Method, electronic system and encryption device for encryption

By introducing an encryption offload engine into the interconnect structure for data encryption and decryption, the security and performance issues of data transmission in SED are solved, achieving efficient and secure data storage and verification, and simplifying system design and operation.

CN113190490BActive Publication Date: 2026-04-24SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2021-01-29
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing self-encrypting drives (SEDs) have security and performance issues during data transmission, including the inability to verify whether the data is correctly encrypted, complex key management, encryption calculations consuming host CPU resources, and the ease with which data can be intercepted over long distances.

Method used

The interconnected structure transmits data to the encryption offload engine for encryption and decryption. Peer-to-peer connections are used to store and decrypt encrypted data, reducing the encryption burden on the host and verifying the correctness of the data at the host. This simplifies key management and reduces data transmission distance.

Benefits of technology

It improves the security and performance of data transmission, simplifies system design and operation, reduces the need for proprietary verification mechanisms for different storage devices, lowers the risk of key leakage, and enhances the reliability and scalability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113190490B_ABST
    Figure CN113190490B_ABST
Patent Text Reader

Abstract

Methods, electronic systems, and encryption devices for encryption are disclosed. A method for encryption can include transferring data from a host to an encryption offload engine over an interconnect fabric, encrypting the data from the host at the encryption offload engine, and transferring the encrypted data from the encryption offload engine to a storage device over a peer-to-peer connection in the interconnect fabric. The method can also include transferring the encrypted data from the storage device to the encryption offload engine over the peer-to-peer connection in the interconnect fabric, decrypting the encrypted data from the storage device at the encryption offload engine, and transferring the decrypted data to the host over the interconnect fabric. The method can also include transferring the encrypted data from the storage device to the host, and verifying the encryption of the encrypted data at the host.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority and benefit to U.S. Provisional Patent Application No. 62 / 967,571, entitled “Peripheral Component Interconnect Express (PCIe) Peer-to-Peer (P2P) Encryption Offload,” filed January 29, 2020, and U.S. Patent Application No. 16 / 856,003, filed April 22, 2020, which are incorporated herein by reference. Technical Field

[0002] This disclosure generally relates to encryption, and more specifically, to offloading encryption via an interconnect fabric. Background Technology

[0003] A self-encrypting drive (SED) is a storage device, such as a hard disk drive (HDD) or solid-state drive (SSD), that uses internal encryption to prevent unauthorized access to data stored on the device. An SED may include dedicated hardware to accelerate encryption and decryption processes, ensuring that the SED does not slow down drive access. An SED can be configured to automatically and continuously encrypt data as it is written to the drive and automatically and continuously decrypt data as it is read from the drive, without any intervention from the user or operating system. The acceleration hardware can use one or more encryption keys maintained internally within the drive to encrypt and decrypt data. The SED may request an additional authentication key each time the drive restarts to prevent unauthorized access to data if the drive is removed from the host system. Depending on the implementation, the authentication key may be manually entered by the user into the SED during boot processing, or it may be automatically entered by the Basic Input / Output System (BIOS) or the operating system. Summary of the Invention

[0004] A method may include: transferring data from a host to an encryption offload engine via an interconnect structure; encrypting the data from the host at the encryption offload engine; and transferring the encrypted data from the encryption offload engine to a storage device via a peer-to-peer connection in the interconnect structure. The method may further include: transferring encrypted data from a storage device to the encryption offload engine via a peer-to-peer connection in the interconnect structure; decrypting the encrypted data from the storage device at the encryption offload engine; and transferring the decrypted data to the host via the interconnect structure. The method may also include: transferring encrypted data from the storage device to the host; and verifying the encryption of the encrypted data at the host. Data from the host may have a source address, and the method may further include mapping the source address to the encryption offload engine. The storage device may initiate a peer-to-peer transfer from the encryption offload engine to the storage device in response to a write command from the host, and the encryption offload engine may retrieve data from the host using a mapping table. Data to be sent to the host may have a destination address, and the method may further include mapping the destination address to the encryption offload engine. The storage device can initiate a peer-to-peer transfer from the crypto-offload engine to the storage device in response to a read command from the host, and the crypto-offload engine can use a mapping table to transfer decrypted data to the host.

[0005] A system may include: a host; an encryption offload engine; and an interconnect structure arranged to interconnect the host, the encryption offload engine, and one or more storage devices, wherein the encryption offload engine may be configured to: receive data from the host; encrypt the data received from the host; and send the encrypted data to at least one storage device via a peer-to-peer connection in the interconnect structure. The host may be configured to read encrypted data from the at least one storage device and verify the encryption of the encrypted data. The host may be configured to read encrypted data from the at least one storage device by bypassing a mapping table in the encryption offload engine. The system may further include a commit queue configured to store write commands from the host, and the write command may include the source address of data to be written to the at least one storage device. The host may be configured to map source addresses to the encryption offload engine. The encryption offload engine may be configured to maintain a mapping table to map data used for peer-to-peer transfers with the at least one storage device to addresses in the host. Peer transfers may be associated with write commands from the host. The at least one storage device can be configured to initiate a peer-to-peer transfer from the crypto-offload engine in response to a write command from the host, and the crypto-offload engine can be configured to receive data from the host, encrypt the data received from the host, and send the encrypted data to the at least one storage device in response to the peer-to-peer transfer initiated by the at least one storage device. The crypto-offload engine can also be configured to: receive encrypted data from at least one storage device via a peer-to-peer connection in an interconnect structure; decrypt the encrypted data received from the at least one storage device; and send the decrypted data to the host. The system may further include a submission queue configured to hold read commands from the host, and the read commands may include a destination address for the decrypted data from the at least one storage device. The host can be configured to map the destination address to the crypto-offload engine.

[0006] An encryption device may include: an interface configured to integrate the encryption device into an interconnected system with peer-to-peer capabilities; and a controller integrated into the interface and configured to receive data from a host via the interface, encrypt the data received from the host, and send the encrypted data to a storage device via the interface. The controller may also be configured to: receive encrypted data from the storage device via the interface; decrypt the data received from the storage device; and send the decrypted data to the host via the interface. Attached Figure Description

[0007] The accompanying drawings are not necessarily drawn to scale and are used throughout the drawings. For illustrative purposes, elements with similar structures or functions are generally designated by the same reference numerals. The drawings are intended only to facilitate the description of the various embodiments described herein. The drawings do not depict every aspect of the teachings disclosed herein and do not limit the scope of the claims. To prevent obscurity, not all components, connections, etc., are shown, and not all components are given reference numerals. However, a pattern of component configurations is clear from the drawings. The drawings, together with the specification, illustrate exemplary embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0008] Figure 1 The architecture of a system for storing data on a self-encrypting drive (SED) is shown.

[0009] Figure 2 An embodiment of a system for providing encrypted data storage according to the present disclosure is shown.

[0010] Figure 3 An example embodiment of the cryptographic unloading engine according to this disclosure is shown.

[0011] Figure 4 An example embodiment of a system for providing encrypted data storage according to this disclosure is shown.

[0012] Figure 5 An example embodiment of a host system according to this disclosure is shown.

[0013] Figure 6 An embodiment of a method for storing encrypted data in a storage device according to the present disclosure is shown.

[0014] Figure 7 An embodiment of a method for reading encrypted data from a storage device according to the present disclosure is shown.

[0015] Figure 8 An embodiment of a method for verifying encryption of data stored on a storage device according to the present disclosure is shown.

[0016] Figure 9 An embodiment of a device that can be used to implement a controller for an encryption offloading engine, according to the present disclosure, is shown. Detailed Implementation

[0017] In some embodiments according to this disclosure, data can be transferred from the host to an encryption offload engine via an interconnect fabric. The encryption offload engine can encrypt the data and transfer the encrypted data to a storage device via a peer-to-peer (P2P) connection in the interconnect fabric. Depending on the implementation details, this can improve performance and security by enabling the host to offload encrypted computations without having to trust the self-encrypting driver (SED). During a verification operation, the host can bypass the encryption offload engine and read the encrypted data directly from the storage device to verify that the encrypted data has been correctly encrypted.

[0018] Figure 1 The architecture of a system for storing data at the SED is shown. Figure 1 The system shown may include a host 100 having a central processing unit (CPU) 102, which may be incorporated into or integrated with a peripheral component interconnect fast (PCIe) root complex 104. System memory (or memory) 106 may be incorporated into the CPU 102, for example, via the root complex 104. A PCIe switch 108 may be incorporated into or integrated with the root complex 104. The PCIe switch 108 may be arranged to incorporate any number of solid-state drives (SSDs) 110 into the root complex 104. Each of the SSDs 110 may have internal encryption (ENC) / decryption (DEC) hardware 112 to enable the drive (e.g., SSD 110) to operate as an SED. The PCIe switch 108 and any PCIe interconnected with the PCIe switch 108 may be collectively referred to as a PCIe fabric. Figure 1 The system shown can implement the Non-Volatile Memory Fast (NVMe) protocol, enabling high-speed data transfer between the SSD 110 and the host 100 via a PCIe architecture.

[0019] A self-encrypting storage operation can begin when users, applications, drives, kernels, etc., at host 100 send unencrypted (i.e., clean or plaintext) data to one of SSDs 110 via the PCIe structure. Upon arrival at SSD 110, encryption / decryption hardware 112 can encrypt the data from the host using one or more encryption keys that can reside in SSD 110. The encrypted data can then be stored in a solid-state storage medium (such as one or more flash memory devices).

[0020] Upon receiving a read command from host 100, any of the SSDs 110 can retrieve the requested data in an encrypted version from its storage medium. The encrypted data can then be decrypted by encryption / decryption hardware 112 using one or more encryption keys residing in the SSD 110. The decrypted data can then be transmitted to host 100 via a PCIe structure.

[0021] As mentioned above Figure 1 The described architecture and operation enable encryption and decryption to be performed in real time at PCIe bus speed without slowing down data reads and / or writes to the SSD 110. However, this architecture and / or operation may have one or more potential security issues. For example, in some systems, unencrypted data may be transferred from the SSD 110 to the host 100, and therefore, the host 100 may not be able to verify whether encrypted (ciphertext) data stored on or on the storage medium in the SSD 110 has been correctly encrypted.

[0022] Some SEDs (Secure Data Encryption Devices) can provide authentication mechanisms that enable a host to access encrypted data as it is stored on the storage medium. However, these authentication mechanisms can be difficult to utilize because each SED manufacturer implements different proprietary solutions for accessing encrypted data. Furthermore, even after gaining access to the stored ciphertext, the host may need to obtain one or more encryption keys used during the encryption process from the SED to verify that the encryption was performed correctly. However, obtaining one or more encryption keys can be difficult because the SED may, for example, wrap one or more encryption keys with a hardware root of trust using an application-specific integrated circuit (ASIC) in the controller used for the SED.

[0023] Such as Figure 1 Another potential problem with the system shown is that, because each SED may need to support the management of one or more encryption keys, there is a possibility of key escrow operations occurring in one or more of the SEDs (e.g., in the system-on-a-chip (SOC) of the controller used for the SED). This provides additional opportunities for encryption keys to be leaked.

[0024] Such as Figure 1 Another potential problem with the system shown is that in some implementations, the SSD 110 may be located at a relatively long distance from the host 100 within a chassis, rack, data center, or similar facility. Since unencrypted data may have to traverse these extended distances, this could provide additional opportunities for unauthorized entities to intercept the data.

[0025] In some systems, data can be encrypted at host 100 and transferred across the PCIe fabric to SSD 110. Therefore, host 100 may not need to trust any of the SSDs 110. Furthermore, if any data is intercepted by an unauthorized entity within the PCIe fabric, that data may have already been encrypted. However, performing encryption and decryption calculations can overload the host CPU and / or degrade system performance.

[0026] Figure 2 An embodiment of a system for providing encrypted data storage according to the present disclosure is shown. Figure 2 The system shown may include a host 120, an encryption offload engine 122, and an interconnect structure 124, which is arranged to interconnect with the host 120, the encryption offload engine 122, and one or more storage devices 126. The interconnect structure 124 may have peer-to-peer (P2P) capability to enable one or more peer-to-peer connections between various devices through the interconnect structure 124.

[0027] In some embodiments, during a storage write operation, the encryption offload engine 122 can be configured to receive unencrypted data from host 120, encrypt the data received from host 120, and transmit the encrypted data to one of the storage devices 126, for example, via peer connection 128 in interconnect structure 124. The storage device 126 can store the encrypted data in a storage medium within the device.

[0028] In some embodiments, during a storage read operation, storage device 126 can retrieve encrypted data from storage media within the device and send the encrypted data to encryption offload engine 122, for example, via the same peer connection 128 or a different peer connection in interconnect structure 124. Encryption offload engine 122 can then decrypt the encrypted data received from storage device 126 and send the decrypted data back to host 120 via interconnect structure 124.

[0029] In some embodiments, during the verification operation, storage device 126 can retrieve encrypted data from the storage medium within the device and send the encrypted data to host 120, thereby bypassing the encryption offload engine 122. Host 120 can then verify whether the encrypted data stored at storage device 126 has been correctly encrypted.

[0030] Therefore, depending on the implementation details, Figure 2 The system shown can address some or all of the security and / or performance concerns discussed above. For example, because encryption and decryption for write and read operations can be separated from host 120, the encryption / decryption burden on host 120 can be reduced or eliminated, and / or system performance can be improved.

[0031] As another example, because encryption and / or decryption and / or authentication can be performed independently of storage device 126, storage device 126 can read and / or write already encrypted data. This reduces or eliminates the need to use any built-in authentication mechanisms that may exist in storage device 126 to obtain access to encrypted (ciphertext) data as it is stored in the storage medium. This simplifies the system design process and / or operation, and / or reduces or eliminates the need to accommodate different proprietary authentication mechanisms that may be implemented by different storage device manufacturers. Furthermore, performing encryption and / or decryption and / or authentication independently of storage device 126 reduces or eliminates the need to obtain one or more encryption keys used by storage device 126 during encryption processing.

[0032] As another example, performing encryption and / or decryption and / or verification independently of storage device 126 can reduce or eliminate concerns about the possibility of key escrow operations in one or more of storage devices 126.

[0033] As another example, in some embodiments, the encryption offload engine 122 may be located relatively close to the host 120. Therefore, unencrypted data may only need to traverse a relatively short distance across the interconnect structure 124 between the host 120 and the encryption offload engine 122. In contrast, if any of the storage devices 126 are located at a relatively long distance from the host 120 and / or the encryption offload engine 122, data traversing these longer distances may have already been encrypted by the encryption offload engine 122, thereby reducing the risk of data leakage should it be intercepted by an unauthorized entity.

[0034] Refer again Figure 2The interconnect structure 124 can be implemented using any suitable interconnect medium, device, protocol, or combination thereof. For example, in some embodiments, the interconnect structure 124 can be implemented using the Non-Volatile Memory Fast (NVMe) protocol via Peripheral Component Interconnect Fast (PCIe) links. In such a PCIe / NVMe embodiment, the interconnect structure 124 may include any number of PCIe switches, bridges, retimers, links, channels, etc., and / or any combination of PCIe switches, bridges, retimers, links, channels, etc., which can be arranged in any topology and configured to transmit data via any arrangement and / or combination of hierarchical (tree) and / or peer-to-peer connections. In such a PCIe / NVMe embodiment, data transmission can be initiated using commit queues (SQs) that can be maintained at one or more locations throughout the system. For example, in some embodiments, one or more commit queues may be maintained in memory provided by one or more storage devices in host 120 and / or storage device 126.

[0035] However, in other embodiments, interconnect structure 124 can be implemented using any other suitable interconnect media, devices, protocols, combinations thereof, etc. Examples may include Peripheral Component Interconnect (PCI), AT Accessory (ATA), Serial ATA (SATA), Small Computer System Interface (SCSI), Serial Attached SCSI (SAS), Ethernet, Fibre Channel, InfiniBand, OCuLink, NVMe over Fabric (NVMe-oF), etc. Interconnect structure 124 may be able to provide peer-to-peer connectivity and / or communication between components. Interconnect structure 124 can be implemented using segments with different interconnect media, devices, protocols, combinations thereof, etc., and each segment may include any combination of bridges, converters, switches, hubs, cables, traces, connectors, etc., arranged in any topology and connected between and / or within segments.

[0036] The encryption offload engine 122 can be implemented using hardware, software, firmware, and / or any combination thereof. In some embodiments, the encryption offload engine 122 can be implemented as a standalone component, for example, as an insert card or module that can interface with the interconnect structure 124 by being inserted into a PCI slot, PCIe slot, M.2 slot, U.2 connector, SATA connector, SAS connector, OCuLink connector, or other slots or connectors located on a motherboard, backplane, midplane, module, or combination thereof. In some other embodiments, the encryption offload engine 122 can be implemented as a module that can be connected to the interconnect structure 124 via a cable and / or connector interface. In some embodiments, the encryption offload engine 122 can be integrated into another component, such as a PCIe switch, root complex, motherboard, insert card or adapter card or insert module or adapter module, backplane, midplane, or combination thereof. The encryption offload engine 122 can utilize any suitable encryption / decryption technology and / or algorithm, such as a 128-bit or 256-bit Advanced Encryption Standard (AES) algorithm using symmetric and / or asymmetric encryption and / or authentication keys or any combination thereof.

[0037] Host 120 can be implemented using any device and / or system that requires data to be stored in an encrypted format. Examples may include one or more CPUs located on one or more motherboards in a server, server rack, desktop or laptop computer, mobile device, Internet of Things (IoT) device, or a combination thereof.

[0038] Storage device 126 can be implemented using any storage medium, including magnetic media, flash memory devices, persistent storage devices, and combinations thereof, with any form factor, including 3.5-inch, 2.5-inch, M.2, U.2, next-generation small form factor (NGSFF), and combinations thereof, and using any interface medium, device, protocol, and combination thereof, with hard disk drives (HDDs), solid-state drives (SSDs), hybrid drives, and combinations thereof.

[0039] Figure 3 An example embodiment of an encrypted offloading engine according to this disclosure is shown. Figure 3In the illustrated embodiment, the encryption offloading engine 130 may include an interface 132 configured to integrate the encryption offloading engine 130 with other components (such as a host and / or storage device) via an interconnect structure. Interface 132 may enable peer-to-peer connectivity and / or communication between the encryption offloading engine 130 and one or more other components via the interconnect structure. The encryption offloading engine 130 may also include a controller 134, which may be integrated with interface 132 and may include an encryption processor 136. Controller 134 may be configured to receive data from the host via interface 132, encrypt the data received from the host using encryption processor 136, and send the encrypted data to the storage device via interface 132. Controller 134 may also be configured to receive encrypted data from the storage device via interface 132, decrypt the data received from the storage device using encryption processor 136, and send the decrypted data to the host via interface 132.

[0040] In some embodiments, controller 134 may also include a mapping table 138, which may be used, for example, to determine the source and / or destination locations of unencrypted (plaintext) data within the host.

[0041] Encryption operations in the encryption offloading engine 130 can be initiated in various ways based on the principles of this disclosure. For example, in some embodiments, encryption operations can be initiated when a storage device initiates peer-to-peer data transfer from the encryption offloading engine 130 to the storage device by sending a peer request to the encryption offloading engine 130. (The peer request from the storage device may have been prompted by a command received from, for example, a host.) Upon receiving the data transfer request from the storage device, the controller 134 in the encryption offloading engine 130 can use source information it may have received from the storage device and / or information in the mapping table 138 to request unencrypted data from the data source address in the host. Upon receiving the unencrypted data from the host, the controller 134 can encrypt the data received from the host using the encryption processor 136 and send the encrypted data to the storage device via interface 132, thereby completing the peer transfer requested by the storage device.

[0042] In some other embodiments, encryption operations in the encryption offloading engine 130 can be initiated directly by a host capable of sending commands to the encryption offloading engine 130, instructing the encryption offloading engine 130 to encrypt data from the host and send the encrypted data to a storage device. In such embodiments, peer-to-peer transmission of encrypted data from the encryption offloading engine 130 to the storage device can be initiated by the encryption offloading engine 130.

[0043] Similarly, decryption operations in the encryption offloading engine 130 can be initiated in various ways according to the principles of this disclosure. For example, in some embodiments, a decryption operation can be initiated when the storage device initiates peer-to-peer data transfer by sending encrypted data to the encryption offloading engine 130. (The peer-to-peer transfer from the storage device may have been prompted by a command received from, for example, a host.) Upon receiving encrypted data from the storage device, the controller 134 in the encryption offloading engine 130 can decrypt the data using the encryption processor 136. The controller 134 can then use destination information that it may have received from the storage device and / or information contained in the mapping table 138 to transmit the decrypted data to the host, thereby transmitting the decrypted data to its destination location in the host.

[0044] In some other embodiments, the decryption operation in the crypto-unloading engine 130 can be directly initiated by a host capable of sending commands to the crypto-unloading engine 130, instructing the crypto-unloading engine 130 to request encrypted data from a specific storage device, decrypt the encrypted data, and transmit the decrypted data to the host. In such embodiments, peer-to-peer transmission of encrypted data from the storage device to the crypto-unloading engine 130 can be initiated by the crypto-unloading engine 130.

[0045] In some embodiments, the encryption offloading engine 130 may not participate in the verification operation, as the purpose may be to verify the correctness and / or integrity of the encryption / decryption operation. However, to facilitate the verification operation, the host may request copies of one or more encryption keys from the encryption offloading engine 130.

[0046] The controller 134 can also implement one or more authentication processes. For example, each time the cryptographic offload engine 130 is restarted, initialized, reconfigured, etc., the controller 134 can request an authentication key from one or more hosts. Depending on the implementation details, the authentication key can be manually entered into the cryptographic offload engine 130 by a user via a host, or it can be automatically entered into the cryptographic offload engine 130 by, for example, the basic input / output system (BIOS) or operating system on the host during the boot process.

[0047] and Figure 2 The embodiment of the encryption offloading engine 122 shown is the same. Figure 3 The embodiments shown can be implemented using hardware, software, firmware, and / or any combination thereof. Figure 3 The embodiments shown can use one or more interfaces for any interconnect medium, device, protocol, combination thereof, etc. Figure 3 The embodiments shown can be implemented as a standalone component with any shape factor, or integrated into one or more other components. Figure 3The embodiments shown can utilize any encryption / decryption techniques and / or algorithms, combinations thereof, etc. Interface 132 may include any number of ports for the same or different interconnect structures.

[0048] Figure 4 An example embodiment of a system for providing encrypted data storage according to this disclosure is shown. For illustrative purposes, it can be described in the context of a system in which the NVMe protocol can be implemented on top of a PCIe interconnect architecture. Figure 4 The embodiments shown are illustrated. However, the inventive principles of this disclosure are not limited to these implementation details.

[0049] Figure 4 The system shown may include a host 160 having a central processing unit (CPU) 162, which may be incorporated into or integrated with a PCIe root complex 164. System memory (or memory) 166 may be incorporated into the CPU 162, for example, via the root complex 164. A PCIe switch 168 may be integrated into or incorporated into the root complex 164 via a PCIe link 165. The PCIe switch 168 may be arranged to incorporate any number of solid-state drives (SSDs) 170 into the root complex 164 via a PCIe link 167. The PCIe switch 168 and anything interconnected or linked to the PCIe switch 168 may be collectively referred to as PCIe fabrication 169. The PCIe root complex 164 may be implemented as, for example, a means to connect one or more host component interfaces to the PCIe fabrication 169. PCIe root complex 164 can, for example, generate and / or monitor transactions between the host and other components attached to PCIe fabric 169, as well as among other components attached to PCIe fabric 169, via P2P transactions. The system may also include an encryption offload engine 172 coupled to PCIe switch 168 via PCIe link 173. Encryption offload engine 172 can, for example, use the methods described in this disclosure, including... Figure 2 , Figure 3 Implemented by any of the embodiments shown in the examples. Figure 4 The components of the system shown can implement the NVMe protocol to enable high-speed data transfer between the host 160, the crypto-offset engine 172, and / or the SSD 170 via PCIe fabric 169. Any PCIe link can be implemented with any number of channels to accommodate varying amounts of data traffic between the components and to provide scalability based on the needs of the various components. The system may also include one or more additional crypto-offset engines to accommodate additional data traffic and / or encryption / decryption workloads as more storage capacity may be added to the system.

[0050] Figure 5 An example embodiment of a host system according to this disclosure is shown. Figure 5 The embodiments shown can be used, for example, to implement Figure 4 The host 160 shown is shown.

[0051] Reference Figure 5 Host 180 may include CPU 182 and PCIe root complex (or, referred to as root complex) 184. Host 180 may also include system memory, which may include a region (e.g., write buffer) 188 allocated for a write buffer to hold data to be written to one or more storage devices and a region (e.g., read buffer) 190 allocated for a read buffer to hold data read from storage devices. System memory may also include another region (e.g., queue) 192 allocated for queues such as commit queue 194 and completion queue 196, which may be used, for example, to facilitate NVMe transactions with storage devices and / or an encryption offload engine. Root complex 184 may include any number of PCIe links 198, which may be configured to interface host 180 to any PCIe device. If host 180 is used to implement... Figure 4 The host 160 shown may include a PCIe link 165 to connect the root complex 184 to the PCIe switch 168. In some other embodiments, the PCIe switch 168 may be integrated into the root complex 184, and other components such as an encryption offload engine and one or more storage devices may be directly connected to the root complex 184 via a PCIe link 198.

[0052] Figure 6 An embodiment of a method for storing encrypted data in a storage device according to the present disclosure is shown. For example, it can be... Figure 4 The system described in the context of the system shown Figure 6 In one embodiment, host 160 can be used Figure 5 The host 180 shown is used to implement this, and the cryptographic offloading engine 172 can be used... Figure 3 The encryption offloading engine 130 shown is used for this purpose. However, Figure 6 The inventive principles of the embodiments shown are not limited to these or any other implementation details.

[0053] Reference Figure 6At element 200, the method can begin, wherein host 180 can place write command 193 into commit queue 194. Write command 193 may include the source address 195 of data to be written to SSD 170. Source address 195 may be in the form of, for example, a Physical Region Page (PRP), a Distributed Collection List (SGL), or any other form. At element 202, SSD 170 can read write command 193 including source address 195 from commit queue 194. However, host 180 may map source address 195 to crypto-offload engine 130 instead of mapping source address 195 to a location in write buffer 188. Therefore, at element 204, SSD 170 can initiate a peer-to-peer transfer from crypto-offload engine 130 to SSD 170 via PCIe structure 169. At element 206, crypto-offload engine 130 can use mapping table 138 to retrieve data from the mapped location in write buffer 188 in host 180. At element 208, the encryption offload engine 130 can encrypt data from the host 180 using the encryption processor 136. At element 210, the encryption offload engine 130 can transfer the encrypted data to the SSD 170, thus completing a peer-to-peer transaction. At element 212, the SSD 170 can write the encrypted data to its storage medium. At element 214, the SSD 170 can place a completion message in the completion queue 196, thus signaling the completion of the write operation.

[0054] Figure 7 An embodiment of a method for reading encrypted data from a storage device according to the present disclosure is shown. For example, it can be... Figure 4 The system described in the context of the system shown Figure 7 In one embodiment, host 160 can be used Figure 5 The host 180 shown is used to implement this, and the cryptographic offloading engine 172 can be used... Figure 3 The encryption offloading engine 130 shown is used for this purpose. However, Figure 7 The inventive principles of the embodiments shown are not limited to these or any other implementation details.

[0055] Reference Figure 7At element 220, the method can begin, wherein host 180 can place read command 197 into commit queue 194. Read command 197 may include destination address 199 of data to be read from SSD 170. Destination address 199 may be, for example, in the form of PRP, SGL, or any other form. At element 222, SSD 170 can read read command 197 including destination address 199 from commit queue 194. At element 224, SSD 170 can read encrypted data from the storage medium of SSD 170. However, host 180 may map destination address 199 to encryption offload engine 130 instead of mapping destination address 199 to a location in read buffer 190. Therefore, at element 226, SSD 170 may initiate a peer-to-peer transfer in which SSD 170 sends encrypted data to encryption offload engine 130 via PCIe structure 169. At element 228, the crypto-offload engine 130 can use the crypto-processor 136 to decrypt encrypted data from the SSD 170, thereby completing the peer-to-peer service. At element 230, the crypto-offload engine 130 can use the mapping table 138 to transfer the decrypted data to the mapped location in the read buffer 190 in the host 180. At element 232, the crypto-offload engine 130 can place a completion message in the completion queue 196, thereby signaling the completion of the read operation.

[0056] Figure 8 An embodiment of a method for verifying encryption of data stored on a storage device according to this disclosure is shown. For example, it can be... Figure 4 The system described in the context of the system shown Figure 8 In one embodiment, host 160 can be used Figure 5 The host 180 shown is used to implement this, and the cryptographic offloading engine 172 can be used... Figure 3 The encryption offloading engine 130 shown is used for this purpose. However, Figure 8 The inventive principles of the embodiments shown are not limited to these or any other implementation details.

[0057] Reference Figure 8 At element 234, the method can begin, wherein host 180 can place read command 197 into submission queue 194. Read command 197 may include destination address 199 of data to be read from SSD 170. Destination address 199 may be in the form of, for example, PRP, SGL, or any other form. At element 236, SSD 170 can read read command 197 including destination address 199 from submission queue 194. At element 238, SSD 170 can read encrypted data from the storage medium of SSD 170.

[0058] However, during the verification operation, host 180 can directly map destination address 199 to a location in read buffer 190 at host 180, thereby bypassing mapping table 138 in encryption offload engine 130. Therefore, at element 240, SSD 170 can directly transfer encrypted (ciphertext) data to host 180 via PCIe structure 169. At element 242, host 180 can perform its own decryption calculation to verify whether the data stored in encrypted form at SSD 170 is correctly encrypted.

[0059] In some embodiments, host 180 may use copies of one or more encryption keys maintained at host 180 to perform its own decryption calculations for authentication purposes. In some other embodiments, host 180 may request copies of one or more encryption keys from encryption offloading engine 130. In some embodiments, encryption keys may be managed using any conventional or custom key management techniques at encryption offloading engine 130, host 180, another component, or a combination thereof.

[0060] In some embodiments, the mapping table 138 may be maintained by the crypto-unloading engine 130 based on mapping information provided by the host 180. For example, during a reboot operation, the host 180 may provide mapping information so that the crypto-unloading engine 130 can construct an initial mapping table 138, which may be periodically updated based on updated mapping information provided by the host 180.

[0061] In some embodiments, data may be encrypted and / or decrypted at the block level and / or sector level, transferred to and from storage devices, and / or authenticated. These operations may be performed and / or supervised, for example, by a device driver that can operate transparently to users, applications, file systems, etc., and / or combinations thereof, who may not be aware of the encryption. In some other embodiments, data may be encrypted and / or decrypted at the file level, object level (e.g., using key / value storage), or combinations thereof, transferred to and from storage devices, and / or authenticated.

[0062] In some embodiments, the cryptographic offload engine can operate independently of the host and / or storage device and manage address translation to maintain an encrypted shadow of plaintext user data.

[0063] As described above and depending on the implementation details, various embodiments of this disclosure can provide a reliable, flexible, scalable, and / or trustworthy solution for storing data in encrypted form in one or more storage devices.

[0064] Figure 9 Embodiments of a device according to this disclosure that can be used to implement a controller for an encryption offloading engine are shown. For example, Figure 9 The device 300 shown can be used to implement Figure 3 The controller 134 is shown. Device 300 may include CPU 302, memory 304, storage device 306, encryption processor 307, management interface 308, and interconnect interface 310. For example, in some embodiments, all functionality of the encryption offloading engine may be implemented entirely by CPU 302 using software stored in storage device 306, without using any hardware acceleration such as that provided by encryption processor 307. In some other embodiments, encryption and / or decryption may be performed primarily or entirely by encryption processor 307. The mapping table may be stored in memory 304 for short-term use during operation, and may be stored in storage device 306 to prevent loss of the mapping table during power cycling. In different embodiments, any of these components may be omitted, or may be included in any component and any other type of component copy, or may include any additional number of any components and any additional number of any other type of components.

[0065] CPU 302 may include any number of cores, cache, bus, interconnect interface, and / or controller. Memory 304 may include any arrangement of dynamic and / or static RAM, non-volatile memory (e.g., flash memory), combinations thereof, etc. Storage device 306 may include hard disk drive (HDD), solid-state drive (SSD), any other type of data storage device, and / or any combination thereof. Management interface 308 may include any type of device, such as a switch, keypad, display, connector, combination thereof, etc., which may enable a user to enter or change license codes, update firmware, view event logs, and / or perform any other functions that may help monitor the operation of the encryption offload engine and / or verify its integrity and trustworthiness. Any or all components of system 300 may be interconnected via system bus 301, which may collectively refer to various interfaces including power buses, address and data buses, high-speed interconnects (such as Serial AT Accessory (SATA), Peripheral Component Interconnect (PCI), Peripheral Component Interconnect Fast (PCIe), System Management Bus (SMB)), and any other type of interface that enables components to work locally in one location and / or distributed between different locations. System 300 may also include various chipsets, interfaces, adapters, glue logic, embedded controllers (such as programmable or non-programmable logic devices or arrays, application-specific integrated circuits (ASICs), system-on-a-chip (SOCs), etc.) arranged to enable various components of system 300 to work together to achieve any or all features and / or functions of the cryptographic offloading engine according to this disclosure.

[0066] The embodiments disclosed herein have been described in the context of various implementation details, but the principles of this disclosure are not limited to these or any other specific details. For example, some functions have been described as being implemented by a particular component, but in other embodiments, the function may be distributed across different systems and components in different locations and with various user interfaces. Some embodiments have been described as having specific processes, steps, combinations thereof, etc., but these terms may also include embodiments in which a particular process, step, combination thereof, etc. may be implemented by multiple processes, steps, combinations thereof, etc., or in which multiple processes, steps, combinations thereof, etc., may be integrated into a single process, step, combination thereof, etc. References to components or elements may refer only to a portion of the component or element. Unless clearly stated from the context, the use of terms such as “first” and “second” in this disclosure and claims may be for the purpose of distinguishing the things they modify only and may not indicate any spatial or temporal order. References to a first thing may not imply the existence of a second thing.

[0067] The various details and embodiments described above can be combined to produce additional embodiments based on the inventive principles disclosed in this patent. Since the inventive principles disclosed in this patent can be modified in arrangement and detail without departing from the inventive concept, such changes and modifications are considered to fall within the scope of the following claims.

Claims

1. A method for encryption, the method comprising: Data is transferred from the host to the cryptographic offloading engine via an interconnected structure; Data from the host is encrypted at the encryption offload engine; as well as Encrypted data is transferred from the encryption offload engine to the storage device via peer-to-peer connections in the interconnect architecture. The interconnect structure includes a PCIe switch connecting the encryption offload engine and the storage device. The interconnect structure has peer-to-peer capabilities to provide peer-to-peer connectivity and / or communication between components.

2. The method according to claim 1, further comprising: Encrypted data is transferred from storage devices to the encryption offload engine via peer-to-peer connections in the interconnect architecture. The encrypted data from the storage device is decrypted at the encryption offload engine; as well as The decrypted data is transmitted to the host via an interconnect structure.

3. The method according to claim 1 or 2, further comprising: Transmit encrypted data from the storage device to the host; as well as The correct encryption of the encrypted data is verified at the host.

4. The method according to claim 1, wherein: Data from the host includes the source address; and The method also includes mapping the source address to the cryptographic offloading engine.

5. The method according to claim 4, wherein: The storage device initiates a peer-to-peer transfer from the cryptographic offload engine to the storage device in response to a write command from the host; and The cryptographic offloading engine uses a mapping table to retrieve data from the host.

6. The method according to claim 2, wherein: The data to be sent to the host has a destination address; and The method also includes mapping the destination address to the cryptographic offloading engine.

7. The method according to claim 6, wherein: The storage device initiates a peer-to-peer transfer from the storage device to the cryptographic offload engine in response to a read command from the host; and The encryption offloading engine uses a mapping table to send decrypted data to the host.

8. An electronic system, the system comprising: Host; Encrypted uninstallation engine; as well as The interconnect structure is arranged to interconnect the host, the cryptographic offload engine, and one or more storage devices; The encrypted uninstallation engine is configured as follows: Receive data from the host; Encrypt the data received from the host; and Encrypted data is sent to at least one of the one or more storage devices via a peer-to-peer connection in the interconnect structure. The interconnect structure includes a PCIe switch connecting the encryption offloading engine and the one or more storage devices. The interconnect structure has peer-to-peer capabilities to provide peer-to-peer connectivity and / or communication between components.

9. The electronic system according to claim 8, wherein, The host is configured as follows: Read encrypted data from the at least one storage device; and Verify the correct encryption of the encrypted data.

10. The electronic system according to claim 9, wherein, The host is configured to read encrypted data from the at least one storage device by bypassing the mapping table in the encryption offloading engine.

11. The electronic system according to claim 8, wherein: The system also includes a commit queue configured to store write commands from the host; and The write command includes the source address of the data to be written to the at least one storage device.

12. The electronic system according to claim 11, wherein, The host is configured to map the source address to the cryptographic offload engine.

13. The electronic system according to claim 8, wherein, The cryptographic offloading engine is configured to maintain a mapping table to map data used for peer-to-peer transfers with the at least one storage device to addresses in the host.

14. The electronic system according to claim 13, wherein, Peer-to-peer transfers are associated with write commands from the host.

15. The electronic system according to claim 14, wherein: The at least one storage device is configured to initiate a peer-to-peer transfer from the cryptographic offload engine in response to a write command from the host; and The encryption offloading engine is configured to receive data from the host, encrypt the data received from the host, and send the encrypted data to the at least one storage device in response to the at least one storage device initiating the peer-to-peer transmission.

16. The electronic system according to claim 8, wherein, The encrypted uninstallation engine is also configured as follows: Encrypted data is received from at least one of the one or more storage devices via a peer-to-peer connection in the interconnect structure; Decrypt encrypted data received from the at least one storage device; as well as The decrypted data is sent to the host.

17. The electronic system according to claim 16, wherein: The system also includes a submission queue configured to store read commands from the host; and The read command includes the destination address for the decrypted data from the at least one storage device.

18. The electronic system according to claim 17, wherein, The host is configured to map the destination address to the cryptographic offload engine.

19. An encryption device, the encryption device comprising: An interface is configured to integrate the encryption device into a peer-to-peer interconnected system via an interconnection structure; as well as The controller is integrated with the interface and configured to receive data from the host through the interface; Encrypting data received from the host; and sending the encrypted data to a storage device via an interface using a peer-to-peer connection in the interconnect structure. The interconnection structure includes a PCIe switch connecting the encryption device and the storage device. The interconnection structure has peer-to-peer capability, and the interface can realize peer-to-peer connection and / or communication between the encryption device and one or more other components through the interconnection structure.

20. The encryption device according to claim 19, wherein, The controller is also configured as follows: Receive encrypted data from the storage device via the interface; Decrypt the data received from the storage device; and The decrypted data is sent to the host via the interface.

Citation Information

Patent Citations

  • Method and system for security protocol partitioning and virtualization

    US20080240432A1

  • Architecture for offload of linked work assignments

    US20190317802A1