Link Encryption Hardware Mechanisms for PCIe Data Confidentiality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems face challenges in protecting the confidentiality of data transmitted over IO links between discrete devices, particularly in scenarios where hardware adversaries can probe or observe the PCIe link between a Host Central Processing Unit (CPU) and a Solid State Drive (SSD), leading to potential exposure of secrets and confidential information.
Innovation Solution
The implementation of hardware mechanisms for link encryption, specifically counter mode encryption, is integrated within the link protocol stack to encrypt data transmitted over IO links, using cryptographic engines at both ends of the link to maintain confidentiality without significant impact on bandwidth or latency, and to prevent infinite error propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transmitted over IO links between discrete devices, then system functionality and performance are improved, but confidentiality of data is compromised due to potential probing by hardware adversaries
Solution Approach 1:
The patent introduces an encryption intermediary layer within the link protocol stack that mediates data transmission between devices. This intermediary encrypts data before transmission and decrypts it at the receiving end, allowing normal high-performance data transfer while protecting against hardware adversaries who may probe the physical link.
2Object-affected harmful factors
If encryption is implemented to protect data confidentiality, then security against adversaries is improved, but bandwidth and latency performance deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-computing and caching encryption/decryption keys and intermediate values before data transmission occurs. This allows the cryptographic operations to be performed efficiently without adding significant overhead to the actual data transfer, thus maintaining high bandwidth while ensuring confidentiality.
Solution Approach 2:
The encryption mechanism is integrated directly into the link protocol stack of each device, allowing each device to perform its own encryption and decryption operations independently. This self-service approach eliminates the need for external encryption hardware that would add bandwidth overhead, while still providing strong security protection.
3Object-affected harmful factors
If encryption mechanisms are added to protect links, then confidentiality is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal encryption module within the link protocol stack that can handle multiple encryption algorithms and modes through a single unified interface. This multi-functional design provides comprehensive security protection against various types of attacks while avoiding the need for multiple separate encryption components, thus limiting the increase in device complexity.
Data Source
AI summary
Methods, systems, and apparatuses associated with hardware mechanisms for link encryption are disclosed. In various embodiments, an interconnect interface is coupled to a processor core to interconnect a peripheral device to the processor core via a link established between the peripheral device and the interconnect interface. The interconnect interface is to select a cryptographic engine of a plurality of cryptographic engines instantiated in the interconnect interface for the link. The cryptographic engine is to symmetrically encrypt data to be transmitted through the link. In more specific embodiments, each of the plurality of cryptographic engines is instantiated for one of a request type on the link, a virtual channel on the link, or a request type within a virtual channel on the link.


