Multi-Crypto-Color-Group Memory Integrity for Replay Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory integrity solutions for virtual machines and enclaves are inefficient in protecting against replay attacks, often resulting in high memory overhead or performance limitations.
Innovation Solution
The Multi-Crypto-Color-Group (MCCG) memory integrity method employs encryption engines to encrypt data using key domain selectors and crypto colors, ensuring separate memory protection for virtual machines and enclaves through a multi-stage diffusion process, shielding key domain selectors and crypto colors from the Virtual Machine Monitor and maintaining integrity check values for each unit of data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If replay tree search or state maintenance is used to protect against replay attacks, then security is improved, but memory overhead increases and performance decreases
Solution Approach 1:
The patent changes the parameter of memory protection by introducing a replay counter stored in a dedicated register rather than in memory structures. This counter is incremented with each memory access and used to detect replay attacks, eliminating the need for replay trees or state maintenance in memory, thus improving performance while maintaining security.
Solution Approach 2:
The patent extracts the replay protection mechanism from memory-based structures (replay trees, state maintenance) and relocates it to a register-based counter. This extraction removes the memory overhead and performance penalties associated with searching replay trees or maintaining complex state, while preserving the ability to detect replay attacks.
2Reliability
If key domain selectors are used for memory encryption, then security against corruption events is improved, but device complexity increases
Solution Approach 1:
The patent makes the key domain selector serve multiple functions: it is used both for memory encryption/decryption and for replay attack detection. By combining these functions into a single mechanism, the patent reduces device complexity while maintaining protection against both corruption events and replay attacks.
Solution Approach 2:
The patent merges the replay counter functionality with the key domain selector mechanism. The replay counter is stored in the same register as the key domain selector and uses the same cryptographic operations, combining multiple security functions into a unified system that reduces overall complexity.
Data Source
AI summary
Embodiments of apparatus, method, and storage medium associated with MCCG memory integrity for securing/protecting memory content/data of VM or enclave are described herein. In some embodiments, an apparatus may include one or more encryption engines to encrypt a unit of data to be stored in a memory in response to a write operation from a VM or an enclave of an application, prior to storing the unit of data into the memory in an encrypted form; wherein to encrypt the unit of data, the one or more encryption engines are to encrypt the unit of data using at least a key domain selector associated with the VM or enclave, and a tweak based on a color within a color group associated with the VM or enclave. Other embodiments may be described and/or claimed.


