Storage device and operating method thereof, nonvolatile memory system
By introducing user authentication, data encryption, and relink triggering circuits into the non-volatile memory system, the problem of SED storage devices being unable to operate independently in different host devices is solved, achieving highly secure and flexible storage device operation.
Patent Information
- Application Number
- CN202011112295.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-03
- Filing Date
- 2020-10-16
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2040-10-16
AI Technical Summary
Existing storage devices that support Self-Encrypting Drives (SEDs) cannot operate independently on host devices that do not support SEDs, and their security is insufficient, failing to provide high security features across a variety of host devices.
A non-volatile memory system is designed, including a storage device, a memory controller, and a link controller. User authentication, data encryption, and decryption are achieved through physical connections of power lines and data lines. A relink trigger circuit is used to control the temporary deactivation and activation of the data lines, ensuring the security and independent operation of the storage device.
It achieves security for storage devices that operate independently on various host devices, prevents data leakage, ensures that the storage device cannot access user data without authorization, and improves the security and flexibility of the storage device.
Smart Images

Figure CN112905495B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims the benefit of priority to Korean Patent Application No. 10-2019-0159366, filed on December 3, 2019, with the Korean Intellectual Property Office, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] The present invention relates to semiconductor memories, and more specifically, to memory devices, non-volatile memory systems including memory controllers, and methods of operating memory devices. Background Technology
[0004] Semiconductor memory devices can be divided into volatile memory devices and non-volatile memory devices. Volatile memory devices lose their stored data when power is cut off, while non-volatile memory devices retain their stored data even when power is cut off. Volatile memory devices have fast read and write speeds, but their stored content is lost when external power is no longer supplied. On the other hand, non-volatile memory devices have slower read and write speeds than volatile memory devices; however, their content is retained even when external power is no longer supplied.
[0005] Due to its high operating speed, low power consumption, low noise, and high capacity stacking, flash memory is a non-volatile memory device used in various fields. With the increasing use of flash memory, the demand for flash security technologies has also increased.
[0006] Self-Encrypting Drive (SED) is a security technology used in flash memory that provides high security by encrypting data to write encrypted data and decrypting encrypted data to read data.
[0007] However, storage devices supporting SED are passive devices and can operate according to commands from the host device. Therefore, when the host device does not support SED, the storage device may not be able to operate independently. Thus, a storage device capable of operating on various host devices is needed. Summary of the Invention
[0008] The present invention provides a storage device, a memory controller, a non-volatile memory system including the memory controller, a method of operating the storage device, and an apparatus and method for independently performing a relink to a host device.
[0009] According to an embodiment of the present invention, a non-volatile memory system is provided, comprising: a host device and a storage device connected to the host device via a physical cable including a power line and a data line, the storage device including: non-volatile memory; a link controller configured to temporarily disable the data line while being powered from the host device via the power line; and a memory controller including: a user authentication circuit configured to authenticate a user of the storage device and change the state of the memory controller based on the authentication result; a relink trigger circuit configured to control the link controller based on the state change of the memory controller; and a data processing circuit configured to encrypt and decrypt data.
[0010] According to another embodiment of the present invention, a storage device is provided, comprising: a non-volatile memory; a user input receiving circuit; a link controller configured to disable a data line, the storage device being physically connected to a host device via the data line; and a memory controller configured to perform user authentication by comparing a pre-stored user input value with a user input value received from the host device or the user input receiving circuit, changing the state of the memory controller based on the user authentication result, and sending a trigger signal indicating temporary disabling of the data line to the link controller based on the change in the state of the memory controller.
[0011] According to another embodiment of the present invention, a method of operating a storage device including a non-volatile memory, a link controller, and a memory controller is provided. The method includes: detecting a physical connection with a host device; receiving user input from a user input receiving circuit in the host device or the storage device; performing user authentication based on the received user input; changing the state of the memory controller to an unlocked state when the user authentication is successful; and performing a relink to the host device in response to changing to the unlocked state. Attached Figure Description
[0012] Embodiments of the inventive concept will become clearer from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0013] Figure 1A This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention;
[0014] Figure 1B This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention;
[0015] Figure 2 This is a signaling diagram of a non-volatile memory system according to an exemplary embodiment of the present invention;
[0016] Figure 3This is a flowchart illustrating the operation of a memory controller according to an exemplary embodiment of the present invention;
[0017] Figure 4A The storage state of a non-volatile memory device according to an example embodiment of the present invention is shown;
[0018] Figure 4B The storage state of a non-volatile memory device according to another exemplary embodiment of the concept of the present invention is shown;
[0019] Figure 5 This is a block diagram of a storage device according to an exemplary embodiment of the present invention;
[0020] Figure 6 This is a block diagram of the interface between a host device and a storage device according to an exemplary embodiment of the present invention.
[0021] Figure 7 This is a flowchart illustrating the operation of a host device according to an exemplary embodiment of the present invention;
[0022] Figure 8 This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention;
[0023] Figure 9 This is a signaling diagram of a non-volatile memory system according to an exemplary embodiment of the present invention; and
[0024] Figure 10 This is a block diagram illustrating an example of applying a storage device according to an exemplary embodiment of the present invention to a solid-state drive (SSD) system. Detailed Implementation
[0025] In the following description, embodiments of the inventive concept will be described in detail with reference to the accompanying drawings. In the drawings, the same reference numerals consistently denote the same elements.
[0026] Figure 1A This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention. Figure 1A A non-volatile memory system 10 is illustrated. The non-volatile memory system 10 may include a host device 100 and a storage device 400. In some embodiments, the host device 100 may be connected to the storage device 400 via a physical cable including power lines and data lines. The physical cable may include a cable for a hot-swappable interface (e.g., interface 150).
[0027] Storage device 400 may include link controller 210, storage device controller (hereinafter, SD controller or memory controller) 220, and non-volatile memory 300.
[0028] The host device 100 can be implemented by an electronic device, such as a personal computer (PC), laptop computer, mobile phone, smartphone, tablet PC, personal digital assistant (PDA), enterprise digital assistant (EDA), digital camera, digital video camera, audio device, portable multimedia player (PMP), personal navigation device (PND), MP3 player, handheld game console, e-book, etc. Alternatively, the host device 100 can be implemented by an electronic device such as a wearable device (e.g., a watch or head-mounted display (HMD)).
[0029] According to an exemplary embodiment of the present invention, host device 100 may include an interface 150 configured to send and receive commands CMD and / or data DATA from storage device 400. Interface 150 may include at least one hot-pluggable interface. For example, interface 150 may include interface protocols such as Peripheral Component Rapid Interconnect (PCI-E), Advanced Technology Attachment (ATA), Serial ATA (SATA), Parallel ATA (PATA), or Serial Attached Small Computer System Interface (SCSI) (SAS). Additionally, various interface protocols may be applied, such as Universal Serial Bus (USB), Multimedia Card (MMC), Enhanced Small Disk Interface (ESDI), Integrated Drive Electronics (IDE), and Thunderbolt.
[0030] According to an exemplary embodiment of the present invention, storage device 400 can store and output data. Storage device 400 can be internal memory embedded in an electronic device. For example, storage device 400 can be an embedded universal flash memory (UFS) storage device, an embedded multimedia card (eMMC), or a solid-state drive (SSD). Storage device 400 can be embedded on the same semiconductor substrate as host device 100. According to an exemplary embodiment of the present invention, storage device 400 can be external memory that is attachable to and removable from an electronic device. For example, storage device 400 can include a UFS memory card, a compact flash memory (CF) card, a secure digital card (SD) card, a micro-secure digital card (Micro-SD) card, a mini-secure digital card (Mini-SD) card, an extreme digital card (xD) card, or a Memory Stick.
[0031] According to an exemplary embodiment of the present invention, the link controller 210 can control the link (or connection) between the storage device 400 and the host device 100. In some embodiments, the link controller 210 and the SD controller 220 may be on the same semiconductor substrate. When the link controller 210 is implemented with a different separate configuration from the SD controller 220, it may be referred to as a bridge board. A controllable link can refer to activating or deactivating a data path for data transmission and reception while receiving power through a power line. For example, the link controller 210 can deactivate pins connected to the data path while maintaining a connection with the host device 100 via a USB cable. For example, deactivating or disabling pins corresponding to the data path while the storage device 400 receives power from the host device 100 can cause the host device 100 to recognize that the host device 100 and the storage device 400 are disconnected due to the deactivation of pins corresponding to the data path, even though the host device 100 is still physically connected to the storage device 400 via the USB cable. Subsequently, when the link controller 210 reactivates (or enables) the pins corresponding to the data path, the host device 100 recognizes the storage device 400 again. For example, link controller 210 can re-identify storage device 400 by reactivating the pin corresponding to the data path. In some embodiments, link controller 210 may include a switch (not shown) on the data path, and link controller 210 can control the link by controlling the switch. As another example, link controller 210 may include a microcontroller (not shown). Link controller 210 can reset or initialize the microcontroller to both receive power and temporarily disable the data path. Therefore, relinking between host device 100 and storage device 400 can be performed even if there is no actual unplugging or physical disconnection between host device 100 and storage device 400.
[0032] According to an exemplary embodiment of the present invention, the SD controller 220 may include a data processing circuit 230, a user authentication circuit 240, a relink trigger circuit 250, and a user input receiving circuit 270.
[0033] The data processing circuit 230 can provide various signals to the non-volatile memory 300 and control operations such as write and read operations. For example, the SD controller 220 can access data stored in the memory cell array by providing the command CMD and address ADDR to the non-volatile memory 300.
[0034] As another example, the data processing circuit 230 can encrypt the data and store the encrypted data in the memory cell array, or the data processing circuit 230 can decrypt the encrypted data stored in the memory cell array and output the decrypted data as read data. Because encryption and decryption are performed during data storage and data output, leakage of the stored data can be prevented even if the storage device 400 is stolen or lost.
[0035] User authentication circuit 240 can determine whether a user is an authorized user of storage device 400. User authentication circuit 240 can receive a password through host device 100 or user input receiving circuit 270 included in storage device 400.
[0036] For example, when storage device 400 is encrypted, a user of storage device 400 can only access the user data area after user authentication (or verification). Therefore, the user can input a password via host device 100 or user input receiving circuit 270 of storage device 400. The password can be referred to as user input. User input can be included in at least one of the data DATA received by storage device 400 from host device 100, or in data transmitted from user input receiving circuit 270 to user authentication circuit 240. User authentication circuit 240 can determine whether a user is an authorized user of storage device 400 by comparing the user input received via host device 100 and link controller 210 or from user input receiving circuit 270 with a pre-stored password. When the comparison result does not match, the storage device remains locked, thus protecting user data. When the comparison result matches, the storage device is unlocked, and access to user data can be enabled.
[0037] The relink trigger circuit 250 can send a trigger signal to the link controller 210. The trigger signal can be a signal used to control the link controller 210 so that the link controller 210 performs a relink (or reconnection). For example, in response to receiving the trigger signal, the link controller 210 can disable a pin corresponding to the data path, disable a switch on the data path, or initialize the microcontroller included in the link controller 210.
[0038] According to an exemplary embodiment of the present invention, the relink trigger circuit 250 can send a trigger signal to the link controller 210 based at least on the state of the SD controller 220. For example, when the SD controller 220 changes from a locked state to an unlocked state, the relink trigger circuit 250 can send a trigger signal to the link controller 210.
[0039] User input receiving circuit 270 can receive user input. User input may include a password or data for a password, which can be used to change the state of SD controller 220 from a locked state to an unlocked state. User input receiving circuit 270 can receive user input and transmit it to user authentication circuit 240. User authentication circuit 240 can perform user authentication by comparing the received user input with a pre-stored password.
[0040] According to exemplary embodiments of the present invention, the user input receiving circuit 270 can be implemented by various devices. For example, the user input receiving circuit 270 can be implemented by a dial device or a keypad. In some embodiments, the user input receiving circuit 270 may include a dial or a slow dial configured to input multiple numbers. The user of the storage device 400 can input numbers that are the same as a preset password by manipulating the dial or slow dial, or by touching or pressing numbers on the keypad.
[0041] In another exemplary embodiment of the invention, the user input receiving circuit 270 may be implemented by a radio frequency identification (RFID) module. The RFID module may be a module configured to exchange data between an RFID tag device and an RFID reader using radio frequency. In another exemplary embodiment of the invention, the RFID module may be implemented by a near field communication (NFC) module and / or a magnetically secure transmission (MST) module. For example, a user may have an external device (not shown) separate from the host device 100. The external device is capable of performing biometrics and may include a device capable of performing wireless communication, such as a smartphone. The external device may send user authentication data to the user input receiving circuit 270 via the NFC module or the MST module in response to successful user authentication. In this case, the user can manipulate the external device such that it is within a predetermined distance of the storage device 400.
[0042] In another exemplary embodiment of the invention, the user input receiving circuit 270 can compare biometric data pre-stored in the biometric module with the input biometric data. Here, the biometric data can be data used to identify or verify an individual based on human physical characteristics. For example, biometric data can include various types of data, including fingerprint data, iris data, vein data, voice data, retinal data, etc. According to the above exemplary embodiment, the user can unlock the storage device without entering a password through the host device 100.
[0043] Figure 1B This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention. (Reference) Figure 1A The descriptions provided here need not be repeated.
[0044] refer to Figure 1A and Figure 1B The SD controller 220 may also include connection management circuitry 260. Although Figure 1A The link controller 210 and SD controller 220 are shown to be separate controllers that can be distinguished from each other, but this embodiment is not limited thereto.
[0045] According to an exemplary embodiment of the present invention, reference is made to Figure 1B The link controller 210 and SD controller 220 can be integrated together. The connection management circuit 260 can control the link to the host device 100. The connection management circuit 260 can perform operations related to... Figure 1A The operation is the same as that of the link controller 210. For example, the connection management circuit 260 can disable the pins of the SD controller 220 corresponding to the data path, disable the switches on the data path, or reset or initialize the SD controller 220. The connection management circuit 260 can be used to: allow the host device 100 to perform a relink (or reconnection) to the storage device 400 while maintaining the physical connection to the storage device 400.
[0046] Figure 2 This is a signaling diagram of a non-volatile memory system according to an exemplary embodiment of the present invention.
[0047] refer to Figure 2 In operation S110, a user configuration can be established between the host device 100 and the storage device 400. For example, a user of the storage device 400 can reset the password of the storage device 400 or change the preset password used for data encryption. According to an exemplary embodiment of the present invention, the user configuration can be established using software that supports the self-encrypting drive (SED) function of the storage device 400. Reference will be made below. Figure 7 A more detailed description of operation S110 is provided.
[0048] In operation S120, the SD controller 220 can change its state from unlocked to locked. After user configuration is completed in operation S110, the user of storage device 400 can disconnect storage device 400 from host device 100. The SD controller 220 can change its state to locked in response to power cutoff to ensure user data security. For example, when the user releases the physical connection to host device 100, power from host device 100 can be cut off. When power to storage device 400 is cut off, the SD controller 220 can change its state to locked. The SD controller 220 can disable access to the user data area by changing the pointer information of non-volatile memory 300. (See reference...) Figure 4A and Figure 4B To provide a more specific description.
[0049] In operation S130, the host device 100 can be physically connected to the storage device 400. For example, when both the host device 100 and the storage device 400 support USB interfaces, a physical connection can be established via a USB cable. When the host device 100 is connected to the storage device 400, the host device 100 can supply power to the storage device 400 via a power line to operate the storage device 400. For example, when the USB interface is a USB Type-C interface, the storage device 400 can receive power from the host device 100 via the VBUS pin.
[0050] In operation S140, the SD controller 220 can receive user input. The user input may be a preset password for unlocking the storage device 400. Specifically, the user authentication circuit 240 of the SD controller 220 can receive user input via the host device 100 or the user input receiving circuit 270. For example, the host device 100 can receive user input via the input / output (I / O) interface 110. The I / O interface 110 may include various I / O devices, such as a mouse, keyboard, and touchscreen. As another example, the user input receiving circuit 270 may be implemented by at least one of a dial, a slow dial, a biometric module, an RFID module, and a keypad.
[0051] In operation S150, the SD controller 220 can perform user authentication. The SD controller 220 can receive user input from the host device 100 or the user input receiving circuit 270, and use the user authentication circuit 240 to determine whether the user is an authorized user of the storage device 400. The user authentication circuit 240 can compare the previously stored password with the received user input to determine whether the received user input matches the previously stored password.
[0052] In operation S160, the SD controller 220 can change its state from locked to unlocked. When the pre-stored password matches the user input received in operation S150, it is determined that the user is an authorized user of the storage device 400, and the state of the SD controller 220 can be changed to unlocked to allow access to the user data area. For example, when the comparison result is a match, the user authentication circuit 240 can activate access to the user data area by changing the pointer information of the non-volatile memory 300. (See reference...) Figure 4A and Figure 4B To provide a more specific description, the user verification circuit 240 can change the pointer information and transmit control signals to the relink trigger circuit 250.
[0053] In operation S170, a relinking can be performed between the host device 100 and the storage device 400. As described above, relinking does not mean that the physical connection is released and then re-established. That is, relinking can indicate that while continuously powered in an inserted state, only the data path is temporarily deactivated and reactivated, rather than being unplugged and then plugged in again. This can be achieved by... Figure 1A Link controller 210 or Figure 1B The connection management circuit 260 performs a reconnection.
[0054] According to an exemplary embodiment of the present invention, when the storage device 400 includes Figure 1A When the link controller 210 is connected, the relink trigger circuit 250 of the SD controller 220 can send a trigger signal to the link controller 210. In response to receiving the trigger signal from the relink trigger circuit 250, the link controller 210 can perform a relink by temporarily disabling a pin corresponding to the data path, temporarily deactivating a switch on the data path, or initializing a microprocessor (not shown). In another embodiment of the invention, when the storage device 400 is implemented as including... Figure 1B When the SD controller 220, which is integrated with the link controller 210, is shown, relinking can be performed by controlling the connection management circuit 260. For example, in response to receiving a trigger signal from the relink trigger circuit 250, the connection management circuit 260 can perform relinking by temporarily disabling the pins corresponding to the data path or temporarily deactivating the switches on the data path.
[0055] In operation S180, host device 100 can write and / or read data. When a relink is performed in operation S170, host device 100 can re-identify storage device 400. However, since the pointer information has been changed in operation S160, host device 100 can begin booting and accessing the user data area. Therefore, host device 100 can request to read user data (CMD_READ) or request to write data to the user data area (CMD_WRITE).
[0056] Figure 3 This is a flowchart illustrating the operation of a memory controller according to an exemplary embodiment of the present invention.
[0057] refer to Figure 3In operation S310, the SD controller 220 can detect the connection to the host device 100. The host device 100 can be connected to the storage device 400 via a mutually supported interface. For example, when both the host device 100 and the storage device 400 support USB interfaces, the connection can be established via a USB cable. The storage device 400 can receive power and send and receive data by being connected to the host device 100. In an exemplary embodiment of the present invention, the SD controller 220 can change its state to a locked state each time the physical connection is released, i.e., each time the power is cut off. For example, before the connection to the host device 100 is detected in operation S310, the state of the SD controller 220 may correspond to a previous locked state.
[0058] In operation S320, the SD controller 220 can receive user input from the host device 100 or the user input receiving circuit 270. The user input may be a preset password for unlocking the non-volatile memory 300. In operation S330, the SD controller 220 can perform user authentication by comparing the previously stored password with the received user input. In operation S340, the SD controller 220 can determine whether user authentication was successful based on the comparison result. For example, when the user input does not match the previously stored password, the SD controller 220 can wait until it receives user input again. As another example, when the user input matches the previously stored password, in operation S350, the SD controller 220 can change its state from locked to unlocked.
[0059] The change to the unlocked state can be achieved by altering the pointer information pointing to the regular Master Boot Record (MBR) via the SD controller 220, as will be explained in the following reference. Figure 4A and Figure 4B The following description is provided. During operation S360, the SD controller 220 can perform a relink, enabling the host device 100 to access the user data area based on the changed pointer information.
[0060] Figure 4A and Figure 4B The storage state of a non-volatile memory device according to an example embodiment of the present invention is shown.
[0061] According to an exemplary embodiment of the present invention, reference is made to Figure 4A The diagram illustrates the storage space of the non-volatile memory 300. This storage space is referred to as a memory region. A memory region may include a non-secure region and a secure region.
[0062] The insecure region may include the first MBR and user data. The insecure region is the area where user data is stored and can be referred to using terms such as user volume group, user data area, and private region. The insecure region can be understood as a memory area accessible in a state where the storage device's security is released (e.g., an insecure state).
[0063] The MBR may include information such as the location of partitions, boot code used for booting, etc. The first MBR may be referred to as the operating system (OS) MBR. For example, when the operating system of host device 100 is Windows, the first MBR may be an MBR loader. As another example, when the operating system of host device 100 is Linux, the first MBR may be a Linux loader (LILO) or a large unified boot loader (GRUB). Logical block addressing (LBA) may be a scheme used to specify the location of data blocks in memory regions. For example, the first data block may correspond to LBA 0, and the second data block may correspond to LBA 1. Therefore, it can be understood that the first MBR is stored in the LBA 0 region. For example, LBA 1 may be a region where user data is stored, and LBA 0 may be a region where the first MBR data is stored.
[0064] According to an exemplary embodiment of the present invention, the secure region may include an area where the second MBR and SED support software are stored. The secure region can be understood as a memory region accessible under conditions that maintain the security of the storage device 400 (e.g., a secure state). Similar to the non-secure region, the LBA can be a scheme for specifying the location of data blocks within the secure region of the memory area. For example, in the secure region, LBA 1 may be an area where the SED support software is stored, and LBA 0 may be an area where the second MBR data is stored.
[0065] The second MBR can be referred to by various terms, such as shadow MBR (SMBR) and pseudo MBR. The second MBR can correspond to an MBR that allows the host device 100 to force booting in an area unrelated to user data when an insecure area is inaccessible due to the security of the unreleased storage device 400. According to an exemplary embodiment of the invention, the firmware file can be stored in LBA 1 within the secure area. This is to guide the user in installing software that supports secure release.
[0066] According to an exemplary embodiment of the present invention, the SD controller 220 can activate pointer 1. When pointer 1 is activated, the host device 100 can connect to the storage device 400 and begin booting using the first MBR in the insecure area. When booting begins via the first MBR, the host device 100 can access the area where user data is stored.
[0067] According to an exemplary embodiment of the present invention, the SD controller 220 can activate pointer 2. When pointer 2 is activated, the host device 100 can connect to the storage device 400 and begin booting using the second MBR in the secure area. When booting via the second MBR begins, the host device 100 may not access the area where user data is stored, and the area accessible to the host device 100 may be only the area where SED support software is stored. That is, the activation of pointer 2 can indicate that the state of the SD controller 220 corresponds to a locked state because the power supply to the storage device 400 is blocked.
[0068] In some embodiments, the SD controller 220 can change the pointer information so that the MBR information indicates the Operating State (OS) MBR, thereby changing the SD controller 220 to an unlocked state. The OS MBR can be stored in a non-secure area of the memory region. Alternatively, the SD controller 220 can change the pointer information to a Shadow MBR (SMBR), thereby changing the SD controller 220 to a locked state. The SMBR can be stored in a secure area of the memory region.
[0069] According to an exemplary embodiment of the present invention, Figure 4BThis illustrates a scenario where multiple users utilize storage areas. LBA 1 could be the area storing data for the first user, LBA 2 could be the area storing data for the second user, and LBA 3 could be the area storing data for the third user. When user input is received from the host device 100 or the user input receiving circuit 270, the SD controller can compare the received user input with pre-stored passwords. For example, it can be assumed that the first user has set a first password, the second user has set a second password, and the third user has set a third password. In this case, the SD controller can compare the received user input with all of the first to third passwords. Storage device 400 remains secure when the received user input does not match any of the first to third passwords. When the received user input matches one of the first to third passwords, the starting address of the user data area corresponding to the matching password in the partition information of the first MBR area can be referenced. For example, when the user input matches the second password, the SD controller 220 can identify the starting address of LBA 2 from the partition information in the first MBR. In this case, the host device 100 may be unable to access the first user's LBA 1 area and the third user's LBA 3 area. This is because the host device 100 can only access the address of LBA 1 referenced according to the partition information in the first MBR.
[0070] Figure 5 This is a block diagram of a storage device according to an exemplary embodiment of the present invention.
[0071] The following describes a storage device 400 in which the link controller 210 and the SD controller 220 are implemented separately. However, this embodiment is not limited to this and can also be applied to, for example... Figure 1B The storage device 400 shown integrates the SD controller 220 and the link controller 210.
[0072] refer to Figure 5 The data processing circuit 230 may include an encryptor 231, a decryptor 232, and a data encryption key (DEK) storage circuit 233.
[0073] Encryptor 231 can encrypt write data DATA_W. In an example embodiment of the present invention, when the SD controller 220 is in a locked state, the write command CMD_W, along with write data DATA_W and a specified write address ADDR_W, can be transmitted from the link controller 210 to the encryptor 231. In this case, the SD controller 220 cannot access the insecure area of the non-volatile memory 300, and therefore, data may not be written. In another example embodiment of the present invention, when the SD controller 220 is in an unlocked state, the write command CMD_W can be transmitted. In the unlocked state, the encryptor 231 can access the insecure area, and therefore, the write command CMD_W can be executed. The encryptor 231 may not store the write data DATA_W as is in the specified address ADDR, but can instead encrypt the write data DATA_W. The encryptor 231 can perform encryption by using a DEK value requested and received from the DEK storage circuit 233. After encryption, the encryptor 231 can store the encrypted write data ENCRYPTEDDATA_W in the specified write address ADDR_W.
[0074] Decryptor 232 can decrypt the encrypted read data ENCRYPTED DATA_R. In an example embodiment of the present invention, when the SD controller 220 is in a locked state, the read command CMD_R can be transmitted from the link controller 210 to the decryptor 232 along with the specified read address ADDR_R. In this case, the SD controller 220 cannot access the insecure area of the non-volatile memory 300, and therefore, data may not be readable. In another example embodiment of the present invention, when the SD controller 220 is in an unlocked state, the read command CMD_R can be transmitted to the decryptor 232. In the unlocked state, the decryptor 232 can access the insecure area, and therefore, the read command CMD_R can be executed. The decryptor 232 can read the data stored in the specified read address ADDR_R. The data read can be the encrypted read data ENCRYPTED DATA_R. The decryptor 232 can perform decryption using the DEK value received from the DEK storage circuit 233. After decryption is complete, the decryptor 232 can transmit the decrypted read data DATA_R to the link controller 210, so that the link controller 210 outputs the decrypted read data DATA_R to the host device 100.
[0075] DEK storage circuit 233 can store key values that will be used to encrypt and decrypt data. According to an exemplary embodiment of the present invention, the DEK can correspond to a unique value of storage device 400. For example, the DEK can be generated based on a globally unique identifier (GUID) of storage device 400.
[0076] Although the user input received from the host device 100 or user input receiving circuit 270 has been described in the above embodiments for user authentication, and the DEK value is a unique value for each storage device 400, these embodiments are not limited thereto. According to an exemplary embodiment of the present invention, the DEK value can be further encrypted based on a preset password. In this case, the user input can be used both for verification by the user authentication circuit 240 to determine if the user is an authorized user, and for obtaining the DEK value. By further encrypting the DEK value, it is possible to prevent external intruders (e.g., hackers) from obtaining the DEK value and decrypting user data.
[0077] Figure 6 This is a block diagram of the interface between a host device and a storage device according to an exemplary embodiment of the present invention.
[0078] refer to Figure 6 The SD controller 220 may include a processor 610, RAM 620, host interface 630, memory interface 640, and relink module 650.
[0079] Processor 610 may include a central processing unit or a microprocessor. Processor 610 can control the general operation of SD controller 220. For example, processor 610 may be configured to execute software or firmware for controlling SD controller 220, and said software or firmware may be loaded onto RAM 620. For example, RAM 620 may be configured to access and store data and information, as well as computer program instructions (e.g., software or firmware) executed by processor 610. RAM 620 may be used as operating memory, cache memory, or buffer memory of processor 610. Write data to be written to the storage device may be temporarily stored in RAM 620, and read data read from the storage device may also be temporarily stored in RAM 620.
[0080] The host interface 630 interfaces with the host device 100 and receives requests for memory operations from the host device 100. Furthermore, the memory interface 640 provides an interface between the SD controller 220 and the memory device (not shown). For example, write and read data can be sent to and received from the memory device via the memory interface 640. Additionally, the memory interface 640 can provide commands and addresses to the memory device, and furthermore, it can receive various information from the memory device and provide the received information to the internal systems of the SD controller 220.
[0081] According to an exemplary embodiment of the present invention, the relinking module 650 can perform various operations related to relinking according to the above exemplary embodiments based on a software solution. The relinking module 650 may include a data processing module 651, a user authentication module 652, and a relinking triggering module 653. When performing operations according to the exemplary embodiment of the present invention based on a software solution, each of the data processing module 651, the user authentication module 652, and the relinking triggering module 653 may include a program executable by the processor 610, and the program may be loaded onto RAM 620 and executed by the processor 610.
[0082] Figure 7 This is a flowchart illustrating the operation of a host device according to an exemplary embodiment of the present invention.
[0083] refer to Figure 7 During S710 operation, host device 100 can detect the connection to storage device 400. (See reference...) Figure 2 Operation S130 and Figure 3 Operation S710 will be described in accordance with the description of operation S310. In operation S720, the host device 100 can identify that the storage device 400 supports the SED function. For example, the host device 100 can receive configuration information of the storage device 400 and check whether the storage device 400 supports the SED function based on an identifier indicating whether the SED function is supported.
[0084] According to an exemplary embodiment of the present invention, when the storage device 400 supports the SED function, communication can be performed based on the Trusted Computing Group (TCG) protocol. The TCG protocol is a communication standard that supports the SED function and relates to methods for partitioning user areas in the storage device 400 and methods for changing lock and unlock states in the storage device 400. For example, when the storage device 400 supports the SED function, a shadow MBR (SMBR) can be generated based on the TCG protocol.
[0085] In operation S730, the host device 100 can install software supporting the SED function. According to an exemplary embodiment of the present invention, although the host device 100 has recognized that the storage device 400 supports the SED function, when the SED function is disabled in the storage device 400, the host device 100 can display a pop-up window to present the software installation, or allow the automatic execution of the software installation file. The execution of the installation file and / or the installation of the software can be performed by the processor 610. In operation S740, the host device 100 can configure a user password using software supporting the SED function. When the software is executed, input of a password for activating the SED function can be requested, and in operation S750, the host device 100 can transmit the input password to the storage device 400. The transmitted password can be stored in the user authentication circuit 240. The user authentication circuit 240 can control the locking state of the SD controller 220 by comparing the user's input password with the stored password each time the storage device 400 is inserted into the host device 100.
[0086] Figure 8 This is a block diagram of a non-volatile memory system according to an exemplary embodiment of the present invention. (Reference) Figure 1A and 1B The descriptions provided here need not be repeated.
[0087] Although not in Figure 8 As shown, however, the SD controller 220 may include data processing circuitry 230, user authentication circuitry 240, relink trigger circuitry 250, and user input receiving circuitry 270, as combined with... Figure 1A and Figure 1B As described above. According to an exemplary embodiment of the present invention, Figure 8 The SD controller 220 may not include Figure 1A Link controller 210 or Figure 1B The connection management circuit 260.
[0088] refer to Figure 8 The host device 100 can send a monitoring signal CMD_MONITOR to identify the status of the SD controller 220. Figure 8The SD controller 220 can rely on commands received from an external source (e.g., host device 100). Host device 100 can periodically send a monitoring signal CMD_MONITOR to the SD controller 220. For example, when the state of the SD controller 220 changes from a locked state to an unlocked state, access to the user data area can be performed based on pointer 1 indicating a change to relink. However, since the SD controller 220 and the non-volatile memory 300 are passive devices, it is necessary to periodically check whether the state of the SD controller 220 has changed. Passive devices can be designated as devices that can only send a response when a command is received, i.e., devices that cannot independently send signals first.
[0089] The SD controller 220 may send a response signal RSP_MONITOR to the host device 100 in response to a monitoring signal CMD_MONITOR that is periodically received by the SD controller 220. The response signal RSP_MONITOR may indicate, for example, whether the SD controller 220 is in an unlocked or locked state. Since the host device 100 does not know when the SD controller 220 is in an unlocked state, the host device 100 may continuously and periodically send the monitoring signal CMD_MONITOR to the SD controller 220 until the SD controller 220 sends the response signal RSP_MONITOR indicating an unlocked state. The periodic sending and receiving of the monitoring signal CMD_MONITOR and the response signal RSP_MONITOR can act as a load on the host device 100 and the SD controller 220, respectively, thereby reducing the performance of the overall memory system.
[0090] According to an exemplary embodiment of the present invention, host device 100 may send a signal CMD_RELINK to SD controller 220 to request a relink. For example, when host device 100 is periodically performing monitoring, it may receive a response signal RSP_MONITOR indicating an unlocked state. Host device 100 may access the user data area only when performing a relink, based on the changed pointer. Therefore, host device 100 may send the signal CMD_RELINK to SD controller 220 to request a relink. Access to non-volatile memory 300 may be delayed each time host device 100 sends the signal CMD_RELINK. This is because, even when SD controller 220 changes to an unlocked state, it is still identified as locked until host device 100 sends the monitoring signal CMD_MONITOR in the next cycle and SD controller 220 sends the response signal RSP_MONITOR in response to the monitoring signal CMD_MONITOR. Additionally, since the host device 100 retransmits the signal CMD_RELINK after receiving the response signal RSP_MONITOR, there may be an additional delay in the time spent transmitting the signal CMD_RELINK.
[0091] Figure 9 This is a signaling diagram of a non-volatile memory system according to an exemplary embodiment of the present invention. (Reference) Figure 2 The descriptions provided here need not be repeated.
[0092] refer to Figure 9 The host device 100 can send a monitoring signal CMD_MONITOR at regular periodic intervals to check whether the SD controller 220 is in a locked state. In response to receiving the monitoring signal CMD_MONITOR at regular periodic intervals, the SD controller 220 sends a response signal RSP_MONITOR indicating the status of the SD controller 220.
[0093] Additionally, referring to operation S910, user input for unlocking the non-volatile memory 300 can be input solely through the host device 100. This is because, in some embodiments, with Figure 1A and Figure 1B Unlike other devices, the SD controller 220 may not include a separate user input receiving circuit 270. Therefore, receiving user input can rely on the host device 100.
[0094] Furthermore, although the SD controller 220 is changed to an unlocked state in operation S160, the host device 100 can still recognize the SD controller 220 as being in a locked state. Subsequently, when the host device 100 receives a response signal RSP_MONITOR(UNLOCK) in response to the periodically transmitted monitoring signal CMD_MONITOR, it can recognize the state change of the SD controller 220. For example, the host device 100 cannot recognize the SD controller 220 as being in an unlocked state until it has received the response signal RSP_MONITOR(UNLOCK) indicating that the SD controller 220 is in an unlocked state. Therefore, there may be a delay between when the SD controller 220 is actually unlocked and when the host device 100 recognizes it as unlocked.
[0095] Additionally, the host device 100 can send a command to request a relink to identify the user data area. The relink can be delayed by the time spent sending the CMD_RELINK signal and the time spent by the SD controller 220 receiving the CMD_RELINK signal and initiating the relink.
[0096] When referring to exemplary embodiments of the present invention Figure 8 and Figure 9 Descriptions and references Figure 1A and Figure 2 The effects of the inventive concept can be clearly understood from the description provided.
[0097] Figure 10 This is a block diagram illustrating an example of applying a storage device according to an exemplary embodiment of the present invention to an SSD system.
[0098] refer to Figure 10 The SSD system 1000 may include a host device 100 and an SSD 1100. The SSD 1100 sends signals to and receives signals from the host device 100 via a signal connector and receives power via a power connector. The SSD 1100 may include an SSD controller 1110, multiple memory devices 1120 to 1140, and a link controller 1150. Here, it can be achieved by using... Figures 1A to 9The illustrated embodiment implements the SSD controller 1110 and the link controller 1150. For example, the SSD controller 1110 (also referred to as the memory controller) and the link controller 1150 may correspond to the SD controller 220 and the link controller 210, respectively. Therefore, the SSD 1100 can perform relinking independently, without relying on commands from the host device 100, even without receiving commands from the host device 100. Furthermore, the SSD 1100 can perform relinking independently without receiving monitoring commands from the host device 100 and without sending response signals in response to monitoring commands, thus reducing the load on the storage system. Additionally, because the SSD 1100 does not receive monitoring commands or commands instructing relinking from the host device 100, it can perform relinking independently even if the host device 100 does not support monitoring commands or commands instructing relinking. Therefore, dependence on the host device 100 or its operating system can be reduced, and the SSD 1100 can be used with various types of host devices. For example, host device 100 can be configured to avoid sending monitoring commands to identify the state of SSD controller 1110 and commands instructing relinking in response to a change in the state of SSD controller 1110 to unlocked state. Furthermore, when the SSD 1100 is released from its locked state, it independently performs relinking; therefore, relinking can be performed quickly without the time delay required for sending and receiving monitoring commands or commands instructing relinking.
[0099] The storage device according to embodiments of the present invention can be installed or applied not only to SSD 1100, but also to memory card systems, computing systems, universal flash memory (UFS), etc. Furthermore, the operation method of the storage device according to embodiments of the present invention can be applied to various types of electronic systems in which non-volatile memory is embedded.
[0100] As is conventional in the disclosed art, features and embodiments are described and illustrated in the accompanying drawings in terms of functional blocks, units, and / or modules. Those skilled in the art will understand that these blocks, units, and / or modules are physically implemented by electronic (or optical) circuitry such as logic circuits, discrete components, microprocessors, hardwired circuits, memory elements, wiring connections, etc., which can be formed using semiconductor-based manufacturing techniques or other manufacturing techniques. Where blocks, units, and / or modules are implemented by microprocessors or the like, they can be programmed using software (e.g., microcode) to perform the various functions discussed herein, and may optionally be driven by firmware and / or software. Alternatively, each block, unit, and / or module may be implemented by dedicated hardware, or by a combination of dedicated hardware for performing some functions and processors (e.g., one or more programmed microprocessors and associated circuitry) for performing other functions. Furthermore, without departing from the scope of the inventive concept, each block, unit, and / or module of the embodiments may be physically divided into two or more interacting and discrete blocks, units, and / or modules. Furthermore, without departing from the scope of the inventive concept, the blocks, units, and / or modules of the embodiments can be physically combined into more complex blocks, units, and / or modules.
[0101] Although the inventive concept has been specifically shown and described with reference to embodiments thereof, it should be understood that various changes in form and detail may be made without departing from the spirit and scope of the appended claims.
Claims
1. A non-volatile memory system, comprising: A host device and a storage device connected to the host device via a physical cable including a power cord and a data cable, the storage device comprising: Non-volatile memory; A link controller configured to temporarily disable the data line while receiving power from the host device via the power line; and The memory controller includes: A user authentication circuit is configured to authenticate the user of the storage device and change the state of the memory controller based on the authentication result; A relink trigger circuit, configured to control the link controller based on a state change of the memory controller; and The data processing circuitry is configured to encrypt and decrypt data. The host device is configured to: avoid sending monitoring commands for identifying the state of the memory controller in the storage device and commands instructing relinking in response to a change in the state of the memory controller to an unlocked state.
2. The non-volatile memory system according to claim 1, wherein The state of the memory controller corresponds to a locked state or an unlocked state, and The non-volatile memory includes a first region accessible to the host device in the unlocked state and a second region accessible to the host device in the locked state.
3. The non-volatile memory system according to claim 2, wherein The storage device further includes: a user input receiving circuit configured to receive user input for unlocking the memory controller, and The memory controller is configured to: change its state to the locked state in response to a power outage of the storage device; and complete user authentication and change the state of the memory controller from the locked state to the unlocked state when a value received from the host device or the user input receiving circuit matches a value pre-stored in the user authentication circuit.
4. The non-volatile memory system according to claim 2, wherein The memory controller is further configured to: change the state of the memory controller to the locked state by changing pointer information so that the master boot record information indicates a second master boot record included in the second region; and change the state of the memory controller to the unlocked state by changing the pointer information so that the master boot record information indicates a first master boot record included in the first region. Wherein, the first master boot record corresponds to the operating system master boot record, and The second master boot record corresponds to the shadow master boot record.
5. The non-volatile memory system according to claim 2, wherein The first area also includes multiple sub-areas corresponding to multiple users, and Among these, the multiple users can only access the corresponding sub-regions in which user verification has been completed.
6. The non-volatile memory system according to claim 1, wherein, The physical cable includes a cable for a hot-pluggable interface, and The interface includes at least one of a Universal Serial Bus interface, a Serial Advanced Technology Attachment interface, a Parallel Advanced Technology Attachment interface, a Small Computer System interface, and a Serial Attached Small Computer System interface.
7. The non-volatile memory system according to claim 1, wherein, The user authentication circuit is further configured to: send a control signal to the reconnection trigger circuit when user authentication is successful, and The reconnection trigger circuit is further configured to send a reconnection trigger signal to the link controller in response to receiving the control signal.
8. The non-volatile memory system according to claim 7, wherein The link controller is also configured to: receive the reconnection trigger signal before receiving a command instructing reconnection from the host device, and in response to receiving the reconnection trigger signal, temporarily disable the data line while the power line is activated.
9. The nonvolatile memory system of claim 1, wherein, The link controller and the memory controller are on the same semiconductor substrate.
10. A storage device, comprising: Non-volatile memory; User input receiving circuit; A link controller is configured to disable the data line through which the storage device is physically connected to the host device; as well as A memory controller is configured to: perform user authentication by comparing a pre-stored user input value with a user input value received from the host device or the user input receiving circuitry; change the state of the memory controller based on the user authentication result; and send a trigger signal indicating temporary disabling of the data line to the link controller based on the change in the state of the memory controller. The storage device is configured to avoid receiving monitoring commands from the host device for identifying the state of the memory controller and commands instructing the data line to be deactivated in response to a change in the state of the memory controller to an unlocked state.
11. The memory device of claim 10, wherein, The link controller is also configured to: receive the trigger signal from the memory controller before receiving a command from the host device instructing the temporary deactivation of the data line, and to temporarily deactivate the data line based on the trigger signal while receiving power from the host device.
12. The storage device according to claim 10, wherein, The link controller and the memory controller are on the same semiconductor substrate.
13. The storage device according to claim 10, wherein, The memory controller is also configured to: change the state of the memory controller from a locked state to an unlocked state when the user verification result indicates that the compared values match, and send the trigger signal to the link controller.
14. The storage device according to claim 13, wherein, The memory controller is further configured to change its state to the unlocked state by altering pointer information to indicate a first master boot record included in the first region.
15. The storage device according to claim 10, wherein, The memory controller is also configured to: recognize that the physical connection to the host device has been released, and to change the state of the memory controller to a locked state in response to recognizing that the physical connection to the host device has been released.
16. The storage device according to claim 10, in, The physical connection is generated based on a hot-swappable interface, and The interface includes at least one of a Universal Serial Bus interface, a Serial Advanced Technology Attachment interface, a Parallel Advanced Technology Attachment interface, a Small Computer System interface, and a Serial Attached Small Computer System interface.
17. A method of operating a storage device, the storage device comprising non-volatile memory, a link controller, and a memory controller, the method comprising: Detect the physical connection between the storage device and the host device; Receive user input from the user input receiving circuit in the host device or the storage device; Perform user authentication based on the received user input; When the user successfully authenticates, the state of the memory controller is changed to the unlocked state; as well as In response to the change to the unlocked state, a reconnection to the host device is performed. The host device is configured to: avoid sending monitoring commands for identifying the state of the memory controller in the storage device and commands instructing relinking in response to a change in the state of the memory controller to an unlocked state.
18. The operating method according to claim 17, wherein, The relinking to the host device includes temporarily disabling the data cable connected to the host device while receiving power from the host device.
Citation Information
Patent Citations
Controller for partition-level security and backup
US20040088513A1
Operation method of memory controller and nonvolatile memory system including the memory controller
US20160048459A1
Self-encrypting module with embedded wireless user authentication
US20190007203A1
Universal serial bus device controller comprising a FIFO associated with a plurality of endpoints and a memory for storing an identifier of a current endpoint
US5974486A
Method for reading data in a write-once memory device using a write-many file system
US7062602B1