Memory Device Cryptographic Protection Host Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems face challenges in securely executing software applications that require access to cryptographically protected memory, as existing solutions often limit processing capabilities and memory usage while maintaining security, particularly in cloud environments where trust and security are paramount.

Innovation Solution

A computer system architecture that utilizes a host computer device and multiple memory devices to cryptographically protect volatile memory, allowing secure execution of software applications by splitting application portions between the host and memory devices, with the memory devices providing direct access and caching policies to enhance data throughput and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software applications are executed on a host computer device with cryptographic protection, then security is improved, but processing capabilities and memory usage are limited

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing capabilities
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the software application into multiple portions, with security-critical portions executed on the memory device with cryptographic protection and non-critical portions executed on the host computer device. This segmentation allows the system to maintain high security for sensitive operations while preserving overall processing capabilities through parallel execution on both devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic protection is applied to volatile memory, then security is improved, but memory access speed and throughput are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidmemory access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The memory device acts as an intermediary between the host computer device and the cryptographic protection mechanism. It provides a dedicated processor that handles cryptographic operations locally, allowing the host to access protected memory through standardized interfaces without directly performing cryptographic checks, thus maintaining access speed while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If software applications are split between host and memory devices, then processing capabilities are improved, but device complexity increases

Engineering Contradiction:
Improveprocessing capabilitiesVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The memory device is designed with multi-functionality, serving both as protected storage and as a processing unit capable of executing application portions. This universal design reduces the need for separate dedicated security hardware, simplifying the overall system architecture while maintaining enhanced processing capabilities through the integrated processor on the memory device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11010309B2Computer system and method for executing one or more software applications, host computer device and method for a host computer device, memory device and method for a memory device and non-transitory computer readable medium
Publication Date: 2021.05.18 INTEL CORP
  • US11010309B2 patent drawing
  • US11010309B2 patent drawing
  • US11010309B2 patent drawing

AI summary

A computer system for executing one or more software applications includes a host computer device configured to execute the one or more software applications. The computer system further includes one or more memory devices configured to cryptographically protect volatile memory of the one or more memory devices. The one or more memory devices are configured to provide access to the cryptographically protected volatile memory for the one or more software applications. The host computer device is configured to execute the one or more software applications by executing a portion of the one or more software applications associated with the cryptographically protected volatile memory using a processor of the one or more memory devices.