IP Library Granted Patent US 12705401
Granted Patent B2
US 12705401 · App. 18/790,127 · Granted Aug 11, 2026

Memory device autonomous measurement attestation

Inventors: James Ruane (San Jose, CA); Artsiom Zankovich (Milpitas, CA)
Assignee: Micron Technology, Inc.
G06F21/64G06F21/54G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705401
App. No.
18/790,127
Granted
Aug 11, 2026
Kind
B2
Abstract

A processing device calculates a set of reference system measurements based on an initial firmware image corresponding to a memory device. The processing device stores the set of reference system measurements in a measurement attestation block of the memory device. A set of current system measurements are calculated by the processing device based on a current firmware image corresponding to the memory device. The processing device performs a comparison of the set of current system measurements with the set of reference system measurements stored in the measurement attestation block of the memory device and performs an action with respect to the memory device based on a result of the comparison.

Claims (50)

1 . A memory sub-system comprising:

a memory device;

a measurement attestation block storing a set of reference system measurements calculated based on an initial firmware image of the memory sub-system, the measurement attestation block comprising one or more action bitmaps specifying actions to be performed when mismatch conditions are identified; and

a processing device, operatively coupled with the memory device and the measurement attestation block, to perform operations comprising:

calculating a set of current system measurements based on a current firmware image of the memory sub-system;

comparing the set of current system measurements with the set of reference system measurements stored in the measurement attestation block;

identifying a mismatch condition between the set of reference system measurements and the set of current system measurements based on the comparing;

in response to identifying the mismatch condition, determining an action to perform based on the one or more action bitmaps of the measurement attestation block; and

performing the action with respect to the memory device.

2 . The memory sub-system of claim 1 , wherein: an action bitmap of the one or more action bitmaps corresponds to the action, each bit in the action bitmap corresponding to one of the reference system measurements in the set of reference system measurements.

3 . The memory sub-system of claim 1 , wherein the performing the action comprises one of: alerting a host system to the mismatch condition; logging the mismatch condition to an error log; preventing the memory device from booting; placing the memory device in a restricted functionality mode to limit the functionality of the memory device; preventing the memory device from providing functionality; and performing a recovery process on the memory device.

4 . The memory sub-system of claim 1 , wherein:

the set of current system measurements is a first set of current system measurements; and

the operations placing the memory device in a normal functionality mode based on determining a second set of current system measurements match the set of reference system measurements.

5 . The memory sub-system of claim 1 , wherein:

the initial firmware image corresponds to a state of the memory sub-system upon being manufactured.

6 . The memory sub-system of claim 1 , wherein the operations further comprise receiving a command to perform system measurement attestation, wherein the comparing is performed in response to receiving the command.

7 . The memory sub-system of claim 1 , wherein the operations further comprise validating the measurement attestation block prior to calculating the set of current system measurements based on the current firmware image corresponding to the memory device.

8 . The memory sub-system of claim 7 , wherein the operations further comprise generating a digital signature based on the measurement attestation block using a private key, wherein validating the measurement attestation block comprises validating the digital signature using a public key corresponding to the private key.

9 . The memory sub-system of claim 1 , wherein the measurement attestation block further comprises a security version, wherein the operations further comprise validating the security version of the measurement attestation block.

10 . The memory sub-system of claim 1 , wherein:

a reference system measurement in the set of reference system measurements comprises a first secure hash associated with a portion of the initial firmware image corresponding to a component of the memory sub-system; and

a current system measurement in the set of current system measurements comprises a second secure hash associated with a portion of the current firmware image corresponding to the component of the memory sub-system.

11 . A method comprising:

calculating, by a processing device, a set of reference system measurements based on an initial firmware image of a memory sub-system comprising a memory device;

storing the set of reference system measurements in a measurement attestation block of the memory sub-system, the measurement attestation block comprising one or more action bitmaps specifying actions to be performed when mismatch conditions are identified;

calculating, by the processing device, a set of current system measurements based on a current firmware image of the memory sub-system;

performing, by the processing device, a comparison of the set of current system measurements with the set of reference system measurements stored in the measurement attestation block of the memory device; and

identifying a mismatch condition between the set of reference system measurements and the set of current system measurements based on the comparison;

in response to identifying the mismatch condition, determining an action to perform based on the one or more action bitmaps of the measurement attestation block;

performing, by the processing device, the action with respect to the memory device.

12 . The method of claim 11 , wherein: an action bitmap of the one or more action bitmaps corresponds to the action, each bit in the action bitmap corresponding to one of the reference system measurements in the set of reference system measurements.

13 . The method of claim 11 , wherein the performing the action comprises one of: alerting a host system to the mismatch condition; logging the mismatch condition to an error log; preventing the memory device from booting; placing the memory device in a restricted functionality mode to limit the functionality of the memory device; preventing the memory device from providing functionality; and performing a recovery process on the memory device.

14 . The method of claim 11 , wherein:

the set of current system measurements is a first set of current system measurements; and

the method further comprises placing the memory device in a normal functionality mode based on determining a second set of current system measurements match the set of reference system measurements.

15 . The method of claim 11 , wherein:

the initial firmware image corresponds to a state of the memory sub-system upon being manufactured; and

the calculating of the set of current system measurements based on the current firmware image is performed during a boot process of the memory sub-system.

16 . The method of claim 11 , further comprising receiving a command to perform system measurement attestation, wherein the performing of the comparison is in response to receiving the command.

17 . The method of claim 11 , further comprising validating the measurement attestation block prior to performing the comparison.

18 . The method of claim 17 , further comprising generating a digital signature based on the measurement attestation block using a private key, wherein validating the measurement attestation block comprises validating the digital signature using a public key corresponding to the private key.

19 . The method of claim 11 , wherein the measurement attestation block further comprises a security version, wherein the method further comprises validating the security version of the measurement attestation block.

20 . A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, configure the processing device to perform operations comprising:

storing a set of reference system measurements in a measurement attestation block of a memory sub-system, the set of reference system measurements being calculated based on an initial firmware image of the memory sub-system comprising a memory device, a reference system measurement in the set of reference system measurements comprising a first hash associated with a portion of the initial firmware image corresponding to a component of the memory sub-system, the measurement attestation block comprising one or more action bitmaps specifying actions to be performed when mismatch conditions are identified;

calculating a set of current system measurements based on a current firmware image corresponding to the memory sub-system comprising the memory device, a current system measurement in the set of current system measurements comprising a second hash associated with a portion of the current firmware image corresponding to the component of the memory sub-system;

comparing the set of current system measurements with the set of reference system measurements stored in the measurement attestation block of the memory sub-system;

identifying a mismatch condition based on the comparing;

determining, based on the measurement attestation block, an action to perform based on the one or more action bitmaps of the measurement attestation block; and

performing the action with respect to the memory device.