Systems, methods, and apparatus for controlling memory devices over a computer network

By combining a key management server and an access control server, and using encryption keys and unique device secrets (UDS) for verification, the security issues of encryption key management and access control for memory devices are solved, and the reliability of security management and access verification for memory devices is achieved.

CN114764504BActive Publication Date: 2026-04-07LODESTAR LICENSING GROUP LLC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-12
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In the prior art, the encryption key management and access control of memory devices present security challenges, making it difficult to effectively protect the key management server from DoS attacks, and the process of transferring and verifying permissions is not secure enough.

Method used

It employs a combined architecture of a key management server and an access control server, using cryptographic keys and unique device secrets (UDS) to ensure that the security manager of the memory device can verify permissions, and uses digital signature technology for command verification to prevent unauthorized access.

Benefits of technology

It improves the security of storage devices, reduces the security risks of key management servers, prevents DoS attacks, and enables secure management of encryption keys and reliable transfer of permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114764504B_ABST
    Figure CN114764504B_ABST
Patent Text Reader

Abstract

This application relates to batch transfer of control of memory devices over a computer network. Systems, methods, and apparatus to control memory devices over a computer network are described. For example, a server system establishes a secure authenticated connection with a client computer system to receive a request with a batch identifier configured in the server system to identify a batch of a plurality of memory devices. After determining that the client computer system is qualified to control the plurality of memory devices in the batch, the server system transmits a response to the client computer system. The response contains control data for each respective memory device in the batch. The control data is based at least on an encryption key stored in the server system in association with the respective memory device. The client computer system uses the control data to submit a command with a digital signature to the respective memory device, which verifies the digital signature before executing the command.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] At least some embodiments disclosed herein relate generally to computer security, and more specifically, but not by way of limitation, to control of secure operation of memory devices. BACKGROUND

[0002] A memory sub-system can include one or more memory devices that store data. The memory devices can be, for example, non-volatile memory devices and volatile memory devices. Generally, a host system can utilize a memory sub-system to store data at and retrieve data from the memory devices. SUMMARY

[0003] In one aspect, the present application provides a method comprising: establishing, by a server system, a secure authenticated connection with a client computer system; receiving, in the server system from the client computer system via the connection, a request having a batch identifier, the batch identifier configured in the server system to identify a batch of a plurality of memory devices; determining, based on data stored in the server system, that the client computer system is entitled to control the plurality of memory devices in the batch; and transmitting, from the server system to the client computer system via the connection, a response to the request, the response containing control data for each respective memory device in the batch, the control data based at least on an encryption key stored in the server system in association with the respective memory device, wherein the client computer system will use the control data to submit a command having a first digital signature to the respective memory device, the respective memory device verifying the first digital signature before executing the command.

[0004] In another aspect, the present application provides a computing system comprising: a memory storing an encryption key of a memory device and data indicating a permission of a client computer system to control the memory device; and at least one processor configured via a set of instructions to: establish a secure authenticated connection with the client computer system; receive, from the client computer system via the connection, a request having a batch identifier, the batch identifier configured in the server system to identify a batch of a plurality of memory devices; determine, based on data stored in the computing system, that the client computer system is entitled to control the plurality of memory devices in the batch; and transmit, to the client computer system via the connection, a response to the request, the response containing control data for each respective memory device in the batch, the control data based at least on an encryption key stored in the server system in association with the respective memory device, wherein the client computer system will use the control data to submit a command having a first digital signature to the respective memory device, the respective memory device verifying the first digital signature before executing the command.

[0005] In another aspect, the present application provides a non-transitory computer storage medium storing instructions that, when executed by a computing system, cause the computing system to perform a method, the method comprising: establishing, by the computing system, a secure authenticated connection with a client computer system; receiving, in the computing system from the client computer system via the connection, a request having a batch identifier, the batch identifier configured in the computing system to identify a batch of a plurality of memory devices; determining, based on data stored in the computing system, that the client computer system is qualified to control the plurality of memory devices in the batch; and transmitting, by the computing system to the client computer system via the connection, a response to the request, the response containing control data for each respective memory device in the batch, the control data based at least on an encryption key associated with the respective memory device stored in the computing system, wherein the client computer system will use the control data to submit a command having a first digital signature to the respective memory device, the respective memory device verifying the first digital signature before executing the command. BRIEF DESCRIPTION OF DRAWINGS

[0006] Embodiments are illustrated by way of example, and not by way of limitation, in the figures of the accompanying drawings in which like reference numerals refer to similar elements.

[0007] Figure 1 A server system configured to control memory devices is shown in accordance with one embodiment.

[0008] Figure 2 An example computing system having a memory subsystem in accordance with some embodiments of the present disclosure is illustrated.

[0009] Figure 3 An integrated circuit memory device having a security manager in accordance with one embodiment is illustrated.

[0010] Figure 4 Techniques to authenticate a memory device in accordance with one embodiment are illustrated.

[0011] Figure 5 Techniques to generate commands to control security operations of a memory device in accordance with one embodiment are illustrated.

[0012] Figure 6 Techniques to group memory devices in batches for transfer of control in accordance with one embodiment are illustrated.

[0013] Figure 7 Techniques to transfer control of memory devices in batches via a computer network in accordance with one embodiment are illustrated.

[0014] Figure 8 A method to control memory devices in accordance with one embodiment is illustrated.

[0015] Figure 9 is a block diagram of an example computer system in which embodiments of the present disclosure can operate. DETAILED DESCRIPTION

[0016] At least some aspects of the present disclosure are directed to a server system configured to control memory devices, such as activating security features of a memory device, transferring permissions instructing a memory device to perform security operations, etc.

[0017] A memory device can be manufactured to include a security manager. The security manager can be activated to enforce control of access to memory cells in the memory device. The access control can be implemented using cryptographic techniques. For example, an entity having a cryptographic key can be vested with a permission instructing a memory device to perform a restricted operation. Examples of such operations can include changing a security setting or configuration of the memory device, reading a portion of memory cells in the memory device, writing data into a portion of memory cells, deleting data from a portion of memory cells, updating data in a portion of memory cells, etc. Securing cryptographic keys used in access control and securing the transfer of permissions is challenging.

[0018] At least some aspects of the present disclosure address the above and other deficiencies and / or challenges by having a server system with a key management server and an access control server.

[0019] The key management server is configured to secure cryptographic keys and computations involving cryptographic keys. The key management server implements operations involving cryptographic keys that are not specific to a memory device and a client. Thus, the functionality of the key management server can be limited, simplified, and / or regularized to improve security.

[0020] The access control server stores client information and is configured to perform computations and / or security tasks that are specific to different clients and / or different memory devices. The access control server is configured between the key management server and client computer systems to which the memory devices connect. A client computer system requests the access control server to provide a response involving a cryptographic key stored in the key management server. The access control server processes the request to determine whether to use the services of the key management server to generate the response. The access control system can act as a gatekeeper and / or proxy for the key management server, thereby rejecting connections from computer systems not on a whitelist, protecting the key management server from denial-of-service (DoS) attacks, and using the cryptographic key management functionality of the key management server to implement client / device-specific operations. By controlling access to the key management server, the access control server can reduce the security risk of the key management server and provide rich services to accommodate various types of memory devices, control activities, and client preferences.

[0021] A memory device can be configured with a unique identity. The identity can be authenticated using cryptographic techniques to prevent counterfeiting of the device and / or tampering of the device to access services and prevent insecure operation. The identity can be generated based on hardware of the memory device and selected data stored in the memory device to represent a combination of hardware and software of the memory device as a whole. Further, the memory device can be configured to provide an entity with one or more cryptographic keys with the authority to request the memory device to perform commands related to security aspects of the memory device. A key management server can be used for authentication of the unique identity of the memory device and transfer of authority.

[0022] For example, a memory device can store a secret for its authentication. During manufacturing of the memory device in a secure facility, a unique device secret (UDS) can be injected in the memory device and stored in a protected and access-controlled region of the memory device. According to standards and / or implementations of the device identity composition engine (DICE) and the robust internet of things (RIoT), a cryptographic key can be generated at boot time based on a combination of the unique device secret (UDS) and other non-secret data stored in the secure memory device. The cryptographic key can then be used as the secret and identity of the memory device.

[0023] During manufacturing of the memory device in a secure facility, a unique device secret (UDS) of the memory device is recorded in a key management server. Subsequently, after shipping of the memory device from the manufacturer of the memory device, the unique device secret (UDS) is not derived, provided, communicated by the memory device outside of a secure section of the memory device and / or outside of the memory device. Since the unique device secret (UDS) is known between the memory device and the key management server, both the memory device 130 and the key management server can perform the same computation of generating a cryptographic key using the unique device secret (UDS). The cryptographic key is derived based at least in part on the authenticated unique device secret (UDS) of the memory device.

[0024] For example, authentication of the memory device can be performed by the memory device having the cryptographic key and thus having the unique device secret and the verification of the unaltered version of the non-secret data stored. The memory device can digitally sign a credential or a message using the cryptographic key. If the digital signature can be verified to have been generated using the cryptographic key, the memory device can be considered to have the cryptographic key and thus the identity representing and associated with the unique device secret.

[0025] Digital authentication of a message can be achieved by applying an encryption function to the message and using an encryption key. For example, symmetric encryption and / or asymmetric encryption can rely on a hash of content that is digitally signed using an encryption key. For example, signing using symmetric encryption can be performed by generating a message authentication code (MAC) (e.g., a hash-based message authentication code (HMAC) or a cipher-based message authentication code (CMAC)). For example, signing using asymmetric encryption can be performed by generating a digital signature (e.g., using a digital signature algorithm (DSA) or an elliptic curve digital signature algorithm (ECDSA)). The encryption function can include hashing and encryption, which are typically used to generate a header that is added to the message for authentication. The header can be a hash digest when symmetric encryption is used, or a digital signature when asymmetric encryption is applied. A recipient of the message can then apply a similar encryption function to the received message and use the encryption key to authenticate that the content of the message was sent by a trusted party that possesses the appropriate encryption key. For example, the encrypted hash value in the header can be decrypted for comparison with a hash value that is computed independently of the message. If there is a match between the hash value computed from the message and the hash value recovered from decrypting the header (e.g., the digital signature and / or hash digest), then the integrity of the message can be confirmed in view of the hash value; and the header can be considered to have been generated using the encryption key.

[0026] An encryption key generated at boot time can be used to sign a credential at boot time and then discarded for security. Alternatively, a key generated at boot time can remain in memory to be used later at run time. In some cases, the encryption key used at boot time is referred to as a DICE device ID key, and the key used at run time is referred to as a DICE alias key. In some cases, the device ID private key can be used to sign a credential that includes the alias public key to prove that the alias key was generated by the memory device.

[0027] In some arrangements, at least some of the security features of a memory device are initially deactivated when the memory device is shipped from a facility that manufactures the memory device to an original equipment manufacturer (OEM) of a computing device in which the memory device is installed. A command can be provided to the memory device to activate the inactive security features.

[0028] Privileges with a command accepted by a memory device for execution can be associated with an encryption key. When the memory device verifies that a command is digitally signed via a correct encryption key, the memory device executes the command; otherwise, the memory device can reject or ignore the command. Various commands to activate or deactivate security features or to read, write, update, delete, and / or modify a secure section of memory cells can be configured to require privileges based on the associated encryption key.

[0029] For example, a memory device is configured to store an encryption key for authentication of permissions for an entity when a command is requested to be executed by the memory device. Permissions can be checked by using the encryption key to verify that a command is signed using a corresponding encryption key. When symmetric encryption is used, a command will be signed using the same encryption key stored in the memory device for verification of permissions. When asymmetric encryption is used, a command will be signed using a private key associated with a public key stored in the memory device for verification of permissions.

[0030] At least some permissions to operate a memory device can be initially provided to a manufacturer of the memory device. For example, a memory device can be manufactured to store a public key of the manufacturer to allow permissions to be checked by the memory device through verification of a digital signature applied on a command using a corresponding private key of the manufacturer. Alternatively, when symmetric encryption is used, the memory device is manufactured to store a secret encryption key known to the memory device and the manufacturer for digital signature verification.

[0031] Permissions can be transferred from a manufacturer of a memory device to another entity, such as a manufacturer of a computing device in which the memory device is installed. The transfer can be accomplished by replacing a corresponding encryption key stored in the memory device, or by providing a secret key that can be used to sign a command.

[0032] An access control server can use the services of a key management server to securely authenticate an identity of a memory device, sign a command requiring permissions, and / or transfer permissions.

[0033] For example, a set of permissions can be assigned to an entity considered as an owner of a memory device. Owner permissions can be authenticated via an encryption key stored within the memory device. Examples of such permissions can be required for activating security features of the memory device, updating an identity of the memory device (e.g., based on updated non-secure data stored in the memory device), and transferring owner permissions to another entity, such as a manufacturer of a computing device in which the memory device is installed. A current owner of the memory device can digitally sign a privileged command to request that the command be executed in the memory device.

[0034] Ownership permissions can further be required for deactivating selected security features, managing encryption keys in the memory device used to authenticate users authorized to use one or more secure sections in the memory device, and / or managing an identity of the memory device and / or a computing device generated based at least in part on a unique device secret of the memory device.

[0035] Figure 1A server system 102 configured to control a memory device is shown in accordance with one embodiment. The server system 102 includes a key management server 103 and an access control server 101.

[0036] In Figure 1 The key management server 103 is configured to store data associating an encryption key 124 with a unique identifier 122.

[0037] For example, the encryption key 124 can be configured for use in operation of a security manager 113 of the memory device 130. The security manager 113 can have a unique device secret (UDS) recorded into the key management server 103 during manufacture of the memory device 130 in a secure facility. Encryption operations that indicate that the memory device 130 has a unique device secret (UDS) can be considered as authentic verification of the memory device 130.

[0038] The encryption key 124 stored in the key management server 103 for the memory device 130 can include a unique device secret (UDS). In addition, the encryption key 124 can include data that can be combined with the unique device secret (UDS) to produce a derived encryption key 124. Such data for producing the derived encryption key 124 can include non-secret data, such as a hash value obtained by applying an encryption hash function to a set of data and / or instructions stored or to be stored in the memory device 130. The encryption key 124 can include the derived encryption key 124 produced using the unique device secret (UDS) and the non-secret data. The memory device 130 and the key management server 103 are configured to produce the same derived encryption key 124 based on the unique device secret (UDS) and other data (e.g., non-secret data). Since the memory device 130 and the key management server 103 can independently produce the same derived key, no communication of the unique device secret (UDS) outside of the memory device 130 and the key management server 103 is performed for authentication of the identity of the memory device 130. Such an arrangement improves security.

[0039] The memory device 130 can demonstrate that it has a unique device secret (UDS) known to the key management server 103 by exhibiting that it has a secret encryption key 124 that is derived based at least in part on the unique device secret (UDS) of the memory device 130. For example, the secret encryption key can be used to generate a digital signature that is applied over a message; and the key management server 103 can use a corresponding key to verify that a digital signature was applied using a secret encryption key that was derived from the unique device secret (UDS) of the memory device 130. The corresponding key can be the same secret encryption key 124 using symmetric encryption, or a public key that corresponds to the secret, a private key using asymmetric encryption. The digital signature can be in the form of a hash-based message authentication code (HMAC), or in the form of an encrypted hash of the message being signed.

[0040] In general, a secret key can be a symmetric encryption key used in symmetric encryption in which both encryption and decryption are configured to use the same key. Alternatively, a secret key can be one of a pair of keys used in asymmetric encryption in which encryption performed using one key will be decrypted using the other key but not the same key used in encryption; and it is substantially infeasible to determine one key from the other key of the pair. Thus, one of the pair of keys can be used as a secret and thus as a private key; and the other key can be revealed as a public key. An entity that has the public key, but not the private key, can verify whether ciphertext was generated using the corresponding private key.

[0041] The memory device 130 can include a unique identifier (UID) 122 that uniquely identifies the memory device 130 from other memory devices in the population. For example, the unique identifier (UID) 122 of the memory device 130 can include a manufacturer part number (MPN) of the memory device 130 and / or a serial number of the memory device 130. For example, the unique identifier (UID) 122 of the memory device 130 can include a public key of a pair of asymmetric encryption keys generated based at least in part on the unique device secret.

[0042] After the memory device 130 is connected to the client computer system 105, the client computer system 105 can initiate one or more operations that depend on the encryption key 124 stored in the key management server 103 in association with the unique identifier (UID) 122 of the memory device 130.

[0043] For example, the client computer system 105 can request verification of the identity of the memory device 130 as represented by a unique device secret (UDS) or secret key of the memory device 130. The client computer system 105 can request the memory device 130 to provide identity data including a unique identifier (UID) 122 of the memory device 130 and a digital signature applied to a message included in the identity data using a secret key of the memory device 130. For example, the message can include the unique identifier (UID) 122, an encrypted random number, and a counter value. The identity data can be transmitted to the key management server 103 for authentication using a corresponding encryption key 124 associated with the unique identifier (UID) 122 of the memory device 130.

[0044] In Figure 1 In systems of the present disclosure, an access control server 101 is configured between the client computer system 105 and the key management server 103. The access control server 101 stores client entitlement data 127 and memory device entitlement data 129.

[0045] For example, the client entitlement data 127 can include a whitelist of Internet protocol (IP) addresses of client computer systems (e.g., 105,..., 106) that are permitted to access functionality of the key management server 103. When a computer system that is not on the whitelist sends a request to the access control server 101, the access control server 101 can discard or ignore the request. The access control server 101 can be configured to prevent denial-of-service (DoS) attacks on the key management server 103.

[0046] Figure 1 Use of one access control server 101 configured to allow a set of client computer systems (e.g., 105,..., 106) to use functionality of the key management server 103 is illustrated. In general, multiple access control servers 101 can be configured to allow different sets of client computer systems to access the key management server 103. In some embodiments, the client computer system 105 can use one or more of multiple access control servers (e.g., 101) to access functionality of the key management server 103.

[0047] The access control server 101 and the client computer system 105 can establish a secure authentication connection 201 via an unsecured communication medium such as the Internet. For example, the access control server 101 is configured to authenticate the identity of the client computer system 105 based on the credentials 121 of the client computer system 105; and the client computer system 105 is configured to authenticate the identity of the access control server 101 based on the credentials 123 of the access control server 101. For example, a public key of the access control server 101 can be used by the client computer system 105 to verify that the access control server 101 has a private key associated with the public key; and a public key of the client computer system 105 can be used by the access control server 101 to verify that the client computer system 105 has a private key associated with the public key. The client computer system 105 and the access control server 101 can negotiate a session key for encryption of messages transmitted between the client computer system 105 and the access control server 101 during a communication session.

[0048] The memory device entitlement data 129 stored in the access control system 101 indicates whether the client computer system 105 has a legitimate reason to access the key management server 103 for a memory device 130 identified by its unique identifier (UID) 122. Optionally, the entitlement data 129 indicates whether the client computer system 105 has a legitimate reason to access the key management server 103 for one or more memory devices (e.g., 130) without specifically and / or individually identifying the respective memory device (e.g., 130) by its unique identifier. In some implementations, the entitlement data 129 indicates whether the client computer system 105 has a legitimate reason to access the key management server 103 for a particular batch or group of memory devices (e.g., 130) identified using a batch or group identifier.

[0049] For example, if the memory device 130 is purchased by an entity that operates the client computer system 105, the memory device entitlement data 129 indicates that the ownership entitlement to operate the memory device 130 can be transferred to the entity via the client computer system 105. Accordingly, requests to operate on the memory device 130 can be accepted and serviced using the functionality of the key management server 103. For example, such requests can be made to verify the authenticity of the memory device 130, activate security features of the memory device 130, replace some of the encryption keys 124 and / or install some of the encryption keys 124 in the memory device 130, access secure portions of the memory cells 107 of the memory device 130, etc. However, if the unique identifier (UID) 122 of the memory device 130 is not associated with the client computer system 105 in the memory device entitlement data 129, the request can be discarded or denied.

[0050] In some implementations, the key management server 103 and the access control server 101 can also communicate via a non-secure communication medium, such as the Internet. The key management server 103 and the access control server 101 can use their respective credentials (e.g., 123 and 125) to establish a secure authenticated connection 203.

[0051] Optionally, the key management server 103 and the access control server 101 can be connected using a dedicated communication connection and / or configured for improved security within an intranet.

[0052] The access control server 101 can request the key management server 103 to determine whether a digital signature from the memory device 130 is signed using an encryption key 124 derived from a unique device secret of the UID 122 of the memory device 130.

[0053] Optionally, the access control server 101 can request the key management server 103 to generate a digital signature on a message or command.

[0054] For example, the key management server 103 can store a private key representing a current holder of a right to operate the memory device 130; and after verifying that the memory device 130 is authentic and that the client computer system 105 is entitled to request a transfer of the right, the access control server 101 can request the key management server 103 to sign a command using the private key representing the current holder of the right, such as a right to configure secure operations of the memory device 130. The command can be configured to change or replace a portion of data used in the memory device 130 to generate identification data of the memory device 130, change or update a public key of the holder of the right, add or change a public key of an authorized user to perform a restricted operation in a section of the memory cells 107. Examples of the restricted operation include reading, writing, erasing, and / or updating data in a section of the memory cells 107 in the memory device 130.

[0055] The memory device 130 can be used as a storage device and / or a memory module of a host system. Examples of storage devices and memory modules are described below in connection with Figure 2 Generally, a host system can utilize a memory sub-system including one or more components, such as the memory device 130, that store data. The host system can provide data to store at the memory sub-system and can request to retrieve data from the memory sub-system.

[0056] Figure 2 An example computing system 100 including a memory sub-system 110 according to some embodiments of the present disclosure is illustrated. The memory sub-system 110 can include media, such as one or more volatile memory devices (e.g., memory device 140), one or more non-volatile memory devices (e.g., memory device 130), or a combination of these.

[0057] The memory sub-system 110 can be a storage device, a memory module, or a hybrid of a storage device and a memory module. Examples of storage devices include a solid state drive (SSD), a flash drive, a universal serial bus (USB) flash drive, an embedded Multi-Media Controller (eMMC) drive, a Universal Flash Storage (UFS) drive, a secure digital (SD) card, and a hard disk drive (HDD). Examples of memory modules include a dual in-line memory module (DIMM), a small outline DIMM (SO-DIMM), and various types of non-volatile dual in-line memory modules (NVDIMM).

[0058] The computing system 100 can be a computing device, such as a desktop computer, a laptop computer, a network server, a mobile device, a vehicle (e.g., an airplane, a drone, a train, a car, or other transportation vehicle), an Internet of Things (IoT) enabled device, an embedded computer (e.g., an embedded computer included in a vehicle, industrial equipment, or a networked commercial device), or such computing device that includes a memory and a processing device.

[0059] The computing system 100 can include a host system 120 coupled to one or more memory sub-systems 110. Figure 3 One example of a host system 120 coupled to one memory sub-system 110 is described. As used herein, “coupled to” or “coupled with” generally refers to a connection between components that can be an indirect communicative connection or direct communicative connection (e.g., without intervening components), whether wired or wireless, including connections such as electrical, optical, magnetic, etc.

[0060] The host system 120 can include a processor chipset (e.g., processing device 118) and a software stack executed by the processor chipset. The processor chipset can include one or more cores, one or more caches, a memory controller (e.g., controller 116) (e.g., NVDIMM controller), and a storage protocol controller (e.g., PCIe controller, SATA controller). The host system 120 uses the memory sub-system 110, for example, to write data to and read data from the memory sub-system 110.

[0061] The host system 120 can be coupled to the memory sub-system 110 via a physical host interface. Examples of a physical host interface include, but are not limited to, a Serial Advanced Technology Attachment (SATA) interface, a Peripheral Component Interconnect Express (PCIe) interface, a Universal Serial Bus (USB) interface, Fibre Channel, a Serial Attached SCSI (SAS) interface, a Double Data Rate (DDR) memory bus interface, a Small Computer System Interface (SCSI), a Dual In-line Memory Module (DIMM) interface (e.g., a DIMM socket interface that supports Double Data Rate (DDR)), an Open NAND Flash Interface (ONFI), a Double Data Rate (DDR) interface, a Low Power Double Data Rate (LPDDR) interface, or any other interface. The physical host interface can be used to transfer data between the host system 120 and the memory sub-system 110. When the memory sub-system 110 is coupled with the host system 120 by a PCIe interface, the host system 120 can further utilize a NVM Express (NVMe) interface to access components (e.g., memory devices 130). The physical host interface can provide an interface for passing control, address, data, and other signals between the memory sub-system 110 and the host system 120. Figure 2The memory sub-system 110 is illustrated as an example. In general, the host system 120 can access multiple memory sub-systems via the same communication connection, multiple separate communication connections, and / or a combination of communication connections.

[0062] The processing device 118 of the host system 120 can be, for example, a microprocessor, a central processing unit (CPU), a processing core of a processor, an execution unit, etc. In some cases, the controller 116 can be referred to as a memory controller, a memory management unit, and / or an initiator. In one example, the controller 116 controls communications over a bus coupled between the host system 120 and the memory sub-system 110. In general, the controller 116 can send commands or requests to the memory sub-system 110 to access the memory devices 130, 140. The controller 116 can further include interface circuitry to communicate with the memory sub-system 110. The interface circuitry can convert responses received from the memory sub-system 110 into information for the host system 120.

[0063] The controller 116 of the host system 120 can communicate with the controller 115 of the memory sub-system 110 to perform operations such as reading data, writing data, or erasing data at the memory devices 130, 140, and other such operations. In some cases, the controller 116 is integrated within the same package as the processing device 118. In other cases, the controller 116 is separate from the package of the processing device 118. The controller 116 and / or the processing device 118 can include hardware such as one or more integrated circuits (ICs) and / or discrete components, a buffer memory, a cache memory, or a combination thereof. The controller 116 and / or the processing device 118 can be a microcontroller, a special-purpose logic circuitry (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.), or another suitable processor.

[0064] The memory devices 130, 140 can include any combination of different types of non-volatile and / or volatile memory components. Volatile memory devices (e.g., the memory devices 140) can be, but are not limited to, random access memories (RAMs) such as dynamic random access memories (DRAMs) and synchronous dynamic random access memories (SDRAMs).

[0065] Some examples of non-volatile memory components include negative- AND (NAND) type flash memory and in-place write memory, such as three-dimensional cross-point ("3D cross-point") memory. Cross-point arrays of non-volatile memory can perform bit storage based on changes in bulk resistance in conjunction with a stackable cross-gridded data access array. Additionally, cross-point non-volatile memory can perform in-place write operations, where a non-volatile memory cell can be programmed without prior erasure of the non-volatile memory cell, as compared to many flash-based memories. NAND type flash memory includes, for example, two-dimensional NAND (2D NAND) and three-dimensional NAND (3D NAND).

[0066] Each of the memory devices 130 can include one or more arrays of memory cells. One type of memory cell, such as a single-level cell (SLC), can store one bit per cell. Other types of memory cells, such as a multi-level cell (MLC), a triple-level cell (TLC), a quad-level cell (QLC), and a penta-level cell (PLC), can store multiple bits per cell. In some embodiments, each of the memory devices 130 can include one or more arrays of memory cells, such as SLC, MLC, TLC, QLC, PLC, or any combination of these. In some embodiments, a particular memory device can include SLC, MLC, TLC, QLC, and / or PLC portions of memory cells. The memory cells of the memory devices 130 can be grouped into pages, which can refer to logical units of the memory device used to store data. For some types of memory (e.g., NAND), pages can be grouped to form blocks.

[0067] Although non-volatile memory devices are described, such as 3D cross-point type and NAND type memory (e.g., 2D NAND, 3D NAND), the memory devices 130 can be based on any other type of non-volatile memory, such as read-only memory (ROM), phase change memory (PCM), self-selecting memory, other chalcogenide-based memory, ferroelectric transistor random access memory (FeTRAM), ferroelectric random access memory (FeRAM), magnetic random access memory (MRAM), spin-transfer torque (STT)-MRAM, conductive-bridge RAM (CBRAM), resistive random access memory (RRAM), oxide-based RRAM (OxRAM), or negative (NOR) flash memory and electrically erasable programmable read-only memory (EEPROM).

[0068] The memory sub-system controller 115 (or, for simplicity, the controller 115) can communicate with the memory devices 130 to perform operations, such as reading data, writing data, or erasing data at the memory devices 130, and other such operations (e.g., in response to commands scheduled by the controller 116 on a command bus). The controller 115 can include hardware, such as one or more integrated circuits (ICs) and / or discrete components, a buffer memory, or a combination thereof. The hardware can include digital circuitry with dedicated (i.e., hard-coded) logic to perform the operations described herein. The controller 115 can be a microcontroller, special purpose logic circuitry (e.g., a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.), or another suitable processor.

[0069] The controller 115 can include a processing device 117 (e.g., a processor) configured to execute instructions stored in local memory 119. In the illustrated example, the local memory 119 of the controller 115 includes embedded memory configured to store instructions for performing various processes, operations, logic flows, and routines that control the operation of the memory sub-system 110, including handling communications between the memory sub-system 110 and the host system 120.

[0070] In some embodiments, the local memory 119 can include memory registers that store memory pointers, fetched data, and the like. The local memory 119 can also include read-only memory (ROM) for storing microcode. Although the local memory 119 is illustrated as being internal to the controller 115, in some embodiments, the local memory 119 can be external to the controller 115. Figure 2 In some embodiments, the local memory 119 can include memory registers that store memory pointers, fetched data, and the like. The local memory 119 can also include read-only memory (ROM) for storing microcode. Although the local memory 119 is illustrated as being internal to the controller 115, in some embodiments, the local memory 119 can be external to the controller 115.

[0071] In general, the controller 115 can receive commands or operations from the host system 120 and can convert the commands or operations into instructions or appropriate commands to achieve the desired access to the memory devices 130. The controller 115 can be responsible for other operations, such as wear leveling operations, garbage collection operations, error detection and error-correcting code (ECC) operations, encryption operations, caching operations, and address translations between a logical address (e.g., a logical block address (LBA), a name space) and a physical address (e.g., a physical block address) associated with the memory devices 130. The controller 115 can further include host interface circuitry to communicate with the host system 120 via the physical host interface. The host interface circuitry can convert commands received from the host system into command instructions to access the memory devices 130, as well as convert responses associated with the memory devices 130 into information for the host system 120.

[0072] The memory sub-system 110 can also include additional circuitry or components not shown. In some embodiments, the memory sub-system 110 can include a cache or buffer (e.g., DRAM) and address circuitry (e.g., row and column decoders) that can receive and decode addresses from the controller 115 to access the memory devices 130.

[0073] In some embodiments, the memory devices 130 include a local media controller 150 that operates in conjunction with the memory sub-system controller 115 to perform operations on one or more memory cells of the memory devices 130. An external controller (e.g., the memory sub-system controller 115) can externally manage the memory devices 130 (e.g., perform media management operations on the memory devices 130). In some embodiments, the memory devices 130 are managed memory devices that are original memory devices combined with a local controller (e.g., the local media controller 150) for media management within the same memory device package. An example of a managed memory device is a managed NAND (MNAND) device.

[0074] The controller 115 and / or the memory devices 130 can include a security manager 113 configured to control access to the memory cells 107 in the memory devices 130. In some embodiments, the controller 115 in the memory sub-system 110 and / or the local media controller 150 can include at least a portion of the security manager 113. In other embodiments, or in combination, the controller 116 and / or the processing device 118 in the host system 120 can include at least a portion of the security manager 113. For example, the controller 115, the controller 116, and / or the processing device 118 can include logic circuitry that implements the security manager 113. For example, the controller 115 or the processing device 118 (e.g., a processor) of the host system 120 can be configured to execute instructions stored in a memory for performing the operations of the security manager 113 described herein. In some embodiments, the security manager 113 is implemented in an integrated circuit chip that is disposed in the memory sub-system 110. In other embodiments, the security manager 113 can be part of firmware of the memory sub-system 110, an operating system, a device driver, or an application program of the host system 120, or any combination thereof.

[0075] For example, when the memory devices 130 are initially shipped from the manufacturer of the memory devices, the memory devices 130 are configured with the manufacturer’s encryption key to provide the manufacturer with the authority to configure security operations of the memory devices 130. To facilitate installation of the memory devices 130 in which the security manager 113 is implemented, the security manager 113 can be configured to perform a security operation to update the manufacturer’s encryption key to a new encryption key of a new owner of the memory devices 130. Figure 2Upon authentication of the identity of the memory device 130, the transfer can include activating security features of the memory device 130 via the access control server 101. Optionally, the authority can be transferred to the manufacturer of the computing system 100 by replacing an encryption key that controls authority to configure security operations of the memory device 130. After activation, the security manager 113 can control software / firmware installed in the memory device 130 to operate the computing system 100 and generate identity data that represents not only the memory device 130 but also the computing system 100 with the memory device 130 and other software / hardware components.

[0076] The security manager 113 can construct an identity of the memory device 130 based not only on its unique device secret (UDS) but also on instructions stored in the memory device 130 for execution by the processing device 118 of the host system 120. For example, the security manager 113 can determine an encrypted hash value of a set of instructions to be executed during a boot time of the computing system 100. The security manager 113 can check the integrity of the set of instructions by comparing the hash value computed at the boot time with a pre-computed hash value. If the two hash values agree with each other, the set of instructions can be considered as not yet tampered and / or corrupted. Accordingly, the set of instructions can be executed in the computing system 100 to further implement security operations of the security manager 113 and / or boot operations of the computing system 100. Optionally, the verification of the hash value can be part of an authentication of the computing system 100 as an end point using a credential generated by executing at least a portion of the set of instructions during the boot time of the computing system 100.

[0077] For example, the identifier of the memory device 130 can be generated based at least in part on the hash value of the set of instructions. Accordingly, when the identifier of the memory device 130 is verified by authenticating using the credential, the hash value of the set of instructions can be considered as verified to be correct; and the set of instructions used to generate the credential and boot the computing system 100 has not been tampered and / or corrupted.

[0078] Execution of the set of instructions in the computing system 100 causes the computing system 100 to determine the identities of other components of the computing system 100, such as an identifier of the processing device 118, an identifier of the controller 116, an identifier of the memory subsystem controller 115, an identifier of the memory device 140, and / or an identifier of a software program (e.g., an operating system, a device driver, an application program, etc.). The set of identifiers of components in the computing system 100 with the memory device 130, including the identifier of the memory device 130, can be combined to produce an encryption key used to sign a credential. The credential is based on a monotonically increasing counter value that is incremented each time the computing system 100 is booted and / or each time the memory device 130 performs a secure operation. Optionally, the credential can exhibit some of the identifiers used to produce the encryption key used to sign the credential. The credential can also include a DICE alias public key that is produced at the time of boot.

[0079] The credential can be communicated to a remote computer (e.g., an access control server 101) via a computer network for authentication. When the credential is authenticated, it can be concluded that the integrity of the set of instructions used to produce the credential is intact, and that the computing system 100 has the memory device 130 combined with the set of components represented by the identifiers used to produce the encryption key used to sign the credential. In addition, the monotonically counter value included in the credential allows its recipient to verify that it is recently produced, and thus it can be trusted. The credential holds the DICE alias public key, which can be compared to a DICE alias public key (e.g., stored on the remote computer, or computed just in time for its use in response to the credential). If the two keys match, then the remote computer can trust other messages sent by the endpoint and signed with the DICE alias private key.

[0080] Figure 3 An integrated circuit memory device with a security manager is described in accordance with one embodiment. For example, Figure 2 The memory device 130 in the memory subsystem 110 and / or the client computer system 105 connected to Figure 1 The memory device 130 in the memory subsystem 110 and / or the client computer system 105 connected to Figure 3 may be implemented using the integrated circuit memory device 130 of

[0081] The integrated circuit memory device 130 can be enclosed in a single integrated circuit package. The integrated circuit memory device 130 includes a plurality of memory regions 131, 132, 133 that can be formed in one or more integrated circuit dies. A typical memory cell in the memory regions 131, 132, 133 can be programmable to store one or more bits of data.

[0082] The local media controller 150 can include at least a portion of the security manager 113 configured to control security of access to at least one of the memory regions 131, 132, 133.

[0083] For example, the security manager 113 can use the access control key 153 to enforce a permission for a type of operation. When a request for such a type of operation is received in the integrated circuit memory device 130, the security manager 113 can use the access control key 153 to verify whether the request is digitally signed with a corresponding encryption key. For example, a requester can digitally sign a request or a challenge message with an encryption key, such that the digital signature can be verified using the access control key 153. When the digital signature verification performed using the access control key 153 is successful, the request operation is performed by the memory device 130. Otherwise, the request can be denied or ignored.

[0084] For example, the permission can be a grant to write data into a memory region (e.g., 131) to prevent tampering of data stored in the memory region, such as a boot loader 171 of the computing system 100, firmware / software / operating system of the computing system 100, security settings of the memory device 130, etc.

[0085] The memory device 130 can have a unique identifier 151 that identifies the memory device 130 and a secret encryption key 155 that indicates a reliability of the memory device 130 with the unique identifier 151. For example, the encryption key 155 can be generated from a unique device secret (UDS) of the memory device 130 and other data, such as information of non-secret data stored in a memory region (e.g., 131) and / or information of other components of the computing system 100.

[0086] The integrated circuit memory device 130 has a communication interface 147 to receive a command with an address 135 from the controller 115 of the memory subsystem 110. In response to the address 135 identifying a memory region 131 that requires access control, the security manager 113 uses the access control key 153 to perform an encryption operation to verify whether the request is from a requester with a corresponding encryption key that represents authorization to access. After verification of authorization, grant, or permission to access, the memory device 130 can provide memory data retrieved from the memory region 131 using an address decoder 141. The address decoder 141 of the integrated circuit memory device 130 converts the address 135 into control signals to select a group of memory cells in the integrated circuit memory device 130; and the local media controller 150 of the integrated circuit memory device 130 performs operations to determine the memory data stored in the memory cells at the address 135.

[0087] Memory region 131 can store a boot loader 171. At boot time, security manager 113 can measure boot loader 171 by computing a cryptographic hash value of boot loader 171. The cryptographic hash value of boot loader 171 can be used to produce identification data of integrated circuit memory device 130 and / or computing system 100. Boot loader 171 (and / or an operating system or device driver, or a security application) can include instructions to implement a portion of security manager 113. During boot time, the instructions can determine a configuration of computing system 100, where integrated circuit memory device 130 is a component.

[0088] For example, Figure 2 The configuration of computing system 100 can include software / firmware components of memory subsystem 110. The software / firmware can be stored in other memory devices (e.g., 140) or in memory device 130 in memory region 133. For example, instructions 173 in memory region 133 in integrated circuit memory device 130 can include an operating system of computing system 100, a device driver, firmware, and / or a software application. Some of the main software / firmware components of memory subsystem 110 can be stored outside of security manager 113's access control and / or outside of integrated circuit memory device 130. Identifiers of the software / firmware components can include component identifiers, version numbers, serial numbers, and / or cryptographic hash values of the software / firmware components.

[0089] Figure 2 The configuration of computing system 100 can include hardware components of memory subsystem 110, such as processing device 118 and / or controller 116. Host system 120 can further include peripheral devices, such as a network interface card, a communication device, another memory subsystem, etc. Identifiers of the hardware components can include serial numbers, addresses, identification numbers, etc.

[0090] The configuration information of computing system 100, including unique identifier 151, can be used to produce secret cryptographic key 155 to sign a credential generated using at least a value from a monotonic counter. The credential identifies the counter value, the unique identifier 151 of memory device 130, and / or the unique identifier of computing system 100 in which memory device 130 is installed.

[0091] Key management server 103 can be used to verify the authenticity of the credential, since key management server 103 has a unique device secret (UDS) after manufacturing memory device 130 and can produce the same cryptographic key (e.g., 155) produced by memory device 130 without requiring communication of the secret over a communication channel.

[0092] In one embodiment of the method to control a memory device, a first computer system (e.g., access control server 101) establishes a secure authenticated connection 201 with a client computer system 105.

[0093] For example, to establish the secure authenticated connection 201, the access control server 101 receives a first credential 121 from the client computer system 105. The first credential 121 indicates an identity of the client computer system 105; and the access control server 101 verifies the first credential 121. For example, the access control server 101 can store a public key of the client computer system 105 and use the public key to verify that the first credential 121 is signed with a private key corresponding to the public key.

[0094] Similarly, to establish the secure authenticated connection 201, the access control server 101 provides a second credential 123 to indicate an identity of the access control server 101. The client computer system 105 is configured to verify the second credential 123 prior to establishing the secure authenticated connection 201.

[0095] Establishment of the secure authenticated connection 201 can include establishing a session key to encrypt data transmitted via the secure authenticated connection 201.

[0096] To reduce the impact of denial of service (DoS) attacks on the performance of the access control server 101, the access control server 101 can store a list of Internet protocol (IP) addresses of client computer systems (e.g., 105,..., 106). The access control server 101 can determine whether to establish the secure authenticated connection 201 based at least in part on whether the address of the client computer system 105 is in the list.

[0097] The first computer system (e.g., access control server 101) receives a request from the client computer system 105 via the connection 201 regarding a memory device 130.

[0098] The request can include identification data of the memory device 130.

[0099] The first computer system (e.g., access control server 101) determines that the client computer system 105 is qualified to operate the memory device 130 based on data stored in the first computer system.

[0100] For example, the data can include client entitlement data 127 indicating that the operator of the client computer system 105 is a new owner of the memory device 130. In one implementation, data is stored associating a unique identifier (e.g., 111) of a memory device (e.g., 130) with client entitlement data 127 for a client computer system 105 that is entitled to control the memory device (e.g., 130) as an owner or manufacturer of the endpoint in which the memory device (e.g., 130) is installed. Additional client-specific data is stored at the time of key retrieval from the key management server 103 for logging, reporting, and invoice generation to facilitate transfer of owner entitlement and / or other entitlements. Separation of access control data and invoice generation data allows the use of the access control server 101 to retrieve an encryption key representing the entitlement to operate a memory device (e.g., 130) from the key management server 103 without requiring the access control server 101 to have any personally identifiable information about the client requesting the encryption key or the client computer system making the request. Thus, the arrangement can provide client partner anonymity when making requests via the access control server 101 while still ensuring that only client computer systems 105 with the correct credentials will be allowed access.

[0101] For example, the data can include memory device entitlement data 129 indicating whether the operator of the client computer system 105 has purchased an entitlement to use a security feature of the memory device 130.

[0102] In response to determining that the client computer system 105 is entitled to operate or control the memory device 130, the first computer system (e.g., the access control server 101) communicates with the second computer system (e.g., the key management server 103) to generate a response to the request. The response is generated using at least an encryption key 124 stored in the second computer system (e.g., the key management server 103) in association with the unique identifier 122 of the memory device 130. The response is generated via the second computer system (e.g., the key management server 103) performing an operation using the encryption key 124 without transmitting the encryption key 124 outside of the second computer system (e.g., the key management server 103). For example, the key management server 103 can have a hardware security module (HSM) to ensure the security of the encryption key 124 while it is stored and used in the key management server 103. A hardware security module (HSM) is not necessary in the access control server 101 for the security of the encryption key 124 since the encryption key 124 is not provided to the access control server 101. Alternatively, the access control server 101 and the key management server 103 can be implemented in the same computer system.

[0103] For example, the request received from the client computer system 105 can include identification data of the memory device 130; and the response can include an indication of whether the memory device 130 is authentic according to the cryptographic key 124.

[0104] For example, the cryptographic key 124 can be a secret key that is independently and respectively generated by the second computer system (e.g., the key management server 103) and by the memory device 130 based on a unique device secret of the memory device 130. The unique device secret of the memory device 130 is recorded and stored during manufacturing of the memory device 130 in the second computer system (e.g., the key management server 103). Subsequently, the unique device secret of the memory device 130 is respectively maintained as a secret within the memory device 130 and within the key management server 103 and is not communicated / revealed outside of the memory device 130 and the key management server 103 for improved security.

[0105] Optionally, the first computer system (e.g., the access control server 101) communicates with the second computer system (e.g., the key management server 103) to establish a separate secure authenticated connection 203 therebetween to generate the response. For example, the access control server 101 can request the key management server 103 to determine whether the identification data of the memory device 130 is derived from the unique device secret of the memory device 130 by cryptographic computation.

[0106] For example, the response can include a command that is executable in the memory device 130 to transfer authority to an operator of the client computer system 106, and / or to activate at least one security feature of the memory device 130. For example, the command includes a digital signature applied on the command using a cryptographic key of a current holder of the authority; and after the digital signature is verified by the memory device 130, the command can be executed in the memory device 130.

[0107] For example, the response can include a cryptographic key that can be used to apply a digital signature on a command, such that after the digital signature is verified in the memory device 130, the command can be executed by the memory device 130. When the command does not have a valid digital signature, the memory device 130 can reject or ignore the command.

[0108] The server system 102 discussed above can be used to provide authority to the client computer system 105 to control security aspects of the memory device 130 without exposing the secret cryptographic key 124 in plaintext outside of the memory device 130 and the key management server 103 and without trusting the client computer system 105 in securing the secret cryptographic key 124.

[0109] Figure 4The techniques to authenticate a memory device according to one embodiment are described. For example, through the authentication operation, a session key can be established to secure communications between the key management server 103 and the memory device 130 without trusting the client computer system 105 in handling security to protect the secrets of the memory device 130.

[0110] In Figure 4 The client computer system 105 can send a request 231 for identification data of the memory device 130 to the memory device 130.

[0111] The request 231 can include an encrypted nonce 227. For example, the encrypted nonce 227 can be generated by the server system 102 in response to a request from the client computer system 105, or generated by the client computer system 105 and shared with the server system 102 for the request 231. Alternatively, the memory device 130 can generate the encrypted nonce 227 and provide a corresponding response 233 including the encrypted nonce 227 in response to the request 231.

[0112] In response to the request 231 for identification data of the memory device 130, the memory device 130 provides a response 233 including a message that identifies a unique identifier (UID) 122 of the memory device 130.

[0113] The digital signature 229 is applied to the message provided in the response using a secret encryption key 124 of the memory device 130. Having the secret encryption key 124 is evidence that the memory device 130 is authentic. For example, the digital signature 229 can include a hash-based message authentication code (HMAC) generated using a message included in the response 233 and the encryption key 124. For example, the encryption key 124 can be used to generate two keys for generating a hash-based message authentication code (HMAC). After one of the two keys is combined with the message to generate a key-modified message, the memory device 130 can apply a cryptographic hash function to the key-modified message to generate a hash value, combine the other key with the hash value to generate another message, and apply a cryptographic hash function (or another cryptographic hash function) to the other message to generate the hash-based message authentication code (HMAC). Alternatively, the digital signature 229 can be generated using other techniques based on a cryptographic hash function and encryption performed using the encryption key 124, where generally the encryption can use symmetric encryption or asymmetric encryption.

[0114] To protect the response 233 and / or the digital signature 229 from security attacks (e.g., reuse of the response 233 and / or attempts to recover the secret encryption key 124), the digital signature 229 is generated on a message that includes the unique identifier (UID) 122, the counter value 225, and the encrypted nonce 227. The counter value 225 is obtained from a counter 221 in the memory device 130. The value of the counter 221 is monotonically increasing. For example, the counter 221 can be used to store a value that represents a count of requests received for identifying data and / or other data items or operations related to security. Thus, a response containing a counter value 225 that is lower than a previously seen counter value can be considered invalid. The encrypted nonce 227 is used to generate the response 233 once and is discarded by the memory device 130. When the encrypted nonce 227 has been previously provided to the server system 102 or generated by the server system 102, the response 233 does not necessarily explicitly include the encrypted nonce 227 in the response 233.

[0115] The client computer system 105 forwards the response 233 to the server system 102 to request authentication of the memory device 130. Using the unique identifier 122 provided in the response 233, the server system 102 can locate the secret encryption key 124 (or the corresponding public key when asymmetric encryption is used) associated with the unique identifier 122 in the key management server 103. The digital signature 229 can be verified using the encryption key 124 (or the corresponding public key when asymmetric encryption is used).

[0116] For example, the server system 102 can independently compute a hash-based message authentication code (HMAC) that is applied to the message contained in the response 233 and compare the computed result with the corresponding result provided in the digital signature 229. If the results are the same, the server system 102 can conclude that the memory device 130 has the secret encryption key 124 and thus the memory device 130 is reliable. Otherwise, the memory device 130 is not reliable.

[0117] Based on the verification of the digital signature 229, the server system 102 provides a reliability indicator 235 to the client computer 105. The reliability indicator 235 indicates whether the memory device 130 is reliable.

[0118] With the authentication of the memory device 130, the memory device 130 and the server system 102 can establish a session key 223 for communicating with each other in a subsequent communication session. The session can be limited in length by a predetermined time period after the verification of the response 233 or the digital signature 229. After the time period, the session key 223 expires and thus can be destroyed or discarded. Furthermore, a subsequent request for identifying data can end a previous session that started with a previous request for identifying data.

[0119] The session key 223 can be generated based at least in part on a secret known between the server system 102 and the memory device 130 but not available to the communication channel between the server system 102 and the memory device 130.

[0120] For example, the session key 223 can be derived based at least in part on the secret encryption key 124. Further, the session key 223 can be based at least in part on the counter value 225 and / or the cryptographic nonce 227. Optionally, the session key 223 can be based at least in part on the digital signature 229. For example, the digital signature 229 and the encryption key 124 can be combined to generate the session key 223.

[0121] In some implementations, the session key 223 is independent of the digital signature 229; and the digital signature 229 can be generated using the session key 223 derived from the encryption key 124 (or another secret known between the server system 102 and the memory device 130).

[0122] Figure 5 A technique to generate a command to control a security operation of a memory device is described in accordance with one embodiment.

[0123] For example, after using the client privilege data 127 and the memory device privilege data 129 to verify that the client computer system 105 has the privilege to issue the command 239 to the memory device 130, the client computer system 105 can request the server system 102 to provide a digital signature 243 for the command 239.

[0124] After the client computer system 105 sends the request 241 identifying the command 239 and the memory device 130, the server system 102 can generate the digital signature 243 for the command 239 if it is determined that the client computer system 105 has the privilege to control or operate the memory device 130 using the command 239. The request 241 can include a unique identifier 122 of the memory device 130 in which the command 239 is to be executed. For example, the unique identifier 122 can be extracted by the client computer system 105 from the response 233 to the request 231 for identification data of the memory device 130 and / or the reliability indicator 235 provided by the server system 102.

[0125] Similar to the digital signature 229 for the identification data, the digital signature 243 for the command 239 can include a hash-based message authentication code (HMAC) generated from a message to be provided to the memory device 130 in a request 245 and a key associated with the unique identifier 122 of the memory device 130. The key can be as described above with respect to the digital signature 229 for the identification data. Figure 4The session key 223, or the encryption key 124, or another secret key used to control execution of the command 239 in the memory device 130. When the digital signature 243 is based on the session key 223, the digital signature 243 expires when the session key 223 expires, which prevents reuse of the digital signature 243 outside of the session in which the session key 223 is valid.

[0126] Alternatively, the digital signature 243 can be generated based on a cryptographic hash function and encryption performed using symmetric or asymmetric encryption. For example, the digital signature 243 can be a ciphertext of a hash value. The hash value is generated by applying a cryptographic hash function to a message; and the ciphertext is generated by encrypting the hash value using a secret encryption key 124. When symmetric encryption is used, the ciphertext is to be decrypted using the same secret encryption key 124 for verification by the memory device 130 (or independently reproduced by the memory device 130 from a received message's hash value for verification). When asymmetric encryption is used, the ciphertext is to be decrypted using a public encryption key corresponding to a private encryption key 124 for verification by the memory device 130.

[0127] For example, the message provided in the request 245 can include the command 239 and an encryption nonce 247. The encryption nonce 247 is arranged for the command 239 / request 245 and thus is different from the encryption nonce 227 used for transmission of the identification data of the memory device 130.

[0128] For example, in response to the request 241, the server system 102 can generate the encryption nonce 247 and use it to generate the digital signature 243. The encryption nonce 247 can be provisioned for the client computer system 105 to generate the digital signature 243 of the request 245. Alternatively, the client computer system 105 can generate the encryption nonce 247 and provide it to the server system 102 with the request 241. Alternatively, to generate the request 241, the client computer system 105 can request the encryption nonce 247 from the server system 102.

[0129] After the client computer system 105 sends the request 245 with the digital signature 243 obtained from the server system 102, the memory device 130 verifies the digital signature 243 for the message included in the request 245 using a corresponding key. If the digital signature 243 is valid, the memory device 130 executes the command 239; otherwise, the request 245 and / or the command 239 can be rejected or ignored.

[0130] For example, the command 239 can be configured to activate a security feature of the memory device 130.

[0131] For example, the command 239 can be configured to replace the encryption key 124 associated with the unique identifier 122. For example, the new encryption key 124 can be generated using additional non-secret data provided during manufacturing of the computing device in which the memory device 130 is installed but not available when the memory device 130 is being manufactured.

[0132] After execution of the command 239, the memory device 130 provides a response 249 to the server system 102 that can be forwarded by the client computer system 105. The server system 102 can determine whether the response 249 is correct. For example, the memory device 130 can sign the response using the session key 223 for verification by the server system 102.

[0133] In some implementations, the replacement encryption key used to replace the key 124 is independently generated by the memory device 130 and by the server system 102 from a secret (e.g., a unique device secret) and additional data exchanged through the client computer system 105. The additional data can be protected by encryption performed using the session key 223.

[0134] In some implementations, the replacement encryption key 124 is communicated from the memory device 130 to the server system 102 in an encrypted form using the session key 223 generated ciphertext.

[0135] In one embodiment of a method to control a memory device, the server system 102 establishes a secure authenticated connection 201 with the client computer system 105.

[0136] The server system 102 receives a request from the client computer system 105 identifying the memory device 130 via the connection 201.

[0137] For example, the server system 102 receives identification data for the memory device 130 from the memory device 130 via the client computer system 105. The server system 102 verifies the identification data based on a secret for the memory device 130 stored in the server system 102. Based on verification of the identification data, the session key 223 is established and known between the server system 102 and the memory device 130.

[0138] For example, the identification data can include a second message and a second digital signature 229 applied on the second message using a secret encryption key 124 for the memory device 130. The second message can have a unique identifier 122 for the memory device 130, a value 225 from a counter 221 configured in the memory device 130, and a second encrypted nonce 227.

[0139] For example, the session key 223 can be configured to expire in a predetermined length of time from authentication of the identification data. The predetermined length can be configured to allow a few message exchanges between the memory device 130 and the server system 102. Further, a subsequent request for identification data can terminate a current session and start a new session with a new session key. In some implementations, the lifetime of the session key is based on a power cycle event in the memory device 130. When the memory device 130 is powered on from a powered off state, a new session key is generated; and the session key can be valid until a next session key is generated after power off and power on. Optionally, a command can be sent to the memory device 130 to instruct the memory device 130 to generate a new session key.

[0140] The server system 102 determines that the client computer system 105 is entitled to control the memory device 130 based on data stored in the server system 102. For example, the client entitlement data 127 and the memory device entitlement data 129 can be used to determine whether the client computer system 105 is entitled to control the memory device 130.

[0141] The server system 102 generates the first digital signature 243 for the command 239 using at least the cryptographic key 124 stored in the server system in association with the memory device 130.

[0142] For example, the first digital signature 243 is applied to a first message in a request 245 from the client computer system 105 to the memory device 130. The first message includes the command 239 and a first cryptographic nonce 247 that is different from the second cryptographic nonce 227.

[0143] For example, the first digital signature 243 can include a hash-based message authentication code (HMAC) generated from the first message and the cryptographic key 124 (or the session key 223) stored in both the memory device 130 and the server system 102.

[0144] In general, the first digital signature 243 can be generated using the session key 223, the cryptographic key 124 stored in the server system 102 in association with the unique identifier 122 of the memory device 130, or another key, or any combination thereof, using symmetric encryption or asymmetric encryption or a hash-based message authentication code (HMAC).

[0145] The server system 102 transmits the first digital signature 243 to the client computer system 105 via the connection 201.

[0146] The client computer system 105 submits the command 239 with the first digital signature 243 to the memory device 130.

[0147] The memory device 130 verifies the first digital signature 243 prior to executing the command 239.

[0148] For example, when executed in the memory device 130, the command 239 causes the memory device 130 to activate a security feature of the memory device 130.

[0149] For example, when executed in the memory device 130, the command 239 causes the memory device 130 to replace the first encryption key with the second encryption key.

[0150] For example, the second encryption key is generated in the memory device 130 based on a unique device secret (UDS) stored in the memory device 130 and in the server system 102. The server system 102 can generate the second encryption key from the unique device secret (UDS) stored in the server system 102 independent of the memory device 130 and thus avoid the need to transmit the second encryption key between the server system 102 and the memory device 130. Alternatively, the second encryption key can be transmitted between the server system 102 and the memory device 130 in encrypted form using ciphertext generated using the session key 223. Alternatively, the second encryption key can be generated based on the session key 223.

[0151] For example, the session key 223 can be used to encrypt at least a portion of data transmitted from the server system 102 to the memory device 130 via the client computer system 105 for execution of the command 239.

[0152] For example, the session key 223 can be used to decrypt at least a portion of a response generated by execution of the command 239 and transmitted from the memory device 130 to the server system 102 via the client computer system 105.

[0153] For example, the server system 102 can generate a first encrypted nonce 247 for the command 239 and a second encrypted nonce 227 for identifying data. The first encrypted nonce 247 and the second encrypted nonce 227 can be provided to the memory device 130 via the client computer system 105. Alternatively, the client computer system 105 and / or the memory device 130 can generate the first encrypted nonce 247 and the second encrypted nonce 227. For example, an encrypted nonce (e.g., 227 or 247) can be generated using a nonce generator and used once in the generation and verification of one digital signature (e.g., 229 or 243).

[0154] In some cases, it is desirable to transfer control of a collection of memory devices (e.g., 130) from the server system 102 to the client computer system 105 in batch operations. The client computer system 105 can apply control to the memory devices (e.g., 130) while there is no real-time communication channel between the individual memory devices (e.g., 130) and the server system 102.

[0155] In one embodiment, the batch identifier is configured to represent a collection of memory devices (e.g., 130) having different unique identifiers (UIDs) (e.g., 122). The client computer system 105 can use the batch identifier to separately request a collection of control data for the collection of memory devices (e.g., 130). The control data can be used by the client computer system 105 to control or configure security operations of the collection of memory devices (e.g., 130) without further contact with the server system 102, as discussed below.

[0156] Figure 6 Techniques to group memory devices in batches to transfer control are shown in accordance with one embodiment.

[0157] In Figure 6 In the batch identifier 257 is configured in the server system 102 to represent the unique identifiers 122, 252, 254,... of different memory devices (e.g., 130). A collection of memory devices (e.g., 130) is arranged to be controlled by a single entity, such as an operator of the client computer system 105.

[0158] For example, during manufacturing of the memory devices (e.g., 130), the unique device secrets of the memory devices (e.g., 130) are identified in a secure facility and recorded in the key management server 103 with their respective unique identifiers 122, 252, 254. For example, the unique device secrets of the memory devices (e.g., 130) can be encryption keys 124, 251, 253 or secrets used to generate the encryption keys 124, 251, 253.

[0159] Optionally, the memory devices (e.g., 130) can be manufactured to store the batch identifier 257. For example, the batch identifier 257 can be a common portion of the unique identifiers 122, 252, 254 of the memory devices.

[0160] Alternatively, the association of the memory devices (e.g., 130) with the lot identifier 257 is not hardwired in the memory devices (e.g., 130). The server system 102 can store data that associates selected unique identifiers 122, 252,..., 254 of respective memory devices (e.g., 130) with the lot identifier 257.

[0161] After allowing a client entity, such as a manufacturer of a computing device in which the memory devices (e.g., 130) are installed, to control transactions of the memory devices (e.g., 130), the lot identifier 257 can be associated in the server system 102 with a client identifier 259 that represents the client entity. For example, the client entitlement data 127 can include data that indicates that the client entity represented by the client identifier 259 has purchased a lot of memory devices (e.g., 130) represented by the lot identifier 257 and therefore has an entitlement 265 to control the memory devices (e.g., 130) in the lot. A public key 261 of the client entity can be used to authenticate credentials 121 from the client entity operating the client computer system 105 to establish a secure authenticated connection 201 with the server system 102. A list of Internet Protocol (IP) addresses 263 of the client computer system 105 can be used to control requests for secure authenticated connections (e.g., 201).

[0162] After the lot identifier 257 is associated in the server system 102 with the unique identifiers 122, 252,..., 254 and the entitlement 265 of the client identifier 259, the lot identifier 257 can be used by the client computer system 105 to request control data for the entire collection of memory devices (e.g., 130) having different unique identifiers 122, 252,..., 254. The control data can be used by the client computer system 105 to configure security aspects of the memory devices (e.g., 130) as described in Figure 7 In one implementation, the key management server 103 stores data that associates the lot identifier 257 with the unique identifiers 122, 252,..., 254 but does not store data that associates the lot identifier 257 with the client identifier 259; and the access control server 101 stores data that associates the lot identifier 257 with the client identifier 259 but does not store data that associates the lot identifier 257 with the unique identifiers 122, 252,..., 254. Thus, neither the access control server 101 nor the key management server 103 can associate a memory device with a client identifier on itself. The server system 102 with the access control server 101 and the key management server 103 has sufficient data to associate each individual unique identifier (e.g., 122, 252,..., or 254) of a memory device with the client identifier 259.

[0163] Figure 7 Techniques to batch transfer control of memory devices via a computer network are presented in accordance with one embodiment.

[0164] In Figure 7 , the client computer system 105 can establish a secure authenticated connection 201 with the server system 102 in the manner described in Figure 1

[0165] Using the connection 201 with the server system 102, the client computer system 105 can transmit a request 271 containing a batch identifier 257.

[0166] For example, the batch identifier 257 can be retrieved from one of the memory devices (e.g., 130) identified by the batch identifier 257. For example, when the batch identifier 257 is part of the unique identifier 122 of the memory device 130, the request 271 can include the unique identifier 122 to provide the batch identifier 257. Alternatively, when the batch identifier 257 is not stored in the memory device (e.g., 130), the client computer system 105 can obtain the batch identifier 257 from a record of the transaction for retrieving the memory device (e.g., 130).

[0167] After verifying that the client computer system 105 is entitled to control the memory device identified by the batch identifier 257, the server system 102 provides a response 273 to the client computer system 105. The response 273 includes control data 272, 281,..., 283 for the respective unique identifier 122, 252,..., 254 of the memory device (e.g., 130) represented by the batch identifier 257.

[0168] After the client computer system 105 obtains the response 273, the client computer system 105 can control the memory device (e.g., 130) represented by the batch identifier 257 without further communication with the server system 102.

[0169] For example, after receiving the response 273, the client computer system 105 can send a request 231 for identification data of the memory device 130, as described in Figure 4 In response, the memory device 130 can generate a response 233 containing the unique identifier 122 of the memory device 130. Based on the unique identifier 122 provided in the response 233, the client computer system 105 can select the corresponding control data 272 from the response 273 for configuring security aspects of the memory device 130.

[0170] ​Optionally, the control data 272 provided by the server system 102 for the unique identifier 122 includes data that can be used to verify the digital signature 229 included in the response 233. For example, the control data 272 can include an encrypted nonce 227 to be transmitted with the request 231 for identification data of the memory device 130. Further, when the digital signature 229 is to be verified using the same encryption key 124 used to generate the digital signature 229, the control data 272 can include an expected digital signature 229 calculated based on an expected value 225 of the counter 221 of the memory device 130. Alternatively, when the digital signature 229 is generated using a private key of the memory device 130 and asymmetric encryption, the control data 272 can include a corresponding public key for verification of the digital signature 229.

[0171] Optionally, the client computer system 105 can skip verification of the digital signature 229 and trust the memory device 130 to be reliable.

[0172] In one example, the client computer system 105 initially requests identification data from the memory device 130 without knowledge of the unique identifier 122 of the memory device 130. From the response to the initial request, the client computer system 105 determines the unique identifier 122 of the memory device 130 and uses the unique identifier 122 to retrieve the control data 272 associated with the unique identifier 122 in the batch response 273. For example, the batch response 273 can include an encrypted nonce 227 that can be used for a subsequent request 231 for identification data from the memory device 130. The identification data in the subsequent response 233 can be verified via the control data 272 provided by the server system 102.

[0173] Alternatively, the same encrypted nonce 227 can be used for each memory device (e.g., 130) in a batch at one time; and thus, the initial request for the purpose of determining the unique identifier 122 and the encrypted nonce 227 can be skipped.

[0174] Using the control data 272 provided for the unique identifier 122 of the memory device 130, the client computer system 105 can generate a request 245 to the memory device 130 to execute a command 239. For example, the command 239 can be executed to activate a security feature, or replace an encryption key in the memory device 130, etc.

[0175] The request 245 can include the command 239 and control data 275 generated for the command 239 using the control data 272 provided in the response 273 to the batch identifier 257.

[0176] For example, the control data 275 can include an encrypted nonce 247 for the command 239 and a digital signature 243 to be verified by the memory device 130 for execution of the command 239. The encrypted nonce 247 can be included in the control data 272 received from the server system 102; and the digital signature 243 can be pre-generated by the server system 102 using the secret encryption key 124 or the session key 223. For example, the session key 223 can be established based on the response 233 using the secret encryption key 124, the encrypted nonce 247, the counter value 225, the digital signature 229, and / or another secret of the memory device 130 known to the server system 102 and the memory device 130, as in Figure 4

[0177] Optionally, the control data 272 can include the secret encryption key 124 associated with the unique identifier 122 of the server system 102 for control of the memory device 130. With the secret encryption key 124, the client computer system 105 has the same control rights associated with the secret encryption key 124 as the server system 102. Optionally, after the secret encryption key 124 is provided to the client computer system 105, the server system 102 can erase the secret encryption key 124 from the server system 102; and thus, the control rights associated with the secret encryption key 124 are transferred to the client computer system 105.

[0178] Figure 8 A method to control a memory device is shown in accordance with one embodiment. Figure 8 The method of can be performed by processing logic that can include hardware (e.g., processing device, circuitry, dedicated logic, programmable logic, microcode, hardware of a device, integrated circuit, etc.), software / firmware (e.g., instructions run or executed on a processing device), or a combination thereof. In some embodiments, the method of Figure 8 The method of is performed, at least in part, by Figure 1 , Figure 4 , Figure 5 and / or Figure 7 the server system 102. Although shown in a particular sequence or order, unless otherwise specified, the order of the processes can be modified. Thus, the illustrated embodiments should be understood only as examples, and the illustrated processes can be performed in a different order, and some processes can be performed in parallel. Additionally, one or more processes can be omitted in various embodiments. Thus, not all processes are required in every embodiment. Other process flows are possible.

[0179] At block 301, the server system 102 establishes a connection (e.g., the secure authenticated connection 201) with the client computer system 105.

[0180] ​At block 303, the server system 102 receives, from the client computer system 105 via the connection 201, the request 271 with the batch identifier 257, which is configured in the server system 102 to identify a batch of multiple memory devices (e.g., 130).

[0181] As explained in Figure 6 For example, as explained in

[0182] At block 305, the server system 102 determines, based on data stored in the server system 102, that the client computer system 105 is eligible to control the multiple memory devices in the batch.

[0183] For example, the server system 102 can store data associating the batch identifier 257 with a client identifier 259 of the client computer system 105 and / or the permissions 265 of the client computer system 105 to control one or more batches of memory devices (e.g., 130).

[0184] In response to determining that the client computer system 105 is eligible to control the memory devices (e.g., 130), at block 307, the server system 102 determines control data (e.g., 272) for each respective memory device (e.g., 130) in the batch based at least on an encryption key (e.g., 124) associated with the respective memory device (e.g., 130) and stored in the server system 102.

[0185] For example, the control data 272 for the unique identifier 122 can include an encryption key that can be used to verify the second digital signature 229 applied over the identification data provided in the response 233 when the client computer system 105 sends the request 231 for the identification data.

[0186] Alternatively, the control data 272 can include a second digital signature 229 that the server system 102 expects the memory device 130 to generate in response to the request 231 for identification data. The second digital signature 229 is to be applied to a second message having a unique identifier 122 of the respective memory device 130, a value 225 from a counter 221 configured in the respective memory device 130, and a second encrypted nonce 227. The server system 102 can determine the second encrypted nonce 227 for the request 231 and determine an expected counter value for the memory device 130 (e.g., based on a last seen value of the counter 221 of the memory device 130). The server system 102 can use the encryption key 124 of the memory device 130 to compute an expected digital signature that is to be applied by the memory device 130 to a response 233 to the request 231 for identification data of the memory device 130. The control data 272 can include the second encrypted nonce 227, the expected counter value, and the expected digital signature. The client computer system 105 can send the request 231 with the second encrypted nonce 227 to cause the memory device 130 to provide a response 233 having a counter value 225 that matches the expected counter value. Then, the expected digital signature provided in the control data 272 can be compared to the second digital signature 229 in the identification data response 233 to determine whether the signatures match each other and thus whether the memory device 130 is authentic. When the memory device 130 generates a response 233 having a matching digital signature 229, the memory device 130 also has the session key 223 that can be used for processing of the request 245 for execution of the command 239.

[0187] At block 309, the server system 102 transmits a response 273 containing control data (e.g., 272) and responsive to the request 271 to the client computer system 105 over the connection 201.

[0188] After receiving the response 273, the client computer system 105 can control security aspects of the respective memory devices (e.g., 130) in the batch without further communication with the server system 102.

[0189] At block 311, the client computer system 105 uses the control data (e.g., 272) to submit the command 239 with the first digital signature 243 to the respective memory device (e.g., 130).

[0190] For example, the first digital signature 243 is applied to a first message in a request 245 from the client computer system 105 to the memory device 130. The first message includes the command 239 and the first encrypted nonce 247.

[0191] For example, the first digital signature 243 includes a hash-based message authentication code (HMAC) generated from the first message and an encryption key stored in both the respective memory device and the server system. The control data 272 provided in the batch response 273 can include the encryption key used to generate the first digital signature 243, or include the first encryption nonce 247 and the first digital signature 243 generated by the server system 102 for the client computer system 105.

[0192] For example, the first digital signature 243 can be generated using the session key 223 established in the respective memory device 130 in response to the request 231 for identification data of the respective memory device 130, or an encryption key stored in the server system 102 in association with the unique identifier 122 of the respective memory device 130, or any combination thereof.

[0193] For example, the control data 272 can include the first digital signature 243 made by the server system 102 for the client computer system 105, or can be used by the client computer system 105 to generate the first digital signature 243 independent of the server system 102.

[0194] At block 313, the respective memory device (e.g., 130) verifies the first digital signature 243 prior to executing the command 239.

[0195] For example, the command 239 can be executed in the respective memory device (e.g., 130) to activate a security feature of the respective memory device (e.g., 130), replace the first encryption key with a second encryption key, or any combination thereof.

[0196] Figure 9 An example machine of a computer system 400, within which a set of instructions, for causing the machine to perform any one or more of the methodologies discussed herein, can be executed, is described. In some embodiments, the computer system 400 can correspond to a server system 102 (e.g., of FIG. 1) that includes, is coupled to, or utilizes a memory sub-system (e.g., the memory sub-system 110 of FIG. 1), or can be used to perform operations of a memory control server 205 (e.g., to execute instructions to perform operations corresponding to the server system 102 described with reference to FIG. 1). In alternative embodiments, the machine can be connected (e.g., networked) to other machines in a LAN, an intranet, an extranet, and / or the Internet. The machine can operate in the capacity of a server or a client machine in client-server network environments, as a peer machine in peer-to-peer (or distributed) network environments, or as a server or a client machine in a capacity of a server or a client machine in cloud computing Figure 2 environments. In an example, the computer system 400 can correspond to the server system 102 of FIG. 1. Figure 1 environments. In an example, the computer system 400 can correspond to the server system 102 of FIG. 1. Figures 1 to 8 environments. In an example, the computer system 400 can correspond to the server system 102 of FIG. 1.

[0197] The machine can be a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular telephone, a web appliance, a server, a network router, a switch or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.

[0198] Example computer system 400 includes a processing device 402, a main memory 404 (e.g., read-only memory (ROM), flash memory, dynamic random access memory (DRAM) such as synchronous DRAM (SDRAM) or Rambus DRAM (RDRAM), static random access memory (SRAM), etc.), and a data storage system 418, which communicate with each other via a bus 430 (which can include multiple buses).

[0199] Processing device 402 represents one or more general-purpose processing devices such as a microprocessor, central processing unit, or the like. More particularly, the processing device can be complex instruction set computing (CISC) microprocessor, reduced instruction set computing (RISC) microprocessor, very long instruction word (VLIW) microprocessor, or processor implementing other instruction sets, or processors implementing a combination of instruction sets. Processing device 402 can also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 402 is configured to execute instructions 426 for performing the operations and steps discussed herein. The computer system 400 can further include a network interface device 408 to communicate over the network 420.

[0200] The data storage system 418 can include a machine-readable medium 424 (also referred to as a computer-readable medium) on which is stored one or more sets of instructions 426 or software embodying any one or more of the methodologies or functions described herein. The instructions 426 can also reside, completely or at least partially, within the main memory 404 and / or within the processing device 402 during execution thereof by the computer system 400, the main memory 404 and the processing device 402 also constituting machine-readable storage media. The machine-readable medium 424, data storage system 418, and / or main memory 404 can correspond to memory subsystem 110 of FIG. 1. Figure 2

[0201] In one embodiment, the instructions 426 include instructions to implement a corresponding access control server 101 (e.g., see FIG. 1) to perform the operations described herein. Figures 1 to 8 ​instructions that describe the functionality of the access control server 101). While the machine-readable medium 424 is shown in an example embodiment to be a single medium, the term "machine-readable storage medium" should be taken to include a single medium or multiple media that store the one or more sets of instructions. The term "machine-readable storage medium" shall also be taken to include any medium that is capable of storing or encoding a set of instructions for execution by the machine and that cause the machine to perform any one or more of the methodologies of the present disclosure. The term "machine-readable storage medium" shall accordingly be taken to include, but not be limited to, solid-state memories, optical media, and magnetic media.

[0202] Some portions of the preceding detailed descriptions have been presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These

[0203] It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. The present disclosure can refer to the action and processes of a computer system, or similar electronic computing device, that manipulates and transforms data represented as physical (electronic) quantities within the computer system's registers and memories into other data similarly represented as physical quantities within the computer system memories or registers or other such information storage systems.

[0204] The present disclosure also relates to an apparatus for performing the operations herein. This apparatus can be specially constructed for the required purposes, or it can include a general purpose computer selectively activated or reconfigured by a computer program stored in the computer. Such a computer program can be stored in a computer readable storage medium, such as, but not limited to, any type of disk including floppy disks, optical disks, CD-ROMs, and magnetic-optical disks, read-only memories (ROMs), random access memories (RAMs), EPROMs, EEPROMs, magnetic or optical cards, or any type of media suitable for storing electronic instructions, each coupled to a computer system bus.

[0205] The algorithms and displays presented herein are not inherently related to any particular computer or other apparatus. Various general purpose systems can be used with programs in accordance with the teachings herein, or it can prove convenient to construct a more specialized apparatus to perform the method. The structure for a variety of these systems will appear as follows in the description below. In addition, the present disclosure is not described with reference to any particular programming language. It will be appreciated that a variety of programming languages can be used to implement the teachings of the disclosure as described herein.

[0206] The present disclosure can be provided as a computer program product, or software, that can include a machine-readable medium having stored thereon instructions, which can be used to program a computer system (or other electronic devices) to perform a process according to the present disclosure. A machine-readable medium includes any mechanism for storing information in a form accessible by a machine (e.g., a computer). In some embodiments, a machine-readable (e.g., computer-readable) medium includes a machine (e.g., a computer) readable storage medium such as read only memory ("ROM"), random access memory ("RAM"), magnetic disk storage media, optical storage media, flash memory components, etc.

[0207] In this specification, to simplify the description, various functions and operations are described as being performed by or caused by computer instructions. However, one of ordinary skill in the art will recognize that the operations and acts of a computer program can generate a transformation of electronic signals or other physical entities into other electronic signals or other physical entities, according to some example embodiments. The details of this process can be implemented in connection with appropriate hardware and software used to perform the transformation. Accordingly, these aspects of the disclosure should not be construed as being limited to any particular hardware and software configuration. Furthermore, unless specifically stated otherwise, the processes and acts described herein can be performed in an order different than the order in which the operations or acts are described.

[0208] In the foregoing specification, embodiments of the disclosure have been described with reference to specific embodiments thereof. It will be evident that various modifications can be made to the disclosure without departing from the broader spirit and scope of embodiments of the disclosure as set forth in the appended claims. The specification and drawings are, accordingly, to be regarded in an illustrative sense rather than a restrictive sense.

Claims

1. A method for controlling a memory device, comprising: Establish a secure authentication connection between the server system and the client computer system; The server system receives a request with a batch identifier from the client computer system via the connection, the batch identifier being configured in the server system to identify a batch of multiple memory devices; Based on data stored in the server system, it is determined that the client computer system is qualified to control the plurality of memory devices in the batch; and The response to the request is transmitted from the server system to the client computer system via the connection. The response contains control data for each corresponding memory device in the batch. The control data is based at least on an encryption key stored in the server system in association with the corresponding memory device. The client computer system uses the control data to submit a command with a first digital signature to the corresponding memory device, which verifies the first digital signature before executing the command.

2. The method of claim 1, wherein the server system comprises a key management server and an access control server; the key management server stores data that associates the batch identifier with the identifiers of the plurality of memory devices but does not store data that associates the batch identifier with the identifier of the client computer system; the access control server stores data that associates the batch identifier with the identifier of the client computer system but does not store data that associates the batch identifier with the identifiers of the plurality of memory devices; and when executed in the respective memory device, the command causes the respective memory device to activate the security features of the respective memory device, replace the first encryption key with a second encryption key, or any combination thereof.

3. The method of claim 2, wherein the first digital signature is applied to a first message in a request from the client computer system to the corresponding memory device; and the first message includes the command and a first encrypted random number.

4. The method of claim 3, wherein the first digital signature comprises a hash-based message authentication code (HMAC) generated from the first message and an encryption key stored in both the corresponding memory device and the server system.

5. The method of claim 4, wherein the control data includes the encryption key.

6. The method of claim 4, wherein the control data comprises the first encrypted random number and the first digital signature.

7. The method of claim 3, wherein the control data includes an encryption key that can be used to verify a second digital signature applied to identification data generated by the respective memory device.

8. The method of claim 3, further comprising: The server system determines the identification data of the corresponding memory device; The session key is calculated based on the determination of the identification data; After the client computer system receives the control data, the corresponding memory device will generate the identification data independently of the server system in response to a request from the client computer system; and The control data can be used by the client computer system to verify the second digital signature in the identification data generated by the corresponding memory device.

9. The method of claim 8, wherein the identification data generated by the respective memory device includes a second message and a second digital signature applied to the second message using a secret encryption key of the respective memory device; the second message includes a unique identifier of the respective memory device, a value from a counter configured in the respective memory device, and a second encrypted random number; and the request for the identification data from the client computer system to the respective memory device includes the second encrypted random number received in the response to the request having the batch identifier.

10. The method of claim 9, wherein the control data comprises a version of the second digital signature generated by the server system.

11. The method of claim 9, wherein the first digital signature is generated using the session key or an encryption key stored in the server system in association with the unique identifier of the corresponding memory device, or any combination thereof.

12. The method of claim 11, wherein the control data includes the first digital signature.

13. The method of claim 11, wherein the control data includes an encryption key for generating the first digital signature.

14. A computing system comprising: A memory that stores encryption keys for a memory device and data instructing a client computer system on the authority to control the memory device; and At least one processor, configured via an instruction set as follows: Establish a secure authentication connection with the client computer system; Receive a request with a batch identifier from the client computer system via the connection, the batch identifier being configured in the computing system to identify a batch of multiple memory devices; Based on data stored in the computing system, it is determined that the client computer system is qualified to control the plurality of memory devices in the batch; and A response to the request is transmitted to the client computer system via the connection. The response contains control data for each corresponding memory device in the batch. The control data is based at least on an encryption key stored in the computing system associated with the corresponding memory device. The client computer system uses the control data to submit a command with a first digital signature to the corresponding memory device, which verifies the first digital signature before executing the command.

15. The computing system of claim 14, wherein when executed in the respective memory device, the command causes the respective memory device to activate the security features of the respective memory device, replace the first encryption key with a second encryption key, or any combination thereof; and the first digital signature is applied to a first message in a request from the client computer system to the respective memory device; and the first message contains the command and a first encrypted random number.

16. The computing system of claim 15, wherein the first digital signature comprises a hash-based message authentication code (HMAC) generated from the first message and an encryption key stored in both the corresponding memory device and the computing system; and the control data comprises the encryption key or comprises the first encrypted random number and the first digital signature.

17. The computing system of claim 15, wherein the at least one processor is further configured via an instruction set to: Determine the identification data of the corresponding memory device; The session key is calculated based on the determination of the identification data; After the client computer system receives the control data, the corresponding memory device will generate the identification data independently of the computing system in response to a request from the client computer system. The control data can be used by the client computer system to verify the second digital signature in the identification data generated by the corresponding memory device; The identification data generated by the corresponding memory device includes a second message and a second digital signature applied to the second message using the secret encryption key of the corresponding memory device; The second message includes a unique identifier for the corresponding memory device, a value from a counter configured in the corresponding memory device, and a second encrypted random number; and The request for the identification data from the client computer system to the corresponding memory device includes the second encrypted random number received in the response to the request having the batch identifier.

18. The computing system of claim 17, wherein the first digital signature is generated using the session key or an encryption key stored in the computing system associated with the unique identifier of the corresponding memory device, or any combination thereof; and the control data includes the first digital signature or the encryption key used to generate the first digital signature.

19. A non-transitory computer storage medium storing instructions, said instructions causing the computing system to perform a method when executed by a computing system, said method comprising: A secure authentication connection is established between the computing system and the client computer system. The computing system receives a request with a batch identifier from the client computer system via the connection, the batch identifier being configured in the computing system to identify a batch of multiple memory devices; Based on data stored in the computing system, it is determined that the client computer system is qualified to control the plurality of memory devices in the batch; and The response to the request is transmitted from the computing system to the client computer system via the connection. The response contains control data for each corresponding memory device in the batch. The control data is based at least on an encryption key stored in the computing system in association with the corresponding memory device. The client computer system uses the control data to submit a command with a first digital signature to the corresponding memory device, which verifies the first digital signature before executing the command.

20. The non-transitory computer storage medium of claim 19, wherein, when executed in the respective memory device, the command causes the respective memory device to activate the security features of the respective memory device, replace the first encryption key with a second encryption key, or any combination thereof; and the first digital signature is applied to a first message in a request from the client computer system to the respective memory device; the first message contains the command and a first encrypted random number; and the control data contains the first digital signature or an encryption key used to generate the first digital signature.

Citation Information

Patent Citations

  • Method and system for deterring product counterfeiting, diversion and piracy

    CN103093359A

  • Memory device and memory system

    CN104350503A