IP Library Granted Patent US 11,797,717
Granted Patent B2
US 11,797,717 · App. 16/765,224 · Granted Oct 24, 2023

Bus encryption for non-volatile memories

Inventors: Paolo Amato (Treviglio, IT); Marco Sforzin (Cernusco sul Naviglio, IT); Daniele Balluchi (Cernusco sul Naviglio, IT); Danilo Caraccio (Milan, IT); Niccolo Izzo (Vignate, IT)
Assignee: Micron Technology, Inc.
G06F21/85G06F12/0246G06F12/1408G06F21/602G06F21/79
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,717
App. No.
16/765,224
Granted
Oct 24, 2023
Kind
B2
Abstract

The present disclosure relates to apparatuses and methods for memory management. The disclosure further relates to an interface protocol for flash memory devices including at least a memory array and a memory controller coupled to the memory array. A host device is coupled to the memory device through a communication channel and a hardware and/or software full encryption-decryption scheme is adopted in the communication channel for data, addresses and commands exchanged between the host device and the memory array.

Claims (39)

1. An apparatus comprising:

a memory device including a memory array;

a host device coupled to the memory device via a communication channel;

the memory device configured to store data in plaintext form;

wherein the memory device and the host device are configured to:

implement a communication channel-only encryption-decryption scheme integrated in the communication channel for the data, addresses, and commands exchanged through the communication channel between the host device and the memory array;

wherein the encryption-decryption scheme includes encryption of the data, addresses, and commands ready to be sent through the communication channel and decryption of the encrypted data back to plaintext form, addresses, and commands received over the communication channel while not increasing write amplification; and

wherein the encryption includes a first hash function, a second hash function arranged symmetrically in an encryption block to the first hash function, a first stream cipher, and a second stream cipher arranged symmetrically in the encryption block to the first stream cipher;

track a TAG value transmitted on the communication channel; and

compare a value of the TAG value before transmission on the communication channel and after transmission on the communication channel.

2. The apparatus of claim 1 , wherein the encryption-decryption scheme is implemented according to a UFS protocol.

3. The apparatus of claim 2 , wherein the encryption-decryption scheme is implemented as an intervention integrated between a physical Adapter Layer and a lower physical sublayer supporting a specification M-PHY.

4. The apparatus of claim 1 , wherein the memory device comprises a non-volatile NAND memory device.

5. The apparatus of claim 1 , wherein the memory device includes a memory controller in communication with the communication channel and configured to encrypt the data, addresses, and commands ready to be sent through the communication channel and decrypt the encrypted data, addresses, and commands received over the communication channel.

6. The apparatus of claim 1 , wherein the host device includes a controller in communication with the communication channel and configured to encrypt the data, addresses, and commands ready to be sent through the communication channel and decrypt the encrypted data, addresses, and commands received over the communication channel.

7. The apparatus of claim 1 , wherein the encryption-decryption scheme includes an authenticated encryption AE block receiving as inputs a secret key and an initialization vector.

8. The apparatus of claim 1 , wherein the data, addresses and commands exchanged through the communication channel are encrypted through a Replay Protected Memory Block (RPMB) that guarantees the integrity of data, addresses and commands using a symmetrical encryption.

9. The apparatus of claim 1 , wherein the communication channel is an interconnecting bus, a wireless channel, or an optical channel.

10. A memory device including:

a memory controller communicatively coupled to an external device through a communication channel;

wherein the memory controller is configured to:

enable or disable data scrambling each power mode change request,

wherein the data scrambling is performed on inbound data and outbound data;

encrypt addresses, commands, and the data ready to be sent through the communication channel and decrypt encrypted addresses, commands, and the data received over the communication channel,

wherein the encryption includes a first hash function, a second hash function arranged symmetrically in an encryption block to the first hash function, a first stream cipher, and a second stream cipher arranged symmetrically in the encryption block to the first stream cipher;

track a TAG value transmitted on the communication channel; and

compare a value of the TAG value before transmission on the communication channel and after transmission on the communication channel.

11. A memory device according to claim 10 , wherein the memory device comprises a storage class memory.

12. The memory device of claim 10 , wherein the memory device is a hybrid memory device including a first storage class memory array and a second non-volatile memory array.

13. The memory device of claim 12 , wherein the second non-volatile memory array comprises a non-volatile NAND Flash memory device.

14. A method, comprising:

utilizing a universal flash storage (UFS) communication protocol for exchanging data, addresses, and commands across a communication channel communicatively coupled to a memory device; and

implementing a full encryption and decryption scheme for the data, addresses and commands exchanged on the communication channel, wherein implementing the full encryption and decryption scheme includes:

encrypting data, addresses, and commands ready to be sent through the communication channel,

wherein the encryption includes a first hash function, a second hash function arranged symmetrically in an encryption block to the first hash function, a first stream cipher, and a second stream cipher arranged symmetrically in the encryption block to the first stream cipher;

decrypting of encrypted data, addresses, and commands received over the communication channel; and

performing the encrypting and the decrypting as an intervention integrated between a physical Adapter Layer and a lower physical sublayer supporting a specification M-PHY as a portion of a communication channel-only encryption and decryption scheme.

15. The method of claim 14 , wherein the encrypting and the decrypting includes a scrambling phase that once activated is not deactivated but reset.

16. The method of claim 14 , wherein the encrypting and the decrypting comprises encrypting the data, addresses and commands ready to be sent through the communication channel utilizing an Authenticated Encryption primitive.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: AMATO, PAOLO; SFORZIN, MARCO; BALLUCHI, DANIELE; CARACCIO, DANILO; IZZO, NICCOLÒ
To: MICRON TECHNOLOGY, INC.
Reel/Frame 061163/0613 →
Continuity (1)
Related Publication 20210406411A1 · Dec 30, 2021