IP Library Granted Patent US 7,401,234
Granted Patent B2
US 7,401,234 · App. 10/791,171 · Granted Jul 15, 2008

Autonomous memory checker for runtime security assurance and method therefore

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,401,234
App. No.
10/791,171
Granted
Jul 15, 2008
Kind
B2
Abstract

Methods and apparatus are provided for an electronic device having an autonomous memory checker for runtime security assurance. The autonomous memory checker comprises a controller, a memory reference file coupled to the controller, and an authentication engine coupled to the controller. A check is performed during runtime operation of the electronic device. The autonomous memory checker generates runtime reference values corresponding to trusted information stored in memory. The runtime reference values are compared against memory reference values stored in the memory reference file. The memory reference values are generated from the trusted information stored in memory. An error signal is generated when the runtime reference values are not identical to the memory reference values thereby indicating that the trusted information has been modified.

Claims (46)

1. An electronic device including an autonomous memory checker for runtime security assurance, the electronic device comprising:

a controller adapted to fetch first memory content from a portion of memory, wherein the first memory content includes software executable on the electronic device;

a memory reference file coupled to said controller, and adapted to store at least one memory reference value that corresponds to the first memory content; and

an authentication engine coupled to said controller, and adapted to perform a runtime check during runtime operation of the electronic device by comparing a at least one runtime reference value with the at least one memory reference value, wherein the at least one runtime reference value corresponds to second memory content fetched from the portion of memory during the runtime operation of the electronic device.

2. The electronic device as recited in claim 1 wherein said check is performed periodically during runtime operation of the electronic device.

3. The electronic device as recited in claim 1 wherein said check is performed at random times during runtime operation of the electronic device.

4. The electronic device as recited in claim 1 further including a clock control block coupled to said authentication engine, said memory reference file, and said controller.

5. The electronic device as recited in claim 4 further including a direct memory access (DMA) controller coupled to said authentication engine and said controller.

6. The electronic device as recited in claim 5 further including a timing module coupled to said controller.

7. The electronic device as recited in claim 1 wherein said memory content includes trusted information stored in the memory, and wherein said memory reference value is generated corresponding to the trusted information stored in the memory.

8. The electronic device as recited in claim 7 wherein said trusted information stored in memory is processed by said authentication engine to generate said memory reference value.

9. The electronic device as recited in claim 8 , wherein said information stored in memory is processed by said authentication engine to generate said runtime reference value, and wherein said information stored in memory has not been modified if said memory reference value is identical to said runtime reference value.

10. The electronic device as recited in claim 1 , wherein the controller is a bus master that is allowed to fetch the memory content from memory without requesting permission.

11. A method of operating an electronic device for runtime security assurance comprising the steps of:

storing trusted information in specific memory locations within a memory of the electronic device, wherein the trusted information includes software executable on the electronic device;

fetching said trusted information from the specific memory locations, and providing said trusted information to an authentication engine;

generating a memory reference value corresponding to said trusted information fetched from the specific memory locations;

storing said memory reference value in a memory reference file;

operating the electronic device in a runtime mode of operation;

fetching memory content from the specific memory locations, and providing the memory content corresponding to the specific memory locations to said authentication engine during the runtime mode of operation of the electronic device;

generating a runtime reference value from the memory content fetched from the specific memory locations; and

comparing said runtime reference value to said memory reference value.

12. The method as recited in claim 11 wherein said step of generating a memory reference value corresponding to said trusted information further includes a step of generating said reference value with a hardware authentication engine.

13. The method as recited in claim 11 further including the steps of:

continuing the runtime mode of operation of the electronic device when said runtime reference value is identical to said memory reference value; and

signaling an error when said runtime reference value is not identical to said memory reference value.

14. The method as recited in claim 13 further including a step of repeating a runtime check process comprising the steps of again fetching memory content from the specific memory locations, generating a another runtime reference value from memory content, and comparing said another runtime reference value to said memory reference value.

15. The method as recited in claim 14 further including a step of running said runtime check process in a background of the runtime mode of operation of the electronic device.

16. The method as recited in claim 15 further including a step of randomizing when said runtime check process occurs during the runtime mode operation of the electronic device.

17. A method of operating an electronic device for runtime security assurance comprising the steps of:

fetching trusted information from a portion of memory of the electronic device, wherein the trusted information includes software executable on the electronic device;

providing the trusted information to an autonomous memory checker during a boot-time mode of operation of the electronic device;

instructing said autonomous memory checker to hash said trusted information during said boot-time mode;

generating, by said autonomous memory checker, reference hash values from said trusted information;

storing said reference hash values to a memory reference file;

fetching, during a runtime mode of operation of the electronic device, memory contents from the portion of memory from which said trusted information was previously fetched;

generating, by said autonomous memory checker, runtime hash values with said memory contents retrieved during the runtime mode;

comparing said reference hash values to said runtime hash values; and

signaling an error when said reference hash values differ from said runtime hash values to indicate that said trusted information has been modified.

18. The method as recited in claim 17 further including a step of repeating randomly the steps of:

fetching, during the runtime mode, the memory contents from the portion of memory from which said trusted information was previously fetched;

generating, by said autonomous memory checker, the runtime hash values with said memory contents retrieved during the runtime mode;

comparing said reference hash values to said runtime hash values; and

signaling the error when said reference hash values differ from said runtime hash values to indicate that said trusted information has been modified.

19. The method as recited in claim 17 wherein said step of fetching the trusted information from the portion of memory includes a step of fetching said trusted information from a plurality of memory blocks.

20. The method as recited in claim 19 further including a step of continuing runtime operation of the electronic device when said runtime hash values are identical to said reference hash values.

Assignments (23)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE LISTED CHANGE OF NAME SHOULD BE MERGER AND CHANGE PREVIOUSLY RECORDED AT REEL: 040652 FRAME: 0180. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Jan 12, 2017
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 041354/0148 →
CHANGE OF NAME Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 040652/0180 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 12, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037486/0517 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0553 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0143 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0757 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0225 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →
SECURITY AGREEMENT Recorded Jun 18, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030633/0424 →
SECURITY AGREEMENT Recorded May 13, 2010
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 024397/0001 →
SECURITY AGREEMENT Recorded Dec 9, 2008
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A.
Reel/Frame 021936/0772 →
SECURITY AGREEMENT Recorded Feb 2, 2007
From: FREESCALE SEMICONDUCTOR, INC.; FREESCALE ACQUISITION CORPORATION; FREESCALE ACQUISITION HOLDINGS CORP.; FREESCALE HOLDINGS (BERMUDA) III, LTD.
To: CITIBANK, N.A. AS COLLATERAL AGENT
Reel/Frame 018855/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2004
From: CASE, LAWRENCE L.; REDMAN, MARK D.; TKACIK, THOMAS E.; FELDMAN, JOEL D.
To: MOTOROLA, INC.
Reel/Frame 015042/0196 →