IP Library Granted Patent US 11,768,942
Granted Patent B2
US 11,768,942 · App. 17/323,430 · Granted Sep 26, 2023

License-protected boot device

Inventor: Zhan Liu (Cupertino, CA)
Assignee: Micron Technology, Inc.
G06F21/575G06F21/54G06F21/572G06F21/64G06F21/79G06F2221/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,768,942
App. No.
17/323,430
Granted
Sep 26, 2023
Kind
B2
Abstract

The disclosed embodiments relate to secure booting of memory device. The disclosed embodiments generate measurement data associated with a memory device. Next, the disclosed embodiments read a golden measurement from a secure location in the memory device, the golden measurement generated based on a version of the data associated with the memory device, and therefore it is unique to the device. The disclosed embodiments validate the golden measurement value using a public key and determine whether the golden measurement is equal to the measurement data. The golden measurement value can also be saved in a write protected area which can only be changed by a secure write command, therefore, it is imutable by others. Finally, the disclosed embodiments continue a boot process when the golden measurement is equal to the measurement data.

Claims (34)

1. A method comprising:

generating, by a memory device, measurement data associated with the memory device in response to an initial booting of the memory device;

reading, by the memory device, a golden measurement from a Platform Configuration Register (PCR), the golden measurement generated based on a version of the data associated with the memory device and signed using a private key of a manufacturer of the memory device;

validating, by the memory device, the golden measurement using a public key, wherein the public key comprises a public key written by the manufacturer to a write-protected region of the memory device;

determining, by the memory device, whether the golden measurement is equal to the measurement data; and

continuing, by the memory device, a boot process when the golden measurement is equal to the measurement data.

2. The method of claim 1 , further comprising halting the boot process when the golden measurement is not equal to the measurement data.

3. The method of claim 2 , further comprising initiating a recovery process after halting the boot process.

4. The method of claim 1 , wherein measuring data associated with the memory device comprises measuring one or more of software, firmware, or signature features of the memory device.

5. The method of claim 1 , wherein validating the golden measurement comprises reading a digital signature associated with the golden measurement; reading a public key from a write-protected storage area; and validating the digital signature using the public key.

6. The method of claim 1 , further comprising determining that the memory device is performing a first boot and enabling an auto measurement capability of a controller of the memory device in response.

7. A non-transitory computer-readable storage medium storing computer program instructions capable of being executed by a controller of a memory device, the computer program instructions defining steps of:

generating measurement data associated with the memory device in response to an initial booting of the memory device;

reading a golden measurement from a Platform Configuration Register (PCR), the golden measurement generated based on a version of the data associated with the memory device and signed using a private key of a manufacturer of the memory device;

validating the golden measurement using a public key, wherein the public key comprises a public key written by the manufacturer to a write-protected region of the memory device;

determining whether the golden measurement is equal to the measurement data; and

continuing a boot process when the golden measurement is equal to the measurement data.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the computer program instructions define a step of halting the boot process when the golden measurement is not equal to the measurement data.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the computer program instructions define a step of initiating a recovery process after halting the boot process.

10. The non-transitory computer-readable storage medium of claim 7 , wherein measuring data associated with the memory device comprises measuring one or more of software, firmware, or signature features of the memory device.

11. The non-transitory computer-readable storage medium of claim 7 , wherein validating the golden measurement comprises reading a digital signature associated with the golden measurement; reading a public key from a write-protected storage area; and validating the digital signature using the public key.

12. The non-transitory computer-readable storage medium of claim 7 , wherein the computer program instructions define a step of determining that the memory device is performing a first boot and enabling an auto measurement capability of a controller of the memory device in response.

13. A memory device comprising:

a storage array; and

a controller configured to:

generate measurement data associated with the memory device in response to an initial booting of the memory device;

read a golden measurement from a Platform Configuration Register (PCR), the golden measurement generated based on a version of the data associated with the memory device and signed using a private key of a manufacturer of the memory device;

validate the golden measurement using a public key, wherein the public key comprises a public key written by the manufacturer to a write-protected region of the memory device;

determine whether the golden measurement is equal to the measurement data; and

continue a boot process when the golden measurement is equal to the measurement data.

14. The memory device of claim 13 , the controller further configured to halt the boot process when the golden measurement is not equal to the measurement data.

15. The memory device of claim 13 , wherein measuring data associated with the memory device comprises measuring one or more of software, firmware, or signature features of the memory device.

16. The memory device of claim 13 , where invalidating the golden measurement comprises reading a digital signature associated with the golden measurement; reading a public key from a write-protected storage area; and validating the digital signature using the public key.

17. The memory device of claim 13 , the controller further configured to determine that the memory device is performing a first boot and enabling an auto measurement capability of a controller of the memory device in response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: LIU, ZHAN
To: MICRON TECHNOLOGY, INC.
Reel/Frame 056276/0277 →
Continuity (1)
Related Publication 20220374521A1 · Nov 24, 2022