Solid state disk, method for controlling access of solid state disk, and electronic device

By introducing access-limiting circuitry and key verification mechanisms into solid-state drives (SSDs), the number of accesses is limited, thus solving the data security problem of SSDs in special scenarios and achieving secure control by locking the flash array after the access limit is reached.

CN115659425BActive Publication Date: 2026-04-21INST OF MICROELECTRONICS CHINESE ACAD OF SCI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INST OF MICROELECTRONICS CHINESE ACAD OF SCI LTD
Filing Date
2022-10-27
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing solid-state drives lack effective access security controls in certain special scenarios, resulting in insufficient data security.

Method used

Introducing a limit access circuit into a solid-state drive (SSD), including a limit counter, a first logic gate circuit, and a state machine, limits the number of accesses and combines it with a key memory and an XOR operation logic circuit for security verification, thus prohibiting accesses exceeding the limit.

Benefits of technology

It effectively improves the data security of solid-state drives, ensuring that the flash array is locked after the access limit is reached to prevent further access, and is suitable for scenarios with high data security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115659425B_ABST
    Figure CN115659425B_ABST
Patent Text Reader

Abstract

The application discloses a solid state disk, a limited access control method thereof and electronic equipment, and relates to the technical field of solid state disks. The solid state disk comprises a main control chip, a flash memory array and a limited access circuit. The main control chip comprises a host interface controller, a central processing unit and a flash memory controller. The limited access circuit comprises a limited access counter, a first logic gate circuit and a state machine. The initialization data of each storage unit of the limited access counter is "1". The first logic gate circuit performs OR operation on the multi-bit count data read from each storage unit of the limited access counter, and transmits the OR operation result to the state machine. The state machine writes a "0" value into the limited access counter every time the host accesses the flash memory array once. When the OR operation result is "0", the state machine prohibits the host from accessing the flash memory array. In this way, an upper limit value can be set for the access times of the flash memory array in the solid state disk, and the safety of the data of the solid state disk is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of memory technology, and in particular to a solid-state drive and its limited access control method and electronic device. Background Technology

[0002] Solid-state drives (SSDs) are a replacement for traditional hard disk drives (HDDs). A typical SSD (Solid State Disk or Solid State Drive) internally includes a controller chip, DDR memory chips, NAND Flash memory chips (also simply referred to as "flash memory"), and SPI Flash chips. Key SSD specifications include data capacity and data retention time. As a data storage medium, secure access control is crucial for SSDs in certain scenarios. Summary of the Invention

[0003] The present invention provides a solid-state drive and a limited access control method and electronic device thereof, which can effectively improve the data security of the solid-state drive.

[0004] In a first aspect, embodiments of the present invention provide a solid-state drive, comprising: a controller chip, a flash memory array, and a limited access circuit, wherein...

[0005] The main control chip includes: a host interface controller, a central processing unit, and a flash memory controller. The host interface controller, the central processing unit, and the flash memory controller are connected via a bus, and the flash memory controller is connected to the flash memory array.

[0006] The limited access circuit includes: a limited access counter, a first logic gate circuit, and a state machine;

[0007] The limit counter includes multiple storage units, all of which are initialized with "1". Each data readout terminal of the limit counter is connected to the input terminal of the first logic gate circuit. The data operation terminal of the limit counter and the output terminal of the first logic gate circuit are both connected to the state machine.

[0008] The first logic gate circuit is used to perform an OR operation on the multi-bit count data read from the plurality of memory cells respectively, and transmit the OR operation result to the state machine;

[0009] The state machine is configured to write a "0" value to the limit counter every time the host accesses the flash array, and to prohibit the host from accessing the flash array when the OR operation result is detected to be "0".

[0010] Furthermore, the limited access circuit also includes: a second logic gate circuit and a key memory for storing the externally written key.

[0011] The first input terminal of the second logic gate is connected to the data read terminal of the key memory, and the second input terminal of the second logic gate is connected to the supply terminal of the preset security key.

[0012] The data operation terminal of the key memory and the output terminal of the second logic gate circuit are connected to the state machine.

[0013] The second logic gate is used to perform an XOR operation on the externally written key and the preset security key, and transmit the XOR operation result to the state machine;

[0014] The state machine is further configured to, when the XOR operation result is detected to be "1", prohibit the host from accessing the flash memory array and allow erasing and programming operations on the limit counter and the key memory; when the XOR operation result is detected to be "0" and the OR operation result is "1", allow the host to access the flash memory array and allow programming operations on the limit counter, prohibit erasing operations on the limit counter, and prohibit erasing and programming operations on the key memory.

[0015] Furthermore, the number of first input terminals and the number of second input terminals of the second logic gate circuit are the same as the data bit width of the key memory, and each second input terminal is connected to a high-level voltage terminal or a low-level voltage terminal according to the preset security key.

[0016] Furthermore, the state machine is connected to the bus.

[0017] Furthermore, the state machine is connected to the flash memory controller.

[0018] Furthermore, the state machine is connected to the host interface controller.

[0019] Secondly, embodiments of the present invention provide an electronic device, including a host and a solid-state drive as described in the first aspect, wherein the host is connected to a host interface controller of the solid-state drive to access the solid-state drive.

[0020] Thirdly, embodiments of the present invention provide a limited access control method for a solid-state drive (SSD). The SSD includes: a main control chip, a flash memory array, and a limited access circuit. The limited access circuit includes: a limited access counter, a first logic gate circuit, and a state machine. The limited access counter includes multiple storage units, all of which are initialized with "1". The data readout terminal of the limited access counter is connected to the input terminal of the first logic gate circuit. The data operation terminal of the limited access counter and the output terminal of the first logic gate circuit are respectively connected to the state machine. The method includes:

[0021] In user mode, monitor the host's access operations to the flash array;

[0022] Each time the host accesses the flash array, a value of "0" is written to the limit counter;

[0023] If the OR operation result of the first logic gate is detected to be "0", then the host is prohibited from accessing the flash memory array.

[0024] Furthermore, before entering the user mode, the method further includes: performing an initialization configuration operation, the initialization configuration operation including:

[0025] A data erasure operation is performed on the limit counter so that the data stored in the multiple storage units are all initialized to "1".

[0026] Furthermore, the limited access circuit further includes: a second logic gate circuit and a key memory for storing an externally written key. The first input terminal of the second logic gate circuit is connected to the data read terminal of the key memory, and the second input terminal of the second logic gate circuit is connected to the supply terminal of a preset security key. The data operation terminal of the key memory and the output terminal of the second logic gate circuit are connected to the state machine. Before entering the user mode, the method further includes: performing an initialization configuration operation, which includes:

[0027] After the solid-state drive is powered on, the XOR operation result of the output of the second logic gate circuit is monitored;

[0028] If the result of the XOR operation is 1, then the limit counter and the key memory are allowed to be erased and programmed. The limit counter and the key memory are erased to initialize the data stored in the limit counter and the key memory to "1". In response to the key write command sent by the host, the externally input key data is written into the key memory.

[0029] If the XOR operation result is "0", then the host access channel to the flash array is enabled, the user mode is entered, and the erasure operation of the limit counter is prohibited, the erasure and programming operation of the key memory is prohibited, and the monitoring of the OR operation result of the first logic gate circuit is enabled.

[0030] The solid-state drive (SSD) provided in this embodiment of the invention adds a limited access circuit. This circuit includes a limited access counter, a first logic gate circuit, and a state machine. The initialization data for each storage cell of the limited access counter is "1". The first logic gate circuit performs an OR operation on the multi-bit count data read from each storage cell of the limited access counter and transmits the result to the state machine. Each time the state machine detects a host access to the flash memory array, it writes a "0" value to the limited access counter. When the OR operation result is detected as "0", it determines that the maximum access count has been reached and prohibits the host from accessing the flash memory array again. This allows setting an upper limit on the number of accesses to the flash memory array in the SSD (the upper limit is the data width of the limited access counter). When the access count reaches this upper limit, the flash memory array access function of the SSD is locked, and it no longer responds to user read / write access requests, effectively improving the security of SSD data. This can be applied to scenarios with high data security requirements. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 This diagram illustrates the structure of a solid-state drive provided in the first aspect of an embodiment of the present invention. Figure 1 ;

[0033] Figure 2 This diagram illustrates a structure of a limited access circuit provided in the first aspect of an embodiment of the present invention.

[0034] Figure 3 This diagram illustrates a structural schematic of a first logic gate circuit provided in the first aspect of an embodiment of the present invention;

[0035] Figure 4 This diagram illustrates the structure of a solid-state drive provided in the first aspect of an embodiment of the present invention. Figure 2 ;

[0036] Figure 5 This diagram illustrates the structure of a solid-state drive provided in the first aspect of an embodiment of the present invention. Figure 3 ;

[0037] Figures 6-10 This diagram illustrates the operating state of the limited access circuit provided in the first aspect of the present invention.

[0038] Figure 11 A schematic diagram of the structure of an electronic device provided in the second aspect of an embodiment of the present invention is shown;

[0039] Figure 12 A flowchart of a limited access control method provided in a third aspect of an embodiment of the present invention is shown. Detailed Implementation

[0040] To facilitate understanding of the technical solutions provided in the embodiments of the present invention, the relevant information of NAND Flash in solid-state drives (SSDs) will be explained below. NAND Flash memory chips are the main components inside solid-state drives (SSDs) used to store data. Data in NAND Flash is not lost after the system loses power, and the data is still there after power is restored. Memory with this characteristic is called "non-volatile memory" in the industry.

[0041] A typical NAND Flash memory chip organizes its internal storage space in the following way: LUN-Plane-Block-Page-Byte, that is:

[0042] A single NAND Flash memory package contains one or more LUNs; a LUN contains one or more Planes; a Plane contains multiple Blocks; a Block contains multiple Pages; and a Page contains multiple Bytes. Among these, the most commonly used concepts are: Block, Page, and Byte.

[0043] There are three common operations for NAND Flash: read, write (i.e., programming), and erase (i.e., erasing). Generally, read and write operations are performed in units of pages, while erase operations are performed in units of blocks. Both write and erase operations are unidirectional; that is, erasing can only change the data in the memory array to "1" (i.e., all FF data), and cannot change "1" to "0"; writing can only change the data in the memory array to "0", and cannot change "0" to "1".

[0044] SSDs possess advantages over traditional hard disk drives (HDDs), including faster read / write speeds, lighter weight, lower power consumption, and smaller size. They are widely used in numerous fields such as military, automotive, industrial control, video surveillance, network monitoring, network terminals, power, medical, aviation, and navigation equipment. In recent years, optimizing SSDs has become a hot research topic. Logically, SSD optimization aims to support more read / write operations and extend data retention time, making the drive more durable and robust.

[0045] Unlike conventional optimization approaches, the inventors proposed an alternative SSD optimization strategy: limiting the number of SSD accesses. Once the SSD is deployed, the host is only allowed a maximum of N accesses to the internal flash array. After that, the SSD's flash array access function is locked, and it no longer responds to user read / write access requests to the internal flash array. This effectively improves the security of SSD data and can be applied to scenarios with high data security requirements, such as military equipment.

[0046] Embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0047] In a first aspect, embodiments of the present invention provide a solid-state drive 10, such as... Figure 1 As shown, the solid-state drive 10 includes: a main control chip 110, a limited access circuit 120, and a flash memory array 130, such as a NAND Flash array.

[0048] Specifically, the main control chip 110 may include a host interface controller 112, a central processing unit 111 (CPU), and a flash memory controller 113, which are connected via a bus 118. The flash memory controller 113 is connected to the flash memory array 130. In addition to these structures, the main control chip 110 may also include other structures such as a cache 115 (Buffer), a cache controller 114, a dynamic random access memory 116 (DRAM), and an error detection and correction circuit 117 (ECC), etc. For details, please refer to relevant technologies; this embodiment will not elaborate on these aspects.

[0049] like Figure 2 As shown, the limited access circuit 120 may include: a limited access counter 121, a first logic gate circuit 122, and a state machine 123.

[0050] The count-limit counter 121 includes multiple storage units 1211 for storing multi-bit count data. The specific data bit width is determined according to the access limit value of the solid-state drive 10 as needed. The initialization data of the multiple storage units 1211 is all "1". For example, the count-limit counter 121 can be an embedded flash memory in the main control chip 110, or an independent non-volatile memory chip such as EEPROM (Electrically Erasable Programmable Read-Only Memory) or SPI (Serial Peripheral Interface) Flash. It should be noted that when the count-limit counter 121 is an embedded flash memory in the main control chip 110, the entire count-limit access circuit 120 can be integrated into the main control chip 110.

[0051] The data operation terminal of the limit counter 121 is connected to the state machine 123. That is, the state machine 123 can perform data operations on the limit counter 121, such as data erasure operations and data programming (i.e., writing operations).

[0052] The first logic gate circuit 122 is an OR operation logic circuit. The first logic gate circuit 122 includes multiple input terminals and one output terminal. Each data readout terminal of the limit counter 121 is connected to a corresponding input terminal of the first logic gate circuit 122. It should be noted that the limit access circuit 120 also includes a data reading circuit (not shown in the figure) for reading data from each storage unit 1211 in the limit counter 121. For example, the data reading circuit may include a sensitive amplifier; details can be found in related technologies, which will not be elaborated upon in this embodiment. Each data readout terminal of the limit counter 121 is the output terminal of the data reading circuit located around the limit counter 121. In specific implementation, the data stored in each storage unit 1211 is read and transmitted to the corresponding input terminal of the first logic gate circuit 122 through the data reading circuit.

[0053] The output of the first logic gate 122 is also connected to the state machine 123. The first logic gate 122 performs an OR operation on the multi-bit count data read from multiple memory cells 1211 and transmits the result to the state machine 123. The number of inputs to the first logic gate 122 is determined by the data width of the finite-count counter 121. Specifically, as shown... Figure 2 As shown, a single multi-input, single-output OR gate can be used, or it can be composed of multiple cascaded two-input OR gates. For example, as Figure 3 As shown, the data width of the limit counter 121 is 16 bits, and the first logic gate circuit 122 can be a 16-input 1-output OR gate obtained by splicing together multiple two-input OR gates 1221.

[0054] State machine 123 can be composed of a state register and combinational logic circuits. State machine 123 is used to access the limit counter 121 each time host 20 accesses the flash array 130 in solid-state drive 10, changing one bit of the multi-bit count data from "1" to "0". When the OR operation result of the first logic gate circuit 122 is detected to be "0", host 20 is prohibited from accessing flash array 130 again. The data width of limit counter 121 determines the upper limit of the number of accesses, which can be set according to the needs of the actual application scenario. For example, if the data width of limit counter 121 is 16, the initial value is "11111111111111111". Each time host 20 accesses flash array 130, one "1" is changed to "0". Therefore, after host 20 accesses flash array 130 16 times, the value of limit counter 121 is "0000000000000000", reaching the maximum number of accesses. At this time, the OR operation result of the first logic gate circuit 122 is "0", which prevents the host 20 from accessing the flash array 130 again.

[0055] The limited access circuit 120 is connected to the main control chip 110. For example, as... Figure 1 As shown, the limited access circuit 120 can be connected to the aforementioned bus 118 in the main control chip 110. That is, the aforementioned state machine 123 is connected to the bus 118 in the main control chip 110. When the detected OR operation result is "0", it outputs a prohibition command, which is transmitted to the central processing unit 111 via the bus 118. After receiving the prohibition command, the central processing unit 111 no longer responds to the host 20's access request to the flash memory array 130, thereby prohibiting the host 20 from accessing the flash memory array 130 again.

[0056] Or, such as Figure 4 As shown, the limited access circuit 120 can also be connected to the flash memory controller 113 in the main control chip 110. That is, the aforementioned state machine 123 is connected to the flash memory controller 113, and when the detected OR operation result is "0", it sends an access prohibition command to the flash memory controller 113. After receiving the access prohibition command, the flash memory controller 113 prohibits access operations to the flash memory array 130, thereby preventing the host 20 from accessing the flash memory array 130 again.

[0057] Or, as Figure 5As shown, the limited access circuit 120 can also be connected to the host interface controller 112 in the main control chip 110. That is, the aforementioned state machine 123 is connected to the host interface controller 112, and when the detected OR operation result is "0", it sends an access denial command to the host interface controller 112. After receiving the access denial command, the host interface controller 112 disables the access interface to the flash array 130, thereby preventing the host 20 from accessing the flash array 130 again.

[0058] In some examples, to further enhance the data security of the SSD 10, such as Figure 2 As shown, the aforementioned limited access circuit 120 may further include a second logic gate circuit 125 and a key memory 124 for storing externally written keys. The data operation terminals of the key memory 124 are connected to the state machine 123. That is, the state machine 123 can perform data operations on the key memory 124, such as data erasure operations and data programming (writing) operations. In specific implementations, the limited access counter 121 and the key memory 124 can be different storage areas of the same non-volatile memory. For example, a limited access counter area and a key area can be divided in the same non-volatile memory. Alternatively, the limited access counter 121 and the key memory 124 can also be two independent non-volatile memories.

[0059] The second logic gate circuit 125 is an XOR operation logic circuit, including a first input terminal, a second input terminal, and an output terminal. The number of first input terminals and the number of second input terminals are the same as the data bit width of the key memory 124. For example, if the data bit width of the key memory 124 is 16, that is, the key data is 16 bits, then the second logic gate circuit 125 includes 16 first input terminals, 16 second input terminals, and one output terminal, used to perform bitwise XOR operations on the data input to the 16 first input terminals and 16 second input terminals, and output the XOR operation result from the output terminal.

[0060] Each first input terminal of the second logic gate circuit 125 is connected to a corresponding data read terminal of the key memory 124. Similarly, each data read terminal of the key memory 124 is the output terminal of the data reading circuit located on the periphery of the key memory 124. The data stored in the key memory 124 is read and transmitted to the corresponding first input terminal of the second logic gate circuit 125 through the data reading circuit.

[0061] Each second input terminal of the second logic gate circuit 125 is connected to the supply terminal 126 of the preset security key. The preset security key (i.e., a predefined pattern) is pre-configured in the solid-state drive 10 and used to verify externally written keys to improve the security of the solid-state drive 10. In some examples, to reduce the probability of the preset security key being tampered with and further improve security, each second input terminal can be connected to a high-level voltage terminal or a low-level voltage terminal according to the preset security key. It can be understood that the preset security key data corresponding to the second input terminal connected to the high-level voltage terminal is "1", and the preset security key data corresponding to the second input terminal connected to the low-level voltage terminal is "0". Taking a 16-bit preset security key as an example, for instance, if the preset security key is “1010101001010101”, then the second input terminals corresponding to bits [0], [2], [4], [6], [9],

[11] ,

[13] , and

[15] are connected to the high-level voltage terminals inside the solid-state drive 10, and the second input terminals corresponding to the remaining data bits are connected to the low-level voltage terminals inside the solid-state drive 10.

[0062] Of course, in other embodiments, another independent non-volatile memory can also be provided within the solid-state drive 10 for configuring a preset security key for the solid-state drive 10. This non-volatile memory is configured at the factory to prevent erasure and programming operations. In this case, each second input terminal of the second logic gate circuit 125 is connected to the corresponding data read terminal of the non-volatile memory, and the second logic gate circuit 125 obtains the preset security key from the non-volatile memory.

[0063] The output of the second logic gate 125 is connected to the state machine 123. The second logic gate 125 is used to perform an XOR operation on the externally written key and the preset security key, and transmit the XOR operation result to the state machine 123.

[0064] At this time, the XOR operation result output by the second logic gate circuit 125 serves two purposes: firstly, as a security verification result, controlling whether the host 20 can access the flash memory array 130; secondly, it controls the access status of the limit counter 121 and the key memory 124. The state machine 123 is also used to, when detecting an XOR operation result of "1", prohibit the host 20 from accessing the flash memory array 130 and allow erasing and programming operations on the limit counter 121 and the key memory 124; and when detecting an XOR operation result of "0" and an OR operation result of "1", allow the host 20 to access the flash memory array 130, allow programming operations on the limit counter 121, prohibit erasing operations on the limit counter 121, and prohibit erasing and programming operations on the key memory 124.

[0065] Furthermore, to improve the reliability of the limited access function, the limited access circuit 120 may further include a voting circuit (not shown in the figure). In some examples, there are multiple limited counters 121, and the number is odd. The data readout terminals of multiple limited counters 121 are all connected to the input terminal of the first logic gate circuit 122 through the voting circuit, and the data operation terminals of multiple limited counters 121 are all connected to the state machine 123. It should be noted that multiple limited counters 121 are set up to back up the counting data and improve the counting reliability. The structure and working process of each limited counter 121 are the same. For example, the data bit width is the same, the data erasure operation is performed synchronously, the data writing operation is performed synchronously, and the written data value is the same. In specific implementation, each bit of data read from each limited counter 121 is first voted through the voting circuit, and the voting result is then input to the corresponding input terminal of the first logic gate circuit 122.

[0066] Similarly, in some examples, there can be multiple key memories 124, and an odd number of them. The data read terminals of multiple key memories 124 are all connected to the first input terminal of the second logic gate circuit 125 through a voting circuit, and the data operation terminals of multiple key memories 124 are all connected to the state machine 123. The structure and operation of each key memory 124 are the same. For example, they have the same data bit width, perform data erasure operations synchronously, perform data write operations synchronously, and write the same data value.

[0067] For example, the voting circuit described above can be a redundant voting circuit with three-mode redundancy, five-mode redundancy, seven-mode redundancy, or more, and this embodiment does not impose any restrictions on this.

[0068] To better understand this technical solution, please refer to the following: Figures 6-10 An exemplary workflow of the solid-state drive 10 will be described. It should be noted that... Figures 6-10 The data bit widths of the limit counter 121 and the key memory 124 shown are for illustrative purposes only; the specific bit widths should be determined according to actual needs.

[0069] like Figure 6 As shown, at the factory, the limit counter 121 and the key memory 124 store random values. Therefore, when the solid-state drive 10 is powered on for the first time after leaving the factory, the XOR operation result of the second logic gate circuit 125 is monitored, and the OR operation result of the first logic gate circuit 122 is ignored. Since the value in the key memory 124 (i.e., the factory-set random value) is usually not equal to the preset security key, the XOR operation result of the second logic gate circuit 125 is "1". At this time, each structure is in the following working state:

[0070] (1) Limit counter 121: Allows erasure and programming;

[0071] (2) Key memory 124: allows erasure and programming;

[0072] (3) Prevent host 20 from accessing flash array 130 in solid-state drive 10.

[0073] Then, as Figure 7 As shown, an erase operation is performed on the limit counter 121 and the key memory 124, erasing the data in each storage cell of the limit counter 121 and the key memory 124 to "1". Taking a 16-bit data width as an example, this means erasing to all FF. It should be noted that this erase operation can be automatically triggered during the first power-on after leaving the factory, or it can be executed when an erase command is received from the host 20. After erasure, the value in the key memory 124 is still not equal to the preset security key. At this time, the XOR operation result of the second logic gate circuit 125 is still "1", and each structure is still in the following working state:

[0074] (1) Limit counter 121: Allows erasure and programming;

[0075] (2) Key memory 124: allows erasure and programming;

[0076] (3) Prevent host 20 from accessing flash array 130 in solid-state drive 10.

[0077] Next, a security verification prompt message can be sent to host 20, prompting relevant personnel to enter the key data of solid-state drive 10 on the security verification interface displayed on host 20. After the relevant personnel enter the key data on the security verification interface, a key write command is generated. Solid-state drive 10 receives the key write command sent by host 20, which includes the key data to be written, and writes the key data to key storage 124. Figure 8 As shown, after the writing is completed, if the written key data is equal to the preset security key, the XOR operation result of the second logic gate circuit 125 will be "0", indicating that the security verification is successful. At this time, each structure is in the following working state:

[0078] (1) Limit counter 121: Erasure is prohibited, programming is allowed only, that is, it can only change from 1 to 0 in one direction;

[0079] (2) The value of key memory 124 is permanently retained and cannot be erased or programmed.

[0080] In addition, when the XOR operation result is detected to change from "1" to "0", the monitoring of the OR operation result output by the first logic gate circuit 122 is started. At this time, all bits of the limit counter 121 are "1", the OR operation result is "1", and the host 20 is allowed to access the flash array 130 in the solid-state drive 10, that is, the solid-state drive 10 enters user mode.

[0081] Subsequently, since the value of the key memory 124 is permanently retained and erasure / programming is prohibited, the XOR operation result of the output of the second logic gate circuit 125 is always "0", and the count counter 121 also always remains in a working state where erasure is prohibited and programming is only allowed, that is, it can only change from 1 to 0 in one direction.

[0082] After entering user mode, each time host 20 accesses the flash array 130 in solid-state drive 10, a value of "0" is written to limit counter 121, until all data bits in limit counter 121 are "0". Taking a data bit width of 16 bits as an example... Figure 9 This shows the state after the host 20 first accesses the flash array 130 in the solid-state drive 10, and the limit counter 121 writes a value of "0". Figure 10 The diagram shows the state after the host 20 accesses the flash array 130 in the solid-state drive 10 for the 16th time, and the limit counter 121 is appended with a value of "0". When the OR operation result of the first logic gate circuit 122 is detected to be "0", it indicates that the maximum number of accesses to the flash array 130 in the solid-state drive 10 has been reached, and thereafter the host 20 is prohibited from accessing the flash array 130 in the solid-state drive 10.

[0083] In addition, since the XOR operation result output by the second logic gate circuit 125 controls access to the limit counter 121 (i.e., when the XOR operation result is "0", the limit counter 121 is prohibited from erasing, only allowed to be programmed, and can only change from 1 to 0 in one direction), each data bit in the limit counter 121 always remains at the value of 0, and the OR operation result output by the first logic gate circuit 122 will also always be "0", thereby permanently prohibiting the host 20 from accessing the flash array 130 in the solid-state drive 10.

[0084] Secondly, embodiments of the present invention also provide an electronic device, such as... Figure 11 As shown, the electronic device 1 includes a host 20 and a solid-state drive 10 provided in the first aspect. The host 20 is connected to the host interface controller 112 of the solid-state drive 10 to access the solid-state drive 10. For example, the electronic device 1 can be a personal computer, laptop computer, tablet computer, mobile phone, wearable device, television, or other device with data access capabilities.

[0085] Thirdly, embodiments of the present invention also provide a limited access control method for a solid-state drive 10. The solid-state drive 10 includes: a main control chip 110, a flash memory array 130, and a limited access circuit 120. The limited access circuit 120 includes: a limited access counter 121, a first logic gate circuit 122, and a state machine 123. The limited access counter 121 includes multiple storage cells 1211, the initialization data of which is "1". The data read terminal of the limited access counter 121 is connected to the input terminal of the first logic gate circuit 122, and the data operation terminal of the limited access counter 121 and the output terminal of the first logic gate circuit 122 are respectively connected to the state machine 123. For details, please refer to the relevant description in the first aspect above, which will not be repeated here.

[0086] like Figure 12 As shown, the above-mentioned limited access control method may include at least the following steps S101 to S103.

[0087] Step S101: In user mode, monitor the host's access operations to the flash array;

[0088] Step S102: Each time the host accesses the flash array, write a "0" value to the limit counter.

[0089] Step S103: If the OR operation result of the first logic gate circuit is detected to be "0", then host access to the flash array is prohibited.

[0090] In step S101, the user mode is the mode that allows the user to access the flash array 130 in the solid-state drive 10 through the host 20. It should be noted that the specific implementation process of the above steps S101 to S103 can be found in the relevant description in the first aspect above, and will not be repeated here.

[0091] In some examples, before entering user mode, the above method further includes performing an initialization configuration operation, which includes performing a data erasure operation on the limit counter 121, so that the data stored in the above multiple storage units are all initialized to "1". The specific implementation process of the data erasure operation can be found in the relevant description in the first aspect above, and will not be repeated here.

[0092] It should be noted that the initialization configuration operation is a configuration operation performed on the first power-on after the solid-state drive 10 leaves the factory and before it enters user mode. For example, it can be automatically triggered when the solid-state drive 10 is detected to be powered on for the first time, or it can be triggered externally on the first power-on. This embodiment does not limit this.

[0093] In some examples, the aforementioned limited access circuit 120 further includes a second logic gate circuit 125 and a key memory 124 for storing externally written keys. The first input of the second logic gate circuit 125 is connected to the data read output of the key memory 124, the second input of the second logic gate circuit 125 is connected to the supply end of a preset security key, and the data operation end of the key memory 124 and the output of the second logic gate circuit 125 are connected to the state machine 123. For details, please refer to the relevant description in the first aspect above, which will not be repeated here. In this case, before entering user mode, the method further includes performing an initialization configuration operation.

[0094] In this example, the initialization configuration operation may include: after the solid-state drive 10 is powered on, monitoring the XOR operation result of the second logic gate circuit 125; if the XOR operation result is 1, then erasing and programming operations are allowed for the limit counter 121 and the key memory 124, and data erasure operations are performed on the limit counter 121 and the key memory 124, so that the data stored in the limit counter 121 and the key memory 124 are all initialized to "1", and in response to the key write command sent by the host 20, the externally input key data is written to the key memory 124; if the XOR operation result is "0", then the host 20 is enabled to access the flash array 130, enters user mode, and erasing operations on the limit counter 121 and the key memory 124 are prohibited, and monitoring of the OR operation result of the first logic gate circuit 122 is enabled. For specific implementation details, please refer to the relevant description in the first aspect above, which will not be repeated here.

[0095] It should also be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0096] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0097] In addition, the functional modules in the various embodiments of the present invention can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0098] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0099] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The term "a plurality of" includes two or more cases.

[0100] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this invention should be included within the protection scope of this invention. Therefore, the protection scope of this invention should be determined by the scope of the claims.

Claims

1. A solid state drive, characterized by, include: The main control chip, flash memory array, and limited access circuitry, among which, The main control chip includes: a host interface controller, a central processing unit, and a flash memory controller. The host interface controller, the central processing unit, and the flash memory controller are connected via a bus, and the flash memory controller is connected to the flash memory array. The limited access circuit includes: a limited access counter, a first logic gate circuit, and a state machine; The limit counter includes multiple storage units, all of which are initialized with 1. Each data readout terminal of the limit counter is connected to the input terminal of the first logic gate circuit. The data operation terminal of the limit counter and the output terminal of the first logic gate circuit are both connected to the state machine. The first logic gate circuit is used to perform an OR operation on the multi-bit count data read from the plurality of memory cells respectively, and transmit the OR operation result to the state machine; The state machine is configured to write a 0 value to the limit counter every time the host accesses the flash array, and to prohibit the host from accessing the flash array when the OR operation result is detected to be 0. The limited access circuit further includes: a second logic gate circuit and a key memory for storing the externally written key. The data operation terminal of the key memory and the output terminal of the second logic gate circuit are connected to the state machine. The second logic gate circuit is used to perform an XOR operation on the externally written key and a preset security key, and transmit the XOR operation result to the state machine. The limit counter and the key memory store random values ​​at the factory. The state machine is also used to monitor the XOR operation result of the second logic gate circuit when the solid-state drive is powered on for the first time after leaving the factory. If the XOR operation result is 1, the limit counter and the key memory are allowed to be erased and programmed. The data erase operation is performed on the limit counter and the key memory, so that the data stored in the limit counter and the key memory is initialized to 1. In response to the key write command sent by the host, the externally input key data is written to the key memory. When the XOR operation result is detected to change from 1 to 0, the erase operation of the limit counter is prohibited, the erase and programming operation of the key memory is prohibited, and the monitoring of the OR operation result of the first logic gate circuit is enabled. If the OR operation result is 1, the host access channel to the flash array is enabled.

2. The solid state drive of claim 1, wherein, The first input terminal of the second logic gate is connected to the data read terminal of the key memory, and the second input terminal of the second logic gate is connected to the supply terminal of the preset security key.

3. The solid state drive of claim 2, wherein, The number of first input terminals and the number of second input terminals of the second logic gate circuit are the same as the data bit width of the key memory, and each second input terminal is connected to a high-level voltage terminal or a low-level voltage terminal according to the preset security key.

4. The solid state drive of claim 1, wherein, The state machine is connected to the bus.

5. The solid state drive of claim 1, wherein, The state machine is connected to the flash memory controller.

6. The solid state drive of claim 1, wherein, The state machine is connected to the host interface controller.

7. An electronic device, comprising: The system includes a host computer and a solid-state drive (SSD) according to any one of claims 1-6, wherein the host computer is connected to a host interface controller of the SSD to access the SSD.

8. A method for limiting access to a solid-state drive, characterized in that, The solid-state drive includes: a main control chip, a flash memory array, and a limited access circuit. The limited access circuit includes: a limited access counter, a first logic gate circuit, and a state machine. The limited access counter includes multiple storage units, all of which are initialized with 1. The data read terminal of the limited access counter is connected to the input terminal of the first logic gate circuit. The data operation terminal of the limited access counter and the output terminal of the first logic gate circuit are respectively connected to the state machine. The method includes: In user mode, monitor the host's access operations to the flash array; Each time the host accesses the flash array, a value of 0 is written to the limit counter; If the OR operation result of the first logic gate is detected to be 0, then the host is prohibited from accessing the flash memory array; The limited access circuit further includes: a second logic gate circuit and a key memory for storing an external write key. The second logic gate circuit is used to perform an XOR operation on the external write key and a preset security key, and transmit the XOR operation result to the state machine. The limited access counter and the key memory store random values ​​at the factory. Before entering the user mode, the method further includes: performing an initialization configuration operation when the solid-state drive is powered on for the first time after leaving the factory. The initialization configuration operation includes: After the solid-state drive is powered on, the XOR operation result of the output of the second logic gate circuit is monitored; When the XOR operation result is 1, erasure and programming operations are allowed on the limit counter and the key memory. Data erasure operation is performed on the limit counter and the key memory, so that the data stored in the limit counter and the key memory are initialized to 1. In response to the key write command sent by the host, externally input key data is written into the key memory. When the XOR operation result is detected to change from 1 to 0, the erasure operation of the limit counter is prohibited, the erasure and programming operation of the key memory is prohibited, and the monitoring of the OR operation result of the first logic gate circuit is enabled. If the OR operation result is 1, the host access channel to the flash array is enabled, and the user mode is entered.

Citation Information

Patent Citations

  • A secure data storage device

    WO2002005098A1