Remote Certificate Provisioning for Memory System Provenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory system authentication methods fail to verify the provenance of memory devices post-manufacture, particularly after firmware updates, as they rely on manufacturer-generated cryptographic certificates that do not account for changes in device characteristics over time.

Innovation Solution

A system that uses a server as a repository and distributor of manufacturer-endorsed certificates, where the memory system generates a self-certificate and transmits it to a host system, which then verifies it with a server using asymmetric cryptography, ensuring that updates are validated and endorsed by the trusted manufacturer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manufacturer-generated cryptographic certificates are used for authentication, then device identity verification is enabled, but the system cannot verify provenance after firmware updates or characteristic changes

Engineering Contradiction:
Improveprovenance verificationVSAvoidfirmware update support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by having the manufacturer embed a cryptographic signature (first signature) and public key in the memory device during manufacture. This pre-configured authentication mechanism allows the device to later prove its provenance to a server, which can then issue updated certificates after verifying firmware integrity, thus enabling both reliable provenance verification and adaptability to firmware updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a server as an intermediary between the memory device and the host system. The server receives the first certificate from the device, verifies it using the embedded public key, and issues a second certificate that confirms current provenance. This intermediary enables the system to maintain reliable authentication while adapting to firmware changes through centralized verification and certificate reissuance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If self-signed certificates are used by memory systems, then device autonomy is improved, but authentication trustworthiness decreases

Engineering Contradiction:
Improvedevice autonomyVSAvoidauthentication trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The memory device performs preliminary action by self-generating a certificate signature using its embedded private key. This self-signed certificate provides device autonomy while maintaining a foundation of trust through the pre-embedded cryptographic key pair. The device can independently create its own authentication credential without requiring external intervention during initialization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by having the server verify the self-signed certificate using the embedded public key, then issue a second certificate that confirms the device's provenance. This feedback loop transforms the initially autonomous but less trustworthy self-signed certificate into a verified, trusted authentication mechanism while preserving device autonomy in certificate generation.

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic verification is performed for each firmware update, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies preliminary action by pre-embedding the public key and first signature in the memory device during manufacture. This pre-configured cryptographic foundation enables straightforward verification of firmware updates without requiring complex verification systems, as the basic authentication infrastructure is already in place and can be easily extended to verify update integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230353391A1Remote provisioning of certificates for memory system provenance
Publication Date: 2023.11.02 MICRON TECHNOLOGY INC
  • US20230353391A1 patent drawing
  • US20230353391A1 patent drawing
  • US20230353391A1 patent drawing

AI summary

Methods, systems, and devices for remote provisioning of certificates for memory system provenance are described. The method may include a server receiving a first certificate that includes a first public key, a first signature generated using a first private key of a memory system, and an indication of a characteristic associated with the memory system. The server may verify the first signature and that the characteristic associated with the memory system is a valid characteristic for the memory system to have. The server may generate a second certificate that includes the first public key and a second signature generated using a second private key. The server may provide the second certificate to a host system such that the host may verify the provenance of the memory system.