Encryption Engine for PCIe Drive DMA Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System on chip (SoC) integration leads to security vulnerabilities due to the addition of components, particularly in non-volatile memory devices like PCIe drives, which can be malicious and compromise user data through direct memory access (DMA) operations.

Innovation Solution

Incorporating an encryption engine in non-volatile memory devices that encrypts all data written and decrypts all data read, with a trusted port for programming cryptographic keys, ensuring secure data storage by using Advanced Encryption Standard (AES) and XTS modes, and generating keys during manufacturing or via a physically unclonable function (PUF) engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third party components are integrated via standardized on-die interconnect protocol in SoC, then functionality and versatility are improved, but security vulnerabilities increase due to potential malicious DMA operations

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption engine as an intermediary component between the third party components and the memory system. This encryption engine intercepts all DMA operations and encrypts/decrypts data in transit, allowing functional integration while preventing unauthorized access to plaintext data. The encryption engine acts as a security mediator that enables both functionality and protection simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the memory system into multiple independent components: third party components for functionality, an encryption engine for security, and memory controllers for data management. This segmentation allows each component to operate independently with defined interfaces, enabling the system to gain functional versatility from third party components while isolating security-critical operations to the dedicated encryption engine.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If encryption engine is added to non-volatile memory device, then security against malicious DMA operations is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the encryption engine directly into the non-volatile memory device controller, combining security functionality with existing storage control logic. This integration approach allows the encryption engine to share physical resources and control pathways with the memory controller, reducing the need for separate dedicated hardware components and thereby limiting the increase in device complexity while maintaining strong security protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11847228B2Platform security mechanism
Publication Date: 2023.12.19 INTEL CORP
  • US11847228B2 patent drawing
  • US11847228B2 patent drawing
  • US11847228B2 patent drawing

AI summary

An apparatus to facilitate security within a computing system is disclosed. The apparatus includes a storage drive, a controller, comprising a trusted port having one or more key slots to program one or more cryptographic keys and an encryption engine to receive the cryptographic keys via the one or more key slots, encrypt data written to the storage drive using the cryptographic keys and decrypt data read from the storage drive using the cryptographic keys.