IP Library › Granted Patent US 12,493,417
Granted Patent B2
US 12,493,417 · App. 17/831,370 · Granted Dec 9, 2025

Verified key replacement in secure memory devices

Inventor: Zhan Liu (Cupertino, CA)
Assignee: Micron Technology, Inc.
G06F3/0622G06F3/0655G06F3/0679H04L9/0838H04L9/3013H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,417
App. No.
17/831,370
Granted
Dec 9, 2025
Kind
B2
Abstract

The disclosure relates to improvements in the delivery of cryptographic data to secure memory devices. In some aspects, the techniques described herein relate to a method including: receiving, by a memory device, a command, the command including a public key and a hash of a unique device secret (UDS); generating, by the memory device, a local UDS using the public key and a locally stored private key; generating, by the memory device, a local UDS hash by inputting the local UDS into a hashing algorithm; determining, by the memory device, whether the local UDS hash matches the hash included in the command; writing, by the memory device, the public key to a key storage area if the local UDS hash matches the hash included in the command; and returning, by the memory device, a failure response if the local UDS hash does not match the hash included in the command.

Claims (42)

1 . A system comprising:

a memory device including a key storage area storing a device public key and a device private key;

a key management server (KMS) configured to receive a unique device secret (UDS) request, generate a UDS in response to the UDS request, compute a hash using the UDS, and return the hash and a KMS public key corresponding to the KMS private key in response to the key request;

a manufacturer computing device configured to receive the KMS public key and the hash as part of the response to the UDS request and issue a command including the KMS public key and the hash to the memory device,

wherein the memory device is configured to compute a local UDS using the KMS public key and the device private key, compute a local UDS hash using the local UDS, compare the local UDS hash to the hash, and write the KMS public key to the key storage area when the local UDS hash matches the hash; and

a customer computing device configured to:

read the device public key;

generate a customer UDS (CUDS) using the device public key;

generate a second hash using the CUDS;

issue a second command including the second hash and a customer public key to the memory device.

2 . The system of claim 1 , wherein the UDS request includes the device public key and the KMS is configured to generate the UDS using the device public key and a KMS private key.

3 . The system of claim 2 , wherein the KMS is configured to generate the UDS using a Diffie-Hellman protocol.

4 . The system of claim 2 , wherein the KMS is configured to generate the UDS using an Elliptic Curve Diffie-Hellman protocol.

5 . The system of claim 1 , wherein the manufacturer is configured to cache the KMS public key in response to the UDS request.

6 . The system of claim 1 , wherein the manufacturer computing device is further configured to detect a failure response associated with the command, request a second UDS hash from the KMS in response to the failure response, and issue a second command including the KMS public key and the second UDS hash.

7 . The system of claim 1 ,

wherein the memory device is configured to generate a second local UDS using the customer public key and the device private key, compute a second local UDS hash using second local UDS, compare the second local UDS hash to the second hash, and write the customer public key to the key storage area if the second local UDS hash is equal to the second hash.

8 . The system of claim 7 , wherein the customer computing device is further configured to include a signature in the second command.

9 . The system of claim 7 , wherein writing the customer public key to the key storage area comprises overwriting an existing public key.

10 . The system of claim 7 , wherein generating a CUDS using the device public key comprises using a key exchange protocol to compute the CUDS using the device public key and a customer private key.

11 . The system of claim 1 , wherein the memory device is further configured to determine that the local UDS hash does not match the hash and, in response, not write the KMS public key to the key storage area.

12 . The system of claim 11 , wherein the memory device returns a failure response in response to determining that the local UDS hash does not match the hash.

13 . A method comprising:

receiving, by a memory device, a command, the command including a public key and a hash of a unique device secret (UDS);

generating, by the memory device, a local UDS using the public key and a locally stored private key;

generating, by the memory device, a local UDS hash by inputting the local UDS into a hashing algorithm;

determining, by the memory device, whether the local UDS hash matches the hash included in the command;

writing, by the memory device, the public key to a key storage area if the local UDS hash matches the hash included in the command; and

returning, by the memory device, a failure response if the local UDS hash does not match the hash included in the command,

wherein determining whether the local UDS hash matches the hash included in the command comprises determining if the local UDS hash is equal to the hash included in the command.

14 . The method of claim 13 , wherein writing the public key to a key storage area comprises overwriting an existing key stored in the key storage area.

15 . The method of claim 13 , wherein returning a failure response comprises returning failure response data as part of the failure response.

16 . A non-transitory computer-readable storage medium for tangibly storing computer program instructions capable of being executed by a computer processor in a memory device, the computer program instructions defining steps of:

receiving, by the memory device, a command, the command including a public key and a hash of a unique device secret (UDS);

generating, by the memory device, a local UDS using the public key and a locally stored private key;

generating, by the memory device, a local UDS hash by inputting the local UDS into a hashing algorithm;

determining, by the memory device, whether the local UDS hash matches the hash included in the command;

writing, by the memory device, the public key to a key storage area if the local UDS hash matches the hash included in the command; and

returning, by the memory device, a failure response if the local UDS hash does not match the hash included in the command,

wherein writing the public key to a key storage area comprises overwriting an existing key stored in the key storage area.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein determining whether the local UDS hash matches the hash included in the command comprises determining if the local UDS hash is equal to the hash included in the command.

18 . The non-transitory computer-readable storage medium of claim 16 , wherein returning a failure response comprises returning failure response data as part of the failure response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2022
From: LIU, ZHAN
To: MICRON TECHNOLOGY, INC.
Reel/Frame 060588/0826 →
Continuity (1)
Related Publication 20230393762A1 · Dec 7, 2023
References Cited (25)
US 6240187B1 · Lewis · 2001 [cited by examiner]
US 10193694B1 · Guditz · 2019 [cited by examiner]
US 11036677B1 · Grunwald · 2021 [cited by examiner]
US 20060294378A1 · Lumsden · 2006 [cited by examiner]
US 20120167169A1 · Ge · 2012 [cited by examiner]
US 20140247939A1 · Hattori · 2014 [cited by examiner]
US 20150310231A1 · Lin · 2015 [cited by examiner]
US 20180190051A1 · Outwater · 2018 [cited by examiner]
US 20190058591A1 · Sharpe · 2019 [cited by examiner]
US 20190230002A1 · Bernat · 2019 [cited by examiner]
US 20220141041A1 · Parikh · 2022 [cited by examiner]
US 20220417030A1 · Shrivastava · 2022 [cited by examiner]
US 20230097712A1 · Sullivan · 2023 [cited by examiner]
WO WO2016065892A1 · 2016 [cited by examiner]
WO WO2020082160A1 · 2020 [cited by examiner]
Fumy et al., “Principles of key management,” in IEEE Journal on Selected Areas in Communications, vol. 11, No. 5, pp. 785-793, Jun. 1993, doi: 10.1109/49.223881. (Year: 1993). [cited by examiner]
Witzke et al., “Key management for large scale end-to-end encryption,” 1994 Proceedings of IEEE International Carnahan Conference on Security Technology, Albuquerque, NM, USA, 1994, pp. 76-79, doi: 10.1109/CCST.1994.363… [cited by examiner]
Carvajal-Roca et al., “A Semi-Centralized Dynamic Key Management Framework for In-Vehicle Networks,” in IEEE Transactions on Vehicular Technology, vol. 70, No. 10, pp. 10864-10879, Oct. 2021, doi: 10.1109/TVT.2021.31066… [cited by examiner]
Shan, “On the Security of a Certificateless Strong Designated Verifier Signature Scheme with Non-delegatability,” 2020 International Conference on Internet of Things and Intelligent Applications (ITIA), Zhenjiang, China… [cited by examiner]
Han et al., “Two-Factor Distributed Authentication Scheme for Cloud Storage,” 2024 9th International Conference on Computer and Communication Systems (ICCCS), Xi'an, China, 2024, pp. 297-303, doi: 10.1109/ICCCS61882.202… [cited by examiner]
Gassend et al., “Caches and hash trees for efficient memory integrity verification,” The Ninth International Symposium on High-Performance Computer Architecture, 2003. HPCA-9 2003. Proceedings., Anaheim, CA, USA, 2003, … [cited by examiner]
Bravi et al., “Exploiting the DICE specification to ensure strong identity and integrity of loT devices,” 2023 8th International Conference on Smart and Sustainable Technologies (SpliTech), Split/Bol, Croatia, 2023, pp.… [cited by examiner]
Naik et al., “A Hardware Implementation of DICE on a RISC-V Processor,” 2024 International Conference on Circuit, Systems and Communication (ICCSC), Fes, Morocco, 2024, pp. 1-6, doi: 10.1109/ICCSC62074.2024.10616834. (Y… [cited by examiner]
Barry, “Enabling Certifiable Asymmetric Cryptography for Hardware Attestation Protocols,” 2024 Cyber Research Conference—Ireland (Cyber-RCI), Carlow, Ireland, 2024, pp. 1-4, doi: 10.1109/Cyber-RCI60769.2024.10939787. (Y… [cited by examiner]
Adi, “Autonomous Physical Secret Functions and Clone-Resistant Identification,” 2009 Symposium on Bio-inspired Learning and Intelligent Systems for Security, Edinburgh, UK, 2009, pp. 83-88, doi: 10.1109/BLISS.2009.16. (… [cited by examiner]