Memory Boot Attestation Using Dual Measurement Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory devices fail to directly report to the host whether the bootloader or firmware is falsified, leading to uncertainty in diagnosing booting failures.

Innovation Solution

A memory device system that includes an interface to receive measurement values, attester firmware to generate and record values, and a host to determine falsification based on recorded measurement values and reference values, enabling direct verification of bootloader and firmware integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the memory device verifies bootloader and firmware integrity internally, then safe booting is enabled, but the host cannot directly determine the cause of booting failures

Engineering Contradiction:
Improvesafe bootingVSAvoiddiagnostic information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces measurement values as an intermediary that carries integrity verification results from the memory device to the host. The memory device generates measurement values representing the integrity status of bootloader and firmware, transmits these values to the host, enabling the host to directly determine falsification without compromising the memory device's internal verification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the memory device transmits measurement values to the host, then the host can directly determine falsification, but the system complexity increases

Engineering Contradiction:
Improvediagnostic informationVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the integrity verification results from the complex internal verification process and represents them as simple measurement values. By taking out only the essential verification outcomes (measurement values) rather than transmitting entire verification processes or detailed internal states, the system reduces complexity while maintaining diagnostic capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If multiple measurement values are recorded and transmitted, then accurate diagnosis of specific falsified components is enabled, but the data processing burden increases

Engineering Contradiction:
Improvediagnosis accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the integrity verification into distinct measurement values for different components (bootloader measurement value, firmware measurement values). Each measurement value corresponds to a specific component's integrity status, enabling precise diagnosis of which component is falsified. This segmentation allows the host to identify specific problematic components without processing unnecessary data.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260073054A1Memory device, operation method of memory device, and authentication system of memory device
Publication Date: 2026.03.12 SAMSUNG ELECTRONICS CO LTD
  • US20260073054A1 patent drawing
  • US20260073054A1 patent drawing
  • US20260073054A1 patent drawing

AI summary

Provided is a system including a memory device including an interface configured to receive a measurement value generation request signal from a host and transmit a first measurement value and a second measurement value to the host, attester firmware configured to receive measurement values for a plurality of pieces of firmware, a bootloader configured to perform booting, a first register configured to record a first measurement value of the bootloader, and a second register configured to record a second measurement value for the attester firmware in response to the first measurement value being recorded, and the host including processing circuitry configured to receive the first measurement value and the second measurement value, and determine whether to falsify the bootloader or the attester firmware based on at least one of (1) the first measurement value and first reference values or (2) the second measurement value and second refence values.