IP Library › Granted Patent US 12,457,103
Granted Patent B2
US 12,457,103 · App. 17/150,834 · Granted Oct 28, 2025

Server system to control memory devices over computer networks

Inventor: Travis Duane Nelson (Boise, ID)
Assignee: Micron Technology, Inc.
H04L9/088G06F21/606
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,103
App. No.
17/150,834
Granted
Oct 28, 2025
Kind
B2
Abstract

A system, method and apparatus to control memory devices over computer networks. For example, the system includes a first computer system and a second computer system. The second computer system manages cryptographic key; and the first computer system controls access to the second computer system. After establishing a secure authenticated connection between the first computer system and a client computer system, the client computer system may submit a request about a memory device. If the first computer system determines that the client computer system is eligible to operate or control the memory device, the first computer system communicate with the second computer system to generate a response to the request using at least a cryptographic key stored in the second computer system in association with an unique identification of the memory device, without the cryptographic key being transmitted to outside of the second computer system.

Claims (48)

1. A method, comprising:

establishing, by a first computer system with a client computer system having a memory device, a secure authenticated connection, wherein the memory device is configured as part of the client computer system to at least store software running in the client computer system, wherein the memory device is further configured to store a unique device secret that is inaccessible from outside of the memory device after completion of manufacture of the memory device, wherein the unique device secret is never sent from the memory device to any device external to the memory device, and wherein a cryptographic key derived at least in part from the unique device secret is never sent from the memory device to any device external to the memory device;

receiving, in the first computer system over the secure authenticated connection from the client computer system, a request about the memory device remote from the first computer system;

determining, based on data stored in the first computer system, that the client computer system is eligible to operate the memory device; and

communicating, by the first computer system, with a second computer system secured behind the first computer system to generate a response to the request using at least the cryptographic key stored in the second computer system in association with an unique identification of the memory device, wherein the memory device is configured to control access to the memory device by the client computer system based on the cryptographic key, wherein after the response is generated and communicated to the client computer system the access to the memory device is permitted without communications between the client computer system and both of the first computer system and the second computer system.

2. The method of claim 1 , wherein the response is generated via the second computer system performing operations using the cryptographic key without transmitting the cryptographic key outside of the second computer system.

3. The method of claim 2 , further comprising:

storing, in the first computer system, a list of Internet Protocol (IP) addresses;

determining, by the first computer system, whether to establish the secure authenticated connection based at least in part on whether an address of the client computer system is in the list.

4. The method of claim 3 , wherein the establishing of the secure authenticated connection comprises:

receiving, in the first computer system, a first certificate from the client computer system, the first certificate indicating an identity of the client computer system; and

validating the first certificate.

5. The method of claim 4 , wherein the establishing of the secure authenticated connection further comprises:

providing, by the first computer system to the client computer system, a second certificate to indicate an identity of the first computer system, wherein the client computer system is configured to validate the second certificate prior to the establishing of the secure authenticated connection.

6. The method of claim 5 , wherein the establishing of the secure authenticated connection further comprises:

establishing a session key to encrypt data transmitted via the secure authenticated connection.

7. The method of claim 3 , wherein the request includes identity data of the memory device; and the response includes an indication of whether the memory device is authentic according to the cryptographic key.

8. The method of claim 7 , wherein the cryptographic key is generated by the second computer system based on the unique device secret of the memory device stored into, during the manufacture of the memory device, the second computer system.

9. The method of claim 7 , further comprising:

establishing, by the first computer system with the second computer system, a separate secure authenticated connection, wherein the communicating of the first computer system with a second computer system is through the separate secure authenticated connection.

10. The method of claim 7 , wherein the response includes a command executable in the memory device to transfer a privilege to an operator of the client computer system.

11. The method of claim 10 , wherein the command includes a digital signature applied on the command using a cryptographic key of a current holder of the privilege; and the command is executable in the memory device after the digital signature is validated by the memory device.

12. The method of claim 7 , wherein the response includes a command executable in the memory device to activate at least one security feature of the memory device.

13. The method of claim 7 , wherein the response includes a cryptographic key usable to apply a digital signature on a command to be executed by the memory device upon validation of the digital signature in the memory device.

14. A computer system, comprising:

memory storing data indicative of privileges of client computer systems to control memory devices; and

at least one processor configured via a set of instructions to:

establish, with a client computer having a local connection to a memory device, a secure authenticated connection, wherein the memory device is configured to at least store software running in the client computer, wherein the memory device is further configured to store a unique device secret that is never sent from the memory device to any device external to the memory device, and wherein a cryptographic key derived at least in part from the unique device secret is never sent from the memory device to any device external to the memory device;

receive, over the secure authenticated connection from the client computer, a request about the memory device remote from the computer system;

determine, based on the data indicative of the privileges, that the client computer is eligible to control the memory device; and

communicate with a server computer secured behind the computer system to generate a response to the request using at least a cryptographic key stored in the server computer in association with an unique identification of the memory device, wherein the response is generated without transmission of the cryptographic key from the server computer, wherein the memory device is configured to allow the client computer to control the memory device over the local connection using the cryptographic key without going through a connection to the computer system, wherein the memory device is configured to control access to the memory device by the client computer based on the cryptographic key, wherein after the response is communicated to the client computer the access to the memory device is permitted without communications between the server computer and the client computer.

15. The computer system of claim 14 , wherein the at least one processor is further configured to determine whether to establish the secure authenticated connection based at least in part on whether an address of the client computer is in a predetermined list of Internet Protocol (IP) addresses.

16. The computer system of claim 14 , wherein the request includes identity data of the memory device; the response includes an indication of whether the memory device is authentic according to the cryptographic key; and wherein the cryptographic key is generated by the server computer based on the unique device secret of the memory device stored in the server computer.

17. The computer system of claim 16 , wherein the response includes a command executable in the memory device to transfer a privilege to an operator of the client computer, or to activate at least one security feature of the memory device, or any combination thereof; and wherein the command includes a digital signature applied on the command using a cryptographic key; and the command is executable in the memory device after the digital signature is validated by the memory device.

18. The computer system of claim 17 , wherein the response includes a cryptographic key usable to apply a digital signature on a command to be executed by the memory device upon validation of the digital signature in the memory device.

19. A non-transitory computer storage medium storing instructions which, when executed by a computer system, cause the computer system to perform a method, the method comprising:

establishing, with a client computer having a memory device, a secure authenticated connection, wherein the memory device is configured to at least store software running in the client computer, wherein the memory device is further configured to store a unique device secret that is never sent from the memory device to any device external to the memory device, and wherein a cryptographic key derived at least in part from the unique device secret is never sent from the memory device to any device external to the memory device;

receiving, over the secure authenticated connection from the client computer, a request about the memory device remote to the computer system;

determining, based on data stored in the computer system and representative of privileges of client computer systems to control memory devices, that the client computer is eligible to control the memory device; and

communicating with a server computer secured behind the computer system to generate a response to the request using at least a cryptographic key stored in the server computer in association with an unique identification of the memory device, wherein the response is generated without transmission of the cryptographic key from the server computer, wherein the memory device is controllable by the client computer using the cryptographic key without going through a connection to the computer system, wherein the memory device is configured to control access to the memory device by the client computer based on the cryptographic key, wherein after the response is communicated to the client computer the access to the memory device is permitted without communications between the client computer and the server computer.

20. The non-transitory computer storage medium of claim 19 ,

wherein the method further comprises:

determining whether to establish the secure authenticated connection based at least in part on whether an address of the client computer is in a predetermined list of Internet Protocol (IP) addresses;

wherein the response includes at least one of:

an indication of whether the memory device is authentic according to the cryptographic key, wherein the cryptographic key is generated by the server computer based on an unique device secret of the memory device stored in the server computer;

a cryptographic key usable to apply a digital signature on a command to be executed by the memory device upon validation of the digital signature in the memory device;

a command having a digital signature and executable in the memory device to transfer a privilege to an operator of the client computer; and

a command having a digital signature and executable in the memory device to activate at least one security feature of the memory device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: NELSON, TRAVIS DUANE
To: MICRON TECHNOLOGY, INC.
Reel/Frame 054938/0199 →
Continuity (1)
Related Publication 20220231838A1 · Jul 21, 2022
References Cited (53)
US 8042163B1 · Karr · 2011 [cited by examiner]
US 8539567B1 · Logue et al. · 2013 [cited by applicant]
US 9530027B2 · Shahidzadeh et al. · 2016 [cited by applicant]
US 11483148B2 · Nelson et al. · 2022 [cited by applicant]
US 20030021417A1 · Vasic et al. · 2003 [cited by applicant]
US 20060180661A1 · Grant et al. · 2006 [cited by applicant]
US 20060248346A1 · Shiomi · 2006 [cited by examiner]
US 20070162674A1 · Leichsenring · 2007 [cited by examiner]
US 20070234042A1 · Gantman · 2007 [cited by examiner]
US 20080244204A1 · Cremelle et al. · 2008 [cited by applicant]
US 20090178124A1 · Manion · 2009 [cited by examiner]
US 20100071030A1 · Rosenan et al. · 2010 [cited by applicant]
US 20100142706A1 · Ryan, Jr. et al. · 2010 [cited by applicant]
US 20130061291A1 · Hegg · 2013 [cited by examiner]
US 20130125249A1 · Sadovsky et al. · 2013 [cited by applicant]
US 20130160145A1 · Henzie et al. · 2013 [cited by applicant]
US 20130212663A1 · Edge et al. · 2013 [cited by applicant]
US 20130262877A1 · Neve De Mevergnies et al. · 2013 [cited by applicant]
US 20130266137A1 · Blankenbeckler et al. · 2013 [cited by applicant]
US 20130301829A1 · Kawamura · 2013 [cited by examiner]
US 20140044265A1 · Kocher et al. · 2014 [cited by applicant]
US 20140130142A1 · Plewnia · 2014 [cited by examiner]
US 20140281563A1 · Nagai · 2014 [cited by examiner]
US 20150074406A1 · Nagai et al. · 2015 [cited by applicant]
US 20160028722A1 · Kocher et al. · 2016 [cited by applicant]
US 20160140334A1 · Forehand · 2016 [cited by examiner]
US 20160182487A1 · Zhu · 2016 [cited by examiner]
US 20160234022A1 · Motika · 2016 [cited by examiner]
US 20170171183A1 · Lingappa · 2017 [cited by examiner]
US 20170223005A1 · Birgisson · 2017 [cited by examiner]
US 20170237725A1 · Camenisch · 2017 [cited by examiner]
US 20180152299A1 · Rossi · 2018 [cited by examiner]
US 20180302400A1 · Covdy · 2018 [cited by examiner]
US 20180307867A1 · Dover · 2018 [cited by examiner]
US 20190294765A1 · Fine · 2019 [cited by examiner]
US 20190319799A1 · Suresh et al. · 2019 [cited by applicant]
US 20200092090A1 · Lin · 2020 [cited by examiner]
US 20200210596A1 · Cariello et al. · 2020 [cited by applicant]
US 20210176056A1 · Cai · 2021 [cited by examiner]
US 20210176247A1 · Smith · 2021 [cited by examiner]
US 20220231839A1 · Nelson et al. · 2022 [cited by applicant]
US 20220231858A1 · Dover · 2022 [cited by applicant]
US 20230006816A1 · Nelson et al. · 2023 [cited by applicant]
CN 101179703 · 2008 [cited by applicant]
CN 107294726 · 2017 [cited by applicant]
EP 1853028 · 2007 [cited by applicant]
KR 20090071307 · 2009 [cited by applicant]
WO 2010078755 · 2010 [cited by applicant]
International Search Report and Written Opinion, PCT/US2022/011458, mailed on Apr. 27, 2022. [cited by applicant]
Control of Memory Devices over Computer Networks, U.S. Appl. No. 17/150,840, filed Jan. 15, 2021, Aug. 21, 2021, Lance Dover, Docketed New Case—Ready for Examination. [cited by applicant]
Batch Transfer of Control of Memory Devices over Computer Networks, U.S. Appl. No. 17/150,849, filed Jan. 15, 2021, Oct. 5, 2022, Travis Nelson, et al., Patented Case. [cited by applicant]
Batch Transfer of Control of Memory Devices over Computer Networks, U.S. Appl. No. 17/943,574, filed Sep. 13, 2022, Oct. 4, 2022, Travis Nelson, et al., Docketed New Case—Ready for Examination. [cited by applicant]
U.S. Appl. No. 17/150,834. [cited by applicant]