Inline Cryptographic Engine for PCIe Root Complex Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication devices face challenges in providing adequate data encryption and decryption for storage devices connected via PCIe interfaces, leading to increased complexity and costs due to the need for multiple host controllers for different storage types.

Innovation Solution

Incorporating an inline cryptographic engine (ICE) within the PCIe root complex, which receives and processes transport layer packets with transaction-specific information to enable encryption and decryption, using standards like AES-XTS or AES-CBC, and computes an initialization vector based on logical block addresses and secret keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple host controllers are used for different storage types, then data protection for various storage devices is improved, but device complexity and costs increase

Engineering Contradiction:
Improvedata protectionVSAvoidhost controller quantity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PCIe root complex is designed to perform multiple functions including data encryption and decryption for various storage devices (HDD, SSD, UFS, eMMC) through a single integrated controller, eliminating the need for multiple specialized host controllers while maintaining comprehensive data protection across different storage types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The encryption and decryption functions are merged into the PCIe root complex itself, combining previously separate cryptographic processing capabilities with the existing storage interface controller to create a unified multi-functional device that handles both storage communication and security operations

Inventive Principle:
Principle #5Merging (Combining)

2Device complexity

If encryption and decryption functions are integrated into PCIe root complex, then device complexity is reduced, but processing capability for data security may be limited

Engineering Contradiction:
Improvehost controller quantityVSAvoidencryption capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The PCIe root complex implements universal encryption and decryption capabilities that work across multiple storage device types and protocols, providing adaptable security processing that is not limited to specific storage technologies while maintaining a single integrated controller architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The root complex dynamically adjusts encryption parameters such as initialization vectors and keys based on the specific storage device type and transaction requirements, enabling flexible adaptation to different security needs without requiring separate dedicated controllers for each storage technology

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3405876B1Inline cryptographic engine for peripheral component interconnect express systems
Publication Date: 2019.12.11 QUALCOMM INC
  • EP3405876B1 patent drawingFigure 1
  • EP3405876B1 patent drawingFigure 2
  • EP3405876B1 patent drawingFigure 3

AI summary

Aspects disclosed in the detailed description include inline cryptographic engine (ICE) for peripheral component interconnect express (PCIe). In this regard, in one aspect, an ICE is provided in a PCIe root complex (RC) in a host system. The PCIe RC is configured to receive at least one transport layer packet (TLP), which includes a TLP prefix, from a storage device. In a non-limiting example, the TLP prefix includes transaction-specific information that may be used by the ICE to provide data encryption and decryption. By providing the ICE in the PCIe RC and receiving the transaction-specific information in the TLP prefix, it is possible to encrypt and decrypt data in the PCIe RC in compliance with established standards, thus ensuring adequate protection during data exchange between the PCIe RC and the storage device.