Memory Device Autonomous Measurement Attestation via MAB
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing measurement attestation solutions for memory sub-systems require the implementation of attestation protocols and deployment of Public Key Infrastructure (PKI) base Certificate Authorities, which are resource intensive and beyond the capabilities of some customers.
Innovation Solution
A memory sub-system configured for autonomous measurement attestation, which includes a Measurement Attestation Block (MAB) that stores reference system measurements calculated based on an initial firmware image. The MAB is digitally signed and validated using a trusted public key, allowing the memory sub-system to perform attestation independently without external PKI infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional measurement attestation solutions are implemented using PKI base Certificate Authorities, then security and measurement verification capability are improved, but device complexity and resource consumption increase significantly
Solution Approach 1:
The patent extracts the measurement attestation functionality from the complex external PKI infrastructure and embeds it directly into the memory device. The measurement attestation block (MAB) contains reference measurements and verification logic locally, eliminating the need for external Certificate Authorities and reducing device complexity while maintaining security.
Solution Approach 2:
The memory device performs self-verification by comparing its current state measurements against reference measurements stored in the MAB. The device autonomously determines whether it is in a trusted state without requiring external PKI validation, enabling self-service security verification.
2Measurement precision
If external PKI infrastructure is deployed for measurement attestation, then verification accuracy is improved, but ease of operation and deployment simplicity deteriorate
Solution Approach 1:
Reference measurements are pre-calculated and stored in the MAB during device manufacturing or firmware initialization. This preliminary action enables the device to perform verification autonomously without requiring real-time connection to external PKI infrastructure, simplifying deployment while maintaining verification accuracy.
3Ease of operation
If autonomous measurement attestation is implemented without external PKI, then ease of operation is improved, but measurement precision and security validation capability may worsen
Solution Approach 1:
The patent creates a local copy of the trusted reference measurements within the MAB on the memory device. This copy enables autonomous verification by comparing current measurements against the stored reference, achieving both operational simplicity and verification precision without external PKI dependency.
Data Source
AI summary
A processing device calculates a set of reference system measurements based on an initial firmware image corresponding to a memory device. The processing device stores the set of reference system measurements in a measurement attestation block of the memory device. A set of current system measurements are calculated by the processing device based on a current firmware image corresponding to the memory device. The processing device performs a comparison of the set of current system measurements with the set of reference system measurements stored in the measurement attestation block of the memory device and performs an action with respect to the memory device based on a result of the comparison.


