Universal flash memory device for preventing replay attack, operating method thereof, and universal flash memory system

By using the first write failure index and the second write failure index in the RPMB area of ​​the UFS device for authentication operations, the problem of difficulty in preventing replay attacks in the prior art is solved, and effective security protection for the UFS device is achieved.

CN120020785APending Publication Date: 2025-05-20SAMSUNG ELECTRONICS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411607752.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-05-17
Filing Date
2024-11-12
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

The prior art is difficult to effectively prevent replay attacks. For universal flash memory (UFS) devices that store sensitive data, the lack of effective defense measures has led to a threat to data security.

Method used

By introducing a playback protection memory block (RPMB) area in the UFS device and configuring execution instructions in the memory controller to receive the RPMB write request, it is determined whether to perform an authentication operation on the external device based on the first write failure index and the second write failure index, thereby preventing a playback attack.

Benefits of technology

Effectively prevent replay attacks, enhance the security and reliability of UFS devices, and ensure that sensitive data stored in the RPMB area is not accessed maliciously.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120020785A_ABST
    Figure CN120020785A_ABST
Patent Text Reader

Abstract

A universal flash memory (UFS) device for preventing replay attacks, an operating method thereof, and a UFS system are provided. The UFS device includes: a memory including a replay-protected memory block (RPMB) region, the RPMB region including one or more index fields storing a second write failure index; and a memory controller including at least one controller memory storing one or more instructions, where the memory controller is configured to execute the one or more instructions to cause the UFS device to: receive an RPMB write request from an external device, the RPMB write request includes a first write failure index, meta information, and a first message authentication code generated based on the first write failure index and the meta information, and determines whether to perform an authentication operation on the external device based on the first write failure index and a second write failure index.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is based on and claims the benefit of priority from Korean Patent Application No. 10-2023-0161031 filed in the Korean Intellectual Property Office on November 20, 2023, and Korean Patent Application No. 10-2024-0064800 filed in the Korean Intellectual Property Office on May 17, 2024, the disclosures of which are incorporated herein in their entirety by reference. Technical Field

[0002] The present disclosure relates to electronic devices, and more particularly, to a Universal Flash Storage (UFS) device for preventing a replay attack, an operation method thereof, and a UFS system. Background Art

[0003] Semiconductor memories are widely used to store data in various electronic devices such as computers, wireless communication devices, etc. For example, non-volatile memory is a device that can store data even in an environment where power is not supplied to the device. Various mobile devices or electronic devices such as smartphones, desktop computers, laptops, tablet personal computers (PCs), and wearable devices are widely used. Such electronic devices may include storage devices for storing data. Storage devices used in mobile devices, portable devices, vehicle electronic devices, or embedded systems are generally referred to as Universal Flash Storage (UFS) devices.

[0004] Storage devices such as UFS devices can store data that is sensitive to users (e.g., personal information, authentication keys, passwords, etc.). In order to prevent malicious users (or attackers) from accessing sensitive data, storage devices can support replay protection storage blocks (hereinafter referred to as "RPMB") and only allow authenticated devices to read or write data stored in the RPMB area. Replay attack is one of the attack methods for attackers to access the RPMB area. In order to reflect measures to prevent replay attacks in the UFS standard, specific technologies for preventing replay attacks have been studied. Summary of the invention

[0005] The present disclosure provides a Universal Flash Storage (UFS) device, an operation method thereof, and a UFS system for preventing a replay attack.

[0006] According to one aspect of the present disclosure, a universal flash memory (UFS) device includes: a memory including a replay protection memory block (RPMB) area, the RPMB area including one or more index fields storing a second write failure index; and a memory controller including at least one controller memory storing one or more instructions, wherein the memory controller is configured to execute one or more instructions to enable the UFS device to: receive an RPMB write request from an external device, the RPMB write request including a first write failure index, meta information, and a first message authentication code generated based on the first write failure index and the meta information, and determine whether to perform an authentication operation on the external device based on the first write failure index and the second write failure index.

[0007] According to one aspect of the present disclosure, a method of operating a universal flash storage (UFS) device configured to communicate with an external device includes: receiving a replay protection memory block (RPMB) write request, the RPMB write request including a first write failure index, meta information, and a first message authentication code generated based on the first write failure index and the meta information; identifying whether to perform an authentication operation on the external device based on a second write failure index and the first write failure index contained in an RPMB area of ​​the UFS device; and based on performing the authentication operation, outputting a response including a result of the authentication operation.

[0008] According to one aspect of the present disclosure, a universal flash memory (UFS) system includes: a UFS host, including: at least one host processor; and at least one host memory storing one or more host instructions, wherein the at least one host processor is configured to execute one or more host instructions so that the UFS host: obtains a first message authentication code based on a first write failure index and meta-information, and outputs a replay protection memory block (RPMB) write request including the first message authentication code, the first write failure index and the meta-information as an RPMB operation; and a UFS device, including: at least one device processor; and at least one device memory storing one or more device instructions, wherein the at least one device processor is configured to execute one or more device instructions so that the UFS device: determines whether to perform an authentication operation on the UFS host based on the first write failure index. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The above and other aspects and features of certain embodiments of the present disclosure will become more apparent from the following description taken in conjunction with the accompanying drawings, in which:

[0010] Figure 1 is a block diagram illustrating a memory system according to an embodiment;

[0011] Figure 2 is a diagram illustrating an example of a replay attack;

[0012] Figure 3 is a diagram showing the format of a command Universal Flash Memory (UFS) Protocol Information Unit (UPIU) in a normal Replay Protection Memory Block (RPMB) operation;

[0013] Figure 4 is a diagram showing the format of the data output UPIU in normal RPMB operation;

[0014] Figure 5 is a diagram showing the format of data input UPIU in normal RPMB operation;

[0015] Figure 6 is a diagram showing the format of command UPIU in advanced RPMB operation;

[0016] Figure 7 is a diagram showing the format of a response UPIU in advanced RPMB operation;

[0017] Figure 8 is a diagram illustrating the operation of a device according to an embodiment of the present disclosure;

[0018] Fig. 9 is a diagram showing a plurality of RPMB areas according to an embodiment of the present disclosure;

[0019] Fig.10 is a diagram showing a format of a query request UPIU associated with a write descriptor according to an embodiment of the present disclosure;

[0020] Fig.11 is a diagram showing a format of a query response UPIU associated with a read descriptor according to an embodiment of the present disclosure;

[0021] Fig.12 is a diagram showing a format of a query request UPIU related to writing attributes according to an embodiment of the present disclosure;

[0022] Fig.13 is a diagram showing an embodiment of the present disclosure of recording a write failure index;

[0023] Fig.14 is a diagram showing an embodiment of the present disclosure of initializing a field storing a write failure index during a power cycle;

[0024] Fig.15 is a diagram showing an embodiment of the present disclosure of initializing a field storing a write failure index in a read-only mode;

[0025] Fig.16 is a flowchart illustrating a method of operating a device according to an embodiment of the present disclosure;

[0026] Fig.17is a diagram illustrating a UFS system according to an embodiment of the present disclosure; and

[0027] Fig.18A , Fig.18B and Fig.18C is a diagram showing the form factor of a UFS card. DETAILED DESCRIPTION

[0028] Hereinafter, one or more embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0029] In the following description, similar reference numerals represent similar elements throughout the specification. Terms such as "unit", "module", "component" and "block" can be embodied in hardware or software. As used herein, multiple "units", "modules", "components" and "blocks" can be implemented as a single component, or a single "unit", "module", "component" and "block" can include multiple components.

[0030] It should be understood that when it is mentioned that an element is “connected” to another element, the element may be directly or indirectly connected to the other element, wherein the indirect connection includes “connected via a wireless communication network”.

[0031] Furthermore, when a component “includes” or “comprises” an element, unless there is a specific description to the contrary, the component may further include other elements, rather than excluding other elements.

[0032] Throughout the description, when a member is "on" another member, this includes not only a case where the member is in contact with the other member but also a case where another member exists between the two members.

[0033] As used herein, the expressions “at least one of a, b, or c” and “at least one of a, b, and c” indicate “only a”, “only b”, “only c”, “both a and b”, “both a and c”, “both b and c”, and “all of a, b, and c”.

[0034] It should be understood that although the terms "first", "second", "third", etc. may be used herein to describe various elements, the present disclosure should not be limited by these terms. These terms are only used to distinguish one element from another element.

[0035] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0036] For any method or process described herein, identification codes may be used to facilitate description, but they are not intended to illustrate the order of each step or operation. Unless the context clearly indicates otherwise, each step or operation may be implemented in an order different from the order shown. Unless the context of the present disclosure clearly indicates otherwise, one or more steps or operations may be omitted.

[0037] Figure 1 is a block diagram showing a memory system 1 according to the embodiment.

[0038] refer to Figure 1 , the memory system 1 may include a host 10 and a device 100 .

[0039] The host 10 may communicate with the device 100 through an interface. The host 10 may provide a write request to the device 100, requesting the device 100 to store data. The host 10 may be implemented by a processor such as a central processing unit (CPU), an application processor (AP), a system on a chip (SoC), etc., and may process data. The host 10 may execute an operating system (OS) and / or various applications. The host 10 may include a physical layer, a multi-protocol multiplexer, an interface circuit, a consistency / cache circuit, a bus circuit, at least one core, and an input / output device.

[0040] In an embodiment, the host 10 may send a request to the device 100 to perform a replay protection memory block (hereinafter referred to as "RPMB") operation on the RPMB area of ​​the device 100. The RPMB may be an area contained in a specific well-known logical unit (hereinafter referred to as "W-LU") and / or the memory 120. The RPMB area may be a space for storing resources contained in the RPMB. Only authorized devices can access the RPMB. In this case, the host 10 may send an authentication key, code, meta information, data, etc. for authentication to the device 100. The RPMB operation may include a normal RPMB operation or an advanced RPMB operation disclosed in the UFS standard issued by the Joint Electron Device Engineering Council (JEDEC). In the following, for ease of explanation, according to an embodiment, the UFS standard issued by JEDEC may be referred to as the "UFS standard."

[0041] The device 100 may store data provided by the host 10, or provide data stored in an internal storage space to the host 10. In an embodiment, the device 100 may be a storage device implemented by UFS. The device 100 may include a memory controller 110 and a memory 120.

[0042] The memory controller 110 may control the memory 120 to write data to the memory 120 or read data stored in the memory 120 in response to a request from the host 10. In an embodiment, the memory controller 110 may control a write operation (or a program operation), a read operation, or an erase operation on the memory 120 by providing a command / address and / or a control signal to the memory 120. In addition, data to be written and data to be read may be transmitted and received between the memory controller 110 and the memory 120.

[0043] In an embodiment, the memory controller 110 may perform an authentication operation (or verification) on the host 10 to perform an RPMB operation on the RPMB area. For example, the memory controller 110 may receive an authentication key (or code), meta information, and data from the host 10. The memory controller 110 may generate an authentication key based on the meta information and data. The memory controller 110 may authenticate the host 10 by comparing the authentication key of the host 10 with the generated authentication key. An embodiment of the authentication operation will be described below. Figure 8 Described in.

[0044] In an embodiment, the memory controller 110 may include a RPMB W-LU 111. The RPMB W-LU 111 may support RPMB functions through independent processes and memory spaces specified by the RPMB security definition. The contents of the RPMB W-LU 111 may be read or written through successfully authenticated read and write accesses. The data may be overwritten by the host 10 but cannot be erased. In an embodiment, the RPMB W-LU 111 may include a device server that processes small computer mini interface (SCSI) commands and task management functions, a task manager that processes commands controlled by a command queue, and a plurality of RPMB areas 121.

[0045] The memory controller 110 may further include a buffer memory implemented as a static random access memory (SRAM) or the like.

[0046] The memory 120 may include a plurality of memory blocks. Each of the memory blocks may include a plurality of memory cells. The plurality of memory cells may have various threshold voltage distributions according to programming data. For example, the memory cell may be a single-level cell, a multi-level cell, a triple-level cell, etc. In an embodiment, the memory 120 may include a plurality of RPMB regions 121 corresponding to some of the plurality of memory blocks. Fig. 9 A plurality of RPMB areas 121 are depicted. In an embodiment, the memory 120 may be implemented as a non-volatile memory, such as a NAND flash memory.

[0047] According to the above embodiment, by providing a method specifically proposed in the existing JEDEC published UFS standard to prevent replay attacks, the security of the device 100 can be enhanced and the reliability of the device 100 can be improved. A replay attack can be an attack method in which an attacker steals the original message of the host 10, sends the modified message to the device 100, induces a write failure of the device 100, and then resends the original message to the device 100 at a time that the host 10 does not expect. Figure 2 Describe replay attacks.

[0048] Figure 2 is a diagram illustrating an example of a replay attack.

[0049] refer to Figure 2 , the host 10 can generate a message authentication code MAC based on the algorithm, meta information META INFO and original data OGN DATA. The algorithm and meta information META INFO may follow the content disclosed in the UFS standard. For example, the algorithm may be HMAC SHA-256 disclosed in the UFS standard. In the HMAC SHA-256 calculation, the key and the message may be the input of HMAC SHA-256, and the output of HMAC SHA-256 may be the message authentication code MAC. The key used for MAC calculation (ie, message authentication code calculation) may be a 256-bit authentication key stored in the target RPMB area. The message used as the input of the MAC calculation may correspond to the meta information META INFO and the data, and the meta information META INFO may be the information contained in the RPMB message data frame (or RPMB data packet) (eg, authentication key, data, write counter, address, block count, result, request message type, response message type, etc.). The host 10 may output an RPMB write request RPMB WREQ including a message authentication code MAC, meta information META INFO and original data OGNDATA. In an embodiment, the RPMB write request RPMB WREQ may be information for accessing a target RPMB of a specific RPMB area among the multiple RPMB areas 121 of the indication device 100 and requesting the target RPMB to write data. For example, the RPMB write request RPMB WREQ may include a code representing any one of an authentication data write request, a security write protection block write request, and an RPMB clear enable request disclosed in the UFS standard.

[0050] The attacker 50 can steal the RPMB write request RPMB WREQ of the host 10. The attacker 50 can modify the original data OGN DATA in the stolen RPMB write request RPMB WREQ. The attacker 50 can send the RPMB write request RPMB WREQ′ containing the modified data MFD DATA, the message authentication code MAC′ and the meta information META INFO to the device 100.

[0051] The device 100 may receive an RPMB write request RPMB WREQ′ from the attacker 50. The device 100 may generate a message authentication code MAC based on the RPMB write request RPMB WREQ′ and an algorithm. However, since the message authentication code MAC generated by the device 100 is different from the message authentication code MAC′ included in the RPMB write request RPMB WREQ′, the device 100 determines that the authentication has failed. Therefore, the device 100 may send a response RESP including a message authentication code MAC and an authentication result code to the host 10. In this regard, the authentication result code is an authentication failure code ATHN FAILURE indicating a failure, and the code value disclosed in the UFS standard is "0002h (0082h)".

[0052] The host 10 may receive a response RESP from the device 100, and may check the authentication result based on the authentication result code. The attacker 50 may send an RPMB write request RPMB WREQ from the host 10 to the device 100 at a time that the host 10 does not expect. The device 100 may generate a message authentication code MAC based on the RPMB write request RPMB WREQ and the algorithm, and since the generated message authentication code MAC matches the message authentication code MAC of the RPMB write request RPMB WREQ, the device 100 may determine that the authentication is successful, and write and store the original data OGN DATA to the target RPMB area. The device 100 may output a response RESP including a message authentication code MAC and an authentication result code. In this case, the authentication result code is an operation approval code OP OK (SUCCESS) that may indicate a successful operation, and the code value disclosed in the UFS standard is "0000h (0080h)".

[0053] In the UFS standard version 4.0 published by JEDEC, there may be a method to prevent replay attacks by setting a value in the Nonce field during a write operation related to the RPMB operation (such as an "authenticated data write request", etc.). However, in the UFS standard version 4.0, since there are no provisions for post-failure exploitation techniques, exception handling techniques, and compatibility maintenance techniques, it is necessary to develop a specific method for defending against replay attacks. In the following, the RPMB operation will be described below, and a replay attack defense method applicable to the RPMB operation will be described.

[0054] Figure 3 is a diagram showing the format of a command UFS protocol information unit (UPIU) CMD UPIU in a normal RPMB operation. Figure 4 is a diagram showing the format of the data output UPIU D_OUT UPIU in normal RPMB operation. Figure 5 is a diagram showing the format of the data input UPIU D_IN UPIU in normal RPMB operation.

[0055] refer to Figures 3 to 5 In the normal RPMB mode disclosed in the UFS standard, various UFS protocol information units (UPIU) may be sent and received between the host 10 and the device 100 .

[0056] The sequence of RPMB write requests RPMB WREQ may be initiated by the security protocol output of the initiator disclosed in the UFS standard (i.e., the "SECURITY PROTOCOL OUT" command SCRY PRTCL OUT). For example, the host-UFS command set layer (UCS) 11 of the host 10 may output the security protocol output command SCRY PRTCL OUT, and the host-UFS transfer protocol layer (UTP) 12 of the host 10 may send a command UPIU CMD UPIU to the device 100. The device 100 may send a ready to transfer UPIU RTT UPIU to the host-UTP 12. The host-UTP 12 may send a data output UPIU D_OUT UPIU to the device 100. The device 100 may authenticate the host 10 and store the data provided from the valid host 10, and may return a response UPIURESP UPIU indicating that the security protocol output command SCRY PRTCL OUT status is good to the host-UTP 12, regardless of whether the writing of the authenticated data is successful. The host-UTP 12 may send a response RESP to the host-UCS 11 .

[0057] The host-UCS 11 may output a security protocol output command SCRYPRTCL OUT for the result read request RSLT RREQ. The result read request RSLT REQ is a verification process for the RPMB write request RPMB WREQ. In this case, a command UPIU CMD UPIU may be sent to the device 100, a ready to send UPIU RTT UPIU may be sent to the host-UTP 12, and a data output UPIU D_OUT UPIU may be sent to the device 100. A response UPIU RESP UPIU indicating a good status may generally be returned to the host-UTP 12, and a response RESP may be sent to the host-UCS 11.

[0058] A security protocol input command SCRYPRTCL IN for a result read response RSLT RRESP may be output from the host-UCS 11. The result read request RSLT RREQ may be information for receiving a result read by the device 100. In this case, when the command UPIU CMD UPIU is sent to the device 100, the device 100 may send a data input UPIU D_IN UPIU to the host-UTP 12 and return a response UPIU RESP UPIU to the host-UTP 12. The response RESP may be sent to the host-UCS 11.

[0059] refer to Figure 3, the UPIU may be a basic configuration of data having a size of 31 bytes. The "0 to 31" indicated in the UPIU may each indicate a 1-byte field. The command UPIU CMD UPIU may include an operation code (e.g., "xx00 0001b"), a flag, a logical unit number (LUN), a task tag, an initiator ID (IID), a command set type, a total extra header segment (EHS) length, a data segment length, an expected data transfer length, a command descriptor block (hereinafter referred to as "CDB"), and a header end-to-end cyclic redundancy check (CRC) E2ECRC. In some cases, the header E2ECRC may be omitted. The fields of addresses 16 to 27 of the command UPIU CMD UPIU may include an operation code field OPERATION CODE, a security protocol field SECURITY PROTOCOL, a security protocol specific field SECURITY PROTOCOL SPECIFIC, an allocation / transfer length field ALLOCATION / TRANSFER LENGTH, and the like. In this regard, a code value 'ECh' indicating JEDEC UFS may be set in the security protocol field SECURITY PROTOCOL, and a code value indicating the RPMB protocol ID of the target RPMB area may be set in the security protocol specific field SECURITY PROTOCOL SPECIFIC.

[0060] refer to Figure 4 , the fields of the data output UPIU D_OUT UPIU are generally similar to those of the command UPIU CMD UPIU, but the value of the opcode contained in the field at address 0 in the data output UPIU D_OUT UPIU may be "xx00 0010b". The command set type COMMAND SET TYPE is omitted, and the field at address 7 of the data output UPIU D_OUT UPIU may contain an identifier EXT_ID indicating the MSB half byte of the initiator identifier Nexus. In the data output UPIU D_OUT UPIU, the fields at addresses 12 to 15 are the data buffer offset, and the fields at addresses 16 to 19 are the data transfer count. In the data output UPIU D_OUT UPIU, the fields at addresses K to K+Length-1 contain specific data. "Length" may be the value of the data segment length. In normal RPMB mode, the field from address K to K+Length-1 in the data output UPIU D_OUT UPIU may contain an RPMB message data frame. Since the size of the RPMB message data frame is 512 bytes, the "Length" may be 512.

[0061] The RPMB message data frame may include a padding byte field SB, a code and key field M / K, a data field DT, a write failure index field WFI, a write counter field WC, an address field ADD, a block count field BC, a result field RSLT, and a message type field MT. In an embodiment, the meta information META INFO may include an authentication key, and information contained in each of the data field DT, the write counter field WC, the address field ADD, the block count field BC, the result field RSLT, and the message type field MT. If necessary, the meta information META INFO may also include a write failure index of the write failure index field WFI. The padding byte field SB may include padding bytes. The code and key field M / K may include a message authentication code MAC and an authentication key. The authentication key may be used for operations disclosed in the UFS standard to program the authentication key. The data field DT is data to be written or read by signature access, and may include specific data to be written to the target RPMB. The write failure index field WFI may include a write failure index for inputting a MAC calculation and recording the situation or detailed information of the authentication failure in the device 100. The write failure index may be a value determined by the host 10. The write counter field WC may include a write counter representing the total amount of successfully authenticated data write operations. The address field ADD may include a logical block address (LBA) of the data to be programmed in or read from the RPMB area. The block count field BC may include a block count representing the number of 256-byte logical blocks requested to be read or programmed. The value of the result field RSLT according to the UFS standard may be "0000h". The message type field MT may include any of the various codes associated with the request. In an embodiment, the message type field MT according to the UFS standard may include any of "0003h", "0006h" and "0008h" contained in the request message type. The request message type "0003h" according to the UFS standard indicates an authenticated data write request. The request message type "0006h" according to the UFS standard indicates a secure write protection configuration block write request. The request message type "0008h" according to the UFS standard indicates an RPMB clear enable request. In an embodiment, the message type field MT according to the UFS standard may indicate a code value "0005h" indicating a result read request.

[0062] In an embodiment, when receiving an RPMB message (e.g., an RPMB message data frame), the device 100 may first check whether the write counter has expired, and may check the value of each of the address and block counters. When the write counter has not expired, the device 100 may calculate the message authentication code MAC based on the request message type, block counter, write counter, address, write failure index, and data, and may perform an authentication operation by comparing the calculated message authentication code MAC with the message authentication code MAC of the code and key field M / K. When the two message authentication codes are different from each other in the authentication operation, the device 100 sets the code value of the result field RSLT to "0002h" (authentication failure) and does not write data in the target RPMB area. When the two message authentication codes are the same, the device 100 may compare the write counter of the write counter field WC with the pre-stored write counter, and when the message authentication code and the write counter are the same, it is considered that the write request is authenticated and the data is written to the physical space corresponding to the address. When the write operation is successfully performed, the write counter may be increased by 1.

[0063] In an embodiment, when the value of the message type field MT according to the UFS standard is '0003h', a loop of sending the ready to send UPIU RTT UPIU and the data output UPIU D_OUTUPIU may be repeated in a sequence of the RPMB write request RPMB WREQ.

[0064] In an embodiment, when the value of the message type field MT according to the UFS standard is '0008h', the sequence of the result read request RSLT RREQ is omitted.

[0065] According to the above-described embodiment, the security of the device 100 can be enhanced by extending the write request types that can defend against replay attacks not only to authenticated data write requests but also to secure write protection block write requests and RPMB clear enable requests.

[0066] refer to Figure 5, the fields of the data input UPIU D_IN UPIU are basically the same as the data command UPIU CMD UPIU, except that the value of the opcode is different. In the data input UPIU D_IN UPIU, the value of the opcode contained in the field of address 0 may be "xx10 0010b". In normal RPMB mode, the fields of addresses K to K+Length-1 in the data input UPIU D_IN UPIU may also contain a 512-byte RPMB message data frame, and the result field RSLT in the RPMB message data frame may include any of a variety of code values. For example, in the result field RSLT, "0000h" indicates that the operation is OK, "0002h" indicates that the authentication failed because the value of the write failure index of the write failure index field WFI is the same as the value of the write failure index pre-stored in the device 100, and "000Eh" indicates that the authentication failed because the device 100 is running in read-only mode. However, the present disclosure is not limited to this. The result field RSLT may include other code values ​​defined in the UFS standard. In the RPMB message data frame of the data input UPIU D_IN UPIU, the message type field MT may include any one of the various code values ​​related to the response. In an embodiment, the message type field MT according to the UFS standard may include any one of "0300h", "0600h" and "0800h" contained in the response message type. The response message type "0300h" according to the UFS standard represents an authenticated data write response. The response message type "0600h" according to the UFS standard represents a secure write protection configuration block write response. The response message type "0800h" according to the UFS standard represents an RPMB clear enable response.

[0067] Figure 6 is a diagram showing the format of a command UPIU CMD UPIU in an advanced RPMB operation, and Figure 7 is a diagram showing the format of a response UPIU RESP UPIU in advanced RPMB operation.

[0068] refer to Figure 6 and Figure 7 In the advanced RPMB mode disclosed in the UFS standard, a command UPIU CMD UPIU, a ready to send UPIU RTT UPIU, a data output UPIU D_OUT UPIU, and a response UPIU RESP UPIU may be sent and received between the host 10 and the device 100 (eg, the term “sending and receiving” may also be referred to as the term “transceiving”).

[0069] refer to Figure 6 The command UPIU CMD UPIU contains the following: Figure 3 The security protocol output field SPO FIELD shown is the same as the security protocol output field SPO FIELD, but the operation code at offset 0 of the security protocol output field SPO FIELD is "B5h". The command UPIU CMD UPIU and the response UPIU RESP UPIU may also each include a 64-byte EHS field EHS FIELD. Similar to the RPMB message data frame, the EHS field EHS FIELD of the command UPIU CMD UPIU may include a message type field MT, a write failure index field WFI, a write counter field WC, an address field ADD, a block count field BC, a result field RSLT, and a code and key field M / K. The message type field MT may include a code value related to a request or response. The block count field BC may include the value of an advanced RPMB block count. The address field ADD may also include a LUN value and an address value. The EHS field EHS FIELD of the command UPIU CMD UPIU may also include a 4-byte EHS header field EHF located at offsets 0 to 3. Different from the RPMB message data frame, data of the data field DT may be included in the data output UPIU D_OUT UPIU.

[0070] refer to Figure 7 , the response UPIU RESP UPIU may include various information similar to the command UPIU CMD UPIU (e.g., flags, LUNs, task tags, etc.). The operation code of the response UPIU RESP UPIU is "xx10 0001b". The response UPIURESP UPIU may also include a remaining send count. The response UPIU RESP UPIU may also include a 64-byte EHS field EHS FIELD. In the response UPIU RESP UPIU, the fields of address K to K+19 may include the read data length and the read data.

[0071] Figure 8 is a diagram illustrating the operation of the device 100 according to the embodiment.

[0072] refer to Figure 8 The host 10 may calculate and generate a first message authentication code MAC1 based on an algorithm (eg, HMAC SHA-256), a first write failure index WFI1, data, and meta information META INFO. The meta information META INFO may include Figures 3 to 5The host 10 may send a RPMB write request RPMB WREQ as a RPMB operation on the RPMB area of ​​the device 100. The RPMB write request RPMB WREQ may include a first message authentication code MAC1, a first write failure index WFI1, and meta information META INFO. In an embodiment, the RPMB write request RPMB WREQ may also include data.

[0073] The memory controller 110 of the device 100 may receive an RPMB write request RPMBWREQ from an external device (eg, the host 10). According to an embodiment, before sending the RPMB write request RPMB WREQ, a write failure index may be stored in the memory 120 of the device 100. The write failure index stored in the memory 120 may be referred to as a second write failure index.

[0074] The memory controller 110 may determine whether to perform an authentication operation on an external device (eg, the host 10 ) based on the first write fail index WFI1 and the second write fail index.

[0075] In an embodiment, the memory controller 110 may perform a write failure index comparison operation (S10). For example, the memory controller 110 may compare the value of the first write failure index WFI1 with the value of the second write failure index. When the storage space in the memory 120 to store the write failure index is empty or the two write failure indexes are different from each other (WFIDIFFERENT), the memory controller 110 may initiate and perform an authentication operation (S20). For example, the memory controller 110 may calculate a message authentication code based on an algorithm (e.g., HMAC SHA-256), the first write failure index WFI1, data, and meta information META INFO. The memory controller 110 may compare the value of the calculated message authentication code with the value of the first message authentication code MAC1, and determine whether the authentication result is successful or failed based on the comparison result.

[0076] In an embodiment, when the two message authentication codes are different (MAC DIFFERENT), the memory controller 110 may write the first write failure index WFI1 into the target RPMB area ( S30 ).

[0077] In an embodiment, when the two message authentication codes are identical (MAC SAME), the memory controller 110 may initialize a field storing a write failure index in the target RPMB area ( S40 ).

[0078] In an embodiment, the memory controller 110 may set code values ​​representing various results, such as authentication results, write results, etc. (S50). For example, when the two message authentication codes are different (MAC DIFFERENT), the memory controller 110 may set the code value of the result field RSLT to "0002h" (authentication failure). For example, when the two message authentication codes are the same (MACSAME), the memory controller 110 may set one of the remaining code values ​​other than "0002h" (authentication failure), "000Dh" (WFI failure) and "000Eh" (WFI failure caused by read-only mode) in the result field RSLT. In this regard, the remaining code values ​​may include, for example, "0000h" (good operation), "0001h" (general failure), "0003h" (counter failure), etc. When the write operation is successfully performed, the code value of the result field RSLT is "0000h" (good operation). For example, when the two write failure indexes are the same (WFI SAME), the memory controller 110 may set the code value of the result field RSLT to "000Dh" (WFI failure).

[0079] According to the above-described embodiment, the host 10 can detect an error response caused by the attacker 50 , thereby checking the state of the device 100 and enhancing the security of the device 100 .

[0080] Fig. 9 is a diagram illustrating a plurality of RPMB areas 910 , 920 , 930 , and 940 according to an embodiment.

[0081] refer to Fig. 9 In the RPMB unit descriptor, the sizes of multiple RPMB areas 910, 920, 930, and 940 are defined, and these sizes are multiples of 128KB, with a minimum of 128KB and a maximum of 16MB. According to the UFS standard, the number of RPMB areas can be 4, but is not limited thereto.

[0082] A plurality of RPMB areas 910, 920, 930, and 940 may include RPMB resources according to the UFS standard. For example, the RPMB area 910 may include RPMB resources such as an authentication key 911, a write counter 912, a result register 913, an RPMB data area 914, a secure write protection configuration block 915, an index field 916, and the like. The specification of each of the authentication key 911, the write counter 912, the result register 913, the RPMB data area 914, and the secure write protection configuration block 915 is disclosed in the UFS standard.

[0083] In an embodiment, the index field 916 may be a field for storing a write failure index. The size of one index field may be 16 bytes. One or more index fields 916 may be provided. The number of index fields 916 may be set by a query request sequence defined in the UFS standard, which will be referred to below. Fig.10 and Fig.11 Described. The number of index fields 916 may correspond to the maximum number of consecutive failures allowed. Here, the maximum number of consecutive failures allowed may indicate the maximum number of times a write failure index may be written in an index field for consecutive write failures. For example, when the maximum number of consecutive failures is set to 3, the number of index fields 916 is 3, and a maximum of 3 different write failure indexes may be recorded on the device 100, but is not limited thereto. Continuous write failures may indicate that a write operation has failed multiple times due to a mismatch in a message authentication code.

[0084] In an embodiment, the data type of the write failure index stored in one index field 916 may be set in an integer method. Therefore, the compatibility of the device 100 with respect to a legacy device (e.g., a legacy host, etc.) may be maintained. In one or more embodiments, the data type of the write failure index stored in one index field 916 may be set in a bitmap method. Therefore, the RPMB resources may be minimized and the security of the device 100 may be further enhanced. The data type of the write failure index may be set by a query request sequence defined in the UFS standard, which will be referred to below. Fig.12 Give a description.

[0085] Fig.10 is a diagram showing a format of a query request UPIU QREQ UPIU associated with a write descriptor according to an embodiment.

[0086] refer to Fig.10 , the initiator device 1000 may initiate a query request sequence disclosed in the UFS standard. The initiator device 1000 may be Figure 1 The host 10 in the embodiment, and the target device 1100 may be Figure 1 Device 100 in.

[0087] The initiator device 1000 may send a query request UPIU QREQ UPIU including a query request QREQ, a write descriptor transaction WT DSCPT, and descriptor data DSCPT DATA to the target device 1100 , and the target device 1100 may send a query response UPIU QRESP UPIU to the initiator device 1000 .

[0088] According to the UFS standard, the operation code of the query request UPIU QREQ UPIU is "xx01 0110b". The query request UPIU QREQ UPIU may include a flag, a task tag, a query function, a total EHS length, a data segment length, a transaction specific field, and the like.

[0089] The write descriptor transaction WT DSCPT (i.e., the transaction specific field of the write descriptor code) may include an operation code (e.g., "02h"), a descriptor identifier DESCRIPTOR IDN, an index INDEX, a selector SELECTOR, and a length LENGTH. Here, for the RPMB unit descriptor, the value of the descriptor identifier DESCRIPTOR IDN is set to "02h", the value of the index INDEX is set to "C4h", and the value of the selector SELECTOR is set to "00h".

[0090] According to the UFS standard, the fields of addresses K to K+Length-1 in the query request UPIU QREQ UPIU include descriptor data DSCPT DATA. In this regard, Length-1 can be 20. That is, the size of the descriptor data DSCPT DATA related to the RPMB unit descriptor can be 21 bytes. However, the present disclosure is not limited to this. The fields of the descriptor data DSCPT DATA may include various information, such as "bLength", "bDescriptorIDN", "bMaxMutipleFailure", etc. "bLength", "bDescriptorIDN", etc. are defined in the UFS standard. "bMaxMutipleFailure" is the maximum number of consecutive failures allowed, that is, the maximum number of consecutive failures described above. When the number of consecutive failures exceeds the value of "bMaxMutipleFailure", the target device 1100 can perform a power cycle to receive power again or switch the operating mode to read-only mode. The value of "bMaxMutipleFailure" can be set differently for each device (ie, device-specific). When the initiator device 1000 sets the value of 'bMaxMutipleFailure' and sends the query request UPIU QREQUPIU to the target device 1100, the target device 1100 may set the same number of index fields 916 as the value of 'bMaxMutipleFailure'.

[0091] The query request UPIU QREQ UPIU may also include a transaction specific field where the descriptor code is written.

[0092] Fig.11is a diagram showing a format of a query request UPIU QREQ UPIU associated with a read descriptor according to an embodiment.

[0093] refer to Fig.11 , the initiator device 1000 can send a query request UPIU QREQ UPIU to the target device 1100.

[0094] The target device 1100 may send a query response UPIU QRESP UPIU including a read descriptor transaction RD DSCPT and descriptor data DSCPT DATA to the initiator device 1000. The query request UPIU QREQ UPIU may also include a read descriptor transaction RD DSCPT, i.e., a transaction specific field for reading a descriptor code. According to the UFS standard, the operation code of the query response UPIU QRESP UPIU is "xx11 0110b", and the query response UPIU QRESP UPIU may include a flag, a task tag, etc., like the query request UPIU QREQ UPIU. Fig.10 Similarly, the transaction-specific fields of the read descriptor code may include an opcode (e.g., "01h"), a descriptor identifier DESCRIPTOR IDN, an index INDEX, a selector SELECTOR, and a length LENGTH. Fig.10 In the same manner as in the example, the fields of addresses K to K+Length-1 in the query response UPIU QRESP UPIU according to the UFS standard include descriptor data DSCPT DATA. The initiator device 1000 may check the value of “bMaxMutipleFailure” set in the target device 1100.

[0095] Fig.12 is a diagram showing a format of a query request UPIU QREQ UPIU related to writing attributes according to an embodiment.

[0096] refer to Fig.12 , the initiator device 1000 may send a query request UPIU QREQ UPIU including a query request QREQ and a write attribute WT ATTRBT to the target device 1100 , and the target device 1100 may send a query response UPIU QRESP UPIU to the initiator device 1000 .

[0097] The write attribute WT ATTRBT (ie, the transaction specific field of the write attribute code) may include an opcode (eg, "04h"), an attribute identifier ATTRIBUTE IDN, an index INDEX, a selector SELECTOR, and a value VALUE[63:0].

[0098] In an embodiment, the value of the attribute identifier ATTRIBUTE IDN may be "47h". The name of the attribute may be "bWFIMutipleFailureMode". "bWFIMutipleFailureMode" specifies a processing method when a request containing a write failure index fails multiple times. The access attributes of "bWFIMutipleFailureMode" are read or write once, and the size of "bWFIMutipleFailureMode" may be 1 byte. The type of "bWFIMutipleFailureMode" may be a device-level attribute D. The manufacturer default value (hereinafter referred to as "MDV") of "bWFIMutipleFailureMode" may be 0. When the value of "bWFIMutipleFailureMode" is "00h", nothing occurs in the target device 1100 (e.g., device 100). In an embodiment, when the value of "bWFIMutipleFailureMode" is "00h", the target device 1100 can execute an ignore mode and ignore requests from external devices (e.g., the host 10, the attacker 50, the initiator device 1000, etc.) in the ignore mode. When the value of "bWFIMutipleFailureMode" is "01h", the target device 1100 can be forced to power cycle. When the value of "bWFIMutipleFailureMode" is "02h", the target device 1100 can execute a read-only mode. The read-only mode may be a mode in which the access attribute corresponding to the RPMB area is read-only. That is, in read-only mode, the target device 1100 can only read data stored in the RPMB area, and cannot write data to the RPMB area.

[0099] In an embodiment, the value of the attribute identifier ATTRIBUTE IDN may be "48h". The name of the attribute may be "bWFIDataType". "bWFIDataType" specifies the data type of the field (e.g., index field 916) where the write failure index is to be stored. The access attribute of "bWFIDataType" is read or write once, and the size of "bWFIDataType" may be 1 byte. The type of "bWFIDataType" may be a device-level attribute D. The MDV of "bWFIDataType" may be 0. When the value of "bWFIDataType" is "00h", the data type of the index field 916 may be an integer method determined by any number of 16 bytes. When the value of "bWFIDataType" is "01h", the data type of the index field 916 may be a bitmap method.

[0100] Fig.13 is a diagram showing an embodiment of recording a write failure index.

[0101] refer to Fig.13 , and the above reference Figure 2 Similar to the description given, the host 10 can output the first RPMB write request RPMB WREQ1 including the write failure index WFI1_1. In this regard, the attacker 50 can attempt a replay attack. For example, the attacker 50 can steal the first RPMB write request RPMB WREQ1 from the host 10, modify the first original data of the host 10, and send the modified data and the first RPMB write request RPMB WREQ1 to the device 100. The first RPMB write request RPMBWREQ1 may include a message authentication code, meta information, etc. When the write failure index is not recorded in the target RPMB area TRR of the device 100, as described above Figure 2 As described, the device 100 may perform an authentication operation by comparing two message authentication codes, and since the data modified by the attacker 50 is sent to the device 100, the two message authentication codes are different from each other, and therefore the result of the authentication operation is processed as a failure. That is, the device 100 may process the result of the authentication operation as a failure and record the write failure index WFI1_1 (S100). For example, the memory controller 110 may store the value of the write failure index WFI1_1 in the first index field IF1 of the target RPMB region TRR. Here, the number of index fields of the target RPMB region TRR may correspond to the value of "bMaxMutipleFailure" set in the RPMB unit descriptor. For example, referring to Fig.13 , assuming that the number of index fields of the target RPMB region TRR is 3. Thereafter, the attacker 50 may provide the first RPMB write request RPMB WREQ1 and the first original data to the device 100 at any time. In this case, the two message authentication codes may be the same, but the device 100 may first compare the write failure indexes with each other, and because the write failure index WFI1_1 matches, it is determined that the authentication has failed (S110), and the code value of the result field RSLT is set to "000Dh" (WFI failure). In this case, in a replay attack, once the write failure index WFI1_1 is stored in the device 100, even if the same write failure index WFI1_1 is repeatedly sent to the device 100, the storage of the write failure index WFI1_1 may be omitted. Therefore, waste of RPMB resources may be prevented, and RPMB resources may be ensured.

[0102] The host 10 may output a second RPMB write request RPMB WREQ2 including a write failure index WFI1_2. The second RPMB write request RPMB WREQ2 may be a request independent of the first RPMB write request RPMB WREQ1. In this regard, the attacker 50 may attempt a replay attack. The device 100 may compare the write failure indexes, and when the value of the write failure index WFI1_2 is different from the value of the write failure index WFI1_1, perform an authentication operation, but since the two message authentication codes are different, the authentication fails again, and the value of the write failure index WFI1_2 may be stored in the second index field IF2 of the target RPMB area TRR. That is, the device 100 may process the result of the authentication operation as a failure and record the write failure index WFI1_2 (S200). The write failure index WFI1_2 may be stored in the second index field IF2 of the target RPMB area TRR. Thereafter, at any time, when the attacker 50 provides the device 100 with the second RPMB write request RPMB WREQ2 and the second original data stolen from the host 10, since the write failure index WFI1_2 is stored in the device 100, the authentication may be processed as failed even if the two message authentication codes are the same (S210).

[0103] The host 10 may output a third RPMB write request RPMB WREQ3 including a write failure index WFI1_3. The first RPMB write request RPMB WREQ1, the second RPMB write request RPMB WREQ2, and the third RPMB write request RPMB WREQ3 may be independent requests. In this case, the attacker 50 may attempt the replay attack again. The device 100 may process the result of the authentication operation as a failure due to a message authentication code mismatch, and may store the value of the write failure index WFI1_3 in the third index field IF3 of the target RPMB region TRR (S300). Thereafter, even if the attacker 50 provides the device 100 with a third RPMB write request RPMB WREQ3 and third original data stolen from the host 10, the authentication may be processed as a failure (S310).

[0104] When the number of consecutive failures exceeds the preset maximum number, there may be no index field to additionally write the write failure index. In this case, the device 100 may execute any one of the ignore mode, power cycle, and read-only mode. For example, when the number of consecutive authentication failures exceeds the maximum number, the device 100 may execute the attribute "bWFIMutipleFailureMode". Fig.14 and Fig.15 Describes an embodiment of the attribute "bWFIMutipleFailureMode".

[0105] Fig.14 is a diagram showing an embodiment of initializing a field storing a write fail index WFI1_4 in a power cycle.

[0106] refer to Fig.13 and Fig.14 In an embodiment, after a maximum number of different write failure indexes are recorded into the target RPMB area TRR (see S300), a fourth RPMB write request RPMB WREQ4 including a write failure index WFI1_4 may be sent to the device 100. The fourth RPMB write request RPMB WREQ4 may be independent of the first RPMB write request RPMB WREQ1, the second RPMB write request RPMB WREQ2, and the third RPMB write request RPMB WREQ3. When the authentication operation result of the fourth RPMB write request RPMB WREQ4 is processed as a failure due to a message authentication code mismatch (S400), the device 100 may execute the attribute "bWFIMutipleFailureMode". In an embodiment, when the value of "bWFIMutipleFailureMode" is set to "01h", the device 100 may be forced to power cycle (S410). For example, after S300 , the memory controller 110 may delete the write failure indexes WFI1_1 , WFI1_2 , and WFI1_3 , or set them to default values ​​(eg, “0”) to initialize the first index field IF1 , the second index field IF2 , and the third index field IF3 of the target RPMB region TRR .

[0107] Fig.15 is a diagram showing an embodiment of initializing fields storing write failure indexes WFI1_4 and WFI1_5 in a read-only mode.

[0108] refer to Fig.13 and Fig.15In an embodiment, when the fourth RPMB write request RPMB WREQ4 including the write failure index WFI1_4 is sent to the device 100 after S300, and the authentication operation result of the fourth RPMB write request RPMB WREQ4 is processed as failed due to the message authentication code mismatch (S400), the device 100 can execute the attribute "bWFIMutipleFailureMode". In an embodiment, when the value of "bWFIMutipleFailureMode" is set to "02h", the device 100 can execute the read-only mode (S420). After S420, when the fifth RPMB write request RPMB WREQ5 including the write failure index WFI1_5 is sent to the device 100, in the read-only mode, the device 100 can set the code value of the authentication result to "000Eh" and output the response RESP including the result RESULT. Here, "000Eh" indicates that the authentication failed because the device 100 is operating in read-only mode, as described above with reference to FIG. Figure 5 For example, in the read-only mode, the memory controller 110 may send a response RESP including a second code value to the external device. The second code value may indicate that the authentication operation failed for a write request (eg, the fifth RPMB write request RPMB WREQ5) provided by the external device, and may be "000Eh".

[0109] Fig.16 is a flowchart illustrating a method of operating the device 100 according to an embodiment.

[0110] refer to Figure 1 and Fig.16 , the device 100 may be a UFS device that communicates with an external device. The external device may be, for example, a host 10 or an attacker 50.

[0111] The device 100 may perform operation S1000 of receiving a write request for the RPMB area. In an embodiment, the write request may include a first message authentication code, a first write failure index, and meta information. The write request according to an embodiment may also include data, such as an RPMB message data frame. The embodiment of the write request is similar to the above reference Figures 3 to 8 and Figures 13 to 15 The first message authentication code may be calculated based on the first write failure index and the meta information. The embodiment of calculating the first message authentication code is the same as that of the above reference Figure 2 and Figure 8 Same as described.

[0112] The device 100 may perform operation S2000 of determining whether to perform an authentication operation on the external device based on the second write failure index and the first write failure index contained in the RPMB area. The RPMB area may be included in the device 100, and the second write failure index may refer to a write failure index stored in an index field of the RPMB area. The embodiment of operation S2000 is similar to the above reference 1. Figure 8 Same as described.

[0113] The device 100 may perform operation S3000 of outputting a response including a result of the authentication operation. The result of the authentication operation may be the result of the authentication operation described above. Figure 5 Any of the code values ​​of the result field RSLT described.

[0114] In an embodiment, operation S2000 may include an operation of comparing the value of the first write failure index with the value of the second write failure index, and for a case where the value of the first write failure index and the value of the second write failure index are the same, determining the result of the authentication operation as failure. Figure 8 The operation S10 is the same as described above.

[0115] In an embodiment, operation S3000 may include an operation of setting a first code value indicating that the result of the authentication operation is a failure, and an operation of sending a response to an external device. Figure 8 The operation S50 is the same as described above.

[0116] In an embodiment, the method of operating the device 100 may further include an operation of storing the first write failure index in the RPMB area. Figure 8 The operation S30 is the same as described above.

[0117] In an embodiment, operation S2000 may further include an operation of comparing the number of failures (the result of the authentication operation is determined to be a failure) with a preset maximum number of times, and an operation of performing any one of a power cycle and a read-only mode when the number of failures reaches the maximum number of times. Fig.13 Operations S100 to S400 are the same as described above.

[0118] Fig.17 is a diagram illustrating a UFS system 2000 according to an embodiment.

[0119] refer to Fig.17 The UFS system 2000 is a system that complies with the UFS standard issued by JEDEC and may include a UFS host 2100, a UFS device 2200, and a UFS interface 2300. Fig.17 To the extent that the description of Figure 1The description of system 1 can also be applied to UFS system 2000.

[0120] The UFS host 2100 and the UFS device 2200 may be connected to each other through a UFS interface 2300. Figure 1 When the host 10 is an AP, the UFS host 2100 can be implemented as a part of the corresponding AP. The UFS device 2200 can correspond to Figure 1 The device 100, and the UFS device controller 2210 and the non-volatile memory 2220 may correspond to Figure 1 A memory controller 110 and a memory 120 are provided.

[0121] The UFS host 2100 may include a UFS host controller 2110, an application 2120, a UFS driver 2130, a host memory 2140, and a UFS interconnect (UIC) layer 2150. The UFS device 2200 may include a UFS device controller 2210, a nonvolatile memory 2220, a storage interface 2230, a device memory 2240, a UIC layer 2250, and a regulator 2260. The nonvolatile memory 2220 may include a plurality of memory cells 2221, and the memory cell 2221 may include a V-NAND flash memory having a 2D structure or a 3D structure, but may include another type of nonvolatile memory such as a phase change random access memory (PRAM) and / or a resistive random access memory (RRAM). The UFS device controller 2210 and the nonvolatile memory 2220 may be connected to each other through a storage interface 2230. The storage interface 2230 may be implemented to comply with a standard protocol such as toggle or ONFI.

[0122] The application 2120 may represent a program that wishes to communicate with the UFS device 2200 to use functions of the UFS device 2200. The application 2120 may send an input-output request (IOR) to the UFS driver 2130 to perform input / output with respect to the UFS device 2200. The IOR may represent a read request, a write request, and / or a disk request for data, but is not limited thereto.

[0123] The UFS driver 2130 can manage the UFS host controller 2110 through the UFS-Host Controller Interface (HCI). The UFS driver 2130 can convert the IOR generated by the application 2120 into a UFS command defined by the UFS standard, and send the converted UFS command to the UFS host controller 2110. One IOR can be converted into multiple UFS commands. The UFS command can basically be a command defined by the SCSI standard, but can also be a UFS standard dedicated command.

[0124] The UFS host controller 2110 may send the UFS command converted by the UFS driver 2130 to the UIC layer 2250 of the UFS device 2200 through the UIC layer 2150 and the UFS interface 2300. In this process, the UFS host register 2111 of the UFS host controller 2110 may serve as a command queue (CQ).

[0125] The UIC layer 2150 on the UFS host 2100 side may include a MIPI M-PHY 2151 and a MIPI UniPro 2152 , and the UIC layer 2250 on the UFS device 2200 side may also include a MIPI M-PHY 2251 and a MIPI UniPro 2252 .

[0126] The UFS interface 2300 may include a line transmitting a reference clock REF_CLK, a line transmitting a hardware reset signal RESET_n for the UFS device 2200 , a pair of lines transmitting a differential input signal pair DIN_t and DIN_c, and a pair of lines transmitting a differential output signal pair DOUT_t and DOUT_c.

[0127] The frequency value of the reference clock REF_CLK provided by the UFS host 2100 to the UFS device 2200 may be one of four values, 19.2 MHz, 26 MHz, 38.4 MHz, and 52 MHz, but is not limited thereto. The UFS host 2100 may change the frequency value of the reference clock REF_CLK even during operation (i.e., during data transmission and reception between the UFS host 2100 and the UFS device 2200). The UFS device 2200 may generate clocks of various frequencies according to the reference clock REF_CLK provided from the UFS host 2100 by using a phase-locked loop PLL. In addition, the UFS host 2100 may set the value of the data rate between the UFS host 2100 and the UFS device 2200 by the frequency value of the reference clock REF_CLK. That is, the value of the data rate may be determined according to the frequency value of the reference clock REF_CLK.

[0128] The UFS interface 2300 may support multiple channels, and each channel may be implemented as a differential line pair. For example, the UFS interface 2300 may include one or more receiving channels and one or more transmitting channels. Fig.17 In the example, a pair of lines that transmit the differential input signal pair DIN_T and DIN_C can constitute a receiving channel, and a pair of lines that transmit the differential output signal pair DOUT_T and DOUT_C ​​can constitute a transmitting channel. Fig.17 One transmit channel and one receive channel are shown, but the number of transmit channels and receive channels may vary.

[0129] The receiving channel and the transmitting channel can transmit data in a serial communication manner, and the structure in which the receiving channel and the transmitting channel are separated enables full-duplex communication between the UFS host 2100 and the UFS device 2200. That is, even if the UFS device 2200 receives data from the UFS host 2100 through the receiving channel, the data can be sent to the UFS host 2100 through the transmitting channel. In addition, control data (such as a command from the UFS host 2100 to the UFS device 2200) and user data that the UFS host 2100 wants to store in the non-volatile memory 2220 of the UFS device 2200 or read from the non-volatile memory 2220 can be transmitted through the same channel. Therefore, in addition to a pair of receiving channels and a pair of transmitting channels, there is no need to further provide a separate channel for data transmission between the UFS host 2100 and the UFS device 2200.

[0130] The UFS device controller 2210 of the UFS device 2200 may control the overall operation of the UFS device 2200. The UFS device controller 2210 may manage the nonvolatile memory 2220 through a logical unit (LU) 2211 (logical data storage unit). The number of LU2211 may be 8, but is not limited thereto. The UFS device controller 2210 may include a flash translation layer (FTL), and may convert a logical data address (e.g., LBA) transmitted from the UFS host 2100 into a physical data address (e.g., physical block address (PBA)) by using address mapping information of the FTL. In the UFS system 2000, a logical block for storing user data may have a certain range of sizes. For example, the minimum size of a logical block may be set to 4K bytes.

[0131] When a command from the UFS host 2100 is input to the UFS device 2200 through the UIC layer 2250 , the UFS device controller 2210 may perform an operation according to the input command and send a completion response to the UFS host 2100 when the operation is completed.

[0132] For example, when the UFS host 2100 wants to store user data in the UFS device 2200, the UFS host 2100 may send a data storage command to the UFS device 2200. When receiving a user data ready to send response from the UFS device 2200, the UFS host 2100 may send the user data to the UFS device 2200. The UFS device controller 2210 may temporarily store the received user data in the device memory 2240, and store the user data temporarily stored in the device memory 2240 in a selected location in the nonvolatile memory 2220 based on the address mapping information of the FTL.

[0133] As another example, when the UFS host 2100 wants to read user data stored in the UFS device 2200, the UFS host 2100 may send a data read command to the UFS device 2200. Upon receiving the command, the UFS device controller 2210 may read the user data from the nonvolatile memory 2220 based on the data read command, and temporarily store the read user data in the device memory 2240. In such a reading process, the UFS device controller 2210 may detect and correct errors in the read user data by using a built-in error correction code (ECC) engine. More specifically, the ECC engine may generate parity bits for write data to be written to the nonvolatile memory 2220, and store the generated parity bits in the nonvolatile memory 2220 together with the write data. When reading data from the nonvolatile memory 2220, the ECC engine may correct errors in the read data by using the parity bits read from the nonvolatile memory 2220 together with the read data, and output the read data in which the errors have been corrected.

[0134] In addition, the UFS device controller 2210 may transmit user data temporarily stored in the device memory 2240 to the UFS host 2100. In addition, the UFS device controller 2210 may further include an Advanced Encryption Standard (AES) engine. The AES engine may perform at least one of an encryption operation and a decryption operation on data input to the UFS device controller 2210 by using a symmetric key algorithm.

[0135] The UFS host 2100 may sequentially store commands to be sent to the UFS device 2200 in the UFS host register 2111, which may be used as a command queue, and sequentially send the commands to the UFS device 2200. In this regard, the UFS host 2100 may send the next command waiting in the CQ to the UFS device 2200 even if the previously sent command is still being processed by the UFS device 2200, that is, even before receiving a notification that the previously sent command has been completely processed by the UFS device 2200, and thus the UFS device 2200 may also receive the next command from the UFS host 2100 while processing the previously sent command. The maximum queue depth of commands that can be stored in the CQ may be, for example, 32. In addition, the CQ may be implemented as a circular queue type, which indicates the beginning and end of a command column stored in the queue by a head pointer and a tail pointer, respectively.

[0136] Each of the plurality of memory cells 2221 may include a memory cell array and a control circuit that controls the operation of the memory cell array. The memory cell array may include a two-dimensional (2D) memory cell array or a three-dimensional (3D) memory cell array. The memory cell array includes a plurality of memory cells, and each memory cell may be a single-level cell (SLC) storing 1 bit of information, but may also be a cell storing 2 or more bits of information, such as a multi-level cell (MLC), a triple-level cell (TLC), and a quad-level cell (QLC). The 3D memory cell array may include a vertical NAND string oriented vertically such that at least one memory cell is located above another memory cell.

[0137] Power supply voltages VCC, VCCQ, VCCQ2, etc. may be input to the UFS device 2200. VCC is the main power supply voltage of the UFS device 2200 and may have a value of 2.4V to 3.6V. VCCQ is a power supply voltage for providing a low range voltage, mainly used for the UFS device controller 2210, and may have a value of 1.14V to 1.26V. VCCQ2 is a power supply voltage for providing a voltage lower than VCC but higher than the VCCQ range, mainly used for input / output interfaces such as MIPIM-PHY 2251, and may have a value of 1.7V to 1.95V. The power supply voltages VCC, VCCQ, and VCCQ2 may be provided to each component of the UFS device 2200 by the regulator 2260. The regulator 2260 may be implemented as a group of unit regulators connected to different power supply voltages among the power supply voltages VCC, VCCQ, and VCCQ2, respectively.

[0138] Fig.18A , Fig.18B and Fig.18C is a diagram showing the form factor of a UFS card. Fig.17 When the UFS device 2200 is implemented in the form of a UFS card 4000, the appearance of the UFS card 4000 may follow Fig.18A , Fig.18B and Fig.18C The appearance shown in .

[0139] Fig.18A A top view of a UFS card 4000 is shown. Fig.18A , it can be confirmed that the UFS card 4000 follows a shark-shaped design as a whole. Fig.18A , the UFS card 4000 may have size values ​​as shown in Table 1 below.

[0140] Table 1:

[0141] Fig.18B FIG. 4 shows a side view of a UFS card 4000. Fig.18B, the UFS card 4000 may have size values ​​as shown in Table 2 below.

[0142] Table 2:

[0143] Fig.18C FIG. 4 shows a bottom view of a UFS card 4000. Fig.18C , a plurality of pins for electrically connecting to the UFS slot may be formed on the bottom surface of the UFS card 4000, and the function of each pin will be described below. Based on the symmetry of the top and bottom surfaces of the UFS card 4000, reference Fig.18A and some of the dimensional information described in Table 1 (e.g. T1 to T5 and T9) may also be applied to Fig.18C A bottom view of a UFS card 4000 is shown.

[0144] A plurality of pins for electrically connecting to a UFS host may be formed on the bottom surface of the UFS card 4000, such as Fig.18C As shown, the total number of pins may be 12. Each pin may have a rectangular shape, and the signal name corresponding to the pin may be as follows: Fig.18C For a summary of each pin, refer to Table 3 below or to the reference Fig.17 Description.

[0145] Table 3:

[0146] The above embodiments (including Figures 1 to 7 , Figures 9 to 12 and Fig.17 At least one of the components, elements, modules, units, etc. (collectively referred to as "components" in this paragraph) represented by blocks or equivalent indications (collectively referred to as "blocks") in the drawings (such as the drawings, etc.) (for example, memory controllers, memories, buffers, hosts, devices, etc.) can perform the above functions. These blocks can be physically implemented by analog and / or digital circuits (such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hard-wired circuits, etc.), and can be optionally driven by firmware. For example, the circuit can be specifically implemented in one or more semiconductor chips, or on a substrate support such as a printed circuit board. The circuits constituting the blocks can be implemented by dedicated hardware or by a processor (for example, one or more programmed microprocessors and associated circuits), or by a combination of dedicated hardware for performing some functions of the block and a processor for performing other functions of the block. Without departing from the scope of the present disclosure, each block of the embodiment can be physically divided into two or more interactive and discrete blocks. Similarly, without departing from the scope of the present disclosure, the blocks of the embodiment can be physically combined into more complex blocks.

[0147] While the present disclosure has been particularly shown and described with reference to embodiments thereof, it will be understood that various changes in form and details may be made therein without departing from the spirit and scope of the appended claims.

Claims

1. A universal flash memory UFS device, comprising: A memory, comprising a replay protection storage block RPMB area, wherein the RPMB area comprises one or more index fields storing a second write failure index; as well as a memory controller comprising at least one controller memory storing one or more instructions, The memory controller is configured to execute the one or more instructions to enable the UFS device to: receiving an RPMB write request from an external device, the RPMB write request comprising a first write failure index, meta information, and a first message authentication code generated based on the first write failure index and the meta information, and Whether to perform an authentication operation on the external device is determined based on the first write failure index and the second write failure index.

2. The UFS device according to claim 1, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: comparing the value of the first write failure index with the value of the second write failure index, performing the authentication operation based on the RPMB write request based on the value of the first write failure index being different from the value of the second write failure index, and Based on the fact that the value of the first write failure index is the same as the value of the second write failure index, the result of the authentication operation is determined to be a failure.

3. The UFS device according to claim 1, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: Obtaining a second message authentication code based on a preset algorithm, the first write failure index and the meta information, comparing the value of the first message authentication code with the value of the second message authentication code, and Whether the authentication operation is successful is determined based on whether the value of the first message authentication code matches the value of the second message authentication code.

4. The UFS device according to claim 1, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: based on a result of the authentication operation being a failure, store the first write failure index in the RPMB area, and send a response to the external device including a first code value indicating that the authentication operation failed.

5. The UFS device according to claim 1, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: Based on the authentication operation failing a predetermined number of times, at least one of a ignore mode, a power cycle, or a read-only mode is entered.

6. The UFS device according to claim 5, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: Based on the UFS device entering the power cycle, a first index field storing the first write failure index and a second index field storing the second write failure index are initialized.

7. The UFS device according to claim 5, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: Based on the UFS device entering the read-only mode, a response including a second code value indicating that the authentication operation failed for the write request of the external device is sent to the external device.

8. The UFS device according to claim 1, wherein: The memory controller is configured to execute the one or more instructions to cause the UFS device to: Based on a result of the authentication operation being successful, the one or more index fields are initialized.

9. The UFS device according to claim 1, wherein: The RPMB write request includes at least one of an authentication data write request, a security write protection configuration block write request, and an RPMB clear enable request.

10. A method of operating a universal flash storage (UFS) device configured to communicate with an external device, the method comprising: Receive a replay protection storage block RPMB write request, the RPMB write request including a first write failure index, meta information, and a first message authentication code generated based on the first write failure index and the meta information; identifying whether to perform an authentication operation on the external device based on a second write failure index included in the RPMB area of ​​the UFS device and the first write failure index; as well as Based on performing the authentication operation, a response is output including a result of the authentication operation.

11. The method according to claim 10, wherein: Identifying whether to perform the authentication operation on the external device includes: comparing the value of the first write failure index with the value of the second write failure index; and Based on the value of the first write failure index being the same as the value of the second write failure index, a result of the authentication operation is identified as a failure.

12. The method according to claim 11, wherein: Outputting a response including the result of the authentication operation includes: setting a first code value indicating that the authentication operation failed; and The response including the first code value is sent to the external device.

13. The method according to claim 11, further comprising: The first write failure index is stored in the RPMB area.

14. The method according to claim 11, wherein: Identifying whether to perform the authentication operation on the external device includes: Based on the authentication operation failing a predetermined number of times, at least one of a ignore mode, a power cycle, and a read-only mode is entered.

15. A universal flash memory UFS system, comprising: UFS host, including: at least one host processor; and at least one host memory storing one or more host instructions, The at least one host processor is configured to execute the one or more host instructions to cause the UFS host to: obtaining a first message authentication code based on the first write failure index and the meta information, and Outputting a replay protection storage block RPMB write request including the first message authentication code, the first write failure index and the meta information as an RPMB operation; and UFS devices, including: at least one device processor; and at least one device memory storing one or more device instructions, The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: A determination is made based on the first write failure index whether to perform an authentication operation on the UFS host.

16. The UFS system according to claim 15, wherein: The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: comparing the value of a second write failure index stored in the RPMB area of ​​the UFS device with the value of the first write failure index, and The authentication operation is performed based on a comparison result between the value of the first write failure index and the value of the second write failure index.

17. The UFS system according to claim 16, wherein: The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: performing the authentication operation based on the RPMB write request based on the value of the first write failure index being different from the value of the second write failure index, and Based on the fact that the value of the first write failure index is the same as the value of the second write failure index, the result of the authentication operation is determined to be a failure.

18. The UFS system according to claim 17, wherein: The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: Based on the result of the authentication operation being a failure, the first write failure index is stored in the RPMB area, and a first response including a first code value indicating the failure of the authentication operation is sent to the UFS host.

19. The UFS system according to claim 18, wherein: The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: Based on the authentication operation failing a predetermined number of times, at least one of a ignore mode, a power cycle, and a read-only mode is entered.

20. The UFS system according to claim 19, wherein: The at least one device processor is configured to execute the one or more device instructions to cause the UFS device to: Based on the UFS device entering the power cycle, the first write failure index and the second write failure index stored in the RPMB area are initialized, and a second response including a second code value indicating that the authentication operation failed for the write request of the UFS host is sent to the UFS host.

Citation Information

Patent Citations

  • Toilet access wireless control system

    KR1020230161031A