US2022278836A1PendingUtilityA1

Device ID for Memory Protection

Assignee: INTEL CORPPriority: Jun 27, 2019Filed: Mar 18, 2022Published: Sep 1, 2022
Est. expiryJun 27, 2039(~12.9 yrs left)· nominal 20-yr term from priority
H04L 9/0866G06F 21/85G06F 21/78H04L 9/002G06F 3/0631H04L 9/088H04L 9/0894G06F 3/062
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There is disclosed in one example a computing system, including: a processor; a memory; and a memory encryption engine (MEE) including circuitry and logic to: allocate a protected isolated memory region (IMR); encrypt the protected IMR; set an access control policy to allow access to the IMR by a device identified by a device identifier; and upon receiving a memory access request directed to the IMR, enforce the access control policy.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method of providing access control to a protected region of a computer memory, comprising:
 receiving, on a communication pathway between a processor and the computer memory, an incoming memory access request, the incoming memory access request comprising a source identifier (source ID) that identifies a device that originated the incoming memory access request;   determining that the incoming memory access request is addressed to a memory address in a memory region for which the source ID is authorized to access; and   based at least in part on the determining, decrypting data from the memory address and providing the decrypted data to the device that originated the incoming memory access request.   
     
     
         22 . The method of  claim 21 , wherein the memory region is an isolated memory region (IMR). 
     
     
         23 . The method of  claim 21 , further comprising denying access to any device not identified by the source ID. 
     
     
         24 . The method of  claim 21 , further comprising determining that the source ID belongs to a class of source IDs authorized to access the memory region. 
     
     
         25 . The method of  claim 21 , further comprising providing partial-scope memory encryption. 
     
     
         26 . The method of  claim 21 , further comprising providing multi-key total memory encryption. 
     
     
         27 . The method of  claim 21 , further comprising providing one or more access policy registers, and setting an access control policy for a memory encryption engine (MEE) on the communication pathway according to the one or more access policy registers. 
     
     
         28 . The method of  claim 21 , further comprising providing a SET_POLICY instruction, the SET_POLICY instruction to provide a software-accessible means for setting an access control policy for the memory region. 
     
     
         29 . The method of  claim 28 , further comprising programming the SET POLICY instruction in microcode. 
     
     
         30 . A computing apparatus, comprising:
 a processor circuit;   a memory; and   a memory encryption circuit between the processor circuit and the memory, the memory encryption circuit comprising circuitry to:
 receive an incoming memory access request, the incoming memory access request comprising a source identifier (source ID) that identifies a device that originated the incoming memory access request; 
 determine that the incoming memory access request is addressed to a memory address in a memory region for which the source ID is authorized to access; and 
 based at least in part on the determining, decrypt data from the memory address and provide the decrypted data to the device that originated the incoming memory access request 
   
     
     
         31 . The computing apparatus of  claim 30 , further comprising an on-die interconnect fabric between the processor circuit and the memory encryption circuit, the on-die interconnect fabric comprising dedicated device identifier bus lines. 
     
     
         32 . The computing apparatus of  claim 30 , further comprising an uncore with source identifier bus lines between the processor circuit and the uncore. 
     
     
         33 . The computing apparatus of  claim 30 , further comprising a peripheral component interconnect express (PCIe) controller, the PCIe controller comprising a device ID processor module. 
     
     
         34 . The computing apparatus of  claim 33 , wherein the device ID processor module comprises circuitry to process a device ID within a transaction layer protocol (TLP) packet prefix. 
     
     
         35 . A memory encryption engine (MEE), comprising circuitry to:
 receive, on a communication pathway between a processor and a computer memory, an incoming memory access request, the incoming memory access request comprising a source identifier (source ID) that identifies a device that originated the incoming memory access request;   determine that the incoming memory access request is addressed to a memory address in a memory region for which the source ID is authorized to access; and   based at least in part on the determining, decrypt data from the memory address and provide the decrypted data to the device that originated the incoming memory access request.   
     
     
         36 . The MEE of  claim 35 , wherein the circuitry is further to deny access to any device not identified by the source ID. 
     
     
         37 . The MEE of  claim 35 , wherein the circuitry is further to determine that the source ID belongs to a class of source IDs authorized to access the memory region. 
     
     
         38 . The MEE of  claim 35 , wherein the circuitry is to provide partial-scope memory encryption. 
     
     
         39 . The MEE of  claim 35 , wherein the circuitry is to provide multi-key total memory encryption. 
     
     
         40 . The MEE of  claim 35 , wherein the circuitry is to interoperate with one or more access policy registers, and set an access control policy for the MEE circuit according to the one or more access policy registers.

Join the waitlist — get patent alerts

Track US2022278836A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.