IP Library Granted Patent US 9,258,111
Granted Patent B2
US 9,258,111 · App. 13/677,715 · Granted Feb 9, 2016

Memory device which protects secure data, method of operating the memory device, and method of generating authentication information

Inventors: Jae-Bum Lee (Yongin-Si, KR); Hyoung-Suk Jang (Suwon-si, KR); Min-Kwon Kim (Hwaseong-si, KR); Seok-Heon Lee (Suwon-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
H04L9/08H04L9/0822H04L9/0877H04L9/0897H04L2209/605
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,258,111
App. No.
13/677,715
Granted
Feb 9, 2016
Kind
B2
Abstract

In one embodiment, the memory device includes a first memory area and a second memory area. The first memory area stores secure data. The first memory area is inaccessible by an external device. The second memory area is configured to store encrypted secure data. The second memory area is accessible by the external device, and the encrypted secure data is an encrypted version of the secure data in the first memory area.

Claims (49)

1. A nonvolatile memory device including a memory array, comprising:

a first memory area in the memory array storing secure data, the first memory area being unable to be read by an external device in response to a request from the external device for the secure data, and the secure data being programmed by a vendor of the nonvolatile memory device;

a second memory area in the memory array storing encrypted secure data, the second memory area being accessible by the external device; and

secure logic configured to access the secure data from the first memory area in response to the request, generate the encrypted secure data from the accessed secure data, and store the encrypted secure data in the second memory area so that the stored encrypted secure data is accessible by the external device,

wherein the secure data includes a unique key of the nonvolatile memory device and the secure logic is located in the nonvolatile memory device,

wherein the first memory area is configured to store a plurality of spare keys, the plurality of spare keys for generating authentication information of the nonvolatile memory device, and

wherein the second memory area is configured to store a plurality of spare key indexes, the plurality of spare key indexes being linked to the plurality of spare keys.

2. The nonvolatile memory device of claim 1 , wherein the external device is a host device.

3. The nonvolatile memory device of claim 1 , wherein the external device is a memory controller.

4. The nonvolatile memory device of claim 1 , further comprising:

input/output logic configured to interface the nonvolatile memory device with the external device.

5. The nonvolatile memory device of claim 1 , wherein the second area is configured to store the encrypted secure data during the manufacture of the nonvolatile memory device.

6. The nonvolatile memory device of claim 1 , wherein the unique key is for authenticating the nonvolatile memory device, and the encrypted secure data includes an encrypted unique key.

7. The nonvolatile memory device of claim 1 , wherein the spare key corresponds to a vendor of the nonvolatile memory device.

8. The nonvolatile memory device of claim 1 , further comprising:

a third memory area configured to store at least one encrypted decryption key, the third memory area being accessible by the external device, the encrypted decryption key being an encrypted version of a decryption key, and the decryption key for decrypting the encrypted unique key.

9. The nonvolatile memory device of claim 8 , wherein the third memory area is further configured to store a plurality of encrypted decryption keys, at least one of the plurality of encrypted decryption keys corresponding to a vendor of the external device.

10. The nonvolatile memory device of claim 1 , wherein the second memory area is only readable by the external device.

11. A nonvolatile memory device including a memory array, comprising:

a first memory area in the memory array storing a main key and at least one spare key, the first memory area being unable to be read by external devices in response to a request from the external devices for secure data that includes the main key, the main key and the least one spare key being programmed by a vendor of the nonvolatile memory device, the main key being a unique key of the nonvolatile memory device; and

a second memory area in the memory array storing at least one spare key index and encrypted secure data including an encrypted main key, the second memory area being accessible by the external devices so that the stored encrypted secure data is accessible in response to the request, the encrypted secure data being an encrypted version of the secure data in the first memory area, the spare key index being linked to the spare key, and the spare key being associated with a vendor of the nonvolatile memory device.

12. The nonvolatile memory device of claim 11 , wherein the spare key index is linked to the spare key by a spare key number.

13. The nonvolatile memory device of claim 11 , wherein

the first memory area stores a plurality of spare keys; and

the second memory area is configured to store a plurality of spare key indexes, the plurality of spare key indexes being linked to the plurality of spare keys.

14. The nonvolatile memory device of claim 13 , wherein the plurality of spare key indexes are linked to the plurality of spare keys by spare key numbers.

15. The nonvolatile memory device of claim 11 , further comprising:

a third memory area storing a plurality of encrypted decryption keys, the third memory area being accessible by the external device, the encrypted decryption keys being encrypted versions of a respective plurality of decryption keys, the plurality of decryption keys being for decrypting the encrypted main key, and the plurality of decryption keys being associated with vendors of the external devices.

16. A nonvolatile memory device including a memory array, comprising:

a first memory area in the memory array storing secure data, the secure data being programmed by a vendor of the nonvolatile memory device, the secure data including a unique key of the nonvolatile memory device;

a second memory area in the memory array storing encrypted secure data, the encrypted secure data being an encrypted version of the secure data in the first memory area;

secure logic configured to access the secure data from the first memory area in response to a request for the secure data, generate the encrypted secure data from the accessed secure data, and store the encrypted secure data in the second memory area; and

the nonvolatile memory device configured such that output of the secure data cannot occur in response to the request, and output of the encrypted secure data can occur in response to the request,

wherein the secure logic is located in the nonvolatile memory device,

wherein the first memory area is configured to store a plurality of spare keys, the plurality of spare keys for generating authentication information of the nonvolatile memory device, and

wherein the second memory area is configured to store a plurality of spare key indexes, the plurality of spare key indexes being linked to the plurality of spare keys.

17. A method of operating a nonvolatile memory device including a memory array, comprising:

storing secure data in a first memory area of the memory array, the first memory area being unable to be read by an external device in response to a request from the external device for the secure data, the secure data being programmed by a vendor of the nonvolatile memory device, the secure data including a unique key of the nonvolatile memory device;

accessing the secure data from the first memory area using logic resident on the nonvolatile memory device in response to the request;

generating an encrypted secure data from the accessed secure data using the logic; and

storing the encrypted secure data in a second memory area of the memory array so that the stored encrypted secure data is accessible by the external device from the second memory area, the encrypted secure data being an encrypted version of the secure data in the first memory area;

storing at least one spare key in the first memory area, the spare key for generating authentication information of the nonvolatile memory device; and

storing at least one spare key index in the second memory area, the spare key index being linked to the spare key.

18. The method of claim 17 , wherein the unique key is for authenticating the nonvolatile memory device, and the encrypted secure data includes an encrypted unique key.

19. The method of claim 18 , wherein the spare key corresponds to a vendor of the nonvolatile memory device.

20. The method of claim 18 , wherein the spare key index is linked to the spare key by a spare key number.

21. The method of claim 18 , further comprising:

storing at least one encrypted decryption key in a third memory area of the nonvolatile memory device, the third memory area being accessible by the external device, the encrypted decryption key being an encrypted version of a decryption key, and the decryption key for decrypting the encrypted main key.

22. The method of claim 21 , wherein the encrypted decryption keys corresponds to vendors of external devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2012
From: LEE, JAE-BUM; JANG, HYOUNG-SUK; KIM, MIN-KWON; LEE, SEOK-HEON
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 029350/0952 →
Priority Claims (1)
KR 10-2011-0136797 · Dec 16, 2011 · national
Continuity (2)
Provisional Application 61585333 · Jan 11, 2012
Related Publication 20130159733A1 · Jun 20, 2013