Inline Cryptographic Engine for PCIe Root Complex Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication devices face challenges in providing adequate data encryption and decryption for storage devices connected via PCIe interfaces, leading to increased complexity and costs due to the need for multiple host controllers for different storage types.
Innovation Solution
Incorporating an inline cryptographic engine (ICE) within the PCIe root complex, which receives and processes transport layer packets with transaction-specific information to enable encryption and decryption, using standards like AES-XTS or AES-CBC, and computes an initialization vector based on logical block addresses and secret keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple host controllers are used for different storage types, then data protection for various storage devices is improved, but device complexity and costs increase
Solution Approach 1:
The PCIe root complex is designed to perform multiple functions including data encryption and decryption for various storage devices (HDD, SSD, UFS, eMMC) through a single integrated controller, eliminating the need for multiple specialized host controllers while maintaining comprehensive data protection across different storage types
Solution Approach 2:
The encryption and decryption functions are merged into the PCIe root complex itself, combining previously separate cryptographic processing capabilities with the existing storage interface controller to create a unified multi-functional device that handles both storage communication and security operations
2Device complexity
If encryption and decryption functions are integrated into PCIe root complex, then device complexity is reduced, but processing capability for data security may be limited
Solution Approach 1:
The PCIe root complex implements universal encryption and decryption capabilities that work across multiple storage device types and protocols, providing adaptable security processing that is not limited to specific storage technologies while maintaining a single integrated controller architecture
Solution Approach 2:
The root complex dynamically adjusts encryption parameters such as initialization vectors and keys based on the specific storage device type and transaction requirements, enabling flexible adaptation to different security needs without requiring separate dedicated controllers for each storage technology
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Aspects disclosed in the detailed description include inline cryptographic engine (ICE) for peripheral component interconnect express (PCIe). In this regard, in one aspect, an ICE is provided in a PCIe root complex (RC) in a host system. The PCIe RC is configured to receive at least one transport layer packet (TLP), which includes a TLP prefix, from a storage device. In a non-limiting example, the TLP prefix includes transaction-specific information that may be used by the ICE to provide data encryption and decryption. By providing the ICE in the PCIe RC and receiving the transaction-specific information in the TLP prefix, it is possible to encrypt and decrypt data in the PCIe RC in compliance with established standards, thus ensuring adequate protection during data exchange between the PCIe RC and the storage device.