EP4655695A1 - Inline encryption and/or decryption using address tagging - Google Patents
Inline encryption and/or decryption using address taggingInfo
- Publication number
- EP4655695A1 EP4655695A1 EP24709546.6A EP24709546A EP4655695A1 EP 4655695 A1 EP4655695 A1 EP 4655695A1 EP 24709546 A EP24709546 A EP 24709546A EP 4655695 A1 EP4655695 A1 EP 4655695A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- storage device
- address
- data
- memory
- encryption
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
Definitions
- the present disclosure generally relates to a technique for protecting information (e.g., encry pting a file system).
- aspects of the present disclosure relate to systems and techniques for inline encryption using address tagging.
- Computing devices often employ various techniques to protect data.
- data may be subjected to encry ption and decry ption techniques in a variety 7 of scenarios, such as writing data to a storage device, reading data from a storage device, writing data to or reading data from a memory device, encrypting and decrypting blocks and/or volumes of data, encrypting and decrypting digital content, performing inline cryptographic operations, etc.
- encry ption and decryption operations are often performed, at least in part, using a security 7 information asset, such as a cryptographic key, a derived cryptographic key, etc.
- a security 7 information asset such as a cryptographic key, a derived cryptographic key, etc.
- a method for data access includes determining a storage device address for a storage device, determining a tag for obtaining metadata for encryption of data for the storage device, generating a return address, the return address including a host memory address and the tag, and accessing the storage device based on the return address and the storage device address.
- the apparatus includes at least one memory, a storage device, and at least one processor coupled to the at least one memory.
- the at least one processor is configured to determine a storage device address for the storage device, determine a tag for obtaining metadata for encryption of data for the storage device, generate a return address, the return address including a host memory address and the tag, and access the storage device based on the return address and the storage device address.
- a non-transitory computer-readable medium has stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: determine a storage device address for a storage device, determine a tag for obtaining metadata for encryption of data for the storage device, generate a return address, the return address including a host memory’ address and the tag, and access the storage device based on the return address and the storage device address.
- an apparatus for data access includes: means for determining a storage device address for a storage device, means for determining a tag for obtaining metadata for encryption of data for the storage device, means for generating a return address, the return address including a host memory address and the tag, and means for accessing the storage device based on the return address and the storage device address.
- one or more of the apparatuses described herein is, is part of, and/or includes a mobile or wireless communication device (e.g., a mobile telephone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a network-connected watch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device such as a mobile phone acting as a server device, an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system-on-a-chip (SoC), any combination thereof, and/or other type
- the apparatus(es) include(s) a display for displaying one or more images, notifications, and/or other displayable data.
- the apparatus(es) include(s) can include one or more sensors (e.g.. one or more RF sensors), such as one or more gyroscopes, one or more gyrometers, one or more accelerometers, any combination thereof, and/or other sensor(s).
- FIG. 1 is a block diagram illustrating certain components of a computing device, in accordance with some examples
- FIG. 2 illustrates an example PCIe transaction layer packet format configured to perform inline encryption/ decry ption using address tagging, in accordance with aspects of the present disclosure
- FIG. 3 is a flow diagram illustrating an example process for data access, in accordance with some examples
- FIG. 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology.
- any component described with regard to a figure, in various examples described herein, may be equivalent to one or more like-named (or numbered) components described with regard to any other figure.
- descriptions of these components may not be wholly repeated with regard to each figure.
- each and every example of the components of each figure is incorporated by reference and assumed to be optionally present within every other figure having one or more like-named components.
- any description of the components of a figure is to be interpreted as an optional example, which may be implemented in addition to, in conjunction with, or in place of the examples described with regard to a corresponding like-named component in any other figure.
- the phrase operatively connected, or operative connection means that there exists between el ements/components/d evices, etc. a direct or indirect connection that allows the elements to interact with one another in some way.
- the phrase "operatively connected' may refer to any direct (e.g., wired directly between two devices or components) or indirect (e.g., wired and/or wireless connections between any number of devices or components connecting the operatively connected devices) connection.
- any path through which information may travel may be considered an operative connection.
- operatively connected devices and/or components may exchange things, and/or may inadvertently share things, other than information, such as. for
- Polsinelli Ref. No. 094922-780686 example, electrical current, radio frequency signals, power supply interference, interference due to proximity, interference due to re-use of the same wire and/or physical medium, interference due to re-use of the same register and/or other logical medium, etc.
- a storage device such as a hard disk, solid state drive, flash drive, etc. may be secured using disk encryption, such as full disk encryption.
- disk encryption such as full disk encryption.
- an encryption operation may be performed. This encryption operation may be based on certain metadata, such as a key and/or tweak value. This key and/or tweak may be based on a logical block address (LB A) such that each encrypted sector has an associated key and a unique 128-bit tweak that includes the LBA. Thus, a portion of the address for data may be used to lookup metadata for access to the storage device.
- LB A logical block address
- Encrypting/decrypting data for disk encryption may be performed using software-based encryption or a stand-alone encryption hardware (e.g., encryption hardware that does not read/write directly from/to a memory' used for reading from/writing to the storage device), but such solutions may increase latency and bandwidth load on the memory.
- Other approaches may involve modifications to existing protocols.
- inline address tagging may use a portion of an address (e.g., a peripheral component interconnect express (PCIe) address) as an inline address tag to lookup metadata for encrypting/decrypting data for/from the storage device.
- PCIe peripheral component interconnect express
- the inline address tag may be used as an index for lookup in a data segment table (DST).
- DST data segment table
- the DST may be an in-memory table including information for determining metadata for encry pting/decry pting data.
- Inline cry ptography may refer to encrypting/decrypting the data for the storage device as a part of the read/write process transparently to existing PCIe/NVMe storage devices.
- a storage device may retrieve encrypted data from the storage device and write the data to a memory location.
- the encrypted data stream may be automatically decrypted and written to the memory location. This may be performed without having to, for example, copy the entirety of the encry pted data to another memory to perform the decoding.
- Polsinelli Ref. No. 094922-780686 including metadata for encrypting/ decry ting data in a PCIe address (e.g., return address) for accessing a storage device allows a single request to be used to obtain data that is to be encrypted/decrypted along with metadata for performing the encryption/decryption.
- a PCIe address e.g., return address
- Encoding the inline address tag into a PCIe address helps avoid having to change an underlying protocol.
- FIG. 1 is a block diagram illustrating an example of a computing device 100 configured to perform inline encryption/decryption using inline address tagging, in accordance with aspects of the present disclosure.
- the computing device 100 includes a processor 102, a nonvolatile memory express (NVMe) device 104, a bus 106, a memory 7 device 108, an additional storage device 110, an inline cryptographic engine 112, and a peripheral component interconnect express (PCIe) interface 114.
- the memory device 108 may include a data segment table (DST) 118.
- the DST 118 may be a part of the inline cryptographic engine 112 or other hardware component.
- the computing device 100 is any device, portion of a device, or any set of devices capable of electronically processing instructions and may include, but is not limited to, any of the following: one or more processors (e.g. components that include integrated circuitry, memory, input and output device(s) (not shown), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and/or any combination thereof. Examples of computing devices include, but are not limited to.
- processors e.g. components that include integrated circuitry, memory, input and output device(s) (not shown), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and/or any combination thereof.
- Examples of computing devices include, but are not limited to.
- a mobile device e.g., laptop computer, smart phone, personal digital assistant, tablet computer, automobile computing system, and/or any other mobile computing device
- an Internet of Things (loT) device e.g., a server (e.g., a blade-server in a blade-server chassis, a rack server in a rack, etc.), a desktop computer, a storage device (e.g., a disk drive array, a fibre channel storage device, an Internet Small Computer Systems Interface (iSCSI) storage device, a tape storage device, a flash storage array, a netw ork attached storage device, etc.), a network device (e.g., switch, router, multi-layer switch, etc.), a wearable device (e.g., a network-connected w atch or smartwatch, or other wearable device), a robotic device, a smart television, a smart appliance, an extended reality (XR) device (e.g.. augmented reality, virtual reality, etc.), any device that
- XR extended
- Polsinelli Ref. No. 094922-780686 includes one or more SoCs, and/or any other type of computing device with the aforementioned requirements. In one or more examples, any or all of the aforementioned examples may be combined to create a system of such devices, which may collectively be referred to as a computing device. Other types of computing devices may be used without departing from the scope of examples described herein.
- the processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program).
- circuitry may be integrated circuitry implemented, at least in part, using transistors implementing such components as arithmetic logic units, control units, logic gates, registers, first-in. first-out (FIFO) buffers, data and control buffers, etc.
- the processor may include additional components, such as, for example, cache memory.
- a processor retrieves and decodes instructions, which are then executed. Execution of instructions may include operating on data, which may include reading and/or writing data.
- the instructions and data used by a processor are stored in the memory (e.g., memory device 108) of the computing device 100.
- a processor may perform various operations for executing software, such as operating systems, applications, etc.
- the processor 102 may cause data to be written from memory to storage of the computing device 100 and/or cause data to be read from storage via the memory. Examples of processors include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), neural processing units, tensor processing units, display processing units, digital signal processors (DSPs), finite state machines, etc.
- the processor 102 may be integrated into a system on a chip (SoC) 116.
- SoC system on a chip
- the SoC 116 may also incorporate the bus 106, the memory device 108, the inline cryptographic engine 112. and the PCIe interface 114.
- the NVMe device 104 and additional storage device 110 may be coupled to, but separate from, the SoC 116.
- the processor 102 may be operatively connected to the memory device 108, any storage (e.g., NVMe device 104, additional storage device 110) of the computing device 100, and/or to the inline cryptographic engine 112 via bus 106.
- any storage e.g., NVMe device 104, additional storage device 110
- FIG. 1 shows the computing device 100 having a single processor 102, the computing device may include any number of processors without departing from the scope of examples described herein.
- the computing device 100 includes a NVMe device 104.
- the NVMe device 104 is a flash storage device conforming to the NVMe specification, which defines a protocol which may be overlaid over (e.g., extend the functionality of) the PCIe interface 114.
- the NVMe device 104 may be used for storing data of any ty pe. Data may be written to and/or read from the NVMe device 104.
- the NVMe device may store operating system images, software images, application data, etc.
- the NVMe device 104 may store any other type of data without departing from the scope of examples described herein.
- the NVMe device 104 includes NAND flash storage.
- the NVMe device 104 may use any other type of storage technology without departing from the scope of examples described herein.
- the NVMe device 104 is capable of data rates that are relatively faster than other storage devices (e.g., additional storage device 110) of the computing device 100.
- the NVMe device 104 may be operatively connected to the processor 102, the memory' device 108, and/or the additional storage device 110.
- FIG. 1 shows the computing device 100 having a single NVMe device 104, the computing device may include any number of NVMe devices without departing from the scope of examples described herein. Additionally, although FIG. 1 shows the NVMe device 104. the computing device 100 may include any' other type of flash storage device without departing from the scope of examples described herein.
- the NVMe device 104 may be coupled to a PCIe interface 114.
- the PCIe interface 114 may be a physical input/output (I/O) interface for connecting various components, or peripheral devices, such the components may be used by the computing device 100.
- multiple device may be coupled via the PCIe interface 114, such as the NVMe device and the additional storage device 110.
- different communications protocols may be used over the PCIe interface 114 to communicate with devices coupled via the PCIe interface 114.
- the NVMe protocol may' be used to communicate with the NVMe device 104 over the PCIe interface 114.
- Other communications protocols may also be used.
- PCIe and NVMe it should be understood that the concepts discussed herein are not limited to PCIe and NVMe, but could be applied to other component interfaces.
- a host for the PCIe interface 114 such as the processor 102, may access the NVMe device 104 by providing commands and/or data for the NVMe device 104.
- the processor 102 may queue a set of NVMe commands (e.g., requests), addresses, and/or data for the NVMe device 104 in a buffer, such as memory device 108.
- the bulfer may be used for the NVMe device 104 to write out data from the buffer to the NVMe device 104 and/or to read in data from the NVMe device 104 to the buffer and the addresses may indicate where on the NVMe device 104 and/or buffer to perform read/writes to.
- An NVMe command to perform a read/write may include an NVMe command identifier to identify the NVMe command. In some cases, the NVMe command may be 64 bits in size.
- placing the NVME command into the bulfer may trigger a doorbell signal configured to indicate to the NVMe device 104 that the NVMe command in the buffer is ready for execution.
- the NVMe device 104 may respond to queued NVMe commands in the buffer in any order (e.g., in order, out of order, etc.). In some cases, there may be multiple queues of NVMe commands.
- the NVMe device 104 may read data from the buffer to be written to the NVMe device 104 (e.g., for write commands), or the NVMe device 104 may write data retrieved from the NVMe device 104 to the buffer (e.g., in response to read commands).
- the computing device 100 includes an additional storage device 110.
- the additional storage device is a non-volatile storage device.
- the additional storage device 110 may. for example, be a persistent memory device.
- the additional storage device 110 may be computer storage of any type. Examples of type of computer storage include, but are not limited to, hard disk drives, solid state drives, flash storage, tape drives, removable disk drives, Universal Serial Bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, etc.
- USB Universal Serial Bus
- SD secure digital
- FIG. 1 shows the additional storage device 110 as part of the computing device 100, the additional storage device may be separate from and operatively connected to the computing device 100 (e.g., an external drive array, cloud storage, etc.).
- the additional storage device 110 operates at a data rate that is relatively slower than the NVMe device 104. In some examples, the additional storage device 110 is also a NVMe storage device. In some examples, the additional storage device 110 is operatively connected to the processor 102. the NVMe device 104, the inline cryptographic engine 112, and/or the memory device 108. Although FIG. 1 shows the computing device 100 having a single additional storage device 110, the computing device 100 may have any number of additional storage devices without departing from the scope of examples described herein.
- the computing device 100 includes a memory device 108.
- the memory device may be any type of computer memory’.
- the memory device 108 is a volatile storage device.
- the memory device 108 may be random access memory (RAM).
- data stored in the memory device 108 is located at memory’ addresses, and is thus accessible to the processor 102 and/or the inline cry ptographic engine 112 using the memory addresses.
- the processor 102 and/or secure execution environment may write data to and/or read data from the memory device 108 using the memory' addresses.
- the memory device 108 may be used to store any type of data, such as, for example, computer programs, the results of computations, etc.
- the memory device 108 is operatively connected to the processor 102, the NVMe device 104, the additional storage device 110, and the inline cryptographic engine 112.
- FIG. 1 shows the computing device 100 having a single memory device 108, the computing device 100 may have any number of memory’ devices without departing from the scope of examples described herein.
- the computing device 100 mcludes any number of security components (e.g., multiple inline cryptographic engines 112).
- the security components may be any component capable of performing various cryptographic services, and may thus be any hardware (e.g., circuitry), software, firmware, or any combination thereof.
- the security components are a sub-chip hardware components of a system on a chip (SoC), which may include other components shown in FIG. 1 such as, for example, the processor 102. Any other components of the computing device 100 may also be included as part of an SoC without departing from the scope of examples described herein.
- SoC system on a chip
- the security components exist in a data path between storage devices (e.g., NVMe storage device 104, additional storage device 110) and the memory device 108, and/or data paths between the processor 102 and the memory device 108 or any of the storage devices (e.g., 104, 110). In some examples, all or any portion of the security components may be considered “inline” cryptographic engines. In some examples, the security components are configured to perform any number of cryptographic service types on data being read from or written to a storage device (e g., NVMe device 104, additional storage device 110) and/or a memory device 108 of the computing device 100. In some examples, all or any portion of the data passing from memory to storage, from storage to memory, or to or from the processor 102 of the computing device 100 passes through a security component.
- storage devices e.g., NVMe storage device 104, additional storage device 110
- the security components are configured to perform any number of cryptographic service types on data being read from or written to a storage device (e g.
- cry ptographic sendee types that may be performed include, but are not limited to. encrypting data, decrypting data, key derivation, performing data integrity verification, and performing authenticated encryption and decryption.
- the security components are configured to perform the various cryptographic service types by being configured to execute one or more cry ptographic algorithms.
- one or more security components may be configured to execute one or more of the Advanced Encryption Standard XOR-encrypt-XOR Tweakable Block Ciphertext Stealing (AES-XTS) algorithm, the AES-Cypher Block Chaining (AES-CBC) algorithm, the AES -Electronic Codebook (AES-EBC) algorithm, the Encrypted Salt-Sector Initialization Vector-AES-CBC (ESSIV-AES-CBC) algorithm, etc., including any variants of such algorithms (e.g., 128 bits, 192 bits, 256 bits, etc.).
- AES-XTS Advanced Encryption Standard XOR-encrypt-XOR Tweakable Block Ciphertext Stealing
- AES-CBC AES-Cypher Block Chaining
- AES-EBC AES -Electronic Codebook
- ESSIV-AES-CBC Encrypted Salt-Sector Initialization Vector-AES-CBC
- the security component may be configured to execute a hash algorithm such as, for example, the one or more members of the SHA family of hash algorithms.
- a security component may be configured to perform the AES-Galois/Counter Mode (GCM) algorithm.
- GCM AES-Galois/Counter Mode
- the security component may be configured to execute any other cryptographic algorithms without departing from the scope of examples described herein.
- the inline cry ptographic engine 112 is a hardware component (e.g.. including circuitry) that may execute software and/or firmware, and is configured to perform various operations or services to secure the computing device 100.
- the inline cryptographic engine 112 can perform inline encryption and/or decryption using inline address tagging.
- FIG. 1 shows a certain number of components in a particular configuration
- the computing device 100 may include more components or fewer components, and/or components arranged in any number of alternate configurations without departing from the scope of examples described herein.
- the computing device 100 may 7 execute any 7 amount or type of software or firmware (e.g., bootloaders, operating systems, hypervisors, virtual machines, computer applications, mobile device apps, etc.). Accordingly, examples disclosed herein should not be limited to the configuration of components shown in FIG. 1.
- the components shown in FIG. 1 may or may not be discrete
- one or more of the components can be combined into different hardware elements, implemented in software, and/or otherwise implemented using software and/or hardware.
- the term device may be a discrete component or apparatus, or may not be a discrete component.
- other devices can exist within, be part of, and/or utilize the same hardware components as a device.
- a processor such as processor 102 of FIG. 1, may access a storage device, such as NVMe device 104 or additional storage device 110 of FIG. 1, via a memory space, such as an SoC memory space or processor memory' space.
- a processor may access a nonvolatile memory express (NVMe) storage device (e.g., part of the additional storage device 110) via a read or write command and the read or write commands may have an associated SoC memory space available (e.g., allocated) for data to be read/written.
- NVMe storage device may be a storage device that is accessible via an NVMe interface.
- the NVMe interface may operate on top of an interface, such as the PCIe interface 114.
- NVMe may include protocol commands and structures that may be transferred by PCIe.
- the NVMe storage device may be accessed using NVMe over the PCIe interface 114.
- NVMe devices such as NVMe device 104, that operate over the PCIe interface 114 may directly access a host memory (e.g., SoC memory, processor I/O memory, and the like) space, such as one on memory' device 108.
- the memory space may be logically organized into one or more sets of data segments.
- data segments may be contiguous sections of SoC memory, and there may be one DST entry per data segment.
- Data segments which may be contiguous in the memory space may be stored in contiguous data segments on the storage.
- each data segment is a contiguous, nonoverlapping section of SoC memory'.
- the inline cry ptographic engine 112 may use a DST 118 configured by software (e.g., a driver, system process, etc.) that defines the location and size of every data segment, which data segments have encry ption enabled, and metadata needed for encryption/decryption operations.
- software e.g., a driver, system process, etc.
- data segments with encryption enabled contain I/O data that is stored in consecutive sectors on the NVMe device 104.
- a storage device may be divided into sectors.
- sectors may be specified by their logical block address (LBA).
- LBA logical block address
- a number and size of sectors for a storage device may be fixed.
- sector size and number may be statically configured, such as by software, prior to enabling encryption for the storage device.
- a storage device such as a non-volatile, non-transitory computer- readable memory device such as a hard disk, flash drive, or other types of computer readable media which can store data that are accessible by a computer
- a storage device may be encrypted using full disk encryption.
- Full disk encr ption may refer to a storage device on which data on the storage device is encrypted.
- metadata to access e.g., read/write
- the storage device such as a master boot record may also be encrypted.
- full disk encryption may be performed based on an encryption scheme such as advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
- AES-XTS advanced encryption standard xor encrypt xor tweakable block ciphertext stealing
- AES-XTS is a tweakable encry ption scheme which uses the AES encry ption cipher and tweak values.
- a tweakable encryption scheme no two sectors should be processed in the same way.
- the tweak attempts to mimic a random permutation for the cipher.
- the tweak may be based on a sector address and an index of a block within the sector.
- AES-XTS uses a key and a non-secret tweak value to perform an encrypt or decrypt operation to read/write data from/to the storage device.
- the key and tweak may be based on the LBA (or other storage device address) such that each encry pted sector has an associated key and a unique 128-bit tweak that includes the LBA (or other storage device address).
- the storage device may be accessible using aNVMe interface or other peripheral interface.
- the peripheral interface may not directly provide a way to provide the metadata for the encrypt/decrypt operation for a storage device with full disk encry ption.
- the NVMe/PCIe protocol stack does not natively provide a way to specify an inline address tag where a portion of the PCIe address may be used as the inline address tag to lookup information for encrypting/decrypting data for the storage device.
- the PCIe address (e.g., return address) may be an address used by the storage device (e.g., storage device accessible via a PCIe bus) to access SoC memory (e.g., host memory 7 ).
- SoC memory 7 may be a memory' space accessible to the components of the SoC (e.g., processor) to which the storage device may write return information or data (e.g., return codes, or data requested by a storage read operation) to.
- FIG. 2 illustrates an example PCIe transaction layer packet format 200 configured to perform inline encryption/decryption using inline address tagging, in accordance with aspects of the present disclosure.
- the example packet format 200 may use 64-bit addressing and include four double words (DW0 202, DW1 204, DW2206, and DW3 208).
- DW0 202 and DW1 204 may include header, status, length, hosting information, completer information, and/or other PCIe configuration information for setting up a PCIe transaction. Details of bit fields in DW0 202 and DW1 204 have been omitted for clarity.
- the packet format 200 may include a 64-bit return address in DW2 206 and DW3 208. In some cases, a reserved field may also be included after the return address (e.g., with a shorter return address).
- the return address may identify the device and address the PCIe device (e.g., a storage device) may return data or return information (e.g.. return codes) to.
- a PCIe device may have a return address space (e.g., PCIe address) that the PCIe device may be access (e.g., by performing I/O operations) to return data or return information (e.g., return codes) from the storage device.
- a portion of the return address (e.g., in DW2 206) may be used for cryptographic operations.
- an upper 16 bits of the PCIe address may be used as an Inline address tag 212.
- the Inline address tag 212 may be used as an index (e.g., pointer, number, and the like) into a DST (e.g., DST 118 of FIG. 1 ).
- Information in the DST table may provide sufficient information to determine the tweak and key for encrypting/decrypting data for the storage device.
- the encrypting/decry pting of the data using the tweak and key may then proceed in memory in a manner similar to current full disk encryption techniques.
- the DST may be stored in a memory (e.g., an in-memory table), such as memory device 108.
- a PCIe host memory address (e.g., SoC address) space 214 may be used for PCIe accesses for the storage device (e.g., NVMe protocol structures, address information data for a given external drive and its associated PCIe interface, and the like).
- a different Inline address tag 212 for NVMe PCIe accesses may be used for each NVMe inline cryptographic engine instance (e.g., implemented using the inline cryptographic engine 112 of FIG. 1).
- software may allocate and configure an entry in the DST for each NVMe storage command (e.g., read/write command) data segment before submitting the command to the command queue (e.g., for execution).
- Each entry in the DST may be 16 bytes long.
- the Inline address tag 212 for NVMe PCIe accesses may be statically configured by software for each interface (e.g., per drive interface).
- the lower 48-bit PCIe host memory address (e.g., SoC address) space 214 does not have to be exclusively used by one
- the lower 48 bits of the PCIe host memory address space 214 may be used as a SoC memory address (e.g.. a host memory address accessible to components of the SoC (e.g., processor) where the storage device may write return data and information) and the upper 16 bits may be used as the Inline address tag 212 for accessing the DST.
- SoC memory address e.g.. a host memory address accessible to components of the SoC (e.g., processor) where the storage device may write return data and information
- the upper 16 bits may be used as the Inline address tag 212 for accessing the DST.
- PCIe transfers associated with a NVMe storage command data segments for a storage device may be processed according to the DST entry selected by the Inline address tag 212.
- software allocates and configures an entry' in the DST for data segments associated with the NVMe interface when drive encryption is enabled.
- SoC memory that is accessed by the NVMe device may fall within a data segment listed in the DST.
- the inline cr ptographic engine may verify transactions against a selected entry in the DST.
- storage commands are verified (e.g., by the inline cry ptographic engine 112 of FIG.
- the DST 118 is stored in a memory and may be up to 64,000 entries (and in some cases higher).
- a RAM that can support a 64.000-entry table can be 1 megabyte (MB). In some examples, a smaller table can be sufficient.
- the hardware can be configured for a smaller local RAM.
- keys (e.g., index) for data (e.g., all data) associated with read and write commands can be (and in some cases must be) preloaded by software into the inline cryptographic engine before issuing the command.
- the DST 118 may be managed (e.g., adding and/or removing entries in the DST 118) by software executing, for example, on a processor, such as processor 102, or as a part of the inline cry ptographic engine 112. In other cases, the DST 118 may be managed by hardware, for example, in the inline cryptographic engine 112.
- the inline cryptographic engine 112 may include a small, fully associative cache that holds the most recently accessed DST entries.
- the cache may include the capability for software to invalidate entries when they are deallocated in the DST 118.
- the DST 118 may be stored in a memory on a processor and/or SOC (e.g., memory device 108), such as a cache.
- the DST 118 may be stored in a RAM separate from the processor and/or SOC, such as a system memory.
- a storage write to store data into a full disk encrypted NVMe device 104 may be performed by the processor 102.
- the processor 102 may write the data along with appropriate commands and headers for the storage write to appropriate mapped memory location(s). for example in the memory device 108. for storage writes.
- the appropriate mapped memory location(s) may be a location accessible by the inline cryptographic engine 112.
- the processor 102 may also write to the appropriate mapped memory location(s) an LBAaddress (e.g., address for the storage device or other storage device address) indicating where on the NVMe device 104 the data should be written.
- the processor 102 may also write to the appropriate mapped memory location(s) a return address (e.g..
- the return address may include a 48 bit portion including the host memory' address (e.g., SoC address) and a 16 bit (e.g., upper 16 bits) Inline address tag (e.g., as discussed above with respect to FIG. 2).
- the lower 48 bits may be sufficient for return SoC address and information to be returned may be written based on the 48 bit return address.
- the processor 102 may also write to a portion (e.g., row) of the DST 118 (or to the inline cryptographic engine 112 to write to the DST 118), metadata for processing a PCIe transaction for the storage write.
- the metadata may include information for encrypting/decrypting data (e.g., to determine the tweak and key), along with addresses to where data may be accessed/written to (e.g., start/end addresses, size), command submission queue identifiers, sector information, etc.
- the inline cryptographic engine 112 may return an index (e.g., pointer) indicating which portion (e.g., row) of the DST 118 the metadata was stored. This index may be included in the Inline address tag.
- multiple segments e. g. , of the DST 118
- the Inline address tag and the LBA address may be used by, for example, the inline cryptographic engine 112 to encrypt/decrypt data transferred to/from the NVMe device 104.
- the Inline address tag may include the index (e.g., pointer) indicating a portion (e.g., row) of a DST 118 (e.g., table, array, linked list, graph, etc.) in the inline cryptographic engine 112 that includes the metadata for processing the PCIe transaction.
- the processor 102 may indicate (e.g., via a doorbell signal such as an interrupt), to the NVMe device 104, that there is data for the NVMe device 104.
- the NVMe device 104 may then, based on the indication, access the appropriate mapped memory location(s) in the memory device 108 to obtain the LBA address, data, return address, and appropriate commands and headers.
- the inline cryptographic engine 112 may encode the data based on the LBA address and tag.
- the NVMe device 104 may then write the encoded data to the LBA address and transmit an appropriate return code to the return address.
- the NVMe device 104 does not process the tag of the return address and may just ignore the tag.
- the processor 102 may remove the entry in the DST 118, for example, after the appropriate return code is received.
- a storage read may be performed in a manner similar to the storage write.
- the processor 102 may write appropriate commands and headers for the storage read, along with LBA information for the requested data and a return address.
- the upper 16 bits of the return address may also include the ICE tag
- the lower 48 bits may include the return SoC address (e.g., or other memory location) for the storage read to a mapped memory location in the memory device 108 for storage reads.
- the processor 102 may also write to a portion (e.g., row) of the DST 118 (or to the inline cryptographic engine 112 to write to the DST 118), metadata for processing a PCIe transaction for the storage read.
- the NVMe device 104 may then, based on the indication, access the mapped memory location in the memory device 108 to obtain the LBA address, return address, and appropriate commands and headers.
- the NVMe device 104 may access the LBA address to obtain the requested data and transmit the requested data for storage at the return address along with LBA address information and return address information.
- the inline cryptographic engine 112 may decode the requested data based on the LBA address and Inline address tag in the return address. For example, the inline cryptographic engine 112 may access the Inline
- Polsinelli Ref. No. 094922-780686 address tag to obtain the index into the DST 118 to retrieve metadata regarding the PCIe transaction.
- the metadata and LBA address may be used to decode the requested data.
- the decoded information may be stored based on the return address (e.g.. in the lower 48 bits).
- FIG. 3 is a flow diagram illustrating a process 300 for image processing, in accordance with aspects of the present disclosure.
- the process 300 may be performed by a computing device (or apparatus) or a component (e.g., a chipset, codec, etc.) of the computing device.
- the computing device may be a mobile device (e g., a mobile phone), a network- connected wearable such as a watch, an extended reality (XR) device such as a virtual reality (VR) device or augmented reality (AR) device, a vehicle or component or system of a vehicle, or other type of computing device.
- the operations of the process 300 may be implemented as software components that are executed and run on one or more processors.
- the computing device may determine a storage device address for a storage device.
- the storage device address comprises a logical block address (LBA), and wherein the memory table includes LBA information for the storage device.
- the computing device may generate a tweak for the encry ption of data based on the LBA information.
- the computing device may determine a tag for obtaining metadata for encry ption of data for the storage device.
- the encryption of the data comprises encrypting or decry pting the data.
- the tag includes 16 bits.
- the storage device is encrypted using full disk encryption.
- the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
- the computing device may generate a return address.
- the return address includes a host memory address and the tag.
- the tag comprises an index (e.g., key) to a memory table of keys for the encryption of data.
- the storage device comprises a peripheral component interconnect express (PCIe) bus device.
- the return address comprises a PCIe address.
- the tag is included in an upper 16 bits of the PCIe address.
- the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCIe bus.
- NVMe nonvolatile memory express
- the computing device may access the storage device based on the return address and the storage device address.
- the computing device (or component thereol) may access the storage device by storing at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
- the techniques or processes described herein may be performed by a computing device, an apparatus, and/or any other computing device.
- the computing device or apparatus may include a processor, microprocessor, microcomputer, or other component of a device that is configured to cany' out the steps of processes described herein.
- the computing device or apparatus may include a camera configured to capture video data (e.g., a video sequence) including video frames.
- the computing device may include a camera device, which may or may not include a video codec.
- the computing device may include a mobile device with a camera (e.g., a camera device such as a digital camera, an IP camera or the like, a mobile phone or tablet including a camera, or other type of device with a camera).
- the computing device may include a display for displaying images.
- a camera or other capture device that captures the video data is separate from the computing device, in which case the computing device receives the captured video data.
- the computing device may further include a network interface, transceiver, and/or transmitter configured to communicate the video data.
- the network interface, transceiver, and/or transmitter may be configured to communicate Internet Protocol (IP) based data or other network data.
- IP Internet Protocol
- the processes described herein can be implemented in hardware, computer instructions, or a combination thereof.
- the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations.
- computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types.
- the order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and/or in parallel to implement the processes.
- the devices or apparatuses configured to perform the operations of the process 300 and/or other processes described herein may include a processor, microprocessor, micro-computer, or other component of a device that is configured to carry out the steps of the process 300 and/or other process.
- such devices or apparatuses may include one or more sensors configured to capture image data and/or other sensor measurements.
- such computing device or apparatus may include one or more sensors and/or a camera configured to capture one or more images or videos.
- such device or apparatus may include a display for displaying images.
- the one or more sensors and/or camera are separate from the device or apparatus, in which case the device or apparatus receives the sensed data.
- Such device or apparatus may further include a network interface configured to communicate data.
- the components of the device or apparatus configured to carry out one or more operations of the process 300 and/or other processes described herein can be implemented in circuitry.
- the components can include and/or can be implemented using electronic circuits or other electronic hardware, which can include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and/or other suitable electronic circuits), and/or can include and/or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein.
- programmable electronic circuits e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and/or other suitable electronic circuits
- the computing device may further include a display (as an example of the output device or in addition to the output device), a network interface configured to communicate and/or receive the data, any combination thereof, and/or other component(s).
- the network interface may be configured to communicate and/or receive Internet Protocol (IP) based data or other type of data.
- IP Internet Protocol
- the process 300 is illustrated as a logical flow diagram, the operations of which represent sequences of operations that can be implemented in hardware, computer instructions, or a combination thereof.
- the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations.
- computerexecutable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of
- the processes described herein may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g.. executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof.
- code e.g.. executable instructions, one or more computer programs, or one or more applications
- the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program including a plurality of instructions executable by one or more processors.
- the computer-readable or machine-readable storage medium may be non-transitory.
- the processes described herein may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g.. executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof.
- code e.g.. executable instructions, one or more computer programs, or one or more applications
- the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors.
- the computer-readable or machine-readable storage medium may be non-transitory.
- FIG. 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology.
- computing system 400 can be for example any computing device making up internal computing system, a remote computing system, a camera, or any component thereof in which the components of the system are in communication with each other using connection 405.
- Connection 405 can be a physical connection using a bus, or a direct connection into processor 410, such as in a chipset architecture.
- Connection 405 can also be a virtual connection, networked connection, or logical connection.
- computing system 400 is a distributed system in which the functions described in this disclosure can be distributed within a datacenter, multiple data centers, a peer network, etc.
- one or more of the described system components represents many such components each performing some or all of the function for
- the components can be physical or virtual devices.
- Example system 400 includes at least one processing unit (CPU or processor) 410 and connection 405 that couples various system components including system memory 415, such as read-only memory (ROM) 420 and random access memory (RAM) 425 to processor 410.
- system memory 415 such as read-only memory (ROM) 420 and random access memory (RAM) 425 to processor 410.
- Computing system 400 can include a cache 412 of high-speed memory connected directly with, in close proximity to, or integrated as part of processor 410.
- Processor 410 can include any general purpose processor and a hardware service or software service, such as services 432, 434. and 436 stored in storage device 430. configured to control processor 410 as well as a special-purpose processor where software instructions are incorporated into the actual processor design.
- Processor 410 may essentially be a completely self-contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc.
- a multi-core processor may be symmetric or asymmetric.
- computing system 400 includes an input device 445, which can represent any number of input mechanisms or sensors, such as a microphone for speech (e.g., a user speaking), a touch-sensitive screen for gesture or graphical input (e.g., a user performing sign language symbols, a user shaking a phone, etc.), keyboard (e.g., a user pressing a key), mouse, motion input, a determination that a user is in a location indicated by a positioning system or modem sub-system, etc., which may be used to activate counters described in previous sections and enable/disable the asset transmission chain at any stage previously described.
- Computing system 400 can also include output device 435, which can be one or more of a number of output mechanisms.
- multimodal systems can enable a user to provide multiple types of input/ output to communicate with computing system 400.
- Computing system 400 can include communications interface 440, which can generally govern and manage the user input and system output.
- the communication interface may perform or facilitate receipt and/or transmission wired or wireless communications using wired and/or wireless transceivers, including those making use of an audio jack/plug, a microphone j ack/plug, a universal serial bus (USB) port/plug, an Apple® Lightning® port/plug, an Ethernet port/plug, a fiber optic port/plug, a proprietary wired port/plug, a BLUETOOTH® wireless signal transfer, a BLUETOOTH® low energy (BLE) wireless signal transfer, an IBEACON®
- Polsinelli Ref. No. 094922-780686 wireless signal transfer a radio-frequency identification (RFID) wireless signal transfer, nearfield communications (NFC) wireless signal transfer, dedicated short range communication (DSRC) wireless signal transfer, 802.11 Wi-Fi wireless signal transfer, wireless local area network (WLAN) signal transfer, Visible Light Communication (VLC), Worldwide Interoperability for Microwave Access (WiMAX), Infrared (IR) communication wireless signal transfer, Public Switched Telephone Network (PSTN) signal transfer, Integrated Services Digital Network (ISDN) signal transfer, 3G/4G/5G/LTE cellular data network wireless signal transfer, ad-hoc network signal transfer, radio wave signal transfer, micro wave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer along the electromagnetic spectrum, or some combination thereof.
- RFID radio-frequency identification
- NFC nearfield communications
- DSRC dedicated short range communication
- 802.11 Wi-Fi wireless signal transfer wireless local area network (WLAN) signal transfer, Visible Light Communication (
- the communications interface 440 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers that are used to determine a location of the computing system 400 based on receipt of one or more signals from one or more satellites associated with one or more GNSS systems.
- GNSS systems include, but are not limited to, the US-based Global Positioning System (GPS), the Russia-based Global Navigation Satellite System (GLONASS), the China-based BeiDou Navigation Satellite System (BDS), and the Europe-based Galileo GNSS.
- GPS Global Positioning System
- GLONASS Russia-based Global Navigation Satellite System
- BDS BeiDou Navigation Satellite System
- Galileo GNSS Europe-based Galileo GNSS
- Storage device 430 can be a non-volatile and/or non-transitory and/or computer- readable memory device and can be a hard disk or other types of computer readable media which can store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory’ devices, digital versatile disks, cartridges, a floppy disk, a flexible disk, a hard disk, magnetic tape, a magnetic strip/stripe, any other magnetic storage medium, flash storage, memristor memory', any other solid-state memory', a compact disc read only memory' (CD-ROM) optical disc, a rewritable compact disc (CD) optical disc, digital video disk (DVD) optical disc, a blu-ray® disc (BDD) optical disc, a holographic optical disk, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory Stick® card, a smartcard chip, a EMV chip, a subscriber identity' module (SSD) card
- the storage device 430 can include software instructions or code that can be executed by the processor 410 to cause the system 400 to perform a function.
- computer-readable medium includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing, containing, or carry ing instruction(s) and/or data.
- a computer-readable medium may include a non-transitory medium in which data can be stored and that does not include carrier waves and/or transitory electronic signals propagating wirelessly or over wired connections. Examples of a non-transitory medium may include, but are not limited to, a magnetic disk or tape, optical storage media such as compact disk (CD) or digital versatile disk (DVD), flash memory, memory or memory devices.
- a computer-readable medium may have stored thereon code and/or machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements.
- a code segment may be coupled to another code segment or a hardware circuit by passing and/or receiving information, data, arguments, parameters, or memory contents.
- Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted using any suitable means including memory sharing, message passing, token passing, nefyvork transmission, or the like.
- the computer-readable storage devices, mediums, and memories can include a cable or yvireless signal containing a bit stream and the like.
- non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals per se.
- Processes and methods according to the above-described examples can be implemented using computer-executable instructions that are stored or otherwise available from computer-readable media.
- Such instructions can include, for example, instructions and data which cause or otherwise configure a general purpose computer, special purpose computer, or a processing device to perform a certain function or group of functions. Portions of computer resources used can be accessible over a network.
- the computer executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmw are, source code, etc.
- Examples of computer-readable media that may be used to store instructions, information used, and/or information created during methods according to described examples include magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, networked storage devices, and so on.
- Devices implementing processes and methods according to these disclosures can include hardware, software, firmware, middleware, microcode, hardware description
- the program code or code segments to perform the necessary tasks may be stored in a computer-readable or machine-readable medium.
- a processor(s) may perform the necessary tasks.
- form factors include laptops, smartphones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rackmount devices, standalone devices, and so on.
- Functionality described herein also can be embodied in peripherals or add-in cards. Such functionality can also be implemented on a circuit board among different chips or different processes executing in a single device, by way of further example.
- the instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are example means for providing the functions described in the disclosure.
- Coupled to refers to any component that is physically connected to another component either directly or indirectly, and/ or any component that is in communication with another component (e.g., connected to the other component over a wired or wireless connection, and/or other suitable communication interface) either directly or indirectly.
- Claim language or other language reciting “at least one of’ a set and/or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim.
- claim language reciting “at least one of A and B” or “at least one of A or B” means A, B. or A and B.
- claim language reciting “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any duplicate information or data (e.g., A and A, B and B, C and C, A and A and B, and so on), or any other ordering, duplication, or combination of A, B. and C.
- the language “at least one of' a set and/or “one or more” of a set does not limit the set to the items listed in the set.
- claim language reciting “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B.
- the phrases “at least one” and “one or more” are used interchangeably herein.
- Claim language or other language reciting “at least one processor configured to,” “at least one processor being configured to,” “one or more processors configured to,” “one or more processors being configured to,” or the like indicates that one processor or multiple processors (in any combination) can perform the associated operation(s).
- claim language reciting “at least one processor configured to: X, Y, and Z” means a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each tasked with a certain subset of operations X, Y, and Z such that together the multiple processors perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z.
- one element may perform all functions, or more than one element may collectively perform the functions.
- each function need not be performed by each of those elements (e.g.. different functions may be performed by different elements) and/or each function need not be performed in whole by only one element (e.g., different elements may perform different sub-functions of a function).
- one element may be configured to cause the other element to perform all functions, or more than one element may collectively be configured to cause the other element to perform the functions.
- an entity e.g., any entity or device described herein
- the entity may be configured to cause one or more elements (individually or collectively) to perform the functions.
- the one or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) of the functions, and/or any combination thereof.
- the entity 7 may be configured to cause one component to perform all functions, or to cause more than one component to collectively perform the functions.
- each function need not be performed by each of those components (e.g., different functions may be performed by different components) and/or each function need not be performed in whole by only one component (e.g., different components may perform different sub-functions of a function).
- the techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices such as general purposes computers, wireless communication device handsets, or integrated circuit devices having multiple uses including application in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, performs one or more of the methods described above.
- the computer-readable data storage medium may form part of a computer program product, which may include packaging materials.
- the computer-readable medium may comprise memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASEI memory, magnetic or optical data storage media, and the like.
- RAM random access memory
- SDRAM synchronous dynamic random access memory
- ROM read-only memory
- NVRAM non-volatile random access memory
- EEPROM electrically erasable programmable read-only memory
- FLASEI memory magnetic or optical data storage media, and the like.
- the techniques additionally, or alternatively, may be realized at least in part by a computer- readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and/or executed by a computer, such as propagated signals or waves.
- the program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, an application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry.
- DSPs digital signal processors
- ASICs application specific integrated circuits
- FPGAs field programmable logic arrays
- a general purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine.
- a processor may also be
- processor implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction wi th a DSP core, or any other such configuration.
- processor may refer to any of the foregoing structure, any combination of the foregoing structure, or any other structure or apparatus suitable for implementation of the techniques described herein.
- Illustrative aspects of the present disclosure include:
- a method for data access comprising: determining a storage device address for a storage device; determining a tag for obtaining metadata for encryption of data for the storage device; generating a return address, the return address including a host memory address and the tag; and accessing the storage device based on the return address and the storage device address.
- Aspect 2 The method of Aspect 1, wherein the encryption of the data comprises encry pting or decrypting the data.
- Aspect 3 The method of any of Aspects 1 or 2, wherein accessing the storage device comprises storing at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
- Aspect 4 The method of any of Aspects 1-3. wherein the tag comprises an index to a memory table.
- Aspect 5 The method of Aspect 4, wherein the memory table includes a key for the encryption of data.
- Aspect 6 The method of any of Aspects 4 or 5, wherein the storage device address comprises a logical block address (LBA), and wherein the memory 7 table includes LBA information for the storage device.
- LBA logical block address
- Aspect 8 The method of any of Aspects 1-7, wherein the storage device comprises a peripheral component interconnect express (PCIe) bus device and wherein the return address comprises a PCIe address.
- PCIe peripheral component interconnect express
- Aspect 9 The method of Aspect 8, wherein the tag includes 16 bits.
- Aspect 10 The method of Aspect 9, wherein the tag is included in an upper 16 bits of the PCIe address.
- Aspect 11 The method of any of Aspects 8-10, wherein the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCIe bus.
- NVMe nonvolatile memory express
- Aspect 12 The method of any of Aspects 1-11, wherein the storage device is encrypted using full disk encryption.
- Aspect 13 The method of any of Aspects 1-12, wherein the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
- AES-XTS advanced encryption standard xor encrypt xor tweakable block ciphertext stealing
- An apparatus for data access comprising: at least one memory 7 ; a storage device; and at least one processor coupled to the at least one memory 7 , the at least one processor being configured to: determine a storage device address for the storage device; determine a tag for obtaining metadata for encryption of data for the storage device; generate a return address, the return address including a host memory 7 address and the tag; and access the storage device based on the return address and the storage device address.
- Aspect 15 The apparatus of Aspect 14, wherein the encry ption of the data comprises encrypting or decrypting the data.
- Aspect 16 The apparatus of any of Aspects 14 or 15, wherein, to access the storage device, the at least one processor is configured to store at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
- Aspect 17 The apparatus of any of Aspects 14-16, wherein the tag comprises an index to a memory table.
- Aspect 18 The apparatus of Aspect 17, wherein the memory table includes a key for the encryption of data.
- Aspect 19 The apparatus of any of Aspects 17 or 18, wherein the storage device address comprises a logical block address (LB A), and wherein the memory 7 table includes LB A information for the storage device.
- LB A logical block address
- Aspect 20 The apparatus of Aspect 19, wherein the at least one processor is further configured to generate a tweak for the encry ption of data based on the LBA information.
- Aspect 21 The apparatus of any of Aspects 14-20. wherein the storage device comprises a peripheral component interconnect express (PCIe) bus device and wherein the return address comprises a PCIe address.
- PCIe peripheral component interconnect express
- Aspect 22 The apparatus of Aspect 21, wherein the tag includes 16 bits.
- Aspect 23 The apparatus of Aspect 22, wherein the tag is included in an upper 16 bits of the PCIe address.
- Aspect 24 The apparatus of any of Aspects 21-23, wherein the storage device is accessed using a nonvolatile memory 7 express (NVMe) interface over a PCIe bus.
- NVMe nonvolatile memory 7 express
- Aspect 25 The apparatus of any of Aspects 14-24. wherein the storage device is encrypted using full disk encry ption.
- a non-transitory computer-readable medium having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: determine a storage device address for a storage device; determine a tag for obtaining metadata for encry ption of data for the storage device; generate a return address, the return address including a host memory address and the tag; and access the storage device based on the return address and the storage device address.
- Aspect 28 The non-transitory computer-readable medium of Aspect 27, wherein the encryption of the data comprises encrypting or decrypting the data.
- Aspect 29 The non-transitory computer-readable medium of any of Aspects 27 or 28, wherein, to access the storage device, the instructions further cause the at least one processor to store at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
- Aspect 30 The non-transitory 7 computer-readable medium of any of Aspects 27-29, wherein the tag comprises an index to a memory- table.
- Aspect 32 The non-transitory computer-readable medium of any of Aspects 30 or 31, wherein the storage device address comprises a logical block address (LBA), and wherein the memory 7 table includes LBA information for the storage device.
- LBA logical block address
- Aspect 33 The non-transitory computer-readable medium of Aspect 32, yvherein the instructions further cause the at least one processor to generate a tweak for the encryption of data based on the LBA information.
- Aspect 34 The non-transitory computer-readable medium of any of Aspects 27-33, wherein the storage device comprises a peripheral component interconnect express (PCle) bus device and yvherein the return address comprises a PCle address.
- PCle peripheral component interconnect express
- Aspect 36 The non-transitory computer-readable medium of Aspect 35, yvherein the tag is included in an upper 16 bits of the PCle address.
- Aspect 38 The non-transitory computer-readable medium of any of Aspects 27-37, wherein the storage device is encrypted using full disk encryption.
- Aspect 39 The non-transitory computer-readable medium of any of Aspects 27-38, wherein the storage device is encrypted using advanced encryption standard xor encry pt xor tweakable block ciphertext stealing (AES-XTS).
- AES-XTS advanced encryption standard xor encry pt xor tweakable block ciphertext stealing
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
Abstract
Techniques and systems are provided for data access. For instance, a process can include determining a storage device address for a storage device, determining a tag for obtaining metadata for encryption of data for the storage device, generating a return address, the return address including a host memory address and the tag, and accessing the storage device based on the return address and the storage device address.
Description
INLINE ENCRYPTION AND/OR DECRYPTION USING ADDRESS TAGGING
FIELD
[0001] The present disclosure generally relates to a technique for protecting information (e.g., encry pting a file system). For example, aspects of the present disclosure relate to systems and techniques for inline encryption using address tagging.
BACKGROUND
[0002] Computing devices often employ various techniques to protect data. As an example, data may be subjected to encry ption and decry ption techniques in a variety7 of scenarios, such as writing data to a storage device, reading data from a storage device, writing data to or reading data from a memory device, encrypting and decrypting blocks and/or volumes of data, encrypting and decrypting digital content, performing inline cryptographic operations, etc. Such encry ption and decryption operations are often performed, at least in part, using a security7 information asset, such as a cryptographic key, a derived cryptographic key, etc. Certain scenarios exist in which attacks are performed in an attempt to obtain such security information assets. Accordingly, it is often advantageous to implement systems and techniques to protect such security7 information assets.
SUMMARY
[0003] Systems and techniques are described herein for protecting against malicious attacks in images. The following presents a simplified summary relating to one or more aspects disclosed herein. Thus, the following summary should not be considered an extensive overview relating to all contemplated aspects, nor should the following summary7 be considered to identify key or critical elements relating to all contemplated aspects or to delineate the scope associated with any particular aspect. Accordingly, the following summary7 presents certain concepts relating to one or more aspects relating to the mechanisms disclosed herein in a simplified form to precede the detailed description presented below.
[0004] Systems and techniques are described for an apparatus for data access, such as for accessing an encrypted data storage device. In one illustrative example, a method for data access is provided. The method includes determining a storage device address for a storage device, determining a tag for obtaining metadata for encryption of data for the storage device,
generating a return address, the return address including a host memory address and the tag, and accessing the storage device based on the return address and the storage device address.
[0005] As another example, and apparatus for data access is provided. The apparatus includes at least one memory, a storage device, and at least one processor coupled to the at least one memory. The at least one processor is configured to determine a storage device address for the storage device, determine a tag for obtaining metadata for encryption of data for the storage device, generate a return address, the return address including a host memory address and the tag, and access the storage device based on the return address and the storage device address.
[0006] In another example, a non-transitory computer-readable medium is provided that has stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: determine a storage device address for a storage device, determine a tag for obtaining metadata for encryption of data for the storage device, generate a return address, the return address including a host memory’ address and the tag, and access the storage device based on the return address and the storage device address.
[0007] In another example, an apparatus for data access is provided. The apparatus includes: means for determining a storage device address for a storage device, means for determining a tag for obtaining metadata for encryption of data for the storage device, means for generating a return address, the return address including a host memory address and the tag, and means for accessing the storage device based on the return address and the storage device address.
[0008] In some aspects, one or more of the apparatuses described herein is, is part of, and/or includes a mobile or wireless communication device (e.g., a mobile telephone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a network-connected watch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device such as a mobile phone acting as a server device, an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system-on-a-chip (SoC), any combination thereof, and/or other type of
2 Polsinelli Ref. No. 094922-780686
device. In some aspects, the apparatus(es) include(s) a display for displaying one or more images, notifications, and/or other displayable data. In some aspects, the apparatus(es) include(s) can include one or more sensors (e.g.. one or more RF sensors), such as one or more gyroscopes, one or more gyrometers, one or more accelerometers, any combination thereof, and/or other sensor(s).
[0009] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all drawings, and each claim.
[0010] The foregoing, together with other features and examples, will become more apparent upon referring to the following specification, claims, and accompanying drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Illustrative examples of the present application are described in detail below with reference to the following figures:
[0012] FIG. 1 is a block diagram illustrating certain components of a computing device, in accordance with some examples;
[0013] FIG. 2 illustrates an example PCIe transaction layer packet format configured to perform inline encryption/ decry ption using address tagging, in accordance with aspects of the present disclosure;
[0014] FIG. 3 is a flow diagram illustrating an example process for data access, in accordance with some examples;
[0015] FIG. 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology.
DETAILED DESCRIPTION
[0016] Certain aspects and examples of this disclosure are provided below. Some of these aspects and examples may be applied independently and some of them may be applied in combination, as would be apparent to those of skill in the art. In the following description, for
3 Polsinelli Ref. No. 094922-780686
the purposes of explanation, specific details are set forth in order to provide a thorough understanding of examples of the application. However, it will be apparent that various examples may be practiced without these specific details. The figures and description are not intended to be restrictive. Additionally, certain details known to those of ordinary skill in the art may be omitted to avoid obscuring the description.
[0017] In the below description of the figures, any component described with regard to a figure, in various examples described herein, may be equivalent to one or more like-named (or numbered) components described with regard to any other figure. For brevity, descriptions of these components may not be wholly repeated with regard to each figure. Thus, each and every example of the components of each figure is incorporated by reference and assumed to be optionally present within every other figure having one or more like-named components. Additionally, in accordance with various examples described herein, any description of the components of a figure is to be interpreted as an optional example, which may be implemented in addition to, in conjunction with, or in place of the examples described with regard to a corresponding like-named component in any other figure.
[0018] The ensuing description provides illustrative examples only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the illustrative examples will provide those skilled in the art with an enabling description for implementing an exemplary example. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the application as set forth in the appended claims.
[0019] As used herein, the phrase operatively connected, or operative connection (or any variation thereol), means that there exists between el ements/components/d evices, etc. a direct or indirect connection that allows the elements to interact with one another in some way. For example, the phrase "operatively connected' may refer to any direct (e.g., wired directly between two devices or components) or indirect (e.g., wired and/or wireless connections between any number of devices or components connecting the operatively connected devices) connection. Thus, any path through which information may travel may be considered an operative connection. Additionally, operatively connected devices and/or components may exchange things, and/or may inadvertently share things, other than information, such as. for
4 Polsinelli Ref. No. 094922-780686
example, electrical current, radio frequency signals, power supply interference, interference due to proximity, interference due to re-use of the same wire and/or physical medium, interference due to re-use of the same register and/or other logical medium, etc.
[0020] In some cases, a storage device, such as a hard disk, solid state drive, flash drive, etc. may be secured using disk encryption, such as full disk encryption. In some cases, to access (e.g.. read/write data from/to) the storage device, an encryption operation may be performed. This encryption operation may be based on certain metadata, such as a key and/or tweak value. This key and/or tweak may be based on a logical block address (LB A) such that each encrypted sector has an associated key and a unique 128-bit tweak that includes the LBA. Thus, a portion of the address for data may be used to lookup metadata for access to the storage device. Encrypting/decrypting data for disk encryption may be performed using software-based encryption or a stand-alone encryption hardware (e.g., encryption hardware that does not read/write directly from/to a memory' used for reading from/writing to the storage device), but such solutions may increase latency and bandwidth load on the memory. Other approaches may involve modifications to existing protocols.
[0021] Systems, apparatuses, electronic devices, methods (also referred to as processes), and computer-readable media (collectively referred to herein as “systems and techniques”) are described herein for performing an inline encryption and/or decry ption using address tagging. For example, inline address tagging may use a portion of an address (e.g., a peripheral component interconnect express (PCIe) address) as an inline address tag to lookup metadata for encrypting/decrypting data for/from the storage device. In some cases, the inline address tag may be used as an index for lookup in a data segment table (DST). In some cases, the DST may be an in-memory table including information for determining metadata for encry pting/decry pting data. Inline cry ptography may refer to encrypting/decrypting the data for the storage device as a part of the read/write process transparently to existing PCIe/NVMe storage devices. For example, a storage device may retrieve encrypted data from the storage device and write the data to a memory location. As a part of the write operation, the encrypted data stream may be automatically decrypted and written to the memory location. This may be performed without having to, for example, copy the entirety of the encry pted data to another memory to perform the decoding.
5 Polsinelli Ref. No. 094922-780686
[0022] In some cases, including metadata for encrypting/ decry ting data in a PCIe address (e.g., return address) for accessing a storage device allows a single request to be used to obtain data that is to be encrypted/decrypted along with metadata for performing the encryption/decryption. Such a solution can help reduce latency for accessing the storage device along with decreasing memory bandwidth use as compared to software-based encryption or stand-alone encryption/decryption hardware. Encoding the inline address tag into a PCIe address helps avoid having to change an underlying protocol.
[0023] Various aspects of the techniques described herein will be discussed below with respect to the figures. FIG. 1 is a block diagram illustrating an example of a computing device 100 configured to perform inline encryption/decryption using inline address tagging, in accordance with aspects of the present disclosure. As shown, the computing device 100 includes a processor 102, a nonvolatile memory express (NVMe) device 104, a bus 106, a memory7 device 108, an additional storage device 110, an inline cryptographic engine 112, and a peripheral component interconnect express (PCIe) interface 114. In some cases, the memory device 108 may include a data segment table (DST) 118. Alternatively, the DST 118 may be a part of the inline cryptographic engine 112 or other hardware component.
[0024] The computing device 100 is any device, portion of a device, or any set of devices capable of electronically processing instructions and may include, but is not limited to, any of the following: one or more processors (e.g. components that include integrated circuitry, memory, input and output device(s) (not shown), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and/or any combination thereof. Examples of computing devices include, but are not limited to. a mobile device (e.g., laptop computer, smart phone, personal digital assistant, tablet computer, automobile computing system, and/or any other mobile computing device), an Internet of Things (loT) device, a server (e.g., a blade-server in a blade-server chassis, a rack server in a rack, etc.), a desktop computer, a storage device (e.g., a disk drive array, a fibre channel storage device, an Internet Small Computer Systems Interface (iSCSI) storage device, a tape storage device, a flash storage array, a netw ork attached storage device, etc.), a network device (e.g., switch, router, multi-layer switch, etc.), a wearable device (e.g., a network-connected w atch or smartwatch, or other wearable device), a robotic device, a smart television, a smart appliance, an extended reality (XR) device (e.g.. augmented reality, virtual reality, etc.), any device that
6 Polsinelli Ref. No. 094922-780686
includes one or more SoCs, and/or any other type of computing device with the aforementioned requirements. In one or more examples, any or all of the aforementioned examples may be combined to create a system of such devices, which may collectively be referred to as a computing device. Other types of computing devices may be used without departing from the scope of examples described herein.
[0025] In some examples, the processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program). As an example, such circuitry may be integrated circuitry implemented, at least in part, using transistors implementing such components as arithmetic logic units, control units, logic gates, registers, first-in. first-out (FIFO) buffers, data and control buffers, etc. In some examples, the processor may include additional components, such as, for example, cache memory. In some examples, a processor retrieves and decodes instructions, which are then executed. Execution of instructions may include operating on data, which may include reading and/or writing data. In some examples, the instructions and data used by a processor are stored in the memory (e.g., memory device 108) of the computing device 100. A processor may perform various operations for executing software, such as operating systems, applications, etc. The processor 102 may cause data to be written from memory to storage of the computing device 100 and/or cause data to be read from storage via the memory. Examples of processors include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), neural processing units, tensor processing units, display processing units, digital signal processors (DSPs), finite state machines, etc. In some cases, the processor 102 may be integrated into a system on a chip (SoC) 116. In some examples, the SoC 116 may also incorporate the bus 106, the memory device 108, the inline cryptographic engine 112. and the PCIe interface 114. In some cases, the NVMe device 104 and additional storage device 110 may be coupled to, but separate from, the SoC 116.
[0026] The processor 102 may be operatively connected to the memory device 108, any storage (e.g., NVMe device 104, additional storage device 110) of the computing device 100, and/or to the inline cryptographic engine 112 via bus 106. Although FIG. 1 shows the computing device 100 having a single processor 102, the computing device may include any number of processors without departing from the scope of examples described herein.
7 Polsinelli Ref. No. 094922-780686
[0027] In some examples, the computing device 100 includes a NVMe device 104. In some examples, the NVMe device 104 is a flash storage device conforming to the NVMe specification, which defines a protocol which may be overlaid over (e.g., extend the functionality of) the PCIe interface 114. The NVMe device 104 may be used for storing data of any ty pe. Data may be written to and/or read from the NVMe device 104. As an example, the NVMe device may store operating system images, software images, application data, etc. The NVMe device 104 may store any other type of data without departing from the scope of examples described herein. In some examples, the NVMe device 104 includes NAND flash storage. The NVMe device 104 may use any other type of storage technology without departing from the scope of examples described herein. In some examples, the NVMe device 104 is capable of data rates that are relatively faster than other storage devices (e.g., additional storage device 110) of the computing device 100. The NVMe device 104 may be operatively connected to the processor 102, the memory' device 108, and/or the additional storage device 110. Although FIG. 1 shows the computing device 100 having a single NVMe device 104, the computing device may include any number of NVMe devices without departing from the scope of examples described herein. Additionally, although FIG. 1 shows the NVMe device 104. the computing device 100 may include any' other type of flash storage device without departing from the scope of examples described herein.
[0028] In some cases, the NVMe device 104 may be coupled to a PCIe interface 114. The PCIe interface 114 may be a physical input/output (I/O) interface for connecting various components, or peripheral devices, such the components may be used by the computing device 100. In some cases, multiple device may be coupled via the PCIe interface 114, such as the NVMe device and the additional storage device 110. In some cases, different communications protocols may be used over the PCIe interface 114 to communicate with devices coupled via the PCIe interface 114. For example, the NVMe protocol may' be used to communicate with the NVMe device 104 over the PCIe interface 114. Other communications protocols may also be used. Of note, while discussed in the context of PCIe and NVMe, it should be understood that the concepts discussed herein are not limited to PCIe and NVMe, but could be applied to other component interfaces.
[0029] In some cases, a host for the PCIe interface 114, such as the processor 102, may access the NVMe device 104 by providing commands and/or data for the NVMe device 104.
8 Polsinelli Ref. No. 094922-780686
For example, the processor 102 may queue a set of NVMe commands (e.g., requests), addresses, and/or data for the NVMe device 104 in a buffer, such as memory device 108. The bulfer may be used for the NVMe device 104 to write out data from the buffer to the NVMe device 104 and/or to read in data from the NVMe device 104 to the buffer and the addresses may indicate where on the NVMe device 104 and/or buffer to perform read/writes to. An NVMe command to perform a read/write may include an NVMe command identifier to identify the NVMe command. In some cases, the NVMe command may be 64 bits in size. In some cases, placing the NVME command into the bulfer may trigger a doorbell signal configured to indicate to the NVMe device 104 that the NVMe command in the buffer is ready for execution. In some cases, the NVMe device 104 may respond to queued NVMe commands in the buffer in any order (e.g., in order, out of order, etc.). In some cases, there may be multiple queues of NVMe commands. In response to NVMe commands, the NVMe device 104 may read data from the buffer to be written to the NVMe device 104 (e.g., for write commands), or the NVMe device 104 may write data retrieved from the NVMe device 104 to the buffer (e.g., in response to read commands).
[0030] In some examples, the computing device 100 includes an additional storage device 110. In some examples, the additional storage device is a non-volatile storage device. The additional storage device 110 may. for example, be a persistent memory device. In some examples, the additional storage device 110 may be computer storage of any type. Examples of type of computer storage include, but are not limited to, hard disk drives, solid state drives, flash storage, tape drives, removable disk drives, Universal Serial Bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, etc. Although FIG. 1 shows the additional storage device 110 as part of the computing device 100, the additional storage device may be separate from and operatively connected to the computing device 100 (e.g., an external drive array, cloud storage, etc.). In some examples, the additional storage device 110 operates at a data rate that is relatively slower than the NVMe device 104. In some examples, the additional storage device 110 is also a NVMe storage device. In some examples, the additional storage device 110 is operatively connected to the processor 102. the NVMe device 104, the inline cryptographic engine 112, and/or the memory device 108. Although FIG. 1 shows the computing device 100 having a single additional storage device 110, the computing device 100 may have any number of additional storage devices without departing from the scope of examples described herein.
9 Polsinelli Ref. No. 094922-780686
[0031] In some examples, the computing device 100 includes a memory device 108. The memory device may be any type of computer memory’. In some examples, the memory device 108 is a volatile storage device. As an example, the memory device 108 may be random access memory (RAM). In one or more examples, data stored in the memory device 108 is located at memory’ addresses, and is thus accessible to the processor 102 and/or the inline cry ptographic engine 112 using the memory addresses. Similarly, the processor 102 and/or secure execution environment (or components therein) may write data to and/or read data from the memory device 108 using the memory' addresses. The memory device 108 may be used to store any type of data, such as, for example, computer programs, the results of computations, etc. In some examples, the memory device 108 is operatively connected to the processor 102, the NVMe device 104, the additional storage device 110, and the inline cryptographic engine 112. Although FIG. 1 shows the computing device 100 having a single memory device 108, the computing device 100 may have any number of memory’ devices without departing from the scope of examples described herein.
[0032] In some examples, the computing device 100 mcludes any number of security components (e.g., multiple inline cryptographic engines 112). The security components may be any component capable of performing various cryptographic services, and may thus be any hardware (e.g., circuitry), software, firmware, or any combination thereof. In some examples, the security components are a sub-chip hardware components of a system on a chip (SoC), which may include other components shown in FIG. 1 such as, for example, the processor 102. Any other components of the computing device 100 may also be included as part of an SoC without departing from the scope of examples described herein. In some examples, the security components exist in a data path between storage devices (e.g., NVMe storage device 104, additional storage device 110) and the memory device 108, and/or data paths between the processor 102 and the memory device 108 or any of the storage devices (e.g., 104, 110). In some examples, all or any portion of the security components may be considered “inline” cryptographic engines. In some examples, the security components are configured to perform any number of cryptographic service types on data being read from or written to a storage device (e g., NVMe device 104, additional storage device 110) and/or a memory device 108 of the computing device 100. In some examples, all or any portion of the data passing from memory to storage, from storage to memory, or to or from the processor 102 of the computing device 100 passes through a security component.
10 Polsinelli Ref. No. 094922-780686
[0033] Examples of cry ptographic sendee types that may be performed include, but are not limited to. encrypting data, decrypting data, key derivation, performing data integrity verification, and performing authenticated encryption and decryption. In some examples, the security components are configured to perform the various cryptographic service types by being configured to execute one or more cry ptographic algorithms. As an example, to perform encryption and decryption, one or more security components may be configured to execute one or more of the Advanced Encryption Standard XOR-encrypt-XOR Tweakable Block Ciphertext Stealing (AES-XTS) algorithm, the AES-Cypher Block Chaining (AES-CBC) algorithm, the AES -Electronic Codebook (AES-EBC) algorithm, the Encrypted Salt-Sector Initialization Vector-AES-CBC (ESSIV-AES-CBC) algorithm, etc., including any variants of such algorithms (e.g., 128 bits, 192 bits, 256 bits, etc.). As another example, to perform integrity verification, the security component may be configured to execute a hash algorithm such as, for example, the one or more members of the SHA family of hash algorithms. As another example, to perform authenticated encry ption, a security component may be configured to perform the AES-Galois/Counter Mode (GCM) algorithm. The security component may be configured to execute any other cryptographic algorithms without departing from the scope of examples described herein.
[0034] In some examples, the inline cry ptographic engine 112 is a hardware component (e.g.. including circuitry) that may execute software and/or firmware, and is configured to perform various operations or services to secure the computing device 100. For instance, as described in more detail herein, the inline cryptographic engine 112 can perform inline encryption and/or decryption using inline address tagging.
[0035] While FIG. 1 shows a certain number of components in a particular configuration, one of ordinary' skill in the art will appreciate that the computing device 100 may include more components or fewer components, and/or components arranged in any number of alternate configurations without departing from the scope of examples described herein. Additionally, although not shown in FIG. 1, one of ordinary skill in the art will appreciate that the computing device 100 may7 execute any7 amount or type of software or firmware (e.g., bootloaders, operating systems, hypervisors, virtual machines, computer applications, mobile device apps, etc.). Accordingly, examples disclosed herein should not be limited to the configuration of components shown in FIG. 1. The components shown in FIG. 1 may or may not be discrete
11 Polsinelli Ref. No. 094922-780686
components. In some aspects, one or more of the components can be combined into different hardware elements, implemented in software, and/or otherwise implemented using software and/or hardware. As used herein, the term device may be a discrete component or apparatus, or may not be a discrete component. In some aspects, other devices can exist within, be part of, and/or utilize the same hardware components as a device.
[0036] In some cases, a processor, such as processor 102 of FIG. 1, may access a storage device, such as NVMe device 104 or additional storage device 110 of FIG. 1, via a memory space, such as an SoC memory space or processor memory' space. As an example, a processor may access a nonvolatile memory express (NVMe) storage device (e.g., part of the additional storage device 110) via a read or write command and the read or write commands may have an associated SoC memory space available (e.g., allocated) for data to be read/written. In some cases, a NVMe storage device may be a storage device that is accessible via an NVMe interface. The NVMe interface may operate on top of an interface, such as the PCIe interface 114. For example, NVMe may include protocol commands and structures that may be transferred by PCIe. Thus, the NVMe storage device may be accessed using NVMe over the PCIe interface 114.
[0037] In some cases, NVMe devices, such as NVMe device 104, that operate over the PCIe interface 114 may directly access a host memory (e.g., SoC memory, processor I/O memory, and the like) space, such as one on memory' device 108. The memory space may be logically organized into one or more sets of data segments. In some cases, data segments may be contiguous sections of SoC memory, and there may be one DST entry per data segment. Data segments which may be contiguous in the memory space may be stored in contiguous data segments on the storage. In some cases, each data segment is a contiguous, nonoverlapping section of SoC memory'.
[0038] In some cases, to support inline encryption/ decry ption, the inline cry ptographic engine 112 may use a DST 118 configured by software (e.g., a driver, system process, etc.) that defines the location and size of every data segment, which data segments have encry ption enabled, and metadata needed for encryption/decryption operations. In some cases, data segments with encryption enabled contain I/O data that is stored in consecutive sectors on the NVMe device 104.
12 Polsinelli Ref. No. 094922-780686
[0039] In some cases, a storage device may be divided into sectors. In some cases, sectors may be specified by their logical block address (LBA). In some cases, a number and size of sectors for a storage device may be fixed. In some cases, sector size and number may be statically configured, such as by software, prior to enabling encryption for the storage device.
[0040] In some cases, a storage device, such as a non-volatile, non-transitory computer- readable memory device such as a hard disk, flash drive, or other types of computer readable media which can store data that are accessible by a computer, may be encrypted using full disk encryption. Full disk encr ption may refer to a storage device on which data on the storage device is encrypted. In some cases, metadata to access (e.g., read/write) the storage device, such as a master boot record may also be encrypted. In some cases, full disk encryption may be performed based on an encryption scheme such as advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS). AES-XTS is a tweakable encry ption scheme which uses the AES encry ption cipher and tweak values. In a tweakable encryption scheme, no two sectors should be processed in the same way. The tweak attempts to mimic a random permutation for the cipher. In some cases, the tweak may be based on a sector address and an index of a block within the sector.
[0041] In some cases, AES-XTS uses a key and a non-secret tweak value to perform an encrypt or decrypt operation to read/write data from/to the storage device. The key and tweak may be based on the LBA (or other storage device address) such that each encry pted sector has an associated key and a unique 128-bit tweak that includes the LBA (or other storage device address). In some cases, the storage device may be accessible using aNVMe interface or other peripheral interface. In some cases, the peripheral interface may not directly provide a way to provide the metadata for the encrypt/decrypt operation for a storage device with full disk encry ption. For example, the NVMe/PCIe protocol stack does not natively provide a way to specify an inline address tag where a portion of the PCIe address may be used as the inline address tag to lookup information for encrypting/decrypting data for the storage device. In some cases, the PCIe address (e.g., return address) may be an address used by the storage device (e.g., storage device accessible via a PCIe bus) to access SoC memory (e.g., host memory7). The SoC memory7 may be a memory' space accessible to the components of the SoC (e.g., processor) to which the storage device may write return information or data (e.g., return codes, or data requested by a storage read operation) to.
13 Polsinelli Ref. No. 094922-780686
[0042] FIG. 2 illustrates an example PCIe transaction layer packet format 200 configured to perform inline encryption/decryption using inline address tagging, in accordance with aspects of the present disclosure. The example packet format 200 may use 64-bit addressing and include four double words (DW0 202, DW1 204, DW2206, and DW3 208). In some cases, DW0 202 and DW1 204 may include header, status, length, hosting information, completer information, and/or other PCIe configuration information for setting up a PCIe transaction. Details of bit fields in DW0 202 and DW1 204 have been omitted for clarity. For regular PCIe transactions, the packet format 200 may include a 64-bit return address in DW2 206 and DW3 208. In some cases, a reserved field may also be included after the return address (e.g., with a shorter return address). The return address may identify the device and address the PCIe device (e.g., a storage device) may return data or return information (e.g.. return codes) to. As an example, a PCIe device may have a return address space (e.g., PCIe address) that the PCIe device may be access (e.g., by performing I/O operations) to return data or return information (e.g., return codes) from the storage device.
[0043] For inline encryption/decry ption with inline address tagging, to help allow an inline address tag to be provided without modifications to existing protocols (e.g., PCIe/NVMe), a portion of the return address (e.g., in DW2 206) may be used for cryptographic operations. For example, an upper 16 bits of the PCIe address may be used as an Inline address tag 212. The Inline address tag 212 may be used as an index (e.g., pointer, number, and the like) into a DST (e.g., DST 118 of FIG. 1 ). Information (e.g., metadata) in the DST table may provide sufficient information to determine the tweak and key for encrypting/decrypting data for the storage device. The encrypting/decry pting of the data using the tweak and key may then proceed in memory in a manner similar to current full disk encryption techniques. In some cases, the DST may be stored in a memory (e.g., an in-memory table), such as memory device 108. The remaining lower 48-bit section of the I/O address space, a PCIe host memory address (e.g., SoC address) space 214, may be used for PCIe accesses for the storage device (e.g., NVMe protocol structures, address information data for a given external drive and its associated PCIe interface, and the like). The PCIe address format may be as follows: pcie addr [ 63 : 48 ] = dst index [ 15 : 0 ] pcie addr [ 47 : 0 ] = soc addr [ 47 : 0 ]
14 Polsinelli Ref. No. 094922-780686
[0044] In some cases, a different Inline address tag 212 for NVMe PCIe accesses may be used for each NVMe inline cryptographic engine instance (e.g., implemented using the inline cryptographic engine 112 of FIG. 1). In some cases, when drive encryption is enabled, software may allocate and configure an entry in the DST for each NVMe storage command (e.g., read/write command) data segment before submitting the command to the command queue (e.g., for execution). Each entry in the DST may be 16 bytes long. In some cases, there may be two DST entry formats, one format for segments that have encryption enabled and a second format for segments that have encry ption disabled. The following fields may be included for entries in the DST where encryption is enabled: base addr[47:2] = base address in SoC memory re served [ 1 : 0 ] = reserved base lba[47:0] = base LBA num_sectors [ 15 : 0 ] = number of sectors key index[7:0] = key index (key 0 - 255) encrypt_mode [ 0 ] = encryption mode (AES-XTS-128 , AES-XTS- 256) reserved [4 : 0] = reserved encrypt_en [ 0 ] = 1 valid[0] = entry valid
[0045] The following fields may be included for entries in the DST where encryption is disabled: base_addr [47 : 2] = base address in SoC memory re served [ 1 : 0 ] = reserved length [47:0] = length in bytes re served [ 29 : 0 ] = reserved encrypt en[0] = 0 valid[0] = entry valid
[0046] In some cases, the Inline address tag 212 for NVMe PCIe accesses may be statically configured by software for each interface (e.g., per drive interface). The lower 48-bit PCIe host memory address (e.g., SoC address) space 214 does not have to be exclusively used by one
15 Polsinelli Ref. No.094922-780686
drive or for NVMe data. Thus, the lower 48 bits of the PCIe host memory address space 214 (e.g., return address) may be used as a SoC memory address (e.g.. a host memory address accessible to components of the SoC (e.g., processor) where the storage device may write return data and information) and the upper 16 bits may be used as the Inline address tag 212 for accessing the DST.
[0047] In some cases, when drive encryption is enabled, PCIe transfers associated with a NVMe storage command data segments for a storage device may be processed according to the DST entry selected by the Inline address tag 212. In some cases, software allocates and configures an entry' in the DST for data segments associated with the NVMe interface when drive encryption is enabled. In some examples, SoC memory that is accessed by the NVMe device may fall within a data segment listed in the DST. In some cases, the inline cr ptographic engine may verify transactions against a selected entry in the DST. In some cases, storage commands are verified (e.g., by the inline cry ptographic engine 112 of FIG. 1) such that the associated I/O transfers fall within selected segment address ranges based on the base addr and length fields. Appropriate errors may be generated for transfers that fall outside the selected data segment and the transaction is processed in the same way as other access control violations. In some cases, drive reads of data segments with encryption enabled are encrypted on-the-fly. Likewise, drive writes are decrypted on-the-fly. Of note, while the upper 16-bits of the PCIe address are used for the tag in this example, other implementations may use any number of bits of the PCIe address for the tag.
[0048] Returning to FIG. 1, in some cases, the DST 118 is stored in a memory and may be up to 64,000 entries (and in some cases higher). A RAM that can support a 64.000-entry table can be 1 megabyte (MB). In some examples, a smaller table can be sufficient. The hardware can be configured for a smaller local RAM. In some aspects, keys (e.g., index) for data (e.g., all data) associated with read and write commands can be (and in some cases must be) preloaded by software into the inline cryptographic engine before issuing the command. In some cases, the DST 118 may be managed (e.g., adding and/or removing entries in the DST 118) by software executing, for example, on a processor, such as processor 102, or as a part of the inline cry ptographic engine 112. In other cases, the DST 118 may be managed by hardware, for example, in the inline cryptographic engine 112.
16 Polsinelli Ref. No. 094922-780686
[0049] In some cases, the inline cryptographic engine 112 may include a small, fully associative cache that holds the most recently accessed DST entries. The cache may include the capability for software to invalidate entries when they are deallocated in the DST 118. In some cases, the DST 118 may be stored in a memory on a processor and/or SOC (e.g., memory device 108), such as a cache. In some cases, the DST 118 may be stored in a RAM separate from the processor and/or SOC, such as a system memory.
[0050] As an example, a storage write to store data into a full disk encrypted NVMe device 104 may be performed by the processor 102. The processor 102 may write the data along with appropriate commands and headers for the storage write to appropriate mapped memory location(s). for example in the memory device 108. for storage writes. In some cases, the appropriate mapped memory location(s) may be a location accessible by the inline cryptographic engine 112. The processor 102 may also write to the appropriate mapped memory location(s) an LBAaddress (e.g., address for the storage device or other storage device address) indicating where on the NVMe device 104 the data should be written. The processor 102 may also write to the appropriate mapped memory location(s) a return address (e.g.. PCIe address) for the NVMe device 104 to use, for example, for return codes. The return address, as described above with respect to FIG. 2, may include a 48 bit portion including the host memory' address (e.g., SoC address) and a 16 bit (e.g., upper 16 bits) Inline address tag (e.g., as discussed above with respect to FIG. 2). In some cases, the lower 48 bits may be sufficient for return SoC address and information to be returned may be written based on the 48 bit return address.
[0051] The processor 102 may also write to a portion (e.g., row) of the DST 118 (or to the inline cryptographic engine 112 to write to the DST 118), metadata for processing a PCIe transaction for the storage write. As an example, the metadata may include information for encrypting/decrypting data (e.g., to determine the tweak and key), along with addresses to where data may be accessed/written to (e.g., start/end addresses, size), command submission queue identifiers, sector information, etc. In some cases, the inline cryptographic engine 112 may return an index (e.g., pointer) indicating which portion (e.g., row) of the DST 118 the metadata was stored. This index may be included in the Inline address tag. In some cases, multiple segments (e. g. , of the DST 118) may be referenced by the Inline address tag, or by the metadata stored in the DST 118.
17 Polsinelli Ref. No. 094922-780686
[0052] The Inline address tag and the LBA address may be used by, for example, the inline cryptographic engine 112 to encrypt/decrypt data transferred to/from the NVMe device 104. For example, the Inline address tag may include the index (e.g., pointer) indicating a portion (e.g., row) of a DST 118 (e.g., table, array, linked list, graph, etc.) in the inline cryptographic engine 112 that includes the metadata for processing the PCIe transaction.
[0053] The processor 102 may indicate (e.g., via a doorbell signal such as an interrupt), to the NVMe device 104, that there is data for the NVMe device 104. The NVMe device 104 may then, based on the indication, access the appropriate mapped memory location(s) in the memory device 108 to obtain the LBA address, data, return address, and appropriate commands and headers. As a part of sending the information from the mapped memory location to the NVMe device 104, the inline cryptographic engine 112 may encode the data based on the LBA address and tag. The NVMe device 104 may then write the encoded data to the LBA address and transmit an appropriate return code to the return address. In some cases, the NVMe device 104 does not process the tag of the return address and may just ignore the tag. In some cases, the processor 102 may remove the entry in the DST 118, for example, after the appropriate return code is received.
[0054] In some cases, a storage read may be performed in a manner similar to the storage write. For example, the processor 102 may write appropriate commands and headers for the storage read, along with LBA information for the requested data and a return address. As discussed in FIG. 2, the upper 16 bits of the return address may also include the ICE tag, and the lower 48 bits may include the return SoC address (e.g., or other memory location) for the storage read to a mapped memory location in the memory device 108 for storage reads. The processor 102 may also write to a portion (e.g., row) of the DST 118 (or to the inline cryptographic engine 112 to write to the DST 118), metadata for processing a PCIe transaction for the storage read. The NVMe device 104 may then, based on the indication, access the mapped memory location in the memory device 108 to obtain the LBA address, return address, and appropriate commands and headers. The NVMe device 104 may access the LBA address to obtain the requested data and transmit the requested data for storage at the return address along with LBA address information and return address information. The inline cryptographic engine 112 may decode the requested data based on the LBA address and Inline address tag in the return address. For example, the inline cryptographic engine 112 may access the Inline
18 Polsinelli Ref. No. 094922-780686
address tag to obtain the index into the DST 118 to retrieve metadata regarding the PCIe transaction. The metadata and LBA address may be used to decode the requested data. The decoded information may be stored based on the return address (e.g.. in the lower 48 bits).
[0055] FIG. 3 is a flow diagram illustrating a process 300 for image processing, in accordance with aspects of the present disclosure. The process 300 may be performed by a computing device (or apparatus) or a component (e.g., a chipset, codec, etc.) of the computing device. The computing device may be a mobile device (e g., a mobile phone), a network- connected wearable such as a watch, an extended reality (XR) device such as a virtual reality (VR) device or augmented reality (AR) device, a vehicle or component or system of a vehicle, or other type of computing device. The operations of the process 300 may be implemented as software components that are executed and run on one or more processors.
[0056] At block 302, the computing device (or component thereof) may determine a storage device address for a storage device. In some cases, the storage device address comprises a logical block address (LBA), and wherein the memory table includes LBA information for the storage device. The computing device (or component thereof) may generate a tweak for the encry ption of data based on the LBA information.
[0057] At block 304, the computing device (or component thereof) may determine a tag for obtaining metadata for encry ption of data for the storage device. In some cases, the encryption of the data comprises encrypting or decry pting the data. In some cases, the tag includes 16 bits. In some cases, the storage device is encrypted using full disk encryption. In some cases, the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
[0058] At block 306, the computing device (or component thereof) may generate a return address. In some cases, the return address includes a host memory address and the tag. In some cases, the tag comprises an index (e.g., key) to a memory table of keys for the encryption of data. In some cases, the storage device comprises a peripheral component interconnect express (PCIe) bus device. In some cases, the return address comprises a PCIe address. In some cases, the tag is included in an upper 16 bits of the PCIe address. In some cases, the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCIe bus.
19 Polsinelli Ref. No. 094922-780686
[0059] At block 308, the computing device (or component thereof) may access the storage device based on the return address and the storage device address. The computing device (or component thereol) may access the storage device by storing at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
[0060] In some examples, the techniques or processes described herein may be performed by a computing device, an apparatus, and/or any other computing device. In some cases, the computing device or apparatus may include a processor, microprocessor, microcomputer, or other component of a device that is configured to cany' out the steps of processes described herein. In some examples, the computing device or apparatus may include a camera configured to capture video data (e.g., a video sequence) including video frames. For example, the computing device may include a camera device, which may or may not include a video codec. As another example, the computing device may include a mobile device with a camera (e.g., a camera device such as a digital camera, an IP camera or the like, a mobile phone or tablet including a camera, or other type of device with a camera). In some cases, the computing device may include a display for displaying images. In some examples, a camera or other capture device that captures the video data is separate from the computing device, in which case the computing device receives the captured video data. The computing device may further include a network interface, transceiver, and/or transmitter configured to communicate the video data. The network interface, transceiver, and/or transmitter may be configured to communicate Internet Protocol (IP) based data or other network data.
[0061] The processes described herein can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and/or in parallel to implement the processes.
20 Polsinelli Ref. No. 094922-780686
[0062] In some cases, the devices or apparatuses configured to perform the operations of the process 300 and/or other processes described herein may include a processor, microprocessor, micro-computer, or other component of a device that is configured to carry out the steps of the process 300 and/or other process. In some examples, such devices or apparatuses may include one or more sensors configured to capture image data and/or other sensor measurements. In some examples, such computing device or apparatus may include one or more sensors and/or a camera configured to capture one or more images or videos. In some cases, such device or apparatus may include a display for displaying images. In some examples, the one or more sensors and/or camera are separate from the device or apparatus, in which case the device or apparatus receives the sensed data. Such device or apparatus may further include a network interface configured to communicate data.
[0063] The components of the device or apparatus configured to carry out one or more operations of the process 300 and/or other processes described herein can be implemented in circuitry. For example, the components can include and/or can be implemented using electronic circuits or other electronic hardware, which can include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and/or other suitable electronic circuits), and/or can include and/or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein. The computing device may further include a display (as an example of the output device or in addition to the output device), a network interface configured to communicate and/or receive the data, any combination thereof, and/or other component(s). The network interface may be configured to communicate and/or receive Internet Protocol (IP) based data or other type of data.
[0064] The process 300 is illustrated as a logical flow diagram, the operations of which represent sequences of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computerexecutable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of
21 Polsinelli Ref. No. 094922-780686
the described operations can be combined in any order and/or in parallel to implement the processes.
[0065] Additionally, the processes described herein (e.g., the process 300 and/or other processes) may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g.. executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program including a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0066] Additionally, the processes described herein may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g.. executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0067] FIG. 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology. In particular, FIG. 4 illustrates an example of computing system 400, which can be for example any computing device making up internal computing system, a remote computing system, a camera, or any component thereof in which the components of the system are in communication with each other using connection 405. Connection 405 can be a physical connection using a bus, or a direct connection into processor 410, such as in a chipset architecture. Connection 405 can also be a virtual connection, networked connection, or logical connection.
[0068] In some examples, computing system 400 is a distributed system in which the functions described in this disclosure can be distributed within a datacenter, multiple data centers, a peer network, etc. In some examples, one or more of the described system components represents many such components each performing some or all of the function for
22 Polsinelli Ref. No. 094922-780686
which the component is described. In some examples, the components can be physical or virtual devices.
[0069] Example system 400 includes at least one processing unit (CPU or processor) 410 and connection 405 that couples various system components including system memory 415, such as read-only memory (ROM) 420 and random access memory (RAM) 425 to processor 410. Computing system 400 can include a cache 412 of high-speed memory connected directly with, in close proximity to, or integrated as part of processor 410.
[0070] Processor 410 can include any general purpose processor and a hardware service or software service, such as services 432, 434. and 436 stored in storage device 430. configured to control processor 410 as well as a special-purpose processor where software instructions are incorporated into the actual processor design. Processor 410 may essentially be a completely self-contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor may be symmetric or asymmetric.
[0071] To enable user interaction, computing system 400 includes an input device 445, which can represent any number of input mechanisms or sensors, such as a microphone for speech (e.g., a user speaking), a touch-sensitive screen for gesture or graphical input (e.g., a user performing sign language symbols, a user shaking a phone, etc.), keyboard (e.g., a user pressing a key), mouse, motion input, a determination that a user is in a location indicated by a positioning system or modem sub-system, etc., which may be used to activate counters described in previous sections and enable/disable the asset transmission chain at any stage previously described. Computing system 400 can also include output device 435, which can be one or more of a number of output mechanisms. In some instances, multimodal systems can enable a user to provide multiple types of input/ output to communicate with computing system 400. Computing system 400 can include communications interface 440, which can generally govern and manage the user input and system output. The communication interface may perform or facilitate receipt and/or transmission wired or wireless communications using wired and/or wireless transceivers, including those making use of an audio jack/plug, a microphone j ack/plug, a universal serial bus (USB) port/plug, an Apple® Lightning® port/plug, an Ethernet port/plug, a fiber optic port/plug, a proprietary wired port/plug, a BLUETOOTH® wireless signal transfer, a BLUETOOTH® low energy (BLE) wireless signal transfer, an IBEACON®
23 Polsinelli Ref. No. 094922-780686
wireless signal transfer, a radio-frequency identification (RFID) wireless signal transfer, nearfield communications (NFC) wireless signal transfer, dedicated short range communication (DSRC) wireless signal transfer, 802.11 Wi-Fi wireless signal transfer, wireless local area network (WLAN) signal transfer, Visible Light Communication (VLC), Worldwide Interoperability for Microwave Access (WiMAX), Infrared (IR) communication wireless signal transfer, Public Switched Telephone Network (PSTN) signal transfer, Integrated Services Digital Network (ISDN) signal transfer, 3G/4G/5G/LTE cellular data network wireless signal transfer, ad-hoc network signal transfer, radio wave signal transfer, micro wave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer along the electromagnetic spectrum, or some combination thereof. The communications interface 440 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers that are used to determine a location of the computing system 400 based on receipt of one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the US-based Global Positioning System (GPS), the Russia-based Global Navigation Satellite System (GLONASS), the China-based BeiDou Navigation Satellite System (BDS), and the Europe-based Galileo GNSS. There is no restriction on operating on any particular hardware arrangement, and therefore the basic features here may easily be substituted for improved hardware or firmware arrangements as they are developed.
[0072] Storage device 430 can be a non-volatile and/or non-transitory and/or computer- readable memory device and can be a hard disk or other types of computer readable media which can store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory’ devices, digital versatile disks, cartridges, a floppy disk, a flexible disk, a hard disk, magnetic tape, a magnetic strip/stripe, any other magnetic storage medium, flash storage, memristor memory', any other solid-state memory', a compact disc read only memory' (CD-ROM) optical disc, a rewritable compact disc (CD) optical disc, digital video disk (DVD) optical disc, a blu-ray® disc (BDD) optical disc, a holographic optical disk, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory Stick® card, a smartcard chip, a EMV chip, a subscriber identity' module (SIM) card, a mini/micro/nano/pico SIM card, another integrated circuit (IC) chip/card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory' (ROM), programmable read-only memory (PROM), erasable programmable read-only memory
24 Polsinelli Ref. No. 094922-780686
(EPROM), electrically erasable programmable read-only memory' (EEPROM), flash EPROM (FLASHEPROM), cache memory (L1/L2/L3/L4/L5/L#), resistive random-access memory (RRAM/ReRAM). phase change memory (PCM), spin transfer torque RAM (STT-RAM). another memory chip or cartridge, and/or a combination thereof. The storage device 430 can include software instructions or code that can be executed by the processor 410 to cause the system 400 to perform a function.
[0073] As used herein, the term “computer-readable medium” includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing, containing, or carry ing instruction(s) and/or data. A computer-readable medium may include a non-transitory medium in which data can be stored and that does not include carrier waves and/or transitory electronic signals propagating wirelessly or over wired connections. Examples of a non-transitory medium may include, but are not limited to, a magnetic disk or tape, optical storage media such as compact disk (CD) or digital versatile disk (DVD), flash memory, memory or memory devices. A computer-readable medium may have stored thereon code and/or machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and/or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted using any suitable means including memory sharing, message passing, token passing, nefyvork transmission, or the like.
[0074] In some examples the computer-readable storage devices, mediums, and memories can include a cable or yvireless signal containing a bit stream and the like. However, yvhen mentioned, non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals per se.
[0075] Specific details are provided in the description above to provide a thorough understanding of the examples and examples provided herein. However, it will be understood by one of ordinary skill in the art that the examples may be practiced without these specific details. For clarity of explanation, in some instances the present technology may be presented
25 Polsinelli Ref. No. 094922-780686
as including individual functional blocks including functional blocks comprising devices, device components, operations, steps, or routines in a method embodied in software, hardware, or combinations of hardware and software. Additional components may be used other than those shown in the figures and/or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the examples in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the examples.
[0076] Individual examples may be described above as a process or method which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed, but could have additional operations not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.
[0077] Processes and methods according to the above-described examples can be implemented using computer-executable instructions that are stored or otherwise available from computer-readable media. Such instructions can include, for example, instructions and data which cause or otherwise configure a general purpose computer, special purpose computer, or a processing device to perform a certain function or group of functions. Portions of computer resources used can be accessible over a network. The computer executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmw are, source code, etc. Examples of computer-readable media that may be used to store instructions, information used, and/or information created during methods according to described examples include magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, networked storage devices, and so on.
[0078] Devices implementing processes and methods according to these disclosures can include hardware, software, firmware, middleware, microcode, hardware description
26 Polsinelli Ref. No. 094922-780686
languages, or any combination thereof, and can take any of a variety7 of form factors. When implemented in software, firmware, middleware, or microcode, the program code or code segments to perform the necessary tasks (e.g.. a computer-program product) may be stored in a computer-readable or machine-readable medium. A processor(s) may perform the necessary tasks. Typical examples of form factors include laptops, smartphones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rackmount devices, standalone devices, and so on. Functionality described herein also can be embodied in peripherals or add-in cards. Such functionality can also be implemented on a circuit board among different chips or different processes executing in a single device, by way of further example.
[0079] The instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are example means for providing the functions described in the disclosure.
[0080] In the foregoing description, aspects of the application are described with reference to specific examples thereof, but those skilled in the art will recognize that the application is not limited thereto. Thus, while illustrative examples of the application have been described in detail herein, it is to be understood that the inventive concepts may be otherwise variously embodied and employed, and that the appended claims are intended to be construed to include such variations, except as limited by the prior art. Various features and aspects of the abovedescribed application may be used individually or jointly. Further, examples described herein can be utilized in any number of environments and applications beyond those described herein without departing from the broader spirit and scope of the specification. The specification and drawings are, accordingly, to be regarded as illustrative rather than restrictive. For the purposes of illustration, methods were described in a particular order. It should be appreciated that in alternate examples, the methods may be performed in a different order than that described.
[0081] One of ordinary skill will appreciate that the less than C'<”) and greater than (“>”) symbols or terminology used herein can be replaced with less than or equal to (“<”) and greater than or equal to (“>”) symbols, respectively, without departing from the scope of this description.
27 Polsinelli Ref. No. 094922-780686
[0082] Where components are described as being “configured to” perform certain operations, such configuration can be accomplished, for example, by designing electronic circuits or other hardware to perform the operation, by programming programmable electronic circuits (e.g., microprocessors, or other suitable electronic circuits) to perform the operation, or any combination thereof.
[0083] The phrase “coupled to” refers to any component that is physically connected to another component either directly or indirectly, and/ or any component that is in communication with another component (e.g., connected to the other component over a wired or wireless connection, and/or other suitable communication interface) either directly or indirectly.
[0084] Claim language or other language reciting “at least one of’ a set and/or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language reciting “at least one of A and B” or “at least one of A or B” means A, B. or A and B. In another example, claim language reciting “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any duplicate information or data (e.g., A and A, B and B, C and C, A and A and B, and so on), or any other ordering, duplication, or combination of A, B. and C. The language “at least one of' a set and/or “one or more” of a set does not limit the set to the items listed in the set. For example, claim language reciting “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B. The phrases “at least one” and “one or more” are used interchangeably herein.
[0085] Claim language or other language reciting “at least one processor configured to,” “at least one processor being configured to,” “one or more processors configured to,” “one or more processors being configured to,” or the like indicates that one processor or multiple processors (in any combination) can perform the associated operation(s). For example, claim language reciting “at least one processor configured to: X, Y, and Z” means a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each tasked with a certain subset of operations X, Y, and Z such that together the multiple processors perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z. In another example, claim language reciting “at least one processor configured to: X, Y.
28 Polsinelli Ref. No. 094922-780686
and Z” can mean that any single processor may only perform at least a subset of operations X, Y, and Z.
[0086] Where reference is made to one or more elements performing functions (e.g., steps of a method), one element may perform all functions, or more than one element may collectively perform the functions. When more than one element collectively performs the functions, each function need not be performed by each of those elements (e.g.. different functions may be performed by different elements) and/or each function need not be performed in whole by only one element (e.g., different elements may perform different sub-functions of a function). Similarly, where reference is made to one or more elements configured to cause another element (e.g., an apparatus) to perform functions, one element may be configured to cause the other element to perform all functions, or more than one element may collectively be configured to cause the other element to perform the functions.
[0087] Where reference is made to an entity (e.g., any entity or device described herein) performing functions or being configured to perform functions (e.g., steps of a method), the entity may be configured to cause one or more elements (individually or collectively) to perform the functions. The one or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) of the functions, and/or any combination thereof. Where reference to the entity performing functions, the entity7 may be configured to cause one component to perform all functions, or to cause more than one component to collectively perform the functions. When the entity is configured to cause more than one component to collectively perform the functions, each function need not be performed by each of those components (e.g., different functions may be performed by different components) and/or each function need not be performed in whole by only one component (e.g., different components may perform different sub-functions of a function).
[0088] The various illustrative logical blocks, modules, circuits, and algorithm operations described in connection with the examples disclosed herein may be implemented as electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations have been descnbed above generally in terms of their functionality.
29 Polsinelli Ref. No. 094922-780686
Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present application.
[0089] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices such as general purposes computers, wireless communication device handsets, or integrated circuit devices having multiple uses including application in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, performs one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may comprise memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASEI memory, magnetic or optical data storage media, and the like. The techniques additionally, or alternatively, may be realized at least in part by a computer- readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and/or executed by a computer, such as propagated signals or waves.
[0090] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, an application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be
30 Polsinelli Ref. No. 094922-780686
implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction wi th a DSP core, or any other such configuration. Accordingly, the term “processor.” as used herein may refer to any of the foregoing structure, any combination of the foregoing structure, or any other structure or apparatus suitable for implementation of the techniques described herein.
[0091] Illustrative aspects of the present disclosure include:
[0092] Aspect 1. A method for data access, comprising: determining a storage device address for a storage device; determining a tag for obtaining metadata for encryption of data for the storage device; generating a return address, the return address including a host memory address and the tag; and accessing the storage device based on the return address and the storage device address.
[0093] Aspect 2. The method of Aspect 1, wherein the encryption of the data comprises encry pting or decrypting the data.
[0094] Aspect 3. The method of any of Aspects 1 or 2, wherein accessing the storage device comprises storing at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
[0095] Aspect 4. The method of any of Aspects 1-3. wherein the tag comprises an index to a memory table.
[0096] Aspect 5. The method of Aspect 4, wherein the memory table includes a key for the encryption of data.
[0097] Aspect 6. The method of any of Aspects 4 or 5, wherein the storage device address comprises a logical block address (LBA), and wherein the memory7 table includes LBA information for the storage device.
[0098] Aspect 7. The method of Aspect 6, further comprising generating a tweak for the encry ption of data based on the LBA information.
31 Polsinelli Ref. No. 094922-780686
[0099] Aspect 8. The method of any of Aspects 1-7, wherein the storage device comprises a peripheral component interconnect express (PCIe) bus device and wherein the return address comprises a PCIe address.
[0100] Aspect 9. The method of Aspect 8, wherein the tag includes 16 bits.
[0101] Aspect 10. The method of Aspect 9, wherein the tag is included in an upper 16 bits of the PCIe address.
[0102] Aspect 11. The method of any of Aspects 8-10, wherein the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCIe bus.
[0103] Aspect 12. The method of any of Aspects 1-11, wherein the storage device is encrypted using full disk encryption.
[0104] Aspect 13. The method of any of Aspects 1-12, wherein the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
[0105] Aspect 14. An apparatus for data access, the apparatus comprising: at least one memory7; a storage device; and at least one processor coupled to the at least one memory7, the at least one processor being configured to: determine a storage device address for the storage device; determine a tag for obtaining metadata for encryption of data for the storage device; generate a return address, the return address including a host memory7 address and the tag; and access the storage device based on the return address and the storage device address.
[0106] Aspect 15. The apparatus of Aspect 14, wherein the encry ption of the data comprises encrypting or decrypting the data.
[0107] Aspect 16. The apparatus of any of Aspects 14 or 15, wherein, to access the storage device, the at least one processor is configured to store at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
[0108] Aspect 17. The apparatus of any of Aspects 14-16, wherein the tag comprises an index to a memory table.
32 Polsinelli Ref. No. 094922-780686
[0109] Aspect 18. The apparatus of Aspect 17, wherein the memory table includes a key for the encryption of data.
[0110] Aspect 19. The apparatus of any of Aspects 17 or 18, wherein the storage device address comprises a logical block address (LB A), and wherein the memory7 table includes LB A information for the storage device.
[0111] Aspect 20. The apparatus of Aspect 19, wherein the at least one processor is further configured to generate a tweak for the encry ption of data based on the LBA information.
[0112] Aspect 21. The apparatus of any of Aspects 14-20. wherein the storage device comprises a peripheral component interconnect express (PCIe) bus device and wherein the return address comprises a PCIe address.
[0113] Aspect 22. The apparatus of Aspect 21, wherein the tag includes 16 bits.
[0114] Aspect 23. The apparatus of Aspect 22, wherein the tag is included in an upper 16 bits of the PCIe address.
[0115] Aspect 24. The apparatus of any of Aspects 21-23, wherein the storage device is accessed using a nonvolatile memory7 express (NVMe) interface over a PCIe bus.
[0116] Aspect 25. The apparatus of any of Aspects 14-24. wherein the storage device is encrypted using full disk encry ption.
[0117] Aspect 26. The apparatus of any of Aspects 14-25, wherein the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
[0118] Aspect 27. A non-transitory computer-readable medium having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: determine a storage device address for a storage device; determine a tag for obtaining metadata for encry ption of data for the storage device; generate a return address, the return address including a host memory address and the tag; and access the storage device based on the return address and the storage device address.
33 Polsinelli Ref. No. 094922-780686
[0119] Aspect 28. The non-transitory computer-readable medium of Aspect 27, wherein the encryption of the data comprises encrypting or decrypting the data.
[0120] Aspect 29. The non-transitory computer-readable medium of any of Aspects 27 or 28, wherein, to access the storage device, the instructions further cause the at least one processor to store at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
[0121] Aspect 30. The non-transitory7 computer-readable medium of any of Aspects 27-29, wherein the tag comprises an index to a memory- table.
[0122] Aspect 31. The non-transitory computer-readable medium of Aspect 30, wherein the memory7 table includes a key for the encry ption of data.
[0123] Aspect 32. The non-transitory computer-readable medium of any of Aspects 30 or 31, wherein the storage device address comprises a logical block address (LBA), and wherein the memory7 table includes LBA information for the storage device.
[0124] Aspect 33. The non-transitory computer-readable medium of Aspect 32, yvherein the instructions further cause the at least one processor to generate a tweak for the encryption of data based on the LBA information.
[0125] Aspect 34. The non-transitory computer-readable medium of any of Aspects 27-33, wherein the storage device comprises a peripheral component interconnect express (PCle) bus device and yvherein the return address comprises a PCle address.
[0126] Aspect 35. The non-transitory computer-readable medium of Aspect 34, yvherein the tag includes 16 bits.
[0127] Aspect 36. The non-transitory computer-readable medium of Aspect 35, yvherein the tag is included in an upper 16 bits of the PCle address.
[0128] Aspect 37. The non-transitory7 computer-readable medium of any of Aspects 34-36, wherein the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCle bus.
34 Polsinelli Ref. No. 094922-780686
[0129] Aspect 38. The non-transitory computer-readable medium of any of Aspects 27-37, wherein the storage device is encrypted using full disk encryption.
[0130] Aspect 39. The non-transitory computer-readable medium of any of Aspects 27-38, wherein the storage device is encrypted using advanced encryption standard xor encry pt xor tweakable block ciphertext stealing (AES-XTS).
[0131] Aspect 40. An apparatus for data access, comprising means for performing one or more of operations according to any of Aspects 1 to 13.
35 Polsinelli Ref. No. 094922-780686
Claims
1. An apparatus for data access, the apparatus comprising: at least one memory; a storage device; and at least one processor coupled to the at least one memory, the at least one processor being configured to: determine a storage device address for the storage device; determine a tag for obtaining metadata for encryption of data for the storage device; generate a return address, the return address including a host memory address and the tag: and access the storage device based on the return address and the storage device address.
2. The apparatus of claim 1, wherein the encry ption of the data comprises encry pting or decrypting the data.
3. The apparatus of claim 1, wherein, to access the storage device, the at least one processor is configured to store at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
4. The apparatus of claim 1, wherein the tag comprises an index to a memory table.
5. The apparatus of claim 4, wherein the memory table includes a key for the encryption of data.
6. The apparatus of claim 4, wherein the storage device address comprises a logical block address (LBA), and wherein the memory table includes LBA information for the storage device.
36 Polsinelli Ref. No. 094922-780686
7. The apparatus of claim 6, wherein the at least one processor is further configured to generate a tweak for the encryption of data based on the LBA information.
8. The apparatus of claim 4, wherein the storage device comprises a peripheral component interconnect express (PCIe) bus device and wherein the return address comprises a PCIe address.
9. The apparatus of claim 8, wherein the tag includes 16 bits.
10. The apparatus of claim 9, wherein the tag is included in an upper 16 bits of the PCIe address.
11. The apparatus of claim 8, wherein the storage device is accessed using a nonvolatile memory express (NVMe) interface over a PCIe bus.
12. The apparatus of claim 1 , wherein the storage device is encrypted using full disk encryption.
13. The apparatus of claim 1. wherein the storage device is encrypted using advanced encryption standard xor encrypt xor tweakable block ciphertext stealing (AES-XTS).
14. A method for data access, comprising: determining a storage device address for a storage device; determining a tag for obtaining metadata for encryption of data for the storage device; generating a return address, the return address including a host memory address and the tag; and accessing the storage device based on the return address and the storage device address.
15. The method of claim 14, wherein the encryption of the data comprises encrypting or decry pting the data.
37 Polsinelli Ref. No. 094922-780686
16. The method of claim 14, wherein accessing the storage device comprises storing at least the return address and the storage device address to a memory location accessible by the storage device for reading from or writing to the storage device.
17. The method of claim 14, wherein the tag comprises an index to a memory' table.
18. The method of claim 17. wherein the memory’ table includes a key for the encryption of data.
19. The method of claim 17, wherein the storage device address comprises a logical block address (LBA), and wherein the memory table includes LBA information for the storage device.
20. The method of claim 19, further comprising generating a tweak for the encryption of data based on the LBA information.
38 Polsinelli Ref. No. 094922-780686
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IN202341005411 | 2023-01-27 | ||
| PCT/US2024/012645 WO2024158833A1 (en) | 2023-01-27 | 2024-01-23 | Inline encryption and/or decryption using address tagging |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4655695A1 true EP4655695A1 (en) | 2025-12-03 |
Family
ID=90361675
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP24709546.6A Pending EP4655695A1 (en) | 2023-01-27 | 2024-01-23 | Inline encryption and/or decryption using address tagging |
Country Status (5)
| Country | Link |
|---|---|
| EP (1) | EP4655695A1 (en) |
| KR (1) | KR20250137572A (en) |
| CN (1) | CN120548531A (en) |
| TW (1) | TW202445397A (en) |
| WO (1) | WO2024158833A1 (en) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10157153B2 (en) * | 2016-02-03 | 2018-12-18 | Qualcomm Incorporated | Inline cryptographic engine (ICE) for peripheral component interconnect express (PCIe) systems |
| WO2022132184A1 (en) * | 2020-12-20 | 2022-06-23 | Intel Corporation | System, method and apparatus for total storage encryption |
| EP4016358A1 (en) * | 2020-12-20 | 2022-06-22 | INTEL Corporation | Storage encryption using converged cryptographic engine |
-
2024
- 2024-01-23 KR KR1020257021765A patent/KR20250137572A/en active Pending
- 2024-01-23 EP EP24709546.6A patent/EP4655695A1/en active Pending
- 2024-01-23 CN CN202480008360.8A patent/CN120548531A/en active Pending
- 2024-01-23 WO PCT/US2024/012645 patent/WO2024158833A1/en not_active Ceased
- 2024-01-25 TW TW113102943A patent/TW202445397A/en unknown
Also Published As
| Publication number | Publication date |
|---|---|
| WO2024158833A1 (en) | 2024-08-02 |
| KR20250137572A (en) | 2025-09-18 |
| TW202445397A (en) | 2024-11-16 |
| CN120548531A (en) | 2025-08-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10810138B2 (en) | Enhanced storage encryption with total memory encryption (TME) and multi-key total memory encryption (MKTME) | |
| TWI545436B (en) | Integrated circuit and method for secure memory management | |
| US9152825B2 (en) | Using storage controller bus interfaces to secure data transfer between storage devices and hosts | |
| CN107851163B (en) | Techniques for Integrity, Anti-Replay, and Authenticity Assurance of I/O Data | |
| US9973335B2 (en) | Shared buffers for processing elements on a network device | |
| US10691627B2 (en) | Avoiding redundant memory encryption in a cryptographic protection system | |
| EP4016358A1 (en) | Storage encryption using converged cryptographic engine | |
| US20240202340A1 (en) | Trusted access control for secure boot process for storage controllers or drivers | |
| US11907120B2 (en) | Computing device for transceiving information via plurality of buses, and operating method of the computing device | |
| US9632953B2 (en) | Providing input/output virtualization (IOV) by mapping transfer requests to shared transfer requests lists by IOV host controllers | |
| KR101684042B1 (en) | Shared buffers for processing elements on a network device | |
| US12355871B2 (en) | Pairwise key establishment between two measurement states | |
| WO2024158833A1 (en) | Inline encryption and/or decryption using address tagging | |
| US20240275575A1 (en) | Fault attack countermeasure using unified mask logic | |
| US20260067096A1 (en) | Support for additional cryptographic algorithms using an inline cryptographic hardware component | |
| US12413390B2 (en) | Compression of matrices for digital security | |
| CN120457431A (en) | Key management and protection in a secure execution environment |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250507 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |