IP Library Granted Patent US 12,379,867
Granted Patent B2
US 12,379,867 · App. 17/866,312 · Granted Aug 5, 2025

Network-ready storage products with cryptography based access control

Inventor: Luca Bert (San Jose, CA)
Assignee: Micron Technology, Inc.
G06F3/0655G06F3/0604G06F3/0679H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,379,867
App. No.
17/866,312
Granted
Aug 5, 2025
Kind
B2
Abstract

A storage product manufactured as a computer component and configured to have: a secure memory region to store cryptographic keys; a network interface; a local storage device having a storage capacity accessible via the network interface; and a host interface to be connected to a local host system. The local host system can control access, made via the network interface, to the storage capacity without receiving a portion of storage access messages received in the network interface. The storage product includes an access controller configured to determine whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys; and if not, the message can be rejected, deleted, discarded, or ignored without further processing.

Claims (59)

1. An apparatus, comprising:

a storage product connectable to a local host system that is not part of the storage product, the storage product comprising:

a secure memory region configured to store cryptographic keys;

a network interface connectable to a computer network that is not part of the storage product;

a local storage device having a storage capacity accessible via the network interface; and

a host interface connectable to the local host system to control access, made via the network interface over the computer network, to the storage capacity;

wherein the storage product includes an access controller configured to:

determine whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys; and

prevent further processing of the message in the storage product in response to a determination that the message has no valid verification code;

wherein the storage product includes a memory device enclosed in an integrated circuit package; and the memory device includes the secure memory region, the access controller, and a cryptographic engine configured to operate on the cryptographic keys to validate verification codes;

wherein the memory device is configured to provide a random-access memory to buffer first messages received in the network interface from the computer network or second messages received in the host interface from the local host system; and

wherein the memory device is configured in the network interface to buffer first messages; and the storage product is configured to select a first portion of the first messages and provide the first portion of the first messages to the local host system via the host interface to allow the local host system to perform access control.

2. The apparatus of claim 1 , wherein the storage product is configured to select a second portion of the first messages and provide the second portion of the first messages to the local storage device without the second portion going through the host interface.

3. The apparatus of claim 1 , wherein the memory device is configured in the host interface to buffer second messages; and the storage product is configured to select a first portion of the first messages and provide the first portion of the first messages to the local host system via the host interface to allow the local host system to perform access control.

4. The apparatus of claim 1 , wherein the memory device is configured in the local storage device to buffer the first messages and the second messages; and wherein the second messages are generated by the local host system based on third messages received in the network interface and forwarded to the local host system via the host interface to perform access control.

5. The apparatus of claim 4 , wherein the integrated circuit package further encloses the local storage device.

6. The apparatus of claim 1 , wherein the memory device is further configured to include a unique device secret configured to identify the memory device among a population of memory devices; and the unique device secret is inaccessible from outside of the memory device after completion of manufacture of the memory device.

7. The apparatus of claim 6 , wherein the memory device is further configured to generate a cryptographic key from the unique device secret, and generate a verification code of a message to demonstrate possession of the unique device secret.

8. The apparatus of claim 1 , wherein the memory device is configured to buffer both the first messages received from the computer network and the second messages received from the local host system; and the access controller is configured to control access to the secure memory region based on cryptography.

9. A method, comprising:

storing, in a secure memory region in a storage product manufactured as a computer component connectable to a local host system that is not part of the storage product, cryptographic keys, wherein the storage product includes a memory device enclosed in an integrated circuit package;

receiving, in a network interface of the storage product and from a computer network, storage access messages including first messages;

forwarding, via a host interface of the storage product, a first portion of the storage access messages to the local host system configured to control access to a storage capacity of a local storage device of the storage product via the network interface;

processing, by the storage product, a second portion of the storage access messages without providing the second portion to the local host system;

receiving, in the host interface and from the local host system, second messages;

determining, by an access controller in the storage product, whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys, wherein the memory device includes the secure memory region, the access controller, and a cryptographic engine;

preventing, by the access controller, further processing of the message in the storage product in response to a determination that the message has no valid verification code; and

performing, by the cryptographic engine, cryptographic operations on the message and a cryptographic key among the cryptographic keys in the secure memory region to determine whether the verification code provided for the message is valid; and

buffering, in a random-access memory provided by the memory device, the first messages received in the network interface from the computer network or the second messages received in the host interface from the local host system,

wherein the memory device is configured in the network interface to buffer the first messages, in the host interface to buffer the second messages, or in the local storage device to buffer the first messages and the second messages.

10. The method of claim 9 , wherein the memory device is further configured to include a unique device secret configured to identify the memory device among a population of memory devices; and the unique device secret is inaccessible from outside of the memory device after completion of manufacture of the memory device.

11. The method of claim 10 , further comprising:

generating, by the memory device, a cryptographic key from the unique device secret; and

generating, by the memory device, a verification code of a message to demonstrate possession of the unique device secret.

12. An apparatus, comprising:

a storage product connectable to a local host system that is not part of the storage product, the storage product comprising:

a secure memory region configured to store cryptographic keys;

a network interface connectable to a computer network that is not part of the storage product;

a local storage device having a storage capacity accessible via the network interface; and

a host interface connectable to the local host system to control access, made via the network interface over the computer network, to the storage capacity;

wherein the storage product includes an access controller configured to:

determine whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys; and

prevent further processing of the message in the storage product in response to a determination that the message has no valid verification code;

wherein the storage product includes a memory device enclosed in an integrated circuit package; and the memory device includes the secure memory region, the access controller, and a cryptographic engine configured to operate on the cryptographic keys to validate verification codes;

wherein the memory device is configured to provide a random-access memory to buffer first messages received in the network interface from the computer network or second messages received in the host interface from the local host system; and

wherein the memory device is configured in the host interface to buffer second messages; and the storage product is configured to select a first portion of the first messages and provide the first portion of the first messages to the local host system via the host interface to allow the local host system to perform access control.

13. An apparatus, comprising:

a storage product connectable to a local host system that is not part of the storage product, the storage product comprising:

a secure memory region configured to store cryptographic keys;

a network interface connectable to a computer network that is not part of the storage product;

a local storage device having a storage capacity accessible via the network interface; and

a host interface connectable to the local host system to control access, made via the network interface over the computer network, to the storage capacity;

wherein the storage product includes an access controller configured to:

determine whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys; and

prevent further processing of the message in the storage product in response to a determination that the message has no valid verification code;

wherein the storage product includes a memory device enclosed in an integrated circuit package; and the memory device includes the secure memory region, the access controller, and a cryptographic engine configured to operate on the cryptographic keys to validate verification codes;

wherein the memory device is configured to provide a random-access memory to buffer first messages received in the network interface from the computer network or second messages received in the host interface from the local host system; and

wherein the memory device is configured in the local storage device to buffer the first messages and the second messages; and wherein the second messages are generated by the local host system based on third messages received in the network interface and forwarded to the local host system via the host interface to perform access control.

14. The apparatus of claim 13 , wherein the integrated circuit package further encloses the local storage device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2022
From: BERT, LUCA
To: MICRON TECHNOLOGY, INC.
Reel/Frame 060526/0188 →
Continuity (1)
Related Publication 20240020047A1 · Jan 18, 2024
References Cited (106)
US 6466994B1 · Burke et al. · 2002 [cited by applicant]
US 6745310B2 · Chow · 2004 [cited by applicant]
US 6766359B1 · Oliveira et al. · 2004 [cited by applicant]
US 9432484B1 · Xie et al. · 2016 [cited by applicant]
US 9514080B1 · Chang · 2016 [cited by applicant]
US 9537953B1 · Dadashikelayeh et al. · 2017 [cited by applicant]
US 10152247B2 · Li et al. · 2018 [cited by applicant]
US 10664217B1 · Laha et al. · 2020 [cited by applicant]
US 10984044B1 · Batsakis et al. · 2021 [cited by applicant]
US 11106734B1 · Batsakis et al. · 2021 [cited by applicant]
US 11410475B2 · Golov · 2022 [cited by applicant]
US 11436194B1 · Salmon et al. · 2022 [cited by applicant]
US 11650868B2 · Jha et al. · 2023 [cited by applicant]
US 11733931B1 · Wu et al. · 2023 [cited by applicant]
US 11775225B1 · Bert · 2023 [cited by applicant]
US 11809361B1 · Bert · 2023 [cited by applicant]
US 11853819B1 · Bert · 2023 [cited by applicant]
US 11868827B1 · Bert · 2024 [cited by applicant]
US 11868828B1 · Bert · 2024 [cited by applicant]
US 11947834B2 · Bert · 2024 [cited by applicant]
US 11983434B2 · Bert · 2024 [cited by applicant]
US 12050945B2 · Bert · 2024 [cited by applicant]
US 20020165961A1 · Everdell · 2002 [cited by applicant]
US 20050172073A1 · Voigt et al. · 2005 [cited by applicant]
US 20050240745A1 · Iyer et al. · 2005 [cited by applicant]
US 20060026229A1 · Ari et al. · 2006 [cited by applicant]
US 20060185015A1 · Cheston et al. · 2006 [cited by applicant]
US 20080228897A1 · Ko · 2008 [cited by applicant]
US 20080320233A1 · Kinter · 2008 [cited by applicant]
US 20090168799A1 · Crowley et al. · 2009 [cited by applicant]
US 20100005234A1 · Ganga et al. · 2010 [cited by applicant]
US 20100095073A1 · Caulkins · 2010 [cited by applicant]
US 20100106889A1 · Manning · 2010 [cited by applicant]
US 20100274971A1 · Solihin · 2010 [cited by applicant]
US 20110153771A1 · Lin et al. · 2011 [cited by applicant]
US 20110246823A1 · Khan et al. · 2011 [cited by applicant]
US 20120030408A1 · Flynn et al. · 2012 [cited by applicant]
US 20120110277A1 · Shin et al. · 2012 [cited by applicant]
US 20120278396A1 · Vuong · 2012 [cited by applicant]
US 20120311271A1 · Klein et al. · 2012 [cited by applicant]
US 20130097369A1 · Talagala et al. · 2013 [cited by applicant]
US 20130282948A1 · Brazao et al. · 2013 [cited by applicant]
US 20140115244A1 · Maybee et al. · 2014 [cited by applicant]
US 20140173195A1 · Rosset et al. · 2014 [cited by applicant]
US 20140181235A1 · Sindhu et al. · 2014 [cited by applicant]
US 20140282613A1 · Jea et al. · 2014 [cited by applicant]
US 20160124880A1 · Goren et al. · 2016 [cited by applicant]
US 20170109098A1 · Nakata et al. · 2017 [cited by applicant]
US 20170288867A1 · Collier · 2017 [cited by examiner]
US 20170344430A1 · Greer et al. · 2017 [cited by applicant]
US 20180069923A1 · Tsalmon · 2018 [cited by applicant]
US 20180141750A1 · Hasegawa et al. · 2018 [cited by applicant]
US 20180217951A1 · Benisty et al. · 2018 [cited by applicant]
US 20180349487A1 · Garg et al. · 2018 [cited by applicant]
US 20190042501A1 · Trika · 2019 [cited by applicant]
US 20190044879A1 · Richardson et al. · 2019 [cited by applicant]
US 20190095107A1 · Wysoczanski et al. · 2019 [cited by applicant]
US 20190243695A1 · Mittal et al. · 2019 [cited by applicant]
US 20190243713A1 · Dunn et al. · 2019 [cited by applicant]
US 20190340024A1 · Brewer · 2019 [cited by applicant]
US 20200065018A1 · Hong · 2020 [cited by examiner]
US 20200117520A1 · Costa et al. · 2020 [cited by applicant]
US 20200136996A1 · Li et al. · 2020 [cited by applicant]
US 20200183785A1 · Shin et al. · 2020 [cited by applicant]
US 20200186445A1 · Govindaraju et al. · 2020 [cited by applicant]
US 20200226077A1 · Kang et al. · 2020 [cited by applicant]
US 20200356498A1 · Shtivelman et al. · 2020 [cited by applicant]
US 20200394143A1 · Subbiah et al. · 2020 [cited by applicant]
US 20210019085A1 · Zhu et al. · 2021 [cited by applicant]
US 20210303424A1 · Jain · 2021 [cited by applicant]
US 20220004668A1 · Dewan · 2022 [cited by examiner]
US 20220083257A1 · Kachare et al. · 2022 [cited by applicant]
US 20220121587A1 · Kragel et al. · 2022 [cited by applicant]
US 20220137835A1 · Malakapalli et al. · 2022 [cited by applicant]
US 20220188028A1 · Mesnier et al. · 2022 [cited by applicant]
US 20220191160A1 · U et al. · 2022 [cited by applicant]
US 20220236902A1 · Pinto et al. · 2022 [cited by applicant]
US 20220245082A1 · Vijayashekar et al. · 2022 [cited by applicant]
US 20220261165A1 · Wang et al. · 2022 [cited by applicant]
US 20220300207A1 · Tsuji et al. · 2022 [cited by applicant]
US 20220404986A1 · Pol · 2022 [cited by applicant]
US 20220405015A1 · Lee et al. · 2022 [cited by applicant]
US 20230029616A1 · Pandit et al. · 2023 [cited by applicant]
US 20230037870A1 · Jones · 2023 [cited by applicant]
US 20230088291A1 · Tsuji et al. · 2023 [cited by applicant]
US 20230127200A1 · Glimcher et al. · 2023 [cited by applicant]
US 20230214333A1 · Glimcher et al. · 2023 [cited by applicant]
US 20240020011A1 · Bert · 2024 [cited by applicant]
US 20240020029A1 · Bert · 2024 [cited by applicant]
US 20240020046A1 · Bert · 2024 [cited by applicant]
US 20240020048A1 · Bert · 2024 [cited by applicant]
US 20240020049A1 · Bert · 2024 [cited by applicant]
US 20240020051A1 · Bert · 2024 [cited by applicant]
US 20240020062A1 · Bert · 2024 [cited by applicant]
US 20240020181A1 · Bert · 2024 [cited by applicant]
US 20240020182A1 · Bert · 2024 [cited by applicant]
US 20240020183A1 · Bert · 2024 [cited by applicant]
US 20240020184A1 · Bert · 2024 [cited by applicant]
US 20240022526A1 · Bert · 2024 [cited by applicant]
US 20240022645A1 · Bert · 2024 [cited by applicant]
US 20240028546A1 · Bert · 2024 [cited by applicant]
US 20240069992A1 · Bert · 2024 [cited by applicant]
US 20240118950A1 · Bert · 2024 [cited by applicant]
US 20240143422A1 · Bert · 2024 [cited by applicant]
US 20240176535A1 · Bert · 2024 [cited by applicant]
WO 2023020055 · 2023 [cited by applicant]