Storage Inline Encryption Circuit for Secure I/O Memory Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing processing systems face security vulnerabilities due to the use of system software for data encryption and decryption, which reduces performance and exposes data to malicious entities during transient execution attacks, and I/O devices lack efficient inline encryption mechanisms.

Innovation Solution

Implementing storage inline encryption circuits (SIECs) that perform encryption and decryption of data directly between I/O devices and memory using hardware-based circuitry, reducing the need for system software involvement and minimizing exposure of unencrypted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system software is used to encrypt and decrypt data, then data security can be maintained, but processing performance deteriorates due to resource allocation requirements

Engineering Contradiction:
Improvedata securityVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the software-based encryption/decryption system with a hardware-based encryption circuit. This substitution eliminates the need for system software to perform cryptographic operations, thereby maintaining data security while removing the performance overhead associated with software resource allocation and transient execution vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The encryption circuit acts as an intermediary component between the I/O device and system memory. It intercepts data streams, performs encryption/decryption operations in hardware, and forwards the processed data, thereby securing data without burdening the system software or processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If system software performs encryption operations, then data can be secured, but system resources are consumed reducing overall performance

Engineering Contradiction:
Improvedata securityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces the software-based encryption/decryption system with a hardware-based encryption circuit. This substitution eliminates the need for system software to perform cryptographic operations, thereby maintaining data security while removing the performance overhead associated with software resource allocation and transient execution vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The encryption circuit is a self-contained hardware module that autonomously performs encryption and decryption operations without requiring system software intervention. It manages its own resource allocation and cryptographic key handling, thereby eliminating the burden on system resources while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If data is encrypted during transfer between I/O devices and memory, then security is improved, but the complexity of the data transfer system increases

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the encryption/decryption functionality directly into the data transfer path between I/O devices and system memory. By integrating the encryption circuit into the existing data bus architecture, the system provides security without requiring separate, complex encryption infrastructure or modifying existing transfer protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encryption circuit acts as an intermediary component between the I/O device and system memory. It intercepts data streams, performs encryption/decryption operations in hardware, and forwards the processed data, thereby securing data without burdening the system software or processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12547550B2Storage inline encryption circuit
Publication Date: 2026.02.10 ADVANCED MICRO DEVICES INC
  • US12547550B2 patent drawing
  • US12547550B2 patent drawing
  • US12547550B2 patent drawing

AI summary

A processing system includes one or more storage encryption circuits (SIECs) interconnected with one or more input/output (I/O) devices and a system memory. Each SIEC is configured to encrypt and decrypt data as the data passes between the I/O devices and the system memory. To this end, an SIEC includes slots each associated with respective memory addresses of the system memory. Each slot provides an aperture to the associated memory addresses such that the I/O devices use these apertures to indirectly target the associated memory addresses. As the data targeting the memory addresses associated with an aperture passes through an SIEC, the SIEC encrypts or decrypts the data using cryptographic keys stored on the SIEC.