Secure file system for memory system
By storing the secure file system in a separate PSMU within the memory system, fast access to secure files is achieved after a memory system reset, solving the problem of the memory system failing to respond promptly after a reset and improving the system's response speed and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MICRON TECHNOLOGY INC
- Filing Date
- 2022-09-07
- Publication Date
- 2026-07-17
AI Technical Summary
Existing memory systems cannot quickly access secure file systems after a reset, resulting in delayed responses and failure to meet specified time requirements, especially when media needs to be rebuilt after a reset.
The secure file system is stored in a physical super management unit (PSMU) that is separate from the host system data, and secure procedures and media reconstruction are executed concurrently to ensure that secure files are still accessible during media reconstruction.
It reduces power-on initialization time, ensures that the storage subsystem responds to host identification controller commands within a specified time, and avoids the impact of media degradation on the secure file system.
Smart Images

Figure CN115774886B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure generally relate to memory subsystems, and more specifically, to secure file systems for memory systems. Background Technology
[0002] The memory subsystem may include one or more memory devices for storing data. The memory devices may be, for example, non-volatile memory devices and volatile memory devices. Generally, the host system can utilize the memory subsystem to store data at the memory devices and retrieve data from the memory devices. Summary of the Invention
[0003] On one hand, this disclosure provides a system comprising: a memory device; and a processing device operatively coupled to the memory device, the processing device being configured to perform operations including: receiving an identification command from a host system; initiating a security program in response to receiving the identification command; transmitting an access command to the memory device, the access command including an identification of a first physical super management unit (PSMU) at a first location of the memory device storing a secure file system, wherein data for the host system is stored at a second location of the memory device; receiving one or more files from the secure file system in response to transmitting the access command; and executing the security program in response to receiving the one or more files.
[0004] In another aspect, this disclosure further provides a method comprising: receiving an identification command from a host system; initiating a security procedure in response to receiving the identification command; transmitting an access command to the memory device, the access command including an identification of a first physical super management unit (PSMU) at a first location of the memory device storing a secure file system, wherein data for the host system is stored at a second location of the memory device; receiving one or more files from the secure file system in response to transmitting the access command; and executing the security procedure in response to receiving the one or more files.
[0005] In another aspect, this disclosure further provides a system comprising: a memory device; and a processing means operatively coupled to the memory device, the processing means being configured to perform operations including: performing a power-on initialization of the memory device; receiving an access command having a file identification; determining, based on the file identification, that the access command is associated with a physical super management unit (PSMU) at a first location of the memory device storing a secure file system; and, in response to determining that the access command is associated with the file, transferring a secure file stored at the PSMU, wherein the transfer of the file and the performance of the power-on initialization of the memory device are concurrent. Attached Figure Description
[0006] This disclosure will become more fully understood from the detailed description given below and from the accompanying drawings of various embodiments thereof. However, the drawings should not be construed as limiting this disclosure to the specific embodiments, but are merely for explanation and understanding.
[0007] Figure 1 This describes an example computing system including a memory subsystem according to some embodiments of the present disclosure.
[0008] Figure 2 This is a flowchart of an example method for accessing security system files according to an embodiment of the present disclosure.
[0009] Figure 3 This is a flowchart of an example method for accessing security system files according to an embodiment of the present disclosure.
[0010] Figure 4 This is a block diagram of an example computer system in which embodiments of this disclosure may be operated. Detailed Implementation
[0011] This disclosure relates to a secure file system for a memory system. The memory subsystem may be a storage device, a memory module, or a combination of a storage device and a memory module. The following is combined with… Figure 1 Describe examples of storage devices and memory modules. Generally, a host system may utilize a memory subsystem that includes one or more components such as memory devices for storing data. The host system can provide data stored in the memory subsystem and can request data to be retrieved from the memory subsystem.
[0012] The memory subsystem may include high-density non-volatile memory devices where it is desirable to retain data when no power is supplied to the memory devices. For example, a three-dimensional cross-point (“3D cross-point”) memory, which may include an array of non-volatile memory cell cross-points, provides storage in a compact, high-density configuration. The following section combines… Figure 1 Other examples of non-volatile memory devices are described. A non-volatile memory device is a package containing one or more dies, each comprising one or more planes. For some types of non-volatile memory devices (e.g., NAND memory), each plane contains a set of physical blocks. Each block contains a set of pages. Each page contains a set of memory cells (“cells”). A cell is an electronic circuit that stores information. Depending on the cell type, a cell may store one or more bits of binary information and has various logic states related to the number of bits stored. Logic states may be represented by binary values, such as “0” and “1” or combinations of such values.
[0013] Memory devices can consist of multiple bits arranged in a two-dimensional or three-dimensional grid. Memory cells are etched onto a silicon wafer in an array of columns (hereinafter also referred to as bit lines) and rows (hereinafter also referred to as word lines). A word line may relate to one or more rows of memory cells in the memory device, and together with one or more bit lines, it is used to generate the address of each of the memory cells. The intersection of a bit line and a word line constitutes the address of the memory cell. A block, hereinafter, refers to a unit of memory device used to store data and may contain a group of memory cells, a group of word lines, a word line, or an individual memory cell. One or more blocks may be grouped together to form separate partitions (e.g., planes) of the memory device to allow concurrent operations to occur on each plane.
[0014] Some non-volatile memory devices (e.g., three-dimensional cross-point memory devices or NAND devices) can initiate power-on initialization after a reset—for example, after a basic reset (PERST). In some examples, the reset can be a cold reset (e.g., when power is applied to the memory device or when the memory device is powered on) or a warm reset (e.g., a reset after power has already been applied to the memory device). In either example, the memory device can be rebuilt (e.g., reconstructed) after a reset (reconstructing the media). For example, rebuilding may involve reconstructing or rebuilding the logic-to-physical (L2P) table each time the memory device is reset. During the initialization cycle (e.g., when the media is reconstructed), the memory device may not be able to perform read, write, or erase operations (e.g., for access operations). Therefore, a memory system controller (e.g., a front-end) coupled to the memory device (e.g., the back end) may not be able to access any data on the memory device until the memory device is reconstructed—e.g., until a media-ready state is received.
[0015] Some memory devices may initiate a security procedure as part of power-on initialization. For example, a memory system controller may have a security module that initializes whenever the memory device is reset. A security file system (e.g., files for the security module) may be stored at the memory device. For example, the security file system may be stored in an extended logical space that shares the same wear leveling algorithm for data stored at the memory device for the host system—such as user data or user space. Thus, the readiness of the security file system (e.g., its accessibility) may be associated with the readiness of the stored data for the host system—e.g., inaccessible until a media-ready state is received. Because the memory system controller cannot access the security file system until the memory device is ready, there may be a delay in the memory system controller responding to host identification controller commands from the host system after a reset. In some cases, the memory system may fail to respond to the host system within a specified time or meet the specified time with a very small margin—e.g., the time specified by the Peripheral Component Interconnect Fast Standard (PCIe). In some memory devices, certain methods have been employed to optimize the time spent on memory device readiness. Such methods may fail to meet the specified time. Alternative methods have been employed to access the backup mode of the secure file system—for example, attempting to access the secure file system before the storage device is ready. Such methods can cause substantial boot (e.g., power-on initialization) code changes and additional inter-module synchronization (e.g., handshake). These additional code changes and inter-module synchronization can result in longer storage device readiness times and prevent the storage device from meeting specified time requirements.
[0016] This disclosure addresses the aforementioned and other drawbacks by providing a memory subsystem capable of storing a secure file system separate from host system data. The secure file system, stored separately from host system data, can be accessed independently of the media-ready state for host system data. For example, the memory subsystem can store the secure file system at a reserved physical super management unit (PSMU). The reserved PSMU can be separated from the stored data for the host system (e.g., stored user data). For example, the memory subsystem controller can avoid performing typical wear leveling operations on the secure file system at the reserved PSMU. Because the secure file system is stored at the reserved PSMU, it remains accessible even when the remaining host data is inaccessible. For example, when the memory subsystem initiates power-on initialization (e.g., booting a program), the memory subsystem controller can begin rebuilding the media stored at the memory device. The memory subsystem controller can also request the secure file system simultaneously—e.g., concurrently or simultaneously. The memory device can recognize that the request is for a secure file stored at the reserved PSMU and send said file to the memory subsystem controller while rebuilding the remaining portion of the media. The memory subsystem controller can receive the security file and initialize the security module. The memory subsystem can then continue with power-on initialization and respond to the host system.
[0017] The advantages of this disclosure include (but are not limited to) reduced power-on initialization time. By accessing the security file without waiting for media readiness (e.g., accessing the security file concurrently with media reconstruction), the memory subsystem can initialize the security module more quickly. Therefore, the memory subsystem can respond to host identification controller commands within a specified time. Furthermore, because the reserved PSMU is separate from the host system data, the memory subsystem controller can access the security file at any time even if the remaining media degrades. Moreover, storing the security file at the PSMU avoids increased media degradation effects. The reserved PSMU storing the security file is written to less frequently than the PSMU storing host data; therefore, the memory subsystem avoids performing wear leveling operations at the reserved PSMU. Instead, the memory subsystem can store redundant copies, and if the security file system at the reserved PSMU is compromised (e.g., an erroneous operation finds one or more errors), the memory subsystem can use the redundant copies to write the security file to a second reserved PSMU. Therefore, the memory subsystem can avoid additional latency while using a separate security file system.
[0018] Figure 1This description describes an example computing system 100 including a memory subsystem 110 according to some embodiments of the present disclosure. The memory subsystem 110 may include media, such as one or more volatile memory devices (e.g., memory device 140), one or more non-volatile memory devices (e.g., memory device 130), or a combination of such things.
[0019] The memory subsystem 110 may be a storage device, a memory module, or a combination of a storage device and a memory module. Examples of storage devices include solid-state drives (SSDs), flash drives, universal serial bus (USB) flash drives, embedded multimedia controller (eMMC) drives, universal flash memory (UFS) drives, secure digital cards (SD cards), and hard disk drives (HDDs). Examples of memory modules include dual in-line memory modules (DIMMs), small form factor DIMMs (SO-DIMMs), and various types of non-volatile dual in-line memory modules (NVDIMMs).
[0020] The computing system 100 may be, for example, a desktop computer, a laptop computer, a web server, a mobile device, a vehicle (e.g., an airplane, a drone, a car or other means of transportation), an Internet of Things (IoT) enabled device, an embedded computer (e.g., an embedded computer contained in a vehicle, industrial equipment or a networked commercial device), or a computing device that includes memory and processing devices.
[0021] The computing system 100 may include a host system 120 coupled to one or more memory subsystems 110. In some embodiments, the host system 120 is coupled to multiple memory subsystems 110 of different types. Figure 1 This describes an example of a host system 120 coupled to a memory subsystem 110. As used herein, “coupled to” or “coupled with” generally refers to a connection between components, which can be an indirect or direct communication connection (e.g., without an intermediary component), whether wired or wireless, including connections such as electrical, optical, magnetic, etc.
[0022] Host system 120 may include a processor chipset and a software stack executed by the processor chipset. The processor chipset may include one or more cores, one or more caches, a memory controller (e.g., an NVDIMM controller), and a storage protocol controller (e.g., a PCIe controller, a SATA controller). Host system 120 uses memory subsystem 110 (for example) to write data to and read data from memory subsystem 110.
[0023] Host system 120 can be coupled to memory subsystem 110 via a physical host interface. Examples of physical host interfaces include (but are not limited to) Serial Advanced Technology Attachment (SATA) interfaces, Peripheral Component Interconnect High Speed (PCIe) interfaces, Universal Serial Bus (USB) interfaces, Fibre Channel, Serial Attached SCSI (SAS), Double Data Rate (DDR) memory bus, Small Computer System Interface (SCSI), Dual In-line Memory Module (DIMM) interfaces (e.g., DIMM slot interfaces supporting Double Data Rate (DDR)), etc. The physical host interface can be used to transfer data between host system 120 and memory subsystem 110. When memory subsystem 110 is coupled to host system 120 via a physical host interface (e.g., a PCIe bus), host system 120 can further utilize an NVM High Speed (NVMe) interface to access components (e.g., memory device 130). The physical host interface provides an interface for passing control, address, data, and other signals between memory subsystem 110 and host system 120. Figure 1 The memory subsystem 110 is described as an example. Generally, the host system 120 can access multiple memory subsystems via the same communication connection, multiple separate communication connections, and / or combinations of communication connections.
[0024] Memory devices 130 and 140 may comprise any combination of different types of non-volatile memory devices and / or volatile memory devices. Volatile memory devices (such as memory device 140) may be (but are not limited to) random access memory (RAM), such as dynamic random access memory (DRAM) and synchronous dynamic random access memory (SDRAM).
[0025] Some examples of non-volatile memory devices (such as memory device 130) include NAND flash memory and in-situ write memory, such as three-dimensional cross-point ("3D cross-point") memory devices, which are cross-point arrays of non-volatile memory cells. Cross-point arrays of non-volatile memory cells can perform bit storage based on volume resistance variations combined with stackable cross-gate format data access arrays. Therefore, in contrast to many flash-based memories, cross-point non-volatile memories can perform in-situ write operations, where non-volatile memory cells can be programmed without prior erasing of the non-volatile memory cells. NAND flash memories include, for example, two-dimensional NAND (2D NAND) and three-dimensional NAND (3D NAND).
[0026] Each of the memory devices 130 may include one or more arrays of memory cells. For example, one type of memory cell, such as a single-level cell (SLC), may store one bit per cell. Other types of memory cells, such as multi-level cell (MLC), three-level cell (TLC), four-level cell (QLC), and five-level cell (PLC), may store multiple bits per cell. In some embodiments, each of the memory devices 130 may include one or more arrays of memory cells, such as SLC, MLC, TLC, QLC, PLC, or any combination thereof. In some embodiments, a particular memory device may include SLC portions and MLC portions, TLC portions, QLC portions, or PLC portions of memory cells. The memory cells of the memory device 130 may be grouped into pages, which may refer to logical units of the memory device used to store data. For some types of memory (e.g., NAND), pages may be grouped to form blocks.
[0027] Although non-volatile memory components such as 3D cross-point arrays of non-volatile memory cells and NAND-type flash memories (e.g., 2D NAND, 3D NAND) are described, memory device 130 may be based on any other type of non-volatile memory, such as read-only memory (ROM), phase-change memory (PCM), self-select memory, other chalcogenide-based memories, ferroelectric transistor random access memory (FeTRAM), ferroelectric random access memory (FeRAM), magnetic random access memory (MRAM), spin-transfer torque (STT)-MRAM, conductive bridged RAM (CBRAM), resistive random access memory (RRAM), oxide-based RRAM (OxRAM), NOR flash memory, or electrically erasable programmable read-only memory (EEPROM).
[0028] The memory subsystem controller 115 (or, for simplicity, controller 115) can communicate with the memory device 130 to perform operations such as reading data, writing data, erasing data, and other such operations at the memory device 130. The memory subsystem controller 115 may include hardware such as one or more integrated circuits and / or discrete components, buffer memories, or combinations thereof. The hardware may include a digital circuit system having dedicated (i.e., hard-coded) logic for performing the operations described herein. The memory subsystem controller 115 may be a microcontroller, a dedicated logic circuit system (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.), or other suitable processor.
[0029] The memory subsystem controller 115 may include processing means configured to execute instructions stored in local memory 119, which includes one or more processors (e.g., processor 117). In the illustrated example, the local memory 119 of the memory subsystem controller 115 includes embedded memory configured to store instructions for performing various processes, operations, logic flows, and routines that control the operation of the memory subsystem 110, including handling communication between the memory subsystem 110 and the host system 120.
[0030] In some embodiments, local memory 119 may include memory registers storing memory pointers, fetched data, etc. Local memory 119 may also include read-only memory (ROM) for storing microcode. Although already Figure 1 The instance memory subsystem 110 is described as including a memory subsystem controller 115, but in another embodiment of this disclosure, the memory subsystem 110 does not include a memory subsystem controller 115 and may instead rely on external control (e.g., provided by an external host or by a processor or controller separate from the memory subsystem).
[0031] Generally, the memory subsystem controller 115 can receive commands or operations from the host system 120 and can translate these commands or operations into instructions or appropriate commands to achieve the desired access to the memory device 130. The memory subsystem controller 115 may handle other operations, such as wear leveling, discard item collection, error detection and error correction code (ECC) operations, encryption, caching, and address translation between logical block addresses (e.g., logical block addresses (LBAs), namespaces) and physical addresses (e.g., physical block addresses) associated with the memory device 130. The memory subsystem controller 115 may further include a host interface circuitry for communicating with the host system 120 via a physical host interface. The host interface circuitry can translate commands received from the host system into command instructions to access the memory device 130, and also translate responses associated with the memory device 130 into information for the host system 120.
[0032] The memory subsystem 110 may also include additional circuitry or components not described. In some embodiments, the memory subsystem 110 may include caches or buffers (e.g., DRAM) and address circuitry (e.g., row decoders and column decoders) that can receive addresses from the memory subsystem controller 115 and decode the addresses to access the memory device 130.
[0033] In some embodiments, memory device 130 includes a local media controller 135 that operates in conjunction with memory subsystem controller 115 to perform operations on one or more memory cells of memory device 130. An external controller (e.g., memory subsystem controller 115) may externally manage memory device 130 (e.g., perform media management operations on memory device 130). In some embodiments, memory subsystem 110 is a managed memory device, which is the original memory device 130 having on-die control logic (e.g., local media controller 135) and a controller (e.g., memory subsystem controller 115) for media management within the same memory device package. An example of a managed memory device is a managed NAND (MNAND) device.
[0034] The memory subsystem 110 includes a security module 113 that allows the memory subsystem 110 to initiate a security initialization procedure upon reset. In some embodiments, the memory subsystem controller 115 includes at least a portion of the security module 113. In some embodiments, the security module 113 is part of the host system 120, an application, or an operating system. In other embodiments, the local media controller 135 includes at least a portion of the security module 113 and is configured to perform the functionality described herein.
[0035] If the memory subsystem controller 115 receives a host identification controller command after a reset, the security module 113 can be configured to initiate a security procedure (e.g., security initialization). In some embodiments, the host system 120 can send a command to the memory subsystem 110 after a reset, enabling the memory subsystem controller 115 to identify whether there is an additional controller in the system—e.g., other controllers associated with the same host system. To respond to the host identification controller command, the memory subsystem 110 can utilize a secure file system. In at least one embodiment, the secure file system can be stored at memory device 130 or memory device 140. For example, memory device 130 can store a security file 145 that forms at least a portion of the secure file system. The security file 145 can be separate from the host system data 150. That is, memory device 130 can store the security file 145 in a first location (e.g., a first PSMU) and store the host system data 150 in a second location (e.g., a set of PSMUs that does not include the first PSMU). While the memory subsystem controller 115 is executing a boot procedure after a reset (e.g., rebuilding the L2P table or other operations to rebuild the media stored at memory device 130 to enable access to host system data 150), the security module 113 may request a security file system stored at security file 145. Even if host system data 150 is inaccessible and being rebuilt, memory device 130 can still access security file 145 because it is stored in a separate location. Memory device 130 can identify that the request is for security file 145 because the request may contain a unique identifier for security file 145 stored at the reserved PSMU. Therefore, memory device 130 can access security files 145 and send them back to security module 113. Security module 113 can respond to host identification controller commands while memory subsystem controller 115 continues media reconstruction. That is, the security module 113 can access the security file 145 while the memory device 130 continues to rebuild the host system data 150 stored in the memory device 130. For example, the security module 113 can perform the rebuild with the memory subsystem controller 115 to access the host system data 150 and access the security file 145 concurrently.
[0036] Figure 2 This is a flowchart of an example method 200 for restricting commands transmitted to a memory subsystem according to some embodiments of the present disclosure. Method 200 may be executed by processing logic, which may include hardware (e.g., processing device, circuit system, dedicated logic, programmable logic, microcode, device hardware, integrated circuit, etc.), software (e.g., instructions running or executed on a processing device), or a combination thereof. In some embodiments, method 200 is performed by… Figure 1Security module 113 executes. Although shown in a specific order or sequence, the order of processes is modifiable unless otherwise specified. Therefore, the illustrated embodiments should be understood as examples only, and the illustrated processes may be executed in different orders, and some processes may be executed in parallel. Furthermore, one or more processes may be omitted in various embodiments. Therefore, not all processes are required in every embodiment. Other process flows are possible.
[0037] In operation 210, the processing logic may receive an identification command. For example, the memory subsystem controller 115 may receive a host identification controller command from the host system 120. In some embodiments, the host identification controller command may enable the memory subsystem controller to determine whether there are other controllers in the system. Additionally, the host identification controller command may allow logical mapping between the host system and the memory system controller. In some embodiments, the processing logic may receive the identification command after a memory subsystem reset—for example, after PERST. In one embodiment, the reset is a cold reset—for example, power is supplied to the memory subsystem to energize it.
[0038] In operation 220, the processing logic may initiate a power-on initialization procedure. For example, the memory subsystem controller may initiate power-on (e.g., startup) initialization after a reset—for example, after PERST. In some embodiments, after a reset, the memory subsystem may reconstruct or rebuild the media (e.g., the memory device). In at least one embodiment, the processing logic may rebuild the L2P table during the power-on initialization procedure. In some embodiments, the power-on initialization procedure may include additional rebuild operations. In some embodiments, while performing the power-on initialization procedure, the memory subsystem controller cannot access stored data for the host system (e.g., user data). That is, the memory subsystem controller cannot write to, read from, or erase the physical location storing host system data.
[0039] In operation 230, the processing logic may initiate a security procedure. In at least one embodiment, the processing logic may execute the security procedure concurrently with power-on initialization. For example, the processing logic may initiate and complete the security procedure while performing power-on initialization. In at least one embodiment, the processing logic may identify which files the security module 113 will use in the security procedure. In an embodiment, the processing logic may execute the security procedure in response to host identification controller commands.
[0040] In operation 240, the processing logic may transmit access commands for files used in a secure program. In at least one embodiment, the memory device may store secure system files in a reserved PSMU separate from the host system. In such embodiments, the memory subsystem controller can access the secure system files at the reserved PSMU even if the remaining host system data is inaccessible—for example, still being rebuilt. Therefore, when sending an access command, the processing logic may include an identification of the secure file system stored at the reserved PSMU in the command. When the memory device receives the identification in the access command, it can identify that the command is for the secure system files at the reserved PSMU. In some embodiments, the memory device may also contain a reserved copy (e.g., a redundant copy or a second copy) of the secure system files at a second PSMU. If the processing logic detects one or more errors in the secure file system (e.g., errors detected due to error correction (ECC) operations), then the processing logic may copy the redundant secure file system to a third reserved PSMU. In such embodiments, the processing logic may send an access command identifying the secure system files stored at the third reserved PSMU.
[0041] In operation 250, the processing logic may receive a file requested from a secure file system. In some embodiments, the processing logic may receive a file that identifies the controller to the host system—for example, a file that can be used to determine whether the memory subsystem controller is the only controller in the system. In other embodiments, the processing logic may receive a file that maps (e.g., logically maps) the memory subsystem controller to the host system. In some embodiments, the processing logic may receive the file while performing a power-on (e.g., startup) procedure. That is, the processing logic may receive the file while the remainder of the media is being reconstructed.
[0042] In operation 260, the processing logic can execute a security program. In some embodiments, the processing logic can respond to host identification controller commands after receiving a security file. In some embodiments, the processing logic can respond to host identification controller commands based on the ability to access a secure file system before the remaining media is ready—for example, based on the secure file system's independence from the remaining host system data for a specified time.
[0043] In operation 270, the processing logic may perform power-on initialization. In some embodiments, the processing logic may perform and complete L2P table reconstruction and other operations associated with media reconstruction. In some embodiments, the processing logic may receive a media-ready state—for example, an indication that host system data is ready and accessible. In some embodiments, the processing logic may perform power-on initialization concurrently with the execution of a security procedure. In some embodiments, the processing logic may complete the security procedure before completing power-on initialization—for example, before the processing logic receives the media-ready state.
[0044] Figure 3 This is a flowchart of an example method 300 for restricting commands transmitted to a memory subsystem according to some embodiments of the present disclosure. Method 300 may be executed by processing logic, which may include hardware (e.g., processing device, circuit system, dedicated logic, programmable logic, microcode, device hardware, integrated circuit, etc.), software (e.g., instructions running or executed on a processing device), or a combination thereof. In some embodiments, method 300 is performed by… Figure 1 The security module 113 executes the method. In some embodiments, method 300 is executed by the local media controller 135 of the memory device 130. Although shown in a specific order or sequence, the order of the processes is modifiable unless otherwise specified. Therefore, the illustrated embodiments should be understood as examples only, and the illustrated processes may be executed in different orders, and some processes may be executed in parallel. In addition, one or more processes may be omitted in various embodiments. Therefore, not all processes are required in every embodiment. Other process flows are possible.
[0045] In operation 310, the processing logic performs power-on initialization (e.g., startup initialization). For example, the local media controller 135 may perform power-on initialization after the memory device is reset. In some embodiments, power-on initialization may include rebuilding the L2P table or other operations to make the media ready at the memory device. In some embodiments, the memory device may perform power-on initialization in response to a command received from the memory subsystem controller. In some embodiments, the memory device may perform power-on initialization after the memory subsystem controller receives a host identification controller command.
[0046] In operation 320, the processing logic may receive an access command. In some embodiments, the local media controller may receive the access command from the memory subsystem controller. In at least one embodiment, the access command may include identification—for example, file identification. In some embodiments, the local media controller may receive the access command concurrently with power-on initialization—for example, concurrently with power-on initialization.
[0047] In operation 330, the processing logic may determine that the received access command is associated with a file in a secure file system located at a reserved physical super management unit (PSMU) on the memory device. In some embodiments, the memory device may store the secure file in a reserved PSMU that is separate from the memory location storing host system data—for example, separate from other PSMUs storing host system data. In at least one embodiment, the local media controller may access the reserved PSMU at any time—for example, even while the remaining media is being rebuilt. In some embodiments, the file stored in the secure file system may have a unique identifier. When the local media controller receives an access command, the local media controller may compare the received identifier with the unique identifier of the secure file system. If the local media controller determines that the identifier in the access command is the same as the unique identifier, then the local media controller may access the file in the secure file system.
[0048] In operation 340, the processing logic may send the requested secure file. In some embodiments, the local media controller may send the secure file requested in the access command to the storage subsystem controller.
[0049] In operation 350, the processing logic may perform power-on initialization. In some embodiments, the processing logic may compare the L2P table rebuilt along with other operations to make the media ready. In some embodiments, the processing logic may send a media-ready indication or status to the memory subsystem controller after power-on initialization is complete. In such embodiments, the processing logic may access the PSMU storing host system data after sending the media-ready status—for example, performing read, write, or erase operations on the host system data.
[0050] In operation 360, the processing logic may optionally perform ECC operations on the secure file system stored at the reserved PSMU. In some embodiments, the local media controller may write the secure file system to the reserved PSMU. In such embodiments, the local media controller may not perform many additional writes to the reserved PSMU. That is, the number of writes to the reserved PSMU may be significantly less than the number of writes to the PSMU storing host system data. Therefore, the local media controller may avoid performing wear leveling operations or other media management operations at the reserved PSMU. Instead of utilizing wear leveling operations, the local media controller may perform occasional ECC operations at the reserved PSMU to ensure no degradation. If the local media controller finds an error at the reserved PSMU due to an error correction operation, then the local media controller may access a copy of the secure file system. In some embodiments, the processing logic may store a copy of the secure file system (e.g., a redundant copy or a second copy) at a different reserved PSMU. The different reserved PSMUs may also be separate from the host system data. If the local media controller detects an error at the initial reserved PSMU, then the local media controller may recover the secure file system from the copy. In such embodiments, the local media controller can write the secure file system to a new, retained PSMU (e.g., a third PSMU). Therefore, the local media controller can swap a degraded PSMU with the new PSMU. The local media controller can access the third PSMU upon receiving additional access commands for the secure file system.
[0051] Figure 4 An example machine illustrating computer system 400 is described, within which a set of instructions is executable to cause the machine to perform any or more of the methodologies discussed herein. In some embodiments, computer system 400 may correspond to a host system (e.g., Figure 1 The host system 120 includes, is coupled to or utilizes a memory subsystem (e.g., Figure 1 The memory subsystem 110) or can be used to perform controller operations (e.g., execute the operating system to perform operations corresponding to...). Figure 1 The security module 113 operates to perform security initialization. In alternative embodiments, the machine may connect (e.g., network) to other machines in a LAN, intranet, extranet, and / or the Internet. The machine may operate as a server or client machine in a client-server network environment, as a peer-to-peer (or distributed) network environment, or as a server or client machine in a cloud computing infrastructure or environment.
[0052] A machine can be a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular phone, a network device, a server, a network router, a switch, or a bridge, or any machine capable of (sequentially or otherwise) executing a set of instructions specifying actions to be taken by said machine. Furthermore, while a single machine is described, the term "machine" should also be considered as any collection of machines that individually or jointly execute one (or more) instructions to perform any or more of the methodologies discussed herein.
[0053] The example computer system 400 includes a processing device 402, a main memory 404 (e.g., read-only memory (ROM), flash memory, dynamic random access memory (DRAM) (e.g., synchronous DRAM (SDRAM) or RDRAM), static memory 406 (e.g., flash memory, static random access memory (SRAM)) and a data storage system 418, which communicate with each other via a bus 430.
[0054] Processing device 402 represents one or more general-purpose processing devices, such as microprocessors, central processing units, or the like. More specifically, the processing device may be a Complex Instruction Set Computing (CISC) microprocessor, a Reduced Instruction Set Computing (RISC) microprocessor, a Very Long Instruction Word (VLIW) microprocessor, or a processor implementing other instruction sets, or multiple processors implementing combinations of instruction sets. Processing device 402 may also be one or more special-purpose processing devices, such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), network processors, or the like. Processing device 402 is configured to execute instructions 426 for performing the operations and steps discussed herein. Computer system 400 may further include a network interface device 408 for communication via network 420.
[0055] Data storage system 418 may include machine-readable storage medium 424 (also referred to as computer-readable medium) thereon storing one or more sets of instructions 426 or software embodying any or more of the methodologies or functions described herein. Instructions 426 may also reside wholly or at least partially within main memory 404 and / or processing device 402 during execution by computer system 400, which also constitute machine-readable storage medium. Machine-readable storage medium 424, data storage system 418, and / or main memory 404 may correspond to... Figure 1 The memory subsystem 110.
[0056] In one embodiment, instruction 426 includes instructions to implement the functionality corresponding to security module 113 to initiate a security procedure for processing device 402. Although machine-readable storage medium 424 is shown as a single medium in the exemplary embodiment, the term "machine-readable storage medium" should be understood to include a single medium or multiple media containing one or more sets of instructions. The term "machine-readable storage medium" should also be considered to include any medium capable of storing or encoding a set of instructions for machine execution and causing the machine to perform any or more of the methods of this disclosure. The term "machine-readable storage medium" should be understood accordingly to include (but is not limited to) solid-state memory, optical media, and magnetic media.
[0057] Some parts of the foregoing detailed description have been presented based on the algorithms and symbolic representations of operations on data bits within computer memory. These algorithmic descriptions and representations are methods used by those skilled in the art of data processing to most effectively convey the essence of their work to others skilled in the art. Algorithms are, and generally are, conceived herein as self-consistent sequences of operations that lead to desired results. Operations are those that require the physical manipulation of physical quantities. Typically, though not always necessary, these quantities take the form of electrical or magnetic signals that can be stored, combined, compared, and otherwise manipulated. It has proven convenient, and sometimes, for customary use, these signals are referred to in principle as bits, values, elements, symbols, characters, items, numbers, or the like.
[0058] However, it should be remembered that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels for application to these quantities. This disclosure may relate to the operation and processes of a computer system or similar electronic computing device that manipulate or transform data representing physical (electronic) quantities in the registers and memories of the computer system into other data similarly represented in the memory or registers of the computer system or other such information storage systems.
[0059] This disclosure also relates to apparatus for performing the operations described herein. Such apparatus may be specially constructed for its intended purpose, or may comprise a general-purpose computer selectively activated or reconfigured by a computer program stored in a computer. This computer program may be stored in a computer-readable storage medium, such as (but not limited to) any type of disk, including floppy disks, optical disks, CD-ROMs and magneto-optical disks, read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards or optical cards, or any type of media suitable for storing electronic instructions, each coupled to a computer system bus.
[0060] The algorithms and displays presented herein are not inherently associated with any particular computer or other device. Various general-purpose systems can be used in conjunction with programs taught herein, or, as may prove convenient, more specialized devices can be constructed to execute the methods. The architectures of many such systems will appear as described below. Furthermore, this disclosure is not intended to refer to any particular programming language. It should be understood that various programming languages can be used to implement the teachings of this disclosure as described herein.
[0061] This disclosure may be provided as a computer program product or software, which may include a machine-readable medium having instructions stored thereon, the instructions being usable to program a computer system (or other electronic device) to perform processes according to this disclosure. The machine-readable medium includes any means for storing information in a form readable by a machine (e.g., a computer). In some embodiments, the machine-readable (e.g., computer-readable) medium includes machine-readable storage media, such as read-only memory (“ROM”), random access memory (“RAM”), disk storage media, optical storage media, flash memory components, etc.
[0062] In the foregoing description, embodiments thereof have been described with reference to specific examples of this disclosure. It will be understood that various modifications may be made to this disclosure without departing from the broader spirit and scope of the embodiments set forth in the appended claims. Therefore, the description and drawings should be regarded in an illustrative rather than restrictive sense.
Claims
1. A memory subsystem comprising: Memory devices; and A memory subsystem controller includes a processing unit operably coupled to the memory device, the processing unit being configured to perform operations including: Receive identification commands from the host system; In response to receiving the identification command, a security procedure is initiated; The access command is transmitted to the memory device, the access command including the identification of a first physical super management unit (PSMU) at a first physical location of the memory device storing a secure file system, wherein data for the host system is stored at a second physical location of the memory device, and wherein the first physical location is reserved for security-related files, and the first physical location is separate from the second physical location storing the data for the host system. In response to transmitting the access command, one or more security-related files are received from the secure file system, the one or more security-related files including files that identify the controller or files that map the memory subsystem controller to the host system; as well as In response to receiving the one or more security-related files, the security procedure is executed and the power-on initialization of the memory device is performed concurrently.
2. The memory subsystem of claim 1, wherein the processing means is configured to receive the identification command from the host system after the memory device is reset.
3. The memory subsystem of claim 1, wherein the processing means is configured to perform operations further comprising: In response to receiving the identification command, the power-on initialization is initiated, wherein transmitting the access command and performing the power-on initialization are at least partially concurrent.
4. The memory subsystem of claim 1, wherein the processing means is configured to perform operations further comprising: A response indicating that the identification command has been completed is transmitted to the host system.
5. The memory subsystem of claim 1, wherein the processing means is configured to perform operations further comprising: The reconstruction of the logical to physical L2P table is performed at least partially concurrently with the execution of the security procedure.
6. The system of claim 5, wherein the processing device is configured to perform operations further including: After receiving the one or more security-related files from the secure file system, a readiness notification is received that is associated with the second physical location of the memory device storing the data for the host system.
7. The memory subsystem of claim 1, wherein a copy of the secure file system is stored at a second physical super management unit (PSMU) at the first physical location of the memory device.
8. A method for a memory subsystem, the method comprising: Receive identification commands from the host system; In response to receiving the identification command, a security procedure is initiated; Transmit an access command to a memory device, the access command including the identification of a first physical super management unit (PSMU) at a first physical location of the memory device storing a secure file system, wherein data for the host system is stored at a second physical location of the memory device, and wherein the first physical location is reserved for security-related files, and the first physical location is separate from the second physical location storing the data for the host system. In response to transmitting the access command, one or more security-related files are received from the secure file system, the one or more security-related files including files identifying the controller or files mapping the memory subsystem controller to the host system; as well as In response to receiving the one or more security-related files, the security procedure is executed and the power-on initialization of the memory device is performed concurrently.
9. The method of claim 8, wherein the identification command is received from the host system after the memory device is reset.
10. The method of claim 8, further comprising: In response to receiving the identification command, the power-on initialization is initiated, wherein transmitting the access command and performing the power-on initialization are at least partially concurrent.
11. The method of claim 8, further comprising: A response indicating the completion of the identification command is transmitted to the host system.
12. The method of claim 8, further comprising: The reconstruction of the logical to physical L2P table is performed at least partially concurrently with the execution of the security procedure.
13. The method of claim 8, further comprising: After receiving the one or more security-related files from the secure file system, a ready state is received associated with the second physical location of the memory device storing the data for the host system.
14. The method of claim 8, wherein a copy of the secure file system is stored at a second physical super management unit (PSMU) at the first physical location of the memory device.
15. A memory subsystem comprising: Memory devices; and A memory subsystem controller includes a processing unit operably coupled to the memory device, the processing unit being configured to perform operations including: Perform power-on initialization of the memory device; Receive access commands with file identification; Based on the file identification, the access command is associated with a Physical Super Management Unit (PSMU) at a first physical location of the storage device of the secure file system, wherein data for the host system is stored at a second physical location of the storage device, and wherein the first physical location is reserved for security-related files, and the first physical location is separate from the second physical location storing the data for the host system. as well as In response to determining that the access command is associated with the security-related file, the security-related file stored at the PSMU is transmitted, wherein the transmission of the security-related file is concurrent with the power-on initialization of the memory device and the execution of a portion of the security procedure, and wherein the security-related file includes a file identifying the controller or a file mapping the memory subsystem controller to the host system.
16. The memory subsystem according to claim 15, wherein: The memory device stores data for the host system at the second physical location of the memory device; and The processing device is used to perform further operations including the following: Avoid performing wear leveling operations on the PSMU storing the secure file system.
17. The memory subsystem of claim 16, wherein the processing means is configured to perform operations further comprising: After transmitting the security-related files stored at the PSMU, a readiness state associated with the data stored at the second physical location of the memory device is transmitted.
18. The memory subsystem of claim 15, wherein the memory device further stores a copy of the secure file system at a second PSMU at the first physical location of the memory device.
19. The memory subsystem of claim 16, wherein the processing means is configured to perform operations further comprising: Perform error correction operations on the secure file system stored at the PSMU at the first physical location of the memory device; In response to performing the error correction operation, one or more errors associated with the secure file system are identified; and In response to determining one or more errors, the secure file system stored at the second PSMU at the first physical location of the memory device is copied to the third PSMU at the first physical location of the memory device.
20. The memory subsystem of claim 15, wherein the processing means is configured to perform operations further comprising: The reconstruction of the logical to physical L2P table is performed at least partially concurrently with the transmission of the security-related files.