disk devices
By introducing a key generation control circuit into the disk device, which generates and manages encryption key generations that cannot be generated, calculated, or predicted, the problem of insufficient security of externally managed keys is solved, and the data security of the disk device is improved.
Patent Information
- Application Number
- CN202110967254.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-03-19
- Filing Date
- 2021-08-23
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2041-08-23
AI Technical Summary
Existing disk devices lack sufficient security during data encryption and decryption, especially in the handling of keys generated and managed by external devices.
The disk drive incorporates a key generation control circuit that ensures the security of encryption keys by generating and managing encryption key generations that cannot be generated, calculated, or predicted. External devices manage the encryption keys and transmit them to the disk drive for processing.
It improves the security of disk devices, ensures more reliable management and update processes for encryption keys, and enhances data protection capabilities.
Smart Images

Figure CN115114680B_ABST
Abstract
Description
[0001] This application enjoys priority based on Japanese Patent Application No. 2021-45391 (filed on March 19, 2021). This application incorporates the entire contents of the basic application by reference. Technical Field
[0002] Embodiments of the present invention relate to disk drives. Background Technology
[0003] Typically, disk devices generate and manage keys for encrypting and decrypting data. In recent years, to improve security, a disk device that processes data using keys generated and managed by external devices such as hosts has been considered. Summary of the Invention
[0004] Embodiments of the present invention provide a disk device that can improve security.
[0005] The disk device according to this embodiment includes: a disk; a head for writing data to the disk and reading data from the disk; and a controller for managing the key generation of the encryption key based on generation confirmation information generated according to the encryption key (password key) and unable to generate the encryption key, the encryption key being managed by an external device and transmitted from the external device. Attached Figure Description
[0006] Figure 1 This is a block diagram illustrating the configuration of the disk device 1 according to the implementation method.
[0007] Figure 2 This is a block diagram illustrating an example configuration of an HDC (hard disk controller) and a host in an implementation method.
[0008] Figure 3 This is a schematic diagram illustrating an example of a key generation update method for an encryption key with a predetermined LBA (Logical Block Address) range involved in an implementation.
[0009] Figure 4 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation.
[0010] Figure 5 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation.
[0011] Figure 6This is a flowchart illustrating an example of a method for updating the key generation of an encryption key involved in an implementation.
[0012] Figure 7 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation.
[0013] Figure 8 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation.
[0014] Figure 9 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation. Detailed Implementation
[0015] The embodiments will now be described with reference to the accompanying drawings. Furthermore, the drawings are merely illustrative and are not intended to limit the scope of the invention.
[0016] (Implementation Method)
[0017] Figure 1 This is a block diagram illustrating the configuration of the disk device 1 according to the implementation method.
[0018] The disk drive 1 includes a head disk assembly (HDA), a driver IC 20, a head amplifier integrated circuit (hereinafter referred to as a head amplifier IC or preamplifier) 30, volatile memory 70, non-volatile memory 80, buffer memory (buffer) 90, and a system controller 130 as a single-chip integrated circuit. Furthermore, the disk drive 1 is connected to an external device, such as a host system (host) 100.
[0019] The head assembly (HDA) includes a disk (hereinafter referred to as disk) 10, a spindle motor (SPM) 12, an arm 13 with a head 15 mounted on it, and a voice coil motor (VCM) 14. The disk 10 is mounted on the spindle motor 12 and rotates under its drive. The arm 13 and VCM 14 constitute an actuator. The actuator, driven by the VCM 14, controls the head 15 mounted on the arm 13 to move to a predetermined position on the disk 10. Two or more disks 10 and heads 15 can also be provided.
[0020] Disk 10 has a user data area 10a available to the user and a system area 10b for writing information required for system management within its recording area. Furthermore, disk 10 may also have a media cache (hereinafter sometimes referred to as a media cache area) allocated as a separate area from the user data area 10a and the system area 10b, temporarily holding data (or commands) transmitted (forwarded) from the host 100, etc., before it is written to a predetermined area of the user data area 10a. Hereinafter, the direction from the inner periphery of disk 10 towards the outer periphery or from the outer periphery of disk 10 towards the inner periphery is called the radial direction. In the radial direction, the direction from the inner periphery towards the outer periphery is called the outer direction (or outer side), and the direction from the outer periphery towards the inner periphery, that is, the direction opposite to the outer direction, is called the inner direction (or inner side). The direction orthogonal to the radial direction of disk 10 is called the circumferential direction. That is, the circumferential direction corresponds to the direction along the circumference of disk 10. Additionally, the predetermined position in the radial direction of disk 10 is sometimes referred to as the radial position, and the predetermined position in the circumferential direction of disk 10 is referred to as the circumferential position. Sometimes, both the radial and circumferential positions are simply referred to as "position." Disk 10 is divided into multiple regions (hereinafter sometimes called zones or zone areas) according to a predetermined range in the radial direction. Data can be written to a zone within a predetermined range in the radial direction. In other words, multiple tracks can be written to a zone. Data can be written to a track within a predetermined range in the circumferential direction. In other words, a track includes multiple sectors. Furthermore, "track" is used to refer to one of the multiple regions divided into a predetermined range in the radial direction of disk 10, the path of the first 15 at a predetermined radial position of disk 10, data extending circumferentially in the predetermined radial direction of disk 10, a circle of data written to a predetermined track of disk 10, data written to a predetermined track of disk 10, and various other meanings. The term "sector" is used to refer to one of several regions in the circumferential direction of a predetermined track of disk 10, data written to a predetermined circumferential position at a predetermined radius position of disk 10, data written to a predetermined sector of disk 10, and various other meanings.
[0021] The head 15 is centered around a slider and includes a write head 15W and a read head 15R mounted on the slider. The write head 15W writes data to the disk 10. The read head 15R reads data recorded on the data tracks of the disk 10. The head 15 writes data to the disk 10 in blocks comprising at least one sector and reads data in blocks. Here, a sector is the smallest unit of data written to or read from the disk 10.
[0022] The driver IC20 controls the driving of SPM12 and VCM14 under the control of the system controller 130 (specifically, MPU40 described later).
[0023] The head amplifier IC (preamplifier) 30 includes a read amplifier and a write driver. The read amplifier amplifies the read signal read from disk 10 and outputs it to the system controller 130 (specifically, the read / write (R / W) channel 50 described later). The write driver outputs a write current corresponding to the write data output from the R / W channel 50 to the head 15.
[0024] Volatile memory 70 is a semiconductor memory that loses its stored data when the power supply is disconnected. Volatile memory 70 stores data required for processing in various parts of disk drive 1. Volatile memory 70 is, for example, DRAM (Dynamic Random Access Memory) or SDRAM (Synchronous Dynamic Random Access Memory).
[0025] Non-volatile memory 80 is a semiconductor memory that records stored data even when the power supply is interrupted. Non-volatile memory 80 is, for example, NOR or NAND type flash memory (FROM).
[0026] The buffer memory 90 is a semiconductor memory that temporarily records data transmitted and received between the disk drive 1 and the host computer 100. Furthermore, the buffer memory 90 may be integrated with the volatile memory 70. Examples of buffer memory 90 include DRAM, SRAM (Static Random Access Memory), SDRAM, FeRAM (Ferroelectric Random Access Memory), or MRAM (Magnetoresistive Random Access Memory).
[0027] The system controller (controller) 130 is implemented, for example, using a large-scale integrated circuit (LSI) called a System-on-a-Chip (SoC), which integrates multiple components onto a single chip. The system controller 130 includes a microprocessor (MPU) 40, a read / write (R / W) channel 50, and a hard disk controller (HDC) 60. The MPU 40, R / W channel 50, and HDC 60 are electrically connected to each other. The system controller 130 is electrically connected, for example, to a driver IC 20, a head amplifier IC 30, volatile memory 70, non-volatile memory 80, a buffer memory 90, and a host system 100.
[0028] MPU40 is the main controller that controls the various parts of disk drive 1. MPU40 controls VCM14 via driver IC20 to perform servo control for positioning head 15. MPU40 controls SPM12 via driver IC20 to rotate disk 10. Additionally, MPU40 controls write operations (operations) that write data to disk 10 and selects the destination for data transferred from host 100, such as the write data's storage location. MPU40 controls read operations that read data from disk 10 and controls the processing of data transferred from disk 10 to host 100. Furthermore, MPU40 manages the areas where data is recorded. MPU40 performs processing based on firmware. Alternatively, MPU40 can also perform processing based on circuitry. MPU40 is connected to various parts of disk drive 1. MPU40 is electrically connected to, for example, driver IC20, R / W channel 50, and HDC60.
[0029] R / W channel 50 performs signal processing on data transferred from disk 10 to host 100 (hereinafter, sometimes referred to as read data) and data transferred from host 100 (hereinafter, sometimes referred to as write data) according to instructions from MPU 40. R / W channel 50 has circuitry or functions for modulating write data. R / W channel 50 has circuitry or functions for measuring and demodulating the signal quality of read data. R / W channel 50 is electrically connected, for example, to head amplifier IC 30, MPU 40, and HDC 60.
[0030] HDC60 controls data transmission according to instructions from MPU40. For example, HDC60 controls data transmission between host 100 and disk 10 according to instructions from MPU40. HDC60 is electrically connected to MPU40, R / W channel 50, volatile memory 70, non-volatile memory 80, buffer memory 90, and host 100, for example.
[0031] The HDC60 manages the key generations (or, sometimes referred to as encryption key generations) of encryption keys managed (acquired, generated, erased (discarded), and stored by the host 100, described later. The HDC60 uses the encryption keys managed by the host 100 to encrypt or decrypt predetermined data. The HDC60 stores the key generations of data encrypted or decrypted using the encryption keys managed by the host 100 as a table in a predetermined non-volatile record area. The HDC60 cannot manage (acquire, generate, discard (erase), and store) encryption keys.
[0032] Host 100 manages (acquires, generates, erases (discards), and stores) encryption keys. Host 100 stores encryption keys for a predetermined key generation and the information associated with the corresponding LBA (Logical Block Address) (hereinafter sometimes referred to as LBA information). Host 100 acquires the encryption key for the predetermined key generation and transmits the encryption key and the corresponding LBA information to HDC60. Additionally, HDC60 discards (erases) the encryption key and the corresponding LBA information for the predetermined key generation.
[0033] Figure 2 This is a block diagram illustrating a configuration example of the HDC60 and host 100 involved in this embodiment.
[0034] The host 100 has an encryption key storage circuit 1001 and an encryption key management circuit 1002, etc.
[0035] The encryption key storage circuit 1001 stores multiple encryption keys and their corresponding LBA information for each LBA (Logical Block Address). In other words, the encryption key storage circuit 1001 stores encryption keys for multiple key generations and their corresponding LBA information for each LBA.
[0036] The encryption key management circuit 1002 manages (acquires, generates, erases (discards), and stores) encryption keys. Based on the LBA information of the data, the encryption key management circuit 1002 obtains the encryption key from the encryption key storage circuit 1001. In other words, based on the LBA information of the data, the encryption key management circuit 1002 obtains the encryption key for a predetermined key generation and the corresponding LBA information from the encryption key storage circuit 1001. The encryption key management circuit 1002 transmits (or sends) the encryption key and the corresponding LBA information obtained from the encryption key storage circuit 1001 to the HDC 60 of the disk drive 1 (e.g., the encryption circuit 601 described later). After the power supply to disk device 1 changes from OFF to ON, authentication between host 100 and disk device 1 is performed. After authentication, encryption key management circuit 1002 transmits information corresponding to an index (e.g., LBA range) (hereinafter sometimes referred to as LBA range information) and an encryption key corresponding to that index (e.g., LBA range) to HDC 60 (specifically, encryption circuit 601 described later). LBA range information may also be included within LBA information. Encryption key management circuit 1002 erases (or discards) the encryption key and the LBA information corresponding to the encryption key. For example, encryption key management circuit 1002 erases (or discards) the encryption key for a predetermined key generation and the LBA information corresponding to the encryption key for that predetermined key generation.
[0037] The HDC60 includes an encryption circuit 601, a key generation insertion / confirmation circuit 602, a key generation storage circuit 603, and a key generation control circuit 604. Furthermore, the HDC60 can also execute the processing of each component, such as the encryption circuit 601, the key generation insertion / confirmation circuit 602, the key generation storage circuit 603, and the key generation control circuit 604, on the firmware.
[0038] Encryption circuit 601 encrypts and decrypts data using an encryption key. Encryption circuit 601 transmits (or sends) data corresponding to predetermined LBA information, encrypted with an encryption key within a predetermined LBA range, to key generation insertion / confirmation circuit 602 and / or key generation control circuit 604, etc. Additionally, encryption circuit 601 performs a process of rewriting data to specified data (hereinafter sometimes simply referred to as rewriting process). When power is switched from off to on, encryption circuit 601 stores the index, such as LBA range information, and the encryption key corresponding to that index, such as LBA range, transmitted from host 100 in a volatile recording area, such as volatile memory 70, which becomes valid only during transmission.
[0039] The key generation insertion / acknowledgment circuit 602 receives data corresponding to predetermined LBA information, which has been encrypted in the encryption circuit 601 using an encryption key within a predetermined LBA range. The key generation control circuit 604 appends the key generation of the encryption key within the predetermined LBA range used for encryption to the data corresponding to the predetermined LBA information. The data with the appended key generation corresponding to the LBA information is then written to a predetermined area of a recording medium, such as a disk 10, via the R / W channel 50, the head amplifier IC 30, and the head 15. Alternatively, the recording medium 10 may not be a disk, but a non-volatile memory. Upon receiving data (read data) from the disk 10 containing key generation information, such as information associated with a predetermined area of the disk 10 being written (hereinafter sometimes referred to as keygen_media), the key generation insertion / acknowledgment circuit 602 transmits the LBA information of the read data to the key generation control circuit 604 and receives from the key generation control circuit 604 the key generation information of the encryption key corresponding to the LBA information of the read data, such as the key generation (keygen). The key generation insertion / verification circuit 602 verifies (or determines) whether the key generation information corresponding to the LBA information of the read data, such as keygen and keygen_media, is consistent with the key generation information corresponding to the LBA information range contained in the LBA information obtained in advance when encrypting the data with the LBA information using an encryption key corresponding to the LBA range contained in the LBA information (hereinafter, for ease of explanation, it is sometimes simply referred to as "pre-obtained"). If the key generation insertion / verification circuit 602 determines that the key generation information (e.g., keygen and keygen_media) corresponding to the LBA information of the read data is consistent with the pre-obtained key generation information corresponding to the LBA range contained in the LBA information, the key generation insertion / verification circuit 602 appends a flag indicating that the key generation information corresponding to the LBA information of the read data is consistent with the pre-obtained key generation information corresponding to the LBA range contained in the LBA information (hereinafter, sometimes referred to as a consistency flag) to the read data, and performs decryption processing on the read data using an encryption key of the key generation corresponding to the LBA range contained in the LBA information of the read data through the encryption circuit 601. If the key generation insertion / acknowledgment circuit 602 determines that the key generation information (e.g., kyegen and keygen_media) corresponding to the LBA information of the read data is inconsistent with the key generation information corresponding to the LBA range containing the LBA information obtained in advance, it appends a flag (hereinafter sometimes referred to as an inconsistency flag) to the read data indicating that the key generation information corresponding to the LBA information of the read data is inconsistent with the key generation information corresponding to the LBA information obtained in advance and the key generation information corresponding to the LBA range containing the LBA information obtained in advance, and performs rewriting processing on the read data through the encryption circuit 601.
[0040] The key generation storage circuit 603 stores an index (e.g., an LBA range), key generation confirmation information corresponding to the index (e.g., an LBA range), and key generation information corresponding to the index (e.g., an LBA range). The information stored in the key generation storage circuit 603 is stored in a non-volatile recording area. The key generation storage circuit 603 can also be a non-volatile recording area, such as non-volatile memory 80.
[0041] The key generation control circuit 604 controls the key generation of the encryption key. The key generation control circuit 604 appends the key generation of the encryption key within a predetermined LBA range to the data corresponding to the predetermined LBA. Based on the LBA information received from the key generation insertion / confirmation circuit 602, the key generation control circuit 604 obtains the key generation information (keygen) of the encryption key corresponding to the LBA information from the key generation storage circuit 603, and transmits the obtained key generation information (keygen) of the encryption key corresponding to the LBA information to the key generation insertion / confirmation circuit 602.
[0042] The key generation control circuit 604 manages and updates the key generation of the encryption key. The key generation control circuit 604 manages and updates the key generation of the encryption key based on information generated from the encryption key that cannot be generated, calculated, predicted, or estimated. For example, the key generation control circuit manages and updates the key generation of the encryption key based on key generation confirmation information generated from the encryption key corresponding to predetermined LBA information (e.g., LBA) that cannot be generated, calculated, predicted, or estimated.
[0043] For example, the key generation control circuit 604, via the encryption circuit 601, encrypts a specific data pattern (hereinafter sometimes referred to as a fixed data pattern or fixed data) transmitted from the MPU40 with an encryption key corresponding to a predetermined index, such as an LBA range and a predetermined key generation, and stores the value of the fixed data (hereinafter sometimes referred to as the encrypted data value) encrypted with the encryption key corresponding to the predetermined index, such as an LBA range and a predetermined key generation as key generation confirmation information in the key generation storage circuit 603.
[0044] For example, when the key generation control circuit 604 receives upgrade information from the host 100 indicating that the encryption key has been upgraded or changed, and an index (e.g., LBA range) of the encryption key associated with the upgrade information, the key generation storage circuit 603 determines whether the key generation storage circuit 603 has stored key generation confirmation information, such as encrypted data value, corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information. If it is determined that the key generation storage circuit 603 has not stored key generation confirmation information, such as encrypted data value, corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, the key generation control circuit 604 stores the key generation confirmation information, such as encrypted data value, corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation new key associated with the encryption key associated with the upgrade information in the key generation storage circuit 603. If the key generation storage circuit 603 determines that it stores key generation confirmation information, such as encrypted data value, corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, the key generation control circuit 604 changes or updates the key generation of the key generation stored in the key generation storage circuit 603 to the key generation confirmation information (e.g., encrypted data value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation of the encryption key associated with the upgrade information, to the key generation confirmation information (e.g., encrypted data value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation corresponding to the encryption key associated with the upgrade information.
[0045] For example, when the key generation control circuit 604 receives upgrade information from the host 100 and an index (e.g., LBA range) set in the encryption key associated with the upgrade information, it retrieves key generation confirmation information (e.g., encrypted data value) from the key generation storage circuit 603 that corresponds to the same index (e.g., LBA range) set in the encryption key associated with the upgrade information. Based on the encryption key associated with the upgrade information retrieved from the host 100, the key generation control circuit 604 decrypts the key generation confirmation information (e.g., encrypted data value) retrieved from the key generation storage circuit 603 that corresponds to the index (e.g., LBA range) set in the encryption key associated with the upgrade information, and determines whether the decrypted key generation confirmation information (e.g., encrypted data value) (hereinafter, sometimes referred to as decrypted data) is consistent with the fixed data pattern transmitted from the MPU 40. When the key generation control circuit 604 determines that the decrypted data and the fixed data mode are consistent, the key generation storage circuit 603 does not update the key generation confirmation information (e.g., the encrypted data value) corresponding to the index (e.g., the LBA range) of the encryption key associated with the upgrade information, or the key generation corresponding to the index (e.g., the LBA range) of the encryption key associated with the upgrade information. Conversely, when the key generation control circuit 604 determines that the decrypted data and the fixed data mode are inconsistent, the key generation storage circuit 603 changes or updates the key generation confirmation information (e.g., the encrypted data value) corresponding to the index (e.g., the LBA range) of the encryption key associated with the upgrade information, or the key generation corresponding to the index (e.g., the LBA range) of the encryption key associated with the upgrade information.
[0046] The following is for reference Figure 3 , Figure 4 as well as Figure 5 The method for updating the key generation is explained.
[0047] Figure 3 This is a schematic diagram illustrating an example of a key generation update method for an encryption key with a predetermined LBA range involved in an implementation method. Figure 3 In the example shown, the key generation storage circuit 603 has a table TB. Table TB contains LBA ranges, encrypted data values corresponding to the LBA ranges, and key generations of the encrypted keys corresponding to the LBA ranges. Figure 3In Table TB, the LBA range includes 0–100, 101–200, 201–300, 301–400, …, global. The encrypted data values in Table TB include encrypted data value A corresponding to LBA range 0–100, encrypted data value B corresponding to LBA range 101–200, encrypted data value C corresponding to LBA range 201–300, encrypted data value D corresponding to LBA range 301–400, …, and encrypted data value N corresponding to LBA range global. The key generations in Table TB include keygeneration A corresponding to LBA range 0–100, keygeneration B corresponding to LBA range 101–200, keygeneration C corresponding to LBA range 201–300, keygeneration D corresponding to LBA range 301–400, …, and keygeneration N corresponding to LBA range global.
[0048] exist Figure 3 In the example shown, when HDC60 receives upgrade information from host 100 and the LBA=110 of the encryption key B associated with the upgrade information, it retrieves the encrypted data value B from table TB of key generation storage circuit 603, which corresponds to the LBA range 101-200 containing the LBA set to 110 of the encryption key B associated with the upgrade information. Based on the encryption key B associated with the upgrade information obtained from host 100, HDC60 decrypts the encrypted data value B obtained from table TB of key generation storage circuit 603 to obtain decrypted data, and determines whether the decrypted data is consistent with the fixed data pattern transmitted from MPU40. If HDC60 determines that the decrypted data is consistent with the fixed data pattern, it will not update the encrypted data value B corresponding to the LBA range 101 to 200 containing the LBA=110 of the encryption key B associated with the upgrade information, and the key generation keygenB corresponding to the LBA range 101 to 200 containing the LBA=110 of the encryption key B associated with the upgrade information in the table TB of the key generation storage circuit 603.
[0049] Figure 4 as well as Figure 5 This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation. Figure 4 as well as Figure 5 and Figure 3 Corresponding. In Figure 5In Table TB, the encrypted data values include encrypted data value A corresponding to the LBA range 0-100, encrypted data value F corresponding to the LBA range 101-200, encrypted data value C corresponding to the LBA range 201-300, encrypted data value D corresponding to the LBA range 301-400, ..., encrypted data value N corresponding to the LBA range global. The key generations in Table TB include key generations keygenA corresponding to the LBA range 0-100, keygenF corresponding to the LBA range 101-200, keygenC corresponding to the LBA range 201-300, keygenD corresponding to the LBA range 301-400, ..., keygenN corresponding to the LBA range global.
[0050] exist Figure 4 In the example shown, when HDC60 receives upgrade information from host 100 and the LBA=110 of the encryption key F associated with the upgrade information, it retrieves the encrypted data value F from table TB of key generation storage circuit 603, which corresponds to the LBA range 101-200 containing the LBA set to 110 of the encryption key F associated with the upgrade information. Based on the encryption key F associated with the upgrade information obtained from host 100, HDC60 decrypts the encrypted data value B obtained from table TB of key generation storage circuit 603 to obtain decrypted data, and determines whether the decrypted data is consistent with the fixed data pattern transmitted from MPU40.
[0051] like Figure 4 as well as Figure 5 As shown, when HDC60 determines that the decrypted data is inconsistent with the fixed data mode, it changes the encrypted data value B, which corresponds to the LBA range 101 to 200 of the encryption key F associated with the LBA=110 set with the encryption key F associated with the upgrade information, and the key generation keygenB, which corresponds to the LBA range 101 to 200 of the encryption key B associated with the upgrade information set with the LBA=110 set with the encryption key B associated with the upgrade information, to the encrypted data value F and the key generation keygenF in the table TB of the key generation storage circuit 603.
[0052] Figure 6 This is a flowchart illustrating an example of a method for updating the key generation of an encryption key according to this embodiment.
[0053] System controller 130 receives upgrade information and an LBA range or LBA set in the encryption key associated with the upgrade information from host 100 (B601). System controller 130 obtains key generation confirmation information corresponding to the same LBA range or LBA set in the encryption key associated with the upgrade information (B602). For example, system controller 130 obtains encrypted data value corresponding to the same LBA range or LBA set in the encryption key associated with the upgrade information. System controller 130 determines whether a predetermined value is consistent with key generation confirmation information generated based on the encryption key corresponding to the predetermined LBA information, and which cannot be generated, calculated, predicted, or estimated (B603). For example, system controller 130 determines whether a fixed data pattern transmitted from MPU 40 is consistent with decrypted data obtained by decrypting the encrypted data value corresponding to the same LBA range or LBA set in the encryption key associated with the upgrade information from table TB of key generation storage circuit 603.
[0054] If the predetermined value and key generation confirmation information are determined to be consistent (B603: Yes), the system controller 130 ends the process. For example, if the fixed data pattern and decrypted data are determined to be consistent, the system controller 130 does not change the AND and AND of the table TB of the key generation storage circuit 603, which are set to the LBA range of the encryption key associated with the upgrade information, or the same LBA range, or the encryption data value and key generation corresponding to the LBA, and ends the process.
[0055] If the predetermined value and key generation confirmation information are determined to be inconsistent (B603: No), the system controller 130 changes or updates the AND and SUM of table TB in the key generation storage circuit 603 to the LBA range of the encryption key associated with the upgrade information, or the same LBA range, or the key generation confirmation information and key generation corresponding to the LBA (B604), and ends the process. For example, if the fixed data pattern and decrypted data are determined to be inconsistent, the system controller 130 changes or updates the AND and SUM of table TB in the key generation storage circuit 603 to the LBA range of the encryption key associated with the upgrade information, or the same LBA range, or the encrypted data value and key generation corresponding to the LBA, and ends the process.
[0056] According to this embodiment, the disk drive 1 receives upgrade information and an LBA range or LBA set in the encryption key associated with the upgrade information from the host 100. The disk drive 1 obtains key generation confirmation information corresponding to the same LBA range or LBA set in the encryption key associated with the upgrade information. If the disk drive 1 determines that the key generation confirmation information generated based on the encryption key corresponding to the predetermined LBA information is inconsistent with the LBA range or LBA set in the encryption key associated with the upgrade information and cannot be generated, calculated, predicted, or estimated, the disk drive 1 changes the key generation confirmation information and key generation in the table TB of the key generation storage circuit 603, which corresponds to the same LBA range or LBA set in the encryption key associated with the upgrade information. Therefore, in the mode where the encryption key is managed by the host 100, the disk drive 1 can manage and update the key generation of the encryption key. Therefore, the disk drive 1 can improve security.
[0057] Next, a disk drive with modifications to the aforementioned embodiments will be described. In the modifications, the same reference numerals are used for the parts that are the same as in the aforementioned embodiments, and their detailed descriptions are omitted.
[0058] (Variation Example 1)
[0059] The difference between the disk device 1 of Variation 1 and the disk device 1 of the aforementioned embodiments is that the key generation update method is different.
[0060] For example, the key generation control circuit 604 generates a hash value for the encryption key corresponding to a predetermined index, such as an LBA range, and a predetermined key generation via the encryption circuit 601. The generated hash value is then stored as key generation confirmation information along with the index, such as the LBA range, and the key generation information (keygen) in the key generation storage circuit 603. The key generation control circuit 604, via the encryption circuit 601, uses a hash function, preferably a cryptographic hash function such as SHA1 / SHA2, or a one-way hash function, to generate a hash value (hereinafter sometimes referred to as the encryption key hash value or update hash value) for the encryption key corresponding to the predetermined index, such as an LBA range, and a predetermined key generation.
[0061] For example, when the key generation control circuit 604 receives upgrade information from the host 100 indicating that the encryption key has been upgraded or changed, and the corresponding index (e.g., LBA range) of the encryption key associated with the upgrade information, it determines whether the key generation storage circuit 603 has stored key generation confirmation information (e.g., encryption key hash value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information. If it is determined that the key generation storage circuit 603 has not stored the key generation confirmation information (e.g., encryption key hash value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, the key generation control circuit 604 stores the key generation confirmation information (e.g., encryption key hash value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation new key associated with the encryption key associated with the upgrade information in the key generation storage circuit 603. If the key generation storage circuit 603 determines that it stores key generation confirmation information, such as an encryption key hash value, corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, the key generation control circuit 604 changes or updates the key generation of the key generation stored in the key generation storage circuit 603 to the key generation confirmation information (e.g., encryption key hash value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation of the encryption key associated with the upgrade information, to the key generation confirmation information (e.g., encryption key hash value) corresponding to the index (e.g., LBA range) of the encryption key associated with the upgrade information, and the key generation of the encryption key associated with the upgrade information.
[0062] For example, when the key generation control circuit 604 receives upgrade information from the host 100 and an index (e.g., LBA range) set for the encryption key associated with the upgrade information, it retrieves key generation confirmation information (e.g., encryption key hash value) from the key generation storage circuit 603 that corresponds to the same index (e.g., LBA range) set for the encryption key associated with the upgrade information. The key generation control circuit 604 uses a hash function to hash the encryption key associated with the upgrade information within the same index (e.g., LBA range) to calculate an encryption key hash value (update hash value). The key generation control circuit 604 then determines whether the key generation confirmation information (e.g., encryption key hash value) and the update hash value obtained from the key generation storage circuit 603 that correspond to the same index (e.g., LBA range) set for the encryption key associated with the upgrade information are consistent. If the key generation control circuit 604 determines that the key generation confirmation information, such as the encryption key hash value, obtained from the key generation storage circuit 603 is consistent with the key generation confirmation information, such as the encryption key hash value, which is set to the same index, such as the LBA range of the encryption key associated with the upgrade information, and the key generation corresponding to the same index, such as the LBA range of the encryption key associated with the upgrade information, is not updated in the key generation storage circuit 603. If the key generation control circuit 604 determines that the key generation confirmation information (e.g., the encryption key hash value) and the updated hash value obtained from the key generation storage circuit 603 are inconsistent with the key generation confirmation information (e.g., the key generation confirmation information) corresponding to the same index (e.g., the LBA range) of the encryption key associated with the upgrade information, and the key generation corresponding to the same index (e.g., the LBA range) of the encryption key associated with the upgrade information, in the key generation storage circuit 603, the key generation control circuit 604 changes or updates the key generation confirmation information (e.g., the key generation confirmation information) corresponding to the same index (e.g., the key generation confirmation information) and the key generation corresponding to the same index (e.g., the key generation confirmation information) and the key generation corresponding to the same index (e.g., the key generation confirmation information) and the key generation confirmation information ...
[0063] The following is for reference Figure 7 , Figure 8 as well as Figure 9 The method for updating the key generation is explained.
[0064] Figure 7 This is a schematic diagram illustrating an example of a key generation update method for an encryption key with a predetermined LBA range involved in an implementation method. Figure 7 In the example shown, the key generation storage circuit 603 has a table TB. Table TB contains the LBA range, the hash value of the encryption key corresponding to the LBA range, and the key generation of the encryption key corresponding to the LBA range. Figure 7 In Table TB, the LBA range includes 0–100, 101–200, 201–300, 301–400, …, global. The encryption key hash values in Table TB include hash value A corresponding to the LBA range 0–100, hash value B corresponding to the LBA range 101–200, hash value C corresponding to the LBA range 201–300, hash value D corresponding to the LBA range 301–400, …, and hash value N corresponding to the LBA range global. The key generations in Table TB include key generation A corresponding to LBA range 0-100, key generation B corresponding to LBA range 101-200, key generation C corresponding to LBA range 201-300, key generation D corresponding to LBA range 301-400, ..., key generation N corresponding to LBA range global.
[0065] exist Figure 7 In the example shown, when HDC60 receives upgrade information and the LBA=110 of the encryption key B associated with the upgrade information from host 100, it retrieves the encryption key hash value B corresponding to the LBA range 101-200 containing the encryption key B associated with the upgrade information (LBA=110) from table TB of key generation storage circuit 603. HDC60 uses a hash function to hash the encryption key B corresponding to the upgrade information (LBA=110) to calculate the updated hash value B. HDC60 then determines whether the encryption key hash value B corresponding to the LBA range 101-200 containing the encryption key B associated with the upgrade information (LBA=110) obtained from key generation storage circuit 603 is consistent with the updated hash value B. If HDC60 determines that the hash value B corresponding to the LBA range 101-200 of the encryption key B with LBA=110 associated with the upgrade information and the updated hash value B are consistent, then HDC60 will not update the key generation keygenB in the table TB of the key generation storage circuit 603. This update will not include the hash value B corresponding to the LBA range 101-200 of the encryption key B with LBA=110 associated with the upgrade information and the key generation keygenB corresponding to the LBA range 101-200 of the encryption key B with LBA=110 associated with the upgrade information.
[0066] Figure 8 as well as Figure 9This is a schematic diagram illustrating an example of a key generation update method for a cryptographic key with a predetermined LBA range involved in an implementation. Figure 8 as well as Figure 9 and Figure 7 Corresponding. In Figure 9 In Table TB, the encryption key hash values include hash values A corresponding to the LBA range 0-100, F corresponding to the LBA range 101-200, C corresponding to the LBA range 201-300, D corresponding to the LBA range 301-400, ..., N corresponding to the LBA range global. The key generations in Table TB include key generations A corresponding to the LBA range 0-100, F corresponding to the LBA range 101-200, C corresponding to the LBA range 201-300, D corresponding to the LBA range 301-400, ..., N corresponding to the LBA range global.
[0067] exist Figure 8 In the example shown, when HDC60 receives upgrade information and the LBA=110 of the encryption key F associated with the upgrade information from host 100, it retrieves the hash value F of the encryption key corresponding to the LBA range 101-200 containing the LBA=110 of the encryption key F associated with the upgrade information from table TB of key generation storage circuit 603. HDC60 uses a hash function to hash the encryption key F with LBA=110 corresponding to the upgrade information to calculate the updated hash value F. HDC60 determines whether the hash value B of the encryption key corresponding to the LBA range 101-200 containing the LBA=110 of the encryption key F associated with the upgrade information obtained from key generation storage circuit 603 is consistent with the updated hash value F.
[0068] like Figure 8 as well as Figure 9As shown, when HDC60 determines that the hash value B corresponding to the LBA range 101-200 of the LBA=110 of the encryption key F associated with the upgrade information and the updated hash value F are inconsistent, HDC60 changes or updates the key generation keygen B corresponding to the LBA range 101-200 of the LBA=110 of the encryption key F associated with the upgrade information and the updated hash value F in the table TB of the key generation storage circuit 603.
[0069] According to Variation 1, the disk drive 1 receives upgrade information and an LBA range or LBA set in the encryption key associated with the upgrade information from the host 100. The disk drive 1 obtains key generation confirmation information corresponding to the same LBA range or LBA set in the encryption key associated with the upgrade information. If the disk drive 1 determines that the key generation confirmation information generated based on the encryption key corresponding to the predetermined LBA information is inconsistent with the LBA range or LBA set in the encryption key associated with the upgrade information, and cannot be generated, calculated, predicted, or estimated, the disk drive 1 changes the key generation confirmation information and key generation in the table TB of the key generation storage circuit 603, which corresponds to the same LBA range or LBA set in the encryption key associated with the upgrade information. Therefore, in the mode where the encryption key is managed by the host 100, the disk drive 1 can manage and update the key generation of the encryption key. Therefore, the disk drive 1 can improve security.
[0070] Several embodiments have been described, but these embodiments are provided as examples and are not intended to limit the scope of the invention. These new embodiments can be implemented in a wide variety of other ways, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and / or variations thereof are included within the scope and / or spirit of the invention, and are included within the scope of the invention described in the technical solution and its equivalents.
[0071] The following is an example of a disk device and a method for updating the key generation of the encryption key obtained from the configuration disclosed in this specification.
[0072] (1) A disk device comprising: a disk; a head for writing data to the disk and reading data from the disk; and a controller for managing a key generation of the encryption key based on generation confirmation information generated according to an encryption key and which cannot be generated, the encryption key being managed by an external device and transmitted from the external device.
[0073] (2) According to the disk device of (1), the controller has a table containing an LBA range, generation confirmation information corresponding to the LBA range, and key generation corresponding to the LBA range.
[0074] (3) According to the disk device of (2), when the controller receives from the external device a first upgrade information indicating an upgrade to the first encryption key in the encryption key and a first LBA range set in the first encryption key, it compares the first information and the first data associated with the first encryption key and corresponding to the first LBA range. If the first information and the first data are inconsistent, in the table, the first generation confirmation information in the generation confirmation information corresponding to the first LBA range and the first key generation corresponding to the first generation confirmation information are changed to the second generation confirmation information in the generation confirmation information associated with the first encryption key and the second key generation associated with the first encryption key, respectively.
[0075] (4) According to the disk device of (2), when the controller receives from the external device a first upgrade information indicating an upgrade to the first encryption key in the encryption key and a first LBA range set in the first encryption key, it compares the first information and the first data associated with the first encryption key and corresponding to the first LBA range. If the first information and the first data are consistent, the controller does not change the first generation confirmation information in the generation confirmation information corresponding to the first LBA range and the first key generation corresponding to the first generation confirmation information in the table.
[0076] (5) According to the disk device of (3) or (4), the generation confirmation information is a value obtained by encrypting a fixed data pattern with the encryption key, the first information is data obtained by decrypting the first generation confirmation information, and the first data is the fixed data pattern.
[0077] (6) According to the disk device described in (5), the controller decrypts the first generation confirmation information with the first encryption key to generate the first information.
[0078] (7) According to the disk device described in (3) or (4), the generation confirmation information is a hash value, the first information is a first hash value corresponding to the first generation confirmation information, and the first data is a second hash value obtained by hashing the first encryption key.
[0079] (8) According to the disk device described in (7), the controller performs a hash transformation on the first encryption key using a hash function to generate the first data.
[0080] (9) According to the disk device described in (8), the hash function is a cryptographic hash function or a one-way hash function.
[0081] (10) A method for changing the key generation of an encryption key, applied to a disk device having a disk and a head, wherein the head writes data to the disk and reads data from the disk, the method for changing the key generation of the encryption key includes: managing the key generation of the encryption key based on generation confirmation information generated according to the encryption key and unable to generate the encryption key, wherein the encryption key is managed by an external device and transmitted from the external device.
Claims
1. A disk device comprising: a disk; a head that writes data to the disk and reads data from the disk; and a controller that manages a key generation of an encryption key based on generation confirmation information that is generated according to the encryption key and that cannot generate the encryption key, the encryption key being managed by an external device and being transmitted from the external device, the controller having a table that includes a logical block address range (LBA range), the generation confirmation information corresponding to the LBA range, and the key generation corresponding to the LBA range, the controller, in a case where first upgrade information indicating upgrade to a first encryption key of the encryption keys and a first LBA range set to the first encryption key are received from the external device, comparing first information associated with the first encryption key and corresponding to the first LBA range and first data, in a case where the first information and the first data are not identical, changing, in the table, first generation confirmation information of the generation confirmation information corresponding to the first LBA range and a first key generation corresponding to the first generation confirmation information to second generation confirmation information associated with the first encryption key and a second key generation associated with the first encryption key, respectively.
2. The disk device according to claim 1, the controller, in a case where the first information and the first data are identical, not changing, in the table, the first generation confirmation information of the generation confirmation information corresponding to the first LBA range and the first key generation corresponding to the first generation confirmation information.
3. The disk device according to claim 1 or 2, the generation confirmation information being a value obtained by encrypting a fixed data pattern with the encryption key, the first information being data obtained by decrypting the first generation confirmation information, and the first data being the fixed data pattern.
4. The disk device according to claim 3, the controller decrypting the first generation confirmation information with the first encryption key to generate the first information.
5. The disk device according to claim 1 or 2, the generation confirmation information being a hash value, the first information being a first hash value corresponding to the first generation confirmation information, and the first data being a second hash value obtained by hash-transforming the first encryption key.
6. The disk device according to claim 5, the controller hash-transforming the first encryption key with a hash function to generate the first data.
7. The disk device according to claim 6, the hash function being a cryptographic hash function or a one-way hash function.
Citation Information
Patent Citations
Game machine
JP2021045391A
Storage virtualization apparatus comprising encryption functions
US20080240434A1
System and method for compaction-less key-value store for improving storage capacity, write amplification, and I / O performance
US20200225882A1