PCIe Device Authentication Engine Using Mailbox Registers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current interconnect architectures in computing systems face challenges in providing high-performance communication while ensuring security and trustworthiness, particularly with the proliferation of PCIe devices that require advanced authentication mechanisms to prevent counterfeiting and ensure device integrity.

Innovation Solution

The implementation of enhanced PCIe device authentication features, including device firmware measurement and cryptographic authentication, to establish trust relationships between hosts and devices, utilizing a layered protocol stack and extended capability structures to verify device identities and capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional multi-drop buses are used for interconnect communication, then device compatibility and ease of implementation are improved, but communication speed and performance are limited

Engineering Contradiction:
Improveease of implementationVSAvoidcommunication speed
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent segments the traditional multi-drop bus architecture into multiple point-to-point interconnect links, allowing parallel communication paths between host and devices. This segmentation enables higher communication speeds while maintaining ease of implementation through standardized link interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional multi-drop bus topology to a multi-dimensional point-to-point interconnect architecture with multiple independent communication channels. This dimensional change enables simultaneous data transfers across multiple links, dramatically increasing overall communication throughput.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If device authentication mechanisms are implemented, then security and trustworthiness are improved, but device complexity and authentication overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-provisioning cryptographic authentication credentials (public keys, certificates) in the devices during manufacturing. This preliminary setup enables rapid authentication operations during runtime without requiring complex real-time key generation or management, thus improving security while controlling complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication protocol that mediates between the host and devices. The protocol uses standardized challenge-response mechanisms with pre-provisioned credentials, simplifying the authentication process while ensuring strong security. The intermediary protocol layer abstracts the cryptographic complexity from the device logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11677730B2Device authentication
Publication Date: 2023.06.13 INTEL CORP
  • US11677730B2 patent drawing
  • US11677730B2 patent drawing
  • US11677730B2 patent drawing

AI summary

A device includes a microcontroller, memory including secure memory to store a private key, a set of registers, and an authentication engine. The set of registers includes a write mailbox register and a read mailbox register, and message data is to be written to the write mailbox register by a host system. The message data includes at least a portion of a challenge request, and the challenge request includes a challenge by the host system to authenticity of the device. The authentication engine generates a response to the challenge, where the response includes data to identify attributes of the device and a signature generated using the private key. The authentication engine causes at least a portion of the response to be written to the read mailbox register to be read by the host system.