Memory devices and systems with security capabilities
Abstract
Several embodiments of systems incorporating memory devices are disclosed herein. In one embodiment, a memory device can include a controller, a main memory operably coupled to the controller, and security hardware operably coupled to the controller and to the main memory. The main memory can include a plurality of memory regions and at least one reserved memory region configured to store genuine backups of memory content stored in the plurality of memory regions. In operation, the security hardware is configured to measure memory content of the plurality of memory regions before startup, shutdown, and reset of the memory device; compare the measured value to an expected value; and direct the controller to replace the memory content with a genuine backup of the memory content stored in the at least one reserved memory region if the measured value and the expected value are not in accord.
Claims
exact text as granted — not AI-modifiedI/We claim:
1 . A memory device comprising:
a controller; a main memory operably coupled to the controller, the main memory having one or more user memory regions and at least one reserved memory region; and security hardware operably coupled to the controller and to the main memory, the security hardware configured to
measure memory content stored in the one or more user memory regions to obtain a measured value,
compare the measured value to an expected value,
based on the comparison, determine that the measured value and the expected value are not in accord, and
based on the determination, initiate a replacement of the memory content stored in the one or more user memory regions with a genuine backup of the memory content stored in the at least one reserved memory region.
2 . The memory device of claim 1 , wherein the controller is configured to prevent access to the main memory at least until the measured value is obtained.
3 . The memory device of claim 1 , wherein the security hardware is further configured to flag the memory device as untrustworthy based on the determination.
4 . The memory device of claim 1 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before initiating a replacement of the memory content with the genuine backup of the memory content based on the determination, the security hardware is further configured to:
measure the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value; compare the second measured value to a second expected value; and replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.
5 . The memory device of claim 4 , wherein the first expected value and the second expected value are equivalent.
6 . The memory device of claim 4 , wherein the security hardware is further configured to
based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are not in accord; and based on the determination that the second measured value and the second expected value are not in accord, direct the memory device to enter a safe mode and/or send a warning message.
7 . The memory device of claim 4 , wherein the security hardware is further configured to
based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are in accord; and based on the determination that the second measured value and the second expected value are in accord, replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.
8 . The memory device of claim 4 , wherein the security hardware is further configured to pipeline memory array reads of the memory content and/or of the genuine backup of the memory content into the security hardware using at least one of a buffer and timing logic.
9 . The memory device of claim 1 , wherein the security hardware includes at least one of a secure hash algorithm engine, one or more monotonic counters, and one or more security registers.
10 . The memory device of claim 1 , wherein the memory content is at least one of a startup routine, a shutdown routine, and a reset routine.
11 . The memory device of claim 1 , wherein the controller comprises the security hardware.
12 . A method for authenticating genuineness of memory content in a memory device having a controller, security hardware, and a main memory, wherein the main memory includes one or more user memory regions and at least one reserved memory region, the method comprising:
measuring memory content of the one or more user memory regions to obtain a measured value; comparing the measured value to an expected value using the security hardware; based on the comparison, determining that the measured value and the expected value are not in accord; and based on the determination, replacing, using the controller, the memory content of the one or more user memory regions with a genuine backup of the memory content stored in the at least one reserved memory region.
13 . The method of claim 12 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before replacing the memory content with the genuine backup of the memory content, the method further comprises:
measuring the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value; comparing the second measured value to a second expected value using the security hardware; and replacing the memory content of the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.
14 . The method of claim 13 , wherein the first expected value and the second expected value are equivalent.
15 . The method of claim 13 , further comprising
based on the comparison of the second measured value and the second expected value, determining that the second measured value and the second expected value are not in accord; and based on the determination that the second measured value and the second expected value are not in accord, directing the memory device to enter a safe mode and/or send a warning message.
16 . The method of claim 13 , further comprising
based on the comparison of the second measured value and the second expected value, determining that the second measured value and the second expected value are in accord; and based on the determination that the second measured value and the second expected value are in accord, replacing the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.
17 . The method of claim 12 , wherein the method further comprises preventing access to the main memory at least until the measured value is obtained.
18 . The method of claim 12 , wherein the memory content of the one or more user memory regions includes at least one of a startup routine, a shutdown routine, and a reset routine.
19 . A memory system comprising:
a host device; and a memory device including
a controller,
a main memory operably coupled to the controller, the main memory having one or more user memory regions and at least one reserved memory region, and
security hardware operably coupled to the controller and to the main memory, wherein the security hardware is configured to:
measure memory content stored in the one or more user memory regions to obtain a measured value,
compare the measured value to an expected value,
based on the comparison, determine that the measured value and the expected value are not in accord, and
based on the determination, initiate a replacement of the memory content stored in the one or more memory regions with a genuine backup of the memory content stored in the at least one reserved memory region.
20 . The system of claim 19 , wherein the controller is configured to prevent the host device from accessing the main memory at least until the measured value is obtained.
21 . The system of claim 19 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before initiating a replacement of the memory content with the genuine backup of the memory content, the security hardware is further configured to:
measure the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value; compare the second measured value to a second expected value; and replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.
22 . The system of claim 21 , wherein the first expected value and the second expected value are equivalent.
23 . The system of claim 21 , wherein
the security hardware is further configured to determine that the second measured value and the second expected value are not in accord based on the comparison of the second measured value to the second expected value; and the host device or the controller is configured to flag the memory device as untrustworthy based on the determination that the second measured value and the second expected value are not in accord.
24 . The system of claim 21 , wherein the security hardware is further configured to
based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are in accord; and based on the determination that the second measured value and the second expected value are in accord, replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.
25 . The system of claim 19 , wherein the memory content of the plurality of memory regions includes at least one of a startup routine, a shutdown routine, and a reset routine.
26 . The system of claim 19 , wherein the controller comprises the security hardware.Join the waitlist — get patent alerts
Track US2019050297A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.