Multi-key cryptographic memory protection
Abstract
In one embodiment, an apparatus comprises a processor to execute instruction(s), wherein the instructions comprise a memory access operation associated with a memory location of a memory. The apparatus further comprises a memory encryption controller to: identify the memory access operation; determine that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory; identify an encryption key associated with the protected domain; perform a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and return a result of the cryptography operation, wherein the result is to be used for the memory access operation.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus, comprising:
a processor to execute one or more instructions, wherein the one or more instructions comprise a memory access operation associated with a memory location of a memory; a memory encryption controller to:
identify the memory access operation associated with the memory location of the memory;
determine that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory;
identify an encryption key associated with the protected domain;
perform a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and
return a result of the cryptography operation, wherein the result of the cryptography operation is to be used for the memory access operation.
2 . The apparatus of claim 1 :
wherein the memory access operation comprises a memory read operation; and wherein the memory encryption controller to perform the cryptography operation on the data associated with the memory access operation is further to:
obtain the data from the memory location of the memory; and
decrypt the data based on the encryption key associated with the protected domain.
3 . The apparatus of claim 1 :
wherein the memory access operation comprises a memory write operation; and wherein the memory encryption controller to perform the cryptography operation on the data associated with the memory access operation is further to encrypt the data based on the encryption key associated with the protected domain, wherein the result of the cryptography operation is to be written to the memory location of the memory.
4 . The apparatus of claim 1 , wherein the memory encryption controller to perform the cryptography operation on the data associated with the memory access operation is further to:
identify an encryption type associated with the protected domain, wherein the plurality of protected domains is associated with a plurality of encryption types; and perform the cryptography operation based on the encryption type associated with the protected domain.
5 . The apparatus of claim 1 :
wherein the plurality of protected domains comprises a plurality of execution contexts; and wherein each protected domain of the plurality of protected domains comprises a particular execution context of the plurality of execution contexts.
6 . The apparatus of claim 1 :
wherein the plurality of protected domains is further associated with a plurality of encryption keys; and wherein each protected domain of the plurality of protected domains is associated with a particular encryption key of the plurality of encryption keys.
7 . The apparatus of claim 6 :
wherein the plurality of protected domains is further associated with a plurality of users; and wherein each protected domain of the plurality of protected domains is associated with a particular user of the plurality of users.
8 . The apparatus of claim 1 , wherein the memory encryption controller is further to:
identify a command to add a second protected domain to the plurality of protected domains; identify a second protected memory region associated with the second protected domain; identify a second encryption key associated with the second protected domain; and configure the second protected domain based on the second protected memory region and the second encryption key.
9 . The apparatus of claim 8 , wherein the processor further comprises:
an instruction cache comprising a platform configuration instruction, wherein the platform configuration instruction comprises the command to add the second protected domain to the plurality of protected domains; a decoder to decode the platform configuration instruction; and an execution unit to program the second protected domain in the memory encryption controller.
10 . The apparatus of claim 8 , wherein the memory encryption controller is further to:
determine a protection mode associated with the second protected domain; and configure the second protected domain based on the protection mode.
11 . The apparatus of claim 10 , wherein the protection mode comprises: plaintext mode; default encryption mode; or custom encryption mode.
12 . At least one machine accessible storage medium having instructions stored thereon, wherein the instructions, when executed on a machine, cause the machine to:
identify a memory access operation associated with a memory location of a memory; determine that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory; identify an encryption key associated with the protected domain; perform a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and return a result of the cryptography operation, wherein the result of the cryptography operation is to be used for the memory access operation.
13 . The storage medium of claim 12 :
wherein the memory access operation comprises a memory read operation; and wherein the instructions that cause the machine to perform the cryptography operation on the data associated with the memory access operation further cause the machine to:
obtain the data from the memory location of the memory; and
decrypt the data based on the encryption key associated with the protected domain.
14 . The storage medium of claim 12 :
wherein the memory access operation comprises a memory write operation; and wherein the instructions that cause the machine to perform the cryptography operation on the data associated with the memory access operation further cause the machine to encrypt the data based on the encryption key associated with the protected domain, wherein the result of the cryptography operation is to be written to the memory location of the memory.
15 . The storage medium of claim 12 , wherein the instructions that cause the machine to perform the cryptography operation on the data associated with the memory access operation further cause the machine to:
identify an encryption type associated with the protected domain, wherein the plurality of protected domains is associated with a plurality of encryption types; and perform the cryptography operation based on the encryption type associated with the protected domain.
16 . The storage medium of claim 12 :
wherein the plurality of protected domains is further associated with a plurality of encryption keys; and wherein each protected domain of the plurality of protected domains is associated with a particular encryption key of the plurality of encryption keys.
17 . The storage medium of claim 16 :
wherein the plurality of protected domains is further associated with a plurality of users; and wherein each protected domain of the plurality of protected domains is associated with a particular user of the plurality of users.
18 . The storage medium of claim 12 , wherein the instructions further cause the machine to:
identify a command to add a second protected domain to the plurality of protected domains; identify a second protected memory region associated with the second protected domain; identify a second encryption key associated with the second protected domain; and configure the second protected domain based on the second protected memory region and the second encryption key.
19 . The storage medium of claim 18 , wherein the instructions further cause the machine to:
determine a protection mode associated with the second protected domain; and configure the second protected domain based on the protection mode.
20 . The storage medium of claim 19 , wherein the protection mode comprises: plaintext mode; standard encryption mode; or custom encryption mode.
21 . A system, comprising:
a memory; a processor to execute one or more instructions, wherein the one or more instructions comprise a memory access operation associated with a memory location of the memory; a memory encryption controller to:
identify the memory access operation associated with the memory location of the memory;
determine that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory;
identify an encryption key associated with the protected domain;
perform a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and
return a result of the cryptography operation, wherein the result of the cryptography operation is to be used for the memory access operation.
22 . The system of claim 21 :
wherein the plurality of protected domains is further associated with a plurality of users of a cloud service provider; and wherein each protected domain of the plurality of protected domains is associated with a particular user of the plurality of users.
23 . The system of claim 21 , wherein the memory comprises solid-state memory for providing persistent data storage.
24 . A method, comprising:
identifying a memory access operation associated with a memory location of a memory; determining that the memory location is associated with a protected domain, wherein the protected domain is associated with a protected memory region of the memory, and wherein the protected domain is identified from a plurality of protected domains associated with a plurality of protected memory regions of the memory; identifying an encryption key associated with the protected domain; performing a cryptography operation on data associated with the memory access operation, wherein the cryptography operation is performed based on the encryption key associated with the protected domain; and returning a result of the cryptography operation, wherein the result of the cryptography operation is to be used for the memory access operation.
25 . The method of claim 24 , further comprising:
identifying a command to add a second protected domain to the plurality of protected domains; identifying a second protected memory region associated with the second protected domain; identifying a second encryption key associated with the second protected domain; and configuring the second protected domain based on the second protected memory region and the second encryption key.Join the waitlist — get patent alerts
Track US2019004973A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.