Host-Based Encryption for Trusted Expansion-Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems face challenges with increased coherence traffic and latency due to the addition of multiple processor sockets and accelerators, leading to inefficient memory management and performance degradation, particularly in cloud-based edge architectures.

Innovation Solution

Implementing a dynamic and flexible memory domain management system using Compute Express Link (CXL) switches that allow for fine-grained control of coherency, enabling independent and per-tenant memory domains with configurable coherence status, and employing CXL.cache and CXL.mem semantics for efficient memory access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple processor sockets and accelerators are added to the system, then computing power and memory capacity are improved, but coherence traffic increases and latency worsens

Engineering Contradiction:
Improvecomputing powerVSAvoidmemory access latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the system into multiple independent memory domains, each associated with specific compute devices. This segmentation allows memory access to be localized within domains, reducing cross-domain coherence traffic and latency while maintaining the benefits of multiple processor sockets and accelerators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements fine-grained control of coherency at the memory domain level, allowing different coherence policies to be applied to different domains. This local quality approach optimizes memory access performance for each domain independently, reducing overall system latency while supporting expanded computing capacity.

Inventive Principle:
Principle #3Local quality

2Productivity

If multiple processor sockets and accelerators are added to the system, then computing power is improved, but coherence traffic increases

Engineering Contradiction:
Improvecomputing powerVSAvoidcoherence traffic
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

By dividing the memory system into separate domains, the patent reduces the scope of coherence operations. Each domain maintains coherence independently, preventing coherence traffic from propagating across the entire system and thus reducing total coherence traffic volume while supporting multiple compute devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies coherence management locally within each memory domain rather than globally across the entire system. This localized approach reduces the amount of coherence traffic generated by limiting coherence operations to only those devices within the same domain, while still enabling expanded computing power through multiple domains.

Inventive Principle:
Principle #3Local quality

3Productivity

If dynamic memory domain management is implemented, then memory management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvememory management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic creation and updating of memory domains, allowing the system to adapt memory management to changing workload requirements. This dynamic capability improves memory management efficiency by optimizing domain configurations, while the system manages complexity through automated domain management mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a new dimension of memory management by organizing memory into hierarchical domains with configurable coherence status. This dimensional organization allows efficient management of complex multi-processor systems by adding structure and control layers that simplify rather than complicate the overall system architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP4617885A1Apparatus and method for trusted access to expansion memory by multiple potentially heterogeneous compute nodes
Publication Date: 2025.09.17 INTEL CORP
  • EP4617885A1 patent drawingFigure 1
  • EP4617885A1 patent drawingFigure 2
  • EP4617885A1 patent drawingFigure 3

AI summary

Multiple roots of trust are described under a super Root of trust (SROT). One embodiment includes: cores of a host processor; a host processor memory subsystem to provide access to a host processor memory; a home agent to provide access by the cores to the host processor memory subsystem and an expansion memory subsystem, a source address decoder to decode memory requests generated from the plurality of cores to determine whether the memory requests are to be directed to the host processor memory subsystem or the expansion memory subsystem. Host-based security circuitry encrypts and decrypts memory requests directed to the expansion memory subsystem, the host-based security circuitry to perform the encryption and decryption based on a second key stored in a cache maintained by the host-based security circuitry.