Memory Module Authentication via Nonce Key Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of next-generation memory modules with high-speed data interfaces poses a challenge in authenticating hardware components, as the management interface used for authentication often operates at slower speeds than the data interface, leading to potential validation discrepancies between the two.

Innovation Solution

A system and method are implemented where each hardware module includes an identification component, such as an SPD hub, storing authentication information. A management system retrieves this information, generates a nonce key, and writes it to a nonce register, ensuring that each access request is validated by comparing the nonce key from the request with the stored key, thereby ensuring the authenticity of the hardware module across both management and data interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a management interface is used for authentication, then security verification can be performed, but the authentication speed is slower compared to the data interface

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary authentication actions during system initialization or module insertion, storing authentication results and configuration parameters in the SPD hub before actual data operations begin. This allows the high-speed data interface to operate without repeated authentication delays while maintaining security verification through the management interface.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates authentication functions into distinct components: the management interface handles security verification and authentication, while the data interface handles high-speed data transfer. The SPD hub acts as an intermediary storage component that bridges these two interfaces, allowing them to operate independently at their respective optimal speeds.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication information is stored in the SPD hub, then module identity can be verified, but validation discrepancies may occur between management and data interfaces

Engineering Contradiction:
Improvemodule identity verificationVSAvoidvalidation consistency
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the management controller continuously monitors and compares authentication status between the management interface and data interface. When discrepancies are detected, the system can trigger re-authentication or error correction procedures to ensure validation consistency across both interfaces.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The SPD hub serves as an intermediary component that stores authentication information and configuration parameters accessible by both the management interface and data interface. This mediator ensures that both interfaces reference the same authentication data, preventing validation discrepancies and ensuring consistent module identity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11899777B2Memory module authentication extension
Publication Date: 2024.02.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11899777B2 patent drawing
  • US11899777B2 patent drawing
  • US11899777B2 patent drawing

AI summary

Systems and methods are provided for a secondary authentication of a memory module. A nonce key is written to a nonce register of a register array on the memory module, the nonce register being accessible over two different interfaces. In various embodiments, the nonce key may be generated by a management system of the computing platform after performing one or more authentication processes for a memory module over a management interface. Authentication information for use in performing authentication can be stored in an identification component on the memory module. If authentication is successful, the management system can generate the nonce key and write it to the nonce register. Upon receiving a request to access an address, a memory controller can read the nonce register of the memory module at the requested address and compare the nonce key to an identifier included in the request.