IP Library › Granted Patent US 12,724,718
Granted Patent B2
US 12,724,718 · App. 18/534,460 · Granted Sep 1, 2026

Cryptographic computations for memory regions

Inventors: Joseph Wright (Tomball, TX); Chris Davenport (Houston, TX); Kevin E. Boyum (Roseville, CA)
Assignee: Hewlett Packard Enterprise Development LP
G06F12/1408G06F12/1441G06F21/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,718
App. No.
18/534,460
Granted
Sep 1, 2026
Kind
B2
Abstract

In some examples, a controller receives, from a validator system in an electronic device, input information including address information identifying a memory region in a memory to validate. The memory is associated with a target system to be validated and the memory is inaccessible to the validator system. Based on the address information, the controller retrieves information from the memory region in the memory, where the controller provides a barrier that prevents access of the retrieved information by the validator system. The controller computes a cryptographic value based on the retrieved information, and the controller sends, to the validator system, an output based on the cryptographic value as a response to the input information.

Claims (45)

1 . An apparatus comprising:

a controller to:

receive, from a validator system in an electronic device, a validation request comprising address information identifying a memory region in a memory to validate, wherein the memory is associated with a target system to be validated and the memory is inaccessible to the validator system, and wherein the target system is part of the electronic device and is separate from the validator system;

determine whether the address information in the validation request identifies the memory region with a size exceeding a threshold size, wherein the size being less than the threshold size indicates an error condition;

based on a determination that the size of the memory region identified by the address information in the validation request exceeds the threshold size, retrieve information from the memory region in the memory identified by the address information, the controller providing a barrier that prevents access of the retrieved information by the validator system;

compute a cryptographic value based on the retrieved information;

based on a comparator determining the computed cryptographic value does not match an input cryptographic value in the validation request, set a compromise indicator by the controller; and

send, from the controller to the validator system, an output as a response to the validation request, the output comprising the compromise indicator indicating a potential compromise of the information in the memory region identified by the address information.

2 . The apparatus of claim 1 , wherein the address information identifies an address range that defines the memory region.

3 . The apparatus of claim 2 , wherein the controller is to reject the validation request in response to determining that the size of the memory region identified by the address information in the validation request is less than the threshold size.

4 . The apparatus of claim 1 , wherein the controller has direct memory access of the memory.

5 . The apparatus of claim 1 , wherein the computing of the cryptographic value is based on an application of a cryptographic hash function on the retrieved information.

6 . The apparatus of claim 1 , wherein the retrieved information comprises machine-readable instructions executable by the target system.

7 . The apparatus of claim 1 , wherein the retrieved information comprises one or more of configuration information or security information of the target system.

8 . The apparatus of claim 1 , wherein the target system comprises a processor to execute machine-readable instructions, and the controller operates independently of the processor of the target system.

9 . The apparatus of claim 1 , wherein the validation request comprises an operation mode field settable to a first value and a second value, and wherein the controller is to:

based on detecting the operation mode field set to the first value, include the compromise indicator in the output sent from the controller to the validator system.

10 . The apparatus of claim 1 , wherein the validator system and the target system are separate embedded systems of the electronic device.

11 . The apparatus of claim 1 , wherein the controller comprises hardware to perform the receiving, the determining, the retrieving, the computing, the setting, and the sending.

12 . The apparatus of claim 1 , wherein the output comprises an interrupt signal to the validator system.

13 . The apparatus of claim 1 , wherein the controller is to perform the receiving, the determining, the retrieving, the computing, the setting, and the sending during a runtime of the electronic device.

14 . An electronic device comprising:

a memory to store information associated with a target system;

a memory transducer comprising a controller, the controller to:

receive, from a validator system, a validation request comprising address information identifying a memory region in the memory to validate, wherein the information in the memory is inaccessible to the validator system, and wherein the target system is separate from the validator system,

determine whether the address information in the validation request identifies the memory region with a size exceeding a threshold size, wherein the size being less than the threshold size indicates an error condition,

based on a determination that the size of the memory region identified by the address information in the validation request exceeds the threshold size, retrieve the information from the memory region in the memory,

compute a cryptographic value based on the retrieved information, and

send, from the controller to the validator system, an output based on the cryptographic value as a response to the validation request; and

a comparator to compare the computed cryptographic value to a reference cryptographic value, and based on determining the computed cryptographic value does not match the reference cryptographic value, set a compromise indicator indicating to the validator system a potential compromise of the information in the memory region identified by the address information.

15 . The electronic device of claim 14 , wherein the validation request further comprises an operational mode indicator to indicate an operational mode of the memory transducer, wherein the operational mode indicator if set to a first value causes the memory transducer to return the cryptographic value to the validator system, and the operational mode indicator if set to a different second value causes the memory transducer to return the compromise indicator.

16 . The electronic device of claim 14 , wherein the comparator is part of the validator system.

17 . The electronic device of claim 14 , wherein the comparator is part of the memory transducer.

18 . A method comprising:

receiving, at a controller from a validator system in an electronic device, a validation request comprising address information identifying a memory region in a memory to validate, wherein the memory is associated with a target system to be validated and the memory is inaccessible to the validator system, and wherein the target system is part of the electronic device and is separate from the validator system;

determining, by the controller, whether the address information in the validation request identifies the memory region with a size exceeding a threshold size, wherein the size being less than the threshold size indicates an error condition;

based on a determination that the size of the memory region identified by the address information in the validation request exceeds the threshold size, retrieving, by the controller, information from the memory region in the memory identified by the address information;

computing, by the controller, a cryptographic value based on the retrieved information;

sending, from the controller to the validator system, an output based on the cryptographic value as a response to the validation request;

comparing, by a comparator, the computed cryptographic value to a reference cryptographic value; and

based on determining the computed cryptographic value does not match the reference cryptographic value, setting, by the comparator, a compromise indicator indicating to the validator system a potential compromise of the information in the memory region identified by the address information.

19 . The method of claim 18 , further comprising:

, obtaining, by the controller, the reference cryptographic value from the validation request; and

including, in the output sent from the controller to the validator system, the compromise indicator.

20 . The method of claim 18 , wherein the comparator is part of the controller or the validator system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2023
From: WRIGHT, JOSEPH; DAVENPORT, CHRIS; BOYUM, KEVIN E.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 065819/0352 →
Continuity (1)
Related Publication 20250190369A1 · Jun 12, 2025
References Cited (7)
US 9225729B1 · Moen · 2015 [cited by examiner]
US 12141595B1 · Radcliffe · 2024 [cited by examiner]
US 20150033034A1 · Gerzon · 2015 [cited by examiner]
US 20180121644A1 · Baker · 2018 [cited by examiner]
US 20230036165A1 · Bursell · 2023 [cited by examiner]
US 20240372731A1 · Kobel · 2024 [cited by examiner]
WO WO2017116803A1 · 2017 [cited by examiner]