IP Library Granted Patent US 11,088,845
Granted Patent B2
US 11,088,845 · App. 16/267,040 · Granted Aug 10, 2021

Non-volatile memory with replay protected memory block having dual key

Inventors: Rotem Sela (Hod Hasharon, IL); Miki Sapir (Nes Ziona, IL)
Assignee: Western Digital Technologies, Inc.
H04L9/3242G06F12/1466H04L9/14G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,088,845
App. No.
16/267,040
Granted
Aug 10, 2021
Kind
B2
Abstract

An apparatus includes a Replay Protected Memory Block (RPMB) formed in a plurality of non-volatile memory cells. Control circuitry is configured to authenticate access to the RPMB with a plurality of keys. Authentication of write access to the RPMB is through a write key and authentication of read access to the RPMB is through a read key.

Claims (35)

1. An apparatus, comprising:

control circuitry configured to authenticate access to a Replay Protected Memory Block (RPMB) formed in a plurality of non-volatile memory cells with a plurality of keys including:

authentication of write access to the RPMB through a write key to limit write access to a first entity that contains a copy of the write key in a secure environment; and

authentication of read access to the RPMB through a read key in response to a RPMB read command from a second entity that contains a copy of the read key.

2. The apparatus of claim 1 wherein the RPMB includes a plurality of regions, the first entity is a remote server that has exclusive write access to a first RPMB.

3. The apparatus of claim 2 wherein the control circuitry is further configured to authenticate access to a second RPMB region with another write key to provide another remote server that contains a copy of the other write key with exclusive write access to the second RPMB region.

4. The apparatus of claim 1 wherein the control circuitry is further configured to maintain a write counter and authenticating write access to the RPMB includes generating a Message Authentication Code (MAC) from the write key and the write counter.

5. The apparatus of claim 1 wherein the control circuitry is further configured to generate a Message Authentication Code (MAC) from the read key in combination with a nonce received with the RPMB read command and send the MAC in response to the RPMB read command.

6. The apparatus of claim 1 wherein the RPMB contains image version data for a processor, the control circuitry configured to allow changes to the image version data only by a remote server using the write key and to authenticate the image version data to the processor using the read key.

7. The apparatus of claim 1 wherein the apparatus is located in a vehicle, the RPMB contains image version data for a processor of a vehicle system, the control circuitry configured to allow changes to the image version data only by an entity using the write key and authenticate the image version data to the processor of the vehicle system using the read key.

8. The apparatus of claim 7 wherein the apparatus is coupled to a plurality of vehicle systems as a shared memory system, the RPMB contains data for processors of the plurality of vehicle systems, the plurality of keys including a plurality of read keys and a plurality of write keys for the plurality of vehicle systems.

9. The apparatus of claim 8 wherein the RPMB includes a plurality of RPMB regions, an individual RPMB region associated with a corresponding vehicle system, the control circuitry configured to authenticate write access to the individual RPMB region through a corresponding write key and authenticate read access to the individual RPMB region through a corresponding read key.

10. The apparatus of claim 9 wherein write access to each of the plurality of RPMB regions is exclusive to a corresponding remote server of a plurality of remote servers that contain corresponding write keys, RPMB data for a processor of an individual vehicle system configurable only by a corresponding remote server.

11. A method comprising:

in response to a request for write access to a Replay Protected Memory Block (RPMB) in a non-volatile memory, authenticating a source of the request for write access using a write key stored in the non-volatile memory and granting write access upon authentication;

in response to granting write access, storing data from the source of the request for write access in the RPMB;

in response to a request to read the data stored in the RPMB, authenticating data read from the RPMB using a read key stored in the non-volatile memory and comparing a first image version of code stored in the non-volatile memory with a second image version specified in the data read from the RPMB; and

in response to authenticating and determining that the first image version and the second image version match, using the code stored in the non-volatile memory.

12. The method of claim 11 wherein the source of the request for write access is a remote server that has exclusive access to at least a portion of the RPMB.

13. The method of claim 11 wherein the non-volatile memory is in a vehicle, the request to read the data stored in the RPMB is from a processor in a vehicle system in the vehicle, the code stored in the non-volatile memory is boot code for the processor, and using the code stored in the non-volatile memory includes using the code to boot the processor.

14. The method of claim 13 wherein the RPMB contains a plurality of RPMB regions, an individual RPMB region associated with a corresponding vehicle system, each RPMB region having a corresponding write key, write counter, and read key, authenticating a source of write access to an individual RPMB region uses a corresponding write key and write counter for the individual RPMB region, and authenticating read access to the individual RPMB region uses a corresponding read key for the individual RPMB region.

15. The method of claim 11 further comprising:

in response to authenticating the source of the request for write access, incrementing a write counter.

16. The method of claim 15 wherein authenticating the source of the request for write access includes generating a Message Authentication Code (MAC) from the write key and the write counter and authenticating the data read from the RPMB includes generating a MAC from the read key and a nonce.

17. The method of claim 11 further comprising:

loading the write key into the RPMB while the non-volatile memory is in a secure location;

maintaining a copy of the write key in a remote server; and

subsequently sending the request for write access to the RPMB from the remote server using the write key to authenticate the remote server as the source of the request for write access.

18. The method of claim 17 wherein sending the request for write access includes sending from the remote server a first Message Authentication Code (MAC) calculated from the copy of the write key in the remote server and a first write count, authenticating the source of the request for write access includes calculating a second MAC using the write key stored in the non-volatile memory and a second write count stored in the non-volatile memory and comparing the first MAC and the second MAC, and authenticating the data read from the RPMB includes calculating a third MAC using the read key stored in the non-volatile memory and a nonce, calculating a fourth MAC using a copy of the read key maintained by a processor and the nonce and comparing the third MAC and the fourth MAC, and in response to determining the third MAC is identical to the fourth MAC, the processor using the data read from the RPMB.

19. A memory system, comprising:

a Replay Protected Memory Block (RPMB) formed in a plurality of non-volatile memory cells, the RPMB containing one or more RPMB regions; and

means for providing at the memory system separate read authentication and write authentication for an individual RPMB region such that write access to an individual RPMB region is limited exclusively to a remote server and read authentication to the individual RPMB region is provided to one or more local processors.

20. The memory system of claim 19 further comprising:

means for authenticating at a local processor that read data is from the RPMB using a read key; and

means for authenticating at the remote server that write data is from the remote server using a write key.

Assignments (8)
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2019
From: SELA, ROTEM; SAPIR, MIKI
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 049805/0075 →
Cited By (3)
US 12,572,699 US 12,639,477 US 12,645,373