Storage Inline Encryption Circuit for Secure I/O Memory Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing processing systems face security vulnerabilities due to the use of system software for data encryption and decryption, which reduces performance and exposes data to malicious entities during transient execution attacks, and I/O devices lack efficient inline encryption mechanisms.
Innovation Solution
Implementing storage inline encryption circuits (SIECs) that perform encryption and decryption of data directly between I/O devices and memory using hardware-based circuitry, reducing the need for system software involvement and minimizing exposure of unencrypted data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If system software is used to encrypt and decrypt data, then data security can be maintained, but processing performance deteriorates due to resource allocation requirements
Solution Approach 1:
The patent replaces the software-based encryption/decryption system with a hardware-based encryption circuit. This substitution eliminates the need for system software to perform cryptographic operations, thereby maintaining data security while removing the performance overhead associated with software resource allocation and transient execution vulnerabilities.
Solution Approach 2:
The encryption circuit acts as an intermediary component between the I/O device and system memory. It intercepts data streams, performs encryption/decryption operations in hardware, and forwards the processed data, thereby securing data without burdening the system software or processor.
2Reliability
If system software performs encryption operations, then data can be secured, but system resources are consumed reducing overall performance
Solution Approach 1:
The patent replaces the software-based encryption/decryption system with a hardware-based encryption circuit. This substitution eliminates the need for system software to perform cryptographic operations, thereby maintaining data security while removing the performance overhead associated with software resource allocation and transient execution vulnerabilities.
Solution Approach 2:
The encryption circuit is a self-contained hardware module that autonomously performs encryption and decryption operations without requiring system software intervention. It manages its own resource allocation and cryptographic key handling, thereby eliminating the burden on system resources while maintaining security.
3Reliability
If data is encrypted during transfer between I/O devices and memory, then security is improved, but the complexity of the data transfer system increases
Solution Approach 1:
The patent merges the encryption/decryption functionality directly into the data transfer path between I/O devices and system memory. By integrating the encryption circuit into the existing data bus architecture, the system provides security without requiring separate, complex encryption infrastructure or modifying existing transfer protocols.
Solution Approach 2:
The encryption circuit acts as an intermediary component between the I/O device and system memory. It intercepts data streams, performs encryption/decryption operations in hardware, and forwards the processed data, thereby securing data without burdening the system software or processor.
Data Source
AI summary
A processing system includes one or more storage encryption circuits (SIECs) interconnected with one or more input/output (I/O) devices and a system memory. Each SIEC is configured to encrypt and decrypt data as the data passes between the I/O devices and the system memory. To this end, an SIEC includes slots each associated with respective memory addresses of the system memory. Each slot provides an aperture to the associated memory addresses such that the I/O devices use these apertures to indirectly target the associated memory addresses. As the data targeting the memory addresses associated with an aperture passes through an SIEC, the SIEC encrypts or decrypts the data using cryptographic keys stored on the SIEC.


