Memory controller and storage device including memory controller
Patent Information
- Application Number
- CN202110006882.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-01-10
- Filing Date
- 2021-01-05
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2041-01-05
AI Technical Summary
[0004]然而,由存储装置提供的安全功能可根据主机装置的命令来操作,因此,当主机装置不支持发送指示使用存储装置的安全功能的命令时,存储装置的安全功能不可以被使用
Smart Images

Figure CN113113068B_ABST
Abstract
Description
[0001] This application is based on and claims priority to Korean Patent Application No. 10-2020-0003885, filed on January 10, 2020, with the Korean Intellectual Property Office, the entire disclosure of which is incorporated herein by reference. Technical Field
[0002] Embodiments of the inventive concept relate to storage devices, and more specifically, to a memory controller that supports self-encryption and a storage device including the memory controller. Background Technology
[0003] Flash memory, as a non-volatile storage medium, retains the data stored within it even when power is off, and storage devices that include flash memory (such as solid-state drives (SSDs) or memory cards) are widely used. Recently, in response to increasing data security needs, security features have been developed to securely store critical data and prevent data leakage even if the storage device is discarded or stolen. Self-encrypting drives (SEDs) (one of the security features for storage devices) provide high data protection by encrypting data to write encrypted data and decrypting encrypted data to read data.
[0004] However, the security functions provided by the storage device can only operate according to commands from the host device. Therefore, when the host device does not support sending commands instructing the use of the storage device's security functions, these functions cannot be used. Thus, a storage device capable of executing security functions under the control of various host devices is needed. Summary of the Invention
[0005] One or more embodiments of the inventive concept provide a memory controller and a storage device including the memory controller, the memory controller being able to provide security functions for the storage device even when the storage device is connected to various types of host devices.
[0006] According to one aspect of an embodiment of the inventive concept, a memory controller for controlling non-volatile memory is provided, the memory controller comprising: a secure access control module configured to convert biometric authentication data received from a biometric module into secure configuration data having a data format according to a security standard protocol, and configured to perform at least one of permission registration and permission authentication of user permissions based on the secure configuration data, wherein user permissions are set for access control of a secure area of the non-volatile memory, and encrypted user data is stored in the secure area; and a data processing unit configured to encrypt user data received from a host device or decrypt encrypted user data read from the secure area based on permission to access the secure area.
[0007] According to one aspect of an embodiment of the inventive concept, a storage device is provided, the storage device comprising: a non-volatile memory including a secure area for storing encrypted user data; and a memory controller configured to perform permission authentication on user permissions for accessing the secure area by determining field values of a first set of features based on biometric authentication data according to a security standard protocol, and to set the secure area of the non-volatile memory to an unlocked state based on successful permission authentication.
[0008] According to one aspect of an embodiment of the inventive concept, a storage device is provided, the storage device comprising: a non-volatile memory including a secure area for storing encrypted user data; and a memory controller configured to control the non-volatile memory, wherein the memory controller is further configured to: perform authorization authentication of a user having access to the secure area based on a password received from the first host device according to a security protocol, the security protocol being set for communication with the first host device, and perform authorization authentication based on biometric authentication data received from a biometric module, based on a connection of the storage device to a second host device. Attached Figure Description
[0009] Embodiments of the inventive concept will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which: Figure 1 This is a block diagram of a storage device and storage system according to an exemplary embodiment of the inventive concept; Figure 2A and Figure 2B This is a block diagram illustrating a method for performing user authorization authentication by a memory controller in a storage device according to a connected host device, based on an example embodiment of the inventive concept. Figure 3 This illustrates the management objectives of a security access control module according to an example embodiment of the inventive concept; Figure 4A and Figure 4B This is an example of an implementation of a feature set table configured by a security access control module according to an exemplary embodiment of the inventive concept; Figure 5 This is a block diagram of a memory controller according to an exemplary embodiment of the inventive concept; Figure 6 This is a flowchart of a method for operating a storage device based on received biometric authentication data, according to an exemplary embodiment of the inventive concept. Figure 7 This shows an example of a data format based on a security standard protocol; Figure 8A and Figure 8BThis is a diagram illustrating a user access authentication method for a storage system according to an example embodiment of the inventive concept; Figure 9 This illustrates a method for setting the locked and unlocked states of a non-volatile memory, performed by a secure access control module, according to an example embodiment of the inventive concept. Figure 10A and Figure 10B This illustrates multiple user permissions for a secure area of a non-volatile memory, according to an example embodiment of the inventive concept.
[0010] Figure 11 This is a diagram illustrating a user permission registration method for a storage system according to an exemplary embodiment of the inventive concept; Figure 12 This is a diagram illustrating a method for deleting user permissions in a storage system according to an exemplary embodiment of the inventive concept; Figure 13 This is a block diagram of a biometric module according to an exemplary embodiment of the inventive concept; Figure 14 This is a block diagram of a storage device and storage system according to an exemplary embodiment of the inventive concept; Figure 15 This is a block diagram of a storage device and storage system according to an exemplary embodiment of the inventive concept; Figure 16 It is a block diagram of an electronic system according to an exemplary embodiment of the inventive concept; Figure 17 This is a block diagram of a solid-state drive (SSD) and an SSD system including an SSD, based on an example embodiment of the inventive concept. Detailed Implementation
[0011] In the following, exemplary embodiments of the inventive concept will be described in detail with reference to the accompanying drawings.
[0012] Figure 1 This is a block diagram of a storage device 100 and a storage system 10 according to an exemplary embodiment of the inventive concept.
[0013] Reference Figure 1 The storage system 10 may include a storage device 100, a host device 200, and a biometric module 300, and the storage device 100 may include a memory controller 110 and a non-volatile memory (NVM) 120.
[0014] Storage system 10 can be implemented by, for example, a personal computer (PC), a data server, a networked storage device, an Internet of Things (IoT) device, or a portable electronic device. Portable electronic devices may include laptops, mobile phones, smartphones, tablet PCs, personal digital assistants (PDAs), enterprise digital assistants (EDAs), digital cameras, digital camcorders, audio devices, portable multimedia players (PMPs), personal navigation devices (PNDs), MP3 players, handheld game consoles, e-readers, wearable devices, etc.
[0015] According to some embodiments of the inventive concept, storage device 100 may be internal memory embedded in an electronic device. For example, storage device 100 may be a solid-state drive (SSD), an embedded universal flash memory (UFS) device, or an embedded multimedia card (eMMC), but is not limited thereto. According to some embodiments of the inventive concept, storage device 100 may be external memory detachably attached to an electronic device. For example, storage device 100 may include a portable SSD, a UFS memory card, a compressed flash memory (CF) card, a secure digital card (SD) card, a micro-secure digital card (Micro-SD) card, a mini-secure digital card (Mini-SD) card, an extreme digital card (xD) card, or a memory stick.
[0016] The host device (or, referred to herein as the host) 200 can communicate with the storage device 100 through various interfaces, sending commands (CMD) and / or data (DT) to be stored in the NVM 120 to the storage device 100, and receiving responses (RES) and / or data (DT) read from the NVM 120 from the storage device 100. For example, the host device 200 may be implemented by an application processor (AP) or a system-on-a-chip (SoC). Alternatively, for example, the host device 200 may be implemented by an integrated circuit, a motherboard, or a database server, but is not limited thereto.
[0017] According to an embodiment of the inventive concept, when electrically connected by cables in a hot-swappable interface scheme, the host device 200 and the storage device 100 can communicate with each other.
[0018] In response to the command CMD received from the host device 200, the storage device 100 may store the data (hereinafter referred to as user data) DT received from the host device 200, or read the user data DT stored in the NVM 120 and send the user data DT to the host device 200.
[0019] Storage device 100 can communicate with host device 200 via a security standard protocol, and the security functions of storage device 100 can be configured under the control of host device 200. In embodiments of the inventive concept, the configuration of security functions indicates configurations related to the use of security functions for performing security functions. Host device 200 can provide storage device 100 with commands (hereinafter referred to as security commands) SCMD according to the security standard protocol for configuring the security functions of storage device 100, and receive responses RES from storage device 100 to the security commands SCMD.
[0020] Security commands (SCMD) and responses (RES) may have a data format according to a security standard protocol, and the security command (SCMD) may include requests and setting values associated with the configuration of security functions. According to one embodiment of the inventive concept, the setting values may include a password for user authentication. For example, storage device 100 may communicate with host device 200 via a Trusted Computing Group (TCG) protocol. Security commands (SCMD) and responses (RES) having a data format according to the TCG protocol may be sent and received between storage device 100 and host device 200. For example, security commands (SCMD) and responses (RES) may have 512-byte data blocks (or packets). However, embodiments of the inventive concept are not limited thereto, and security standard protocols provided by various interface schemes, such as Advanced Technology Attachment (ATA) interfaces and Serial ATA (SATA) interfaces, may be applied between host device 200 and storage device 100.
[0021] However, some of the various devices that can be implemented as host device 200 cannot configure the security functions of storage device 100. For example, security standard protocols may not be applicable between host device 200 and storage device 100, and host device 200 may not provide the security command SCMD to storage device 100. In this case, according to one embodiment of the inventive concept, storage device 100 can configure security functions by independently determining a feature set based on biometric authentication data (BAD) received from biometric module 300 according to the security standard protocol. For example, storage device 100 can independently determine setting values based on BAD received from biometric module 300, instead of receiving setting values from host device 200. According to one embodiment of the inventive concept, storage device 100 can generate security configuration data corresponding to the security command SCMD based on BAD (e.g., security configuration data with a data format according to the security standard protocol), and configure security functions based on the security configuration data. Therefore, the security functions of storage device 100 can be executed. This will be described in detail below.
[0022] NVM 120 may refer to a memory module or memory device having the characteristic of retaining stored data even when power is off. According to one embodiment of the inventive concept, NVM 120 may include a flash memory device (e.g., a NAND flash memory device). According to one embodiment of the inventive concept, NVM 120 may include a vertical NAND (VNAND) flash memory device having a three-dimensional array structure. However, NVM 120 is not limited to this and may include, but is not limited to, resistive memory devices (such as resistive random access memory (ReRAM), phase-change random access memory (PRAM), or magnetic random access memory (MRAM)). Optionally, NVM 120 may be implemented not only by a semiconductor memory device but also by a disk drive device. Hereinafter, for ease of description, NVM 120 is described as a NAND flash memory device, but it should be understood that embodiments of the inventive concept are not limited thereto. According to one embodiment of the inventive concept, NVM 120 may include a plurality of NVM chips, and the plurality of NVM chips may communicate with memory controller 110 through a plurality of channels.
[0023] Given the NVM 120's ability to retain stored data even during power outages, it is necessary to maintain the data stored in the NVM 120 in a secure state. For example, when the storage device 100 is reused or discarded, or when the storage device 100 is used by an unauthorized user, it is essential to prevent the leakage of secure data stored in the storage device 100. To this end, the storage device 100 may support a self-encryption function. The storage device 100 may encrypt user data DT received from the host device 200 and store the encrypted user data EDT in a secure area SA of the NVM 120. Because the encrypted user data EDT stored in the secure area SA of the NVM 120 remains encrypted, the encrypted user data EDT remains secure even when the power supply to the storage device 100 is cut off. As described above, the storage device 100 supporting self-encryption may be referred to as a self-encryption device or a self-encryption drive (SED).
[0024] The memory controller 110 controls the overall operation of the storage device 100 and the write and read operations of the NVM 120. Furthermore, the memory controller 110 supports security functions of the storage device 100 (e.g., self-encryption). The memory controller 110 can encrypt user data DT received from the host device 200 and store the encrypted user data EDT in the secure area SA of the NVM 120. Additionally, the memory controller 110 can read the encrypted user data EDT from the NVM 120, decrypt the encrypted user data EDT, and provide the user data DT to the host device 200.
[0025] The memory controller 110 can control access to the security zone SA of the NVM 120 (e.g., control the configuration of security functions). The memory controller 110 can register (or enroll) user rights for users who can access the security zone SA of the NVM 120, and when authentication of user rights (i.e., user rights authentication) is successful, access to the security zone SA of the NVM 120 is permitted. In other words, when user rights authentication performed by the memory controller 110 is successful, the host device 200 can access the security zone SA of the NVM 120 to write or read user data DT.
[0026] The memory controller 110 may include a security access control module (SACM) and a data processing unit (DPU). The SACM can configure security functions by managing user permissions for users with access rights to a security zone (SA) of the NVM 120. For example, the SACM can register, authenticate, and / or delete user permissions. The DPU can encrypt user data (DT) received from the host device 200 based on a security key (SKEY), or decrypt encrypted user data (EDT) read from the security zone (SA) of the NVM 120. The security key (SKEY) can be created based on a random key created in the hardware logic within the storage device 100, or it can be created based on a combination of a random key and a unique key provided externally (e.g., from the host device 200). For example, the SACM can encrypt or decrypt the security key (SKEY) based on a unique value (or password) used for user permission registration and / or authentication to lock or unlock the storage device 100. Specifically, the Security Access Control Module (SACM) can set a locked or unlocked state associated with read and / or write operations on the Security Area SA of the NVM 120. When the SACM encrypts and stores the encrypted Security Key SKEY based on a unique value, the Security Area SA of the NVM 120 can be set to a locked state, disallowing read and / or write access. When user authentication is successful, the SACM can decrypt the encrypted Security Key SKEY to set the Security Area SA of the NVM 120 to an unlocked state, allowing read and / or write access. The Data Processing Unit (DPU) can encrypt user data DT to be stored in the Security Area SA based on the Security Key SKEY, or decrypt encrypted user data EDT read from the Security Area SA.
[0027] As described above, security standard protocols can be applied between host device 200 and storage device 100 to provide security functions for storage device 100, and host device 200 can send security commands (SCMD) to storage device 100 based on the security standard protocols. For example, host device 200 can send a user permission registration request and password for user permission authentication as security commands (SCMD) to storage device 100, and also provide a user permission activation request as a security command (SCMD), a setting value for setting NVM 120 to a locked or unlocked state, etc. The setting value can be defined in the security standard protocols and can include field values of the feature set according to the security standard protocols for user permissions. For example, host device 200 can generate security commands (SCMD) according to the TCG protocol and provide the security commands (SCMD) to storage device 100. In this case, the security commands (SCMD) can be packaged (or command tokenized) according to the data format of the security standard protocols, and host device 200 can send the packaged commands (e.g., data packets) to storage device 100 (specifically, to memory controller 110). The Security Access Control Module (SACM) can set field values for a feature set used for user permissions based on the security command (SCMD) received from the host device 200, in order to register, authenticate, and / or delete user permissions and set the NVM 120 to a locked or unlocked state.
[0028] As described above, in a storage device 100 according to one embodiment of the inventive concept, a memory controller 110 can configure security functions under the control of a host device 200 (in other words, based on security commands SCMD), and also independently configure security functions based on a BAD received from a biometric module 300. For example, the memory controller 110 can manage user permissions based on the BAD according to a security standard protocol. A security access control module (SACM) can register, authenticate, and / or delete user permissions based on the BAD. According to one embodiment of the inventive concept, the security access control module (SACM) can convert the BAD into security configuration data with a data format according to a security standard protocol, and register, authenticate, and / or delete user permissions based on the security configuration data.
[0029] The Security Access Control Module (SACM) can set field values for a feature set used for user permissions based on the BAD received from the biometric module 300. According to one embodiment of the inventive concept, the SACM can set a credential value for user permissions based on the BAD. Therefore, user permissions can be registered using the credential value. Furthermore, when the storage device 100 is connected to the host device 200, the SACM can receive the BAD from the biometric module 300 and perform user permission authentication based on the BAD. When user permission authentication is successful, the SACM can independently set the NVM 120 (specifically, the security zone SA of the NVM 120) to a locked or unlocked state. According to one embodiment of the inventive concept, the SACM can register user permissions based on a registration command CMD for requesting user permissions received from the host device 200 and the BAD received from the biometric module 300, and then independently perform user permission authentication based on the BAD if no security command SCMD is received from the host device 200.
[0030] Thus, because the memory controller 110 can manage user rights (e.g., user rights authentication, user rights registration, and user rights deletion) based on BAD according to security standard protocols without the control of the host device 200, and sets the NVM 120 to a locked or unlocked state, the security functions of the storage device 100 can be used (in other words, activated) even when the storage device 100 is connected to the host device 200 without providing the security command SCMD. The memory controller 110 can perform user rights authentication based on the user password received from the host device 200, and perform data encryption and decryption (in other words, self-encryption) upon successful user rights authentication, and can also perform user rights authentication based on BAD received from the biometric module 300 even when no user password is received from the host device 200.
[0031] The biometric module 300 can sense the user's liveness to obtain biometric data (e.g., fingerprint, iris, voice, etc.), and provide BAD (Biometric Data Access Detection) to the memory controller 110 based on the biometric data. The biometric module 300 can be implemented by, for example, but not limited to, recognition modules capable of obtaining biometric data (such as fingerprint recognition modules, iris recognition modules, face recognition modules, vein recognition modules, voice recognition modules, etc.).
[0032] According to one embodiment of the inventive concept, the biometric module 300 can convert biometric data into biometric information based on a set data format, and store and manage the biometric information. The biometric module 300 can store the biometric information of each user with registered user permissions in an NVM included therein. The biometric module 300 can generate a unique value based on the biometric information and send a biometric authentication message and the unique value as a BAD to the memory controller 110. In the biometric information registration operation, the biometric module 300 can send a biometric information registration message (or a biometric information registration completion message) and the unique value to the memory controller 110. When the biometric information registration message (or biometric information registration completion message) is received, the memory controller 110 can register user permissions based on the unique value. Subsequently, in the user permission authentication operation, the biometric module 300 can obtain the user's biometric data; when the biometric information based on the obtained biometric data matches the pre-stored biometric information, a unique value is generated based on the matching biometric information; and a biometric authentication success message and the unique value are sent to the memory controller 110. When a biometric authentication success message is received, the memory controller 110 can perform user authorization authentication based on a unique value.
[0033] For example, when the biometric module 300 is a fingerprint recognition module, the fingerprint recognition module can obtain a fingerprint image as biometric data by scanning the user's fingerprint, and convert the fingerprint image into fingerprint information based on a set format. The fingerprint recognition module can generate a unique value based on the fingerprint information, and send the fingerprint information registration message or fingerprint authentication success message and the unique value as a BAD to the memory controller 110. The memory controller 110 (specifically, the security access control module SACM) can register user permissions by setting a credential value based on the unique value, or perform user permission authentication based on the unique value. For example, the security access control module SACM can generate a hash value by hashing the unique value received in the BAD along with the fingerprint information registration message, and set the hash value as the credential value to register user permissions. When user permission authentication is performed, the security access control module SACM can perform user permission authentication by comparing the credential value with the hash value generated by hashing the unique value received in the BAD along with the fingerprint authentication success message.
[0034] According to one embodiment of the inventive concept, the biometric module 300 can provide biometric data, or biometric information obtained by converting biometric data into a preset data format, as BAD to the memory controller 110, and the memory controller 110 can perform at least one of user permission registration and user permission authentication based on the biometric data or biometric information.
[0035] Storage device 100 can be connected to various types of host devices 200 and operate under the control of host devices 200. Assuming that the security functions of storage device 100 are activated based on a security command SCMD received from host device 200, the security functions of storage device 100 cannot be used (or activated) when host device 200 cannot provide a security command SCMD; in other words, when the security standard protocol cannot be applied to host device 200. However, in the storage device 100 according to an embodiment of the inventive concept, memory controller 110 can configure security functions by setting a feature set according to the security standard protocol under the control of host device 200 (in other words, based on a security command SCMD from host device 200), and can also configure security functions independently by determining a feature set according to the security standard protocol based on BAD received from biometric module 300 without the control of host device 200. For example, even if the user permission request and password as the security command SCMD are not received from the host device 200, the storage device 100 can still generate security configuration data corresponding to the security command SCMD based on BAD, and perform user permission authentication by using the security configuration data. Therefore, even when the storage device 100 is connected to the host device 200 that does not provide the security command SCMD, the storage device 100 can still provide security functions. Thus, the security functions of the storage device 100 can be used even when the storage device 100 is connected to various types of host devices 200.
[0036] Figure 2A and Figure 2B This is a block diagram illustrating a method by which a memory controller 110 in a storage device 100 performs user authorization authentication based on a connected host device, according to an example embodiment of the inventive concept.
[0037] Reference Figure 2A In storage system 10a, storage device 100 can be connected to a first host device 200a, and storage device 100 and first host device 200a can communicate with each other according to a security standard protocol (e.g., TCG protocol). First host device 200a can control the configuration of security functions of storage device 100. First host device 200a can execute software for controlling the security functions of storage device 100 (e.g., self-encryption function).
[0038] The first host device 200a can send a security command SCMD to the storage device 100. The security command SCMD includes a password PW for user rights and a user rights authentication request. The security access control module SACM of the memory controller 110 can perform access authentication (i.e., user rights authentication) based on the password PW in response to the security command SCMD. When the received password PW is the password set as the credential value of the user rights during registration, the security access control module SACM can determine that the access authentication is successful. When the access authentication is successful, it locks the security provider (SP) (e.g., ...). Figure 3 A session for NVM 120 (SP2) can be opened. Storage device 100 can send a response RES indicating that the session has been opened to first host device 200a, and first host device 200a can send a setting value to storage device 100 for setting the security zone SA of NVM 120 to a locked or unlocked state. The Security Access Control Module (SACM) can change the security zone SA of NVM 120 from a locked state to an unlocked state by setting a feature set according to the security standard protocol based on the received setting value. Therefore, first host device 200a can provide a security command SCMD to storage device 100, and the memory controller 110 of storage device 100 can configure the security functions of storage device 100 by setting the security zone SA of NVM 120 to a locked or unlocked state (hereinafter referred to as locked and / or unlocked states) based on the security command SCMD received from first host device 200a.
[0039] refer to Figure 2B In storage system 10b, storage device 100 can be connected to a second host device 200b, but the second host device 200b cannot communicate with storage device 100 according to security standard protocols. In other words, the second host device 200b cannot provide security commands to storage device 100.
[0040] The Security Access Control Module (SACM) can operate without the control of a second host device 200b (e.g., when no access is received). Figure 2A In the case of the security command SCMD, user permissions are authenticated based on the BAD received from the biometric module 300.
[0041] When storage device 100 is connected to second host device 200b, the Security Access Control Module (SACM) can send a trigger signal TRIG to the biometric module 300. According to one embodiment of the inventive concept, the trigger signal TRIG can be a signal requesting the biometric module 300 to perform biometric authentication. The biometric module 300 can perform biometric authentication in response to the trigger signal TRIG. The biometric module 300 can sense the user's liveness to obtain biometric data and perform biometric authentication based on the biometric data. When biometric authentication is successful, the biometric module 300 can send a BAD (Biometric Authentication Successful) message, including a unique value and a biometric authentication success message, to the memory controller 110. According to one embodiment of the inventive concept, the trigger signal TRIG can be a signal requesting the biometric module 300 to obtain biometric data by sensing the user's liveness. The biometric module 300 can send the biometric data or biometric information generated based on the biometric data as a BAD to the memory controller 110.
[0042] The Security Access Control Module (SACM) can independently configure the security functions of the storage device 100 based on the BAD. The SACM can perform authentication of user permissions based on the BAD. When the BAD includes authentication data corresponding to the credential value of the user permission (i.e., when the unique value included in the received BAD is the same as the unique value used when the credential value of the user permission was set), the SACM can determine that the authentication is successful. When the authentication is successful, it locks the SP (e.g., Figure 3 A session (SP2) can be opened. The Security Access Control Module (SACM) can change the security zone SA of the NVM 120 from a locked state to an unlocked state through the opened session. The SACM can set the locked or unlocked state by determining a setting value corresponding to a field value of a feature set set according to a security standard protocol, which indicates the locked or unlocked state of the security zone SA of the NVM 120. In this way, the storage device 100 can configure the security functions of the storage device 100 by setting the lock / unlocked state of the security zone SA of the NVM 120 based on the BAD received from the biometric module 300 without the control of the second host device 200b. Figure 3 The management objectives of a Security Access Control Module (SACM) according to an example embodiment of the inventive concept are shown.
[0043] Reference Figure 3 Storage devices (e.g., Figure 1Storage device 100 may include multiple security providers (SPs) (e.g., a first SP SP1 and a second SP SP2), and a security access control module (SACM) may manage multiple SPs (e.g., a first SP SP1 and a second SP SP2). Storage device 100 may include a first SP SP1 and a second SP SP2, wherein the first SP SP1 is a management SP, and the second SP SP2 is a locking SP. The management SP controls information about storage device 100 and the configuration of storage device 100 and publishes other SPs. The locking SP controls the lock / unlock state of the security area (SA) of NVM 120. However, embodiments of the inventive concept are not limited thereto, and the number and configuration of SPs may vary.
[0044] The first SP SP1 and the second SP SP2 may each include a feature set table (e.g., Figure 4A The permissions table (ATB) and Figure 4B The Lock Table (LTB) and Feature Set Table include feature sets associated with access control for administrators and / or users, as well as control over lock / unlock status.
[0045] The Security Access Control Module (SACM) can, according to security standard protocols (e.g., the TCG protocol), base its access on the host device (e.g., Figure 1 (200) receive security commands to set (or change) field values of the feature set, or based on data from the biometric module (e.g., Figure 1 The 300) received BAD determines the field values of the feature set and sets (or changes) the field values of the feature set based on the determined field values.
[0046] Figure 4A and Figure 4B This is an example implementation of a feature set table configured by a security access control module according to an exemplary embodiment of the inventive concept.
[0047] Figure 4A This shows an implementation example of an Access Control Table (ATB). Figure 4B An implementation example of a Locked Table (LTB) is shown. Each of the ATB and LTB may include at least one feature set, which includes multiple fields (FDs) and setting values corresponding to each of the multiple FDs.
[0048] Reference Figure 4AATB's multiple function fields (FDs) may include, for example, a unique identifier field (UID), a name field (NM), a permission enable field (EN), an operation field (OP), and a credential field (CRD). However, this is merely an example; ATB may omit or replace any of the above fields, or further include other types of fields. The unique identifier field (UID) may indicate a setting value used to identify an object (e.g., the target of a feature set) in a corresponding table (e.g., ATB) and the SP that includes that table, and may indicate, for example, an 8-byte identifier. The name field (NM) indicates the name of the object, and in ATB, the name of the object may indicate a user (e.g., first administrator Admin1, first user User1, and second user User2). The permission enable field (EN) indicates whether the corresponding permission is activated and can be set to true (T) or false (F). The operation field (OP) indicates the authentication method to be performed based on the credential, and for example, when a password is set in the operation field (OP), permission authentication based on the password scheme may be performed based on the credential value set in the credential field (CRD). The credential field CRD indicates the authentication information used to authenticate objects used with permissions, and for example, the individual identifiers of users (C_PIN_Admin1, C_PIN_User1, C_PIN_User2) can be set as credential values. See above. Figure 2A and Figure 2B The credential value can be set based on a unique value included in the password PW received from the first host device 200a or the BAD received from the biometric module 300.
[0049] Reference Figure 4B The LTB may include multiple read / write operations (FDs), such as a unique identifier field (UID), a name field (NM), a range field (RNG), a read / write lock enable field (RWEN), a read / write lock field (RWL), etc. However, this is just an example; the LTB may omit or replace any of the above fields, or further include other types of fields. The range field RNG indicates the NVM (e.g., ...). Figure 1 The lock and unlock range for reading / writing within the secure area SA (120) is controlled, and can indicate, for example... Figure 4B The range of Logical Block Addresses (LBAs) is shown. According to one embodiment of the inventive concept, the range of read / write locking and unlocking can be controlled for each user (e.g., first administrator Admin1, first user User1, and second user User2). Figure 4B The settings shown are different. However, embodiments of the inventive concept are not limited to this, and read / write locking and unlocking can be controlled for at least one user over the entire security zone SA.
[0050] The Read / Write Lock Enable field RWEN indicates whether a lock is active for reading and / or writing an object, and the Read / Write Lock field RWL indicates the locked or unlocked state for reading and / or writing. Both the Read / Write Lock Enable field RWEN and the Read / Write Lock field RWL can be set to T or F. When the Read / Write Lock field RWL is set to T, the corresponding range is locked for reading and / or writing, thus preventing access to the corresponding range for reading and / or writing.
[0051] For example, in Figure 4B In the LTB, based on the feature set settings in the third row, for the second user User2, for the range corresponding to the fifth LBA LBA5 to the eighth LBA LBA8 in the security zone SA of NVM 120, the read / write lock is activated in response to the read / write lock enable field RWEN being set to T, and the read / write is unlocked in response to the read / write lock field RWL being set to F.
[0052] Already referred to Figure 4A and Figure 4B The examples describe ATB and LTB. However, the feature set tables set by the Security Access Control Module (SACM) are not limited to these, and the SACM can set various types of feature set tables based on security standard protocols and determine the field values of the feature sets during authorization authentication operations.
[0053] Reference Figure 3 For example, when the security functions of storage device 100 are configured under the control of host device 200, the Security Access Control Module (SACM) can receive a security command (e.g., a permission registration security command) from host device 200 during a user permission registration operation, including a user permission registration request and setting values, and set a feature set regarding user permissions based on the setting values (e.g., ...). Figure 4A Feature set FS1 in ATB and Figure 4B The feature set FS2 in the LTB. Received setting values may include, for example... Figure 4A The values of the unique identifier field UID, name field NM, permission enable field EN, and operation field OP in the feature set FS1 of the ATB, and Figure 4BThe LTB contains the unique identifier field UID, name field NM, range field RNG, read / write lock enable field RWEN, and read / write lock field RWL of the feature set FS2. In this case, the Security Access Control Module (SACM) can set the credential value of the credential field CRD based on the password received from the host device 200, and set the read / write lock field RWL to T. During user authentication, the SACM receives an authentication request, the set value of the unique identifier field UID, and the password from the host device 200 as a security command to request user authentication. The SACM performs user authentication based on the password. When user authentication is successful, it receives the set value of the read / write lock field RWL (e.g., a set value indicating F) from the host device 200, and sets the LTB's read / write lock field RWL to F based on the set value. Therefore, for a user associated with the received password, access to the range of the security zone SA of the NVM set for the user (e.g., the range indicated by the range field RNG) for reading and / or writing is permitted.
[0054] When storage device 100 is independently configured with security functions, the Security Access Control Module (SACM) can receive permission registration commands from host device 200 (or other input and / or output devices) during user permission registration operations, and from biometric modules (e.g., Figure 1 (300) Receive BAD (see ) Figure 1 Based on BAD, determine the feature set regarding user permissions (e.g., Figure 4A Feature set FS1 and in ATB Figure 4B The feature set (FS2) in the LTB is used to set the feature set based on the determined field values. In this case, the Security Access Control Module (SACM) can set the credential value of the credential field CRD based on the BAD received from the biometric module 300, and set the read / write lock field RWL to T. However, when the range is set differently for each user, the setting value of the range field RNG can be received from the host device 200 (or another input / output device), and the Security Access Control Module (SACM) can set the range field RNG based on the received setting value.
[0055] During user authentication, the Security Access Control Module (SACM) receives a BAD from the biometric module, performs user authentication based on the BAD, and sets the Read / Write Lock Field (RWL) of the LTB to F when the user authentication is successful. Thus, for the user associated with the received BAD, access to the range of the Security Zone (SA) set for the user is permitted for reading and / or writing.
[0056] As described above, in a storage device according to an embodiment of the inventive concept, the Security Access Control Module (SACM) can set (or change) the field values of the feature set according to a security standard protocol, and even when the host device 200 does not provide a setting value including a password, the Security Access Control Module (SACM) can determine the field values of the feature set according to the security standard protocol based on the BAD received from the biometric module, and set (or change) the feature set based on the determined field values.
[0057] Figure 5 This is a block diagram of a memory controller 110a according to an exemplary embodiment of the inventive concept.
[0058] Reference Figure 5 The memory controller 110a may include a processor 11, a memory 12, a security key storage unit 13, a host interface 14, a peripheral interface 15, a data processing unit 16, and a memory interface (hereinafter referred to as the NVM interface) 17. According to one embodiment of the inventive concept, the components of the memory controller 110a (e.g., processor 11, memory 12, security key storage unit 13, host interface 14, peripheral interface 15, data processing unit 16, and NVM interface 17) may communicate with each other via a system bus 18. According to one embodiment of the inventive concept, the memory controller 110a may also include other components (e.g., read-only memory (ROM), error correction circuitry, buffers, etc.).
[0059] The processor 11 may include a central processing unit (CPU), a microprocessor, etc., and controls the overall operation of the memory controller 110a. According to one embodiment of the inventive concept, the processor 11 may be implemented by a multi-core processor (e.g., a dual-core processor or a quad-core processor).
[0060] Memory 12 may be implemented using volatile memory (such as dynamic random access memory (DRAM), static random access memory (SRAM), or NVM), and firmware may be loaded onto memory 12. The firmware may include program code (or instructions) for implementing the operating algorithm of the aforementioned Security Access Control Module (SACM). The firmware may be stored internally or externally in an NVM (e.g., ROM, electrically erasable programmable read-only memory (EEPROM), phase-change random access memory (PRAM), flash memory, etc.) of memory controller 110a, or stored in NVM 120, and when the storage device (e.g., Figure 1 When the processor 11 powers on, the firmware loaded into the memory 12 is stored. When the processor 11 executes the firmware loaded into the memory (e.g., a security access control module SACM), the security functions of the storage device 100 can be performed. For example, the security access control module SACM can encrypt or decrypt security keys, and the security key storage unit 13 can store encrypted security keys.
[0061] According to one embodiment of the inventive concept, when multiple user permissions are registered, multiple encrypted security keys, each encrypted with a unique value or password corresponding to a user permission, can be stored. The security key storage unit 13 can be implemented using an NVM (such as a register, PRAM, or flash memory).
[0062] Host interface 14 provides an interface between host device 200 and storage controller 110a, and host interface 14 may be implemented by one of various interfaces such as Universal Serial Bus (USB) interface, Universal Flash (USF) interface, Multimedia Controller (MMC) interface, Embedded MMC (eMMC) interface, Fast Peripheral Component Interconnect (PCIe) interface, Advanced Technology Attachment (ATA) interface, Serial Advanced Technology Attachment (SATA) interface, Parallel Advanced Technology Attachment (PATA) interface, Small Computer System Interface (SCSI), Serial Attached SCSI (SAS), Enhanced Small Disk Interface (ESDI), and Electronic Integrated Drive (IDE) interface.
[0063] Peripheral interface 15 provides an interface between storage controller 110a and biometric module 300. For example, peripheral interface 15 may provide a communication interface such as a Universal Asynchronous Receiver Transmitter (UART) interface, an Internal Integrated Circuit (I2C) interface, a Serial Peripheral Interface (SPI), a Mobile Industry Processor Interface (MIPI), or an Embedded Display Port (eDP) interface.
[0064] Peripheral interface 15 can send trigger signals (e.g., biometric authentication trigger signals or biometric registration trigger signals) for operating biometric module 300. Furthermore, peripheral interface 15 can receive biometric authentication messages and unique values from biometric module 300. For example, biometric information registration messages or biometric authentication result messages (e.g., biometric authentication success or biometric authentication failure) messages can be received as biometric authentication messages.
[0065] Data processing unit 16 can encrypt or decrypt user data. Data processing unit 16 can encrypt or decrypt user data based on a security key. Data processing unit 16 can encrypt user data received from host device 200 based on a security key. For example, data processing unit 16 can scramble user data based on a security key. The encrypted user data can be stored in NVM 120. Data processing unit 16 can decrypt encrypted user data read from NVM 120 based on a security key. For example, data processing unit 16 can descramble encrypted user data based on a security key. The decrypted user data can be sent to host device 200.
[0066] NVM interface 17 provides an interface between memory controller 110a and NVM 120. Encrypted user data can be sent and received between memory controller 110a and NVM 120 via NVM interface 17. According to one embodiment of the inventive concept, the number of NVM interfaces 17 may correspond to the number of NVM chips included in storage device 100 or the number of channels between memory controller 110a and NVM 120.
[0067] Figure 6 This is a flowchart illustrating a method for operating a storage device based on received biometric authentication data, according to an exemplary embodiment of the inventive concept. Figure 7 This shows an example of a data format based on a security standard protocol.
[0068] Figure 6 The operation method can be provided by Figure 1 The storage device 100 is used to execute the above description of the storage device 100, and the above description of the storage device 100 can be applied to... Figure 6 Examples of implementations.
[0069] Reference Figure 1 and Figure 6 In operation S10, the storage device 100 may receive a BAD from the biometric module 300. The BAD may include biometric data generated by sensing the user's liveness, or biometric information generated based on the biometric data. Optionally, the BAD may include a unique value based on the biometric information and the biometric authentication result.
[0070] In operation S20, storage device 100 can convert BAD into secure configuration data according to a security standard protocol (e.g., Figure 7 (SCSD). The security configuration data may have the same data format as the security commands that can be received from the host device 200. The Security Access Control Module (SACM) of the memory controller 110 can be used as a parser to generate the security configuration data (SCSD) based on the BAD.
[0071] Reference Figure 7 Data formats according to security standard protocols (e.g., the TCG protocol) may have data blocks comprising multiple bytes. For example, a data format according to the TCG protocol may include 16 rows of R (e.g., 0000 to 01F0 represented by hexadecimal numbers), and each row may include 16 bytes of data. Therefore, security configuration data SCSD and security commands may include data blocks (or packets) of 512 bytes. The meaning (or purpose) of each of the single-byte or multi-byte data values included in each row is defined by the security standard protocol and may indicate field values according to the feature set of the security standard protocol.
[0072] For example, when the Security Configuration Data SCSD corresponds to a security command used to request the locking of the SP, the Security Access Control Module (SACM) can set a total of 17 bytes of data value (i.e., “3C 41 64 6D 69 6E 31 5F 70 61 73 73 77 6F 72 643E”) based on the unique value of BAD, including the 5 least significant bytes (or the 5 bytes on the right) of the sixth line (0050) and the 12 most significant bytes (or the 12 bytes on the left) of the seventh line (0060), as the password according to the security standard protocol.
[0073] Return to reference Figure 6 In operation S30, storage device 100 can perform user authentication based on security configuration data SCSD. When the password of security configuration data SCSD is the same as the credential value of the user permission set when registering the user permission, security access control module SACM can determine that the permission authentication is successful. In operation S40, storage device 100 can open a session. For example, when the permission authentication for the user permission is successful, security access control module SACM can open (or start) a session with the locked SP.
[0074] In operation S50, storage device 100 can set the lock / unlock state of the security zone SA of NVM 120. For example, the security access control module SACM can set the lock / unlock state by determining the field value (or setting value) of the read / write lock field RWL via the session.
[0075] In operation S60, storage device 100 may be configured to shadow the master boot record. For example, through a session, the security access control module SACM may configure the master boot record table to read the master boot record included in the secure region SA (here referred to as master boot record unshadowing), or configure the master boot record table to read the master boot record included in the non-secure region (here referred to as master boot record shadowing).
[0076] For example, the Security Access Control Module (SACM) can set the storage device 100 to an unlocked state by setting the Read / Write Lock field (RWL) to F in operation S50 and setting the Master Boot Record table in operation S60 to read the Master Boot Record included in the Security Area (SA).
[0077] In operation S70, storage device 100 can terminate the session. The Security Access Control Module (SACM) can configure security functions (e.g., set storage device 100 to an unlocked state) and then terminate the session.
[0078] Figure 8A and 8B This is a diagram illustrating a user access authentication method for a storage system based on an example embodiment of the inventive concept.
[0079] Figure 8A This is shown as including in storage devices (e.g., Figure 1 In the case where the memory controller 110 in (100) configures security functions by independently performing user authorization authentication without the control of the host device 200, Figure 8B This illustrates a scenario where the memory controller 110, under the control of the host device 200, configures security functions by performing user authorization authentication. For example, Figure 2B The main unit 200b can be used as Figure 8A The main unit 200, Figure 2A The main unit 200a can be used as Figure 8B The main unit 200.
[0080] Reference Figure 8A In operation S111, storage device 100 is connected (or linked) to host device 200, and in this case, storage device 100 can be set to a locked state in operation S112. Storage device 100 can be set to a locked state when it is disconnected from host device 200 or powered off, and thereafter, even when storage device 100 is connected to host device 200 as in operation S111, storage device 100 remains locked. When storage device 100 is locked, memory controller 110 can set the read and / or write states of the secure region SA of NVM 120 to a locked state and provide information about non-secure regions (e.g., shadow master boot record) to host device 200. For example, memory controller 110 can provide information about non-secure regions (e.g., shadow master boot record) to host device 200. Figure 4B The read / write lock field RWL in the LTB is set to T, which locks the read and / or write status of the secure region SA of the NVM 120, and sets the value of the Master Boot Record table to indicate the masked Master Boot Record stored in the non-secure region. The host device 200 can access the non-secure region based on the masked Master Boot Record.
[0081] In operation S113, the memory controller 110 may send a biometric authentication trigger signal to the biometric module 300 for requesting biometric authentication. When the storage device 100 is connected to the host device 200, the memory controller 110 may automatically send the biometric authentication trigger signal to the biometric module 300, in other words, independently of the control of the host device 200.
[0082] In operation S121, the biometric module 300 can perform biometric authentication in response to a biometric authentication trigger signal. The biometric module 300 can obtain biometric data by sensing the user's liveness. According to one embodiment of the inventive concept, the biometric module 300 can generate biometric information based on the biometric data, and determine that biometric authentication is successful when the biometric information matches pre-stored biometric information.
[0083] In operation S122, the biometric module 300 may send a BAD to the memory controller 110. The user's biometric data (or biometric information) may be sent to the memory controller 110 as a BAD, or a unique value generated based on the biometric information and a biometric authentication success message may be sent to the memory controller 110 as a BAD. For example, as described in operation S121, when determining whether biometric authentication is successful based on whether the biometric information generated from the biometric data obtained through the biometric module 300 matches pre-stored biometric information, a unique value and a biometric authentication success message may be sent to the memory controller 110 as a BAD.
[0084] In operation S114, the memory controller 110 may perform user authorization authentication based on biometric data. For example, the memory controller 110 may perform user authorization authentication based on a unique value. (See reference...) Figure 6 As described, the memory controller 110 can generate security configuration data with a data format according to a security standard protocol based on BAD (e.g., unique value), and perform user authorization authentication based on the security configuration data.
[0085] In operation S115, the memory controller 110 can determine whether user authorization authentication was successful. The memory controller 110 can determine successful user authorization authentication when the password for the security configuration data generated based on BAD is the same as the credential value of the user authorization set when the user authorization was registered. In this case, the password for the security configuration data can be the hash value of the unique value of BAD.
[0086] When user authentication is successful, the memory controller 110 can set the storage device 100 to an unlocked state in operation S116. The memory controller 110 can also set the read and / or write status of the security zone SA of the NVM 120 to an unlocked state and provide information about the security zone SA to the host device 200. For example, the memory controller 110 can do so by... Figure 4BThe read / write lock field RWL in the LTB is set to F to unlock the read and / or write status of the security region SA (or a specific range corresponding to a unique value in the security region SA) of the NVM 120, and the value of the Master Boot Record (MBR) is set to indicate the MBR stored in the security region SA. The host device 200 can access the security region SA of the NVM 120 based on the MBR. The host device 200 can send a command to the memory controller 110 requesting a write or read operation of the security region SA for which user authorization authentication has been performed, and the memory controller 110 can encrypt user data to be stored in the security region SA based on a security key and store the encrypted user data, or decrypt encrypted user data read from the security region SA based on a security key and send the decrypted user data to the host device 200.
[0087] According to one embodiment of the inventive concept, when the storage device 100 changes from a locked state to an unlocked state, a relink between the host device 200 and the storage device 100 can be performed, after which the host device 200 can access the security zone SA of the NVM 120.
[0088] When user authentication fails, storage device 100 can be locked in operation S112. In other words, storage device 100 can remain locked, and host device 200 can access the non-secure zone of NVM 120, but cannot access the secure zone SA of NVM 120.
[0089] Reference Figure 8B In operation S211, the storage device (e.g., Figure 1 The storage device 100 is connected to the host device 200, and in this case, the storage device 100 can be set to a locked state in operation S212.
[0090] In operation S231, the host device 200 can execute software to provide security functions for the storage device 100. For example, the operating system of the host device 200 can execute self-encrypting drive (SED) support software for the storage device 100. Therefore, the host device 200 can communicate with the storage device 100 according to security standard protocols.
[0091] In operation S232, host device 200 may send a security command, including a user authentication request and a password, to memory controller 110. The security command may be defined by a security standard protocol, and the password may have a value generated through user input. For example, the security command may be a command to request session opening according to a security standard protocol. The security command may include a 512-byte data block (or data packet).
[0092] In operation S213, the memory controller 110 may perform user authentication based on the password received from the host device 200. In operation S214, the memory controller 110 may determine whether the user authentication was successful. The memory controller 110 may determine whether the received password is the same as the password used when setting the credential value for user permissions.
[0093] When user authentication is successful, in operation S215, the memory controller 110 may send a response corresponding to the security command to the host device 200. For example, the response may indicate that a session has been opened.
[0094] In operation S233, the host device 200 may send a security command to the memory controller 110, including a setting value for setting the storage device 100 to an unlocked state. In operation S216, the memory controller 110 may set the storage device 100 to an unlocked state based on the received security command. When user authentication fails, the storage device 100 may be set to a locked state in operation S212. In other words, the storage device 100 may remain in a locked state.
[0095] For reference Figure 8A and Figure 8B As described, when storage device 100 is connected to host device 200, memory controller 110 can convert BAD from biometric module 300 into security configuration data with a data format according to a security standard protocol, and perform user authentication without the control of host device 200. Optionally, memory controller 110 can perform user authentication based on security commands from host device 200. In this way, storage device 100 can set security functions by performing user authentication under the control of host device 200, and can also independently set security functions by performing user authentication based on BAD from biometric module 300 without the control of host device 200, thus improving the availability of security functions of storage device 100.
[0096] Figure 9 A method for setting the lock and unlock states of an NVM120, performed by a security access control module (SACM), according to an example embodiment of the inventive concept, is shown. Figure 9 This illustrates a method performed by the Security Access Control Module (SACM) to set the locked and unlocked states by setting the Master Boot Mask.
[0097] Reference Figure 9The NVM 120 may include a secure area (SA) and a non-secure area (NSA). The secure area (SA) is an area where encrypted user data is stored and may be referred to as a user area. The secure area (SA) may be divided into multiple user areas (e.g., multiple partitions or volumes). The non-secure area (NSA) is a predefined specific area and may be referred to as, for example, a reserved area. According to one embodiment of the inventive concept, each of the secure area (SA) and the non-secure area (NSA) may have multiple ranges based on LBA settings. In each of the secure area (SA) and the non-secure area (NSA), a Master Boot Record (MBR) including information about the respective area (e.g., partition or volume information, boot code for booting, etc.) may be stored. According to one embodiment of the inventive concept, the MBR may indicate a first MBR stored in the secure area (SA), and the masked MBR (SMBR) may indicate a second MBR stored in the non-secure area (NSA).
[0098] When the secure area SA is set to the unlocked state after successful user authentication, the secure area SA is accessible, and the non-secure area NSA is accessible regardless of user authentication. In the initial state of storage device 100 connected to host device 200 (i.e., before performing user authentication), the NVM may be in a locked state, and the security access control module SACM may set the MBR table so that the SMBR in the non-secure area NSA can be read. For example, the setting value in the MBR table may indicate the position of the pointer of NVM 120, and the locked pointer may indicate the LBA of its stored SMBR. Therefore, the SMBR can be loaded into the memory controller ( Figure 1 On the 110), the host device 200 can read data stored in the non-secure area NSA based on information included in the SMBR. For example, in the non-secure area NSA, the SMBR and software (e.g., software supporting user configuration or SED support software) may be stored.
[0099] When user authentication is successful, the security zone SA can be set to the unlocked state, and the security access control module SACM can set the MBR table so that the MBR in the security zone SA can be read. For example, based on the setting value in the MBR table, a pointer can be directed to the LBA where the MBR is stored. Therefore, the MBR can be loaded onto the memory controller 110, and the host device 200 can read the data (e.g., user data) stored in the security zone SA based on the information included in the MBR.
[0100] Figure 10A and Figure 10B This illustrates multiple user permissions for a secure zone SA of an NVM 120 that can be accessed according to an example embodiment of the inventive concept.
[0101] Reference Figure 10A and Figure 10B The security zone SA of the NVM 120 can be accessed by multiple users who have set user permissions for it, and the zones that each user can access can be set uniformly or differently.
[0102] Reference Figure 10A First user User1 and second user User2 may have user permissions that allow access to the entire security zone SA (e.g., global range). When user permission authentication for first user User1 or second user User2 is successful (e.g., when authentication is successful based on the BAD of first user User1 or second user User2), read and / or write access to the entire security zone SA is set to an unlocked state, and in response to the host device ( Figure 1 The request of 200), memory controller ( Figure 1 (110) can access the secure area SA for reading and / or writing.
[0103] Reference Figure 10B User1 (first user) may have user permissions to access a first range (Range 1), User2 (second user) may have user permissions to access a second range (Range 2), and User3 (third user) may have user permissions to access both the second and third ranges (Range 2 and Range 3). When user permission authentication for User1 is successful, User1's read and / or write permissions for the first range (Range 1) may be unlocked. Similarly, when user permission authentication for User2 is successful, User2's read and / or write permissions for the second range (Range 2) may be unlocked. Furthermore, when user permission authentication for User3 is successful, User3's read and / or write permissions for both the second and third ranges (Range 2 and Range 3) may be unlocked.
[0104] Figure 11 This is a diagram illustrating a user permission registration method for a storage system based on an example embodiment of the inventive concept. Figure 11 The method is based on BAD registration user permissions, and can be used by... Figure 1 The storage system 10 will execute. (Refer to...) Figure 1 Describe together Figure 11 .
[0105] Reference Figure 11In operation S331, the host device 200 may send a registration command for requesting user permission registration to the memory controller 110. In operation S311, the memory controller 110 may, in response to the registration command, send a registration trigger signal for requesting biometric information registration to the biometric module 300.
[0106] In operation S321, the biometric module 300 can store the user's biometric information. In response to a registration trigger signal, the biometric module 300 can obtain biometric data by sensing the user's liveness and generate biometric information based on the biometric data. The biometric module 300 can register the user's biometric information by storing the biometric information. In other words, the biometric module 300 can manage the user's biometric information.
[0107] In operation S322, the biometric module 300 may send a BAD to the memory controller 110. The biometric module 300 may send a message indicating that biometric information registration is complete and a BAD based on the unique value of the biometric information (e.g., the hash value of the biometric information).
[0108] In operation S312, the memory controller 110 can set user permissions based on BAD. (See reference...) Figure 3 As described, the Security Access Control Module (SACM) can determine a set of features regarding user permissions based on BAD (e.g., Figure 4A Feature set FS1 and in ATB Figure 4B The feature set (FS2) in the LTB is used to set field values, and the feature set is set based on the determined values. For example, the Security Access Control Module (SACM) can set the name of the user permission and set the credential value of the user permission based on the unique value of the BAD. According to one embodiment of the inventive concept, the Security Access Control Module (SACM) can generate security configuration data with a data format according to a security standard protocol based on the BAD, and set user permissions based on the security configuration data.
[0109] In operation S313, the memory controller 110 can activate user rights. For example, the security access control module (SACM) can activate user rights by setting the permission enable field EN in the ATB to T. In operation S314, the memory controller 110 can lock the storage device 100. For example, the security access control module (SACM) can set the read / write lock field RWL in the LTB to T. In operation S315, the memory controller 110 can send a registration completion response to the host device 200. Therefore, user rights registration can be completed.
[0110] However, although the storage of user biometric information by the biometric module 300 has been described in operation S321, embodiments of the inventive concept are not limited thereto, and according to one embodiment of the inventive concept, the biometric module 300 can obtain biometric data by sensing the user's liveness and send the biometric data as BAD to the memory controller 110. The biometric module 300 neither stores biometric data nor biometric information. In this case, the biometric module 300 only performs the function of obtaining the user's biometric data, and the memory controller 110 can generate and store biometric information based on the biometric data. In other words, the memory controller 110 can register and manage the user's biometric information. The memory controller 110 can generate a unique value based on the generated biometric information and set a credential value based on the unique value.
[0111] Despite Figure 11 The example embodiment shows the memory controller 110 performing user permission registration in response to a request from the host device 200. However, the example embodiment of the inventive concept is not limited to this, and according to the embodiment of the inventive concept, the memory controller 110 may perform user permission registration in response to a request from an input / output device included in the storage system 10 instead of the host device 200. For example, the storage device 100 may include an input / output device with a user interface, and in operation S331, the memory controller 110 may receive a signal requesting user permission registration from the input / output device instead of the host device 200. Furthermore, in operation S315, the memory controller 110 may send a registration completion response to the input / output device.
[0112] Figure 12 This is a diagram illustrating a method for deleting user permissions in a storage system according to an example embodiment of the inventive concept. Figure 12 The method is to remove user permissions, and this can be done by... Figure 1 The storage system 10 will execute. (Refer to...) Figure 1 Describe together Figure 12 .
[0113] Reference Figure 12In operation S431, the host device 200 may send a delete command to the memory controller 110 to request the deletion of user permissions. In operation S411, the memory controller 110 may, in response to the delete command, send a delete trigger signal to the biometric module 300 to request the deletion of biometric information (or biometric data). When the biometric module 300 stores multiple biometric information entries, the delete command sent from the host device 200 to the memory controller 110 may include an index indicating the biometric information to be deleted, and the memory controller 110 may send the index along with the delete trigger signal to the biometric module 300.
[0114] In operation S421, the biometric module 300 may delete stored biometric information in response to a deletion trigger signal. The biometric module 300 may delete the indexed biometric information from among multiple biometric information entries. In operation S422, the biometric module 300 may send a deletion completion message to the memory controller 110.
[0115] In operation S412, the memory controller 110 can disable user rights. For example, the security access control module SACM can disable user rights by setting the permission enable field EN in the ATB to F. In operation S413, the memory controller 110 can delete user rights by deleting the name of the user rights. In operation S424, the memory controller 110 can send a deletion completion response to the host device 200. Therefore, the deletion of user rights can be completed.
[0116] Despite Figure 12 The example embodiment shows the memory controller 110 performing user permission deletion in response to a request from the host device 200. However, the example embodiment of the inventive concept is not limited thereto, and according to one embodiment of the inventive concept, the memory controller 110 may perform user permission deletion in response to a request from an input / output device (instead of the host device 200) included in the storage system 10, and send a user permission deletion completion response to the input / output device.
[0117] Figure 13 This is a block diagram of a biometric module 300a according to an exemplary embodiment of the inventive concept.
[0118] Reference Figure 13 The biometric module 300a may include a sensor 310, a controller 320, a storage unit 330, and an interface 340.
[0119] Sensor 310 can acquire biometric data by sensing the user's liveness. For example, when sensor 310 is implemented as a fingerprint sensor, the fingerprint sensor can generate (or acquire) a fingerprint image by sensing the fingerprint of the user's finger. Sensor 310 can acquire the user's biometric data when it receives a trigger signal (e.g., a biometric authentication trigger signal or a biometric registration trigger signal) from memory controller 110.
[0120] Controller 320 can generate and manage biometric information AUIF. Controller 320 can store, manage, and delete biometric information AUIF. Furthermore, controller 320 can perform biometric authentication. Controller 320 can convert biometric data into template data based on a set data format (i.e., biometric information AUIF). In a storage device (e.g., ...), Figure 1 In the user permission registration operation of (100), the controller 320 can register the biometric information AUIF by storing the biometric information AUIF in the storage unit 330 as the biometric information AUIF_R.
[0121] Storage unit 330 can be implemented using NVM and can retain the stored biometric information AUIF_R even if the power applied to the biometric module 300a is interrupted. When biometric registration is performed for multiple users, storage unit 330 can store biometric information AUIF_R for each of the multiple users.
[0122] When user authentication is performed, controller 320 can perform biometric authentication based on biometric information AUIF generated by sensing the user's liveness, and when biometric authentication is successful, it sends a BAD based on the biometric information AUIF to memory controller 110. Controller 320 can determine whether the biometric information AUIF matches the biometric information AUIF_R stored in storage unit 330 by comparing the biometric information AUIF with one of the stored biometric information AUIF_R, and determine that biometric authentication is successful when the biometric information AUIF matches one of the stored biometric information AUIF_R.
[0123] The controller 320 can also generate a unique value UNQV based on the biometric information AUIF. For example, the controller 320 can generate a unique value UNQV by encoding the biometric information AUIF. The unique value UNQV can have a data format that is recognizable by both the biometric module 300a and the memory controller 110; for example, the unique value UNQV can include ten bytes of hash data.
[0124] When a trigger signal requesting the deletion of biometric information is received from the memory controller 110, the controller 320 may delete the user's biometric data. According to one embodiment of the inventive concept, when multiple biometric information entries AUIF_R are stored in the storage unit 330, the controller 320 may delete the corresponding biometric information entry AUIF_R based on an index received along with the trigger signal, indicating the biometric information entry AUIF_R to be deleted.
[0125] The controller 320 can be implemented by a combination of a processor (such as a microcontroller (MCU) or a central processing unit (CPU)) and firmware or hardware logic (such as a field programmable gate array (FPGA)).
[0126] Interface 340 may receive trigger signals (e.g., biometric registration trigger signals or biometric authentication trigger signals) from memory controller 110 and send biometric authentication messages MSG and unique values UNQV to memory controller 110. For example, interface 340 may provide a communication interface (such as a UART interface, I2C interface, SPI interface, MIPI interface, or eDP interface).
[0127] Figure 14 This is a block diagram of a storage device 100c and a storage system 10c according to an exemplary embodiment of the inventive concept.
[0128] Reference Figure 14 The storage system 10c may include a storage device 100c and a host device 200. The storage device 100c may include a memory controller 110, an NVM 120, and a biometric module 300.
[0129] The configuration and operation of storage system 10c can be similar to Figure 1 The configuration and operation of the storage system 10. However, according to Figure 14 In one embodiment, the biometric module 300 may be included in the storage device 100c. According to one embodiment of the inventive concept, Figure 13 The biometric module 300a can be like Figure 14The biometric module 300 is used in the same way as described above. The biometric module 300 can store and manage biometric information, and provides a BAD containing a unique value based on the biometric information to the memory controller 110 during user registration and authentication operations. However, the biometric module 300 is not limited to this; it can also acquire biometric data by sensing the user's liveness and provide this data to the memory controller 110. The memory controller 110 can convert the biometric data into biometric information and store and manage this information. The memory controller 110 can generate a unique value based on the biometric information that will be used during user registration and authentication.
[0130] Figure 15 This is a block diagram of a storage device 100d and a storage system 10d according to an exemplary embodiment of the inventive concept.
[0131] Reference Figure 15 The storage system 10d may include a storage device 100d and a host device 200, and the storage device 100d may include a memory controller 110, an NVM 120, and an input / output device 130. The configuration and operation of the storage system 10d can be similar to... Figure 1 The configuration and operation of the storage system 10. However, according to Figure 15 In one embodiment, storage device 100d may include input / output device 130, and security functions may be configured based on user input and / or BAD received through input / output device 130.
[0132] Input / output device 130 can receive user input and send it to memory controller 110. For example, input / output device 130 can be implemented as a touchscreen, a screen including functions for sensing user biometric data (e.g., fingerprint, iris, face, etc.). Through input / output device 130, a user's password or BAD can be received, and input / output device 130 can send the password or BAD to memory controller 110. Security access control module SACM can configure security functions by setting user permissions or performing user permission authentication based on the received password or BAD.
[0133] According to one embodiment of the inventive concept, the input / output device 130 can receive user requests (e.g., user permission registration, user permission authentication, user permission deletion, etc.) and send the user requests to the memory controller 110 through a user interface. The memory controller 110 can then perform user permission registration, user permission authentication, user permission deletion, etc. in response to the user requests.
[0134] Figure 16This is a block diagram of an electronic system based on an exemplary embodiment of the inventive concept.
[0135] Reference Figure 16 The computing system 1000 may include a memory system 1100, a processor 1200, RAM 1300, input / output devices 1400, a power supply 1500, and a biometric module 1600. Although in Figure 16 Although not shown, the computing system 1000 may also include ports for communicating with video cards, sound cards, memory cards, USB devices, etc., or ports for communicating with other electronic devices. The computing system 1000 may be implemented by a PC, by a portable electronic device (such as a laptop computer, cellular phone, PDA, or camera), or by an electronic device installed in a vehicle such as a car, airplane, or ship.
[0136] Processor 1200 can perform specific calculations or tasks. According to one embodiment of the inventive concept, processor 1200 may include a microprocessor or CPU. Processor 1200 can communicate with RAM 1300, input / output device 1400, and memory system 1100 via bus 1700, which includes address bus, control bus, data bus, etc. Processor 1200 may also be connected to an expansion bus (such as a peripheral component interconnect (PCI) bus).
[0137] The memory system 1100 and the biometric module 1600 can be used Figure 1 and Figure 12 The storage device 100 and biometric module 300 shown are used to implement this. The memory system 1100 may include a storage device supporting self-encryption. The memory system 1100 may include a memory device 1110 and a memory controller 1120. The memory device 1110 may include non-volatile memory. When the processor 1200 provides security commands and setting values (e.g., passwords) according to a security standard protocol, the memory controller 1120 may perform at least one of user permission registration and user permission authentication based on the security commands and setting values received from the processor 1200. Alternatively, when the processor 1200 neither provides security commands nor setting values, the memory controller 1120 may independently perform user permission registration and user permission authentication based on BAD received from the biometric module 1600.
[0138] RAM 1300 stores data required to operate the computing system 1000. For example, RAM 1300 may be implemented using DRAM, mobile DRAM, SRAM, PRAM, ferroelectric RAM (FRAM), resistive RAM (RRAM), and / or MRAM. Input / output device 1400 may include input devices or input interfaces (such as a keyboard, keypad, or mouse) and output devices or output interfaces (such as a printer or monitor). Power supply 1500 provides the operating voltage required to operate the computing system 1000.
[0139] Figure 17 This is a block diagram of a solid-state drive (SSD) 2200 and an SSD system 2000 including the SSD 2200, according to an example embodiment of the inventive concept.
[0140] Reference Figure 17 The SSD system 2000 may include a host device 2100, an SSD 2200, and a biometric module 2300. According to one embodiment of the inventive concept, the biometric module 2300 may be included in the SSD 2200.
[0141] The SSD 2200 can send the signal SGL to the host device 2100 and receive the signal SGL from the host device 2100 via the signal connector SC, and receive power PWR from the host device 2100 via the power connector PC.
[0142] The SSD 2200 may include an SSD controller 2210 and multiple NVM 2220, 2230 and 2240. Figure 1 , Figure 14 and Figure 15 Storage devices 100, 100c, and 100d can be applied to SSD 2200, and memory controller 110 can be applied to SSD controller 2210. SSD controller 2210 can communicate with multiple NVMs (e.g., NVM1 2220, NVM2 22230, NVMn 2240, where n is an integer greater than 1) via multiple channels CH1, CH2, ... CHn. SSD controller 2210 can configure security functions under the control of host device 2100 by performing user permission registration or authentication based on security commands and setting values received from host device 2100, or independently based on BAD received from biometric module 2300. Therefore, SSD controller 2210 can perform communication to provide security functions according to security standard protocols, regardless of whether SSD controller 2210 is connected to host device 2100 that provides security commands and setting values associated with security functions, or connected to host device 2100 that neither provides security commands nor setting values.
[0143] The storage systems 10, 10c, and 10d according to the above embodiments of the inventive concept can be installed or applied not only to the SSD system 2000, but also to memory card systems, computing systems, UFS, etc.
[0144] According to one example embodiment, at least one of the components, elements, modules, or units described herein can be implemented as various numbers of hardware, software, and / or firmware structures that perform their respective functions. For example, at least one of these components, elements, or units can use a direct circuit structure (such as a memory, processor, logic circuit, lookup table, etc.) that can perform its respective function under the control of one or more microprocessors or other control devices. Furthermore, at least one of these components, elements, or units can be specifically implemented by a module, program, or portion of code and executed by one or more microprocessors or other control devices, the module, program, or portion of code containing one or more executable instructions for performing a particular logical function. Additionally, at least one of these components, elements, or units may also include or be implemented by a processor (such as a central processing unit (CPU), microprocessor, etc., performing its respective function). Two or more of these components, elements, or units can be combined into a single component, element, or unit, with the single component, element, or unit performing all the operations or functions of the combined two or more components, elements, or units. Furthermore, at least a portion of the function of at least one of these components, elements, or units can be performed by another of these components, elements, or units. Furthermore, although a bus is not shown in the block diagram, communication between components, elements, or units can be performed via a bus. The functional aspects of the above example embodiments can be implemented as algorithms executed on one or more processors. Moreover, the components, elements, or units represented by blocks or processing steps can employ techniques from any number of related fields used in electronic configuration, signal processing and / or control, data processing, etc.
[0145] Although the inventive concept has been specifically shown and described with reference to exemplary embodiments thereof, it will be understood that various changes in form and detail may be made herein without departing from the spirit and scope of the claims.
Claims
1. A memory controller for controlling non-volatile memory, the memory controller comprising: The secure access control module is configured to convert first biometric authentication data received from the biometric module into first secure configuration data with a data format according to a security standard protocol, and is configured to perform user permission registration based on the first secure configuration data, wherein user permissions are set for access control of a secure area of non-volatile memory, and encrypted user data is stored in the secure area. and The data processing unit is configured to: encrypt user data received from the host device or decrypt encrypted user data read from the secure zone, based on whether access to the secure zone is permitted. Among them, based on the connection of the storage device to the host device, the security access control module is also configured as follows: Send the authentication trigger signal to the biometric module. The system receives second biometric authentication data from the biometric module. This second biometric authentication data includes the biometric authentication result and a unique value based on the user's biometric data. Based on the unique value of the second biometric authentication data, second security configuration data with a data format conforming to security standard protocols is generated, and When the password for the second security configuration data is the same as the credential value for the user permissions set when the user permission registration is executed, the user permission authentication is confirmed to be successful.
2. The memory controller according to claim 1, wherein, The secure access control module is also configured to determine the field values of the feature set according to the security standard protocol based on the first biometric authentication data and the second biometric authentication data, respectively, for user permissions.
3. The memory controller according to claim 2, wherein, The feature set corresponds to at least one of the multiple security providers within a trusted computing organization.
4. The memory controller according to claim 1, wherein, The first security configuration data and the second security configuration data are each implemented using 512-byte data blocks according to the security standard protocol.
5. The memory controller according to claim 1, wherein, The security access control module is also configured to: open a session based on successful authorization authentication, lock and / or unlock the security area of non-volatile memory through the session, and set the master boot record mask.
6. The memory controller according to claim 1, wherein, The security access control module is also configured to allow access to the secure zone by setting the write and read states of the secure zone to unlocked upon successful authorization authentication.
7. The memory controller according to claim 6, wherein, The security access control module is also configured to set the master boot record table so that the first master boot record included in the secure area of non-volatile memory can be read.
8. The memory controller according to any one of claims 1-7, wherein, The secure access control module is also configured to send a registration trigger signal to the biometric module in response to receiving a user permission registration request, wherein the registration trigger signal requests the biometric module to store the user's biometric data.
9. The memory controller according to claim 8, wherein, The secure access control module is also configured to perform permission registration by setting credential values for user permissions based on first biometric authentication data and activating user permissions.
10. The memory controller of claim 9, wherein the secure access control module is further configured to: set the write and read states of the secure area to a locked state based on user permission activation, and set the master boot record table such that a second master boot record included in the non-secure area of the non-volatile memory is read.
11. The memory controller according to any one of claims 1-7, wherein, The security access control module is also configured to perform permission registration based on user permission registration requests received from the host device.
12. The memory controller according to any one of claims 1-7, wherein, The secure access control module is also configured to perform permission registration based on user permission registration requests received from input and / or output devices independent of the host device.
13. The memory controller according to any one of claims 1-7, wherein, The secure access control module is also configured to: in response to receiving a user permission deletion request, send a deletion trigger signal to the biometric module, and disable the user permission based on the deletion completion message received from the biometric module, wherein the deletion trigger signal requests the biometric module to delete the user's biometric data.
14. A storage device, comprising: Non-volatile memory, including a secure area for storing encrypted user data; and The memory controller is configured to: perform permission authentication by determining field values of a first set of features based on biometric authentication data according to a security standard protocol for user permissions used to access the secure area, and set the secure area of the non-volatile memory to an unlocked state upon successful permission authentication. Wherein, based on the connection of the storage device to the host device, the memory controller is further configured to: Send the authentication trigger signal to the biometric module. The system receives biometric authentication data from the biometric module. This data includes the biometric authentication result and a unique value based on the user's biometric data. Based on the unique value of biometric authentication data, secure configuration data with a data format conforming to security standard protocols is generated, and The authentication is successful when the password for the security configuration data matches the credential value for the user permissions set during the user permission registration process.
15. The storage device according to claim 14, wherein, The memory controller is also configured to: in response to a user rights registration command received from the host device, set the credential value of the user rights based on biometric authentication data, and activate the user rights.
16. The storage device according to any one of claims 14-15, wherein, The memory controller is also configured to determine the field values of the second feature set according to a security standard protocol, and the lock and unlock states of the secure areas of the non-volatile memory are controlled based on the field values of the second feature set.
17. A storage device, comprising: Non-volatile memory, including a secure area for storing encrypted user data; and The memory controller is configured to control non-volatile memory. The memory controller is also configured as follows: When the storage device is connected to the first host device, authentication of the user with access rights to the secure area is performed based on a password received from the first host device according to a security protocol. This security protocol is set for communication with the first host device. When the storage device is connected to the second host device, permission authentication is performed based on the biometric authentication data received from the biometric module. The process of performing authorization authentication based on biometric authentication data received from the biometric module includes: Send the authentication trigger signal to the biometric module. The system receives biometric authentication data from the biometric module. This data includes the biometric authentication result and a unique value based on the user's biometric data. Based on the unique value of biometric authentication data, secure configuration data with a data format conforming to security standard protocols is generated, and The authentication is successful when the password for the security configuration data matches the credential value for the user permissions set during the user permission registration process.
Citation Information
Patent Citations
Signaling of multiple short TTI transmissions
KR1020200003885A
Biometric authentication unit and biometric authentication method
EP2254072A1
System and Method of Providing Security to an External Attachment Device
US20110087889A1