Hardware-based data protection for replaying protected data

By applying encryption technology when transferring data between memory devices and other components, and exporting authentication and encryption keys, the security problem of data transmission in portable electronic devices is solved, the protection of playback protection memory blocks is realized, and the confidentiality and security of data are improved.

CN120569714APending Publication Date: 2025-08-29QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380091979.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-10
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

Data from memory systems in portable electronic devices are susceptible to snooping attacks by threat actors during transmission, resulting in insufficient security of user data.

Method used

When data is transferred between memory devices and other components, encryption technology is applied to protect data by deriveing ​​authentication keys and encryption keys, especially access to and data transmission of playback protection memory block (RPMB) portions of memory modules.

Benefits of technology

Improve the confidentiality of user data, prevent unauthorized users or threat actors from snooping and accessing sensitive data, and enhance the security of the memory system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120569714A_ABST
    Figure CN120569714A_ABST
Patent Text Reader

Abstract

This disclosure provides systems, methods, and devices for a memory system that supports encryption of in-transit data for replaying protected memory blocks (RPMBs). In a first aspect, a method of processing data for a memory system includes receiving, from a host device, an authentication key for authenticating access to data stored in a portion of a memory module; deriving an encryption key based on the authentication key; and processing data transmitted over a first interface between the host device and the memory system based on the encryption key. Other aspects and features are also claimed and described.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Aspects of the present disclosure generally relate to an apparatus and method for controlling a memory device. More specifically, some aspects may relate to an apparatus and method for controlling an operation of encrypting data communicated to a memory storage device. Background Art

[0002] As the value and use of information continues to increase, individuals and businesses are seeking additional ways to process and store information. Furthermore, the use of information in a variety of locations and the desire for information portability are increasing. To this end, users are increasingly turning to portable electronic devices such as mobile phones, digital cameras, and laptop computers. Portable electronic devices often employ memory systems that use memory devices to store data. Memory systems can serve as either primary memory or secondary memory for portable electronic devices.

[0003] The memory devices of a memory system may include one type of storage device or a combination of multiple types of storage devices. For example, magnetic-based memory systems, such as hard disk drives (HDDs), store data by encoding the data as a combination of small magnets. As another example, optical-based memory systems, such as digital versatile discs (DVDs) and Blu-ray media, store data by encoding the data as physical bits that reflect differently when illuminated by a light source. As another example, electronic memory devices store data as a collection of electrons that can be detected by voltage and / or current measurements.

[0004] Electronic memory devices can be advantageous in certain systems because they can access data quickly and consume little power. Examples of electronic memory devices with these advantages include Universal Serial Bus (USB) memory devices (sometimes called "memory sticks"), memory cards (such as those used in some cameras and gaming systems), and solid-state drives (SSDs) (such as those used in laptop computers). NAND flash memory is a type of memory device that can be used in electronic memory devices. NAND flash memory is manufactured as memory cards or flash drives. Example memory cards include Compact Flash (CF) cards, MultiMediaCards (eMMC), SmartMedia (SM) cards, and Secure Digital (SD) cards. Summary of the Invention

[0005] The following summarizes some aspects of the present disclosure to provide a basic understanding of the technology discussed. This summary is not an exhaustive overview of all anticipated features of the present disclosure and is neither intended to identify key or important elements of all aspects of the present disclosure nor to delineate the scope of any or all aspects of the present disclosure. The sole purpose of this summary is to provide some concepts of one or more aspects of the present disclosure in a summarized form as a prelude to the more detailed description that will be presented later.

[0006] Information passed between a memory device and other components in an electronic device is subject to being viewed by people who should not have access to the data. Although channels carrying user data within an electronic device may not be easily visible or exposed, a skilled threat actor can easily access the channels and perform a snooping attack that exposes the user's security-sensitive data. According to aspects of the present disclosure, encryption is applied to data during transmission from a memory device to other components. The encrypted data appears to be incomprehensible to recipients other than the intended recipient, thereby preventing snooping attacks from providing user data to threat actors. Aspects of the present disclosure describe systems and methods for encrypting data sent to and from a memory storage device to improve the security of the user data. Some of these aspects include: deploying keys to components; deriving encryption keys from other keys in a component; applying encryption to specific areas of data in a storage device, such as a replay protected memory block (RPMB) of a universal flash storage (UFS) device; or a combination thereof.

[0007] In one aspect of the present disclosure, a memory device includes: a memory controller coupled to a memory module via a first channel and configured to access data stored in the memory module via the first channel; and coupled to a host device via a first interface and configured to communicate with the host device via the first interface. The memory controller may be configured to perform operations including: receiving a seed key from the host device; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protection memory block (RPMB) portion of the memory module; controlling access to the RPMB portion of the memory module based on the authentication key; deriving an encryption key based on the seed key; and processing data on the first interface based on the encryption key.

[0008] In an additional aspect of the present disclosure, an apparatus includes at least one processor and a memory coupled to the at least one processor. The at least one processor is configured to, at a memory controller of a memory system, receive a seed key from a host device via a first interface between the memory controller and the host device; derive, at the memory controller, an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protected memory block (RPMB) portion of a memory module, the memory module being coupled to the memory controller via a first channel; derive, by the memory controller, an encryption key based on the seed key; and process, by the memory controller, data on the first interface based on the encryption key.

[0009] In an additional aspect of the present disclosure, an apparatus includes: a memory controller of a host device, the memory controller configured to couple the host device to a memory system via a first interface, the memory controller configured to perform operations comprising: determining a seed key; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protected memory block (RPMB) portion of the memory system; deriving an encryption key based on the seed key; and processing data on the first interface based on the encryption key.

[0010] In an additional aspect of the present disclosure, a non-transitory computer-readable medium stores instructions that, when executed by a processor, cause the processor to perform operations including: determining a seed key at a memory controller of a host device; deriving, by the memory controller of the host device, an authentication key based on the seed key, the authentication key for authenticating access to data stored in a replay protected memory block (RPMB) portion of a memory system; deriving, by the memory controller of the host device, an encryption key based on the authentication key; and processing, by the memory controller of the host device, data on a first interface coupling the memory controller of the host device to a memory system, wherein the processing of the data is based on the encryption key.

[0011] The features and technical advantages of the examples according to the present disclosure have been summarized in a rather broad manner above so that the detailed description below may be better understood. Additional features and advantages will be described below. The concepts and specific examples disclosed may be easily used as a basis for modifying or designing other structures for achieving the same purpose of the present disclosure. Such equivalent constructions do not depart from the scope of the appended claims. The characteristics of the concepts disclosed herein (both their organization and method of operation) and the associated advantages will be better understood from the following description when considered in conjunction with the accompanying drawings. Each of the figures in the accompanying drawings is provided for the purpose of illustration and description and not as a definition of limitations of the claims.

[0012] Although various aspects and specific implementations are described in this application by way of illustration of some examples, it will be understood by those skilled in the art that additional specific implementations and use cases may be generated in many different arrangements and scenarios. The innovations described herein can be implemented across many different platform types, devices, systems, shapes, sizes, and packaging arrangements. For example, various aspects and / or uses may be implemented via integrated chip implementations and other devices based on non-module components (e.g., end-user devices, vehicles, communication equipment, computing equipment, industrial equipment, retail / purchase equipment, medical equipment, devices that enable artificial intelligence (AI), etc.). Although some examples may or may not specifically point to use cases or applications, the applicability of various types of the described innovations may occur. The scope of specific implementations may range from chip-level or module components to non-module, non-chip-level implementations, and further to aggregated, distributed, or original equipment manufacturer (OEM) devices or systems in conjunction with one or more aspects of the described innovations. In some actual settings, the devices in conjunction with the described various aspects and features may also necessarily include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals necessarily include multiple components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The innovations described herein are intended to be practiced in a variety of devices, chip-level components, systems, distributed arrangements, end-user devices, etc., having different sizes, shapes, and configurations. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] A further understanding of the nature and advantages of the present disclosure may be achieved by referring to the following drawings. In the drawings, similar components or features may have the same reference numerals. In addition, various components of the same type may be distinguished by following the reference numeral with a dash and a second reference numeral to distinguish between similar components. If only the first reference numeral is used in the specification, the description applies to any of the similar components having the same first reference numeral, regardless of the second reference numeral.

[0014] Figure 1 is a block diagram illustrating a data processing system including a memory system according to an embodiment of the present invention.

[0015] Figure 2 is a block diagram illustrating an example electronic device including a memory system according to one or more aspects of the present disclosure.

[0016] Figure 3 is a block diagram illustrating an electronic device with an encrypted channel to a playback protected memory body (RPMB) of a storage device according to one or more aspects of the present disclosure.

[0017] Figure 4 is a call flow diagram illustrating encryption of data in transit using a memory storage device according to one or more aspects of the present disclosure.

[0018] Figure 5 is a flow chart illustrating a method for processing data on an interface between a host device and a memory system using two keys according to one or more aspects of the present disclosure.

[0019] Figure 6 is a block diagram illustrating details of an example wireless communication system in accordance with one or more aspects.

[0020] The same reference numbers and names in different drawings represent the same elements. DETAILED DESCRIPTION

[0021] The detailed description set forth below in conjunction with the accompanying drawings is intended as a description of various configurations and is not intended to limit the scope of the present disclosure. Instead, the detailed description includes specific details for providing a thorough understanding of the subject matter of the present invention. It will be apparent to those skilled in the art that these specific details are not required in every case, and in some instances, well-known structures and components are shown in block diagram form for clarity of presentation.

[0022] The present disclosure provides systems, devices, methods, and computer-readable media that support data processing, including techniques for storing, retrieving, and organizing data in a memory system. Specifically, aspects of the present disclosure provide for encrypting data while in transit between components of an electronic device. For example, data on a physical channel between a host device and a playback protected memory block (RPMB) of a memory system can be encrypted.

[0023] Specific implementations of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages or benefits. In some aspects, the present disclosure provides techniques for improving the confidentiality of user data by reducing the likelihood of a threat actor obtaining user data through a snooping channel or preventing a threat actor from obtaining user data through a snooping channel. The present disclosure can provide additional benefits, such as reducing the likelihood of an unauthenticated user of a memory system (e.g., an application or virtual machine executing on a host device) gaining access to protected areas of the memory system (e.g., RPMBs assigned to other applications or virtual machines).

[0024] The memory can be used for Figure 1 In a computing system organized as illustrated. Figure 1A data processing system 100, such as may be included in a mobile computing device, according to one or more aspects of the present disclosure is illustrated. A memory system 110 may be coupled to a host device 102 via one or more channels. For example, the host device 102 and the memory system 110 may be coupled via a serial interface including a single channel for transmitting data or a parallel interface including two or more channels for transmitting data. In some aspects, control data may be passed via the same channel as the data, or the control data may be passed via additional channels. The host device 102 may be, for example, a system on a chip (SoC), a portable electronic device such as a mobile phone, an MP3 player, a laptop computer, or a non-portable electronic device such as a desktop computer, a game console, a television (TV), a media player, or a projector. Reference Figure 6 Additional example host devices are illustrated and described.

[0025] Memory system 110 can perform operations in response to commands (e.g., requests) from host device 102. For example, memory system 110 can store data provided by host 102, and memory system 110 can also provide stored data to host 102. Memory system 110 can be used by host device 102 as main memory, short-term memory, or long-term memory. As an example of main memory, host device 102 can use memory system 110 to supplement or replace system memory by using memory system 110 to store temporary data (such as data related to an operating system and / or threads executing in the operating system). As an example of short-term memory, host device 102 can use memory system 110 to store a page file for an operating system. As an example of long-term memory, host device 102 can use memory system 110 to store user files (e.g., documents, videos, pictures) and / or application files (e.g., word processing executable files, game applications).

[0026] The memory system 110 may be implemented using any of a variety of storage devices according to a protocol of a host interface for coupling the memory system 110 to one or more channels of the host device 102. The memory system 110 may be implemented using any of a variety of storage devices, such as a solid-state drive (SSD), a multimedia card (MMC), an embedded MMC (eMMC), a reduced-size MMC (RS-MMC), a micro MMC, a secure digital (SD) card, a mini SD, a micro SD, a universal serial bus (USB) storage device, a universal flash storage (UFS) device, a compact flash (CF) card, a smart media (SM) card, or a memory stick.

[0027] The memory system 110 may include a memory portion 150 and a controller portion 130 coupled to the memory portion 150 via one or more channels. The memory 150 may store and retrieve data under the control of the controller 130, which may execute commands received from the host device 102. The controller 130 is configured to control data exchange between the memory device 150 and the host 102. The storage components in the memory 150 may be implemented as volatile memory devices (such as dynamic random access memory (DRAM) and static random access memory (SRAM)) or non-volatile memory devices (such as read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), ferroelectric random access memory (FRAM), phase change RAM (PRAM), magnetoresistive RAM (MRAM), resistive RAM (SCRAM), or flash memory).

[0028] The controller 130 and the memory 150 can be formed as integrated circuits on one or more semiconductor dies (or other substrates). In some aspects, the controller 130 and the memory 150 can be integrated into one chip. In some aspects, the memory 150 can include one or more chips coupled to each other in series or in parallel and coupled to the controller 130, which is located on a separate chip. In some aspects, the memory 150 and the controller 130 chips are integrated into a single package, such as in a package-on-package (PoP) system. In some aspects, the memory system 110, together with one or more or all of the components of the host device 102 (e.g., an application processor, a system memory, a digital signal processor, a modem, a graphics processor unit, a memory interface, an input / output interface, a network adapter), are integrated on a single chip, such as in a system on a chip (SoC). The controller 130 and the memory 150 can be integrated into one semiconductor device to form a memory card, such as, for example, a Personal Computer Memory Card International Association (PCMCIA) card, a Compact Flash (CF) card, a Smart Media Card (SMC), a Memory Stick, a MultiMedia Card (MMC), RS-MMC, a Micro MMC, a Secure Digital (SD) card, a Mini SD, a Micro SD, a SDHC, and a Universal Flash Storage (UFS) device.

[0029] The controller 130 of the memory system 110 can control the memory 150 in response to commands from the host device 102. The controller 130 can execute a read command to provide data from the memory 150 to the host device 102, and execute a write command to store data provided from the host device 102 in the memory 150. The controller 130 can execute other commands to manage the data in the memory 150, such as program and erase commands. The controller 130 can also execute other commands to manage the control of the memory system 110, such as setting the configuration registers of the memory system 110. By executing commands according to the configuration specified in the configuration registers, the controller 130 can control the operations of the memory device 150, such as read, write, program, and erase operations.

[0030] The controller 130 may include several components configured to execute received commands. For example, the controller 130 may include a host interface (I / F) unit 132, a processor 134, an error correction code (ECC) unit 138, a power management unit (PMU) 140, a NAND flash memory controller (NFC) 142, and / or a memory 144. The power management unit (PMU) 140 may provide and manage power to the components within the controller 130.

[0031] The host interface unit 132 may process commands and data provided from the host device 102, and may communicate with the host device 102 through at least one of various interface protocols, such as Universal Serial Bus (USB), MultiMediaCard (MMC), Peripheral Component Interconnect Express (PCI-e), Serial Attached SCSI (SAS), Serial Advanced Technology Attachment (SATA), Parallel Advanced Technology Attachment (PATA), Small Computer System Interface (SCSI), Enhanced Small Disk Interface (ESDI), and Integrated Drive Electronics (IDE). For example, the host interface 6431 may be a parallel interface, such as an MMC interface, or a serial interface, such as an Ultra High Speed ​​Class 1 (UHS-I) / UHS Class 2 (UHS-II) and Universal Flash Storage (UFS) interface.

[0032] The ECC unit 138 may detect and correct errors in data read from the memory device 150 during a read operation. When the number of error bits is greater than a threshold number of correctable error bits, the ECC unit 138 may not correct the error bits and may then output an error correction failure signal indicating a failure in correcting the error bits. In some aspects, the ECC unit 138 may not be provided, or the ECC unit 138 may be configured to be active for some or all of the memories 150. The ECC unit 138 may perform error correction operations using coded modulation, such as a low-density parity-check (LDPC) code, a Bose-Chaudhuri-Hochwengeim code (BCH) code, a turbo code, a Reed-Solomon (RS) code, a convolutional code, a recursive systematic code (RSC), a trellis coded modulation (TCM), or a block coded modulation (BCM).

[0033] NFC 142 provides an interface between controller 130 and memory 150, allowing controller 130 to control memory device 150 in response to commands received from host device 102. NFC 142 can generate control signals for memory 150 (such as signals for row lines and bit lines) and process data under the control of processor 134. Although NFC 142 is described as a NAND flash memory controller, other controllers can perform similar functions for other memory types used as memory 150.

[0034] The memory 144 may serve as a working memory for the memory system 110 and the controller 130. The memory 144 may store data for driving the memory system 110 and the controller 130. When the controller 130 controls the operations of the memory device 150 (such as, for example, read, write, program, and erase operations), the memory 144 may store data used by the controller 130 and the memory device 150 for these operations. The memory 144 may be implemented using a volatile memory such as, for example, a static random access memory (SRAM) or a dynamic random access memory (DRAM). In some aspects, the memory 144 may store an address map, a program memory, a data memory, a write buffer, a read buffer, a map buffer, and the like.

[0035] The processor 134 may control the general operation of the memory system 110 and the write operation or the read operation for the memory device 150 in response to a write request or a read request received from the host 102, respectively. For example, the processor 134 may execute firmware called a flash translation layer (FTL) to control the general operation of the memory system 110. The processor 134 may be implemented, for example, using a microprocessor, a central processing unit (CPU), or an application-specific integrated circuit (ASIC).

[0036] Figure 2is a block diagram illustrating an example electronic device including a memory system according to one or more aspects of the present disclosure. Electronic device 200 may include a user interface 210, a memory module 220, an application processor 230, a network adapter 240, and a storage device 250.

[0037] Application processor 230 may execute computer program code including applications, drivers, and an operating system to coordinate the performance of tasks by components included in electronic device 200. Application processor 230 may be part of a system on a chip (SoC) that includes one or more of the other components shown in electronic device 200.

[0038] The memory module 220 can operate as a main memory, a working memory, a buffer memory, or a cache memory of the electronic device 200. The memory module 220 may include a volatile random access memory (such as a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate (DDR) SDRAM, a DDR2 SDRAM, a DDR3 SDRAM, a low power double data rate (LPDDR) SDRAM, a LPDDR2 SDRAM, a LPDDR3 SDRAM, a LPDDR4 SDRAM, a LPDDR5 SDRAM, or a LPDDR6 SDRAM) or a non-volatile random access memory (such as a phase change random access memory (PRAM), a resistive random access memory (ReRAM), a magnetic random access memory (MRAM), and a ferroelectric random access memory (FRAM)). In some aspects, the application processor 230 and the memory module 220 can be combined using a package-on-package (POP).

[0039] The network adapter 240 can communicate with external devices. For example, the network adapter 240 can support wired communication and / or various wireless communications, such as code division multiple access (CDMA), global system for mobile communications (GSM), wideband CDMA (WCDMA), CDMA-2000, time division multiple access (TDMA), long term evolution (LTE), world interoperability for microwave access (WiMAX), wireless local area network (WLAN), ultra-wideband (UWB), Bluetooth, wireless display (WI-DI), etc., so that it can communicate with wired and / or wireless electronic appliances (e.g., mobile electronic appliances).

[0040] The storage device 250 may store data (e.g., data received from the application processor 230) and transmit the data stored therein to the application processor 230. The storage device 250 may be a non-volatile semiconductor memory device such as a phase change RAM (PRAM), a magnetic RAM (MRAM), a resistive RAM (ReRAM), a NAND flash memory, a NOR flash memory, or a 3-dimensional (3-D) NAND flash memory. The storage device 250 may be a removable storage medium such as a memory card or an external drive. For example, the storage device 250 may correspond to the memory device described above with reference to FIG. Figure 1 The memory system 110 is described and may be an SSD, eMMC, or UFS.

[0041] The user interface 210 provides one or more graphical user interfaces (GUIs) for inputting data or commands to the application processor 230 or for outputting data to an external device. For example, the user interface 210 may include a user input interface (such as a virtual keyboard, a touch screen, a camera, a microphone, a gyroscope sensor, or a vibration sensor) and a user output interface (such as a liquid crystal display (LCD), an organic light emitting diode (OLED) display device, an active matrix OLED (AMOLED) display device, a light emitting diode (LED), a speaker, or a haptic motor).

[0042] Encryption can be used to protect data on interfaces between components. Unencrypted data can be vulnerable to snooping or other physical attacks, where an eavesdropper can obtain unencrypted data while it is in transit across the interface. Data sent between a storage device and an electronic device can be particularly vulnerable when the storage device is physically separate from the rest of the electronic device. Data encrypted across the interface, while vulnerable to snooping, produces garbled data that is difficult for an eavesdropper to understand.

[0043] Figure 3 An electronic device with an encryption-protected memory interface is shown in FIG. Figure 3is a block diagram illustrating an electronic device having an encrypted channel to a storage device according to one or more aspects of the present disclosure. The electronic device 300 may include software 310 executing on hardware 320. The software 310 may include an application 312 and / or one or more virtual machines 314, 316 executing in a host operating system. The software 310 may be executed on an application processor core 322 in a system on a chip (SoC). The SoC may also include a universal flash storage (UFS) controller 324 that provides an interface between the application processor core 322 and the UFS device 330 through one or more channels. The UFS controller 324 may include an inline cryptographic engine (ICE) 324A for encrypting data sent to the UFS device 330 through a physical channel. The ICE 324A may include a memory portion of a key space memory for storing authentication and / or encryption keys. Although in Figure 3 The UFS controller 324 and UFS device 330 are illustrated in the example of FIG, but the encryption aspects described herein can be applied to other memory systems, including reference Figure 1 Any of the memory systems described.

[0044] The UFS device 330 may include a controller 336 for interfacing with the UFS controller 324 via a physical channel. The UFS device 330 may also include a replay protected memory block (RPMB) 332 that is configured to store application security data that provides replay protection. For example, the RPMB 332 may protect data written in certain areas from being overwritten (such as by write protection until power cycle or permanent write protection state). The RPMB 332 may be used by software to reduce or prevent downgrade attacks that rewrite software version authentication, or may be used by software to prevent secure boot of unwanted code running on the device.

[0045] RPMB 332 may include one or more defined regions 334A-334D accessible via cryptographic engine 332A. Regions 334A-334D may be Figure 1The cryptographic engine 332A may be part of one of the storage blocks 152, 154, 156 of the RPMB, or may be one of the storage blocks 152, 154, 156 dedicated to the RPMB. The cryptographic engine 332A may restrict access to areas 334A-334D to authorized users and encrypt data from areas 334A-334D before sending it to the UFS controller 324 over the physical channel. Areas 334A-334D may be used by the software 310 to store information related to digital rights management (RDM) (e.g., keys for accessing protected media content in a media player application), biometric data (e.g., fingerprints, facial authentication data, iris authentication data), and / or software rollback versions (e.g., anti-rollback versions of trusted applications). The cryptographic engine 332A may include a key memory space for storing authorization or encryption keys. The key memory space may be sized or allocated from the shared memory as the combined size of the first key and the encryption key (eg, 256 bits or 512 bits) multiplied by the number of regions 334A-334D.

[0046] The encryption applied to data sent over the physical channel can be based on a confidentiality algorithm. For example, the ICE 324A and / or the cryptographic engine 332A can execute one or more algorithms including AES-XTS, CBC, and SHA256-HMAC. In some aspects, the ICE 324A and the cryptographic engine 332A may include dedicated logic for performing encryption and / or decryption of one or more confidentiality algorithms. During an RPMB write operation performed by the UFS controller 324 on the UFS device 330, the UFS controller ICE 324A can encrypt the RPMB data packets assembled by the software 310, and the UFS device 330 can decrypt the content to obtain the RPMB packets for storage. During an RPMB read operation performed by the UFS controller 324 on the UFS device 330, the cryptographic engine 332A of the UFS device is configured to encrypt data from areas 334A-334D, and the UFS controller ICE 324A is configured to decrypt the content and provide the data to the software 310.

[0047] Within the RPMB 332, certain areas can be assigned for exclusive access to certain users (e.g., one or applications 312 or virtual machines 314, 316). Authentication keys can be used to limit access to areas to authorized applications or virtual machines. The authentication key can be deployed by one of the applications 312 or virtual machines 314, 316 to protect one of the areas 334A-334D for exclusive access. The encryption applied to data in transit via the physical channel can be derived from the authentication key. For example, the virtual machine 314 can deploy an authentication key for area 334A in the RPMB 332. The cryptographic engine 332A in the UFS device 330 can derive an encryption key for encryption from the authentication key. The cryptographic engine 332A uses the derived key to encrypt data in the cryptographic engine 332A or controller 336 before sending it to the UFS controller 324 over the physical channel. The encrypted data received at the UFS controller 324 may be decrypted by the UFS controller 324 (such as in the ICE 324A) and delivered to the requesting software 310. Alternatively, the encrypted data may be received at the UFS controller 324 and delivered to the requesting software 310 as encrypted data, and the requesting software 310 may decrypt the data. The UFS controller 324 or the requesting software 310 may derive the decryption key from the authentication key in parallel with the derivation of the encryption key in the UFS device 330.

[0048] Figure 4 An example communication session using encryption to transmit RPMB data between a host device and a memory storage device is shown in FIG. Figure 4 is a call flow diagram illustrating encryption of data in transit using a memory storage device according to one or more aspects of the present disclosure. Figure 3 UFS controller 324) and UFS device 404 (e.g., Figure 3Call 400 is illustrated between a UFS device 330 and a host controller 402. The first call 410 begins with the host controller 402 constructing and transmitting a security protocol command with RPMB metadata. Call 410 can establish an area of ​​the UFS device 404 for secure access by a specific application that accesses data through the host controller 402. At box 412, the host controller 402 encrypts the RPMB data packet, which is sent to the UFS device at call 414. The encryption at box 412 can be performed using an encryption key derived from an authentication key (such as the key used to construct the security protocol command at call 410). If a threat actor is able to obtain the encrypted data, the user data will not be exposed because the data is incomprehensible without the encryption key. The UFS device 404 responds to the host controller 402 at call 416 to indicate the result of the command, such as indicating success, failure, or other information about the execution of the RPMB write operation or the status of the UFS device 404.

[0049] Figure 4 An example RPMB write operation performed by a host device to store data in the RPMB area of ​​a memory storage device is illustrated. During the RPMB write operation, the UFS controller ICE can be used for a software application to encrypt the RPMB data packet, and the receiver-side UFS device decrypts the content. The cryptographic engine of the UFS device can be configured to execute one or more confidentiality algorithms in a set of confidentiality algorithms for decryption. A similar process can be performed for performing an RPMB read operation to retrieve data from the RPMB area. During the RPMB read operation, the cryptographic engine of the UFS device can encrypt the data retrieved from the RPMB area, and the receiver-side UFS controller ICE can decrypt the content for the software application.

[0050] Figure 5 An example method for using multiple keys when transferring data between a host device and a memory system according to RPMB write operation and RPMB read operation examples is shown in FIG. Figure 5 1 is a flow chart illustrating a method for processing data on an interface between a host device and a memory system using two keys according to one or more aspects of the present disclosure. The method 500 includes: at block 502, determining a seed key, such as by generating the seed key from a randomization function by the host device or receiving the seed key from the host device by the memory device. The authentication key can be used to authenticate access to data stored in a protected portion (e.g., an RPMB portion) of a memory module of the memory system.

[0051] An authentication key may be derived from the seed key at block 503. In one example derivation, the authentication key may be used as a seed in a key derivation function (KDF), which may be based on a cryptographic hash function such as SHA-2, SHA-3, HMAC-SHA256, or HMAC-SHA3-512.

[0052] At block 504, the seed key may be used to derive an encryption key for use in processing data on the first interface when communicating data in the protected portion on the first interface. In one example derivation, the encryption key may be derived from the seed key based on a key derivation function (KDF), which may be based on a cryptographic hash function such as SHA-2, SHA-3, HMAC-SHA256, or HMAC-SHA3-512. Both the host device and the memory system may execute the KDF using the seed key to derive authentication and encryption keys.

[0053] In some aspects, the handshake process can be used to synchronize or otherwise align the derivation processes in the host device's memory controller and the memory system's memory controller. For example, a seed value can be established on both memory controllers to synchronize the derivation process, wherein the seed key of block 502 is sent from the host device's memory controller to the memory system's memory controller. As another example, the handshake can be used to configure both memory controllers with the same confidentiality algorithm. The encryption keys derived by the host device's and memory system's memory controllers can be programmed on the host device ICE and the memory system's cryptographic block, respectively.

[0054] At box 506, the data on the first interface is processed based on the encryption key. The encryption key can be used to encrypt / decrypt data retrieved from the protected area of ​​the memory system, or to otherwise protect the confidentiality of data from the protected area. For example, when data is written from a host device to the memory system (e.g., in an RPMB write operation) and / or when data is read from the memory system by a host device (e.g., in an RPMB read operation), the data stored in the playback protected memory block (RPMB) of the memory system can be encrypted. In some aspects, a command for a protected read or protected write in a protected area can include a mark indicating whether the data being sent (in a write operation) or requested (in a read operation) should be encrypted. Such a mark can reduce the power consumed when encrypting and decrypting data that does not need to be protected. In some aspects, whether the data is encrypted during transmission through the interface can be specified by the configuration of the protected area. That is, whether the data written to or retrieved from the protected area is encrypted through the interface can be determined based on the protected area being accessed. When a protected zone is assigned to a specific application or virtual machine, the protected zone can be configured for encrypted data-in-motion or unencrypted data-in-motion.

[0055] The operations of method 500 may be performed by a UE (such as a reference Figure 6 For example, the example operations (also referred to as "blocks") of method 500 may enable UE 115 to support greater confidentiality of user data. Figure 6 6 is a block diagram illustrating details of an example wireless communication system according to one or more aspects. The wireless communication system may include a wireless network 600. The wireless network 600 may, for example, include a 5G wireless network. As will be appreciated by those skilled in the art, Figure 6 Components appearing in are likely to have related corresponding components in other network arrangements, including, for example, cellular-style network arrangements as well as non-cellular-style network arrangements (e.g., device-to-device or peer-to-peer or ad hoc network arrangements, etc.).

[0056] Figure 6The illustrated wireless network 600 includes multiple base stations 605 and other network entities. A base station can be a station that communicates with a UE and can also be referred to as an evolved Node B (eNB), a next-generation eNB (gNB), an access point, etc. Each base station 605 can provide communication coverage for a specific geographic area. In 3GPP, the term "cell" can refer to a specific geographic coverage area of ​​a base station or a base station subsystem serving that coverage area, depending on the context in which the term is used. In specific implementations of the wireless network 600 herein, the base stations 605 can be associated with the same operator or different operators (e.g., the wireless network 600 can include multiple operator wireless networks). Additionally, in specific implementations of the wireless network 600 herein, the base stations 605 can provide wireless communications using one or more of the same frequencies as neighboring cells (e.g., one or more frequency bands in a licensed spectrum, an unlicensed spectrum, or a combination thereof). In some examples, an individual base station 605 or UE 615 can be operated by more than one network operating entity. In some other examples, each base station 605 and UE 615 can be operated by a single network operating entity.

[0057] A base station may provide communication coverage for a macro cell or a small cell (such as a pico cell or femto cell) or other type of cell. A macro cell generally covers a relatively large geographic area (e.g., several kilometers in radius) and may allow unrestricted access by UEs that have a service subscription with a network provider. A small cell (such as a pico cell) will generally cover a relatively small geographic area and may allow unrestricted access by UEs that have a service subscription with a network provider. A small cell (such as a femto cell) will generally also cover a relatively small geographic area (e.g., a home) and, in addition to unrestricted access, may also provide restricted access by UEs associated with the femto cell (e.g., UEs in a closed subscriber group (CSG), UEs of users in a home, etc.). A base station for a macro cell may be referred to as a macro base station. A base station for a small cell may be referred to as a small cell base station, a pico base station, a femto base station, or a home base station. In Figure 6 In the example shown, base stations 605d and 605e are conventional macro base stations, while base stations 605a-605c are macro base stations implemented using one of 3D, full-dimensional (FD), or massive MIMO. Base stations 605a-605c utilize their higher-dimensional MIMO capabilities to employ 3D beamforming in elevation and azimuth beamforming to increase coverage and capacity. Base station 605f is a small cell base station, which can be a home node or a portable access point. The base station can support one or more (e.g., two, three, four, etc.) cells.

[0058] Wireless network 600 can support synchronous or asynchronous operation. For synchronous operation, base stations can have similar frame timing, and transmissions from different base stations can be roughly aligned in time. For asynchronous operation, base stations can have different frame timing, and transmissions from different base stations may not be aligned in time. In some scenarios, the network can be enabled or configured to handle dynamic switching between synchronous or asynchronous operation.

[0059] UEs 615 are dispersed throughout the wireless network 600, and each UE may be stationary or mobile. It should be understood that although mobile devices are generally referred to as UEs in the standards and specifications promulgated by 3GPP, such devices may additionally or otherwise be referred to by those skilled in the art as mobile stations (MSs), subscriber stations, mobile units, subscriber units, wireless units, remote units, mobile devices, wireless devices, wireless communication devices, remote devices, mobile subscriber stations, access terminals (ATs), mobile terminals, wireless terminals, remote terminals, handsets, terminals, user agents, mobile clients, clients, gaming devices, augmented reality devices, vehicle components, vehicle devices, or vehicle modules, or some other suitable terminology. In this document, a "mobile" device or UE does not necessarily have the ability to move and may be stationary. Some non-limiting examples of mobile devices such as may include specific implementations of one or more UEs in UE 615 include mobile phones, cellular (cell) phones, smart phones, Session Initiation Protocol (SIP) phones, wireless local loop (WLL) stations, laptop computers, personal computers (PCs), laptop computers, netbooks, smartbooks, tablet computers, and personal digital assistants (PDAs). The mobile device may additionally be an IoT or "Internet of Everything" (IoE) device, such as a car or other transportation vehicle, a satellite radio, a Global Positioning System (GPS) device, a Global Navigation Satellite System (GNSS) device, a logistics controller, a drone, a multi-rotor helicopter, a quadcopter, smart energy or security equipment, solar panels or solar arrays, city lighting, water supply or other infrastructure; industrial automation and enterprise equipment; consumer and wearable devices, such as eyeglasses, wearable cameras, smart watches, health or fitness trackers, mammalian implantable devices, gesture tracking devices, medical devices, digital audio players (e.g., MP3 players), cameras, game consoles, etc.; and digital home or smart home devices, such as home audio, video and multimedia devices, appliances, sensors, vending machines, smart lighting, home security systems, smart meters, etc. In one aspect, the UE may be a device that includes a Universal Integrated Circuit Card (UICC). In another aspect, the UE may be a device that does not include a UICC. In some aspects, a UE that does not include a UICC may also be referred to as an IoE device. The UEs 615a-615d of the specific implementation illustrated in FIGA are examples of mobile smartphone-type devices accessing the wireless network 600. A UE may also be a machine specifically configured to implement connected communications, including machine type communications (MTC), enhanced MTC (eMTC), narrowband IoT (NB-IoT), and the like. Figure 6 The illustrated UEs 615e-615k are examples of various machines configured for communication that access the wireless network 600.

[0060] A mobile device (such as UE 615) may be able to communicate with any type of base station (whether macro, pico, femto, relay, etc.). In Figure A, a communication link (represented as a lightning ball) indicates wireless transmissions between the UE and a serving base station (which is a base station designated to serve the UE on the downlink or uplink), or desired transmissions between base stations, as well as backhaul transmissions between base stations. The UE may operate as a base station or other network node in some scenarios. Backhaul communications between base stations of wireless network 600 may be performed using wired or wireless communication links.

[0061] In operation, at wireless network 600, base stations 605a-605c use 3D beamforming and coordinated spatial technologies (such as coordinated multipoint (CoMP) or multi-connectivity) to serve UE 615a and UE 615b. Macro base station 605d performs backhaul communications with base stations 605a-605c and small cells (base station 605f). Macro base station 605d also transmits multicast services that are subscribed to and received by UE 615c and UE 615d. Such multicast services may include mobile TV or streaming video, or may include other services for providing community information, such as weather emergencies or alerts, such as Amber Alerts or Gray Alerts.

[0062] The wireless network 600 of the specific implementation supports mission-critical communications with ultra-reliable and redundant links for mission-critical devices such as UE 615e, which is a drone. The redundant communication links with UE 615e include links from macro base station 605d and macro base station 605e, as well as small cell base station 605f. Other machine-type devices, such as UE 615f (thermometer), UE 615g (smart meter), and UE 615h (wearable device), can communicate directly with base stations such as small cell base station 605f and macro base station 605e via the wireless network 600, or in a multi-hop configuration by communicating with another user device that relays its information to the network, such as UE 615f communicating temperature measurement information to smart meter UE 615g, which then reports it to the network via small cell base station 605f. The wireless network 600 may also provide additional network efficiency through dynamic, low-latency TDD communications or low-latency FDD communications, such as in a vehicle-to-vehicle (V2V) mesh network between UEs 615i-615k communicating with a macro base station 605e.

[0063] In various specific implementations, the techniques and apparatus may be used in wireless communication networks, such as code division multiple access (CDMA) networks, time division multiple access (TDMA) networks, frequency division multiple access (FDMA) networks, orthogonal FDMA (OFDMA) networks, single carrier FDMA (SC-FDMA) networks, LTE networks, GSM networks, fifth generation (5G) or new radio (NR) networks (sometimes referred to as "5G NR" networks, systems, or devices), and other communication networks. As described herein, the terms "network" and "system" can be used interchangeably. A CDMA network, for example, may implement radio technologies such as Universal Terrestrial Radio Access (UTRA), cdma2000, and the like. UTRA includes Wideband CDMA (W-CDMA) and Low Chip Rate (LCR). CDMA2000 covers IS-2000, IS-95, and IS-856 standards. For example, a TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). The 3rd Generation Partnership Project (3GPP) defines the standard for the GSM EDGE (Enhanced Data rates for GSM Evolution) radio access network (RAN), also known as GERAN. OFDMA networks can implement radio technologies such as Evolved UTRA (E-UTRA), Institute of Electrical and Electronics Engineers (IEEE) 802.11, IEEE 802.16, IEEE 802.20, flash-OFDM, and others. UTRA, E-UTRA, and GSM are part of the Universal Mobile Telecommunications System (UMTS). In particular, Long Term Evolution (LTE) is a version of UMTS that uses E-UTRA. Different network types can use different radio access technologies (RATs) and RANs.

[0064] Although various aspects and specific implementations are described in this application by way of illustration of some examples, it will be understood by those skilled in the art that additional specific implementations and use cases may be generated in many different arrangements and scenarios. The innovations described herein can be implemented across many different platform types, devices, systems, shapes, sizes, and packaging arrangements. For example, specific implementations or uses may be implemented via integrated chip implementations or other devices based on non-module components (e.g., end-user devices, vehicles, communication equipment, computing equipment, industrial equipment, retail equipment or purchasing equipment, medical equipment, AI-enabled devices, etc.). Although some examples may or may not specifically point to use cases or applications, the applicability of various types of the described innovations may occur. The scope of specific implementations may range from chip-level or modular components to non-modular, non-chip-level specific implementations, and further to aggregated, distributed, or original equipment manufacturer (OEM) devices or systems comprising one or more of the various aspects described. In some actual settings, the devices in combination with the various aspects and features described may also necessarily include additional components and features for implementing and practicing the various aspects claimed and described. It is intended that the innovations described herein may be implemented in a wide variety of embodiments of different sizes, shapes, and configurations, including both large and small devices, chip-level components, multi-component systems (e.g., radio frequency (RF) chains, communication interfaces, processors), distributed arrangements, end-user devices, etc.

[0065] In one or more aspects, techniques for supporting data storage and / or data transmission may include additional aspects, such as any single aspect or any combination of aspects described below or in combination with one or more other processes or devices described elsewhere herein. In a first aspect, an electronic device (such as a UE) may include an apparatus as a host device, the apparatus including a memory controller coupled to an interface to a memory system, wherein the memory system may be integrated with the host device or externally coupled to the host device. The memory system may include a memory controller coupled to a memory module via a first channel and configured to access data stored in the memory module via the first channel; and coupled to a host device via a first interface and configured to communicate with the host device via the first interface. The memory controller of the memory system may be configured to perform operations including: receiving a seed key from the host device; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protection memory block (RPMB) portion of the memory module; controlling access to the RPMB portion of the memory module based on the authentication key; deriving an encryption key based on the seed key; and processing data on the first interface based on the encryption key. The operation can be performed as part of an initialization operation, a read operation, or a write operation.

[0066] In a first aspect, the memory controller is further configured to perform operations comprising: authenticating access to the data stored in the RPMB portion of the memory module based on the authentication key; retrieving a portion of the data after authenticating access to the data; encrypting at least a portion of the data based on the encryption key to form encrypted data; and sending the encrypted data through the first interface.

[0067] In a second aspect, in combination with the first aspect, the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

[0068] In a third aspect, in combination with one or more of the first aspect or the second aspect, sending the encrypted data through the first interface prevents the encrypted data from being snooped by unauthorized users.

[0069] In a fourth aspect, in combination with one or more of the first to third aspects, deriving the authentication key includes performing a key derivation function (KDF) based on the seed key.

[0070] In a fifth aspect, in combination with one or more of the first to fourth aspects, the KDF is based on a cryptographic hash function.

[0071] In a sixth aspect, in combination with one or more of the first to fifth aspects, the memory controller is further configured to perform operations, the operations including: receiving encrypted data from the host device through the first interface; decrypting the encrypted data based on the encryption key to obtain decrypted data; authenticating access to the RPMB portion of the memory module based on the authentication key; and storing the decrypted data to the RPMB portion of the memory module after authenticating the access.

[0072] In a seventh aspect, in combination with one or more of the first to sixth aspects, the memory controller includes a cryptographic engine configured to encrypt data retrieved from the portion of the memory module and to decrypt data for writing to the portion of the memory module.

[0073] In an eighth aspect, in combination with one or more of the first to seventh aspects, the memory controller is configured to communicate with a memory module, the memory module comprising a universal flash storage (UFS) device.

[0074] In a ninth aspect, in combination with one or more of the first to eighth aspects, a method includes: at a memory controller of a memory system, receiving a seed key from a host device via a first interface between the memory controller and the host device; deriving an authentication key based on the seed key at the memory controller, the authentication key being used to authenticate access to data stored in a replay protection memory block (RPMB) portion of a memory module, the memory module being coupled to the memory controller via a first channel; deriving an encryption key by the memory controller based on the seed key; and processing data on the first interface by the memory controller based on the encryption key.

[0075] In a tenth aspect, in combination with one or more of the first to ninth aspects, the method includes: authenticating access to the data stored in the RPMB portion of the memory module based on the authentication key; retrieving a portion of the data after authenticating access to the data; encrypting at least a portion of the data based on the encryption key to form encrypted data; and sending the encrypted data through the first interface.

[0076] In an eleventh aspect, in combination with one or more of the first to tenth aspects, the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

[0077] In a twelfth aspect, in combination with one or more of the first to eleventh aspects, sending the encrypted data through the first interface prevents the encrypted data from being snooped by unauthorized users.

[0078] In a thirteenth aspect, in combination with one or more of the first to twelfth aspects, deriving the authentication key includes performing a key derivation function (KDF) based on the seed key.

[0079] In a fourteenth aspect, in combination with one or more of the first to thirteenth aspects, the KDF is based on a cryptographic hash function.

[0080] In the fifteenth aspect, in combination with one or more of the first to fourteenth aspects, the method includes: receiving encrypted data from the host device through the first interface; decrypting the encrypted data based on the encryption key to obtain decrypted data; authenticating access to the RPMB part of the memory module based on the authentication key; and storing the decrypted data to the RPMB part of the memory module after authenticating the access.

[0081] In a sixteenth aspect, in combination with one or more of the first to fifteenth aspects, processing data on the first interface based on the encryption key includes: encrypting or decrypting the data according to a confidentiality algorithm.

[0082] In a seventeenth aspect, in combination with one or more of the first to sixteenth aspects, processing data on the first interface includes: storing or retrieving the data through the first channel using a universal flash storage (UFS) device.

[0083] In an eighteenth aspect, in combination with one or more of the first to seventeenth aspects, an apparatus includes: a memory controller of a host device, the memory controller being configured to couple the host device to a memory system via a first interface, the memory controller being configured to perform operations, the operations including: determining a seed key; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protection memory block (RPMB) portion of the memory system; encrypting at least a portion of the data based on the encryption key to form encrypted data; and sending the encrypted data via the first interface.

[0084] In the nineteenth aspect, in combination with one or more of the first to eighteenth aspects, the operation also includes: before processing the data on the first interface, sending a read request for the data to the memory system through the first interface; retrieving encrypted data from the first interface, wherein processing the data on the first interface includes: decrypting the encrypted data based on the encryption key.

[0085] In a twentieth aspect, in combination with one or more of the first to nineteenth aspects, the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

[0086] In the twenty-first aspect, in combination with one or more of the first to twentieth aspects, the operation includes: encrypting data for a write request to the RPMB portion based on the encryption key; and sending the data for the write request to the RPMB portion to the memory system through the first interface.

[0087] In a twenty-second aspect, in combination with one or more of the first to twenty-first aspects, sending the data through the first interface after encrypting the data prevents the encrypted data from being snooped by unauthorized users.

[0088] In a twenty-third aspect, in combination with one or more of the first to twenty-second aspects, the operation includes deriving the authentication key, including performing a key derivation function (KDF) based on the seed key.

[0089] In a twenty-fourth aspect, in combination with one or more of the first to twenty-third aspects, the KDF is based on a cryptographic hash function.

[0090] In a twenty-fifth aspect, in combination with one or more of the first to twenty-fourth aspects, processing data on the first interface includes: storing or retrieving the data through the first channel using a universal flash storage (UFS) device.

[0091] In a twenty-sixth aspect, the memory controller includes an inline cryptographic engine (ICE) coupled to the first interface and configured to encrypt or decrypt data according to a confidentiality algorithm using the encryption key.

[0092] In aspect twenty-seven, in combination with one or more of aspects one to twenty-six, a method includes: determining a seed key at a memory controller of a host device; deriving, by the memory controller of the host device, an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protected memory block (RPMB) portion of a memory system; deriving, by the memory controller of the host device, an encryption key based on the authentication key; and processing, by the memory controller of the host device, data on a first interface coupling the memory controller of the host device to a memory system, wherein the processing of the data is based on the encryption key.

[0093] In aspect 28, in combination with one or more of aspects 1 to 27, the method or operation further includes: before processing the data on the first interface based on the encryption key, sending a read request for the data to the memory system through the first interface; retrieving the encrypted data from the first interface, wherein processing the data on the first interface includes: decrypting the encrypted data based on the encryption key.

[0094] In a twenty-ninth aspect, in combination with one or more of the first to twenty-eighth aspects, the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

[0095] In a thirtieth aspect, in combination with one or more of the first to twenty-ninth aspects, deriving the authentication key includes performing a key derivation function (KDF) based on the seed key.

[0096] It will be understood by those skilled in the art that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be mentioned throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof.

[0097] This article is relative to Figures 1 to 6The components, functional blocks, and modules described herein include processors, electronic devices, hardware devices, electronic components, logical circuits, memories, software codes, firmware codes, and the like, or any combination thereof. Software should be broadly interpreted to mean instructions, instruction sets, codes, code segments, program codes, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, processes, and / or functions, and the like, whether referred to as software, firmware, middleware, microcode, hardware description languages, or other terms. In addition, the features discussed herein may be implemented via dedicated processor circuits, via executable instructions, or a combination thereof.

[0098] It should be understood by those skilled in the art that: Figure 4 A. Figure 4 B. Figure 5 A or Figure 5 One or more blocks (or operations) described in FIG. B may be combined with one or more blocks (or operations) described in another figure in the reference figure. For example, Figure 1 One or more boxes (or operations) of Figure 3 One or more boxes (or operations) of . Figure 1 One or more boxes can be associated with Figure 4 A. Figure 4 B. Figure 5 A or Figure 5 B is associated with one or more boxes (or operations). Additionally or alternatively, the above reference Figures 1 to 2 One or more of the operations described may be combined with Figures 4 and 5 A combination of one or more of the operations described.

[0099] It will also be appreciated by those skilled in the art that the various illustrative logic blocks, modules, circuits, and algorithmic steps described in conjunction with the disclosure herein can be implemented as electronic hardware, computer software, or a combination thereof. In order to clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. Those skilled in the art can implement the described functionality in different ways for each specific application, but such specific implementation decisions should not be interpreted as resulting in departure from the scope of this disclosure. It will also be readily appreciated that the order or combination of components, methods, or interactions described herein are merely examples, and that the components, methods, or interactions of various aspects of this disclosure can be combined or performed in ways other than those illustrated and described herein.

[0100] The various illustrative logical components, logic blocks, modules, circuits, and algorithmic processes described in conjunction with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. The interchangeability of hardware and software has been generally described in terms of functionality and illustrated in the various illustrative components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware or software depends on the specific application and the design constraints imposed on the overall system.

[0101] The hardware and data processing apparatus for implementing the various illustrative logic components, logic blocks, modules, and circuits described in conjunction with the various aspects disclosed herein may be implemented or executed using a general-purpose single-chip or multi-chip processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, or any conventional processor, controller, microcontroller, or state machine. In some implementations, a processor may be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration. In some implementations, a particular process and method may be performed by circuits specific to a given function.

[0102] In one or more aspects, the functions described may be implemented in hardware, digital electronic circuitry, computer software, firmware, including the structures disclosed in this specification and their structural equivalents, or any combination thereof. Implementations of the subject matter described in this specification may also be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on computer storage media for execution by, or for controlling the operation of, data processing apparatus.

[0103] If implemented in software, the function may be stored as one or more instructions or codes on a computer-readable medium or sent via a computer-readable medium. The process of the method or algorithm disclosed herein may be implemented in a processor-executable software module that may reside on a computer-readable medium. Computer-readable media include both computer storage media and communication media, and the communication media include any media that can be implemented to transfer a computer program from one place to another. The storage medium can be any available medium that a computer can access. As an example and not limitation, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), CD-ROM or other optical disk storage devices, magnetic disk storage devices or other magnetic storage devices, or any other medium that can be used to store the required program code in the form of an instruction or data structure and can be accessed by a computer. In addition, any connection may be appropriately referred to as a computer-readable medium. Disks and optical disks as used herein include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks and blue-ray discs, wherein disks typically reproduce data magnetically, while optical discs reproduce data optically with lasers. The above combination should also be included within the scope of computer-readable media. Additionally, the operations of a method or algorithm may reside as a code and instruction set, or any combination of code and instruction sets, on a machine-readable medium or computer-readable medium, which may be incorporated into a computer program product.

[0104] Various modifications to the specific implementations described in this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other specific implementations without departing from the spirit or scope of this disclosure. Therefore, the claims are not intended to be limited to the specific implementations shown herein but are to be accorded the widest scope consistent with this disclosure, the principles and novel features disclosed herein.

[0105] Additionally, those skilled in the art will readily recognize that, for convenience in describing the drawings, opposing terms such as "upper" and "lower" or "front" and "back" or "top" and "bottom" are sometimes used and indicate relative positions corresponding to the orientation of the drawing on a correctly oriented page, and may not reflect the correct orientation of any device as implemented.

[0106] Certain features described in this specification in the context of separate implementations may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented in multiple implementations, either individually or in any suitable subcombination. Furthermore, while features may be described above as functioning in certain combinations and even initially claimed as such, one or more features from a claimed combination may in some cases be omitted from that combination, and a claimed combination may be directed to subcombinations or variations of subcombinations.

[0107] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring such operations to be performed in the particular order shown or in a sequential order, or to perform all illustrated operations to achieve the desired result. In addition, the accompanying drawings may schematically depict one or more example processes in the form of flow charts. However, other operations not depicted may be combined with the schematically illustrated example processes. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the illustrated operations. In certain environments, multitasking and parallel processing are advantageous. In addition, the separation of various system components in the specific implementations described above should not be understood as requiring such separation in all specific implementations, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products. Additionally, some other specific implementations also fall within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in different orders and still achieve the desired result.

[0108] As used herein, including in the claims, the term "or" used in a list of two or more items means that any one of the listed items may be employed alone, or any combination of two or more of the listed items may be employed. For example, if a composition is described as containing component A, B, or C, the composition may contain A alone; B alone; C alone; A and B combined; A and C combined; B and C combined; or A, B, and C combined. Furthermore, as used herein, including in the claims, "or" as used in a list of items preceded by "at least one of" indicates a separate list, such that, for example, a list of "at least one of A, B, or C" means A or B or C or AB or AC or BC or ABC (i.e., A and B and C) or any combination of any of these. The term "substantially" is defined as being largely, but not necessarily entirely, what is specified (and includes what is specified; e.g., substantially 90 degrees includes 90 degrees, and substantially parallel includes parallel), as understood by one of ordinary skill in the art. In any disclosed embodiment, the term "substantially" may be replaced with "within [percentage] of" that specified, where percentages include 0.1%, 1%, 5%, or 10%.

[0109] The previous description of the disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the spirit or scope of the disclosure. Therefore, the disclosure is not intended to be limited to the examples and designs described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A device, comprising: Memory Controller: coupled to a memory module via a first channel and configured to access data stored in the memory module via the first channel; as well as coupled to a host device via a first interface and configured to communicate with the host device via the first interface, The memory controller is configured to perform operations comprising: receiving a seed key from the host device; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protected memory block (RPMB) portion of the memory module; controlling access to the RPMB portion of the memory module based on the authentication key; deriving an encryption key based on the seed key; and Data on the first interface is processed based on the encryption key.

2. The apparatus of claim 1 , wherein the memory controller is further configured to perform operations comprising: authenticating access to the data stored in the RPMB portion of the memory module based on the authentication key; retrieving a portion of the data after authenticating access to the data; encrypting at least a portion of the data based on the encryption key to form encrypted data; as well as The encrypted data is sent through the first interface.

3. The apparatus of claim 2, wherein the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

4. The apparatus of claim 2, wherein sending the encrypted data through the first interface prevents the encrypted data from being viewed by an unauthorized user.

5. The apparatus of claim 1 , wherein deriving the encryption key comprises: A key derivation function (KDF) is performed based on the seed key. The apparatus of claim 5 , wherein the KDF is based on a cryptographic hash function.

7. The apparatus of claim 1 , wherein the memory controller is further configured to perform operations comprising: receiving encrypted data from the host device via the first interface; decrypting the encrypted data based on the encryption key to obtain decrypted data; authenticating access to the RPMB portion of the memory module based on the authentication key; as well as The decrypted data is stored to the RPMB portion of the memory module after authenticated access.

8. The apparatus of claim 1 , wherein the memory controller comprises a cryptographic engine configured to encrypt data retrieved from the RPMB portion of the memory module and to decrypt data for writing to the RPMB portion of the memory module.

9. The apparatus of claim 8, wherein the apparatus comprises a Universal Flash Storage (UFS) device.

10. A method comprising: At a memory controller of a memory system, receiving a seed key from a host device via a first interface between the memory controller and a host device; deriving, at the memory controller, an authentication key based on the seed key, the authentication key for authenticating access to data stored in a replay protected memory block (RPMB) portion of a memory module, the memory module being coupled to the memory controller via a first channel; deriving, by the memory controller, an encryption key based on the seed key; and processing, by the memory controller, data on the first interface based on the encryption key.

11. The method according to claim 10, further comprising: authenticating access to the data stored in the RPMB portion of the memory module based on the authentication key; retrieving a portion of the data after authenticating access to the data; encrypting at least a portion of the data based on the encryption key to form encrypted data; as well as The encrypted data is sent through the first interface.

12. The method of claim 11, wherein the RPMB portion of the memory module is configured with a monotonic write counter for replay protection.

13. The method of claim 11, wherein sending the encrypted data through the first interface prevents the encrypted data from being viewed by an unauthorized user.

14. The method of claim 10, wherein deriving the encryption key comprises: A key derivation function (KDF) is performed based on the seed key.

15. The method of claim 14, wherein the KDF is based on a cryptographic hash function.

16. The method according to claim 10, further comprising: receiving encrypted data from the host device via the first interface; decrypting the encrypted data based on the encryption key to obtain decrypted data; authenticating access to the RPMB portion of the memory module based on the authentication key; and The decrypted data is stored to the RPMB portion of the memory module after authenticated access.

17. The method of claim 10, wherein processing data on the first interface based on the encryption key comprises: Data is encrypted or decrypted according to a confidentiality algorithm.

18. The method of claim 17, wherein the memory system comprises a Universal Flash Storage (UFS) device.

19. A device comprising: A memory controller of a host device, the memory controller configured to couple the host device to a memory system via a first interface, the memory controller configured to perform operations, the operations comprising: Determine the seed key; sending the seed key to the memory system via the first interface; deriving an authentication key based on the seed key, the authentication key being used to authenticate access to data stored in a replay protected memory block (RPMB) portion of the memory system; deriving an encryption key based on the seed key; accessing the RPMB portion of the memory system based on the authentication key; and Data on the first interface is processed based on the encryption key.

20. The apparatus of claim 19, wherein the memory controller is configured to perform operations comprising: Before processing the data on the first interface, sending a read request for the data to the memory system through the first interface; as well as retrieving encrypted data from said first interface, Processing the data on the first interface includes: decrypting the encrypted data based on the encryption key.

21. The apparatus of claim 20, wherein the RPMB portion of the memory system is configured with a monotonic write counter for replay protection.

22. The apparatus of claim 19, wherein the memory controller is configured to perform operations comprising: Encrypting data for a write request to the RPMB portion based on the encryption key; as well as The data for the write request to the RPMB portion is sent to the memory system through the first interface.

23. The apparatus of claim 22, wherein sending the data through the first interface after encrypting the data prevents the encrypted data from being snooped by an unauthorized user.

24. The apparatus of claim 19, wherein deriving the encryption key comprises: A key derivation function (KDF) is performed based on the seed key.

25. The apparatus of claim 24, wherein the KDF is based on a cryptographic hash function.

26. The apparatus of claim 19, wherein the memory controller comprises an inline cryptographic engine (ICE) coupled to the first interface and configured to encrypt or decrypt data according to a confidentiality algorithm using the encryption key.

27. A method comprising: determining a seed key at a memory controller of the host device; deriving, by the memory controller of the host device based on the seed key, an authentication key for authenticating access to data stored in a replay protected memory block (RPMB) portion of a memory system; deriving, by the memory controller of the host device, an encryption key based on the authentication key; sending, by the memory controller of the host device, the seed key to the memory system via a first interface coupling the memory controller of the host device to the memory system; and Data on the first interface is processed by the memory controller of the host device, wherein the processing of the data is based on the encryption key.

28. The method according to claim 27, further comprising: before processing the data on the first interface based on the encryption key, sending a read request for the data to the memory system through the first interface; as well as retrieving encrypted data from said first interface, Processing the data on the first interface includes: decrypting the encrypted data based on the encryption key.

29. The method of claim 27, wherein the RPMB portion of the memory system is configured with a monotonic write counter for replay protection.

30. The method of claim 27, wherein deriving the encryption key comprises: A key derivation function (KDF) is performed based on the seed key.