IP Library Granted Patent US 10,521,617
Granted Patent B2
US 10,521,617 · App. 15/676,708 · Granted Dec 31, 2019

Non-volatile memory device with secure read

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,521,617
App. No.
15/676,708
Granted
Dec 31, 2019
Kind
B2
Abstract

Technology that provides security for a requestor of data stored in a non-volatile memory device is disclosed. In one aspect, the non-volatile memory device provides data on a host interface only if a digest for the data matches an expected digest for the data. The non-volatile memory device may store expected digests for data for various logical addresses. Upon receiving a request on the host interface to read data for a logical address, the non-volatile memory device may access the data for the logical address, compute a digest for the accessed data, and compare the computed digest with the expected digest. The non-volatile memory device provides the accessed data on the host interface only if the computed digest matches the expected digest, in one aspect. The non-volatile memory device may be used to provide a secure boot of a host.

Claims (61)

1. An apparatus, comprising:

non-volatile memory;

a host interface; and

a control circuit in communication with the non-volatile memory and the host interface, the control circuit configured to:

access data stored in the non-volatile memory in response to a request on the host interface for data for a logical address;

access a stored list of expected digests for data associated with logical addresses, wherein the list contains an expected digest for data associated with each logical address on the list;

compute a digest of the accessed data for the logical address; and

provide the accessed data on the host interface only if the computed digest matches the expected digest for data associated with the logical address.

2. The apparatus of claim 1 , wherein the control circuit is further configured to:

verify integrity of the accessed data based on whether the computed digest matches the expected digest; and

provide the accessed data on the host interface only if the integrity of the accessed data is verified.

3. The apparatus of claim 2 , wherein the control circuit is further configured to:

verify authenticity of the accessed data based on whether the computed digest matches the expected digest; and

provide the accessed data on the host interface only if the authenticity of the accessed data is verified.

4. The apparatus of claim 1 , wherein the control circuit is further configured to:

verify authenticity of the accessed data based on whether the computed digest matches the expected digest; and

provide the accessed data on the host interface only if the authenticity of the accessed data is verified.

5. The apparatus of claim 1 , wherein:

the non-volatile memory and the control circuit reside within a memory device; and the host interface is connected to a host connection to the memory device.

6. The apparatus of claim 5 , wherein:

the list is stored on the memory device.

7. The apparatus of claim 5 , wherein:

the expected digest for data for the logical address is provided to the memory device from a host via the host connection; and

the control circuit is configured to verify the expected digest based on a shared secret between the memory device and a trusted entity.

8. The apparatus of claim 5 , further comprising a host controller connected to the host connection and configured to request the data over the host connection.

9. The apparatus of claim 8 , wherein the host controller is configured to request the data over the host connection responsive to a host boot up sequence.

10. A method comprising:

receiving a request from a host on a host interface of a non-volatile memory device to read data for a host logical address;

accessing the data for the host logical address from the non-volatile memory device;

computing a digest for the accessed data for the host logical address;

accessing a list that is stored on the non-volatile memory device, the list contains host logical addresses and an expected digest for each host logical address on the list;

determining whether the computed digest matches the expected digest for the host logical address; and

providing the data for the host logical address on the host interface to the host only upon a condition that the computed digest for the host logical address matches the expected digest for the host logical address.

11. The method of claim 10 , further comprising:

storing, on the non-volatile memory device, the list of host logical addresses with the expected digest for data associated with each host logical address.

12. The method of claim 11 , further comprising:

receiving, at the non-volatile memory device, a signed token comprising the list; and

verifying the signed token as a condition to use the list to determine whether data stored at the host logical addresses on the list is trusted by the host.

13. The method of claim 11 , further comprising:

receiving the list over a secure channel between the non-volatile memory device and a trusted entity, wherein the list is received from the host over the host interface.

14. The method of claim 11 , further comprising:

receiving, at the host, the list from a server;

receiving the list at the non-volatile memory device from the host over the host interface; and

verifying the list, by the non-volatile memory device, based on a shared secret between the server and the non-volatile memory device that is not shared with the host.

15. The method of claim 11 , further comprising:

receiving the list at the non-volatile memory device from a secure environment (SE) on the host over the host interface; and

verifying the list, by the non-volatile memory device, based on a shared secret between the SE on the host and the non-volatile memory device.

16. The method of claim 10 , further comprising:

initiating, by the host, the request for the data for the host logical address in response to a host boot up sequence to load a program into the host.

17. A non-volatile memory device, comprising:

non-volatile memory;

host interface means for communicating with a host that is external to the non-volatile memory device, the host interface means further for receiving a request from the host to read data that is stored in the non-volatile memory for a host logical address;

memory interface means for accessing the data for the host logical address from the non-volatile memory;

digest computation means for computing a digest of the data for the host logical address;

digest matching means for determining whether the computed digest of the data for the host logical address matches an expected digest of the data for the host logical address, wherein the non-volatile memory device stores the expected digest of data for each host logical address on a list;

data integrity and authenticity verification means for determining integrity and authenticity of the accessed data based on whether the computed digest matches the expected digest for the host logical address; and

data transfer control means for transferring the accessed data to the host only upon verifying integrity and authenticity of the accessed data.

18. The non-volatile memory device of claim 17 , further comprising:

host boot means for initiating a host boot up sequence; and

boot data request means for requesting that host boot data be transferred to the host responsive to the host boot up sequence being initiated;

wherein the data integrity and authenticity verification means is further for providing trusted boot data.

Assignments (10)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: SELA, ROTEM; LEVI, ENOSH
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 043299/0146 →