Storage device, security pin device and method of operating a storage device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-23
- Publication Date
- 2026-08-11
AI Technical Summary
然而,用户可能无法检查用户的数据是否被正常丢弃,因此,数据服务器难以向用户提供具有最优安全功能和/或可验证安全功能的服务
Smart Images

Figure CN113569303B_ABST
Abstract
Description
[0001] This application claims the benefit of priority to Korean Patent Application No. 10-2020-0051831, filed on April 28, 2020, with the Korean Intellectual Property Office (KIPO), the entire disclosure of which is incorporated herein by reference. Technical Field
[0002] Various exemplary embodiments of the inventive concept relate to storage devices, and more specifically, to storage devices that provide the function of securely discarding data, systems including storage devices, and / or methods of operating thereof. Background Technology
[0003] A storage system may include hosts and storage devices. A data server that manages multiple storage devices can be an example of a storage system, and can encrypt user data and store the encrypted data on the storage system, or decrypt the encrypted data and provide the decrypted data to the user.
[0004] When a user wants to erase or discard data stored on a data server, this is typically done by discarding the encryption keys used for data encryption and / or decryption. However, users may not be able to verify that their data has been properly discarded, making it difficult for data servers to provide users with services featuring optimal and / or verifiable security features. Summary of the Invention
[0005] Various exemplary embodiments of the inventive concept provide a storage device, a system including the storage device, a method of operating the storage device, and / or a non-transitory computer-readable medium including computer-readable instructions for performing the method of operating the storage device, the storage device including the ability to securely discard user data and allowing the user to directly check and / or directly determine whether the data or the storage device has been properly discarded.
[0006] According to at least one example embodiment of the inventive concept, a storage device is provided, the storage device comprising: a security pin device removably mounted on the storage device, the security pin device being configured to store first encrypted information and second encrypted information, the first encrypted information being encrypted using a first key associated with a first user, and the second encrypted information being encrypted using a second key associated with a second user; a security circuit configured to receive the first encrypted information from the security pin device, decrypt the first encrypted information, and generate a data encryption key based on the result of decrypting the first encrypted information; and a non-volatile memory configured to store data encrypted with the data encryption key.
[0007] According to at least one example embodiment of the inventive concept, a security pin device is provided, the security pin device comprising: at least one storage circuit configured to store first encrypted information and second encrypted information, the first encrypted information being encrypted using a first key and the second encrypted information being encrypted using a second key; and a first interface circuit configured to output the second encrypted information after the security pin device is removed from the storage device, so as to allow a second user to determine whether the storage device has been properly discarded.
[0008] According to at least one example embodiment of the inventive concept, a method of operating a storage device is provided, the method comprising: providing first encrypted information stored in a security pin device to a security circuit via communication between a security pin device and a security circuit; decrypting the first encrypted information via the security circuit using a first key stored in the security circuit; generating a data encryption key based on the first information via the security circuit, wherein the first information is extracted from the first encrypted information; encrypting data using the data encryption key; and storing the encrypted data. Attached Figure Description
[0009] Various exemplary embodiments of the inventive concept will become clearer from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0010] Figure 1 It is a block diagram of a storage system according to at least one example embodiment;
[0011] Figure 2 According to at least one example embodiment Figure 1 A block diagram of an example implementation of a safety circuit;
[0012] Figure 3 This is a block diagram of an example implementation of a storage device having a safety pin mounted thereon, according to at least one example embodiment;
[0013] Figure 4 According to at least one example embodiment Figure 3 A perspective view of an example implementation of a storage device;
[0014] Figure 5 It is a flowchart of an operation method of a storage system according to at least one example embodiment;
[0015] Figure 6 It is a flowchart of data storage and read operations of a solid-state drive (SSD) with a safety pin mounted thereon, according to at least one example embodiment;
[0016] Figure 7 and Figure 8 This is a diagram illustrating the operation of setting a safety pin according to some example embodiments;
[0017] Figure 9 It is a flowchart of the operation of a storage device according to at least one example embodiment;
[0018] Figure 10 and Figure 11 These are illustrations of a storage device and its operation methods according to some example embodiments;
[0019] Figure 12 and Figure 13 These are diagrams illustrating various operations of a storage system according to at least one example embodiment;
[0020] Figure 14 This is a flowchart of a process for checking whether a storage device has been discarded, according to at least one example embodiment;
[0021] Figure 15 This is a block diagram of a network system including a data server according to at least one example embodiment; and
[0022] Figure 16 It is a block diagram of a network system according to at least one example embodiment. Detailed Implementation
[0023] In the following text, various exemplary embodiments will be described in detail with reference to the accompanying drawings.
[0024] Figure 1 It is a block diagram of a storage system according to at least one example embodiment.
[0025] Reference Figure 1 Storage system 10 may include storage device 100 and / or host 200, etc., but the example embodiment is not limited thereto. Storage device 100 may include control logic 110 (e.g., control logic circuitry, etc.) and non-volatile memory (NVM) 120 (e.g., NVM device, etc.), etc. Host 200 may communicate with storage device 100 through various interfaces, and when there is a request from a user or data owner to store data in storage system 10 and / or read data from storage system 10, host 200 may control storage device 100 to store and / or read data according to the user's request.
[0026] For example, when storage system 10 is a data server (or data center, cloud server, web server, network attached storage (NAS) system, etc.) and the server controlling data storage (e.g., application server) is separate from the server including storage media (e.g., storage server), host 200 may be included in the application server. However, the example embodiments are not limited thereto, and host 200 and / or storage system 10 may be any capable computing device, and storage device 10 may be any capable storage system (e.g., personal computer (PC), laptop computer, smartphone, etc.) and storage device connected to and / or capable of accessing PC, laptop computer, smartphone, etc. According to various example embodiments, when storage device 100 is applied to a mobile device, host 200 may include an application processor (AP) and / or system-on-a-chip (SoC), etc., but the example embodiments are not limited thereto.
[0027] Storage device 100 may include one or more storage media for storing data under the control of host 200. For example, storage device 100 may include at least one solid-state drive (SSD), at least one hard disk drive (HDD), a combination of non-heterogeneous storage media (e.g., different types of storage media such as SSDs and HDDs) etc. When storage device 100 includes an SSD, NVM 120 may include multiple flash memory modules (e.g., NAND chips, etc.) that store data in a non-volatile manner. In some example embodiments, storage device 100 may include a Universal Flash Memory (UFS) card, Compact Flash Memory (CF), Secure Digital Memory (SD), Micro SD, Mini SD, Extreme Digital Memory (xD), Memory Stick, etc. According to some example embodiments, storage device 100 may include a mass storage device (e.g., a hard disk drive (HDD), etc.).
[0028] When the storage device 100 includes flash memory, the flash memory may include a two-dimensional (2D) NAND memory array and / or a three-dimensional (3D) or vertical NAND (VNAND) memory array. The 3D memory array may be monolithically formed at at least one physical level of a memory cell array having active regions on a silicon substrate, or circuitry relating to the operation of memory cells and formed on or in the substrate. The term "monolithic" means that the layers of each level of the array are directly stacked on top of the layers of the next lower level of the array.
[0029] In at least one example embodiment, the 3D memory array includes vertical NAND strings arranged in a vertical direction, such that at least one memory cell is placed on top of another memory cell. The memory cell may include a charge trapping layer.
[0030] Structures of 3D memory arrays are disclosed in U.S. Patent Publications No. 7,679,133, 8,553,466, 8,654,587, 8,559,235, and 2011 / 0233648, wherein the 3D memory array comprises multiple levels and word lines and / or bit lines are shared by multiple levels, and the publications of the aforementioned U.S. patents and U.S. patent applications are incorporated herein by reference.
[0031] According to some example embodiments, storage device 100 may include other types of memory. For example, storage device 100 may include various types of non-volatile memory (such as magnetic random access memory (MRAM), spin-torque MRAM, conductive bridged RAM (CBRAM), ferroelectric RAM (FeRAM), phase RAM (PRAM), resistive RAM, nanotube RAM, polymer RAM (PoRAM), nanofloating gate memory (NFGM), holographic memory, molecular electronic memory, and / or insulator resistance change memory, etc.).
[0032] Control logic 110 can write data to and / or read data from NVM 120 under the control of host 200. In at least one example embodiment, although in Figure 1 Not shown, but storage device 100 may include buffer circuitry for temporarily storing data written to and / or data read from. The buffer circuitry may include volatile memory (such as dynamic RAM (DRAM)).
[0033] Storage system 10 can encrypt user data and / or store encrypted data in storage device 100 upon user request, and / or decrypt encrypted data and / or provide decrypted data to the user, etc. For example, storage system 10 may include a data server storing data from multiple users, and host 200 may perform control operations to store user data in storage device 100, but the example embodiment is not limited thereto. Although for ease of description, Figure 1 Only one storage device 100 is shown, but multiple storage devices may be included in the storage system 10, etc.
[0034] According to at least one example embodiment, the storage device 100 may further include processing circuitry, and the processing circuitry may include, but is not limited to, security circuitry (e.g., security module) 130 and / or security circuitry (e.g., security module) 140, etc. According to some example embodiments, the processing circuitry is capable of performing the functions of one or more of the security circuitry 130, security circuitry 140, and / or control logic circuitry 110, etc. The processing circuitry may include hardware (such as a processor, processor core, logic circuitry, storage device, etc.), hardware / software combinations (such as at least one processor core executing software and / or executing any instruction set, etc.), or combinations thereof. For example, the processing circuitry may more specifically include, but is not limited to, field-programmable gate arrays (FPGAs), programmable logic cells, application-specific integrated circuits (ASICs), system-on-a-chip (SoCs), etc. In other example embodiments, security circuitry 130, security circuitry 140, and / or control logic circuitry 110 may be combined into a single circuit, or one or more separate circuits / components / elements, etc.
[0035] According to at least one example embodiment, the security circuitry 130 may be mounted as a separate chip on the storage device 100 and / or may be included in the control logic 110 of the storage device 100. The security circuitry 130 may perform various security processes (such as data encryption and / or decryption) within the storage device 100, but is not limited thereto. For example, the security circuitry 130 may include at least one encryption / decryption key (hereinafter referred to as a data encryption key) and may encrypt data in response to a write request from the host 200, and decrypt encrypted data read from the NVM 120 using one or more data encryption keys in response to a read request from the host 200.
[0036] Security circuitry 140 may be included in storage device 100 and may provide functionality for securely discarding, deleting, or removing user data. When storage system 10 corresponds to a data server storing user data, the user may want to securely erase their data from storage system 10. For example, the user may want to actually discard (e.g., ensure and / or verifiably discard, etc.) the data stored on the storage device and / or the data on the actual storage device storing the user's data. Furthermore, the user may want to directly check and / or determine whether the storage device being actually discarded is the same storage device the user intends to discard.
[0037] According to at least one example embodiment, security circuit 140 provides a function that allows a user to check whether data or storage devices that a user wants to discard have been correctly discarded. Furthermore, security circuit 140 provides a function that allows the data server and / or the server administrator running the data server to check and / or determine whether the storage devices that a user wants to discard have been correctly discarded. For example, security circuit 140 may be removably mounted on storage device 100 and may store information used by the user and / or server during the discard check process (e.g., information related to and / or corresponding to the discard check process, etc.). After security circuit 140 is removed from storage device 100, the information stored in security circuit 140 may be provided to the user and / or device (e.g., a server's Security Pin Tester (SPT) circuit), etc.
[0038] According to at least one example embodiment, the security circuit 140 may include a storage circuit that stores information in a non-volatile manner, and the first encrypted information Info_E1 and / or the second encrypted information Info_E2, etc., may be stored in the storage circuit, but is not limited thereto. For example, although in Figure 1 In this configuration, the first storage circuit 141 storing the first encrypted information Info_E1 is separate from the second storage circuit 142 storing the second encrypted information Info_E2. However, the first encrypted information Info_E1 and the second encrypted information Info_E2 can be stored in a single storage circuit. There can be more than two storage circuits and / or more than two encrypted information items.
[0039] The first encrypted information Info_E1 is information encrypted using a unique key (e.g., a unique encryption key, etc.) managed by the company operating the storage system 10 (e.g., a data server, etc.) or the company manufacturing the storage system 10 (hereinafter referred to as the manufacturer key). The data server may check and / or determine whether the storage device 100 whose security circuit 140 has been removed is the storage device 100 that the user has actually requested to be discarded, based on the information generated by decrypting the first encrypted information Info_E1, but the example embodiment is not limited thereto. The second encrypted information Info_E2 is information encrypted using a unique key (e.g., a unique encryption key, etc.) managed by the data owner who requested the storage of data (hereinafter referred to as the owner key), but the example embodiment is not limited thereto. The user may check whether the storage device 100 whose security circuit 140 has been removed is the storage device that the user has actually requested to be discarded, based on the information generated by decrypting the second encrypted information Info_E2.
[0040] According to at least one example embodiment, the security circuit 140 can be removed from the storage device 100 that the user wants to discard, and the data server and / or the user can check and / or determine whether the storage device actually discarded is the storage device that the user has requested to discard, based on the first encrypted information Info_E1 and the second encrypted information Info_E2 stored in the security circuit 140.
[0041] According to at least one example embodiment, at least one of the first encrypted information Info_E1 and the second encrypted information Info_E2 (e.g., selected encrypted information from Info_E1 or Info_E2) can be used to generate a data encryption key used in data encryption and / or decryption operations of the storage device 100. In at least one example embodiment, the security circuit 130 may include a key derivation circuit (not shown) configured to derive the data encryption key, and may generate the data encryption key based on information extracted from at least one encrypted information selected between the first encrypted information Info_E1 and the second encrypted information Info_E2, but the example embodiment is not limited thereto. Therefore, when the storage device 100 is discarded at the user's request by removing the security circuit 140, the encrypted data stored in the storage device 100 will not be decrypted, and thus, the user data can be securely discarded.
[0042] According to at least one example embodiment, compared to discarding data simply by erasing the data encryption key, the user can explicitly check and / or determine (e.g., verify, etc.) whether the discarded storage device (e.g., a storage device that has been discarded, removed, deleted, erased, securely formatted, etc.) is the storage device the user actually intended to discard. For example, there may be a situation where the data encryption key is mistakenly erased from a storage device different from the storage device the user actually intended to discard (e.g., expected to discard, intended to discard, etc.) in the storage system 10 which includes multiple storage devices 100. However, according to at least one example embodiment, each of the data server and / or user can perform a discard check process based on information from the security circuit 140 removed from the storage device 100, so the user can directly check and / or determine whether the target storage device has been explicitly discarded and / or actually discarded. Therefore, user security can be enhanced. Furthermore, according to at least one example embodiment, because the storage device 100 is discarded by physically removing the security circuit 140, there is no possibility that the data encryption key may be unintentionally retained in the storage device 100. Furthermore, because the information required and / or necessary for exporting the data encryption key is removed from the storage device 100, the data stored in the storage device 100 can be safely discarded.
[0043] Because the security circuit 140 can be removably mounted on the storage device 100, the security circuit 140 can be referred to as a security pin or a security pin device, etc. When the security circuit 130 is implemented as a separate semiconductor chip, the security circuit 130 can be referred to as a security chip or a security chip device, etc.
[0044] Although the storage system 10 has been described as corresponding to a data server, the example embodiments are not limited thereto. The storage device 100 according to at least one example embodiment may be used differently. For example, the storage system 10 may correspond to a personal computer (PC), network attached storage (NAS), smart device, Internet of Things (IoT) device, Internet of Everything (IoE) device, wearable device, game console, virtual reality (VR) device, augmented reality (AR) device, autonomous device, vehicle and / or portable electronic device, etc.
[0045] Various feasible example embodiments will be described below. In the description of the example embodiments, the term "user" as set forth above corresponds to the owner of the data and can therefore be used with the terms "data owner," etc., and the key generated and managed by the user can be referred to as the owner key. Furthermore, the manufacturer of the storage device can cooperate with the operating system... Figure 1 The storage system 10 may be from the same or different company (e.g., a data server). In the example embodiments described below, it is assumed that the data server is configured with multiple storage devices from the manufacturer and runs the server, but the example embodiments are not limited to this.
[0046] According to at least one example embodiment, the encryption / decryption key managed by the data server and / or its administrator (e.g., a first user) may be referred to as a manufacturer key, and the data server may be provided with manufacturer keys for each of a plurality of storage devices, but the example embodiment is not limited thereto. Each storage device may include, for example, a serial number as unique information corresponding to the storage device and / or other unique identifiers using the storage device, and the data server may also be provided with and manage the serial number (e.g., a unique identifier) of the corresponding storage device. However, the example embodiment is not limited thereto, and in some example embodiments, at least some operations of the storage system or data server may be configured to be performed by the manufacturer of the storage device. According to at least one example embodiment, "discarding data" may be used interchangeably with "discarding storage device," but the example embodiment is not limited thereto. For example, it may be indicated that data has been discarded when the security pin is removed from the storage device and the data in the storage device is no longer usable. Furthermore, it may be indicated that the storage device has been discarded because the storage device from which the security pin has been removed is no longer reusable or available.
[0047] Figure 2 yes Figure 1A block diagram of an example implementation of a safety circuit is shown. In at least one of the example embodiments below, the safety circuit may be referred to as a safety pin.
[0048] Reference Figure 2 The security pin 300 may include, but is not limited to, a first storage circuit 310 and / or a second storage circuit 320, and may include more or fewer storage circuits and / or other components. The first storage circuit 310 may store first encrypted information Emfrk (PIN*, SN1), and the second storage circuit 320 may store second encrypted information Eok (PIN*, SN1), etc. According to at least one example embodiment, after the first encrypted information Emfrk (PIN*, SN1) and the second encrypted information Eok (PIN*, SN1) are set in the security pin 300, the security pin 300 may be installed on a storage device (not shown). Furthermore, the first encrypted information Emfrk (PIN*, SN1) and the second encrypted information Eok (PIN*, SN1) may be set in a security pin 300 already installed on a storage device, etc.
[0049] The first encrypted information Emfrk (PIN*, SN1) may correspond to information encrypted using the manufacturer's key mfrk. For example, the first encrypted information Emfrk (PIN*, SN1) can be obtained by encrypting the serial number SN1 (and / or unique identifier) of the storage device and the personal identification number PIN* using the manufacturer's key mfrk. The personal identification number (PIN) is unique information set and / or assigned to the data owner and may include various information such as passwords set by the data owner, personal information, etc. When the data owner (e.g., a second user, etc.) provides the personal identification number to the data server, the personal identification number can be protected by encryption, for example, performed by the user and / or the data server. Figure 2 The Personal Identifier (PIN)* can be defined as encrypted information of the Personal Identifier. However, the example embodiments are not limited to this; for example, the plaintext of the Personal Identifier can be directly encrypted.
[0050] The second encrypted information Eok(PIN*, SN1) may correspond to information (e.g., data, etc.) encrypted using the owner key ok. A user (e.g., a data owner, etc.) may generate the second encrypted information Eok(PIN*, SN1) and provide it to the data server. The data owner may perform encryption using the owner key ok via a user terminal based on various methods. For example, the second encrypted information Eok(PIN*, SN1) may be generated by digitally signing the personal identification number PIN* and the serial number SN1 using a private key in a public key infrastructure (PKI) (such as Rivest-Shamir-Adleman (RSA)), however, the example embodiment is not limited to this. In addition to the above, the data owner may use various methods to generate the second encrypted information Eok(PIN*, SN1). For example, various encryption algorithms (such as the Diffie-Hellman (DH) key protocol, etc.) may be used.
[0051] To generate the first encrypted information Emfrk(PIN*, SN1) and the second encrypted information Eok(PIN*, SN1), various information can be exchanged between the data owner and at least one data server. For example, the data owner's personal identification number PIN* can be provided to the user server via a user terminal in a wired and / or wireless communication network, or information associated with the personal identification number PIN* can be provided to the data server offline (e.g., directly entered into the data server without being sent over the network (using a connected storage device, etc.)) to enhance security. The data server may also provide the data owner with a serial number SN1 for digital signature, but the example embodiments are not limited thereto.
[0052] The security pin 300 may also include a first interface circuit 331, a second interface circuit 332, and / or a third interface circuit 340, etc., but the example embodiment is not limited thereto. When the security pin 300 is removed from the storage device, the first interface circuit 331 can communicate with at least one device of a data server (e.g., server SPT SPT1 device) that can access the security pin 300, and the first encrypted information Emfrk (PIN*, SN1) can be provided to server SPT SPT1 through the first interface circuit 331. Server SPT SPT1 can decrypt the first encrypted information Emfrk (PIN*, SN1) using a manufacturer key (e.g., a first key). The information extracted and / or decrypted from the first encrypted information Emfrk (PIN*, SN1) can be used to check and / or verify whether the storage device from which the security pin 300 has been removed is a storage device that was genuinely requested and / or intended to be discarded.
[0053] The second interface circuit 332 can communicate with at least one device of a user with access to the security pin 300 (e.g., user SPT2), and the second encrypted information Eok (PIN*, SN1) can be provided to user SPT2 through the second interface circuit 332. User SPT2 can decrypt the second encrypted information Eok (PIN*, SN1) using an owner key (e.g., a second key). The information extracted and / or decrypted from the second encrypted information Eok (PIN*, SN1) can be used by the user to check and / or verify whether the storage device whose security pin 300 has been removed is a storage device that was genuinely requested and / or intended to be discarded.
[0054] The third interface circuit 340 can perform communication to set the security pin 300. For example, the third interface circuit 340 can communicate with at least one external device (e.g., a security pin creation module (SPCM) and / or a security pin creation circuit, etc.) that controls the operation of setting the security pin 300. The SPCM can provide the first encrypted information Emfrk (PIN*, SN1) and the second encrypted information Eok (PIN*, SN1) to the security pin 300 through the third interface circuit 340, but the example embodiment is not limited thereto. At least one method for generating the first encrypted information Emfrk (PIN*, SN1) and the second encrypted information Eok (PIN*, SN1) using the SPCM will be described below.
[0055] Although the first to third interface circuits 331, 332 and 340 are in Figure 2 While these are individual components, the example embodiments are not limited thereto. For instance, at least a portion of the communication with server SPT SPT1, user SPT SPT2, and SPCM can be performed via an interface circuit, etc.
[0056] Figure 3 This is a block diagram of an example implementation of a storage device having a safety pin mounted thereon, according to at least one example embodiment.
[0057] Reference Figure 3The storage device 400 may include a security pin 410 (e.g., a security circuit, security module, etc.), a security circuit 420 (e.g., a security module 420), and / or an NVM 430, etc., but the example embodiments are not limited thereto. When the security pin 410 is mounted on the storage device 400, at least one terminal of the security pin 410 may be connected to the security circuit 420, enabling the security pin 410 to communicate with the security circuit 420. According to at least one example embodiment, the security pin 410 may include first encrypted information Emfrk (PIN*, SN1) and second encrypted information Eok (PIN*, SN1), but the example embodiments are not limited thereto. The security circuit 420 may include various information and components. For example, the security circuit 420 may include a key derivation circuit 421 (e.g., a key derivation module 421), a first storage circuit 422 storing the manufacturer key mfrk, and / or a second storage circuit 423 storing the serial number SN2 of the storage device 400, etc., but the example embodiments are not limited thereto. Although the serial number SN1 included in the encrypted information and the serial number SN2 stored in the second storage circuit 423 are represented by different reference symbols, the serial numbers SN1 and SN2 may have the same value indicating the storage device 400.
[0058] The key derivation circuit 421 can execute a key derivation function KDF and can perform operations based on information stored in the security circuit 420 to generate a data encryption key MEK for encrypting and / or decrypting user data. For example, the key derivation circuit 421 can derive a third key kek based on the expected and / or specific function operation (such as a hash operation) on the input, and the third key kek can correspond to, but is not limited to, a key encryption key used to encrypt the data encryption key MEK.
[0059] In the example operation, the key derivation circuit 421 can use at least one selected from the personal identification number PIN* and the serial number SN1 as input to derive the third key kek. In the example operation, the security circuit 420 can receive the first encrypted information Emfrk(PIN*, SN1) from the security pin 410 and extract the personal identification number PIN* and the serial number SN1 by decrypting the first encrypted information Emfrk(PIN*, SN1) using the manufacturer key mfrk stored therein, and the key derivation circuit 421 can use at least one selected from the personal identification number PIN* and the serial number SN1 as input to derive the third key kek, but the example embodiment is not limited to this.
[0060] Security circuit 420 can use the serial number SN1 extracted from the first encryption information Emfrk(PIN*, SN1) to authenticate the security pin 410 mounted on storage device 400. For example, security circuit 420 can perform authentication based on whether the serial number SN2 stored in security circuit 420 is the same as the extracted serial number SN1, and can only perform a series of operations to generate the data encryption key MEK if authentication is successful (e.g., the result indicates that the serial number SN2 is the same as the serial number SN1).
[0061] The third encrypted information, Ekek(MEK), obtained by encrypting the data encryption key MEK used to encrypt and / or decrypt user data, can be stored in the NVM 430, but the example embodiment is not limited thereto. The encrypted user data, Emek(Data), can also be stored in the NVM 430. Although in Figure 3 In at least one example embodiment, the third encrypted information Ekek (MEK) is stored in the NVM 430, but this example embodiment is limited to this. For example, the third encrypted information Ekek (MEK) may be stored in a separate storage circuit (not shown) located outside the NVM 430.
[0062] According to at least one example embodiment, when the third key kek is derived, the third encrypted information Ekek (MEK) can be decrypted using the third key kek, thus the data encryption key MEK can be extracted. Because the storage device 400 uses the data encryption key MEK to encrypt and / or decrypt user data, data can only be encrypted and / or decrypted when the security pin 410 is authenticated as a normal device by the storage device 400, thereby improving and / or enhancing the security of the storage device 400.
[0063] The security circuit 420 may also include an encryption / decryption circuit (EN / DE) 424 (e.g., an encryption / decryption module 424) that performs desired and / or required encryption and / or decryption operations in the storage device 400. For example, the encryption / decryption circuit (EN / DE) 424 may perform decryption to generate a data encryption key MEK, and the data encryption key MEK may be used to encrypt and / or decrypt user data.
[0064] According to at least one example embodiment, the functions of the key output circuit 421 and the encryption / decryption circuit 424 can be implemented in various forms within the security circuit 420. For example, each of the key output circuit 421 and the encryption / decryption circuit 424 can be a processing circuit and implemented by hardware and / or software by executing computer-readable instructions. Furthermore, each of the key output circuit 421 and the encryption / decryption circuit 424 can be implemented by separate circuits and / or modules, etc.
[0065] The security circuit 420 may include, but is not limited to, a first interface I / F1 and / or a second interface I / F2. The first interface I / F1 may communicate with the security pin 410. The second interface I / F2 may communicate with at least one external device outside the storage device 400. For example, the security circuit 420 may communicate with an external SPCM via the second interface I / F2 to provide information about the storage device 400 required to set the security pin 410, but the example embodiment is not limited to this.
[0066] Figure 4 According to at least one example embodiment Figure 3 A perspective view of an example implementation of storage device 400.
[0067] like Figure 4 As shown, as an example of a storage device, an SSD may include a security pin SP mounted on the outer surface of the body. The body may include multiple NAND chips, security circuitry (e.g., a security module) SM, a controller (or control logic, control logic circuitry, processing circuitry, etc.), and / or buffers, etc. However, the example embodiment is not limited to this, and the example embodiment may include more or fewer components. Because the security pin SP is mounted on the outer surface of the SSD body, the security pin SP can be installed on the SSD after the setting operation of the security pin SP is completed, and can be easily removed from the SSD for disposal, etc.
[0068] According to at least one example embodiment, the safety pin SP can be connected to the safety circuit SM via physical wiring in the SSD, and the safety circuit SM can communicate with the controller. Although not in Figure 4 Specifically, the controller can be connected to the buffer and the NAND chip and can exchange data with an external host, but is not limited thereto. According to at least one example embodiment, after the security circuit SM normally receives information (e.g., first encryption information, etc.) from the security pin SP for generating a data encryption key, the data can be normally stored in or read from the SSD. After the security pin SP is removed from the SSD, the data encryption key is not retained in the SSD; therefore, the data stored in the SSD can be securely discarded and / or cannot be accessed by unauthorized users, etc.
[0069] Figure 5 This is a flowchart of an operation method of a storage system according to at least one example embodiment. Figure 5In the description of the operating method, according to at least one example embodiment, it is assumed that the storage system represents one of a plurality of storage devices included in a data server, that a server administrator may purchase the storage device from the manufacturer to run the server, and that a security pin is set by the data server or the server administrator. In at least one example embodiment below, it is also assumed that the storage device corresponds to an SSD, but the example embodiments are not limited thereto.
[0070] According to at least one example embodiment, in order to securely discard an SSD at the request of the data owner and / or to support the function of allowing users to check the discarding, the data server or server administrator may create a security pin corresponding to the SSD, and the security pin may be installed (e.g., connected, installed, etc.) to the SSD. For example, at least one SSD may be allocated to a data owner (e.g., a second user) for data storage through a contract with the data server or at the request of the data owner, and various information may be exchanged between the data server and / or the data server administrator (e.g., the first user) and the data owner offline and / or via wired / wireless communication during the creation of the security pin.
[0071] The data server may be configured with multiple SSDs from the SSD manufacturer that will be used in the data server, and may also be configured with a manufacturer key and serial number and / or other form of unique identifier for each SSD. For example, the data server may be configured with a manufacturer key shared by multiple SSDs or with a manufacturer key configured individually for each SSD, but the example embodiment is not limited thereto. The data server may provide a serial number to the data owner, or may be configured with a personal identification number from the data owner (and / or a unique identifier associated with the data owner, etc.), but the example embodiment is not limited thereto.
[0072] In operation S11, the data server can generate first encrypted information using the manufacturer's key and can set the first encrypted information in the security pin. The data server can generate the first encrypted information by encrypting the serial number of the expected and / or specific SSD (hereinafter referred to as the first SSD) assigned to the data owner and the personally identifiable information requested and provided by the data owner using the manufacturer's key, and can set the first encrypted information in the security pin, but the example embodiment is not limited thereto.
[0073] Furthermore, the data server can request second encrypted information generated using the owner's key from the data owner, and can provide the serial number of the first SSD to the data owner. In operation S12, the data owner can generate second encrypted information by encrypting the serial number of the first SSD provided from the data server and the personal identification information provided to the data server using the owner's key, and can provide the second encrypted information to the data server. The data server can also set the second encrypted information in a security lock, but the example embodiment is not limited to this.
[0074] Subsequently, in operation S13, the data server can install the configured security pin on the first SSD, and the first SSD can communicate with the security pin and generate a data encryption key using the information stored in the security pin; however, the example embodiment is not limited to this. According to at least one example embodiment, the data encryption key for data encryption and / or decryption can be encrypted using a desired and / or specific key (e.g., a key encryption key), then stored in the first SSD, and the security circuitry of the first SSD can have information as input to extract and / or decrypt the first encrypted information and be used to derive the key encryption key. After deriving the key encryption key, the data encryption key can be extracted and / or generated using the key encryption key through decryption, and in operation S14, the first SSD can use the data encryption key to encrypt and / or decrypt user data. According to at least one example embodiment, the data encryption key for data encryption and / or decryption can be generated based on the information stored in the security pin; therefore, user data can only be encrypted and / or decrypted when a properly authenticated security pin is installed on the first SSD. Thus, data security can be enhanced and / or improved.
[0075] In operation S15, when there is a request from the data owner to discard the first SSD, a security pin can be removed from the first SSD by a server administrator or similar entity. In operation S16, the data server can perform a process for checking, determining, and / or verifying whether the discarded first SSD is the SSD that the data owner actually requested to discard and / or expected to discard, using the security pin removed from the first SSD, and the security pin can output first encrypted information to the data server's means (e.g., server SPT). According to at least one example embodiment, because the data server has determined the manufacturer key, the server SPT can use the manufacturer key to decrypt the first encrypted information and check the information extracted through decryption (e.g., at least one selected from personal identification number and serial number, etc.), thereby checking, determining, and / or verifying whether the SSD requested and / or expected to be discarded by the data owner has been correctly discarded.
[0076] According to at least one example embodiment, in operation S17, the data owner can perform a discard check process, and the security pin can output second encrypted information to the data owner's device (e.g., user SPT, etc.). According to at least one example embodiment, because the data owner knows and / or possesses the owner key, the user SPT can use the owner key to decrypt the second encrypted information and check, determine, and / or verify the information extracted through decryption (e.g., at least one selected from a personal identification number and a serial number), enabling the data owner to check, determine, and / or verify whether the SSD has been correctly discarded. For example, the data owner may have stored a serial number provided from a data server and / or stored a personal identification number set by the data owner, and can check whether the requested discarded SSD has been correctly discarded based on the extracted information and the information held by the data owner.
[0077] Figure 6 It is a flowchart of data storage and read operations of an SSD with a security pin mounted thereon, according to at least one example embodiment.
[0078] Reference Figure 6 The security pin can communicate with the security circuitry of the SSD. During the initial drive of the SSD, the first encrypted information Emfrk (PIN*, SN1) stored in the security pin can be provided to the security circuitry, and in operation S21, the SSD's security circuitry can decrypt the first encrypted information Emfrk (PIN*, SN1) using the manufacturer key mfrk stored therein; however, the example embodiments are not limited thereto. According to at least one example embodiment, the security circuitry may include a key derivation circuit. The key derivation circuitry may be a processing circuitry including hardware and / or a combination of hardware that performs software for performing at least one key derivation function; however, the example embodiments are not limited thereto, for example, the key derivation circuitry may be included in the security circuitry, etc.
[0079] The personal identification number PIN* and / or serial number SN1 extracted from the first encrypted information Emfrk(PIN*, SN1) can be provided as inputs to the key derivation circuit, and in operation S22, the key encryption key kek can be derived through the key derivation function. For example, the key derivation circuit can use both the personal identification number PIN* and the serial number SN1 as inputs. The data encryption key MEK used for real data encryption and / or decryption can be encrypted using the key encryption key kek and then stored in the SSD, and in operation S23, the security circuit can obtain the data encryption key MEK by performing decryption using the previously derived key encryption key kek.
[0080] Subsequently, the data owner can provide data to the data server and send a request to store the data. In operation S24, the data server can encrypt the data using the data encryption key MEK and store the encrypted data in the NVM. The data owner can then request the data from the data server. In operation S25, the data server can decrypt the data using the data encryption key MEK and provide the decrypted data to the data owner.
[0081] Figure 7 and Figure 8 This is a diagram illustrating the operation of setting a safety pin according to some example embodiments.
[0082] Reference Figure 7 The data server 500 can perform server functions based on various devices. For example, the data server 500 may include an SSD 520, a security pin 530, and / or an SPCM 510 for performing setup operations on the security pin 530, but the example embodiment is not limited thereto. The SPCM 510 may include interface circuitry (not shown) to communicate with the SSD 520 and the security pin 530, etc. Although in Figure 7 In this system, SPCM 510 can perform configuration operations on security pin 530 when security pin 530 is detached from SSD 520, but SPCM 510 can also perform configuration operations on security pin 530 when security pin 530 is installed on SSD 520.
[0083] SPCM 510 may include a serial number database (SN DB) that stores the serial numbers of multiple SSDs located in and / or connected to the data server 500. A personal identification number (PIN*) provided by each data owner using an SSD may also be stored in the SN DB. Figure 7 The example illustrates N pairs of serial numbers (SN) and personal identification numbers (PIN*) (e.g., {SN, PIN*}_1 to {SN, PIN*}_N, where N can be a positive integer) stored in a serial number database (SN DB), but the example embodiment is not limited thereto. According to at least one example embodiment, the serial number (SN) may be provided from the SSD 520 to a security circuitry with a security pin (530) mounted thereon, such as an SPCM 510. The personal identification number (PIN*) matching the serial number (SN) can be determined. For each SSD, the serial number (SN) and the personal identification number (PIN*) matching the serial number (SN) are encrypted using the manufacturer key (mfrk).
[0084] The following will refer to Figure 8 describe Figure 7 Example of setting up security locks on a data server 500.
[0085] Reference Figure 7 and Figure 8 The SPCM 510 can be provided with a serial number (SN) from the SSD and a personal identification number (PIN)* from the data owner, and can manage multiple serial number SNs and PINs* stored in at least one database. When it is expected and / or a specific SSD (e.g., Figure 7 When an SSD 520 (e.g., SSD 520) is connected to an SPCM 510, the SSD 520's serial number SN can be provided to the SPCM 510, and the SPCM 510 can generate a first encrypted message Emfrk(PIN*, SN) by encrypting the serial number SN and the personal identification number PIN* that matches the serial number SNPIN* using the manufacturer key mfrk, and can set and / or store the first encrypted message Emfrk(PIN*, SN) in the security pin 530, but the example embodiment is not limited thereto.
[0086] Data server 500 can provide the serial number SN to the data owner and request the data owner to generate second encrypted information Eok(PIN*, SN). The data owner may possess and / or know the personal identification number PIN* that the data owner has set, and generates the second encrypted information Eok(PIN*, SN) by encrypting the serial number SN and the personal identification number PIN* using the owner key ok. The second encrypted information Eok(PIN*, SN) generated by the data owner can be provided to SPCM 510. SPCM 510 can set, input, and / or store the second encrypted information Eok(PIN*, SN) in security pin 530.
[0087] Once the security pin 530 is configured, it can be installed on the SSD 520. In one example operation, the security pin 530 may be installed on the SSD 520 using an insertion method, but the example embodiment is not limited to this. Therefore, when power is applied to the SSD 520 with the security pin 530 installed thereon, communication can be performed between the security pin 530 and the security circuitry (not shown) of the SSD 520. The security pin 530 can be authenticated, and based on the authentication result, a series of operations can be performed to generate data encryption keys, etc., for data encryption and / or decryption.
[0088] Figure 9 This is a flowchart of the operation of a storage device according to at least one example embodiment. Figure 9 An example of certifying the security pins in the initial drive of an SSD with security pins installed on it is shown.
[0089] Reference Figure 9The security pin generated according to at least one example embodiment can be installed on the SSD, and in operation S31, when power is supplied to the SSD, the SSD can perform a boot operation (e.g., power-on operation, power-on operation, etc.). In operation S32, during the boot operation, first encrypted information stored in the security pin can be provided to the security circuit. Since the first encrypted information has been generated by encrypting it using a manufacturer's key, the security circuit can use the manufacturer's key stored therein to decrypt the first encrypted information. Therefore, in operation S33, the SSD's security circuit can extract the serial number, etc., included in the first encrypted information by decrypting it.
[0090] In operation S34, authentication of the security pin can be performed based on the result of determining whether the serial number extracted from the first encrypted information is the same as the serial number stored in the security pin. For example, when the serial numbers are different, in operation S35, the SSD (e.g., the SSD's processing circuitry (such as security circuitry)) determines that the authentication of the security pin has failed, and therefore, the process for generating the data encryption key for data encryption and / or decryption may not be performed. Conversely, when the serial numbers are the same, in operation S36, the SSD (e.g., the SSD's processing circuitry (such as security circuitry)) determines that the authentication of the security pin has succeeded, and therefore, in operation S37, the process for generating the data encryption key can be performed based on the information extracted from the first encrypted information (e.g., the serial number and the personal identification number).
[0091] In at least one example embodiment, a serial number including a random number string (and / or a pseudo-random number string, etc.), a unique identifier, etc., is used as information for authentication, but the example embodiment is not limited thereto. For example, additional information (such as a checksum) may be further used for authentication, making it possible to check whether the serial number has been forged, thus enhancing the accuracy of authentication.
[0092] According to at least one example embodiment, because authentication can be successful in an SSD with the security pin properly installed, and user data can be encrypted and / or decrypted based on successful authentication, the user data stored in the SSD can be securely discarded when the security pin is removed from the SSD. Furthermore, the authentication operation can be performed during each boot of the SSD, and the data encryption key temporarily stored in the security circuitry can be removed and / or discarded when data storage and provisioning are complete. In other words, after the security pin is removed from the SSD, the data encryption key is not in the SSD and is difficult and / or impossible to generate; therefore, the user data can be securely discarded.
[0093] Figure 10 and Figure 11 These are illustrations of a storage device and its operation methods according to some example embodiments.
[0094] Reference Figure 10 The storage device 600 may include a security pin 610 and / or security circuitry (e.g., a security module) 620, but is not limited thereto. The security pin 610 may store first encrypted information Emfrk (PIN*, SN) 611 and second encrypted information Eok (PIN*, SN) 612, and may include a flag storage circuit 613, etc. The security circuitry 620 may include a security pin authentication circuit (SCM) 621 (e.g., a security pin authentication module 621) and a key derivation circuit 622, and may store a manufacturer key 623 (e.g., a manufacturer key mfrk) and a serial number 624 (e.g., a serial number SN), but the example embodiment is not limited thereto.
[0095] According to at least one example embodiment, the security pin authentication circuit 621 can authenticate the security pin 610. For example, the security pin authentication circuit 621 can perform authentication based on a comparison between the serial number SN extracted from the first encrypted information Emfrk(PIN*, SN) and the serial number 624 stored in the security circuit 620. The security circuit 620 can perform a setting operation on the flag storage circuit 613 according to the authentication result. For example, the security circuit 620 can set a flag Set_F with a first value in the flag storage circuit 613 when authentication fails, and can set a flag Set_F with a second value in the flag storage circuit 613 when authentication succeeds.
[0096] The following will refer to at least one example embodiment. Figure 11 describe Figure 10 An example of the operation of storage device 600.
[0097] Reference Figure 10 and Figure 11 In operation S41, the security circuit 620 can authenticate the security pin 610; in operation S42, it can determine whether the authentication was successful or failed; and in operation S43, in response to authentication failure, it can set a flag with a first value in the flag storage circuit 613, thus eliminating the need to perform the process for generating the data encryption key. Otherwise, in operation S44, in response to successful authentication, the security circuit 620 can set a flag with a second value in the flag storage circuit 613 of the security pin 610.
[0098] In operation S45, when authentication of the security pin 610 is successful, a data encryption key can be generated and stored in the security circuit 620. Subsequently, in operation S46, when the storage device 600 is restarted, communication can be performed between the security pin 610 and the security circuit 620, and the security circuit 620 can determine the flag stored in the flag storage circuit 613 of the security pin 610 without performing authentication.
[0099] In operation S47, it can be determined whether the flag has a second value indicating that authentication has been successful. When the flag does not have a second value, in operation S48, data access using the data encryption key can be prohibited and / or disabled. Otherwise, when the flag has a second value, in operation S49, data encryption and / or decryption can be performed using the data encryption key that has been generated through the authentication operation and stored in the security circuit 620.
[0100] According to at least one example embodiment, storage device 600 does not require and / or does not require authentication of security pin 610 during each boot operation, and data encryption and / or decryption can be performed based on the result of authentication of security pin 610 during the initial boot operation. For example, when the installation state of security pin 610 is successfully authenticated during the initial boot operation and the configuration of storage device 600 is maintained (e.g., security pin 610 is not removed from storage device 600 and / or storage device 600 is not modified, etc.), normal data access can be performed using the data encryption key stored in security circuitry 620 based on the result of checking the flag set in security pin 610, without re-performing authentication of security pin 610. Conversely, when initial authentication of security pin 610 fails, if a flag value indicating authentication failure is set, storage device 600 will not operate normally (e.g., data access to encrypted user data is prohibited and / or disabled) even when storage device 600 is restarted, until successful authentication of security pin 610 is performed, making user data inaccessible without permission and / or preventing the use of user data.
[0101] Even if authentication of the security pin 610 is successful during the initial startup operation, the flag value set in the security pin 610 may not be recognized after the security pin 610 is removed from the storage device 600. Therefore, user data may be more difficult to use without permission and / or prevented from being used without permission. When the flag value set in the security pin 610 cannot be recognized after the data encryption key is stored in the security circuit 620, the operation of removing the data encryption key can be further performed under the control of the security circuit 620, so that the data encryption key can be deleted, removed, and / or not retained in the storage device 600 after the security pin 610 is removed from the storage device 600.
[0102] Figure 12 and Figure 13 It is a diagram illustrating various operations of a storage system according to at least one example embodiment. Figure 12 Various devices that communicate with a security pin (e.g., an SSD security pin) are shown.
[0103] Reference Figure 12The storage system 700 may include an SSD security pin 710, and various means of communicating with the SSD security pin 710 are shown. For example, the SSD security pin 710 may communicate with an SPCM 720 that sets encryption information, a security circuit 730 included in the storage device (not shown), and / or an SPT 740 that checks whether the storage device has been properly discarded; however, the example embodiments are not limited thereto. According to some example embodiments, the SPT 740 may include an SPT used by the administrator of the storage device for discard checks and / or an SPT used by the data owner for discard checks. Assuming... Figure 12 SPT 740 in the example corresponds to the SPT used by the data owner for discard checks, but the example embodiment is not limited to this.
[0104] The SSD security pin 710 may include, but is not limited to, various components (e.g., security pin action history log 711, SSD security pin input / output (I / O) engine 712, storage circuitry 713, and / or I / O interface circuitry 714, etc.). The I / O interface circuitry 714 of the SSD security pin 710 provides a common interface for communication with various devices. The storage circuitry 713 may store first encrypted information Emfrk (PIN*, SN) and second encrypted information Eok (PIN*, SN).
[0105] The SSD security pin I / O engine 712 can determine the type and / or class of the device connected to the SSD security pin 710 based on information sent and received through the I / O interface circuit 714, and can set access permissions to the storage circuit 713 based on the determination result. In one example operation, the I / O interface circuit 714 can receive information identifying the device and / or unique information about the device from a device located outside or connected to the SSD security pin 710, and the SSD security pin I / O engine 712 can determine the type of device based on the received information. The SSD security pin I / O engine 712 can be implemented as a processing circuit, for example, through hardware circuitry such as an application-specific integrated circuit (ASIC) and / or using a combination of hardware and software such as a microcontroller unit (MCU) and / or other various forms, and can be integrated, for example, with the SSD's processing circuitry, security circuitry 730, etc.
[0106] For example, when SPCM 720 is connected to SSD security pin 710, SSD security pin I / O engine 712 can determine the connection of SPCM 720 based on information received through I / O interface circuit 714, and can set access permissions so that the first encrypted information Emfrk (PIN*, SN) and the second encrypted information Eok (PIN*, SN) from SPCM 720 are stored in storage circuit 713. When security circuit 730 is connected to SSD security pin 710, SSD security pin I / O engine 712 can set access permissions to storage circuit 713 so that the first encrypted information Emfrk (PIN*, SN) is read and provided to security circuit 730. When the data owner's SPT 740 is connected to SSD security pin 710, SSD security pin I / O engine 712 can set access permissions to storage circuit 713 so that the second encrypted information Eok (PIN*, SN) is read and provided to SPT 740.
[0107] To enhance the security of the SSD security pin 710 or the storage device on which the SSD security pin 710 is installed, the security pin action history log 711 can store the access history of the storage circuit 713, but the example embodiment is not limited to this. In one example operation, access to the storage circuit 713 can be controlled by the SSD security pin I / O engine 712, and the SSD security pin I / O engine 712 can store the access history in the security pin action history log 711, etc. For example, when the first encrypted information Emfrk (PIN*, SN) and the second encrypted information Eok (PIN*, SN) are stored in the storage circuit 713 through the SPCM 720, information indicating that the SPCM 720 has accessed the storage circuit 713, timestamps indicating the access time, etc., can be stored in the security pin action history log 711 under the control of the SSD security pin I / O engine 712, but the example embodiment is not limited to this.
[0108] The following will refer to at least one example embodiment. Figure 13 describe Figure 12 Example operation of storage system 700.
[0109] In operation S51, any of various external devices (such as SPCM 720, security circuit 730, and SPT 740) can be connected to SSD security pin 710. In operation S52, SSD security pin 710 can determine the type and / or class of the external device connected to it. Authentication can be performed between SSD security pin 710 and the external device. For example, in operation S53, SSD security pin 710 and the external device can perform authentication with each other by exchanging and processing various information. Various methods for authentication can be used. For example, challenge-response authentication can be performed, but the example embodiment is not limited thereto.
[0110] When authentication is successful, in operation S54, the SSD security pin 710 can set access permissions for external devices to the storage circuit, and the storage circuit stores key information in the SSD security pin 710. For example, access permissions to the storage circuit can be set differently depending on the type and / or kind of external device connected to the SSD security pin 710. Permissions to store or read the first encrypted information Emfrk (PIN*, SN) and the second encrypted information Eok (PIN*, SN) from the storage circuit can be set differently. According to at least one example embodiment, in operation S55, the storage circuit storing the first encrypted information Emfrk (PIN*, SN) and the second encrypted information Eok (PIN*, SN) can be accessed according to the set permissions, and in operation S56, information indicating the access history can be stored in the SSD security pin 710; however, the example embodiment is not limited to this.
[0111] Figure 14 This is a flowchart of a process for checking whether a storage device has been discarded, according to at least one example embodiment.
[0112] Reference Figure 14 When the security pin is connected to the data server SPT_ds (e.g., the storage device and / or interface of the data server SPT), the security pin can perform mutual authentication with the data server SPT_ds and determine that the connected device is the data server SPT_ds. The security pin can be configured with access permissions such that the first encrypted information Emfrk (PIN*, SN) can be read from the storage circuitry, thus providing the first encrypted information Emfrk (PIN*, SN) to the data server SPT_ds. According to at least one example embodiment, the data server SPT_ds can decrypt the first encrypted information Emfrk (PIN*, SN) using the manufacturer key mfrk and can perform a discard check process. According to at least one example embodiment, the data server can manage serial numbers and / or personal identification numbers in at least one database. For storage devices determined to be discarded through the discard check process, a tag and / or information indicating the discarded storage device can be stored in the database, but the example embodiments are not limited to this.
[0113] Similarly, when the security pin is connected to the data owner SPT_owner, the security pin can perform mutual authentication with the data owner SPT_owner, and can provide the second encrypted information Eok(PIN*, SN) to the data owner SPT_owner based on the authentication result. According to at least one example embodiment, the data owner SPT_owner can decrypt the second encrypted information Eok(PIN*, SN) and can perform a discard check process.
[0114] Figure 15 This is a block diagram of a network system including a data server according to at least one example embodiment. Figure 15 The diagram illustrates multiple terminals (e.g., compute nodes) and a data server, which may include a storage system according to some example embodiments, but the example embodiments are not limited thereto.
[0115] Reference Figure 15 The network system 800 may include a data server 810 and multiple terminals (e.g., terminal 1 801, terminal 2 802, and terminal n 803, etc., where n is an integer greater than 1) that communicate with each other over the network. However, the example embodiment is not limited to this, and any number of terminals may exist. The data server 810 may include a server 811 that serves as a host and at least one SSD 812 that serves as a storage device.
[0116] Server 811 can process requests received from terminals 801 to 803 connected to the network. For example, server 811 can store data from one or more of the terminals 801 to 803 in SSD 812. Data from terminals 801 to 803 can be encrypted and then stored in SSD 812. Data stored in SSD 812 can be decrypted and then provided to one or more of the terminals 801 to 803. According to at least one example embodiment, a security pin SP can be installed on SSD 812. When one of the terminals 801 to 803 requests to discard SSD 812, the security pin SP can be removed from SSD 812.
[0117] Figure 16 This is a block diagram of a network system 900 according to at least one example embodiment.
[0118] Reference Figure 16The network system 900 may include a client group 910 and a data center 920. The client group 910 may include client devices C that communicate with the data center 920 via at least one first network NET1 (e.g., the Internet, cloud network, intranet, LAN, etc.), but the example embodiment is not limited thereto. The data center 920 may store various types of data and provide services, and may include an application server group 921, a database server group 923, and / or an object cache server group 922, etc., that communicate with each other via at least one second network NET2 (e.g., a LAN, intranet, etc.).
[0119] Application server group 921 may include, but is not limited to, one or more application server devices AS. Application server devices AS may process requests received from client group 910 and may access database server group 923 and / or object cache server group 922, etc., upon request from client group 910. Database server group 923 may include one or more database server devices DS that store data processed by application server devices AS. Object cache server group 922 may include one or more object cache server devices OCS, which temporarily store (e.g., buffer and / or cache) data to be stored in and / or read from database server devices DS; therefore, object cache server devices OCS act as a cache between application server devices AS and database server devices DS.
[0120] According to some example embodiments, storage devices and storage systems may be included in network system 900 in various forms. For example, storage devices according to some example embodiments may be used to store data in database server group 923, but the example embodiments are not limited thereto. Therefore, multiple storage devices (e.g., SSDs or HDDs) may be included. Figure 16 In the database server group 923, and according to some example embodiments, a security pin may be installed on each storage device, etc.
[0121] Although various exemplary embodiments of the inventive concept have been specifically shown and described with reference to exemplary embodiments thereof, it will be understood that various changes in form and detail may be made therein without departing from the spirit and scope of the appended claims.
Claims
1. A storage device for storing data, the storage device comprising: A security pin device is removably installed in the storage device. The security pin device is configured to store first encrypted information and second encrypted information. The first encrypted information is encrypted using a first key associated with a first user, and the second encrypted information is encrypted using a second key associated with a second user. The first user includes a data server and / or the administrator of the data server, and the second user includes a data owner. The safety circuit is configured as follows: Receive the first encrypted information from the security pin device. Decrypt the first encrypted information, and A data encryption key is generated based on the result of decrypting the first encrypted information; and Non-volatile memory, configured to store data encrypted with a data encryption key. The first encrypted information is generated by encrypting first unique information associated with the storage device and second unique information associated with the second user using a first key. The second encrypted information is generated by encrypting the first and second unique information using a second key, and The information extracted and / or decrypted from the first encrypted information is used to determine whether the storage device has been properly discarded, and / or the information extracted and / or decrypted from the second encrypted information is used to determine whether the storage device has been properly discarded.
2. The storage device according to claim 1, wherein, The storage device includes at least a solid-state drive.
3. The storage device according to claim 1, wherein, The second encrypted information is generated by the second user and stored in the security pin device.
4. The storage device according to claim 1, wherein, The first unique information includes a unique identifier corresponding to the storage device, and the second unique information includes a personal identification number associated with the second user.
5. The storage device according to claim 1, wherein, The safety circuit is also configured as follows: Store the first key and a unique identifier corresponding to the storage device; Decryption of the first encrypted information is performed using the first key; Extract the first unique information from the decrypted first encrypted information; as well as The security pin device is authenticated based on the unique identifier corresponding to the storage device and the extracted first unique information.
6. The storage device according to claim 5, wherein, The safety circuit and the safety pin device are each configured to be connected to the safety pin creation circuit, and The safety pin creation circuit is configured as follows: Perform the setting operation on the safety pin device. Receive a unique identifier corresponding to the storage device stored in the security circuit. First encrypted information and second encrypted information are generated using a unique identifier corresponding to the storage device as the first unique information, and The generated first encrypted information and the generated second encrypted information are sent to the security pin device.
7. The storage device according to any one of claims 1 to 6, wherein, The safety pin device includes an interface circuit configured to communicate with a safety pin tester device, and The security pin device is also configured to send second encrypted information to the security pin tester device via an interface circuit when the security pin device has been removed from the storage device.
8. The storage device according to claim 7, wherein, The second encrypted information is generated by encrypting the same information that corresponds to the second user and is stored in the security pin tester device.
9. The storage device according to any one of claims 1 to 6, further comprising: The storage circuit is configured to store third encrypted information generated by encrypting the data encryption key with a third key; The safety circuit is also configured as follows: The third key is derived using information extracted from the first encrypted information as input, and A data encryption key is generated by decrypting the third encrypted information using a third key.
10. The storage device according to claim 9, wherein, The security circuit is also configured to encrypt and / or decrypt the second user's data using a data encryption key.
11. A safety pin device, removably mounted on at least one storage device configured to store data, the safety pin device comprising: At least one storage circuit is configured to store first encrypted information and second encrypted information, the first encrypted information being encrypted using a first key associated with a first user, and the second encrypted information being encrypted using a second key associated with a second user, wherein the first user includes a data server and / or an administrator of the data server, and the second user includes a data owner; and A first interface circuit is configured to output a second encrypted message after the security pin is removed from the storage device, allowing a second user to determine whether the storage device has been properly discarded. The first encrypted information is generated by encrypting first unique information associated with the storage device and second unique information associated with the second user using a first key. The second encrypted information is generated by encrypting the first and second unique information using a second key, and The information extracted and / or decrypted from the first encrypted information is used to determine whether the storage device has been properly discarded, and / or the information extracted and / or decrypted from the second encrypted information is used to determine whether the storage device has been properly discarded.
12. The safety pin device according to claim 11, wherein, The first interface circuit is also configured to connect to a second user safety pin tester device associated with the second user, and The second user security pin tester device is configured to: store a second key and receive second encrypted information.
13. The safety pin device according to claim 11, wherein, The first interface circuit is also configured to connect to a first user safety pin tester device associated with the first user, and The first user security pin tester device is configured to: store a first key and receive first encrypted information to allow a first user to determine whether the storage device has been properly discarded.
14. The safety pin device according to claim 11, wherein, The first unique information includes a unique identifier associated with the storage device, and the second unique information includes a personal identification number associated with a second user.
15. The safety pin device according to claim 14, wherein, The safety pin device is also configured to: A safety pin creation circuit connected to the outside of the safety pin device; and The circuit is created from the security pin to receive the first encrypted information.
16. The safety pin device according to claim 14, wherein, The safety pin device is also configured to: A safety pin creation circuit connected to the exterior of the safety pin device; as well as The circuit receives second encrypted information via a security pin. The second encrypted information is generated by the second user by encrypting a unique identifier associated with the storage device and a personal identification number using a second key.
17. The safety pin device according to any one of claims 11 to 16, further comprising: At least one second interface circuit is configured as follows: Communicating with security circuitry included in the storage device; as well as The first encryption information is provided to the security circuit so that the storage device can generate a data encryption key for data encryption and / or decryption.
18. A method of operating a storage device, the method comprising: The first encrypted information stored in the security pin device is provided to the security circuit through communication between the security pin device and the security circuit. The first encrypted information is encrypted using a first key associated with a first user, wherein the first user includes the data server and / or the administrator of the data server. The first encrypted information is decrypted using the first key stored in the security circuit; A data encryption key is generated based on the first information through a security circuit, and the first information is extracted from the first encrypted information. Encrypt the data using a data encryption key; and Store encrypted data. The first encrypted information is generated by encrypting first unique information associated with the storage device and second unique information associated with the second user using a first key. The second user includes the data owner. The information extracted and / or decrypted from the first encrypted information is used to determine whether the storage device has been properly discarded.
Citation Information
Patent Citations
Method of guided cross-component prediction for video coding
KR1020200051831A
Three-Dimensional Semiconductor Memory Devices And Methods Of Fabricating The Same
US20110233648A1
Non-volatile memory device, erasing method thereof, and memory system including the same
US8553466B2
Nonvolatile memory device, operating method thereof and memory system including the same
US8559235B2
Nonvolatile memory devices, channel boosting methods thereof, programming methods thereof, and memory systems including the same
US8654587B2