Data storage device with secure optical data link
By combining quantum key distribution and cryptographic engines in optical communication links, the security problem of encrypted key exchange in optical communication links is solved, and data security protection in distributed data storage architecture is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SANDISK TECH
- Filing Date
- 2021-02-23
- Publication Date
- 2026-08-04
AI Technical Summary
Existing optical communication links are difficult to securely exchange encryption keys in data storage, and the risk of eavesdropping increases in decentralized data storage architectures, making it difficult to guarantee the security of user content data.
Quantum key distribution is performed using optical devices, transmitting user content data via an optical data link, and combining a cryptographic engine and controller to achieve quantum-secure key exchange and data protection. Quantum key distribution is performed using optical key distribution devices such as Mach-Zehnder modulators and coherent states.
It enables secure key exchange and data protection over optical communication links, enhances the security of data storage devices, prevents eavesdropping, and is suitable for distributed data storage architectures.
Smart Images

Figure CN114730253B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to secure optical communication links. Specifically, this disclosure relates to data storage devices, random access memory, host interfaces, and network layers that include secure optical communication links. Background Technology
[0002] Recently, the demand for data storage has increased significantly. As a result, more advanced data storage solutions have become available. Specifically, optical links for transferring data to and from data storage devices have become more common.
[0003] However, a major problem with this type of link is data security, as it is often difficult to securely exchange encryption keys. Furthermore, in some applications, storing user content data in encrypted form is impractical because access to the data would require accessing it from various different systems that may not have the necessary cryptographic keys available. Moreover, as data storage architectures become more decentralized, eavesdropping becomes a risk that compromises the security of cryptographic key distribution.
[0004] Therefore, there is a need for more secure optical communication links for data storage devices, random access memory, host interfaces, and network layers. Summary of the Invention
[0005] This disclosure provides an optical device integrated with a data storage device, random access memory, host interface, or network layer. This optical device performs quantum key distribution via an optical data link, which is also used to transmit user content data stored on the storage device, random access memory, or host interface. After exchanging cryptographic keys in a quantum-safe manner, conventional cryptography can be used to protect the optical communication channel. The additional network layer enables the discovery of quantum key distribution capabilities, key protocols at the physical layer, and cryptographic functions.
[0006] This document discloses a data storage device comprising: an optical data port configured to connect to an external optical communication link; and a non-volatile storage medium configured to store user content data received via the optical communication link. The data storage device further comprises: a controller configured to control access to the user content data stored on the non-volatile storage medium; a cryptographic engine configured to perform cryptographic operations on data sent and received via the optical data port using a cryptographic key; and an optical key distribution device coupled to the optical data port and configured to perform quantum key distribution via the optical communication link to provide the cryptographic key to the cryptographic engine.
[0007] In some implementations, the controller is also configured to execute a protocol stack based on Non-Volatile Memory Express over Fabrics.
[0008] In some implementations, the protocol stack includes features for discovering quantum key distributions.
[0009] In some implementations, the protocol stack includes features for key negotiation.
[0010] In some implementations, the optical key distribution device is manufactured as an integrated silicon device.
[0011] In some implementations, the optical key distribution device includes a Mach-Zehnder modulator with interleaved grating couplers.
[0012] In some implementations, the optical key distribution device is also configured to perform quantum key distribution based on photon polarization.
[0013] In some implementations, the optical key distribution device is also configured to convert the polarization of the photon in the optical communication link into the path that the photon takes in the integrated circuit.
[0014] In some implementations, the optical key distribution device is also configured to perform quantum key distribution based on coherent states.
[0015] This document discloses a method for transmitting data stored on a data storage device. The method includes: receiving a key exchange capability discovery message from the data storage device via an optical communication link; in response to receiving the discovery message, performing quantum key distribution via the optical communication link to generate a cryptographic key at the data storage device; and using the cryptographic key to perform cryptographic functions to protect the data transmitted via the optical communication link.
[0016] In some implementations, performing these cryptographic functions includes encrypting and decrypting user content data stored on non-volatile memory.
[0017] In some implementations, performing these cryptographic functions includes encrypting and decrypting communications over the optical communication link.
[0018] In some implementations, performing quantum key distribution includes: encoding quantum information onto a photon; and transmitting the photon over the optical communication link.
[0019] In some implementations, performing quantum key distribution involves transmitting classical digital data over the optical communication link, the classical digital data being indicative relative to the encoded quantum information.
[0020] This document discloses a data storage device comprising: means for receiving a discovery message of key exchange capability via an optical communication link; means for performing quantum key distribution via the optical communication link in response to receiving the discovery message to generate a cryptographic key at the data storage device; and means for using the cryptographic key to perform cryptographic functions to protect data transmitted via the optical communication link.
[0021] This document discloses a random access memory module comprising: an optical data port configured to be connected to an optical communication link external to the random access memory module; a volatile random access memory configured to store user content data received via the optical communication link; a cryptographic engine configured to perform cryptographic operations on data sent and received via the optical data port using a cryptographic key; and an optical key distribution device coupled to the optical data port and configured to perform quantum key distribution via the optical communication link to provide the cryptographic key to the cryptographic engine.
[0022] This document discloses a host interface for providing communication between a host computer and a memory device. The host interface includes: an optical data port configured to connect to the memory device via an external optical communication link; a cryptographic engine configured to perform cryptographic operations on data sent and received through the optical data port using a cryptographic key; and an optical key distribution device coupled to the optical data port and configured to perform quantum key distribution via the optical communication link to provide the cryptographic key to the cryptographic engine.
[0023] This document also discloses a method for operating interconnected data storage devices. The method includes: determining whether key distribution capability exists at one of the interconnected data storage devices; in response to determining the existence of such key distribution capability at one of the interconnected data storage devices, performing quantum key distribution via an optical communication link to generate a cryptographic key pair, the cryptographic key pair including a first key stored at a host computer and a second key stored at the one of the interconnected data storage devices; and using the cryptographic key to perform cryptographic functions to protect data transmitted via the optical communication link.
[0024] In some implementations, performing quantum key distribution involves transmitting photons encoded with quantum information over the optical communication link.
[0025] In some implementations, performing quantum key distribution includes transmitting classical digital data associated with the quantum information encoded on the photon. Attached Figure Description
[0026] A non-limiting example will now be described with reference to the following figures, in which:
[0027] Figure 1 A data storage device according to one embodiment is shown;
[0028] Figure 2 A Mach-Zehnder modulator, implemented as a photonic integrated circuit according to one embodiment, is shown.
[0029] Figure 3 An example from one implementation scheme is shown. Figure 1 The physical implementation of optical ports and optical key distribution devices;
[0030] Figure 4 A host-based fast protocol for nonvolatile memory, executed according to one embodiment, is illustrated.
[0031] Figure 5 A method for transferring data stored on a data storage device, performed by a controller integrated with the data storage device, according to one embodiment, is shown.
[0032] Figure 6 A computer architecture including a processor and random access memory according to one embodiment is shown;
[0033] Figure 7 A host interface according to one implementation scheme is shown;
[0034] Figure 8 A network connectivity layer, representing a method for operating an interconnected data storage device according to one embodiment, is shown. Detailed Implementation
[0035] Data storage devices
[0036] Figure 1 A data storage device 100 according to one embodiment is shown. The data storage device 100 includes an optical data port 101, a non-volatile storage medium 102, a controller 103, a cryptographic engine 104, and an optical key distribution device 105.
[0037] Optical data port 101 is configured to connect to an optical communication link 106, such as a fiber optic cable, external to the data storage device. In this document, "external" means that the optical communication link has at least one connection point or end that is physically located outside the housing containing the data storage device 100. For example, optical data port 101 could be a small pluggable (SFP) network interface module that connects the data storage device to a Fiber Channel (FC) medium. Other physical layer options, such as InfiniBand and integrated waveguides, are also possible. Furthermore, the communication link may not require physical fiber optics or other media, as described below in free-space optics.
[0038] In some examples, optical data port 101 connects to optical media according to the Non-Volatile Memory Fast (NVMe) specification or the Non-Volatile Memory Host Controller Interface (NVMHCIS) specification. Specifically, optical data port 101 can connect data storage device 100 to a fabricated NVMe (NVMe-oF) network. This can include switching fabricated network topologies. The term "fabrication" as used in this context enables arbitrary connections between components. A fabrication can be distinguished from a network, which may limit the possible connections between attached components.
[0039] The non-volatile storage medium 102 is configured to store user content data received via an optical communication link through the optical data port 101. The storage medium can be a spinning disk in a hard disk drive (HDD), NAND flash memory in a solid-state drive (SSD), or emerging memory devices such as magnetic random access memory (RAM), phase-change memory, or resistive RAM. Other storage media may also be used.
[0040] Controller 103 is connected to optical port 101 and, in one embodiment, includes a fiber-to-copper converter. Alternatively, the converter may be integrated with optical port 101. Controller 103 controls access to user content data stored on non-volatile storage media, such as read and write access, and implements communication protocols to establish connections with a communication party, such as a host computer or other NVMe-oF infrastructure, such as a Fibre Channel switch or rack controller. It should be noted that NVMe bypasses certain levels of code in the FC protocol stack. However, other protocols may also be used. Controller 103 may implement a Remote Direct Memory Access (RDMA) protocol to establish connections and receive commands, including commands to read data from storage medium 102 or write data to storage medium 102.
[0041] cryptography
[0042] The cryptographic engine 104 is configured to perform cryptographic operations on data sent and received through the optical data port using cryptographic key pairs. The cryptographic operations can be symmetric with two identical secret keys, or asymmetric with a public key and a private key. Furthermore, the cryptographic operations can be based on cipher suites such as Rivest–Shamir–Adleman (RSA), Data Encryption Standard (DES), Advanced Encryption Standard (AES), Blowfish, etc.
[0043] exist Figure 1 In this example, cryptographic engine 104 is connected to controller 103, and controller 103 sends cryptographic commands to cryptographic engine 104 and receives results from cryptographic engine 103. For example, controller 103 provides all data to be sent through optical port 101 for encryption, receives encrypted data from cryptographic engine 104, and sends encrypted data through the optical port. Conversely, controller 103 receives encrypted data from optical port 101, provides the encrypted data to cryptographic engine 104, and receives decrypted data from cryptographic engine 104. Cryptographic engine 104 may store the required key on integrated non-volatile memory or receive the key from controller 103.
[0044] In other examples, the cryptographic engine 104 is connected between the controller 103 and the optical port 101, also referred to as "through-hole," and encrypts and decrypts all data transmitted through the optical data port 101 without any intervention from the controller 103. In other words, the controller 103 is unaware of the presence of the cryptographic engine 104 when sending and receiving unencrypted data.
[0045] This disclosure focuses on the encryption and decryption of communications over an external communication link 106, such as a fiber optic cable. However, any key distributed according to the methods disclosed herein can also be used to encrypt and decrypt user content data stored on storage medium 102.
[0046] An optical key distribution device 105 is coupled to an optical data port 101, enabling the optical key distribution device to receive optical signals transmitted via a communication link 106. The optical key distribution device 105 is configured to perform quantum key distribution via the optical communication link to provide cryptographic keys to the cryptographic engine.
[0047] Quantum key distribution process
[0048] In one example, the quantum key distribution process utilizes quantum uncertainty. In this sense, quantum information in a physical system, such as a photon, can only be measured once. Quantum measurement causes the quantum state to collapse, resulting in one of two possible outcomes. This means that an eavesdropper intercepting a carrier of quantum information, such as a photon, can destroy that quantum information by measuring the encoded quantum information.
[0049] Furthermore, quantum information can be encoded onto photons on different bases. In particular, there are two conjugate bases, which, for ease of explanation, can be considered "orthogonal." If quantum information is encoded onto a photon on the first base, that quantum information can be measured on the first base. Measurements on the second "orthogonal" base will produce random results.
[0050] This principle can be used by both "Alice" and "Bob". Alice creates random bits (0 or 1) and then randomly chooses one of her two bases (in this case, a straight line or a diagonal) for transmission. She then prepares the photon polarization state based on the bit values and the base. Alice then transmits a single photon in a state assigned to Bob using a quantum channel. This process is then repeated from the random bit stage, where Alice records the state, base, and time for each photon transmitted. Since Bob does not know the base encoded by the photon, he can only randomly choose one base to measure, which can be either a straight line or a diagonal. He does this for each received photon, recording the time, the measurement base used, and the measurement result. After Bob has measured all the photons, he communicates with Alice via a public classical channel. Alice broadcasts the base of each photon, and Bob broadcasts the base of each photon measurement. They both discard the photon measurements (bits), with Bob using a different base, averaging half, leaving half the bits as a shared key. To check for the presence of an eavesdropper, Alice and Bob now compare a predetermined subset of their remaining bit strings. If a third party (often referred to as Eve, the "eavesdropper") has obtained any information about the photon polarization, this will introduce errors into Bob's measurements. Other environmental conditions can cause errors in a similar way. If more than p bits differ, they abort the key and retry, possibly using a different quantum channel, because the security of the key cannot be guaranteed. p is chosen such that if the number of bits known to Eve is less than this value, privacy amplification can be used to reduce Eve's knowledge of the key to an arbitrarily small amount, at the cost of reducing the key length.
[0051] In other examples, different schemes can be used, such as those relying on entangled photon pairs, such as the Artur Ekert scheme according to the E91 protocol described in Artur K.'s "Quantum cryptography based on Bell's theorem" (Physical Review Letters. 67(6): 661–663) (August 5, 1991), or continuous variable schemes, such as Gaussian modulation.
[0052] Quantum key distribution hardware
[0053] In one example, the optical key distribution device 105 includes a Mach-Zehnder modulator (MZM) with interleaved grating couplers that convert the polarization of photons in an optical fiber into the path that photons take in an integrated circuit, and vice versa.
[0054] Figure 2 An MZM200 in the form of a photonic integrated circuit (PIC) according to one embodiment is shown. The MZM200 includes an input 201 and an output 202, as well as internal phase modulators 203 / 204 and external phase modulators 205 / 206. Optical fibers are coupled into and out of the encoder using an array of V-grooves with a spacing of 250 μm. A polarization grating coupler is used to convert between polarization coding in the input-output fibers and path coding within the PIC. The overall transformation is similar to that of a polarization beam splitter (PBS). Within the PIC, the MZM200, with two internal electro-optic phase modulators 203 / 204 and two external electro-optic phase modulators 205 / 206, manipulates the paths of photons and their relative phases, which in turn manipulate the polarization of photons in the output fiber. The input polarization grating coupler separates light from horizontally and vertically polarized light into two distinct paths, both in transverse electrical (TE) polarization: their electric fields oscillate parallel to the chip surface. Any light that is inadvertently converted to transverse magnetic (TM) polarization in these waveguides is greatly attenuated by phase modulators, which strongly support transmission with higher TE polarization than TM polarization.
[0055] The electro-optic phase modulators 203 / 204 / 205 / 206 in the MZM 200 are based on depletion-mode free carrier dispersion from a doped pin junction superimposed on an optical mode. The overlap between the optical mode and the free carrier causes free carrier refraction, which can be controlled with a gigahertz radio frequency signal to achieve high-speed phase modulation.
[0056] In one example, controller 103 uses an MZM 200 to execute the Bennett-Brassard 1984 (BB84) quantum key distribution (QKD) protocol. Therefore, the first party, 'Alice', prepares three quantum states: two Z eigenstates and one X eigenstate. Alice randomly chooses the basis she has prepared. When choosing the Z basis, Alice prepares |0... z >=H or |1 z >= V, where the probability is equal to 1 / 2. Otherwise, when X is chosen as the basis, Alice is ready.
[0057] The internal phase modulators 203 / 204 and the external phase modulators 205 / 206 can be configured to generate states. It will be considered as |0 z >. Applying radio frequency (RF) signals of different voltages to one of the external phase modulators to generate... in It is an applied phase shift. All three BB84 states can be determined by applying a phase shift. It is generated from π / 2 and π.
[0058] Bob, for example, uses a device similar to optical key distribution device 105 to receive the signal and transforms it back to the original coordinate system using a suitable polarization controller. Here, not only is the arbitrary polarization transformed to the desired polarization (0°), but the phase shift between this polarization (0°) and its orthogonal counterpart (90°) is also controlled. This polarization controller will have three degrees of freedom. The following describes the implementation of a tracking speed of 20 kiloradians per second (krad / s) on a Poincaré sphere: "20 krad / s Endless Optical Polarization and Phase Control" by Koch, B.; Noe, R.; Mirvoda, V.; Sandel, D. et al. (2013) (Electronics Letters. 49(7):483–485), and the First Endless Optical Polarization and Phase Tracker by B. Koch, R. Noé, V. Mirvoda, and D. Sandel (Proc. OFC / NFOEC 2013, Anaheim, CA, Paper No. OTh3B.7, March 17–21, 2013). In this way, the entire normalized Stokes space is stabilized, meaning that the rotation of the Poincaré sphere caused by fiber birefringence disappears.
[0059] As described above, the optical key distribution device 105, including the MZM 200, can be fabricated as a photonic integrated circuit. This means that the MZM is fabricated on a silicon substrate, for example, generated from a waveguide by appropriately doping the silicon substrate. Figure 2 The substrate is fabricated using the curved shape shown. It can then be used to create additional circuitry, such as analog or digital logic circuits, like application-specific integrated circuits (ASICs) or general-purpose processors, on the same substrate. An advantage is that the resulting optical key distribution device 105 is small enough to be integrated into the form factor of a data storage device. Furthermore, the fabrication of the optical key distribution device 105 can contribute only a small amount of additional cost, enabling quantum key distribution to be used on a large number of devices. This is particularly suitable for construction-based memory architectures such as NVMe-oF, where a large number of devices are interconnected.
[0060] coherent state
[0061] In another example, the optical key distribution device 105 is configured to perform quantum key distribution based on coherent states. A coherent state refers to the state of the quantized electromagnetic field of a photon, which describes a maximum coherence and a classical behavior. The optical key distribution device 105 can also be configured to perform continuous variable quantum key distribution (CV-QKD) using Gaussian modulation.
[0062] In the case of Gaussian modulation, Alice prepares permutational coherent states with orthogonal components q and p, which are realizations of two independent and identically distributed (i.id) random variables Q and P. The random variables Q and P follow the same zero-centered normal distribution. After preparing each coherent state, Alice transmits |α| through a Gaussian quantum channel. j > Transmitted to Bob. Bob uses zero-difference or heterodyne detection to measure the eigenvalues of one or two orthogonal operators.
[0063] Screening: In some variants of CV-QKD, Alice and Bob each select the basis for the preparation and measurement states using independently and uniformly generated random bits. In these cases, the screening step eliminates all (irrelevant) signals where different basis sets have already been used for preparation and measurement. In variants of CV-QKD where Alice and Bob use two basis sets simultaneously, no screening is performed.
[0064] Parameter estimation: After transmitting a series of states, Alice and Bob will display and compare a random subset of the transmitted data with the corresponding measurements. This comparison allows them to estimate the total transmission and excess noise of the channel, and from this data, they can calculate their mutual information I. AB And restrict Eve's information χ. If χ is greater than βI AB If so, the agreement is terminated at this point.
[0065] Information verification: Otherwise, if βI AB If the value is greater than χ, Alice and Bob will perform a data check, a form of error correction. A one-way data check, where one party sends its key information to the other, can be performed in two different ways: Bob corrects its bits based on Alice's data (direct check) or Alice corrects its bits based on Bob's data (reverse check). In the case of a forward check, for the total transmittance T... tot<0.5 (≈-3dB), Eve might have more information than Bob about what Alice has prepared, and therefore cannot extract any secret key (assuming Eve could use all the loss for her own benefit). This 3dB loss limitation can be overcome using reverse reconciliation, where Bob sends correction information to Alice, who then corrects her bit string based on Bob's information. In this case, Bob's data is primary, and since Alice always has more information about Bob's measurements than Eve, the mutual information I... AB It can be maintained at χ greater than any total transmission T (of course, the lower T is, the more important the excessive noise ξ becomes).
[0066] Confirmation: After information verification, Alice and Bob perform a confirmation step using a (nearly) universal hash function to limit the probability of error correction failure: Alice or Bob selects a specific hash function from this series with uniform probability and transmits the selection to their partner. Both apply that hash function to their keys to obtain a hash value. Alice and Bob then exchange and compare their hash values. If the hash values are different, the keys are different, and they abort; if the hash values are equal, they continue until they have obtained an upper limit on the probability that the keys are different. This probability of error depends on the length of the hash value and the type of hash function used.
[0067] Privacy Enhancement: After successful confirmation, Alice and Bob will share the same bit string with a very high probability. However, Eve possesses a certain amount of key information. To reduce the probability of Eve successfully guessing (a portion) of the key to an acceptable level, Alice and Bob will implement a privacy amplification protocol by applying a seed randomness extractor (algorithm) to their bit strings. Similarly, a range of general-purpose hash functions are typically used for this purpose.
[0068] Authentication: To prevent Eve's man-in-the-middle attack, Alice and Bob use a series of strong general hash functions to authenticate their classic communication.
[0069] More information can be found in the following references, which are incorporated herein by reference in full:
[0070] • Fabian Laudenbach, Christoph Pacher, Chi-Hang Fred Fung, Andreas Poppe, Momtchil Peev, Bernhard Schrenk, Michael Hentschel, Philip Walther, Hannes Hübel: “Continuous-Variable Quantum Key Distribution with Gaussian Modulation: The Theory of Practical Implementations” (Adv. Quantum Technol. 1800011 (2018)).
[0071] Hua-Lei Yin and Zeng-Bing Chen: “Coherent-State-Based Twin-Field Quantum Key Distribution” (Nature Scientific Reports, (2019) 9:14918).
[0072] • Li Liu, Yukun Wang, Emilien Lavie, Arno Ricou, Chao Wang, Fen Zhuo Guo, Charles Ci Wen Lim: “Practical quantumkey distribution with non-phase-randomized coherent states” (Phys.Rev.Applied. 12, 024048 (2019)).
[0073] Optical connection
[0074] Figure 3The physical implementation of an optical port 101 and an optical key distribution device 105 according to one embodiment is shown. This implementation includes an optical fiber 300 that carries NVMe-oF commands and data to and from a data storage device 100 (not shown). The optical port 101 includes multiple optical ring resonators 301, 302, and 303 coupled to the optical fiber 300. In this example, three optical ring resonators 301, 302, and 303 are present, but this number can be higher or lower for different applications and depending on the number of different wavelengths used. Each of the three optical ring resonators 301, 302, and 303 is tuned to and coupled to a specific wavelength in the optical fiber 300. Therefore, signals transmitted through the optical fiber 300 at that wavelength are coupled to corresponding detectors 311, 312, and 313. These detectors 311, 312 and 313 are photodiodes that convert optical signals into digital voltage signals, which can then be detected and processed by conventional electronic devices such as access controller 103.
[0075] The optical key distribution device 105 includes an additional ring resonator 304 that couples the signal from the optical fiber 300 to the MZM 200. The ring resonator 304 can be tuned to the same wavelength or a different wavelength than one of the resonators 301, 302, and 303. The optical fiber 300 may be a northbound fiber for communication to the data storage device 100, and a southbound fiber (not shown) may be present for communication from the data storage device 100. In some examples, the optical key distribution device 105 includes two MZMs: a first MZM for decoding quantum information received on the northbound fiber and a second MZM for encoding quantum information to be transmitted on the southbound fiber. For communication from the data storage device 100, the optical ports may include optical drivers that convert digital voltage signals into optical pulses, which are then coupled to the optical fiber 300 or a separate southbound fiber via a ring oscillator modulator (not shown).
[0076] protocol
[0077] As described above, controller 103 can implement a Remote Direct Memory Access (RDMA) protocol stack, such as NVMe-oF. Furthermore, the quantum key distribution implemented in optical key distribution device 105 operates via the same optical fiber as the RDMA protocol. Therefore, NVMe-oF can be extended with additional key distribution capabilities. In other words, key distribution-related operations are woven into the NVMe-oF protocol stack. More specifically, the operations disclosed herein occur at the architecture-related top layer of the NVMe-oF stack, where the discovery enables the host computer to discover the quantum key capability of data storage device 100. On the other hand, the actual quantum key distribution occurs at the bottom layer, which is the physical layer of the architecture, because optical key distribution device 105 directly accesses the physical medium to exchange keys.
[0078] The NVMe architecture defines a discovery mechanism that hosts can use to determine which NVM subsystems they can access. The discovery controller supports minimal functionality and implements only the features required to allow retrieval of discovery log rules. The discovery controller does not implement I / O queues or expose namespaces. The discovery service is an NVM subsystem that only exposes the discovery controller. The discovery log page provided by the discovery controller contains one or more entries. Each entry specifies the information a host uses to connect to an NVM subsystem via NVMe. Entries can specify an NVM subsystem that exposes namespaces accessible to the host, or a referral to another discovery service. The maximum supported referral depth is eight levels. The method a host uses to obtain the information necessary to connect to the initial discovery service can be implementation-specific. This information can be determined using host configuration files, hypervisors, OS properties, or other mechanisms.
[0079] Regarding authentication, NVMe-oF supports constructing secure channels (including authentication) and NVMe in-band authentication. An NVM subsystem may require the host to use constructing secure channels, NVMe in-band authentication, or both. The discovery service indicates whether constructing secure channels should be used for the NVM subsystem. The connection response indicates whether NVMe in-band authentication should be used with the controller. Before establishing a secure channel, the controller associated with the NVM subsystem requiring the construction of a secure channel must not accept any commands (construct, administrator, or I / O) regarding NVMe transfers. After a connection command, the controller requiring NVMe in-band authentication must not accept any commands other than authentication commands until NVMe in-band authentication is complete.
[0080] Figure 4An NVMe-oF protocol 400 executed by host 401 according to one embodiment is illustrated. The protocol includes a protocol stack 402 with multiple layers from the top-level NVMe-oF architectural layer 403 down to the physical layer 404. The protocol now also includes additional functionality for a discovery and key protocol 405. In this way, host 401 can query data storage device 100 and, as part of the discovery process, determine that data storage device 100 has the capability to perform quantum key distribution as described above.
[0081] Once quantum key distribution capability has been discovered, host 401 switches to actual quantum key distribution 406 via physical layer 404. This involves encoding quantum information about photons subsequently transmitted via optical fiber, and / or receiving photons to retrieve the quantum information stored thereon. In some examples, data storage device 100 creates all the necessary photons with the quantum information encoded thereon and does not receive any photons from other communicating parties as described above. In other examples, data storage device 100 receives photons and decodes the quantum information, such as measuring the quantum state under one of two possible foundations. This generates a key at host 401 and data storage device 100. As described above, the key protocol can also involve transmitting classical digital data associated with the quantum information encoded on the photons, such as the state under which the quantum information is encoded and measured. This classical communication is called the key protocol and is also performed by protocol element 405.
[0082] Protocol 400 further includes a cryptographic function 407 that uses the key generated at 405. For example, cryptographic function 407 can use the key to perform encryption, decryption, signature calculations, and other cryptographic primitives that can be used to protect communication channels.
[0083] method
[0084] Figure 5 A method 500, performed by a controller 103, is illustrated according to one embodiment for transmitting data stored on a data storage device 100. According to method 500, the controller 103 receives a discovery message 501 from, for example, a host 401 or other constructed component. The discovery message is used to discover key exchange capabilities via an optical communication link. The discovery message is sent and received as digital data via the communication link and therefore involves one or more of the resonators 301, 302, 303 or the detectors 311, 312, 313 and their corresponding modulators.
[0085] In response to receiving a discovery message, controller 103 performs quantum key distribution via optical communication link 300 to generate a cryptographic key at a data storage device. Instead of sending and receiving digital data, this involves sending and receiving quantum information, such as photon polarization. The term "in response to receiving a discovery message" may involve additional steps, such as responding to host 401 that QKD is available, and receiving a request for QKD from host 401. Once it is determined that controller 103 will perform QKD, the controller activates optical key distribution device 105, which directly accesses optical communication link 300 via resonator 304. Therefore, QKD is performed at the physical layer 404 of protocol stack 402.
[0086] Finally, controller 103 uses a cryptographic key to perform the 503 cryptographic function to protect data transmitted over the optical communication link. In one example, this means encrypting and decrypting user content data stored on non-volatile storage medium 102. This means using a cryptographic key exchanged or generated using QKD for disk encryption. In another example, controller 103 uses a cryptographic key to encrypt and decrypt communication over the optical communication link. Therefore, a cryptographic key exchanged or generated using QKD is used for communication encryption. Controller 103 can perform both disk encryption and communication encryption using the same key, or perform QKD multiple times to generate multiple cryptographic keys for these functions.
[0087] Computer Architecture
[0088] Figure 6 A computer architecture 600 according to one embodiment is shown, which includes a processor 601 and a memory module 602, such as a dual in-line memory module (DIMM) including random access memory (RAM). Figure 6 As shown, there may be another DIMM, which may be the same as memory module 602, and therefore will not be described further.
[0089] Processor 601 includes a central processing unit (CPU) 603, which may also include a memory cache, and a memory controller 604. Additionally, a modulator 605 and a detector 606 are present to write and read data onto corresponding north-facing and south-facing optical fibers 607 and 608. The optical fibers use an off-chip laser 609, which generates laser light, which is then modulated to transmit information. A corresponding modulator and detector are also included in memory module 602, but are not shown for clarity.
[0090] The memory controller 604 can now operate the modulator 605 and detector 606 to read and write data stored on the memory module 602. However, there is a risk that an attacker could eavesdrop on the northbound 607 and southbound 608 optical fibers to obtain the transmitted data. Therefore, the processor 601 further includes a security module 610, which has a corresponding security module 611 in the memory module 602. Security modules 610 / 611 include a quantum key distribution module 611, a cryptographic engine 612, a key processing module 613, and a controller 614. The quantum key distribution module 611 is an optical key distribution device coupled to the northbound 607 and southbound 608 optical fibers as described below. Thus, for example, the quantum key distribution module 611 includes a Mach-Zehnder modulator that encodes quantum information about photon polarization and guides photons onto different paths depending on their polarization. In this way, the quantum key distribution module 611 generates cryptographic keys and can store the cryptographic keys in volatile memory.
[0091] Then, the cryptographic engine 612 uses a cryptographic key to encrypt the communication between the processor 601 and the memory module 602. The key processing module 613 manages the key generation process, ensuring that one key is generated and stored for each memory module 602. Finally, the controller 614 controls the quantum key distribution module 611, the cryptographic engine 612, and the key processing module 613, enabling the memory controller 604 to be agnostic to the operation of the security module 610 and to use the memory module 602 like a conventional electronic memory. (Including references) Figures 1-5 The above-described public information also applies to Figure 6 The implementation plan.
[0092] Host Interface
[0093] Figure 7 This illustrates a possible implementation scheme. Figure 6 The host interface 700 is implemented using components already shown. The host interface 700 provides communication between the host computer 401 and a memory device 701, such as a non-volatile data storage device 100, a volatile random access memory module 602, or other memory devices. The host interface 700 includes an optical data port 702 configured to connect to the memory device 701 via an external optical communication link 703, and may include two optical fibers for northbound and southbound communication, respectively. Figure 6 As shown. As previously described, the optical data port 702 includes a detector and a modulator coupled to the communication link 703 via a resonator.
[0094] The host interface 700 further includes a cryptographic engine 703 configured to perform cryptographic operations on data sent and received through the optical data port 702 using a cryptographic key. Additionally, the host interface 700 includes an optical key distribution device 704 coupled to the optical data port 704 and configured to perform quantum key distribution via the optical communication link 702, for example, by using an MZM 705 as described above to provide a cryptographic key to the cryptographic engine 703.
[0095] Figure 8 A method 800 for operating an interconnected data storage device according to one embodiment is illustrated. Essentially, method 800 represents a network connectivity layer implementation, as it is performed by each node in a network or configuration comprising an interconnected data storage device and a host computer system. In performing method 800, a node determines 801 whether key distribution capability exists at one of the interconnected data storage devices. In response to determining the existence of key distribution capability at one of the interconnected data storage devices, the node performs 802 quantum key distribution via an optical communication link to generate a cryptographic key pair. The key pair includes a first key stored at the host computer and a second key stored at one of the interconnected data storage devices. Similarly, for symmetric encryption methods, the first and second keys can be the same, or for asymmetric encryption, the first and second keys can include a public key and a private key.
[0096] The node can then use a cryptographic key to perform cryptographic functions to protect data transmitted over the optical communication link. This protects the communication, making eavesdropping and unauthorized access to the data virtually impossible.
[0097] Free-space optical devices
[0098] While the examples in this paper relate to communication via optical fiber, other communication media can be used. These include integrated waveguides for on-chip communication and free-space optics (FSOs). In an FSO, an optical signal is transmitted across free space without a physical carrier (potentially air or gas). An advantage of FSOs is their high fan-out, meaning that an optical signal (e.g., from an optical fiber) can be split into multiple beams. These beams can be identical or separated based on their wavelengths. The beams can be formed by an integrated optical processor that can construct diffraction gratings to separate the wavelengths. In this example, Figure 3 The individual resonators 301, 302, and 303 shown may not be necessary, as the beam can be directly directed to detectors 311, 312, and 313. The same or different beams can be directed to the MSM 200.
[0099] Quantum Networks
[0100] While the examples in this paper involve direct optical links, the disclosed devices can also be linked via quantum networks that include zero or more repeaters.
[0101] Those skilled in the art will understand that many variations and / or modifications can be made to the above embodiments without departing from the broad general scope of this disclosure. Embodiments of the present invention are therefore to be considered exemplary and not restrictive in all respects.
Claims
1. A data storage device, the data storage device comprising: An optical data port, configured to connect to an external optical communication link of the data storage device; A non-volatile storage medium configured to store user content data received via the optical communication link; A cryptographic engine configured to perform cryptographic operations using a cryptographic key, the cryptographic operations including encrypting and decrypting data transmitted and received through the optical data port; An optical key distribution device, coupled to the optical data port and configured to perform quantum key distribution via the optical communication link; and The controller is configured to: The protocol stack is executed to receive, via the optical communication link to the host, memory commands as digital data for controlling access to the user content data. At the top layer of the protocol stack, a discovery message indicating key exchange capability is received from the host using digital data messages; as well as In response to receiving the discovery message and using the optical key distribution device, a quantum key distribution is initiated from the physical layer of the optical communication link to the host, wherein: The cryptographic engine is also configured to receive the cryptographic key based on the quantum key distribution; as well as Initiating quantum key distribution includes switching the optical key distribution device to utilize the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key.
2. The data storage device according to claim 1, wherein the protocol stack is a remote direct memory access protocol stack, used to receive commands to read user content data from the non-volatile storage medium and write the user content data to the non-volatile storage medium.
3. The data storage device of claim 1, wherein the protocol stack includes the feature of performing key negotiation by exchanging digital data messages at the top layer of the protocol stack to use quantum information exchanged at the physical layer of the optical communication link.
4. The data storage device of claim 1, wherein the optical key distribution device is manufactured as an integrated silicon device.
5. The data storage device of claim 1, wherein the optical key distribution device comprises a Mach-Zehnder modulator with an interleaved grating coupler.
6. The data storage device of claim 1, wherein the optical key distribution device is further configured to perform quantum key distribution based on photon polarization.
7. The data storage device of claim 6, wherein the optical key distribution device is further configured to convert the polarization of the photons in the optical communication link into the path taken by the photons in the integrated circuit.
8. The data storage device of claim 1, wherein the optical key distribution device is further configured to perform quantum key distribution based on coherent states.
9. A method for transmitting data stored on a data storage device, the method comprising: The execution protocol stack is used to receive memory commands as digital data from the host via an optical communication link outside the data storage device; The data storage device, and at the top layer of the protocol stack, utilizes digital data messages for the optical communication link to receive discovery messages regarding quantum key exchange capabilities; In response to receiving the discovery message: Switch the optical key distribution device in the data storage device to use the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key; as well as Using the optical key distribution device, quantum key distribution is performed through the physical layer of the optical communication link to generate the cryptographic key at the data storage device; as well as The cryptographic key is used to perform cryptographic functions, including encrypting and decrypting data, to protect digital data transmitted through the optical communication link.
10. The method of claim 9, wherein performing the cryptographic function includes encrypting and decrypting user content data stored on non-volatile memory.
11. The method of claim 9, wherein performing the cryptographic function includes encrypting and decrypting communications on the optical communication link.
12. The method of claim 9, wherein performing quantum key distribution comprises: Encoding quantum information onto photons; as well as The photons are transmitted via the optical communication link.
13. The method of claim 12, wherein performing quantum key distribution includes transmitting classical digital data via the optical communication link, the classical digital data being indicative relative to the encoded quantum information.
14. A data storage device, the data storage device comprising: An optical data port, configured to connect to an external optical communication link of the data storage device; A non-volatile storage medium configured to store user content data received via the optical communication link; A cryptographic engine configured to perform cryptographic operations using a cryptographic key, the cryptographic operations including encrypting and decrypting data transmitted and received through the optical data port; An optical key distribution device, coupled to the optical data port and configured to perform quantum key distribution via the optical communication link; A means for executing a protocol stack for receiving memory commands as digital data from a host via the optical communication link; A means for receiving a discovery message for key exchange capability using digital data messages for the optical communication link from the data storage device and at the top layer of the protocol stack; A means for responding to receiving the discovery message and performing quantum key distribution via the physical layer of the optical communication link using the optical key distribution device to generate a cryptographic key at the data storage device, wherein the means for performing the distribution is configured to switch the optical key distribution device to use the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key; and A means for performing cryptographic functions using the cryptographic key to protect digital data transmitted over the optical communication link.
15. A random access memory module, the random access memory module comprising: An optical data port, configured to connect to an optical communication link external to the random access memory module; A volatile random access memory configured to store user content data received via the optical communication link; A cryptographic engine configured to perform cryptographic operations using a cryptographic key, the cryptographic operations including encrypting and decrypting data transmitted and received through the optical data port; An optical key distribution device, coupled to the optical data port and configured to perform quantum key distribution via the optical communication link; as well as The controller is configured to: The protocol stack is executed to receive memory commands as digital data via the optical communication link to the memory controller; At the top layer of the protocol stack, a discovery message indicating key exchange capability is received from the host using digital data messages; as well as In response to receiving the discovery message and using the optical key distribution device, a quantum key distribution is initiated from the physical layer of the optical communication link to the memory controller, wherein: The cryptographic engine is also configured to receive the cryptographic key based on the quantum key distribution; as well as Initiating quantum key distribution includes switching the optical key distribution device to utilize the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key.
16. A host interface for providing communication between a host computer and a memory device, the host interface comprising: An optical data port, configured to connect to the memory device via an optical communication link external to the host interface; A cryptographic engine configured to perform cryptographic operations using a cryptographic key, the cryptographic operations including encrypting and decrypting data transmitted and received through the optical data port; and An optical key distribution device, coupled to the optical data port and configured to perform quantum key distribution via the optical communication link; as well as The controller is configured to: Execute a protocol stack for receiving memory commands as digital data via the optical communication link to the memory device; At the top layer of the protocol stack, a discovery message indicating key exchange capability is received from the host computer using digital data messages; as well as In response to receiving the discovery message and using the optical key distribution device, a quantum key distribution is initiated from the physical layer of the optical communication link to the memory device, wherein: The cryptographic engine is also configured to receive the cryptographic key based on the quantum key distribution; as well as Initiating the quantum key distribution includes switching the optical key distribution device to utilize the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key.
17. A method for operating an interconnected data storage device, the method comprising: An execution protocol stack is used to receive storage commands as digital data via optical communication links between and outside the interconnected data storage devices; At the top layer of the protocol stack, digital data messages are used to determine whether key distribution capability exists at one of the interconnected data storage devices. In response to determining that the key distribution capability exists at one of the interconnected data storage devices: Switching the optical key distribution device in the interconnected data storage device to utilize the physical layer of the optical communication link to transmit quantum information for determining the cryptographic key; and Using the optical key distribution device, quantum key distribution is performed through the physical layer of the optical communication link to generate a cryptographic key pair, the cryptographic key pair including a first key stored at one of the interconnected data storage devices and a second key stored at another interconnected data storage device in the interconnected data storage device, wherein the optical key distribution device uses the physical layer of the optical communication link to transmit quantum information for generating the cryptographic key pair; as well as The cryptographic key pair is used to perform cryptographic functions to protect digital data transmitted through the optical communication link, the cryptographic functions including encrypting and decrypting data transmitted through the optical communication link.
18. The method of claim 17, wherein performing quantum key distribution comprises transmitting photons encoded with quantum information over the optical communication link.
19. The method of claim 18, wherein performing quantum key distribution includes transmitting classical digital data associated with the quantum information encoded on the photon.