Encryption Engine for PCIe Drive DMA Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
System on chip (SoC) integration leads to security vulnerabilities due to the addition of components, particularly in non-volatile memory devices like PCIe drives, which can be malicious and compromise user data through direct memory access (DMA) operations.
Innovation Solution
Incorporating an encryption engine in non-volatile memory devices that encrypts all data written and decrypts all data read, with a trusted port for programming cryptographic keys, ensuring secure data storage by using Advanced Encryption Standard (AES) and XTS modes, and generating keys during manufacturing or via a physically unclonable function (PUF) engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If third party components are integrated via standardized on-die interconnect protocol in SoC, then functionality and versatility are improved, but security vulnerabilities increase due to potential malicious DMA operations
Solution Approach 1:
The patent introduces an encryption engine as an intermediary component between the third party components and the memory system. This encryption engine intercepts all DMA operations and encrypts/decrypts data in transit, allowing functional integration while preventing unauthorized access to plaintext data. The encryption engine acts as a security mediator that enables both functionality and protection simultaneously.
Solution Approach 2:
The patent segments the memory system into multiple independent components: third party components for functionality, an encryption engine for security, and memory controllers for data management. This segmentation allows each component to operate independently with defined interfaces, enabling the system to gain functional versatility from third party components while isolating security-critical operations to the dedicated encryption engine.
2Object-affected harmful factors
If encryption engine is added to non-volatile memory device, then security against malicious DMA operations is improved, but device complexity increases
Solution Approach 1:
The patent merges the encryption engine directly into the non-volatile memory device controller, combining security functionality with existing storage control logic. This integration approach allows the encryption engine to share physical resources and control pathways with the memory controller, reducing the need for separate dedicated hardware components and thereby limiting the increase in device complexity while maintaining strong security protection.
Data Source
AI summary
An apparatus to facilitate security within a computing system is disclosed. The apparatus includes a storage drive, a controller, comprising a trusted port having one or more key slots to program one or more cryptographic keys and an encryption engine to receive the cryptographic keys via the one or more key slots, encrypt data written to the storage drive using the cryptographic keys and decrypt data read from the storage drive using the cryptographic keys.


