Memory Measurement Command for Cryptographic Digest Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory systems face inefficiencies in accessing and securing protected data regions, leading to increased signaling overhead, bandwidth consumption, and reduced security due to the need for multiple commands to perform cryptographic functions.
Innovation Solution
A measurement command is introduced that allows memory systems and host systems to perform multiple cryptographic functions, such as generating digests, extending registers, and generating key pairs, using a single command, thereby reducing signaling overhead and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple commands are used to perform cryptographic functions, then security and functionality are maintained, but signaling overhead and bandwidth consumption increase
Solution Approach 1:
The patent combines multiple cryptographic commands (read, verify, and measure operations) into a single integrated command structure. The host system issues one command that triggers sequential execution of cryptographic operations within the memory device, eliminating the need for separate command sequences and reducing signaling overhead while maintaining security verification.
Solution Approach 2:
The integrated command enables the memory device to perform multiple cryptographic functions (data retrieval, cryptographic verification, and digest generation) through a single command interface. This multi-functional approach allows the same command structure to handle various cryptographic operations without requiring separate specialized commands for each function.
2Adaptability or versatility
If multiple commands are used to perform cryptographic functions, then cryptographic operations can be completed, but bandwidth consumption increases
Solution Approach 1:
Multiple cryptographic operations are merged into a single command transaction. The command structure integrates read operations, cryptographic verification, and digest generation into one unified flow, reducing the number of separate data transfers and command exchanges required between host and memory device.
Solution Approach 2:
The memory device performs cryptographic verification and digest generation in advance during the same command transaction used to retrieve data. By completing cryptographic operations concurrently with data access rather than in separate subsequent commands, the system reduces total bandwidth consumption while maintaining full cryptographic functionality.
3Reliability
If multiple commands are used for cryptographic operations, then security verification is performed, but the number of commands increases system complexity
Solution Approach 1:
The patent merges the command structure for data access and cryptographic verification into a single integrated command format. This unified structure reduces the complexity of coordinating multiple separate commands while preserving all necessary security verification steps within the consolidated command flow.
4Reliability
If multiple commands are used to access protected regions, then data security is maintained, but access time increases
Solution Approach 1:
The memory device performs cryptographic verification and digest generation as preliminary actions within the same command transaction used to access protected data. By completing security verification concurrently with data retrieval rather than in separate sequential commands, the system maintains data security while reducing total access time.
Data Source
AI summary
Methods, systems, and devices for a measurement command for memory systems are described. A memory system and a host system may support a measure command to calculate a cryptographic value of data stored in a region of the memory system. In some cases, a region indicated by the measure command may correspond to a protected region of the memory system. In such cases, the measure command may include a cryptographic signature from the host system. Upon receiving the measure command, the memory system may perform a hashing operation on the data to generate the cryptographic value. In some cases, the memory system may transmit the digest to the host. Additionally or alternatively, the memory system may extend the digest into a register indicated by the command. Further, the measure command may be used to generate a key pair associated with the memory system.


