Multi-Key Memory Encryption via Ownership Table Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information processing systems face challenges in securing data in memory, especially as data and enterprise workloads are increasingly moved to the cloud, where data in memory remains vulnerable to attacks.
Innovation Solution
The implementation of a trust domain architecture with Multi-Key Total Memory Encryption (MK-TME) engine, Memory Ownership Table (MOT), and secure arbitration mode (SEAM) provides cryptographic isolation and secure operation of tenant workloads by using multiple encryption keys for different memory regions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple encryption keys are used for different memory regions, then data security and isolation are improved, but device complexity increases
Solution Approach 1:
The memory address space is segmented into different regions, each associated with a specific encryption key. The Memory Ownership Table (MOT) divides memory into pages, where each page can be independently encrypted with different keys. This segmentation allows multiple encryption keys to be managed systematically without overwhelming complexity, as each segment has dedicated key management.
Solution Approach 2:
The Memory Ownership Table (MOT) acts as an intermediary structure between the memory hardware and the encryption key management system. It mediates the complexity by providing a centralized mapping mechanism that translates memory addresses to corresponding encryption keys, eliminating the need for complex distributed key management across the system.
2Adaptability or versatility
If cloud-based virtualization is used to host enterprise workloads, then resource sharing and accessibility are improved, but data vulnerability to attacks increases
Solution Approach 1:
Different memory regions are assigned different encryption keys based on their ownership and sensitivity requirements. This local quality approach ensures that each memory region is encrypted with the appropriate key for its specific workload and security requirements, rather than using a uniform encryption scheme that would compromise either flexibility or security.
Solution Approach 2:
The virtualized memory space is segmented into distinct regions with separate encryption keys for different tenants and workloads. This segmentation isolates data from different cloud customers, preventing cross-tenant data access even though all workloads share the same physical hardware infrastructure.
Data Source
AI summary
Embodiments of apparatuses, methods, and systems for scalable multi-key memory encryption are disclosed. In an embodiment, an apparatus includes a core, an encryption unit, and key identification hardware. The core is to write data to and read data from memory regions, each to be identified by a corresponding address. The encryption unit to encrypt data to be written and decrypt data to be read. The key identification hardware is to use a portion of the corresponding address to look up a corresponding key identifier in a key information data structure. The corresponding key identifier is one multiple key identifiers. The corresponding key identifier is to identify which one of multiple encryption keys is to be used to encrypt and decrypt the data.


