Method and storage system for protecting a partial space of an SSD

By dividing the SSD storage space into multiple regions and managing the area types, the problems of waste and complex operations of existing SSD encryption security protocols are solved, and the simple self-encryption and locking functions with low resource consumption are realized to meet the basic needs of end customers.

CN115509455BActive Publication Date: 2025-08-01INNOGRIT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211236522.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-10
Publication Date
2025-08-01
Estimated Expiration
2042-10-10

AI Technical Summary

Technical Problem

Although the existing SSD encryption security protocols such as Opal have diverse functions, they are seriously wasted resources in actual end-customer usage scenarios, high development and maintenance costs, and complex operations.

Method used

The storage space of the SSD is divided into multiple areas, and the area type is managed through the partition table, supporting three states: unlocked, unlocked and locked, providing simple self-encryption and locking functions, supporting dynamic adjustment of locking range and user permissions, and reducing operating resources.

Benefits of technology

It realizes SSD space protection with lower resource consumption, is simple to operate, and can clip functions to meet basic self-encryption and locking requirements, reducing development and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115509455B_ABST
    Figure CN115509455B_ABST
Patent Text Reader

Abstract

This application relates to the field of storage technologies, and discloses a method for protecting a partial space of an SSD and a storage system. The storage space of the SSD is divided into multiple regions and the SSD stores a partition table, where the partition table includes the region type of each region. The method includes: the SSD receives a command to read the partition table; the SSD obtains the partition table, deletes one or more regions with the region type of being locked from the partition table, and returns the partition table after deletion. This application provides a solution with simple implementation, self-encryption protection, fewer required operating resources, simple operation, strong functional portability, and can meet basic self-encryption and locking requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of solid-state storage technology, and particularly to a method for protecting a part of the SSD space and a storage system. Background Art

[0002] Currently, in the field of SSD encryption security, there are many common protocol applications. A relatively representative one is the Opal protocol under the TCG specification. It is a security standard specification formulated by the TCG, which defines security policies for protecting static data, including device self-encryption (SED, Self-Encrypting Drive) based on AES-128 or AES-256, user permission management, pre-boot authentication, etc. Since it uses hardware self-encryption technology, Opal will not affect the performance of the system. At the same time, it is independent of the operating system, and different operating systems and their vulnerabilities cannot affect it. It is an improvement of traditional self-encryption technology and one of the important specifications in the storage industry.

[0003] Opal can set multiple users of different categories and permissions, and divide the device into multiple locked ranges; each locked range, user configuration, and access permission are independent of each other, making it flexible to use; even if the device leaves the owner, it can prevent unauthorized access, protect the user's static data, and effectively reduce the risk of data leakage; it supports MEK deletion and can quickly and securely clear user data. In addition, Opal also has the characteristic of easy expansion and can support more user requests by adding new functions.

[0004] Opal has diverse functions and is flexible to use, but at the same time, its function implementation is relatively complex, resulting in relatively high development and maintenance costs. In actual end-user usage scenarios, only a very small part of its functions may be used, and most functions will not or rarely be used, which also causes unnecessary waste of device resources. Summary of the Invention

[0005] The purpose of this application is to provide a method for protecting a part of the SSD space, which requires less operating resources, is simple to operate, has strong function portability, and can meet basic self-encryption and locking requirements.

[0006] This application discloses a method for protecting a part of the SSD space. The storage space of the SSD is divided into multiple regions and the SSD stores a partition table, and the partition table includes the region type of each region. The method includes:

[0007] The SSD receives a command to read the partition table;

[0008] The SSD obtains the partition table, deletes one or more regions with the region type being locked from the partition table, and returns the partition table after deletion.

[0009] In a preferred example, the partition table includes partition planning information for each region, and the partition planning information includes a region type and start and end addresses. Deleting one or more regions with the region type being locked from the partition table includes: setting the partition planning information corresponding to the one or more regions with the region type being locked to a preset value.

[0010] In a preferred example, if the types of the one or more regions are all unlocked or not locked, the partition table is directly returned.

[0011] In a preferred example, the not-locked type indicates that the region can be read, written to, and erased, and the unlocked type indicates that the region can be read, written to, and not erased.

[0012] In a preferred example, the locked type indicates that the region cannot be read, written to, or erased.

[0013] This application also discloses an SSD storage system. The storage space of the SSD is divided into multiple regions and the SSD stores a partition table. The partition table includes the region type of each region; when the SSD receives a command to read the partition table, it obtains the partition table, deletes one or more regions with the region type being locked from the partition table, and returns the partition table after deletion.

[0014] In a preferred example, the partition table includes partition planning information for each region, and the partition planning information includes a region type and start and end addresses. Deleting one or more regions with the region type being locked from the partition table includes: setting the partition planning information corresponding to the one or more regions with the region type being locked to a preset value.

[0015] In a preferred example, if the types of the one or more regions are all unlocked or not locked, the partition table is directly returned.

[0016] In a preferred example, the SSD storage system has at least four states:

[0017] State 0: The SSD space is not divided into multiple regions;

[0018] State 1: The SSD space is divided into multiple regions, and each region is not locked;

[0019] State 2: The SSD space is divided into multiple regions, and at least one region is locked and has been unlocked;

[0020] State 3: The SSD space is divided into multiple regions, and at least one region is locked.

[0021] In a preferred example, the unlocked type means that the region can be read, written, and erased, the unlocked type means that the region can be read, written, and not erased, and the locked type means that the region cannot be read, written, or erased.

[0022] In the embodiments of the present application, compared with Opal, it requires fewer running resources, is simple to operate, has strong function portability, and can meet basic self-encryption and locking requirements. At the same time, according to customer needs, the functions can be trimmed. For example, in the case of low security requirements, if only the user access permission management function is required, then the self-encryption function can be removed to further reduce the running resource overhead.

[0023] A large number of technical features are recorded in the specification of the present application, distributed in various technical solutions. If all possible combinations of technical features (i.e., technical solutions) of the present application are listed, the specification will be too long. To avoid this problem, each technical feature disclosed in the above-mentioned invention content of the present application, each technical feature disclosed in the following embodiments and examples, and each technical feature disclosed in the drawings can be freely combined with each other to form various new technical solutions (these technical solutions should all be regarded as having been recorded in this specification), unless the combination of such technical features is technically infeasible. For example, in one example, features A + B + C are disclosed, and in another example, features A + B + D + E are disclosed, and features C and D are equivalent technical means that play the same role. Technically, only one of them can be used and it is impossible to use both at the same time. Feature E can be combined with feature C technically. Then, the solution of A + B + C + D should not be regarded as having been recorded because it is technically infeasible, while the solution of A + B + C + E should be regarded as having been recorded. Brief Description of the Drawings

[0024] Figure 1 It is a schematic flowchart of a method for protecting a partial space of an SSD according to an embodiment of the present application.

[0025] Figure 2 It is a schematic diagram of the SSD space in State 1 according to an embodiment of the present application.

[0026] Figure 3 It is a schematic diagram of the SSD space in State 2 according to an embodiment of the present application.

[0027] Figure 4 It is a schematic diagram of the SSD space in State 3 according to an embodiment of the present application.

[0028] Figure 5It is a schematic diagram of the conversion of an SSD between various states according to an embodiment of the present application.

[0029] Figure 6 It is a block diagram of an SSD storage system according to an embodiment of the present application. Detailed implementation manners

[0030] In the following description, many technical details are provided to help the reader better understand the present application. However, those of ordinary skill in the art can understand that the technical solutions claimed in the present application can be implemented even without these technical details and various changes and modifications based on the following embodiments.

[0031] To make the objectives, technical solutions, and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0032] The present application discloses a method for protecting a part of the space of an SSD. The storage space of the SSD can be divided into multiple regions, and the SSD stores a partition table, and the partition table includes the region type of each region. Specifically, in one embodiment, the partition table may include partition planning information of each region, where the partition planning information includes a region type and start and end addresses. In one embodiment, the region type may include unlocked, locked, and un-locked, etc. Among them, the locked type indicates that the region cannot be read, written, or erased. The unlocked type indicates that the region can be read, written, and erased, and the un-locked type indicates that the region can be read, written, but cannot be erased.

[0033] Figure 1 It shows a flowchart of a method for protecting a part of the space of an SSD in one embodiment. The method includes the following steps:

[0034] Step 101, the SSD receives a command to read the partition table.

[0035] Step 102, the SSD obtains the partition table, deletes one or more regions with the region type of locked from the partition table, and returns the deleted partition table.

[0036] In one embodiment, deleting one or more regions with the region type of locked from the partition table includes: setting the partition planning information corresponding to one or more regions with the region type of locked to a preset value. For example, setting the partition planning information corresponding to one or more regions with the region type of locked to zero.

[0037] In addition, in one embodiment, if the types of the one or more regions are all un-locked or unlocked, that is, none of the regions are locked, the partition table is directly returned.

[0038] To better understand the technical solution of this application, a specific example is given below for illustration. The details listed in this example are mainly for easy understanding and do not limit the protection scope of this application.

[0039] This application designs a solution that is simple to implement and can self-encrypt and protect at the same time. Its main functions are as follows:

[0040] 1. It has a dynamically adjustable locking range, which can only be accessed by specific permissions, and the data within the range is self-encrypted and protected by the device;

[0041] 2. The access permissions of users are divided into three levels. Ordinary users can only be allowed to access the non-locked range of space; ordinary encrypted users can access all range of space; in addition to accessing all spaces, administrator (Admin) users can also manage the keys of ordinary encrypted users, adjust the locking range, and the function of wiping all data on the disk;

[0042] 3. When the locked space switches between the locked and unlocked states, it can automatically hide and display the locked partitions;

[0043] 4. It has a storage space for administrator information, which is used to store important user information. For example, when the password is forgotten, the administrator can retrieve the password.

[0044] The host of this application provides the following commands to the SSD:

[0045] 1. Set password

[0046] It is used to set the passwords of ordinary users (User) and administrator (Admin) users, and input the security information for retrieving the password, and at the same time enable the locking function.

[0047] 2. Unlock

[0048] It is used to unlock the locked logical block address (LBA) range;

[0049] 3. Set lock range

[0050] It is used to set the LBA range that needs to be locked;

[0051] 4. Disable password

[0052] Delete the current general user password and disable the locking function at the same time;

[0053] 5. Enable / disable LBA0 read only

[0054] Set LBA0 to read-only or remove it from read-only mode to prevent users without permission from modifying the disk partition information.

[0055] Depending on the command executed, the SSD will display the following different states. The following examples assume that the SSD disk partitions have been set up. For example, LBA0 to LBAn on the disk are set as partition A, LBAn+1 to LBAm on the disk are set as partition B, and the LBA range to be locked is set to disk partition B using the Set lock range command.

[0056] Status 0: The disk has no partitions and is in factory default state.

[0057] Status 1: The status when the lock function is not enabled, such as Figure 2 shown

[0058] Status 2: Locking is enabled, but the locked partition is in unlocked state, such as Figure 3 shown

[0059] Status 3: Locking is enabled and the partition is locked. In this state, the host cannot see disk partition B and can only see disk partition A. Figure 4 In order to allow the host to see the unlocked partitions, the partition table information is dynamically modified when the host queries the partition information so that the host can only see the unlocked and unlocked partitions. When partition B is locked,

[0060] Status 4: Read only LBA0.

[0061] The responses to host commands in various states are shown in Table 1 below. In addition, the host uses the state machine to make the SSD switch between the states described above, such as Figure 5 shown.

[0062] Table 1 SSD response to host commands in various states

[0063]

[0064] This application can automatically hide and display the locked partition when switching between locked and unlocked states. Taking MBR format partition as an example, the following table 2 shows the MBR standard structure information:

[0065] Table 2 MBR standard structure information

[0066]

[0067] After the SSD device determines the locked partition by the lock information stored in the NAND flash, it sets the 16-byte content of the corresponding primary partition in the partition table plan column to 0, and then sends the modified partition table back to the host. In this way, the host will only see the unlocked partitions. Among them, the lock information stored in the NAND flash is actively saved when the host executes commands such as setting passwords or deleting passwords during the previous power-on stage, and this information will not be lost due to power failure.

[0068] Another aspect of the present application also relates to an SSD storage system. Figure 6 FIG. 600 shows a storage system 600 according to an embodiment of the present disclosure. The storage system 600 may include storage grains 604 and a memory controller 602 coupled to the storage grains 604. When the memory controller 602 is coupled to a host, it can provide data storage and / or access to the stored data for the host. The memory controller 502 according to this embodiment receives a control signal and executes an operation corresponding to the control signal. The storage grains 604 send the execution result of the operation corresponding to the control signal to the memory controller 602. The storage grains 604 may be a storage device based on non-volatile memory (NVM), for example, may include NAND flash, NOR flash, magnetoresistive random access memory (MRAM), resistive random access memory (RRAM), phase change random access memory (PCRAM), Nano-RAM, and so on. NAND flash can be used as an example. It should be noted that the storage system 600 may include multiple storage grains, and the storage grains 604 may be shown as a representative of multiple storage grains.

[0069] The storage space of the SSD is divided into multiple regions and the SSD stores a partition table, and the partition table includes the region type of each region. When the SSD receives a command to read the partition table, it obtains the partition table, deletes one or more regions with the region type being locked from the partition table, for example, sets the partition plan information corresponding to one or more regions with the region type being locked to a preset value. Then, it returns the deleted partition table. If the types of the one or more regions are all unlocked or not locked, it directly returns the partition table.

[0070] In one embodiment, the SSD storage system has at least four states:

[0071] State 0: The SSD space is not divided into multiple regions;

[0072] State 1: The SSD space is divided into multiple regions, and each region is not locked;

[0073] Status 2: The SSD space is divided into multiple regions, and at least one region is locked and then unlocked;

[0074] Status 3: The SSD space is divided into multiple regions, and at least one region is locked.

[0075] In one embodiment, the unlocked type means that the region can be read, written, and erased, the unlocked type means that the region can be read, written, but not erased, and the locked type means that the region cannot be read, written, or erased.

[0076] It should be noted that in the application documents of this patent, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one" does not exclude the existence of additional identical elements in the process, method, article or device comprising the element. In the application documents of this patent, if it is mentioned that an action or step is performed according to a certain element, it means at least performing the action according to the element, including two cases: performing the action only according to the element, and performing the action according to the element and other elements. Expressions such as multiple, multiple times, and multiple types include 2, 2 times, 2 types, as well as more than 2, more than 2 times, and more than 2 types.

[0077] All documents mentioned in this specification are considered to be integrally included in the disclosure of this application so that they can be used as a basis for modification when necessary. In addition, it should be understood that the above are only preferred embodiments of this specification and are not used to limit the protection scope of this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the protection scope of one or more embodiments of this specification.

[0078] In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. A method for protecting a part of the space of an SSD, characterized in that, The storage space of the SSD is divided into multiple regions and the SSD stores a partition table, the partition table including the region type of each region, the method comprising: The SSD receives a command to read the partition table; The SSD obtains the partition table, deletes one or more regions with the region type being locked from the partition table, and returns the partition table after deletion.

2. The method for protecting a partial space of an SSD according to claim 1, wherein The partition table includes partition planning information of each region, the partition planning information including the region type and start and end addresses, and deleting one or more regions with the region type being locked from the partition table includes: setting the partition planning information corresponding to the one or more regions with the region type being locked to a preset value.

3. The method for protecting a partial space of an SSD according to claim 1, wherein If the types of the one or more regions are all unlocked or not locked, directly return the partition table.

4. The method for protecting a partial space of an SSD according to claim 3, characterized in that, The not-locked type indicates that the region can be read, written to, and erased, and the unlocked type indicates that the region can be read, written to, and not erased.

5. The method for protecting a partial space of an SSD according to claim 1, wherein, The locked type indicates that the region cannot be read, written to, or erased.

6. An SSD storage system, characterized in that, The storage space of the SSD is divided into multiple regions and the SSD stores a partition table, the partition table including the region type of each region; When the SSD receives a command to read the partition table, it obtains the partition table, deletes one or more regions with the region type being locked from the partition table, and returns the partition table after deletion.

7. The SSD storage system according to claim 6, wherein The partition table includes partition planning information of each region, the partition planning information including the region type and start and end addresses, and deleting one or more regions with the region type being locked from the partition table includes: setting the partition planning information corresponding to the one or more regions with the region type being locked to a preset value.

8. The SSD storage system according to claim 6, wherein If the types of the one or more regions are all unlocked or not locked, directly return the partition table.

9. The SSD storage system according to claim 6, characterized in that, The SSD storage system has at least four states: State 0: The SSD space is not divided into multiple regions; State 1: The SSD space is divided into multiple regions, and each region is not locked; State 2: The SSD space is divided into multiple regions, and at least one region is locked and has been unlocked; State 3: The SSD space is divided into multiple regions, and at least one region is locked.

10. The SSD storage system according to claim 9, wherein The not-locked type indicates that the region can be read, written to, and erased, the unlocked type indicates that the region can be read, written to, and not erased, and the locked type indicates that the region cannot be read, written to, or erased.

Citation Information

Patent Citations

  • Storage device

    CN112861194A

  • Host Device and Method for Partitioning Attributes in a Storage Device

    US20130173931A1