US2023071723A1PendingUtilityA1

Technologies for establishing secure channel between i/o subsystem and trusted application for secure i/o data transfer

Assignee: INTEL CORPPriority: Mar 29, 2019Filed: Nov 2, 2022Published: Mar 9, 2023
Est. expiryMar 29, 2039(~12.7 yrs left)· nominal 20-yr term from priority
H04L 9/083G06F 21/606G06F 13/20G06F 21/575H04L 63/0428G06F 21/82H04L 67/34H04L 2209/127
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Technologies for secure I/O data transfer includes a compute device, which includes a processor to execute a trusted application, an input/output (I/O) device, and an I/O subsystem. The I/O subsystem is configured to establish a secured channel between the I/O subsystem and a trusted application running on the compute device, and receive, in response to an establishment of the secured channel, I/O data from the I/O device via an unsecured channel. The I/O subsystem is further configured to encrypt, in response to a receipt of the I/O data, the I/O data using a security key associated with the trusted application that is to process the I/O data and transmit the encrypted I/O data to the trusted application via the secured channel, wherein the secured channel has a data transfer rate that is higher than a data transfer rate of the unsecured channel between the I/O device and the I/O subsystem.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computing device comprising:
 a processor to execute a trusted application;   an input/output (I/O) subsystem circuitry coupled to the processors, the I/O subsystem circuitry to:
 receive a security key shared with the trusted application running at the computing device; 
 receive encrypted configuration data from the trusted application via an established secured channel relating to the trusted application; 
 decrypt the encrypted configuration data; and 
 configure the established secured channel based on the decrypted configuration data. 
   
     
     
         2 . The computing device of  claim 1 , wherein the I/O subsystem circuitry is further to receive encrypted packet defining initialization parameters for I/O data transferred from an I/O device. 
     
     
         3 . The computing device of  claim 1 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device. 
     
     
         4 . The computing device of  claim 1 , wherein the I/O subsystem circuitry is further to configure the secure channel upon power reset. 
     
     
         5 . The computing device of  claim 1 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry. 
     
     
         6 . A method comprising:
 receiving, by an input/output (I/O) subsystem circuitry, a security key shared with the trusted application running at a computing device;   receiving, by the I/O subsystem circuitry, encrypted configuration data from the trusted application via an established secured channel relating to the trusted application;   decrypting, by the I/O subsystem circuitry, the encrypted configuration data; and   configuring, by the I/O subsystem circuitry, the established secured channel based on the decrypted configuration data.   
     
     
         7 . The method of  claim 6 , further comprising receiving, by the I/O subsystem circuitry, encrypted packet defining initialization parameters for I/O data transferred from an I/O device. 
     
     
         8 . The method of  claim 6 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device. 
     
     
         9 . The method of  claim 6 , further comprising configuring, by the I/O subsystem circuitry, the secure channel upon power reset. 
     
     
         10 . The method of  claim 6 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry. 
     
     
         11 . At least one computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:
 receiving, by an input/output (I/O) subsystem circuitry, a security key shared with the trusted application running at the computing device;   receiving, by the I/O subsystem circuitry, encrypted configuration data from the trusted application via an established secured channel relating to the trusted application;   decrypting, by the I/O subsystem circuitry, the encrypted configuration data; and   configuring, by the I/O subsystem circuitry, the established secured channel based on the decrypted configuration data.   
     
     
         12 . The computer-readable medium of  claim 11 , wherein the operations further comprise receiving, by the I/O subsystem circuitry, encrypted packet defining initialization parameters for I/O data transferred from an I/O device. 
     
     
         13 . The computer-readable medium of  claim 11 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device. 
     
     
         14 . The computer-readable medium of  claim 11 , wherein the operations further comprise configuring, by the I/O subsystem circuitry, the secure channel upon power reset. 
     
     
         15 . The computer-readable medium of  claim 11 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry.

Join the waitlist — get patent alerts

Track US2023071723A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.