Data storage device encryption

By configuring the hardware circuit system in the controller of the data storage device for encryption and decryption when requesting data, the problem of insufficient security during transmission is solved, and the secure transmission of data in an insecure link is realized.

CN114730342BActive Publication Date: 2025-06-06SANDISK TECH

Patent Information

Application Number
CN202180006733.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-03-31
Filing Date
2021-06-21
Publication Date
2025-06-06
Estimated Expiration
2041-06-21

AI Technical Summary

Technical Problem

The prior art cannot effectively protect the security of data in data storage devices, especially in the data links that may be eavesdropped by attackers.

Method used

By configuring the hardware circuit system in the controller of the data storage device, encryption of data is realized and decryption is disabled when requesting data, ensuring that the data remains encrypted during transmission.

Benefits of technology

It realizes the secure transmission of data in unsecured links, prevents attackers from obtaining unencrypted data, and improves the security of data storage devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114730342B_ABST
    Figure CN114730342B_ABST
Patent Text Reader

Abstract

The present disclosure relates to data storage device (DSD) hardware, and more particularly to systems and methods for encrypting data stored on the DSD. The DSD includes a non-volatile storage medium for storing a plurality of file system data objects using block addressing. A device controller is integrated with the DSD and includes hardware circuitry configured to encrypt data to be stored on the storage medium. The controller receives a request for an encrypted file system data object from a host computer system, identifies a range of block ranges in which the requested encrypted file system data object is stored on the storage medium, and sends the file system data object stored in the identified block range to the host computer system in an encrypted form as stored on the storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Aspects of the present disclosure relate generally to data storage device hardware, and more particularly to systems and methods for encrypting data stored on a data storage device. Background Art

[0002] Figure 1 A typical scenario 100 is shown, which includes a host computer system 101 and a data storage device (DSD) 102 connected to the host computer system 101 via a data link 103, such as Fibre Channel (FC), Serial Advanced Technology Attachment (SATA), Serial Attached Small Computer System Interface (SAS), etc. The DSD 102 can be located within the host computer system 101 or external to the host computer system 101, such as on a separate rack in a server room.

[0003] The host computer system 101 also includes a processor 104 and volatile memory, such as random access memory (RAM) 105. The host computer system 101 can be a desktop or laptop computer, a mobile device, or a server located in a data center, and can have an operating system such as Microsoft Windows or Linux installed thereon. The host computer system 101 can also be a virtual machine or cloud instance or any other computing device. The DSD 102 includes a controller 106, a physical data storage medium 107, and a read / write device 108. Although the current example describes a hard disk drive (HDD) with rotating media, the present disclosure is equally applicable to other storage media, such as those found in a solid-state drive (SSD) or magnetic tape.

[0004] One difficulty with data storage is that the DSD 102 can be physically removed or stolen and installed in a different host computer to retrieve sensitive information stored on the DSD 102. Therefore, it is important to provide encrypted "data at rest".

[0005] One method for providing encrypted static data is full disk hardware encryption. To this end, the controller 106 includes hardware circuitry that performs encryption functions such as the Advanced Encryption Standard (AES). The controller 106 can then encrypt all data it receives via the data link 103 and store the encrypted data on the storage medium 107. Conversely, the controller 106 retrieves the encrypted data from the storage medium 107, decrypts the data, and sends the decrypted data via the data link 103.

[0006] Processor 104 may then perform software encryption to encrypt data received from DSD 102, which may be useful, for example, if the data is then sent to a different computer system over an insecure channel. However, this is not an end-to-end solution because the data link 103 between the DSD and the host computer system 101 carries the data in plain text (i.e., unencrypted). Therefore, it is possible for an attacker to eavesdrop on the data link 103 and gain unauthorized access to the unencrypted data. Summary of the invention

[0007] Hardware encryption is improved by encrypting received data but disabling decryption when requesting data. In this way, a file spanning a defined range of blocks can be retrieved in encrypted form. The blocks can then be sent across an unsecured link and stored on a second computer system. The decryption hardware of the second computer system can then decrypt the blocks when needed.

[0008] The present invention discloses a data storage device, comprising:

[0009] a non-volatile storage medium for storing a plurality of file system data objects using block addressing, the plurality of file system data objects being addressable by corresponding ranges of blocks; and

[0010] a device controller integrated with the data storage device and comprising hardware circuitry configured to:

[0011] encrypting data to be stored on the storage medium based on the encryption key;

[0012] The device controller is configured as follows:

[0013] receiving a request for an encrypted file system data object from a host computer system;

[0014] identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; and

[0015] The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

[0016] In some embodiments, the device controller is further configured to control the hardware circuitry to encrypt the data to be stored on the storage medium using a single encryption key for the block range.

[0017] In some embodiments, the device controller is further configured to control the hardware circuitry to encrypt the data to be stored on the storage medium using a single encryption key for a volume or a partition.

[0018] In some embodiments, the device controller is further configured to:

[0019] controlling the hardware circuit system to decrypt data stored on the storage medium, and

[0020] Receives and executes commands from the command set, and

[0021] The command set includes commands for deactivating decryption of the data stored on the storage medium to cause the device controller to send the file system data object stored in the identified block range to the host computer system in an encrypted form as stored on the storage medium.

[0022] In some embodiments, the device controller is further configured to perform the step of receiving the request for the encrypted file system data object from the host computer system after receiving the command to disable decryption of the data stored on the storage medium.

[0023] In some embodiments, the plurality of file system data objects are one or more of the following:

[0024] document;

[0025] File groups; and

[0026] Table of contents.

[0027] In some embodiments, the device controller is further configured to:

[0028] receiving an indication of a block range from a host file system, the host file system maintaining a file structure associated with the block range;

[0029] controlling the hardware circuitry to encrypt data using the encryption key; and

[0030] The data is written to the block range of the storage medium in encrypted form.

[0031] In some embodiments, the data storage device further comprises data storage means for storing an association between the file system data object and the corresponding range of blocks,

[0032] in:

[0033] The association between the file system data object and the corresponding range of blocks is encrypted using an encryption key, and

[0034] The device controller is also configured to:

[0035] receiving a request for the association between the file system data object and the corresponding range of blocks;

[0036] sending the association between the file system data object and the corresponding range of blocks to a host computer system to enable the host computer system to determine the range of blocks based on the stored association;

[0037] receiving an indication of a block range from a host file system, the host file system maintaining a file structure associated with the block range; and

[0038] The file system data object stored in the block range is sent to the host computer system in encrypted form as stored on the storage medium.

[0039] In some embodiments, the device controller is further configured to:

[0040] receiving the encryption key;

[0041] controlling the hardware circuitry to decrypt the association between the file system data object and the corresponding range of blocks using the encryption key; and

[0042] The association between the file system data object and the corresponding range of blocks is sent in decrypted form to the host computer system.

[0043] In some embodiments, the device controller is further configured to:

[0044] controlling the hardware circuitry to encrypt data to be stored on the storage medium based on different encryption keys; and

[0045] Each of the different encryption keys is used for a range of the block range that addresses a corresponding file system data object.

[0046] In some embodiments, the device controller is further configured to control the hardware circuitry to calculate a hash value for the file system data object and send the hash value to the host computer system for verification.

[0047] In some embodiments, the encryption key used to encrypt the data to be stored on the storage medium is a public key associated with a private key stored external to the data storage device.

[0048] In some embodiments, the data storage device also includes volatile memory for storing the encryption key.

[0049] In some embodiments, the device controller is further configured to:

[0050] receiving an indication of the encryption key from the host computer system; and

[0051] The hardware circuitry is controlled to encrypt data using the encryption key until an indication of another encryption key is received.

[0052] In some embodiments, the device controller is further configured to:

[0053] receiving and executing commands from a set of commands, wherein the set of commands includes a command for activating decryption of the data stored on the storage medium;

[0054] receiving an encrypted file system data object that has been encrypted externally to the data storage device;

[0055] storing the encrypted file system data object in encrypted form on the storage medium;

[0056] receiving the encryption key from the host computer system;

[0057] receiving the command for activating decryption of the data stored on the storage medium;

[0058] controlling the hardware circuitry to decrypt the file system data object on the storage medium using the encryption key received from the host computer system; and

[0059] The file system data object is sent to the host computer system in decrypted form.

[0060] A method for storing data in a data storage device is disclosed herein, the method comprising:

[0061] storing a plurality of file system data objects on a storage medium using block addressing, the plurality of file system data objects being addressable by corresponding ranges of blocks;

[0062] using an encryption key by hardware circuitry integrated with the data storage device to encrypt data to be stored on the storage medium;

[0063] receiving a request for an encrypted file system data object from a host computer system;

[0064] identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; and

[0065] The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

[0066] In some embodiments, the method further comprises:

[0067] receiving and executing commands from a command set, the command set including a command for activating decryption of the data stored on the storage medium;

[0068] receiving an encrypted file system data object that has been encrypted externally to the data storage device;

[0069] storing the encrypted file system data object in encrypted form on the storage medium;

[0070] receiving the encryption key from a host computer system;

[0071] receiving the command for activating decryption of the data stored on the storage medium;

[0072] decrypting, by the hardware circuitry integrated with the data storage device, the file system data object on the storage medium using the encryption key received from the host computer system; and

[0073] The file system data object is sent to the host computer system in decrypted form.

[0074] In some embodiments, the method further comprises:

[0075] receiving and executing a command from a command set, the command set including a command for deactivating decryption of the data stored on the storage medium;

[0076] After receiving the command to disable decryption of the data stored on the storage medium, receiving a request for an encrypted file system data object from a host computer system, the request including an indication of a block range; and

[0077] The file system data object stored in the block range is sent in encrypted form as stored on the storage medium.

[0078] Disclosed herein is a non-transitory computer-readable storage medium integrated with a data storage device and with firmware stored thereon, the firmware, when executed by a controller of the data storage device, causing the controller to perform the following steps:

[0079] Using block addressing to store a plurality of file system data objects, the plurality of file system data objects being addressable by corresponding ranges of blocks;

[0080] using an encryption key by hardware circuitry integrated with the data storage device to encrypt data to be stored on the storage medium;

[0081] receiving a request for an encrypted file system data object from a host computer system;

[0082] identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; and

[0083] The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

[0084] The present invention discloses a data storage device, comprising:

[0085] means for storing a plurality of file system data objects using block addressing, the plurality of file system data objects being addressable by corresponding ranges of blocks;

[0086] means for using, by hardware circuitry integrated with the data storage device, an encryption key to encrypt data to be stored on the means for storing;

[0087] means for receiving a request for an encrypted file system data object from a host computer system;

[0088] means for identifying a range of the range of blocks in which the requested encrypted file system data object is stored on the means for storing; and

[0089] Means for sending the file system data object stored in the identified block range to the host computer system in encrypted form as stored on the means for storing. BRIEF DESCRIPTION OF THE DRAWINGS

[0090] Figure 1 A typical scenario according to the prior art and involving a host computer system and a data storage device (DSD) is shown.

[0091] Examples will now be described with reference to the following drawings:

[0092] Figure 2 An example is shown in which the DSD uses different keys for different block ranges according to an embodiment.

[0093] Figure 3 An exemplary data storage medium having block boundaries and block ranges using different keys is shown in accordance with an embodiment.

[0094] Figure 4 An example is shown in which the controller sends data (which is stored on a storage medium) in decrypted form according to an embodiment.

[0095] Figure 5 An example is shown in which a controller sends data (which is stored on a storage medium) in an encrypted form as the data is stored on the storage medium according to an embodiment.

[0096] Figure 6 A receiving DSD receiving an encrypted file system data object is shown. According to an embodiment, the receiving DSD may decrypt the file system data object upon receiving the appropriate key.

[0097] Figure 7 Another example of data flow between a host computer system and a DSD according to an embodiment is shown.

[0098] Figure 8 A method for storing data in a DSD according to an embodiment is shown.

[0099] Fig. 9 A DSD comprising means for storing a plurality of file system data objects using block addressing is shown according to an embodiment. DETAILED DESCRIPTION

[0100] Figure 2 A scenario 200 according to an embodiment is shown. The scenario 200 includes a host computer system 201 and a data storage device (DSD) 202 connected to the host computer system 201 via a data link 203, such as Fibre Channel (FC), Serial ATA (SATA), Serial Attached SCSI (SAS), etc. The DSD 202 can be located within the host computer system 201 or external to the host computer system 201, such as on a separate rack in a server room, in a cloud storage architecture, or as an external drive connected via a Universal Serial Bus (USB) or Firewire.

[0101] The host computer system 201 includes a processor 204 and a volatile memory (RAM) 205. The DSD 202 includes a controller 206, which includes a hardware circuit system 210, such as a microcontroller having an x86, reduced instruction set computing (RISC), advanced RISC machine (ARM) or other architecture. Advantageously, the controller 206 includes a dedicated hardware circuit system 210 to perform cryptographic functions, such as hardware implementations of encryption and decryption algorithms. This provides the following advantages: encryption and decryption can be performed at the full speed of the DSD 202 and all reads and writes from the DSD 202, so that encryption and decryption do not slow down data transfer between the host computer system 201 and the DSD 202. Exemplary encryption and decryption algorithms that can be implemented in hardware include Blowfish and Advanced Encryption Standard (AES) with a key length of 128 bits, 192 bits or 256 bits. In one example, the controller only includes encryption functionality (rather than decryption functionality), which can be used for storage card media used, for example, in a camera capture device. The controller 206 uses the dedicated hardware circuit system 210 when decryption or encryption is to be performed. In this sense, the controller 206 controls the dedicated hardware circuit system 210 to perform encryption or decryption, such as by setting a digital enable signal that connects a processor in the controller 206 to the hardware circuit system 210 to activate the hardware circuit system 210.

[0102] DSD 202 also includes non-volatile physical data storage media 207 and read / write devices 208 to store multiple file system data objects using block addressing. This means that multiple file system data objects can be addressed by corresponding ranges of blocks. This is often referred to as a block device, which means that DSD 202 supports reading and writing data in fixed-size blocks, sectors, or clusters. For example, these blocks can be 512 bytes or 4096 bytes each. Examples include: block devices with rotating media, such as hard drives; and block devices using solid-state media, such as NAND flash cards, NAND flash chips, and solid-state drives (SSDs).

[0103] A block range means a plurality of blocks in a logical sequence that store a file system data object together. Block ranges may be contiguous or may have gaps or separations. In addition, a block range may be defined by a starting logical block address (LBA) and an ending LBA. Alternatively, a block range may be defined by a starting LBA and the number of blocks in the range. It is also possible that the last block in the range includes a pointer to another range when the file system data object is spread over multiple ranges.

[0104] The controller 206 (also referred to as a "device controller") is integrated with the DSD, meaning that the controller 206 is located within a housing that houses all of the components of the DSD 202, including the physical data storage medium 207. Importantly, the integration of the controller 206 with the DSD 202 means that the signals between the controller 206 and the storage medium and read / write devices 208 are not easily accessible from outside the DSD 202 without disassembling the DSD 202. It should be noted that some designs of the DSD 202 do not allow the DSD 202 to be disassembled without damaging it.

[0105] Controller Configuration

[0106] Although Figure 2 The scene in looks similar to Figure 1 But Figure 2 The controller 206 in is now configured to Figure 1 The controller 106 in the embodiment functions in a different manner. The configuration of the controller 206 can be performed by means of firmware installed on the program memory 209, because the methods described herein are implemented as source code, compiled and written to the program memory 209 as machine code. Figure 2 Also shown is a data memory 210 that can be used to store encryption keys, as will be described below. The program memory 209 and the data memory 210 can be volatile memory (e.g., RAM), non-volatile memory (e.g., read-only memory (ROM)), electrically erasable programmable read-only memory (EEPROM), flash memory, etc. In addition, the program memory 209 and the data memory 210 can be integrated into the controller 206, such as by being assembled on the same board as the controller 206, manufactured in the same chip / die, or connected to the controller 206 via a data connection. It is also possible that the controller 206 uses the storage medium 207 as the data memory 210 and / or the program memory 209.

[0107] Controller 206 executes program code (which is stored on program memory 209) and thus encrypts data to be stored on storage medium 207 by controlling encryption hardware circuit system 210. Controller 206 also decrypts data (which is stored on storage medium) based on encryption key by controlling encryption hardware circuit system 210. Controller 206 includes hardware circuit system 210 configured to encrypt and decrypt data, which means that circuit system such as application-specific integrated circuit (ASIC) implementation or gate-level, semi-custom or full-custom implementation of encryption algorithm can be used for controller 206. However, components of circuit system 210 can be disabled as described herein to send and receive encrypted data. Controller 206 uses encryption key to encrypt or decrypt data by providing access to key for hardware circuit system 210 or by indicating to hardware circuit system 210 which encryption key is selected for encryption or decryption.

[0108] Figure 3 An exemplary data storage medium 300 is shown in accordance with an embodiment, wherein block boundaries are shown as vertical dashed lines, such as line 301 defining a block 302 (shown as a square). Likewise, each block may have a predefined size, such as 512 bytes or 4096 bytes. For simplicity, the storage medium 300 is shown as a rectangular shape, but in a rotating medium, horizontal lines would bend to form a circle around the axis of rotation, and vertical lines would be angled to define a "sector," which is therefore used herein as a synonym for a "block."

[0109] Exemplary block range 303 is shown as being outlined by a bold rectangle. In this example, the block ranges are encrypted with different corresponding encryption keys, it should be noted that in other examples, the entire storage medium 300 may be encrypted with a single encryption key. Exemplary block range 303 is encrypted by hardware circuitry in controller 206 using a first encryption key. This is indicated by the hatched pattern of exemplary block range 303. The next range extends across two rows of storage medium 300, and a different key is used, which is indicated by the square hatched pattern. In practice, each range is encrypted using a different key, which is typically indicated by Figure 3 . It should be noted that the blocks in a block range do not need to be contiguous. For example, a block range encrypted with "Key4" is segmented into a first sub-range 304 (a single block) and a second sub-range 305 (four contiguous blocks). The blocks are numbered consecutively, and the file allocation table (FAT) stores a block number indicating the start of each file and the length of the range from that block, which can be linked to the next start block in the case of a sub-range of a segmented file. When reference is made herein to the FAT, this should also be understood to include file system metadata with journal data.

[0110] Command Set

[0111] Program code stored on program memory 209 enables controller 206 to receive, interpret and execute commands received from host computer system 201. For example, controller 206 can be configured to implement a Serial ATA (SATA) and / or ATA Packet Interface (ATAPI) command set, which can be obtained from Technical Committee T13, it should be noted that the same functionality can be implemented within Trusted Computing Group (TCG) Opal, SCSI and other proprietary architectures. Importantly, the command set includes a READ SECTORS command with a command input of a count of sectors and an index of a starting sector (it should be noted that "sector" is used synonymously with "block" in this document). It should be noted that there is a DSD driver installed on host computer system 101, and the DSD driver uses the command set to provide advanced services to the operating system, such as file read functionality. Where new commands are disclosed herein, it should be understood that these commands can be incorporated into a DSD driver installed on host computer system 101 so that the new commands can be used for host computer system 101. For example, the operating system provides an encrypted file read function that returns a file if the file has been encrypted by hardware circuitry 210 integrated with DSD 202 when the file was stored.

[0112] The command set may include a command set from the ATA SECURITY feature set. Specifically, the command set may include the command SECURITY SET PASSWORD. It should be noted that this command in the ATA standard is not related to encryption, but only to access to data on the storage medium 207. In other words, user data can be stored in plain text (unencrypted), but the controller denies access until the correct password is provided through the SECURITY SET PASSWORD command and the device is unlocked with the SECURITY UNLOCK command.

[0113] In the present disclosure, the SECURITY SET PASSWORD command may also be used by the host computer system 201 to send a password to the DSD 202 for each block range. However, the controller 206 may implement other encryption commands, such as SECURITY DECRYPT ON and SECURITY DECRYPT OFF. Although these commands do not define whether the host computer system 201 can access user data on the storage medium 207, these commands define whether the controller 206 decrypts the user data (SECURITY DECRYPT ON) or sends the data in an encrypted form as stored on the storage medium 207 (SECURITY DECRYPT OFF), as further described below. It should be noted that the previously mentioned commands can still be used to lock / unlock the data storage device 202 according to all data access.

[0114] In another example, the controller 206 calculates a hash, such as message digest 5 (MD5), on each file that can be sent back to the host computer system 201. This hash can be calculated to verify that the data written to the storage medium 207 is correctly written (e.g., by writing a value, reading back a value, and calculating a hash value). The host computer system 201 can request a final hash value to see if the final hash value matches the original file hash value. This feature provides hardware accelerated hashing, which will save time for enterprises that perform this function at a higher level (e.g., read the entire file after writing the entire file to calculate the hash). It can also be a feature for the controller 206 to calculate the hash value on the file at a later date to verify the data integrity of the file. The hash can be located on encrypted or unencrypted file data. This can be implemented with SET HASH ON / OFF, READ HASHVALUE, and PERFORM HASH ON BLOCK RANGE nn to mm type commands.

[0115] File Allocation Table

[0116] The block range of each file system data object may be defined in a file allocation table (FAT) stored on the data storage 210 or storage medium 207. In this table, each file system data object is represented by a single linked list of blocks. In other words, the data storage 210 stores an association between a file system data object and a corresponding range of blocks. Furthermore, it should be noted that this association (FAT) may be stored on the storage medium 207 itself, for example, according to the FAT32 format. The FAT may also be referred to as a "block map structure".

[0117] File system data objects include files, file groups, folders, and folder groups. In one example, the controller 206 uses the same encryption key for all files, while in a different example, the controller 206 uses a different encryption key for each file stored on the storage medium 207. In other examples, files are divided into groups, such as a group of files with the same owner, so that all files with the same owner can be encrypted and decrypted with the same encryption key, but files with different owners require different keys.

[0118] It should be noted that the FAT can be stored in encrypted form on the data storage 210 or storage medium 207. In this case, the key used for encryption and decryption of the FAT is called a "volume key". In many cases, the FAT is relatively small compared to other files, so the computational load for decrypting the FAT is relatively low. This means that: in practice, the host computer system 201 and the controller 206 can decrypt the FAT. Therefore, the host computer system 201 can (1) send a SECURITYDECRYPT OFF command, read the encrypted FAT, decrypt the FAT locally with the processor 204 and identify the block range for the specifically requested file, or (2) send a volume key (volume_key) with SECURITY SET PASSWORD, turn on decryption with SECURITY DECRYPT ON and read the unencrypted FAT. It should be noted in this context that the volume key can be the same as or different from the encryption key used to encrypt the file system data object.

[0119] From the perspective of the controller 206, the data storage 210 stores the association between the file system data object and the corresponding range of blocks (FAT). The association between the file system data object and the corresponding range of blocks is encrypted with the volume key. The controller 206 then receives a request for the FAT and sends the FAT to the host computer system 201 so that the host computer system can determine the block range based on the FAT. The request for the FAT can be a standard read command (READ SECTORS), where the starting block is a predefined start of the FAT, such as a logical block address (LBA) 65, and the number of blocks is the size of the FAT.

[0120] As described in more detail herein, the controller 206 then receives the data key (which may be the same as the volume key) and an indication of the block range (as determined by the host computer system 201 based on the FAT) from the host computer system 201. In this sense, the host computer system 201 maintains a file structure associated with the block range. Finally, the controller 206 uses the data key to decrypt the file system data object stored in the block range and sends the decrypted file system data object to the host computer system.

[0121] In one example, the controller 206 sends the FAT in a decrypted form. That is, the controller 206 receives the volume key, decrypts the FAT using the volume key, and sends the FAT in a decrypted form to the host computer system. The host computer system 201 can then use the FAT to determine the block range of the file by using the full path of each file to find the block range. In another example, the controller 206 sends the FAT in an encrypted form, and the host computer system 201 decrypts the FAT using the volume key.

[0122] Send decrypted data

[0123] Figure 4 An example is shown in which the device controller 206 sends data (which is stored on the storage medium 207) in decrypted form according to an embodiment. It should be noted that the controller 206 can provide both functionality of sending encrypted data and decrypted data. These can occur at different times and can be controlled by activation and deactivation of the decryption circuit system by means of commands received from the host computer as described herein. The controller 206 can obtain the necessary encryption key from the data storage 210. The controller 206 may also have received the encryption key from the host computer system 201 with a previous command such as SECURITY SET PASSWORD 401 and saved the key on the data storage 210. Next, the controller 206 receives a request 402 for the decrypted file system data object from the host computer system 201. This request can be a standard SATA command for reading a block range, such as READ SECTORS. In response, the controller 206 identifies a range of block ranges in which the file system data object is stored, for example by extracting the block number from the read request. Next, the controller 206 obtains one of the different encryption keys 403 based on one of the block ranges by using the last received key from step 401 or a key from the stored key list. The controller 206 may then decrypt 404 the file system data object stored on the storage medium using the obtained encryption key and send the decrypted file system data object 405 to the host computer system 201.

[0124] It should be noted that there may be multiple different encryption keys that may each encrypt different file system data objects, such as Figure 3. This means that DSD 202 can support per-file encryption. This per-file encryption will be similar to the file encryption performed by processor 204 of host system 201, but with the advantage of hardware acceleration due to the hardware implementation of the encryption and decryption algorithms integrated with DSD 202. Therefore, host computer system 201 can maintain a key list with one key for each file.

[0125] Sending encrypted data

[0126] Figure 5 Another example is shown in which the controller 206 sends data (which is stored on the storage medium 207) in an encrypted form as the data is stored on the storage medium 207, according to an embodiment. More specifically, the controller 206 receives and executes a command from a command set, which, as described above, includes a command (SECURITY DECRYPT OFF) 501 for deactivating decryption of data stored on the storage medium. This command causes the controller 206 to send 503 a file system data object in an encrypted form as stored on the storage medium 207 to the host computer system 201 in response to a read request 502. In another example, the default is that the controller 206 sends encrypted data without a command. In yet another example, the controller 206 does not have the ability to decrypt any data and can therefore only send encrypted data. Advantageously, an attacker cannot steal any unencrypted data by intercepting communications between the DSD 202 and the host computer system 201. The host computer system 201 can send the encrypted data over an insecure channel such as email or cloud storage, and the receiving system can decrypt the data by storing the data on another storage medium and activating decryption. In Figure 5 In the example shown, the controller 206 may still provide hardware accelerated encryption.

[0127] It should be noted that the entire disk can be sent from one disk to another in encrypted form. This will be useful for disk cloning and transferring the entire content to another computer over a network.

[0128] Receiving encrypted data

[0129] The receiving system can be Figure 2 Therefore, for the following description, it is assumed that DSD202 receives encrypted file system data objects from another DSD (there is a corresponding host computer system between the DSD and the other DSD). Figure 6The DSD 202 is shown as a receiving DSD according to an embodiment and the controller 206 is again configured to receive and execute commands from a command set. However, now the command set includes a command for activating decryption of data stored on a storage medium. The receiving DSD 202 receives 601 an encrypted file system data object, which has been encrypted external to the receiving DSD, for example, by a sending DSD. It is important to note that the file system data object is not encrypted by the host computer system or another third party computer system. Instead, the file system data object has been encrypted by another DSD, namely by a hardware circuit system 210 integrated with the sending DSD. This ensures that the data is always encrypted and is not transmitted in an unencrypted form.

[0130] Controller 206 stores 602 the encrypted file system data object in encrypted form on storage medium 207. At this stage, the data is the same as if controller 206 had first encrypted the data (assuming the same key was used). Controller 206 receives 603 the key from the host computer system. For example, the party that sent the encrypted data may have also provided the corresponding key to host computer system 201 via a separate channel, which forwarded the key to DSD 201.

[0131] The controller 206 also receives a command to activate decryption of data stored on the storage medium 604. This causes the controller 206 to decrypt the file system data object on the storage medium by the hardware circuitry 210 of the device controller integrated with the DSD in response to the data request 605. To perform this decryption, the controller 206 uses the encryption key received from the host computer system in step 603. Finally, the controller 206 sends 606 the file system data object to the host computer system in decrypted form.

[0132] Read requests with or without block ranges

[0133] There are different options for mapping file system data objects to block ranges. In most cases, DSD 202 stores an association between a file system data object, such as a file, and a block range. Examples include a file allocation table and a block map structure. This association can be used by the host computer system 201 or the controller 206. In one example, the host computer system 201 performs the mapping, which means that a read request from the host computer system 201 already includes an indication of the block range according to the standard ATA command set. The controller 206 typically receives the read request after receiving a command to deactivate decryption of data stored on the data storage medium. In response, the controller 206 does not decrypt the data, but sends one of the multiple file system data objects stored in the block range in an encrypted form as stored on the storage medium.

[0134] In another example, the controller 206 performs mapping, which means that the controller 206 receives a request for an encrypted file system data object from the host computer system. This request identifies the file system data object, for example, by providing the full path of the file rather than a block range. Therefore, the controller 206 identifies a range of block ranges in which the requested encrypted file system data object is stored on the storage medium. For example, the controller 206 does this by querying the stored associations in the FAT to find the first block and the number of blocks. The controller 206 then sends the file system data object (which is stored in the identified block range) to the host computer system in an encrypted form as stored on the storage medium.

[0135] Key Generation

[0136] In one example, the controller 206 generates an asymmetric key pair including a public key and a private key. The controller 206 may include circuitry or software for generating a new key, which may be symmetric or asymmetric. The controller 206 then sends the public key to the host computer system 201 via the data link 203, where the public key is stored on the volatile memory 205. This public key is referred to as being associated with a corresponding private key stored on the DSD 202. The public key is generated by the controller 206 by executing the elliptic curve cryptography (ECC) primitive ECC-Pub ({private key}). (Recall that, although elliptic curve cryptography is used as an example in this article for reasons of computational efficiency and security, it should be noted that other encryption techniques may be used as well.) The corresponding private key is stored on the data memory 210 of the DSD 202, and the public key is sent to the host computer system 201 and stored in the memory 205. The host computer system 201 is configured to use the public key, also referred to as an identifier, or to generate and store another public key to generate a challenge to the DSD 202. It should be noted here that the challenge is unique in that each challenge is different, making subsequent challenges different from any previous challenges. This is achieved by multiplying the stored data by a random blinding factor, as described below. Next, the host computer system 201 sends the challenge to the DSD 202 via a communication channel that may be different from the data link 203. For example, the data link 203 may include a wired USB connection, while the key communication channel between the host computer system 201 and the DSD 202 is a wireless (e.g., Bluetooth) connection.

[0137] Controller 206 can calculate a response to a challenge that cannot be calculated by any other device. More specifically, a device that cannot access the data corresponding to the identifier stored on memory 205 cannot calculate the correct response. For example, controller 206 uses a stored private key (which is associated with a corresponding public key stored on memory 205) to calculate a response to the challenge. The correct response can then be used to calculate an encryption key to encrypt and decrypt data stored on storage medium 207. In one example, in the case where controller 206 does not decrypt the encrypted data, controller 206 can only store the public key and use the public key for encryption. Upon request, controller 206 then sends the encrypted data to a device with the private key required for decryption. For example, there may be two DSDs, where the first DSD generates a private / public key pair and only sends the public key to the second DSD (e.g., a camera memory card). The second DSD controls the integrated hardware circuit system to encrypt the data using the public key, and sends the encrypted data to the first DSD (possibly via a host computer system, including a memory card reader) upon request. The first DSD can then use the private key to decrypt the data.

[0138] In yet another example, the host computer system 201 generates a private / public key pair and stores the private key securely on a non-volatile memory. The controller 206 then registers the host computer system 201 by storing a public key associated with the private key stored on the host computer system 201. The controller 206 can then send a challenge to the host computer system 201, and only the host computer system 201 can calculate the correct response based on the stored private key. The controller 206 receives a response to the challenge from the host computer system 201 through a communication channel. It should be noted here that if the controller 206 only verifies the response to the challenge and reads the encryption key from the memory 210 upon success, the encryption key will be stored in plain text, which is not ideal because it will enable an attacker to disassemble the DSD 202 and read the key from the memory 210 to access the user content data stored on the storage medium 207.

[0139] Calculate the key

[0140] Therefore, instead, the controller 206 calculates the encryption key based at least in part on the response from the host computer system 201. This means that the encryption key is not a pure function of the response, but also involves other values. The encryption key is stored in encrypted form on the memory 210, and the response based on the private key stored on the host computer system 201 enables the calculation of the secret to decrypt the encryption key.

[0141] In one example, the challenge generated by the controller 206 and sent to the host computer system 201 is based on elliptic curve encryption. This has the advantage of shorter keys, resulting in more efficient communication and storage. In addition, the host computer system can provide dedicated functionality of elliptic curve encryption within the secure hardware module. The secure hardware module securely stores private keys and executes encryption primitives within the secure hardware module, and the key does not leave the secure hardware module and is not sent to a general processor core, such as processor 204, where the key may be attacked and unauthorized retrieval is performed. In one embodiment, the secure hardware module includes a separate processor that executes its own microkernel, which cannot be directly accessed by an operating system or any program running on a general processor core. The secure hardware module may also include a non-volatile storage device for storing a 256-bit elliptic curve private key. In one embodiment, the secure hardware module is a Secure Enclave coprocessor available on some Apple devices. The secure hardware module can be located in the host computer system 201 or in the DSD202 to generate and store private keys respectively. The above process can then be repeated for each encryption key in different encryption keys of different block ranges. The host computer system 201 and the DSD 202 may also perform a Diffie-Hellman (DH) key exchange which may be based on elliptic curve cryptography (ECC-DH).

[0142] Additional information regarding key generation can be found in U.S. patent application Ser. No. 16 / 706,780, filed on Dec. 8, 2019, entitled “Unlocking a data storage device,” which is incorporated herein by reference in its entirety.

[0143] It is also possible to temporarily store one or more keys in a volatile memory included in the DSD 202. This "key cache" will minimize the sending of keys over the data link 203 to achieve speed efficiency and improve security. The host computer system 201 can refer to each key as a table entry, i.e., SET PASSWORD 1, SET PASSWORD 2, SECURITY DECRYPT ON 1, SECURITY DECRYPT ON 2, etc. If the DSD 202 loses power or the DSD 202 is disconnected and the physical tamper detection circuit is triggered, the keys may become inaccessible to protect the security of the DSD 202. If the DSD 202 is in a state where the keys are inaccessible, it can automatically revert to sending encrypted data without receiving any keys. In this sense, any host computer system can power the DSD 202 and read the encrypted data. But only a host computer system that has the key (or can access the DSD with the key) can decrypt the data.

[0144] Key selection

[0145] There are different options for how to select the appropriate key for encryption and decryption. In a first example, the host computer system 201 maintains the FAT, and the controller 206 receives an indication of a block range, such as a starting block address and a number of blocks. The controller 206 then selects one of the different encryption keys based on the indicated block range. To this end, the controller 206 can maintain a table that stores a corresponding key for each starting block address. That is, the table has a row for each file system data object, and each row includes a starting block address and a key. The controller 206 then queries the received starting block address in the table, and uses the encryption key selected from the table to encrypt the data.

[0146] In other examples, the controller 206 performs mapping between the file system data object and the block range as described above. That is, the controller 206 receives a request for the file system data object and determines the block range based on the stored FAT. The controller 206 then selects an encryption key from a plurality of encryption keys based on the determined block range. In addition, this may involve using a key table that can store the start block address or the complete path of the file system data object or both in a row with a corresponding key. Therefore, the controller 206 can also select a key by looking up the complete path in the key table instead of the start block address. The controller 206 then uses the selected encryption key to decrypt the file system data object stored in the determined block range and sends the decrypted file system data object.

[0147] As described above, the controller 206 may also be configured to receive different keys from the host computer system 201. The controller 206 then stores the key in the DSD 202, which may include volatile memory to store one or more of the different encryption keys so that the key is not retained in the DSD 202 when the DSD 202 is powered off. The controller 206 may receive the different encryption keys from the host computer system 201 with a command such as SECURITY SET PASSWORD. The controller 206 then uses the key to encrypt and decrypt data until an indication of a different key is received through the same command. In addition, there may be only a single key, and the controller 206 uses the single key to encrypt all files.

[0148] In other examples, the key is sent via a communication channel, such as a wireless (e.g., Bluetooth) channel, different from the communication channel used to send the encrypted data. In addition, the key can be sent at a different time relative to the encrypted data, such as a time offset, to disassociate the key from the encrypted data.

[0149] Data flow example

[0150] Figure 7Another example of a display complete data flow according to an embodiment is shown. First, the host computer system 201 sets 701 a per-file encryption key by issuing a SECURITY SET PASSWORD (file_key) command. This activates the hardware encryption module with the file key. Next, the host computer system 201 issues 702 a WRITE SECTORS command for sending the file data to the DSD 202 in an unencrypted form. Since the host computer system 201 maintains the FAT at this stage, the host computer system 201 can also perform the allocation of file data to blocks and specify those blocks or at least the starting block address in the write command. The controller 206 then encrypts 703 the received data with the file key and stores 704 the encrypted data on the storage medium 207. The data is now stored, and the DSD 202 can be used for unrelated tasks or power off. At a later stage, when the data needs to be read, the host computer system 201 disables decryption 705 by issuing a SECURITY DECRYPT OFF command. Alternatively, decryption can be disabled by default, so there is no need to send a command. The host computer system 201 then reads 706 the FAT table by issuing a READ SECTORS command for the predefined sectors where the FAT is stored. In response, the controller 206 returns 707 the encrypted FAT to the host computer system 201. The host computer system 201 then decrypts 708 the FAT using the volume key (which is different from the file key). Alternatively, the host computer system 201 can activate decryption and read the FAT in decrypted form.

[0151] Based on the decrypted FAT, the host computer system 201 can now find the required blocks 709 for a particular file and read those blocks 710 by issuing a READ SECTORS command for those blocks. The controller 206 responds by sending 711 the encrypted file data back to the host computer system 201. This encrypted file data can now be stored elsewhere or sent over an unsecured communication channel. Since the file key is available (with limited access of course), the encrypted file data can be decrypted by an authorized entity with the key.

[0152] method

[0153] Figure 8A method 800 for storing data in DSD 202 according to an embodiment is shown. Method 800 can be performed by controller 206 because method 800 is implemented in program code stored in program memory 209, noting that the program code controls hardware circuit system 210 to execute individual commands. That is, program memory 209 is a non-transitory computer-readable storage medium integrated with the DSD and with firmware stored thereon, which, when executed by the controller of the DSD, causes the controller to perform the steps of method 800.

[0154] Specifically, the method includes storing 801 a plurality of file system data objects using block addressing. The plurality of file system data objects may be stored as follows: Figure 3 804. The controller 206 uses 802 an encryption key to encrypt data to be stored on the storage medium by controlling a hardware circuit system 210 integrated with the DSD. One of the different encryption keys is used for a corresponding range in the block range that addresses one of the plurality of file system data objects. In addition, the controller 206 receives 803 a request for an encrypted file system data object from the host computer system, and identifies 804 a range in the block range in which the requested encrypted file system data object is stored on the storage medium. Next, the controller 206 sends 805 the file system data object stored in the identified block range to the host computer system in an encrypted form as stored on the storage medium.

[0155] Data storage devices

[0156] Fig. 9 900 according to an embodiment is shown, the DSD comprising means 901 for storing a plurality of file system data objects using block addressing. The plurality of file system data objects may be stored as follows: Figure 3900 is a memory device for storing a file system 901. The device for storing 901 may include a rotating storage medium (e.g., a magnetic hard disk), a solid-state storage medium (e.g., located in a solid-state drive (SSD)), or other suitable storage medium. The DSD 900 also includes a device 902 for encrypting data to be stored on the device for storing 901 using an encryption key by a hardware circuit system 210 integrated with the DSD 900. Different encryption keys may be used for corresponding ranges of blocks addressing a file system data object in a plurality of file system data objects. The DSD 900 also includes a device 903 for receiving a request for an encrypted file system data object from a host computer system, a device 904 for identifying a range of blocks in which the requested encrypted file system data object is stored on the storage medium, and a device 905 for sending the file system data object stored in the identified block range to the host computer system in an encrypted form as stored on the storage medium. Devices 902, 903, 904, and 905 may be data storage device controllers including a microprocessor integrated with or connected to a hardware circuit that implements encryption and decryption algorithms in hardware. Devices 902, 903, 904, and 905 may be integrated and implemented in a single electronic device such as a processor. In addition, device 902 may be implemented as a separate hardware circuit system, while devices 903, 904, and 905 may be implemented together on a processor. Other implementations such as ASICs, field programmable gate arrays (FPGAs), or other architectures may also be used for devices 902, 903, 904, and 905.

[0157] It will be appreciated by those skilled in the art that many variations and / or modifications may be made to the above-described embodiments without departing from the broad general scope of the present disclosure. The embodiments of the present invention are therefore to be considered in all aspects as illustrative and not restrictive.

Claims

1. A data storage device, include: a non-volatile storage medium configured to store a plurality of file system data objects using block addressing, the plurality of file system data objects being addressable by corresponding block ranges; and a device controller integrated with the data storage device and comprising hardware circuitry configured to: encrypting data to be stored on the storage medium based on at least one encryption key; The device controller is configured as follows: storing, in encrypted form, associations between the plurality of file system data objects and the corresponding block ranges; receiving, from a host computer system, a request for said association between said plurality of file system data objects and said corresponding block ranges; controlling the hardware circuitry to decrypt the associations between the plurality of file system data objects and the corresponding block ranges using an encryption key; sending, in decrypted form, the associations between the plurality of file system data objects and the corresponding block ranges to the host computer system; receiving a request for an encrypted file system data object from the host computer system; identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; as well as The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

2. The data storage device of claim 1, wherein the device controller is further configured to control the hardware circuitry to encrypt the data to be stored on the storage medium using a single encryption key for the block range.

3. The data storage device of claim 1, wherein the device controller is further configured to control the hardware circuit system to encrypt the data to be stored on the storage medium using a single encryption key for one volume or one partition.

4. The data storage device according to claim 1, wherein The device controller is further configured to: controlling the hardware circuitry to decrypt data stored on the storage medium, and Receives and executes commands from the command set, and The command set includes commands for deactivating decryption of the data stored on the storage medium to cause the device controller to send the file system data objects stored in the identified block range to the host computer system in an encrypted form as stored on the storage medium.

5. The data storage device of claim 4 , wherein the device controller is further configured to execute the step of receiving the request for the encrypted file system data object from the host computer system after receiving the command to disable decryption of the data stored on the storage medium.

6. The data storage device of claim 1 , wherein the plurality of file system data objects are one or more of: document; File groups; and Table of contents.

7. The data storage device of claim 1 , wherein the device controller is further configured to: receiving an indication of a target block range from a host file system, the host file system maintaining a file structure associated with the respective block ranges of the plurality of file system data objects; controlling the hardware circuitry to encrypt data using a single encryption key; as well as The data is written in encrypted form to the target block range of the storage medium.

8. The data storage device according to claim 1, further comprising data storage means for storing said associations between said plurality of file system data objects and said corresponding block ranges, in: The device controller is further configured to: encrypting the associations between the plurality of file system data objects and the corresponding block ranges using the encryption key before storing the associations between the plurality of file system data objects and the corresponding block ranges on the data storage device; as well as receiving, in response to sending said associations between said plurality of file system data objects and said corresponding block ranges, an indication of a target block range from a host file system, The host file system maintains a file structure associated with the respective block ranges of the plurality of file system data objects.

9. The data storage device of claim 8, wherein the device controller is further configured to receive the encryption key from the host computer system; and The encryption key is different from a second encryption key used to encrypt the requested encrypted file system data object.

10. The data storage device of claim 1, wherein the device controller is further configured to: controlling the hardware circuitry to encrypt data to be stored on the storage medium based on different encryption keys; and Each of the different encryption keys is used for a range of the respective range of blocks that addresses a respective file system data object.

11. The data storage device of claim 1, wherein the device controller is further configured to control the hardware circuitry to calculate hash values ​​for the plurality of file system data objects and send the hash values ​​to the host computer system for verification.

12. The data storage device of claim 1, wherein the at least one encryption key used to encrypt the data to be stored on the storage medium is a public key associated with a private key stored external to the data storage device.

13. The data storage device of claim 12, further comprising a volatile memory for storing the at least one encryption key.

14. The data storage device of claim 1, wherein the device controller is further configured to: receiving an indication of the at least one encryption key from the host computer system; and The hardware circuitry is controlled to encrypt data using the at least one encryption key until an indication of another encryption key is received.

15. The data storage device of claim 1, wherein the device controller is further configured to: receiving and executing commands from a command set, wherein the command set includes a command for activating decryption of the data stored on the storage medium; receiving an encrypted file system data object that has been encrypted externally to the data storage device; storing the encrypted file system data object in encrypted form on the storage medium; receiving at least one of said encryption keys from said host computer system; receiving the command for activating decryption of the data stored on the storage medium; controlling the hardware circuitry to decrypt the file system data object on the storage medium using the at least one encryption key received from the host computer system; as well as The file system data object is sent to the host computer system in decrypted form.

16. A method for storing data in a data storage device, the method include: storing a plurality of file system data objects on a storage medium using block addressing, the plurality of file system data objects being addressable by corresponding block ranges; using at least one encryption key by hardware circuitry integrated with the data storage device to encrypt data to be stored on the storage medium; storing, in encrypted form, associations between the plurality of file system data objects and the corresponding block ranges; receiving, from a host computer system, a request for said association between said plurality of file system data objects and said corresponding block ranges; decrypting, by the hardware circuitry integrated with the data storage device, the associations between the plurality of file system data objects and the corresponding block ranges using an encryption key; sending, in decrypted form, the associations between the plurality of file system data objects and the corresponding block ranges to the host computer system; receiving a request for an encrypted file system data object from the host computer system; identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; as well as The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

17. The method according to claim 16, further comprising: include: receiving and executing commands from a command set, the command set including a command for activating decryption of the data stored on the storage medium; receiving an encrypted file system data object that has been encrypted externally to the data storage device; storing the encrypted file system data object in encrypted form on the storage medium; receiving the at least one encryption key from a host computer system; receiving the command for activating decryption of the data stored on the storage medium; decrypting, by the hardware circuitry integrated with the data storage device, the file system data object on the storage medium using the at least one encryption key received from the host computer system; as well as The file system data object is sent to the host computer system in decrypted form.

18. The method according to claim 17, further comprising: include: receiving and executing a command from a command set, the command set including a command for deactivating decryption of the data stored on the storage medium; receiving, after receiving the command to disable decryption of the data stored on the storage medium, a request for an encrypted file system data object from a host computer system, the request including an indication of a block range; as well as The file system data object stored in the block range is sent in encrypted form as stored on the storage medium.

19. The method according to claim 16, further comprising: include: encrypting data to be stored on the storage medium based on different encryption keys; as well as Each of the different encryption keys is used for a range of the respective range of blocks that addresses a respective file system data object.

20. A non-transitory computer-readable storage medium integrated with a data storage device and with firmware stored thereon, the firmware, when executed by a controller of the data storage device, causing the controller to perform the following steps: storing a plurality of file system data objects using block addressing, the plurality of file system data objects being addressable by corresponding block ranges; using at least one encryption key by hardware circuitry integrated with the data storage device to encrypt data to be stored on the storage medium; storing, in encrypted form, associations between the plurality of file system data objects and the corresponding block ranges; receiving, from a host computer system, a request for said association between said plurality of file system data objects and said corresponding block ranges; decrypting, by the hardware circuitry integrated with the data storage device, the associations between the plurality of file system data objects and the corresponding block ranges using an encryption key; sending, in decrypted form, the associations between the plurality of file system data objects and the corresponding block ranges to the host computer system; receiving a request for an encrypted file system data object from the host computer system; identifying a range of the block ranges in which the requested encrypted file system data object is stored on the storage medium; as well as The file system data object stored in the identified block range is sent to the host computer system in encrypted form as stored on the storage medium.

21. A data storage device, include: means for storing a plurality of file system data objects using block addressing, the plurality of file system data objects being addressable by respective block ranges; means for encrypting data to be stored on said means for storing using at least one encryption key by hardware circuitry integrated with said data storage device; means for storing in encrypted form associations between the plurality of file system data objects and the corresponding block ranges; means for receiving, from a host computer system, a request for said association between said plurality of file system data objects and said corresponding block ranges; means for decrypting, by said hardware circuitry integrated with said data storage device, said associations between said plurality of file system data objects and said corresponding block ranges using an encryption key; means for sending, in decrypted form, said associations between said plurality of file system data objects and said corresponding block ranges to said host computer system; means for receiving a request for an encrypted file system data object from said host computer system; means for identifying a range of said block ranges in which the requested encrypted file system data object is stored on said means for storing; and Means for sending the file system data object stored in the identified block range to the host computer system in encrypted form as stored on the means for storing.

Citation Information

Patent Citations

  • Unlocking a data storage device

    US20210173953A1

  • Storage system for data encryption

    US20100042832A1

  • Secure storage device

    US20130311737A1

  • Encryption key selection

    US20150242640A1

Cited By

  • Encrypted data storage system with real-time monitoring function

    CN120995482A