US20210218548A1

Technologies for real-time updating of encryption keys

Claim Score by NHIP

Read claim 16, the broadest

Abstract

Techniques for real-time updating of encryption keys are disclosed. In the illustrative embodiment, an encrypted link is established between a local and remote processor over a point-to-point interconnect. The encrypted link is operated for some time until the encryption key should be updated. The local processor sends a key update message to the remote processor notifying the remote processor of the change. The remote processor prepares for the change and sends a key update confirmation message to the local processor. The local processor then sends a key switch message to the remote processor. The local processor pauses transmission of encrypted message while the remote processor completes use of the encrypted message. After a pause, the local processor continues sending encrypted messages with the updated encryption key.

US20210218548A1, drawing sheet 1
Sheet 1 of 11

Term

16.7 yearsto projected expiry

Projected expiry 26 May 2043, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

25 claims: 3 independent, 22 dependent

  1. 1
    An apparatus comprising:point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to: establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;determine an updated encryption key;transmit a key switch message to the processor to instruct the processor to use the updated encryption key;and perform, after transmission of the key switch message and without sending encrypted messages on at least one channel corresponding to the updated encryption key over the point-to-point link, one or more stages of a pipeline of the cryptographic engine to encrypt messages with the updated encryption key.
  2. 11
    A system comprising:a plurality of processors comprising a first processor and a second processor, wherein the first processor comprises first point-to-point interface circuitry and the second processor comprises second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to: establish an encrypted point-to-point link with the second point-to-point interface circuitry, wherein the first point-to-point interface circuitry is to use a first encryption key to encrypt messages for the encrypted point-to-point link;determine an updated encryption key;and transmit a key switch message to the second processor to instruct the second processor to use the updated encryption key, wherein the second point-to-point interface circuitry is to: receive, from the first processor, the key switch message to instruct the second processor to use the updated encryption key;and clear, in response to the key switch message, a pipeline of a cryptographic engine of the second point-to-point interface circuitry with use of the first encryption key;and switch, in response to the key switch message, the cryptographic engine to use the updated encryption key in place of the first encryption key.
  3. 16
    Broadest claimClaim Score 69, broad(NHIP)An apparatus comprising:point-to-point interface circuitry comprising a cryptographic engine, the point-to-point interface circuitry to: establish an encrypted point-to-point link with a processor, wherein the point-to-point interface circuitry is to use a first encryption key to encrypt messages in the cryptographic engine for the encrypted point-to-point link;determine an updated encryption key;transmit a key switch message to the processor to instruct the processor to use the updated encryption key;and transmit, after transmission of the key switch message and without a reset of the encrypted point-to-point link, encrypted messages with use of the updated encryption key.