Non-transitory computer readable medium storing computer readable code for a device, a method for operating a device, and manufacturing a device

A three-tiered counter system addresses replay attacks and storage overhead in data protection by selectively re-encrypting data items based on counter overflows, enhancing data integrity and security with reduced memory usage.

JP2025532483APending Publication Date: 2025-10-01ARM LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025512570
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-07
Filing Date
2023-07-19
Publication Date
2025-10-01

Smart Images

  • Figure 2025532483000001_ABST
    Figure 2025532483000001_ABST
Patent Text Reader

Abstract

An apparatus is provided that includes counter control circuitry that maintains counters associated with a data item, including a minor counter, an intermediate counter, and a major counter. The apparatus also includes a memory protection unit configured to modify the minor counters associated with the data item in response to transferring the data item from secure storage to off-chip storage and to encrypt the data item based on the counters associated with the data item. The memory protection unit also performs an intermediate re-encryption process in response to the minor counter overflowing, the intermediate counters being modified and re-encrypting the data item associated with the intermediate counters. The memory protection unit also performs a major re-encryption process in response to the intermediate counters overflowing, the major counters being modified and re-encrypting each of the data items.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present technique relates to a non-transitory computer-readable medium storing computer-readable code for an apparatus, a method for operating the apparatus, and for the manufacture of the apparatus.

[0002] Some devices include memory protection circuitry configured to perform an encryption process to encrypt a data item in response to a transfer of the data item from secure storage to off-chip storage.

[0003] According to some configurations, a counter control circuit for maintaining a plurality of counters associated with a plurality of data items, the plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; a counter control circuit including a major counter associated with a plurality of data items; 1. A memory protection unit, comprising: In response to a transfer of one of the plurality of data items from the secure storage to the off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process in response to an overflowed minor counter of the plurality of minor counters, the intermediate re-encryption process including modifying an intermediate counter associated with the overflowed minor counter and re-encrypting each of a subset of the plurality of data items associated with the intermediate counter using an encryption process; and a memory protection unit configured to perform a major re-encryption process in response to an overflowed intermediate counter among the plurality of intermediate counters, the major counter being modified to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.

[0004] According to some configurations, there is provided a method of operating an apparatus, the method comprising: a plurality of counters associated with a plurality of data items, the plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; maintaining a plurality of counters, including a major counter associated with a plurality of data items; In response to transferring one of the plurality of data items from the secure storage to the off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process in response to an overflowed minor counter of the plurality of minor counters, the intermediate re-encryption process including: modifying an intermediate counter associated with the overflowed minor counter; and re-encrypting each of a subset of the plurality of data items associated with the intermediate counter using an encryption process; A method is provided that includes performing a major re-encryption process that includes, in response to an overflowed intermediate counter of the plurality of intermediate counters, modifying a major counter to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.

[0005] According to some configurations, a non-transitory computer-readable medium for storing computer-readable code for manufacturing an apparatus, the apparatus comprising: a counter control circuit for maintaining a plurality of counters associated with a plurality of data items, the plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; a counter control circuit including a major counter associated with a plurality of data items; 1. A memory protection unit, comprising: In response to a transfer of one of the plurality of data items from the secure storage to the off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process in response to an overflowed minor counter of the plurality of minor counters, the intermediate re-encryption process including modifying an intermediate counter associated with the overflowed minor counter and re-encrypting each of a subset of the plurality of data items associated with the intermediate counter using an encryption process; and a memory protection unit configured to perform a major re-encryption process in response to an overflowed intermediate counter among the plurality of intermediate counters, the major counter being modified to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process. [Brief explanation of the drawings]

[0006] The technique will be further described, by way of example only, with reference to arrangements thereof illustrated in the accompanying drawings, in which: [Figure 1] 1 illustrates a schematic diagram of a data processing apparatus according to various configurations of the present technique; [Figure 2] 1 illustrates a schematic diagram of a data processing apparatus according to various configurations of the present technique; [Figure 3] 1 illustrates a schematic representation of a data integrity tree according to various configurations of the present technique; [Figure 4] 1 illustrates a schematic representation of a data integrity tree according to various configurations of the present technique; [Figure 5] 1 illustrates a schematic representation of a data integrity tree according to various configurations of the present technique; [Figure 6] 1 illustrates a schematic diagram of a data processing apparatus according to various configurations of the present technique; [Figure 7] 10A-10C show schematic details of a data integrity tree according to various configurations of the present technique; [Figure 8] 10A-10C show schematic details of a data integrity tree according to various configurations of the present technique; [Figure 9] 10A-10C show schematic details of a data integrity tree according to various configurations of the present technique; [Figure 10] 10A-10C show schematic details of a data integrity tree according to various configurations of the present technique; [Figure 11] 1 illustrates a schematic sequence of steps performed by an apparatus according to various configurations of the present technique; [Figure 12] 1 illustrates a schematic diagram of a data processing apparatus according to various configurations of the present technique;

[0007] At least some configurations provide an apparatus including a counter control circuit for maintaining a plurality of counters associated with a plurality of data items, the plurality of counters including a plurality of minor counters each associated with one of the plurality of data items, a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters, and a major counter associated with the plurality of data items. The memory protection unit is configured to modify the corresponding minor counter associated with the data item in response to a transfer of one of the plurality of data items from secure storage to off-chip storage, and thereafter encrypt the data item using an encryption process based on each of the plurality of counters associated with the data item. The memory protection unit is configured to perform an intermediate re-encryption process in response to an overflowed minor counter of the plurality of minor counters, the intermediate re-encryption process including modifying the intermediate counter associated with the overflowed minor counter and re-encrypting each of the subset of the plurality of data items associated with the intermediate counter using the encryption process. The memory protection unit is further configured to perform a major re-encryption process in response to an overflowed intermediate counter among the plurality of intermediate counters, the major re-encryption process including modifying the major counter to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.

[0008] To maintain the integrity and security of data items stored in off-chip storage, some devices perform cryptographic processes to protect the data items from being read by external entities or to provide assurance of the data item's integrity, i.e., to allow the device to verify that the data item has not been altered by an external entity. In particular, it is possible to prevent a data item from being read by encrypting the data item itself based on an on-chip value. Alternatively, or in addition, by creating an encrypted hash of the data item (i.e., stored with the data item, for example) as an encryption process, the integrity of the data item can be determined when the data item is read by transferring the data item from off-chip storage to secure storage, recalculating the encrypted hash of the data item, and comparing it to the previously stored encrypted value. If the data item has been altered, the recalculated encrypted hash value will not match the stored hash value. Such an approach may be vulnerable to replay attacks, in which an attacker attempts to circumvent such systems by resending previously observed data in order to fool the system into believing the altered data is authentic.

[0009] To protect the data items, the device includes a counter control circuit that maintains multiple counters. The multiple counters are used as inputs to an encryption process and are updated in response to the transfer of the data item to off-chip storage. In this way, a different counter value will be used each time data is written to off-chip storage, thereby mitigating replay attacks. A consequence of such an approach is the need to store and maintain a large number of counter values. One approach to reducing the storage overhead associated with counter values ​​is to associate a single counter value with multiple data items. This approach has the disadvantage that each time the counter value is updated, each of the multiple data items must be decrypted using the previous counter value and re-encrypted using the new counter value. The inventors have realized that by providing the multiple counters as different level counters, including a minor counter each associated with one of the multiple data items (the single data item), intermediate counters each associated with the multiple minor counters and the corresponding multiple data items, and a major counter each associated with the multiple intermediate counters and the corresponding multiple data items, it is possible to reduce the storage required per data item while avoiding the need to re-encrypt multiple data items for each access. The data item may be encrypted to generate a message authentication code (MAC) that is used to verify the integrity of the data item.

[0010] Providing counters in this manner means that for each data item protected by the mechanism, at least a minor counter, an intermediate counter, and a major counter are provided. When a minor counter is incremented, only the (single) data item associated with the minor counter needs to be re-encrypted. If a minor counter overflows (due to a particular data item being transferred from secure storage to off-chip storage), the intermediate counter associated with the data item is incremented. Because the encryption process for each data item is based on all counters associated with that data item, all data items associated with intermediate counters need to be re-encrypted. Similarly, if an intermediate counter overflows (due to a particular data item being transferred from secure storage to off-chip storage, also overflowing its associated minor counter), the major counter associated with the data item is incremented. Because the encryption process for each data item is based on all counters associated with that data item, all data items associated with major counters need to be re-encrypted. Providing three tiers of counters (minor, intermediate, and major) allows a sufficient number of counter values ​​to be maintained, providing a highly flexible approach that does not require re-encryption of all data items associated with major counters every time any such data item is accessed.

[0011] In addition to improved flexibility, the use of three-tiered counters can reduce the overhead associated with counters. Considering the alternative of two-tiered counters (minor and major), when a set number of bits is used, two options exist: either a small number of minor counters can be used, or a small number of bits must be provided for each minor counter. In the former case, the number of data items that can be associated with the set number of bits is small (equal to the number of minor counters), while in the latter case, the major counter increments frequently, resulting in memory-intensive rewriting of all data items associated with the major counter. In the present invention, providing intermediate counters makes it possible to provide a large number of minor counters. Because a large number of minor counters are provided, each minor counter has only a small number of bits relative to the set number of bits and can frequently overflow. Overflow of a minor counter increments the intermediate counter, triggering a rewrite of the data item associated with the intermediate counter. This is more memory-intensive than rewriting a single data item, but less memory-intensive than rewriting all data items associated with the major counter. By choosing the total size of the intermediate and minor counters to be large enough, the frequency at which the major counter is incremented (major counter increment / minor counter increment) can be kept at a manageable level.

[0012] In some configurations, the intermediate re-encryption process includes resetting each of a corresponding subset of the plurality of minor counters associated with the intermediate counter before re-encrypting each of the subset of the plurality of data items associated with the intermediate counter, thereby increasing the minimum number of accesses required to cause a subsequent overflow of the minor counter associated with the intermediate counter. In some alternative configurations, the intermediate re-encryption process includes retaining the current value of each of the corresponding subset of the plurality of minor counters associated with the intermediate counter.

[0013] In some configurations, the major re-encryption process includes resetting each of the plurality of intermediate counters before re-encrypting each of the plurality of data items, thereby increasing the minimum number of accesses required to cause a subsequent overflow of one of the plurality of intermediate counters. In some alternative configurations, the major re-encryption process includes retaining the current value of each of the plurality of intermediate counters.

[0014] In some configurations, the major re-encryption process includes resetting each of the plurality of minor counters before re-encrypting each of the plurality of data items, thereby increasing the minimum number of accesses required to cause a subsequent overflow of one of the plurality of minor counters, thereby increasing the number of accesses required to increment one of the plurality of intermediate counters. In some alternative configurations, the major re-encryption process includes retaining the current value of each of the plurality of minor counters.

[0015] The size of the data items may be fixed or variable. However, in some configurations, each of the multiple data items has a size corresponding to the size of a single cache line. A cache line is typically the smallest unit of data transferred between a device and off-chip storage. Therefore, providing counter control circuitry to maintain minor counters at cache line granularity reduces implementation overhead.

[0016] In some configurations, the total number of bits used to store the multiple counters is less than or equal to the number of bits in a single cache line. Storing the multiple counters in a single cache line means that all minor and intermediate counters associated with a major counter can be retrieved from off-chip storage in a single access, and the counters needed to perform encryption and decryption processes for data items associated with the multiple counters can be performed without having to retrieve additional counters from off-chip storage.

[0017] The minor, intermediate, and major counters may be provided as any size. However, in some configurations, each of the plurality of minor counters is a 5-bit counter, and the plurality of intermediate counters includes eight intermediate counters, each of which is an 8-bit counter. In such configurations, a total of two counters to the same data item must be present to trigger an overflow of the minor counter associated with the same data item. 5 Furthermore, a total of two writes to the same data item are required to trigger an overflow of the intermediate counter associated with the same data item. (5+8) As a result, major counter increments are triggered less frequently, reducing the memory-intensive operation required to rewrite all data items associated with the major counter.

[0018] In some configurations, each of the plurality of minor counters is a 3-bit counter and the plurality of intermediate counters includes eight intermediate counters, each of the eight intermediate counters being a 4-bit counter. In such configurations, a total of two inputs to the same data item may be required to trigger an overflow of the minor counter associated with the same data item. 3 Furthermore, a total of two writes to the same data item are required to trigger an overflow of the intermediate counter associated with the same data item. (3+4)writes are required. Using this choice of counter size allows for a larger number of data items to be associated with a counter, for example, for a fixed storage space within a single cache line.

[0019] The above technique can be implemented for cache lines of any size. However, in some configurations, the number of bits in a single cache line is 512 bits. In such a configuration, when each minor counter is a 5-bit counter and the multiple intermediate counters include eight 8-bit counters, the total number of supported data items is 64, corresponding to 64 minor counters (one minor counter for each data item), with eight minor counters associated with each intermediate counter. This requires 64 × 5 = 320 bits for the minor counters and 8 × 8 = 64 bits for the intermediate counters, for a total of 384 bits. The remaining 128 bits are used for the major counter and (optionally) to store any additional metadata associated with the counters. While it is theoretically possible to support 64 data items using only two layers of counters (minor and major), such an arrangement of counters allows for only 6 bits per minor counter (assuming 128 bits are left for the major counter and any additional metadata). As a result, if there were no intermediate counters, the major counter would be used only if any of the minor counters were 2 6 It is incremented once it has been incremented a count of 1. Therefore, providing an intermediate counter can be used to reduce memory overhead.

[0020] In a configuration where a single cache line is 512 bits, if each minor counter is 3 bits and the intermediate counters include eight 4-bit counters, the counters can be associated with 128 data items, with each intermediate counter associated with 16 minor counters. This requires 128 x 3 = 384 bits for the minor counters and 8 x 4 = 32 bits for the intermediate counters, for a total of 416 bits. The remaining 96 bits are used for the major counter and (optionally) to store any additional metadata associated with the counters. Again, while it is theoretically possible to support 128 data items using only two layers of counters (minor and major), such an arrangement only allows for 3 bits per minor counter, resulting in the possibility that any one of the minor counters may be 2 3 When the major counter is incremented, the major counter is incremented, resulting in a large memory overhead that can quickly become prohibitive. Therefore, providing an intermediate counter can be used to increase the number of data items that can be associated with a single 512-bit cache line. By providing counters associated with 128 data items in a single cache line rather than 64 data items in a single cache line, the amount of memory used to store multiple counters is halved. Considering a server that stores 1.5 Tb of data and provides a minor counter for each cache line, the total memory required to store counters associated with this amount of data is reduced from 24 Gb for 64 512-bit cache lines to 12 Gb for 128 512-bit cache lines.

[0021] In some configurations, the major counter is a 64-bit counter. Providing a large counter for the major counter reduces the likelihood that the same set of counter values ​​will be used for encryption. A 64-bit counter is 2 64possible values, which, even when combined with the relatively small minor and intermediate counters, results in a range of encrypted values ​​that are unlikely to be repeated.

[0022] Counters can be implemented in several different ways. In some configurations, each of the multiple counters is implemented as one of a linear feedback shift register, where an overflow corresponds to the linear feedback shift register reaching a predetermined state; a nonlinear feedback shift register, where an overflow corresponds to the nonlinear feedback shift register reaching a predetermined state; or a binary counter, where an overflow corresponds to a binary counter exceeding a predetermined value. A linear / nonlinear feedback shift register is a shift register whose input is a linear / nonlinear function of its previous state. Such a shift register has a finite number of possible states and eventually repeats. A linear / nonlinear feedback shift register is considered to have overflowed when it reaches a certain state, in which case the next counter in the multiple counters is incremented. If a binary counter is used, the binary counter is considered to have overflowed when it exceeds a certain value. In some configurations, the certain value is a maximum value, in which case the binary counter is reset to a minimum value and the next counter in the multiple counters is incremented. In other configurations, the certain value is a value other than the maximum value set in the counter control circuit. In some configurations, different counter levels use different counter implementations. For example, in some configurations, the minor counter may be a linear feedback shift register, and both the intermediate and major counters may be binary counters. In some alternative configurations, all of the counters may be implemented as the same type of counter.

[0023] In some configurations, the encryption process is performed using a combination of each of a plurality of counters associated with the data item as an encryption key. For each data item, there is an associated minor counter, an associated intermediate counter, and an associated major counter. In some configurations, the encryption key is a hash of the combination of each of the plurality of counters associated with the data item. The encryption process may also use a secure key stored in secure storage.

[0024] In some configurations, the combination is a concatenation of each of multiple counters associated with the value. The minor, intermediate, and major counters associated with the data item may be concatenated in any order, and may be concatenated before or after a hash is applied to the counters.

[0025] In some configurations, the combination is an addition of the values ​​stored in each of a plurality of counters associated with the data item. In some configurations, each of the plurality of counters is hashed before the hashed counter values ​​are added together. In some configurations, a combination of concatenation and addition is used to combine the counters to generate the encryption key. In some configurations, minor and intermediate counters associated with the data item are concatenated and the result is added to a major counter.

[0026] The plurality of counters is not limited to three layers. In some configurations, the plurality of intermediate counters include a plurality of layers of intermediate counters arranged as part of a hierarchical tree structure comprising a major counter, a plurality of layers of intermediate counters, and a plurality of minor counters, each intermediate counter of one of the plurality of layers being associated with a plurality of lower-level counters associated with a successively lower layer of the hierarchical structure, and the memory protection unit, in response to an overflowed lower-level counter of a corresponding subset of the plurality of lower-level counters, performs a next-level re-encryption process including modifying a next-level counter associated with the overflowed lower-level counter and re-encrypting each of the subsets of the plurality of data items associated with the next-level counter. The separation of the intermediate counters into multiple layers of intermediate counters provides an additional level of flexibility. In such configurations, each data item is associated with a minor counter, a major counter, and one intermediate counter from each layer of intermediate counters.

[0027] In some configurations, the memory protection engine and secure storage are integrated on the same chip. The memory protection engine and secure storage may be implemented as separate logic blocks integrated as separate units within the same chip. Alternatively, a single logic block can be provided that provides the functionality of both the secure storage and the memory protection engine. In some configurations, the counter control circuitry is also integrated on the same chip and may be provided as a separate circuit or as a combined logic block that functions as one or more of the secure storage and the memory protection engine. Integrating the memory protection engine and secure storage on the same chip provides additional security because it is difficult to forge information to perform an attack within the chip.

[0028] In some configurations, the counters are stored in secure storage. Storing the counters in secure storage avoids the need to encrypt or otherwise protect the counters. In some alternative configurations, the counters are stored off-chip and encrypted using a master key stored in secure storage. This approach avoids the need to provide a large area of ​​secure storage for the counters.

[0029] In some configurations, each data item is associated with a single minor counter, at least one intermediate counter, and a major counter. If multiple tiers of intermediate counters are provided, each data item is associated with one intermediate counter from each of the multiple tiers of intermediate counters.

[0030] In some configurations, the memory protection unit is configured to decrypt encrypted data items transferred from the off-chip storage to the secure storage using a decryption process based on each of a plurality of counters associated with the encrypted data items. In this manner, the memory protection unit ensures that unencrypted data is stored in the secure storage and that only encrypted versions of the data are stored in the off-chip storage.

[0031] In some configurations, the multiple counters correspond to a single node in a data integrity tree, and the data integrity tree comprises multiple nodes each storing a corresponding multiple counters, where at least one node of the multiple nodes is an intermediate node associated with a corresponding set of data items, and each data item comprises a further node of the multiple nodes. The data integrity tree comprises multiple nodes arranged in a tree-like structure having a single root node, (optionally) one or more intermediate-level nodes, and leaf nodes. Each of the multiple nodes comprises multiple counters. The data items associated with the counters of the root node and (optional) intermediate-level nodes are lower-level nodes of the data integrity tree. The data items associated with the counters of the leaf nodes are data items to be protected. In this manner, each data item is protected by a counter included in a leaf node of the multiple nodes, and each node of the data integrity tree is protected by a counter included in a layer of nodes closer to the root node. The counter of the root node is stored in secure storage. Thus, each node of the multiple nodes is protected by a node one layer closer to the root node. Placing multiple counters within the nodes of the data integrity tree provides a means to increase the number of data items that are protected while maintaining only one set of counters in secure storage.

[0032] The concepts described herein may be embodied in computer-readable code for the manufacture of devices embodying the described concepts. For example, the computer-readable code may be used in one or more stages of the semiconductor design and manufacturing process, including Electronic Design Automation (EDA) stages, to manufacture integrated circuits comprising devices embodying the concepts. Such computer-readable code may additionally or alternatively enable the definition, modeling, simulation, verification, and / or testing of devices embodying the concepts described herein.

[0033] For example, computer-readable code for producing a device embodying the concepts described herein may be embodied in code defining a Hardware Description Language (HDL) representation of the concept. For example, the code may define a Register-Transfer-Level (RTL) abstraction of one or more logic circuits to define a device embodying the concept. The code may define an HDL representation of one or more logic circuits embodying the device in intermediate representations such as Verilog, SystemVerilog, Chisel, or Very High-Speed ​​Integrated Circuit Hardware Description Language (VHDL) and FIRRTL. The computer-readable code may provide a definition embodying the concept using system-level modeling languages ​​such as SystemC and SystemVerilog or other behavioral representations of the concept that can be interpreted by a computer to enable simulation, functional and / or formal verification, and testing of the concept.

[0034] Additionally or alternatively, the computer-readable code may define a low-level description of integrated circuit components embodying the concepts described herein, such as one or more netlists or integrated circuit layout definitions, including representations such as GDSII. One or more netlists or other computer-readable representations of the integrated circuit components may be generated by applying one or more logic synthesis processes to the RTL representations to generate definitions used to manufacture devices embodying the invention. Alternatively or additionally, the one or more logic synthesis processes may generate a bitstream from the computer-readable code that is loaded into a Field Programmable Gate Array (FPGA) to configure the FPGA to embody the described concepts. The FPGA may be deployed for concept verification and testing purposes prior to fabrication in an integrated circuit, or the FPGA may be deployed directly into a product.

[0035] The computer readable code may include a mixture of code representations for fabricating a device, including, for example, a mixture of one or more of an RTL representation, a netlist representation, or another computer readable definition used in a semiconductor design and manufacturing process to fabricate a device embodying the invention. Alternatively or additionally, a concept may be defined in a combination of a computer readable definition used in a semiconductor design and manufacturing process to fabricate a device and computer readable code that defines instructions to be executed by the defined device once fabricated.

[0036] Such computer readable code may be disposed on any known transitory computer readable medium (such as wired or wireless transmission of code over a network) or on a non-transitory computer readable medium such as a semiconductor, magnetic disk, or optical disk. Integrated circuits manufactured using computer readable code may include one or more components such as a central processing unit, graphics processing unit, neural processing unit, digital signal processor, or other components that individually or collectively embody the concepts.

[0037] A particular configuration of the present technique will now be described with reference to the figures.

[0038] FIG. 1 schematically illustrates an apparatus 10 according to some configurations of the present technology. The apparatus 10 includes a counter control circuit 12 and a memory protection unit 16. The counter control circuit 12 is configured to maintain and update a plurality of counters. The counters include a minor counter, an intermediate counter, and a major counter. The memory protection unit 16 is configured to control encryption of data transferred from the secure memory 14 to the off-chip memory 18. Each data item is associated with a minor counter, at least one intermediate counter, and a major counter. The encryption of data by the memory protection unit 16 is performed based on the counters associated with the data item. Furthermore, when a data item is transferred from the secure memory 14 to the off-chip memory 18, the memory protection unit 14 is configured to modify the counter associated with the data item and perform encryption of the data item using an encryption process based on the plurality of counters associated with the data item.

[0039] FIG. 2 schematically illustrates further details of an apparatus according to some configurations of the present technique. The data processing apparatus includes a secure area 20 surrounded by a security boundary. Circuits contained within the secure area 20 are considered trusted, while circuits outside the secure area 20 are considered vulnerable to attack and therefore untrusted. For example, the DRAM 22 is off-chip storage outside the secure area 20 and can potentially be tampered with without the knowledge of components within the secure area. The secure area includes a dynamic memory controller 30 (DMC), a memory protection unit 28 (MPU) including an integration counter control circuit, caches 26, 28 (which are secure storage located within the secure area 20), an interconnect 34, and master devices including the CPU 24, GPU 32, and AI accelerator 36. Data items are transferred between the DRAM 22 and the cache 26 via the memory controller 30 and the memory protection unit 28. Data items may be transferred when requested by one of the master devices and cached in one or more higher level caches associated with the CPU 24, the GPU 32, or the AI ​​accelerator 36. As noted above, data stored within the secure region 20 does not need to be protected through an encryption process, whereas data stored outside the secure region 20, for example in the DRAM 22, should be protected using an encryption process.

[0040] Figure 3 illustrates the concept of a data integrity tree used to protect data items in a series of memory blocks (memory block 0-0 through memory block 3-3). Each memory block is stored in off-chip storage. To verify that the data stored in the memory block has not been tampered with, a hash (hash 0-0 through hash 3-3) is generated for each memory block at the time of storage. When the data is read, the corresponding hash can also be read and compared with a newly generated version of the hash based on the data being read. In this way, it can be determined whether the hash or the memory block was modified during storage. For example, if memory block 1-2 was modified during storage, the hash generated from the data in memory block 1-2 would not match hash 1-2, which was generated before memory block 1-2 was stored. Using such a technique can provide some assurance that the data in the memory blocks has not been modified. However, this data alone does not guarantee that both the data in the memory blocks and the corresponding hashes have not been modified. Therefore, as the next level of the data integrity tree, several higher-level hashes are formed based on combinations of hashes generated from the data blocks. For example, hash 0 is generated as the hash of hash 0-0, hash 0-1, hash 0-2, and hash 0-3. Hash 1 is generated as the hash of hash 1-0, hash 1-1, hash 1-2, and hash 1-3. Hash 2 is generated as the hash of hash 2-0, hash 2-1, hash 2-2, and hash 2-3, and hash 3 is generated as the hash of hash 3-0, hash 3-1, hash 3-2, and hash 3-3.Thus, if upper-level hashes (Hash 0, Hash 1, Hash 2, Hash 3) are stored simultaneously with hashes (Hash 0-0 through Hash 3-3) and the corresponding memory blocks, when reading the data in the memory blocks, the integrity of the data read from the memory block (e.g., Memory Block 1-2) can be achieved by recalculating the hash and comparing it to the previously stored hash (Hash 1-2 in the above example). Similarly, the integrity of the stored hash value can be determined by recalculating the upper-level hash and comparing it to the upper hash value (Hash 1 in this case) stored simultaneously with hashes 1-0 through 1-3 and the corresponding memory blocks. In the above example, the stored value of Hash 1 is compared to the hash generated from Hash 1-0, Hash 1-1, Hash 1-2, and Hash 1-3. As with hashes (Hash 0-0 through Hash 3-3), this process cannot verify that the data blocks, corresponding hash values, and upper-level hash values ​​are all unchanged. Therefore, the top-level hashes are generated based on the upper-level hashes (Hash 0, Hash 1, Hash 2, and Hash 3). The top hash can be recalculated when the data is read and compared to the stored value of the top hash to verify the integrity of the upper level hash. The top hash is stored in secure storage to ensure that the top level hash is also unchanged. In this way, it is possible to verify the integrity of the data item stored in the memory block.

[0041] Figure 4 shows a schematic of an alternative integrity tree for verifying the integrity of stored data. Rather than storing a tree of hash values ​​generated from data items whose hash values ​​are stored further from the root of the integrity tree, the integrity tree stores a set of counters. A counter at each level (denoted c in the figure) is stored in association with a MAC (denoted T in Figure 4). The MAC is generated from the associated counter and a higher-level counter. Starting at the top of the tree, a single top-level counter C is stored in secure storage. The top-level node of the counter tree region of the integrity tree stores multiple counters c0...c, each associated with the next level of the counter tree region. k The top-level nodes of the counter tree also contain counters c0...c k , the top-level counter C, and the MAC T generated from the hash of the secret key K. In this way, the counters c0...c k can be verified by regenerating the MAC T and comparing it with the stored T. Counters c0...c k If any of the MAC T changes, the comparison fails. At the next level in the counter tree region of the integrity tree, each node has multiple next-level counters c 00 ...c kk Includes counter c- i0 ...c ik is the counter c of the top-level node of the integrity tree. i Each node (i) at the next level in the counter tree region of the data integrity tree is also associated with a counter c i and a counter c combined with a secret key K i0 ...c ik MAC T for i in the range 0...k, generated from the hash of i In this way, the counter c of node i i0 ...c ik MAC T i and store it in the stored T iThe counter c i0 ...c ik , MAC T i , or the counter c of the top-level node i If any of the values ​​have changed, the comparison fails. Each counter at the next level of the counter tree region has data D for i in the range 0...k and j in the range 0...k. ij and the corresponding MAC T ij Each MAC T ij is the counter c ij and data D in combination with the private key ij In this way, the data D ij MAC T ij and store it in the stored T ij An integrity tree containing a counter tree region can be made robust against replay attacks by incrementing (or otherwise modifying) the counter before the data item is written. 10 Changes to MAC T 10 A change in a counter of a higher level node, say c0, will require MACS T and T0 to be recalculated.

[0042] 5 illustrates the use of multiple levels of counters within a single node of a counter tree in accordance with various configurations of the present technique. In the illustrated configuration, the node of the counter tree 54 includes a single major counter C and 64 minor counters c for j ranging from 0 to 63. j Each of the 64 minor counters stores a corresponding data D j and minor counter c j , a measure counter C, and data D combined with a secret key K. j The corresponding MAC T is generated as a hash of jAs explained, providing the counters as a set of minor counters combined with a single major counter allows for more counters to be provided for the same number of bits in a node of the integrity tree. j The completeness of MAC T j and store it in the MAC T j Counters C and c can be determined at the time of reading by comparing them with j is the secret key K and the major counter C' and minor counter c' from the next level node closer to the root of the integrity tree. i Counters C and c combined with j As in Figure 4, the data D j When is written to off-chip storage, the associated minor counter c j is modified to indicate mitigation against replay attacks. j When changes occur, MAC T j is the minor counter c j Furthermore, MAC T' must be recalculated for consistency with the minor counter c j The minor counter c must be recalculated for consistency with j If MAC T0...T overflows, the major counter C is incremented. When C is incremented, MAC T0...T 63 Each of the MACs T' must be recalculated for consistency with the changed major counter. Additionally, MAC T' must be recalculated for consistency with the major counter C. Thus, in this manner, more data items can be associated with a single node of the counter tree. However, if a data item is modified enough times that the minor counter associated with that data item changes, the counter will overflow, and as a result, the MAC associated with each data item associated with a minor counter must be recalculated.

[0043] 6 shows a schematic layout of counters 66 and data values ​​68 in off-chip memory. Data values ​​68 and counters 66 are stored as 512-bit cache lines and transferred to and from secure memory by memory protection unit 64. During transfers, counters 66 are maintained by counter control circuitry 60. Data values ​​68 may include both the data value and the calculated MAC; alternatively, the data value and the corresponding MAC may be stored in different portions of off-chip memory. Counters 66 associated with data values ​​68 may be stored in a specific region of off-chip memory; alternatively, counters associated with a page of memory may be stored in a location aligned to a page boundary.

[0044] 7 schematically illustrates multiple counters within a single node of an integrity tree, according to some configurations of the present technique. The multiple counters include a major counter 72, multiple intermediate counters 74, and multiple minor counters 76. Each of the minor counters 76 is associated with a data item (not shown). Each of the data items is associated with a single minor counter 76, a single intermediate counter 74, and a major counter 72. In the illustrated configuration, encryption of a single data item is based on a combination of the major counter 72, intermediate counters 74, and minor counters 76 associated with that data item. In particular, count Cnt087(1) is associated with a first data item and is generated from the combination of major counter 72, intermediate counter 74(1), and minor counter 76(1); count Cnt187(2) is associated with a first data item and is generated from the combination of major counter 72, intermediate counter 74(1), and minor counter 76(2); count Cnt187(3) is associated with a first data item and is generated from the combination of major counter 72, intermediate counter 74(1), and minor counter 76(2); N 87(N) is associated with the first data item and is generated from a combination of the major counter 72, the intermediate counter 74(K) and the minor counter 76(N). The combination operation is a concatenation of the data items. In an alternative configuration, the combination can be achieved by addition or any other arithmetic operation.

[0045] FIG. 8 illustrates a schematic layout of counters associated with some configurations of the present technique. The counters include a major counter 84, eight intermediate counters 86, each an 8-bit counter, and 64 minor counters arranged in groups of eight minor counters 88, each a 5-bit counter. The counters are stored in a single 512-bit cache line 80, along with additional metadata 82. The counters are used to generate a MAC for a set of data item cache lines. Each cache line is a 512-bit cache line. Each data item cache line is associated with a single minor counter 88, a single intermediate counter 86, and a major counter 84. Each intermediate counter 86 is associated with a group of eight minor counters 88. In this manner, a total of 64 cache lines can be covered by the counters stored in a single cache line. The counters are used, for example, in performing an encryption process on a data item to generate a MAC used to verify that a data item stored in off-chip storage has not been modified. Each time a cache line, for example cache line 89, is written, the memory protection unit increments a corresponding minor counter 87 in response to cache line 89 being written. The memory protection unit is configured to perform an encryption process in response to the change to minor counter 87 to generate a MAC based on minor counter 87, intermediate counter 86(2) associated with cache line 89, and major counter 84. The memory protection unit modifies intermediate counter 86(2) in response to the change to minor counter 87 that causes minor counter 87 to overflow, and performs an intermediate encryption process to encrypt each of the cache lines associated with intermediate counter 86(2) and minor counter 88(2) based on the modified intermediate counter 86(2).Similarly, in response to the modification of intermediate counter 86(2), the memory protection unit overflows intermediate counter 86(2), modifies major counter 84, and performs a major encryption process to encrypt each of the cache lines associated with the major counter based on the modified major counter.

[0046] FIG. 9 schematically illustrates the layout of counters associated with some configurations of the present technique. The counters include a major counter 94, eight intermediate counters 96, each a 5-bit counter, and 128 minor counters arranged in groups of 16 minor counters 98, each a 3-bit counter. The counters are stored in a single 512-bit cache line 90, along with additional metadata 92. The counters are used to generate a MAC for a set of data item cache lines. Each cache line is a 512-bit cache line. Each data item cache line is associated with a single minor counter 98, a single intermediate counter 96, and a major counter 94. Each intermediate counter 96 is associated with a group of 16 minor counters 98. In this manner, a total of 128 cache lines may be covered by the counters stored in a single cache line. The counters are used, for example, in performing an encryption process on a data item to generate a MAC used to verify that a data item stored in off-chip storage has not been modified. Each time a cache line, for example cache line 99, is written, the memory protection unit increments a corresponding minor counter 97 in response to the cache line 99 being written. The memory protection unit is configured to perform an encryption process in response to the change to minor counter 97 to generate a MAC based on minor counter 97, intermediate counter 96(2) associated with cache line 99, and major counter 94. The memory protection unit modifies intermediate counter 96(2) in response to the change to minor counter 97 that causes minor counter 97 to overflow, and performs an intermediate encryption process to encrypt each of the cache lines associated with intermediate counter 96(2) and minor counter 98(2) based on the modified intermediate counter 96(2).Similarly, in response to the modification of intermediate counter 96(2), the memory protection unit overflows intermediate counter 96(2), modifies major counter 94, and performs a major encryption process to encrypt each of the cache lines associated with the major counter based on the modified major counter.

[0047] 10 illustrates a schematic layout of counters associated with some configurations of the present technique. The counters include a major counter 104, two upper-tier intermediate counters 106, each an 8-bit counter, 16 lower-tier intermediate counters 108 arranged in two groups of intermediate counters, and 64 minor counters arranged in groups of four minor counters 110, 112. The first group of minor counters 110 is associated with the lower intermediate counter 108(1) and the first of the upper intermediate counters 106, and the second group of minor counters 112 is associated with the lower intermediate counter 108(2) and the second of the upper intermediate counters 106. Each minor counter is a 4-bit counter. Multiple counters are stored in a single 512-bit cache line 100, along with additional metadata 102. The counters are used to generate a MAC for a set of data item cache lines. Each cache line is a 512-bit cache line. Each data item cache line is associated with a single minor counter from one of the group of minor counters 110, 112, a single lower intermediate counter 108, a single upper intermediate counter from the group of upper intermediate counters 106, and a major counter 104. In this manner, a total of 64 cache lines can be covered by the counters stored within a single cache line. The counters are used, for example, in performing an encryption process on the data item to generate a MAC used to verify that the data item stored in off-chip storage has not been modified. Each time a cache line, for example, cache line 109, is written, the memory protection unit increments the corresponding minor counter 107 in response to the cache line 109 being written. The memory protection unit is configured, in response to a change to the minor counter 107, to perform an encryption process to generate a MAC based on the minor counter 107, the lower intermediate counter 105 associated with the cache line 109, the upper intermediate counter 103 associated with the cache line 109, and the major counter 104.The memory protection unit, in response to the change to minor counter 107 that causes minor counter 107 to overflow, modifies lower intermediate counter 105 and performs a lower intermediate encryption process to encrypt each of the cache lines associated with lower intermediate counter 105 and minor counter 110(8) based on the modified intermediate counter 105. The memory protection unit, in response to the change to lower intermediate counter 105 that causes lower intermediate counter 105 to overflow, modifies upper intermediate counter 103 and performs an upper intermediate encryption process to encrypt each of the cache lines associated with upper intermediate counter 103, including all cache lines associated with lower intermediate counter 108(1) and minor counter 110. Similarly, in response to the change to upper intermediate counter 103, the memory protection unit, in response to the change to upper intermediate counter 103, causes upper intermediate counter 103 to overflow, modifies major counter 104, and performs a major encryption process to encrypt each of the cache lines associated with the major counter based on the modified major counter.

[0048] FIG. 11 generally illustrates a series of steps performed by the memory protection unit. Flow begins in step S110, where it is determined whether data is being transferred from secure storage to off-chip storage. If no, flow returns to step S110. If it is determined in step S110 that data is being transferred from secure storage to off-chip storage, flow proceeds to step S112, where the memory protection unit modifies a minor counter associated with the data item. Next, flow proceeds to step S114, where it is determined whether the minor counter overflowed as a result of the modification in step S112. If it is determined in step S114 that the minor counter did not overflow, flow proceeds to step S116, where the data item is encrypted using an encryption process. The encryption process generates a MAC based on the data item and the counter associated with the data item, including the modified minor counter. Then, flow returns to step S110. If it is determined in step S114 that the minor counter overflowed, flow proceeds to step S118. In step S118, the memory protection unit modifies the intermediate counter associated with the data item, and flow proceeds to step S120. In step S120, it is determined whether the intermediate counter has overflowed. If in step S120 it is determined that the intermediate counter has not overflowed, flow proceeds to step S112, where all minor counters associated with the overflowed intermediate counter are (optionally) reset. Flow then proceeds to step S124, where the memory protection unit re-encrypts all data values ​​associated with the modified intermediate counter to generate a new MAC for each of the data items associated with the intermediate counter. Flow then returns to step S110. If in step S120 it is determined that the intermediate counter has overflowed, flow proceeds to step S126, where the major counter is modified. Flow then proceeds to step S128, where all intermediate counters and all minor counters are (optionally) reset.Flow then proceeds to step S130, where all data values ​​associated with the major counters are re-encrypted based on the modified major, minor, and intermediate counters, and a new MAC is generated that matches the modified counter values. Flow then returns to step S110.

[0049] FIG. 12 schematically illustrates a non-transitory computer-readable medium containing computer-readable code for fabricating a data processing device according to various configurations of the present technique. Fabrication occurs based on computer-readable code 1002 stored on non-transitory computer-readable medium 1000. The computer-readable code can be used in one or more stages of a semiconductor design and fabrication process, including an electronic design automation (EDA) stage, to fabricate an integrated circuit comprising a device embodying the concepts. The fabrication process includes applying computer-readable code 1002 directly to one or more programmable hardware units, such as field programmable gate arrays (FPGAs), to configure the FPGA to embody the configurations described above, or to facilitate fabrication of a device implemented as one or more integrated circuits or embodying the configurations described above. The fabricated design 1004 includes counter control circuitry 12 and memory protection unit 16 configured to perform encryption and decryption in connection with transfer of data items between secure memory 14 and off-chip storage 18, as described with reference to FIG. 1 .

[0050] In summary, an apparatus is provided that includes counter control circuitry that maintains counters associated with a data item, including a minor counter, an intermediate counter, and a major counter. The apparatus also includes a memory protection unit configured to modify the minor counters associated with the data item in response to transferring the data item from secure storage to off-chip storage and to encrypt the data item based on the counters associated with the data item. The memory protection unit also performs an intermediate re-encryption process in response to the minor counter overflowing, the intermediate counters being modified and re-encrypting the data item associated with the intermediate counters. The memory protection unit also performs a major re-encryption process in response to the intermediate counters overflowing, the major counters being modified and re-encrypting each of the data items.

[0051] In this application, the term "configured to" is used to mean that elements of a device have a configuration that is capable of performing a defined operation. In this context, "configuration" refers to a manner of arrangement or interconnection of hardware or software. For example, a device may have dedicated hardware that provides the defined operation, or a processor or other processing device may be programmed to perform the function. "Configured to" does not imply that the device elements need to be modified in any way to provide the defined operation.

[0052] Although exemplary configurations have been described in detail herein with reference to the accompanying drawings, it will be understood that the invention is not limited to exact configurations thereof, and that various changes, additions, and modifications may be made by those skilled in the art without departing from the scope and spirit of the invention as defined by the appended claims. For example, various combinations of the features of the following dependent claims may be made with the features of the independent claims without departing from the scope of the invention.

Claims

1. 1. An apparatus comprising: A counter control circuit for maintaining a plurality of counters associated with a plurality of data items, said plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; a counter control circuit including a major counter associated with the plurality of data items; 1. A memory protection unit, comprising: responsive to a transfer of one of the plurality of data items from secure storage to off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process, in response to an overflowed minor counter of the plurality of minor counters, including modifying an intermediate counter associated with the overflowed minor counter and re-encrypting each of a subset of the plurality of data items associated with the intermediate counter using the encryption process; and a memory protection unit configured to perform a major re-encryption process in response to an overflowed intermediate counter among the plurality of intermediate counters, the major counter being modified to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.

2. 2. The apparatus of claim 1, wherein the intermediate re-encryption process includes resetting each of the subset of the plurality of minor counters associated with the intermediate counter before re-encrypting each of the subset of the plurality of data items associated with the intermediate counter.

3. 3. The apparatus of claim 1 or claim 2, wherein the major re-encryption process includes resetting each of the plurality of intermediate counters before re-encrypting each of the plurality of data items.

4. The apparatus of claim 1 , wherein the major re-encryption process includes resetting each of the plurality of minor counters before re-encrypting each of the plurality of data items.

5. The apparatus of claim 1 , wherein each of the plurality of data items has a size corresponding to the size of a single cache line.

6. 6. The apparatus of claim 1, wherein a total number of bits used to store the plurality of counters is less than or equal to the number of bits in a single cache line.

7. each of the plurality of minor counters is a 5-bit counter; the plurality of intermediate counters include eight intermediate counters, each of the eight intermediate counters being an 8-bit counter; 7. The apparatus of claim 6.

8. each of the plurality of minor counters is a 3-bit counter; the plurality of intermediate counters include eight intermediate counters, each of the eight intermediate counters being a four-bit counter; 7. The apparatus of claim 6.

9. The device according to claim 6 , wherein the number of bits of the single cache line is 512 bits.

10. The apparatus of claim 1 , wherein the major counter is a 64-bit counter.

11. Each of the plurality of counters a linear feedback shift register, wherein an overflow corresponds to the linear feedback shift register reaching a predetermined state; a non-linear feedback shift register, wherein an overflow corresponds to the non-linear feedback shift register reaching a predetermined state; a binary counter, wherein an overflow corresponds to the binary counter exceeding a predetermined value.

12. 12. The apparatus of claim 1, wherein the encryption process is performed using a combination of each of the plurality of counters associated with the data item as an encryption key.

13. The apparatus of claim 12 , wherein the combination is a concatenation of each of the plurality of counters associated with the value.

14. 13. The apparatus of claim 12, wherein the combination is an addition of values ​​stored in each of the plurality of counters associated with the data item.

15. the plurality of intermediate counters include the plurality of tier intermediate counters arranged as part of a hierarchical tree structure comprising the major counter, the plurality of tier intermediate counters, and the plurality of minor counters; each intermediate counter of one of the plurality of layers is associated with a plurality of lower level counters associated with successively lower layers of the hierarchical structure; the memory protection unit, in response to an overflowed lower-level counter of the corresponding subset of the plurality of lower-level counters, performs a next-level re-encryption process including: modifying a next-level counter associated with the overflowed lower-level counter; and re-encrypting each of the subset of the plurality of data items associated with the next-level counter.

15. An apparatus according to any one of claims 1 to 14.

16. The apparatus of claim 1 , wherein the memory protection engine and the secure storage are integrated on the same chip.

17. The apparatus of claim 1 , wherein the plurality of counters are stored in the secure storage.

18. The apparatus of claim 1 , wherein the plurality of counters are stored off-chip and encrypted using a master key stored in the secure storage.

19. 19. Apparatus according to any one of claims 1 to 18, wherein each data item is associated with a single minor counter, at least one intermediate counter and the major counter.

20. 20. The apparatus of claim 1, wherein the memory protection unit is configured to decrypt the encrypted data item transferred from the off-chip storage to the secure storage using a decryption process based on each of the plurality of counters associated with the encrypted data item.

21. 21. The apparatus of claim 1, wherein the plurality of counters corresponds to a single node in a data integrity tree, the data integrity tree comprising a plurality of nodes each storing a corresponding plurality of counters, at least one node of the plurality of nodes being an intermediate node associated with a corresponding set of data items, each data item comprising a further node of the plurality of nodes.

22. 1. A method of operating an apparatus, the method comprising: maintaining a plurality of counters associated with a plurality of data items, said plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; maintaining a plurality of counters, including a major counter associated with said plurality of data items; responsive to transferring one of the plurality of data items from secure storage to off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process in response to an overflowed minor counter of the plurality of minor counters, the intermediate re-encryption process comprising: modifying an intermediate counter associated with the overflowed minor counter; and re-encrypting each of the subset of the plurality of data items associated with the intermediate counter using the encryption process; performing a major re-encryption process that includes, in response to an overflowed intermediate counter among the plurality of intermediate counters, modifying the major counter to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.

23. 1. A non-transitory computer-readable medium for storing computer-readable code for manufacturing an apparatus, the medium comprising: A counter control circuit for maintaining a plurality of counters associated with a plurality of data items, said plurality of counters comprising: a plurality of minor counters, each associated with one of the plurality of data items; a plurality of intermediate counters each associated with a subset of the plurality of data items and a corresponding subset of the plurality of minor counters; a counter control circuit including a major counter associated with the plurality of data items; 1. A memory protection unit, comprising: responsive to a transfer of one of the plurality of data items from secure storage to off-chip storage, modifying a corresponding minor counter associated with the data item, and thereafter encrypting the data item using an encryption process based on each of the plurality of counters associated with the data item; performing an intermediate re-encryption process, in response to an overflowed minor counter of the plurality of minor counters, including modifying an intermediate counter associated with the overflowed minor counter and re-encrypting each of the subset of the plurality of data items associated with the intermediate counter using the encryption process; and a memory protection unit configured to perform a major re-encryption process in response to an overflowed intermediate counter among the plurality of intermediate counters, the major counter being modified to indicate the occurrence of the overflowed intermediate counter, and thereafter re-encrypting each of the plurality of data items using the encryption process.