Secure collection of diagnostics data about integrated circuit memory cells
Systems, apparatuses, and methods to secure remote collection of memory diagnostics data generated during operations of memory cells configured in a memory device connected to a host system. The diagnostics data is stored in a secure memory region within the memory device, which controls access to the secure memory region based on cryptography. After a communication connection is established, via the host system and between the memory device and a security server having a privilege to access the secure memory region, the diagnostics data can be transmitted from the memory device to the security server in an encrypted form over the communication connection.
1 . A method, comprising:
generating, during operations of memory cells configured in a memory device connected to a host system, diagnostics data about the memory cells;
storing, in a secure memory region within the memory device, the diagnostics data;
controlling, by the memory device based on cryptography, access to the secure memory region, wherein access to the secure memory region is controlled by the memory device based on a type of security requirement specified for a requested type of access;
establishing, via the host system and between the memory device and a security server having a privilege to access the secure memory region based on verification of the security server satisfying the type of security requirement for the requested type of access, a communication connection;
validating, in response to a command received from the security server to read the diagnostics data, a verification code for the command generated using a cryptographic key representative of the privilege, wherein the cryptographic key is generated based on a unique device secret of the memory device that is registered into a key management server of the security server during manufacturing of the memory device and is inaccessible via an interface of the memory device to the host system after completion of the manufacturing of the memory device; and
communicating, over the communication connection and based on validation of the verification code, the diagnostics data from the memory device to the security server in an encrypted form, wherein the encrypted form is generated by utilizing a session key established during at least one authentication operation that authenticates an identity of the memory device based on the unique device secret to establish the communication connection between the memory device and the security server.
2 . The method of claim 1 , wherein the privilege is based on the unique device secret of the memory device registered with the security server during manufacturing of the memory device.
3 . The method of claim 2 , further comprising:
monitoring health of the memory device based on the diagnostics data to detect an anomaly; and
transmitting an alert to a manufacturer of an endpoint having the host system and the memory device in response to the anomaly.
4 . The method of claim 3 , further comprising:
running a diagnostics utility in the host system to establish the communication connection over an insecure computer network periodically.
5 . The method of claim 4 , wherein the privilege is represented by the cryptographic key used to sign the command to read the secure memory region; and the cryptographic key is generated based at least in part on the unique device secret.
6 . The method of claim 5 , further comprising:
generating a cipher text of the diagnostics data using the cryptographic key derived at least in part from the unique device secret to communicate the diagnostics data from the memory device to the security server in the encrypted form.
7 . The method of claim 6 , wherein the diagnostics data includes statistics on thermal usage conditions of the memory cells, statistics on a power supply to the memory cells, statistics on data access modes of the memory cells, statistics on data access types of the memory cells, statistics on data access parameters of the memory cells, or an error log of reading the memory cells, or any combination thereof.
8 . The method of claim 7 , wherein the diagnostics data includes no user data received from the host system.
9 . The method of claim 7 , further comprising:
receiving in the diagnostics utility a user input representative of a consent from a user of the endpoint to transmit the diagnostics data to the security server.
10 . A memory device, comprising:
memory cells formed on one or more integrated circuit dies;
a logic circuit implementing a cryptographic engine and an access controller; and
a first communication interface connectable to a host system;
wherein a portion of the memory cells is allocated as a secure memory region;
wherein the access controller is configured to control access to the secure memory region based on cryptography wherein access to the secure memory region is controlled by the access controller based on a type of security requirement specified for a requested type of access;
wherein during operations of the memory cells servicing the host system, the logic circuit is configured to generate diagnostics data about the memory cells and store the diagnostics data in the secure memory region;
wherein, in response to a command received from a security server to read the diagnostics data, the memory device is configured to validate a verification code for the command generated using a cryptographic key representative of a privilege to access the secure memory region, wherein the cryptographic key is generated based on a unique device secret of the memory device that is registered into a key management server of the security server during manufacturing of the memory device that is inaccessible via a second communication interface of the memory device to the host system after completion of the manufacturing of the memory device; and
wherein when a communication connection is established, via the host system and between the memory device and the security server having the privilege to access the secure memory region based on verification of the security server satisfying the type of security requirement for the requested type of access, the memory device, after validation of the verification code, is configured to communicate the diagnostics data over the communication connection to the security server in an encrypted form, wherein the encrypted form is generated by utilizing a session key established during at least one authentication operation that authenticates an identity of the memory device based on the unique device secret to establish the communication connection between the memory device and the security server.
11 . The memory device of claim 10 , wherein the diagnostics data includes statistics on thermal usage conditions of the memory cells, statistics on a power supply to the memory cells, statistics on data access modes of the memory cells, statistics on data access types of the memory cells, statistics on data access parameters of the memory cells, or a log of errors in operating the memory cells, or any combination thereof; the memory cells store a diagnostics utility having instructions executable in the host system; and the memory device is configured to validate integrity of the instructions in response to a request from the host system to retrieve the instructions for execution.
12 . The memory device of claim 11 , wherein the instructions, when executed in the host system, cause the host system to establish the communication connection between the memory device and the security server.
13 . The memory device of claim 11 , wherein the memory device is configured to transmit the diagnostics data in a cipher text generated using the cryptographic key derived at least in part from the unique device secret.
14 . The memory device of claim 11 , wherein the memory device is configured to transmit the diagnostics data in a cipher text generated using the session key established during the at least one authentication operation to establish the communication connection between the memory device and the security server.
15 . A system, comprising:
a key management server configured to store a cryptographic key associated with a memory device, wherein the memory device is configured to store diagnostics data about memory cells in the memory device in a secure memory region in the memory device, wherein the cryptographic key is generated based on a unique device secret of the memory device that is registered into the key management server of a security server during manufacturing of the memory device; and
wherein an access controller of the memory device is configured to:
receive, from the security server, a command to read the diagnostics data;
validate a verification code of the command to retrieve the diagnostics data from the secure memory region of the memory device, wherein the verification code is generated using the cryptographic key representative of a privilege of the security server to access the secure memory region, wherein the cryptographic key is generated based on the unique device secret of the memory device that is registered into the key management server during manufacturing of the memory device and that is inaccessible via an interface of the memory device to a host system after completion of the manufacturing of the memory device; and
wherein, in response to the access controller of the memory device verifying the verification code, a communication connection is established between the security server and the memory device and the diagnostics data is transferred from the secure memory region to the security server via the communication connection in an encrypted form generated by utilizing a session key established during at least one authentication operation that authenticates an identity of the memory device based on the unique device secret to establish the communication connection.
16 . The system of claim 15 , wherein instructions are configured to cause the system to monitor the diagnostics data retrieved from the memory device to detect an anomaly and transmit an alert about the anomaly to a manufacturer of an endpoint having the host system and the memory device.
17 . The system of claim 16 , wherein the diagnostics data includes statistics on thermal usage conditions of the memory cells, statistics on a power supply to the memory cells, statistics on data access modes of the memory cells, statistics on data access types of the memory cells, statistics on data access parameters of the memory cells, or an error log, or any combination thereof.