IP Library › Granted Patent US 12,619,791
Granted Patent B2
US 12,619,791 · App. 17/146,274 · Granted May 5, 2026

Encrypted key management

Inventors: David Hulton (Seattle, WA); Jeremy Chritz (Seattle, WA)
Assignee: Micron Technology, Inc.
G06F21/79G06F12/0246G06F13/1668G06F13/4068G06F13/4221G06F21/602G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,791
App. No.
17/146,274
Granted
May 5, 2026
Kind
B2
Abstract

Examples of systems and methods described herein provide for erasing an encrypted key used for data access to a non-volatile memory device. A memory controller may generate an encrypted key for data access to non-volatile memory devices; and, to provide security of data stored on the non-volatile memory devices, the memory controller may store the encrypted key in a local cache of the memory controller. The encrypted key may be erased responsive to losing power or powering down of memory controller. Advantageously, the data stored at the non-volatile memory device may not be accessed when the memory controller (or a computing device implementing the memory controller) loses power. Accordingly, if a malicious actor were to physically remove (or steal) a computing device implementing the memory controller (e.g., a laptop computer), in an attempt to acquire the data, the data stored on the non-volatile memory devices could not be accessed.

Claims (49)

1 . A method comprising:

writing, to a cache coupled to a volatile memory device and a memory controller, an encrypted key to provide authenticated access to encrypted data stored at a plurality of non-volatile memory devices coupled to the volatile memory device and the memory controller, wherein the encrypted data is accessible at a host coupled to the plurality of non-volatile memory devices using the memory controller, wherein the encrypted key is specific to data associated with a memory address of a memory access request, and wherein the memory address of the memory access request corresponds to a memory address of at least one of the plurality of non-volatile memory devices;

detecting, by the memory controller a loss of power by comparing a received voltage to a threshold operating voltage;

determining, by the memory controller and using a timing circuit, that a duration of the loss of power exceeds a threshold amount of time; and

responsive to the determination that the duration of the loss of power exceeds the threshold amount of time, erasing the stored encrypted key for the plurality of non-volatile memory devices.

2 . The method of claim 1 , further comprising:

receiving a power down indication for the volatile memory device that is electrically connected to at least one non-volatile memory device of the plurality of non-volatile memory devices.

3 . The method of claim 2 , wherein the volatile memory device that is electrically connected to the at least one non-volatile memory device is powered by a computing device electrically connected to a power source.

4 . The method of claim 3 , wherein the computing device electrically connected to the power source is the memory controller.

5 . The method of claim 1 , wherein the plurality of non-volatile memory devices comprise at least one of a NAND memory device or a 3D XPoint memory device.

6 . The method of claim 1 , further comprising:

receiving a pseudorandom value from a pseudorandom number generator;

encrypting a key for at least one non-volatile memory device of the plurality of non-volatile memory devices based partly on the pseudorandom value; and

providing the encrypted key for the at least one non-volatile memory device to the at least one non-volatile memory device.

7 . The method of claim 6 , wherein encrypting the key for the at least one non-volatile memory device based partly on the pseudorandom value comprises using an authenticated stream cipher to generate the key.

8 . The method of claim 7 , wherein the authenticated stream cipher comprises an advanced encryption standard (AES) cipher that uses the pseudorandom value as an initialization vector.

9 . The method of claim 1 , wherein the threshold amount of time is set by a user, or wherein the threshold amount of time is based on a flicker metric.

10 . The method of claim 1 , wherein erasing the stored encrypted key includes terminating, by the memory controller, a connection between the cache and a power supply.

11 . A method comprising:

receiving, from a host computing device coupled to a plurality of non-volatile memory devices, a memory access request for a non-volatile memory device of the plurality of non-volatile memory devices;

responsive to the memory access request, encrypting, at encryption logic comprising an advanced encryption standard (AES) cipher, a key for data associated with the memory access request, wherein the key is to provide authenticated access, by the host computing device, to encrypted data stored at the plurality of non-volatile memory devices, wherein the encrypted key is specific to data associated with a memory address of the memory access request, and wherein the memory address of the memory access request corresponds to a memory address of at least one of the plurality of non-volatile memory devices;

writing, to a cache of a memory controller, the key for the plurality of non-volatile memory devices;

providing, to at least one non-volatile memory device, the key for accessing, by the host computing device, data associated with the memory access request;

detecting, by the memory controller, a loss of power by comparing a received voltage to a threshold operating voltage;

determining, by the memory controller and using a timing circuit, that a duration of the loss of power exceeds a threshold amount of time; and

erasing, by the memory controller, the key when the duration of the loss of power exceeds the threshold amount of time.

12 . The method of claim 11 , further comprising:

powering down the memory controller.

13 . The method of claim 11 , further comprising:

receiving a power down indication for the memory controller; and

disconnecting an electrical connection to the memory controller.

14 . The method of claim 13 , wherein the host computing device comprises the memory controller, and wherein disconnecting the electrical connection to the memory controller comprises disconnecting an electrical connection of host computing device.

15 . The method of claim 11 , wherein writing, to the cache of a memory controller, the key for the at least one non-volatile memory device comprises configuring the cache of the memory controller to be associated with the AES cipher.

16 . The method of claim 11 , further comprising:

providing/retrieving, to/from the at least one non-volatile memory device, the data associated with the memory access request using the key.

17 . The method of claim 16 , when retrieving from the at least one non-volatile memory device the data associated with the memory access request, the method further comprising:

decrypting the data associated with the memory request using the key.

18 . An apparatus comprising:

encryption logic configured to encrypt a key configured to provide authenticated access, by a host, to encrypted data stored at a plurality of non-volatile memory devices coupled to the host, wherein the encrypted key is specific to data associated with a memory address of a memory access request and wherein the memory address of the memory access request corresponds to a memory address of at least one of the plurality of non-volatile memory devices;

a cache of a volatile memory configured to store the key;

a memory bus coupled to the plurality of non-volatile memory devices, the encryption logic further configured to provide, via the memory bus, the key to at least one non-volatile memory device of the plurality of non-volatile memory devices coupled to the host; and

a memory controller configured to detect a loss of power by comparing a received voltage to a threshold operating voltage and to erase the key from the cache when a duration of the loss of power exceeds a threshold amount of time.

19 . The apparatus of claim 18 , wherein the at least one non-volatile memory device comprises a NAND memory device and the memory bus comprises an NVDIMM bus.

20 . The apparatus of claim 18 , wherein the encryption logic is further configured to receive the memory access request from the host via a PCIe bus and to provide the key with the memory access request.

21 . The apparatus of claim 20 , wherein to provide the memory access request with the key, the encryption logic is further configured to identify the memory address, in the memory access request, that corresponds to the memory address of the at least one non-volatile memory device.

22 . The apparatus of claim 18 , wherein the memory controller is coupled to the at least one non-volatile memory device via an NVDIMM bus.

23 . The apparatus of claim 18 , wherein the cache comprises a register configured to store the key.

24 . The method of claim 1 , wherein the host is separate from the plurality of non-volatile memory devices, and wherein the cache is included in the memory controller.

25 . The apparatus of claim 18 , wherein the encryption logic comprises an advanced encryption standard (AES) cipher.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2021
From: HULTON, DAVID; CHRITZ, JEREMY
To: MICRON TECHNOLOGY, INC.
Reel/Frame 054880/0826 →
Continuity (1)
Related Publication 20220222384A1 · Jul 14, 2022
References Cited (55)
US 5457748A · Bergum · 1995 [cited by examiner]
US 7814316B1 · Hughes · 2010 [cited by examiner]
US 8674823B1 · Contario · 2014 [cited by examiner]
US 8938624B2 · Obukhov · 2015 [cited by examiner]
US 9954828B1 · Chandrasekhar · 2018 [cited by examiner]
US 10175118B1 · Rezayee · 2019 [cited by examiner]
US 10733291B1 · McLeod · 2020 [cited by examiner]
US 10809944B1 · Ostrikov et al. · 2020 [cited by applicant]
US 10929572B2 · Wu · 2021 [cited by examiner]
US 11409918B1 · Sugavanam · 2022 [cited by examiner]
US 11537298B2 · Chritz et al. · 2022 [cited by applicant]
US 11899829B2 · Chritz et al. · 2024 [cited by applicant]
US 11899942B2 · Chritz et al. · 2024 [cited by applicant]
US 12321616B2 · Chritz et al. · 2025 [cited by applicant]
US 20050076228A1 · Davis · 2005 [cited by examiner]
US 20100005317A1 · Pribadi et al. · 2010 [cited by applicant]
US 20110082979A1 · Ramesh · 2011 [cited by examiner]
US 20110154043A1 · Lim et al. · 2011 [cited by applicant]
US 20110205016A1 · Al-azen et al. · 2011 [cited by applicant]
US 20150058637A1 · Raskin · 2015 [cited by examiner]
US 20160018996A1 · Doumen · 2016 [cited by applicant]
US 20160078252A1 · Chandra et al. · 2016 [cited by applicant]
US 20160098359A1 · Adkins et al. · 2016 [cited by applicant]
US 20160204931A1 · Kamath et al. · 2016 [cited by applicant]
US 20180095675A1 · Kachare et al. · 2018 [cited by applicant]
US 20180181499A1 · Branco et al. · 2018 [cited by applicant]
US 20180307848A1 · Leiseboer · 2018 [cited by examiner]
US 20180349293A1 · Lin · 2018 [cited by applicant]
US 20180373598A1 · Mondello et al. · 2018 [cited by applicant]
US 20190050347A1 · Bolotov et al. · 2019 [cited by applicant]
US 20190056999A1 · Foxworth · 2019 [cited by examiner]
US 20190243714A1 · Foxworth · 2019 [cited by examiner]
US 20200226270A1 · Benedict · 2020 [cited by applicant]
US 20200364159A1 · Lee et al. · 2020 [cited by applicant]
US 20210240862A1 · Pelissier et al. · 2021 [cited by applicant]
US 20210328790A1 · Eckel · 2021 [cited by examiner]
US 20210377017A1 · Benisty · 2021 [cited by examiner]
US 20220050741A1 · Lee · 2022 [cited by applicant]
US 20220171545A1 · Chritz et al. · 2022 [cited by applicant]
US 20220171887A1 · Chritz et al. · 2022 [cited by applicant]
US 20230126741A1 · Chritz et al. · 2023 [cited by applicant]
US 20240176916A1 · Chritz et al. · 2024 [cited by applicant]
US 20240201871A1 · Chritz et al. · 2024 [cited by applicant]
US 20250225236A1 · Chritz et al. · 2025 [cited by applicant]
CN 109255231A · 2019 [cited by applicant]
EP 3716071A1 · 2020 [cited by applicant]
JP 2009245020A · 2009 [cited by examiner]
JP 2012168737A · 2012 [cited by applicant]
WO 2022119819A1 · 2022 [cited by applicant]
WO 2022119822A1 · 2022 [cited by applicant]
U.S. Appl. No. 18/146,120, filed Dec. 23, 2022 titled, “Memory Systems and Devices Including Examples of Accessing Memory Andgenerating Access Codes Using an Authenticated Stream Cipher,”; pp. all pages of application a… [cited by applicant]
U.S. Appl. No. 17/108,904, titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, dated Dec. 1, 202. [cited by applicant]
U.S. Appl. No. 17/108,934, titled “Memory Systems and Devices Including Examples of Generating Access Codes for Memory Regions Using Authentication Logic”, dated Dec. 1, 2020. [cited by applicant]
U.S. Appl. No. 18/428,157 titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, filed Jan. 31, 2024; pp. all pages of application as… [cited by applicant]
U.S. Appl. No. 19/205,070 titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, filed May 12, 2025; pp. all pages of application as … [cited by applicant]
Cited By (1)
US 12,748,841