《6520 - An Update on OCP L.O.C.K..pdf》由会员分享,可在线阅读,更多相关《6520 - An Update on OCP L.O.C.K..pdf(21页珍藏版)》请在三个皮匠报告上搜索。
1、An Update on OCP L.O.C.K.LayeredOpen-sourceCryptographicKey-managementJeff Andersen,GoogleEric Eilertson,MicrosoftAn Update on OCP L.O.C.K.Room for improvement in storage securityAuditing of cryptographic purgeData access authorization modelDrive encryption implementation qualityA project to deliver
2、 an open implementation at CHIPS Alliance,coupled with new storage APIs defined at TCG(Trusted Computing Group)Scoped specifically to storage devicesProvides key management services to the drive and host,utilizing services from CaliptraOCP L.O.C.K.L.O.C.K.LayeredOpen-sourceCryptographicKey-managemen
3、tStandard interface for media key programmingStandard interface for media key programmingKMB:Key Management BlockAES crypto engineStorage controller firmwareAES engine interface(new)Lets KMB securely communicate media keysto the crypto engine,without exposing to firmwareAES crypto engineMetadata_1Au
4、x_1MEK_1Metadata_2Aux_2MEK_2Metadata_nAux_nMEK_nStandard interface for media key programmingKey cacheKMBSet metadata,aux,MEKDoneRemove metadataDoneMEK=media encryption keyData I/OAES crypto engineMetadata_1Aux_1MEK_1Metadata_2Aux_2MEK_2Metadata_nAux_nMEK_nStandard interface for media key programming
5、Key cacheRegisterAddressByte sizeControlSFR_BASE+0h4hMetadata(i.e.NSID+LBA range)SFR_BASE+10h14hAux(i.e.operational mode)SFR_BASE+30h20hMEKSFR_BASE+50h40hMEK=media encryption keyAccess control in TCG OpalAccess control in TCG OpalRecall:TCG Opal supports default or single-user modeUser PINAdmin PINO
6、RDefault caseUser PINSingle-User ModeUser 1User 2User 1 PINUser 2 PINAccess control in TCG OpalUser 1User 2User 1 PINUser 2 PINKey Management ServiceWe would like media keys to be gated by an access key held by the platform.Customer VMPlatform firmwareHost OSTPMAccess control in TCG OpalUser 1User 2