IP Library › Granted Patent US 10,757,087
Granted Patent B2
US 10,757,087 · App. 15/859,780 · Granted Aug 25, 2020

Secure client authentication based on conditional provisioning of code signature

Inventor: Nir Tasher (Herzliya, IL)
Assignee: WINBOND ELECTRONICS CORPORATION
H04L63/08G06F3/065G06F3/0619G06F3/0679G06F12/1441G06F21/575G06F21/64G06F2212/1052H04L9/3239
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,757,087
App. No.
15/859,780
Granted
Aug 25, 2020
Kind
B2
Abstract

A memory subsystem includes a memory interface for accessing a non-volatile memory (NVM), a host interface for communicating with a host, and a processor. The processor is configured to calculate a signature over program code that is used by the host and is stored in the NVM, to verify, upon detecting a boot process performed by the host, whether the boot process is legitimate, and, only if the boot process was verified to be legitimate, to provide the signature to the host for authentication to a remote server.

Claims (25)

1. A memory subsystem, comprising:

a memory interface for accessing a non-volatile memory (NVM);

a host interface for communicating with a host; and

a microprocessor, configured to:

calculate a signature over program code that is used by the host and is stored in the NVM;

upon detecting a power-up of the host, verify whether first read commands issued by the host following the power-up are directed to addresses in accordance with predefined addresses expected for a genuine boot code; and

only if the first read commands were verified to be directed to addresses of the genuine boot code, provide the signature to the host for authentication to a remote server.

2. The memory subsystem according to claim 1 , wherein the processor is configured to store the signature in a volatile register, and to clear the volatile register in response to detecting a read command addressed to an address outside a range of the genuine boot code.

3. The memory subsystem according to claim 1 , wherein the processor is further configured to verify that memory accesses after the first read commands issued by the host following the power-up are directed to a range of memory addresses considered legitimate for after boot access, wherein the range of memory addresses considered legitimate for after boot access is larger than a range including the predefined addresses expected for a genuine boot code.

4. A secure client device, comprising:

a non-volatile memory (NVM);

a host; and

a memory subsystem, configured to:

access the NVM for the host;

calculate a signature over program code that is used by the host and is stored in the NVM;

upon detecting a power-up of the host, verify whether first read commands issued by the host following the power-up are directed to addresses in accordance with predefined addresses expected for a genuine boot code; and

only if the first read commands were verified to be directed to addresses of the genuine boot code, provide the signature to the host for authentication to a remote server.

5. The secure client device according to claim 4 , wherein the memory subsystem is configured to store the signature in a volatile register, and to clear the volatile register in response to detecting a read command addressed to an address outside a range of the genuine boot code.

6. The secure client device according to claim 4 , wherein the memory subsystem is further configured to verify that memory accesses after the first read commands issued by the host following the power-up are directed to a range of memory addresses considered legitimate for after boot access, wherein the range of memory addresses considered legitimate for after boot access is larger than a range including the predefined addresses expected for a genuine boot code.

7. A method, comprising:

calculating a signature over program code that is used by a host and is stored in a non-volatile memory (NVM);

upon detecting a power-up of the host, verifying whether first read commands issued by the host following the power-up are directed to addresses in accordance with predefined addresses expected for a genuine boot code; and

only if the first read commands were verified to be directed to addresses of the genuine boot code, providing the signature to the host for authentication to a remote server.

8. The method according to claim 7 , and comprising storing the signature in a volatile register, and clearing the volatile register in response to detecting a read command addressed to an address outside a range of the genuine boot code.

9. The method according to claim 7 , and comprising verifying that memory accesses after the first read commands issued by the host following the power-up are directed to a range of memory addresses considered legitimate for after boot access, wherein the range of memory addresses considered legitimate for after boot access is larger than a range including the predefined addresses expected for a genuine boot code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2018
From: TASHER, NIR
To: WINBOND ELECTRONICS CORPORATION
Reel/Frame 044512/0139 →
Continuity (1)
Related Publication 20190207917A1 · Jul 4, 2019