IP Library Granted Patent US 10,706,154
Granted Patent B2
US 10,706,154 · App. 15/985,526 · Granted Jul 7, 2020

Enabling a secure boot from non-volatile memory

Inventor: Brent Ahlquist (Loomis, CA)
Assignee: Micron Technology, Inc.
G06F21/575G06F9/4401G06F9/4405G06F9/4406G06F12/1408G06F21/57G06F21/572G06F21/606H04L9/0841G06F21/79G06F2212/1052H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,706,154
App. No.
15/985,526
Filed
May 21, 2018
Granted
Jul 7, 2020
Kind
B2
Art Unit
2494
USPC
713/193
Abstract

A system may include a host that may include a processor coupled to a non-volatile memory over a secure communication protocol. As a result, prior to release for manufacturing, a binding code may be established between the host and the non-volatile memory. In some embodiments, this binding code may be stored on the non-volatile memory and not on the host. Then during a boot up of the system, the boot up process may be initiated by the host using code associated with the host, followed by secure booting using the secure protocol using code stored on the non-volatile memory.

Claims (35)

1. A non-transitory computer readable medium having instructions stored therein that, when executed by a processor, operates to perform a method comprising:

transmitting a bind command and one or more parameters to a non-volatile memory;

accessing a response from the non-volatile memory to the bind command and extracting a secret key;

encrypting binding code, wherein the binding code is configured to be executed by a host to enable encrypted communications between the host and a non-volatile memory; and

storing the encrypted binding code in a binding code storage of the non-volatile memory, the binding code storage configured to store the binding code.

2. The computer readable medium of claim 1 , wherein transmitting the bind command and the one or more parameters includes transmitting one or more parameters indicative of a key type.

3. The computer readable medium of claim 2 , wherein transmitting the one or more parameters includes transmitting at least one of X, g, or n in a Diffie-Hellman key exchange algorithm.

4. The computer readable medium of claim 1 , further comprising instructions stored therein that, when executed by a processor, operates to perform the method further comprising:

storing a first boot code on the non-volatile memory; and

enabling a second boot code on the host to initiate a booting process and transferring the booting process to the first boot code stored on the non-volatile memory.

5. The computer readable medium of claim 4 , further comprising instructions stored therein that, when executed by a processor, operates to perform the method further comprising executing the binding code to facilitate transfer of the first boot code from the non-volatile memory to the host.

6. The computer readable medium of claim 4 , further comprising instructions stored therein that, when executed by a processor, operates to perform the method further comprising:

reading the binding code stored in the non-volatile memory with the second boot code;

decrypting the binding code with the host; and

storing the binding code on the host.

7. A non-transitory computer readable medium having instructions stored therein that, when executed by a processor, operates to perform a method comprising:

storing a secret key in a volatile memory of a host, the secret key extracted from a response to a bind command;

establishing encrypted communication between the host and a non-volatile memory via binding code executable by the host, wherein the encrypted communication is established using the secret key to encrypt the binding code stored at the host; and

storing a boot code in a boot code storage, and providing the boot code and the binding code to the host, wherein the boot code is provided to the host via the encrypted communications.

8. The computer readable medium of claim 7 , wherein the non-volatile memory comprises an execute-in-place memory.

9. The computer readable medium of claim 7 , further comprising instructions stored therein that, when executed by a processor, operates to perform the method further comprising configuring the host to establish the encrypted communication via a Diffie-Hellman key exchange algorithm.

10. The computer readable medium of claim 7 , further comprising instructions stored therein that, when executed by a processor, operates to perform the method further comprising providing the binding code to the host responsive, at least in part, to a request for the binding code from the host.

11. The computer readable medium of claim 10 , wherein the request for the binding code from the host is initiated by a second boot code executed on the host.

12. The computer readable medium of claim 7 , wherein the boot code is configured to boot the host.

13. The computer readable medium of claim 7 , wherein the non-volatile memory comprises flash memory.

14. A method comprising:

generating, via a host, a bind command;

receiving the bind command at a non-volatile memory coupled to the host, and generating a response to the bind command and providing the response to the host, the host configured to extract a secret key from the response to the bind command, wherein the host configures a binding code based, at least in part, on the response and provides the binding code to a binding code storage of the non-volatile memory; and

establishing encrypted communication, via the binding code, between the non-volatile memory and the host when the binding code is executed by the host using the secret key.

15. The method of claim 14 , wherein generating, via the host, the bind command includes generating one or more parameters indicative of a key type.

16. The method of claim 14 , wherein generating, via the host, the bind command includes generating one or more parameters comprising at least one of X, g, or n in a Diffie-Hellman key exchange algorithm.

17. The method of claim 14 , further comprising generating an identification tag for the host to identify a key in the future.

18. The method of claim 14 , further comprising generating the bind command responsive to executing a first boot code on the host.

19. The method of claim 18 , further includes storing a second boot code on the non-volatile memory.

20. The method of claim 19 , further includes executing, via the host, the second boot code responsive, at least in part, to establishment of the encrypted communication between the non-volatile memory and the host.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Nov 12, 2019
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.; MICRON SEMICONDUCTOR PRODUCTS, INC.
Reel/Frame 051028/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 11, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 050713/0001 →
SUPPLEMENT NO. 9 TO PATENT SECURITY AGREEMENT Recorded Aug 9, 2018
From: MICRON TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 047282/0463 →
SECURITY INTEREST Recorded Jul 13, 2018
From: MICRON TECHNOLOGY, INC.; MICRON SEMICONDUCTOR PRODUCTS, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 047540/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2018
From: AHLQUIST, BRENT
To: NUMONYX B.V.
Reel/Frame 045868/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2018
From: NUMONYX B.V.
To: MICRON TECHNOLOGY
Reel/Frame 046204/0637 →
Continuity (3)
Continuation 14693758 · Apr 22, 2015
Continuation 12411784 · Mar 26, 2009
Related Publication 20180276388A1 · Sep 27, 2018