Memory system, control method of memory system, and information processing system
By using the combination of data encryption key and key encryption key in the memory system, the contradiction between cross-user data deduplication and confidentiality is solved, efficient storage efficiency and data confidentiality are achieved, and it is suitable for non-volatile memory systems.
Patent Information
- Application Number
- CN202110196076.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-07
- Filing Date
- 2021-02-22
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-02-22
AI Technical Summary
When existing memory systems realize data deduplication across multiple users, it is difficult to maintain the data confidentiality of each user and improve storage efficiency at the same time.
By using a combination of data encryption key (DEK) and key encryption key (KEK) in the memory system, a unique DEK is generated based on the user and encrypted with KEK, the data deduplication and encryption are realized, ensuring the data confidentiality of each user, and deduplication is performed when the user data is the same.
It realizes the improvement of storage efficiency without leaking data confidentiality, allowing multiple users to share encrypted data of the same data, extending the life of the storage device, and preventing illegal access.
Smart Images

Figure CN114064525B_ABST
Abstract
Description
[0001] This application claims priority based on Japanese Patent Application No. 2020-134803 (filing date: August 7, 2020). This application incorporates the entire contents of the base application by reference thereto. Technical Field
[0002] Embodiments of the present invention relate to a memory system including a non-volatile memory, a control method of the memory system, and an information processing system. Background Art
[0003] In recent years, memory systems including non-volatile memories have become widespread.
[0004] As one such memory system, a solid state drive (SSD) including a NAND type flash memory is known. The SSD is used as a main storage of various computing devices.
[0005] Data stored in a storage may sometimes be encrypted. For example, by encrypting data with an encryption key (password key) unique to each user, confidentiality such that data of a certain user cannot be obtained by other users can be achieved.
[0006] In addition, recently, there has been a demand for efficiently storing a large amount of data in a storage. As a technique for improving storage efficiency, a de-duplication technique is known.
[0007] However, since data encrypted with a key of each user cannot be shared by multiple users, it is difficult to achieve de-duplication of data across multiple users. For this reason, there is a need to implement a new function that can maintain the confidentiality of data of each user and (simultaneously) improve storage efficiency. Summary of the Invention
[0008] The present invention provides a memory system, a control method of the memory system, and an information processing system that can maintain the confidentiality of data of each user and improve storage efficiency.
[0009] According to an embodiment, a memory system includes a first non-volatile memory and a controller. The first non-volatile memory stores first encrypted data obtained by encrypting first data with a first data encryption key. When the second data received from a host together with a write request is the same as the first data (identical data) and the user using the host is a first user, the controller encrypts the first data encryption key with a first key encryption key associated with the first user to obtain a first encrypted data encryption key, and stores the first encrypted data encryption key. When the second data is the same as the first data and the user using the host is a second user different from the first user, the controller encrypts the first data encryption key with a second key encryption key associated with the second user to obtain a second encrypted data encryption key, and stores the second encrypted data encryption key. When the second data is different from the first data and the user using the host is the first user, the controller generates a second data encryption key using the second data, encrypts the second data with the second data encryption key to obtain second encrypted data, writes the second encrypted data into the first non-volatile memory, encrypts the second data encryption key with the first key encryption key to obtain a third encrypted data encryption key, and stores the third encrypted data encryption key. When the second data is different from the first data and the user using the host is the second user, the controller generates the second data encryption key using the second data, encrypts the second data with the second data encryption key to obtain the second encrypted data, writes the second encrypted data into the first non-volatile memory, encrypts the second data encryption key with the second key encryption key to obtain a fourth encrypted data encryption key, and stores the fourth encrypted data encryption key. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 FIG. is a block diagram showing a configuration example of an information processing system including the memory system according to the first embodiment.
[0011] Figure 2 FIG. is a diagram showing an example of data deduplication in the memory system according to the first embodiment.
[0012] Figure 3 FIG. is a diagram showing a structural example of a logical-physical address translation table used in the memory system according to the first embodiment.
[0013] Figure 4 FIG. is a diagram showing a structural example of a physical address-hash value correspondence table used in the memory system according to the first embodiment.
[0014] Figure 5 This is a diagram showing a structural example of an encrypted DEK (Data Encryption Key) table used in the memory system according to the first embodiment.
[0015] Figure 6 This is a block diagram showing examples of write operations and read operations in the memory system according to the first comparative example.
[0016] Figure 7 This is a block diagram showing examples of write operations and read operations in the memory system according to the second comparative example.
[0017] Figure 8 This is a block diagram showing an example of a write operation in the memory system according to the third comparative example when there is no duplicate data.
[0018] Figure 9 This is a block diagram showing an example where a write operation cannot be achieved in the memory system according to the third comparative example when there is duplicate data.
[0019] Figure 10 This is a block diagram showing an example of a write operation in the memory system according to the first embodiment.
[0020] Figure 11 This is a block diagram showing an example of a read operation in the memory system according to the first embodiment.
[0021] Figure 12 This is a flowchart showing an example of the steps of control processing executed in the memory system according to the first embodiment.
[0022] Figure 13 This is a flowchart showing an example of the steps of read processing executed in the memory system according to the first embodiment.
[0023] Figure 14 This is a flowchart showing an example of the steps of write processing executed in the memory system according to the first embodiment.
[0024] Figure 15 This is a block diagram showing a configuration example of an information processing system including the memory system according to the second embodiment.
[0025] Figure 16 This is a block diagram showing an example of a write operation in the memory system according to the second embodiment.
[0026] Reference Numeral Explanation
[0027] 1 Information processing system; 2 Host; 3 SSD; 4 Controller; 5 NAND flash memory; 6 DRAM; 11 Host I / F (interface); 12 CPU; 13 NAND I / F; 14 DRAM I / F; 121 Write control unit; 122 Read control unit; 123 Repetition control unit; 124 DEK (Data Encryption Key) generation unit; 125 KEK (Key Encryption Key) generation unit; 126 DEK encryption / decryption unit; 127 Data encryption / decryption unit; 20 FW (Firmware); 21 Logical-physical address translation table; 22 Physical address - hash value correspondence table; 23 Encrypted DEK table. Detailed implementation
[0028] Hereinafter, with reference to the drawings, the embodiments will be described.
[0029] (First Embodiment)
[0030] First, with reference to Figure 1 , the configuration of the information processing system 1 including the memory system according to the first embodiment will be described. The information processing system 1 includes a host device 2 (hereinafter referred to as the host 2) and a memory system.
[0031] The memory system is a semiconductor storage device configured to write data to a non-volatile memory such as the NAND flash memory 5 and read data from the non-volatile memory, and is also referred to as a storage device. The non-volatile memory includes a plurality of storage elements, and data can be written to each of the plurality of storage elements multiple times. The memory system is implemented, for example, as an SSD (Solid State Drive) 3 having the NAND flash memory 5. Although the case where the memory system is implemented as the SSD 3 will be exemplified below, the memory system can also be implemented as a hard disk drive (HDD). Alternatively, the memory system can also be implemented as a storage system (so-called enterprise storage) having a plurality of storage devices.
[0032] The host 2 can be either a storage server that stores a large amount and variety of data in the SSD 3 or a personal computer. The host 2 can be used by multiple users (for example, users A, B, and C). In addition, there can be multiple hosts, and each host can be used by one or more users.
[0033] The SSD 3 can be used as the storage of the host 2. The SSD 3 can be either built into the host 2 or connected to the host 2 via a cable or a network.
[0034] The interface for connecting the host 2 and the SSD 3 complies with SCSI (Small Computer System Interface Standard), SAS (Serial Attached SCSI), ATA (AT Attachment), SATA (Serial ATA), PCIe (PCI Express, a high-speed serial computer expansion bus standard) (registered trademark), Ethernet (registered trademark), Fibre Channel, NVMe (NVM Express, a non-volatile memory standard) (registered trademark), etc.
[0035] The SSD 3 includes a controller 4 and a NAND flash memory 5. The controller 4 can be implemented by a circuit such as a SoC (System-on-a-Chip).
[0036] The SSD 3 may also include a random access memory (RAM) as a volatile memory, such as a DRAM (Dynamic Random Access Memory) 6. Alternatively, a RAM such as a static random access memory (SRAM) may be built into the controller 4. In addition, the DRAM 6 may also be built into the controller 4.
[0037] In a RAM such as the DRAM 6, for example, a storage area for loading the FW (Firmware) 20 from the NAND flash memory 5 is provided.
[0038] The NAND flash memory 5 includes a plurality of blocks. Each block includes multiple pages. One block functions as the smallest erasure unit. A block is sometimes also referred to as an "erasure block" or a "physical block". Each page includes multiple memory cells connected to the same word line. One page is the unit of data writing and data reading operations. In addition, the word line may also be used as the unit of data writing and data reading operations.
[0039] There is an upper limit (maximum P / E cycle number) for the number of programming / erasure cycles that can be tolerated for each block. One P / E cycle of a certain block includes an erasure operation for making all the memory cells in the block in the erased state and a writing operation for writing data to each page of the block.
[0040] The controller 4 may also include a host I / F (host interface) 11, a CPU 12, a NAND I / F 13, a DRAM I / F (DRAM interface) 14, etc. The above host I / F 11, CPU 12, NAND I / F 13, DRAM I / F 14 can be interconnected via a bus 10.
[0041] The controller 4 is electrically connected to the NAND type flash memory 5 via a NAND I / F 13 corresponding to interface standards such as Toggle DDR and ONFI (Open NAND Flash Interface). The NAND I / F 13 functions as a NAND control circuit configured to control the NAND type flash memory 5.
[0042] The NAND I / F 13 may also be connected to a plurality of NAND type flash memory chips in the NAND type flash memory 5 via a plurality of channels (Ch). By driving the plurality of NAND type flash memory chips in parallel, it is possible to widen the access bandwidth to the NAND type flash memory 5.
[0043] The controller 4 functions as a memory controller configured to control the NAND type flash memory 5.
[0044] The controller 4 may also function as a flash translation layer (FTL: Flash translation layer) configured to perform data management and block management of the NAND type flash memory 5. Data management performed by the FTL includes (1) management of mapping information indicating the correspondence between each logical address and each physical address of the NAND type flash memory 5, (2) processing for hiding read / write operations in units of pages and erase operations in units of blocks, etc. The logical address is an address used by the host 2 to specify an address for the SSD 3.
[0045] Regarding the management of the mapping between each logical address and each physical address, it is performed using a logical physical address translation table 21. The controller 4 uses the logical physical address translation table 21 to manage the mapping between each logical address and each physical address in units of a specific management size. The physical address corresponding to a certain logical address indicates the physical storage location in the NAND type flash memory 5 where the data of the logical address is written. The logical physical address translation table 21 may also be loaded from the NAND type flash memory 5 to the DRAM 6 when the power of the SSD 3 is turned on (ON).
[0046] Each P / E cycle can only perform a data write to one page once. Therefore, instead of writing the updated data corresponding to a certain logical address to the physical storage location storing the previous data corresponding to that logical address, the controller 4 writes the updated data to another physical storage location. Moreover, the controller 4 updates the logical-physical address translation table 21 in a manner that associates the logical address with the other physical storage location, thereby invalidating the previous data. Hereinafter, the data referred to from the logical-physical address translation table 21 (i.e., the data associated with the logical address) is called valid data. In addition, the data not associated with any logical address is called invalid data. Valid data is data that may be read from the host 2 later. Invalid data is data that can no longer be read from the host 2.
[0047] The above physical address and logical address are concepts used to control the NAND flash memory 5 and the hard disk (HD). This physical address usually determines a storage area in units of 512 bytes to 4096 bytes. In addition, this logical address is defined by various international standards. These physical addresses and logical addresses are the physical / logical addresses of NAND technology and are hereinafter referred to as the physical / logical addresses of the lower layer. The controller 4 uses the physical / logical addresses of the lower layer, for example, in a layer close to the control of the NAND flash memory 5.
[0048] The controller 4 can also manage the physical address and logical address (hereinafter referred to as the physical / logical addresses of the upper layer) for determining a larger storage area in a layer close to the host 2. These physical addresses and logical addresses determine a storage area in units of several kilobytes (KB) to several megabytes (MB), for example. In the present embodiment, the physical / logical addresses of the upper layer are used, for example, in the deduplication and encryption of data described later.
[0049] That is to say, the controller 4 can be configured to use the physical / logical addresses of the lower layer in a layer close to the NAND flash memory 5 and use the physical / logical addresses of the upper layer in a layer closer to the host 2.
[0050] Block management includes management of bad blocks, wear leveling, garbage collection, etc.
[0051] The host I / F 11 is a hardware interface circuit that conducts communication between the SSD 3 and the host 2 which is an external device of the SSD 3. The host I / F 11 functions as a circuit that receives various commands such as I / O commands and various control commands from the host 2. The I / O commands may include write commands and read commands. The control commands may include unmap commands (trim commands) and format commands. The format command is a command for unmapping the entire SSD 3. The host I / F 11 also functions as a transmission circuit that sends responses and data corresponding to the commands to the host 2.
[0052] The DRAM I / F 14 functions as a DRAM control circuit configured to control access to the DRAM 6. The storage area of the DRAM 6 is, for example, allocated as an area for storing the FW 20, a buffer area used as a read / write buffer, etc., and a cache area for information such as the logical-physical address translation table 21, the physical address-hash value correspondence table 22, and the encrypted DEK table 23.
[0053] The physical address-hash value correspondence table 22 and the encrypted DEK table 23 can be loaded from the NAND flash memory 5 into the DRAM 6 when the power of the SSD 3 is turned on. The physical address-hash value correspondence table 22 shows the correspondence between the physical address indicating the physical storage location of the user data encrypted and stored in the NAND flash memory 5 and the hash value of the user data. The encrypted DEK table 23 is a table for storing the data encryption key (DEK) used to encrypt the user data in an encrypted manner. Details of the physical address-hash value correspondence table 22 and the encrypted DEK table 23 will be described later with reference to Figure 4 and Figure 5 respectively.
[0054] The controller 4 has functions for data deduplication and encryption.
[0055] Figure 2 An example of data deduplication in the SSD 3 is shown. Deduplication is a control method that prevents the same pattern of data from being repeatedly written to the NAND flash memory 5. The controller 4 analyzes the user data to be written to the NAND flash memory 5 and automatically excludes the detected duplicate data. That is, when the user data to be written to the NAND flash memory 5 is duplicate data, the controller 4 skips (omits) the writing of the user data.
[0056] For example, in the regular backup process, the writing of user data identical to the user data already written to the NAND flash memory 5 may occur frequently. In this case, through deduplication, the data transfer volume and data storage capacity can be significantly reduced. In addition, in hardware with an upper limit on the number of P / E cycles such as the NAND flash memory 5, the life of the hardware can be extended by reducing the number of data writes.
[0057] In Figure 2 , an example of data deduplication is shown by the data configuration (layout) 51 based on the physical address and the data configuration 52 based on the logical address. The data configuration 51 based on the physical address represents the physical storage location of the data (data pattern) on the NAND flash memory 5. The data configuration 52 based on the logical address represents the logical storage location of the data recognized by the host 2.
[0058] Specifically, in the data configuration 51 based on the physical address, the data pattern A is stored at the physical address "1". The data pattern B is stored at the physical address "2". The data pattern C is stored at the physical address "3". In addition, the physical address "4" is in an unused state.
[0059] In contrast, in the data configuration 52 based on the logical address, the data pattern A is stored at the logical address "1". The data pattern B is stored at the logical address "2". The data pattern C is stored at the logical address "3". The data pattern B is stored at the logical address "4".
[0060] Accordingly, the data pattern B is physically stored only at one place (i.e., the physical address "2"), but is recognized by the host 2 as being stored at two places (i.e., the logical addresses "2" and "4").
[0061] The controller 4 can manage the relationship between such logical addresses and physical addresses using the logical-physical address conversion table 21.
[0062] Figure 3 Shows a structural example of the logical-physical address conversion table 21. The logical-physical address conversion table 21 represents the mapping between the logical address and the physical address of the NAND flash memory 5. The logical-physical address conversion table 21 is implemented as a lookup table (LUT), for example.
[0063] The mapping between the logical address and the physical address shown in the logical-physical address conversion table 21 corresponds to the aggregation of data such as blocks. That is to say, the controller 4 can use the logical-physical address conversion table 21 to manage the mapping between the logical address and the physical address in units of blocks. The size of a block is, for example, several kilobytes (KB) to several megabytes (MB).
[0064] Figure 3 The logical-physical address conversion table 21 shown andFigure 2 The data configuration 51 based on the physical address corresponds to the data configuration 52 based on the logical address. More specifically, the logical-physical address translation table 21 represents: (1) the mapping of the logical address "1" to the physical address "1"; (2) the mapping of the logical address "2" to the physical address "2"; (3) the mapping of the logical address "3" to the physical address "3"; and (4) the mapping of the logical address "4" to the physical address "2".
[0065] Accordingly, multiple logical addresses "2" and "4" are associated with one physical address "2" (i.e., data pattern B), so there is no need to physically store the data pattern B in two locations. That is to say, it is possible to avoid repeatedly storing the same data pattern in the NAND flash memory 5.
[0066] Referring again to Figure 1 . The CPU 12 is a processor configured to control the host I / F 11, the NAND I / F 13, and the DRAM I / F 14. The CPU 12 performs various processes by executing the FW 20 loaded into the DRAM 6. That is to say, the FW 20 is a control program for controlling the operation of the CPU 12. In addition to the above-mentioned FTL process, the CPU 12 can also execute command processing and the like for processing various commands from the host 2. In addition, part or all of the FTL process and the command processing can also be executed by dedicated hardware in the controller 4.
[0067] The CPU 12 functions as, for example, a write control unit 121, a read control unit 122, a duplicate control unit 123, a DEK generation unit 124, a KEK generation unit 125, a DEK encryption / decryption unit 126, and a data encryption / decryption unit 127 in order to perform data deduplication and encryption. The CPU 12 functions as the above-mentioned respective parts (units) by executing the FW 20, for example. In addition, at least a part of the above-mentioned respective part functions can also be implemented by hardware (circuit). Or, part of the above-mentioned respective part functions can be implemented by hardware, and other functions can be implemented by the CPU 12 that executes the FW 20.
[0068] The write control unit 121 receives a write command from the host 2 via the host I / F 11. The write control unit 121 can control the duplicate control unit 123, the DEK generation unit 124, the KEK generation unit 125, the DEK encryption / decryption unit 126, and the data encryption / decryption unit 127 in order to perform a write operation corresponding to the write command.
[0069] The read control unit 122 receives a read command from the host 2 via the host I / F 11. The read control unit 122 can control the KEK generation unit 125, the DEK encryption / decryption unit 126, and the data encryption / decryption unit 127 in order to perform a read operation corresponding to the read command.
[0070] The read control unit 122 reads encrypted data corresponding to a read command from the NAND flash memory 5. In addition, the read control unit 122 obtains the encrypted DEK corresponding to the encrypted data from the encrypted DEK table 23.
[0071] The DEK generation unit 124 generates a DEK for encrypting the user data using the user data received together with the write command. In the DEK, a value derived from the user data itself (in other words, corresponding to the user data) is used, and a value not derived from the user data such as a random number is not used. In the DEK, for example, a hash value derived from the user data, a hash-based message authentication code (HMAC) value can be used. The DEK generation unit 124, for example, substitutes the user data into the first hash function to generate a hash value.
[0072] The repetition control unit 123 determines whether the user data received together with the write command is the same as the plaintext data (hereinafter, also referred to as the saved data) corresponding to the encrypted data stored in the NAND flash memory 5. That is, the repetition control unit 123 determines whether the received user data is duplicate data. In addition, the correspondence between a certain encrypted data and a certain plaintext data means the following relationship: by encrypting the plaintext data with the DEK, the encrypted data can be obtained.
[0073] More specifically, the repetition control unit 123 calculates the hash value of the received user data. Then, the repetition control unit 123 determines whether the calculated hash value is the same as the hash value of the plaintext data corresponding to the encrypted data stored in the NAND flash memory 5. When the two hash values are the same, the repetition control unit 123 determines that the received user data is duplicate data. On the other hand, when the two hash values are different, the repetition control unit 123 determines that the received user data is not duplicate data. The hash value of the plaintext data corresponding to the encrypted data stored in the NAND flash memory 5 is managed by, for example, the physical address-hash value correspondence table 22.
[0074] Figure 4 Fig. 14 shows a structural example of the physical address-hash value correspondence table 22 used by the repetition control unit 123. The physical address-hash value correspondence table 22 may include a plurality of entries corresponding to a plurality of physical addresses. Each entry includes a field for the physical address and a field for the hash value.
[0075] In the entry corresponding to a certain physical address, the field of the physical address represents the physical address. The field of the hash value represents the hash value of the plaintext data (user data) corresponding to the encrypted data stored at the physical address.
[0076] InFigure 4 In the example shown, the hash value of the user data corresponding to the encrypted data stored at the physical address "1" is "0980340". The hash value of the user data corresponding to the encrypted data stored at the physical address "2" is "3412355". Additionally, the hash value of the user data corresponding to the encrypted data stored at the physical address "3" is "5154131".
[0077] Furthermore, in the entry corresponding to the physical address "4", no value is set in the hash value field. This is because no valid data is stored at the physical address "4".
[0078] The data encryption / decryption unit 127 encrypts and decrypts data. The data encryption / decryption unit 127 encrypts, for example, the data to be written to the NAND type flash memory 5 via the NAND I / F 13. Additionally, the data encryption / decryption unit 127 decrypts the data (i.e., the encrypted data) read from the NAND type flash memory 5 via the NAND I / F 13.
[0079] More specifically, when the user data received together with a write command is not duplicate data, the data encryption / decryption unit 127 encrypts the user data with the DEK to obtain encrypted data. The encrypted data is written to the NAND type flash memory 5 via the NAND I / F 13.
[0080] Furthermore, the aforementioned duplicate control unit 123 may also calculate the hash value of the encrypted data in order to determine whether the received user data is duplicate data. In this case, when the calculated hash value is included in any entry of the physical address - hash value correspondence table 22, the duplicate control unit 123 determines that the received user data is duplicate data. Additionally, when the calculated hash value is not included in any entry of the physical address - hash value correspondence table 22, the duplicate control unit 123 determines that the received user data is not duplicate data.
[0081] In the case of using the hash value of the user data as plaintext data, depending on the strength of the hash value, there is a possibility of determining the original user data from the hash value. However, in the case of using the hash value of the encrypted data, it is difficult to determine the original user data from the hash value. Therefore, by using the hash value of the encrypted data to determine whether it is duplicate data, the security can be made higher.
[0082] Additionally, the data encryption / decryption unit 127 decrypts the encrypted data read from the NAND type flash memory 5 with the DEK to obtain plaintext data. When the encrypted data is the data read according to a read command, the obtained plaintext data is sent to the host 2.
[0083] The KEK generation unit 125 generates a Key Encryption Key (KEK) associated with the user using the host 2. The KEK is a key used to encrypt the DEK. The KEK generation unit 125 generates the KEK using, for example, the password input by the user on the host 2. The KEK generation unit 125 generates, for example, the hash value of the password as the KEK.
[0084] The DEK encryption / decryption unit 126 encrypts the DEK with the KEK to obtain the encrypted DEK. The encrypted DEK is stored in the encrypted DEK table 23 in association with the logical address specified by the write command.
[0085] In addition, the DEK encryption / decryption unit 126 decrypts the encrypted DEK obtained from the encrypted DEK table 23 with the KEK to obtain the DEK. This DEK is used for decrypting the encrypted data by the data encryption / decryption unit 127.
[0086] Figure 5 Shows a structural example of the encrypted DEK table 23. The encrypted DEK table 23 contains one or more entries corresponding to one or more logical addresses. Each entry contains a field for the logical address and a field for the encrypted DEK.
[0087] In the entry corresponding to a certain logical address (hereinafter referred to as the first logical address), the field of the logical address represents the first logical address.
[0088] The field of the encrypted DEK represents the encrypted DEK corresponding to the first logical address. When storing user data at the first logical address, the controller 4 encrypts the user data with the DEK and writes the encrypted user data to the NAND flash memory 5. The encrypted DEK is obtained by encrypting the DEK used to encrypt the user data with the KEK of the corresponding user.
[0089] Hereinafter, as an example, the operations of each part when a write command for requesting to write the second data is received from the host 2 when the first encrypted data obtained by encrypting the first data with the first DEK is stored in the NAND flash memory 5 will be specifically described. The first DEK is an encryption key generated using the first data.
[0090] The write control unit 121 receives a write command for requesting to write the second data from the host 2. The second data is received together with the write command. The second data is the user data to be written to the NAND flash memory 5.
[0091] The repetition control unit 123 determines whether the second data is the same as the first data. When the second data is the same as the first data, the DEK generation unit 124 generates the first DEK using the second data. The KEK generation unit 125 generates the first KEK associated with the first user (e.g., user A) when the user using the host 2 is the first user. The KEK generation unit 125 generates the first KEK using, for example, the first password input by the first user on the host 2. The DEK encryption / decryption unit 126 encrypts the first DEK with the first KEK to obtain the first encrypted DEK. The first encrypted DEK is stored, for example, in the encrypted DEK table 23. In addition, the KEK generation unit 125 generates the second KEK associated with the second user (e.g., user B) when the user using the host 2 is the second user. The KEK generation unit 125 generates the second KEK using, for example, the second password input by the second user on the host 2. The DEK encryption / decryption unit 126 encrypts the first DEK with the second KEK to obtain the second encrypted DEK. The second encrypted DEK is stored, for example, in the encrypted DEK table 23.
[0092] On the other hand, when the second data is different from the first data, the DEK generation unit 124 generates the second DEK using the second data. The second DEK is different from the first DEK used to encrypt the first data. The data encryption / decryption unit 127 encrypts the second data with the second DEK to obtain the second encrypted data. The write control unit 121 writes the second encrypted data to the NAND flash memory 5. The KEK generation unit 125 generates the first KEK associated with the first user when the user using the host 2 is the first user. The DEK encryption / decryption unit 126 encrypts the second DEK with the first KEK to obtain the third encrypted DEK. The third encrypted DEK is stored, for example, in the encrypted DEK table 23. In addition, the KEK generation unit 125 generates the second KEK associated with the second user when the user using the host 2 is the second user. The DEK encryption / decryption unit 126 encrypts the second DEK with the second KEK to obtain the fourth encrypted DEK. The fourth encrypted DEK is stored, for example, in the encrypted DEK table 23.
[0093] In addition, the read control unit 122 receives a read command for requesting to read the second data.
[0094] When the second data is the same as the first data, the read control unit 122 reads the first encrypted data from the NAND flash memory 5. When the user using the host 2 is the first user, the DEK encryption / decryption unit 126 decrypts the first encrypted DEK stored in the encrypted DEK table 23 corresponding to the first encrypted data with the first KEK to obtain the first DEK. In addition, when the user using the host 2 is the second user, the DEK encryption / decryption unit 126 decrypts the second encrypted DEK stored in the encrypted DEK table 23 corresponding to the first encrypted data with the second KEK to obtain the first DEK. Then, the data encryption / decryption unit 127 decrypts the read first encrypted data with the first DEK. The first data (= the second data) obtained by decryption is sent to the host 2.
[0095] On the other hand, when the second data is different from the first data, the read control unit 122 reads the second encrypted data from the NAND flash memory 5. When the user using the host 2 is the first user, the DEK encryption / decryption unit 126 decrypts the third encrypted DEK stored in the encrypted DEK table 23 corresponding to the second encrypted data with the first KEK to obtain the second DEK. In addition, when the user using the host 2 is the second user, the DEK encryption / decryption unit 126 decrypts the fourth encrypted DEK stored in the encrypted DEK table 23 corresponding to the second encrypted data with the second KEK to obtain the second DEK. Then, the data encryption / decryption unit 127 decrypts the read second encrypted data with the second DEK. The second data obtained by decryption is sent to the host 2.
[0096] In addition, before receiving the above write command for requesting to write the second data, the write control unit 121 receives from the host 2 a write command for requesting to write the first data by the second user (e.g., user B) using the host 2. The first data is received together with the write command. The first data is user data to be written to the NAND flash memory 5.
[0097] The DEK generation unit 124 generates the first DEK using the first data. The data encryption / decryption unit 127 encrypts the first data with the first DEK to obtain the first encrypted data. The write control unit 121 writes the first encrypted data to the NAND flash memory 5. The KEK generation unit 125 generates the second KEK associated with the second user (e.g., user B) using the host 2. The KEK generation unit 125 generates the second KEK using, for example, the second password input by the second user on the host 2. The DEK encryption / decryption unit 126 encrypts the first DEK with the second KEK to obtain the third encrypted DEK. The third encrypted DEK is stored, for example, in the encrypted DEK table 23.
[0098] In addition, the read control unit 122 receives a read command from the host 2 requesting to read the first data. In addition, it is assumed that the user who requests to read the first data through this read command is the second user.
[0099] Based on this read command, the read control unit 122 reads the first encrypted data from the NAND flash memory 5. The DEK encryption / decryption unit 126 decrypts the third encrypted DEK stored in the encrypted DEK table 23 with the second KEK to obtain the first DEK. The data encryption / decryption unit 127 decrypts the read first encrypted data with the first DEK. The first data obtained by decryption is sent to the host 2. Accordingly, when the first data and the second data are the same, both the first user and the second user can obtain the first data obtained by decrypting the first encrypted data from the SSD 3.
[0100] According to the above configuration, the SSD 3 of the present embodiment can protect the confidentiality of each user's data and improve storage efficiency. When the saved first data and the second data received together with the new write request are the same, the DEK generation unit 124 can use the second data to generate the first DEK used for encrypting the first data. In this case, the second data encrypted with the first DEK is the same as the first data (i.e., the first encrypted data) encrypted with the first DEK. Therefore, it is not necessary to write the second data encrypted with the first DEK into the NAND flash memory 5, and deduplication can be achieved.
[0101] In addition, the DEK encryption / decryption unit 126 encrypts the first DEK with the first KEK and stores the first encrypted DEK. Thus, it can be said that the first data (= the second data) obtained by decrypting the first encrypted data in the NAND flash memory 5 is kept secret (hidden) by the first user associated with the first KEK used for decrypting the first encrypted DEK. Accordingly, even if the NAND flash memory 5 is physically removed, the stored encrypted data cannot be decrypted, so that leakage of the corresponding plaintext data can be prevented.
[0102] In addition, regarding the above functions for data deduplication and encryption, they are not limited to being provided by the controller 4 of the SSD 3, and can also be provided by a file system driver and / or an operating system (OS) executed in various computing devices, or can also be provided by a storage system of an enterprise and / or a data center equipped with multiple SSDs and / or HDs.
[0103] In addition, a part of the work for data deduplication and encryption performed by the controller 4 can also be carried out by the host 2. That is to say, it can also be that the host 2 and the controller 4 cooperate to achieve data deduplication and encryption.
[0104] Next, refer to Figures 6 to 9, three comparative examples will be described. These comparative examples are implemented as storage devices with security functions in the case where multiple users perform access. Specifically, the storage device related to the first comparative example is a non-encrypted storage device with an access management function. The storage device related to the second comparative example is an encrypted storage device that uses the DEK of each user. The storage device related to the third comparative example is an encrypted storage device that uses the KEK of each user. Hereinafter, a case where deduplication (assembling a deduplication function) is implemented in the storage devices of the respective comparative examples will be described.
[0105] (Non-encrypted storage device with access management function)
[0106] Figure 6 FIG. is a block diagram showing an example of a write operation and a read operation in the storage device 7A (hereinafter referred to as the first storage device 7A) related to the first comparative example. The first storage device 7A sets the permission or non-permission of access to data of each user for a specific unit (for example, block unit, file unit), and controls access to the data.
[0107] The first storage device 7A includes a host I / F 11A, a NAND flash memory 5A, a write control unit 131, a duplicate control unit 132, a read control unit 133, an access control unit 134, an access privilege table 135, and the like. The access privilege table 135 shows whether each user has the privilege to access data of each specific unit stored in the NAND flash memory 5A.
[0108] The write control unit 131 receives a write command from the host 2 via the host I / F 11A. When the write control unit 131 receives the write command, the duplicate control unit 132 determines whether the user data received together with the write command duplicates the plaintext data (stored data) corresponding to the encrypted data stored in the NAND flash memory 5A.
[0109] When it is determined by the duplicate control unit 132 that the user data does not duplicate the stored data, the write control unit 131 performs a write operation for writing the user data to the NAND flash memory 5A. That is, the write control unit 131 transmits the user data to the NAND flash memory 5A and issues a write instruction (more specifically, a programming instruction). Further, the duplicate control unit 132 updates the access privilege table 135 so as to give the user who requests to write the user data by the write command the privilege to access the written user data.
[0110] On the other hand, when the duplication control unit 132 determines that the user data duplicates the saved data, the write control unit 131 skips the write operation for writing the user data to the NAND flash memory 5A. Further, the duplication control unit 132 updates the access privilege table 135 so as to grant the user the access privilege to the saved data.
[0111] In addition, the read control unit 133 receives a read command from the host 2 via the host I / F 11A. When the read control unit 133 receives the read command, the access control unit 134 refers to the access privilege table 135 and determines whether the user who requests to read data by the read command is granted the access privilege to the data.
[0112] When the access control unit 134 determines that the user is granted the access privilege to the data, the read control unit 133 performs a read operation for reading data corresponding to the read command from the NAND flash memory 5A. More specifically, the read control unit 133 sends a read instruction to the NAND flash memory 5A. Further, the read control unit 133 sends the read data to the host 2.
[0113] On the other hand, when the access control unit 134 determines that the user is not granted the access privilege to the data, the read control unit 133 does not perform the read operation for reading data corresponding to the read command from the NAND flash memory 5A. Thus, it is possible to prevent unauthorized (illegal) access by unauthorized users.
[0114] As described above, in the first storage device 7A, it is possible to implement deduplication and access control in which only users with privileges can access data.
[0115] However, plaintext data is stored in the NAND flash memory 5A of the first storage device 7A. Therefore, the first storage device 7A has a vulnerability that data can be easily stolen by physically removing the NAND flash memory 5A (storage unit).
[0116] (Encryption storage device using the DEK of each user)
[0117] Figure 7 is a block diagram showing an example of a write operation and a read operation in a storage device 7B (hereinafter referred to as the second storage device 7B) according to a second comparative example. The second storage device 7B stores user data encrypted with a unique DEK of each user.
[0118] The second storage device 7B includes a host I / F 11B, a NAND flash memory 5B, a write control unit 141, a read control unit 142, a duplication control unit 143, a DEK generation unit 144, a data encryption / decryption unit 145, and the like.
[0119] The DEK generation unit 144 generates a DEK associated with the user using the password input by the user who is using the host 2. For example, the DEK generation unit 144 generates a hash value of the user's password as the DEK.
[0120] The write control unit 141 receives a write command from the host 2 via the host I / F 11B. When the write control unit 141 receives the write command, the repetition control unit 143 determines whether the user data received together with the write command duplicates the plaintext data (stored data) corresponding to the encrypted data stored in the NAND flash memory 5B.
[0121] When the repetition control unit 143 determines that the user data does not duplicate the stored data, the data encryption / decryption unit 145 encrypts the user data with the DEK. This DEK is the DEK associated with the user who requests to write the user data through the write command.
[0122] Then, the data encryption / decryption unit 145 transmits the encrypted user data to the NAND flash memory 5B, and the write control unit 141 sends a write instruction for writing the encrypted user data to the NAND flash memory 5B. Thus, the user data encrypted with the unique DEK of each user can be stored in the NAND flash memory 5B.
[0123] On the other hand, when the repetition control unit 143 determines that the user data duplicates the stored data, the data encryption / decryption unit 145 does not encrypt the user data. Moreover, the write control unit 141 skips the write operation for writing the encrypted user data to the NAND flash memory 5B.
[0124] In addition, the read control unit 142 receives a read command from the host 2 via the host I / F 11B. The read control unit 142 performs a read operation for reading data corresponding to the read command. More specifically, the read control unit 142 sends a read instruction to the NAND flash memory 5A.
[0125] The data encryption / decryption unit 145 performs a process for decrypting the encrypted data read by the read operation with the DEK. The encrypted data is encrypted with a unique DEK for each user. Therefore, when the DEK associated with the user who requests to read the data through the read command is the same as the DEK used to encrypt the encrypted data, the data encryption / decryption unit 145 can successfully decrypt the encrypted data. On the other hand, when the DEK associated with the user is different from the DEK used to encrypt the encrypted data, the data encryption / decryption unit 145 cannot decrypt the encrypted data.
[0126] As described above, the second storage device 7B can avoid repeatedly writing the same data to the NAND flash memory 5. However, in the second storage device 7B, since the data is encrypted with the DEK of each user, the encrypted data cannot be shared by multiple users. That is to say, a certain encrypted data can only be decrypted with the DEK of the user who encrypted it.
[0127] Therefore, in the case where the write operation for writing the user data is skipped because the user data received together with the write command duplicates the saved data, the user who requests writing through this write command cannot obtain the user data from the second storage device 7B. This is because the encrypted data corresponding to the saved data cannot be decrypted with the DEK associated with this user.
[0128] Thus, since the encrypted data cannot be shared by multiple users, deduplication cannot be achieved in the second storage device 7B.
[0129] (Encryption storage device using the KEK of each user)
[0130] Figure 8 FIG. is a block diagram showing an example of a write operation in the storage device 7C (hereinafter referred to as the third storage device 7C) according to the third comparative example in the case where there is no duplicate saved data. The third storage device 7C encrypts and stores the DEK for encrypting user data with the unique KEK of each user.
[0131] The third storage device 7C includes a host I / F 11C, a NAND flash memory 5C, a write control unit 151, a duplicate control unit 152, a DEK generation unit 153, a KEK generation unit 154, a DEK encryption / decryption unit 155, a data encryption / decryption unit 156, a logical physical address conversion table 21C, a physical address-hash value correspondence table 22C, an encrypted DEK table 23C, etc.
[0132] The KEK generation unit 154 generates a KEK associated with the user using the password input by the user of host 2. The KEK generation unit 154 generates, for example, the hash value of the user's password as the KEK. The KEK generation unit 154 sends the generated KEK to the DEK encryption / decryption unit 155.
[0133] The write control unit 151 receives a write command from host 2 via the host I / F 11C.
[0134] When the write control unit 151 receives a write command, the DEK generation unit 153 generates a unique DEK for the user data of each specific unit. The specific unit is, for example, a region, a block, or a file. The DEK generation unit 153 generates a random number as the DEK, for example. The DEK generation unit 153 sends the generated DEK to the data encryption / decryption unit 156 and the DEK encryption / decryption unit 155.
[0135] In addition, when the write control unit 151 receives a write command, the repetition control unit 152 determines whether the user data received together with the write command duplicates the plaintext data (stored data) corresponding to the encrypted data stored in the NAND flash memory 5C.
[0136] When it is determined by the repetition control unit 152 that the user data does not duplicate the stored data, the data encryption / decryption unit 156 encrypts the user data with the DEK. Further, the data encryption / decryption unit 156 transmits the encrypted user data to the NAND flash memory 5C, and the write control unit 151 sends a write instruction for writing the encrypted user data to the NAND flash memory 5C. Thus, it is possible to store the user data encrypted with the DEK unique to the user data of each specific unit in the NAND flash memory 5C.
[0137] Furthermore, the DEK encryption / decryption unit 155 encrypts the DEK with the KEK to obtain an encrypted DEK. The KEK is the KEK associated with the user who requests to write the user data through the write command. The DEK encryption / decryption unit 155 sends the encrypted DEK to the write control unit 151. The write control unit 151 stores the encrypted DEK in the encrypted DEK table 23C. In the encrypted DEK table 23C, for example, the encrypted DEK associated with the logical address specified by the write command is stored.
[0138] As Figure 8 shown, in the case where there is no stored data that duplicates the user data to be written, the third storage device 7C encrypts the user data with a random number DEK and writes it to the NAND flash memory 5C, and encrypts and stores the DEK with the KEK of each user.
[0139] Figure 9 is a block diagram showing an example in which a write operation cannot be achieved in the third storage device 7C when there is duplicate stored data.
[0140] When it is determined by the repetition control unit 152 that the user data duplicates the stored data, the data encryption / decryption unit 156 does not encrypt the user data. Further, the write control unit 151 skips the write operation for writing the encrypted user data to the NAND flash memory 5C.
[0141] In this case, the write control unit 151 and the DEK encryption / decryption unit 155 need to encrypt the DEK used in the encryption of the encrypted data corresponding to the stored data with the KEK of the user who requests to write user data through a write command and store it in the encrypted DEK table 23C. However, this DEK is a random number, which is encrypted with the KEK of another user and stored in the encrypted DEK table 23C. The DEK encryption / decryption unit 155 cannot decrypt the encrypted DEK encrypted with the KEK of another user with the KEK of the current user. Therefore, the write control unit 151 cannot store the DEK encrypted with the KEK of the current user in the encrypted DEK table 23C. Moreover, when the current user requests to read the user data through a read command, since the corresponding encrypted DEK is not stored in the encrypted DEK table 23C, the user data cannot be obtained from the third storage device 7C.
[0142] Thus, since the DEK used to encrypt a certain user's data (i.e., the data pattern) cannot be shared by multiple users, deduplication cannot be achieved in the third storage device 7C.
[0143] Compared with the storage devices 7A, 7B, and 7C of the first to third comparative examples above, the controller 4 of the SSD 3 according to the present embodiment generates a DEK from the user data and stores the DEK encrypted with a KEK unique to each user. The DEK is not a random number but is derived from the user data, so multiple users who are going to write user data in the same pattern can share the DEK corresponding to the user data. By encrypting the user data with the shared DEK, multiple users can share the encrypted data.
[0144] In addition, since the controller 4 stores the DEK encrypted with the KEK of each user, for example, when the password used to generate the KEK is correctly input, the encrypted DEK can be decrypted. On the other hand, when the password is not correctly input, the encrypted DEK cannot be decrypted. Therefore, since the encrypted DEK cannot be decrypted in an abnormal access, even if the encrypted data in the NAND flash memory 5 is read, it is possible to prevent the encrypted data from being decrypted and the plaintext data from being leaked.
[0145] Through the above, the SSD 3 according to the present embodiment can protect the confidentiality of each user's data and improve the storage efficiency.
[0146] Figure 10 It is a block diagram showing an example of the write operation in the SSD 3.
[0147] The KEK generation unit 125 generates a KEK associated with the user using the password input by the user of the host 2 in use. For example, the KEK generation unit 125 generates a hash value of the user's password as the KEK. The KEK generation unit 125 sends the generated KEK to the DEK encryption / decryption unit 126.
[0148] The write control unit 121 receives a write command from the host 2 via the host I / F 11.
[0149] When the write control unit 121 receives a write command, the DEK generation unit 124 generates a DEK using the user data received together with the write command. For example, the DEK generation unit 124 uses the first hash value calculated by substituting the user data into the first hash function as the DEK. The user data is, for example, data in a specific unit such as a region, a block, or a file. The DEK generation unit 124 sends the generated DEK to the data encryption / decryption unit 127 and the DEK encryption / decryption unit 126.
[0150] In addition, when the write control unit 121 receives a write command, the repetition control unit 123 determines whether the user data received together with the write command is the same as the plaintext data (stored data) corresponding to the encrypted data stored in the NAND flash memory 5.
[0151] Specifically, for example, the repetition control unit 123 substitutes the user data into the second hash function to calculate the second hash value. The second hash function is, for example, different from the above-mentioned first hash function. Moreover, the repetition control unit 123 determines whether there is an entry in the physical address-hash value correspondence table 22 that includes the calculated second hash value. If there is an entry in the physical address-hash value correspondence table 22 that includes the second hash value, the repetition control unit 123 determines that the user data is the same as the stored data. On the other hand, if there is no entry in the physical address-hash value correspondence table 22 that includes the second hash value, the repetition control unit 123 determines that the user data is different from the stored data.
[0152] (When the user data is different from the stored data)
[0153] When it is determined by the repetition control unit 123 that the user data is different from the stored data, the data encryption / decryption unit 127 encrypts the user data with the DEK. This DEK is different from the DEK used to encrypt the stored data. Moreover, the data encryption / decryption unit 127 transmits the encrypted user data to the NAND flash memory 5, and the write control unit 121 sends a write instruction for writing the encrypted user data to the NAND flash memory 5. Thus, the user data encrypted with the DEK derived from the user data can be written to the NAND flash memory 5.
[0154] In addition, the write control unit 121 updates the logical physical address conversion table 21 and the physical address - hash value correspondence table 22 according to the writing of the user data. Specifically, the write control unit 121 updates the logical physical address conversion table 21 so that it shows the mapping between the logical address specified by the write command and the physical address where the user data is written. In addition, the write control unit 121 updates the physical address - hash value correspondence table 22 so that it shows the correspondence between the physical address where the user data is written and the second hash value of the user data.
[0155] Furthermore, the DEK encryption / decryption unit 126 encrypts the DEK with the KEK to obtain the encrypted DEK. This KEK is the KEK associated with the user who requests to write user data through the write command. The DEK encryption / decryption unit 126 sends the encrypted DEK to the write control unit 121.
[0156] The write control unit 121 stores the encrypted DEK in the encrypted DEK table 23. In the encrypted DEK table 23, for example, the encrypted DEK associated with the logical address specified by the write command is stored.
[0157] In this way, when the user data is different from the stored data, the controller 4 encrypts the user data with the DEK generated using the user data and writes it to the NAND flash memory 5. Moreover, the controller 4 encrypts the DEK with the KEK associated with the user who requests to write user data through the write command and stores it in the encrypted DEK table 23.
[0158] (Case where the user data is the same as the stored data)
[0159] When the repetition control unit 123 determines that the user data is the same as the stored data, the data encryption / decryption unit 127 does not encrypt the user data. Moreover, the write control unit 121 skips the write operation for writing the encrypted user data to the NAND flash memory 5. That is to say, the write control unit 121 does not send a write instruction to the NAND flash memory 5.
[0160] In addition, the write control unit 121 updates the logical physical address conversion table 21 so that it shows the mapping between the logical address specified by the write command and the physical address where the encrypted data obtained by encrypting the stored data is stored. In addition, since no new physical writing occurs, the write control unit 121 does not update the physical address - hash value correspondence table 22.
[0161] The DEK encryption / decryption unit 126 encrypts the DEK with the KEK to obtain the encrypted DEK. This DEK is the same as the DEK used to encrypt the stored data. In addition, the KEK is the KEK associated with the user who requests to write user data through the write command. The DEK encryption / decryption unit 126 sends the encrypted DEK to the write control unit 121.
[0162] The write control unit 121 stores the encrypted DEK in the encrypted DEK table 23. In the encrypted DEK table 23, for example, the encrypted DEK associated with the logical address specified by the write command is stored.
[0163] In this way, when the user data is the same as the saved data, the controller 4 does not encrypt the user data and does not write it to the NAND flash memory 5. However, the controller 4 encrypts the DEK generated using the user data with the KEK associated with the user who requests to write the user data through the write command, and stores it in the encrypted DEK table 23.
[0164] Accordingly, when the user data is the same as the saved data, the controller 4 does not perform the operation of writing the user data to the NAND flash memory 5, and deduplication can be achieved. In addition, the controller 4 generates the DEK used to encrypt the saved data using the user data, and encrypts and stores the DEK with the KEK associated with the user. Therefore, it can be said that the saved data identical to the user data is kept confidential by the user associated with the KEK.
[0165] As described above, the content of the write operation differs depending on whether the user data is the same as the saved data. For example, when the user data is the same as the saved data, the operation of encrypting the user data and writing it to the NAND flash memory 5 is not performed. In this case, compared with the case where the user data is different from the saved data, the processing time corresponding to the write command is shorter and the power consumption is also lower.
[0166] Therefore, when a certain user requests to write a certain user data through a write command and the corresponding write operation is performed, there is a possibility that it can be inferred whether the user data is duplicated with the saved data based on its processing time and / or power consumption.
[0167] In order to prevent such inference, when the user data is the same as the saved data, the write control unit 121 and the data encryption / decryption unit 127 may also perform virtual (dummy) encryption processing and writing processing. Specifically, the data encryption / decryption unit 127 encrypts the virtual data with the DEK to obtain virtual encrypted data. Moreover, the write control unit 121 writes the virtual encrypted data to the NAND flash memory 5.
[0168] Thereby, the difference in processing time and / or power consumption generated between the case where the user data is different from the saved data and the case where the user data is the same as the saved data can be reduced. Accordingly, it is impossible to infer whether the user data requested to be written is the same as the saved data.
[0169] Figure 11It is a block diagram showing an example of a read operation in the SSD 3.
[0170] The KEK generation unit 125 generates a KEK associated with the user using the password input by the user of the host 2 in use. For example, the KEK generation unit 125 generates a hash value of the user's password as the KEK. The KEK generation unit 125 sends the generated KEK to the DEK encryption / decryption unit 126.
[0171] The read control unit 122 receives a read command from the host 2 via the host I / F 11. The read control unit 122 performs a read operation for reading data corresponding to the read command.
[0172] Specifically, the read control unit 122 uses the logical-physical address translation table 21 to convert the logical address specified by the read command into the corresponding physical address. The read control unit 122 sends a read instruction for reading data from this physical address to the NAND flash memory 5. Thereby, encrypted data corresponding to the read command is read from the NAND flash memory 5.
[0173] In addition, the read control unit 122 uses the encrypted DEK table 23 to obtain the encrypted DEK associated with the logical address specified by the read command. The read control unit 122 sends the obtained encrypted DEK to the DEK encryption / decryption unit 126.
[0174] The DEK encryption / decryption unit 126 decrypts the encrypted DEK with the KEK to obtain the DEK. This KEK is the KEK associated with the user who requests to read the user data through the read command. The DEK encryption / decryption unit 126 sends the obtained DEK to the data encryption / decryption unit 127.
[0175] The data encryption / decryption unit 127 decrypts the encrypted data read from the NAND flash memory 5 according to the read instruction with this DEK to obtain the plaintext user data. The data encryption / decryption unit 127 sends the user data to the host 2 via the host I / F 11.
[0176] Thereby, the user of the host 2 can obtain the user data corresponding to the read command using the KEK associated with the user.
[0177] In addition, when the KEK associated with the user is different from the KEK used to encrypt the encrypted DEK, the DEK encryption / decryption unit 126 cannot decrypt the encrypted DEK. In this case, the data encryption / decryption unit 127 cannot decrypt the encrypted data read from the NAND flash memory 5. Accordingly, for example, in an abnormal access where the correct password cannot be input, since the KEK used to encrypt the encrypted DEK cannot be generated, the encrypted DEK cannot be decrypted and the encrypted data cannot be decrypted. Thus, it is possible to prevent the encrypted data from being decrypted and the plaintext user data from being leaked.
[0178] Based on the above Figure 10 and Figure 11 configuration shown, the SSD 3 can maintain the confidentiality of each user's data and improve storage efficiency.
[0179] Figure 12 is a flowchart showing an example of the steps of the control process executed by the controller 4. This control process starts, for example, when the SSD 3 is connected to the host 2.
[0180] The controller 4 determines whether a user password is received from the host 2 (step S101). If no password is received (step S101: No), the controller 4 returns to step S101 and determines again whether a password is received.
[0181] On the other hand, if a password is received (step S101: Yes), the controller 4 generates a KEK using the password (step S102). The controller 4 generates, for example, the hash value of the password as the KEK. Thus, the controller 4 can encrypt the DEK using the KEK and can decrypt the encrypted DEK using the KEK.
[0182] Next, the controller 4 determines whether an I / O command is received from the host 2 (step S103). If no I / O command is received (step S103: No), the controller 4 returns to step S103 and determines again whether an I / O command is received.
[0183] On the other hand, if an I / O command is received (step S103: Yes), the controller 4 branches the process according to the category of the received I / O command (step S104). If the received I / O command is a read command (step S104: read command), the controller 4 executes a read process (step S105). The read process is a process for acquiring data corresponding to the read command and sending it to the host 2. Details of the read process will be described later with reference to Figure 13 the flowchart of.
[0184] In addition, when the received I / O command is a write command (step S104: write command), the controller 4 executes a write process (step S106). The write process is a process for deduplicating and encrypting user data received together with the write command and storing it in the NAND flash memory 5. Details of the write process will be described later with reference to Figure 14 the flowchart of
[0185] After the read process is executed in step S105 or the write process is executed in step S106, the controller 4 returns to step S103. Thereby, the controller 4 can continue to perform processing corresponding to the read command or write command received again.
[0186] Through the above control processing, the controller 4 can generate a KEK for each user used for encryption and decryption of the DEK, and perform a read process corresponding to the read command and a write process corresponding to the write command. In addition, steps S101 to S102 can be performed at any timing as long as they are earlier than the step of decrypting the encrypted DEK in the read process of step S105 (step S204 described later in Figure 13 and the step of encrypting the DEK in the write process of step S106 (step S310 described later in Figure 14 .
[0187] Figure 13 is a flowchart showing an example of the steps of the read process executed by the controller 4. Referring to Figure 12 the flowchart of
[0188] The controller 4 uses the logical-physical address translation table 21 to determine the physical address corresponding to the logical address specified by the read command (step S201). Then, the controller 4 reads the encrypted data from the determined physical address in the NAND flash memory 5 (step S202).
[0189] In addition, the controller 4 obtains the encrypted DEK corresponding to the logical address specified by the read command from the encrypted DEK table 23 (step S203). Then, the controller 4 decrypts the encrypted DEK with the KEK corresponding to the user (step S204). The KEK is generated using the password input by the user using the host 2. In addition, the encrypted DEK can only be decrypted with the KEK used for its encryption. Therefore, the controller 4 can also determine that it is an abnormal access and abort the read process when an incorrect password is received from the host 2 or when the encrypted DEK cannot be normally decrypted with the KEK.
[0190] In addition, the controller 4 performs the processes of step S201 and step S202 and the processes of step S203 and step S204 in parallel, for example. The controller 4 may also perform the processes of step S203 and step S204 after performing the processes of step S201 and step S202. Alternatively, the controller 4 may also perform the processes of step S201 and step S202 after performing the processes of step S203 and step S204.
[0191] Next, the controller 4 decrypts the read encrypted data using the DEK (step S205). The controller 4 sends the plaintext user data obtained by decryption to the host 2 (step S206).
[0192] Through the above read process, the controller 4 can read the encrypted data from the NAND flash memory 5 according to the read command, and send the plaintext user data obtained by decrypting the encrypted data to the host 2. In the decryption of the encrypted data, the DEK obtained by decrypting the encrypted DEK with the unique KEK of each user is used. Therefore, in an abnormal access where the corresponding user's KEK cannot be obtained, the encrypted data will not be decrypted. Accordingly, it is possible to prevent the leakage of plaintext user data in an abnormal access.
[0193] Figure 14 It is a flowchart showing an example of steps of a write process executed by the controller 4. Refer to Figure 12 the flowchart of, this write process corresponds to step S106 of the above control process.
[0194] The controller 4 receives user data to be written to the NAND flash memory 5 from the host 2 (step S301). The controller 4 calculates the hash value of the user data (step S302).
[0195] Then, the controller 4 uses the calculated hash value and the physical address-hash value correspondence table 22 to determine whether the received user data duplicates the plaintext data (stored data) corresponding to the encrypted data stored in the NAND flash memory 5 (step S303). That is to say, the controller 4 determines whether data of the same pattern as the received user data has been encrypted and stored in the NAND flash memory 5.
[0196] In the case where the user data duplicates the saved data (step S303: Yes), the controller 4 generates a DEK using the user data (step S304). The controller 4 generates, for example, a hash value of the user data as the DEK. Then, the controller 4 updates the logical-physical address conversion table 21 so that the logical address specified by the write command is associated with the physical address where the encrypted data corresponding to the saved data is written (i.e., establish a mapping) (step S305). Thereby, one physical address where the encrypted data is written can be associated with multiple logical addresses.
[0197] In addition, in the case where the user data does not duplicate the saved data (step S303: No), the controller 4 generates a DEK using the user data (step S306). The controller 4 encrypts the user data with the DEK (step S307), and writes the encrypted user data (encrypted data) to the NAND flash memory 5 (step S308). The controller 4 updates the logical-physical address conversion table 21 so that the logical address specified by the write command is associated with the physical address where the encrypted data is written (i.e., establish a mapping) (step S309). Then, the controller 4 updates the physical address-hash value correspondence table 22 (step S310). More specifically, when there is an entry in the physical address-hash value correspondence table 22 that includes the physical address where the encrypted data is written, the controller 4 sets the hash value of the user data calculated in step S302 in the hash value field in the entry.
[0198] After updating the logical-physical address conversion table 21 in step S305 or after updating the physical address-hash value correspondence table 22 in step S310, the controller 4 encrypts the DEK with the KEK corresponding to the user (step S311). The KEK is generated using the password input by the user who is using the host 2. Then, the controller 4 saves the encrypted DEK (step S312). More specifically, when there is no entry in the encrypted DEK table 23 that includes the logical address corresponding to the user data (i.e., the logical address specified by the write command), the controller 4 appends an entry including the logical address and the encrypted DEK to the encrypted DEK table 23. In addition, when there is an entry in the encrypted DEK table 23 that includes the logical address corresponding to the user data, the controller 4 sets the encrypted DEK obtained in step S311 in the encrypted DEK field in the entry.
[0199] Through the above write process, the controller 4 can skip the process of encrypting the user data and the process of writing the encrypted data to the NAND flash memory 5 in the case where the user data received together with the write command duplicates the saved data, and achieve deduplication.
[0200] In addition, regardless of whether the user data duplicates the saved data, the controller 4 generates a DEK using the user data. Thus, the encrypted data obtained by encrypting the user data with the DEK can be shared by multiple users who request to write user data in the same pattern.
[0201] Furthermore, the controller 4 encrypts the DEK with a unique KEK for each user and saves the encrypted DEK. Accordingly, in order to decrypt the encrypted data, it is necessary to decrypt the saved encrypted DEK with the KEK of each user. Therefore, the user can keep the user data obtained by decrypting the encrypted data with the DEK confidential through the KEK (or the password used to derive the KEK).
[0202] (Second Embodiment)
[0203] In the first embodiment, a DEK is generated using the user data to be written to the NAND flash memory 5. In contrast, in the second embodiment, a DEK is generated using the user data to be written to the NAND flash memory 5 and a Key Derivation Key (KDK) unique to each SSD.
[0204] The controller 4 (more specifically, the DEK generation unit 124) can generate a certain DEK only when the corresponding user data exists. Accordingly, if the corresponding user data does not exist, the controller 4 cannot generate its DEK.
[0205] However, for example, a user with knowledge of hashing can generate a DEK corresponding to the user data on the host 2. Therefore, there may be an operational vulnerability such that the DEK is leaked due to improper handling by the user.
[0206] In addition, the method of generating a DEK based on user data may not achieve the strength of a method for generating a cryptographically correct key.
[0207] Therefore, the SSD 3 according to the second embodiment generates a DEK not only using the user data but also using a KDK unique to each SSD. Thereby, the strength of encrypting the user data with the DEK can be improved.
[0208] The configuration of the SSD 3 according to the second embodiment is the same as that of the SSD 3 according to the first embodiment. The difference between the second embodiment and the first embodiment lies only in the configuration for also generating a DEK using the KDK. Hereinafter, the differences from the first embodiment will be mainly described.
[0209] Figure 15FIG. 0 is a block diagram showing a configuration example of an information processing system 1 including the SSD 3 according to the second embodiment. The SSD 3 according to the second embodiment further includes an OTP memory (One Time Programmable memory) 15 on the basis of the configuration of the SSD 3 according to the first embodiment.
[0210] The OTP memory 15 includes a plurality of storage elements (i.e., memory cells), and data can be written to each of the plurality of storage elements once. Each storage element in the OTP memory 15 is an irreversible storage element that can only write data once. As the OTP memory 15, for example, an electric fuse (e-Fuse) is used, but it is not limited thereto.
[0211] The OTP memory 15 stores a KDK 15A for generating a DEK. The KDK 15A is the unique key of this SSD 3. That is to say, multiple SSDs use their respective unique KDKs. By storing the KDK 15A in the OTP memory 15, leakage of the KDK 15A can be prevented. Hereinafter, the KDK 15A is also referred to as the device key 15A.
[0212] Figure 16 FIG. 10 is a block diagram showing an example of the write operation in the SSD 3.
[0213] When the write control unit 121 receives a write command, the DEK generation unit 124 generates a DEK using the user data received together with the write command and the device key 15A. Specifically, the DEK generation unit 124 uses the device key 15A as the KDK and the hash value of the user data as an index, and executes a key derivation function (Key Derivation Function: KDF) to generate a DEK. The DEK generation unit 124 sends the generated DEK to the data encryption / decryption unit 127 and the DEK encryption / decryption unit 126.
[0214] The operations of the other parts are the same as those in the first embodiment. In addition, the read operation is also the same as that in the first embodiment.
[0215] According to the above configuration, the SSD 3 can improve the strength of encrypting user data using the DEK.
[0216] As described above, according to the first and second embodiments, it is possible to protect the confidentiality of data of each user and improve storage efficiency. The NAND flash memory 5 stores the first encrypted data obtained by encrypting the first data with the first DEK. When the second data received from the host 2 together with a write request (e.g., a write command) is the same as the first data and the user using the host 2 is the first user, the controller 4 encrypts the first DEK with the first KEK associated with the first user to obtain the first encrypted DEK, and stores the first encrypted DEK. When the second data is the same as the first data and the user using the host 2 is the second user different from the first user, the controller 4 encrypts the first DEK with the second KEK associated with the second user to obtain the second encrypted DEK, and stores the second encrypted DEK. When the second data is different from the first data and the user using the host 2 is the first user, the controller 4 generates the second DEK using the second data, encrypts the second data with the second DEK to obtain the second encrypted data, writes the second encrypted data into the NAND flash memory 5, encrypts the second DEK with the first KEK to obtain the third encrypted DEK, and stores the third encrypted DEK. When the second data is different from the first data and the user using the host 2 is the second user, the controller 4 generates the second DEK using the second data, encrypts the second data with the second DEK to obtain the second encrypted data, writes the second encrypted data into the NAND flash memory 5, encrypts the second DEK with the second KEK to obtain the fourth encrypted DEK, and stores the fourth encrypted DEK.
[0217] When the first data stored in the NAND flash memory 5 is the same as the second data received together with the write request, since the second data encrypted with the first DEK is the same as the first encrypted data, there is no need to write to the NAND flash memory 5, and deduplication can be achieved.
[0218] In addition, when the first data and the second data are the same and the user using the host 2 is the first user, the controller 4 encrypts the first DEK with the first KEK associated with the first user and stores it. In this case, it can be said that the first data (= the second data) obtained by decrypting the first encrypted data in the NAND flash memory 5 is kept confidential by the first user associated with the first KEK used to decrypt the encrypted first DEK.
[0219] Furthermore, in the case where the first data is the same as the second data and the user using the host 2 is a second user different from the first user, the first DEK is encrypted with a second KEK associated with the second user and saved. In this case, it can be said that the first data (= the second data) obtained by decrypting the first encrypted data in the NAND flash memory 5 is kept confidential by the second user associated with the second KEK used to decrypt the encrypted first DEK.
[0220] Through the above, the SSD 3 can maintain the confidentiality of each user's data and improve storage efficiency.
[0221] Each of the various functions described in the first and second embodiments can also be implemented by a circuit (processing circuit). Examples of the processing circuit include a programmed processor such as a central processing unit (CPU). This processor executes each of the described functions by executing a computer program (command group) stored in the memory. This processor can also be a microprocessor including a circuit. Examples of the processing circuit also include a digital signal processor (DSP), an application specific integrated circuit (ASIC), a microcontroller, a controller, and other circuit components. Each of the other components other than the CPU described in these embodiments can also be implemented by the processing circuit.
[0222] Several embodiments of the present invention have been described, but these embodiments are presented as examples and are not intended to limit the scope of the invention. These new embodiments can be implemented in various other ways, and various omissions, substitutions, and changes can be made without departing from the gist of the invention. These embodiments and / or their modifications are included in the scope and / or gist of the invention, and are included in the scope of the invention described in the claims and equivalents thereof.
Claims
1. A memory system comprising: A first non-volatile memory that stores first encrypted data obtained by encrypting first data with a first data encryption key; and A controller configured to control the first non-volatile memory, The controller is configured such that, When the second data received from the host together with a write request is the same as the first data and the user using the host is a first user, the first data encryption key is encrypted with a first key encryption key associated with the first user to obtain a first encrypted data encryption key, and the first encrypted data encryption key is saved; When the second data is the same as the first data and the user using the host is a second user different from the first user, the first data encryption key is encrypted with a second key encryption key associated with the second user to obtain a second encrypted data encryption key, and the second encrypted data encryption key is saved; When the second data is different from the first data and the user using the host is the first user, a second data encryption key is generated using the second data, the second data is encrypted with the second data encryption key to obtain second encrypted data, the second encrypted data is written to the first non-volatile memory, the second data encryption key is encrypted with the first key encryption key to obtain a third encrypted data encryption key, and the third encrypted data encryption key is saved; When the second data is different from the first data and the user using the host is the second user, a second data encryption key is generated using the second data, the second data is encrypted with the second data encryption key to obtain the second encrypted data, the second encrypted data is written to the first non-volatile memory, the second data encryption key is encrypted with the second key encryption key to obtain a fourth encrypted data encryption key, and the fourth encrypted data encryption key is saved, When the second data is the same as the first data, the first data encryption key is a hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value; When the second data is different from the first data, the first data encryption key is a hash value of the first data or a hash-based message authentication code value, i.e., an HMAC value, and the second data encryption key is a hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value.
2. The memory system according to claim 1, The controller is further configured to, Receive a read request for reading the second data from the host; In the case where the second data is the same as the first data and the user using the host is the first user, the first encrypted data is read from the first non-volatile memory, the encryption key of the first encrypted data is decrypted with the first key encryption key to obtain the first data encryption key, and the read first encrypted data is decrypted with the first data encryption key; In the case where the second data is the same as the first data and the user using the host is the second user, the first encrypted data is read from the first non-volatile memory, the encryption key of the second encrypted data is decrypted with the second key encryption key to obtain the first data encryption key, and the read first encrypted data is decrypted with the first data encryption key.
3. The memory system according to claim 1 or 2, The controller is further configured to, Receive a read request for reading the second data from the host; In the case where the second data is different from the first data and the user using the host is the first user, the second encrypted data is read from the first non-volatile memory, the encryption key of the third encrypted data is decrypted with the first key encryption key to obtain the second data encryption key, and the read second encrypted data is decrypted with the second data encryption key; In the case where the second data is different from the first data and the user using the host is the second user, the second encrypted data is read from the first non-volatile memory, the encryption key of the fourth encrypted data is decrypted with the second key encryption key to obtain the second data encryption key, and the read second encrypted data is decrypted with the second data encryption key.
4. The memory system according to claim 1 or 2, The controller is further configured to, Generate the first key encryption key using the first password input by the first user on the host; Generate the second key encryption key using the second password input by the second user on the host.
5. The memory system according to claim 1 or 2, The controller is further configured to, before receiving the second data, generate the first data encryption key using the first data received from the host used by the second user together with the write request, encrypt the first data with the first data encryption key to obtain the first encrypted data, write the first encrypted data into the first non-volatile memory, encrypt the first data encryption key with the second key encryption key to obtain the third encrypted data encryption key, and save the third encrypted data encryption key.
6. The memory system according to claim 5, The controller is further configured to, Receive a read request for reading the first data from the host; When the user using the host is the second user, the first encrypted data is read from the first non-volatile memory, the encryption key of the third encrypted data is decrypted with the second key encryption key to obtain the first data encryption key, and the read first encrypted data is decrypted with the first data encryption key.
7. The memory system according to claim 1, The controller is configured to generate the first data encryption key using the second data when the second data is the same as the first data.
8. The memory system according to claim 1, It further includes a second non-volatile memory for storing a key derivation key, The controller is further configured to, When the second data is the same as the first data and the user using the host is the first user, generate the first data encryption key using the second data and the key derivation key, encrypt the first data encryption key with the first key encryption key to obtain the first encrypted data encryption key, and save the first encrypted data encryption key; When the second data is the same as the first data and the user using the host is the second user, generate the first data encryption key using the second data and the key derivation key, encrypt the first data encryption key with the second key encryption key to obtain the second encrypted data encryption key, and save the second encrypted data encryption key; When the second data is different from the first data and the user using the host is the first user, generate the second data encryption key using the second data and the key derivation key, encrypt the second data with the second data encryption key to obtain the second encrypted data, write the second encrypted data into the first non-volatile memory, encrypt the second data encryption key with the first key encryption key to obtain the third encrypted data encryption key, and save the third encrypted data encryption key; When the second data is different from the first data and the user using the host is the second user, generate the second data encryption key using the second data and the key derivation key, encrypt the second data with the second data encryption key to obtain the second encrypted data, write the second encrypted data into the first non-volatile memory, encrypt the second data encryption key with the second key encryption key to obtain the fourth encrypted data encryption key, and save the fourth encrypted data encryption key.
9. The memory system according to claim 1, The controller is further configured to, In the case where the second data is the same as the first data and the user using the host is the first user, generate the first data encryption key using the second data, encrypt the third data with the first data encryption key to obtain the third encrypted data, write the third encrypted data into the first non-volatile memory, encrypt the first data encryption key with the first key encryption key to obtain the first encrypted data encryption key, and save the first encrypted data encryption key; In the case where the second data is the same as the first data and the user using the host is the second user, generate the first data encryption key using the second data, encrypt the fourth data with the first data encryption key to obtain the fourth encrypted data, write the fourth encrypted data into the first non-volatile memory, encrypt the first data encryption key with the second key encryption key to obtain the second encrypted data encryption key, and save the second encrypted data encryption key.
10. A control method for a memory system, which is a control method for a memory system having a non-volatile memory, The non-volatile memory stores first encrypted data obtained by encrypting first data with a first data encryption key, The control method includes: In the case where the second data to be written into the non-volatile memory is the same as the first data and the user using the host is the first user, encrypt the first data encryption key with the first key encryption key associated with the first user to obtain the first encrypted data encryption key, and save the first encrypted data encryption key; In the case where the second data is the same as the first data and the user using the host is a second user different from the first user, encrypt the first data encryption key with the second key encryption key associated with the second user to obtain the second encrypted data encryption key, and save the second encrypted data encryption key; In the case where the second data is different from the first data and the user using the host is the first user, generate a second data encryption key using the second data, encrypt the second data with the second data encryption key to obtain the second encrypted data, write the second encrypted data into the non-volatile memory, encrypt the second data encryption key with the first key encryption key to obtain the third encrypted data encryption key, and save the third encrypted data encryption key; In the case where the second data is different from the first data and the user using the host is the second user, generate the second data encryption key using the second data, encrypt the second data with the second data encryption key to obtain the second encrypted data, write the second encrypted data into the non-volatile memory, encrypt the second data encryption key with the second key encryption key to obtain the fourth encrypted data encryption key, and save the fourth encrypted data encryption key, When the second data is the same as the first data, the first data encryption key is the hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value. When the second data is different from the first data, the first data encryption key is the hash value of the first data or a hash-based message authentication code value, i.e., an HMAC value, and the second data encryption key is the hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value.
11. An information processing system is an information processing system composed of a host and a memory system having a non-volatile memory. The non-volatile memory stores first encrypted data obtained by encrypting first data with a first data encryption key. The host is configured to send second data together with a write request to the memory system. The memory system is configured as follows: When the second data is the same as the first data and the user using the host is a first user, the first data encryption key is encrypted with a first key encryption key associated with the first user to obtain a first encrypted data encryption key, and the first encrypted data encryption key is saved. When the second data is the same as the first data and the user using the host is a second user different from the first user, the first data encryption key is encrypted with a second key encryption key associated with the second user to obtain a second encrypted data encryption key, and the second encrypted data encryption key is saved. When the second data is different from the first data and the user using the host is the first user, a second data encryption key is generated using the second data, the second data is encrypted with the second data encryption key to obtain second encrypted data, the second encrypted data is written to the non-volatile memory, the second data encryption key is encrypted with the first key encryption key to obtain a third encrypted data encryption key, and the third encrypted data encryption key is saved. When the second data is different from the first data and the user using the host is the second user, a second data encryption key is generated using the second data, the second data is encrypted with the second data encryption key to obtain the second encrypted data, the second encrypted data is written to the non-volatile memory, the second data encryption key is encrypted with the second key encryption key to obtain a fourth encrypted data encryption key, and the fourth encrypted data encryption key is saved. When the second data is the same as the first data, the first data encryption key is the hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value. In the case where the second data is different from the first data, the first data encryption key is the hash value of the first data or a hash-based message authentication code value, i.e., an HMAC value, and the second data encryption key is the hash value of the second data or a hash-based message authentication code value, i.e., an HMAC value.
Citation Information
Patent Citations
Variable power optical system, optical device, and method for manufacturing variable power optical system
JP2020134803A
Security layer for containers in multi-tenant environments
US10326744B1
Deduplication-aware per-tenant encryption
US20190073152A1