Host-Based Encryption for Trusted Expansion-Memory Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems face challenges with increased coherence traffic and latency due to the addition of multiple processor sockets and accelerators, leading to inefficient memory management and performance degradation, particularly in cloud-based edge architectures.
Innovation Solution
Implementing a dynamic and flexible memory domain management system using Compute Express Link (CXL) switches that allow for fine-grained control of coherency, enabling independent and per-tenant memory domains with configurable coherence status, and employing CXL.cache and CXL.mem semantics for efficient memory access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple processor sockets and accelerators are added to the system, then computing power and memory capacity are improved, but coherence traffic increases and latency worsens
Solution Approach 1:
The patent segments the system into multiple independent memory domains, each associated with specific compute devices. This segmentation allows memory access to be localized within domains, reducing cross-domain coherence traffic and latency while maintaining the benefits of multiple processor sockets and accelerators.
Solution Approach 2:
The patent implements fine-grained control of coherency at the memory domain level, allowing different coherence policies to be applied to different domains. This local quality approach optimizes memory access performance for each domain independently, reducing overall system latency while supporting expanded computing capacity.
2Productivity
If multiple processor sockets and accelerators are added to the system, then computing power is improved, but coherence traffic increases
Solution Approach 1:
By dividing the memory system into separate domains, the patent reduces the scope of coherence operations. Each domain maintains coherence independently, preventing coherence traffic from propagating across the entire system and thus reducing total coherence traffic volume while supporting multiple compute devices.
Solution Approach 2:
The patent applies coherence management locally within each memory domain rather than globally across the entire system. This localized approach reduces the amount of coherence traffic generated by limiting coherence operations to only those devices within the same domain, while still enabling expanded computing power through multiple domains.
3Productivity
If dynamic memory domain management is implemented, then memory management efficiency is improved, but system complexity increases
Solution Approach 1:
The patent implements dynamic creation and updating of memory domains, allowing the system to adapt memory management to changing workload requirements. This dynamic capability improves memory management efficiency by optimizing domain configurations, while the system manages complexity through automated domain management mechanisms.
Solution Approach 2:
The patent introduces a new dimension of memory management by organizing memory into hierarchical domains with configurable coherence status. This dimensional organization allows efficient management of complex multi-processor systems by adding structure and control layers that simplify rather than complicate the overall system architecture.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Multiple roots of trust are described under a super Root of trust (SROT). One embodiment includes: cores of a host processor; a host processor memory subsystem to provide access to a host processor memory; a home agent to provide access by the cores to the host processor memory subsystem and an expansion memory subsystem, a source address decoder to decode memory requests generated from the plurality of cores to determine whether the memory requests are to be directed to the host processor memory subsystem or the expansion memory subsystem. Host-based security circuitry encrypts and decrypts memory requests directed to the expansion memory subsystem, the host-based security circuitry to perform the encryption and decryption based on a second key stored in a cache maintained by the host-based security circuitry.