Technologies for establishing secure channel between i/o subsystem and trusted application for secure i/o data transfer
Abstract
Technologies for secure I/O data transfer includes a compute device, which includes a processor to execute a trusted application, an input/output (I/O) device, and an I/O subsystem. The I/O subsystem is configured to establish a secured channel between the I/O subsystem and a trusted application running on the compute device, and receive, in response to an establishment of the secured channel, I/O data from the I/O device via an unsecured channel. The I/O subsystem is further configured to encrypt, in response to a receipt of the I/O data, the I/O data using a security key associated with the trusted application that is to process the I/O data and transmit the encrypted I/O data to the trusted application via the secured channel, wherein the secured channel has a data transfer rate that is higher than a data transfer rate of the unsecured channel between the I/O device and the I/O subsystem.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computing device comprising:
a processor to execute a trusted application; an input/output (I/O) subsystem circuitry coupled to the processors, the I/O subsystem circuitry to:
receive a security key shared with the trusted application running at the computing device;
receive encrypted configuration data from the trusted application via an established secured channel relating to the trusted application;
decrypt the encrypted configuration data; and
configure the established secured channel based on the decrypted configuration data.
2 . The computing device of claim 1 , wherein the I/O subsystem circuitry is further to receive encrypted packet defining initialization parameters for I/O data transferred from an I/O device.
3 . The computing device of claim 1 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device.
4 . The computing device of claim 1 , wherein the I/O subsystem circuitry is further to configure the secure channel upon power reset.
5 . The computing device of claim 1 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry.
6 . A method comprising:
receiving, by an input/output (I/O) subsystem circuitry, a security key shared with the trusted application running at a computing device; receiving, by the I/O subsystem circuitry, encrypted configuration data from the trusted application via an established secured channel relating to the trusted application; decrypting, by the I/O subsystem circuitry, the encrypted configuration data; and configuring, by the I/O subsystem circuitry, the established secured channel based on the decrypted configuration data.
7 . The method of claim 6 , further comprising receiving, by the I/O subsystem circuitry, encrypted packet defining initialization parameters for I/O data transferred from an I/O device.
8 . The method of claim 6 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device.
9 . The method of claim 6 , further comprising configuring, by the I/O subsystem circuitry, the secure channel upon power reset.
10 . The method of claim 6 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry.
11 . At least one computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:
receiving, by an input/output (I/O) subsystem circuitry, a security key shared with the trusted application running at the computing device; receiving, by the I/O subsystem circuitry, encrypted configuration data from the trusted application via an established secured channel relating to the trusted application; decrypting, by the I/O subsystem circuitry, the encrypted configuration data; and configuring, by the I/O subsystem circuitry, the established secured channel based on the decrypted configuration data.
12 . The computer-readable medium of claim 11 , wherein the operations further comprise receiving, by the I/O subsystem circuitry, encrypted packet defining initialization parameters for I/O data transferred from an I/O device.
13 . The computer-readable medium of claim 11 , wherein the initialization parameters include one or more of a packet size, a header size, a header format, or control information relating to the I/O data transfer from the I/O device, wherein the initialization parameters are not shared with the I/O device.
14 . The computer-readable medium of claim 11 , wherein the operations further comprise configuring, by the I/O subsystem circuitry, the secure channel upon power reset.
15 . The computer-readable medium of claim 11 , wherein the secure channel is established between the I/O subsystem circuitry and the trusted application, and wherein the I/O subsystem circuitry hosts imposer security circuitry.Join the waitlist — get patent alerts
Track US2023071723A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.