Memory Device Security Capsule for HSM-Free Feature Enablement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional memory sub-systems rely on network-based or USB-based Hardware Security Modules (HSMs for transitioning memory devices from an unauthenticated to an authenticated state, which are limited by accessibility and supply issues, and customer security policies restrict their use, leading to challenges in enabling restricted features of memory devices.

Innovation Solution

A security capsule is used to transition memory devices from an unauthenticated to an authenticated state through in-band mechanisms, digitally signed and verified using a private/public key pair, eliminating the need for network-based HSMs and allowing secure enablement of restricted features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-based or USB-based Hardware Security Modules (HSMs) are used to transition memory devices from unauthenticated to authenticated state, then security authentication can be achieved, but accessibility is limited and supply issues arise

Engineering Contradiction:
Improvesecurity authenticationVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the HSM functionality from external network-based or USB-based devices and embeds it directly within the memory device itself. The memory device includes an authentication component that can perform security authentication locally, eliminating the need for external HSMs and their associated accessibility and supply constraints.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The memory device performs self-authentication using an embedded authentication component and private key stored within the device. The device can transition from unauthenticated to authenticated state autonomously without requiring external HSM intervention, thereby improving ease of operation and accessibility.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional HSMs are used for enabling restricted features, then security authentication is maintained, but turnaround time increases and deployment becomes complex

Engineering Contradiction:
Improvesecurity authenticationVSAvoidturnaround time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication component and private key are pre-configured within the memory device during manufacturing. When authentication is needed, the device can immediately use the pre-stored credentials to transition to authenticated state without requiring time-consuming external HSM communication, thereby reducing turnaround time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By extracting HSM functionality from external devices and embedding it within the memory device, the patent eliminates the time required for external authentication device communication and deployment, enabling faster feature enablement while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network-based HSMs are used, then authentication can be performed, but customer security policies restrict their use and deployment becomes limited

Engineering Contradiction:
ImproveauthenticationVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The memory device performs self-authentication using locally stored credentials, making it independent of external network-based HSMs. This self-service capability allows the device to be deployed in various customer environments without being constrained by network security policies or requiring external authentication infrastructure, thereby improving deployment flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent removes the dependency on external network-based HSMs by embedding authentication functionality within the memory device. This extraction eliminates the restrictions imposed by customer security policies on external devices and enables more versatile deployment scenarios.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12361177B2Security capsule for enabling restricted features of a memory device
Publication Date: 2025.07.15 MICRON TECHNOLOGY INC
  • US12361177B2 patent drawing
  • US12361177B2 patent drawing
  • US12361177B2 patent drawing

AI summary

A processing device initializes a memory device in an unauthenticated state in which the memory device is unable to execute one or more restricted commands. The processing device accesses a security capsule that is digitally signed using a private key. The processing device transitions the memory device to an authenticated state based on verifying that the security capsule is validly signed. The processing device uses a public key corresponding to the private key to verify the security capsule is validly signed. While in the authenticated state, the memory device is able to execute the one or more restricted commands.