PCIe Link Protection Using Monotonic Counters and Accumulated MACs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic mechanisms for securing PCIe transactions introduce significant latency, limiting the adoption of link protection and offsetting the benefits of acceleration in secure computing environments, such as those using Trust Domain Extensions (TDX), due to cryptographic waste and bandwidth overheads.
Innovation Solution
The implementation of monotonic counters as initialization vectors for AES-GCM encryption and cryptographic splitting with accumulated MACs reduces latency and bandwidth overheads by eliminating cryptographic waste, allowing for zero or reduced latency encryption/decryption of variable-sized requests over PCIe links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authenticated encryption (AES-GCM) is used for PCIe link encryption, then confidentiality, integrity, and replay protection are provided, but significant latency is introduced to PCIe transactions
Solution Approach 1:
The patent pre-generates cryptographic pads (keystreams) for AES-GCM encryption before they are actually needed for data encryption. By anticipating future encryption needs and preparing cryptographic materials in advance, the system eliminates the computational delay that would normally occur during PCIe transactions, thus reducing latency while maintaining security
Solution Approach 2:
The patent divides the cryptographic processing into separate stages: pad generation, pad validation, and data encryption. By segmenting the cryptographic workflow and validating pads independently before use, the system can prepare cryptographic materials in parallel with data transmission, reducing the overall latency impact on PCIe transactions
2Reliability
If conventional cryptographic mechanisms are used for link protection, then security requirements are met, but bandwidth overheads increase due to cryptographic waste
Solution Approach 1:
The patent pre-generates cryptographic pads in advance with validation, ensuring they are ready for immediate use during PCIe transactions. This eliminates the need to generate and validate pads during actual data transmission, reducing cryptographic waste and bandwidth overhead by avoiding redundant computational operations
Solution Approach 2:
The patent changes the timing parameter of cryptographic operations from synchronous (during transmission) to asynchronous (before transmission). By altering when cryptographic operations occur, the system optimizes bandwidth utilization and reduces overhead without compromising security
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, apparatuses, methods, and computer-readable media are provided for reducing or eliminating cryptographic waste for link protection in computer buses. In various embodiments, data packets are encrypted/decrypted in accordance with advanced encryption standard (AES) Galois counter mode (GCM) encryption/decryption. Monotonically increased counter values are used as initialization vectors; and/or accumulated MAC is practiced to reduce or eliminate cryptographic waste. Other related aspects are also described and/or claimed.