Memory device and operating method thereof
By generating multiple comparison authentication codes in the storage device and comparing them at specific times, the problem of storage devices failing to operate normally under fault injection is solved, thereby improving the security of storage devices and the reliability of authentication verification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2025-06-24
- Publication Date
- 2026-04-28
AI Technical Summary
Storage devices are unable to perform normal storage operations when faced with fault injection, leading to security issues and making it easy to bypass existing authentication and verification processes.
By generating multiple comparison authentication codes at different points in time, using a hash key to generate first and second comparison authentication codes at different times, and comparing these authentication codes with a standard authentication code, the security of data storage can be identified.
It improves the security of storage devices, prevents storage operation anomalies caused by fault injection, and enhances the reliability of authentication and verification.
Smart Images

Figure CN121934760A_ABST
Abstract
Description
Cross-references to related applications
[0001] This application claims the benefit of Korean Patent Application No. 10-2024-0147961, filed with the Korean Intellectual Property Office on October 25, 2024, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0002] The example embodiment relates to a storage device for managing data and a method for operating the storage device. Background Technology
[0003] Storage devices provide storage services to users through the process of storing and exporting data in at least one storage block. Storage devices can manage data independently or by communicating with external devices (e.g., host devices). External devices can provide various services to users by communicating with storage devices. For example, an external device can transfer data to be stored to the storage device or request data to be processed from the storage device.
[0004] Storage devices can perform authentication and verification processes on data received from external devices. For example, a storage device can perform authentication and verification on data based on an authentication code (e.g., a Message Authentication Code (MAC)), and when the authentication and verification result meets specified criteria, the storage device can store the data in its storage blocks. However, during the authentication and verification process, the storage device may be unable to perform normal storage operations due to fault injection (e.g., electromagnetic fault injection) performed to bypass authentication and verification.
[0005] Therefore, by establishing a highly secure authentication and verification process, problems in storage operations can be prevented due to accidental attacks. Summary of the Invention
[0006] The present invention provides a storage device and a method for operating the storage device. With the storage device and the method, when data and a standard authentication code are identified, multiple comparison authentication codes corresponding to the data at different time points are generated, and the standard authentication code and the multiple comparison authentication codes are used to identify whether to store the data in the storage block.
[0007] The technical tasks to be achieved in this example embodiment are not limited to those described above, and other technical tasks can be inferred from the following example embodiments.
[0008] According to an example embodiment, a storage device may include a storage block and a processor. The processor is configured to identify data, identify a standard authentication code corresponding to the data, generate a first comparison authentication code corresponding to the data using a hash key, generate a second comparison authentication code corresponding to the data using the hash key at a different time than the first comparison authentication code, and determine whether to store the data in the storage block based on at least one of the first and second comparison authentication codes and the standard authentication code.
[0009] According to an example embodiment, a method for managing data performed by a storage device may include: identifying data, identifying a standard authentication code corresponding to the data, generating a first comparison authentication code corresponding to the data using a hash key, generating a second comparison authentication code corresponding to the data at a time different from the first comparison authentication code using the hash key, and identifying whether to store the data in a storage block of the storage device based on at least one of the first comparison authentication code and the second comparison authentication code and the standard authentication code.
[0010] According to an example embodiment, the storage device may include a counter, a first processing device and a second processing device, a first comparison device and a second comparison device, a storage block, and a processor. The processor is configured to: identify data; identify a standard authentication code corresponding to the data; determine a first time point from the time point of identifying the data or the standard authentication code where a time corresponding to a first delay value has elapsed; determine a second time point from the time point of identifying the data or the standard authentication code where a time corresponding to a second delay value has elapsed; generate a first comparison authentication code corresponding to the data at the first time point based on the first delay value using the first processing device; generate a second comparison authentication code corresponding to the data at the second time point based on the second delay value using the second processing device; identify a first comparison result between the first comparison authentication code and the standard authentication code at a third time point after the first time point using the first comparison device; identify a second comparison result between the second comparison authentication code and the standard authentication code at a fourth time point after the second time point using the second comparison device; and determine whether to store the data in the storage block based on the first comparison result and the second comparison result. The first comparison authentication code and the second comparison authentication code are generated based on at least one of the data, a hash key, and a count value of the number of times the data has been stored as identified by the counter. Attached Figure Description
[0011] These and / or other aspects, features, and advantages of the present invention will become apparent and more readily understood from the following description of exemplary embodiments taken in conjunction with the accompanying drawings, in which:
[0012] Figure 1 This is a diagram illustrating a system including a storage device and a host device according to an example embodiment;
[0013] Figure 2This is a diagram illustrating a system including a storage device and a host device according to an example embodiment;
[0014] Figure 3 This is an operation flowchart illustrating the operation method of a storage device according to an example embodiment;
[0015] Figure 4 This is an operation flowchart illustrating the operation method of a storage device according to an example embodiment;
[0016] Figure 5A This is a diagram illustrating the operation of a storage device according to an example embodiment;
[0017] Figure 5B This is a diagram illustrating the operation of a storage device according to an example embodiment;
[0018] Figure 5C This is a diagram illustrating the operation of a storage device according to an example embodiment;
[0019] Figure 6 This is an operation flowchart illustrating the operation method of a storage device according to an example embodiment; and
[0020] Figure 7 This is an operation flowchart used to illustrate the operation methods of the storage device and the host device according to the example embodiment. Detailed Implementation
[0021] The terminology used in the example embodiments has been selected, to the extent possible, from currently widely used and common terms while taking into account the functionality of this disclosure. However, terms may vary depending on the intent or precedent of those skilled in the art, the emergence of new technologies, etc. Furthermore, in some cases, terms may be arbitrarily chosen by the applicant, and in such cases, their meaning will be described in detail in the corresponding description. Therefore, the terms used in this disclosure should be defined based on their meaning and the content of this disclosure, rather than on their simple names.
[0022] Throughout this specification, unless otherwise stated, when a component is described as "containing or including" an element, it does not exclude another component, but may further include another component. Furthermore, terms such as "...unit," "...group," and "...module" described in this specification refer to a unit that performs at least one function or operation, which may be implemented as hardware, software, or a combination thereof.
[0023] In the following, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings, enabling those skilled in the art to readily implement the present disclosure. However, the present disclosure may be implemented in many different forms and is not limited to the exemplary embodiments described herein.
[0024] Figure 1 This is a diagram illustrating a system including a storage device and a host device according to an example embodiment.
[0025] refer to Figure 1 The system (or data management system) 10 according to an example embodiment of this disclosure may include a storage device 100 (or storage unit) and a host device 200. The storage device 100 and the host device 200 may exchange various types of data through a communication channel. The storage device 100 and the host device 200 may be contained in a single device and are physically separate.
[0026] In an example embodiment, storage device 100 may include storage block 130 and processor 140. Storage device 100 may include embedded multimedia card (eMMC) or universal flash memory (UFS).
[0027] Storage block 130 can store instructions or data. For example, storage block 130 can store data managed by storage device 100. For example, storage block 130 can store at least some of the data received from host device 200.
[0028] Storage block 130 can store various information related to the operation of storage device 100. For example, storage block 130 can store information about the operation history, operation parameters, performance, etc. of storage device 100. For example, storage block 130 can contain replay protection memory blocks (RPMBs).
[0029] Storage block 130 may be coupled to processor 140, and processor 140 may read information from or write information to the storage medium included in storage block 130. For example, storage block 130 and processor 140 may be implemented as separate components or integrated into a single module.
[0030] Processor 140 (or storage controller) may be operatively connected to storage block 130. For example, processor 140 may store (or write) data to storage block 130, or decode (or read) data stored in storage block 130.
[0031] Processor 140 can identify data and a corresponding standard authentication code. Host device 200 can generate a standard authentication code corresponding to the data. Processor 140 can generate at least one comparison authentication code corresponding to the data, and determine whether to store the data in storage block 130 based on at least one comparison authentication code and the standard authentication code.
[0032] In an example embodiment, host device 200 may store data in storage device 100 or process data stored in storage device 100. Host device 200 may control the operation of at least some components included in storage device 100. Host device 200 may include a processor (e.g., an application processor, etc.) contained together with storage device 100 in a single electronic device.
[0033] Figure 1 The components included in the storage device 100 shown in the figure are exemplary, and therefore the example embodiment is not limited thereto. For example, the storage device 100 may also include Figure 1 Components not shown (e.g., counter, at least one processing device, at least one comparison device, etc.).
[0034] Figure 2 This is a diagram illustrating a system including a storage device and a host device according to an example embodiment.
[0035] refer to Figure 2 The system (or data management system) 10 may include a host 200. Storage device 100 can recognize various information transmitted through communication with host device 200. Storage device 100 can be based on... Figure 2 The components shown (e.g., processor 140, first processing device 211, second processing device 212, first comparison device 221 and second comparison device 222) are used to identify whether data should be stored in the storage block. Figure 2 The partitioning of the components of the storage device 100 shown may correspond to a logical partitioning, and is described as an operation performed by at least some of the components that may be performed by a single device (e.g., processor 140).
[0036] In the example embodiment, storage device 100 can identify data.
[0037] Storage device 100 can recognize data received from host device 200. Host device 200 can transfer data to storage device 100 for storage in storage block 130 contained in storage device 100.
[0038] In an example embodiment, storage device 100 can recognize a standard authentication code corresponding to the data.
[0039] For example, storage device 100 can recognize a standard authentication code corresponding to data received from host device 200.
[0040] In an example embodiment, storage device 100 can identify or generate a first comparison authentication code and a second comparison authentication code corresponding to the data.
[0041] For example, storage device 100 can use first processing device 211 to generate a first comparison authentication code and use second processing device 212 to generate a second comparison authentication code.
[0042] Storage device 100 can identify or generate a first comparison authentication code at a first time point based on a first latency value, and identify or generate a second comparison authentication code at a second time point based on a second latency value. For example, storage device 100 can identify or generate the first comparison authentication code at a first time point after a time corresponding to the first latency value has elapsed since the time point when the standard authentication code was identified or generated. The first time point can be the time point when storage device 100 starts using first processing device 211 to identify or generate the first comparison authentication code. For example, storage device 100 can identify or generate the second comparison authentication code at a second time point after a time corresponding to the second latency value has elapsed since the time point when the standard authentication code was identified or generated. The second time point can be the time point when storage device 100 starts using second processing device 212 to identify or generate the second comparison authentication code. For example, the first latency value can be different from the second latency value. For example, the difference between the time corresponding to the first latency value and the time corresponding to the second latency value can be less than or equal to a specified difference (e.g., 100 ns).
[0043] Storage device 100 can identify or determine a range of latency values based on its operational performance, and identify or determine a first latency value and a second latency value within the identified or determined range. For example, based on the clock frequency (clock rate) or clock speed of storage device 100, storage device 100 can identify or determine a range of latency values, which is set such that the difference between the time corresponding to the first latency value and the time corresponding to the second latency value is less than or equal to a specified difference.
[0044] Storage device 100 can identify or generate a first comparison authentication code and a second comparison authentication code based on at least one of data, a hash key, and a count value related to the number of times data is stored. For example, the hash key corresponds to an algorithm key that is input along with the data as a hash function to verify the data, and this hash key can be the same as the hash key used by host device 200 to generate a standard authentication code. For example, the count value can be the number of times host device 200 stores data in storage block 130. Storage device 100 can update the count value using a counter. For example, the first comparison authentication code and the second comparison authentication code can include the storage address of the data and identification information. Storage device 100 can store data in storage block 130 based on the storage address of the data. Storage device 100 can identify the data packet corresponding to the data based on the identification information.
[0045] In an example embodiment, storage device 100 may identify whether to store data in storage block 130 based on at least one of a first comparison authentication code and a second comparison authentication code, as well as a standard authentication code.
[0046] Storage device 100 can identify whether to store data in storage block 130 based on a first delay value corresponding to a first comparison authentication code and a second delay value corresponding to a second comparison authentication code.
[0047] Storage device 100 can identify the first comparison result between the first authentication code and the standard authentication code at a third time point after the first time point, and identify the second comparison result between the second authentication code and the standard authentication code at a fourth time point after the second time point. For example, the difference between the first and third time points may be the first time period consumed by the first processing device 211 in identifying or generating the first authentication code. For example, the difference between the second and fourth time points may be the second time period consumed by the second processing device 212 in identifying or generating the second authentication code. For example, the first and second time periods may be substantially the same. For example, the third time point may be different from the fourth time point.
[0048] Figure 3 This is an operation flowchart used to illustrate the operation method of a storage device according to an example embodiment.
[0049] According to the example embodiment, storage device 100 can perform reference... Figure 3 Public operation. For example, components included in storage device 100 (e.g., Figure 1 At least some of the storage blocks 130, processors 140, etc. can be configured to execute Figure 3 The operation.
[0050] In the following example embodiments, operations S310, S320, S330, S340, and S350 can be executed sequentially, but not necessarily in that order. For example, the order of each operation can be changed, and at least two operations can be executed in parallel. Furthermore, for... Figure 3 Any content that corresponds to or overlaps with the above may be briefly described or omitted.
[0051] According to the example embodiment, in operation S310, the storage device 100 can identify data.
[0052] For example, storage device 100 can recognize data received from host device 200.
[0053] According to an example embodiment, in operation S320, storage device 100 can identify a standard authentication code corresponding to the data.
[0054] For example, storage device 100 can receive a standard authentication code generated from data used by host device 200.
[0055] For example, a standard authentication code may include a Message Authentication Code (MAC) corresponding to the data. For example, a standard authentication code may contain information generated by host device 200 based on at least one of the data, a hash key, and a count value for the number of times the data has been stored. For example, a standard authentication code may include the storage address and identification information of the data.
[0056] According to an example embodiment, in operation S330, storage device 100 can identify or generate a first comparison authentication code corresponding to the data.
[0057] According to an example embodiment, in operation S340, storage device 100 can identify or generate a second comparison authentication code corresponding to the data.
[0058] For example, storage device 100 can identify or generate a first comparison authentication code and a second comparison authentication code based on a hash key that is the same as the hash key stored in host device 200, and data. In other words, storage device 100 can use a hash key based on a symmetric key algorithm to identify or generate the first comparison authentication code and the second comparison authentication code.
[0059] For example, storage device 100 may begin recognizing or generating a first comparison authentication code and a second comparison authentication code at different points in time.
[0060] According to an example embodiment, in operation S350, storage device 100 can identify whether to store data in storage block 130 based on at least one of a first comparison authentication code and a second comparison authentication code, as well as a standard authentication code.
[0061] For example, storage device 100 can identify a first comparison result between a first authentication code and a standard authentication code, and a second comparison result between a second authentication code and a standard authentication code. Storage device 100 can determine whether to store data in storage block 130 based on whether the first and second comparison results meet a specified criterion. When the first authentication code and the standard authentication code contain the same information, storage device 100 can identify that the first comparison result meets the specified criterion. When at least some information contained in the first authentication code differs from the information contained in the standard authentication code, storage device 100 can identify that the first comparison result does not meet the specified criterion.
[0062] For example, when both the first comparison result and the second comparison result meet the specified criteria, storage device 100 can store the data in storage block 130. Storage device 100 can store the data at a specified address in storage block 130, which is identified based on the storage address included in the standard authentication code.
[0063] For example, if neither the first comparison result nor the second comparison result meets the specified criteria, storage device 100 may not store the data in storage block 130. Storage device 100 may send information about the first and second comparison results to host device 200. For example, storage device 100 may send information about the comparison result between each of the first and second authentication codes and the standard authentication code, as well as information about whether the data has been stored, to host device 200.
[0064] For example, when the first comparison result or the second comparison result meets a specified criterion, the storage device 100 can execute a response strategy for authentication errors. This response strategy can include user-defined operations.
[0065] In this case, in the example embodiment, storage device 100 can pause the operation of storage device 100 or initialize storage device 100.
[0066] In this example embodiment, storage device 100 may identify or generate at least one additional comparison authentication code based on at least one additional latency value different from the first latency value and the second latency value. Storage device 100 may further determine whether to store data in storage block 130 based on the comparison result between the at least one additional comparison authentication code and an additional standard authentication code. For example, storage device 100 may receive an additional standard authentication code generated from host device 200 using additional data. In this case, storage device 100 may identify any additional latency value different from the first latency value and the second latency value within a specified range based on the operational performance of storage device 100.
[0067] although Figure 3 Not shown, but when identifying additional data, storage device 100 can identify whether to store the additional data in storage block 130 based on the additional standard authentication code and the new comparison authentication code.
[0068] For example, when identifying additional data and an additional standard authentication code, storage device 100 can identify or generate a third comparison authentication code and a fourth comparison authentication code corresponding to the additional data. Storage device 100 can identify or determine a third delay value and a fourth delay value arbitrarily determined within a range corresponding to each of the third and fourth comparison authentication codes. For example, storage device 100 can generate a third comparison authentication code at a fifth time point based on the third delay value and a fourth comparison authentication code at a sixth time point based on the fourth delay value. For example, storage device 100 can generate a third comparison authentication code at a fifth time point after a time corresponding to the third delay value has elapsed since the time point when the additional data or additional standard authentication code was identified. For example, storage device 100 can generate a fourth comparison authentication code at a sixth time point after a time corresponding to the fourth delay value has elapsed since the time point when the additional data or additional standard authentication code was identified. Storage device 100 can determine whether to store the additional data in storage block 130 based on at least one of the third and fourth comparison authentication codes and the additional standard authentication code. At least one of the third and fourth delay values can be different from the first and second delay values. Storage device 100 can identify whether to store additional data in storage block 130 based on whether the third comparison result between the third comparison authentication code and the additional standard authentication code and the fourth comparison result between the fourth comparison authentication code and the additional standard authentication code meet the design criteria.
[0069] Figure 4 This is an operation flowchart used to illustrate the operation method of a storage device according to an example embodiment.
[0070] According to the example embodiment, storage device 100 can perform reference... Figure 4 Public operation. For example, components included in storage device 100 (e.g., Figure 1 At least some of the storage blocks 130, processors 140, etc. can be configured to execute Figure 4 The operation.
[0071] In the following example embodiments, operations S410, S420, S430, S440, and S450 can be executed sequentially, but not necessarily in that order. For example, the order of each operation can be changed, and at least two operations can be executed in parallel. Furthermore, for... Figure 4 Any content that corresponds to or overlaps with the above may be briefly described or omitted.
[0072] According to an example embodiment, in operation S410, the storage device 100 can identify or generate a first comparison authentication code at a first time point based on a first delay value.
[0073] According to an example embodiment, in operation S420, storage device 100 can identify or generate a second comparison authentication code at a second time point based on a second delay value.
[0074] Based on the operational performance of the storage device 100 (e.g., clock frequency or clock speed), the storage device 100 can identify or determine a range of latency values, which is configured such that the difference between a first time period corresponding to a first latency value and a second time period corresponding to a second latency value is less than or equal to a specified time (e.g., 100 ns). The storage device 100 can identify or determine any first latency value and any second latency value within the identified range.
[0075] For example, storage device 100 can identify or generate a first comparison authentication code at a first time point using first processing device 211. This first time point is the time period corresponding to a first delay value that has elapsed since the time point of identifying the data or the time point of identifying the standard authentication code.
[0076] For example, storage device 100 can identify or generate a second comparison authentication code at a second time point by using second processing device 212. This second time point is the time period corresponding to a second delay value that has elapsed since the time point of identifying the data or the time point of identifying the standard authentication code.
[0077] According to an example embodiment, in operation S430, the storage device 100 can identify the first comparison result between the first comparison authentication code and the standard authentication code at a third time point after the first time point.
[0078] According to an example embodiment, in operation S440, the storage device 100 can identify the second comparison result between the second comparison authentication code and the standard authentication code at a fourth time point after the second time point.
[0079] For example, storage device 100 can use first processing device 211 to identify the first comparison result between the first comparison authentication code and the standard authentication code at a third time point. The difference between the first time point and the third time point can be the time consumed by the first processing device 211 in identifying the first comparison authentication code.
[0080] For example, storage device 100 can use second processing device 212 to identify a second comparison result between the second comparison authentication code and the standard authentication code at a fourth time point. The difference between the second time point and the fourth time point can be the time consumed by the second processing device 212 in identifying the second comparison authentication code.
[0081] According to an example embodiment, in operation S450, storage device 100 can identify whether to store data in a storage block based on a first comparison result and a second comparison result.
[0082] For example, storage device 100 can identify whether the first comparison result and the second comparison result meet a specified standard.
[0083] For example, when the first comparison authentication code and the standard authentication code contain the same information, the storage device 100 can determine that the first comparison result meets the specified standard. For example, when at least some of the information contained in the first comparison authentication code is different from the information contained in the standard authentication code, the storage device 100 can determine that the first comparison result does not meet the specified standard.
[0084] For example, when the second comparison authentication code and the standard authentication code contain the same information, the storage device 100 can determine that the second comparison result meets the specified standard. For example, when at least some of the information contained in the second comparison authentication code is different from the information contained in the standard authentication code, the storage device 100 can determine that the second comparison result does not meet the specified standard.
[0085] For example, the process by which storage device 100 identifies whether to store data in storage block 130 can be described using the above... Figure 3 Replace the description of operation S350.
[0086] Figure 5A This is a diagram illustrating the operation of a storage device according to an example embodiment.
[0087] Figure 5B This is a diagram illustrating the operation of a storage device according to an example embodiment.
[0088] refer to Figure 5A and Figure 5B The storage device 100 includes multiple logically distinct components, and at least some of the operations performed by the illustrated components can be controlled by the device (e.g., Figure 1 The processor 140 in the middle executes.
[0089] According to an example embodiment, storage device 100 may include a counter 510, a hash key 520, and an RPMB 530 (or Figure 1 The storage device 100 includes storage block 130 and authentication device 550. The storage device 100 can recognize data 591 and MAC 592 (or standard authentication code) received from the host device 200.
[0090] For example, counter 510 can identify the count value for the number of times data is stored. When data 591 received from host device 200 is stored in RPMB 530, counter 510 can increment the count value.
[0091] For example, hash key 520 can be stored in host device 200, and hash key 520 can be the same as the algorithm key used by host device 200 to generate standard authentication codes. For example, storage device 100 can use hash key 520 based on a symmetric key algorithm to identify or generate a first comparison authentication code and a second comparison authentication code.
[0092] For example, the RPMB 530 may contain at least one partition for storing data. The RPMB 530 may include secure storage for managing data based on authentication verification and replay protection access.
[0093] For example, the authentication verification device 550 may include at least one processing device 560 and at least one comparison device 580.
[0094] At least one processing device 560 may include a first processing device 561 and a second processing device 562. The first processing device 561 may include a first delay counter 563, and the second processing device 562 may include a second delay counter 564.
[0095] Storage device 100 can generate at least one comparison authentication code 570 based on at least one of data 591, a count value of the number of times data is stored identified by counter 510, and hash key 520. For example, at least one comparison authentication code 570 may include a first comparison authentication code 571 (e.g., MAC') and a second comparison authentication code 572 (e.g., MAC''). For example, storage device 100 may use first processing device 561 and second processing device 562 to identify or generate the first comparison authentication code 571 and the second comparison authentication code 572, respectively.
[0096] At least one comparison device 580 may include: a first comparison device 581 that identifies a first comparison result between a first comparison authentication code 571 and a MAC 592; and a second comparison device 582 that identifies a second comparison result between a second comparison authentication code 572 and a MAC 592.
[0097] Storage device 100 can identify data 591 and the corresponding MAC address 592. Data 591 and MAC address 592 can be received from host device 200. MAC address 592 can be a standard authentication code generated by host device 200 based on data 591.
[0098] Storage device 100 can identify or generate a first comparison authentication code 571 at a first time point corresponding to a first delay value identified by a first delay counter 563, and identify or generate a second comparison authentication code 572 at a second time point corresponding to a second delay value identified by a second delay counter 564.
[0099] Storage device 100 may use a first comparison device 581 to identify a first comparison result between a first comparison authentication code 571 and a MAC 592, and a second comparison device 582 to identify a second comparison result between a second comparison authentication code 572 and a MAC 592.
[0100] Storage device 100 may include result verification component 590, which is configured to identify whether a first comparison result and a second comparison result meet a specified standard, generate information based on the identified result, and send the information to host device 200.
[0101] For example, when the first comparison result and the second comparison result meet the specified criteria, the storage device 100 can send the signal "match 1" and the signal "match 2" to the result verification unit 590, respectively.
[0102] For example, when the first comparison result and the second comparison result do not meet the specified criteria, the storage device 100 can send the signal "Mismatch 1" and the signal "Mismatch 2" to the result verification component 590, respectively.
[0103] Below, for reference Figure 5C The operation of storage device 100 based on the results identified by result verification component 590 is described in detail.
[0104] Figure 5C This is a diagram illustrating the operation of a storage device according to an example embodiment.
[0105] Referring to reference numeral 501, according to an exemplary embodiment, when both the first comparison result and the second comparison result meet a specified criterion, the storage device 100 can use the result verification component 590 to identify the first information indicating a pass status. When both signals "match 1" and "match 2" in the result verification component 590 are enabled, the storage device 100 can determine that both the first comparison result and the second comparison result meet the specified criterion. The storage device 100 can send the first information to the host device 200, and based on the control command corresponding to the first information obtained from the host device 200, the storage device 100 can store data 591 in the storage block 130.
[0106] Referring to reference numeral 502, according to an exemplary embodiment, when neither the first comparison result nor the second comparison result meets a specified criterion, the storage device 100 can use the result verification component 590 to identify second information indicating a failure state (e.g., FAIL_IRQ). The storage device 100 can send the second information to the host device 200, and based on a control command corresponding to the second information obtained from the host device 200, the storage device 100 may choose not to store the data 591 in the storage block 130.
[0107] Referring to reference numeral 503, according to an exemplary embodiment, when the status is neither pass nor fail, storage device 100 can use result verification unit 590 to identify third information indicating an error status (e.g., ERROR_IRQ). For example, storage device 100 can identify the third information when only one of the first comparison result and the second comparison result meets a specified criterion. Storage device 100 can send the third information to host device 200, and based on the control command corresponding to the third information obtained from host device 200, storage device 100 can execute a response strategy for authentication errors.
[0108] For example, storage device 100 can suspend operation or initialize storage device 100 based on a control command corresponding to third information.
[0109] In this scenario, storage device 100 can use data 591 (i.e., additional data), a count value, and hash key 520 to identify or generate at least one additional comparison authentication code, and storage device 100 can identify or determine at least one additional delay value corresponding to the at least one additional comparison authentication code. Storage device 100 can then determine again whether to store data 591 in storage block 130 based on at least one additional comparison authentication code, at least one additional delay value, and MAC 592. The operation of identifying whether to store additional data using the additional comparison authentication code can include the same algorithm as the operation of identifying whether to store data using the first comparison authentication code and the second comparison authentication code.
[0110] In the above example embodiment, it is described that the storage device 100 stores data 591 in the storage block 130 or executes a response strategy based on control commands obtained from the host device 200, but the present invention is not limited thereto. For example, the storage device 100 may perform the above operations itself based on the results identified by the result verification unit 590.
[0111] Figure 6 This is an operation flowchart used to illustrate the operation method of a storage device according to an example embodiment.
[0112] According to the example embodiment, storage device 100 can perform... Figure 6 The operation disclosed herein. For example, components included in storage device 100 (e.g., Figure 1 At least some of the storage blocks 130, processors 140, etc. can be configured to execute Figure 6 The operation.
[0113] In the following example embodiments, operations S610, S620, S630, S640, S645, and S650 can be executed sequentially, but these operations are not necessarily executed sequentially. For example, the order of each operation can be changed, and at least two operations can be executed in parallel. Furthermore, for... Figure 6 Any content that corresponds to or overlaps with the above may be briefly described or omitted.
[0114] According to an example embodiment, in operation S610, the storage device 100 can determine whether the first comparison result and the second comparison result meet a specified standard.
[0115] For example, storage device 100 can identify a first comparison result between a first comparison authentication code and a standard authentication code, and a second comparison result between a second comparison authentication code and a standard authentication code.
[0116] For example, storage device 100 can determine whether a specified standard is met based on the correspondence between the information contained in the authentication code and the information contained in the standard authentication code. When the matching rate between the information contained in the authentication code and the information contained in the standard authentication code exceeds a specified value, storage device 100 can determine that the comparison result meets the specified standard.
[0117] According to an example embodiment, in operation S620, the storage device 100 can identify whether the first comparison result and the second comparison result meet a specified standard.
[0118] For example, when both the first comparison result and the second comparison result meet the specified criteria (e.g., operation S620 - Yes), the storage device 100 can execute operation S630.
[0119] For example, when at least one of the first comparison result and the second comparison result does not meet the specified criteria (e.g., operation S620 - No), the storage device 100 may perform operation S640.
[0120] According to an example embodiment, in operation S630, storage device 100 can store data in storage block 130.
[0121] For example, storage device 100 can send first information, in which both the first comparison result and the second comparison result meet a specified criterion, to host device 200. Storage device 100 can then store the data in storage block 130 based on a control command obtained from host device 200 corresponding to the first information.
[0122] According to an example embodiment, in operation S640, storage device 100 can identify whether the first comparison result or the second comparison result meets a specified standard.
[0123] For example, when the first comparison result or the second comparison result meets the specified criteria (e.g., operation S640 - Yes), the storage device 100 can execute operation S650.
[0124] For example, when neither the first comparison result nor the second comparison result meets the specified criteria (e.g., operation S640 - No), the storage device 100 may perform operation S645.
[0125] According to an example embodiment, in operation S650, storage device 100 can execute a response strategy corresponding to authentication errors.
[0126] For example, storage device 100 can identify the authentication verification result of the data according to the above. Figure 5C The attached diagram shows the status of 503, and in response to the authentication error, a predefined operation is performed.
[0127] For example, storage device 100 may send third information to host device 200, in which only one of the first comparison result and the second comparison result meets a specified criterion. Storage device 100 may, based on a control command obtained from host device 200 corresponding to the third information, execute at least some operations of a response strategy corresponding to the control command.
[0128] For example, the response strategy corresponding to authentication errors can be described using the above... Figure 5C Replace the description of the attached figure 503.
[0129] According to the example embodiment, in operation S645, storage device 100 can send the determination result to host device 200 without storing the data in storage block 130.
[0130] For example, storage device 100 may not store data in storage block 130 and may send a second message to host device 200 stating that neither the first comparison result nor the second comparison result meets the specified criteria.
[0131] Figure 7 This is an operation flowchart used to illustrate the operation methods of the storage device and the host device according to the example embodiment.
[0132] According to the example embodiment, storage device 100 and host device 200 can perform... Figure 7 The operation disclosed herein. For example, components included in storage device 100 (e.g., Figure 1 At least some of the storage blocks 130 and processors 140 can be configured to execute Figure 7 The operation.
[0133] In the following example embodiments, operations S710, S720, S730, S740, S750, and S760 can be executed sequentially, but these operations are not necessarily executed sequentially. For example, the order of each operation can be changed, and at least two operations can be executed in parallel. Furthermore, for... Figure 7 Any content that corresponds to or overlaps with the above may be briefly described or omitted.
[0134] According to the example embodiment, in operation S710, the host device 200 can send data and a standard authentication code to the storage device 100.
[0135] For example, host device 200 can send data to storage device 100 for storage in storage device 100.
[0136] For example, host device 200 may also send a standard authentication code corresponding to the data to storage device 100. Host device 200 may generate the standard authentication code based on at least one of the data, a hash key, and a count of the number of times the data is stored. For example, the standard authentication code may include the storage address and identification information within the storage block 130 where the host device 200 wishes to store the data.
[0137] According to an example embodiment, in operation S720, storage device 100 can generate at least one authentication code corresponding to the data.
[0138] For example, storage device 100 can use at least one processing device to generate at least one authentication code.
[0139] For example, storage device 100 can input at least one of the following: data received from host device 200, a hash key, and a count value for the number of times data is stored, to at least one processing device. Storage device 100 can recognize or generate at least one authentication code output from at least one processing device.
[0140] For example, storage device 100 may identify or generate at least one authentication code at different points in time. For example, storage device 100 may identify or generate a first comparison authentication code using a first processing device at a first point in time based on a first latency value, and identify or generate a second comparison authentication code using a second processing device at a second point in time based on a second latency value.
[0141] According to an example embodiment, in operation S730, the storage device 100 may compare at least one authentication code with a standard authentication code.
[0142] For example, storage device 100 can identify a first comparison result between a first comparison authentication code and a standard authentication code, and a second comparison result between a second comparison authentication code and a standard authentication code.
[0143] For example, storage device 100 can identify at least one comparison result at different time points. Storage device 100 can identify a first comparison result at a third time point after a first time point, and a second comparison result at a fourth time point after a second time point. The difference between the first and third time points and the difference between the second and fourth time points can be substantially equal.
[0144] According to an example embodiment, in operation S740, storage device 100 may send comparison results to host device 200.
[0145] For example, storage device 100 can send a comparison result between an authentication code that includes a first comparison result and a second comparison result to host device 200.
[0146] For example, the comparison results can refer to the above. Figure 5C One of the first to third pieces of information described.
[0147] According to the example embodiment, in operation S750, the host device 200 can generate a control command corresponding to the comparison result.
[0148] For example, when both the first comparison result and the second comparison result meet the specified criteria, the host device 200 can generate a control command to control the storage device 100 to store the data in the storage block 130.
[0149] For example, when neither the first comparison result nor the second comparison result meets the specified criteria, the host device 200 can generate a control command to control the storage device 100 not to store the data in the storage block 130.
[0150] For example, when the first comparison result or the second comparison result does not meet the specified criteria, the host device 200 can generate a control command to cause the storage device 100 to execute a response strategy in response to the authentication error.
[0151] According to an example embodiment, in operation S760, the host device 200 may send control commands to the storage device 100.
[0152] For example, storage device 100 can perform operations corresponding to control commands obtained from host device 200.
[0153] For example, storage device 100 can perform an operation corresponding to a control command and then send information to host device 200 about the completion of the operation.
[0154] The electronic device according to the above example embodiments may include a processor, a memory for storing and executing program data, a permanent storage device (e.g., a disk drive), and / or a user interface device (e.g., a communication port for communicating with external devices, a touchscreen, buttons, and / or keypads). Methods implemented as software modules or algorithms may be stored as computer-readable code or program instructions executable on a processor in a computer-readable recording medium. Here, computer-readable recording media include magnetic storage media (e.g., ROM, RAM, floppy disks, and hard disks) and optically readable media (e.g., CD-ROMs and DVDs). The computer-readable recording medium may be distributed across a network-connected computer system, allowing the computer-readable code to be stored and executed in a distributed manner. The medium can be read by a computer, stored in memory, and executed on a processor.
[0155] The example embodiments can be represented by functional block elements and various processing steps. Functional blocks can be implemented as any number of hardware and / or software configurations performing a specific function. For example, the example embodiments can employ integrated circuit configurations, such as memory, processing, logic, and / or lookup tables, which can perform various functions under the control of one or more microprocessors or other control devices. Similar to elements, which can be implemented as software programming or software elements, the example embodiments can also be implemented using programming or scripting languages (e.g., C, C++, Java, assembly, etc.), including various algorithms implemented as combinations of data structures, processes, routines, or other programming constructs. Functional aspects can be implemented as algorithms running on one or more processors. Furthermore, the example embodiments can employ existing techniques for electronic environment setup, signal processing, and / or data processing. Terms such as “mechanism,” “element,” “device,” and “configuration” can be used broadly and are not limited to mechanical and physical elements. Terms can include the meaning of a series of software routines associated with processors, etc.
[0156] While the inventive concept has been specifically shown and described with reference to embodiments thereof, it should be understood that various changes in form and detail may be made therein without departing from the spirit and scope of the invention as set forth in the appended claims.
Claims
1. A storage device, comprising: Storage blocks; as well as The processor is configured as follows: Identify data received from external hosts. Identify a standard authentication code corresponding to the data, the standard authentication code being received from the external host. A first comparison authentication code corresponding to the data is generated using the hash key. At a time different from the first comparison authentication code, the hash key is used to generate a second comparison authentication code corresponding to the data, and Based on at least one of the first comparison authentication code and the second comparison authentication code, as well as the standard authentication code, it is determined whether the data is stored in the storage block.
2. The storage device according to claim 1, wherein, The processor is configured to: Determine a first time point from the time point when the data or the standard authentication code has been identified, after which a time corresponding to a first delay value has elapsed, and A second time point is determined, which is the time elapsed since the time point from which the data or the standard authentication code was identified, corresponding to the second delay value.
3. The storage device according to claim 2, wherein, The processor is configured to: Based on the operational performance of the storage device, the ranges of the first latency value and the second latency value are determined, and The first delay value and the second delay value are determined within the range.
4. The storage device according to claim 2, wherein, The processor is configured to: Generate the first comparison authentication code at the first time point based on the first delay value, and The second comparison authentication code is generated at the second time point based on the second delay value.
5. The storage device according to claim 4, wherein, The processor is configured to: At a third time point after the first time point, identify the first comparison result between the first comparison authentication code and the standard authentication code, and At a fourth time point after the second time point, the second comparison result between the second authentication code and the standard authentication code is identified, and The third time point is different from the fourth time point.
6. The storage device according to claim 2, wherein, The processor is configured to: Identify additional data received from the external host. An additional standard authentication code corresponding to the additional data is identified, and the additional standard authentication code is received from the external host. The hash key is used to generate a third comparison authentication code corresponding to the additional data. A third time point is determined, from the time point when the additional data or the additional standard authentication code was identified, after a time corresponding to the third delay value. The hash key is used to generate a fourth comparison authentication code corresponding to the additional data. Determine the fourth time point from the time point when the additional data or the additional standard authentication code was identified, which corresponds to the fourth delay value. Based on at least one of the third and fourth comparison authentication codes and the additional standard authentication code, it is determined whether to store the additional data in the storage block. Wherein, at least one of the third delay value and the fourth delay value is different from the first delay value and the second delay value.
7. The storage device according to claim 1, wherein, The processor is configured to: identify each of the first comparison authentication code and the second comparison authentication code, which includes the storage address and identification information of the data, based on at least one of the data, the hash key, and a count of the number of times the data is stored.
8. The storage device according to claim 1, wherein, The processor is configured to store the data in the storage block when a first comparison result between the first comparison authentication code and the standard authentication code and a second comparison result between the second comparison authentication code and the standard authentication code meet a specified standard.
9. The storage device according to claim 1, wherein, The processor is configured to: not store the data in the storage block when the first comparison result between the first comparison authentication code and the standard authentication code and the second comparison result between the second comparison authentication code and the standard authentication code do not meet the specified standard.
10. The storage device according to claim 1, wherein, The processor is configured to execute a response strategy for authentication errors when a first comparison result between the first comparison authentication code and the standard authentication code or a second comparison result between the second comparison authentication code and the standard authentication code meets a specified standard.
11. The storage device according to claim 10, wherein, The processor is configured to suspend the operation of the storage device or initialize the storage device by executing the response policy.
12. The storage device according to claim 10, wherein, The processor is configured to: Identify additional data received from the external host. An additional standard authentication code corresponding to the additional data is identified, and the additional standard authentication code is received from the external host. Based on the identification that the first comparison result or the second comparison result meets the specified criteria, at least one additional comparison authentication code corresponding to the additional data is generated. Determine a third time point from the time point when the additional data or the additional standard authentication code was identified, after a time corresponding to at least one additional delay value. Based on the at least one additional comparison authentication code and the additional standard authentication code, it is determined whether the additional data is stored in the storage block.
13. A method for managing data performed by a storage device, the method comprising: Identify data received from external hosts; A standard authentication code corresponding to the data is identified, and the standard authentication code is received from the external host. A first comparison authentication code corresponding to the data is generated using the hash key; At a time different from the first comparison authentication code, the hash key is used to generate a second comparison authentication code corresponding to the data; as well as Based on at least one of the first comparison authentication code and the second comparison authentication code, as well as the standard authentication code, it is determined whether the data is stored in the storage block of the storage device.
14. The method of claim 13, further comprising: A first time point is determined from the time point when the data or the standard authentication code was identified, after a time corresponding to a first delay value has elapsed; as well as A second time point is determined, which is the time elapsed since the time point from which the data or the standard authentication code was identified, corresponding to the second delay value.
15. The method of claim 14, further comprising: The range of the first latency value and the second latency value is determined based on the operational performance of the storage device; as well as The first delay value and the second delay value are determined within the range.
16. The method of claim 15, further comprising: When the first comparison result between the first authentication code and the standard authentication code or the second comparison result between the second authentication code and the standard authentication code meets the specified standard, a response strategy for authentication errors is executed.
17. The method of claim 14, further comprising: The first comparison authentication code is generated at the first time point corresponding to the first delay value; as well as The second comparison authentication code is generated at the second time point corresponding to the second delay value.
18. The method of claim 17, further comprising: The first comparison result between the first comparison authentication code and the standard authentication code is identified at a third time point after the first time point; as well as At a fourth time point after the second time point, identify the second comparison result between the second comparison authentication code and the standard authentication code. The third time point is different from the fourth time point.
19. The method of claim 13, further comprising: When the first comparison result between the first comparison authentication code and the standard authentication code and the second comparison result between the second comparison authentication code and the standard authentication code meet the specified standard, the data is stored in the storage block.
20. A storage device, comprising: counter; First processing equipment and second processing equipment; First comparison device and second comparison device; Storage blocks; as well as The processor is configured as follows: Identify data received from external hosts. Identify a standard authentication code corresponding to the data, the standard authentication code being received from the external host. A first time point is determined, from the time point when the data or the standard authentication code was identified, on which time corresponding to a first delay value has elapsed. A second time point is determined, on the eve of the time from when the data or the standard authentication code was identified, that corresponds to a second delay value. Using the first processing device, a first comparison authentication code corresponding to the data is generated at the first time point based on the first delay value. Using the second processing device, a second comparison authentication code corresponding to the data is generated at the second time point based on the second delay value. Using the first comparison device, a first comparison result between the first comparison authentication code and the standard authentication code is identified at a third time point after the first time point. Using the second comparison device, at a fourth time point after the second time point, identify the second comparison authentication code and the standard authentication code, and Based on the first comparison result and the second comparison result, it is determined whether the data should be stored in the storage block. The first comparison authentication code and the second comparison authentication code are generated based on at least one of the data, the hash key, and the count value of the number of times the data is stored as identified by the counter.
Citation Information
Patent Citations
Compound and organic light emitting device comprising the same
KR1020240147961A