IP Library Granted Patent US 11,169,717
Granted Patent B2
US 11,169,717 · App. 16/235,482 · Granted Nov 9, 2021

Unauthorized access command logging using a key for a protected region of memory

Inventors: Brent Keeth (Boise, ID); Naveh Malihi (University City, MO)
Assignee: Micron Technology, Inc.
G06F3/0622G06F3/0653G06F3/0659G06F3/0673G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,169,717
App. No.
16/235,482
Granted
Nov 9, 2021
Kind
B2
Abstract

Apparatuses and methods related to tracking unauthorized access commands for memory. Identifying unauthorized memory access can include verifying whether an access command is authorized to access a protected region of a memory array. The authorization can be verified utilizing a key and a memory address corresponding to the access command. If an access command is authorized to access a protected region, then a row of the memory array corresponding to the access command can be activated. If an access command is not authorized to access the protected region, then an access count can be incremented to signify the unauthorized access command.

Claims (51)

1. An apparatus, comprising:

a memory array;

a key register configured to store a first key used to determine whether access commands are allowed access to a protected region of the memory array;

a protected region register configured to store addresses defining the protected region;

an access count register configured to store an access count corresponding to the protected region; and

control circuitry coupled to the memory array, the key register, the protected region register, and the access counter register, and configured to:

responsive to receiving an access command:

determine that an address corresponding to the access command is in the protected region;

determine whether a second key corresponding to the access command matches the first key;

responsive to determining that the address is in the protected region and the second key matches the first key, enabling a row driver of the memory array;

responsive to determining that the address is in the protected region and the second key does not match the first key, increment the access count stored in the access count register and preventing enablement of the row driver of the memory array; and

responsive to determining that the address is in the protected region and that no key is associated with the access command, increment the access count stored in the access count register and preventing enablement of the row driver of the memory array.

2. The apparatus of claim 1 , wherein the control circuitry is configured to, responsive to determining that the address is in the protected region and the second key matches the first key, prevent incrementing of the access count.

3. The apparatus of claim 1 , wherein the control circuitry is configured to, responsive to determining that the address is not in the protected region, prevent determining that the second key corresponding to the access command matches the first key.

4. The apparatus of claim 3 , wherein the control circuitry is configured to, responsive to determining that the address is not in the protected region, prevent an incrementing of the access count.

5. The apparatus of claim 1 , wherein the control circuitry is configured to, responsive to incrementing the access count, transmit a signaling indicative of the access command.

6. The apparatus of claim 5 , wherein the control circuitry is configured to transmit the signaling to a virtual machine.

7. The apparatus of claim 5 , wherein the control circuitry is configured to transmit the signaling to a host.

8. The apparatus of claim 5 , wherein the control circuitry is configured to transmit the signaling a hypervisor.

9. The apparatus of claim 5 , wherein the control circuitry is configured to transmit the signaling by providing access to the access count register.

10. The apparatus of claim 1 , wherein the control circuitry is further configured to, responsive to receiving an authorized access command to the protected region, transmit a signaling indicative of the access count to the host.

11. A method comprising:

receiving an access command;

determining whether an address corresponding to the access command is in a protected region of a memory array;

determining whether a second key corresponding to the access command matches a first key stored in a key register; and

responsive to determining that the address is in the protected region and the second key does not match the first key, incrementing an access count and preventing signals from being provided to a row driver of the memory array;

responsive to determining that the address is in the protected region and that no key is associated with the access command, incrementing the access count and preventing enablement of the row driver of the memory array.

12. The method of claim 11 , further comprising:

transmitting signaling indicative of the access count to a host device.

13. The method of claim 12 , further comprising:

receiving another command from the host device to report the signaling indicative of the access count; and

transmitting the signaling in response to the other command.

14. The method of claim 13 , wherein the other command is received via a command/address bus and the signaling indicative of the access count is transmitted via a data bus.

15. The method of claim 13 , wherein the other command is received in one of a series of commands that comprises the access command.

16. The method of claim 13 , wherein the signaling indicative of the access count is multiplexed with data responsive to the access command.

17. The method of claim 12 , wherein the signaling comprises an indication that the access count has met or exceeded a threshold value.

18. The method of claim 12 , wherein transmitting the signaling comprises updating a register or activating a pin.

19. The method of claim 11 , wherein the access command comprises one of a pre-charge command, an activate command, a read command, or a write command.

20. The method of claim 11 , wherein the access count represents unauthorized access commands to the address.

21. The method of claim 11 , wherein responsive to determining that the address is in the protected region, identifying a row of the memory array corresponding to the address.

22. The method of claim 21 , wherein the access count represents unauthorized access commands to the row of the memory array.

23. A system, comprising:

a host comprising a processing resource configured to execute a hypervisor; and

a memory device configured to:

receive an access count retrieval command from a host;

determine whether a second key corresponding to the access count retrieval command matches a first key stored in the key register and wherein the first key is used to determine whether access commands are allowed access to a protected region of a memory array; and

responsive to determining that the first key matches the second key, provide access to an access count register of the memory device, wherein the first key is used to access the access count register and the protected region.

24. The system of claim 23 , wherein the access count retrieval command is a mode read command.

25. The system of claim 23 , wherein the memory device is configured to, responsive to determining that the first key matches the second key, provide access to an access count register configured to store an access count of unauthorized access commands to the protected region of the memory array.

26. The system of claim 25 , wherein the memory device is further configured to set the access count register responsive to determining that the access count is greater than a threshold count, wherein setting the mode register includes storing a value in the mode register representing an unauthorized access command.

27. The system of claim 23 , wherein the memory device is further configured to, responsive to determining that the first key matches the second key, reset an access count register.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Nov 15, 2019
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 051041/0317 →
RELEASE OF SECURITY INTEREST Recorded Oct 14, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 050724/0392 →
SUPPLEMENT NO. 12 TO PATENT SECURITY AGREEMENT Recorded Apr 19, 2019
From: MICRON TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 048948/0677 →
SUPPLEMENT NO. 3 TO PATENT SECURITY AGREEMENT Recorded Apr 19, 2019
From: MICRON TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 048951/0902 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2018
From: KEETH, BRENT; MALIHI, NAVEH
To: MICRON TECHNOLOGY, INC.
Reel/Frame 047869/0630 →