Multi-Domain Memory Encryption Engine for Isolated Cryptographic Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption engines face challenges in implementing multiple cryptographically isolated domains with memory protections due to complex and inefficient techniques, leading to poor performance and limited capabilities in memory encryption, integrity, and replay protection.

Innovation Solution

An encryption engine that uses three keys or pairs of keys for encryption, MAC generation, and metadata tree updates, enabling quick and efficient memory protections by generating data and MACs with domain-specific keys and updating metadata trees with a metadata key, providing integrity and replay protection across multiple cryptographic domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple cryptographically isolated domains are implemented with memory protections, then memory security and capabilities are enhanced, but device complexity and implementation difficulty increase significantly

Engineering Contradiction:
Improvememory securityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic system into distinct domains, each with its own encryption keys and memory protection mechanisms. This allows multiple isolated cryptographic domains to coexist while managing complexity through modular organization of security contexts and key management structures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal memory protection framework that can serve multiple cryptographic domains simultaneously. The same memory encryption engine and protection mechanisms are reused across different domains, reducing overall system complexity while maintaining security isolation through domain-specific key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If complex encryption techniques are used for multiple domains, then memory protection capabilities are improved, but processing speed and performance deteriorate

Engineering Contradiction:
Improvememory protection capabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary actions by pre-establishing encryption keys and security contexts for each domain before actual memory operations. This allows the encryption engine to quickly switch between domains using pre-configured parameters, reducing real-time processing overhead while maintaining strong protection capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes cryptographic parameters efficiently by domain, allowing the system to optimize encryption operations for each specific domain's requirements. The encryption engine can switch between different key sets and parameters without full re-initialization, maintaining both security and performance.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If domain-specific keys are used for encryption and MAC generation, then cryptographic isolation between domains is improved, but key management complexity increases

Engineering Contradiction:
Improvecryptographic isolationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary key management structure that mediates between multiple domain-specific keys and the encryption engine. This intermediary layer handles key selection, switching, and management operations, providing strong cryptographic isolation while simplifying the overall key management process through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a dimensional layer to key management by organizing keys in a hierarchical or multi-level structure. Instead of managing multiple independent keys at the same level, the system introduces an additional management dimension that allows efficient organization, selection, and switching between domain keys through structured access patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If metadata trees are updated with separate metadata keys, then integrity verification is improved, but operation overhead increases

Engineering Contradiction:
Improveintegrity verificationVSAvoidoperation overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the metadata update and verification operations into a unified process. By combining the metadata tree structure with the existing memory protection framework and using the same encryption engine for both data encryption and metadata verification, the system reduces operational overhead while maintaining strong integrity verification across domains.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11042652B2Techniques for multi-domain memory encryption
Publication Date: 2021.06.22 INTEL CORP
  • US11042652B2 patent drawing
  • US11042652B2 patent drawing
  • US11042652B2 patent drawing

AI summary

Various embodiments are generally directed to techniques for multi-domain memory encryption, such as with a plurality of cryptographically isolated domains, for instance. Some embodiments are particularly directed to a multi-domain encryption system that provides one or more of memory encryption, integrity, and replay protection services to a plurality of cryptographic domains. In one embodiment, for example, an apparatus may comprise a memory and logic for an encryption engine, at least a portion of the logic implemented in circuitry coupled to the memory. In various embodiments, the logic may receive a memory operation request associated with a data line of a set of data lines stored in a protected memory separate from the memory.