US2019050297A1PendingUtilityA1

Memory devices and systems with security capabilities

Assignee: MICRON TECHNOLOGY INCPriority: Jun 26, 2017Filed: Oct 18, 2018Published: Feb 14, 2019
Est. expiryJun 26, 2037(~10.9 yrs left)· nominal 20-yr term from priority
G06F 2201/83G06F 11/1666G06F 11/1458G06F 11/1461G06F 21/57G06F 21/50G06F 11/1446G06F 21/79
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Several embodiments of systems incorporating memory devices are disclosed herein. In one embodiment, a memory device can include a controller, a main memory operably coupled to the controller, and security hardware operably coupled to the controller and to the main memory. The main memory can include a plurality of memory regions and at least one reserved memory region configured to store genuine backups of memory content stored in the plurality of memory regions. In operation, the security hardware is configured to measure memory content of the plurality of memory regions before startup, shutdown, and reset of the memory device; compare the measured value to an expected value; and direct the controller to replace the memory content with a genuine backup of the memory content stored in the at least one reserved memory region if the measured value and the expected value are not in accord.

Claims

exact text as granted — not AI-modified
I/We claim: 
     
         1 . A memory device comprising:
 a controller;   a main memory operably coupled to the controller, the main memory having one or more user memory regions and at least one reserved memory region; and   security hardware operably coupled to the controller and to the main memory, the security hardware configured to
 measure memory content stored in the one or more user memory regions to obtain a measured value, 
 compare the measured value to an expected value, 
 based on the comparison, determine that the measured value and the expected value are not in accord, and 
 based on the determination, initiate a replacement of the memory content stored in the one or more user memory regions with a genuine backup of the memory content stored in the at least one reserved memory region. 
   
     
     
         2 . The memory device of  claim 1 , wherein the controller is configured to prevent access to the main memory at least until the measured value is obtained. 
     
     
         3 . The memory device of  claim 1 , wherein the security hardware is further configured to flag the memory device as untrustworthy based on the determination. 
     
     
         4 . The memory device of  claim 1 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before initiating a replacement of the memory content with the genuine backup of the memory content based on the determination, the security hardware is further configured to:
 measure the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value;   compare the second measured value to a second expected value; and   replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.   
     
     
         5 . The memory device of  claim 4 , wherein the first expected value and the second expected value are equivalent. 
     
     
         6 . The memory device of  claim 4 , wherein the security hardware is further configured to
 based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are not in accord; and   based on the determination that the second measured value and the second expected value are not in accord, direct the memory device to enter a safe mode and/or send a warning message.   
     
     
         7 . The memory device of  claim 4 , wherein the security hardware is further configured to
 based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are in accord; and   based on the determination that the second measured value and the second expected value are in accord, replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.   
     
     
         8 . The memory device of  claim 4 , wherein the security hardware is further configured to pipeline memory array reads of the memory content and/or of the genuine backup of the memory content into the security hardware using at least one of a buffer and timing logic. 
     
     
         9 . The memory device of  claim 1 , wherein the security hardware includes at least one of a secure hash algorithm engine, one or more monotonic counters, and one or more security registers. 
     
     
         10 . The memory device of  claim 1 , wherein the memory content is at least one of a startup routine, a shutdown routine, and a reset routine. 
     
     
         11 . The memory device of  claim 1 , wherein the controller comprises the security hardware. 
     
     
         12 . A method for authenticating genuineness of memory content in a memory device having a controller, security hardware, and a main memory, wherein the main memory includes one or more user memory regions and at least one reserved memory region, the method comprising:
 measuring memory content of the one or more user memory regions to obtain a measured value;   comparing the measured value to an expected value using the security hardware;   based on the comparison, determining that the measured value and the expected value are not in accord; and   based on the determination, replacing, using the controller, the memory content of the one or more user memory regions with a genuine backup of the memory content stored in the at least one reserved memory region.   
     
     
         13 . The method of  claim 12 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before replacing the memory content with the genuine backup of the memory content, the method further comprises:
 measuring the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value;   comparing the second measured value to a second expected value using the security hardware; and   replacing the memory content of the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.   
     
     
         14 . The method of  claim 13 , wherein the first expected value and the second expected value are equivalent. 
     
     
         15 . The method of  claim 13 , further comprising
 based on the comparison of the second measured value and the second expected value, determining that the second measured value and the second expected value are not in accord; and   based on the determination that the second measured value and the second expected value are not in accord, directing the memory device to enter a safe mode and/or send a warning message.   
     
     
         16 . The method of  claim 13 , further comprising
 based on the comparison of the second measured value and the second expected value, determining that the second measured value and the second expected value are in accord; and   based on the determination that the second measured value and the second expected value are in accord, replacing the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.   
     
     
         17 . The method of  claim 12 , wherein the method further comprises preventing access to the main memory at least until the measured value is obtained. 
     
     
         18 . The method of  claim 12 , wherein the memory content of the one or more user memory regions includes at least one of a startup routine, a shutdown routine, and a reset routine. 
     
     
         19 . A memory system comprising:
 a host device; and   a memory device including
 a controller, 
 a main memory operably coupled to the controller, the main memory having one or more user memory regions and at least one reserved memory region, and 
 security hardware operably coupled to the controller and to the main memory, wherein the security hardware is configured to:
 measure memory content stored in the one or more user memory regions to obtain a measured value, 
 compare the measured value to an expected value, 
 based on the comparison, determine that the measured value and the expected value are not in accord, and 
 based on the determination, initiate a replacement of the memory content stored in the one or more memory regions with a genuine backup of the memory content stored in the at least one reserved memory region. 
 
   
     
     
         20 . The system of  claim 19 , wherein the controller is configured to prevent the host device from accessing the main memory at least until the measured value is obtained. 
     
     
         21 . The system of  claim 19 , wherein the measured value is a first measured value and the expected value is a first expected value, and wherein, before initiating a replacement of the memory content with the genuine backup of the memory content, the security hardware is further configured to:
 measure the genuine backup of the memory content stored in the at least one reserved memory region to obtain a second measured value;   compare the second measured value to a second expected value; and   replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region only if the second measured value and the second expected value are in accord.   
     
     
         22 . The system of  claim 21 , wherein the first expected value and the second expected value are equivalent. 
     
     
         23 . The system of  claim 21 , wherein
 the security hardware is further configured to determine that the second measured value and the second expected value are not in accord based on the comparison of the second measured value to the second expected value; and   the host device or the controller is configured to flag the memory device as untrustworthy based on the determination that the second measured value and the second expected value are not in accord.   
     
     
         24 . The system of  claim 21 , wherein the security hardware is further configured to
 based on the comparison of the second measured value and the second expected value, determine that the second measured value and the second expected value are in accord; and   based on the determination that the second measured value and the second expected value are in accord, replace the memory content stored in the one or more user memory regions with the genuine backup of the memory content stored in the at least one reserved memory region.   
     
     
         25 . The system of  claim 19 , wherein the memory content of the plurality of memory regions includes at least one of a startup routine, a shutdown routine, and a reset routine. 
     
     
         26 . The system of  claim 19 , wherein the controller comprises the security hardware.

Join the waitlist — get patent alerts

Track US2019050297A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.