Data integrity verification in a non-volatile memory
US-2019286823-A1 · Sep 19, 2019 · US
US11657165B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11657165-B2 |
| Application number | US-201917055035-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 22, 2019 |
| Priority date | Jun 20, 2018 |
| Publication date | May 23, 2023 |
| Grant date | May 23, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A cryptography module for a computing device. The cryptography module is designed to check at least one memory area of a memory device which the computing device may access, as the result of which a result of the check is obtained, and to store the result at least temporarily.
Opening claim text (preview).
What is claimed is: 1. A cryptography module for a computing device, the cryptography module configured to: perform a check operation that produces a result, the checking operation checking at least one memory area of a memory device which is accessible by the computing device; and store the result at least temporarily, wherein the result indicates whether a change has occurred in a content of the at least one memory area on account of a manipulation or an error, and wherein the cryptography module checks multiple memory areas of the memory device, the cryptography module checking the multiple memory areas at least occasionally in a random or pseudorandom sequence, and wherein the cryptography module is configured to carry out the check of the at least one memory area using a cypher-based message authentication code (CMAC). 2. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to periodically check multiple memory areas of the memory device. 3. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to store at least temporarily the result of the check in a volatile and/or nonvolatile manner. 4. The cryptography module as recited in claim 1 , wherein the result of the check of a memory area of the at least one memory area includes at least one truth value that characterizes the result of the check. 5. The cryptography module claim 4 , wherein the cryptography module is configured to periodically check multiple memory areas of the memory device, wherein the result of the check of a memory area of the multiple memory areas includes at least one truth value that characterizes the result of the check, and wherein multiple truth values that are associated in each case with checked memory areas of the memory device as the result undergo an OR link in order to ascertain an overall result, the overall result characterizing whether at least one result of the multiple checked memory areas of the memory device is negative. 6. The cryptography module as recited in claim 5 , wherein the cryptography module is configured to store at least temporarily the overall result in a volatile and/or nonvolatile manner. 7. The cryptography module as recited in claim 5 , wherein the cryptography module is configured to initiate an error response when the overall result is negative, the error response including at least one of the following measures: a) resetting the computing device, and/or resetting the computing device and the cryptography module, b) transmitting an interrupt request to the computing device, c) blocking an access of the computing device to cryptographic keys that are stored in the cryptography module or providable by the cryptography module and/or to other first data, d) preventing the execution of a bootloader of the computing device by holding in a reset state the computing device, e) providing the overall result for the computing device and/or transmitting the overall result to the computing device. 8. The cryptography module as recited in claim 1 , wherein the cryptography module includes a memory unit integrated into the cryptography module, for storing at least one reference value and/or a reference layout for the at least one memory area. 9. The cryptography module as recited in claim 8 , wherein the cryptography module is configured to carry out the check as a function of the reference value. 10. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to establish within the scope of the check whether the content of the at least one memory area corresponds to a predefinable memory content. 11. The cryptography module as recited in claim 1 , wherein the at least one memory area includes a bootloader for the computing device for execution on the computing device. 12. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to provide the computing device with first data, the first data being cryptographic keys, the cryptography module being configured to provide the computing device with the first data only partially, or not at all, as a function of the check. 13. A method for operating a cryptography module for a computing device, the method comprising the following steps: performing, by the cryptography module, a checking operation that produces a result, the checking operation checking at least one memory area of a memory device accessible by the computing device to obtain a result of the check; and at least temporarily storing the result, wherein the result indicates whether a change has occurred in a content of the at least one memory area on account of a manipulation or an error, and wherein the cryptography module checks multiple memory areas of the memory device, the cryptography module checking the multiple memory areas at least occasionally in a random or pseudorandom sequence, and wherein the cryptography module is configured to carry out the check of the at least one memory area using a cypher-based message authentication code (CMAC). 14. The method as recited in claim 13 , wherein the cryptography module stores the result of the check, at least temporarily, in a volatile and/or nonvolatile manner.
Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title
at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title
Bootstrapping (security arrangements therefor G06F21/57) · CPC title
by using cryptography (for digital transmission H04L9/00) · CPC title
Secure boot · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.