Shared Security Metadata Memory Space for Encryption Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory encryption systems, such as Total Memory Encryption with integrity (TMEi) and Memory Encryption Engine (MEE), face significant storage overheads due to the need for extensive security metadata, which hinders efficient memory protection and increases system resource utilization.
Innovation Solution
The proposed solution involves sharing the security metadata memory space between MEE and TMEi, allowing portions of the metadata to coexist and share memory, thereby reducing storage overheads by utilizing address mapping and resetting counters and MACs to prevent integrity failures during page conversions between encryption types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security metadata is stored separately for each encryption type (MEE and TMEi), then security protection is ensured, but memory storage overhead increases significantly
Solution Approach 1:
The patent merges the security metadata storage for MEE and TMEi into a shared memory space. Instead of allocating separate metadata regions for each encryption type, the system allows both MEE and TMEi to store their security metadata in the same memory region, thereby reducing overall memory overhead while maintaining security protection for both encryption types
Solution Approach 2:
The shared security metadata memory space serves multiple functions simultaneously - it stores security metadata for both MEE-encrypted pages and TMEi-encrypted pages. This multi-functional approach allows a single memory region to fulfill the security metadata storage requirements of two different encryption systems, eliminating the need for duplicate storage
2Reliability
If separate security metadata is allocated for MEE and TMEi, then integrity protection is maintained, but system resource utilization decreases
Solution Approach 1:
The system combines the security metadata management of MEE and TMEi into a unified shared memory space, allowing both encryption types to coexist with their respective integrity protection mechanisms while utilizing the same storage resources, thereby improving system resource utilization without compromising integrity protection
3Quantity of substance
If security metadata is shared between MEE and TMEi, then storage overhead is reduced, but complexity of managing different encryption types increases
Solution Approach 1:
The shared security metadata memory space is segmented into distinct regions or logically separated areas, where MEE security metadata and TMEi security metadata are stored in separate but adjacent or interleaved segments. This segmentation allows the system to reduce storage overhead through sharing while maintaining manageable complexity by providing clear boundaries and organization for different encryption types
Solution Approach 2:
The patent introduces an intermediary mechanism (such as a metadata management unit or control logic) that mediates between MEE and TMEi when accessing the shared security metadata space. This intermediary handles the complexity of managing different encryption types by providing a unified interface and coordination layer, allowing both encryption systems to access their required metadata without direct conflict or complex interaction
Data Source
AI summary
The presently disclosed method and apparatus for sharing security metadata memory space proposes a technique to allow metadata sharing two different encryption techniques. A section of memory encrypted using a first type of encryption and having first security metadata associated therewith is converted to a section of memory encrypted using a second type of encryption and having second security metadata associated therewith. At least a portion of said first security metadata shares a memory space with at least a portion of said second security metadata for a same section of memory.


