein can provide replay protection even when multiple keys (MKTME) are used for AES-XTS encryption of data. For example, the MAC manager 120 can periodically rekey the MAC value using a unique key, where the MKTME AES-XTS ciphertext and the unique MAC key are used to recompute the MAC. The rekeying can be coordinated with a memory refresh where the memory is read, the MAC is computed using the old key and compared to the old stored MAC for the same memory row, and if the values match, the MAC is recomputed using the new key before writing the new MAC back to memory. In some examples, these techniques can use constructs such as an ICV that is equal to HMACrk(Ck) XOR AESk(address). This construct allows for refreshing the key rk for the HMAC. This independently combines the MAC on the ciphertext (Ck) from a particular domain key (k) and a key-dependent test using an adjustment (XTS adjustment using the address).
[0085] In this example, if an adversary or unauthorized user replays content from another key domain for the same memory address, the HMAC on the ciphertext will be correctly computed, but the address-based adjustment using the current key domain key k will not match during the memory read. The MAC manager 120 can compute the old HMAC (using the previous refresh key rk) on the ciphertext data cache line, XOR the data cache line content from the stored ICV, and XOR this with the new HMAC using the refreshed key.
[0086] In some embodiments, the MAC manager 120 can use an alternative construct to rekey the MAC. For example, the MAC manager 120 can use a construct for the ICV that is equal to HMACrk(Ck) XOR HMACk(address). This construct provides ciphertext corruption detection, which can be extended for cross-key domain corruption detection, and can be refreshed to limit replay without an additional MAC key.
[0087] In another embodiment, the MAC manager 120 may reset the key for the MAC value using a constructed ICV equal to ENCRYPTrk(SHA3(Ck, TWEAKk)). Here, ENCRYPT may be a small block cipher (e.g., SIMON, among others), which is the same size as the truncated SHA3 HMAC that encrypts the HMAC using the refresh key rk (e.g., 32 bits or 64 bits, etc.). In addition to the ciphertext based on the data encryption key k, the HMAC also includes an XTS-based tweak (e.g., the memory address encrypted by AES based on the data encryption key). This allows the ICV to prevent cross-domain attacks and be bound to the memory address / location where the data is physically stored. The tweak operation may be the same as the operation used to encrypt the data with XTS to produce Ck, but different tweak offsets may be exclusively used for this operation (e.g., based on an extended address value to produce an additional unique tweak value from the tweak used to encrypt the data row). Similarly, other cryptographic key derivation techniques may be used instead of the tweak to produce an HMAC that depends on the data encryption key. In some examples, TWEAKk based on the data encryption key k is actually a key derivation function that causes the SHA3 hash algorithm to output a MAC, which can then be truncated. The advantage of using a tweak with an encryption key is that it eliminates the need to store a separate key for computing the MAC. Instead, the encryption key can be reused through a key derivation function that uses the encryption key k to encrypt the memory address (with padding) of the encrypted data row (Ck). Similarly, any secure hash function may be used instead of SHA3, and any key derivation function may be used instead of the tweak.
[0088] A replay / version tree can also be used with this construction. Here, the embedded MAC is the ECC memory MAC as previously described. The MAC of the replay tree can include the parent counter value for the cache line. The root counter / once-use nonce (or counter / once-use nonce for multiple memory regions) can also be embedded in the hardware on the die. The first level of the tree in memory contains cache lines with a set of counter / once-use nonce values and the MAC in the ECC memory. This MAC is computed over all counter values including the cache line and the associated root counter / once-use nonce stored on the die. Each counter / once-use nonce value on the line is the parent of the next level of the tree. The next level of the tree is a line with counter / once-use nonce values, again, where the MAC in the ECC memory hashes all counter / once-use nonce values in the line and a single parent once-use nonce / counter from the previous line in the tree. The last level / leaf of the tree consists of the data line as previously described and its MAC in the ECC memory, with the difference that the MAC is also hashed over the parent counter / once-use nonce value. In this way, replay can be prevented each time data is written to memory, the root counter and all counter values in the branches of the counter / once-use nonce tree pointing to the updated data line are incremented / updated, and all affected MACs in the ECC memory are recomputed. On memory read, the MAC is verified for the branch of the tree associated with the read data line by checking that the counter / once-use nonce values are correct / unmodified. The MAC value can be computed using a secret key different from the key used to encrypt the data line, and the MAC is computed over the AES-XTS ciphertext of the data line, thus allowing different data to be encrypted using different keys such as MKTME.
[0089] In some embodiments, the ECC / integrity value can also be stored to a separate memory location so that it does not require adding physical ECC memory / ECG DIMM. In this case, additional memory reads / writes will be used to fetch the ECG / integrity value from the separate memory location. For example, the ECC correction field can be extended to the correct memory and is an HMAC for error detection. Using an entropy test to confirm which device might be in error eliminates the need to store any other value, thus saving half of the ECC memory overhead and reducing cost.
[0090] Figure 11A block diagram of a non - transitory computer - readable medium for managing encrypted data is shown. The tangible, non - transitory computer - readable medium 1100 can be accessed by a processor 1102 via a computer interconnect 1104. Additionally, the tangible, non - transitory computer - readable medium 1100 can include code for directing the processor 1102 to perform the operations of the current method.
[0091] The various software components discussed herein can be stored on the tangible, non - transitory computer - readable medium 1100, as Figure 11 shown. For example, a MAC manager 1106 can store a first message authentication code (MAC) based on data stored in the system memory in response to a write operation to the system memory. In some embodiments, the MAC manager 1106 can also detect a read operation corresponding to the data stored in the system memory and calculate a second MAC based on the data stored in the system memory. The MAC manager 1106 can also determine that the second MAC does not match the first MAC and use a corrective operation to recalculate the second MAC, where the corrective operation includes an XOR operation based on the data stored in the system memory and an alternative value for the device of the system memory. Additionally, a decryption manager 1108 can decrypt the data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC. In some embodiments, a data transmitter 1110 can send the decrypted data to a cache residing on the processor 102 or any other suitable cache or memory device.
[0092] Alternatively, in some embodiments, the MAC manager 1106 can store an encrypted first block correction value based on data stored in the system memory in response to a write operation to the system memory. Additionally, the MAC manager 1106 can also detect a read operation corresponding to the data stored in the system memory and calculate a second block correction value based on the data stored in the system memory, where the second block correction value is calculated based on an XOR operation including the plaintext data stored in the system memory. In some embodiments, the MAC manager 1106 can determine that the second block correction value does not match the decrypted first block correction value and use a corrective operation to recalculate the second block correction value, where the corrective operation includes an XOR operation based on the encrypted data stored in the system memory and an alternative value for the device of the system memory. Additionally, the decryption manager 1108 can decrypt the data stored in the system memory in response to detecting that the recalculated second block correction value matches the first block correction value, and the data transmitter 1110 can send the decrypted data to the cache.
[0093] It should be understood that Figure 11Any suitable number of software components as shown in FIG. may be included within the tangible, non-transitory computer-readable medium 1100. Additionally, depending on the particular application, Figure 11 Any number of additional software components not shown in FIG. may be included within the tangible, non-transitory computer-readable medium 1100.
[0094] Example 1
[0095] In some examples, a system for managing an encrypted memory includes a processor that stores a first Message Authentication Code (MAC) based on data stored in the system memory in response to a write operation to the system memory. The processor may also detect a read operation corresponding to the data stored in the system memory, calculate a second MAC based on the data retrieved from the system memory, and determine that the second MAC does not match the first MAC. Additionally, the processor may recalculate the second MAC after a correction operation, where the correction operation includes an XOR operation based on the data retrieved from the system memory and an alternative value for the device for the system memory. Further, the processor may decrypt the data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC, and send the decrypted data to the cache.
[0096] Alternatively or additionally, the correction operation includes recalculating the second MAC for a plurality of devices of the system memory. Alternatively or additionally, the processor is configured to perform an XOR operation for each of the plurality of devices, where the XOR operation is based on the alternative value and the data in each device excluding one of the plurality of devices. Alternatively or additionally, the processor is configured to: for each device of the system memory, generate an uncorrectable error in response to detecting that the recalculated second MAC does not match the first MAC. Alternatively or additionally, the processor is configured to decrypt a block of data stored in the system memory, where the size of the block corresponds to the size of the input or output of a block cipher, determine that the entropy of the plaintext in the decrypted block of data is higher than a threshold level, and perform a correction command on each device of the system memory storing a portion of the block of data. Alternatively or additionally, the processor includes logic for performing the correction commands in a parallel pipeline, where the parallel pipeline includes generating the second MAC for each device of the system memory using the alternative value. Alternatively or additionally, the processor is configured to generate a block correction value. Alternatively or additionally, the processor is configured to reset the keys for the first MAC and the second MAC in response to the expiration of a predetermined time period.
[0097] Example 2
[0098] In one embodiment, a system for managing encrypted data includes a processor that stores an encrypted first block correction value based on data stored in a system memory in response to a write operation to the system memory. The processor may also detect a read operation corresponding to the data stored in the system memory and calculate a second block correction value based on the data stored in the system memory, the second block correction value being calculated based on an XOR operation including plaintext data stored in the system memory. Additionally, the processor may determine that the second block correction value does not match the decrypted first block correction value, determine that a stored first MAC value does not match a calculated second MAC, and recalculate the second block correction value using a correction operation, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and an alternative value for the device for the system memory. Further, the processor may decrypt the data stored in the system memory in response to detecting that the recalculated second MAC matches the first block correction value and send the decrypted data to a cache device.
[0099] Alternatively or additionally, the processor is used to generate a first MAC based on an XOR operation including ciphertext data stored in the system memory. Alternatively or additionally, the processor is used to decrypt the data stored in the system memory and the first block correction value. Alternatively or additionally, the system includes a single device in the system memory for storing the first block correction value.
[0100] Example 3
[0101] In one example, a method for managing an encrypted memory includes: storing a first Message Authentication Code (MAC) based on data stored in a system memory in response to a write operation to the system memory. The method may also include detecting a read operation corresponding to the data stored in the system memory, calculating a second MAC based on data retrieved from the system memory, and determining that the second MAC does not match the first MAC. Additionally, the method may include recalculating the second MAC after a correction operation, where the correction operation includes an XOR operation based on data retrieved from the system memory and an alternative value for the device for the system memory. Further, the method may include: decrypting the data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC and sending the decrypted data to a cache.
[0102] Alternatively or additionally, the correction operation includes recalculating a second MAC for multiple devices of the system memory. Alternatively or additionally, the method includes performing an XOR operation for each of the multiple devices, where the XOR operation is based on a replacement value and data stored in each of the devices excluding one of the multiple devices. Alternatively or additionally, the method includes: for each device of the system memory, generating an uncorrectable error in response to detecting that the recalculated second MAC does not match the first MAC. Alternatively or additionally, the method includes decrypting a block of data stored in the system memory, where the size of the block corresponds to the size of the input or output of the block cipher, determining that the entropy of the plaintext in the decrypted block of data is higher than a threshold level, and performing a correction command on each device of the system memory storing a portion of the data block. Alternatively or additionally, the method includes performing the correction command in a parallel pipeline, where the parallel pipeline includes generating a second MAC for each device of the system memory using a replacement value. Alternatively or additionally, the method includes generating a block correction value. Alternatively or additionally, the method includes resetting the key or re-encrypting the first MAC and the second MAC based on a new key in response to the expiration of a predetermined time period.
[0103] Example 4
[0104] In one embodiment, a method for managing encrypted data includes: storing an encrypted first block correction value based on data stored in the system memory in response to a write operation to the system memory. The method may further include detecting a read operation corresponding to the data stored in the system memory and calculating a second block correction value based on the data stored in the system memory, the second block correction value being calculated based on an XOR operation including the plaintext data stored in the system memory. Additionally, the method may include determining that the second block correction value does not match the decrypted first block correction value, determining that the stored first MAC value does not match the calculated second MAC, and using a correction operation to recalculate the second block correction value, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and a replacement value for the device of the system memory. Further, the method may include: decrypting the data stored in the system memory in response to detecting that the recalculated second MAC matches the first block correction value and sending the decrypted data to a cache device.
[0105] Alternatively or additionally, the method may include generating a first MAC based on an XOR operation including the ciphertext data stored in the system memory. Alternatively or additionally, the method may include decrypting the data stored in the system memory and the first block correction value. Alternatively or additionally, the method may include using a single device in the system memory to store the first block correction value.
[0106] Example 5
[0107] In some examples, a non - transitory computer - readable medium for managing an encrypted memory includes a plurality of instructions that, when executed by a processor, cause the processor to store a first Message Authentication Code (MAC) based on data stored in a system memory in response to a write operation to the system memory. The processor can also detect a read operation corresponding to the data stored in the system memory, calculate a second MAC based on the data retrieved from the system memory, and determine that the second MAC does not match the first MAC. Additionally, the processor can recalculate the second MAC after a correction operation, where the correction operation includes an XOR operation based on the data retrieved from the system memory and an alternative value for the device of the system memory. Further, the processor can decrypt the data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC and send the decrypted data to a cache.
[0108] Alternatively or additionally, the correction operation includes recalculating the second MAC for a plurality of devices of the system memory. Alternatively or additionally, the processor is configured to perform an XOR operation for each of the plurality of devices, where the XOR operation is based on the alternative value and the data in each device excluding one of the plurality of devices. Alternatively or additionally, the processor is configured to: for each device of the system memory, generate an uncorrectable error in response to detecting that the recalculated second MAC does not match the first MAC. Alternatively or additionally, the processor is configured to decrypt a block of data stored in the system memory, where the size of the block corresponds to the size of the input or output of a block cipher, determine that the entropy of the plaintext in the decrypted data block is higher than a threshold level, and execute a correction command for each device in the system memory storing a portion of the data block. Alternatively or additionally, the processor includes logic for executing the correction command in a parallel pipeline, where the parallel pipeline includes generating the second MAC for each device of the system memory using the alternative value. Alternatively or additionally, the processor is configured to generate a block correction value. Alternatively or additionally, the processor is configured to reset the keys for the first MAC and the second MAC in response to the expiration of a predetermined time period.
[0109] Example 6
[0110] In one embodiment, a non-transitory computer-readable medium for managing encrypted memory includes a plurality of instructions that, when executed by a processor, cause the processor to store an encrypted first block correction value based on data stored in system memory in response to a write operation to the system memory. The processor may also detect a read operation corresponding to the data stored in the system memory and calculate a second block correction value based on the data stored in the system memory, the second block correction value being calculated based on an XOR operation including the plaintext data stored in the system memory. Additionally, the processor may determine that the second block correction value does not match the decrypted first block correction value, determine that a stored first MAC value does not match a calculated second MAC, and use a correction operation to recalculate the second block correction value, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and an alternative value for the device of the system memory. Further, the processor may decrypt the data stored in the system memory in response to detecting that the recalculated second MAC matches the first block correction value and send the decrypted data to a cache device.
[0111] Alternatively or additionally, the processor is configured to generate a first MAC based on an XOR operation including the ciphertext data stored in the system memory. Alternatively or additionally, the processor is configured to decrypt the data stored in the system memory and the first block correction value. Alternatively or additionally, the system includes a single device in the system memory for storing the first block correction value.
[0112] Although example embodiments of the disclosed subject matter have been described with reference to the block diagrams and flowcharts in Figures 1 - 11 , those of ordinary skill in the art will readily recognize that many other methods for implementing the disclosed subject matter may alternatively be used. For example, the order of execution of the blocks in the flowchart may be changed, and / or some of the blocks in the described block diagrams / flowcharts may be changed, eliminated, or combined.
[0113] In the foregoing description, various aspects of the disclosed subject matter have been described. For purposes of explanation, specific numbers, systems, and configurations have been set forth in order to provide a thorough understanding of the subject matter. However, it will be apparent to those skilled in the art who benefit from this disclosure that the subject matter may be practiced without specific details. In other instances, well-known features, components, or modules have been omitted, simplified, combined, or split in order not to obscure the disclosed subject matter.
[0114] The various embodiments of the disclosed subject matter can be implemented in hardware, firmware, software, or a combination thereof, and can be described by reference to the following program code or in conjunction with the following program code: for example, instructions, functions, procedures, data structures, logic, applications, design representations, or formats for design, simulation, and fabrication, which, when accessed by a machine, cause the machine to perform tasks, define abstract data types, or low-level hardware contexts, or produce results.
[0115] The program code can represent hardware using a hardware description language or other functional description language, which substantially provides a model of how the intended design of the hardware will perform. The program code can be assembly language or machine language or a hardware definition language, or data that can be compiled and / or interpreted. Additionally, in the art, software is commonly referred to in one form or another as taking an action or causing a result. Such expressions are merely shorthand ways of stating that the program code is executed by a processing system, which causes the processor to perform the action or produce the result.
[0116] The program code can be stored in, for example, volatile and / or non-volatile memories, such as storage devices and / or associated machine-readable or machine-accessible media, including solid-state memories, hard disk drives, floppy disks, optical storage devices, magnetic tapes, flash memories, memory sticks, digital video disks, digital versatile disks (DVDs), etc., as well as more exotic media such as machine-accessible biometric state-preserving storage devices. Machine-readable media can include any tangible mechanism for storing, sending, or receiving information in a machine-readable form, such as antennas, optical fibers, communication interfaces, etc. The program code can be transmitted in the form of packets, serial data, parallel data, etc., and can be used in a compressed or encrypted format.
[0117] The program code can be implemented in a program that executes on the following programmable machines: for example, mobile or fixed computers, personal digital assistants, set-top boxes, cellular telephones, and pagers, as well as other electronic devices, each of which includes a processor, processor-readable volatile and / or non-volatile memory, at least one input device, and / or one or more output devices. The program code can be applied to data input using the input device to perform the described embodiments and generate output information. The output information can be applied to one or more output devices. One of ordinary skill in the art will recognize that the embodiments of the disclosed subject matter can be practiced using a variety of computer system configurations, including multi-processor or multi-core processor systems, minicomputers, mainframe computers, and pervasive or microcomputers or processors that can be embedded in almost any device. The embodiments of the disclosed subject matter can also be practiced in a distributed computing environment, where tasks can be performed by remote processing devices linked through a communication network.
[0118] Although operations may be described as a sequential process, some of the operations may in fact be performed in parallel, concurrently, and / or in a distributed environment, and program code may be stored locally and / or remotely for access by a single processor machine or a multi-processor machine. Additionally, in some embodiments, the order of operations may be rearranged without departing from the spirit of the disclosed subject matter. The program code may be used by or in conjunction with an embedded controller.
[0119] Although the disclosed subject matter has been described with reference to illustrative embodiments, such description is not intended to be construed in a limiting sense. Various modifications of the illustrative embodiments, as well as other embodiments of the subject matter, which are apparent to those of ordinary skill in the art to which the disclosed subject matter pertains, are considered to be within the scope of the disclosed subject matter.
Claims
1. A system for managing encrypted memory, comprising: a processor for: storing a first Message Authentication Code (MAC) based on data stored in the system memory in response to a write operation to the system memory; detecting a read operation corresponding to the data stored in the system memory; calculating a second MAC based on the data retrieved from the system memory; determining that the second MAC does not match the first MAC; recalculating the second MAC after a correction operation, wherein the correction operation includes an XOR operation based on the data retrieved from the system memory and an alternative value for the device of the system memory; decrypting the data stored in the system memory in response to detecting that the recalculated second MAC matches the first MAC; sending the decrypted data to a cache; decrypting a block of the data stored in the system memory, wherein the size of the block corresponds to the size of the input or output of a block cipher; determining that the entropy of the plaintext in the decrypted data block is higher than a threshold level; and performing the correction operation on each device in the system memory storing a portion of the block of the data.
2. The system according to claim 1, wherein, the correction operation includes recalculating the second MAC for a plurality of devices of the system memory.
3. The system according to claim 2, wherein, the processor is for: performing the XOR operation for each device of the plurality of devices, wherein the XOR operation is based on the alternative value and the data in each device excluding one of the plurality of devices.
4. The system according to claim 1 or 2, wherein, the processor is for: generating an uncorrectable error for each device of the system memory in response to detecting that the recalculated second MAC does not match the first MAC.
5. The system according to claim 1 or 2, wherein, the processor includes logic for performing the correction operation in a parallel pipeline, wherein the parallel pipeline includes generating the second MAC for each device of the system memory using the alternative value.
6. The system according to claim 1 or 2, wherein, the processor is for: generating a block correction value.
7. The system according to claim 1, wherein, the processor is for: resetting the keys for the first MAC and the second MAC in response to the expiration of a predetermined time period.
8. The system according to claim 7, wherein, the processor is for: resetting the keys for the first MAC and the second MAC based on a memory refresh rate, wherein resetting the keys includes: detecting a second read operation; comparing the first MAC with a previously stored key; recalculating the first MAC using a new key; and storing the first MAC encrypted with the new key in the system memory.
9. A system for managing encrypted data, comprising: a processor for: Store an encrypted first block correction value based on data stored in the system memory in response to a write operation to the system memory; Detect a read operation corresponding to the data stored in the system memory; Calculate a second block correction value based on the data stored in the system memory, where the second block correction value is calculated based on an XOR operation including plaintext data stored in the system memory; Determine that the second block correction value does not match the decrypted first block correction value; Determine that the stored first MAC value does not match the calculated second MAC; Recalculate the second block correction value using a correction operation, where the correction operation includes an XOR operation based on the decrypted data stored in the system memory and a replacement value for the device of the system memory; In response to detecting that the recalculated second MAC value matches the first block correction value, decrypt the data stored in the system memory; Send the decrypted data to the cache device; Decrypt a block of the data stored in the system memory, where the size of the block corresponds to the size of the input or output of the block cipher; Determine that the entropy of the plaintext in the decrypted data block is higher than a threshold level; and Perform the correction operation on each device in the system memory storing a portion of the block of the data.
10. The system according to claim 9, wherein, the processor is configured to: generate the first MAC based on an XOR operation including ciphertext data stored in the system memory.
11. The system according to claim 9, wherein, the processor is configured to: decrypt the data stored in the system memory and the first block correction value.
12. The system according to claim 9, 10 or 11, wherein, the system includes a single device in the system memory for storing the first block correction value.
13. A method for managing an encrypted memory, comprising: Store a first message authentication code (MAC) based on data stored in the system memory in response to a write operation to the system memory; Detect a read operation corresponding to the data stored in the system memory; Calculate a second MAC based on the data retrieved from the system memory; Determine that the second MAC does not match the first MAC; Recalculate the second MAC after a correction operation, where the correction operation includes an XOR operation based on the data retrieved from the system memory and a replacement value for the device of the system memory; In response to detecting that the recalculated second MAC matches the first MAC, decrypt the data stored in the system memory; Send the decrypted data to the cache; Decrypt a block of the data stored in the system memory, where the size of the block corresponds to the size of the input or output of the block cipher; Determine that the entropy of the plaintext in the decrypted data block is higher than a threshold level; and Perform the correction operation on each device in the system memory that stores a portion of the block of the data.
14. The method according to claim 13, wherein, the correction operation includes recalculating the second MAC for a plurality of devices of the system memory.
15. The method according to claim 14, comprising: performing the XOR operation on each of the plurality of devices, wherein the XOR operation is based on the replacement value and the data stored in each of the devices from which one of the plurality of devices is excluded.
16. The method according to claim 13 or 14, comprising: for each device of the system memory, in response to detecting that the recalculated second MAC does not match the first MAC, generating an uncorrectable error.
17. The method according to claim 13 or 14, comprising: in response to expiration of a predetermined time period, resetting or re-encrypting the first MAC and the second MAC based on a new key.
18. A non-transitory computer-readable medium storing a plurality of instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 13-17.
19. A computer program product comprising instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 13-17.
Citation Information
Patent Citations
Memory integrity with error detection and correction
US20170185532A1
Self testing and securing ram system and method
US20050283566A1
System and method for error correction and detection in a memory system
US20090006886A1
Method of and apparatus for storing data
US20120317344A1
Method and apparatus for memory encryption with integrity check and protection against replay attacks
US20140223197A1