Security subsystem

By introducing dedicated security processors and secure hardware registers into the data storage system, limiting the communication boundaries, the security problem of secret data objects in traditional systems is solved, and higher security and isolation are achieved.

CN114417436BActive Publication Date: 2025-08-19MICRON TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210088916.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-10-06
Filing Date
2016-09-28
Publication Date
2025-08-19
Estimated Expiration
2036-09-28

AI Technical Summary

Technical Problem

In traditional data storage systems, the security of secret data objects is limited by shared microprocessors, resulting in unauthorized access and security vulnerabilities, making it difficult to isolate components that perform secure operations from general components while ensuring system security.

Method used

Using dedicated security processors and secure hardware registers, the components that perform secure operations are isolated from common components by limiting communication boundaries, ensuring that secret data objects are processed and stored only within the secure subsystem.

Benefits of technology

Improve the security of secret data objects, prevent unauthorized access, enhance the overall security of the data storage system, and ensure that secret information only operates and stores within the secure subsystem.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417436B_ABST
    Figure CN114417436B_ABST
Patent Text Reader

Abstract

The present application relates to security subsystems. In one embodiment, an apparatus and method for performing security operations using a dedicated security processor are described. The apparatus includes security firmware that defines security operations; a processor configured to execute the security firmware and perform a set of operations limited to the security operations; and a plurality of security hardware registers accessible by the processor and configured to receive instructions to perform the security operations. In another embodiment, an apparatus for performing security operations using a plurality of security assist hardware circuits is described. The apparatus includes one or more security hardware registers configured to receive commands to perform security operations; and one or more security assist hardware circuits configured to perform discrete security operations using one or more secret data objects.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Information about divisional applications

[0002] This application is a divisional application. The parent application is PCT International Application No. 201680057650.7, filed on September 28, 2016, with application number PCT / US2016 / 054106, which was filed in China with the invention title “Security Subsystem.” Technical Field

[0003] This application relates to a security subsystem. Background Art

[0004] Data security is a priority in the manufacturing of storage systems (e.g., solid-state drives (SSDs), hard disk drives (HDDs), tape drives, optical drives, etc.). Preventing access to secret data objects (e.g., encryption keys) gives individuals, businesses, and governments confidence in the ability of storage systems to accommodate the increasing amount of electronically stored information without sacrificing security. Traditional storage systems integrate a controller on a single system-on-a-chip (SOC) design, which includes a processor for performing security operations, firmware for accessing and performing operations on secret data objects, and security information (e.g., encryption keys) stored within internal SOC memory. In such a configuration, the boundaries of the SOC (e.g., the various connections and components that access the components of the SOC) are the minimum boundaries within which secret data objects (e.g., encryption keys or keys used to derive encryption keys) can be kept secure. That is, the secret data objects are only as secure as the SOC, and any device that can access a component of the SOC (e.g., the processor) can also access the secret data objects. Summary of the Invention

[0005] The present application relates to apparatus and methods for performing security operations using a dedicated security processor.

[0006] In one aspect, an apparatus comprises a memory device configured to store one or more secret data objects; a processor configured to execute security firmware and perform a set of operations limited to multiple operations for manipulating the one or more secret data objects; and a plurality of secure hardware registers accessible by the processor and configured to receive instructions to perform the security operations.

[0007] On the other hand, an apparatus includes: an internal memory device for storing one or more secret data objects; one or more secure hardware registers configured to receive commands to perform operations using the one or more secret data objects; and one or more security assist hardware circuits configured to perform discrete operations using the one or more secret data objects.

[0008] In another aspect, a method includes receiving a request at a secure hardware register to perform a security operation using one or more secret data objects; performing the security operation using a dedicated security processor; and transferring a value to an unsecure hardware register in response to performing the security operation, wherein the secure hardware register, the one or more secret data objects, and the dedicated security processor are located within a secure boundary.

[0009] On the other hand, an apparatus includes: memory access circuitry configured to receive instructions to perform memory operations, wherein at least one of the memory operations manipulates a secret data object; and security subsystem circuitry configured to receive instructions from the memory access circuitry to perform the at least one memory operation by manipulating the secret data object.

[0010] On the other hand, a method includes: receiving a request at a secure hardware register to perform a security operation involving one or more secret data objects; identifying one or more of a plurality of security-assist hardware circuits configured to perform the security operation; and performing the security operation using the one or more identified security-assist hardware circuits. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is a functional block diagram of a device including a data storage system according to an embodiment of the present invention.

[0012] Figure 2 is a functional block diagram of a device including a data storage system having a security subsystem according to an embodiment of the present invention.

[0013] Figure 3 It is based on the description Figure 2 A flowchart of operational steps for performing a security operation according to an embodiment of the present invention.

[0014] Figure 4 is a functional block diagram of a device including a data storage system having a security subsystem according to an embodiment of the present invention.

[0015] Figure 5 It is based on the description Figure 4 A flowchart of operational steps for performing a security operation according to an embodiment of the present invention.

[0016] Figure 6 is a flow chart depicting operational steps for performing security operations according to an embodiment of the present invention. DETAILED DESCRIPTION

[0017] The present invention recognizes that conventional data storage systems have certain security-related shortcomings. For example, conventional systems use one or more shared microprocessors that are subject to commands from both security firmware and unsecure storage system firmware. Because system resources that process secret information and perform security operations are accessible by any firmware running on the system microprocessor, secret information is only as susceptible to manipulation by the storage system firmware as the security firmware. Therefore, when ensuring the security of the system, the entire SOC, including any non-security-related components, must meet any security requirements because unauthorized access to unsecure components can result in the compromise of secret information and lead to security vulnerabilities. Embodiments disclosed herein relate to a security subsystem that isolates components that perform security operations and process security information from general components while limiting communication between secure and unsecure components in order to prevent unauthorized access to secret data objects.

[0018] Referring now to the accompanying drawings, Figure 1 1 is a functional block diagram of an apparatus (generally designated 100) (e.g., an integrated circuit, a memory device, a memory system, an electronic device or system, a smartphone, a tablet, a computer, a server, etc.). According to an embodiment of the present invention, apparatus 100 includes a data storage system 102. Data storage system 102 is a memory system capable of performing secure data operations, such as data encryption and decryption. Data storage system 102 can also store and retrieve data (including encrypted data) from one or more memories or storage media. Data storage system 102 generally includes a controller 104, dynamic memory 106, external non-volatile memory 108 (external to the controller), storage media 110, and can be connected to a host device 116.

[0019] Controller 104 can be any combination of components capable of performing security operations and storing secret data objects (e.g., encryption keys) within the security subsystem. Controller 104 can restrict communication between system components and security components based on the components and the purpose of the operations being performed. To effect this restricted communication, controller 104 includes memory controller circuitry 114, security subsystem 112, and memory / media interface 118. In various embodiments, security subsystem 112, memory controller circuitry 114, and / or memory / media interface 118 can be part of a single integrated circuit, with circuit connections defining the boundaries therebetween. In other embodiments, security subsystem 112 can be a discrete circuit or chip that can be connected to memory controller circuitry 114 and / or memory / media interface 118. Security subsystem 112 can include several components configured to perform security operations and store secret data. Security subsystem 112 can include several system components for performing general security operations involving secret data objects.

[0020] The security subsystem 112 may include, for example, a dedicated security processor, security hardware registers, security assist hardware, security firmware, components for performing encryption and decryption operations, and internal storage devices (e.g., random access memory (RAM) and / or non-volatile memory). The storage controller circuit 114 may include several system components for performing general controller operations that do not involve secret data objects. The storage controller circuit 114 may include, for example, one or more processing elements, system hardware registers, system firmware, system assist hardware, host, memory and media interfaces, and / or read and write data path control circuitry. The memory / media interface 118 may include one or more interfaces to enable communication between the security subsystem 112 and one or more external storage devices (e.g., dynamic memory 106, external non-volatile memory 108, and / or storage media 110). Detailed embodiments of the controller 104 are described below with respect to Figure 2 and 4 Further detailed discussion.

[0021] The dynamic memory 106 may be, for example, dynamic random access memory (DRAM). The dynamic memory 106 is accessible by the controller 104 via a memory / media interface 118. One or more of the components of the controller 104 (e.g., the security subsystem 112 and / or the memory controller circuit 114) are capable of accessing the dynamic memory 106 via the memory / media interface 118. The controller 104 may store data on the dynamic memory 106 and / or retrieve data therefrom. In various embodiments, the dynamic memory 106 may have encrypted data stored thereon, such as program instructions or other information for use by the controller 104, including one or more subsystems within the controller 104 (e.g., the security subsystem 112 and / or the memory controller circuit 114). The external non-volatile memory 108 may be, for example, a flash memory device (e.g., NOR flash). The external non-volatile memory 108 is accessible by the controller 104, including one or more subsystems of the controller 104, such as the security subsystem 112 and / or the memory controller circuit 114. The controller 104 may store data on and / or retrieve data from the external non-volatile memory 108. In various embodiments, the external non-volatile memory 108 may have encrypted data stored thereon, such as program instructions or other information for use by the controller 104, including by one or more subsystems within the controller 104, such as the security subsystem 112 and / or the memory controller circuit 114.

[0022] Storage medium 110 may include arrays of memory cells (e.g., nonvolatile memory cells). The array may be, for example, a flash array having a NAND architecture. However, embodiments are not limited to a particular type of memory array or array architecture. Memory cells may, for example, be grouped into blocks comprising physical pages. Blocks may be included in planes of memory cells, and the array may include planes. As an example, a memory device may be configured to store 8 KB (kilobytes) of user data per page, 128 pages of user data per block, 2048 blocks per plane, and 16 planes per device.

[0023] In operation, for example, data can be written to and / or read from storage medium 110 as page data. Data can be sent to / from a host (e.g., host device 116) in data segments called sectors (e.g., host sectors) mapped onto page units. Security subsystem 112 can perform any encryption or decryption necessary to facilitate data transfer between storage medium 110 and host device 116, while ensuring that all secret data objects (e.g., encryption / decryption keys) remain within security subsystem 112.

[0024] Host device 116 may be any host system, such as a personal laptop computer, desktop computer, tablet computer, smartphone, personal digital assistant, or any other programmable electronic device capable of using and / or generating secret information. In various embodiments, host device 116 may provide data to be written to storage medium 110 or request data from storage medium 110 via data storage system 102. Controller 104 may use one or more subsystems (e.g., security subsystem 112 and / or storage controller circuitry 114) to receive the request and perform the requested function so that the secret data object remains within security subsystem 112 and is inaccessible to any system or component external to security subsystem 112.

[0025] Figure 2 is a functional block diagram of an apparatus (generally designated 200) including a data storage system 202 according to an embodiment of the present invention. The data storage system 202 generally includes: a controller 204 having a security subsystem 212, a storage controller circuit 214, and a memory / media interface 254; a dynamic memory 206; an external non-volatile memory 208; and a storage medium 210. A host device 216 can be coupled to the data storage system 202. In various embodiments, the apparatus 200 can be implemented as described above with respect to Figure 1 Specifically, the dynamic memory 206, the external non-volatile memory 208, the storage medium 210, and the host device 216 may be respectively as described above with respect to Figure 1The dynamic memory 106, the external non-volatile memory 108, the storage medium 110, and the host device 116 are implemented as described above.

[0026] Controller 204 may include several components for performing operations related to data storage and retrieval, including security operations that generate and / or manipulate secret data. Components of controller 204 may include a security subsystem 212 for performing security operations, such as data encryption and decryption, and manipulating secret data objects, such as encryption keys. In one embodiment, security subsystem 212 is a self-contained integrated circuit or chip instantiated within controller 204. In another embodiment, security subsystem 212 may be an integrated circuit subsystem of a system-on-chip (SoC). Security subsystem 212 may be enclosed by a security boundary, which may be a physical boundary and / or defined by the number and type of connections between security subsystem 212 and other components of data storage system 202. Controller 204 may further include storage controller circuitry 214 for performing controller functions that do not require access to secret data objects. For example, storage controller circuitry 214 may provide an interface for communication between data storage system 202 and host device 216. For example, storage controller circuitry 214 may receive incoming read and write requests and request that security operations be performed by security subsystem 212.

[0027] The memory / media interface 254 may generally include one or more interfaces to enable communication with one or more external storage devices (e.g., dynamic memory 206, external non-volatile memory 208, and / or storage media 210). The memory / media interface 254 may include a memory interface 252 and a media interface 250. The memory interface 252 provides an interface between the transfer control 234 of the security subsystem 212 and the dynamic memory 206 and / or external non-volatile memory 208. As described above, some secret data objects may be encrypted and stored outside the security subsystem 212, as long as the key for decrypting the secret data object remains stored within the security subsystem 212 or is self-encrypted for storage outside the security subsystem 212. The memory interface 252 may be the communication interface between the transfer control 234 and the dynamic memory 206 and / or external non-volatile memory 208, and thus, despite being located outside the security subsystem, may be controlled by the security subsystem 212. The memory interface 252 may also be controlled, for example, by one or more components of the storage controller circuitry 214. The media interface 250 may access the storage medium 210 on behalf of the host device 216 via commands (e.g., read / write commands) issued to the host interface 244. The media interface 250 may allocate storage, access, read data, write data, erase data, and / or perform other management operations with respect to the storage medium 210.

[0028] exist Figure 2In an embodiment, the security subsystem 212 includes security hardware registers 218, a security processor 220, security firmware 222, security assist hardware 224, internal non-volatile memory 226, internal RAM 228, encryption circuitry 230, decryption circuitry 232, and transfer control circuitry 234. The security hardware registers 218 may include a plurality of hardware registers. In various embodiments, the security hardware registers 218 may be general-purpose registers in a register file. A subset of the security hardware registers 218 is accessible by one or more components external to the security subsystem 212, such as one or more components of the memory controller circuitry 214 (described below). External components may write information, such as commands and / or data, used to perform security operations within the security subsystem 212 to the subset of the security hardware registers 218. While access to the security hardware registers 218 by external components may be limited to a subset of the security hardware registers 218, components within the security subsystem 212 (e.g., the security processor 220) can access all of the security hardware registers 218. In various embodiments, the secure hardware registers 218 may be configured to notify the security processor 220 executing the security firmware 222 that a request for a security operation to be performed by the security processor 220 has been received.

[0029] exist Figure 2 In one embodiment, the security subsystem 212 includes a security processor 220, which may be a dedicated processor or microcontroller for performing security operations involving, generating, and / or manipulating secret data objects (e.g., cryptographic keys). In various embodiments, the security processor 220 may be a general-purpose processor or a dedicated processor capable of performing security operations. The security processor 220 may access secure hardware registers 218 to receive commands and / or data to perform security operations within the security subsystem 212. The security processor 220 may access and execute security firmware 222. In various embodiments, the security firmware 222 may control the operations that the security processor 220 may perform. For example, the security firmware 222 may define the full set of security operations that the security processor 220 may perform. The security processor may be configured to perform operations limited to the set of security operations defined by the security firmware 222. The security firmware 222 may also define the components with which the security processor 220 may communicate (both within the security subsystem 212 and external to the security subsystem 212).

[0030] The security assist hardware 224 can provide hardware execution for various discrete operations performed by the security subsystem 212. Those skilled in the art will appreciate that various embodiments of the device 200 may include any number of security assist hardware 224, or none at all. The security assist hardware 224 may include various circuits for performing specific functions, including, but not limited to, data encryption and decryption, signature calculation and verification, and / or random number generation. Such operations may be steps in a process performed to meet the operational requirements of the security subsystem 212. Thus, the security assist hardware 224 may include various hardware submodules, each of which may be controlled by the security firmware 222 executed by the security processor 220. The operations performed by the security assist hardware 224 may be component operations of security operations, such as client authentication, encryption key generation, key identification, key selection, and retrieval. In various embodiments, the security assist hardware 224 is completely controlled by the security firmware 222 executed on the security processor 220, such that any data provided to or through the security assist hardware 224 is inaccessible from outside the security subsystem 212.

[0031] exist Figure 2In an embodiment, internal non-volatile memory 226 and internal RAM 228 may provide internal memory used by various components in security subsystem 212. Both internal non-volatile memory 226 and internal RAM 228 may be accessed by security processor 220 executing security firmware 222. Internal non-volatile memory 226 may contain secret data objects or other information that may need to persist across power cycles. Internal RAM 228 may buffer data used by components of security subsystem 212. For example, internal RAM 228 may receive encrypted secret data objects from external memory (e.g., dynamic memory 206 and / or external non-volatile memory 208) or buffer encrypted secret data objects for storage in external memory (e.g., dynamic memory 206 and / or external non-volatile memory 208). Secret data objects may be stored external to security subsystem 212 if they are first encrypted using a secret encryption key retained within security subsystem 212. In various embodiments, the internal RAM 228 may communicate with the dynamic memory 206 and / or the external non-volatile memory 208 via the transfer control circuit 234. The transfer control circuit 234 may provide an interface for data transfer between the security subsystem 212 and external systems (e.g., the memory controller circuit 214, the dynamic memory 206, and / or the external non-volatile memory 208) via the memory interface 252. Those skilled in the art will appreciate that various embodiments may not include the internal non-volatile memory 226 and the internal RAM 228. In such embodiments, the security subsystem 212 may encrypt secret information for storage external to the security subsystem 212 (e.g., in the dynamic memory 206 and / or the external non-volatile memory 208).

[0032] Encryption circuitry 230 and decryption circuitry 232 may reside within security subsystem 212 and perform encryption and decryption functions, respectively, on data provided by storage controller circuitry 214 (e.g., during a write operation) or requested by storage controller circuitry 214 (e.g., during a read operation). In various embodiments, encryption circuitry 230 receives encrypted data from storage controller circuitry 214. Security processor 220, executing security firmware 222, provides encryption circuitry 230 with an encryption key (e.g., an encryption key stored in internal non-volatile memory 226). Encryption circuitry 230 may encrypt the received data using the provided encryption key and provide the encrypted information to media interface 250 in memory / media interface 254 for storage in storage media 210. By performing encryption functions within security subsystem 212, all secret data objects (e.g., encryption keys) remain within security subsystem 212 and are inaccessible to components outside the security boundary defining security subsystem 212. Decryption circuitry 232 operates in a similar manner. Specifically, decryption circuitry 232 receives a request to retrieve encrypted data stored in storage medium 210. The decryption circuitry retrieves the encrypted data from storage medium 210 via media interface 250. The security processor 220, executing security firmware 222, provides a decryption key to the decryption circuitry 232. The decryption circuitry 232 decrypts the requested data using the provided decryption key and provides the decrypted data to the storage controller circuitry 214. By performing the decryption function within the security subsystem 212, any secret data objects (e.g., decryption keys) remain within the security subsystem 212 and cannot be accessed by components outside the security boundary defining the security subsystem 212.

[0033] exist Figure 2In one embodiment, the storage controller circuitry 214 includes one or more system processors 236, system hardware registers 238, storage system firmware 240, system auxiliary hardware 242, a host interface 244, write data path control circuitry 246, and read data path control circuitry 248. The system processors may be one or more general-purpose processors or one or more specialized processors or microcontrollers for performing operations not involving secret data objects and communicating with the secure subsystem 212. The system processor 236 may provide commands and / or information (e.g., command parameters) to the secure hardware registers 218 across the security boundaries of the secure subsystem 212. As discussed above, the system processor 236 may have access to a subset of the secure hardware registers 218 (e.g., the ability to read and write to the subset). By restricting access to secret data objects within the secure subsystem 212 by the system processor 236, the security of the secret data objects may be increased. The system processor 236 may execute the storage system firmware 240. The storage system firmware 240 may define the operations that the system processor 236 may perform. Additionally, the storage system firmware 240 may define which commands may be submitted by the system processor 236 to the secure hardware registers 218 for execution by the security processor 220. Thus, the type and content of communications between the storage controller circuitry 214 and the security subsystem 212 may be controlled and limited to increase the security of secret data objects stored in the security subsystem 212.

[0034] The system hardware registers 238 may include a plurality of hardware registers. In various embodiments, the system hardware registers 238 may be general registers in a register file. All or a subset of the system hardware registers 238 may be accessible by one or more components within the security boundary of the security subsystem 212 (e.g., the security processor 220). Components of the security subsystem 212 may write information (e.g., confirmation of successful completion of a security operation) to a subset of the system hardware registers 238. While access to the system hardware registers 238 by components of the security subsystem 212 may be limited to a subset of the system hardware registers 238, components external to the security subsystem 212 (e.g., the system processor 236) may access all of the system hardware registers 238.

[0035] The host interface 244 can be in the form of a standardized interface or a proprietary interface. For example, the host interface 244 can be a Serial Advanced Technology Attachment (SATA), Peripheral Component Interconnect Express (PCIe), or Universal Serial Bus (USB), including other connectors and interfaces. Generally speaking, the host interface 244 provides a communication mechanism for passing control signals, address information, data, and other signals between the data storage system 202 and the host device 216. In various embodiments, the host interface 244 can receive write commands and data from the host device 216 to be encrypted and written to the storage medium 210. The host interface 244 can also receive read commands to decrypt and return data stored in the storage medium 210.

[0036] Write data path control circuitry 246 directs and controls the flow of write data from host interface 244 to encryption circuitry 230 in security subsystem 212. The write data path control circuitry may be controlled by system processor 236 executing storage system firmware 240. For example, host interface 244 may receive a write request and data to be written to storage media 210 from host device 216. System processor 236 may write an encryption command to secure hardware register 218 to perform the write operation. Secure hardware register 218 may notify security processor 220 executing security firmware 222 that the encryption command has been received. Security processor 220 may provide an encryption key to encryption circuitry 230. System processor 236 may instruct write data path control circuitry 246 to provide the data to be encrypted and stored to encryption circuitry 230 across the security boundary of security subsystem 212. Encryption circuitry 230 may then encrypt the received data using the encryption key provided by security processor 220. Thus, all secret data objects (e.g., encryption keys) remain within the secure subsystem 212 and cannot be accessed by components external to the secure subsystem 212. The encrypted data may then be provided to the media interface 250 in the memory / media interface 254 and stored on the storage medium 210.

[0037] Read data path control circuitry 248 directs and controls the flow of read data from decryption circuitry 232 in security subsystem 212 to host interface 244. Read data path control circuitry 248 may be controlled by system processor 236 executing storage system firmware 240. For example, host interface 244 may receive a read request from host device 216 for data stored in an encrypted format on storage medium 210. The system processor may write the read request identifying the data to security hardware registers 218 in security subsystem 212. Security hardware registers 218 may notify security processor 220 executing security firmware 222 that the read request has been received. Security processor 220 may provide an encryption key associated with the requested data to decryption circuitry 232. Decryption circuitry 232 may retrieve the requested encrypted data from storage medium 210 via media interface 250. Decryption circuitry 232 may then decrypt the requested data using the decryption key provided by security processor 220 and provide the decrypted data to read data path control circuitry 248. Read data path control circuitry 248 may provide the decrypted data to host interface 244 , which provides the decrypted data to host device 216 .

[0038] Figure 3 It is based on the description Figure 2 Flowchart (generally designated 300) of operational steps for processing a security operation of an embodiment of the present invention. In operation 302, a security subsystem (e.g., security subsystem 212) receives a command at one or more security hardware registers (e.g., security hardware register 218). The command may be received from a device external to the security subsystem (e.g., a system processor (e.g., system processor 236)). The command may include instructions to perform a specific security operation involving a secret data object, such as a read or write command involving an encryption key stored within the security subsystem. The command may further include any necessary parameters for performing the security operation. As described above with respect to Figure 2 In other words, commands may be received at one or more of a subset of secure hardware registers 218 accessible to the system processor 236. Those secure hardware registers that are not accessible to the system processor 236 cannot receive commands from the system processor 236. By limiting access to the secure hardware registers 218, the security of secret data objects stored within the security subsystem 212 may be increased.

[0039] In operation 304, the security subsystem 212 or a component thereof notifies the security processor 220 that a command has been received. The security hardware registers 218 may be configured to transmit a notification to the security processor 220 via an internal bus within the security subsystem 212 in response to receiving the command. The security processor 220, executing the security firmware 222, may determine how the received command should be handled. As discussed above, the security processor 220 may be limited to performing specific security operations defined by the security firmware 222. In such embodiments, the security processor 220 may only execute the requested command if permitted by the security firmware 222. If the received command does not correspond to a permitted security operation as defined by the security firmware 222, the security processor 220 may return an exception or error by, for example, writing a description of the exception to the system hardware registers 238 indicating that the received command is not permitted by the security firmware 222.

[0040] If the received command is an allowed command, the security subsystem 212 performs a security operation based on the received command using the security processor 220 and / or security assistance hardware (e.g., security assistance hardware 224) in operation 306. The security processor 220 may perform the security operation requested by the received command (e.g., a write operation, a read operation, an encryption / decryption operation, encryption key generation, etc.). Before, during, and after performing the security operation, the security subsystem 212 may ensure that all secret data objects remain within the security boundary unless encrypted.

[0041] In operation 308, the security subsystem 212 transmits the response to the system hardware register 238. The security processor 220 may transmit the response across the security boundary of the security subsystem 212. In various embodiments, the response may be an appropriate value or set of values based on the received command. For example, the response may be an indication of successful completion of the received command. The system processor 236 may read the value from the system hardware register 238 and interpret the response.

[0042] Figure 4 is a functional block diagram of an apparatus (generally designated 400) including a data storage system 402 according to an embodiment of the present invention. The data storage system 402 may include: a controller 404 including a security subsystem 412, a storage controller circuit 414, and a memory / media interface 454; a dynamic memory 406; an external non-volatile memory 408; and a storage medium 410. In various embodiments, the memory media interface 454 (including the memory interface 452 and the media interface 450), the dynamic memory 406, the external non-volatile memory 408, and the storage medium 410 may be described above with respect to Figure 2The memory / media interface 254 (including the memory interface 252 and the media interface 250), the dynamic memory 206, the external non-volatile memory 208 and the storage medium 210 and / or Figure 1 The memory / media interface 118, dynamic memory 106, external non-volatile memory 108, and storage medium 110 are implemented as described in the embodiment of FIG. The data storage system 402 can be coupled to a host device 416. The host device 416 can be implemented as described above with respect to Figure 1 and 2 The controller 404 may be implemented as described in the host device 116 and the host device 216 in the embodiment of FIG. Figure 1 Controller 104 in.

[0043] exist Figure 4 In the embodiment of the present invention, the security subsystem 412 includes a plurality of security hardware registers 418, a security auxiliary hardware circuit 420, an internal RAM 424, an internal non-volatile memory 422, a security control circuit 426, an encryption circuit 428, a decryption circuit 430, and a transmission control circuit 432. The security hardware registers 418, the internal RAM 424, the internal non-volatile memory 422, the encryption circuit 428, the decryption circuit 430, and the transmission control circuit 432 can be respectively described above with respect to Figure 2 The secure hardware registers 218, internal RAM 228, internal non-volatile memory 226, encryption circuit 230, decryption circuit 232, and transmission control circuit 234 of the embodiment are implemented as described. Figure 4 In an embodiment of the present invention, the security assist hardware circuit provides functionality to perform secure operations within a security boundary without a dedicated security processor.

[0044] Security control circuitry 426 provides communication functionality between components within security subsystem 412. Additionally, security control circuitry 426 may provide a communication path between security subsystem 412 and storage controller circuitry 414. The specific functionality of security control circuitry 426 is described in further detail below.

[0045] The security assistance hardware circuit 420 may be a plurality of hardware circuits configured to completely perform discrete security operations. Examples of discrete security operations performed by the security assistance hardware circuit 420 include, but are not limited to, random number generation, encryption key generation, signature calculation, symmetric encryption or decryption, asymmetric encryption or decryption, data manipulation operations, and data movement operations. Figure 2As described above, one or more security assist hardware circuits 420 may be triggered in response to receiving a command at the secure hardware register 418. In a particular embodiment, a particular register location in the secure hardware register 418 may correspond to a particular security assist hardware circuit 420. The secure hardware register 418 may provide notification to the one or more security assist hardware circuits 420 via the security control circuit 426 that a command (and any associated parameters) was received at the secure hardware register 418 for execution by the one or more security assist hardware circuits 420. Once the security assist hardware circuit 420 completes execution of the security operation, the security assist hardware circuit 420 may provide a value indicating completion of the security operation back to the secure hardware register 418 or to the memory controller circuit 414.

[0046] The security assist hardware circuitry 420 may use, access, generate, or otherwise involve secret data objects (e.g., encryption keys) that are stored within the secure subsystem 412 and / or are inaccessible to components external to the secure subsystem 412 (e.g., the memory controller circuitry 414). To maintain the security of the secret data objects, the security assist hardware circuitry 420 may store the secret data objects in an internal memory system, such as internal RAM 424, internal non-volatile memory 422, or register locations within the secure hardware registers 418 that are inaccessible to the memory controller circuitry 414. The secret data objects may also be encrypted and stored in an external memory device (e.g., the dynamic memory 406 and / or the external non-volatile memory 408) via the memory / media interface 454, as long as the key to decrypt the secret data objects remains within the secure subsystem 412.

[0047] An example of a specific security assist hardware circuit 420 will now be discussed. It should be understood that this discussion is provided by way of example only, and that additional circuits that perform different security operations are possible without departing from the scope of the present invention.

[0048] In a first example, the security assist hardware circuit 420 implements random number generation. A command to generate a random number may be received at the security hardware register 418, which notifies the applicable security assist hardware circuit 420. The security assist hardware circuit 420 may generate a series of random bits from a generator, accumulate the series of bits into a holding register of a defined length, adjust the accumulated value according to an adjustment algorithm using, for example, a deterministic random bit generator, write the result to an internal memory location (e.g., internal RAM 424), and transmit a completion notification to the memory controller circuit 414.

[0049] In a second example, the security assist hardware circuit 420 implements encryption key generation. The encryption key generation may depend on a previously generated secret data object, such as a random number generated by the random number generation security assist hardware circuit 420 to serve as an encryption key. The encryption key generation security assist hardware circuit 420 may implement any appropriate transformation function to generate the encryption key. In operation, a component of the storage controller circuit 414 may provide a command to generate an encryption key to the secure hardware register 418 and supply an address to a previously generated random number, parameterize the transformation, and define the location of the resulting encryption key. The encryption key generation security assist hardware circuit 420 may perform a defined transformation on the random number at a specified location to generate an encryption key and store the resulting encryption key at the specified location. The encryption key generation security assist hardware circuit 420 may then transmit a notification (e.g., an event interrupt) to the storage controller circuit 414, indicating the successful generation of the encryption key and the location of the encryption key.

[0050] In a third example, the security assist hardware circuit 420 implements a signature calculation. The signature calculation security assist hardware circuit 420 may be used for security operations that require confirming the security of information by adding or verifying a signature value. The storage controller circuit 414 may write the opcode, the address of the value to be digitally signed or verified, the length of the value, the parameters for the signature calculation itself, and the location of the resulting signature or signature verification result into the secure hardware register 418. The signature calculation security assist hardware circuit 420 may then generate or verify the signature value based on the provided parameters and store the result in a specified location. The signature calculation security assist hardware circuit 420 may then transmit a notification (e.g., an event interrupt) to the storage controller circuit 414 of the successful generation or verification of the signature value and the location of the result.

[0051] In a fourth example, security assist hardware circuitry 420 implements symmetric encryption and / or decryption. Symmetric cryptographic security assist hardware circuitry 420 can be used to hide secret data objects or other data that will be moved outside the security boundary of secure subsystem 412. Storage controller circuitry 414 can access secure hardware registers 418 to define the operation (e.g., encryption or decryption), any operands (e.g., encryption / decryption keys), an initialization vector (if applicable), the location and length of the data to be encrypted / decrypted, and the location / length of the result to be stored. Symmetric cryptographic security assist hardware circuitry 420 can then transmit a notification (e.g., an event interrupt) to storage controller circuitry 414 of the successfully encrypted / decrypted data and the location of the result.

[0052] In a fifth example, the security assist hardware circuitry 420 implements asymmetric encryption and / or decryption (e.g., public key / private key operations based on RSA or other algorithms). Symmetric cryptographic security assist hardware circuitry 420 can be used to hide secret data objects or other data that will be moved outside the security boundary of the secure subsystem 412. The storage controller circuitry 414 can access the secure hardware registers 418 to define the operation (e.g., encryption or decryption), any operands (e.g., encryption and decryption keys), an initialization vector (if applicable), the location and length of the data to be encrypted / decrypted, and the location / length of the result to be stored. The asymmetric cryptographic security assist hardware circuitry 420 can then transmit a notification (e.g., an event interrupt) to the storage controller circuitry 414 of the successfully encrypted or decrypted data and the location of the result.

[0053] In a sixth example, the one or more security assist hardware circuits 420 may perform data manipulation functions. For example, the data manipulation may include transferring a key value from a location that is inaccessible to the storage controller circuit 414 (e.g., internal RAM 424 or internal non-volatile memory 422) to a location where the storage controller circuit 414 can indirectly access the key value (e.g., secure hardware register 418).

[0054] In a seventh example, one or more security assist hardware circuits 420 may perform data movement functions. One example of a data movement security assist hardware circuit may be a transfer control circuit 432 that supports data transfer between the security subsystem 412 and an external memory device (e.g., dynamic memory 406 and / or external non-volatile memory 408).

[0055] The storage controller circuit 414 may include a system processor 434, storage system firmware 436, security firmware 438, system hardware registers 440, system auxiliary hardware 442, a host interface 444, a write data path control circuit 446, and a read data path control circuit 448. The system processor 434, storage system firmware 436, system hardware registers 440, system auxiliary hardware 442, host interface 444, write data path control circuit 446, and read data path control circuit 448 may be described above with respect to Figure 2 The system processor 236, storage system firmware 240, system hardware registers 238, system auxiliary hardware 242, host interface 244, write data path control circuit 246, and read data path control circuit 248 are implemented as described in detail.

[0056] Figure 44. Embodiments include security firmware 438 in the storage controller circuit 414, and the system processor 434 is responsible for executing both the storage system firmware 436 and the security firmware 438. The security firmware 438 defines specific security operations that can be requested by the system processor 434 of the security subsystem 412 to be performed by the security assist hardware circuit 420. Thus, operations to be performed and access to secret data objects stored within the security subsystem 412 can be maintained without requiring a dedicated security processor within the security subsystem 412.

[0057] Figure 5 It is based on the description Figure 4 A flow chart (generally designated 500) of operational steps for performing a security operation according to an embodiment of the present invention.

[0058] In operation 502, the security subsystem 412 receives a command at one or more security hardware registers 418. For example, the system processor 434 executing security firmware 438 may transmit a command to perform one or more security operations that create, move, modify, or otherwise contain secret data objects maintained within the security subsystem 412. In various embodiments, the system processor 434 may be limited to accessing a subset of the security hardware registers 418. In operation 504, the security subsystem 412 identifies one or more applicable security assist hardware circuits 420 to perform the security operation. The security subsystem 412 may identify the one or more applicable security assist hardware circuits, for example, by decoding the received command. In various embodiments, the received command may instruct a specific security assist hardware circuit 420 to perform the operation. In some embodiments, the command may be received at a specific security hardware register 418 corresponding to a specific security assist hardware circuit 420. In such embodiments, upon detecting receipt of the command, the security control circuit 426 may automatically transmit the received command to the applicable security assist hardware circuit 420.

[0059] In operation 506, the security subsystem executes the requested command by performing security operations using the applicable security assist hardware circuit 420 or other components (e.g., encryption circuit 428 or decryption circuit 430). Figure 4 Various example security assistance hardware circuits 420 are described for performing discrete security operations. In operation 508, the security subsystem 412 writes the result to the system hardware register 440. In various embodiments, the result may include a value indicating whether the security operation was successfully completed and / or the location of any resulting data (e.g., decrypted data). The security control circuit 426 may provide a communication interface between the security subsystem 412 and the system hardware register 440.

[0060] Figure 6is a flow chart (generally designated 600 ) depicting operational steps for performing security operations in accordance with an embodiment of the present invention.

[0061] In operation 602, the security subsystem receives a command at a secure hardware register (e.g., secure hardware register 218, 418). In operation 604, the security subsystem determines whether the received command is a write command. In various embodiments, the security subsystem may determine whether the command is a write command based on the format of the received command as interpreted by the security processor (e.g., security processor 220) or the specific hardware register to which the command is written. If the security subsystem determines that the received command is a write command (decision block 604, yes branch), then in operation 606, the security subsystem receives the data to be written. In operation 608, the security subsystem encrypts the data, for example, using encryption circuitry (e.g., encryption circuitry 230, 428). In operation 610, the security subsystem stores the encrypted data in external memory (e.g., storage media 210, 410). In operation 624, the security subsystem transfers the result to the system hardware register. In various embodiments, the result may include a value indicating that the data was successfully encrypted and written to the storage medium 210 , 410 .

[0062] If the security subsystem determines that the received command is not a write command (decision block 604, NO branch), then in operation 612, the security subsystem determines whether the received command is a read command. If the security subsystem determines that the received command is a read command (decision block 612, YES branch), then in operation 614, the security subsystem retrieves the data to be read from the external memory device (e.g., storage medium 210, 410). In operation 616, the security subsystem decrypts the retrieved data, for example, using decryption circuitry 232, 430. In operation 618, the security subsystem transmits the decrypted data to a location external to the security subsystem. For example, the security subsystem may provide the decrypted data to a read data path control circuit (e.g., read data path control circuitry 248, 448). In operation 624, the security subsystem transmits the result to a system hardware register. In various embodiments, the result may include a value indicating that the data was successfully retrieved, decrypted, and provided to the read data path control circuitry.

[0063] If the security subsystem determines that the received command is not a read command (decision block 612, no branch), then in operation 620, the security subsystem determines the type of security operation requested by the command. In operation 622, the security subsystem performs the security operation based on the determined type of operation. The security operation may be performed, for example, by a security processor (e.g., security processor 220) or by one or more security hardware assist circuits (e.g., security assist hardware 224, 420). In operation 624, the security subsystem transmits a result to a system hardware register indicating successful completion of the security operation.

Claims

1. A device for safe operation, comprising: a plurality of secure hardware registers configured to receive instructions to perform a plurality of security operations for manipulating one or more secret data objects; and One or more security assist hardware circuits configured to perform discrete operations using the one or more secret data objects, wherein each of the plurality of security hardware registers corresponds to a different security assist hardware circuit, the discrete operations comprising at least one of data encryption, data decryption, signature calculation and verification, and random number generation.

2. The apparatus according to claim 1, further comprising: a memory configured to store the one or more secret data objects; and A processor executes security firmware and performs a set of operations including the plurality of security operations to manipulate the one or more secret data objects.

3. The apparatus of claim 1, wherein the one or more secret data objects include at least one encryption key. The apparatus of claim 1 , wherein the one or more secret data objects are inaccessible to devices external to the apparatus.

5. The apparatus of claim 1 , further comprising: encryption circuitry configured to encrypt data using the one or more secret data objects; and Decryption circuitry is configured to decrypt data using the one or more secret data objects.

6. The device of claim 2, wherein the processor is configured to execute the security firmware stored on the memory external to the device.

7. The apparatus of claim 2, wherein the processor, the plurality of secure hardware registers, and the one or more secret data objects are placed within a secure boundary.

8. The apparatus of claim 7, wherein the processor is configured to execute the security firmware stored on the memory within the security boundary.

9. The apparatus of claim 2, wherein the processor is configured to manipulate the one or more secret data objects based on a limited number of security operations.

10. A method for safe operation, comprising: receiving a request to perform a security operation at one or more of a plurality of secure hardware registers; and The security operation is performed using one of a plurality of security assistance hardware circuits, the security operation including at least one of random number generation, encryption key generation, signature calculation, signature confirmation, symmetric encryption, symmetric decryption, asymmetric encryption, and asymmetric decryption, wherein a corresponding one of the plurality of security hardware registers corresponds to a different security assistance hardware circuit among the plurality of security assistance hardware circuits. The method of claim 10 , wherein the request to perform the security operation comprises manipulating one or more secret data objects.

12. The method of claim 11, wherein manipulating the one or more secret data objects occurs based on a defined number of security operations.

13. The method according to claim 10, further comprising: A value responsive to performing the secure operation is transferred to a non-secure hardware register, wherein the plurality of secure hardware registers, the one or more secret data objects, and the dedicated security processor are located within a secure boundary.

14. The method according to claim 13, further comprising: The dedicated security processor is notified of the request to perform the security operation.

15. The method of claim 13, further comprising: The security operations are performed based on dedicated security firmware stored on memory within the security boundary.

16. The method of claim 15, wherein performing the security operation comprises encrypting data using the one or more secret data objects.

17. The method of claim 16, wherein performing the security operation comprises storing encrypted data in a storage device outside the security boundary.

18. The method of claim 15, wherein performing the security operation comprises retrieving encrypted data from a storage device outside the security boundary.

19. The method of claim 18, wherein performing the security operation comprises decrypting the encrypted data using the one or more secret data objects.

20. The method of claim 18, wherein performing the security operation comprises: One or more of the plurality of security-assistance hardware circuits configured to perform the security operation are identified.

21. An apparatus for safe operation, comprising: The security subsystem located within the security boundary includes: a memory device configured to receive, from outside the security boundary, one or more secret data objects that are inaccessible to any system or component external to the secure subsystem, the memory device further configured to store the received one or more secret data objects; a processor configured to execute security firmware and perform a set of operations limited to a plurality of security operations for manipulating the one or more secret data objects received from outside the security boundary; a plurality of secure hardware registers accessible by the processor and configured to receive instructions to perform the plurality of security operations; and one or more security-assisting hardware circuits configured to perform discrete operations using the one or more secret data objects, The one or more secret data objects are keys for security operations.

22. The apparatus of claim 21, wherein the one or more secret data objects include at least one encryption key that is inaccessible to means external to the apparatus.

23. The apparatus of claim 21, wherein the security subsystem further comprises encryption circuitry configured to encrypt the data using the one or more secret data objects.

24. The apparatus of claim 21, wherein the processor is a secure processor, and in, The security firmware is stored on external memory and defines a limited number of security operations performed by the security processor.

25. The apparatus of claim 21, wherein the security subsystem further comprises decryption circuitry configured to decrypt the data using the one or more secret data objects.

26. The apparatus of claim 21 , wherein the security subsystem further comprises: an encryption circuit coupled between the processor and the media interface; a decryption circuit coupled to the media interface; and A transmit control circuit is coupled to at least one of the one or more security-assist hardware circuits.

27. The apparatus of claim 21, wherein the one or more security-assistance hardware circuits are configured to perform at least one of client authentication, encryption key generation, key identification, key selection, and retrieval operations.

28. The apparatus of claim 21, wherein the security subsystem is configured to encrypt secret information for storage external to the security subsystem in at least one of dynamic memory and non-volatile memory.

29. The apparatus of claim 21, wherein the one or more secret data objects comprise an encryption key, and in, The security subsystem further includes encryption circuitry configured to encrypt the data using the encryption key and provide the encrypted data to a media interface for storage in a storage medium.

30. The apparatus of claim 21, wherein the one or more secret data objects include a decryption key stored in the memory device to be maintained within the secure subsystem, and The security subsystem further includes a decryption circuit configured to decrypt the data using the decryption key that is inaccessible to components outside the security boundary, and the decryption circuit is further configured to provide the decrypted data to the storage controller circuit.

31. An apparatus for safe operation, comprising: an internal memory device configured to receive one or more secret data objects from outside the secure boundary, the internal memory device further configured to store the one or more secret data objects inaccessible to any system or component external to the secure subsystem; one or more secure hardware registers within the security boundary configured to receive a command to perform an operation using the one or more secret data objects received from outside the security boundary; and one or more security assist hardware circuits respectively coupled to the one or more secure hardware registers, the one or more security assist hardware circuits being configured to perform discrete operations to access data using the one or more secret data objects, wherein the data accessed using the one or more secret data objects is provided to or by the one or more security assist hardware circuits and is inaccessible from outside the security boundary, and The one or more secret data objects are keys for security operations.

32. The apparatus of claim 31 , further comprising: encryption circuitry configured to encrypt the data using the one or more secret data objects; and Decryption circuitry is configured to decrypt the data using the one or more secret data objects.

33. The apparatus of claim 31 , wherein the one or more secret data objects encrypt secret information for storage outside of a secure subsystem.

34. The apparatus of claim 31, wherein at least one of the one or more secret data objects is encrypted by a secret encryption key and thereafter stored external to the secure subsystem.

35. The apparatus of claim 31 , further comprising: a memory configured to store the one or more secret data objects; and A processor is configured to execute security firmware and perform a set of operations including a plurality of security operations for manipulating the one or more secret data objects.

36. The apparatus of claim 31 , wherein the one or more secret data objects include at least one encryption key.

37. A method for safe operation, comprising: receiving, by one or more secure hardware registers of a plurality of secure hardware registers in a security subsystem within a secure boundary of an integrated circuit, a request to perform a security operation involving one or more secret data objects encrypted by the security subsystem, wherein the encrypted one or more secret data objects are stored outside the security subsystem and are inaccessible to any system or component external to the security subsystem; accessing, by one or more security assistance hardware circuits, the one or more encrypted secret data objects using a key stored in the security subsystem; and performing, by the one or more security assist hardware circuits, the security operation on the data using the accessed one or more secret data objects, The one or more secret data objects are keys for security operations.

38. The method of claim 37, further comprising: Security firmware is executed by a memory system processor in response to a notification from the one or more secure hardware registers, the notification provided by the one or more secure hardware registers based on the received request.

39. The method of claim 37, further comprising: A value is transferred to an unsecure hardware register in response to performing the secure operation.

40. The method of claim 37, wherein the security operations are performed based on dedicated security firmware stored on a memory within the security boundary.

Citation Information

Patent Citations

  • Data processing apparatus

    CN101556638A

  • Circuit chip for cryptographic processing having a secure interface to an external memory

    US20060059369A1