Batch transfer of control of memory devices over computer networks
View Patent ↗A system, method and apparatus to control memory devices over computer networks. For example, a server system establishes a secure authenticated connection with a client computer system to receive a request having a batch identification that is configured in the server system to identify a batch of multiple memory devices. After determining that the client computer system is eligible to control the multiple memory devices in the batch, the server system transmits to the client computer system a response. The response contains control data for each respective memory device in the batch. The control data is based on at least a cryptographic key stored in the server system in association with the respective memory device. Using the control data the client computer system submits a command with a digital signature to the respective memory device, which validates the digital signature prior to execution of the command.
1 . A method, comprising:
storing data associating a batch identification with unique identifications of a batch of memory devices and authentication information of an entity; and
communicating, based on a computing device being authenticated according to the authentication information and the batch identification, cryptographic data to the computing device to enable the computing device to access the memory devices in the batch.
2 . The method of claim 1 , wherein the authentication information includes an internet protocol address of the computing device.
3 . The method of claim 1 , wherein the authentication information of the entity includes a public key of the entity; and authenticating according to the authentication information includes validation of a message received from the computing device using the public key.
4 . The method of claim 3 , wherein the message includes a certificate; and the validation of the message includes a determination of whether the certificate is signed using a private key associated with the public key according to a technique of asymmetric cryptography.
5 . The method of claim 1 , wherein for a respective memory device in the batch, the cryptographic data includes:
a unique identification that uniquely identifies the respective memory device among the memory devices in the batch; and
control data usable to access the respective memory device.
6 . The method of claim 5 , wherein the control data includes a cryptographic nonce and a digital signature that is based on the cryptographic nonce.
7 . The method of claim 5 , wherein the control data includes a hash-based message authentication code for a message including a cryptographic nonce.
8 . The method of claim 7 , wherein the message further includes a command executable in the respective memory device to access the respective memory device.
9 . The method of claim 8 , wherein when executed in the respective memory device, the command causes the respective memory device to replace a cryptographic key.
10 . The method of claim 8 , wherein when executed in the respective memory device, the command causes the respective memory device to activate a security feature of the respective memory device.
11 . The method of claim 1 , wherein the cryptographic data is first cryptographic data, and wherein each respective memory device in the batch is configured with second cryptographic data to secure access to the respective memory device.
12 . A system, comprising:
an access control server configured to store a batch identification of a batch of memory devices in association with authentication information of an entity;
wherein the access control server is further configured to, based on a computing device being authenticated according to the authentication information and the batch identification, communicate cryptographic data to the computing device to enable the computing device to access the memory devices in the batch.
13 . The system of claim 12 , wherein the authentication information includes:
an internet protocol address of the computing device; and
a public key of the entity;
wherein the access control server is configured to validate, using the public key, a message received from the computing device to authenticate the computing device.
14 . The system of claim 13 , wherein the message includes a certificate; and the access control server is configured to validate the message based on whether the certificate is signed using a private key associated with the public key according to a technique of asymmetric cryptography.
15 . The system of claim 12 , wherein for a respective memory device in the batch, the cryptographic data includes:
a unique identification that uniquely identifies the respective memory device among the memory devices in the batch; and
control data usable to access the respective memory device.
16 . The system of claim 15 , wherein the control data includes a cryptographic nonce and a digital signature on a message that includes the cryptographic nonce.
17 . The system of claim 16 , wherein the message further includes a command executable in the respective memory device to access the respective memory device.
18 . The system of claim 17 , wherein when executed in the respective memory device, the command causes the respective memory device to replace a cryptographic key.
19 . The system of claim 17 , wherein when executed in the respective memory device, the command causes the respective memory device to activate a security feature of the respective memory device.
20 . The system of claim 12 , further comprising a key management server configured to store a cryptographic key of a respective memory device in association with a unique identification of the respective memory device.
21 . The system of claim 20 , wherein the memory devices in the batch comprise the respective memory device having the unique identification.
22 . A non-transitory computer storage medium storing instructions which, when executed by a system, cause the system to perform a method, the method comprising:
storing data associating a batch identification with unique identifications of a batch of memory devices and authentication information of an entity; and
communicating, based on a computing device being authenticated according to the authentication information and the batch identification, cryptographic data to the computing device to enable the computing device to access the memory devices in the batch.
23 . The non-transitory computer storage medium of claim 22 , wherein the authentication information includes:
an internet protocol address of the computing device; and
a public key of the entity;
wherein an access control server is configured to validate, using the public key, a certificate of the computing device to authenticate the computing device; and
wherein for a respective memory device in the batch, the cryptographic data includes:
a unique identification that uniquely identifies the respective memory device among the memory devices in the batch; and
a hash-based message authentication code for a message including:
a cryptographic nonce; and
a command executable in the respective memory device to access the respective memory device.
24 . The non-transitory computer storage medium of claim 22 , wherein the cryptographic data is first cryptographic data, and wherein each respective memory device in the batch is configured with second cryptographic data to secure access to the respective memory device.