Trusted Domain Architecture PUF Key Generation TCB Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for providing isolation in virtualized environments do not effectively exclude cloud service provider (CSP) software from the trusted compute base (TCB) and often increase the TCB significantly, failing to provide adequate security and isolation for customer workloads.

Innovation Solution

The implementation of a Trusted Domain (TD) architecture with extensions to the processor instruction set architecture (ISA) that utilizes a physical unclonable function (PUF) to generate encryption keys, enabling secure memory encryption and integrity protection, and a Secure Extended Page Table (SEPT) for isolated memory management, reducing the TCB and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional isolation systems are used in virtualized environments, then isolation between customer workloads and CSP software is provided, but the trusted compute base (TCB) is significantly increased and security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidtrusted compute base
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the TCB reduction capability by implementing a PUF-based key generation system that eliminates the need for traditional key management infrastructure. The PUF circuit generates cryptographic keys locally within the processor, removing the need for external key distribution and management systems, thereby significantly reducing the TCB while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a PUF circuit as an intermediary component that bridges the gap between hardware security requirements and processor operations. This PUF-based intermediary generates unique cryptographic identifiers and keys directly within the processor, serving as a mediator that provides security without requiring additional trusted external systems, thus reducing overall TCB complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PUF-based key generation is implemented, then encryption keys are protected from unauthorized access, but the system complexity increases due to additional hardware components

Engineering Contradiction:
Improvekey protectionVSAvoidhardware components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the PUF circuit functionality directly into the processor core, combining key generation capabilities with existing processor operations. By integrating the PUF circuit with the memory controller and execution units, the system provides key protection without adding separate standalone hardware components, thus minimizing system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The PUF circuit is designed to serve multiple functions: generating cryptographic keys, creating unique processor identifiers, and providing random number generation. This multi-functional approach eliminates the need for separate hardware components for each function, reducing overall system complexity while providing comprehensive key protection and security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If memory encryption is implemented for security, then confidentiality is maintained, but processing overhead and system performance are reduced

Engineering Contradiction:
ImproveconfidentialityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by generating cryptographic keys and encryption parameters in advance using the PUF circuit during processor initialization. The memory encryption keys are pre-generated and stored in secure registers before memory operations begin, eliminating the need for real-time key generation during data processing, thus maintaining high processing speed while ensuring confidentiality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional software-based encryption mechanisms with hardware-accelerated encryption operations. The memory controller incorporates dedicated encryption/decryption circuitry that operates in parallel with memory access operations, substituting mechanical/software processing with hardware-based cryptographic operations, thereby maintaining confidentiality without significant performance penalty.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If platform-unique entropy is generated for each device, then unclonable cryptographic keys are created, but the system requires additional entropy sources and complexity

Engineering Contradiction:
Improvecryptographic uniquenessVSAvoidentropy sources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by designing the PUF circuit to automatically generate platform-unique entropy based on inherent physical variations in the processor's manufacturing process. The system does not require external entropy sources or additional complexity; instead, it exploits the unique physical characteristics of each processor (such as transistor threshold variations) to self-generate cryptographic keys, thereby achieving unclonable security without adding system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4020877B1Isa accessible physical unclonable function
Publication Date: 2024.06.26 INTEL CORP
  • EP4020877B1 patent drawingFigure 1
  • EP4020877B1 patent drawingFigure 2(A)
  • EP4020877B1 patent drawingFigure 2(B)~2(C)

AI summary

Techniques for encrypting data using a key generated by a physical unclonable function (PUF) are described. An apparatus according to the present disclosure may include decoder circuitry to decode an instruction and generate a decoded instruction. The decoded instruction includes operands and an opcode. The opcode indicates that execution circuitry is to encrypt data using a key generated by a PUF. The apparatus may further include execution circuitry to execute the decoded instruction according to the opcode to encrypt the data to generate encrypted data using the key generated by the PUF.