Control method of memory device
By introducing PIN management and data deletion with hierarchical permissions, the problem of data leakage when the storage device is discarded is solved, secure recovery and flexible data processing are achieved, reducing costs and improving security.
Patent Information
- Application Number
- CN202210629690.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-09-21
- Filing Date
- 2018-03-07
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2038-03-07
Smart Images

Figure CN114895853B_ABST
Abstract
Description
[0001] Information about divisional applications
[0002] This application is a divisional application. The parent application is an invention patent application filed on March 7, 2018, with application number 201810188444.0 and the title of invention being “Memory Device.”
[0003] [Related Applications]
[0004] This application claims the benefit of priority from Japanese Patent Application No. 2017-181632 (filing date: September 21, 2017), the entire contents of which are incorporated herein by reference. Technical Field
[0005] Embodiments of the present invention relate to a memory device. Background Art
[0006] Conventionally, various security functions have been required for large-capacity memory devices. One example of the security function is processing data as needed. Summary of the Invention
[0007] Embodiments provide a memory device that can process data according to a purpose.
[0008] A memory device according to an embodiment stores unencrypted user data and has at least one data deletion method. The memory device includes: a mechanism for receiving a deletion method inquiry from a host device; and a mechanism for transmitting response information indicating the at least one data deletion method to the host device upon receiving the inquiry. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 (a) and (b) show examples of connection between the memory device and the host device according to the first embodiment.
[0010] Figure 2 An example of the configuration of the memory device according to the first embodiment is shown.
[0011] picture An example of the PIN defined in the first embodiment is shown.
[0012] Figure 4 This shows an example of the state transition of a memory device.
[0013] Figure 5A An example of the data deletion procedure in the first embodiment is shown.
[0014] Figure 5B An example of the data deletion procedure in the first embodiment is shown.
[0015] Figure 6 (a) and (b) indicate Figure 5A 、 Figure 5B The deletion method of the order shown is an example of a display request.
[0016] picture express Figure 5A 、 Figure 5B An example of how to delete the order shown is returned.
[0017] Figure 8 This shows an example of setting access rights for each area.
[0018] Figure 9 (a) and (b) are flowcharts showing an example of data deletion including data management in preparation for power outage.
[0019] Figure 10 This is a flowchart showing an example of data deletion in which access is denied during data deletion.
[0020] Figure 11 This is a flowchart showing an example of data deletion in which access to an area being deleted is denied.
[0021] Figure 12 This is a flowchart showing an example of data deletion in which a simultaneous deletion instruction for a plurality of areas is rejected.
[0022] Figure 13 This is an example of the relationship between Namespace and Range.
[0023] picture This is a flowchart showing an example of data deletion in Namespace units.
[0024] Figure 15 This is an example of a state transition that includes a destruction state.
[0025] Figure 16 (a) and (b) are flowcharts showing an example of the destruction operation.
[0026] Figure 17 An example of the configuration of a memory device according to the second embodiment having a destruction function is shown.
[0027] Figure 18 An example of the configuration of a memory device according to the third embodiment having a data encryption function is shown.
[0028] Figure 19 An example of the configuration of a memory device according to a fourth embodiment having a destruction function and a data encryption function is shown.
[0029] Figure 20An example of the configuration of a memory device according to the fifth embodiment is shown.
[0030] Figure 21 An example of the Set command and Get command permissions of the administrator PIN in the fifth embodiment is shown.
[0031] Figure 22 An example of the configuration of a memory device according to the sixth embodiment is shown.
[0032] Figure 23 This section shows an example of the issuance authority of the Set command and the Get command in the sixth embodiment. DETAILED DESCRIPTION
[0033] The following describes the embodiments with reference to the accompanying drawings. The following description exemplifies devices or methods used to embody the technical concepts of the embodiments. The technical concepts of the embodiments are not limited to the structures and arrangements of the components described below. Variations that are readily conceivable to those skilled in the art are naturally within the scope of this disclosure. For clarity, components with substantially the same function and structure are denoted by the same reference numerals in multiple drawings, and repeated descriptions may be omitted.
[0034] [First embodiment]
[0035] Figure 1 The following is an example of the connection between the memory device and the host device according to the first embodiment. The memory device 12 is connected to the host device 14, and writes data sent from the host device 14 to its own storage medium, or sends data read from the storage medium to the host device 14. The interface between the memory device 12 and the host device 14 includes SCSI (Small Computer System Interface), ATA (Advanced Technology Attachment), NVM Express (registered trademark), e·MMC (Embedded Multi Media Card), etc. The memory device 12 can be as follows: Figure 1 (a) is connected to the host device 14 in a one-to-one manner, or as shown in FIG. Figure 1 As shown in (b), the host device 14 is connected to the host device 14 in a many-to-one manner via the network 16. Figure 1 (a) refers to electronic devices such as personal computers (hereinafter referred to as PCs). Figure 1 (b) is a server, etc. Figure 1The memory device 12 shown in (a) can also be incorporated into the housing of a PC by a PC supplier. The number of users who use one memory device 12 is not limited to one person. There are also cases where one memory device 12 is used by multiple users. For example, in Figure 1 When the host device 14 provides virtual machine services to multiple users as shown in (b), one storage device 12 may be divided into multiple areas (eg, Namespace, Range, Partition), and each area becomes a virtual machine for each user.
[0036] [Outline composition]
[0037] Figure 2 FIG2 shows an example of the configuration of the memory device 12. The memory device 12 includes an I / F processing unit 22, which is connected to the host device 14 via a host interface (I / F). The I / F processing unit 22 is connected to the authentication processing unit 102, the permission processing unit 104, the deletion mode display unit 106, and the deletion mode display request receiving unit 108.
[0038] The authentication processing unit 102 uses a PIN (Personal Identification Number) to perform user authentication to control access to the memory device 12. A PIN management unit 112 is connected to the authentication processing unit 102. The PIN management unit 112 manages multiple PINs, such as an owner PIN (Security Identifier: also known as SID) 112a, an administrator PIN (also known as AdminPIN) 112b, a identification PIN (also known as PSID) 112c, and a user PIN 112d. Administrator PINs and user PINs are set to hierarchically determine user authority.
[0039] Sometimes, for some reason, the user wants to restore the memory device 12 to its factory state. For example, when the memory device 12 is discarded, the user wants to prevent the user data stored in the data storage unit 34 from leaking from the memory device 12. In this specification, restoring the memory device 12 to its factory state is called resetting. Resetting includes both deleting (reading out) user data and initializing the PIN set after leaving the factory. Here, resetting requires a specific PIN, such as an owner PIN or an identification PIN. In addition, the memory device 12 has a locking function, and a specific PIN is required to lock (change from unlocked state to locked state) or unlock (change from locked state to unlocked state).
[0040] The permission processing unit 104 is connected to the authentication processing unit 102, the lock management unit 110, the area information management unit 114, the data deletion unit 118, and the read / write processing unit 122. When a reset instruction is issued by the host device 14, the authentication processing unit 102 authenticates the user who issued the instruction. Specifically, it checks whether the input PIN value matches the PIN value stored in the PIN management unit 112. For example, when an authentication request is received from the host device 14 as the owner, the authentication processing unit 102 checks whether the PIN value included in the authentication request matches the owner PIN 112a stored in the PIN management unit 114. If they match, the authentication is determined to be successful; if they do not match, the authentication is determined to be unsuccessful. The permission processing unit 104 determines whether the source of the instruction (the user of the host device 14) has the authority to issue the instruction and, based on the result, transmits the instruction to the lock management unit 110, the read / write processing unit 122, the data deletion unit 118, etc. That is, the permission processing unit 104 manages a table for determining which instruction can be executed with which execution authority, and when receiving an instruction, performs a determination process on whether the instruction is a process that can be executed with the authority. For example, the permission processing unit 104 manages that the Revert instruction for resetting the memory device 12 can be executed as long as the owner PIN and the identification PIN are authenticated. At this time, the user who has successfully authenticated with the owner PIN sends the Revert instruction for resetting the memory device 12 from the host device 14. The permission processing unit 104 performs a determination process on whether the source of the Revert instruction has the authority to issue the Revert instruction. In this example, the execution of the Revert instruction is allowed by the owner PIN, so it is determined to have the authority. If the user who has successfully authenticated with the user PIN wants to execute the Revert instruction, it is determined to have no authority. If it is determined that the user has the authority, the Revert instruction is transmitted to the execution data deletion unit 118 to execute data deletion in order to reset the memory device 12, and the PIN is reset to the initial value.
[0041] Furthermore, when an issuer authenticated with a user PIN or an administrator PIN issues an unlock command, the permission processing unit 104 transmits the unlock command to the lock management unit 110, which then unlocks the memory device 12. The lock management unit 110 can lock / unlock the entire user area of the data storage unit 34 managed by the area information management unit 114, or can lock / unlock a specific area of the data storage unit 34. Furthermore, even if an issuer authenticated with a successful identification PIN issues an unlock command, the permission processing unit 104 does not transmit the unlock command to the lock management unit 110, and thus the memory device 12 is not unlocked.
[0042] The deletion method display unit 106 is connected to a deletion method display request receiving unit 108 and a deletion information management unit 124. The deletion method display request receiving unit 108 receives a data deletion method inquiry from the host device 14 and transmits it to the deletion method display unit 106. The deletion method display unit 106 presents the host device 14 with the data deletion methods supported by the memory device 12.
[0043] Examples of data deletion methods include overwrite deletion, block deletion, unmapping, write pointer reset, and encryption erasure (key update). Overwrite deletion means completely overwriting the area storing the data to be deleted with data generated by "0" or random numbers. Block deletion means making the original data in the entire block containing the data to be deleted unreadable. Unmapping means resetting the mapping table indicating which block of the storage medium the data is stored in for the data. Write pointer reset means resetting the indicator indicating which block of the storage medium the data is stored in. Encryption erasure means encrypting the input data using the key possessed by the memory device 12. If encrypted data is stored in the data storage unit 34, the key used for data encryption is updated. As a result, the encrypted data cannot be decrypted, and the input data cannot be read.
[0044] The deletion information management unit 124 is connected to the data deletion unit 118. The deletion information management unit 124 does not accept read / write commands during data deletion, manages the status of the data deletion process to prevent power outage during data deletion, and notifies the host device 14 of information indicating the data deletion status after power is restored after a power outage.
[0045] The data deletion unit 118 and the read / write processing unit 122 are connected to the data storage unit 34. The data storage unit 34 includes a large-capacity nonvolatile storage medium, such as a flash memory or a hard disk. The data storage unit 34 receives read and write commands from the host device 14 and writes and reads data.
[0046] Each unit of the memory device 12 is controlled by the CPU 24 .
[0047] [PIN]
[0048] Reference Figure 3 Describe the PIN. Figure 3 (a) shows the commands that can be issued according to the type of PIN. The owner PIN has the authority to issue the Activate / Revert command. The permission processing unit 104 manages which PIN can issue which command.
[0049] The Activate command is used to activate the lock function. The Revert command is used to set the PIN to the initial value, disable the lock function, and forcibly delete the data. The administrator PIN (also known as the AdminPIN) has the authority to issue the RevertSP command. The RevertSP command is used to set the PIN to the initial value, disable the lock function, and can specify whether to delete the data forcibly as a parameter. The identification PIN (also known as the PSID) has the authority to issue the Revert command. The user PIN does not have the authority to issue commands, but can unlock the area assigned to the user.
[0050] Figure 3 (b) Regarding resetting the memory device 12, this command indicates the action initiated by the command, namely, the type of PIN initialized and the type of data deleted. The Activate command does not reset, but rather its opposite, Activate (activate), without initializing the PIN or deleting data. The Revert command deletes data and initializes the owner PIN and administrator PIN. The RevertSP command deletes data and initializes the administrator PIN. The RevertSP command can specify, via a parameter when issuing the command, whether to delete data or not, retaining the data. The Revert command does not have a parameter to specify whether to delete data; data is always deleted.
[0051] In addition to these commands, there's also the Set command, used to set a PIN. The Set command contains a parameter indicating the type of PIN to set. The issuer's authority varies depending on the parameter value, specifically the type of PIN to set. For example, only administrators and users can issue the Set command to set a user's PIN; the owner does not have authority to set a user's PIN. Therefore, authentication of the Set command with the identification PIN will fail. Furthermore, the Activate, Revert, and RevertSP commands are not determined by parameters but by issuing authority.
[0052] The first embodiment can set two types of identification PIN (PSID). Figure 3As shown in (c), the first type of identification PIN (PSID1) is a PIN used to reset the above-mentioned memory device 12, which deletes data in the entire storage area and initializes the owner PIN and the administrator PIN. The second type of identification PIN is the identification PIN (PSID2, PSID3, ...) of each user. The storage area is allocated to multiple users (here, user 1 and user 2). The Revert command issued by the identification PIN (PSID2) of user 1 deletes data in the area allocated to user 1 and initializes the user PIN of user 1. The Revert command issued by the identification PIN (PSID3) of user 2 deletes data in the area allocated to user 2 and initializes the user PIN of user 2. In other words, the Revert command issued by the identification PIN (PSID2) of user 1 deletes data in the area allocated to user 2 and initializes the user PIN of user 2. The Revert command issued by the identification PIN (PSID3) of user 2 deletes data in the area allocated to user 1 and initializes the user PIN of user 1.
[0053] Thereby, the security of each user can be improved.
[0054] The administrator PIN can reset the memory device 12 to its factory default state. However, to prevent the administrator PIN from being lost, a reset PIN identification PIN may be printed somewhere on the memory device 12, such as on a nameplate attached to the memory device housing. For example, if a storage area is allocated to multiple users 1 and 2, PSID1, PSID2, and PSID3 may be printed on a nameplate.
[0055] Alternatively, the identification PIN may be not printed on the memory device 12 but instead notified to the PC vendor or user. For example, the PC vendor may provide a website to the user, where the identification PIN is displayed upon inputting the PC's serial number. Similarly, the memory device vendor may provide a website to the user, where the identification PIN is displayed upon inputting the memory device's serial number. Figure 1 As shown in (b), a plurality of memory devices 12 are connected to a host device 14 such as a server. To prevent a situation in which the memory devices 12 in the server are to be reset at once, the supplier of the memory devices 12 may set an identification PIN of the same value for the plurality of memory devices 12, and notify the server supplier of the value of the identification PIN by means of an e-mail or the like.
[0056] [Memory device state transition]
[0057] Figure 4An example of the state transition of the memory device 12 is shown. It is in the Inactive state 40A when shipped from the factory. The Inactive state 40A is a state in which the administrator PIN and user PIN cannot be set, and the lock function is invalid. The SID (owner PIN) is the initial value. There is a case where the MSID PIN is defined as the initial value of the SID. The MSID PIN can be obtained by anyone using the Get command. The method of notifying the user of the initial value of the SID is not limited to using the command. The initial value of the SID can also be recorded in the user manual in advance, or printed on the nameplate in advance. The memory device 12 that has just shipped uses the initial value of the SID, such as the MSID PIN, as the SID for authentication. The initial value of the SID is the MSID PIN, so the authentication is successful. Thereafter, the SID can be set from the initial value to an arbitrary value (the value of the PIN that the owner wants to use).
[0058] Assume that the memory device 12 is shipped to, for example, a PC vendor while maintaining the Inactive state 40A. The PC vendor sets the SID using the aforementioned method. Upon receiving a Set command from the host device 14 to set the SID, the memory device 12 in the Inactive state 40A checks the authority of the user who issued the Set command. The Set command includes the SID to be set as a parameter. The owner is the only one authorized to set the SID. If the Set command is issued by the owner, the SID is set. In the Inactive state 40B, the SID is the value (initial value) set by the owner using the Set command.
[0059] When the memory device 12 in the Inactive state 40B receives the Activate command from the host device 14, it checks the issuing source user of the Activate command. The Activate command is a command for transferring the memory device 12 to the Active state. The issuing authority is as follows: Figure 3 As shown in (a), the owner is the owner. When the owner issues an Activate command, the memory device 12 enters the Active state 40C. In the Active state 40C, the administrator PIN and the user PIN are initialized, and the lock function is enabled.
[0060] For example, it is assumed that the memory device 12 incorporated into a PC is shipped to a terminal user in the Active state 40C, and an administrator PIN or a user PIN is set on the terminal user side. When the memory device 12 in the Active state 40C receives a Set command for setting an administrator PIN or a Set command for setting a user PIN from the host device 14, it checks the user who issued the Set command. The Set command includes the administrator PIN or user PIN to be set as a parameter. The administrator PIN can be set to the administrator. The user PIN can be set to the administrator and the owner. When a user with issuance authority issues a Set command, the terminal user uses the Set command to set the administrator PIN or the user PIN (initial value state), and the memory device 12 enters the Active state 40D.
[0061] When the memory device 12 in the Active state 40D receives a Revert command from the host device 14 to reset the memory device 12, it checks the user who issued the Revert command. The Revert command can only be issued by a user who knows the owner PIN or identification PIN. If the Revert command is issued by an authorized user, the data is deleted, the owner PIN, administrator PIN, and user PIN are initialized, and the memory device 12 returns to the Inactive state (at factory shipment) 40A.
[0062] On the other hand, when the memory device 12 in the Active state 40D receives a RevertSP command from the host device 14 to reset the memory device 12, it checks the user who issued the RevertSP command. The only authorized user to issue the RevertSP command is the administrator. If the authorized user issues the RevertSP command, the data is deleted, the administrator PIN and user PIN are initialized, and the memory device 12 enters the Inactive state 40B. Furthermore, even after being reset using the RevertSP command, the memory device can remain in the Active state instead of the Inactive state. Furthermore, when the PIN is initialized, it is automatically unlocked. The owner PIN can also be unlocked by initializing the PIN using the Revert command. However, since the data is deleted using the Revert command, the user's recorded data is not retained after unlocking.
[0063] The identification PIN can also be reset using the Revert command, thus unlocking the device. However, since the data is deleted using the Revert command, the user's recorded data will not be retained after unlocking.
[0064] When the memory device 12 receives the Revert command, it simultaneously performs data deletion through internal processing and unlocks the memory device. However, strictly speaking, one process must be executed first, and the other later. Considering power outages, not unlocking the memory device after data deletion is safer. This is because if a power outage occurs immediately before data deletion, the memory device may remain unlocked without data deletion. However, if measures are taken to prevent this from occurring during a power outage, data deletion can be performed after unlocking the memory device.
[0065] [Data Deletion Order]
[0066] Figure 5A 、 Figure 5B This section shows an example of a data deletion sequence for resetting the memory device 12. Before resetting, the host device 14 sends a deletion method display request to the memory device 12 to inquire about the deletion methods supported by the memory device 12. An example of this transmission sequence is when the host device 14 is booted.
[0067] The deletion method display request received by the deletion method display request receiving unit 108 is sent to the deletion method display unit 106. In step 50A, the deletion method display unit 106 obtains information indicating one or more supported deletion methods from the deletion information management unit 124. The deletion method display unit 106 returns deletion method response information indicating the obtained one or more deletion methods to the host device 14.
[0068] Reference Figure 6 An example of a deletion method display request and a deletion method response message is described. Here, the application is TCG Storage, Security Subsystem Class: Opal, Specification Version 2.01, Revision 1.00, August 5, 2015, URL: https: / / trustedcomputinqqroup.orq / wp-content / upIoads / TCG-Storage-OpalSSCv2.01revl.00.pdf (Retrieved August 29, 2017) Defined Level 0 Discovery Header and Level 0 Discovery Response. Figure 6 (a) shows an example of a request to display the Level 0 Discovery Header in a deleted format. The Level 0 Discovery Header indicates only the format of a Level 0 Discovery Response reply to the storage device 12, and does not include the content portion in the header portion.
[0069] Figure 6(b) shows an example of a deletion method response message using Level 0 Discovery Response. Level 0 Discovery Response contains Figure 6 (a) shows the Level 0 Discovery Header and content section. The content section, or feature descriptor, contains multiple feature descriptors.
[0070] like Figure 7 As shown in (a), one of the feature descriptors is in the deletion mode. An example of the data structure of the feature descriptor is shown in Figure 7 (b) The feature descriptor includes a header and a content portion. Bytes 0-3 are the header portion, and bytes 4-n are the content portion. The header portion includes a feature code. The feature description data of the deletion method supported by the memory device 12 is described in byte 4. Figure 7 As shown in (c), an erasure method is assigned. If each bit is "1," it indicates support for that erasure method; if it is "0," it indicates support for that erasure method. For example, if bit 0 of the feature description data is "1," it indicates support for the Overwrite Data Erasure method; if bit 1 is "1," it indicates support for the Block Erasure method; if bit 2 is "1," it indicates support for the Unmap method; if bit 3 is "1," it indicates support for the Reset Write Pointers method; and if bit 4 is "1," it indicates support for the Crypto Erasure method.
[0071] Back to Figure 5A 、 Figure 5B The description of the deletion sequence shown assumes that, when information indicating a single deletion method is returned from the storage device 12, the host device 14 specifies that deletion method. If information indicating multiple deletion methods is returned, the host device 14 selects one of the selected deletion methods and notifies the storage device 12 of the selected deletion method. However, the host device 14 may also specify a different deletion method. Alternatively, the host device 14 may notify the storage device 12 of the deletion method using, for example, a Set command that includes the deletion method information as a parameter.
[0072] The deletion method designation information received by the memory device 12 is supplied to the authentication processing unit 102. The authentication processing unit 102 authenticates the user who issued the Set command that designated the deletion method in step 50B. In order to verify whether the source of the command has the authority to issue the command, the permission processing unit 104 checks in step 50C which PIN-authenticated issuing authority (authority) issued the Set command. If the Set command was issued by an issuing authority authenticated using an identification PIN or user PIN, the permission is determined to have failed in step 50D, and the permission processing unit 104 transmits information indicating the failure to issue the command to the host device 14. If the Set command was issued by an issuing authority authenticated using an owner PIN or administrator PIN, the permission is determined to have succeeded. If the permission is successful, the deletion information management unit 124 checks in step 50C-1 whether the deletion method designated by the host device 14 is a deletion method supported by the host device 14. If the deletion method designated by the host device 14 is not supported (No in step 50C-1), the deletion information management unit 124 transmits information indicating a designation error to the host device 14 in step 50D-1. If the deletion method specified by the host device 14 is supported (Yes in step 50C- 1 ), the deletion information management unit 124 sets the deletion method specified by the host device 14 in the data deletion unit 118 in step 50E.
[0073] Thereafter, when the memory device 12 needs to be reset, the host device 14 notifies the memory device 12 of a reset instruction (deletion instruction). The host device 14 may also notify the memory device 12 of the deletion instruction using, for example, a Revert instruction or a RevertSP instruction.
[0074] The deletion instruction received by the memory device 12 is supplied to the authentication processing unit 102. The authentication processing unit 102 authenticates the user who issued the deletion instruction, ie, the Revert command or the RevertSP command, in step 50F. The permission processing unit 104 checks whether the instruction received in step 50G is the Revert command or the RevertSP command.
[0075] When a Revert instruction is received, the permission processing unit 104 checks in step 50H which PIN authentication source was used to send the Revert instruction in order to check whether the issuing source has the authority to issue the Revert instruction. In the case where the Revert instruction is issued by the issuing source authenticated by the administrator PIN or user PIN, it is determined that the permission has failed in step 50I, and data deletion and PIN initialization are not performed. In the case where the Revert instruction is issued by the issuing source authenticated by the owner PIN or identification PIN, it is determined that the permission has succeeded. In step 50J, the data deletion unit 118 executes data deletion, and the PIN management unit 112 initializes the owner PIN, administrator PIN, and user PIN. As a result, the memory device 12 becomes Figure 4 Inactive state (factory default) shown: 40A.
[0076] When the RevertSP instruction is received, the permission processing unit 104 checks in step 50K which PIN authentication issuing source sent the RevertSP instruction in order to check whether the issuing source has the authority to issue the RevertSP instruction. In the case where the RevertSP instruction is issued by the issuing source authenticated by the owner PIN, identification PIN or user PIN, it is set as permission failure in step 50L, and data deletion and PIN initialization are not performed. In the case where the RevertSP instruction is issued by the issuing source authenticated by the administrator PIN, it is set as permission success, and in step 50M it is checked whether data deletion is specified in the parameters in the RevertSP instruction. In the case where data deletion is specified (yes in step 50M), in step 50J, the data deletion unit 118 executes data deletion, and the PIN management unit 112 initializes the administrator PIN and user PIN. In the case where data deletion is not specified (no in step 50M), in step 50N, the PIN management unit 112 initializes the administrator PIN and user PIN. As a result, the memory device 12 becomes Figure 4 Inactive state 40B is shown.
[0077] As described above, the storage device 12 notifies the host device 14 of the deletion methods it supports. Based on this information, the host device 14 can then execute the deletion method on the storage device 12. The storage device 12 checks the authority of the person who specified it and, if authorized, sets the specified deletion method. During the actual reset, the host device 14 issues a reset instruction to the storage device. The storage device 12 checks the authority of the person who issued the reset instruction and, if authorized, deletes the data and initializes the PIN according to the previously set deletion method.
[0078] Thus, the memory device 12 storing unencrypted data can also be reset. Data will not be leaked from the reset memory device 12 after it is discarded, and security can be ensured. Since the memory device 12 does not store encrypted data, the host device 14 does not need to have an encryption application, and the processing load of the host device 14 is low. Since no encryption circuit is required, the manufacturing cost of the memory device 12 can be suppressed. The memory device 12 does not set the same access permission (unlock) for the entire storage area, but divides the storage area into multiple areas (also called Range) according to the LBA range, and sets different access permissions (PIN required for unlocking) for each Range. The concept of Range will be referred to below. Figure 13 For example, Figure 8 As shown, Range 2 is in an unlocked state accessible to anyone, Range 1 is in a locked state unlockable only by users and administrators who normally use the storage device, and Range 3 can be set to a locked state unlockable only by administrators. By dividing the storage area of the storage device 12 into multiple ranges, multiple users can share the storage device 12 while maintaining mutual security.
[0079] [Management of deletion processing]
[0080] Figure 9 (a) is a flowchart illustrating an example of deletion processing to prevent power outages. In step 222, the memory device 12 receives a Revert / RevertSP command (" / " represents "or"). In step 224, the permission processing unit 104 checks the authority to issue the command. In step 226, it determines whether the command was issued by a user with permission to issue the command. If the command was not issued by a user with permission to issue the command, permission is rejected in step 228.
[0081] When the instruction is issued by a user with issuance authority, in step 230, the permission processing unit 104 sends a Revert / RevertSP instruction to the data deletion unit 118. In step 232, the data deletion unit 118 parses the Revert / RevertSP instruction and determines which Range the Revert / RevertSP instruction corresponds to. The data deletion unit 118 obtains the LBA range corresponding to the Range of the determination result, for example, LBA XY, and starts data deletion from its first LBA X. During the data deletion, the deletion information management unit 124 writes the deleted LBA to the non-volatile memory in step 234. The non-volatile memory can also be implemented by a flash memory provided in the deletion information management unit 124, or by a part of the data storage unit 34. In step 236, the data deletion unit 118 determines whether the data deletion of the LBA range corresponding to the Range of the determination result is completed. If not completed, the data deletion continues. If the processing is completed, in step 238 , the data deletion unit 118 causes the deletion information management unit 124 to write a completion flag indicating that the processing of the Revert / RevertSP command is completed into the nonvolatile memory.
[0082] In this manner, even if power is lost during the processing of a Revert / RevertSP command, since the incomplete and deleted LBAs of the Revert / RevertSP command are stored in the non-volatile memory, the memory device 12 can efficiently restart the incomplete Revert / RevertSP command from the LBAs where data has not been deleted when power is restored. Since data deletion does not need to be performed from the beginning after the restart, data deletion time is not unnecessarily prolonged.
[0083] Figure 9(b) is a flowchart showing an example of the restart processing of the Revert / RevertSP instruction when the power is restored. When the power is turned on, the deletion information management unit 124 determines whether there is an unfinished Revert / RevertSP instruction in step 242. If there is no unfinished Revert / RevertSP instruction, normal processing is performed in step 246. If there is an unfinished Revert / RevertSP instruction, the deletion information management unit 124 reads the deletion completed LBA from the non-volatile memory in step 244, sets the deletion completed LBA to the deletion start address of the data deletion unit 118, and causes the data deletion unit 118 to start data deletion from the undeleted LBA. During the data deletion, the deletion information management unit 124 writes the deletion completed LBA to the non-volatile memory in step 248. The data deletion unit 118 determines in step 250 whether the data deletion of the Range currently being deleted is completed. If it is not completed, the data deletion continues. If the processing is completed, the data deletion unit 118 causes the deletion information management unit 124 to write a completion flag indicating that the processing of the Revert / RevertSP command is completed to the nonvolatile memory in step 252. Thereafter, normal processing is performed in step 254.
[0084] Figure 9 The deletion process shown can be Figure 5A 、 Figure 5B As shown, the memory device 12 notifies the host device 14 of the deletion method it supports, and the host device 14 executes the deletion method after specifying it. Figure 5A 、 Figure 5B The order shown is irrelevant and can be executed independently.
[0085] [Exclusive Control of Data Deletion]
[0086] Reference Exclusive control for giving priority to the data deletion process being executed will be described.
[0087] Figure 10 This flowchart shows an example of a process in which access is denied during deletion and deletion is prioritized. The storage device 12 receives the Revert / RevertSP command in step 262. The permission processing unit 104 checks the authority to issue the command in step 264 and determines in step 266 whether the command was issued by a user with permission to issue it. If the command was not issued by a user with permission to issue it, permission is considered a failure in step 268.
[0088] When a command is issued by a user with issuance authority, the memory device 12 determines in step 270 whether a read / write command has been received from the host device 14 during command execution. If a read / write command has been received, the memory device 12 stores the command in a queue or returns an error to the host device 14. The queue may be provided within the read / write processing unit 122, for example. If a read / write command has not been received, the memory device 12 continues executing the command in step 274.
[0089] Figure 10 The deletion process shown can also be done as Figure 5A 、 Figure 5B As shown, the memory device 12 notifies the host device 14 of the deletion method it supports, and the host device 14 executes the deletion method after executing the deletion method. Figure 5A 、 Figure 5B The order shown is irrelevant and can be executed independently.
[0090] Figure 11 This is a flowchart showing an example of denying access to a Range during deletion (allowing access to areas other than the area being deleted) as a second example of exclusive control of data deletion processing. Figure 10 In the processing of , multiple areas are not defined in the storage area, but Figure 11 In the processing, multiple ranges are defined in the storage area. The memory device 12 receives the RevertSP command in step 282. In step 284, the permission processing unit 104 checks the authority to issue the command. In step 286, it determines whether the command was issued by a user with issuance authority. If the command was not issued by a user with issuance authority, the permission is determined to have failed in step 288.
[0091] If the command is issued by a user with issuance authority, the license processing unit 104 sends a RevertSP command to the data deletion unit 118 in step 290. In step 292, the data deletion unit 118 analyzes the RevertSP command and determines which range the RevertSP command corresponds to. The data deletion unit 118 begins deleting data within the LBA range corresponding to the determined range. During data deletion, the memory device 12 determines in step 294 whether a read / write command has been received from the host device 14. If no read / write command has been received, the memory device 12 continues executing the RevertSP command in step 296.
[0092] When the memory device 12 receives a read / write command, it determines in step 298 whether the received read / write command is for a range being deleted. If it is a read / write command for a range being deleted, the memory device 12 stores the command in a queue or returns an error to the host device 14 in step 300. If it is not a read / write command for a range being deleted, the memory device 12 executes the read / write command for a range other than the range being deleted in step 302.
[0093] Thus, even if data is being written to another area while data is being deleted from one area, data will not be deleted from that area, so normal data writing and reading can be performed. Furthermore, the area where data is being deleted is under exclusive control as described above, preventing access other than deletion. Therefore, data will not be retained or deleted against the user's wishes.
[0094] Figure 11 The deletion process shown can also be done as Figure 5A 、 Figure 5B As shown, the memory device 12 notifies the host device 14 of the deletion method it supports, and the host device 14 executes the deletion method after specifying it. Figure 5A 、 Figure 5B The order shown is irrelevant and can be executed independently.
[0095] Figure 12 This flowchart illustrates an example of execution control of multiple Revert / RevertSP commands, a third example of exclusive control of data deletion processing. The memory device 12 receives the first Revert / RevertSP command in step 312. In step 314, the authentication processing unit 102 checks the authority to issue the command. In step 316, it determines whether the command was issued by a user with issuance authority. If the command was not issued by a user with issuance authority, authorization is failed in step 318.
[0096] If the command is issued by a user with issuance authority, the permission processing unit 104 sends the first Revert / RevertSP command to the data deletion unit 118 in step 320. In step 322, the data deletion unit 118 analyzes the first Revert / RevertSP command and determines which range the Revert / RevertSP command corresponds to. The data deletion unit 118 begins deleting data in the LBA range corresponding to the determined range. During data deletion, the memory device 12 determines in step 324 whether the second Revert / RevertSP command has been received. Step 324 may also be executed before step 322.
[0097] If the second Revert / RevertSP command is not received, the memory device 12 continues to execute the first Revert / RevertSP command in step 328. If the second Revert / RevertSP command is received, the authentication processing unit 102 checks the command issuance authority in step 322 and determines in step 334 whether the command was issued by a user with issuance authority. If the command was not issued by a user with issuance authority, authorization fails in step 336.
[0098] If the command is issued by a user with issuance authority, in step 338, the permission processing unit 104 sends the second Revert / RevertSP command to the data deletion unit 118. In step 342, the data deletion unit 118 analyzes the second Revert / RevertSP command to determine which range the Revert / RevertSP command corresponds to, and also determines whether the range of the first Revert / RevertSP command and the range of the second Revert / RevertSP command differ.
[0099] If the Range of the second Revert / RevertSP command differs from the Range of the first Revert / RevertSP command, the data deleter 118 determines in step 344 whether the two received commands are the first RevertSP command and the second RevertSP command. If the two received commands are the first RevertSP command and the second RevertSP command, the data deleter 118 also executes the second RevertSP command in step 346 because the two RevrrtSP commands with different Ranges were received. Alternatively, instead of executing the second RevertSP command in step 346, the deletion operation of the second RevertSP command may be stored in the queue.
[0100] If it is determined in step 342 that the Range of the second Revert / RevertSP command is the same as the Range of the first Revert / RevertSP command, and if it is determined in step 344 that the two commands are not the first RevertSP command and the second RevertSP command, the data deletion unit 118 stores the deletion operation of the second Revert / RevertSP command in the queue in step 348 or returns an error to the host device 14. Combinations of the first and second commands include (first Revert command, second Revert command), (first Revert command, second RevertSP command), (first RevertSP command, second Revert command), and (first RevertSP command, second RevertSP command). However, with respect to (first RevertSP command, second RevertSP command), if the Ranges of the first and second commands are different, the second RevertSP command is executed along with the first RevertSP command as shown in step 346. Regarding the others (1st Revert instruction, 2nd Revert instruction), (1st Revert instruction, 2nd RevertSP instruction), (1st RevertSP instruction, 2nd Revert instruction), whether the Ranges of the 1st and 2nd instructions are the same or different, the 2nd instruction is not executed as shown in step 348.
[0101] As a result, the memory device 12 can execute the Revert / RevertSP instructions in a centralized manner, thereby preventing the data deletion time from being prolonged.
[0102] Figure 12 The deletion process shown can also be done as Figure 5A 、 Figure 5B As shown, the memory device 12 notifies the host device 14 of the deletion method it supports, and the host device 14 executes the deletion method after specifying it. Figure 5A 、 Figure 5B The order shown is irrelevant and can be executed independently.
[0103] [Multiple area deletion using Namespace]
[0104] Figure 13Conceptually represents the storage area of the memory device 12. Namespace is defined in NVM Express, Revision 1.3, May 1, 2017. Namespace is a partial area divided from the entire storage area of the memory device 12, specifically a collection of logical blocks. At least one Namespace identified by NamespaceID can be defined for a memory device. A Namespace of size n contains logical block addresses. Each namespace has a namespace global range, and each namespace global range contains multiple ranges. As mentioned above, a different PIN can be set for each range. Global ranges can span multiple namespaces.
[0105] In addition, there are partitions as partial areas divided from the entire storage area. Partitions are partial areas managed by the host device 14, while Namespaces are partial areas managed by the memory device 12. When the host device 14 accesses a partition, it specifies a logical address included in the partition to be accessed. However, when accessing a Namespace, it specifies the Namespace to be accessed. The Range information management unit 114 of the memory device 12 manages Figure 13 The relationship between Namespace and Range is shown.
[0106] Figure 14 (a) is a flowchart showing an example of deletion of Namespace units. In step 402, the memory device 12 receives a deletion instruction of Namespace units from the host device 14. Since parameters can be added to the deletion instruction, parameters such as Namespace can also be added as a deletion instruction of Namespace units. Alternatively, since parameters can also be added to the above-mentioned Revert / RevertSP instructions, parameters such as Namespace can also be added, and the Revert / RevertSP instructions for executing the deletion of Namespace units can be set as deletion instructions of Namespace units. Furthermore, it is also possible as Figure 14As shown in (b), a Namespace Table is predefined to indicate which Namespace the Revert / RevertSP command deletes. A Namespace can be registered with the Namespace Table using the Set command, with the NamespaceID specified as a parameter. Deleting a Namespace in units of Namespaces includes both deleting a single Namespace and deleting all Namespaces (i.e., the GlobalRange). Therefore, specifying 00h or FFh as a parameter also specifies all Namespaces.
[0107] Figure 14 (c) shows an example of Namespace Table settings. Upon receiving the Set command in step 412, the memory device 12 sets the NamespaceID specified as a parameter in the Namespace Table. If NamespaceID = 00h or FFh, all NamespaceIDs are set in the Namespace Table. Subsequently, upon receiving the Revert / RevertSP command from the host device (step 414), the memory device 12 retrieves the NamespaceID from the Namespace Table in step 416 and deletes all Ranges contained in the Namespace corresponding to the retrieved NamespaceID.
[0108] Thus, if the storage device 12 has multiple Namespaces, each with multiple Ranges, the host device 14 can simply instruct the storage device 12 to delete the data in all Ranges contained in the designated Namespace. This eliminates the need for the host device 14 to manage the relationship between Namespaces and Ranges, simplifying the configuration of applications on the host device 14 and reducing costs.
[0109] Figure 14 The deletion process shown can also be done as Figure 5A 、 Figure 5B As shown, the memory device 12 notifies the host device 14 of the deletion method it supports, and the host device 14 executes the deletion method after specifying it. Figure 5A 、 Figure 5B The order shown is irrelevant and can be executed independently.
[0110] Furthermore, refer to Figures 9 to 14 Several deletion operations are described, but these deletion operations can also be freely combined and executed.
[0111] According to the first embodiment, the memory device 12 notifies the host device 14 of the deletion methods it supports. The host device 14 specifies the deletion method, and the memory device 12 deletes the data using the specified deletion method. Therefore, a memory device 12 storing unencrypted data can be reset. Data will not be leaked from the reset memory device 12 after it is discarded, ensuring security. Since the memory device 12 does not store encrypted data, the host device 14 does not need to have an encryption application, and the processing load on the host device 14 is low. Since an encryption circuit is not required, the manufacturing cost of the memory device 12 can be reduced. Other embodiments are described below. These other embodiments only describe the differences from the first embodiment, and the same descriptions are omitted.
[0112] [Second embodiment]
[0113] The possibility of data leakage from a memory device 12 that has been discarded after being reset is not zero. To minimize this possibility, mechanically destroying or shredding the memory device 12 during disposal is a possible method, rendering the memory device 12 physically nonexistent. Mechanical destruction or shredding is laborious and time-consuming. In the second embodiment, the memory device 12 can be electrically destroyed.
[0114] In the second embodiment, Figure 15 As shown, in addition to the Active state and the Inactive state, a Destroy state is defined as the state of the memory device 12. When the host device 14 issues a Destroy command to the memory device 12 in the Active state, the memory device 12 enters the Destroy state.
[0115] Figure 17 The memory device 12A of the second embodiment that can be set to the Destroy state is schematically shown. Figure 2 The memory device 12 shown differs in that it has an additional destruction processing unit 116. The destruction processing unit 116 is connected to the I / F processing unit 22, the permission processing unit 104, the read / write processing unit 122, and the data deletion unit 118. When the memory device 12 is in the Destroy state, the destruction processing unit 116 instructs the read / write processing unit 122 that it cannot accept commands (a confirmation command can be accepted).
[0116] Figure 16(a) shows an example of a process for setting the memory device 12 to the Destroy state. The memory device 12 receives a Destroy command in step 422. Since the Destroy command is issued similarly to the Revert / RevertSP command, an owner PIN or administrator PIN is required. Users other than the owner or administrator cannot issue the Destroy command, thus preventing the memory device 12 from being destroyed. In step 424, the permission processing unit 104 checks the authority to issue the command. In step 426, it determines whether the command was issued by a user with issuance authority. If the command was not issued by a user with issuance authority, authentication fails in step 428.
[0117] When a command is issued by a user with issuance authority, in step 429, the memory device 12 can only accept a confirmation command inquiring whether it is in the destruction state among the commands from the host device 14, but cannot accept other commands (such as read / write commands). In addition, the data is deleted and the PIN is initialized. Thereafter, the memory device 12 enters the Destroy state. Therefore, the Destroy state is similar to the Inactive state (factory shipment) 40A, in which the administrator PIN and user PIN cannot be set, and it is a state in which it cannot be unlocked or locked. In addition, commands or instructions other than confirmation commands cannot be accepted. Therefore, the memory device 12 in the Destroy state cannot transition to other states, the Active state, or the Inactive state.
[0118] Figure 16 (b) is a flowchart illustrating an example of the operation of the memory device 12 in the Destroy state. Upon receiving a command (YES in step 434), the memory device 12 determines in step 436 whether the received command is a confirmation command. If the received command is a confirmation command, the memory device 12 returns destruction status information indicating the destruction state to the host device 14 in step 440. If the received command is not a confirmation command, the memory device 12 returns error information indicating an error to the host device 14 in step 438.
[0119] Thus, when the memory device 12 receives an instruction to transition to the Destroy state, it deletes the data in the data storage unit 34 and restores the PIN to its initial value. In the Destroy state, the memory device 12 cannot access the data storage unit 34, making the possibility of data leakage virtually zero. Furthermore, in the Destroy state, the memory device 12 responds to a confirmation command from the host device 14 by returning a response indicating the Destroy state to the host device 14. This allows the host device 14 to identify whether the memory device 12 is in the Destroy state, a Fault state, or a Reset state. Since no destruction or shredding equipment is required, the management cost of the memory device 12 is reduced. Furthermore, since the memory device 12 is distinguished from defective parts and is not mistakenly discarded as such, data leakage from discarded parts is prevented.
[0120] In the Destroy state, read / write commands cannot be accepted, but data that is safe from leakage can be read. In other words, the storage area for data that is safe from leakage can be made a read-only area.
[0121] [Third embodiment]
[0122] In the above description, the memory device 12 does not have data encryption and stores plaintext data. Next, a third embodiment of the memory device 12 that stores encrypted data will be described. Figure 18 The memory device 12B according to the third embodiment is schematically shown. Figure 2 The memory device 12 shown differs in that an encryption processing unit 142 and a key management unit 140 are added. The key management unit 140 generates a key for data encryption and stores it in itself. The key is a random value generated by a random number generator. The encryption processing unit 142 uses the key to encrypt the plaintext data input to the data storage unit 34. An example of an encryption algorithm is a well-known public key algorithm such as the Advanced Encryption Standard (AES). The encryption processing unit 142 decrypts the encrypted data output from the data storage unit 34 using the same key as the key used for encryption, and restores the encrypted data to plaintext data. That is, data is always encrypted when written to the data storage unit 34 and is always decrypted when read from the data storage unit 34.
[0123] As described above, the host device 14 has a function of specifying the data deletion method to be executed by the memory device 12. Figure 7As shown in (c), the memory device 12 can also implement Crypto Erase as a data deletion method. When the host device 14 specifies Crypto Erase as the data deletion method, or when data deletion is instructed using the Revert or RevertSP command, the data deletion unit 118 instructs the key management unit 140 to update the key. When instructed to update the key, the key management unit 140 generates a new random number to create a new key value, discards the previously used key value, and stores the new key value in its memory. The encryption processing unit 142 then uses the new key value for encryption and decryption.
[0124] When the key value is updated in this way, the data already stored in the data storage unit 34 is encrypted with the old key value. Therefore, even if the new key value is used for decryption processing, it cannot be decrypted (restored) to the correct plaintext data. After the key value is updated in this way, the encryption and decryption processing of the encryption processing unit 142 becomes meaningless, so the execution of the encryption and decryption processing itself can also be stopped. Figure 18 The key management unit 140 shown in the figure transmits an instruction to the encryption processing unit 142 to stop the encryption process and the decryption process after the key is updated.
[0125] Therefore, when the memory device 12 stores encrypted data, the host device 14 may also specify a data deletion method, and the memory device 12 is reset using the specified deletion method.
[0126] [Fourth embodiment]
[0127] Figure 19 The memory device 12C according to the fourth embodiment is schematically shown for storing encrypted data. Figure 18The memory device 12B shown, which includes a key management unit 140 and an encryption processing unit 142, differs in that it also has a destruction processing unit 116. The destruction processing unit 116 is connected to the I / F processing unit 22, the permission processing unit 104, the read / write processing unit 122, the data deletion unit 118, and the encryption processing unit 142. When the memory device 12 is in the Destroy state, the destruction processing unit 116 instructs the encryption processing unit 142 to disable the encryption function and instructs the read / write processing unit 122 that it cannot accept commands (a confirmation command can be accepted). Furthermore, when the memory device 12 is in the Destroy state, a new random number can be generated for the key management unit 140 to generate a new key value, discarding the previously used key value and storing the new key value in the memory. The updated key value makes it impossible to decrypt encrypted data encrypted with the previous key value. Furthermore, when the memory device 12 is in the Destroy state, the key management unit 140 may send an instruction to the encryption processing unit 142 to stop the encryption process and the decryption process.
[0128] According to the fourth embodiment, the effects of the second embodiment and the effects of the third embodiment can be exhibited.
[0129] [Fifth embodiment]
[0130] In the embodiment, it is assumed that the memory device 12, 12A, 12B or 12C is shipped to, for example, a PC vendor while maintaining the Inactive state 40A. The PC vendor sets the SID and ships the memory device 12 in the Active state to the end user. The end user sets the administrator PIN and the user PIN. In the embodiment, at least the PC vendor is required to notify the end user of the initial value of the administrator PIN by, for example, describing it in the user manual. A fifth embodiment describes a method for restoring the administrator PIN notified to the end user to its initial value without deleting the data even if the end user loses the administrator PIN.
[0131] In the fifth embodiment, as Figure 20 As shown, the PIN management unit 112 of the memory device 12D includes a plurality of administrator PINs, which are defined here as an administrator PIN 1 and an administrator PIN 2. Figure 20 In the first embodiment, the memory device 12 has a plurality of administrator PINs, but it is also possible to The memory devices 12A, 12B, and 12C of the embodiment have multiple administrator PINs. When the PC vendor sets the memory device to the Active state using the Activate command, the administrator PIN1 and the administrator PIN2 are set to initial values. Here, the PC vendor sets the values of the administrator PIN1 and the administrator PIN2, but the value of the administrator PIN1 is notified to the end user by a method such as that described in the user manual. However, the value of the administrator PIN2 is not disclosed to the end user, and the PC vendor appropriately manages it in advance so that the value is not leaked to the outside. In addition, if Figure 21 As shown, the setting permissions for Administrator PIN1 and Administrator PIN2 are pre-determined. That is, with Administrator PIN1's permissions, you can use the Set command to view the value of Administrator PIN1 or the Get command to set it, but you cannot use the Set command to view the value of Administrator PIN2 or the Get command to set it. Similarly, with Administrator PIN2's permissions, you can use the Set command to view the value of Administrator PIN2 or the Get command to set it, but you cannot use the Set command to view the value of Administrator PIN1 or the Get command to set it.
[0132] Administrator PIN1 is a value that can be known by the user for management purposes. If the value of Administrator PIN2 is changed (set) with the authority of Administrator PIN1, the value of Administrator PIN2 will become different from the value of Administrator PIN2 set at the factory of the PC vendor. To prevent this, authority separation is performed so that the value of Administrator PIN2 cannot be browsed (Set command) or set (Get command) with the authority of Administrator PIN1. In addition, Figure 21 In the example, it is set that administrator PIN1 cannot be set or viewed under the authority of administrator PIN2, but it is set that administrator PIN2 cannot be changed under the authority of administrator PIN1. Therefore, access control can also be set in a way that administrator PIN1 can be set and viewed under the authority of administrator PIN2.
[0133] As in the first embodiment Figure 3As shown in (a), a RevertSP command can be issued using the administrator PIN. In response to a request from an end user, the PC vendor uses the RevertSP command with administrator PIN 2 to perform a reset process. This reset process, i.e., the execution command of the RevertSP command, can also be sent remotely from a server managed by the PC vendor to the end user's PC via a network. The RevertSP command can specify a parameter indicating whether to delete or retain data. In other words, if the option to retain data is specified in the Revert command using administrator PIN 2, the data is retained as is, but administrator PIN 1 is initialized. Furthermore, even after a reset using the RevertSP command, the memory device can remain in the Active state rather than the Inactive state.
[0134] In this manner, by configuring the memory device 12D in a manner of defining a plurality of administrator PINs in advance, even if the terminal user loses the administrator PIN 1 , the administrator PIN 1 can still be initialized.
[0135] [Sixth embodiment]
[0136] In the embodiment, it is envisioned that the memory device 12, 12A, 12B, 12C, or 12D is shipped to, for example, a PC vendor while maintaining the Inactive state 40A. The PC vendor then sets the SID and ships the memory device to the end user in the Active state, whereupon the end user sets the administrator PIN and user PIN. In a sixth embodiment, it is envisioned that the PC vendor sets the SID but does not transition the memory device to the Active state. Instead, the memory device is shipped to the end user while maintaining the Inactive state. The end user then transitions the memory device to the Active state and sets the administrator PIN and user PIN.
[0137] like Figure 3 As shown in (a), the owner PIN is required to transition from the Inactive state to the Active state. In this scenario, the PC vendor sets the administrator PIN from an initial value to a value known to the PC vendor. However, the Activate command is executed on the end user side, so the owner PIN must be entered into the memory device on the end user side. There are two methods to achieve this: (1) the PC has the owner PIN value itself; and (2) the PC does not have the owner PIN value itself, and the owner PIN is calculated on the end user side.
[0138] (1) Method of making the PC have the owner PIN value itself
[0139] PC vendors store the SID in an area of the BIOS (Basic Input / Output System) that is not easily accessible to users before shipping the memory device to end users. Since the device is shipped to the end user in an Inactive state, the lock function is initially disabled. When the end user activates the lock function, a program stored in the BIOS, etc., reads the SID stored in the area that is not easily accessible to the end user, and uses the Activate command to transition the memory device from the Inactive state to the Active state.
[0140] (2) Method in which the PC does not have the value of the owner PIN itself
[0141] The PC vendor pre-generates the SID using the SID's identification information and the memory device's serial number, and then pre-sets the SID value in the memory device. This generation algorithm, including its parameters, is known only to the PC vendor. Identification information refers to the SID's ID. The SID value (e.g., XXX, YYY, ZZZ) corresponds to the identification information (e.g., 0001, 0002, 0003). The SID value is not disclosed to users, but the identification information is.
[0142] The SID identification information is stored in an area of the memory device that cannot be set (written) by the user. A program stored in the BIOS or the like on the terminal user side uses this identification information and the serial number of the memory device to generate the SID. The terminal user uses this SID to transfer the memory device from the Inactive state to the Active state using the Activate command. In addition, when the PC is connected to the network, the PC communicates with the PC vendor's server, and the SID identification information and the serial number of the memory device are sent from the PC to the PC vendor's server. The PC vendor generates the SID based on this information. This allows authentication of the owner PIN even when the terminal user does not have the owner PIN.
[0143] Alternatively, the PC vendor may pre-store pairs of SID values (e.g., XXX, YYY, ZZZ) and identification information (e.g., 0001, 0002, 0003) in a table. The SID value (e.g., XXX) is set in a SID storage area of each memory device that is not easily accessible or user-configurable. The PC notifies the PC vendor's server of the SID identification information, i.e., which SID is set. Therefore, it is preferable that the identification information cannot be changed by the user without authorization. The PC vendor can obtain the SID from the identification information by referring to the table. Even if the PC vendor transmits the obtained SID to the PC program via the network, the owner PIN can still be authenticated even if the end user does not have the owner PIN.
[0144] In either case, the memory device must pre-determine an area for storing the SID's identification information. Ideally, this area should be defined outside the LBA area to prevent end users from accessing it with standard read / write commands. Furthermore, write permissions should be limited to the SID to prevent end users from arbitrarily changing the SID's identification information. Figure 22 FIG. 1 is a diagram showing the structure of the memory device 12E according to this embodiment. Figure 22 As shown, the memory device 12E newly includes a label storage (LabelStore) management unit 150. The label storage management unit 150 sets SID label information in a label storage table 152 or retrieves label information from the label storage table 152. The label storage table 152 is accessed not via read or write commands to LBAs but via Set and Get commands. Specifically, the label storage management unit 150 sets a value in the label storage table 152 using a Set command and retrieves the set value from the label storage table 152 using a Get command. Figure 22 The memory device 12 of the first embodiment includes the identification storage management unit 150, but it may also be The memory device 12A, 12B, 12C, or 12D according to the embodiment includes an identification storage management unit 150 .
[0145] Furthermore, if Figure 23 As shown, access rights to the identification storage table 152 are restricted by the source of the command. While values in the identification storage table 152 can be read (Get) regardless of permissions, writing (Set) to the identification storage table 152 is limited to the administrator's PIN permissions. For example, when a Set command regarding the identification storage table 152 is supplied to the memory device 12E, the authentication processing unit 102 performs PIN authentication, and the permission processing unit 104 determines whether the source of the Set command is the owner. If the source of the Set command is the owner, the identification information is set in the identification storage table 152.
[0146] The SID is set at the factory of the PC supplier. The SID identification information is stored in the identification storage table 152 in advance using the authority of the SID. In this way, the writing authority of the SID identification information can be limited to the SID in advance.
[0147] This allows the end user to switch from the Inactive state to the Active state using the Activate command, allowing them to continue using a PC shipped in the Inactive state without using the Lock function. Users who wish to use the Lock function can activate it by switching from the Inactive state to the Active state using the Activate command. This improves user convenience by providing both users who want to use the Lock function and those who don't, thus improving user convenience.
[0148] Furthermore, the present invention is not limited to the embodiments described above in their entirety. During implementation, the components may be modified and embodied within the scope of the present invention. Furthermore, various inventions may be formed by appropriately combining multiple components disclosed in the embodiments. For example, several components may be deleted from all components shown in the embodiments. Furthermore, components across different embodiments may be appropriately combined.
[0149] [Explanation of Symbols]
[0150] 12 memory devices
[0151] 14 host device
[0152] 22I / F processing unit
[0153] 34 Data storage unit
[0154] 102 Authentication Processing Department
[0155] 104 Licensing Processing Department
[0156] 106 Delete mode display section
[0157] 116 Destruction Processing Department
[0158] 118 Data Deletion Department
[0159] 112 PIN Management Department
[0160] 122 Read / write processing unit
[0161] 124 Delete Information Management Department
Claims
1. A method for controlling a memory device, characterized in that The memory device stores unencrypted user data and has at least one deletion method. The control method of the memory device includes: receiving an inquiry from a host device, the inquiry being about the at least one deletion method provided by the memory device; and upon receiving the inquiry, sending a response message indicating the at least one deletion method to the host device; The response information includes: a plurality of bits corresponding to respective ones of the plurality of deletion modes; Each of the plurality of bits indicates whether the memory device has an erasure mode corresponding to each of the plurality of bits; and The plurality of deletion methods include: the at least one deletion method provided by the memory device.
2. The memory device control method according to claim 1, wherein: The receiving includes receiving the consultation when the host device is powered on or booted up.
3. The control method of the memory device according to claim 1, further comprising: include: receiving, from the host device, designated information specifying a deletion method after sending the response information; determining whether the host device has the authority to issue the specified information; and If the host device has the authority to issue the designated information, the host device receives the deletion method.
4. The control method of the memory device according to claim 3, further comprising: include: When receiving a deletion instruction from the host device, determining whether the host device has authority to issue the deletion instruction; and When it is determined that the host device has the authority to issue the deletion instruction, the deletion instruction is executed in the received deletion method.
5. The control method of the memory device according to claim 4, further comprising: include: Set personal identification information; and Restoring the set personal identification information to the initial value; and The personal identification information includes at least first identification information related to the first person and second identification information related to the second person. The deletion instruction includes restoring the set personal identification information to an initial value, The deletion instruction includes: at least a first instruction and a second instruction, wherein the deleted data is different from the personal identification information restored to the initial value; The issuance authority of the first instruction is different from the issuance authority of the second instruction.
6. The memory device control method according to claim 1, further comprising: include: When receiving designation information designating a deletion method from the host device after sending the response information, determining whether the deletion method designated by the host device is different from the at least one deletion method possessed by the host device; When the deletion method designated by the host device is different from the at least one deletion method possessed by the host device, a designation error signal is transmitted to the host device.
7. The memory device control method according to claim 1, wherein: The at least one deletion method includes any one of an overwrite deletion method, a block deletion method, and a non-mapping method.
Citation Information
Patent Citations
Map note processor, map note processing method, map note processing program, and map display device
JP2017181632A
Information processing apparatus, image forming apparatus, data erasure method, and data erasure program
JP2014174862A
Secure Erase in a Memory Device
US20150121537A1