Shared Security Metadata Memory Space for Encryption Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current memory encryption systems, such as Total Memory Encryption with integrity (TMEi) and Memory Encryption Engine (MEE), face significant storage overheads due to the need for extensive security metadata, which hinders efficient memory protection and increases system resource utilization.

Innovation Solution

The proposed solution involves sharing the security metadata memory space between MEE and TMEi, allowing portions of the metadata to coexist and share memory, thereby reducing storage overheads by utilizing address mapping and resetting counters and MACs to prevent integrity failures during page conversions between encryption types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security metadata is stored separately for each encryption type (MEE and TMEi), then security protection is ensured, but memory storage overhead increases significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidmemory storage overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security metadata storage for MEE and TMEi into a shared memory space. Instead of allocating separate metadata regions for each encryption type, the system allows both MEE and TMEi to store their security metadata in the same memory region, thereby reducing overall memory overhead while maintaining security protection for both encryption types

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared security metadata memory space serves multiple functions simultaneously - it stores security metadata for both MEE-encrypted pages and TMEi-encrypted pages. This multi-functional approach allows a single memory region to fulfill the security metadata storage requirements of two different encryption systems, eliminating the need for duplicate storage

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate security metadata is allocated for MEE and TMEi, then integrity protection is maintained, but system resource utilization decreases

Engineering Contradiction:
Improveintegrity protectionVSAvoidsystem resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system combines the security metadata management of MEE and TMEi into a unified shared memory space, allowing both encryption types to coexist with their respective integrity protection mechanisms while utilizing the same storage resources, thereby improving system resource utilization without compromising integrity protection

Inventive Principle:
Principle #5Merging (Combining)

3Quantity of substance

If security metadata is shared between MEE and TMEi, then storage overhead is reduced, but complexity of managing different encryption types increases

Engineering Contradiction:
Improvestorage overheadVSAvoidmanagement complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The shared security metadata memory space is segmented into distinct regions or logically separated areas, where MEE security metadata and TMEi security metadata are stored in separate but adjacent or interleaved segments. This segmentation allows the system to reduce storage overhead through sharing while maintaining manageable complexity by providing clear boundaries and organization for different encryption types

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (such as a metadata management unit or control logic) that mediates between MEE and TMEi when accessing the shared security metadata space. This intermediary handles the complexity of managing different encryption types by providing a unified interface and coordination layer, allowing both encryption systems to access their required metadata without direct conflict or complex interaction

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10528485B2Method and apparatus for sharing security metadata memory space
Publication Date: 2020.01.07 INTEL CORP
  • US10528485B2 patent drawing
  • US10528485B2 patent drawing
  • US10528485B2 patent drawing

AI summary

The presently disclosed method and apparatus for sharing security metadata memory space proposes a technique to allow metadata sharing two different encryption techniques. A section of memory encrypted using a first type of encryption and having first security metadata associated therewith is converted to a section of memory encrypted using a second type of encryption and having second security metadata associated therewith. At least a portion of said first security metadata shares a memory space with at least a portion of said second security metadata for a same section of memory.