IP Library › Granted Patent US 12,748,841
Granted Patent B2
US 12,748,841 · App. 18/989,583 · Granted Sep 29, 2026

Methods to improve security of multi-tenant memory modules

Inventors: Jeremy Chritz (Seattle, WA); David Hulton (Seattle, WA)
Assignee: Micron Technology, Inc.
G06F21/554G06F12/1408G06F12/1441G06F12/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,841
App. No.
18/989,583
Granted
Sep 29, 2026
Kind
B2
Abstract

An example system includes a host computing device configured to host a first tenant and a second tenant, non-volatile memory configured to store data for the first tenant and data for the second tenant, and a memory controller including a cache of a volatile memory configured to store a first encrypted key associated with the first tenant used to access the data stored at the non-volatile memory and a second encrypted key associated with a second tenant used to access the data stored at the non-volatile memory. The memory controller further includes a processor having encryption logic configured to detect an attack on a portion of the cache storing the second encrypted key by the first tenant, and to erase the stored second encrypted key from the cache in response to detection of the attack.

Claims (36)

1 . A method comprising:

writing, to a cache coupled to a volatile memory device, a first encrypted key associated with a first tenant for a non-volatile memory device coupled to the volatile memory device;

writing, to the cache coupled to the volatile memory device, a second encrypted key associated with a second tenant for the non-volatile memory device coupled to the volatile memory device; and

responsive to detection of an attack on a portion of the cache storing the second encrypted key by the first tenant, erasing the stored second encrypted key from the cache.

2 . The method of claim 1 , further comprising detecting the attack on the cache via repeated accesses of one portion of the cache physically adjacent the portion or the cache storing the second encrypted key.

3 . The method of claim 1 , further comprising, further responsive to detection of an attack on a portion of the cache storing the second encrypted key by the first tenant, blocking all access to the non-volatile memory by the second tenant.

4 . The method of claim 1 , further comprising, responsive to receipt of a memory access request from the second tenant, using the second encrypted key to store data to or retrieve data from the non-volatile memory device.

5 . The method of claim 4 , further comprising, responsive to receipt of a memory access request from the first tenant, using the first encrypted key to store data to or retrieve data from the non-volatile memory device.

6 . The method of claim 1 , wherein the first tenant and the second tenant are both hosted on a host computing device.

7 . The method of claim 1 , wherein the non-volatile memory device comprises at least one of a NAND memory device or a 3D XPoint memory device.

8 . The method of claim 1 , further comprising generating the first encrypted key based partly on a pseudorandom value from a pseudorandom number generator.

9 . The method of claim 8 , further comprising generating the first encrypted key using an authenticated stream cipher.

10 . An apparatus comprising:

a cache of a volatile memory configured to store a first encrypted key associated with a first tenant used to access a non-volatile memory and a second encrypted key associated with a second tenant used to access the non-volatile memory; and

a processor having encryption logic configured to detect an attack on a portion of the cache storing the second encrypted key by the first tenant, and to erase the stored second encrypted key from the cache in response to detection of the attack.

11 . The apparatus of claim 10 , wherein the encryption logic is configured to detect the attack on the cache based on repeated accesses of one portion of the cache physically adjacent the portion or the cache storing the second encrypted key.

12 . The apparatus of claim 10 , wherein the encryption logic is further configured to, responsive to detection of an attack on a portion of the cache storing the second encrypted key by the first tenant, block all access to the non-volatile memory by the second tenant.

13 . The apparatus of claim 10 , wherein the processor is configured to:

responsive to receipt of a memory access request from the second tenant, using the second encrypted key to store data to or retrieve data from the non-volatile memory device; and

responsive to receipt of a memory access request from the first tenant, using the first encrypted key to store data to or retrieve data from the non-volatile memory device.

14 . The apparatus of claim 10 , wherein the first tenant and the second tenant are both hosted on a host computing device.

15 . The apparatus of claim 10 , wherein the encryption logic is further configured to generate the first encrypted key based partly on a pseudorandom value from a pseudorandom number generator.

16 . The apparatus of claim 15 , wherein the encryption logic is further configured to generate the first encrypted key using an authenticated stream cipher.

17 . A system comprising:

a host computing device configured to host a first tenant and a second tenant;

non-volatile memory configured to store data for the first tenant and data for the second tenant; and

a memory controller comprising:

a cache of a volatile memory configured to store a first encrypted key associated with the first tenant used to access the data stored at the non-volatile memory and a second encrypted key associated with the second tenant used to access the data stored at the non-volatile memory; and

a processor having encryption logic configured to detect an attack on a portion of the cache storing the second encrypted key by the first tenant, and to erase the stored second encrypted key from the cache in response to detection of the attack.

18 . The system of claim 17 , wherein the encryption logic is configured to detect the attack on the cache based on repeated accesses of one portion of the cache physically adjacent the portion or the cache storing the second encrypted key.

19 . The system of claim 17 , wherein the encryption logic is further configured to, responsive to detection of an attack on a portion of the cache storing the second encrypted key by the first tenant, block all access to the non-volatile memory by the second tenant.

20 . The system of claim 17 , wherein the processor is configured to:

responsive to receipt of a memory access request from the second tenant, using the second encrypted key to store data to or retrieve data from the non-volatile memory device; and

responsive to receipt of a memory access request from the first tenant, using the first encrypted key to store data to or retrieve data from the non-volatile memory device.

21 . The system of claim 17 , wherein the encryption logic is further configured to generate the first encrypted key based partly on a pseudorandom value from a pseudorandom number generator.

22 . The system of claim 21 , wherein the memory controller further comprises the pseudorandom number generator configured to generate the pseudorandom value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2024
From: CHRITZ, JEREMY; HULTON, DAVID
To: MICRON TECHNOLOGY, INC.
Reel/Frame 069651/0540 →
Continuity (2)
Provisional Application 63617710 · Jan 4, 2024
Related Publication 20250225236A1 · Jul 10, 2025
References Cited (76)
US 5457748A · Bergum et al. · 1995 [cited by applicant]
US 7814316B1 · Hughes et al. · 2010 [cited by applicant]
US 8674823B1 · Contario et al. · 2014 [cited by applicant]
US 8938624B2 · Obukhov et al. · 2015 [cited by applicant]
US 9954828B1 · Chandrasekhar et al. · 2018 [cited by applicant]
US 10175118B1 · Rezayee et al. · 2019 [cited by applicant]
US 10733291B1 · Mcleod · 2020 [cited by applicant]
US 10809944B1 · Ostrikov et al. · 2020 [cited by applicant]
US 10929572B2 · Wu · 2021 [cited by applicant]
US 11409918B1 · Sugavanam et al. · 2022 [cited by applicant]
US 11537298B2 · Chritz et al. · 2022 [cited by applicant]
US 11899829B2 · Chritz et al. · 2024 [cited by applicant]
US 11899942B2 · Chritz et al. · 2024 [cited by applicant]
US 12321616B2 · Chritz et al. · 2025 [cited by applicant]
US 12619791B2 · Hulton et al. · 2026 [cited by applicant]
US 20090217058A1 · Obereiner et al. · 2009 [cited by applicant]
US 20090300312A1 · Handschuh · 2009 [cited by examiner]
US 20100005317A1 · Pribadi et al. · 2010 [cited by applicant]
US 20110082979A1 · Ramesh et al. · 2011 [cited by applicant]
US 20110154043A1 · Lim et al. · 2011 [cited by applicant]
US 20110205016A1 · Al-azen et al. · 2011 [cited by applicant]
US 20130239195A1 · Turgeman · 2013 [cited by examiner]
US 20140108794A1 · Barton · 2014 [cited by examiner]
US 20140281587A1 · Ignatchenko · 2014 [cited by applicant]
US 20150002900A1 · Cochran et al. · 2015 [cited by applicant]
US 20150058637A1 · Raskin et al. · 2015 [cited by applicant]
US 20160018996A1 · Doumen · 2016 [cited by applicant]
US 20160078252A1 · Chandra et al. · 2016 [cited by applicant]
US 20160098359A1 · Adkins et al. · 2016 [cited by applicant]
US 20160204931A1 · Kamath et al. · 2016 [cited by applicant]
US 20180095675A1 · Kachare et al. · 2018 [cited by applicant]
US 20180181499A1 · Branco et al. · 2018 [cited by applicant]
US 20180307848A1 · Leiseboer et al. · 2018 [cited by applicant]
US 20180349293A1 · Lin · 2018 [cited by applicant]
US 20180373598A1 · Mondello et al. · 2018 [cited by applicant]
US 20190050347A1 · Bolotov et al. · 2019 [cited by applicant]
US 20190056999A1 · Foxworth et al. · 2019 [cited by applicant]
US 20190243714A1 · Foxworth et al. · 2019 [cited by applicant]
US 20200167487A1 · Kida et al. · 2020 [cited by applicant]
US 20200226270A1 · Benedict · 2020 [cited by applicant]
US 20200364159A1 · Lee et al. · 2020 [cited by applicant]
US 20210216629A1 · Miller · 2021 [cited by examiner]
US 20210240862A1 · Pelissier et al. · 2021 [cited by applicant]
US 20210328790A1 · Eckel et al. · 2021 [cited by applicant]
US 20210377017A1 · Benisty et al. · 2021 [cited by applicant]
US 20220050741A1 · Lee · 2022 [cited by applicant]
US 20220171545A1 · Chritz et al. · 2022 [cited by applicant]
US 20220171887A1 · Chritz et al. · 2022 [cited by applicant]
US 20220222384A1 · Hulton et al. · 2022 [cited by applicant]
US 20230126741A1 · Chritz et al. · 2023 [cited by applicant]
US 20240176916A1 · Chritz et al. · 2024 [cited by applicant]
US 20240201871A1 · Chritz et al. · 2024 [cited by applicant]
US 20240291835A1 · Sethi · 2024 [cited by examiner]
US 20240311496A1 · Karr · 2024 [cited by examiner]
US 20250076228A1 · Karoum et al. · 2025 [cited by applicant]
US 20250225236A1 · Chritz · 2025 [cited by examiner]
US 20250335107A1 · Chritz et al. · 2025 [cited by applicant]
CN 108710805A · 2018 [cited by applicant]
CN 109255231A · 2019 [cited by applicant]
CN 110795776A · 2020 [cited by applicant]
CN 111367834A · 2020 [cited by applicant]
CN 111752743A · 2020 [cited by applicant]
EP 3716071A1 · 2020 [cited by applicant]
JP 2009245020A · 2009 [cited by applicant]
JP 2011239123A · 2011 [cited by applicant]
JP 2012168737A · 2012 [cited by applicant]
JP 2020119298A · 2020 [cited by applicant]
WO 2022119822A1 · 2022 [cited by applicant]
WO WO2022119819A1 · 2022 [cited by applicant]
U.S. Appl. No. 18/428,157 titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, filed Jan. 31, 2024; pp. all pages of application as… [cited by applicant]
U.S. Appl. No. 19/205,070 titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, filed May 12, 2025; pp. all pages of application as … [cited by applicant]
U.S. Appl. No. 17/146,274 titled “Encrypted Key Management” filed Jan. 11, 2021, pp. all pages of application as filed. [cited by applicant]
U.S. Appl. No. 18/146,120 titled, “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher,”, filed on Dec. 23, 2022, pp. all pages of applicati… [cited by applicant]
U.S. Appl. No. 17/108,904, titled “Memory Systems and Devices Including Examples of Accessing Memory and Generating Access Codes Using an Authenticated Stream Cipher”, filed Dec. 1, 2020, pp. all pages of application as… [cited by applicant]
U.S. Appl. No. 17/108,934, titled “ Memory Systems and Devices Including Examples of Generating Access Codes for Memory Regions Using Authentication Logic”, filed Dec. 1, 2020, pp. all pages of application as filed. [cited by applicant]
U.S. Appl. No. 19/535,273, titled “Encrypted Key Management”, filed Feb. 10, 2026; pp. all pages of application as filed. [cited by applicant]