Storage devices, including non-volatile memory systems therein, and methods of operation thereof

CN112905504BActive Publication Date: 2026-09-01SAMSUNG ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202011297633.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-03
Filing Date
2020-11-18
Publication Date
2026-09-01
Estimated Expiration
2040-11-18

AI Technical Summary

Technical Problem

[0007]然而,支持SED的存储设备是被动设备,并且可以根据来自主机设备的命令进行操作,因此,当主机设备不支持SED时,存储设备将无法独立进行操作

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112905504B_ABST
    Figure CN112905504B_ABST
Patent Text Reader

Abstract

The storage device is configured to connect to a host device via a physical cable, which includes power lines and data lines. The storage device includes non-volatile memory, a data path controller, and a memory controller. The data path controller is configured to temporarily deactivate the data lines when powered from the host device via the power lines. The memory controller includes: a biometric module configured to receive biometric data and perform user authentication based on the biometric data; biometric processing circuitry configured to change the state of the memory controller based on the result of user authentication; and data processing circuitry configured to encrypt and decrypt data. The data path controller is configured to temporarily deactivate the data lines in response to a change in the state of the memory controller.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference of related applications

[0002] This application claims priority to Korean Patent Application No. 10-2019-0159365, filed on December 3, 2019, with the Korean Intellectual Property Office, the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] The present invention relates to semiconductor memories, and more specifically, to memory devices including memory controllers, non-volatile memory systems including the memory devices, and methods of operating the same. Background Technology

[0004] Semiconductor memory devices can be classified into volatile memory devices and non-volatile memory devices. Data stored in volatile memory devices is lost when power is cut off, while data stored in non-volatile memory devices is not lost when power is cut off. Volatile memory devices have high read and write speeds, but the data stored in them is lost when the external power is disconnected. Conversely, non-volatile memory devices have lower read and write speeds than volatile memory devices, but the data stored in them is retained even when the external power is disconnected.

[0005] Flash memory, as a type of non-volatile memory device, has been used in various fields due to its advantages (e.g., high operating speed, low power consumption, low noise, and high capacity achieved through stacked cells). With the increasing prevalence of flash memory, the demand for its security technologies is growing.

[0006] Self-Encrypting Drivers (SEDs) used in security technologies for flash memory can provide high security by writing data in encrypted format and decrypting and reading encrypted data.

[0007] However, storage devices that support SED are passive devices and can only operate based on commands from the host device. Therefore, when the host device does not support SED, the storage device cannot operate independently. Consequently, the demand for storage devices capable of operating on various types of host devices is constantly growing. Summary of the Invention

[0008] A storage device capable of relinking independently of a host device, a non-volatile memory system including the storage device, and a method of operating the non-volatile memory system are provided.

[0009] According to one aspect of the present invention, a non-volatile memory system includes a storage device configured to be connected to a host device via a physical cable, the physical cable including a power line and a data line. The storage device includes non-volatile memory, a link controller, and a memory controller, the link controller being configured to temporarily deactivate the data line when powered from the host device via the power line. The memory controller includes: a biometric module configured to receive biometric data and perform user authentication based on the biometric data; a biometric processing circuit configured to change the state of the memory controller based on the result of user authentication; a relink trigger circuit configured to control the link controller based on the change in the state of the memory controller; and a data processing circuit configured to encrypt and decrypt the data.

[0010] According to some embodiments, the storage device is configured to be connected to a host device via a physical cable, the physical cable including power lines and data lines. The storage device includes non-volatile memory, a data path controller, and a memory controller. The data path controller is configured to temporarily deactivate the data lines when powered from the host device via the power lines. The memory controller includes: a biometric module configured to receive biometric data and perform user authentication based on the biometric data; biometric processing circuitry configured to change the state of the memory controller based on the result of user authentication; and data processing circuitry configured to encrypt and decrypt data. The data path controller is configured to temporarily deactivate the data lines in response to a change in the state of the memory controller.

[0011] According to some embodiments, in a non-volatile memory system including a storage device configured to be connected to a host device via a physical cable including power lines and data lines, wherein the storage device includes non-volatile memory, a method includes receiving biometric data and performing user authentication based on the biometric data. Based on the result of the user authentication, the state of a memory controller is changed; and in response to the changed state, the data lines are temporarily deactivated when power is supplied from the host device via the power lines. Attached Figure Description

[0012] Embodiments of the inventive concept will become clearer from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0013] Figures 1A to 1D This is a block diagram of a non-volatile memory system according to an embodiment of the present invention.

[0014] Figure 2 The present invention illustrates the switching of signals in a non-volatile memory system according to an embodiment of the present invention.

[0015] Figure 3This is a flowchart illustrating the operation of a memory controller according to an embodiment of the present invention;

[0016] Figure 4A The data storage state of a non-volatile memory device according to an embodiment of the present invention is shown;

[0017] Figure 4B Another data storage state of a non-volatile memory device according to an embodiment of the present invention is shown;

[0018] Figure 5 This is a block diagram of a storage device according to an embodiment of the present invention.

[0019] Figure 6 An interface between a host device and a storage device according to an embodiment of the present invention is shown;

[0020] Figure 7 This is a flowchart illustrating the operation of a host device according to an embodiment of the concept of the present invention;

[0021] Figure 8 This is a block diagram of a non-volatile memory system;

[0022] Figure 9 The switching of signals in a non-volatile memory system is illustrated;

[0023] Figure 10 This is a block diagram illustrating an example of applying a memory device to a solid-state drive (SSD) system according to an embodiment of the present invention; and

[0024] Figure 11 This is a block diagram of a non-volatile memory system according to an embodiment of the present invention. Detailed Implementation

[0025] In the following, various embodiments of the inventive concept will be described in detail with reference to the accompanying drawings.

[0026] Figures 1A to 1D This is a block diagram of a non-volatile memory system according to an embodiment of the present invention.

[0027] refer to Figure 1A A non-volatile memory system 10 is provided. The non-volatile memory system 10 may include a host device 100 and a storage device 500.

[0028] Storage device 500 may include a link controller 210, a storage device (SD) controller 220, a non-volatile memory 300, and a biometric module 400.

[0029] Host device 100 may be embodied as, for example, an electronic device such as a personal computer (PC), laptop computer, mobile phone, smartphone, tablet PC, personal digital assistant (PDA), enterprise digital assistant (EDA), digital camera, digital camcorder, audio equipment, portable multimedia player (PMP), personal navigation device (PND), MP3 player, handheld game console, or e-reader. Alternatively, host device 100 may be embodied as, for example, an electronic device such as a wearable device, such as a watch or head-mounted display (HMD).

[0030] According to various embodiments, host device 100 may include interface 150 for sending and receiving commands (CMD) and / or data (DATA) with storage device 500. Interface 150 may include at least one hot-pluggable interface. For example, interface 150 may include interface protocols such as Peripheral Component Rapid Interconnect (PCI-E), Advanced Technology Attachment (ATA), Serial ATA (SATA), Parallel ATA (PATA), or Serial Attached SCSI (SAS). Furthermore, various interface protocols such as Universal Serial Bus (USB), Multimedia Card (MMC), Enhanced Small Disk Interface (ESDI), Integrated Drive Electronics (IDE), and Thunderbolt interfaces are applicable.

[0031] According to various embodiments, storage device 500 can store and output data. Storage device 500 can be internal memory embedded in an electronic device. For example, storage device 500 can be an embedded universal flash memory (UFS) device, an embedded multimedia card (eMMC), or a solid-state drive (SSD). Storage device 500 can be formed on a substrate formed within host device 100. In some embodiments, storage device 500 can be external memory removably mounted in an electronic device. For example, storage device 500 can include at least one of a UFS memory card, a compact flash (CF) card, a secure digital card (SD) card, a micro SD card, a miniature SD card, an ultra-fast digital (XD) card, and a memory stick.

[0032] According to various embodiments, LINK controller 210 can control the connection between storage device 500 and host device 100. When LINK controller 210 is embodied as a separate component distinct from SD controller 220 (e.g., when it is not on the same chip or semiconductor package as SD controller 220), LINK controller 210 can be referred to as a bridge board. LINK controller 210 can also be referred to as an interface device or interface circuit, or as a data path controller. Furthermore, SD controller 220 and LINK controller 210 together can be simply described as a "controller" or "memory controller," regardless of whether they are part of a single semiconductor chip or device or separate semiconductor chips or devices. Control of the connection between storage device 500 and host device 100 can refer to activating or deactivating the data path used for data transmission and reception during power supply via power lines. For example, LINK controller 210 can deactivate pins connecting the data path while maintaining connection to host device 100 via a USB cable. For example, when receiving power from host device 100, if the pin corresponding to the data path is deactivated or disabled, host device 100 can still recognize the deactivated pin even though it is physically connected to storage device 500 via USB cable. Subsequently, when the pin corresponding to the data path is reactivated by LINK controller 210, host device 100 can recognize storage device 500 again. LINK controller 210 includes a switch (not shown) in the data path, and the connection between storage device 500 and host device 100 can be controlled by controlling this switch. As another example, LINK controller 210 may also include a microcontroller (not shown). LINK controller 210 can temporarily deactivate the data path by resetting or activating the microcontroller when it is powered on. Therefore, relinking can be performed between host device 100 and storage device 500 even when there is no actual unplugging or physical disconnection between host device 100 and storage device 500.

[0033] According to various embodiments, the SD controller 220 may include a data processing circuit 230, a biometric processing circuit 240, and a relink trigger circuit 250.

[0034] The data processing circuit 230 can provide various signals to the non-volatile memory 300 and control operations such as writing and reading. For example, the SD controller 220 can provide the non-volatile memory 300 with commands CMD and addresses ADDR to access data stored in the memory cell array.

[0035] As another example, the data processing circuit 230 can encrypt data and store the encrypted data in the memory cell array, or decrypt the encrypted data stored in the memory cell array and output the decrypted data as read data. Because encryption and decryption are performed during the storage and output of data, data leakage can be prevented even if the storage device 500 is stolen or lost.

[0036] The biometric processing circuit 240 can change the state of the SD controller 220 based on the biometric verification result. The biometric processing circuit 240 can receive user verification data from the biometric module 400. The user verification data indicates whether the biometric verification performed by the biometric module 400 was successful or failed. When the biometric verification is successful, the biometric processing circuit 240 can change the state of the SD controller 220 to the unlocked state and send a control signal to the relink trigger circuit 250. This control signal can correspond to the signal used to control the relink trigger circuit 250 to send a trigger signal to the LINK controller 210.

[0037] The relink trigger circuit 250 can send a trigger signal to the LINK controller 210. The trigger signal can be a signal that controls the LINK controller 210 to perform a relink. The relink trigger circuit 250 can send the trigger signal to the LINK controller 210 in response to a control signal received from the biometric processing circuit 240. For example, in response to the trigger signal, the LINK controller 210 can deactivate a pin corresponding to the data path, deactivate a switch in the data path, or initialize the microcontroller included in the LINK controller 210.

[0038] According to various embodiments, the relink trigger circuit 250 can send a trigger signal to the LINK controller 210 based at least on the state of the SD controller 220. For example, when the SD controller 220 changes from a locked state to an unlocked state, the relink trigger circuit 250 can send a trigger signal to the LINK controller 210.

[0039] According to various embodiments, the biometric module 400 can compare the input biometric data with previously stored biometric data. Here, biometric data can refer to data used to identify or verify a person based on their physical characteristics. For example, biometric data can include various types of data, such as fingerprint data, iris data, vein data, voice data, facial feature data, and retinal data.

[0040] The biometric module 400 can determine whether the user of the storage device 500 is a genuine user based on biometric data. For example, when the storage device 500 is encrypted, the user of the storage device 500 must pass user authentication to access the user data area. Therefore, the user of the storage device 500 can input biometric data through the biometric module 400 integrated in the storage device 500. The biometric module 400 can compare the input biometric data with previously stored biometric data. The biometric module 400 can send user verification data indicating the comparison result to the biometric processing circuit 240. When the comparison result indicates a mismatch, the biometric processing circuit 240 maintains the storage device 500 in a locked state, thereby protecting the user data. When the comparison result indicates a match, the biometric processing circuit 240 changes the state of the storage device 500 to an unlocked state, thereby making the user data accessible.

[0041] In one embodiment, the biometric module 400 may be embodied as a fingerprint recognition module. A fingerprint recognition module can be a module that identifies a user by acquiring a digital image of the fingerprints distributed on the user's finger. For example, a fingerprint recognition module may be optical, capacitive, or ultrasonic.

[0042] In another embodiment, the biometric module 400 may be embodied as a vein recognition module. The vein recognition module may also include an infrared sensor. The vein recognition module may be a module that emits infrared light into a blood vessel and identifies an individual based on a residual image. For example, the vein recognition module may identify an individual based on vein images of at least one of the user's hands, either the back or palm of the hand or one of the user's fingers.

[0043] In another embodiment, the biometric module 400 may be embodied as an iris recognition module. The iris recognition module may be a module used to identify an individual based on the shape of the user's iris.

[0044] Although the above embodiments describe the biometric module 400 as being based on fingerprints, veins, or irises, the biometric module 400 is not limited to these. For example, a user can be identified based on various biometric data (e.g., the user's gait, face, and voice).

[0045] According to various embodiments, the biometric module 400 can send user verification data indicating a comparison result to the biometric processing circuit 240. When user authentication is successful, the user verification data can be, for example, "1" or a high logic value, while when user authentication fails, the user verification data can be, for example, "0" or a low logic value. The biometric processing circuit 240 can receive user verification data from the biometric module 400, and when the user verification data is "1", it changes the SD controller 220 from a locked state to an unlocked state. Reference will be made below. Figure 4A and Figure 4B The description states that the SD controller 220 can be changed to an unlocked state by the biometric module 400 changing the pointer information to the normal Master Boot Record (MBR).

[0046] According to various embodiments, the trigger signal can be sent via a different path than the path used to send the command CMD and data DATA to the data processing circuit 230. The trigger signal can be sent via a communication method independent of command reception. For example, the communication method could correspond to general purpose input / output (GPIO) communication 150.

[0047] refer to Figure 1B In response to successful user authentication, the biometric module 400 can send user authentication data to the LINK controller 210 and the biometric processing circuitry 240. According to various embodiments, the LINK controller 210 can be configured to perform a reconnection upon receiving user authentication data directly from the biometric module 400.

[0048] However, since the exact timing of when the biometric processing circuit 240 receives user authentication data and changes the state of the SD controller 220 to the unlocked state may not be known precisely, user authentication data can be sent to the biometric processing circuit 240 first, and then sent to the LINK controller 210 after a certain time interval. By sending user authentication data at time intervals, the host device 100 can be prevented from reconnecting to the SD controller 220 before unlocking it. According to various embodiments, when the biometric module 400 sends user authentication data directly to the LINK controller 210, the reconnection trigger circuit 250 can be omitted.

[0049] refer to Figure 1C The SD controller 220 may also include connection management circuitry 270. Figure 1A and Figure 1B In this case, LINK controller 210 and SD controller 220 are described as separate controllers distinguishable from each other, but are not limited thereto. According to various embodiments, LINK controller 210 may be integrated into SD controller 220 (e.g., as part of the same chip or semiconductor package). Connection management circuitry 270 may be circuitry for controlling connections to host device 100. Connection management circuitry 270 may perform operations related to… Figure 1A and Figure 1BThe operation is the same as or similar to that of the LINK controller 210. For example, the connection management circuit 270 can activate or disable a pin of the SD controller 220 corresponding to the data path, activate a switch set in the data path, or reset or initialize the SD controller 220. Using the connection management circuit 270, the host device 100 can perform relinking to the storage device 500 while maintaining a physical connection with the storage device 500. (See reference...) Figure 1C The biometric processing circuit 240 can receive user authentication data from the biometric module 400 and send a control signal to the connection management circuit 270 when the user authentication is successful. The control signal may refer to a signal used to control the connection management circuit 270 to activate a pin corresponding to the data path among a plurality of pins of the SD controller 220, deactivate a switch set in the data path, or reset the SD controller 220.

[0050] refer to Figure 1D The biometric module 400 can send user authentication data to both the biometric processing circuit 240 and the connection management circuit 270. For example, the biometric processing circuit 240 can change the state of the SD controller 220 to an unlocked state in response to the user authentication data, and the connection management circuit 270 can perform a reconnection to the host device 100 in response to the user authentication data. (See above reference...) Figure 1D As described above, when the biometric module 400 simultaneously sends user verification data to both the biometric processing circuit 240 and the connection management circuit 270, a reconnection can be performed before the SD controller 220 is changed to the unlocked state. Therefore, the biometric module 400 can first send user verification data to the biometric processing circuit 240 at regular time intervals, and then send user verification data to the connection management circuit 270 after a certain time interval.

[0051] Figure 2 The present invention illustrates the exchange of signals in a non-volatile memory system according to an embodiment of the present invention.

[0052] refer to Figure 2 In operation S110, user configuration can be set between host device 100 and storage device 500. For example, for data encryption, a user of storage device 500 can set new user biometric data or change previously set user biometric data in storage device 500. According to various embodiments, user configuration can be performed by software that supports the self-encrypting drive (SED) function of storage device 500. Reference will be made below. Figure 7 Describe operation S110 in detail.

[0053] In operation S120, the SD controller 220 can change its state to a locked state. After user configuration is completed in operation S110, the user of storage device 500 can disconnect storage device 500 from host device 100. The SD controller 220 can change its state to a locked state in response to power cutoff for user data security. For example, when the user cancels the physical connection with host device 100, the power supply from host device 100 can be cut off. When the power supply from host device 100 is cut off, the SD controller 220 can change its state to a locked state. For example, the SD controller 220 can deactivate access to the user data area by changing the pointer information of the SD controller 220.

[0054] In operation S130, the host device 100 and the storage device 500 can be physically connected. For example, when both the host device 100 and the storage device 500 support USB interfaces, a physical connection can be established via a USB cable. When the host device 100 is connected to the storage device 500, the host device 100 can operate the storage device 500 by supplying power to it via a power line. For example, in the case of a USB Type-C interface, power can be supplied from the host device 100 to the storage device 500 via the VBUS pin.

[0055] In operation S140, the biometric module 400 can perform user authentication. The biometric data obtained in operation S110 can be compared with the biometric data input by the user, and the comparison result can be output. For example, when a comparison between a previously stored fingerprint image and the input fingerprint image shows they are identical, successful user authentication can be identified, and user verification data can be sent to the biometric processing circuit 240 of the SD controller 220.

[0056] In operation S150, the SD controller 220 can be switched to an unlocked state. The biometric processing circuit 240 can receive user authentication data, such as a "1" or a high logic value, from the biometric module 400 and modify the pointer information for the non-volatile memory 300 to activate access to the user data area. References will follow below. Figure 4A and Figure 4B Describe its description.

[0057] In operation S160, a relink can be performed between the host device 100 and the storage device 500. As mentioned above, a relink does not mean re-establishing a physical connection after it has been cancelled. That is, a relink can mean temporarily deactivating the data path while continuously powered in the plugged-in state, rather than performing a plug-in and unplugging operation.

[0058] In one embodiment, when the storage device 500 includes Figure 1A When the LINK controller 210 is activated, the relink trigger circuit 250 of the SD controller 220 can send a trigger signal to the LINK controller 210. In response to the trigger signal, the LINK controller 210 can perform a relink by temporarily disabling a pin corresponding to the data path, temporarily deactivating a switch set in the data path, or initializing a microprocessor (not shown). From the host's perspective, this appears to disconnect the storage device 500 (communication is disconnected), requiring the host to re-establish communication with the storage device 500. This re-establishment of communication is performed based on pointer-based updated settings.

[0059] In another embodiment, when the storage device 500 is embodied as including, Figure 1D When an SD controller 220 is shown, relinking can be performed by controlling the connection management circuit 270. For example, when receiving control signals from the biometric processing circuit 240 or user authentication data directly from the biometric module 400, the connection management circuit 270 can perform relinking by temporarily disabling pins corresponding to the data path or temporarily deactivating switches set in the data path.

[0060] In operation S170, host device 100 can write and / or read data. Because a relink was performed in operation S160, host device 100 can recognize storage device 500 again after a pin or switch has been reactivated or enabled, or SD controller 220 has been reset or reinitialized. However, the pointer information has been changed in operation S150, so host device 100 can begin booting and accessing the user data area. Therefore, host device 100 can request to read user data (CMD_READ) or write user data to the user data area (CMD_WRITE). The above-described pointer-changing and relinking process can occur without any commands from the host (e.g., periodic commands to check the lock / unlock status of storage device 500).

[0061] Figure 3 This is a flowchart illustrating the operation of a memory controller according to an embodiment of the present invention.

[0062] refer to Figure 3The SD controller 220 can detect the connection to the host device 100 (operation S310). The host device 100 and the storage device 500 can be connected based on a common supported interface. For example, when both the host device 100 and the storage device 500 support USB interfaces, they can be connected via a USB cable. The storage device 500 can connect to the host device 100 to receive power and send and receive data. According to various embodiments, when the SD controller 220 and the host device 100 are connected, the SD controller 220 can be in a locked state. Before connection is established, the power supply can be cut off when the connection between the SD controller 220 and the host device 100 is canceled. Whenever the power supply is cut off, the SD controller 220 can change its state to a locked state.

[0063] The biometric module 400 can perform user authentication (operation S320). A user wishing to unlock the storage device 500 can input biometric data through the biometric module 400 within the storage device 500. For example, when the biometric module 400 is embodied as a fingerprint recognition module, the user can input biometric data representing their fingerprint shape by touching the fingerprint recognition module with their finger. The biometric module 400 can identify whether the input biometric data matches biometric data previously stored through the user registration process (operation S330). For example, when the biometric module is embodied as a fingerprint recognition module, the biometric module 400 can identify whether the input fingerprint image matches a previously stored fingerprint image. When a comparison between the two fingerprint images shows a match, the biometric module 400 can determine that user authentication was successful.

[0064] When the previously stored biometric data and the input biometric data do not match, the biometric module 400 can wait until it receives biometric data again. When the previously stored biometric data and the input biometric data match, the SD controller 220 can change its state to an unlocked state (operation S340). Specifically, when biometric authentication is successful, the biometric module 400 can send user verification data to the SD controller 220. The biometric processing circuit 240 of the SD controller 220 can change the state of the SD controller 220 to an unlocked state based on the user verification data. The state of the SD controller 220 can be changed to an unlocked state by changing the pointer information used for the non-volatile memory 300 to the operating system (OS) MBR. After the state of the SD controller 220 is changed to an unlocked state, the SD controller 220 can perform a relink to enable access to the user data area (operation S350). For example, after the pointer information changes, the biometric processing circuit 240 can send a control signal to the relink trigger circuit 250 or the connection management circuit 270 to control them to perform a relink (e.g., cause a temporary deactivation or disable pin or switch so that the host appears as if the storage device 500 has been disconnected).

[0065] Figure 4A and Figure 4B The data storage state of a non-volatile memory device according to an embodiment of the present invention is shown.

[0066] Figure 4A The storage space of a non-volatile memory 300 according to various embodiments is shown. The storage space of the non-volatile memory 300 will be referred to as a memory region. The memory region may include a non-secure region and a secure region.

[0067] The insecure area may include the first master boot record and user data. The insecure area is the region where user data is stored and can be referred to by various terms such as user volume, user data area, and private area. The insecure area can be understood as the storage area accessible when the security of the storage device 500 is disabled (insecure state).

[0068] The MBR may include information such as the location of partitions and boot code used for booting. The first MBR may be referred to as the operating system MBR. For example, when the operating system of host device 100 is Windows, the first MBR may be the MBR loader. As another example, when the operating system of host device 100 is Linux, the first MBR may be the Linux loader (LILO) or the Rand Unified Boot Loader (GRUB). The LBA scheme (Logical Block Addressing Scheme) may be a scheme used to specify the location of data blocks in memory regions. For example, the first data block may correspond to LBA (Logical Block Address) 0, and the second data block may correspond to LBA 1. Therefore, it can be understood that the first MBR is stored in the LBA 0 region. LBA 1 is the region for storing user data, and LBA 0 may store MBR data.

[0069] According to various embodiments, the secure area may include the area of ​​the second MBR and the storage SED support software. The secure area can be understood as a memory area accessible while maintaining the security of the storage device 500.

[0070] The second MBR can be referred to by various terms such as shadow MBR and pseudo MBR. When the security of storage device 500 is not deactivated and access to insecure areas should therefore not be permitted, the second MBR can correspond to the MBR used to force host device 100 to begin booting in an area unrelated to user data. According to various embodiments, firmware files can be stored in the LBA 1 area of ​​the secure area. This is to induce the installation of software that allows the user to disable security.

[0071] According to various embodiments, the biometric processing circuit 240 can activate pointer 1. Pointer 1 can be activated when the biometric processing circuit 240 receives user verification data from the biometric module 400 indicating that biometric authentication has been successful. When pointer 1 is activated, the host device 100 can connect to the storage device 500 and begin booting using the first MBR in the non-secure area. When booting using the first MBR, the host device 100 can access the area storing user data.

[0072] According to various embodiments, the biometric processing circuit 240 can activate pointer 2. Pointer 2 can be activated when the biometric processing circuit 240 receives user authentication data indicating biometric authentication failure from the biometric module 400. When pointer 2 is activated, the host device 100 can connect to the storage device 500 and begin booting using the second MBR of the secure region. When booting using the second MBR, the region storing user data is invisible to the host device 100, and the host device 100 can only access the region storing the SED support software. Although the region storing user data is referred to herein as the non-secure region, it is actually a secure region. That is, the region storing user data is inaccessible when user authentication fails; in this sense, it is a secure region.

[0073] Figure 4B The illustration shows a scenario where multiple users use storage areas according to various embodiments. LBA 1 may be an area storing data for a first user, LBA 2 may be an area storing data for a second user, and LBA 3 may be an area storing data for a third user. When biometric data is received, the biometric module 400 can compare the biometric data with previously stored biometric data to determine if they match. For example, it can be assumed that the first user corresponds to the first biometric data, the second user corresponds to the second biometric data, and the third user corresponds to the third biometric data. In this case, the biometric module 400 can compare the received biometric data with all of the first to third biometric data. When the received biometric data does not match any of the first to third biometric data, the storage device 500 can remain secure. When the received biometric data matches any of the first to third biometric data, the biometric processing circuit 240 can reference the start address of the user data area (corresponding to the matching biometric data) in the partition information of the first MBR. For example, when the second biometric data matches the user input, the biometric processing circuit 240 can identify the start address of the LBA 2 region based on the partition information in the first MBR. In this case, the LBA 1 region of the first user or the LBA 3 region of the third user may be invisible to the host device 100. This is because the host device 100 can only access the address of the LBA 1 region referenced by the partition information of the first MBR.

[0074] Figure 5 This is a block diagram of a storage device according to an embodiment of the present invention.

[0075] The storage device 500 with separate LINK controller 210 and SD controller 220 will be described below. However, the inventive concept is not limited thereto, and can also be applied to, for example... Figure 1C and Figure 1D The diagram only shows a storage device 500 with an SD controller 220.

[0076] refer to Figure 5 The data processing circuit 230 may include an encryptor 231, a decryptor 232, and a data encryption key (DEK) storage circuit 233.

[0077] Encryptor 231 can encrypt the written data DATA_W. In one embodiment, when SD controller 220 is in a locked state, a write command CMD_W can be sent to encryptor 231. In this case, SD controller 220 cannot access the insecure area of ​​non-volatile memory 300, so data writing can be avoided. When SD controller 220 is in an unlocked state, a write command CMD_W can be sent. In the unlocked state, encryptor 231 can access the insecure area, so the write command CMD_W can be executed. Encryptor 231 can encrypt the written data DATA_W instead of directly storing it in the specified address ADDR. Encryptor 231 can perform encryption using DEK requested from and received from DEK storage circuit 233. After encryption is complete, encryptor 231 can store the encrypted written data ENCRYPTEDDATA_W in the specified address ADDR_W.

[0078] The decryptor 232 can decrypt the encrypted read data ENCRYPTED DATA_R. In one embodiment, when the SD controller 220 is in a locked state, a read command CMD_R can be sent to the decryptor 232. In this case, the SD controller 220 cannot access the insecure area of ​​the non-volatile memory 300, and therefore data reading can be avoided. When the SD controller 220 is in an unlocked state, a read command CMD_R can be sent to the decryptor 232. In the unlocked state, the decryptor 232 can access the insecure area and therefore execute the read command CMD_R. The decryptor 232 can read the data stored at the specified address ADDR_R. The read data can be the encrypted read data ENCRYPTED DATA_R. The decryptor 232 can use the DEK received from the DEK storage circuit 233 to perform decryption. After decryption is complete, the decryptor 232 can output the decrypted read data DATA_R to the host device 100 by sending the decrypted read data DATA_R to the LINK controller 210.

[0079] DEK storage circuit 233 can store key values ​​used for encrypting and decrypting data. In one embodiment, the DEK can be a unique value of storage device 500. For example, the DEK can be generated based on a globally unique identifier (GUID) of storage device 500.

[0080] In the above embodiments, the biometric data received by the biometric module 400 is used for user authentication, and DEK is described above as a unique value of the storage device 500, but the embodiments are not limited thereto.

[0081] According to various embodiments, the DEK can be additionally encrypted based on previously stored biometric data. In this case, the biometric data can be used not only for authentication by the biometric module 400, but also to obtain the DEK. When the DEK is additionally encrypted, external intruders (such as hackers) can be prevented from decrypting user data by obtaining only the DEK.

[0082] According to various embodiments, the biometric module 400 may include a biometric data storage circuit 410 and an authentication circuit 420. The biometric data storage circuit 410 may store biometric data entered during the user registration process. References below may be used. Figure 7 The software supporting SED functionality is used to execute the user registration process. The biometric data storage circuit 410 can send stored biometric data to the authentication circuit 420 in response to biometric data input to the biometric module 400.

[0083] The authentication circuit 420 can perform data comparisons for user authentication. For example, the authentication circuit 420 can compare input biometric data with biometric data stored in the biometric data storage circuit 410. When the input biometric data and the biometric data stored in the biometric data storage circuit 410 do not match, it can output "0" or a low logic value as the authentication result. When the input biometric data and the biometric data stored in the biometric data storage circuit 410 match, it can output "1" or a high logic value as the authentication result. The authentication result can be compared with... Figures 1A to 1D The user verification data shown corresponds to this.

[0084] Figure 6 An interface between a host device and a storage device according to an embodiment of the present invention is shown.

[0085] refer to Figure 6 The SD controller 220 may include a processor 610, random access memory (RAM) 620, host interface (I / F) 630, memory interface 640, biometric module 660, and relink module 650.

[0086] Processor 610 may include a central processing unit (CPU) or a microprocessor and control the overall operation of SD controller 220. For example, processor 610 may be configured to drive software or firmware for controlling SD controller 220, and this software or firmware may be driven by loading it into RAM 620. RAM 620 may be used as operating memory, cache memory, or buffer memory for processor 610. Write data to be written to the memory device and read data read from the memory device may be temporarily stored in RAM 620.

[0087] The host interface 630 interfaces with the host device 100 to receive requests for memory operations from the host device 100. Furthermore, the memory interface 640 provides an interface between the SD controller 220 and a memory device (not shown). For example, write data can be sent to the memory device through the memory interface 640, and read data can be received from the memory device through the memory interface 640. Additionally, the memory interface 640 can provide commands and addresses to the memory device, receive various information from the memory device, and provide information to the SD controller 220.

[0088] In one embodiment, the relinking module 650 and the biometric module 660 can perform various relink-related operations according to the above embodiments based on a software method, and the relinking module 650 may include a data processing module 651, a biometric processing module 652, and a relink triggering module 653. When performing operations according to embodiments of the present invention based on a software method, each of the biometric module 660, the data processing module 651, the biometric processing module 652, and the relink triggering module 653 may include a program executable by the processor 610, and this program may be loaded into RAM 620 and executed by the processor 610. Therefore, the biometric module 660 and the relinking module 650 including the data processing module 651, the biometric processing module 652, and the relink triggering module 653 can be implemented using various software (e.g., computer program code) for processor execution. In some cases, the biometric module 660 or a portion of the relinking module 650 including the data processing module 651 and the biometric processing module 652 can be implemented using a combination of software, hardware, and / or firmware.

[0089] Figure 7 This is a flowchart illustrating the operation of a host device according to an embodiment of the present invention.

[0090] refer to Figure 7 The host device 100 can detect the connection to the storage device 500 (operation S710). Please refer to the above for further details. Figure 2 Operation S130 and Figure 3 Operation S710 will be described in the same way as operation S310. Host device 100 can identify that storage device 500 supports SED function (operation S720). For example, host device 100 can receive configuration information for storage device 500 and check whether SED function is supported by an identifier indicating whether SED is supported.

[0091] According to various embodiments, when storage device 500 supports SED, communication can be established based on the Trusted Computing Group (TCG) protocol. The TCG protocol is a communication protocol that supports SED and involves methods for changing the partitioning, locking, and unlocking states of user areas in storage device 500. For example, when storage device 500 supports SED, a shadow MBR (SMBR) can be generated based on the TCG protocol.

[0092] Host device 100 can install software that supports SED functionality (operation S730). In one embodiment, host device 100 can identify whether storage device 500 supports SED functionality; however, when the SED functionality of storage device 500 is disabled, a pop-up window suggesting software installation or allowing automatic execution of the software installation file can be displayed. Host device 100 can guide biometric data to be obtained by software supporting SED functionality (operation S740). When executing the software, host device 100 can request biometric data to be input into the biometric module 400 of storage device 500 to activate the SED functionality. The biometric data can be guided to be obtained based on at least one of visual guidance including a pop-up window and audio guidance including voice output. Storage device 500 can store the input biometric data in biometric data storage circuit 410 (operation S750). Because it is not necessary to send input biometric data to host device 100, even if no software is installed on host device 100 or host device 100 is not connected to storage device 500, after activating the SED function through the user registration process, storage device 500 can be unlocked by simply inputting biometric data via biometric module 400 of storage device 500.

[0093] The above embodiments describe that biometric data entered during user registration is not sent to host device 100, but the embodiments are not limited thereto. According to various embodiments, host device 100 may also include a separate biometric module, distinct from the biometric module 400 of storage device 500. For example, the separate biometric module is a separate device and may be connected via an input / output interface of host device 100, or it may be integrated and embedded into host device 100. When a biometric module is connected to host device 100, host device 100 may request biometric data from storage device 500. Alternatively, host device 100 may obtain biometric data from the user via the biometric module connected to host device 100 and send the obtained biometric data to storage device 500. Alternatively, host device 100 may store the biometric data received from storage device 500 and use the biometric data for user authentication. For example, host device 100 may recognize the connection to storage device 500 including biometric module 400 and automatically execute software to request biometric data. When a user responds to a request by inputting biometric data through the biometric module 400 of the storage device 500, the host device 100 can perform user authentication by comparing the biometric data with previously stored biometric data and sending the user authentication result to the storage device 500, or it can simply send the biometric data input through a separate biometric module to the storage device 500 so that the storage device 500 can perform user authentication.

[0094] Figure 8 This is a block diagram of a non-volatile memory system. Details regarding this can be omitted. Figure 8 In and Figures 1A to 1D A description of a part that is the same as a part of the text. Figure 8 and Figure 9 These are examples described to compare certain features previously described with systems that may not include these features.

[0095] refer to Figure 8 The host device 100 can send the command CMD_MONITOR to identify the status of the SD controller 220. Figure 8 The SD controller 220 may not include Figures 1A to 1D The LINK controller 210 or connection management circuit 270. Figure 8The SD controller 220 can receive commands from an external source (e.g., host device 100). Host device 100 can periodically send a CMD_MONITOR signal to the SD controller 220. For example, when the state of the SD controller 220 changes from a locked state to an unlocked state, the user data area can be accessed by performing a relink based on the changed pointer 1. However, the SD controller 220 and the non-volatile memory 300 are passive devices, and therefore may need to periodically check whether the state of the SD controller 220 has changed. Passive devices are devices that can only send a response to a command when they receive one, and therefore may include devices that cannot independently send signals in the first place.

[0096] In some embodiments, the SD controller 220 sends a response signal in response to periodically received CMD_MONITOR signals. For example, in some embodiments, the host device 100 cannot recognize the time when the SD controller 220 is unlocked, and therefore periodically sends CMD_MONITOR signals to the SD controller 220 until it receives an RSP_MONITOR signal, which is a response signal indicating the unlocked state. Therefore, in this embodiment, the SD controller 220 sends an RSP_MONITOR signal to the host device 100 in response to the periodically sent CMD_MONITOR signals. The periodically sent and received CMD_MONITOR and RSP_MONITOR signals can act as loads on the host device 100 and SD controller 220, respectively, thereby reducing the performance of the entire memory system.

[0097] In some embodiments, host device 100 may send a signal requesting SD controller 220 to perform a relink. For example, host device 100 may receive a response signal indicating an unlocked state during periodic monitoring. Host device 100 needs to perform a relink based on a changed pointer to access the user data area. Therefore, host device 100 may send a command instructing SD controller 220 to perform a relink. Each time host device 100 sends a CMD_RELINK signal, a delay occurs when SD controller 220, in an unlocked state, accesses non-volatile memory 300. This is because even when SD controller 220 changes to an unlocked state, host device 100 sends a subsequent CMD_MONITOR signal, recognizing the SD controller as locked, until SD controller 220 sends an RSP_MONITOR signal in response to the CMD_MONITOR signal. Furthermore, because host device 100 needs to send the CMD_RELINK signal again after receiving the RSP_MONITOR signal, an additional delay occurs corresponding to the time required to send the CMD_RELINK signal.

[0098] Figure 9 This illustrates signal switching in a non-volatile memory system. Details regarding this will be omitted here. Figure 9 In and Figure 3 A description of a part that is the same as a part of the text.

[0099] refer to Figure 9 The host device 100 sends a monitoring signal CMD_MONITOR at regular intervals to check whether the SD controller 220 is in a locked state. The SD controller 220 should respond to the monitoring signal CMD_MONITOR received at regular intervals by sending a response signal RSP_MONITOR indicating its status.

[0100] In operation S190, user input to the SD controller 220 can be unlocked simply by inputting an instruction from the host device 100. This is because... Figure 1A and Figure 1B Unlike other devices, storage device 500 does not include biometric module 400. Therefore, unlocking storage device 500 is subject to control by host device 100.

[0101] Although the SD controller 220 is changed to an unlocked state during operation S160, the host device 100 can recognize that the SD controller 220 is in a locked state. Subsequently, the change in the state of the SD controller 220 can be recognized at the point in time when the RSP_MONITOR (unlock) signal is received as a response signal to the periodically sent CMD_MONITOR signal. Therefore, there is a time delay between the time when the SD controller 220 is actually unlocked and the time when the host device 100 recognizes the unlocked state of the SD controller 220.

[0102] In addition, in order to identify the user data area, the host device 100 needs to send a command to request reconnection. Due to the time required to send the CMD_RELINK signal and the time required for the SD controller 220 to receive the CMD_RELINK signal and begin reconnection, the reconnection may be delayed.

[0103] By reference Figure 8 and Figure 9 Together Figure 1A and Figure 2 By examining the embodiments and comparing the differences, one will understand the effects of certain aspects of the inventive concept.

[0104] Figure 10 This is a block diagram illustrating an example of applying a memory device to a solid-state drive (SSD) system according to an embodiment of the present invention.

[0105] refer to Figure 10The SSD system 1000 may include a host device 100 and an SSD 1100. The SSD 1100 exchanges signals with the host device 100 via a signal connector and is powered via a power connector. The SSD 1100 may include an SSD controller 1110, multiple storage devices 1120 to 1140, a LINK controller 1160, and a biometric module 1170. In this configuration, a biometric module 1170 can be used. Figures 1A to 7 The illustrated embodiment implements the SSD controller 1110, LINK controller 1160, and biometric module 1170. Therefore, the SSD 1100 does not perform relinking based on commands from the host device 100, but can perform relinking independently even without receiving commands from the host device 100. Furthermore, the SSD 1100 does not receive monitoring commands from the host device 100, thus eliminating the need to send response signals in response to monitoring commands, thereby reducing the load on the memory system. Moreover, the SSD 1100 does not receive monitoring commands or commands instructing relinking from the host device 100, therefore it can perform relinking independently even based on protocols or operating systems that do not support monitoring commands or commands instructing relinking. For example, the SSD 1100's dependence on the host device 100 or its operating system can be reduced, and the SSD 1100 can be applied to n types of host devices. Furthermore, when the SSD 1100's lock state is released, the SSD 1100 independently performs a relink, thus enabling a fast relink without causing time delays in sending and receiving monitoring commands and commands instructing for relinking.

[0106] The memory device according to embodiments of the present invention can be installed in or applied not only to SSD 1100, but also to memory card systems, computing systems, UFS, etc. The operating method of the memory device according to embodiments of the present invention can be applied to various types of electronic systems equipped with non-volatile memory.

[0107] Figure 11 This is a block diagram of a storage device according to an embodiment of the present invention. Details can be omitted here. Figure 11 In and Figure 1A A description of a part that is the same as a part of the text.

[0108] refer to Figure 11 The storage device 500 may also include a radio frequency identification (RFID) module 430. The RFID module 430 can refer to a module used to exchange data between an RFID tag device and an RFID reader device using radio frequency. According to various embodiments, the RFID module 430 may be embodied as a near field communication (NFC) module and / or a magnetically secure transmission (MST) module.

[0109] According to various embodiments, a user may have an external device (not shown) distinct from the host device 100. Examples of external devices may include devices capable of performing biometric authentication and establishing wireless communication, such as smartphones. The user may use the external device to perform biometric authentication. The external device includes a biometric module and can therefore complete user authentication based on input biometric data. In response to successful user authentication, the external device may send user verification data to the NFC module or via the NFC module or MST module to the storage device 500. In this case, the external device can be manipulated by the user to be within a predetermined distance of the storage device 500. For example, the MST module may send user verification data indicating whether user authentication was successful via a magnetic field, along with the external device's unique identifier. The storage device 500 may receive the user verification data via the RFID module 430 and be unlocked when the user verification data is "1" or a high logic value. According to the above embodiments, the user can unlock the storage device 500 not only by using the biometric module 400 of the storage device 500 but also by using his or her existing external devices without intervention from the host device 100.

[0110] Although the inventive concept has been specifically shown and described with reference to embodiments thereof, it will be understood that various changes in form and detail may be made therein without departing from the spirit and scope of the appended claims.

Claims

1. A non-volatile memory system including a storage device configured to be connected to a host device via a physical cable, the physical cable including power lines and data lines. in, The storage device includes: Non-volatile memory; The link controller is configured to: deactivate the data line and then reactivate the data line when powered from the host device via the power line by disabling and subsequently enabling a pin corresponding to the data path, deactivating a switch located in the data path and subsequently reactivating the switch, or resetting or starting the microcontroller; and Memory controller, The memory controller includes: a biometric module configured to receive biometric data and perform user authentication based on the biometric data; a biometric processing circuit configured to change the state of the memory controller based on the result of the user authentication; a relink trigger circuit configured to control the link controller based on the change in the state of the memory controller; and a data processing circuit configured to encrypt and decrypt data. The switch is located on the data line in the data path to electrically open and close the data line, and to deactivate and subsequently reactivate the switch such that, while maintaining the physical connection between the storage device and the host device via the physical cable, the host device re-identifies the storage device as if the storage device had been physically disconnected and reconnected to the host device. The relink trigger circuit is configured to send a relink trigger signal to the link controller via a signal path different from the path that transmits commands and data to the data processing circuit. The link controller is configured to deactivate the data line and then reactivate the data line in response to receiving the relink trigger signal, without the storage device receiving a monitoring command from the host device to identify the state of the memory controller or a command instructing the link controller to perform a relink.

2. The non-volatile memory system according to claim 1, wherein, The states of the memory controller correspond to locked or unlocked states, and The non-volatile memory includes: a first region that is accessible to the host device during the unlocked state and inaccessible to the host device during the locked state; and a second region that is accessible to the host device during the locked state.

3. The non-volatile memory system according to claim 2, wherein, The memory controller is configured to change its state to the locked state when the storage device is powered off. as well as Specifically, when the input biometric data matches the previously stored biometric data, the biometric module completes user authentication and sends user verification data indicating the result of the user authentication to the biometric processing circuit.

4. The non-volatile memory system according to claim 2, wherein, The biometric processing circuit is configured to change the state of the memory controller to the locked state by changing pointer information so that the Master Boot Record (MBR) information indicates the second MBR included in the second region, and is also configured to change the state of the memory controller to the unlocked state by changing the pointer information so that the MBR information indicates the first MBR included in the first region. Wherein, the first MBR corresponds to the operating system OS MBR, and The second MBR corresponds to the shadow MBR.

5. The non-volatile memory system according to claim 1, wherein, The physical cable corresponds to the cable used for the interface that supports hot-plugging, and The interface corresponds to at least one of the following: Universal Serial Bus (USB) interface, Serial ATA interface, Parallel ATA interface, Small Computer System Interface (SCSI), and Serial Attached SCSI.

6. The non-volatile memory system according to claim 1, wherein, The signal path includes general purpose input / output (GPIO) communication, and the relink trigger signal is sent according to a communication scheme independent of command reception.

7. The non-volatile memory system according to claim 1, wherein, The link controller and the memory controller are formed on the same semiconductor substrate.

8. The non-volatile memory system according to claim 1, wherein, The biometric data includes at least one of the following: an image of the user's fingerprint, an image of the user's iris, an image of the user's veins, and data from the user's voice.

9. The non-volatile memory system according to claim 1, wherein, In response to the memory controller changing its state to an unlocked state, the host device bypasses the transmission of monitoring commands used to identify the state of the memory controller and commands instructing the execution of relinking.

10. The non-volatile memory system according to claim 1, further comprising: The host device is configured to send commands and data to the storage device via the physical cable, and is also configured to supply power to the storage device via the physical cable.

11. A storage device configured to be connected to a host device via a physical cable, the physical cable including power lines and data lines, the storage device comprising: Non-volatile memory; A data path controller is configured to deactivate the data line when power is supplied from the host device via the power line and then reactivate the data line. as well as Memory controller, The memory controller includes: a biometric module configured to receive biometric data and perform user authentication based on the biometric data; a biometric processing circuit configured to change the state of the memory controller based on the result of the user authentication; a relink trigger circuit; and a data processing circuit configured to encrypt and decrypt data. The data path controller is configured to, in response to a change in the state of the memory controller, deactivate the data line and then reactivate the data line by disabling and subsequently enabling a pin corresponding to the data path, deactivating a switch in the data path and then reactivating the switch, or resetting or starting the microcontroller. The biometric processing circuit is further configured to change the state of the memory controller from a locked state to an unlocked state in response to successful user authentication, and is configured to send a control signal to the relink trigger circuit in response to the completion of the change from the locked state to the unlocked state. The relink trigger circuit is configured to send a relink trigger signal to the data path controller in response to receiving the control signal via a signal path different from the path that transmits commands and data to the data processing circuit. The data path controller is configured to deactivate the data line and subsequently reactivate it in response to receiving the relink trigger signal, without requiring the storage device to receive a monitoring command from the host device to identify the state of the memory controller or a command instructing the data path controller to perform a relink. The switch is located on the data line in the data path to electrically open and close the data line, and to deactivate and subsequently reactivate the switch such that while maintaining the physical connection between the storage device and the host device via the physical cable, the host device re-identifies the storage device as if the storage device had been physically disconnected from and reconnected to the host device.

12. The storage device according to claim 11, wherein, The states of the memory controller correspond to locked or unlocked states, and The non-volatile memory includes: a first region that is accessible to the host device during the unlocked state and inaccessible to the host device during the locked state; and a second region that is accessible to the host device during the locked state.

13. The storage device according to claim 12, wherein, The memory controller is configured to change its state to the locked state when the storage device is powered off. as well as Specifically, when the input biometric data matches the previously stored biometric data, the biometric module completes user authentication and sends user verification data indicating the result of the user authentication to the biometric processing circuit.

14. The storage device according to claim 12, wherein, The biometric processing circuit is configured to change the state of the memory controller to the locked state by changing pointer information so that the Master Boot Record (MBR) information indicates the second MBR included in the second region, and is also configured to change the state of the memory controller to the unlocked state by changing the pointer information so that the MBR information indicates the first MBR included in the first region. Wherein, the first MBR corresponds to the operating system OS MBR, and The second MBR corresponds to the shadow MBR.

15. The storage device according to claim 11, wherein, The physical cable corresponds to the cable used for the interface that supports hot-plugging, and The interface corresponds to at least one of the following: Universal Serial Bus (USB) interface, Serial ATA interface, Parallel ATA interface, Small Computer System Interface (SCSI), and Serial Attached SCSI.

16. The storage device according to claim 11, wherein, The signal path includes general purpose input / output (GPIO) communication, and the relink trigger signal is sent according to a communication scheme independent of command reception.

17. A method of operating a non-volatile memory system, the non-volatile memory system including a storage device configured to be connected to a host device via a physical cable, the physical cable including power lines and data lines, wherein... The storage device includes non-volatile memory, and the method includes: Receive biometric data and perform user authentication based on the biometric data; Based on the result of the user authentication, change the state of the memory controller; and In response to a changed state, the data line can be deactivated and then reactivated when powered from the host device via the power line by disabling and subsequently enabling the pin corresponding to the data path, deactivating and subsequently reactivating a switch located in the data path, or resetting or starting the microcontroller. The method further includes: In response to successful user authentication, the state of the memory controller is changed from a locked state to an unlocked state, and a control signal is sent to the relink trigger circuit in response to the completion of the change from the locked state to the unlocked state. In response to receiving the control signal via a signal path different from the path for transmitting commands and data to access the non-volatile memory, a relink trigger signal is sent to the link controller. The deactivation and subsequent reactivation of the data line is performed in response to receiving the relink trigger signal, without requiring the storage device to receive a monitoring command from the host device to identify the state of the memory controller or a command instructing the relink to be performed. The switch is located on the data line in the data path to electrically open and close the data line, and to deactivate and subsequently reactivate the switch such that while maintaining the physical connection between the storage device and the host device via the physical cable, the host device re-identifies the storage device as if the storage device had been physically disconnected from and reconnected to the host device.

18. The operating method according to claim 17, wherein: Changing the state of the memory controller includes changing between a locked state and an unlocked state; The non-volatile memory includes: a first region that is accessible to the host device during the unlocked state and inaccessible to the host device during the locked state; and a second region that is accessible to the host device during the locked state.

19. The operating method according to claim 18, further comprising: By changing the pointer information so that the Master Boot Record (MBR) information indicates the second MBR included in the second region, the state of the memory controller is changed to the locked state; as well as By changing the pointer information so that the MBR information indicates the first MBR included in the first region, the state of the memory controller is changed to the unlocked state. Wherein, the first MBR corresponds to the operating system OS MBR, and The second MBR corresponds to the shadow MBR.

Citation Information

Patent Citations

  • Operation method of memory controller and nonvolatile memory system including the memory controller

    US20160048459A1

  • Self-encrypting module with embedded wireless user authentication

    US20190007203A1

  • Method for reading data in a write-once memory device using a write-many file system

    US7062602B1