Storage device and data cleaning method thereof
Patent Information
- Application Number
- CN202110162565.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-04-13
- Filing Date
- 2021-02-05
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2041-02-05
AI Technical Summary
然而,这种物理粉碎方法可能是昂贵的
Smart Images

Figure CN113536330B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application is based on and claims priority to Korean Patent Application No. 10-2020-0044554, filed on April 13, 2020, with the Korean Intellectual Property Office, the inventive concept of which is incorporated herein by reference in its entirety. Technical Field
[0003] The present invention relates to a storage device and a data cleaning method thereof. Background Technology
[0004] Typically, important data is stored on storage devices such as hard disk drives (HDDs) or solid-state drives (SSDs) installed in computers, laptops, servers, etc. Therefore, when disposing of computers, laptops, servers, etc., the data inside these storage devices must be completely removed and / or destroyed. In existing physical shredding methods, the data stored on such storage devices is completely removed. However, this physical shredding method can be expensive. Summary of the Invention
[0005] One aspect of the present invention is to provide a storage device and a data cleaning method that can clean data at low cost.
[0006] According to one aspect of the inventive concept of this disclosure, a storage device is provided, comprising: at least one non-volatile memory device; a memory controller configured to: encrypt data using key information and store the encrypted data in the at least one non-volatile memory device, or read the encrypted data from the at least one non-volatile memory device, decrypt the read encrypted data using the key information as decrypted data, and output the decrypted data to an external device; and a security chip connected to the memory controller and configured to store the key information, wherein the security chip includes an identification module related to data cleanup operations.
[0007] According to another aspect of the inventive concept of this disclosure, a storage device is provided, comprising: at least one non-volatile memory device; a memory controller configured to control the at least one non-volatile memory device; and a security chip connected to the memory controller and configured to store key information corresponding to an encryption algorithm, wherein the memory controller includes: at least one processor configured to control the overall operation of the memory controller; a buffer memory configured to temporarily store data required for the overall operation of the memory controller; and an error correction circuit configured to generate a first error correction code for first data during a write operation and to use a second error correction code to correct at least one of the second data during a read operation. The system includes: an error-corrected second data; a cryptographic module configured to generate the first data by encrypting the data using the encryption algorithm during the write operation, and to decrypt the error-corrected second data using the encryption algorithm during the read operation; a code memory configured to store code data for operating the memory controller; a host interface circuit configured to provide an interface with an external device; and a non-volatile memory interface circuit configured to provide an interface with the at least one non-volatile memory device, wherein, during a data cleanup operation, the security chip is decoupled from the memory controller, and data cleanup is confirmed by an authentication operation between the decoupled security chip and the external device.
[0008] According to another aspect of the inventive concept of this disclosure, a data cleanup method for a storage device is provided, the storage device comprising: at least one non-volatile memory device, a security chip storing key information, and a memory controller, the memory controller being configured to use the key information to store encrypted data in the at least one non-volatile memory device, or to decrypt the encrypted data read from the at least one non-volatile memory device, the data cleanup method comprising: separating the security chip from the storage device; and performing an authentication operation between the separated security chip and an external verification device.
[0009] According to another aspect of the inventive concept of this disclosure, a security device is provided, comprising: an elongated flexible substrate; a housing disposed on the flexible substrate; a security core chip disposed in the housing, and the security core chip being configured to store key information corresponding to an encryption algorithm; a connector disposed at one end of the flexible substrate, the connector being configured to be electrically connected to a memory controller; and an identification module disposed at the other end of the flexible substrate, and the identification module being configured to include information for confirming data cleanup operations. Attached Figure Description
[0010] The above and other aspects, features, and advantages of the present invention will become more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0011] Figure 1 This is a diagram illustrating an example of a storage device according to an exemplary embodiment of the concept of the present invention.
[0012] Figure 2 It is shown Figure 1 An example diagram of a memory controller is shown.
[0013] Figure 3A and Figure 3B This is a diagram illustrating an example of a security chip according to an exemplary embodiment of the concept of the present invention.
[0014] Figure 4A and Figure 4B This is a diagram illustrating an example of a security chip according to another exemplary embodiment of the concept of the present invention.
[0015] Figure 5 This is a diagram illustrating an example of a security chip according to another exemplary embodiment of the concept of the present invention.
[0016] Figure 6 This is a ladder diagram illustrating an example of the data cleanup process of a storage device according to an exemplary embodiment of the present invention.
[0017] Figure 7 This is a ladder diagram illustrating an example of an authentication process for verifying the cleanup of data on a storage device, according to an exemplary embodiment of the present invention.
[0018] Figure 8 This is a ladder diagram illustrating an example of an authentication process for verifying the cleanup of data on a storage device, according to another exemplary embodiment of the concept of the present invention.
[0019] Figure 9 This is a diagram illustrating an example of a data cleaning method for a storage device according to an exemplary embodiment of the present invention.
[0020] Figure 10 This is a diagram illustrating an example of a data cleanup operation for multiple storage devices according to an exemplary embodiment of the concept of the present invention.
[0021] Figure 11 This is a diagram illustrating an example of a mobile device according to an exemplary embodiment of the concept of the present invention.
[0022] Figure 12 This is a block diagram illustrating an example of a computing system according to an exemplary embodiment of the concept of the present invention.
[0023] Figure 13This is a block diagram illustrating an example of an electrical system according to an exemplary embodiment of a concept based on the present invention.
[0024] Figure 14 This is a diagram illustrating a data center using a memory device according to an example embodiment of the concept of the present invention. Detailed Implementation
[0025] In the following, exemplary embodiments of the inventive concept will be described in detail with reference to the accompanying drawings.
[0026] Typically, according to exemplary embodiments of the present invention, in a storage device and its data disposal method, a secure chip (e.g., a secure element (SE)) whose key is difficult to copy and crack during a data disposal operation can be used. For example, a data disposal operation for a storage device may include the operation of separating the secure chip from the storage device. In particular, the secure chip may be implemented in the form of an elongated rectangular package so that data can be easily corrupted even by a user's hand, thereby facilitating the data disposal operation of the storage device. Furthermore, the secure chip may include an identification module such as a QR code or NFC to prove that the separated secure chip corresponds to the storage device being disposed of.
[0027] Figure 1 This is a diagram illustrating an example of a storage device 100 according to an exemplary embodiment of the concept of the present invention. (Refer to...) Figure 1 The storage device 100 may include at least one non-volatile memory device 110, a memory controller (CTRL) 120, and a security chip (security element) SE 130.
[0028] Storage device 100 can be implemented to store user data. For example, storage device 100 can be a solid-state drive (SSD), a memory card (CF, SD, microSD, etc.), a universal serial bus (USB) storage device, etc.
[0029] According to an example embodiment, at least one non-volatile memory device 110 can be implemented to store data. The non-volatile memory device 110 may include NAND flash memory, vertical NAND (VNAND) flash memory, NOR flash memory, resistive random access memory (RRAM), phase-change memory (PRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), spin-torque random access memory (STTRAM), etc. Furthermore, the non-volatile memory device 110 can be implemented as a three-dimensional (3D) array structure.
[0030] In an example embodiment, the non-volatile memory device 110 may be implemented to store encrypted data.
[0031] The memory controller 120 can be implemented to control the non-volatile memory device 110 in response to commands or addresses from a host device. The memory controller 120 can send commands, addresses, or control signals to the non-volatile memory device 110, write data to the non-volatile memory device 110, or read data from the non-volatile memory device 110. For example, commands or addresses provided from the host device can be signals based on a communication protocol (e.g., a host interface) previously determined between the host device and the memory controller 120. Additionally, commands, addresses, and control signals provided to the non-volatile memory device 110 can be signals based on a communication protocol (e.g., a non-volatile memory interface) previously determined between the memory controller 120 and the non-volatile memory device 110.
[0032] Additionally, the memory controller 120 can encrypt data received from the host device based on an encryption algorithm and write the encrypted data to the non-volatile memory device 110. Furthermore, the memory controller 120 can be implemented to decrypt encrypted data read from the non-volatile memory device 110 based on an encryption algorithm. Here, the encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm. In example embodiments, the symmetric encryption algorithm can be Data Encryption Standard (DES), Advanced Encryption Standard (AES) (AES-128, AES-192, AES-256, etc.), SEED, RC4, Twofish, Serpent, Blowfish, CAST5, 3DES, IDEA, etc. In example embodiments, the asymmetric encryption algorithm can be Diffie-Helman key exchange, DSS, ElGamal, ECC, RSA, etc.
[0033] In an example embodiment, the memory controller 120 may include a crypto module 124 that performs encryption or decryption operations based on an encryption algorithm. Here, the crypto module may be implemented in hardware, software, or firmware.
[0034] The security chip 130 can be connected to the memory controller 120 and can be implemented to store encryption algorithms or key information for performing encryption algorithms. Here, the key information may include encryption key information or decryption key information. In an example embodiment, the security chip 130 can be connected to the memory controller 120 via a flexible printed circuit board (PCB). In an example embodiment, the security chip 130 can be implemented so that it can be easily removed from the memory controller 120 by a user.
[0035] Furthermore, the security chip 130 can be implemented as including an identification module 135 with identification information (ID) to identify data cleanup of the storage device 100. In an example embodiment, the identification module 135 may include a barcode, a quick response (QR) code, a radio frequency identification (RFID) chip, a near field communication (NFC) chip, etc.
[0036] although Figure 1 The security chip 130 shown is disposed (or located) outside the memory controller 120, but the inventive concept is not limited thereto. For example, according to another exemplary embodiment, the security chip of the inventive concept can be embedded or disposed within the memory controller 120.
[0037] Typically, it is difficult to dispose of data stored on a storage device during a cleanup operation. Typically, the storage device has been physically shredded to dispose of the data. However, such physical shredding is expensive and / or requires a long cleanup time.
[0038] According to an exemplary embodiment of the present invention, the storage device 100 can easily perform data disposal by separating a security chip 130 with an identification information ID for confirming data disposal operations from the controller 120. If the storage device 100 encrypts data using an encryption key and stores the data in the security chip 130, and then the security chip 130 is damaged, it becomes difficult to decrypt the data stored in the storage device 100. This results in the data in the storage device 100 being disposed of. Furthermore, even if the security chip 130 is damaged by a third party, the disposal operation of the storage device 100, on which the security chip 130 is installed, can be confirmed using an identification module linked to the security chip 130.
[0039] Figure 2 It is shown Figure 1 A diagram illustrating an example of the memory controller 120 shown. (Refer to...) Figure 2 The memory controller 120 may include at least one processor (CPU) 121, a buffer memory 122, an error correction circuit (ECC) 123, a cryptographic module 124, a code memory (CODE) 125, a host interface circuit (host I / F) 126, and a non-volatile memory interface circuit (NVM I / F) 127.
[0040] At least one processor 121 may be implemented as a control storage device 100 (see...) Figure 1 The processor 121 may include a central processing unit (CPU) for the overall operation of the system.
[0041] The buffer memory 122 can temporarily store data required for the operation of the memory controller 120. According to an example embodiment, Figure 2 The buffer memory 122 shown is disposed within the memory controller 120; however, the inventive concept is not limited thereto. According to an exemplary embodiment of the inventive concept, the buffer memory 122 may be configured as a separate intellectual property (IP) external to the memory controller 120.
[0042] Error correction circuit (ECC) 123 can be implemented to calculate error correction code values for data to be written in a write operation and to perform error correction on data read in a read operation based on the error correction code values. According to an example embodiment, error correction circuit 123 can correct errors in data recovered from non-volatile memory device 110 during a data recovery operation. Error correction circuit 123 can use coding modulation such as low-density parity-check (LDPC) codes, BCH codes, turbo codes, Reed-Solomon codes, convolutional codes, recursive systematic codes (RSC), trellis-coded modulation (TCM), block-coded modulation (BCM), etc., to correct errors.
[0043] The cryptographic module 124 can be implemented to encrypt data using an encryption algorithm or to decrypt encrypted data using an encryption algorithm. For example... Figure 1 As described herein, cryptographic module 124 can use key information stored on security chip 130 to execute encryption algorithms.
[0044] The code memory 125 can be implemented to store code data necessary for the operation memory controller 120. Here, the code memory can be implemented as a non-volatile memory device.
[0045] The host interface circuit 126 can be implemented to provide interface functionality with external devices. The host interface circuit 126 can be implemented as Non-Volatile Memory High Speed (NVMe), Peripheral Component Interconnect High Speed (PCIe), Serial Advanced Technology Attachment (SATA), Small Computer System Interface (SCSI), Serial Attached SCSI (SAS), Universal Storage Bus (USB) Attached SCSI (UAS), Internet Small Computer System Interface (iSCSI), Fibre Channel, or Ethernet Fibre Channel (FCoE).
[0046] The non-volatile memory interface circuit 127 can be implemented to provide interface functionality with the non-volatile memory device 110. It can also be implemented in an extraction type. Figure 2 The security chip 130 and memory controller 120 are shown.
[0047] In an example embodiment, during the data cleanup operation, the security chip 130 can be decoupled from the memory controller 120. Data cleanup can be verified through authentication operations between the decoupled security chip 130 and an external device.
[0048] According to the example embodiment, Figure 2 The security chip 130 shown is provided externally to the memory controller 120. However, the inventive concept is not limited thereto. According to another example embodiment, the security chip 130 of the inventive concept can be embedded in or disposed within the memory controller 120.
[0049] Meanwhile, the security chip 130 of the exemplary embodiment of the present invention can be implemented as a thin and elongated rectangular package shape so as to be easily separated from the storage device 100.
[0050] Figure 3A and Figure 3B This is a diagram illustrating an example of a security chip 130 according to an exemplary embodiment of the concept of the present invention. (Refer to...) Figure 3A The security chip 130 can be connected to the memory controller 120 via the flexible substrate 131 (see...). Figure 1 A connector 132 for electrical connection to the memory controller 120 can be provided at one end of the flexible substrate 131. Additionally, a barcode 135 for identification and cleaning can be connected to the other end of the flexible substrate 131. Figure 3A The barcode 135 shown may include an upper surface 135-1 of the barcode 135 that shows the identification code.
[0051] Reference Figure 3B , Figure 3B It is shown Figure 3A The diagram shows an example of the security chip 130 being flipped. (Refer to...) Figure 3B The flexible substrate 131 may include a package 133 for encapsulating the core chip 134 of the security chip 130. For example... Figure 3B As shown, by implementing the package 133 in a thin and elongated shape, the security chip 130 can be made easily damaged by a user. For example, the security chip 130 may include at least one groove or irregularity to allow the security chip 130 to be easily damaged near the dotted lines, such as... Figure 3B As shown.
[0052] at the same time, Figure 3B The barcode 135 shown may include a lower surface 135-2 of the barcode 135, wherein the identification code is either invisible or well visible.
[0053] at the same time, Figure 3A and Figure 3BThe core of the security chip 130 shown is implemented in the form of a connection to a barcode 135. However, the inventive concept is not limited to this.
[0054] Figure 4A and Figure 4B This is a diagram illustrating an example of a security chip 130a according to another exemplary embodiment of the concept of the present invention. (Refer to...) Figure 4A The internal structure of security chip 130a can be covered by barcode 135a. (See reference...) Figure 4B The security chip 130a can have Figure 4A The security chip 130a shown is in a flipped form. In an example embodiment, a flexible substrate 131a may be formed in the central portion of the barcode 135a. A connector 132a for electrical connection to the memory controller 120 may be connected to one end of the flexible substrate 131a. The flexible substrate 131a may include a package 133a that encapsulates the core chip 134a of the security chip 130a. Meanwhile, as... Figure 4B As shown, the security chip 130a can be implemented in a way that makes it easy for users to compromise it.
[0055] Meanwhile, in another exemplary embodiment of the present invention, the security chip 130 may utilize an NFC chip to implement identification information (ID).
[0056] Figure 5 This is a diagram illustrating an example of a security chip 130b according to another exemplary embodiment of the concept of the present invention. (Refer to...) Figure 5 The security chip 130b may include a flexible substrate 131b, a connector 132b, a package 133b, a first security core chip 134b, and an NFC chip 135b. The first security core chip 134b may perform operations with the memory controller 120 (see...). Figure 1 Mutual authentication.
[0057] In an example embodiment, the connection is made to the memory controller 120 (see...). Figure 1 The connector 132b can be disposed at one end of the flexible substrate 131b, and the NFC chip 135b can be disposed at the other end of the flexible substrate 131b.
[0058] Additionally, the NFC chip 135b can be implemented to perform wireless communication or receive wireless power from an external wireless device. Furthermore, the NFC chip 135b can be implemented to automatically or manually perform authentication operations with the first security core chip 134b.
[0059] The NFC chip 135b may include a second security core chip 135b-1 and an NFC antenna 135b-2. The second security core chip 135b-1 may be configured to perform mutual authentication with the first security core chip 134b. Furthermore, the second security core chip 135b-1 may perform mutual authentication with external wireless devices.
[0060] The NFC antenna 135b-2 can be implemented to receive wireless signals or wireless power from an external wireless device. The NFC antenna 135b-2 can also be implemented to transmit the received wireless signals or wireless power to the second security core chip 135b-1.
[0061] According to an example embodiment, the NFC chip 135b, in which a second security core chip 135b-1 is embedded, can be used to prevent forgery of cleanup evidence due to copying. Hereinafter, the data cleanup process will be described when the NFC chip 135b has the second security core chip 135b-1 embedded therein. For ease of description, the first security core chip 134b of the security chip 130b used for data cleanup will be defined as SE1, and the second security core chip 135b-1 embedded in the NFC chip 135b will be defined as SE2.
[0062] When a user first uses storage device 100, it prevents the separation and forgery of SE2 and SE1 via authentication of security chip 130b. After data cleanup, SE1 is inactive, allowing authentication information indicating that SE2 and SE1 have been authenticated to be stored in SE2. Authentication can be performed on NFC chip 135b's SE2, preventing duplication of NFC chip 135b, in which SE2 is embedded. Authentication can be performed, including information indicating that SE2 and SE1 have been simultaneously authenticated. Identification information, such as the serial number of storage device 100, can be stored in the smartphone using NFC communication with the smartphone. Subsequently, when using storage device 100, and when using SE1 to encrypt data, it prevents the separation and use of SE2 and SE1 via periodic mutual authentication with SE2. After storage device 100 is cleaned, when a user receives a damaged SE1 and a modular SE2 from a cleaning company, authentication of NFC chip 135b's SE2 and the smartphone can be performed. Authentication can be performed, including information indicating that SE2 and SE1 have been simultaneously authenticated. By using communication with the embedded NFC chip 135b to read the serial number of the storage device 100 via a smartphone, it can be confirmed that the user's storage device 100 has been tampered with.
[0063] Meanwhile, the data cleaning process of the storage device 100 according to an example embodiment of the present invention will be described below.
[0064] Figure 6 This is a ladder diagram illustrating an example of a data cleanup process for a storage device 100 according to an exemplary embodiment of the present invention. First, the user 10 of the storage device (SSD) 100 may store the QR code of the storage device 100 in a verifier 20. Here, the user 10 may be a data center, government agency, or individual, and the verifier 20 may be the user's mobile device (e.g., a mobile phone or smartphone). The verifier 20 may use a verification application that activates the scanner to recognize the QR code of the storage device 100 (S11). The verifier 20 may store the recognized QR code of the storage device 100 (S12).
[0065] Subsequently, user 10 can determine the cleaning of storage device 100 according to internal policies or predetermined methods (S13). User 10 can request cleaning of storage device 100 from cleaning company 30 (S14). Cleaning company 30 can destroy the security chip of storage device 100 (S15).
[0066] The cleaning company 30 can identify (scan) the QR code connected to the compromised security chip (S16). The cleaning company 30 can use wired or wireless communication methods to send the QR code identified as belonging to the compromised security chip to the verifier 20 (S17).
[0067] Subsequently, the verifier 20 can complete the data cleaning process of the storage device 100 (S18) by comparing the QR code received from the cleaning company 30 with the stored QR code.
[0068] By verifying the QR code of the security chip, the data cleaning process of the storage device 100 according to an example embodiment of the present invention can be performed simply and inexpensively.
[0069] Furthermore, the storage device 100 according to an exemplary embodiment of the present invention may use a security chip 130, wherein the keys used for encryption and decryption are difficult to disclose. For example, the keys used for encryption and decryption stored in the security chip 130 may not be altered or copied. The storage device 100 may use the keys to perform authentication between the security chip 130 and the memory controller 120, such that data in the storage device 100 can only be read or written when an authenticated security chip 130 is installed. Therefore, using the security chip 130 makes it difficult for unauthorized users to steal data within the storage device 100.
[0070] Figure 7 This is a ladder diagram illustrating an example of an authentication process for verifying data cleanup of a storage device 100 according to an exemplary embodiment of the present invention. (Refer to...) Figure 7First, a first authentication operation (S21) can be performed between the memory controller 120 of the storage device 100 and the security chip 130. Here, the first authentication operation can be performed using a query-response authentication method. However, it should be understood that the first authentication operation conceived in this invention is not limited to this. In an example embodiment, the security chip 130 can perform the authentication operation with the memory controller 120 periodically or non-periodically.
[0071] After completing the first authentication operation, the security chip 130 can store the first authentication information corresponding to the first authentication operation (S22). Here, the first authentication information may include information related to the storage device 100, authentication time, or authentication expiration time. It should be understood that the first authentication information conceived in this invention is not limited to this.
[0072] Subsequently, the security chip 130 can perform a second authentication operation with the authenticator 20 wirelessly (S23). Here, a query-response authentication method can be used to perform the second authentication operation. However, it should be understood that the second authentication operation conceived in this invention is not limited thereto.
[0073] After completing the second authentication operation, the verifier 20 can store the second authentication information corresponding to the second authentication operation (S24). Here, the second authentication information may include the first authentication information, information related to the security chip 130, authentication time, or authentication expiration time. It should be understood that the second authentication information conceived in this invention is not limited to these. In the example embodiment, the security chip 130 may store the second authentication information.
[0074] Subsequently, a data cleanup operation for the storage device (SSD) 100 can be determined. During the data cleanup operation, it can be determined whether the security chip 130 is detached from the memory controller 120 (S25). In an example embodiment, the detachment determination operation of the security chip 130 can be performed by the security chip 130 itself. In another example embodiment, the detachment determination operation of the security chip 130 can be performed by the user with the naked eye.
[0075] Subsequently, the verifier 20 can use a wireless communication method to perform a third authentication operation (S26) on the security chip 130, which is separate from the memory controller 120. Here, the third authentication operation can be performed using a query-response authentication method. However, it should be understood that the third authentication operation conceived in this invention is not limited thereto.
[0076] After completing the third authentication operation, the verifier 20 can verify the destruction of the security chip 130 by using the third authentication information corresponding to the third authentication operation and the stored second authentication information (S27). Here, the third authentication information may include the first authentication information, the second authentication information, information related to the security chip 130, the authentication time, or the authentication expiration time. It should be understood that the third authentication information conceived in this invention is not limited to this.
[0077] In the data cleanup operation of the storage device 100 according to an exemplary embodiment of the present invention, by comparing identification information such as a serial number read from the verifier 20 (such as a smartphone) using a QR code or NFC chip with the state after the data has been cleaned, it can be confirmed that even if the storage device 100 has been cleaned by a third party, the storage device 100 in use has also been cleaned. Simultaneously, the storage device 100 according to the exemplary embodiment of the present invention can periodically or non-periodically perform authentication operations between the NFC chip of the security chip and the verifier 20 to confirm the data cleanup of the storage device 100.
[0078] Figure 8 This is a ladder diagram illustrating an example of an authentication process for verifying data cleanup of storage device 100 according to another exemplary embodiment of the concept of the present invention. (Refer to...) Figure 8 It can be stored in storage device 100 (see Figure 1 The memory controller 120 (see) Figure 1 ) and security chip 130b (see Figure 5 The first authentication operation (S31) is performed between them.
[0079] After completing the first authentication operation, security chip 130b (see...) Figure 5 The first security core chip (SE1) 134b can store the first authentication information (S32) corresponding to the first authentication operation.
[0080] Subsequently, the first security core chip 134b of the security chip 130b can perform a second authentication operation with the second security core chip 135b-1 of the NFC chip 135b (S33). Here, an interrogation-response authentication method can be used to perform the second authentication operation. However, it should be understood that the second authentication operation of the present invention is not limited thereto.
[0081] After completing the second authentication operation, the second security core chip 135b-1 of the NFC chip 135b can store the second authentication information corresponding to the second authentication operation (S34). Here, the second authentication information may include the first authentication information, information related to the first security core chip 134b of the security chip 130b, authentication time, or authentication expiration time. It should be understood that the second authentication information conceived in this invention is not limited to this. In the example embodiment, the first security core chip 134b of the security chip 130b can store the second authentication information.
[0082] Subsequently, the second security core chip (SE2) 135b-1 of the NFC chip 135b can perform a third authentication operation with the verifier 20 wirelessly (S35). After completing the third authentication operation, the verifier 20 can store the third authentication information corresponding to the third authentication operation (S36). Here, the third authentication information may include the second authentication information, information related to the security chip 130b, authentication time, or authentication expiration time.
[0083] Subsequently, a data cleanup operation for the storage device (SSD) 100 can be determined. During the data cleanup operation, it can be determined whether the security chip 130b is separated from the memory controller 120. Afterward, the verifier 20 can perform a fourth authentication operation (S37) on the NFC chip 135b of the security chip 130b separated from the memory controller 120 using a wireless communication method. Specifically, the fourth authentication operation can be performed between the second security core chip (SE2) 135b-1 of the NFC chip 135b and the verifier 20 via NFC communication.
[0084] After completing the fourth authentication operation, the verifier 20 can use the fourth authentication information corresponding to the fourth authentication operation and the stored third authentication information to verify the destruction of the security chip 130b (S38). Therefore, the data cleanup operation of the storage device 100 can be completed.
[0085] As described above, storage device 100 can store data by encrypting the data using a key stored in security chip 130. Therefore, when the security chip storing the key is cleaned up (or destroyed), the data stored in storage device 100 cannot be decrypted because the key information is no longer available. Thus, the data and storage device 100 have been logically cleaned up (or destroyed). For example, data stored in storage device 100 can be logically cleaned up (or destroyed) if it is necessary to physically shred storage device 100.
[0086] Figure 9 This is an illustrative diagram illustrating a method for cleaning data in a storage device 100 according to an exemplary embodiment of the present invention. (Refer to...) Figures 1 to 9The method for cleaning up the data in storage device 100 can be as follows.
[0087] In operation S110, based on the determination that storage device 100 needs to be cleaned, the user or cleaning company can install the security chip 130 (see...). Figure 1 ) and storage device 100 (see Figure 1 Separation. In an example embodiment, the security chip 130 may be made of a thin and elongated rectangular chip so that it can be easily destroyed, even by hand, during data cleanup operations.
[0088] Subsequently, the separated security chip 130 and verifier 20, used for verification cleaning (see...) Figure 6 Verification operations are performed between the verifier 20 and the security chip 130 (S120). Here, the verifier 20 may pre-store authentication information corresponding to the security chip 130. The verifier 20 can use the stored authentication information and the identification information scanned or read during the cleanup operation to perform authentication.
[0089] For example, when using storage device 100 for the first time, a user can scan a QR code with their smartphone and store identification information such as the serial number of storage device 100 in their smartphone. After cleaning the storage device, the user can verify that the QR code connected to the damaged security chip received from the cleaning company matches the serial number stored in their smartphone, thus proving that the user's storage device 100 has been cleaned.
[0090] Meanwhile, the wireless device according to an example embodiment of the present invention can perform data cleaning operations simultaneously on multiple storage devices via a wireless communication method.
[0091] Figure 10 This is a diagram illustrating an example of a data cleanup operation for multiple storage devices according to an exemplary embodiment of the present invention. (Refer to...) Figure 10 The wireless device 200 can broadcast authentication requests to multiple storage devices (SSDs). Each of the multiple storage devices may include a reference... Figures 1 to 9 The security chip SE is described. The security chip SE can receive authentication requests from the wireless device 200 and initiate an authentication operation corresponding to the data cleanup operation. Furthermore, after performing the authentication operation, the security chip SE can send a completion signal to the wireless device 200. In an example embodiment, the completion signal may include an identification information ID corresponding to each storage device SSD. In an example embodiment, the wireless device 200 can receive the identification information ID corresponding to the security chip SE and verify that it was used for cleanup of the corresponding storage device.
[0092] In this embodiment, the wireless device may be a mobile device. For example, the wireless device may perform data cleanup operations for a storage device (SSD) via a deletion application installed on the mobile device.
[0093] Furthermore, the authentication request method conceived in this invention is not limited to broadcasting. The authentication request method of the exemplary embodiments of this invention can be sent via unicast or multicast.
[0094] Meanwhile, in the data cleanup operation of the storage device in the exemplary embodiment of the present invention, after first deleting the internal data of the non-volatile memory device, the security chip can be separated.
[0095] Meanwhile, the data cleaning method of the exemplary embodiment of the present invention can be applied to mobile devices.
[0096] Furthermore, the authentication request method conceived in this invention is not limited to using wireless communication. An example embodiment of the authentication request method conceived in this invention can use wired communication for transmission.
[0097] Figure 11 This is a diagram illustrating an example of a mobile device 1000 according to an exemplary embodiment of the concept of the present invention. (Refer to...) Figure 11 The mobile device 1000 may include an application processor (AP) 1100, at least one buffer memory 1200, at least one storage device 1300, a display / touch module 1400, and a security chip 1500. For example, the mobile device 1000 may be implemented as a laptop computer, mobile phone, smartphone, tablet PC, or wearable computer.
[0098] Application processor (AP) 1100 can be implemented to control the overall operation of mobile device 1000. Application processor 1100 can execute applications that provide internet browsers, games, videos, etc. In an example embodiment, application processor 1100 may include a single core or multiple cores. In an example embodiment, application processor 1100 may also include internal or external cache memory. Additionally, application processor 1100 may optionally include a controller, neural processing unit (NPU), etc.
[0099] In an example embodiment, the application processor 1100 may be implemented as a system-on-a-chip (SoC). The kernel of the operating system running on the SoC may include an input / output scheduler and a device driver for controlling the storage device 1300. The device driver may control the access performance of the storage device 1300 by referring to the number of synchronization queues managed by the input / output scheduler, or control the CPU mode, DVFS level, etc. in the SoC.
[0100] The buffer memory 1200 can be implemented to store data necessary for the operation of the application processor 1100. For example, the buffer memory 1200 can temporarily store operating system (OS) and application data, or it can be used as execution space for various software codes. Additionally, the buffer memory 1200 can store data related to artificial intelligence operations. In an example embodiment, the buffer memory 1200 can be implemented as DRAM or PRAM.
[0101] Storage device 1300 can be implemented to store user data. Storage device 1300 can be included in mobile device 1000 in an embedded form. In another example embodiment, storage device 1300 can be included in mobile device 1000 in a detachable manner. In the example embodiment, user data can be data encrypted based on an encryption algorithm. Here, the key information required for the encryption algorithm is stored in security chip 1500.
[0102] Storage device 1300 can store data collected from at least one sensor, or data network data, augmented reality (AR) / virtual reality (VR) data, and high-definition (HD) content. Storage device 1300 may include solid-state drives (SSDs), embedded multimedia cards (eMMC), etc.
[0103] The display / touch module 1400 can be implemented to output or input data via touch. For example, the display / touch module 1400 can output image data sensed using at least one sensor, or output data calculated using the application processor 1100. Additionally, the display / touch module 1400 can recognize user touches.
[0104] The security chip 1500 can perform or process general security operations of the mobile device 1000. The security chip 1500 can store important information necessary for performing security operations. For example, the security chip 1500 can store key information necessary for operating encryption algorithms. Additionally, the security chip 1500 may include identification information (ID) for identifying the mobile device 1000. The security chip 1500 can verify the data sanitization of the mobile device 1000 through authentication with an external wireless device, as described in reference... Figures 1 to 10 As described.
[0105] According to the example embodiments, the inventive concept can be applied to computing systems.
[0106] Figure 12 This is a block diagram illustrating an example of a computing system 2000 according to an exemplary embodiment of the concept of the present invention. (Refer to...) Figure 12The computing system 2000 may include at least one memory module (DIMM) 2100, at least one non-volatile memory module (NVDIMM) 2200, and at least one processor 2300. Here, each of the at least one memory module 2100 and the at least one non-volatile memory module 2200 may be embedded with a security chip SE having identification information ID used in the data cleanup operation described above.
[0107] Furthermore, the concept of this invention can be applied to various types of computing systems (e.g., central processing unit (CPU) / graphics processing unit (GPU) / neural processing unit (NPU) platforms).
[0108] According to the example embodiments, the inventive concept can be applied to electrical systems that prevent hacker threats.
[0109] Figure 13 This is a block diagram illustrating an electrical system 4000 according to an exemplary embodiment of the present invention. (Refer to...) Figure 13 The vehicle electrical system 4000 may include an electronic control unit (ECU) 4100, a memory device 4200, at least one dynamic range sensor (DVS) 4300, a display device 4400, a communication processor 4500, and a safety ECU 4600.
[0110] ECU 4100 can be implemented to control overall operation. ECU 4100 can process image data received from DVS4300. ECU 4100 may include a neural processing unit (NPU). The NPU can quickly derive the optimal image for driving by comparing the image data received from DVS 4300 with a learned model.
[0111] The memory device 4200 can be implemented to store learning models related to the operation of the NPU. The memory device 4200 can include volatile or non-volatile memory devices. For example, the memory device 4200 can be DRAM or PRAM.
[0112] The DVS 4300 can be implemented to detect the external environment of a vehicle. The DVS 4300 can output an event signal in response to changes in relative light intensity. The DVS 4300 may include a pixel array and an address event processor; the pixel array comprises multiple DVS pixels.
[0113] The display device 4400 can be implemented to display images processed by the ECU 4100 or images transmitted by the communication processor 4500.
[0114] The communication processor 4500 can be implemented to send processed images to an external device (e.g., an external vehicle) or to receive images from an external vehicle. In other words, the communication processor 4500 can be implemented to communicate with external devices via wired or wireless means.
[0115] The safety ECU 4600 can be implemented to control general operations related to the safety of the electrical system 4000. The safety ECU 4600 may include performing the actions described above. Figures 1 to 10 The description describes the structure or function of a security chip that performs data destruction operations. Additionally, when the security ECU 4600 detects a hacker threat, it can perform data destruction operations on its internal data.
[0116] According to the example embodiments, the inventive concept can be applied to data server systems.
[0117] Figure 14 This is a diagram illustrating a data center using a memory device according to an exemplary embodiment of the concept of the present invention. (Refer to...) Figure 14 Data center 7000 is a facility that collects various types of data and provides services; it can also be referred to as a data storage center. Data center 7000 can be a system used to operate search engines and databases, or it can be a computing system used by companies such as banks or government agencies. Data center 7000 can include application servers 7100 to 7100n and storage servers 7200 to 7200m. The number of application servers 7100 to 7100n and the number of storage servers 7200 to 7200m can be selected differently according to example embodiments, and the number of application servers 7100 to 7100n and the number of storage servers 7200 to 7200m can differ from each other.
[0118] Application server 7100 or storage server 7200 may include at least one of processors 7110 and 7210 and memories 7120 and 7220. Taking storage server 7200 as an example, processor 7210 may control the overall operation of storage server 7200 and access memory 7220 to execute instructions and / or data loaded into memory 7220. Memory 7220 may be dual data rate synchronous DRAM (DDR SDRAM), high bandwidth memory (HBM), hybrid memory cube (HMC), dual in-line memory module (DIMM), optan DIMM, or non-volatile DIMM (NVMDMIM). According to example embodiments, the number of processors 7210 and the number of memories 7220 included in storage server 7200 may be selected differently. In example embodiments, processors 7210 and memory 7220 may provide processor-memory pairs. In example embodiments, the number of processors 7210 and memory 7220 may be different from each other. Processor 7210 may include a single-core processor or a multi-core processor. The above description of storage server 7200 can be similarly applied to application server 7100. According to an example embodiment, application server 7100 may not include storage device 7150. Storage server 7200 may include at least one storage device 7250. According to an example embodiment, the number of storage devices 7250 included in storage server 7200 may be selected differently.
[0119] Application servers 7100 to 7100n and storage servers 7200 to 7200m can communicate with each other via network 7300. Network 7300 can be implemented using Fibre Channel (FC) or Ethernet. Here, FC can be a medium for relatively high-speed data transmission and can be an optical switch providing high performance / high availability. Depending on the access method of network 7300, storage servers 7200 to 7200m can be provided as file storage, block storage, or object storage.
[0120] In example embodiments, network 7300 may be a storage-only network such as a Storage Area Network (SAN). For example, the SAN may be an FC-SAN implemented using an FC network and according to the FC protocol (FCP). As another example, the SAN may be an IP-SAN implemented using a TCP / IP network and according to the iSCSI (SCSI over TCP / IP or Internet SCSI) protocol. In other example embodiments, network 7300 may be a general-purpose network such as a TCP / IP network. For example, network 7300 may be implemented according to protocols such as Ethernet FC (FCoE), Network Attached Storage (NAS), and NVMe over Fabrics (NVMe-oF).
[0121] The following text will primarily describe the application server 7100 and the storage server 7200. The description of the application server 7100 can also be applied to other application servers 7100n, and the description of the storage server 7200 can also be applied to other storage servers 7200m.
[0122] Application server 7100 can store data requested by users or clients in one of storage servers 7200 to 7200m via network 7300. Additionally, application server 7100 can retrieve data requested by users or clients from one of storage servers 7200 to 7200m via network 7300. For example, application server 7100 can be implemented as a web server, a database management system (DBMS), etc.
[0123] Application server 7100 can access memory 7120n or storage device 7150n included in another application server 7100n via network 7300, or access memory 7220 to 7220m or storage device 7250 to 7250m included in storage servers 7200 to 7200m via network 7300. Therefore, application server 7100 can perform various operations on data stored on application servers 7100 to 7100n and / or storage servers 7200 to 7200m. For example, application server 7100 can execute commands for moving or copying data between application servers 7100 to 7100n and / or storage servers 7200 to 7200m. In this scenario, data can be moved directly from storage devices 7250 to 7250m of storage servers 7200 to 7200m to storage devices 7120 to 7120n of application servers 7100 to 7100n, or via storage devices 7220 to 7220m of storage servers 7200 to 7200m. Data moved over network 7300 can be encrypted for security or privacy purposes.
[0124] Taking storage server 7200 as an example, interface 7254 can provide physical connectivity between processor 7210 and controller 7251, as well as physical connectivity between NIC 7240 and controller 7251. For example, interface 7254 can be implemented using a Direct Attached Storage (DAS) method, which directly connects storage device 7250 to a dedicated cable. Alternatively, taking storage server 7200 as an example, interface (NIC) 7254 can provide physical connectivity between processor 7210 and controller 7251, as well as physical connectivity between NIC 7240 and controller 7251. For example, interface 7254 can be implemented using a Direct Attached Storage (DAS) method, which directly accesses storage device 7250 via a dedicated cable. Furthermore, interface 7254 can be implemented through various interface methods such as: Advanced Technology Attachment (ATA), Serial ATA (SATA), External SATA (e-SATA), Small Computer System Interface (SCSI), Serial Attached SCSI (SAS), Peripheral Component Interconnect (PCI), PCI High Speed (PCIe), NVM High Speed (NVMe), IEEE 1394, Universal Serial Bus (USB), Secure Digital (SD) card, Multimedia Card (MMC), Embedded Multimedia Card (e-MMC), Universal Flash Storage (UFS), Embedded Universal Flash Storage (eUFS), and Compact Flash (CF) card interface.
[0125] The storage server 7200 may also include a switch 7230 and a NIC 7240. The switch 7230 may selectively connect the processor 7210 and the storage device 7250, or selectively connect the NIC 7240 and the storage device 7250, under the control of the processor 7210.
[0126] In an example embodiment, NIC 7240 may include a network interface card, network adapter, etc. NIC 7240 can connect to network 7300 via a wired interface, wireless interface, Bluetooth interface, optical interface, etc. NIC 7240 may include internal memory, DSP, host bus interface, etc., and can be connected to processor 7210 and / or switch 7230 via the host bus interface. The host bus interface can be implemented as one of the examples of interface 7254 described above. In an example embodiment, NIC 7240 may be integrated with at least one of processor 7210, switch 7230, and storage device 7250.
[0127] In storage servers 7200 to 7200m or application servers 7100 to 7100n, the processor can send commands to storage devices 7150 to 7150n and 7250 to 7250m or memories 7120 to 7120n and 7220 to 7220m to program or retrieve data. In this case, data error correction can be performed on the data using an error correction code (ECC) engine. The data may have undergone data bus inversion (DBI) or data masking (DM) and may include cyclic redundancy check (CRC) information. The data may be encrypted for security or privacy purposes.
[0128] Storage devices 7150 to 7150n and 7250 to 7250m can send control signals and command / address signals to NAND flash memory devices 7252 to 7252m in response to a read command received from the processor. Therefore, when reading data from NAND flash memory devices 7252 to 7252m, a read enable (RE) signal can be input as a data output control signal to output data to the DQ bus. A data strobe (DQS) can be generated using the RE signal. The command / address signal can be latched into the page buffer based on the rising or falling edge of the write enable (WE) signal.
[0129] Controller 7251 can control the overall operation of storage device 7250. In an example embodiment, controller 7251 may include static random access memory (SRAM). Controller 7251 can write data to NAND flash memory device 7252 in response to a write command, or can read data from NAND flash memory device 7252 in response to a read command. For example, write and / or read commands can be provided from processor 7210 in storage server 7200, processor 7210m in another storage server 7200m, or processors 7110 to 7110n in application servers 7100 to 7100n. DRAM 7253 can temporarily store (cache) data written to or read from NAND flash memory device 7252. In addition, DRAM 7253 can store metadata. Here, metadata is user data or data generated by controller 7251 for managing NAND flash memory device 7252. Storage device 7250 may include a security element (SE) for security or privacy. at the same time, Figure 14 The SE shown exists external to the memory controller, but the inventive concept is not limited thereto. The SE of the inventive concept can be embedded within the memory controller. The SE of the inventive concept can be used to demonstrate, for example... Figures 1 to 10 Data cleanup operations on the storage device shown.
[0130] A storage device according to an example embodiment of the present invention may include a structure that allows damage to an integrated circuit (IC) caused by physical force from a user by connecting each structure to a security chip.
[0131] Additionally, a storage device according to an exemplary embodiment of the present invention may include a structure for attaching an identification module, such as a barcode / QR / RFID, to the extraction structure and security chip of the storage device.
[0132] Additionally, the storage device according to an exemplary embodiment of the present invention may include an antenna attachment structure for wireless power communication within the storage device. A secure element (SE) for clearing data in a data storage device such as an SSD or hard disk drive (HDD) can be applied. Furthermore, the storage device according to an exemplary embodiment of the present invention may use means for proving clearing, such as a QR code or NFC, associated with the secure element in the data storage device such as an SSD or HDD.
[0133] As described above, in the storage device and its cleaning method embodiments according to the exemplary embodiments of the present invention, the data cleaning operation can be easily and inexpensively authenticated by providing a security chip with identification information.
[0134] Although exemplary embodiments have been shown and described above, it will be apparent to those skilled in the art that modifications and changes can be made without departing from the scope of the inventive concept as defined by the appended claims.
Claims
1. A storage device, comprising: At least one non-volatile memory device; The memory controller is configured as follows: Data is encrypted using key information, and the encrypted data is stored in the at least one non-volatile memory device, or The encrypted data is read from the at least one non-volatile memory device, the read encrypted data is decrypted using the key information to obtain the decrypted data, and the decrypted data is output to an external device. as well as A security chip, connected to the memory controller, is configured to store the key information. The security chip includes an identification module related to data cleanup operations, and During the data cleanup operation, the cleanup of the storage device is confirmed through a third authentication operation between the identification module and an external device using the identification information of the storage device.
2. The storage device according to claim 1, wherein, The memory controller and the security chip periodically or non-periodically perform the first authentication operation, and The security chip stores the first authentication information corresponding to the first authentication operation.
3. The storage device according to claim 1, wherein, The identification module includes at least one of a barcode, a fast response code, an RFID chip, and a near-field communication chip.
4. The storage device according to claim 1, wherein, The identification module includes a barcode. During the data cleanup operation, the external device confirms the cleanup of the storage device by identifying the barcode of the security chip that is separate from the storage device.
5. The storage device according to claim 4, wherein, The security chip includes: The first core security chip; A package configured to house the first security core chip; A flexible substrate, wherein the package is mounted on the flexible substrate; A connector, disposed at one end of the flexible substrate, is configured for electrical connection to the memory controller; and The barcode is located at the other end of the flexible substrate.
6. The storage device according to claim 4, wherein, The security chip includes: The first core security chip; A package configured to house the first security core chip; Flexible substrate, the package is mounted on the flexible substrate; and A connector, disposed at one end of the flexible substrate, is configured to be electrically connected to the memory controller. The flexible substrate is covered by the barcode.
7. The storage device according to claim 1, wherein, The identification module includes a near-field communication chip, and During the data cleanup operation, the external device confirms the cleanup of the storage device by performing wireless communication with the near-field communication chip.
8. The storage device according to claim 7, wherein, The security chip includes: The first core security chip; A package configured to house the first security core chip; and A flexible substrate, on which the package is mounted. A connector, disposed at one end of the flexible substrate, is configured to be electrically connected to the memory controller. The near-field communication chip is located at the other end of the flexible substrate.
9. The storage device according to claim 8, wherein, The near-field communication chip includes: A second security core chip, configured to communicate with the first security core chip; and A near-field communication antenna, configured to perform wireless communication with the external device.
10. The storage device according to claim 9, wherein, The first security core chip and the second security core chip perform the second authentication operation periodically or non-periodically. During the data cleaning operation, the external device and the near-field communication chip perform the third authentication operation.
11. A storage device, comprising: At least one non-volatile memory device; A memory controller configured to control the at least one non-volatile memory device; as well as A security chip, connected to the memory controller, is configured to store key information corresponding to the encryption algorithm. The memory controller includes: At least one processor is configured to control the overall operation of the memory controller; A buffer memory configured to temporarily store data required for the overall operation of the memory controller; An error correction circuit is configured to generate a first error correction code for first data in a write operation and to use a second error correction code in a read operation to correct at least one error in the second data to produce error-corrected second data. A cryptographic module is configured to generate the first data by encrypting the data using the encryption algorithm in the write operation, and to decrypt the error-corrected second data using the encryption algorithm in the read operation; A code memory configured to store code data for operating the memory controller; A host interface circuit, configured to provide an interface with external devices; and A non-volatile memory interface circuit is configured to provide an interface with the at least one non-volatile memory device. During the data cleanup operation, the security chip is separated from the memory controller, and the data cleanup is confirmed by an authentication operation between the separated security chip and an external device using the identification information of the storage device.
12. The storage device according to claim 11, wherein, The memory controller and the security chip periodically or non-periodically perform the first authentication operation, and The security chip stores the first authentication information corresponding to the first authentication operation.
13. The storage device according to claim 11, wherein, The security chip includes a near-field communication chip. The security chip and the near-field communication chip periodically or non-periodically perform a second authentication operation, and The near-field communication chip stores the second authentication information corresponding to the second authentication operation.
14. The storage device according to claim 13, wherein, During the data cleanup operation, the external device performs wireless communication with the near-field communication chip to perform a third authentication operation.
15. A data cleaning method for a storage device, the storage device comprising: The data cleanup method includes at least one non-volatile memory device, a security chip storing key information, and a memory controller configured to use the key information to store encrypted data in the at least one non-volatile memory device, or to decrypt the encrypted data read from the at least one non-volatile memory device. Separate the security chip from the storage device; and The data cleanup of the storage device is confirmed by performing an authentication operation between the separated security chip and an external verification device using the identification information of the storage device.
16. The data cleaning method according to claim 15, further comprising: Perform a first authentication operation between the memory controller and the security chip; as well as The first authentication information corresponding to the first authentication operation is stored in the security chip. The first authentication information includes the identification information of the storage device.
17. The data cleaning method according to claim 15, wherein, Performing the authentication operation includes: The external verification device is used to identify the barcode connected to the security chip; and The barcode stored using the external verification device is compared with the identified barcode.
18. The data cleaning method according to claim 15, further comprising: Perform a second authentication operation between the security chip and the near-field communication chip, wherein the security chip includes the near-field communication chip; as well as The second authentication information corresponding to the second authentication operation is stored in the near-field communication chip.
19. The data cleaning method according to claim 18, in, Performing the authentication operation includes: The external verification device is used to perform a third authentication operation with the near-field communication chip.
20. The data cleaning method according to claim 18, further comprising: The near-field communication chip receives an authentication request for data cleaning operations from the external verification device.
Citation Information
Patent Citations
Leg assembly
KR1020200044554A
Encryption Key Destruction For Secure Data Erasure
US20120093318A1
Memory and controller mutual secure channel association
US20190332763A1
Encrypted data storage device
US9195858B2