Provided are a storage device with high security and an electronic device including the same
By introducing basic memory, secure memory, controller, and security engine into the storage device, and generating and verifying message authentication codes, the problem of messages being intercepted or modified by attackers in electronic devices is solved, achieving highly secure data transmission.
Patent Information
- Application Number
- CN202010114385.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-05-08
- Filing Date
- 2020-02-25
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2040-02-25
AI Technical Summary
During data transmission, messages may be intercepted or modified by attackers, making it impossible for receivers to identify or detect the authenticity of the messages. Existing technologies are unable to effectively prevent such intrusions.
The design employs a storage device that includes basic memory, secure memory, a controller, and a security engine. By generating and verifying message authentication codes, message authentication and integrity are ensured. The security engine controls access to the secure memory, preventing the controller from obtaining authentication keys and thus enhancing message security.
It effectively prevents attackers from obtaining authentication keys, ensures the security and integrity of messages during transmission, and improves the reliability and security of data transmission.
Smart Images

Figure CN111914310B_ABST
Abstract
Description
[0001] Korean Patent Application No. 10-2019-0053736, filed on May 8, 2019, in the Korean Intellectual Property Office and entitled "Storage device providing high security and electronic device including the same" is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] Embodiments relate to a storage device and an electronic device, and more particularly, to a storage device performing a security function and an electronic device including the same. BACKGROUND
[0003] According to the development of information technology, the importance of communication between electronic devices increases. Electronic devices (e.g., a smart phone, a tablet personal computer (PC), a laptop PC, and a wearable device) can be implemented with one of storage devices capable of storing data. The electronic devices can exchange data with each other.
[0004] The electronic devices can be classified into a transmitter and a receiver. For example, the transmitter can output internal data to the receiver, and the receiver can receive data from the transmitter. The transmitter can instruct the receiver to perform an operation by transmitting a message. When the receiver receives the message from the transmitter, the receiver can perform the operation instructed by the message.
[0005] However, when the message is transmitted from the transmitter to the receiver, the message from the transmitter can be intruded or modified by an attacker. Accordingly, to prevent intrusion by the attacker, the receiver can perform the operation instructed by the message after checking whether the message is output from an authenticated transmitter or whether the message is not modified by the attacker. SUMMARY
[0006] An embodiment is directed to a storage device. The storage device can include a basic memory storing a message received from an external device, a secure memory storing an authentication key for authenticating the message, a controller outputting a control signal, and a security engine obtaining the authentication key from the secure memory with a right to access the secure memory in response to the control signal from the controller and blocking access of the secure memory by the controller.
[0007] An embodiment is directed to an electronic device. The electronic device can include a basic memory storing a message transmitted from an external device and a first message authentication code, a secure memory storing an authentication key for authenticating the message, a controller outputting a control signal, and a security engine obtaining the authentication key from the secure memory in response to the control signal from the controller and generating a second message authentication code. The security engine blocks the authentication key from being transmitted to the controller from the secure memory.
[0008] Embodiments are directed to a storage device. The storage device can include a base memory storing a message, a secure memory storing an authentication key for protecting the message, a controller outputting a control signal, and a secure engine obtaining the authentication key from the secure memory with a right to access the secure memory, generating a message authentication code based on the authentication key, and blocking access of the secure memory by the controller in response to the control signal from the controller. BRIEF DESCRIPTION OF DRAWINGS
[0009] The features will become apparent to one of ordinary skill in the art upon examination of the following details. It is also to be understood that the exemplary embodiments are only examples and do not limit the scope of the disclosure to these embodiments.
[0010] Figure 1 A transmitter according to an example embodiment is illustrated.
[0011] Figure 2 A transmitter according to an example embodiment is illustrated.
[0012] Figure 3 A transmitter according to another example embodiment is illustrated.
[0013] Figure 4 A flowchart for describing an operation of a secure engine in Figure 2 is illustrated.
[0014] Figure 5 A flowchart for describing an operation of a controller in Figure 2 is illustrated.
[0015] Figure 6 A flowchart for describing an operation of a transmitter in Figure 2 is illustrated.
[0016] Figure 7 A receiver according to an example embodiment is illustrated.
[0017] Figure 8 A receiver according to another example embodiment is illustrated.
[0018] Figure 9 A flowchart for describing an operation of a secure engine in Figure 7 is illustrated.
[0019] Figure 10 A flowchart for describing an operation of a controller in Figure 7 is illustrated.
[0020] Figure 11 A flowchart for describing an operation of a receiver in Figure 7 is illustrated. DETAILED DESCRIPTION
[0021] Figure 1Transmitters and receivers according to example embodiments are shown. Reference is made to Figure 1 The transmitter 100 and the receiver 200 can be electronic devices performing a security function according to example embodiments. The transmitter 100 and the receiver 200 can be implemented with one of storage devices (e.g., a smart phone, a tablet personal computer (PC), a laptop PC, and a wearable device) capable of storing data.
[0022] For example, the transmitter 100 can transmit a security signal 300 to the receiver 200. The security signal 300 can include a message 121 and a message authentication code (MAC) 131. The message 121 can include information about an operation of the receiver 200 indicated by the transmitter 100. The message authentication code 131 can be used to determine whether the message 121 is authenticated by the receiver 200.
[0023] The transmitter 100 and the receiver 200 can operate at a high security level by improving security of a key 141 of the transmitter 100 and a key 241 of the receiver 200. The keys 141 and 241 can be authentication keys or security keys used for communication between the transmitter 100 and the receiver 200. For example, when security of the keys 141 and 241 is improved, a possibility that the keys 141 and 241 are exposed to an attacker 400 decreases. The attacker 400 can be an electronic device or a system external to the transmitter 100 and the receiver 200. The attacker 400 can intercept and modify the message 121 from the transmitter 100. For example, the attacker 400 can transmit the modified message 121 to the receiver 200. In addition, the attacker 400 can generate a fake message and transmit the fake message to the receiver 200, so that the receiver 200 can regard the fake message as the message 121 from the transmitter 100. For example, when the keys 141 and 241 are exposed to the attacker 400, the receiver 200 can not be able to identify or detect whether the message 121 is modified or the message is transmitted from the attacker 400 or from the transmitter 100. According to example embodiments, the transmitter 100 and the receiver 200 can improve a security level of the message 121 by preventing the keys 141 and 241 from being exposed to the attacker 400.
[0024] The receiver 200 can check or evaluate the message 121. For example, when the receiver 200 checks the message 121, the receiver 200 can check or determine whether the message 121 is sent from the authenticated sender 100, and whether the message 121 is not modified by the attacker 400 when the message 121 is transmitted. Also, when the message is authenticated by the receiver 200, the message can be sent from the authenticated sender 100, and the message 121 can not be modified when the message 121 is transmitted. Alternatively, when the message is not authenticated by the receiver 200, the message can not be sent from the authenticated sender 100, and the message 121 can be modified when the message 121 is transmitted. For example, when the receiver 200 successfully performs message authentication (i.e., when the message passes the message authentication of the receiver 200), the receiver 200 can perform an operation indicated by the message.
[0025] The sender 100 can include a controller 110, a base memory 120, a security engine 130, and a security memory 140. The controller 110 of the sender 100 can have an authority to access the base memory 120 of the sender 100. For example, when the controller 110 of the sender 100 has the authority to access the base memory 120 of the sender 100, the controller 110 of the sender 100 can be able to obtain information stored in the base memory 120 of the sender 100. For example, the base memory 120 of the sender 100 can store the message 121. The base memory 120 of the sender 100 can be implemented with one of a non-volatile memory (e.g., an electrically erasable programmable read only memory (EEPROM), a flash memory, a ferroelectric RAM (FeRAM or FRAM), a magnetoresistive RAM (MRAM), a phase change RAM (PRAM), a resistive RAM (RRAM), and a nano RAM (NRAM)).
[0026] The controller 110 of the sender 100 can control the security engine 130 of the sender 100. The security engine 130 of the sender 100 can generate a message authentication code 131 under the control of the controller 110 of the sender 100. For example, the security engine 130 of the sender 100 can have an authority to access the security memory 140 of the sender 100. Accordingly, the security engine 130 of the sender 100 can obtain information stored in the security memory 140 of the sender 100 under the control of the controller 110 of the sender 100. The security memory 140 of the sender 100 can store a key 141 of the sender 100. The security engine 130 of the sender 100 can generate the message authentication code 131 by using the key 141 obtained from the security memory 140 of the sender 100. The security memory 140 of the sender 100 can be implemented with one of a non-volatile memory (e.g., an EEPROM, a flash memory, a FeRAM or FRAM, a MRAM, a PRAM, a RRAM, and a NRAM).
[0027] The controller 110 of the transmitter 100 can generate the secure signal 300 based on the message 121 obtained from the base memory 120 of the transmitter 100 and the message authentication code 131 received from the security engine 130 of the transmitter 100. The transmitter 100 can transmit the secure signal 300 to the receiver 200.
[0028] For example, the receiver 200 can include a controller 210, a base memory 220, a security engine 230, and a secure memory 240. The receiver 200 can receive the secure signal 300 from the transmitter 100. The secure signal 300 can include the message 121 and the message authentication code 131. The base memory 220 of the receiver 200 can store the message 121 and the message authentication code 131. The base memory 220 of the receiver 200 can be implemented with one of non-volatile memories (e.g., EEPROM, flash, FeRAM or FRAM, MRAM, PRAM, RRAM, and NRAM).
[0029] The controller 210 of the receiver 200 can have an authority to access the base memory 220 of the receiver 200. The controller 210 of the receiver 200 can authenticate the message 121 by using the message authentication code 131 stored in the base memory 220 of the receiver 200. In addition, the controller 210 of the receiver 200 can control the security engine 230 of the receiver 200. The security engine 230 of the receiver 200 can have an authority to access the secure memory 240 of the receiver 200. The security engine 230 of the receiver 200 can obtain information stored in the secure memory 240 of the receiver 200 under the control of the controller 210 of the receiver 200. The secure memory 240 of the receiver 200 can store a key 241. The security engine 230 of the receiver 200 can generate information for message authentication of the controller 210 of the receiver 200 by using the key 241 obtained from the secure memory 240 of the receiver 200. The secure memory 240 of the receiver 200 can be implemented with one of non-volatile memories (e.g., EEPROM, flash, FeRAM or FRAM, MRAM, PRAM, RRAM, and NRAM). In one example, the base memory 220 and the secure memory 240 can operate independently of each other.
[0030] The controller 210 of the receiver 200 can determine whether the message 121 is authenticated based on the information generated by the security engine 230. For example, when the message 121 is authenticated, the receiver 200 can perform an operation indicated by the message 121. Alternatively, when the message 121 is not authenticated, the receiver 200 can not perform the operation indicated by the message 121. In addition, the receiver 200 can delete the message 121 stored in the base memory 220 of the receiver 200.
[0031] Figure 2 A transmitter according to an example embodiment is shown. An example operation of the transmitter 100a for generating a secure signal 300 will be described with reference to Figure 2 The transmitter 100a can include a controller 110a, a base memory 120, a secure memory 140, and a secure engine 130a. The controller 110a can output a control signal CS0 to the secure engine 130a. For example, upon receiving the control signal CS0, the secure engine 130a can generate a message authentication code 131.
[0032] Referring to Figure 2 , the secure engine 130a of the transmitter 100a can have access rights to the base memory 120 and the secure memory 140. Accordingly, the secure engine 130a can obtain information stored in the base memory 120 and the secure memory 140.
[0033] The base memory 120 can store a message 121 and an encryption function 122. Alternatively, the encryption function 122 can not be stored in the base memory 120, but can be stored in the secure memory 140. The encryption function 122 can be used to convert the message 121 into the message authentication code 131. For example, the encryption function 122 can include a hash function (e.g., a message digest (MD) function or a secure hash algorithm (SHA)).
[0034] The secure memory 140 can store a key 141. For example, after the key 141 is stored in the secure memory 140, the stored key 141 in the secure memory 140 can not be updated or replaced by new data in the secure memory 140. For example, the secure memory 140 can be a one-time programmable (OTP) area or a one-time programmable (OTP) memory of the base memory 120. For example, the OTP memory can allow data to be written only once and to maintain the written data without power. Also, the OTP area of the base memory 120 can be a memory area that is permanently not able to store additional data after the data is stored once.
[0035] Referring to Figure 2 , the secure engine 130a of the transmitter 100a can receive the message 121, the encryption function 122, and the key 141 from the base memory 120 and the secure memory 140. The secure engine 130a can generate the message authentication code 131 by using the message 121, the encryption function 122, and the key 141. For example, the message authentication code 131 can be generated by the encryption function 122 (e.g., a hash function) using an encryption algorithm when the message 121 and the key 141 are provided to the encryption function 122. Accordingly, the information of the key 141 can be protected or ensured by the encryption function 122.
[0036] A security protocol can be defined for communication between the security engine 130a and the controller 110a. For example, according to the security protocol, the security engine 130a can output only the message authentication code 131 to the controller 110a, and can not output the key 141. Also, the security engine 130a can provide other processing results to the controller 110a, through which the key 141 is not predicted.
[0037] Referring to Figure 2 The controller 110a of the transmitter 100a can receive the message authentication code 131 from the security engine 130a. The controller 110a can have a right to access only one of the basic memory 120 and the security memory 140. For example, the controller 110a can have a right to access only the basic memory 120. The controller 110a can obtain the message 121 stored in the basic memory 120. Alternatively, the controller 110a can have a right to access only the security memory 140. Also, the controller 110a can combine the message 121 and the message authentication code 131 to generate a security signal 300. The controller 110a can encode the message 121 to generate the security signal 300. The controller 110a can transmit the security signal 300 to the receiver 200.
[0038] According to an example embodiment, the controller 110a can not have a right to access the security memory 140. The security engine 130a can block access of the controller 110a to the security memory 140. For example, the controller 110a can not obtain the key 141 from the security memory 140. Also, the security engine 130a can not output the key 141 to the controller 110a according to a protocol defined for communication between the controller 110a and the security engine 130a. The security engine 130a can output only processing results so that the controller 110a cannot predict the key 141. For example, the controller 110a can not obtain or predict the key 141. Accordingly, when the controller 110a is intruded by the attacker 400, the key 141 is not exposed to the attacker 400 because the attacker 400 cannot obtain information of the key 141 through the controller 110a.
[0039] Also, because the controller 110a cannot obtain the key 141, information of the key 141 is not stored in the basic memory 120. Accordingly, even through memory dumping, the key 141 is not exposed to the attacker 400 or the outside. The memory dumping can mean an operation in which a plurality of pieces of information stored in the basic memory 120 are recorded in the outside or opened to the attacker 400. Accordingly, the transmitter 100a according to an example embodiment can improve security of the message 121 by securing the key 141 (i.e., by protecting the key 141 from intrusion or memory dumping).
[0040] Figure 3A transmitter according to another example embodiment is shown. Reference will be made to Figure 3 An example operation of the transmitter 100b for generating the secure signal 300 is described. The difference between the operation of the transmitter 100b in Figure 3 and the operation of the transmitter 100a in Figure 2 will be described.
[0041] Referring to Figure 3 , the secure engine 130b of the transmitter 100b can have access rights to the base memory 120 and the secure memory 140. Accordingly, the secure engine 130b can obtain information stored in the base memory 120 and the secure memory 140. The secure engine 130b can receive the message 121, the encryption function 122, and the key 141 from the base memory 120 and the secure memory 140.
[0042] Referring to Figure 3 , the controller 110b of the transmitter 100b can output a control signal CS1 to the secure engine 130b. When receiving the control signal CS1 from the controller 110b, the secure engine 130b can generate a message authentication code 131. The secure engine 130b can generate the message authentication code 131 by using the message 121, the encryption function 122, and the key 141. For example, the encryption function 122 can generate the message authentication code 131 based on the message 121 and the key 141, such that the message 121 and the key 141 are protected. Also, although the secure engine 130a of the transmitter 100a in Figure 2 does not incorporate the message 121 and the message authentication code 131, the secure engine 130b of the transmitter 100b in Figure 3 can incorporate the message 121 and the message authentication code 131 after generating the message authentication code 131. The secure engine 130b can incorporate the message 121 and the message authentication code 131 to generate incorporated data 350. The secure engine 130b can output the incorporated data 350 to the controller 110b.
[0043] Referring to Figure 3 , in accordance with the security protocol, the secure engine 130b of the transmitter 100b can output only a processing result, such that the key 141 is not predicted. The incorporated data 350 can be processing data generated by the encryption function 122 of the secure engine 130b. Accordingly, the key 141 will not be detected or predicted by the attacker 400. The secure engine 130b can output the incorporated data 350 to the controller 110b in accordance with the security protocol.
[0044] The controller 110b can receive the incorporated data 350 from the secure engine 130b and transmit the incorporated data 350 to transmit the secure signal 300 to the receiver (e.g., the receiver 200). Figure 1(Receiver 200 in the middle). Therefore, because key 141 is protected or encrypted by encryption function 122, and the encrypted key is included in the merged data 350, controller 110b cannot obtain or predict key 141. Therefore, even if controller 110b is compromised by attacker 400, key 141 is not exposed to attacker 400.
[0045] Furthermore, because the controller 110b cannot obtain the key 141, the information of the key 141 will not be stored in the basic memory 120. Therefore, even if the memory is dumped, the key 141 will not be exposed to the attacker 400 or the outside world.
[0046] According to the example embodiment, refer to Figure 3 The controller 110b of transmitter 100b may not have permission to access both basic memory 120 and secure memory 140. Security engine 130b may prevent controller 110b from accessing both basic memory 120 and secure memory 140. Controller 110b may be unable to obtain key 141 from secure memory 140 and message 121 from basic memory 120. Therefore, when controller 110b is attacked (e.g., by an attacker), Figure 1 When an attacker (400) makes an intrusion, because the attacker cannot obtain information about key 141 and message 121 through controller 110b, key 141 and message 121 will not be exposed to the attacker.
[0047] Figure 4 Showing the description Figure 2 The flowchart shows the operation of the security engine. (Refer to...) Figure 4 In operation S110, Figure 2 The security engine 130a of the transmitter 100a can receive control signal CS0 from the controller 110a.
[0048] Reference Figure 4 During operation S120, Figure 2 The security engine 130a of the transmitter 100a can request a key 141 from the secure memory 140. The security engine 130a can receive the key 141 from the secure memory 140. The security engine 130a can also request a message 121 from the base memory 120. The security engine 130a can receive the message 121 from the base memory 120. Furthermore, the security engine 130a can receive information about the encryption function 122 from either the base memory 120 or the secure memory 140.
[0049] Reference Figure 4 In operation S130, Figure 2The security engine 130a of the transmitter 100a in FIG. 1 can provide the message 121 and the key 141 to the encryption function 122. The encryption function 122 can generate the message authentication code 131 based on the message 121 and the key 141.
[0050] Referring to Figure 4 In operation S140, the security engine 130a of the transmitter 100a in FIG. 1 can output the message authentication code 131 to the secure storage 140 according to the security protocol. Figure 2 In operation S140, the security engine 130a of the transmitter 100a in FIG. 1 can output the message authentication code 131 to the secure storage 140 according to the security protocol. Figure 2 In operation S140, the security engine 130a of the transmitter 100a in FIG. 1 can output the message authentication code 131 to the secure storage 140 according to the security protocol.
[0051] Figure 5 A flowchart for describing the operation of the controller in FIG. 1 is illustrated. Referring to Figure 2 In operation S210, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. Figure 5 In operation S210, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. Figure 2 In operation S210, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. For example, the control signal CS0 can be used to generate the security signal 300.
[0052] Referring to Figure 5 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 2 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 2 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 2 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 2 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 2 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230, Figure 1 In operation S220, the controller 110a of the transmitter 100a in FIG. 1 can receive the message authentication code 131 from the security engine 130a. In operation S230,
[0053] Figure 6 A flowchart for describing the operation of the transmitter 100a in FIG. 1 is illustrated. Referring to Figure 2 In operation S310, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. In operation S320, Figure 6 In operation S310, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. In operation S320, Figure 2 In operation S310, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. In operation S320, Figure 2 In operation S310, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. In operation S320, Figure 2 In operation S310, the controller 110a of the transmitter 100a in FIG. 1 can output a control signal CS0 to the security engine 130a. In operation S320,
[0054] In addition, refer to Figure 6 In operating S330, Figure 2 The security engine 130a can request message 121 from the base memory 120. During operation S335, Figure 2 The basic memory 120 can output message 121 to the security engine 130a in response to a request from the security engine 130a. During operation S340, Figure 2 The security engine 130a can generate a message authentication code 131 using key 141 and message 121. In operation S350, Figure 2 The security engine 130a can output the message authentication code 131 to the controller 110a.
[0055] In addition, refer to Figure 6 In operating the S360, Figure 2 The controller 110a can request message 121 from the base memory 120. During operation S365, Figure 2 The basic memory 120 can output message 121 to the controller 110a. In operation S370, Figure 2 The controller 110a can generate a security signal 300 by using message 121 and message authentication code 131. Figure 1 The controller 110a in the middle can send the safety signal 300 to Figure 7 Receiver 200 in the middle.
[0056] Figure 7 A receiver according to an example embodiment is shown. Reference will be made to... Figure 1 This describes the operation of receiver 200a for checking message 121. Receiver 200a may correspond to... Figure 1 An embodiment of receiver 200 in the middle.
[0057] For example, receiver 200a can receive data from transmitter (e.g., Figure 2 Transmitter 100 in Figure 3 Transmitter 100a and Figure 7 The transmitter 100b) in the receiver 200a receives the security signal 300. The security signal 300 may include a message 121 and a message authentication code 131. For example, when the receiver 200a receives the security signal 300, the controller 210a of the receiver 200a may output a control signal CS2 to the security engine 230a. Furthermore, when the security engine 230a receives the control signal CS2, the security engine 230a may generate a message authentication code 231 based on the message 121 and the key 241. The controller 210a may determine whether the message 121 of the security signal 300 is authenticated based on the message authentication code 231 from the security engine 230a.
[0058] For example, the security engine 230a can have access to the secure memory 240. The secure memory 240 can store the key 241. The security engine 230a can request the key 241 from the secure memory 240 to generate the message authentication code 231. The security engine 230a can request the key 241 from the secure memory 240. Figure 2 The key 241 in the secure memory 240 can correspond to the key 141 in the basic memory 220. For example, when the key 241 is stored in the secure memory 240, the key 241 in the secure memory 240 can not be updated or replaced by new data. For example, the secure memory 240 can be an OTP area or an OTP memory of the basic memory 220. The OTP area of the basic memory 220 can be an area that is permanently not storable of additional data after the data is stored once. Figure 7 The key 241 in the secure memory 240 can correspond to the key 141 in the basic memory 220. For example, when the key 241 is stored in the secure memory 240, the key 241 in the secure memory 240 can not be updated or replaced by new data. For example, the secure memory 240 can be an OTP area or an OTP memory of the basic memory 220. The OTP area of the basic memory 220 can be an area that is permanently not storable of additional data after the data is stored once.
[0059] For example, the security engine 230a can have access to the basic memory 220. The basic memory 220 can store the message 121 and the message authentication code 131 received from the transmitter 100. In addition, the basic memory 220 can store information for the encryption function 222. The encryption function 222 can generate the message authentication code 231 based on the message 121 and the key 241. For example, Figure 2 The encryption function 222 in the basic memory 220 can correspond to the encryption function 122 in the basic memory 220. For example, the encryption function 222 can be a hash function (e.g., MD function or SHA). Figure 1 The encryption function 222 in the basic memory 220 can correspond to the encryption function 122 in the basic memory 220. For example, the encryption function 222 can be a hash function (e.g., MD function or SHA).
[0060] For example, the security engine 230a can request the message 121 and the encryption function 222 from the basic memory 220 to generate the message authentication code 231. The security engine 230a can receive the message 121 and the encryption function 222 from the basic memory 220. Alternatively, the encryption function 222 can not be stored in the basic memory 220, but can be stored in the secure memory 240. The security engine 230a can receive the encryption function 222 from the secure memory 240.
[0061] The security engine 230a can generate the message authentication code 231 by using the key 241, the message 121, and the encryption function 222. For example, when the message 121 and the key 241 are provided to the encryption function 222, the message authentication code 231 can be generated by the encryption function 222.
[0062] A security protocol can be defined for the communication between the security engine 230a and the controller 210a. According to the security protocol, the security engine 230a can be able to output only the message authentication code 231 to the controller 210a, but not the key 241. In addition, for example, the security engine 230a can provide the controller 210a with any other result processed to protect or secure the key 241.
[0063] For example, the controller 210a can receive a message authentication code 231 from the security engine 230a. The controller 210a can have access to only one of the memories 220 and 240. For example, the controller 210a can have access to only the base memory 220. Thus, the controller 210a can request the message authentication code 131 from the base memory 220. The controller 210a can receive the message authentication code 131 from the base memory 220. The message authentication code 131 can be a message authentication code received from the transmitter 100 in Figure 2 , Figure 3 the transmitter 100a in Figure 1 , and the transmitter 100b in . The message authentication code 231 can be a message authentication code generated or computed in the receiver 200a (e.g., in the security engine 230a).
[0064] Optionally, the base memory 220 can not store the message authentication code 131. The message authentication code 131 can be stored in a memory of the controller 210a. Thus, the controller 210a can not request the message authentication code 131 from the base memory 220.
[0065] Figure 1 The controller 210a can compare the message authentication code 131 with the message authentication code 231 to check the message 121. The controller 210a can identify whether the message authentication code 131 matches the message authentication code 231. The message authentication code 131 can match the message authentication code 231 when the message 121 is output from the authenticated transmitter 100 and is not modified by the attacker 400 in Figure 8 . Conversely, the message authentication code 131 can not match the message authentication code 231 when the message 121 is not a message output from the authenticated transmitter 100 or is modified by the attacker 400 in
[0066] The controller 210a can authenticate the message 121 when the message authentication code 131 matches the message authentication code 231. When the controller 210a fully authenticates the message 121, the controller 210a can output a signal to perform an operation indicated by the message 121. The receiver 200a can perform the operation indicated by the message 121 based on the signal output from the controller 210a.
[0067] When the message authentication code 131 does not match the message authentication code 231, the controller 210a can not authenticate the message 121. When the controller 210a does not authenticate the message 121, the receiver 200a can not perform the operation indicated by the message 121. Also, the controller 210a can control the base memory 220 so that the message 121 stored in the base memory 220 is deleted.
[0068] According to an example embodiment, the controller 210a has no authority to access the secure memory 240. The secure engine 230a can block the controller 210a's access to the secure memory 240. For example, the controller 210a can not be able to obtain the key 241 from the secure memory 240. Also, the secure engine 230a can not be able to output the key 241 to the controller 210a according to a protocol defined between the controller 210a and the secure engine 230a. The secure engine 130a can output only a processing result so that the controller 210a cannot predict the key 241. Thus, the controller 210a can not be able to obtain or predict the key 241. Accordingly, when the controller 210a is intruded by the attacker 400, the key 241 is not exposed to the attacker 400.
[0069] Because the controller 210a cannot obtain the key 241, information of the key 241 is not stored in the base memory 220. For example, the key 241 is not exposed to the attacker 400 or the outside even through memory dumping. Thus, the receiver 200a according to an example embodiment can secure the key 241. Because the security of the keys 141 and 241 is secured, the receiver 200a can determine with high accuracy whether the message 121 is transmitted from an authenticated transmitter 100 and whether the message 121 is not modified.
[0070] Figure 8 A receiver according to another example embodiment is illustrated. The operation of the receiver 200b for checking the message 121 will be described with reference to Figure 1 The receiver 200b can correspond to the embodiment of the receiver 200 in Figure 8 The operation of the receiver 200b described with reference to Figure 7 will be mainly described. The difference between the operation of the receiver 200b described with reference to Figure 8 and the operation of the receiver 200a described with reference to
[0071] When the secure signal 300 is received, the controller 210b can output a control signal CS3 to the secure engine 230b. When the control signal CS3 is received, the secure engine 230b can generate the message authentication code 231.
[0072] The secure engine 230b can have access to Figure 7the secure engine 230b can obtain information stored in the base memory 220 and the secure memory 240. The secure engine 230b can receive the message 121, the cryptographic function 222, and the key 241 from the memories 220 and 240. The secure engine 230b can generate the message authentication code 231 by using the message 121, the cryptographic function 222, and the key 241. Further, although the secure engine 230a in the secure engine 230a does not compare the message authentication code 131 with the message authentication code 231, the secure engine 230b can compare the message authentication code 131 with the message authentication code 231 after generating the message authentication code 231. Figure 7
[0073] The secure engine 230b can request the message authentication code 231 from the base memory 220. The secure engine 230b can receive the message authentication code 231 from the base memory 220. The secure engine 230b can identify whether the message authentication code 131 matches the message authentication code 231. As described with reference to FIG. 1, when the message 121 is output from the authenticated transmitter 100 and is not modified by the attacker 400 in the attacker 400, the message authentication code 131 stored in the base memory 220 can match the message authentication code 231 generated by the secure engine 230b. In contrast, when the message 121 is not a message output from the authenticated transmitter 100 or is modified by the attacker 400 in the attacker 400, the message authentication code 131 can not match the message authentication code 231. Figure 1 Figure 1 Figure 8
[0074] For example, the secure engine 230b can generate a result signal RSO based on a result of comparing the message authentication code 131 with the message authentication code 231. The result signal RSO can indicate whether the message authentication code 131 matches the message authentication code 231. For example, when the result signal RSO has a first logic value or a first voltage level, the message authentication code 131 can match the message authentication code 231. Further, when the result signal RSO has a second logic value or a second voltage level, the message authentication code 131 can not match the message authentication code 231. The first logic value can be different from the second logic value, and the first voltage level can be different from the second voltage level.
[0075] The secure engine 230b can output the result signal RSO to the controller 210b in accordance with a security protocol. Figure 7 The result signal RSO in the secure engine 230b can correspond to the message authentication code 231 in the secure engine 230a, and Figure 8 The result signal RSO in the secure engine 230b can be processed such that the key 241 included in the message authentication code 231 is protected and encrypted. Figure 9
[0076] The controller 210b can receive the result signal RS0. The controller 210b can determine whether the message 121 is authenticated based on a logic value of the result signal RS0 or a voltage level of the result signal RS0.
[0077] When the result signal RS0 has the first logic value or the first voltage level, the controller 210b can authenticate the message 121. Also, when the controller 210b completely authenticates the message 121, the controller 210b can output a signal for performing an operation indicated by the message 121. The receiver 200b can perform the operation indicated by the message 121 based on the signal output from the controller 210b.
[0078] When the result signal RS0 has the second logic value or the second voltage level, the controller 210b can not authenticate the message 121. Also, when the controller 210b does not authenticate the message 121, the receiver 200b can not perform the operation indicated by the message 121. For example, the controller 210b can control the basic memory 220 to delete the message 121 stored in the basic memory 220.
[0079] Accordingly, the controller 210b can not obtain or predict the key 241. Accordingly, when the controller 210b is intruded by the attacker 400, the key 241 is not exposed to the attacker 400. Because the controller 210b cannot obtain the key 241, information of the key 241 is not stored in the basic memory 220. Accordingly, even through memory dumping, the key 241 is not exposed to the attacker 400 or the outside.
[0080] Figure 7 A flowchart for describing an operation of a security engine in Figure 9 is illustrated. Referring to Figure 10 , in operation S410, the security engine 230a can receive the control signal CS2 from the controller 210a.
[0081] In operation S420, the security engine 230a can request the key 241 from the secure memory 240. The security engine 230a can receive the key 241 from the secure memory 240. The security engine 230a can request the message 121 from the basic memory 220. The security engine 230a can receive the message 121 from the basic memory 220. Also, the security engine 230a can receive information of the encryption function 222 from the basic memory 220 or the secure memory 240.
[0082] In operation S430, the security engine 230a can provide the message 121 and the key 241 to the encryption function 222. The encryption function 222 can generate the message authentication code 231 based on the message 121 and the key 241. In operation S440, the security engine 230a can output the message authentication code 231 to the controller 210a in accordance with a security protocol.
[0083] Figure 7 A flowchart for describing an operation of a controller in Figure 10 is shown. Referring to Figure 11 , in operation S510, the controller 210a can output a control signal CS2 to the security engine 230a.
[0084] The security engine 230a can generate a message authentication code 231 in response to the control signal CS2. In operation S520, the controller 210a can receive the message authentication code 231 from the security engine 230a. In operation S530, the controller 210a can compare the message authentication code 131 with the message authentication code 231. The controller 210a can receive the message authentication code 131 from the outside (e.g., the transmitter 100). The message authentication code 131 and the message authentication code 231 can be respectively denoted as a received message authentication code and a calculated message authentication code.
[0085] When the message authentication code 131 matches the message authentication code 231, the process can proceed to operation S540. In operation S540, the controller 210a can generate a signal for performing an operation indicated by the message 121.
[0086] When the message authentication code 131 does not match the message authentication code 231, the process can proceed to operation S550. In operation S550, the controller 210a can generate a signal for deleting the message 121 stored in the base memory 220.
[0087] Figure 7 A flowchart for describing an operation of a receiver in Figure 11 is shown. Referring to , in operation S610, the controller 210a can output a control signal CS2 to the security engine 230a. In operation S620, the security engine 230a can request a key 241 to the security memory 240. In operation S625, the security memory 240 can output the key 241 to the security engine 230a in response to the request of the security engine 230a.
[0088] For example, in operation S630, the security engine 230a can request a message 121 to the base memory 220. In operation S635, the base memory 220 can output the message 121 to the security engine 230a in response to the request of the security engine 230a. In operation S640, the security engine 230a can calculate a message authentication code 231 by using the key 241 and the message 121. The message authentication code 231 can be denoted as a calculated message authentication code. In operation S650, the security engine 230a can output the message authentication code 231 to the controller 210a.
[0089] Further, in operation S660, the controller 210a can compare the message authentication code 131 with the message authentication code 231. The controller 210a can receive the message authentication code 231 from the security engine 230a. Further, the controller 210a can receive the message authentication code 131 from outside (e.g., the transmitter 100). The message authentication code 131 can be denoted as a received message authentication code. In operation S670, the controller 210a can determine whether the message 121 is authenticated based on a result of the comparison.
[0090] According to the example embodiment, because the controller cannot obtain or predict the authentication key, the authentication key is not exposed to an attacker when the controller is intruded. Further, because the authentication key is not stored in the base memory, the authentication key is not exposed to an attacker through memory dumping. Accordingly, the storage device according to the example embodiment can provide high security by improving security of the authentication key.
[0091] Various operations of the above-described methods can be performed appropriately, such as by various hardware components and / or software components, modules, and / or circuitry. When implemented in software, the operations can be implemented using, for example, an ordered listing of executable instructions for implementing logic functions, and can be embodied in one or more processor-readable media, used by or in connection with an instruction execution system, apparatus, or device, such as a single- or multi-processor system, or including a processor.
[0092] In some embodiments, the blocks or steps of the methods or algorithms and functions described in connection with the embodiments disclosed herein can be implemented directly in hardware, in a software module executed by a processor, or in a combination of software and hardware. If implemented in software, the functions can be stored or transmitted over as one or more instructions or code on a tangible, non-transitory computer-readable medium. Software modules can reside in, for example, RAM, flash memory, ROM, electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD ROM, or any other form of storage medium.
[0093] Example embodiments have been disclosed herein and, although a particular order thereof was disclosed, they are merely examples and are not intended to imply an order of execution. For instance, certain embodiments can be performed sequentially, in parallel, or in a different order. Additionally, certain embodiments can be performed by different entities of varying structure. Furthermore, certain embodiments can be performed under the control of one or more computer systems configured and arranged to perform the corresponding tasks. One of ordinary skill in the art will appreciate that the teachings of the present application can be implemented in various forms of hardware, software, or combinations thereof, for use in various systems. Therefore, the embodiments disclosed herein are merely examples and should not be considered limiting as the scope of the application is to be given by the appended claims.
Claims
1. A storage device comprising: a base memory storing a message received from an external device, the message indicating an operation to be performed by the storage device; a secure memory storing an authentication key for authenticating the message; a controller outputting a control signal; and a security engine obtaining the authentication key from the secure memory with a privilege to access the secure memory in response to the control signal from the controller, and blocking access of the secure memory by the controller, wherein the security engine is to calculate a message authentication code based on the message obtained from the base memory and the authentication key obtained from the secure memory, wherein the controller is to output a signal for performing the operation indicated by the message based on a comparison result obtained by comparing the calculated message authentication code with a message authentication code sent from the external device, and wherein the security engine has the privilege to access the secure memory, and the controller does not have the privilege to access the secure memory. The security engine is to block the authentication key from being transferred from the secure memory to the controller.
2. The memory device of claim 1, wherein, The base memory and the secure memory are non-volatile memories.
3. The memory device of claim 1, wherein, The security engine is to output the comparison result obtained by comparing the calculated message authentication code with the message authentication code sent from the external device to the controller.
4. The memory device of claim 1, wherein, The base memory and the secure memory operate independently of each other.
5. The memory device of claim 1, wherein, The secure memory and the base memory are included in the same memory device, and 6. The memory device of claim 1, wherein, The secure memory corresponds to a one-time programmable area of the same memory device. The authentication key is stored in the secure memory only once and is maintained.
7. The memory device of claim 1, wherein, The authentication key is stored only in the secure memory among the base memory and the secure memory.
8. The memory device of claim 1, wherein, 9. An electronic device comprising: a base memory storing a message sent from an external device and a first message authentication code, the message indicating an operation to be performed by the electronic device; a secure memory storing an authentication key for authenticating the message; a controller outputting a control signal; and a security engine obtaining the authentication key from the secure memory in response to the control signal from the controller, and generating a second message authentication code based on the message obtained from the base memory and the authentication key obtained from the secure memory, wherein the security engine blocks the authentication key from being transferred from the secure memory to the controller, wherein the controller is to output a signal for performing the operation indicated by the message based on a comparison result obtained by comparing the second message authentication code with the first message authentication code, and wherein the security engine has the privilege to access the secure memory, and the controller does not have the privilege to access the secure memory. The authentication key is blocked from being output to the controller by a protocol defined for communication between the controller and the security engine. Information for predicting the authentication key is prevented from being output from the security engine to the controller. 10.The electronic device of claim 9, wherein The controller is to authenticate the message when the first message authentication code matches the second message authentication code. 11.The electronic device of claim 9, wherein The controller is to generate a signal for performing the operation indicated by the message when the message is authenticated. 12.The electronic device of claim 9, wherein The controller is to delete the message stored in the base memory when the message is not authenticated. 13.The electronic device of claim 9, wherein The base memory is to store information of an encryption function, and 14.The electronic device of claim 9, wherein the controller is to output the signal for performing the operation based on a result of the encryption function applied to the message. 15.The electronic device of claim 9, wherein wherein the encryption function generates a second message authentication code based on the authentication key and the message.
16. A storage device comprising: a base memory storing a message, the message indicating an operation to be performed by the storage device; a secure memory storing an authentication key for protecting the message; a controller outputting a control signal; and a security engine obtaining the authentication key from the secure memory with authority to access the secure memory in response to the control signal from the controller, generating a message authentication code based on the message obtained from the base memory and the authentication key obtained from the secure memory, and blocking access of the secure memory by the controller, wherein the controller is to output a signal for performing the operation indicated by the message based on a comparison result obtained by comparing the generated message authentication code with a message authentication code transmitted from an external device, and wherein the security engine has authority to access the secure memory and the controller does not have authority to access the secure memory.
17. The memory device of claim 16, wherein, The security engine is to block output of the authentication key from the secure memory to the controller.
18. The memory device of claim 16, wherein, The security engine is to block output of the authentication key from the security engine to the controller.
19. The memory device of claim 16, wherein, The authentication key is stored only in the secure memory among the base memory and the secure memory. The authentication key is stored only in the secure memory among the base memory and the secure memory.
Citation Information
Patent Citations
A marshmallow comprising allulose and method for preparation thereof
KR1020190053736A
Method for accessing and uploading data in data storage system
CN103701611A