Technologies for real-time updating of encryption keys
Claim Score by NHIP
Abstract
Techniques for real-time updating of encryption keys are disclosed. In the illustrative embodiment, an encrypted link is established between a local and remote processor over a point-to-point interconnect. The encrypted link is operated for some time until the encryption key should be updated. The local processor sends a key update message to the remote processor notifying the remote processor of the change. The remote processor prepares for the change and sends a key update confirmation message to the local processor. The local processor then sends a key switch message to the remote processor. The local processor pauses transmission of encrypted message while the remote processor completes use of the encrypted message. After a pause, the local processor continues sending encrypted messages with the updated encryption key.

Term
16.7 yearsto projected expiry
Projected expiry 26 May 2043, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
25 claims: 3 independent, 22 dependent
- 1An apparatus comprising:point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to: establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;determine an updated encryption key;transmit a key switch message to the processor to instruct the processor to use the updated encryption key;and perform, after transmission of the key switch message and without sending encrypted messages on at least one channel corresponding to the updated encryption key over the point-to-point link, one or more stages of a pipeline of the cryptographic engine to encrypt messages with the updated encryption key.
- 11A system comprising:a plurality of processors comprising a first processor and a second processor, wherein the first processor comprises first point-to-point interface circuitry and the second processor comprises second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to: establish an encrypted point-to-point link with the second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to use a first encryption key to encrypt messages for the encrypted point-to-point link;determine an updated encryption key;and transmit a key switch message to the second processor to instruct the second processor to use the updated encryption key, wherein the second point-to-point interface circuitry is to: receive, from the first processor, the key switch message to instruct the second processor to use the updated encryption key;and clear, in response to the key switch message, a pipeline of a cryptographic engine of the second point-to-point interface circuitry with use of the first encryption key;and switch, in response to the key switch message, the cryptographic engine to use the updated encryption key in place of the first encryption key.
- 16Broadest claimClaim Score 69, broad(NHIP)An apparatus comprising:point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to: establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;determine an updated encryption key;transmit a key switch message to the processor to instruct the processor to use the updated encryption key;and transmit, after transmission of the key switch message and without a reset of the encrypted point-to-point link, encrypted messages with use of the updated encryption key.
Independent claims3
162 paragraphs in 3 sections, as filed
BACKGROUND
0001Communication channels in compute systems are encrypted, such as communication channel between different components of a compute system. In some cases, encryption keys should be periodically updated. The encryption keys can be updated by shutting down a communication channel, updating the encryption keys, and then restarting the communication channel along with a warm reset of the components communicating over the communication channel.
BRIEF DESCRIPTION OF THE DRAWINGS
0002The concepts described herein are illustrated by way of example and not by way of limitation in the accompanying figures. For simplicity and clarity of illustration, elements illustrated in the figures are not necessarily drawn to scale. Where considered appropriate, reference labels have been repeated among the figures to indicate corresponding or analogous elements.
0003<figref idref="DRAWINGS">FIG. 1</figref> illustrates an embodiment of a computing system including an interconnect architecture.
0004<figref idref="DRAWINGS">FIG. 2</figref> illustrates an embodiment of a interconnect architecture including a layered stack.
0005<figref idref="DRAWINGS">FIG. 3</figref> illustrates an embodiment of a transmitter and receiver pair for an interconnect architecture.
0006<figref idref="DRAWINGS">FIG. 4</figref> illustrates an example implementation of a computing system including two host processors coupled by a link.
0007<figref idref="DRAWINGS">FIGS. 5-7</figref> are a simplified flow diagram of at least one embodiment of a method for real-time updating of encryption keys that may be performed by the computing system of <figref idref="DRAWINGS">FIG. 1</figref>.
0008<figref idref="DRAWINGS">FIG. 8</figref> illustrates an embodiment of a block diagram for a computing system including a multicore processor.
0009<figref idref="DRAWINGS">FIG. 9</figref> illustrates an embodiment of a block for a computing system including multiple processors.
DETAILED DESCRIPTION OF THE DRAWINGS
0010In the following description, numerous specific details are set forth, such as examples of specific types of processors and system configurations, specific hardware structures, specific architectural and micro architectural details, specific register configurations, specific instruction types, specific system components, specific measurements/heights, specific processor pipeline stages and operation etc. in order to provide a thorough understanding of the present disclosure. It will be apparent, however, to one skilled in the art that these specific details need not be employed to practice embodiments of the present disclosure. In other instances, well known components or methods, such as specific and alternative processor architectures, specific logic circuits/code for described algorithms, specific firmware code, specific interconnect operation, specific logic configurations, specific manufacturing techniques and materials, specific compiler implementations, specific expression of algorithms in code, specific power down and gating techniques/logic and other specific operational details of computer system haven't been described in detail in order to avoid unnecessarily obscuring embodiments of the present disclosure.
0011Although the following embodiments may be described with reference to energy conservation and energy efficiency in specific integrated circuits, such as in computing platforms or microprocessors, other embodiments are applicable to other types of integrated circuits and logic devices. Similar techniques and teachings of embodiments described herein may be applied to other types of circuits or semiconductor devices that may also benefit from better energy efficiency and energy conservation. For example, the disclosed embodiments are not limited to desktop computer systems or Ultrabooks™. And may be also used in other devices, such as handheld devices, tablets, other thin notebooks, systems on a chip (SOC) devices, and embedded applications. Some examples of handheld devices include cellular phones, Internet protocol devices, digital cameras, personal digital assistants (PDAs), and handheld PCs. Embedded applications typically include a microcontroller, a digital signal processor (DSP), a system on a chip, network computers (NetPC), set-top boxes, network hubs, wide area network (WAN) switches, or any other system that can perform the functions and operations taught below. Moreover, the apparatus', methods, and systems described herein are not limited to physical computing devices, but may also relate to software optimizations for energy conservation and efficiency. As will become readily apparent in the description below, the embodiments of methods, apparatus', and systems described herein (whether in reference to hardware, firmware, software, or a combination thereof) are vital to a ‘green technology’ future balanced with performance considerations.
0012As computing systems are advancing, the components therein are becoming more complex. As a result, the interconnect architecture to couple and communicate between the components is also increasing in complexity to ensure bandwidth requirements are met for optimal component operation. Furthermore, different market segments demand different aspects of interconnect architectures to suit the market's needs. For example, servers require higher performance, while the mobile ecosystem is sometimes able to sacrifice overall performance for power savings. Yet, it's a singular purpose of most fabrics to provide highest possible performance with maximum power saving. Below, a number of interconnects are discussed, which would potentially benefit from aspects of the present disclosure.
0013Referring to <figref idref="DRAWINGS">FIG. 1</figref>, an embodiment of a fabric composed of point-to-point Links that interconnect a set of components is illustrated. System <b>100</b> includes processor <b>105</b>, processor <b>107</b>, system memory <b>110</b> coupled to processor <b>105</b>, system memory <b>112</b> coupled to processor <b>107</b>, and controller hub <b>115</b>. Processor <b>105</b> includes any processing element, such as a microprocessor, a host processor, an embedded processor, a co-processor, or other processor. Processor <b>105</b> and processor <b>107</b> are connected by a link <b>109</b>. In the illustrative embodiment, the link <b>109</b> is a low-latency point-to-point coherent interconnect, such as a Quick Path Interconnect (QPI) or an Ultra Path Interconnect (UPI). Processors <b>105</b> and <b>107</b> are coupled to controller hub <b>115</b> through front-side buses (FSB) <b>106</b> and <b>108</b>, respectively. It should be appreciated that, in some embodiments, the system <b>100</b> may include more or fewer processors. In systems <b>100</b> with more processors, each pair of processors may be connected by a link <b>109</b>. In one embodiment, FSB <b>106</b> is a serial point-to-point interconnect as described below. In another embodiment, link <b>106</b> includes a serial, differential interconnect architecture that is compliant with different interconnect standard, such as a Quick Path Interconnect (QPI) or an Ultra Path Interconnect (UPI). In some implementations, the system may include logic to implement multiple protocol stacks and further logic to negotiation alternate protocols to be run on top of a common physical layer, among other example features.
0014System memory <b>110</b> and <b>112</b> include any memory device, such as random access memory (RAM), non-volatile (NV) memory, or other memory accessible by devices in system <b>100</b>. System memory <b>110</b> and <b>112</b> are coupled to processor <b>105</b> and <b>107</b>, respectively, though a memory interface. Examples of a memory interface include a double-data rate (DDR) memory interface, a dual-channel DDR memory interface, and a dynamic RAM (DRAM) memory interface.
0015In one embodiment, controller hub <b>115</b> is a root hub, root complex, or root controller in a Peripheral Component Interconnect Express (PCIe or PCIE) interconnection hierarchy. Examples of controller hub <b>115</b> include a chipset, a memory controller hub (MCH), a northbridge, an interconnect controller hub (ICH) a southbridge, and a root controller/hub. Often the term chipset refers to two physically separate controller hubs, i.e. a memory controller hub (MCH) coupled to an interconnect controller hub (ICH). Note that current systems often include the MCH integrated with processors <b>105</b> and <b>107</b>, while controller <b>115</b> is to communicate with I/O devices, in a similar manner as described below. In some embodiments, peer-to-peer routing is optionally supported through root complex <b>115</b>.
0016Here, controller hub <b>115</b> is coupled to switch/bridge <b>120</b> through serial link <b>119</b>. Input/output modules <b>117</b> and <b>121</b>, which may also be referred to as interfaces/ports <b>117</b> and <b>121</b>, include/implement a layered protocol stack to provide communication between controller hub <b>115</b> and switch <b>120</b>. In one embodiment, multiple devices are capable of being coupled to switch <b>120</b>.
0017Switch/bridge <b>120</b> routes packets/messages from device <b>125</b> upstream, i.e., up a hierarchy towards a root complex, to controller hub <b>115</b> and downstream, i.e., down a hierarchy away from a root controller, from processor <b>105</b> or system memory <b>110</b> to device <b>125</b>. Switch <b>120</b>, in one embodiment, is referred to as a logical assembly of multiple virtual PCI-to-PCI bridge devices. Device <b>125</b> includes any internal or external device or component to be coupled to an electronic system, such as an I/O device, a Network Interface Controller (NIC), an add-in card, an audio processor, a network processor, a hard-drive, a storage device, a CD/DVD ROM, a monitor, a printer, a mouse, a keyboard, a router, a portable storage device, a Firewire device, a Universal Serial Bus (USB) device, a scanner, and other input/output devices. Often in the PCIe vernacular, such as device, is referred to as an endpoint. Although not specifically shown, device <b>125</b> may include a PCIe to PCI/PCI-X bridge to support legacy or other version PCI devices. Endpoint devices in PCIe are often classified as legacy, PCIe, or root complex integrated endpoints.
0018Graphics accelerator <b>130</b> is also coupled to controller hub <b>115</b> through serial link <b>132</b>. In one embodiment, graphics accelerator <b>130</b> is coupled to an MCH, which is coupled to an ICH. Switch <b>120</b>, and accordingly I/O device <b>125</b>, is then coupled to the ICH. I/O modules <b>131</b> and <b>118</b> are also to implement a layered protocol stack to communicate between graphics accelerator <b>130</b> and controller hub <b>115</b>. Similar to the MCH discussion above, a graphics controller or the graphics accelerator <b>130</b> itself may be integrated in processor <b>105</b>. Further, one or more links (e.g., <b>123</b>) of the system can include one or more extension devices (e.g., <b>150</b>), such as retimers, repeaters, etc.
0019Turning to <figref idref="DRAWINGS">FIG. 2</figref> an embodiment of a layered protocol stack is illustrated. Layered protocol stack <b>200</b> includes any form of a layered communication stack, such as a Quick Path Interconnect (QPI) stack, an Ultra Path Interconnect (UPI) stack, a PCIe stack, a Compute Express Link (CXL), a next generation high performance computing interconnect stack, or other layered stack. Although the discussion immediately below in reference to <figref idref="DRAWINGS">FIGS. 1-3</figref> are in relation to a UPI stack, the same concepts may be applied to other interconnect stacks. In one embodiment, protocol stack <b>200</b> is a UPI protocol stack including protocol layer <b>202</b>, routing layer <b>205</b>, link layer <b>210</b>, and physical layer <b>220</b>. An interface or link, such as link <b>109</b> in <figref idref="DRAWINGS">FIG. 1</figref>, may be represented as communication protocol stack <b>200</b>. Representation as a communication protocol stack may also be referred to as a module or interface implementing/including a protocol stack.
0020UPI uses packets to communicate information between components. Packets are formed in the Protocol Layer <b>202</b> to carry the information from the transmitting component to the receiving component. As the transmitted packets flow through the other layers, they are extended with additional information necessary to handle packets at those layers. At the receiving side the reverse process occurs and packets get transformed from their Physical Layer <b>220</b> representation to the Data Link Layer <b>210</b> representation and finally to the form that can be processed by the Protocol Layer <b>202</b> of the receiving device.
0021Protocol Layer
0022In one embodiment, protocol layer <b>202</b> is to provide an interface between a device's processing core and the interconnect architecture, such as data link layer <b>210</b> and physical layer <b>220</b>. In this regard, a primary responsibility of the protocol layer <b>202</b> is the assembly and disassembly of packets. The packets may be categorized into different classes, such as home, snoop, data response, non-data response, non-coherent standard, and non-coherent bypass.
0023Routing Layer
0024The routing layer <b>205</b> may be used to determine the course that a packet will traverse across the available system interconnects. Routing tables may be defined by firmware and describe the possible paths that a packet can follow. In small configurations, such as a two-socket platform, the routing options are limited and the routing tables quite simple. For larger systems, the routing table options may be more complex, giving the flexibility of routing and rerouting traffic.
0025Link Layer
0026Link layer <b>210</b>, also referred to as data link layer <b>210</b>, acts as an intermediate stage between protocol layer <b>202</b> and the physical layer <b>220</b>. In one embodiment, a responsibility of the data link layer <b>210</b> is providing a reliable mechanism for exchanging packets between two components. One side of the data link layer <b>210</b> accepts packets assembled by the protocol layer <b>202</b>, applies an error detection code, i.e., CRC, and submits the modified packets to the physical layer <b>220</b> for transmission across a physical to an external device. In receiving packets, the data link layer <b>210</b> checks the CRC and, if an error is detected, instructs the transmitting device to resend. In the illustrative embodiment, CRC are performed at the flow control unit (flit) level rather than the packet level. In the illustrative embodiment, each flit is 80 bits. In other embodiments, each flit may be any suitable length, such as 16, 20, 32, 40, 64, 80, or 128 bits.
0027In the illustrative embodiment, the link layer <b>210</b> manages credit-base flow control. In this scheme, a device, such as processor <b>105</b> in <figref idref="DRAWINGS">FIG. 1</figref>, advertises an initial amount of credit for each of the receive buffers in link layer <b>210</b>. An external device at the opposite end of the link, such as processor <b>107</b> in <figref idref="DRAWINGS">FIG. 1</figref>, counts the number of credits consumed by each packet or flit. A transaction may be transmitted if the transaction does not exceed a credit limit. Upon receiving a response an amount of credit is restored. An advantage of a credit scheme is that the latency of credit return does not affect performance, provided that the credit limit is not encountered.
0028In some embodiments, the link layer <b>210</b> may perform encryption and decryption on phits, flits, or packets. The encryption functions are described in more detail below. In other embodiments, the encryption and decryption may be done at the physical layer <b>220</b> or the protocol layer <b>202</b>.
0029Physical Layer
0030In one embodiment, physical layer <b>220</b> includes logical sub block <b>221</b> and electrical sub-block <b>222</b> to physically transmit a packet to an external device. Here, logical sub-block <b>221</b> is responsible for the “digital” functions of Physical Layer <b>221</b>. In this regard, the logical sub-block includes a transmit section to prepare outgoing information for transmission by physical sub-block <b>222</b>, and a receiver section to identify and prepare received information before passing it to the Link Layer <b>210</b>.
0031Physical block <b>222</b> includes a transmitter and a receiver. The transmitter is supplied by logical sub-block <b>221</b> with symbols, which the transmitter serializes and transmits onto to an external device. The receiver is supplied with serialized symbols from an external device and transforms the received signals into a bit-stream. The bit-stream is de-serialized and supplied to logical sub-block <b>221</b>. In the illustrative embodiment, the physical layer <b>220</b> sends and receives bits in groups of 20 bits, called a physical unit or phit. In some embodiments, a line coding, such as an 8b/10b transmission code or a 64b/66b transmission code, is employed. In some embodiments, special symbols are used to frame a packet with frames <b>223</b>. In addition, in one example, the receiver also provides a symbol clock recovered from the incoming serial stream.
0032As stated above, although protocol layer <b>202</b>, routing layer <b>205</b>, link layer <b>210</b>, and physical layer <b>220</b> are discussed in reference to a specific embodiment of a QPI protocol stack, a layered protocol stack is not so limited. In fact, any layered protocol may be included/implemented. As an example, a port/interface that is represented as a layered protocol includes: (1) a first layer to assemble packets, i.e. a protocol layer; a second layer to sequence packets, i.e. a link layer; and a third layer to transmit the packets, i.e. a physical layer. As a specific example, a common standard interface (CSI) layered protocol is utilized.
0033Referring next to <figref idref="DRAWINGS">FIG. 3</figref>, an embodiment of a UPI serial point-to-point link is illustrated. Although an embodiment of a UPI serial point-to-point link is illustrated, a serial point-to-point link is not so limited, as it includes any transmission path for transmitting serial data. In the embodiment shown, a basic UPI serial point-to-point link includes two, low-voltage, differentially driven signal pairs: a transmit pair <b>306</b>/<b>312</b> and a receive pair <b>311</b>/<b>307</b>. Accordingly, device <b>305</b> includes transmission logic <b>306</b> to transmit data to device <b>310</b> and receiving logic <b>307</b> to receive data from device <b>310</b>. In other words, two transmitting paths, i.e. paths <b>316</b> and <b>317</b>, and two receiving paths, i.e. paths <b>318</b> and <b>319</b>, are included in a UPI link.
0034A transmission path refers to any path for transmitting data, such as a transmission line, a copper line, an optical line, a wireless communication channel, an infrared communication link, or other communication path. A connection between two devices, such as device <b>305</b> and device <b>310</b>, is referred to as a link, such as link <b>315</b>. A link may support one lane—each lane representing a set of differential signal pairs (one pair for transmission, one pair for reception). To scale bandwidth, a link may aggregate multiple lanes denoted by xN, where N is any supported Link width, such as 1, 2, 4, 5, 8, 10, 12, 16, 20, 32, 64, or wider. In some implementations, each symmetric lane contains one transmit differential pair and one receive differential pair. Asymmetric lanes can contain unequal ratios of transmit and receive pairs. Some technologies can utilize symmetric lanes (e.g., UPI), while others (e.g., Displayport) may not and may even including only transmit or only receive pairs, among other examples. A link may refer to a one-way link (such as the link established by transmission logic <b>306</b> and receive logic <b>311</b>) or may refer to a bi-directional link (such as the links established by transmission logic <b>306</b> and <b>312</b> and receive logic <b>307</b> and <b>311</b>).
0035A differential pair refers to two transmission paths, such as lines <b>316</b> and <b>317</b>, to transmit differential signals. As an example, when line <b>316</b> toggles from a low voltage level to a high voltage level, i.e. a rising edge, line <b>317</b> drives from a high logic level to a low logic level, i.e. a falling edge. Differential signals potentially demonstrate better electrical characteristics, such as better signal integrity, i.e. cross-coupling, voltage overshoot/undershoot, ringing, etc. This allows for better timing window, which enables faster transmission frequencies.
0036Turning to <figref idref="DRAWINGS">FIG. 4</figref>, a simplified block diagram <b>400</b> is shown illustrating an example system utilizing a UPI link <b>416</b>. For instance, the link <b>416</b> may interconnect a first host processor <b>402</b>A (e.g., a first CPU) and a second host processor <b>402</b>B (e.g., a second CPU). In this example, each host processor <b>402</b>A, <b>402</b>B includes one or more processor cores (e.g., <b>404</b>A-D). Each processor <b>402</b>A, <b>402</b>B is connected to host memory <b>412</b>A, <b>412</b>B over a link <b>414</b>A, <b>414</b>B. In this example, each host processor <b>402</b>A, <b>402</b>B may include circuitry to implement coherence/cache logic <b>406</b>A, <b>406</b>B. Each processor <b>402</b>A, <b>402</b>B includes point-to-point interface circuitry <b>408</b>A, <b>408</b>B to communicate over the UPI link <b>416</b>. Point-to-point interface circuitry <b>408</b>B may be similar to point-to-point interface circuitry <b>408</b>A, described in more detail below.
0037The point-to-point interface circuitry <b>408</b>A is configured to send and receive data over the UPI link <b>416</b>. The point-to-point interface circuitry <b>408</b>A may, e.g., implement the UPI stack <b>200</b> described above in regard to <figref idref="DRAWINGS">FIG. 2</figref>. The point-to-point interface circuitry <b>408</b>A includes a cryptographic manager <b>409</b>A and a cryptographic engine <b>410</b>A. It should be appreciated that, in some embodiments, the point-to-point interface circuitry <b>408</b>A operates both a transmit link and a receive link. As such, the point-to-point interface circuitry <b>408</b>A may include an independent cryptographic manager <b>409</b>A and/or an independent cryptographic engine <b>410</b>A for each of a transmit link and a receive link. In other embodiments, a single cryptographic manager <b>409</b>A and/or a single cryptographic engine <b>410</b>A may be able to operate both a transmit channel and a receive channel contemporaneously.
0038The point-to-point interface circuitry <b>408</b>A may be embodied as hardware, software, firmware, or a combination thereof. For example, the various modules, logic, and other components of the point-to-point circuitry <b>408</b>A may form a portion of, or otherwise be established by, the processor <b>402</b>A or other hardware components such as the host memory <b>412</b>A, data storage, etc. For example, in one embodiment, the cryptographic manager <b>409</b>A to control update of the keys used by the cryptographic engine <b>410</b>A may be embodied as firmware or software. In some embodiments, the cryptographic manager <b>409</b>A may be embodied as a processor as well as memory and/or data storage storing instructions to be executed by the processor. It should be appreciated that the cryptographic manager <b>409</b>A does not need to be fully contained within the host processor <b>402</b>A. For example, the cryptographic manager <b>409</b>A controlling key updates for the cryptographic engine <b>410</b>A and cryptographic engine <b>410</b>B may be partially or wholly within the host processor <b>402</b>B or a processor of a different device. The cryptographic manager <b>409</b>A may perform any suitable task relating the update of keys, such as determining whether a key should be updated, generating and distributing keys, instructing the point-to-point interface circuitry <b>408</b>A to send messages related to the key update process (such as a key update message, a key update confirmation message, or a key switch message), etc. In some embodiments, the cryptographic manager <b>409</b>A may include the cryptographic engine <b>410</b>A. It should be appreciated that some of the functionality of the point-to-point interface circuitry <b>408</b>A may require a hardware implementation, in which case embodiments which implement such functionality will be embodied at least partially as hardware.
0039The cryptographic manager <b>409</b>A is configured to perform various tasks related to encryption, creating and distributing encryption keys, updating encryption keys, configuring the cryptographic engine <b>410</b>A with encryption keys, etc. The cryptographic engine <b>410</b>A is configured to encrypt and decrypt messages sent to and received from a link with another device. The cryptographic manager <b>409</b>A may establish an encrypted link between the local processor <b>402</b>A and a remote processor, such as processor <b>402</b>B using the cryptographic engine <b>410</b>A. Additionally or alternatively, in some embodiments, the cryptographic manager <b>409</b>A may establish a link with other components, such as a field programmable gate array, a root complex, a chipset, a memory, etc.
0040To establish the encrypted link, the cryptographic manager <b>409</b>A generates an initial encryption key using a public key cryptography system, such as a Diffie-Hellman key exchange. The cryptographic manager <b>409</b>A may use the public key cryptography system to generate a key for any suitable encryption algorithm. In the illustrative embodiment, the cryptographic manager <b>409</b>A uses the encryption key to establish an Advanced Encryption Standard (AES) link in Galois/Counter Mode (AES-GCM). In other embodiments, the cryptographic manager <b>409</b>A may establish the encrypted link using any suitable encryption algorithm, such as AES with Galois message authentication code (GMAC). The cryptographic manager <b>409</b>A may establish a random or pseudo-random initialization vector to use to begin the encryption.
0041In the illustrative embodiment, the cryptographic manager <b>409</b>A establishes an independent encryption link for a transmit link and a receive link, such as the transmit link and receive link shown in <figref idref="DRAWINGS">FIG. 3</figref>. The cryptographic manager <b>409</b>A may establish a transmit link based on a transmit encryption key and a receive link based on a receive encryption key. In the illustrative embodiment, the cryptographic manager <b>409</b>A controls the transmit link, and the remote processor (such as processor <b>402</b>B) controls the receive link (i.e., the link in which the remote processor is on the transmit end and the processor <b>402</b>A is the receive end). In some embodiments, the encryption link between the local processor and the remote processor may include several channels, each of which may have a separate encryption key. For example, a link may have two channels, each of which has a transmit encryption key and a receive encryption key. In some embodiments, the channels are virtual channels, each of which is communicated over the same physical link. It should be appreciated that, in some embodiments, each of the messages sent between the local and remote processors may include an indication of the channel the message corresponds to.
0042Once established, the cryptographic manager <b>409</b>A may operate the encrypted link between the local processor <b>402</b>A and the remote processor using the cryptographic engine <b>410</b>A. The cryptographic engine <b>410</b>A may send and receive packets, flits, and phits. In the illustrative embodiment, each packet is encrypted and decrypted. In some embodiments, some subset of the packet, such as the payload, may be encrypted, while other parts of the packet, such as a header or CRC information, may not be encrypted. In other embodiments, encryption and decryption may be applied to each flit or phit. In the illustrative embodiment, the cryptographic engine <b>410</b>A is pipelined, such that several packets can undergo different stages of encryption or decryption simultaneously. It should be appreciated that, in some embodiments, some packets, flits, or phits may not be encrypted, such as control packets. The cryptographic engine <b>410</b>A may, in conjunction with other components such as the coherence/cache logic <b>406</b>A, process memory requests, such as requests for memory sent to the remote processor, requests for memory sent by the remote processor, data response messages sent to the remote processor, data response messages received from the remote processor, etc. The cryptographic engine <b>410</b>A may also encrypt and decrypt other types of packets, such as control packets, packets related to the encryption of the link, etc.
0043In certain circumstances, the transmit encryption key should be updated. For example, the cryptographic manager <b>409</b>A may determine whether the transmit encryption key should be updated based on an amount of data that has been transferred using the transmit encryption key or may determine whether the transmit encryption key should be updated based on an amount of time since the key was first used. The amount of time could be any suitable amount of time, such as any time from one hour up to one year. In the illustrative embodiment, the threshold amount of time is several months. In other embodiments, the cryptographic manager <b>409</b>A may determine whether the transmit encryption key should be updated based on any suitable combination of an amount of data that has been transferred using the transmit encryption key, an amount of time since the key was first used, etc. The cryptographic manager <b>409</b>A may make the determination based on encryption standards, such as encryption standards from the National Institute for Standards and Technology (NIST). In some embodiments, the cryptographic manager <b>409</b>A may be instructed to update the encryption key, such as by a user or an orchestrator server. The cryptographic manager <b>409</b>A may be instructed to update the encryption key if, e.g., a data breach occurred that could affect the current key.
0044When a transmit key is to be updated, the cryptographic manager <b>409</b>A generates an updated encryption key. The cryptographic manager <b>409</b>A may generate the updated encryption key in any suitable manner. For example, the cryptographic manager <b>409</b>A may use a random number generator to generate a new key, or the cryptographic manager <b>409</b>A may use a key generation function or key derivation function (KDF) on the previously generated random key to generate a new key. Once a new key has been generated, cryptographic manager <b>409</b>A may send the key to the remote agent using any suitable manner. For example, the cryptographic manager <b>409</b>A may use a similar Diffie-Hellman key exchange protocol used to generate the initial transmit encryption key or the cryptographic manager <b>409</b>A may use a previously-generated session key to send a key to the remote processor. The cryptographic manager <b>409</b>A stores the updated transmit encryption key in a shadow register of the cryptographic engine <b>409</b>A. By placing the transmit encryption key in the shadow register, the cryptographic engine <b>410</b>A can be prepared to begin using the updated encryption key with little or no advanced notice.
0045After preparing the updated transmit encryption key, the cryptographic manager <b>409</b>A sends a key update message to the remote processor. In some embodiment, the cryptographic manager <b>409</b>A sends the updated transmit encryption key in the key update message. In other embodiments, the cryptographic manager <b>409</b>A may coordinate with the remote processor to share the updated transmit encryption key before or after sending the key update message.
0046After the cryptographic manager <b>409</b>A sends the key update message, the remote processor prepares to switch to using the updated transmit encryption key. While it is doing so, the cryptographic engine <b>410</b>A continues operating the encryption link between the local processor and the remote processor using the current transmit encryption key (and the current receive encryption key). After the remote processor is ready to switch to the updated transmit encryption key, it sends a key update confirmation message to the cryptographic manager <b>409</b>A. In the illustrative embodiment, the key update confirmation message indicates that the remote processor is ready to switch to the updated key. In other embodiments, the key update confirmation message may indicate that the remote processor will be ready to switch to the updated key at a particular time in the future.
0047After receiving the key update confirmation message, the cryptographic manager <b>409</b>A sends a key switch message to the remote processor. In the illustrative embodiment, the key switch message instructs the remote processor to begin using the updated transmit encryption key and indicates that the next message will be encrypted with the updated transmit encryption key. In some embodiments, the key switch message indicates that the use of the updated transmit encryption key will begin at some point in the future, such as at a particular time or after a particular number of additional messages have been sent with the updated transmit encryption key.
0048After sending the key switch message, the cryptographic engine <b>410</b>A activates the updated transmit encryption key. In the illustrative embodiment, the cryptographic engine <b>410</b>A activates the updated transmit encryption key immediately after sending the key switch message. To do so, in the illustrative embodiment, the cryptographic engine <b>410</b>A copies the updated transmit encryption key from a shadow register to an active register. In some embodiments, the cryptographic engine <b>410</b>A may wait to activate the updated transmit encryption key until a later time, such as when the first message is to be encrypted using the updated transmit encryption key.
0049After sending the key switch message, the cryptographic engine <b>410</b>A pauses transmission of encrypted messages in order to allow the remote processor time to activate the updated transmit key. In the illustrative embodiment, the cryptographic engine <b>410</b>A pauses transmission of all encrypted messages (e.g., pauses transmission of encrypted messages on the only channel in use). In other embodiments, the cryptographic engine <b>410</b>A may only pause sending encrypted messages on the channel corresponding to the updated transmit encryption key and may continue sending encrypted messages for other channels that use other encryption keys. It should be appreciated that, in embodiments which do not encrypt all messages, the point-to-point interface circuitry <b>408</b>A may continue to send unencrypted messages on the same channel. In some embodiments, during the pause, the cryptographic engine <b>410</b>A may begin to fill a pipeline of encrypted messages to be sent using the updated transmit encryption key.
0050The cryptographic engine <b>410</b>A may pause for any suitable amount of time, such as any amount of time from 1-1,000 nanoseconds. In the illustrative embodiment, the cryptographic engine <b>410</b>A pauses for a pre-determined amount of time of 100 nanoseconds. In some embodiments, the cryptographic engine <b>410</b>A may pause until a trigger occurs, such as another confirmation message from the remote processor. After completing the pause, the cryptographic engine <b>410</b>A can continue operating the encrypted link. It should be appreciated that, in the illustrative embodiment, the cryptographic engine <b>410</b>A pauses sending encrypted messages on the channel associated with the key being updated. The cryptographic engine <b>410</b>A may send unencrypted messages, send encrypted messages for other channels, receive encrypted messages, etc.
0051In the illustrative embodiment, the cryptographic manager <b>409</b>A manages the transmit encryption key used to encrypt data sent to the processor <b>402</b>B. Conversely, the cryptographic manager <b>409</b>B manages the key used to encrypt data sent from the processor <b>402</b>B to the cryptographic engine <b>410</b>A using what is, from the perspective of the cryptographic engine <b>410</b>A, the receive encrypt key.
0052When the cryptographic manager <b>409</b>B determines that the receive encryption key should be updated, it sends a key update message to the cryptographic engine <b>410</b>A indicating that the receive encryption key should be updated. The receive encryption key can be shared with the cryptographic engine <b>410</b>A in a similar manner as the transmit encryption key is shared with the cryptographic engine <b>410</b>B.
0053The cryptographic engine <b>410</b>A stores the updated receive encryption key in a shadow register, such as a shadow register of the cryptographic engine <b>410</b>A. The illustrative cryptographic engine <b>410</b>A stores the updated receive encryption key in a shadow register in order to be able to switch to using the updated receive encryption key quickly. The cryptographic engine <b>410</b>A may take any additional or alternative action necessary to prepare to switch to using the updated receive encryption key on short notice. When the cryptographic engine <b>410</b>A is ready to switch to the updated receive encryption key, the cryptographic engine <b>410</b>A sends a key update confirmation message to the remote processor. The illustrative embodiment, the key update confirmation message indicates that the cryptographic engine <b>410</b>A is ready to switch to the updated key. In other embodiments, the key update confirmation message may indicate that the cryptographic engine <b>410</b>A will be ready to switch to the updated key at a particular time in the future.
0054When the cryptographic manager <b>409</b>B is ready to switch to the receive encryption key, it sends a key switch message to the cryptographic engine <b>410</b>A. In the illustrative embodiment, the key switch message instructs the cryptographic engine <b>410</b>A to begin using the updated transmit encryption key and indicates that the next message will be encrypted with the updated transmit encryption key. In some embodiments, the key switch message indicates that the use of the updated transmit encryption key will begin at some point in the future, such as at a particular time or after a particular number of additional messages have been sent with the updated transmit encryption key.
0055After receiving the key switch message, the cryptographic engine <b>410</b>A completes processing received messages with the current receive encryption key. In the illustrative embodiment, the cryptographic engine <b>410</b>A operates a pipeline, and the cryptographic engine <b>410</b>A must complete some or all of the decryption operation before changing the receive encryption key. Additionally or alternatively, the cryptographic engine <b>410</b>A may perform tasks such as integrity verification with the current receive encryption key. It should be appreciated that, during the time that the cryptographic engine <b>410</b>A is clearing out the pipeline based on the current receive encryption key, the cryptographic engine <b>410</b>A cannot begin decrypting messages using the updated receive encryption key. As such, the remote processor will pause sending messages on the channel corresponding to the updated receive encryption key.
0056Once the processing operations using the current receive encryption key have been completed, the cryptographic engine <b>410</b>A activates the updated receive encryption ley. The cryptographic engine <b>410</b>A can then continue performing encryption operations.
0057It should be appreciated that the description of the cryptographic manager <b>409</b>A and the cryptographic engine <b>410</b>A above is for one possible embodiment, but other embodiments with additional or different operations or operations performed in a different order are possible. For example, the cryptographic manager <b>409</b>A can determine the updated transmit encryption key before even determining that the transmit encryption key should be updated, such as shortly after activating a new transmit encryption key. As another example, the cryptographic manager <b>409</b>A can send the transmit encryption key to the remote processor before or after sending the key update message. In yet another example, the cryptographic manager <b>409</b>A may continue sending messages encrypted with the current transmit key after sending the key switch message, such as sending a predetermined number of messages before activating the updated encryption key and pausing transmission of encrypted messages.
0058Referring now to <figref idref="DRAWINGS">FIG. 5</figref>, in use, the system <b>100</b> may execute a method <b>500</b> for real-time updating of encryption keys. The method <b>500</b> may be performed by any suitable combination of hardware, software, and/or other components of the system <b>100</b>, such as the processor <b>402</b>A, the point-to-point interface circuitry <b>408</b>A, the cryptographic manager <b>409</b>A, the cryptographic engine <b>410</b>A, etc. In the embodiment discussed below, some of the method <b>500</b> is described as being performed by the processor <b>402</b>A. It should be appreciate that, in other embodiments, some or all of the method <b>500</b> may be performed by any suitable component, such as hardware, firmware, and/or software of any suitable component, such as the processor <b>402</b>A, the processor <b>402</b>B, the host memory <b>412</b>A, the host memory <b>412</b>B, the cryptographic manager <b>409</b>A, the cryptographic engine <b>410</b>A, etc.
0059In block <b>502</b>, the processor <b>402</b>A establishes an encrypted link between the local processor <b>402</b>A and a remote processor, such as processor <b>402</b>B. It should be appreciated that the remote processor does not need to be any particular distance away from the processor <b>402</b>A. Rather, the remote processor refers to the component on the other end of the encrypted link established between the processors. In practice, the remote processor may be, e.g., adjacent to the local processor on the same motherboard. It should also be appreciated that the link may be established between any two suitable components, such any combination of a processor, field programmable gate array, root complex, chipset, memory, etc.
0060In the illustrative embodiment, the processor <b>402</b>A generates an initial encryption key using a public key cryptography system, such as a Diffie-Hellman key exchange in block <b>504</b>. The processor <b>402</b>A may use the public key cryptography system to generate a key for any suitable encryption algorithm. In the illustrative embodiment, the processor <b>402</b>A uses the encryption key to encrypt and integrity protect the link using an Advanced Encryption Standard (AES) link Galois/Counter Mode (AES-GCM) in block <b>506</b>. In other embodiments, the processor <b>402</b>A may establish the encrypted link using any suitable encryption algorithm, such as AES Counter mode for encryption and AES Galois message authentication code (GMAC) for data integrity. The processor <b>402</b>A may establish a random or pseudo-random initialization vector to use to begin the encryption.
0061In the illustrative embodiment, the processor <b>402</b>A establishes an independent encryption link for a transmit link and a receive link. The processor <b>402</b>A may establish a transmit link based on a transmit encryption key and a receive link based on a receive encryption key in block <b>508</b>. In the illustrative embodiment, the processor <b>402</b>A controls the transmit link, and the remote processor controls the receive link (i.e., the link in which the remote processor is on the transmit end and the processor <b>402</b>A is the receive end). In some embodiments, the encryption link between the local processor and the remote processor may include several channels, each of which may have a separate encryption key. For example, a link may have two channels, each of which has a transmit encryption key and a receive encryption key. In some embodiments, the channels are virtual channels, each of which is communicated over the same physical link. It should be appreciated that, in some embodiments, each of the messages sent between the local and remote processors may include an indication of the channel the message corresponds to.
0062In block <b>510</b>, the processor <b>402</b>A operates the encrypted link between the local processor <b>402</b>A and the remote processor. The processor <b>402</b>A may send and receive packets, flits, and phits. In the illustrative embodiment, each packet is encrypted and decrypted. In some embodiments, some subset of the packet, such as the payload, may be encrypted, while other parts of the packet, such as a header or CRC information, may not be encrypted. In other embodiments, encryption and decryption may be applied to each flit or phit. Each transmitted (or received) packet may be encrypted (or decrypted) in a cryptographic engine, such as cryptographic engine <b>410</b>A. In the illustrative embodiment, the cryptographic engine <b>410</b>A is pipelined, such that several packets can undergo different stages of encryption or decryption simultaneously. It should be appreciated that, in some embodiments, some packets, flits, or phits may not be encrypted, such as control packets.
0063In block <b>512</b>, the processor <b>402</b>A processes memory requests, such as requests for memory sent to the remote processor, requests for memory sent by the remote processor, data response messages sent to the remote processor, data response messages received from the remote processor, etc. The processor <b>402</b>A may also process other types of packets, such as control packets, packets related to the encryption of the link, etc.
0064In block <b>514</b>, the processor <b>402</b>A may receive from the remote processor a key update message for the receive encryption key indicating that the receive encryption key should be updated. In the illustrative embodiment, the key update message includes an updated receive encryption key. In embodiments with different encryption keys for different channels, the key update message includes an indication of the channel for which the key is to be updated.
0065In block <b>518</b>, the processor <b>402</b>A determines whether the transmit encryption key should be updated. The processor <b>402</b>A may determine whether the transmit encryption key should be updated based on an amount of data that has been transferred using the transmit encryption key in block <b>518</b>. The processor <b>402</b>A may determine whether the transmit encryption key should be updated based on an amount of time since the key was first used in block <b>520</b>. The amount of time could be any suitable amount of time, such as any time from one hour up to one year. In the illustrative embodiment, the threshold amount of time is several months. In other embodiments, the processor <b>402</b>A may determine whether the transmit encryption key should be updated based on any suitable combination of an amount of data that has been transferred using the transmit encryption key, an amount of time since the key was first used, etc. The processor <b>402</b>A may make the determination based on encryption standards, such as encryption standards from the National Institute for Standards and Technology (NIST). In some embodiments, the processor <b>402</b>A may be instructed to update the encryption key, such as by a user or an orchestrator server. The processor <b>402</b>A may be instructed to update the encryption key if, e.g., a data breach occurred that could affect the current key.
0066Referring now to block <b>522</b>, if the processor <b>402</b>A determined that the transmit encryption key should not be updated, the method <b>500</b> proceeds to block <b>524</b> to check if a key update message was received from the remote processor in regard to the receive encryption key. If the processor <b>402</b>A determined that the transmit encryption key should be updated, the method <b>500</b> proceeds to block <b>526</b> in <figref idref="DRAWINGS">FIG. 6</figref>.
0067Referring now to <figref idref="DRAWINGS">FIG. 6</figref>, in block <b>526</b>, the processor <b>402</b>A determines the updated transmit encryption key. The processor <b>402</b>A may determine the updated transmit encryption key in any suitable manner. For example, the processor <b>402</b>A may use a similar Diffie-Hellman key exchange protocol used to generate the initial transmit encryption key or the processor <b>402</b>A may use a previously-generated session key to send a key to the remote processor. In some embodiments, the generation of the updated may be performed by specialized key generation hardware. The processor <b>402</b>A may generate the updated encryption key using, e.g., a random or pseudo-random number generator. In block <b>528</b>, the processor <b>402</b>A stores the updated transmit encryption key in a shadow register, such as in a shadow register of the cryptographic engine <b>410</b>A. By placing the transmit encryption key in the shadow register, the cryptographic engine <b>410</b>A can be prepared to begin using the updated encryption key with little or no advanced notice.
0068In block <b>530</b>, the processor <b>402</b>A sends a key update message to the remote processor. In some embodiments, the processor <b>402</b>A sends the updated transmit encryption key in the key update message in block <b>532</b>. In other embodiments, the processor <b>402</b>A may coordinate with the remote processor to the updated transmit encryption key before or after sending the key update message. In the illustrative embodiment, the key update message is embodied as a flit. Additionally or alternatively, the key update message may be embodied as another type of message, such as a packet or phit.
0069After the processor <b>402</b>A sends the key update message, the remote processor prepares to switch to using the updated transmit encryption key. While it is doing so, the processor <b>402</b>A continues operating the encryption link between the local processor and the remote processor using the current transmit encryption key (and the current receive encryption key) in block <b>534</b>. In block <b>536</b>, the processor <b>402</b>A receives a key update confirmation message from the remote processor. In the illustrative embodiment, the key update confirmation message indicates that the remote processor is ready to switch to the updated key. In other embodiments, the key update confirmation message may indicate that the remote processor will be ready to switch to the updated key at a particular time in the future. In the illustrative embodiment, the key update confirmation message is embodied as a flit. Additionally or alternatively, the key update confirmation message may be embodied as another type of message, such as a packet or phit.
0070In block <b>538</b>, if the processor <b>402</b>A did not receive a key update confirmation message, the method <b>500</b> loops back to block <b>534</b> to continue operating the encrypted link. If the processor <b>402</b>A did receive a key update confirmation message, the method <b>500</b> proceeds to block <b>540</b>.
0071In block <b>540</b>, the processor <b>402</b>A sends a key switch message to the remote processor. In the illustrative embodiment, the key switch message instructs the remote processor to begin using the updated transmit encryption key and indicates that the next message will be encrypted with the updated transmit encryption key. In some embodiments, the key switch message indicates that the use of the updated transmit encryption key will begin at some point in the future, such as at a particular time or after a particular number of additional messages have been sent with the updated transmit encryption key. In the illustrative embodiment, the key switch message is embodied as a flit. Additionally or alternatively, the key switch message may be embodied as another type of message, such as a packet or phit.
0072In block <b>542</b>, the processor <b>402</b>A activates the updated transmit encryption key. In the illustrative embodiment the processor <b>402</b>A activates the updated transmit encryption key immediately after sending the key switch message. To do so, in the illustrative embodiment, the cryptographic engine <b>410</b>A copies the updated transmit encryption key from a shadow register to an active register. In some embodiments, the processor <b>402</b>A may wait to activate the updated transmit encryption key until a later time, such as when the first message is to be encrypted using the updated transmit encryption key.
0073In block <b>544</b>, the processor <b>402</b>A pauses transmission of encrypted messages in order to allow the remote processor time to activate the updated transmit key. In the illustrative embodiment, the processor <b>402</b>A pauses transmission of all encrypted messages (e.g., pauses transmission of encrypted messages on the only channel in use). In other embodiments, the processor <b>402</b>A may only pause sending encrypted messages on the channel corresponding to the updated transmit encryption key and may continue sending encrypted messages for other channels that use other encryption keys. It should be appreciated that, in embodiments which do not encrypt all messages, the processor <b>402</b>A may continue to send unencrypted messages on the same channel. In some embodiments, during the pause, the processor <b>402</b>A may begin to fill a pipeline of encrypted messages to be sent using the updated transmit encryption key.
0074The processor <b>402</b>A may pause for any suitable amount of time, such as any amount of time from 1-1,000 nanoseconds. In the illustrative embodiment, the processor <b>402</b>A pauses for a pre-determined amount of time of 100 nanoseconds. In some embodiments, the processor <b>402</b>A may pause until a trigger occurs, such as another confirmation message from the remote processor. After completing the pause, the processor <b>402</b>A loops back to block <b>510</b> in <figref idref="DRAWINGS">FIG. 5</figref> to continue operating the encrypted link.
0075Referring back to block <b>524</b> in <figref idref="DRAWINGS">FIG. 5</figref>, if the processor <b>402</b>A did not receive a key update message from the remote processor in regard to the receive encryption key in block <b>514</b>, the method <b>500</b> loops back to block <b>510</b> to continue operating the encrypted link. If the processor <b>402</b>A did receive a key update message from the remote processor in regard to the receive encryption key in block <b>514</b>, the method <b>500</b> proceeds to block <b>540</b> in <figref idref="DRAWINGS">FIG. 7</figref>.
0076Referring now to <figref idref="DRAWINGS">FIG. 7</figref>, in block <b>546</b>, the processor <b>402</b>A stores the updated receive encryption key in a shadow register, such as a shadow register of the cryptographic engine <b>410</b>A. The illustrative processor <b>402</b>A stores the updated receive encryption key in a shadow register of the cryptographic engine <b>410</b>A in order to be able to switch to using the updated receive encryption key quickly. The processor <b>402</b>A may take any additional or alternative action necessary to prepare to switch to using the updated receive encryption key on short notice.
0077In block <b>548</b>, the processor <b>402</b> sends a key update confirmation message to the remote processor. The illustrative embodiment, the key update confirmation message indicates that the processor <b>402</b>A is ready to switch to the updated key. In other embodiments, the key update confirmation message may indicate that the processor <b>402</b>A will be ready to switch to the updated key at a particular time in the future.
0078In block <b>550</b>, the processor <b>402</b>A continues operating the encryption link between the local processor and the remote processor using the current receive encryption key (and the current transmit encryption key). In block <b>552</b>, the processor <b>402</b>A receives a key switch message from the remote processor. In the illustrative embodiment, the key switch message instructs the processor <b>402</b>A to begin using the updated transmit encryption key and indicates that the next message will be encrypted with the updated transmit encryption key. In some embodiments, the key switch message indicates that the use of the updated transmit encryption key will begin at some point in the future, such as at a particular time or after a particular number of additional messages have been sent with the updated transmit encryption key.
0079In block <b>554</b>, if the processor <b>402</b>A did not receive a key switch message, the method <b>500</b> loops back to block <b>550</b> to continue operating the encrypted link. If the processor <b>402</b>A did receive a key update confirmation message, the method <b>500</b> proceeds to block <b>556</b>.
0080In block <b>556</b>, the processor <b>402</b>A completes processing received messages with the current receive encryption key. In the illustrative embodiment, the cryptographic engine <b>410</b>A operates a pipeline, and the cryptographic engine <b>410</b>A must complete some or all of the decryption operation before changing the receive encryption key. Additionally or alternatively, the cryptographic engine <b>410</b>A may perform tasks such as integrity verification with the current receive encryption key. It should be appreciated that, during the time that the cryptographic engine <b>410</b>A is clearing out the pipeline based on the current receive encryption key, the cryptographic engine <b>410</b>A cannot begin decrypting messages using the updated receive encryption key. As such, the remote processor will pause sending messages on the channel corresponding to the updated receive encryption key, similar to the pause described in block <b>544</b> in <figref idref="DRAWINGS">FIG. 6</figref>.
0081Once the processing operations using the current receive encryption key have been completed, the processor <b>402</b>A activates the updated receive encryption key in block <b>558</b>. The method <b>500</b> then loops back to block <b>510</b> in <figref idref="DRAWINGS">FIG. 5</figref> to continue performing encryption operations.
0082It should be appreciated that the method <b>500</b> describes one embodiment, but other embodiments with additional or different operations or operations performed in a different order are possible. For example, the processor <b>402</b>A can determine the updated transmit encryption key before even determining that the transmit encryption key should be updated, such as shortly after activating a new transmit encryption key. As another example, the processor <b>402</b>A can send the transmit encryption key to the remote processor before or after sending the key update message. In yet another example, the processor <b>402</b>A may continue sending messages encrypted with the current transmit key after sending the key switch message, such as sending a predetermined number of messages before activating the updated encryption key and pausing transmission of encrypted messages.
0083It should further be appreciated that the flowchart shown in <figref idref="DRAWINGS">FIGS. 5-7</figref> do not correspond to the only possible flow of a method. For example, the processor <b>402</b>A may send a key update message for the transmit encryption key to the remote processor and, while waiting for a key update confirmation message, may receive a key update message for the receive key from the remote processor. As another example, the processor <b>402</b>A may send a key update message for the transmit encryption key for a first channel and, while waiting for a key update confirmation message for the first channel, may send a key update message for the transmit encryption key for a second channel.
0084Referring to <figref idref="DRAWINGS">FIG. 8</figref>, an embodiment of a block diagram for a computing system including a multicore processor is depicted. Processor <b>800</b> includes any processor or processing device, such as a microprocessor, an embedded processor, a digital signal processor (DSP), a network processor, a handheld processor, an application processor, a co-processor, a system on a chip (SOC), or other device to execute code. Processor <b>800</b>, in one embodiment, includes at least two cores—core <b>801</b> and <b>802</b>, which may include asymmetric cores or symmetric cores (the illustrated embodiment). However, processor <b>800</b> may include any number of processing elements that may be symmetric or asymmetric.
0085In one embodiment, a processing element refers to hardware or logic to support a software thread. Examples of hardware processing elements include: a thread unit, a thread slot, a thread, a process unit, a context, a context unit, a logical processor, a hardware thread, a core, and/or any other element, which is capable of holding a state for a processor, such as an execution state or architectural state. In other words, a processing element, in one embodiment, refers to any hardware capable of being independently associated with code, such as a software thread, operating system, application, or other code. A physical processor (or processor socket) typically refers to an integrated circuit, which potentially includes any number of other processing elements, such as cores or hardware threads.
0086A core often refers to logic located on an integrated circuit capable of maintaining an independent architectural state, wherein each independently maintained architectural state is associated with at least some dedicated execution resources. In contrast to cores, a hardware thread typically refers to any logic located on an integrated circuit capable of maintaining an independent architectural state, wherein the independently maintained architectural states share access to execution resources. As can be seen, when certain resources are shared and others are dedicated to an architectural state, the line between the nomenclature of a hardware thread and core overlaps. Yet often, a core and a hardware thread are viewed by an operating system as individual logical processors, where the operating system is able to individually schedule operations on each logical processor.
0087Physical processor <b>800</b>, as illustrated in <figref idref="DRAWINGS">FIG. 8</figref>, includes two cores—core <b>801</b> and <b>802</b>. Here, core <b>801</b> and <b>802</b> are considered symmetric cores, i.e. cores with the same configurations, functional units, and/or logic. In another embodiment, core <b>801</b> includes an out-of-order processor core, while core <b>802</b> includes an in-order processor core. However, cores <b>801</b> and <b>802</b> may be individually selected from any type of core, such as a native core, a software managed core, a core adapted to execute a native Instruction Set Architecture (ISA), a core adapted to execute a translated Instruction Set Architecture (ISA), a co-designed core, or other known core. In a heterogeneous core environment (i.e. asymmetric cores), some form of translation, such a binary translation, may be utilized to schedule or execute code on one or both cores. Yet to further the discussion, the functional units illustrated in core <b>801</b> are described in further detail below, as the units in core <b>802</b> operate in a similar manner in the depicted embodiment.
0088As depicted, core <b>801</b> includes two hardware threads <b>801</b><i>a </i>and <b>801</b><i>b</i>, which may also be referred to as hardware thread slots <b>801</b><i>a </i>and <b>801</b><i>b</i>. Therefore, software entities, such as an operating system, in one embodiment potentially view processor <b>800</b> as four separate processors, i.e., four logical processors or processing elements capable of executing four software threads concurrently. As alluded to above, a first thread is associated with architecture state registers <b>801</b><i>a</i>, a second thread is associated with architecture state registers <b>801</b><i>b</i>, a third thread may be associated with architecture state registers <b>802</b><i>a</i>, and a fourth thread may be associated with architecture state registers <b>802</b><i>b</i>. Here, each of the architecture state registers (<b>801</b><i>a</i>, <b>801</b><i>b</i>, <b>802</b><i>a</i>, and <b>802</b><i>b</i>) may be referred to as processing elements, thread slots, or thread units, as described above. As illustrated, architecture state registers <b>801</b><i>a </i>are replicated in architecture state registers <b>801</b><i>b</i>, so individual architecture states/contexts are capable of being stored for logical processor <b>801</b><i>a </i>and logical processor <b>801</b><i>b</i>. In core <b>801</b>, other smaller resources, such as instruction pointers and renaming logic in allocator and renamer block <b>830</b> may also be replicated for threads <b>801</b><i>a </i>and <b>801</b><i>b</i>. Some resources, such as re-order buffers in reorder/retirement unit <b>835</b>, ILTB <b>820</b>, load/store buffers, and queues may be shared through partitioning. Other resources, such as general purpose internal registers, page-table base register(s), low-level data-cache and data-TLB <b>815</b>, execution unit(s) <b>840</b>, and portions of out-of-order unit <b>835</b> are potentially fully shared.
0089Processor <b>800</b> often includes other resources, which may be fully shared, shared through partitioning, or dedicated by/to processing elements. In <figref idref="DRAWINGS">FIG. 8</figref>, an embodiment of a purely exemplary processor with illustrative logical units/resources of a processor is illustrated. Note that a processor may include, or omit, any of these functional units, as well as include any other known functional units, logic, or firmware not depicted. As illustrated, core <b>801</b> includes a simplified, representative out-of-order (OOO) processor core. But an in-order processor may be utilized in different embodiments. The OOO core includes a branch target buffer <b>820</b> to predict branches to be executed/taken and an instruction-translation buffer (I-TLB) <b>820</b> to store address translation entries for instructions.
0090Core <b>801</b> further includes decode module <b>825</b> coupled to fetch unit <b>820</b> to decode fetched elements. Fetch logic, in one embodiment, includes individual sequencers associated with thread slots <b>801</b><i>a</i>, <b>801</b><i>b</i>, respectively. Usually core <b>801</b> is associated with a first ISA, which defines/specifies instructions executable on processor <b>800</b>. Often machine code instructions that are part of the first ISA include a portion of the instruction (referred to as an opcode), which references/specifies an instruction or operation to be performed. Decode logic <b>825</b> includes circuitry that recognizes these instructions from their opcodes and passes the decoded instructions on in the pipeline for processing as defined by the first ISA. For example, as discussed in more detail below decoders <b>825</b>, in one embodiment, include logic designed or adapted to recognize specific instructions, such as transactional instruction. As a result of the recognition by decoders <b>825</b>, the architecture or core <b>801</b> takes specific, predefined actions to perform tasks associated with the appropriate instruction. It is important to note that any of the tasks, blocks, operations, and methods described herein may be performed in response to a single or multiple instructions; some of which may be new or old instructions. Note decoders <b>826</b>, in one embodiment, recognize the same ISA (or a subset thereof). Alternatively, in a heterogeneous core environment, decoders <b>826</b> recognize a second ISA (either a subset of the first ISA or a distinct ISA).
0091In one example, allocator and renamer block <b>830</b> includes an allocator to reserve resources, such as register files to store instruction processing results. However, threads <b>801</b><i>a </i>and <b>801</b><i>b </i>are potentially capable of out-of-order execution, where allocator and renamer block <b>830</b> also reserves other resources, such as reorder buffers to track instruction results. Unit <b>830</b> may also include a register renamer to rename program/instruction reference registers to other registers internal to processor <b>800</b>. Reorder/retirement unit <b>835</b> includes components, such as the reorder buffers mentioned above, load buffers, and store buffers, to support out-of-order execution and later in-order retirement of instructions executed out-of-order.
0092Scheduler and execution unit(s) block <b>840</b>, in one embodiment, includes a scheduler unit to schedule instructions/operation on execution units. For example, a floating point instruction is scheduled on a port of an execution unit that has an available floating point execution unit. Register files associated with the execution units are also included to store information instruction processing results. Exemplary execution units include a floating point execution unit, an integer execution unit, a jump execution unit, a load execution unit, a store execution unit, and other known execution units.
0093Lower level data cache and data translation buffer (D-TLB) <b>850</b> are coupled to execution unit(s) <b>840</b>. The data cache is to store recently used/operated on elements, such as data operands, which are potentially held in memory coherency states. The D-TLB is to store recent virtual/linear to physical address translations. As a specific example, a processor may include a page table structure to break physical memory into a plurality of virtual pages.
0094Here, cores <b>801</b> and <b>802</b> share access to higher-level or further-out cache, such as a second level cache associated with on-chip interface <b>810</b>. Note that higher-level or further-out refers to cache levels increasing or getting further way from the execution unit(s). In one embodiment, higher-level cache is a last-level data cache—last cache in the memory hierarchy on processor <b>800</b>—such as a second or third level data cache. However, higher level cache is not so limited, as it may be associated with or include an instruction cache. A trace cache—a type of instruction cache—instead may be coupled after decoder <b>825</b> to store recently decoded traces. Here, an instruction potentially refers to a macro-instruction (i.e. a general instruction recognized by the decoders), which may decode into a number of micro-instructions (micro-operations).
0095In the depicted configuration, processor <b>800</b> also includes on-chip interface module <b>810</b>. Historically, a memory controller, which is described in more detail below, has been included in a computing system external to processor <b>800</b>. In this scenario, on-chip interface <b>810</b> is to communicate with devices external to processor <b>800</b>, such as system memory <b>875</b>, a chipset (often including a memory controller hub to connect to memory <b>875</b> and an I/O controller hub to connect peripheral devices), a memory controller hub, a northbridge, or other integrated circuit. And in this scenario, bus <b>805</b> may include any known interconnect, such as multi-drop bus, a point-to-point interconnect, a serial interconnect, a parallel bus, a coherent (e.g. cache coherent) bus, a layered protocol architecture, a differential bus, and a GTL bus.
0096Memory <b>875</b> may be dedicated to processor <b>800</b> or shared with other devices in a system. Common examples of types of memory <b>875</b> include DRAM, SRAM, non-volatile memory (NV memory), and other known storage devices. Note that device <b>880</b> may include a graphic accelerator, processor or card coupled to a memory controller hub, data storage coupled to an I/O controller hub, a wireless transceiver, a flash device, an audio controller, a network controller, or other known device.
0097Recently however, as more logic and devices are being integrated on a single die, such as SOC, each of these devices may be incorporated on processor <b>800</b>. For example in one embodiment, a memory controller hub is on the same package and/or die with processor <b>800</b>. Here, a portion of the core (an on-core portion) <b>810</b> includes one or more controller(s) for interfacing with other devices such as memory <b>875</b> or a graphics device <b>880</b>. The configuration including an interconnect and controllers for interfacing with such devices is often referred to as an on-core (or un-core configuration). As an example, on-chip interface <b>810</b> includes a ring interconnect for on-chip communication and a high-speed serial point-to-point link <b>805</b> for off-chip communication. Yet, in the SOC environment, even more devices, such as the network interface, co-processors, memory <b>875</b>, graphics processor <b>880</b>, and any other known computer devices/interface may be integrated on a single die or integrated circuit to provide small form factor with high functionality and low power consumption.
0098In one embodiment, processor <b>800</b> is capable of executing a compiler, optimization, and/or translator code <b>877</b> to compile, translate, and/or optimize application code <b>876</b> to support the apparatus and methods described herein or to interface therewith. A compiler often includes a program or set of programs to translate source text/code into target text/code. Usually, compilation of program/application code with a compiler is done in multiple phases and passes to transform hi-level programming language code into low-level machine or assembly language code. Yet, single pass compilers may still be utilized for simple compilation. A compiler may utilize any known compilation techniques and perform any known compiler operations, such as lexical analysis, preprocessing, parsing, semantic analysis, code generation, code transformation, and code optimization.
0099Larger compilers often include multiple phases, but most often these phases are included within two general phases: (1) a front-end, i.e. generally where syntactic processing, semantic processing, and some transformation/optimization may take place, and (2) a back-end, i.e. generally where analysis, transformations, optimizations, and code generation takes place. Some compilers refer to a middle, which illustrates the blurring of delineation between a front-end and back end of a compiler. As a result, reference to insertion, association, generation, or other operation of a compiler may take place in any of the aforementioned phases or passes, as well as any other known phases or passes of a compiler. As an illustrative example, a compiler potentially inserts operations, calls, functions, etc. in one or more phases of compilation, such as insertion of calls/operations in a front-end phase of compilation and then transformation of the calls/operations into lower-level code during a transformation phase. Note that during dynamic compilation, compiler code or dynamic optimization code may insert such operations/calls, as well as optimize the code for execution during runtime. As a specific illustrative example, binary code (already compiled code) may be dynamically optimized during runtime. Here, the program code may include the dynamic optimization code, the binary code, or a combination thereof.
0100Similar to a compiler, a translator, such as a binary translator, translates code either statically or dynamically to optimize and/or translate code. Therefore, reference to execution of code, application code, program code, or other software environment may refer to: (1) execution of a compiler program(s), optimization code optimizer, or translator either dynamically or statically, to compile program code, to maintain software structures, to perform other operations, to optimize code, or to translate code; (2) execution of main program code including operations/calls, such as application code that has been optimized/compiled; (3) execution of other program code, such as libraries, associated with the main program code to maintain software structures, to perform other software related operations, or to optimize code; or (4) a combination thereof.
0101Referring now to <figref idref="DRAWINGS">FIG. 9</figref>, shown is a block diagram of another system <b>900</b> in accordance with an embodiment of the present disclosure. As shown in <figref idref="DRAWINGS">FIG. 19</figref>, multiprocessor system <b>900</b> is a point-to-point interconnect system, and includes a first processor <b>970</b> and a second processor <b>980</b> coupled via a point-to-point interconnect <b>950</b>. Each of processors <b>970</b> and <b>980</b> may be some version of a processor. In one embodiment, <b>952</b> and <b>954</b> are part of a serial, point-to-point coherent interconnect fabric, such as a high-performance architecture. As a result, aspects of the present disclosure may be implemented within the QPI architecture.
0102While shown with only two processors <b>970</b>, <b>980</b>, it is to be understood that the scope of the present disclosure is not so limited. In other embodiments, one or more additional processors may be present in a given processor.
0103Processors <b>970</b> and <b>980</b> are shown including integrated memory controller units <b>972</b> and <b>982</b>, respectively. Processor <b>970</b> also includes as part of its bus controller units point-to-point (P-P) interfaces <b>976</b> and <b>978</b>; similarly, second processor <b>980</b> includes P-P interfaces <b>986</b> and <b>988</b>. Processors <b>970</b>, <b>980</b> may exchange information via a point-to-point (P-P) interface <b>950</b> using P-P interface circuits <b>978</b>, <b>988</b>. As shown in <figref idref="DRAWINGS">FIG. 19</figref>, IMCs <b>972</b> and <b>982</b> couple the processors to respective memories, namely a memory <b>932</b> and a memory <b>934</b>, which may be portions of main memory locally attached to the respective processors.
0104Processors <b>970</b>, <b>980</b> each exchange information with a chipset <b>990</b> via individual P-P interfaces <b>952</b>, <b>954</b> using point to point interface circuits <b>976</b>, <b>994</b>, <b>986</b>, <b>998</b>. Chipset <b>990</b> also exchanges information with a high-performance graphics circuit <b>938</b> via an interface circuit <b>992</b> along a high-performance graphics interconnect <b>939</b>.
0105A shared cache (not shown) may be included in either processor or outside of both processors; yet connected with the processors via P-P interconnect, such that either or both processors' local cache information may be stored in the shared cache if a processor is placed into a low power mode.
0106Chipset <b>990</b> may be coupled to a first bus <b>916</b> via an interface <b>996</b>. In one embodiment, first bus <b>916</b> may be a Peripheral Component Interconnect (PCI) bus, or a bus such as a PCI Express bus or another third generation I/O interconnect bus, although the scope of the present disclosure is not so limited.
0107As shown in <figref idref="DRAWINGS">FIG. 9</figref>, various I/O devices <b>914</b> are coupled to first bus <b>916</b>, along with a bus bridge <b>918</b> which couples first bus <b>916</b> to a second bus <b>920</b>. In one embodiment, second bus <b>920</b> includes a low pin count (LPC) bus. Various devices are coupled to second bus <b>920</b> including, for example, a keyboard and/or mouse <b>922</b>, communication devices <b>927</b> and a storage unit <b>928</b> such as a disk drive or other mass storage device which often includes instructions/code and data <b>930</b>, in one embodiment. Further, an audio I/O <b>924</b> is shown coupled to second bus <b>920</b>. Note that other architectures are possible, where the included components and interconnect architectures vary. For example, instead of the point-to-point architecture of <figref idref="DRAWINGS">FIG. 9</figref>, a system may implement a multi-drop bus or other such architecture.
0108While aspects of the present disclosure have been described with respect to a limited number of embodiments, those skilled in the art will appreciate numerous modifications and variations therefrom. It is intended that the appended claims cover all such modifications and variations as fall within the true spirit and scope of this present disclosure.
0109A design may go through various stages, from creation to simulation to fabrication. Data representing a design may represent the design in a number of manners. First, as is useful in simulations, the hardware may be represented using a hardware description language or another functional description language. Additionally, a circuit level model with logic and/or transistor gates may be produced at some stages of the design process. Furthermore, most designs, at some stage, reach a level of data representing the physical placement of various devices in the hardware model. In the case where conventional semiconductor fabrication techniques are used, the data representing the hardware model may be the data specifying the presence or absence of various features on different mask layers for masks used to produce the integrated circuit. In any representation of the design, the data may be stored in any form of a machine readable medium. A memory or a magnetic or optical storage such as a disc may be the machine readable medium to store information transmitted via optical or electrical wave modulated or otherwise generated to transmit such information. When an electrical carrier wave indicating or carrying the code or design is transmitted, to the extent that copying, buffering, or re-transmission of the electrical signal is performed, a new copy is made. Thus, a communication provider or a network provider may store on a tangible, machine-readable medium, at least temporarily, an article, such as information encoded into a carrier wave, embodying techniques of embodiments of the present disclosure.
0110A module as used herein refers to any combination of hardware, software, and/or firmware. As an example, a module includes hardware, such as a micro-controller, associated with a non-transitory medium to store code adapted to be executed by the micro-controller. Therefore, reference to a module, in one embodiment, refers to the hardware, which is specifically configured to recognize and/or execute the code to be held on a non-transitory medium. Furthermore, in another embodiment, use of a module refers to the non-transitory medium including the code, which is specifically adapted to be executed by the microcontroller to perform predetermined operations. And as can be inferred, in yet another embodiment, the term module (in this example) may refer to the combination of the microcontroller and the non-transitory medium. Often module boundaries that are illustrated as separate commonly vary and potentially overlap. For example, a first and a second module may share hardware, software, firmware, or a combination thereof, while potentially retaining some independent hardware, software, or firmware. In one embodiment, use of the term logic includes hardware, such as transistors, registers, or other hardware, such as programmable logic devices.
0111Use of the phrase ‘configured to,’ in one embodiment, refers to arranging, putting together, manufacturing, offering to sell, importing and/or designing an apparatus, hardware, logic, or element to perform a designated or determined task. In this example, an apparatus or element thereof that is not operating is still ‘configured to’ perform a designated task if it is designed, coupled, and/or interconnected to perform said designated task. As a purely illustrative example, a logic gate may provide a 0 or a 1 during operation. But a logic gate ‘configured to’ provide an enable signal to a clock does not include every potential logic gate that may provide a 1 or 0. Instead, the logic gate is one coupled in some manner that during operation the 1 or 0 output is to enable the clock. Note once again that use of the term ‘configured to’ does not require operation, but instead focus on the latent state of an apparatus, hardware, and/or element, where in the latent state the apparatus, hardware, and/or element is designed to perform a particular task when the apparatus, hardware, and/or element is operating.
0112Furthermore, use of the phrases ‘to,’ ‘capable of/to,’ and or ‘operable to,’ in one embodiment, refers to some apparatus, logic, hardware, and/or element designed in such a way to enable use of the apparatus, logic, hardware, and/or element in a specified manner. Note as above that use of to, capable to, or operable to, in one embodiment, refers to the latent state of an apparatus, logic, hardware, and/or element, where the apparatus, logic, hardware, and/or element is not operating but is designed in such a manner to enable use of an apparatus in a specified manner.
0113A value, as used herein, includes any known representation of a number, a state, a logical state, or a binary logical state. Often, the use of logic levels, logic values, or logical values is also referred to as 1 's and 0's, which simply represents binary logic states. For example, a 1 refers to a high logic level and 0 refers to a low logic level. In one embodiment, a storage cell, such as a transistor or flash cell, may be capable of holding a single logical value or multiple logical values. However, other representations of values in computer systems have been used. For example the decimal number ten may also be represented as a binary value of 1010 and a hexadecimal letter A. Therefore, a value includes any representation of information capable of being held in a computer system.
0114Moreover, states may be represented by values or portions of values. As an example, a first value, such as a logical one, may represent a default or initial state, while a second value, such as a logical zero, may represent a non-default state. In addition, the terms reset and set, in one embodiment, refer to a default and an updated value or state, respectively. For example, a default value potentially includes a high logical value, i.e. reset, while an updated value potentially includes a low logical value, i.e. set. Note that any combination of values may be utilized to represent any number of states.
0115The embodiments of methods, hardware, software, firmware or code set forth above may be implemented via instructions or code stored on a machine-accessible, machine readable, computer accessible, or computer readable medium which are executable by a processing element. A non-transitory machine-accessible/readable medium includes any mechanism that provides (i.e., stores and/or transmits) information in a form readable by a machine, such as a computer or electronic system. For example, a non-transitory machine-accessible medium includes random-access memory (RAM), such as static RAM (SRAM) or dynamic RAM (DRAM); ROM; magnetic or optical storage medium; flash memory devices; electrical storage devices; optical storage devices; acoustical storage devices; other form of storage devices for holding information received from transitory (propagated) signals (e.g., carrier waves, infrared signals, digital signals); etc., which are to be distinguished from the non-transitory mediums that may receive information there from.
0116Instructions used to program logic to perform embodiments of the present disclosure may be stored within a memory in the system, such as DRAM, cache, flash memory, or other storage. Furthermore, the instructions can be distributed via a network or by way of other computer readable media. Thus a machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), but is not limited to, floppy diskettes, optical disks, Compact Disc, Read-Only Memory (CD-ROMs), and magneto-optical disks, Read-Only Memory (ROMs), Random Access Memory (RAM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), magnetic or optical cards, flash memory, or a tangible, machine-readable storage used in the transmission of information over the Internet via electrical, optical, acoustical or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Accordingly, the computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).
Examples
0117Illustrative examples of the technologies disclosed herein are provided below. An embodiment of the technologies may include any one or more, and any combination of, the examples described below.
0118Example 1 includes an apparatus comprising point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link; determine an updated encryption key; transmit a key switch message to the processor to instruct the processor to use the updated encryption key; and perform, after transmission of the key switch message and without sending encrypted messages on at least one channel corresponding to the updated encryption key over the point-to-point link, one or more stages of a pipeline of the cryptographic engine to encrypt messages with the updated encryption key.
0119Example 2 includes the subject matter of Example 1, and wherein the point-to-point interface circuitry is further to transmit a key update message to the processor to instruct the processor to prepare to use the updated encryption key; and receive a key update confirmation message from the processor indicating that the processor is prepared to use the updated encryption key, wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the processor.
0120Example 3 includes the subject matter of any of Examples 1 and 2, and wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time.
0121Example 4 includes the subject matter of any of Examples 1-3, and wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein the first encryption key is associated with the first channel, wherein the point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.
0122Example 5 includes the subject matter of any of Examples 1-4, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.
0123Example 6 includes the subject matter of any of Examples 1-5, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of time since the first encryption key was first used.
0124Example 7 includes the subject matter of any of Examples 1-6, and wherein to establish the encrypted point-to-point link comprises to establish a transmit link to transmit messages to the processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and establish a receive link to receive messages from the processor with use of a first receive encryption key, wherein the point-to-point interface circuitry is further to decrypt messages received from the processor in the cryptographic engine with use of the first receive encryption key and with use of a receive pipeline of the cryptographic engine; determine an updated receive encryption key; receive, from the processor, a key switch message to instruct the apparatus to use the updated receive encryption key; and clear, in response to the key switch message, the receive pipeline of the encrypted engine with use of the first receive encryption key; and switch the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key.
0125Example 8 includes the subject matter of any of Examples 1-7, and wherein to determine the updated receive encryption key comprises to determine the updated receive encryption key based on communication with the processor.
0126Example 9 includes the subject matter of any of Examples 1-8, and wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with integrity protection with use of Advanced Encryption Standard-Galois/Counter Mode (AES-GCM).
0127Example 10 includes the subject matter of any of Examples 1-9, and wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with use of Advanced Encryption Standard in Counter mode (AES-CTR) and an integrity key to integrity protect messages with use of AES-Galois message authentication code (AES-GMAC).
0128Example 11 includes an apparatus comprising point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link; determine an updated encryption key; transmit a key switch message to the processor to instruct the processor to use the updated encryption key; and transmit, after transmission of the key switch message and without a reset of the encrypted point-to-point link, encrypted messages with use of the updated encryption key.
0129Example 12 includes the subject matter of Example 11, and wherein the point-to-point interface circuitry is further to transmit a key update message to the processor to instruct the processor to prepare to use the updated encryption key; and receive a key update confirmation message from the processor indicating that the processor is prepared to use the updated encryption key, wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the processor.
0130Example 13 includes the subject matter of any of Examples 11 and 12, and wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time.
0131Example 14 includes the subject matter of any of Examples 11-13, and wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein the first encryption key is associated with the first channel, wherein the point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.
0132Example 15 includes the subject matter of any of Examples 11-14, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.
0133Example 16 includes the subject matter of any of Examples 11-15, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of time since the first encryption key was first used.
0134Example 17 includes the subject matter of any of Examples 11-16, and wherein to establish the encrypted point-to-point link comprises to establish a transmit link to transmit messages to the processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and establish a receive link to receive messages from the processor with use of a first receive encryption key, wherein the point-to-point interface circuitry is further to decrypt messages received from the processor in the cryptographic engine with use of the first receive encryption key and with use of a pipeline of the cryptographic engine; determine an updated receive encryption key; receive, from the processor, a key switch message to instruct the apparatus to use the updated receive encryption key; and clear, in response to the key switch message, the pipeline of the encrypted engine with use of the first receive encryption key; and switch the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key.
0135Example 18 includes the subject matter of any of Examples 11-17, and wherein to determine the updated receive encryption key comprises to determine the updated receive encryption key based on communication with the processor.
0136Example 19 includes the subject matter of any of Examples 11-18, and wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with integrity protection with use of Advanced Encryption Standard-Galois/Counter Mode (AES-GCM).
0137Example 20 includes the subject matter of any of Examples 11-19, and wherein the encrypted point-to-point link is to use the first encryption key to encrypt messages with use of Advanced Encryption Standard in Counter mode (AES-CTR) and an integrity key to integrity protect messages with use of AES-Galois message authentication code (AES-GMAC).
0138Example 21 includes a system comprising a plurality of processors comprising a first processor and a second processor, wherein the first processor comprises first point-to-point interface circuitry and the second processor comprises second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to establish an encrypted point-to-point link with the second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to use a first encryption key to encrypt messages for the encrypted point-to-point link; determine an updated encryption key; and transmit a key switch message to the second processor to instruct the second processor to use the updated encryption key, wherein the second point-to-point interface circuitry is to receive, from the first processor, the key switch message to instruct the second processor to use the updated encryption key; and clear, in response to the key switch message, a pipeline of a cryptographic engine of the second point-to-point interface circuitry with use of the first encryption key; and switch, in response to the key switch message, the cryptographic engine to use the updated encryption key in place of the first encryption key.
0139Example 22 includes the subject matter of Example 21, and wherein the point-to-point interface circuitry is further to transmit a key update message to the second processor to instruct the second processor to prepare to use the updated encryption key; and receive a key update confirmation message from the second processor indicating that the second processor is prepared to use the updated encryption key, wherein to transmit the key switch message comprises to transmit the key switch message in response to receipt of the key update confirmation message from the second processor.
0140Example 23 includes the subject matter of any of Examples 21 and 22, and wherein transmission of encrypted messages by the first point-to-point interface circuitry is to be paused after transmission of the key switch message.
0141Example 24 includes the subject matter of any of Examples 21-23, and wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein the first encryption key is associated with the first channel, wherein the first point-to-point interface circuitry is to pause transmission of encrypted messages of the first channel and continue transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.
0142Example 25 includes the subject matter of any of Examples 21-24, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of data transferred with use of the first encryption key.
0143Example 26 includes the subject matter of any of Examples 21-25, and wherein to transmit the key switch message comprises to transmit the key switch message based on an amount of time since the first encryption key was first used.
0144Example 27 includes a method comprising establishing, by a processor, an encrypted point-to-point link with a second processor, wherein the encrypted point-to-point link is to use a first encryption key to encrypt messages; determining that the first encryption key should be updated; determining an updated encryption key; transmitting, by the processor, a key switch message to the second processor to instruct the second processor to use the updated encryption key; and performing, after transmission of the key switch message and without sending encrypted messages on at least one channel corresponding to the updated encryption key over the point-to-point link, one or more stages of a pipeline of the cryptographic engine to encrypt messages with the updated encryption key.
0145Example 28 includes the subject matter of Example 27, and further including transmitting, by the processor, a key update message to the second processor to instruct the second processor to prepare to use the updated encryption key; and receiving, by the processor, a key update confirmation message from the second processor indicating that the second processor is prepared to use the updated encryption key, wherein transmitting the key switch message comprises transmitting the key switch message in response to receipt of the key update confirmation message from the second processor.
0146Example 29 includes the subject matter of any of Examples 27 and 28, and wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time.
0147Example 30 includes the subject matter of any of Examples 27-29, and wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein the first encryption key is associated with the first channel, further comprising pausing transmission of encrypted messages of the first channel and continuing transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.
0148Example 31 includes the subject matter of any of Examples 27-30, and wherein determining that the first encryption key should be updated comprises determining that the first encryption key should be updated based on an amount of data transferred with use of the first encryption key.
0149Example 32 includes the subject matter of any of Examples 27-31, and wherein determining that the first encryption key should be updated comprises determining that the first encryption key should be updated based on an amount of time since the first encryption key was first used.
0150Example 33 includes the subject matter of any of Examples 27-32, and wherein establishing the encrypted point-to-point link comprises establishing a transmit link to transmit messages to the second processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and establishing a receive link to receive messages from the second processor with use of a first receive encryption key, the method further comprising decrypting, by the processor, messages received from the second processor in a cryptographic engine with use of the first receive encryption key and with use of a pipeline of the cryptographic engine; determining, by the processor, an updated receive encryption key; receiving, by the processor and from the second processor, a key switch message to instruct the processor to use the updated receive encryption key; and clearing, by the processor and in response to the key switch message, the pipeline of the encrypted engine with use of the first receive encryption key; and switching, by the processor, the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key.
0151Example 34 includes the subject matter of any of Examples 27-33, and wherein determining the updated receive encryption key comprises determining the updated receive encryption key based on communication with the second processor.
0152Example 35 includes one or more computer-readable media comprising a plurality of instructions stored thereon that, when executed, causes a processor to perform the method of any of Examples 19-26.
0153Example 36 includes an apparatus comprising means to perform the method of any of Examples 19-26.
0154Example 37 includes an apparatus comprising means for establishing an encrypted point-to-point link with a processor, wherein the encrypted point-to-point link is to use a first encryption key to encrypt messages; means for determining that the first encryption key should be updated; means for determining an updated encryption key; means for transmitting a key switch message to the processor to instruct the processor to use the updated encryption key; and means for performing, after transmission of the key switch message and without sending encrypted messages on at least one channel corresponding to the updated encryption key over the point-to-point link, one or more stages of a pipeline of the cryptographic engine to encrypt messages with the updated encryption key.
0155Example 38 includes the subject matter of Example 37, and further including means for transmitting a key update message to the processor to instruct the processor to prepare to use the updated encryption key; and means for receiving a key update confirmation message from the processor indicating that the processor is prepared to use the updated encryption key, wherein the means for transmitting the key switch message comprises means for transmitting the key switch message in response to receipt of the key update confirmation message from the processor.
0156Example 39 includes the subject matter of any of Examples 37 and 38, and wherein transmission of encrypted messages is to be paused after transmission of the key switch message for a predetermined amount of time.
0157Example 40 includes the subject matter of any of Examples 37-39, and wherein the encrypted point-to-point link comprises a plurality of channels, wherein the plurality of channels comprises a first channel and a second channel, wherein the first encryption key is associated with the first channel, further comprising means for pausing transmission of encrypted messages of the first channel and means for continuing transmission of encrypted messages of the second channel for a predetermined amount of time after transmission of the key switch message.
0158Example 41 includes the subject matter of any of Examples 37-40, and wherein the means for determining that the first encryption key should be updated comprises means for determining that the first encryption key should be updated based on an amount of data transferred with use of the first encryption key.
0159Example 42 includes the subject matter of any of Examples 37-41, and wherein the means for determining that the first encryption key should be updated comprises means for determining that the first encryption key should be updated based on an amount of time since the first encryption key was first used.
0160Example 43 includes the subject matter of any of Examples 37-42, and wherein the means for establishing the encrypted point-to-point link comprises means for establishing a transmit link to transmit messages to the processor with use of a first transmit encryption key, wherein the first encryption key is the first transmit encryption key; and means for establishing a receive link to receive messages from the processor with use of a first receive encryption key, the apparatus further comprising means for decrypting messages received from the processor in a cryptographic engine with use of the first receive encryption key and with use of a pipeline of the cryptographic engine; means for determining an updated receive encryption key; means for receiving, from the processor, a key switch message to instruct the apparatus to use the updated receive encryption key; and means for clearing, in response to the key switch message, the pipeline of the encrypted engine with use of the first receive encryption key; and means for switching the cryptographic engine to use the updated receive encryption key in place of the first receive encryption key.
0161Example 44 includes the subject matter of any of Examples 37-43, and wherein the means for determining the updated receive encryption key comprises means for determining the updated receive encryption key based on communication with the processor.
Contents3
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US12332289B2 | Cited by | United States of America | Applicant |
| US2023214475A1 | Cited by | United States of America | Search report |
| US12160510B2 | Cited by | United States of America | Applicant |
| US2024015009A1 | Cited by | United States of America | Search report |
| US2023224154A1 | Cited by | United States of America | Search report |
| US2023188336A1 | Cited by | United States of America | Search report |
| EP4445546A4 | Cited by | European Patent Office (EPO) | Search report |
| US11265301B1 | Cites | United States of America | Search report |
| US11582195B1 | Cites | United States of America | Search report |
| US2010151822A1 | Cites | United States of America | Search report |
| US2011055558A1 | Cites | United States of America | Search report |
| US2015156181A1 | Cites | United States of America | Search report |
| US2016249210A1 | Cites | United States of America | Search report |
| US2017272408A1 | Cites | United States of America | Search report |
| US2019220721A1 | Cites | United States of America | Search report |
| US2019288842A1 | Cites | United States of America | Search report |
| US2020245401A1 | Cites | United States of America | Search report |
| US2021075587A1 | Cites | United States of America | Search report |
| US6957329B1 | Cites | United States of America | Search report |
| US7818563B1 | Cites | United States of America | Search report |
2 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 202117213465 | United States of America | A | |
| US202117213465 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2021218548A1 | United States of America | A1 | |
| DE102022101490A1 | Germany | A1 |
66 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Patent eGrant NotificationMEPG_NTF | MEPG_NTF | |
| Patent eGrant NotificationEPG_NTF | EPG_NTF | |
| Recordation of Patent eGrantEPG/ | EPG/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Response to Reasons for AllowanceREAS | REAS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Interview Summary RecordEXIN | EXIN | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Electronic request for Examiner InterviewM865E | M865E | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| to Close the A/R Record and Reset the Status for Expired Suspensions.EOSP | EOSP | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Letter Suspending Prosecution at Applicant's RequestMAISP | MAISP | |
| Suspension Letter- Applicant InitiatedAISP | AISP | |
| Letter Requesting Suspension of ProsecutionM856 | M856 | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| PGPubs early publication requestEPRQ | EPRQ | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
2 recorded assignments at the USPTO, latest first
- Now
Now: Held by
INTEL CORP - 2023-06-07
Corrective assignment to correct the filing date of the application previously recorded on reel 055733 frame 0455. assignor(s) hereby confirms the assignment.
- From
- ABRAHAM, VINIT MATHEWYAP, KIRK S.MAKARAM, RAGHUNANDAN
and 2 moreShow fewer
GADEY, SIVA PRASADKAR, TANMOY - To
- INTEL CORPORATION
Recorded 2023-06-07, Signed 2021-02-07
- 2021-03-26
Assignment of assignors interest.
Ownership change- From
- ABRAHAM, VINIT MATHEWYAP, KIRK S.MAKARAM, RAGHUNANDAN
and 2 moreShow fewer
GADEY, SIVA PRASADKAR, TANMOY - To
- INTEL CORPORATION
Recorded 2021-03-26, Signed 2021-02-07
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT RECEIVEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| AssignmentAS | AS | |
| Information on status: administrative procedure adjustmentPROSECUTION SUSPENDEDSTCT | STCT | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| Information on status: patent application and granting procedure in generalAPPLICATION DISPATCHED FROM PREEXAM, NOT YET DOCKETEDSTPP | STPP | |
| AssignmentAS | AS | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP |
Numbers
- Publication
- 20210218548
- Publication, DOCDB
- 2021218548
- Publication, EPODOC
- US2021218548
- Application
- 17213465
- Application, DOCDB
- 202117213465
- Application, EPODOC
- US202117213465
Titles
- English
- TECHNOLOGIES FOR REAL-TIME UPDATING OF ENCRYPTION KEYS
Patent term adjustment
- A delay
- +727 daysthe office missed an examination deadline
- B delay
- +364 dayspendency past three years
- Overlap
- −56 daysdelays counted once
- Applicant delay
- −244 days
- Net adjustment
- 791 days
Classification
- CPC, 11
- H04L9/0631
- H04L9/0841
- H04L9/0643
- H04L9/0891
- H04L9/0872
- H04L9/16
- H04L9/0637
- H04L9/3242
- H04L63/0428
- H04L63/061
- H04L63/068
- IPC, 2
- H04L9 06
- H04L9 08