Memory Encryption Engine for Hardware Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems are vulnerable to hardware-based attacks, allowing attackers with physical access to read system memory contents, including keys and secret information, by removing or isolating memory chips from the system.
Innovation Solution
The implementation of a memory encryption engine (MEE) that seamlessly encrypts memory regions, using cryptographic units to redirect and protect memory transactions, presenting a 'ghost' memory space that is inaccessible directly, thereby preventing unauthorized data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If memory chips are removed or isolated from the system to prevent attacks, then physical security is improved, but direct access to memory contents is lost and system functionality deteriorates
Solution Approach 1:
The patent introduces a memory encryption engine as an intermediary component between the processor and memory chips. This engine intercepts and encrypts memory transactions, allowing physical access to be blocked while maintaining system functionality through cryptographic protection. The encryption engine acts as a mediator that prevents direct reading of memory contents by attackers while still enabling legitimate access through proper decryption protocols.
Solution Approach 2:
The patent changes the state of memory data from plaintext to encrypted form through cryptographic transformation. By altering the parameter of data representation (from readable to encrypted), the system maintains memory functionality for authorized components while rendering the data inaccessible to unauthorized physical access, thus resolving the contradiction between security and accessibility.
2Object-affected harmful factors
If encryption is implemented to protect memory regions, then security against hardware attacks is improved, but system complexity increases due to additional encryption components
Solution Approach 1:
The memory encryption engine is designed to perform multiple functions: it encrypts memory transactions, manages cryptographic keys, and interfaces with both the processor and memory subsystem. By consolidating these functions into a single multi-functional component, the patent reduces overall system complexity compared to having separate components for each function, while still providing comprehensive security protection.
3Object-affected harmful factors
If memory encryption is implemented, then data protection is improved, but processing overhead increases due to encryption/decryption operations
Solution Approach 1:
The encryption key is pre-loaded into the memory encryption engine before memory operations begin. This preliminary action allows the encryption engine to quickly access the key without requiring repeated key retrieval during encryption/decryption operations, thereby reducing processing overhead and maintaining higher memory transaction throughput while still providing strong security protection.
Data Source
AI summary
Systems, apparatuses, and methods, and for seamlessly protecting memory regions to protect against hardware-based attacks are disclosed. In one embodiment, an apparatus includes a decoder, control logic, and cryptographic logic. The decoder is to decode a transaction between a processor and memory-mapped input/output space. The control logic is to redirect the transaction from the memory-mapped input/output space to a system memory. The cryptographic logic is to operate on data for the transaction.


