首页> 外国专利> CO-EXISTENCE OF TRUST DOMAIN ARCHITECTURE WITH MULTI-KEY TOTAL MEMORY ENCRYPTION TECHNOLOGY IN SERVERS

CO-EXISTENCE OF TRUST DOMAIN ARCHITECTURE WITH MULTI-KEY TOTAL MEMORY ENCRYPTION TECHNOLOGY IN SERVERS

机译:服务器中信任域架构与多密钥总内存加密技术的共存

摘要

Implementations described provide hardware support for the co-existence of restricted and non-restricted encryption keys on a computing system. Such hardware support may comprise a processor having a core, a hardware register to store a bit range to identify a number of bits, of physical memory addresses, that define key identifiers (IDs) and a partition key ID identifying a boundary between non-restricted and restricted key IDs. The core may allocate at least one of the non-restricted key IDs to a software program, such as a hypervisor. The core may further allocate a restricted key ID to a trust domain whose trust computing base does not comprise the software program. A memory controller coupled to the core may allocate a physical page of a memory to the trust domain, wherein data of the physical page of the memory is to be encrypted with an encryption key associated with the restricted key ID.
机译:所描述的实施方式为计算系统上受限和非受限加密密钥的共存提供了硬件支持。这样的硬件支持可以包括具有核心的处理器,用于存储位范围以标识物理存储器地址的位范围的硬件寄存器,所述物理存储器地址定义了密钥标识符(ID)和分区密钥ID,该分区密钥ID标识了非受限之间的边界。和受限制的密钥ID。核心可以将非受限密钥ID中的至少一个分配给软件程序,例如系统管理程序。核心可以进一步将受限密钥ID分配给其信任计算基础不包括软件程序的信任域。耦合到核心的存储器控​​制器可以将存储器的物理页面分配给信任域,其中存储器的物理页面的数据将用与受限密钥ID相关联的加密密钥来加密。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号