Secure storage verification using multiple computing devices
By generating and individually associating multiple encryption key pairs in a secure storage device with each computing device, the security vulnerability caused by single key pair authentication is solved, thereby improving the system's security and resistance to cracking.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MICRON TECHNOLOGY INC
- Filing Date
- 2021-10-14
- Publication Date
- 2026-05-05
AI Technical Summary
In existing technologies, there is a security vulnerability when using a single encryption key pair to authenticate a computing device. An unauthorized party may gain access to a secure storage device through a single key pair, resulting in compromise of the overall system security.
Multiple encryption key pairs are generated using physically non-clonable functions, and each key pair is individually associated with a different computing device. The communication of the computing device is authenticated through encryption and signing processes, thereby restricting its access permissions.
By using multiple encryption key pairs, the possibility of unauthorized access is reduced, the overall security of the system is improved, and the impact of cracking a single computing device on the overall security of the system is prevented.
Smart Images

Figure CN114372273B_ABST
Abstract
Description
[0001] Cross-reference
[0002] This patent application claims priority to U.S. Patent Application No. 17 / 072,541, filed October 16, 2020, by Szubbocsev, entitled "Secure Storage Device Verification with Multiple Computing Devices," which is assigned to the assignee and is expressly incorporated herein by reference in its entirety. Technical Field
[0003] The following text generally refers to one or more systems for memory, and more specifically, to the verification of secure storage devices that utilize multiple computing devices.
[0004] The technical field involves the verification of secure storage devices utilizing multiple computing devices. Background Technology
[0005] Memory devices are widely used to store information in various electronic devices such as computers, wireless communication devices, cameras, and digital displays. Information is stored by programming memory cells within the memory device to different states. For example, a binary memory cell can be programmed to one of two supported states, typically represented by logic 1 or logic 0. In some instances, a single memory cell can support more than two states, any of which can be stored. To access the stored information, a component can read or sense at least one stored state in the memory device. To store information, a component can write states into the memory device or program states.
[0006] Various types of memory devices and memory cells exist, including magnetic hard disks, random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), auto-select memory, and chalcogenide memory technology. Memory cells can be volatile or non-volatile. For example, non-volatile FeRAM can maintain its stored logic state for a long time even without external power. Volatile DRAM devices, on the other hand, may lose their stored state when disconnected from external power. Summary of the Invention
[0007] A method is described. The method may include: receiving a first command and a first public key of a first key pair associated with the computing device at a secure storage device and from a computing device; selecting a second key pair from a plurality of key pairs to associate with the computing device, at least in part based on the receipt of the first command and the first public key; encrypting a second public key of the second key pair using the first public key, at least in part based on the selection of the second key pair; and transmitting a message containing the encrypted second public key to the computing device.
[0008] An apparatus is described. The apparatus may include: a secure storage device comprising a memory array; and a controller coupled to the memory array and configured to cause the apparatus to: receive a first command from a computing device and a first public key of a first key pair associated with the computing device; select a second key pair from a plurality of key pairs to associate with the computing device, at least in part based on the receipt of the first command and the first public key; encrypt a second public key of the second key pair using the first public key, at least in part based on the selection of the second key pair; and transmit a message containing the encrypted second public key to the computing device.
[0009] A non-transitory computer-readable medium storing code is described. The non-transitory computer-readable medium storing code may contain instructions that, when executed by a processor of an electronic device, cause the electronic device to: receive a first command and a first public key of a first key pair associated with the computing device at a secure storage location and from a computing device; select a second key pair from a plurality of key pairs to associate with the computing device, at least in part based on the receipt of the first command and the first public key; encrypt a second public key of the second key pair using the first public key, at least in part based on the selection of the second key pair; and transmit a message containing the encrypted second public key to the computing device. Attached Figure Description
[0010] Figure 1 This document describes examples of systems that support secure storage device verification using multiple computing devices, based on the examples disclosed herein.
[0011] Figure 2 This document describes examples of systems that support secure storage device verification using multiple computing devices, based on the examples disclosed herein.
[0012] Figure 3 This document describes an example of a flowchart illustrating secure storage device verification using multiple computing devices, based on the examples disclosed herein.
[0013] Figure 4 A block diagram illustrating a secure storage device that supports secure storage device verification using multiple computing devices, based on the examples disclosed herein.
[0014] Figure 5The flowchart illustrates one or more methods for supporting secure storage device verification using multiple computing devices, based on the examples disclosed herein. Detailed Implementation
[0015] Some systems may comprise several different devices, services, and processes. A single device can authenticate different devices, services, and processes. For example, a single device can be a secure storage device used by the remaining different devices, services, and processes to perform their functions. In some instances, the system may be an automotive system. In such instances, the secure storage device may be contained within a central computing unit that acts as storage for one or more electrical systems or subsystems of the system. Examples of electrical systems or subsystems may include drivetrain control units, human-machine interface control units, door control units, different types of engine control units, seat control units, speed control units, telematics control units, transmission control units, braking control units, battery management control units, or other units, or combinations thereof. In some instances, encryption keys can be used to authenticate different devices, services, and processes. In some cases, using the same encryption key for each device, service, or process may lead to security vulnerabilities. For example, an unauthorized party or unauthorized device could access data or exploit the operation or functionality of the secure storage device by using a single encryption key. In other instances, the use of one device, service, or process in the system may compromise the overall security of the system.
[0016] This document describes systems, techniques, and apparatuses for authenticating each device, service, or process in a system containing a secure storage device using different encryption key pairs. For example, the secure storage device may generate a number of encryption key pairs using a physically non-cloning function. When a device, service, or process first communicates with the secure storage device, the secure storage device may select an encryption key pair from the generated key pairs to associate with the device, service, or process. The secure storage device may then use the selected key pair to secure future communications with the device, service, or process. The secure storage device may perform the same process until each device, service, or process in the system is associated with a unique encryption key pair. By individually authenticating each device, service, or process, security vulnerabilities in the system can be reduced. For example, because each device, system, or process has a unique encryption key pair, unauthorized parties using a device, service, or process may exclude the system as a whole. Furthermore, increasing the number of encryption key pairs reduces the likelihood of unauthorized parties using the system.
[0017] First, as referenced Figure 1 The features of this disclosure are described in the context of the system and the bare die. (See references...) Figure 2 and 3 The features of this disclosure are described in the context system and flowcharts. (See references...) Figure 4 and5 The device diagrams and flowcharts describing the use of multiple computing devices for secure storage device verification are used to further illustrate and describe these and other features of this disclosure, and reference is made to the device diagrams and flowcharts.
[0018] Figure 1 This document describes an example of a system 100 that supports authentication software images based on the examples disclosed herein. System 100 may include a central computing unit 105 and one or more computing units 150. The computing units 150 may be examples of a vehicle's infotainment system, a vehicle's telematics system, a vehicle's powertrain system, a vehicle's speed control system, etc.
[0019] Central computing device 105 may include processor 110, secure storage device 115, and one or more additional components 120. Secure storage device 115 may include user space 125 configured to store data (e.g., general data). Storage device 115 may also include a security component 130, which includes a key generator 135, a key store 140, and software 145. In some cases, security component 130 may securely store additional data or information.
[0020] Storage device 115 may generate one or more keys at key generator 135. In some instances, key generator 135 may generate one or more keys using a physically non-cloning function. Additionally, security component 130 may store one or more of the keys generated by key generator 135 in key storage area 140, such as management keys and / or identity keys. The keys may be an instance of a symmetric server root key (SRK) or a set of two keys (e.g., a management public key and a device-side identity private key). The server root key or management public key allows an entity possessing a copy of the SRK or management private key to manage security component 130 by enabling or configuring security features of security component 130. Security component 130 may also include software 145. Storage device 115 may include one or more components associated with the storage device that can be used to perform one or more authentication procedures as discussed herein.
[0021] Storage device 115 may be integrated into a central computing device 105 that may include a processor 110 that interacts with storage device 115. Processor 110 may transmit commands and information to and from computing device 150. Processor 110 may also transmit keys and messages to computing device 150 during the authentication process. Before executing a command from computing device 150, storage device 115 may authenticate the command to ensure it has not been tampered with by a malicious actor or unauthorized party, and to prevent execution of the command if its code has been modified by a malicious actor or unauthorized party.
[0022] This document describes techniques for authenticating information transmitted from and from computing device 150 to central computing device 105. For example, secure storage device 115 may generate a number of key pairs (e.g., a predetermined number of key pairs). When computing device 150 communicates with secure storage device 115, secure storage device 115 may select a key pair from the generated key pairs to associate with computing device 150. Secure storage device 115 may then use the selected key pair to authenticate future communications from computing device 150. Alternatively, secure storage device 115 may restrict access to computing device 150 to a portion of secure storage device 115 rather than the entire secure storage device 115. That is, computing device 150 may access data relevant to performing its respective functions, but not all data. Secure storage device 115 also utilizes additional computing devices 150 within system 100 to implement key pair selection. For example, secure storage device 115 may select a second key pair to associate with a second computing device 150.
[0023] By using different key pairs to authenticate each computing device 150, security vulnerabilities in system 100 can be reduced. Increasing the number of key pairs reduces the likelihood of unauthorized parties gaining access to secure storage device 115.
[0024] Figure 2 This document describes an example of a system 200 that supports secure storage device verification using multiple computing devices, based on the examples disclosed herein. The central computing device 205 may be as described in the references. Figure 2 An example of the central computing device 105 described herein. The secure storage device 215 may be as described in the reference. Figure 1 Examples of the described secure storage device 115 or secure component 130. System 200 may also include a computing device 250. The computing device 250 may be as described in the reference... Figure 1 An example of the computing device 150 described. Figure 2 Four computing devices 250 are shown for illustrative purposes only. That is to say, the system 200 may also contain more or fewer than four computing devices 250.
[0025] Central computing device 205 may be a control unit of system 200. In other instances, central computing device 205 may store data or information accessible by computing device 250. That is, computing device 250 may access the information stored at central computing device 205 to perform its corresponding functions or operations. Secure storage device 215 may store information and data. Computing device 250 may be an instance of a device, service, processor, control unit, server, virtual machine, or a combination thereof.
[0026] In some instances, system 200 may be an example of an automotive system. In such instances, computing device 250 may be an example of a powertrain control unit, human-machine interface control unit, door control unit, different types of engine control units, seat control units, speed control units, telematics control units, transmission control units, braking control units, battery management control units, entertainment control units, or other units, or combinations thereof. Alternatively or additionally, in such instances, central computing device 205 may store information used by computing device 250 in secure storage device 215. That is, secure storage device 215 may be an example of a fixed storage device.
[0027] In some cases, computing device 250 may also include security procedures, such as authentication procedures. Such features reduce the risk of an authorized party gaining access to computing device 250 or information on secure storage device 215. In some instances, when each computing device 250 has its own security procedure, system 200 may lack cohesion. That is, system 200 may not be able to detect which computing device 250 has been compromised. In other instances, central computing device 205 can manage the security procedures of system 200. In such instances, central computing device 205 can authenticate computing devices 250 before sharing information and data. Such instances simplify the security procedures of system 200 and enable system 200 to be notified when a given computing device 250 is compromised.
[0028] In some instances, central computing device 205 may use a single encryption key pair—such as a single public key and a single private key—to authenticate computing device 250. When central computing device 205 uses a single encryption key pair, system 200 may be vulnerable. For example, computing device 250 can be compromised if an unauthorized party or device accesses data or exploits the operation or functionality of computing device 250 by using a single encryption key. In other instances, when computing device 250 is used, system 200 as a whole can be compromised. That is, an unauthorized party could gain access to all data stored in secure storage device 215 by obtaining a single encryption key pair.
[0029] As described herein, secure storage device 215 may utilize multiple encryption key pairs to individually authenticate each central computing device 250 using associated encryption key pairs. For example, secure storage device 215 may generate a predetermined number of encryption key pairs during an initialization process, such as when system 200 is first powered on. In some instances, the predetermined number generated may be based on the number of computing devices 250, for example, four encryption key pairs may be generated when there are four computing devices 250. In some instances, the predetermined number generated may be based on parameters used to operate the secure storage device, characteristics of the secure storage device, or a combination thereof. When computing device 250-a first communicates with secure storage device 215, secure storage device 215 may select a first encryption key pair from the generated number of encryption key pairs to associate with computing device 250-a. Secure storage device 215 may then use the first encryption key pair to authenticate messages from computing device 250-a. Additionally, the secure storage device 215 can associate a second encryption key pair with computing device 250-b, a third encryption key pair with computing device 250-c, and a fourth encryption key pair with computing device 250-d. In instances where system 200 has an additional computing device 250, the secure storage device 215 can implement a similar process to associate the additional encryption key pairs with the additional computing device 250.
[0030] In some instances, when multiple encryption key pairs are implemented, secure storage device 215 can restrict access to computing device 250 to information or data associated with the functionality of computing device 250. For example, computing device 250-a may be a drivetrain control unit. Secure storage device 215 can restrict access to computing device 250-a to data and information associated with drivetrain control functions and operations. By implementing multiple encryption key pairs, system 200 can reduce security vulnerabilities. For example, even with a single computing device 250, unauthorized access can remain restricted, for example, limited to data or information associated with the functionality and operation of the computing device 250 used. Furthermore, increasing the number of encryption key pairs reduces the likelihood of an unauthorized party using the entire system 200. See below for reference. Figure 3 Describe additional details of the authentication process.
[0031] Figure 3 This document describes an example of a flowchart 300 illustrating secure storage device verification supporting multiple computing devices, based on the examples disclosed herein. Flowchart 300 may include a secure storage device 315 and a computing device 350, which may be as shown in the reference... Figure 1 The described examples are corresponding instances of the secure storage device 115 or secure component 130 and the computing device 350. The secure storage device may be included in a central computing device, such as as shown in the reference... Figure 2In the described central computing device 205, although shown in sequence or order, the order of the processes can be modified unless otherwise specified. Therefore, the illustrated examples are for illustrative purposes only, and the illustrated processes can be executed in different orders, and some processes can be executed in parallel. Additionally, one or more processes can be omitted in various examples. Therefore, not all processes are required in each example. Other process flows are possible. Flowchart 300 illustrates an example for generating multiple encryption key pairs and associating the multiple encryption key pairs with the personal computing device 350.
[0032] At 305, the secure storage device 315 can generate a number of key pairs (e.g., encryption key pairs). In some instances, the secure storage device 315 can generate the number of key pairs by implementing a physically unclonable function (PUF). In such instances, the key pairs can be generated based on the physical characteristics of the secure storage device 315, such as the memory technology of the secure storage device 315 (e.g., NAND or SRAM). Additionally, the secure storage device 315 can generate key pairs containing a public key and a private key (e.g., an RSA cryptosystem). The secure storage device 315 can share the generated public key and avoid sharing the generated private key. In some instances, the secure storage device 315 can be based on a key contained in the system (e.g., as referenced). Figure 2 The number of computing devices 350 in the described system 200) generates a predetermined number of key pairs. In other instances, the secure storage device 315 may generate key pairs during an initialization process, such as when the secure storage device 315 is first powered on.
[0033] At point 310, computing device 350 may issue a request key command and its corresponding public key. In some instances, computing device 350 may issue the request key command when it first communicates with secure storage device 315. By issuing the request key command, computing device 350 may initiate an authentication process between secure storage device 315 and computing device 350. In addition to the request key command, computing device 350 may also issue the public key of a key pair (e.g., a first key pair) associated with computing device 350. Secure storage device 315 may receive the request key command and public key from computing device 350.
[0034] At 320, the secure storage device 315 can select a key pair (e.g., a second key pair) from the generated number of key pairs. In some instances, the secure storage device 315 can select key pairs based on the sequential order of available key pairs, such as a first-come, first-served basis. For example, the secure storage device 315 can generate a first key pair first, followed by a second key pair, a third key pair, and so on. When selecting a key pair, the secure storage device 315 can select a key pair based on the generation sequence, such as generating the first key pair first. In other instances, the secure storage device 315 can select key pairs in a different order (e.g., randomly).
[0035] In some instances, after selecting a key pair, the secure storage device 315 may encrypt the public key of the key pair selected using the public key received from the computing device 350. Alternatively, the secure storage device 315 may also use the private key of the key pair selected at the secure storage device 315 to sign a request key command. For example, the secure storage device 315 may use the private key of the selected key pair to generate a first value associated with the public key of the selected key pair. By encrypting the public key of the selected key pair and signing the command, the central computing device 350 may associate the selected key pair with the computing device 350. In some instances where the system has an additional computing device 350, the secure storage device 315 may implement a similar process to associate an additional key pair with an additional computing device 350, for example, selecting a second key pair to associate with a second computing device 350.
[0036] At 325, the secure storage device 315 may transmit a request key command response to the computing device 350. For example, the secure storage device 315 may convey the encrypted public key of the selected key pair and the value generated from signing the request key command.
[0037] At 330, computing device 350 can instruct the receipt of a request key command response. That is, computing device 350 can instruct the receipt of an encrypted public key associated with the key pair selected by secure storage device 315.
[0038] At point 335, the computing device may generate a second command. For example, computing device 340 may generate a command requesting information and data from the secure storage device contained in secure storage device 315. In some instances, computing device 350 may sign the second command based on the private key of a key pair associated with computing device 350. That is, computing device 350 may generate a second value associated with its corresponding private key to sign the second command. In some instances, computing device 350 may use its corresponding private key to sign all commands sent to secure storage device 315 after the initial authentication process.
[0039] At 340, computing device 350 may send a second command to secure storage device 315. For example, the second command may include a second value associated with the private key of computing device 350.
[0040] At 345, the secure storage device 315 can verify the second command received from the computing device 350. That is, the secure storage device 315 can authenticate that the received second command originates from the computing device 350 and is not from an unauthorized party. For example, the secure storage device 315 can authenticate the second command using a public key received from the computing device 350 (e.g., the public key of a key pair associated with the computing device 350). In other words, the secure storage device 315 can verify that the second command originated from the computing device 350 based on the public key received from the computing device 350, for example, by using the public key received from the computing device 350 to decrypt the second command. In some instances, the secure storage device 315 can use the public key received from the computing device 350 to verify all commands received from the computing device 350.
[0041] At 355, the secure storage device 315 can generate a second response to the second command. That is, the secure storage device 315 can execute the second command and generate a response based on the execution of the second command. For example, when the second command requests data or information, the secure storage device 315 can access the requested information. Additionally, the secure storage device 315 can sign the second response based on the private key of a selected key pair of the secure storage device 315. That is, the secure storage device 315 can generate a third value associated with its corresponding private key to sign the second response. In some instances, the secure storage device 315 can use its corresponding private key to sign all responses sent to the computing device 350 after the initial authentication process.
[0042] At 360, the secure storage device 315 may send a second response to the computing device 350. For example, the secure storage device 315 may send a second response containing a generated third value and any information or data requested by the computing device 350.
[0043] At point 365, computing device 350 can verify the second response received from secure storage device 315. That is, computing device 350 can authenticate that the received second response is from secure storage device 315 and not from an unauthorized party. For example, computing device 350 can authenticate the second response by using a public key received from secure storage device 315 (e.g., the public key of a selected key pair associated with secure storage device 315). In other words, computing device 350 can verify that a second command originates from secure storage device 315 based on the public key received from secure storage device 315, for example, by decrypting the second command using the public key received from secure storage device 315. In some instances, computing device 350 can use the public key received from secure storage device 315 to verify all commands received from secure storage device 315.
[0044] Figure 4 A block diagram 400 illustrates a secure storage device 405 that supports secure storage device verification using multiple computing devices, based on examples disclosed herein. The secure storage device 405 may be as shown in the reference... Figures 1 to 3 Examples of aspects of the described secure storage device. Secure storage device 405 may include a receiving component 410, a key manager component 415, an output component 420, a value component 425, and an authentication component 430. Each of these modules may communicate with each other directly or indirectly (e.g., via one or more buses).
[0045] The receiving component 410 may receive a first command and a first public key of a first key pair associated with the computing device at a secure storage device and from a computing device. In some instances, the receiving component 410 may receive a second command and a third public key of a third key pair associated with the second computing device at a secure storage device and from a second computing device. In some cases, the receiving component 410 may receive the second command at a secure storage device from the computing device after a transmission message. In some cases, the receiving component 410 may receive a second message from the computing device indicating the reception of the second public key at the computing device. In some instances, the receiving component 410 may receive the second command from the computing device after a transmission message, wherein the second command is generated based on a first private key of the first key pair associated with the computing device.
[0046] Key manager component 415 may select a second key pair from a set of key pairs to associate with a computing device based on receiving a first command and a first public key. In some instances, key manager component 415 may encrypt a second public key of the second key pair using the first public key based on the selection of the second key pair. In some cases, key manager component 415 may select a fourth key pair from a set of key pairs to associate with a second computing device based on receiving a second command and a third public key. In some cases, key manager component 415 may encrypt a fourth public key of the fourth key pair using the third public key based on the selection of the fourth key pair. In some instances, key manager component 415 may select a fourth key pair based on the sequential order of available key pairs from the set of key pairs. In some cases, key manager component 415 may initialize a secure storage device before receiving the first command. In some cases, key manager component 415 may generate a set of key pairs at the secure storage device based on the initialization of the secure storage device.
[0047] Output component 420 may transmit a message containing an encrypted second public key to a computing device. In some instances, output component 420 may transmit a second message containing an encrypted fourth public key to a second computing device. In some cases, output component 420 may transmit a second message instructing the execution of a second command to a computing device based on verification of the second command.
[0048] Value component 425 may use the first private key of the second key pair to generate a value associated with the second public key of the second key pair, wherein the message transmitted to the computing device contains the value.
[0049] The verification component 430 can verify that the second command originates from the computing device based on the first public key and the second key pair associated with the computing device.
[0050] In some instances, the computing device may have a similar authentication component that can authenticate a second message as originating from the secure storage device based on a second public key associated with the secure storage device.
[0051] Figure 5 The flowchart illustrates one or more methods 500 for verifying secure storage devices using multiple computing devices, based on examples disclosed herein. The operation of method 500 can be implemented by a secure storage device or its components as described herein. For example, the operation of method 500 can be implemented by, as referenced... Figure 4 The described secure storage device performs the functions described herein. In some instances, the secure storage device may execute a set of instructions to control the functional elements of the secure storage device to perform the functions described herein. Alternatively, the secure storage device may use dedicated hardware to perform aspects of the functions described herein.
[0052] At point 505, the secure storage device may receive a first command and a first public key of a first key pair associated with the computing device from the secure storage device. The operation of point 505 can be performed according to the methods described herein. In some instances, aspects of the operation of point 505 may be as described in references... Figure 4 The described receiving component is executed.
[0053] At point 510, the secure storage device can select a second key pair from a set of key pairs to associate with the computing device based on receiving a first command and a first public key. The operation of 510 can be performed according to the method described herein. In some instances, aspects of the operation of 510 can be derived from, as referenced... Figure 4 The described key manager component is executed.
[0054] At point 515, the secure storage device can encrypt the second public key of the second key pair using the first public key based on the selection of the second key pair. The operation at point 515 can be performed according to the method described herein. In some instances, aspects of the operation at point 515 may be as described in the references... Figure 4 The described key manager component is executed.
[0055] At point 520, the secure storage device can transmit a message containing an encrypted second public key to the computing device. The operation at point 520 can be performed according to the method described herein. In some instances, it can be achieved by, as referenced... Figure 4 The described output component performs the 520 operation.
[0056] In some instances, the device as described herein may perform one or more methods, such as method 500. The device may include features, means, or instructions (e.g., a non-transitory computer-readable medium storing instructions executable by a processor) for performing the following operations: receiving a first command and a first public key of a first key pair associated with the computing device at a secure storage location and from a computing device; selecting a second key pair from a set of key pairs to associate with the computing device based on the received first command and the first public key; encrypting a second public key of the second key pair using the first public key based on the selected second key pair; and transmitting a message containing the encrypted second public key to the computing device.
[0057] Method 500 and some instances of the device described herein may further include operations, features, means, or instructions for generating a value associated with a second public key of the second key pair using a first private key of the second key pair, wherein the message transmitted to the computing device contains the value.
[0058] Method 500 and some examples of the apparatus described herein may further include operations, features, means, or instructions for performing the following: receiving a second command and a third public key of a third key pair associated with the second computing device at a secure storage device and from the second computing device; selecting a fourth key pair from a set of key pairs to associate with the second computing device based on receiving the second command and the third public key; encrypting the fourth public key of the fourth key pair using the third public key based on the selection of the fourth key pair; and transmitting a second message containing the encrypted fourth public key to the second computing device.
[0059] Method 500 and some instances of the devices described herein may further include operations, features, means, or instructions for selecting a fourth key pair based on a sequential sequence of available key pairs from a set of key pairs.
[0060] Method 500 and some examples of the devices described herein may further include operations, features, means, or instructions for performing the following: receiving a second command from a computing device at a secure storage device after transmitting a message; verifying that the second command originates from the computing device based on a first public key and a second key pair associated with the computing device; and transmitting a second message instructing the execution of the second command to the computing device based on the verification of the second command.
[0061] Method 500 and some instances of the devices described herein may further include the ability to verify, at the computing device, a second message as an operation, feature, means, or instruction from the secure storage device based on a second public key associated with the secure storage device.
[0062] Method 500 and some examples of the devices described herein may further include operations, features, means or instructions for performing the following: initializing the secure storage device before receiving the first command; and generating a set of key pairs at the secure storage device based on the initialization of the secure storage device.
[0063] Method 500 and some examples of the devices described herein may further include operations, features, means, or instructions for receiving from the computing device a second message indicating the receipt of the second public key at the computing device.
[0064] Method 500 and some examples of the devices described herein may further include operations, features, means, or instructions for receiving a second command from a computing device after a transmission message, wherein the second command may be generated based on a first private key of a first key pair associated with the computing device.
[0065] It should be noted that the methods described herein describe possible implementations, and the operations and steps can be rearranged or otherwise modified, and other implementations are possible. Furthermore, two or more parts from the methods may be combined.
[0066] An apparatus is described. The apparatus may include: a secure storage device comprising a memory array; a controller coupled to the memory array and configured to cause the apparatus to: select a second key pair from a set of key pairs to associate with a computing device based on receiving a first command and a first public key; encrypt a second public key of the second key pair using the first public key based on the selected second key pair; and transmit a message containing the encrypted second public key to the computing device.
[0067] In some cases, the controller may be further configured to use the first private key of the second key pair to generate a value associated with the second public key of the second key pair, wherein the message transmitted to the computing device contains the value.
[0068] In some instances, the controller may be further configured to perform the following operations: receive a second command from the second computing device and a third public key of a third key pair associated with the second computing device; select a fourth key pair from the set of key pairs to associate with the second computing device based on the received second command and third public key; encrypt the fourth public key of the fourth key pair using the third public key based on the selected fourth key pair; and transmit a second message containing the encrypted fourth public key to the second computing device.
[0069] In some instances, the controller can be configured to select a fourth key pair based on the sequential order of available key pairs from the set of key pairs.
[0070] In some cases, the controller may be further configured to: receive a second command from the computing device after transmitting a message; verify that the second command originates from the computing device based on a first public key and a second key pair associated with the computing device; and transmit a second message instructing the execution of the second command to the computing device based on the verification of the second command.
[0071] In some cases, the controller may be further configured to initialize the secure storage device before receiving the first command, and to generate a set of key pairs at the secure storage device based on the initialization of the secure storage device.
[0072] In some cases, the controller may be further configured to receive from the computing device a second message indicating the receipt of the second public key at the computing device.
[0073] In some cases, the controller may be further configured to receive a second command from the computing device after the transmission message, wherein the second command may be generated based on a first private key of a first key pair associated with the computing device.
[0074] The information and signals disclosed herein can be represented using any of a variety of different techniques and skills. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the foregoing description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or optical particles, or any combination thereof. Some diagrams may show signals as single signals; however, those skilled in the art will understand that said signals may represent signal buses, wherein the buses may have various bit widths.
[0075] The terms "electronic communication," "conductive contact," "connection," and "coupling" refer to the relationship between components that enables the flow of signals between them. Components are considered to be in electronic communication with each other (or in conductive contact with each other, or connected to each other, or coupled to each other) if any conductive path exists between them that enables the flow of signals between them at any given time. At any given time, the conductive path between components that are in electronic communication with each other (or in conductive contact with each other, or connected to each other, or coupled to each other) can be open or closed, depending on the operation of the device containing the connected components. The conductive path between connected components can be a direct conductive path between the components, or an indirect conductive path between connected components that may include intermediate components such as switches, transistors, or other components. In some instances, one or more intermediate components, such as switches or transistors, may be used to interrupt the signal flow between connected components for a period of time.
[0076] The term "coupling" refers to the condition of moving from an open-circuit relationship between components to a closed-circuit relationship, in which a signal is currently not allowed to travel between the components via a conductive path, and in which a signal can travel between the components via the conductive path. When a component, such as a controller, couples other components together, the component initially allows a change in the flow of signals between the other components via conductive paths that were previously not permitted.
[0077] The devices containing memory arrays discussed herein can be formed on semiconductor substrates such as silicon, germanium, silicon-germanium alloys, gallium arsenide, and gallium nitride. In some instances, the substrate is a semiconductor wafer. In other instances, the substrate can be a silicon-on-insulator (SOI) substrate, such as silicon-on-glass (SOG) or silicon-on-sapphire (SOP), or an epitaxial layer of semiconductor material on another substrate. The conductivity of the substrate or subregions of the substrate can be controlled by doping with various chemicals containing, but not limited to, phosphorus, boron, or arsenic. Doping can be performed during the initial formation or growth of the substrate, either by ion implantation or by any other doping method.
[0078] The switching components or transistors discussed herein may represent field-effect transistors (FETs) and include a three-terminal device comprising a source, drain, and gate. These terminals may be connected to other electronic components via a conductive material, such as a metal. The source and drain may be conductive and may comprise heavily doped (e.g., degenerate) semiconductor regions. The source and drain may be separated by lightly doped semiconductor regions or channels. If the channel is n-type (i.e., the majority of charge carriers are electrons), then the FET may be called an n-type FET. If the channel is p-type (i.e., the majority of charge carriers are holes), then the FET may be called a p-type FET. The channel may be end-capped with an insulating gate oxide. The channel conductivity can be controlled by applying a voltage to the gate. For example, applying a positive or negative voltage to an n-type FET or a p-type FET, respectively, can make the channel conductive. When a voltage greater than or equal to the transistor's threshold voltage is applied to the transistor's gate, the transistor may be "on" or "activated." When a voltage less than the transistor's threshold voltage is applied to the transistor's gate, the transistor may be "off" or "deactivated."
[0079] The descriptions herein, illustrated with reference to the accompanying drawings, depict exemplary configurations and do not represent all instances that can be implemented or that are within the scope of the claims. The term "exemplary" as used herein means "serving as an example, illustration, or description" and is not "preferred" or "superior" to other instances. The detailed description includes specific details that provide an understanding of the described techniques. However, these techniques can be practiced without these specific details. In some cases, well-known structures and apparatuses are shown in block diagram form to avoid obscuring the concepts of the described instances.
[0080] In the accompanying drawings, similar components or features may have the same reference numerals. Furthermore, various components of the same type can be distinguished by a dash followed by the reference numeral and a second label to differentiate similar components. If only the first reference numeral is used in the specification, the description applies to any of the similar components that have the same first reference numeral but are independent of the second reference numeral.
[0081] The functions described herein can be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented as software executed by a processor, the functions can be stored as one or more instructions or code on or transmitted via a computer-readable medium. Other examples and embodiments are within the scope of this disclosure and the appended claims. For example, due to the nature of software, the functions described herein can be implemented using software executed by a processor, hardware, firmware, hardwired, or any combination thereof. Features implementing the functions can also be physically located in various locations, including distributed implementations such that different parts of the functions are implemented in different physical locations.
[0082] For example, the various illustrative blocks and modules described herein may be implemented or performed using a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors incorporating a DSP core, or any other such configuration).
[0083] As used herein, the word "or" in a list of items contained in the claims (e.g., a list of items beginning with phrases such as "at least one of" or "one or more of") indicates an inclusive list, such that a list of at least one of, for example, A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase "based on" should not be construed as a reference to a closed set of conditions. For example, an exemplary step described as "based on condition A" may be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase "based on" should also be construed as the phrase "at least partially based on".
[0084] Computer-readable media includes both non-transitory computer storage media and communication media, with communication media encompassing any media that facilitates the transfer of a computer program from one place to another. Non-transitory storage media can be any available media accessible by a general-purpose or special-purpose computer. By way of example, and not limitation, non-transitory computer-readable media may include RAM, ROM, electrically erasable programmable read-only memory (EEPROM), optical disc (CD) ROM or other optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, or any other non-transitory media that can be used to carry or store desired program code components in the form of instructions or data structures and is accessible by a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. Furthermore, any connection is appropriately referred to as computer-readable media. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then such coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave are included in the definition of media. As used herein, disks and optical discs include CDs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. Combinations of these are also included within the scope of computer-readable media.
[0085] This description is provided to enable those skilled in the art to make or use this disclosure. Those skilled in the art will appreciate the various modifications to this disclosure and can apply the general principles defined herein to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but is given the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for operating a memory device, comprising: At a secure storage device, and from a computing device, a first command and a first public key of a first key pair associated with the computing device are received; The second key pair is selected from multiple key pairs to be associated with the computing device, based at least in part on receiving the first command and the first public key; The second public key of the second key pair is encrypted using the first public key, at least in part, based on the selection of the second key pair; A first message containing an encrypted second public key is transmitted to the computing device, wherein the first message is signed with the private key of the second key pair; In response to the first message, a second command is received from the computing device at the secure storage device, wherein the second command includes a request for data to be stored at the secure storage device; The second command is verified as originating from the computing device based at least in part on the first public key and the second key pair associated with the computing device, wherein the first public key and the second key are selected from the plurality of key pairs in response to the first command; and A second message instructing the execution of the second command is transmitted to the computing device, at least in part based on the verification of the second command.
2. The method according to claim 1, further comprising: The private key of the second key pair is used to generate a value associated with the second public key of the second key pair, wherein the first message transmitted to the computing device contains the value.
3. The method according to claim 1, further comprising: At the secure storage device, and from the second computing device, a third command and a third public key of a third key pair associated with the second computing device are received; At least in part, a fourth key pair is selected from the plurality of key pairs to be associated with the second computing device based on the receipt of the third command and the third public key; The fourth public key of the fourth key pair is encrypted using the third public key, at least in part, based on the selection of the fourth key pair; and A third message containing an encrypted fourth public key is transmitted to the second computing device.
4. The method according to claim 3, wherein: The fourth key pair is selected based on the sequential order of available key pairs from the plurality of key pairs.
5. The method of claim 1, further comprising: The second message is verified at the computing device as originating from the secure storage device, at least in part, based on the second public key associated with the secure storage device.
6. The method of claim 1, further comprising: Initialize the secure storage device before receiving the first command; and The plurality of key pairs are generated at the secure storage device at least in part based on the initialization of the secure storage device.
7. The method of claim 1, further comprising: Receive a third message from the computing device indicating the receipt of the second public key at the computing device.
8. The method of claim 1, further comprising: A third command is received from the computing device after the first message is transmitted, wherein the third command is generated at least in part based on a first private key of the key pair associated with the computing device.
9. A memory device comprising: A secure storage device, comprising a memory array; and A controller, coupled to the memory array and configured to cause the memory device to perform the following operations: Receive a first command from the computing device and a first public key of a first key pair associated with the computing device; The second key pair is selected from multiple key pairs to be associated with the computing device, based at least in part on receiving the first command and the first public key; The second public key of the second key pair is encrypted using the first public key, at least in part, based on the selection of the second key pair; A first message containing an encrypted second public key is transmitted to the computing device, wherein the first message is signed with the private key of the second key pair; In response to the first message, a second command is received from the computing device, wherein the second command includes a request for data to be stored in the secure storage device; The second command is verified as originating from the computing device based at least in part on the first public key and the second key pair associated with the computing device, wherein the first public key and the second key are selected from the plurality of key pairs in response to the first command; and A second message instructing the execution of the second command is transmitted to the computing device, at least in part based on the verification of the second command.
10. The memory device of claim 9, wherein the controller is further configured to: The private key of the second key pair is used to generate a value associated with the second public key of the second key pair, wherein the first message transmitted to the computing device contains the value.
11. The memory device of claim 9, wherein the controller is further configured to: Receive a third command and a third public key of a third key pair associated with the second computing device from the second computing device; At least in part, a fourth key pair is selected from the plurality of key pairs to be associated with the second computing device based on the receipt of the third command and the third public key; The fourth public key of the fourth key pair is encrypted using the third public key, at least in part, based on the selection of the fourth key pair; and A third message containing an encrypted fourth public key is transmitted to the second computing device.
12. The memory device of claim 11, wherein the controller is configured to select the fourth key pair based on a sequential sequence of available key pairs from the plurality of key pairs.
13. The memory device of claim 9, wherein the controller is further configured to: Initialize the secure storage device before receiving the first command; and The plurality of key pairs are generated at the secure storage device at least in part based on the initialization of the secure storage device.
14. The memory device of claim 9, wherein the controller is further configured to: Receive a third message from the computing device indicating the receipt of the second public key at the computing device.
15. The memory device of claim 9, wherein the controller is further configured to: A third command is received from the computing device after the first message is transmitted, wherein the third command is generated at least in part based on the private key of the first key pair associated with the computing device.
16. A non-transitory computer-readable medium storing code comprising instructions that, when executed by a processor of an electronic device, cause the electronic device to perform the following operations: At a secure storage device, and from a computing device, a first command and a first public key of a first key pair associated with the computing device are received; The second key pair is selected from multiple key pairs to be associated with the computing device, based at least in part on receiving the first command and the first public key; The second public key of the second key pair is encrypted using the first public key, at least in part, based on the selection of the second key pair; A first message containing an encrypted second public key is transmitted to the computing device, wherein the first message is signed with the private key of the second key pair; In response to the first message, a second command is received from the computing device at the secure storage device, wherein the second command includes a request for data to be stored at the secure storage device; The second command is verified as originating from the computing device based at least in part on the first public key and the second key pair associated with the computing device, wherein the first public key and the second key are selected from the plurality of key pairs in response to the first command; and A second message instructing the execution of the second command is transmitted to the computing device, at least in part based on the verification of the second command.
17. The non-transitory computer-readable medium of claim 16, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to perform the following operations: The private key of the second key pair is used to generate a value associated with the second public key of the second key pair, wherein the first message transmitted to the computing device contains the value.
18. The non-transitory computer-readable medium of claim 16, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to perform the following operations: At the secure storage device, and from the second computing device, a third command and a third public key of a third key pair associated with the second computing device are received; At least in part, a fourth key pair is selected from the plurality of key pairs to be associated with the second computing device based on the receipt of the third command and the third public key; The fourth public key of the fourth key pair is encrypted using the third public key, at least in part, based on the selection of the fourth key pair; and A third message containing an encrypted fourth public key is transmitted to the second computing device.
19. The non-transitory computer-readable medium of claim 18, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to select the fourth key pair based on a sequential sequence of available key pairs from the plurality of key pairs.
20. The non-transitory computer-readable medium of claim 16, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to perform the following operations: Initialize the secure storage device before receiving the first command; and The plurality of key pairs are generated at the secure storage device at least in part based on the initialization of the secure storage device.
21. The non-transitory computer-readable medium of claim 16, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to perform the following operations: Receive a third message from the computing device indicating the receipt of the second public key at the computing device.
22. The non-transitory computer-readable medium of claim 16, wherein the instructions, when executed by the processor of the electronic device, further cause the electronic device to perform the following operations: A third command is received from the computing device after the first message is transmitted, wherein the third command is generated at least in part based on the private key of the first key pair associated with the computing device.
Citation Information
Patent Citations
Key attestation statement generation providing device anonymity
CN110892672A
Key distribution system
US20110235806A1
Kernel program including relational database, and method and apparatus for executing said program
US20180232266A1