Intermediate-State Authentication for Low-Latency Memory Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data authentication techniques in memory systems require restarting the authentication process and re-transmitting entire data packets due to the chaining nature of tag computation, leading to increased computational effort, power consumption, and latency in the event of errors.
Innovation Solution
A closed-loop authentication architecture that utilizes intermediate states to store and reuse hash computations, allowing for limited data re-transmission and reduced re-computation in case of errors, thereby maintaining data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication techniques are used with chaining nature of tag computation, then data integrity can be detected, but the entire data packet must be re-transmitted and re-computed when an error is detected, increasing computational effort and latency
Solution Approach 1:
The authentication process is segmented into independent packet-level operations. Each packet is authenticated independently using its own initialization vector (IV) and authentication tag, rather than chaining dependencies across the entire data stream. This allows error detection at the packet level without requiring re-authentication of subsequent packets, reducing latency while maintaining data integrity detection.
Solution Approach 2:
Authentication tags and initialization vectors are pre-computed and stored for each packet before transmission. When a packet is received, the pre-stored authentication information is immediately available for verification without requiring real-time computation during the authentication process, thereby reducing latency while ensuring reliable integrity detection.
2Reliability
If conventional authentication techniques are used with chaining nature of tag computation, then data integrity can be detected, but computational effort increases due to re-transmission and re-computation
Solution Approach 1:
The authentication mechanism is divided into independent packet-level operations where each packet carries its own authentication information. This segmentation eliminates the need to re-compute authentication tags for entire data streams when errors occur, reducing computational effort and power consumption while maintaining reliable error detection capabilities.
Solution Approach 2:
Authentication information including initialization vectors and authentication tags are copied and stored with each packet. This allows the receiving end to verify integrity using the copied authentication data without requiring re-computation, thereby reducing power consumption while ensuring reliable data integrity detection.
3Reliability
If conventional authentication techniques are used, then authentication can be performed, but memory bandwidth is consumed due to frequent re-transmissions
Solution Approach 1:
Authentication is segmented at the packet level with each packet containing independent authentication credentials. This allows the system to verify authentication status locally without requiring frequent re-transmissions, thereby reducing memory bandwidth consumption while maintaining reliable authentication.
Solution Approach 2:
Authentication information is prepared in advance and attached to each packet before transmission. This preliminary preparation eliminates the need for repeated authentication computations and re-transmissions, reducing memory bandwidth usage while ensuring reliable authentication.
Data Source
AI summary
Technologies for protecting data integrity of an authentication algorithm using intermediate states are described. One inline memory encryption (IME) engine performs an authentication algorithm that uses a hash function to compute an authentication tag. The IME engine includes integrity-protection logic to store an intermediate state of a tag computation and incoming data segments. In the event of an error in the computation, the integrity-protection logic can compute the intermediate state again using a last intermediate state and the last data segment.


