Link Encryption Hardware Mechanisms for PCIe Data Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face challenges in protecting the confidentiality of data transmitted over IO links between discrete devices, particularly in scenarios where hardware adversaries can probe or observe the PCIe link between a Host Central Processing Unit (CPU) and a Solid State Drive (SSD), leading to potential exposure of secrets and confidential information.

Innovation Solution

The implementation of hardware mechanisms for link encryption, specifically counter mode encryption, is integrated within the link protocol stack to encrypt data transmitted over IO links, using cryptographic engines at both ends of the link to maintain confidentiality without significant impact on bandwidth or latency, and to prevent infinite error propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted over IO links between discrete devices, then system functionality and performance are improved, but confidentiality of data is compromised due to potential probing by hardware adversaries

Engineering Contradiction:
Improvesystem performanceVSAvoiddata exposure to adversaries
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption intermediary layer within the link protocol stack that mediates data transmission between devices. This intermediary encrypts data before transmission and decrypts it at the receiving end, allowing normal high-performance data transfer while protecting against hardware adversaries who may probe the physical link.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is implemented to protect data confidentiality, then security against adversaries is improved, but bandwidth and latency performance deteriorate

Engineering Contradiction:
Improveconfidentiality protectionVSAvoidlink bandwidth
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-computing and caching encryption/decryption keys and intermediate values before data transmission occurs. This allows the cryptographic operations to be performed efficiently without adding significant overhead to the actual data transfer, thus maintaining high bandwidth while ensuring confidentiality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption mechanism is integrated directly into the link protocol stack of each device, allowing each device to perform its own encryption and decryption operations independently. This self-service approach eliminates the need for external encryption hardware that would add bandwidth overhead, while still providing strong security protection.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If encryption mechanisms are added to protect links, then confidentiality is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against probingVSAvoidlink protocol stack complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal encryption module within the link protocol stack that can handle multiple encryption algorithms and modes through a single unified interface. This multi-functional design provides comprehensive security protection against various types of attacks while avoiding the need for multiple separate encryption components, thus limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11533170B2Hardware mechanisms for link encryption
Publication Date: 2022.12.20 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US11533170B2 patent drawing
  • US11533170B2 patent drawing
  • US11533170B2 patent drawing

AI summary

Methods, systems, and apparatuses associated with hardware mechanisms for link encryption are disclosed. In various embodiments, an interconnect interface is coupled to a processor core to interconnect a peripheral device to the processor core via a link established between the peripheral device and the interconnect interface. The interconnect interface is to select a cryptographic engine of a plurality of cryptographic engines instantiated in the interconnect interface for the link. The cryptographic engine is to symmetrically encrypt data to be transmitted through the link. In more specific embodiments, each of the plurality of cryptographic engines is instantiated for one of a request type on the link, a virtual channel on the link, or a request type within a virtual channel on the link.