Multi-Domain Memory Encryption Engine for Isolated Cryptographic Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption engines face challenges in implementing multiple cryptographically isolated domains with memory protections due to complex and inefficient techniques, leading to poor performance and limited capabilities in memory encryption, integrity, and replay protection.
Innovation Solution
An encryption engine that uses three keys or pairs of keys for encryption, MAC generation, and metadata tree updates, enabling quick and efficient memory protections by generating data and MACs with domain-specific keys and updating metadata trees with a metadata key, providing integrity and replay protection across multiple cryptographic domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple cryptographically isolated domains are implemented with memory protections, then memory security and capabilities are enhanced, but device complexity and implementation difficulty increase significantly
Solution Approach 1:
The patent segments the cryptographic system into distinct domains, each with its own encryption keys and memory protection mechanisms. This allows multiple isolated cryptographic domains to coexist while managing complexity through modular organization of security contexts and key management structures.
Solution Approach 2:
The patent creates a universal memory protection framework that can serve multiple cryptographic domains simultaneously. The same memory encryption engine and protection mechanisms are reused across different domains, reducing overall system complexity while maintaining security isolation through domain-specific key management.
2Reliability
If complex encryption techniques are used for multiple domains, then memory protection capabilities are improved, but processing speed and performance deteriorate
Solution Approach 1:
The patent performs preliminary actions by pre-establishing encryption keys and security contexts for each domain before actual memory operations. This allows the encryption engine to quickly switch between domains using pre-configured parameters, reducing real-time processing overhead while maintaining strong protection capabilities.
Solution Approach 2:
The patent changes cryptographic parameters efficiently by domain, allowing the system to optimize encryption operations for each specific domain's requirements. The encryption engine can switch between different key sets and parameters without full re-initialization, maintaining both security and performance.
3Reliability
If domain-specific keys are used for encryption and MAC generation, then cryptographic isolation between domains is improved, but key management complexity increases
Solution Approach 1:
The patent introduces an intermediary key management structure that mediates between multiple domain-specific keys and the encryption engine. This intermediary layer handles key selection, switching, and management operations, providing strong cryptographic isolation while simplifying the overall key management process through centralized control.
Solution Approach 2:
The patent adds a dimensional layer to key management by organizing keys in a hierarchical or multi-level structure. Instead of managing multiple independent keys at the same level, the system introduces an additional management dimension that allows efficient organization, selection, and switching between domain keys through structured access patterns.
4Reliability
If metadata trees are updated with separate metadata keys, then integrity verification is improved, but operation overhead increases
Solution Approach 1:
The patent merges the metadata update and verification operations into a unified process. By combining the metadata tree structure with the existing memory protection framework and using the same encryption engine for both data encryption and metadata verification, the system reduces operational overhead while maintaining strong integrity verification across domains.
Data Source
AI summary
Various embodiments are generally directed to techniques for multi-domain memory encryption, such as with a plurality of cryptographically isolated domains, for instance. Some embodiments are particularly directed to a multi-domain encryption system that provides one or more of memory encryption, integrity, and replay protection services to a plurality of cryptographic domains. In one embodiment, for example, an apparatus may comprise a memory and logic for an encryption engine, at least a portion of the logic implemented in circuitry coupled to the memory. In various embodiments, the logic may receive a memory operation request associated with a data line of a set of data lines stored in a protected memory separate from the memory.


