Memory system and operating method thereof, host and operating method thereof, electronic device
By introducing dynamic authentication information and key update mechanisms into the memory system, the problem of insufficient security in existing memory systems is solved, the system's protection capabilities are improved, and its resistance to unauthorized access is enhanced.
Patent Information
- Application Number
- CN202311232680.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-21
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2043-09-21
AI Technical Summary
The security authentication mechanisms of existing memory systems are easily cracked, posing significant security risks and making it difficult to effectively prevent malicious access by unauthorized users and data leakage.
By generating dynamic authentication information and a dynamic update mechanism for keys, and utilizing dynamic information interaction between the memory controller and the host controller, dynamic matching of authentication information and key updates are achieved, thereby improving security.
It enhances the security of the memory system, increases the difficulty of malicious unlocking, and strengthens the protection against unauthorized access.
Smart Images

Figure CN119668494B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to, but is not limited to, a memory system and its operation method, a host and its operation method, an electronic device, and a computer-readable storage medium. Background Technology
[0002] With the rapid development of data storage technology, more and more data storage systems are appearing in electronic devices used by people, such as solid-state drives (SSDs). Due to their characteristics of fast read and write speeds, shock resistance, low power consumption, no noise, low heat, and light weight, SSDs have been widely used in military, automotive, industrial, medical, and aerospace fields.
[0003] However, there are still many problems to be solved in the memory systems of related technologies. Summary of the Invention
[0004] According to a first aspect of the present disclosure, a memory system is provided, the memory system comprising:
[0005] The memory is configured to store key information; and
[0006] A memory controller, coupled to the memory and configured to:
[0007] First authentication information is generated based on the first dynamic information and the first key determined from the key information;
[0008] Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0009] Determine whether the first authentication information matches the second authentication information;
[0010] In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated;
[0011] Update the first authentication information based on the second dynamic information and the first key;
[0012] Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0013] The system determines that authentication has been successful upon matching the updated first authentication information with the updated second authentication information.
[0014] In some embodiments, the memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
[0015] In some embodiments, the memory controller is further configured to:
[0016] Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained.
[0017] In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
[0018] In some implementations, the memory is external to the memory controller, and the key information includes a key set and key rules, the key rules being used to select a key from the key set to generate the first key.
[0019] In some implementations, the memory controller is configured to:
[0020] A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
[0021] In some implementations, the memory controller is configured to:
[0022] If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
[0023] In some implementations, the memory controller is configured to:
[0024] If authentication is successful, the received read and / or write commands are allowed to be executed;
[0025] If authentication fails, the received read and / or write commands will not be allowed to be executed.
[0026] In some implementations, the memory controller is configured to:
[0027] If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
[0028] According to a second aspect of the present disclosure, a host is provided, the host including a host controller and a host interface.
[0029] The host interface is configured as follows:
[0030] Receive the first dynamic information from the memory system;
[0031] Receive second dynamic information from the memory system;
[0032] The updated second authentication information is sent to the memory system;
[0033] The host controller is configured as follows:
[0034] The second authentication information is generated based on the first dynamic information and the second key determined from the key information;
[0035] In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; the first authentication information is generated based on the first dynamic information and the first key in the memory system.
[0036] Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
[0037] In some implementations, the host controller is configured to:
[0038] Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
[0039] According to a third aspect of the present disclosure, an electronic device is provided, the electronic device including a host and a memory system; wherein, the memory system includes a memory and a memory controller coupled to the memory, and the host includes a host controller and a host interface;
[0040] The memory is configured to store key information;
[0041] The memory controller is configured to:
[0042] First authentication information is generated based on the first dynamic information and the first key determined from the key information;
[0043] Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0044] Determine whether the first authentication information matches the second authentication information;
[0045] In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated;
[0046] Update the first authentication information based on the second dynamic information and the first key;
[0047] Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0048] In response to the matching of the updated first authentication information and the updated second authentication information, authentication is confirmed to be successful;
[0049] The host interface is configured as follows:
[0050] Receive the first dynamic information from the memory system;
[0051] Receive the second dynamic information from the memory system;
[0052] The updated second authentication information is sent to the memory system;
[0053] The host controller is configured as follows:
[0054] The second authentication information is generated based on the first dynamic information and the second key determined from the key information;
[0055] In response to a mismatch between the second authentication information and the first authentication information, the second key is updated;
[0056] Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
[0057] According to a fourth aspect of the present disclosure, a method for operating a memory system is provided, wherein first authentication information is generated based on first dynamic information and a first key determined from key information stored in the memory of the memory system;
[0058] Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0059] Determine whether the first authentication information matches the second authentication information;
[0060] In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated;
[0061] Update the first authentication information based on the second dynamic information and the first key;
[0062] Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0063] The system determines that authentication has been successful upon matching the updated first authentication information with the updated second authentication information.
[0064] In some embodiments, the memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
[0065] In some embodiments, the method further includes:
[0066] Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained.
[0067] In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
[0068] In some implementations, the memory is external to the memory controller, and the key information includes a key set and key rules, the key rules being used to select a key from the key set to generate the first key.
[0069] In some embodiments, the method further includes:
[0070] A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
[0071] In some embodiments, the method further includes:
[0072] If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
[0073] In some embodiments, the method further includes:
[0074] If authentication is successful, the received read and / or write commands are allowed to be executed;
[0075] If authentication fails, the received read and / or write commands will not be allowed to be executed.
[0076] In some embodiments, the method further includes:
[0077] If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
[0078] According to a fifth aspect of the present disclosure, a method for operating a host is provided, comprising:
[0079] Receive the first dynamic information from the memory system;
[0080] The second authentication information is generated based on the first dynamic information and the second key determined from the key information;
[0081] In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; the first authentication information is generated based on the first dynamic information and the first key in the memory system.
[0082] Receive second dynamic information from the memory system;
[0083] Based on the second dynamic information and the updated second key, generate updated second authentication information;
[0084] The updated second authentication information is sent to the memory system.
[0085] In some embodiments, the method further includes:
[0086] Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
[0087] According to a sixth aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, performs an operation method of a host as described in any of the above embodiments.
[0088] In this embodiment, firstly, first authentication information is generated based on first dynamic information and a first key, and second authentication information is generated based on the first dynamic information and a second key. The method of determining whether authentication is successful by checking whether the first authentication information and the second authentication information match improves security compared to directly comparing the first key and the second key. Secondly, in the event of a previous authentication failure, second dynamic information is generated during the re-authentication process. Since the generated dynamic information is different each time, this increases the difficulty of maliciously unlocking the memory system, further enhancing the security of the memory system. Attached Figure Description
[0089] Figure 1 This is a schematic diagram of an exemplary electronic device having a memory system according to an embodiment of the present disclosure;
[0090] Figure 2a This is a schematic diagram of an exemplary memory card having a memory system according to an embodiment of the present disclosure;
[0091] Figure 2b This is a schematic diagram of an exemplary solid-state drive with a memory system according to an embodiment of the present disclosure;
[0092] Figure 3 This is a schematic diagram of an exemplary memory device including peripheral circuitry according to an embodiment of the present disclosure;
[0093] Figure 4 This is a schematic cross-sectional view of a memory array including memory strings according to an embodiment of the present disclosure;
[0094] Figure 5 This is a schematic diagram of an exemplary memory including a memory array and peripheral circuitry according to an embodiment of the present disclosure;
[0095] Figure 6 This is a schematic diagram of the frame structure of an electronic device according to an embodiment of the present disclosure;
[0096] Figure 7 This is a schematic diagram illustrating the implementation flow of an operation method for a memory system according to an embodiment of the present disclosure;
[0097] Figure 8 This is a schematic diagram illustrating the implementation flow of a host operation method according to an embodiment of the present disclosure;
[0098] Figure 9 This is a schematic diagram of the framework process for authenticating a memory system according to an embodiment of the present disclosure. Detailed Implementation
[0099] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the specific embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0100] In the following description, numerous specific details are set forth in order to provide a more thorough understanding of this disclosure. However, it will be apparent to those skilled in the art that this disclosure may be practiced without one or more of these details. In other instances, to avoid confusion with this disclosure, certain technical features well-known in the art have not been described; that is, not all features of actual embodiments are described herein, nor are well-known functions and structures described in detail.
[0101] In the accompanying drawings, for clarity, the dimensions of layers, areas, and elements, as well as their relative dimensions, may be exaggerated. The same reference numerals denote the same elements throughout.
[0102] It should be understood that when an element or layer is referred to as "on," "adjacent to," "connected to," or "coupled to" other elements or layers, it may be directly on, adjacent to, connected to, or coupled to other elements or layers, or there may be intervening elements or layers. Conversely, when an element is referred to as "directly on," "directly adjacent to," "directly connected to," or "directly coupled to" other elements or layers, there are no intervening elements or layers. It should be understood that although the terms first, second, third, etc., may be used to describe various elements, components, areas, layers, and / or portions, these elements, components, areas, layers, and / or portions should not be limited by these terms. These terms are only used to distinguish one element, component, area, layer, or portion from another element, component, area, layer, or portion. Therefore, without departing from the teachings of this disclosure, the first element, component, area, layer, or portion discussed below may be referred to as a second element, component, area, layer, or portion. And the discussion of a second element, component, area, layer, or portion does not imply that the first element, component, area, layer, or portion necessarily exists in this disclosure.
[0103] Spatial relation terms such as “below,” “under,” “below,” “under,” “above,” “above,” etc., are used herein for convenience of description to describe the relationship between one element or feature shown in the figure and other elements or features. It should be understood that, in addition to the orientation shown in the figure, spatial relation terms are intended to also include different orientations of the device in use and operation. For example, if the device in the figure is flipped, then the element or feature described as “below,” “under,” or “below” other elements or features will be oriented “above” other elements or features. Therefore, the exemplary terms “below” and “under” can include both above and below orientations. The device may be otherwise oriented (rotated 90 degrees or otherwise) and the spatial descriptive terms used herein will be interpreted accordingly.
[0104] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. When used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the terms “comprise” and / or “comprising,” when used in this specification, identify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups. When used herein, the term “and / or” includes any and all combinations of the associated listed items.
[0105] To gain a more detailed understanding of the features and technical content of the embodiments of this disclosure, the implementation of the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this disclosure.
[0106] Figure 1 A block diagram of an exemplary electronic device 100 having memory according to some aspects of this disclosure is shown. Electronic device 100 may be a mobile phone, desktop computer, laptop computer, tablet computer, vehicle computer, game console, printer, positioning device, wearable electronic device, smart sensor, virtual reality (VR) device, augmented reality device, or any other suitable electronic device having storage therein. Figure 1 As shown, electronic device 100 may include host 108 and memory system 102, the memory system 102 having one or more memory devices 104 and memory controller 106. Host 108 may be a processor (e.g., central processing unit) or system-on-a-chip (e.g., application processor) of electronic device. Host 108 may be configured to send data to memory device 104 or receive data from memory device 104.
[0107] According to some embodiments, memory controller 106 is coupled to memory device 104 and host 108 and is configured to control memory device 104. Memory controller 106 can manage data stored in memory device 104 and communicate with host 108. In some embodiments, memory controller 106 is designed to operate in low duty cycle environments, such as secure digital cards, compact flash memory cards, universal serial bus flash drives, or other media used in electronic devices such as personal calculators, digital cameras, mobile phones, etc. In some embodiments, memory controller 106 is designed to operate in high duty cycle environments, such as SSDs or embedded multimedia cards used as data storage in mobile devices such as smartphones, tablets, laptops, etc., and in enterprise storage arrays.
[0108] The memory controller 106 can be configured to control the operation of the memory device 104, such as read, erase, and program operations. The memory controller 106 can also be configured to manage various functions relating to data stored or to be stored in the memory device 104, including but not limited to bad block management, garbage collection, logical-to-physical address translation, wear leveling, etc. In some embodiments, the memory controller 106 is also configured to process error correction codes relating to data read from or written to the memory device 104. The memory controller 106 can also perform any other suitable function, such as formatting the memory device 104. The memory controller 106 can communicate with an external device (e.g., host 108) according to a specific communication protocol. For example, the memory controller 106 can communicate with an external device via at least one of various interface protocols, such as USB, MMC, Peripheral Component Interconnect (PCI), Peripheral Component Interconnect High Speed (PCHIHS), Advanced Technology Attached Protocol (ATIP), Serial Advanced Technology Attached Protocol (STP), Parallel Advanced Technology Attached Protocol (PATP), Minicomputer Small Interface Protocol (MSIP), Enhanced Small Disk Interface (MSDI), Integrated Drive Electronic Devices Protocol (IDEMP), firmware protocols, etc.
[0109] The memory controller 106 and one or more memory devices 104 can be integrated into various types of storage devices, for example, included in the same package (e.g., a Universal Flash Storage (UFS) package or an embedded multimedia card package). That is, the memory system 102 can be implemented and packaged into different types of end electronic products. Figure 2aIn one example shown, the memory controller 106 and a single memory device 104 may be integrated into a memory card 202. The memory card 202 may include a compact flash memory card, a smart media card, a memory stick, a multimedia card, a secure digital card, UFS, etc. The memory card 202 may also include a connection between the memory card 202 and a host (e.g., Figure 1 The host 108) is coupled to the memory card connector 204. In such a... Figure 2b In another example shown, the memory controller 106 and multiple memory devices 104 may be integrated into the SSD 206. The SSD 206 may also include components for connecting the SSD 206 to a host computer (e.g., Figure 1 The SSD connector 208 is coupled to the host 108. In some embodiments, the storage capacity and / or operating speed of the SSD 206 is greater than the storage capacity and / or operating speed of the memory card 202.
[0110] Figure 3 A schematic circuit diagram of an exemplary memory device 300, including peripheral circuitry, is shown according to some aspects of this disclosure. The memory device 300 may be... Figure 1 An example of memory device 104 is provided. Memory device 300 may include memory array 301 and peripheral circuitry 302 coupled to memory array 301. Taking memory array 301 as an example of a three-dimensional NAND-type memory array, where memory cells 306 are NAND memory cells, provided in the form of an array of memory strings 308, each memory string 308 extending vertically above a substrate (not shown). In some embodiments, each memory string 308 includes a plurality of memory cells 306 coupled in series and stacked vertically. Each memory cell 306 may hold a continuous analog value, such as voltage or charge, depending on the number of electrons trapped in the region of memory cell 306. Each memory cell 306 may be a floating-gate type memory cell including a floating-gate transistor, or a charge-trapping type memory cell including a charge-trapping transistor.
[0111] In some implementations, each memory cell 306 is a single-level cell (SLC) having two possible memory states and thus capable of storing one bit of data. For example, a first memory state "0" may correspond to a first voltage range, and a second memory state "1" may correspond to a second voltage range. In some implementations, each memory cell 306 is a multi-level cell (MLC) capable of storing more than a single bit of data in more than four memory states. For example, an MLC may store two bits per cell, three bits per cell (also known as a three-level cell (TLC)), or four bits per cell (also known as a four-level cell (QLC)). Each MLC can be programmed to take a range of possible nominal storage values. In one example, if each MLC stores two bits of data, the MLC can be programmed to take one of three possible programming levels from the erase state by writing one of the three possible nominal storage values to the cell. A fourth nominal storage value can be used for the erase state.
[0112] like Figure 3 As shown, each memory string 308 may include a bottom-selected transistor (BST) 310 at its source end and a top-selected transistor (TST) 312 at its drain end. BST 310 and TST 312 may be configured to activate the selected memory string 308 during read and program operations. In some embodiments, the sources of memory strings 308 within the same memory block 304 are coupled via a common source line (SL) 314 (e.g., a common SL). In other words, according to some embodiments, all memory strings 308 within the same memory block 304 have an array common source (ACS). According to some embodiments, the TST 312 of each memory string 308 is coupled to a corresponding bit line (BL) 316, from which data can be read or written via an output bus (not shown). In some implementations, each memory string 308 is configured to be selected or deselected by applying a selection voltage (e.g., higher than the threshold voltage of the transistor having TST312) or a deselection voltage (e.g., 0V) to the corresponding TST312 via one or more TSL (Top selected line) 313 and / or by applying a selection voltage (e.g., higher than the threshold voltage of the transistor having BST310) or a deselection voltage (e.g., 0V) to the corresponding BST310 via one or more BSL (Bottom Selected line) 315.
[0113] like Figure 3As shown, memory strings 308 can be organized into multiple memory blocks 304, each of which may have a common source line 314 (e.g., coupled to ground). In some embodiments, each memory block 304 is the basic data unit for an erase operation, i.e., all memory cells 306 on the same memory block 304 are erased simultaneously. To erase memory cells 306 in a selected memory block, an erase voltage (Vers) (e.g., a high positive voltage (e.g., 20V or higher)) biased and coupled to the source line 314 of the selected memory block and unselected memory blocks on the same plane as the selected memory block can be used. It should be understood that in some examples, erase operations can be performed at the half-block level, at the quarter-block level, or at a level with any suitable number of memory blocks or any suitable fraction of memory blocks. Memory cells 306 of adjacent memory strings 308 can be coupled via word lines 318, which select which row of memory cells 306 is affected by read and program operations. In some implementations, each word line 318 is coupled to a memory page 320 of memory cell 306. The size of a memory page 320, in bits, may be related to the number of memory strings 308 coupled by word lines 318 in a memory block 304. Each word line 318 may include multiple control gates (gate electrodes) at each memory cell 306 in the corresponding memory page 320, as well as gate lines coupling the control gates.
[0114] Figure 4 A schematic cross-sectional view of an exemplary memory array 301 including a memory string 308 is shown, according to some aspects of this disclosure. Figure 4 As shown, the memory string 308 may include a stacked structure 410, which includes multiple gate layers 411 and multiple insulating layers 412 stacked alternately in sequence, and a memory string 308 perpendicularly penetrating the gate layers 411 and insulating layers 412. The gate layers 411 and insulating layers 412 may be stacked alternately, with adjacent gate layers 411 separated by an insulating layer 412. The number of memory cells included in the memory array 301 is mainly related to the number of pairs of gate layers 411 and insulating layers 412 in the stacked structure 410.
[0115] The constituent materials of the gate layer 411 may include conductive materials. Conductive materials include, but are not limited to, tungsten (W), cobalt (Co), copper (Cu), aluminum (Al), polysilicon, doped silicon, silicide, or any combination thereof. In some embodiments, each gate layer 411 includes a metal layer, such as a tungsten layer. In some embodiments, each gate layer 411 includes a doped polysilicon layer. Each gate layer 411 may include a control gate surrounding a memory cell. The gate layer 411 at the top of the stack 410 may extend laterally as an upper select gate line, the gate layer 411 at the bottom of the stack 410 may extend laterally as a lower select gate line, and the gate layer 411 extending laterally between the upper and lower select gate lines may serve as a word line layer.
[0116] In some embodiments, the stacked structure 410 may be disposed on the substrate 401. The substrate 401 may include silicon (e.g., single-crystal silicon), silicon germanium (SiGe), gallium arsenide (GaAs), germanium (Ge), silicon-on-insulator (SOI), germanium-on-insulator (GOI), or any other suitable material.
[0117] In some embodiments, the memory string 308 includes a channel structure extending vertically through the stacked structure 410. In some embodiments, the channel structure includes channel holes filled with one or more semiconductor materials (e.g., as a semiconductor channel) and one or more dielectric materials (e.g., as a memory film). In some embodiments, the semiconductor channel includes silicon, for example, polycrystalline silicon. In some embodiments, the memory film is a composite dielectric layer including a tunneling layer, a storage layer (also referred to as a "charge trap / storage layer"), and a barrier layer. The channel structure may have a cylindrical shape (e.g., a pillar shape). According to some embodiments, the semiconductor channel, tunneling layer, storage layer, and barrier layer are arranged radially from the center of the pillar toward the outer surface of the pillar in this order. The tunneling layer may include silicon oxide, silicon oxynitride, or any combination thereof. The storage layer may include silicon nitride, silicon oxynitride, or any combination thereof. The barrier layer may include silicon oxide, silicon oxynitride, a high dielectric constant (high k) dielectric, or any combination thereof. In one example, the memory film may include a composite layer of silicon oxide / silicon oxynitride / silicon oxide (ONO).
[0118] Return to reference Figure 3Peripheral circuitry 302 can be coupled to memory array 301 via bit line 316, word line 318, source line 314, BSL 315, and TSL 313. Peripheral circuitry 302 can include any suitable analog, digital, and mixed-signal circuitry to facilitate operation of memory array 301 by applying voltage and / or current signals to each target memory cell 306 via bit line 316, word line 318, source line 314, BSL 315, and TSL 313, and sensing voltage and / or current signals from each target memory cell 306. Peripheral circuitry 302 can include various types of peripheral circuitry formed using metal-oxide-semiconductor technology. For example, Figure 5 Some exemplary peripheral circuitry is shown. Peripheral circuitry 302 includes a page buffer / sensor amplifier 504, a column decoder / bit line driver 506, a row decoder / word line driver 508, a voltage generator 510, a control logic unit 512, a register 514, a third interface 516, and a data bus 518. It should be understood that in some examples, additional peripheral circuitry may be included. Figure 5 Additional peripheral circuitry not shown.
[0119] Page buffer / sensor amplifier 504 can be configured to read data from memory array 301 and program (write) data to memory array 301 according to control signals from control logic unit 512. In one example, page buffer / sensor amplifier 504 can store a page of programming data (write data) to be programmed into a page 320 of memory array 301. In another example, page buffer / sensor amplifier 504 can perform a programming verification operation to ensure that data has been correctly programmed into memory cell 306 coupled to selected word line 318. In yet another example, page buffer / sensor amplifier 504 can also sense a low-power signal from bit line 316 representing a data bit stored in memory cell 306 and amplify a small voltage swing to a recognizable logic level during read operations. Column decoder / bit line driver 506 can be configured to be controlled by control logic unit 512 and select one or more memory strings 308 by applying a bit line voltage generated from voltage generator 510.
[0120] The row decoder / word line driver 508 can be configured to be controlled by the control logic unit 512 and to select / deselect memory blocks 304 of the memory array 301 and to select / deselect word lines 318 of memory blocks 304. The row decoder / word line driver 508 can also be configured to drive word lines 318 using word line voltages generated from the voltage generator 510. In some embodiments, the row decoder / word line driver 508 can also select / deselect and drive BSL 315 and TSL 313. As described in detail below, the row decoder / word line driver 508 is configured to perform programming operations on memory cells 306 coupled to one or more selected word lines 318. The voltage generator 510 can be configured to be controlled by the control logic unit 512 and to generate word line voltages (e.g., read voltage, programming voltage, pass voltage, local voltage, verification voltage, etc.), bit line voltages, and source line voltages to be supplied to the memory array 301.
[0121] Control logic unit 512 can be coupled to each of the peripheral circuits described above and is configured to control the operation of each peripheral circuit. Register 514 can be coupled to control logic unit 512 and includes a status register, a command register, and an address register for storing status information, command opcodes (OP codes), and command addresses for controlling the operation of each peripheral circuit. Third interface 516 can be coupled to control logic unit 512 and acts as a control buffer to buffer control commands received from the host (not shown) and relay them to control logic unit 512, as well as to buffer status information received from control logic unit 512 and relay it to the host. Third interface 516 can also be coupled to column decoder / bit line driver 506 via data bus 518 and acts as a data I / O interface and data buffer to buffer data and relay it to or from memory array 301.
[0122] Figure 6A block diagram of an electronic device is shown. The electronic device includes a host and a memory system. The memory system 601 includes a memory controller 602 and a memory device 603. The memory controller 602 controls the memory device 603 to perform read and write operations. Here, the memory controller 602 and the memory device 603 can be coupled in any suitable manner. The memory controller 602 includes a control unit (CPU) 608, a register 609, an error correction module 606, a first interface 605, a second interface 607, a second encryption module 611, and a random number generator 612. In this embodiment, the memory device 603 can be a non-volatile semiconductor memory for storing data, such as a NAND flash memory. The memory system 601 is connected to the host 604. The first interface 605 outputs commands received from the host 604, valid data (write data), etc., to a first internal bus 610 in the memory system 601, and sends valid data read from the memory device 603 (read data), responses from the control unit 608, etc., to the host 604.
[0123] The second interface 607 controls the processes of writing data to and reading data from the memory device 603 based on instructions from the control unit 608. The control unit 608 controls the memory system 601 as a whole; the control unit 608 may be, for example, a central processing unit (CPU) or a microprocessor (MPU). The control unit 608 performs control based on commands received from the host 604 via the first interface 605. For example, the control unit 608 instructs the second interface 607 to write data to the memory device 603 based on a command from the host 604. Furthermore, the control unit 608 instructs the second interface 607 to read data from the memory device 603 based on a command from the host 604.
[0124] The buffer 609 temporarily saves the data received from the host 604 before storing it in the memory device 603, and temporarily saves the data read from the memory device 603 before sending it to the host 604.
[0125] The error correction module 606 is a data encoding and decoding unit. Because flash memory inherently has a bit error rate, error checking and correction (ECC) protection must be added to the original data during data writing operations to ensure data integrity. This is an encoding process. Similarly, when reading data, decoding is required for error detection and correction. If the number of erroneous bits exceeds the ECC error correction capability, the data will be uploaded to the host in an "uncorrectable" form. The ECC encoding and decoding process is performed by the error correction module 606.
[0126] The host 604 includes a host controller 613 and a host interface 614. The host controller 613 includes a command module 615 and a first encryption module 616. The host interface 614 receives commands and valid data (write data) received from the memory system 601, and sends the commands generated by the command module 615 and the data in the host to the memory system 601.
[0127] User data is typically stored in memory devices within a memory system, and firmware is stored in the memory controller. Operations of the memory system are achieved by running this firmware. If the memory system is accessed by an unauthorized user, important data in the memory devices could be leaked or maliciously modified, or the firmware in the memory controller could be maliciously replaced. For security reasons, the memory system can be locked by default. When the memory system is locked, many commands (such as read and write commands) cannot be executed. Authorized users must first send specific commands for authentication to unlock the memory system before read / write commands can be executed. However, in some embodiments, the authentication mechanism for the memory system is weak, and even unauthorized users may be able to crack it. Once cracked, it is vulnerable to malicious commands that could be sent to launch attacks, posing a significant security risk to the memory system.
[0128] Improving the security of memory systems has become an urgent problem to be solved.
[0129] To address one or more of the aforementioned problems, embodiments of this disclosure provide a method for operating a memory system, such as... Figure 7 As shown, the method includes:
[0130] Step S1001: Generate first authentication information based on the first dynamic information and the first key determined from the key information stored in the memory of the memory system;
[0131] Step S1002: Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0132] Step S1003: Determine whether the first authentication information matches the second authentication information;
[0133] Step S1004: In response to the mismatch between the first authentication information and the second authentication information, generate second dynamic information;
[0134] Step S1005: Update the first authentication information according to the second dynamic information and the first key;
[0135] Step S1006: Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0136] Step S1007: In response to the matching of the updated first authentication information and the updated second authentication information, it is determined that the authentication has been passed.
[0137] In this embodiment, firstly, first authentication information is generated based on first dynamic information and a first key, and second authentication information is generated based on the first dynamic information and a second key. The method of determining whether authentication is successful by checking whether the first authentication information and the second authentication information match is more secure than directly comparing the first key and the second key. Secondly, in the event of a previous authentication failure, second dynamic information is generated during the re-authentication process. Since the generated dynamic information is different each time, this increases the difficulty of maliciously unlocking the memory system, further enhancing the security of the memory system.
[0138] In some embodiments, the method further includes:
[0139] Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained.
[0140] In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
[0141] The command to obtain the authorization status information of the memory system can be sent by the host. The host can choose to obtain only the lock status information, or it can choose to obtain both the lock status information and the first dynamic information.
[0142] Here, the memory system may include a memory and a memory controller. The memory stores key information, and the execution entity in the above-mentioned memory system operation method may be the memory controller.
[0143] In some embodiments, the memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
[0144] The random numbers here can be obtained by a random number generator based on a random number seed. The random number seed refers to the initial value used in the random number generator to generate random numbers. The random number seed can be obtained using software or hardware. For example, when the random number seed is obtained through hardware, the randomness of the seed comes from the randomness of the collected hardware information. This could be obtained by collecting sound, light, and electrical information from the current environment, or by collecting noise from the computer system during operation, such as timestamps of I / O (Input / Output) operations. These I / O operation timestamps include, but are not limited to, timestamps from disks, networks, and devices such as keyboards and mice. These timestamps are captured and their millisecond or microsecond portions are extracted; this portion of the value is usually random and non-repeatable. Random number seeds obtained through hardware are truly random. Random number seeds can also be obtained through software, for example, using the `seed(a)` function. Here, `a` is the value obtained through software or hardware. Random numbers can be obtained using the `random(b)` function, where `b` is the random number seed.
[0145] In some embodiments, the memory is external to the memory controller, and the key information includes a key set and key rules, wherein the key rules are used to select a key from the key set to generate the first key.
[0146] In some specific examples, the memory may be external to the memory controller; exemplary examples include NAND memory devices coupled to the memory controller. In other specific examples, the memory may be other non-volatile memory external to the memory controller. In still other specific examples, the memory may be non-volatile memory built into the memory controller.
[0147] In some specific examples, the key set may include multiple keys, and the key rules specify the rules for selecting keys from the key set.
[0148] In some embodiments, the method further includes:
[0149] A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
[0150] Here, the memory controller can directly load the key information stored in the memory, thereby generating the first key within the memory controller. The memory controller can then use the first dynamic information and the first key, along with an encryption algorithm such as a hash algorithm, to generate first authentication information.
[0151] It is understood that, in this embodiment of the present disclosure, the first key in the memory controller is not directly compared with the second key input by the host. Instead, the first key and the first dynamic information are encrypted using an encryption algorithm to generate the first authentication information, and the second key and the first dynamic information are encrypted using an encryption algorithm to generate the second authentication information. Since the first dynamic information is a random number, this makes the security higher.
[0152] In some specific examples, the second authentication information in the host is generated based on the first dynamic information sent to the host by the memory controller and the second key in the host. This second key can be input by the user terminal, specifically generated by the user reading key information. The memory storing the key information can include multiple memories or only one. For example, the key information can be stored solely in the NAND memory device, or it can be stored separately in the NAND memory device and other non-volatile memories of the memory controller peripheral. The first key can be generated by loading key information from the NAND memory device, and the second key can be generated by reading key information from other non-volatile memories; alternatively, both the first and second keys can be generated based on key information from the NAND memory device.
[0153] Understandably, authorized users know the specific location of the key information stored in the memory. For example, the key information can be set in a specific byte segment of a byte file in the memory. Only by knowing which byte segment the key information is located can the user correctly obtain the key information and input the correct second key, so that the first key matches the second key, and thus the generated first authentication information matches the second authentication information. However, when users do not know the specific location of the key information stored in the memory, they may not be able to obtain the correct key information, thus inputting an incorrect second key, causing the second key to not match the first key, and thus the first authentication information to not match the second authentication information.
[0154] When the first authentication information does not match the second authentication information, it indicates that the second key entered by the user is incorrect, the memory system cannot be unlocked successfully, authentication fails, and re-authentication is required. In this embodiment of the disclosure, when the first authentication information and the second authentication information do not match, second dynamic information is generated for re-authentication.
[0155] Understandably, the difference between the second dynamic information and the first dynamic information increases the difficulty of deciphering the authentication information and enhances security.
[0156] During the re-authentication process, the memory controller generates updated first authentication information based on the second dynamic information and the first key. The user can update the second key on the host side. The host generates updated second authentication information using the updated second key and the second dynamic information, and sends the updated second authentication information to the memory controller. After receiving the updated second authentication information, the memory controller determines whether the updated first authentication information matches the updated second authentication information. If the updated first authentication information matches the updated second authentication information, the authentication is successful.
[0157] In some embodiments, the method further includes:
[0158] If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
[0159] In some specific examples, if re-authentication fails, the decision to re-authenticate can be made based on the authentication time and the number of times authentication has already been performed.
[0160] In some embodiments, the method further includes:
[0161] If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
[0162] In some specific examples, if authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time is less than or equal to the first preset value and the number of authentication attempts is less than or equal to the second preset value, then authentication is allowed again.
[0163] For example, the first preset value here can be 30 seconds; for example, the second preset value here can be 3 times. It should be noted that the specific values of the first and second preset values here are merely exemplary examples and are not intended to limit the specific values of the first and second preset values in this disclosure. In some specific examples, the first and second preset values can be specifically set according to user needs.
[0164] It is understood that, in the embodiments of this disclosure, if the second authentication still fails, determining whether to allow authentication again based on the authentication time or the number of authentication attempts can improve the difficulty of maliciously cracking authentication information caused by unlimited or excessively long authentication times, thereby further enhancing security.
[0165] In some embodiments, the method further includes:
[0166] If authentication is successful, the received read and / or write commands are allowed to be executed;
[0167] If authentication fails, the received read and / or write commands will not be allowed to be executed.
[0168] When read and / or write operations are required on the memory system, the memory system can be authenticated first. If the authentication is successful, read and / or write operations can be allowed on the memory system. That is, if the memory system receives read and / or write instructions after authentication, it can be allowed to execute the received read and / or write instructions.
[0169] This disclosure provides a method for operating a host, such as... Figure 8 As shown, the method includes:
[0170] Step S2001: Receive first dynamic information from the memory system;
[0171] Step S2002: Generate second authentication information based on the first dynamic information and the second key determined from the key information;
[0172] Step S2003: In response to the mismatch between the second authentication information and the first authentication information, update the second key; the first authentication information is generated based on the first dynamic information and the first key in the memory system;
[0173] Step S2004: Receive second dynamic information from the memory system;
[0174] Step S2005: Generate updated second authentication information based on the second dynamic information and the updated second key;
[0175] Step S2006: Send the updated second authentication information to the memory system.
[0176] In some embodiments, the method further includes:
[0177] Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
[0178] Figure 9 This is a schematic diagram of the framework flow for authenticating a memory system according to an embodiment of this disclosure. The following is in conjunction with... Figure 9 as well as Figure 6 The operation methods of the host and the memory system described above will be further introduced.
[0179] like Figure 9 As shown, the command module 615 in the host controller 613 generates a command to obtain the authorization status information of the memory system 601, and sends the command to obtain the authorization status information of the memory system 601 through the host interface 614. After receiving the command to obtain the authorization status information of the memory system 601, the memory controller 602 in the memory system 601 determines whether it is necessary to generate random numbers. When it is determined that random numbers need to be generated, random numbers are generated by the random number generator 612, and the memory controller 602 sends the obtained authorization status information of the memory system 601 to the host 604. The authorization status information includes the lock status information of the memory system 601 and the obtained random numbers. When it is determined that random numbers do not need to be generated, no random numbers are generated, and the memory controller 602 directly sends the obtained authorization status information of the memory system 601 to the host 604. The authorization status information includes the lock status information of the memory system 601.
[0180] After obtaining the authorization status information, the host controller 613 in the host 604 determines whether the authorization status information contains a random number. If it does not contain a random number, the host 604 obtains the lock status information of the memory system 601. If it contains a random number, the host controller 613 obtains the second key from the key set according to the key rules. The first encryption module 616 in the host controller obtains the second authentication information according to the encryption algorithm, such as the hash algorithm. Then, the command module 615 in the host controller 613 generates a command to send the second authentication information to the memory controller 602 of the memory system 601 based on the memory system being in a locked state. The second authentication information is then sent to the memory controller 602 of the memory system 601 through the host interface 614.
[0181] After generating a random number, the memory controller 602 generates a first key using key information loaded from the memory device 603. The second encryption module 611 in the memory controller 602 obtains first authentication information based on an encryption algorithm, such as a hash algorithm. The memory controller 602 determines whether the first authentication information and the received second authentication information from the host 604 match. If they match, authentication is successful; otherwise, authentication fails. In the case of a mismatch, the memory controller 602 determines whether the authentication time is greater than a first preset value or whether the number of authentication attempts is greater than a second preset value. If the authentication time is greater than the first preset value or the number of authentication attempts is greater than the second preset value, authentication fails, and further authentication is not allowed. If the authentication time is less than or equal to the first preset value and the number of authentication attempts is less than or equal to the second preset value, authentication fails. At the second preset value, a new random number is generated using the random number generator 612; the memory controller 602 sends the new random number to the host 604; after receiving the new random number, the host interface 614 obtains a new second key from the key set according to the key rules; the first encryption module 616 in the host controller 613 obtains the updated second authentication information according to the encryption algorithm; then the command module 615 in the host controller 613 generates a command to send the updated second authentication information to the memory system 601; the memory controller 602 generates updated first authentication information using the encryption algorithm based on the updated random number and the first key; the host interface 614 sends the updated second authentication information to the memory controller 602 in the memory system 601 for re-authentication.
[0182] Based on the above-described operation method of the memory system, this disclosure also provides a memory system, the memory system comprising:
[0183] The memory is configured to store key information; and
[0184] A memory controller, coupled to the memory and configured to:
[0185] First authentication information is generated based on the first dynamic information and the first key determined from the key information;
[0186] Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0187] Determine whether the first authentication information matches the second authentication information;
[0188] In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated;
[0189] Update the first authentication information based on the second dynamic information and the first key;
[0190] Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0191] The system determines that authentication has been successful upon matching the updated first authentication information with the updated second authentication information.
[0192] In some embodiments, the memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
[0193] In some embodiments, the memory controller is further configured to:
[0194] Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained.
[0195] In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
[0196] In some embodiments, the memory is external to the memory controller, and the key information includes a key set and key rules, wherein the key rules are used to select a key from the key set to generate the first key.
[0197] In some embodiments, the memory controller is configured to:
[0198] A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
[0199] In some embodiments, the memory controller is configured to:
[0200] If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
[0201] In some embodiments, the memory controller is configured to:
[0202] If authentication is successful, the received read and / or write commands are allowed to be executed;
[0203] If authentication fails, the received read and / or write commands will not be allowed to be executed.
[0204] In some embodiments, the memory controller is configured to:
[0205] If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
[0206] In some embodiments, the memory system includes a memory card or a solid-state drive.
[0207] Here, the specific structure and composition of the memory system can be referred to the aforementioned section. Figure 1 , Figure 2a , Figure 2b , Figure 3 , Figure 4 , Figure 5 , Figure 6 The detailed introduction of the memory system is provided here, and other details regarding the memory system are similar to those in the aforementioned memory system operation method. For the sake of brevity, they will not be repeated here.
[0208] Based on the above-described host operation method, this disclosure also provides a host, which includes a host controller and a host interface.
[0209] The host interface is configured as follows:
[0210] Receive the first dynamic information from the memory system;
[0211] Receive second dynamic information from the memory system;
[0212] The updated second authentication information is sent to the memory system;
[0213] The host controller is configured as follows:
[0214] The second authentication information is generated based on the first dynamic information and the second key determined from the key information;
[0215] In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; the first authentication information is generated based on the first dynamic information and the first key in the memory system.
[0216] Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
[0217] In some embodiments, the host controller is configured to:
[0218] Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
[0219] Based on the above-described memory system and host, this disclosure also provides an electronic device, which includes a host and a memory system; wherein the memory system includes a memory and a memory controller coupled to the memory, and the host includes a host controller and a host interface;
[0220] The memory is configured to store key information;
[0221] The memory controller is configured to:
[0222] First authentication information is generated based on the first dynamic information and the first key determined from the key information;
[0223] Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host;
[0224] Determine whether the first authentication information matches the second authentication information;
[0225] In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated;
[0226] Update the first authentication information based on the second dynamic information and the first key;
[0227] Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host;
[0228] In response to the matching of the updated first authentication information and the updated second authentication information, authentication is confirmed to be successful;
[0229] The host interface is configured as follows:
[0230] Receive the first dynamic information from the memory system;
[0231] Receive the second dynamic information from the memory system;
[0232] The updated second authentication information is sent to the memory system;
[0233] The host controller is configured as follows:
[0234] The second authentication information is generated based on the first dynamic information and the second key determined from the key information;
[0235] In response to a mismatch between the second authentication information and the first authentication information, the second key is updated;
[0236] Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
[0237] Here, the specific structure and composition of the host and electronic devices can be referred to the aforementioned section. Figure 1 as well as Figure 6 The detailed introduction is as follows, and other details about the host are similar to those in the aforementioned host operation method, so for the sake of brevity, they will not be repeated here.
[0238] This disclosure also provides a computer-readable storage medium on which a computer program is stored.
[0239] In some embodiments, when the computer program is executed by a processor, it performs the operation method of the memory system described in any of the above embodiments.
[0240] In other embodiments, when the computer program is executed by a processor, it performs the host operation method described in any of the embodiments above.
[0241] Here, implementing all or part of the processes in the methods of the above embodiments can be accomplished by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive, etc.; the storage medium can also include combinations of the above types of memory.
[0242] It should be understood that the phrase "an embodiment" or "one embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this disclosure. Therefore, "in one embodiment" or "one embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this disclosure, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this disclosure. The sequence numbers of the above-described embodiments are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0243] The methods disclosed in the several method embodiments provided in this disclosure can be arbitrarily combined without conflict to obtain new method embodiments.
[0244] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A memory system, characterized in that, The memory system includes: The memory is configured to store key information; and A memory controller, coupled to the memory and configured to: First authentication information is generated based on the first dynamic information and the first key determined from the key information; Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host; Determine whether the first authentication information matches the second authentication information; In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated; Update the first authentication information based on the second dynamic information and the first key; Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host; The system determines that authentication has been successful upon matching the updated first authentication information with the updated second authentication information.
2. The memory system according to claim 1, characterized in that, The memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
3. The memory system according to claim 1, characterized in that, The memory controller is also configured to: Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained. In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
4. The memory system according to claim 3, characterized in that, The memory peripheral is connected to the memory controller, and the key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
5. The memory system according to claim 4, characterized in that, The memory controller is configured to: A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
6. The memory system according to claim 1, characterized in that, The memory controller is configured to: If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
7. The memory system according to claim 6, characterized in that, The memory controller is configured to: If authentication is successful, the received read and / or write commands are allowed to be executed; If authentication fails, the received read and / or write commands will not be allowed to be executed.
8. The memory system according to claim 6, characterized in that, The memory controller is configured to: If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
9. A host computer, characterized in that, The host includes a host controller and a host interface. The host interface is configured as follows: Receive the first dynamic information from the memory system; Receive second dynamic information from the memory system; The updated second authentication information is sent to the memory system; The host controller is configured as follows: The second authentication information is generated based on the first dynamic information and the second key determined from the key information; In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; the first authentication information is generated based on the first dynamic information and the first key in the memory system. Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
10. The host computer according to claim 9, characterized in that, The host controller is configured as follows: Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
11. An electronic device, characterized in that, The electronic device includes a host and a memory system; wherein the memory system includes a memory and a memory controller coupled to the memory, and the host includes a host controller and a host interface; The memory is configured to store key information; The memory controller is configured to: First authentication information is generated based on the first dynamic information and the first key determined from the key information; Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host; Determine whether the first authentication information matches the second authentication information; In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated; Update the first authentication information based on the second dynamic information and the first key; Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host; In response to the matching of the updated first authentication information and the updated second authentication information, authentication is confirmed to be successful; The host interface is configured as follows: Receive the first dynamic information from the memory system; Receive the second dynamic information from the memory system; The updated second authentication information is sent to the memory system; The host controller is configured as follows: The second authentication information is generated based on the first dynamic information and the second key determined from the key information; In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; Based on the second dynamic information and the updated second key, the updated second authentication information is generated.
12. A method for operating a memory system, characterized in that, The method includes: First authentication information is generated based on the first dynamic information and the first key determined from the key information stored in the memory of the memory system; Receive second authentication information from the host, the second authentication information being generated based on the first dynamic information and the second key in the host; Determine whether the first authentication information matches the second authentication information; In response to a mismatch between the first authentication information and the second authentication information, second dynamic information is generated; Update the first authentication information based on the second dynamic information and the first key; Receive updated second authentication information from the host, the updated second authentication information being generated based on the second dynamic information and the updated second key in the host; The system determines that authentication has been successful upon matching the updated first authentication information with the updated second authentication information.
13. The operating method according to claim 12, characterized in that, The memory controller includes a random number generator, and the first dynamic information and the second dynamic information include random numbers generated by the random number generator.
14. The operating method according to claim 12, characterized in that, The method further includes: Before generating the first authentication information, a command to obtain the authorization status information of the memory system is received. The authorization status information includes the lock status information of the memory system and information on whether the first dynamic information needs to be obtained. In response to the authorization status information including information requiring the acquisition of the first dynamic information, the first dynamic information is generated.
15. The operating method according to claim 14, characterized in that, The memory peripheral is connected to the memory controller, and the key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
16. The operating method according to claim 15, characterized in that, The method further includes: A command is sent to read the key information from the memory, and the key information is stored in the memory controller, thereby generating the first key in the memory controller.
17. The operating method according to claim 12, characterized in that, The method further includes: If the updated first authentication information does not match the updated second authentication information, authentication is confirmed to have failed.
18. The operating method according to claim 17, characterized in that, The method further includes: If authentication is successful, the received read and / or write commands are allowed to be executed; If authentication fails, the received read and / or write commands will not be allowed to be executed.
19. The operating method according to claim 17, characterized in that, The method further includes: If authentication fails based on the updated first authentication information and the updated second authentication information, and the authentication time exceeds the first preset value, or if authentication fails based on the updated first authentication information and the updated second authentication information, and the number of authentication attempts exceeds the second preset value, authentication fails and is not allowed to be performed again.
20. A method for operating a host computer, characterized in that, include: Receive the first dynamic information from the memory system; The second authentication information is generated based on the first dynamic information and the second key determined from the key information; In response to a mismatch between the second authentication information and the first authentication information, the second key is updated; the first authentication information is generated based on the first dynamic information and the first key in the memory system. Receive second dynamic information from the memory system; Based on the second dynamic information and the updated second key, generate updated second authentication information; The updated second authentication information is sent to the memory system.
21. The operating method according to claim 20, characterized in that, The method further includes: Based on the location where the key information is stored in the memory, the key information in the memory is obtained. The key information includes a key set and key rules. The key rules are used to select a key from the key set to generate the first key.
22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, can implement the host operation method as described in any one of claims 20 to 21.
Citation Information
Patent Citations
Access control method and device of mobile memory, electronic equipment and storage medium
CN111783074A
Memory operation method, memory and memory system
CN114527933A