Memory Encryption Engine for Hardware Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems are vulnerable to hardware-based attacks, allowing attackers with physical access to read system memory contents, including keys and secret information, by removing or isolating memory chips from the system.

Innovation Solution

The implementation of a memory encryption engine (MEE) that seamlessly encrypts memory regions, using cryptographic units to redirect and protect memory transactions, presenting a 'ghost' memory space that is inaccessible directly, thereby preventing unauthorized data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If memory chips are removed or isolated from the system to prevent attacks, then physical security is improved, but direct access to memory contents is lost and system functionality deteriorates

Engineering Contradiction:
ImprovePhysical security against hardware attacksVSAvoidDirect memory access capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent introduces a memory encryption engine as an intermediary component between the processor and memory chips. This engine intercepts and encrypts memory transactions, allowing physical access to be blocked while maintaining system functionality through cryptographic protection. The encryption engine acts as a mediator that prevents direct reading of memory contents by attackers while still enabling legitimate access through proper decryption protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of memory data from plaintext to encrypted form through cryptographic transformation. By altering the parameter of data representation (from readable to encrypted), the system maintains memory functionality for authorized components while rendering the data inaccessible to unauthorized physical access, thus resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If encryption is implemented to protect memory regions, then security against hardware attacks is improved, but system complexity increases due to additional encryption components

Engineering Contradiction:
ImproveVulnerability to hardware-based attacksVSAvoidSystem architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The memory encryption engine is designed to perform multiple functions: it encrypts memory transactions, manages cryptographic keys, and interfaces with both the processor and memory subsystem. By consolidating these functions into a single multi-functional component, the patent reduces overall system complexity compared to having separate components for each function, while still providing comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If memory encryption is implemented, then data protection is improved, but processing overhead increases due to encryption/decryption operations

Engineering Contradiction:
ImproveData accessibility by attackersVSAvoidMemory transaction throughput
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The encryption key is pre-loaded into the memory encryption engine before memory operations begin. This preliminary action allows the encryption engine to quickly access the key without requiring repeated key retrieval during encryption/decryption operations, thereby reducing processing overhead and maintaining higher memory transaction throughput while still providing strong security protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8799673B2Seamlessly encrypting memory regions to protect against hardware-based attacks
Publication Date: 2014.08.05 TENSTORRENT USA INC
  • US8799673B2 patent drawing
  • US8799673B2 patent drawing
  • US8799673B2 patent drawing

AI summary

Systems, apparatuses, and methods, and for seamlessly protecting memory regions to protect against hardware-based attacks are disclosed. In one embodiment, an apparatus includes a decoder, control logic, and cryptographic logic. The decoder is to decode a transaction between a processor and memory-mapped input/output space. The control logic is to redirect the transaction from the memory-mapped input/output space to a system memory. The cryptographic logic is to operate on data for the transaction.