Storage device, host device, and storage system including same
By generating and managing triples in the storage device and using the security managers of the host device and the storage device for mutual authentication, the problem of excessive consumption of computing device resources in multi-party computation is solved, and more efficient processing speed and performance optimization are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2025-08-15
- Publication Date
- 2026-05-08
AI Technical Summary
In multi-party computation, the direct generation and management of triples by computing devices leads to excessive resource consumption, which may result in performance degradation and resource limitation issues.
By generating and managing triples in the storage device, mutual authentication is performed between the host device and the storage device using a security manager. The storage device's device security manager generates triples and stores them in non-volatile memory. The host device's host security manager requests and receives triples or partial triples, reducing the host device's resource consumption.
It saves host equipment resources, improves processing speed, and optimizes storage system efficiency, thus avoiding performance degradation of computing devices.
Smart Images

Figure CN121997389A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to storage devices, host devices, and storage systems including the same. Background Technology
[0002] Multi-party computation (MPC) is a technology that allows multiple parties to perform joint computations without exposing their personal data. MPC can be widely used in various application areas that require collaborative computation while protecting sensitive data. These technologies can be used in fields such as finance, healthcare data processing, privacy-preserving computation, and training machine learning models using private data, and are particularly useful when data security and privacy are critical.
[0003] To perform multiplication in multi-party computation, pre-generated triples are required. Triples are a tool that helps participants in multi-party computation perform multiplication without exposing their data. If triples are exposed externally, there is a risk of exposing the private data of the multi-party participants. Therefore, the creation and management of triples should be performed through reliable configuration.
[0004] Typically, each multiplication operation consumes one triplet, so multi-party computations require a very large number of triples. This necessitates the pre-generating of a large number of triples to handle large-scale computational tasks. However, if the computing devices involved in multi-party computations directly create and manage triples, their resources may be over-consumed. This can lead to performance degradation and resource limitations on the computing devices.
[0005] The above information is intended to enhance understanding of the background of this disclosure and may include information that does not constitute prior art. Summary of the Invention
[0006] This disclosure relates to storage devices, host devices, and storage systems including the above-mentioned devices for solving the above-mentioned problems.
[0007] The problems to be solved by this disclosure are not limited to those described above, and other problems not mentioned will be clearly understood by those skilled in the art from the following description of this disclosure.
[0008] According to some aspects, the storage system includes a host device and a storage device configured to send and receive data with the host device. Here, the host device includes host memory and a host security manager configured to manage the security of the host device and send triple requests to the storage device. Here, the storage device includes non-volatile memory and a storage controller including a device security manager configured to manage the security of the storage device, generate triples and store the triples in the non-volatile memory, and, in response to receiving a triple request from the host security manager, send the triple or a partial triple generated based on the triple to the host security manager. In this document, a triple includes a pair of numbers containing three numbers used to perform a multiplication operation via multi-party computation (MPC) in the host device, and a partial triple contains a secret shared value of the triple, which is distributed to the participants in the multi-party computation.
[0009] According to some aspects, a storage device includes non-volatile memory and a device security manager configured to manage the security of the storage device and perform mutual authentication with a host security manager of a host device configured to send and receive data with the storage device. Here, the device security manager is configured to generate triples and store the generated triples in the non-volatile memory, and in response to receiving a triple request from the host security manager, send a triple or a partial triple generated based on the triple to the host security manager. Here, the triple includes a set of numbers containing three numbers used to perform multiplication operations through multi-party computation in the host device, and a partial triple includes a secret shared value of the triple, which is distributed to the participants in the multi-party computation.
[0010] According to some aspects, the host device includes host memory and a host security manager configured to manage the security of the host device and perform mutual authentication with a device security manager configured to send and receive data with the host device. Here, the host security manager is also configured to send a triplet request to the device security manager and receive a triplet or a partial triplet generated from the device security manager, wherein the triplet includes a set of numbers containing three numbers used to perform a multiplication operation through multi-party computation in the host device. Here, the partial triplet includes a secret shared value of the triplet, which is distributed to the participants in the multi-party computation.
[0011] According to various embodiments of this disclosure, when the storage device performs the generation and management of triples for multi-party computation by offloading, host device resources can be saved, processing speed can be improved, and performance can be optimized. Furthermore, the efficiency of the storage system can be increased by generating triples when the storage device is not performing data write / read operations.
[0012] The effects that can be obtained through this disclosure are not limited to those described above. Any technical effects not mentioned will be clearly understood by those skilled in the art from the description of this disclosure set forth below. Attached Figure Description
[0013] The above and other embodiments and features of this disclosure will become clearer from the detailed description of exemplary embodiments with reference to the accompanying drawings, in which:
[0014] Figure 1 This is an exemplary block diagram illustrating a storage system according to an embodiment of the present disclosure.
[0015] Figure 2 This is an exemplary block diagram illustrating a host device performing multi-party computation according to an embodiment of the present disclosure.
[0016] Figure 3 This is a block diagram illustrating an example of a storage system for performing multi-party computation according to an embodiment of the present disclosure.
[0017] Figure 4 This is a flowchart illustrating an example of a method for operating a storage device according to an embodiment of the present disclosure.
[0018] Figure 5 This is a flowchart illustrating an example of a method for operating a host device according to an embodiment of the present disclosure.
[0019] Figure 6 , Figure 7 , Figure 8 and Figure 9 This is a block diagram illustrating an example of the operation of a storage system according to an embodiment of the present disclosure.
[0020] Figure 10 and Figure 11 This is a diagram illustrating an example of a method of operating a storage system according to some embodiments of the present disclosure.
[0021] Figure 12 This is a diagram illustrating an example of an operation method of a storage system according to another embodiment of the present disclosure.
[0022] Figure 13 This is a diagram illustrating an example of a method of operating a storage system according to another embodiment of the present disclosure.
[0023] Figure 14 and Figure 15 This is a diagram illustrating an example of a method of operating a storage system according to other embodiments of the present disclosure.
[0024] Figure 16 This is an exemplary block diagram illustrating a storage system according to an embodiment of the present disclosure.
[0025] Figure 17 This is an exemplary block diagram illustrating a data center using a storage device according to an embodiment of the present disclosure. Detailed Implementation
[0026] In the following text, reference will be made to Figures 1 to 17 Various embodiments of this disclosure are described. Throughout the specification, the same reference numerals may refer to the same parts.
[0027] Figure 1 This is an exemplary block diagram illustrating a storage system according to an embodiment of the present disclosure. (Refer to...) Figure 1 The storage system 10 may include a host device 100 and a storage device 200 configured to send and receive data with the host device 100.
[0028] According to one embodiment, host device 100 may include host controller 110 and host memory 120. In one embodiment, host memory 120 may also act as a buffer for temporarily storing data to be sent to or from storage device 200, but the embodiment is not limited to this example.
[0029] According to one embodiment, the host controller 110 and the host memory 120 may be implemented as separate semiconductor chips. Alternatively, the host controller 110 and the host memory 120 may be integrated into the same semiconductor chip. For example, the host controller 110 may be one of multiple modules provided in an application processor, and the application processor may be implemented as a system-on-a-chip (SoC). Additionally, the host memory 120 may be embedded memory provided within the application processor and / or non-volatile memory or memory module located outside the application processor.
[0030] The host controller 110 can manage operations that store data (e.g., write data) from a buffer area of host memory 120 into non-volatile memory 220 or store data (e.g., read data) from non-volatile memory 220 into a buffer area.
[0031] According to one embodiment, the host device 100 may further include a host security manager 130. The host security manager 130 may include hardware and / or software modules for managing the security of the host device 100. Although the host security manager 130 is shown as a component separate from the host controller 110 and the host memory 120, the scope of this disclosure is not limited thereto, and the host security manager 130 may be included in the host controller 110 and / or the host memory 120.
[0032] According to one embodiment, storage device 200 may include storage controller 210 and non-volatile memory (NVM) 220. Storage device 200 may include storage media for storing data when requested by host device 100. For example, storage device 200 may include at least one of solid-state drive (SSD), embedded memory, and removable external memory, but the embodiment is not limited to this example.
[0033] If storage device 200 is an SSD, then storage device 200 can be a device conforming to the Fast Non-Volatile Memory (NVMe) standard. If storage device 200 is embedded memory or external memory, then storage device 200 can be a device conforming to the Universal Flash Memory (UFS) or Embedded Multimedia Card (eMMC) standard. Host device 100 and storage device 200 can each generate packets according to the standard protocol they employ and send the generated packets.
[0034] When the non-volatile memory 220 of storage device 200 includes flash memory, the flash memory may include a 2D NAND memory array and / or a 3D (or vertical) NAND (VNAND) memory array. Additionally or alternatively, storage device 200 may include various other types of non-volatile memory. For example, storage device 200 may include magnetic RAM (MRAM), spin-torque MRAM, conductive bridged RAM (CBRAM), ferroelectric RAM (FeRAM), phase RAM (PRAM), resistive RAM, and various other types of memory.
[0035] The storage controller 210 can write data to or read data stored in the non-volatile memory 220 according to requests from the host device. Furthermore, the storage controller 210 can manage the data stored in the non-volatile memory 220 to prevent data corruption.
[0036] According to one embodiment, the storage controller 210 may include a host interface 211, a memory interface 212, and a central processing unit (CPU) 213. Furthermore, the storage controller 210 may also include a flash translation layer (FTL) 214, a device security manager 215, a buffer memory 216, an error correction code (ECC) engine 217, and an encryption / decryption engine 218. The storage controller 210 may also include working memory (not shown) in which the flash translation layer (FTL) 214 is loaded, and data write and read operations for the non-volatile memory 220 may be controlled by the CPU 213 executing the flash translation layer (FTL) 214.
[0037] Host interface 211 can send and receive packets with host device 100. Packets sent from host device 100 to host interface 211 may include commands or data to be recorded in non-volatile memory 220, and packets sent from host interface 211 to host device 100 may include responses to commands or data read from non-volatile memory 220. Memory interface 212 can send data to be written to non-volatile memory 220 or receive data read from non-volatile memory 220. Such memory interface 212 can be implemented in accordance with standard protocols such as Switching-On or Open NAND Flash Interface (ONFI).
[0038] The flash translation layer 214 can perform various functions, such as address mapping, wear leveling, and garbage collection. Address mapping refers to the operation of changing a logical address received from host device 100 to a physical address used to actually store data in non-volatile memory 220. Wear leveling refers to the operation of preventing excessive degradation of specific blocks by allowing even use of blocks within non-volatile memory 220, and can be implemented, for example, through firmware techniques that balance the erase counts of physical blocks. Garbage collection refers to the operation of ensuring available capacity within non-volatile memory 220 by copying valid data from a block to a new block and then erasing the existing block.
[0039] ECC engine 217 can perform error detection and correction functions on read data read from non-volatile memory 220. More specifically, ECC engine 217 can generate parity bits for write data to be written to non-volatile memory 220, and the generated parity bits can be stored in non-volatile memory 220 along with the write data. When reading data from non-volatile memory 220, ECC engine 217 can use the parity bits read from non-volatile memory 220 along with the read data to correct errors in the read data, and can output the error-corrected read data.
[0040] Device security manager 215 may include hardware and / or software modules for managing the security of storage device 200. Device security manager 215 is shown as being included in storage controller 210, but the scope of this disclosure is not limited thereto, and device security manager 215 may be included in host controller 110 and / or host memory 120.
[0041] Buffer memory 216 can temporarily store data to be written to or read from non-volatile memory 220. Furthermore, although buffer memory 216 is illustrated as being included within memory controller 210, the scope of this disclosure is not limited thereto, and buffer memory 216 can be placed externally to memory controller 210. Buffer memory 216 can be, for example, dynamic random access memory (DRAM), but embodiments are not limited to this example.
[0042] The encryption / decryption engine 218 can perform encryption and / or decryption operations on data input to the storage controller 210. For example, the encryption / decryption engine 218 can use a symmetric key algorithm to perform encryption and / or decryption operations on data input to the storage controller 210.
[0043] Figure 2 This is an exemplary block diagram illustrating a host device 100 performing multi-party computation (MPC) according to one embodiment of the present disclosure. In one embodiment, multiple tenants 102, 104, and 106 may use host device 100 to perform multi-party computation. In some embodiments of the present disclosure, tenants 102, 104, and 106 may refer to the tenant itself (e.g., a user or a group of users) and / or virtual machines associated with the tenant. Here, a virtual machine may refer to an independent computing environment associated with each tenant 102, 104, or 106. For example, a virtual machine may refer to a host controller (e.g., a host controller that processes data associated with each tenant 102, 104, or 106) that handles such data. Figure 1 At least a portion of 110) and / or host memory storing data associated with each tenant 102, 104, or 106 (e.g., Figure 1 At least a portion of (120) (e.g., the host memory region associated with each tenant 102, 104 or 106), etc.
[0044] Multi-party computation refers to collaboration among multiple parties to perform computations without sharing the personal data owned by each party. The primary goal of multi-party computation can be to obtain the desired computational results while protecting personal data from exposure. For example, multi-party computation can be applied to tasks such as multiple tenants 102, 104, and 106 jointly training a machine learning model while protecting their personal information; multiple tenants 102, 104, and 106 analyzing data while protecting their personal information; and secret voting tasks.
[0045] In some embodiments, participants in a multi-party computation (e.g., tenants 102, 104, and 106) may require triples to safely perform multiplication operations. Triples are tools that allow participants in a multi-party computation to safely perform multiplication operations without exposing their data and can contain three numbers (e.g., three integers). For example, a triple can be represented by the following mathematical formula 1.
[0046]
Mathematical Formula 1
[0047]
[0048] In other words, a triplet can contain three numbers, one of which is the product of the other two numbers.
[0049] To allow participants in multi-party computation to perform multiplication, each participant may share one of the secret shared values of the triples. In this disclosure, the secret shared value of the triples distributed to the participants in multi-party computation may be referred to as a "partial triple". The sum of the partial triples distributed to each participant may be a triple. For example, a partial triple may be represented by the following mathematical formula 2.
[0050]
Mathematical Formula 2
[0051]
[0052] Here, n can represent the number of participants in a multi-party computation. If we again represent partial triples, then partial triples can be expressed as the following mathematical formula 3.
[0053]
Mathematical Expression 3
[0054]
[0055]
[0056] Here, n can represent the number of participants in a multi-party computation, and , ,and It can represent any value. That is, when using a triplet and 3(n-1) random values, n partial triplets can be generated. Each participant can use the partial triplets distributed to that participant to perform operations, and in this way, multiplication operations of multi-party computation can be performed.
[0057] To securely perform multi-party computations, triples and partial triples should not be exposed. Therefore, trusted devices within the system should generate and manage triples and partial triples, which need to be stored in a secure area. Furthermore, since each multiplication operation consumes one triple, a very large number of triples should be pre-generated and stored. However, there may be resource limitations for host device 100 to perform all the creation, storage, and management of triples.
[0058] Figure 3 This is a block diagram illustrating an example of a storage system for performing multi-party computation according to an embodiment of the present disclosure. In the following, descriptions related to the above references will be omitted or briefly described. Figure 1 and Figure 2 The description should not repeat any content, and the added / changed parts should be highlighted.
[0059] To securely perform multi-party computations, the confidential values (e.g., personal data, partial triples, intermediate computation results, etc.) of each tenant VM1, VM2, ..., or VMn should be protected from exposure, and an isolated environment should be provided so that the computations of each tenant VM1, VM2, ..., and VMn do not interfere with each other. For this purpose, confidential computing techniques can be applied to storage systems to provide a Trusted Execution Environment (TEE).
[0060] Reference Figure 3 The storage system may include a host device 100 and a storage device 200 configured to send and receive data with the host device 100.
[0061] According to one embodiment, host device 100 may include host controller 110, host memory 120, and host security manager 130. Host security manager 130 may include hardware and / or software modules for managing the security of host device 100. That is, host security manager 130 may be a trusted component of host device 100. Although host security manager 130 is depicted as a component separate from host controller 110 and host memory 120, the scope of this disclosure is not limited thereto, and host security manager 130 may be included within host controller 110 and / or host memory 120.
[0062] According to one embodiment, host memory 120 may include a secure region 128 accessible only to host security manager 130. In one embodiment, host security manager 130 may set up a secure region 128 within host memory 120 that is accessible only to host security manager 130.
[0063] Additionally or alternatively, in an environment where multiple tenant VMs (VM1, VM2, ..., VMn) use host device 100 (where n is a natural number greater than or equal to 2), a security zone can be set for each of the multiple tenant VMs (VM1, VM2, ..., VMn). For example, host memory 120 may include memory zones 122, 124, and 126, allowing only each associated tenant VM1, VM2, ..., or VMn to access it. As a specific example, host security manager 130 may set a first host memory zone 122 within host memory 120, allowing only the first tenant VM1 to access it. Additionally, host security manager 130 may set a second host memory zone 124 within host memory 120, allowing only a second tenant VM2, different from the first tenant VM1, to access it. Here, the first host memory zone 122 and the second host memory zone 124 may be different zones within host memory 120. In this way, the host security manager 130 can set up different host storage zones 122, 124, and 126 in some areas of the host storage 120, allowing only each tenant VM1, VM2, ..., or VMn to access them.
[0064] The host security manager 130 can manage a mapping table that includes the addresses of security zones within the host memory 120, the addresses of host memory zones 122, 124, and 126 associated with each tenant VM1, VM2, ..., VMn, and encryption key information associated with each tenant VM1, VM2, ..., VMn.
[0065] According to one embodiment, storage device 200 may include a device security manager 215 and non-volatile memory 220. Device security manager 215 may include hardware and / or software modules for managing the security of storage device 200. That is, device security manager 215 may be a trusted component of storage device 200.
[0066] In one embodiment, the non-volatile memory 220 may include a secure region 222 that is accessible only to the device security manager 215. For example, the device security manager 215 may set up a secure region 222 within the non-volatile memory 220 that is accessible only to the device security manager 215.
[0067] Host security manager 130 can perform mutual authentication with device security manager 215 using security protocols (e.g., Security Protocol and Data Model (SPDM)). In this way, host security manager 130 and device security manager 215 can become a trusted configuration for host device 100 and storage device 200. That is, the trusted zone of host device 100 can be extended. According to one embodiment, a secure path can be formed between host security manager 130 and device security manager 215, and host security manager 130 and device security manager 215 can send and receive data, commands, etc., through the secure path.
[0068] According to one embodiment, device security manager 215 can generate triples and store the generated triples in a secure region 222 of non-volatile memory 220. The generation of triples by device security manager 215 can be performed by a storage controller (e.g., Figure 1 (210) This is executed when data writing / reading is not performed. Furthermore, the device security manager 215 can send a triple or a partial triple generated based on that triple to the host security manager 130 in response to receiving a triple request from the host security manager 130. See later. Figures 4 to 15 Provide a more detailed description of the relevant configuration.
[0069] As described above, when the storage device performs the generation and management of triples for multi-party computation by offloading, host device resources can be saved, processing speed can be improved, and performance can be optimized. Furthermore, the efficiency of the storage system can be improved by generating triples while the storage device 200 is not performing data recording / reading.
[0070] exist Figure 3 The illustration shows host device 100 including a host controller 110, and all tenant VM1, VM2, ..., VMn sharing and using the same host controller 110. However, this is only for illustrative purposes, and the scope of this disclosure is not limited thereto. Host device 100 may include multiple host controllers and / or at least some of the tenants VM1, VM2, ..., VMn may use different host controllers. Furthermore, in... Figure 3 In this embodiment, host device 100 includes a host storage 120, and all tenant VM1, VM2, ..., VMn and host security manager 130 share and use the same host storage 120, but this is only for illustrative purposes and the scope of this disclosure is not limited thereto. Host device 100 may include multiple host storages and / or host security managers 130, and at least some of the multiple tenant VM1, VM2, ..., VMn may use different host storages.
[0071] Figure 4This is a flowchart illustrating an example of an operation method 400 of a storage device according to an embodiment of the present disclosure. Figure 5 This is a flowchart illustrating an example of an operation method 500 of a host device according to an embodiment of the present disclosure, and Figures 6 to 9 This is a block diagram illustrating an example of the operation of a storage system according to an embodiment of the present disclosure. In the following, any content that overlaps with the foregoing will be omitted or briefly described, and reference will be made to… Figures 1 to 3 The key points to be explained are the parts that have been added or changed.
[0072] refer to Figure 4 The operation method 400 of the storage device can be executed by the device security manager 215 of the storage device. The device security manager 215 of the storage device can first perform mutual authentication with the host security manager of the host device using a security protocol (S410).
[0073] Subsequently, the device security manager 215 can generate a triplet and store it in non-volatile memory (S420). For example, the device security manager can create a triplet and store it in a secure area of the non-volatile memory that only the device security manager can access. In one embodiment, the device security manager can generate a triplet when the storage controller does not perform a data write / read operation at the request of the host device.
[0074] As a specific example, such as Figure 6 As shown, the device security manager 215 can generate triples such as "(a,b,c), (d,e,f), (g,h,i)" without performing data write / read operations according to the request of the host device 100, and can store the generated triples in the secure area 222 of the non-volatile memory 220. According to one embodiment, the device security manager 215 can further generate random values required for the generation of some triples and store the generated random values in the secure area 222 of the non-volatile memory 220.
[0075] Refer again Figure 4 Device security manager 215 can receive a triple request from host security manager (S430), and then transmit the triple or a partial triple generated based on the triple to host security manager in response to receiving the triple request from host security manager (S440).
[0076] As a specific example, such as Figure 7 As shown, device security manager 215 can receive triple requests from host security manager 130. In response to this request, device security manager 215 can load the triple "(a, b, c)" (e.g., load it into...). Figure 1In the buffer memory 216 or the separate buffer memory (not shown) of the device security manager 215, such as Figure 8 As illustrated in the diagram, the triple "(a, b, c)" is deleted from the secure region 222 of non-volatile memory 220, and the triple "(a, b, c)" is transferred to the host security manager 130. As another specific example, device security manager 215 can transfer a triple and a random value to host security manager 130. As yet another specific example, device security manager 215 can generate a partial triple based on the triple and the random value, and transfer the generated partial triple to host security manager 130. See below for reference. Figures 10 to 15 Various embodiments relating thereto are described in more detail. According to one embodiment, triples, random values, and / or portions of triples can be transmitted via a secure path established between device security manager 215 and host security manager 130.
[0077] Reference Figure 5 The operation method 500 of the host device can be executed by the host security manager 130 of the host device. The host security manager 130 can first perform mutual authentication with the device security manager of the storage device using a security protocol (S510).
[0078] Subsequently, the host security manager 130 can send a triple request to the device security manager (S520) and receive a triple or a partial triple generated based on the triple from the device security manager (S530).
[0079] As a specific example, such as Figure 7 As shown, host security manager 130 can transmit a triplet request to device security manager 215. Thereafter, host security manager 130 can receive the triplet TRIPLET(a, b, c) from device security manager 215, as shown... Figure 8 As illustrated in the diagram. As another specific example, host security manager 130 can receive triples and random values from device security manager 215. As another specific example, host security manager 130 can also receive partial triples from device security manager 215. See below for reference. Figures 10 to 15 Various embodiments relating thereto are described in more detail. According to one embodiment, triples, random values, and / or portions of triples can be received via a secure path established between host security manager 130 and device security manager 215.
[0080] Refer again Figure 5When the host security manager receives a triple from the device security manager, the host security manager can generate a partial triple based on the triple (S540) and distribute the partial triple to the participants in the multi-party computation (S550). On the other hand, if the host security manager receives a partial triple from the device security manager, the received partial triple can be distributed to the participants in the multi-party computation (S550) without the need for the process of generating the partial triple (S540).
[0081] As a specific example, such as Figure 9 As shown, the host security manager 130 can generate partial triples based on the received triplet TRIPLET(a, b, c): PARTIAL TRIPLET 1(a1, b1, c1), PARTIAL TRIPLET 2(a2, b2, c2), ..., PARTIAL TRIPLET n(an, bn, cn), and distribute the generated partial triples to tenants VM1, VM2, ..., VMn (where n is a natural number greater than or equal to 2) who are participants in a multi-party computation. In some embodiments, distributing partial triples to tenants VM1, VM2, ..., VMn may mean storing each partial triple in a host memory region 122, 124, or 126 associated with each tenant VM1, VM2, ..., VMn. Each tenant VM1, VM2, ..., VMn can use the distributed partial triples to perform computations.
[0082] Figure 10 and Figure 11 This is a diagram illustrating an example of a method of operating a storage system according to some embodiments of the present disclosure. Any content that is repeated above will be omitted or simply described below, and reference will be made to... Figures 1 to 9 The key points to be explained are the parts that have been added or changed.
[0083] Reference Figure 10 and Figure 11 According to one embodiment, the device security manager 215 can generate the random values required for generating triples and partial triples, and store the generated triples and partial triples in a secure area of non-volatile memory (S1010). According to one embodiment, the device security manager 215 can generate triples and random values when the storage controller does not perform a data write / read operation at the request of the host device.
[0084] Subsequently, the host security manager 130 may transmit a triplet request, including information about the number of participants in a multi-party computation (e.g., n, where n is a natural number greater than or equal to 2), to the device security manager 215 (S1020). For example, the host security manager 130 may send a triplet request when partial triplet distribution is required (e.g., when tenants 102, 104, and 106 of the host device, as participants in a multi-party computation, perform a multiplication operation). In response to receiving a triplet request from the host security manager 130, a triplet and a random value (e.g., a value that can be loaded into a secure region of non-volatile memory) may be loaded. Figure 1 The buffer memory 216 or a separate buffer memory of the device security manager 215 (not shown) can be used, and the loaded triplet and random value can be deleted from the secure area of the non-volatile memory (S1030). For example, the device security manager 215 can load a triplet and as many random values as three times the number of participants minus one (e.g., 3(n-1) random values), and delete the loaded triplet and random value from the secure area of the non-volatile memory.
[0085] In one embodiment, the triplet request may also include information about the number of triplets required (e.g., m, where m is a natural number). That is, the triplet request may include information about the number of participants (e.g., n, where n is a natural number greater than or equal to 2) and information about the number of triplets required. In this case, the device security manager 215 may load as many triplets as required (e.g., m triplets) and as many random values as the number of participants minus 1 multiplied by the number of required triplets (e.g., 3m(n-1) random values), and may delete the loaded triplets and random values from a secure area of non-volatile memory.
[0086] According to one embodiment, the device security manager 215 can generate partial triples based on loaded triples and random values, such as... Figure 10 (S1040) is shown in the diagram.
[0087] For example, the device security manager 215 can generate a number of partial triples (e.g., n partial triples) based on the loaded triples and a number of random values equal to three times the number of participants minus one.
[0088] In another example where the triple request further includes information about the number of required triples, the device security manager 215 may generate a set of partial triples that is as many as the number of required triples (e.g., m sets of partial triples, that is, n x m partial triples) based on the same number of triples as the number of required triples loaded and as many random values as 3 × the number of required triples x (number of participants - 1). The set of partial triples includes as many partial triples as the number of participants (e.g., n partial triples).
[0089] Additionally, the device security manager 215 can transmit the generated partial triples (e.g., n partial triples or n×m partial triples) to the host security manager 130 (S1050). The host security manager 130 can then distribute the received partial triples to tenants 102, 104, and 106, who are participants in the multi-party computation (S1060).
[0090] Alternatively, the device security manager 215 can transfer the loaded triples and random values to the host security manager 130 instead of directly generating partial triples, such as... Figure 11 As shown in (S1110).
[0091] For example, device security manager 215 can send a loaded triplet and a random value equal to 3 x (number of participants minus one) to host security manager 130.
[0092] In another example where the triplet request also includes information about the number of required triplets, the device security manager 215 may send the host security manager 130 as many triplets as the number of required triplets loaded, and as many random values as 3 x the number of required triplets x (number of participants - 1).
[0093] The host security manager 130 can generate partial triples based on the received triples and random values (S1120).
[0094] For example, the host security manager 130 can generate a number of partial triples (e.g., n partial triples) based on the received triples and a number of random values equal to three times the number of participants minus one.
[0095] In another example where the triple request also includes information about the number of required triples, the host security manager 130 may generate a set of partial triples that is as many as the number of required triples received, and a set of random values that is as many as 3 × the number of required triples x (number of participants - 1), which includes a set of partial triples that is as many as the number of participants (e.g., n partial triples).
[0096] Subsequently, the host security manager 130 may send the generated partial ternary components to tenants 102, 104 and 106 as participants in the multi-party computation (S1130).
[0097] Figure 12 This is a diagram illustrating an example of an operation method of a storage system according to another embodiment of the present disclosure. In the following, any content that overlaps with the foregoing will be omitted or briefly described, and reference will be made to… Figures 1 to 11 The key points to be explained are the parts that have been added or changed.
[0098] According to one embodiment, whenever the device security manager 215 receives a triplet request and / or random value request from the host security manager 130, the device security manager 215 may transmit a predetermined number of triplets and / or random values to the host security manager 130. The host security manager 130 may store the received triplets and / or random values in a secure area of the host memory. Whenever a partial triplet needs to be distributed, the host security manager 130 may load the stored triplets and random values, generate a partial triplet, and distribute the generated partial triplet to tenants 102, 104, and 106. Additionally, whenever it is determined that the number of triplets and / or random values stored in the secure area of the host memory is insufficient, the host security manager 130 may transmit a triplet request and / or random value request to the device security manager 215.
[0099] Specifically, refer to Figure 12 According to one embodiment, the device security manager 215 can generate the triplet and random value required for the generation of partial triplets, and store the generated triplet and random value in a secure area of non-volatile memory (S1010).
[0100] In response to determining that the number of triples stored in the secure region of host memory is insufficient (S1202), host security manager 130 may transmit a triple request to device security manager 215 (S1204). In one embodiment, the triple request may not include information about the number of participants in the multi-party computation. In response to receiving a triple request from host security manager 130, device security manager 215 may load a first predetermined number of triples from the secure region of non-volatile memory and delete the loaded triples from the secure region of non-volatile memory (S1206). Thereafter, device security manager 215 may transmit the first predetermined number of loaded triples to host security manager 130 (S1208). Host security manager 130 may store the received triples in the secure region of host memory (S1210).
[0101] In response to determining that there is a shortage of random values stored in the secure area of the host memory (S1212), the host security manager 130 may transmit a random value request to the device security manager 215 (S1214). In response to receiving the random value request from the host security manager 130, the device security manager 215 may load a second predetermined number of random values from the secure area of the non-volatile memory and delete the loaded random values from the secure area of the non-volatile memory (S1216). Thereafter, the device security manager 215 may transmit the second predetermined number of loaded random values to the host security manager 130 (S1218). The host security manager 130 may store the received random values in the secure area of the host memory (S1220).
[0102] Subsequently, when partial triples need to be distributed (e.g., when tenants 102, 104, and 106 of the host device, as participants in a multi-party computation, perform a multiplication operation), the host security manager 130 can generate partial triples based on triples stored in a secure area of the host memory and random values (S1222). As a specific example, the host security manager 130 can generate as many partial triples as the number of participants in the multi-party computation (e.g., n partial triples) based on a triple stored in a secure area of the host memory and as many random values as 3 × (number of participants minus one) (e.g., 3(n-1) random values). Furthermore, the host security manager 130 can distribute the generated partial triples to tenants 102, 104, and 106, who are participants in the multi-party computation (S1224).
[0103] Whenever the host security manager 130 determines that the number of triples and / or random values stored in the secure area of the host memory is insufficient, the host security manager 130 may subsequently transmit a triple request and / or random value request to the device security manager 215.
[0104] exist Figure 12 In the illustration, steps S1202 to S1210 related to the triplet request are shown to be executed before steps S1212 to S1220 related to the random value request. However, the embodiment is not limited to this example, and steps S1202 to S1210 related to the triplet request may be executed after steps S1212 to S1220 related to the random value request, or at least a portion of steps S1202 to S1210 related to the triplet request and at least a portion of steps S1212 to S1220 related to the random value request may be executed in parallel.
[0105] Figure 13 This is a diagram illustrating an example of a method of operating a storage system according to another embodiment of the present disclosure. In the following, any content that overlaps with the foregoing will be omitted or briefly described, and reference will be made to… Figures 1 to 12 The key points to be explained are the parts that have been added or changed.
[0106] Reference Figure 13 According to one embodiment, the device security manager 215 can generate triples and store the generated triples in a secure area of non-volatile memory (S1310). Additionally, the host security manager 130 can generate random values required for the generation of some triples and store the generated random values in a secure area of the host memory (S1320).
[0107] The host security manager 130 may send a triple request (S1330). In one embodiment, the triple request may not include information about the number of participants in the multi-party computation. In response to receiving a triple request from the host security manager 130, the device security manager 215 may load a triple from a secure region of non-volatile memory and delete the loaded triple from the secure region of non-volatile memory (S1340). For example, the device security manager 215 may load a triple from a secure region of non-volatile memory and delete the loaded triple from the secure region of non-volatile memory.
[0108] As another example, a triplet request may include information about the number of triplets required (e.g., m, where m is a natural number). In this case, the device security manager 215 can load as many triplets as required (e.g., m triplets) from the secure region of non-volatile memory and remove the loaded triplets from the secure region of non-volatile memory.
[0109] Afterward, the device security manager 215 can transfer the loaded triplet to the host security manager 130 (S1350).
[0110] The host security manager 130 can generate a partial triplet (S1360) based on the triplet (e.g., a triplet) received from the device security manager 215 and random values stored in the security area of the host memory (e.g., 3(n-1) random values in the security area of the host memory, where n is the number of participants).
[0111] In another example where the triplet request also includes information about the number of required triplets (e.g., m, where m is a natural number), the host security manager 130 may generate a set of partial triplets that is as many as the number of required triplets received (e.g., m triplets) and random values stored in a secure region of the host memory (e.g., 3m(n-1) random values in a secure region of the host memory, where n is the number of participants). The set of partial triplets includes a set of partial triplets that is as many as the number of participants in the multi-party computation (e.g., a set of m partial triplets, i.e., n×m partial triplets).
[0112] In addition, the host security manager 130 can send the generated partial ternary components to tenants 102, 104 and 106 (S1370).
[0113] Figure 14 and Figure 15 This is a diagram illustrating an example of a method of operating a storage system according to another embodiment of this disclosure. In the following, any content that overlaps with the foregoing will be omitted or briefly described, and reference will be made to… Figures 1 to 13 The key points to be explained are the parts that have been added or changed.
[0114] In some embodiments, in response to receiving a triplet request from the host security manager 130, the device security manager 215 may transmit a third predetermined number of random values or a fourth predetermined number of partial triplets to the host security manager 130. The host security manager 130 may generate as many partial triplets as the number of participants in the multi-party computation based on the received random values or partial triplets, and distribute the generated partial triplets to the participating tenants 102, 104, and 106.
[0115] Specifically, refer to Figure 14 and Figure 15According to one embodiment, the device security manager 215 can generate random values required for generating triples and partial triples, and store the generated random values in a secure area of non-volatile memory (S1010). Additionally, the host security manager 130 can generate random values required for generating partial triples, and store the generated random values in a secure area of host memory (S1410).
[0116] The host security manager 130 may send a triplet request (S1420). In one embodiment, the triplet request may not include information about the number of participants in the multi-party computation. In response to receiving a triplet request from the host security manager 130, the device security manager 215 may load a triplet (e.g., a triplet) and a third predetermined number of random values from a secure region of non-volatile memory, and delete the loaded triplet and random values from the secure region of non-volatile memory (S1430).
[0117] According to one embodiment, the device security manager 215 can transmit the loaded triplet and a third predetermined number of random values to the host security manager 130, such as... Figure 14 As shown in (S1440). The host security manager 130 can generate as many partial triples as the number of participants (e.g., n partial triples, where n is the number of participants) based on the received triples and a third predetermined number of random values (S1450).
[0118] For example, if more random values are received than are needed to generate partial triples equal to the number of participants (e.g., if the third predetermined number > 3 (n-1)), the device security manager 215 can generate partial triples equal to the number of participants using only the required number of random values from the received random values. As another example, if fewer random values are received than are needed to generate partial triples equal to the number of participants (e.g., if the third predetermined number < 3 (n-1)), the device security manager 215 can further use random values stored in a secure area of the host memory to generate partial triples equal to the number of participants. As another example, if more random values are received than are needed to generate partial triples equal to the number of participants (e.g., if the third predetermined number = 3 (n-1)), the device security manager 215 can use the received random values to generate partial triples. Thereafter, the device security manager 215 can distribute the generated partial triples to tenants 102, 104, and 106 as participants in the multi-party computation (S1460).
[0119] Alternatively, the device security manager 215 may generate a fourth predetermined number (e.g., k) of partial triples (S1510) based on the loaded triples and a third predetermined number (e.g., 3(k - 1)) of random values, as Figure 15 shown, and send the generated fourth predetermined number of partial triples to the host security manager 130 (S1520). The host security manager 130 may convert the received fourth predetermined number of partial triples into as many partial triples as the number of participants in the multiparty computation (S1530).
[0120] For example, if the number of received partial triples is greater than the number of participants in the multiparty computation (e.g., if the fourth predetermined number > n, where n is the number of participants), the host security manager 130 may convert some of the received fourth predetermined number of partial triples into as many partial triples as the number of participants in the multiparty computation by adding the partial triples together. As another example, if fewer partial triples are received than the number of participants in the multiparty computation (e.g., if the fourth predetermined number < n), the host security manager 130 may generate as many partial triples as the number of participants in the multiparty computation based on the fourth predetermined number of partial triples and the random values stored in the secure area of the host memory. As another example, if as many partial triples as the number of participants in the multiparty computation are received (e.g., if the fourth predetermined number = n), the host security managerThe System 2000 is not necessarily limited to mobile systems, and can be a personal computer, laptop computer, server, media player, or automotive device such as a navigation system.
[0123] System 2000 may include a main processor 2100, a memory 2200a or 2200b and a storage device 2300a or 2300b, and may additionally include one or more of an image capture device 2410, a user input device 2420, a sensor 2430, a communication device 2440, a display 2450, a speaker 2460, a power supply device 2470 and a connection interface 2480.
[0124] The main processor 2100 can control the overall operation of the system 2000, and more specifically, control the operation of other components constituting the system 2000. Such a main processor 2100 can be implemented as a general-purpose processor, a special-purpose processor, or an application processor.
[0125] The main processor 2100 may include one or more CPU cores 2110, and may also include a controller 2120 for controlling memories 2200a and 2200b and / or storage devices 2300a and 2300b. In some embodiments, the main processor 2100 may also include an accelerator 2130, which is dedicated circuitry for high-speed data computation, such as AI artificial intelligence data computation. The accelerator 2130 may include a graphics processing unit (GPU), a neural processing unit (NPU), and / or a data processing unit (DPU), and may be implemented as a separate chip physically independent of other components of the main processor 2100.
[0126] Memory 2200a and 2200b can be used as the main memory device of system 2000 and can include volatile memory such as SRAM and / or DRAM, but can also include non-volatile memory such as flash memory, PRAM and / or RRAM. Memory 2200a and 2200b can also be implemented in the same package as main processor 2100.
[0127] Storage devices 2300a or 2300b can be based on the above reference. Figures 1 to 15Storage device 200 of the described embodiment. Storage device 2300a or 2300b can be used as a non-volatile storage device that stores data regardless of power supply and can have a relatively large storage capacity compared to memory 2200a or 2200b. Storage device 2300a or 2300b may include storage controller 2310a or 2310b and non-volatile memory 2320a or 2320b that stores data under the control of storage controller 2310a or 2310b. Non-volatile memory 2320a or 2320b may include flash memory with a 2D structure or a 3D vertical NAND (V-NAND) structure, but may also include other types of non-volatile memory, such as PRAM and / or RRAM.
[0128] Storage devices 2300a or 2300b may be included in system 2000, which is physically separate from main processor 2100, or may be implemented within the same package as main processor 2100. Furthermore, storage devices 2300a or 2300b may take the form of a solid-state drive (SSD) or memory card and may be detachably connected to other components of system 2000 via an interface such as connection interface 2480, which will be described later. Such storage devices 2300a and 2300b may be devices applying standard specifications such as Universal Flash Memory (UFS), embedded multimedia card (eMMC), or high-speed non-volatile memory (NVMe), but are not necessarily limited to these.
[0129] Image capture device 2410 can capture still images or moving images, and can be a camera, camcorder, and / or webcam.
[0130] User input device 2420 can receive various types of data input from the user of system 2000, and can be a touchpad, keypad, keyboard, mouse and / or microphone.
[0131] Sensor 2430 can detect various types of physical quantities that can be obtained from outside the system 2000 and convert the detected physical quantities into electrical signals. Such sensor 2430 can be a temperature sensor, pressure sensor, illuminance sensor, position sensor, acceleration sensor, biosensor, and / or gyroscope sensor.
[0132] The communication device 2440 can send and receive signals between other devices outside the system 2000 according to various communication protocols. Such a communication device 2440 can be implemented as including an antenna, transceiver, and / or modem.
[0133] The display 2450 and the speaker 2460 can be used as output devices to output visual and auditory information to the user of the system 2000, respectively.
[0134] The power supply device 2470 can appropriately convert power supplied from a battery (not shown) built into the system 2000 and / or an external power source, and supply the converted power to each component of the system 2000.
[0135] The connection interface 2480 provides a connection between the system 2000 and an external device that can connect to and exchange data with the system 2000. The connection interface 2480 can be implemented using various interface methods, such as Advanced Technology Attachment (ATA), Serial ATA (SATA), External SATA (e-SATA), Small Computer Small Interface (SCSI), Serial Attached SCSI (SAS), Peripheral Component Interconnect (PCI), High-Speed PCI (PCIe), NVMe, IEEE 1394, Universal Serial Bus (USB), Secure Digital (SD) card, Multimedia Card (MMC), eMMC, UFS, Embedded Universal Flash Memory (eUFS), Compact Flash Memory (CF) card interface, etc.
[0136] Figure 17 This is an exemplary block diagram illustrating a data center 3000 employing storage devices (3250_1 to 3250_m, where m is a natural number) according to an embodiment of this disclosure. Reference Figure 17 Data center 3000 is a facility that collects various types of data and provides services, and may also be referred to as a data storage center. Data center 3000 can be a system for operating search engines and databases, and can be a computing system used in companies such as banks or government agencies. Data center 3000 may include application servers 3100_1 to 3100_n (n is a natural number) and storage servers 3200_1 to 3200_m. The number of application servers 3100_1 to 3100_n and the number of storage servers 3200_1 to 3200_m may be selected differently depending on the embodiment, and the number of application servers 3100_1 to 3100_n and the number of storage servers 3200_1 to 3200_m may differ from each other.
[0137] Application server 3100_n or storage server 3200_m may include at least one of processors 3110_n and 3210_m and memory 3120_n and 3220_m. Taking storage server 3200_m as an example, processor 3210_m may control the overall operation of storage server 3200_m and access memory 3220_m to execute commands and / or data loaded into memory 3220_m. Memory 3220_m may be double data rate synchronous DRAM (DDR SDRAM), high bandwidth memory (HBM), hybrid memory cube (HMC), dual in-line memory module (DIMM), optane DIMM, and / or non-volatile DIMM (NVMDIMM). According to embodiments, the number of processors 3210_m and the number of memory 3220m included in storage server 3200_m may be selected in various ways. In one embodiment, processors 3210_m and memory 3220m may provide processor-memory pairs. In one embodiment, the number of processors 3210_m and the number of memory devices 3220_m may differ from each other. Processors 3210_m may include single-core or multi-core processors. The above description for storage server 3200_m can be similarly applied to application server 3100_n. According to an embodiment, application server 3100_n may not include storage device 3150_n. Storage server 3200_m may include at least one storage device 3250_m. The number of storage devices 3250_m included in storage server 3200_m can be selected in various ways according to embodiments.
[0138] Application servers 3100_1 to 3100_n and storage servers 3200_1 to 3200_m can communicate with each other via network 3300. Network 3300 can be implemented using Fibre Channel (FC) or Ethernet. In this case, FC is the medium for relatively high-speed data transmission and can utilize optical switches that provide high performance / high availability. Depending on the access method of network 3300, storage servers 3200_1 to 3200_m can be provided as file storage, block storage, or object storage.
[0139] In one embodiment, network 3300 may be a storage-only network, such as a storage area network (SAN). For example, the SAN may be an FC-SAN that utilizes an FC network and is implemented according to the FC protocol (FCP). As another example, the SAN may be an IP-SAN that uses a TCP / IP network and is implemented according to the SCSI over TCP / IP or Internet SCSI protocol (iSCSI). In another embodiment, network 3300 may be a general-purpose network, such as a TCP / IP network. For example, network 3300 may be implemented according to protocols such as Ethernet FC (FCoE), Network Attached Storage (NAS), and Fibre NVMe (NVMe-oF).
[0140] The following section focuses on application server 3100_n and storage server 3200_m. The description of application server 3100_n can also be applied to other application servers, and the description of storage server 3200_m can also be applied to other storage servers.
[0141] Application server 3100_n can store data requested by users or clients in one of storage servers 3200_1 to 3200_m via network 3300. Furthermore, application server 3100_n can retrieve data requested by users or clients from one of storage servers 3200_1 to 3200_m via network 3300. For example, application server 3100_n can be implemented as a web server or a database management system (DBMS).
[0142] Application server 3100_n can access memory or storage devices included in another application server via network 3300, or it can access memory 3220_1 to 3220_m or storage devices 3250_1 to 3250_m included in storage servers 3200_1 to 3200_m via network 3300. Therefore, application server 3100_n can perform various operations on data stored in application servers 3100_1 to 3100_n and / or storage servers 3200_1 to 3200_m. For example, application server 3100_n can execute commands to move or copy data between application servers 3100_1 to 3100_n and / or storage servers 3200_1 to 3200_m. At this point, data can be moved directly from storage devices 3250_1 to 3250_m of storage servers 3200_1 to 3200_m to storage devices 3220_1 to 3220m of storage servers 3200_1 to 3200_m, or after being transferred to storage devices 3220_1 to 3220m of storage servers 3200_1 to 3200_m, to storage devices 3220_1 to 3220m. Data moved over network 3300 can be encrypted for security or privacy purposes.
[0143] Storage devices 3250_1 to 3250_m can be based on the above reference. Figures 1 to 15 Storage device 200 of the described embodiment.
[0144] Taking storage server 3200_m as an example, interface 3254_m can provide physical connections between processor 3210_m and controller 3251_m, as well as physical connections between network interconnect (NIC) 3240_m and controller 3251_m. For example, interface 3254_m can be implemented as a direct-attach storage (DAS) method, directly connecting storage device 3250_m to a dedicated cable. Furthermore, interface 3254 can be implemented using various interface methods, such as Advanced Technology Attachment (ATA), Serial ATA (SATA), External SATA (e-SATA), Small Computer Small Interface (SCSI), Serial Attached SCSI (SAS), Peripheral Component Interconnect (PCI), High-Speed PCI (PCIe), NVMe, IEEE 1394, Universal Serial Bus (USB), Secure Digital (SD) card, Multimedia Card (MMC), eMMC, UFS, Embedded Universal Flash Memory (eUFS), Compact Flash Memory (CF) card interface, etc.
[0145] The storage server 3200_m may also include a switch 3230_m and a NIC 3240_m. The switch 3230_m can selectively connect the processor 3210_m and the storage device 3250_m or selectively connect the NIC 3240_m and the storage device 3250 under the control of the processor 3210_m.
[0146] In one embodiment, NIC 3240_m may include a network interface card, network adapter, etc. NIC 3240_m may connect to network 3300 via a wired interface, wireless interface, Bluetooth interface, optical interface, etc. NIC 3240_m may include internal memory, digital signal processor (DSP), host bus interface, etc., and may connect to processor 3210_m and / or switch 3230_m via the host bus interface. The host bus interface may be implemented as one of the examples of the aforementioned interface 3254_m. In one embodiment, NIC 3240_m may be integrated with at least one of processor 3210_m, switch 3230_m, and storage device 3250_m.
[0147] In storage servers 3200_1 to 3200_m or application servers 3100_1 to 3100_n, the processor can program or read data by sending commands to storage devices 3150_1 to 3150_n and 3250_1 to 3250_m or memories 3120_1 to 3120_n and 3220_1 to 3220_m. The data can be error-corrected using error correction codes (ECC). The data has undergone data bus reversal (DBI) or data masking (DM) processes and may include cyclic redundancy check (CRC) information. The data can be encrypted for security or privacy purposes.
[0148] Storage devices 3150_1 to 3150_n and 3250_1 to 3250_m can send control signals and command / address signals to NAND flash memory devices 3252_1 to 3252_m based on read commands received from the processor. Correspondingly, when reading data from NAND flash memory devices 3252_1 to 3252_m, the read enable (RE) signal can be input as a data output control signal and function to output data to the DQ bus. The RE signal can be used to generate a data strobe (DQS). Command and address signals can be latched into the page buffer based on the rising or falling edge of the write enable (WE) signal.
[0149] The controller 3251_m can control the overall operation of the storage device 3250_m. In one embodiment, the controller 3251_m may include static random access memory (SRAM). The controller 3251_m can write data to the NAND flash memory 3252_m in response to a write command, or can read data from the NAND flash memory 3252_m in response to a read command. For example, the write command and / or read command may be provided from the processor 3210_m in the storage server 3200_m, a processor in another storage server, or processors 3110_1 to 3110_n in application servers 3100_1 to 3100_n. The DRAM 3253_m can temporarily store (buffer) data to be written to the NAND flash memory 3252_m or data to be read from the NAND flash memory 3252_m. In addition, the DRAM 3253_m can store metadata. Here, the metadata is generated by the controller 3251_m to manage user data or data in the NAND flash memory 3252_m. Storage device 3250_m may include a security element (SE) for security or privacy purposes.
[0150] Although embodiments of the present disclosure have been described with reference to the accompanying drawings, the present disclosure is not limited to the above embodiments, but can be made in various different forms, and those skilled in the art will understand that the present disclosure can be implemented in other specific forms without changing the technical concept or essential characteristics of the present disclosure. Therefore, it should be understood that the above embodiments are exemplary in all respects and not restrictive.
Claims
1. A storage system, comprising: Host equipment; as well as The storage device is configured to send and receive data with the host device. The host device includes: Host memory; and A host security manager, configured to manage the security of the host device and send triple requests to the storage device. The storage device includes: Non-volatile memory; and A storage controller, including a device security manager configured to manage the security of the storage device, generate triples and store the triples in the non-volatile memory, and, in response to receiving a triple request from a host security manager, send the triples or a portion of the triples generated based on the triples to the host security manager. The triple includes a pair of numbers containing three numbers used to perform a multiplication operation via multi-party computation (MPC) in the host device, and The partial triple contains a secret shared value of the triple, which is distributed to the participants in the multi-party computation.
2. The storage system according to claim 1, wherein, The device security manager and the host security manager are also configured to use a security protocol to perform mutual authentication.
3. The storage system according to claim 1, wherein, The storage controller is configured to write data to the non-volatile memory or read data stored in the non-volatile memory in response to a request from the host device. The device security manager is also configured to generate the triplet when the storage controller does not perform a write operation or a read operation on the data.
4. The storage system according to claim 1, in, The non-volatile memory includes a secure region accessible only by the device security manager, and The device security manager is also configured to store the generated triples in the security area of the non-volatile memory.
5. The storage system according to claim 1, wherein, The host security manager is also configured to: A first host memory region is set in the host memory, and only the first tenant among the participants of the multi-party computation is allowed to access the first host memory region; as well as A second host memory region is set up in the host memory, and only the second tenant among the participants in the multi-party computation is allowed to access the second host memory region. The first host memory region and the second host memory region are different regions within the host memory.
6. The storage system according to claim 1, wherein, The device security manager is also configured to: The random values required to generate the partial triples; and The generated random values are stored in the non-volatile memory.
7. The storage system according to claim 6, wherein, The device security manager is further configured to: in response to receiving the triplet request from the host security manager, generate the partial triplet based on the triplet and the random value, and send the generated partial triplet to the host security manager.
8. The storage system according to claim 7, in, The triplet request includes information about the number of participants, and The device security manager is also configured to generate a number of partial triples corresponding to the number of participants based on the triples and the random value.
9. The storage system according to claim 6, wherein, The device security manager is also configured to: in response to receiving the triplet request from the host security manager, send the triplet and the random value to the host security manager.
10. The storage system according to claim 9, in, The triplet request includes information about the number of participants, and The device security manager is further configured to, in response to receiving the triplet request from the host security manager, send the triplet and a random value corresponding to 3x (number of participants - 1) to the host security manager.
11. The storage system according to claim 9, wherein, The host security manager is also configured to generate the partial triples based on the received triples and the received random values.
12. The storage system according to claim 1, wherein, The host storage includes a secure area that is accessible only to the host security manager.
13. The storage system according to claim 12, in, The device security manager is also configured to send a first predetermined number of triplets to the host security manager in response to receiving the triplet request from the host security manager. The host security manager is also configured as follows: The triplet received from the device security manager is stored in the secure area of the host memory; and In response to the determination that there are insufficient triples stored in the secure area of the host memory, a triple request is sent to the device security manager.
14. The storage system according to claim 12, in, The device security manager is also configured to: The random values required to generate the aforementioned partial triplets; The generated random values are stored in the non-volatile memory; as well as In response to receiving a random value request from the host security manager, a second predetermined number of random values are sent to the host security manager, and The host security manager is also configured as follows: The random value received from the device security manager is stored in the secure area of the host memory; as well as In response to determining that the random value stored in the secure area of the host memory is insufficient, a random value request is sent to the device security manager.
15. The storage system according to claim 12, wherein, The host security manager is also configured to generate random values required for the generation of the partial triples and to store the generated random values in a secure area of the host memory.
16. The storage system according to claim 15, wherein, The host security manager is also configured to generate the partial triples based on the received triples and the generated random values.
17. The storage system according to claim 1, in, The device security manager is also configured to: The random values required to generate the aforementioned partial triplets; The generated random values are stored in the non-volatile memory; as well as In response to receiving the triplet request from the host security manager, the triplet and a third predetermined number of random values are sent to the host security manager, and The host security manager is also configured to generate a number of partial triples corresponding to the number of participants based on the received triples and a third predetermined number of received random values.
18. The storage system according to claim 1, in, The device security manager is also configured to: The random values required to generate the aforementioned partial triplets; The generated random values are stored in the non-volatile memory; as well as In response to receiving the triplet request from the host security manager, a fourth predetermined number of partial triplets are generated based on the triplet and the random value, and the fourth predetermined number of partial triplets are sent to the host security manager. The host security manager is further configured to convert the received fourth predetermined number of partial triples into a number of partial triples corresponding to the number of participants.
19. A storage device, comprising: Non-volatile memory; as well as A device security manager is configured to manage the security of the storage device and perform mutual authentication with the host device's host security manager, wherein the host device is configured to send and receive data with the storage device. The device security manager is also configured as follows: Generate triples; The generated triples are stored in the non-volatile memory; and In response to receiving a triplet request from the host security manager, the triplet or a partial triplet generated based on the triplet is sent to the host security manager. The triple comprises a set of numbers, the set of numbers containing three numbers used to perform multiplication through multi-party computation in the host device, and The partial triples include a secret shared value of the triples, which is distributed to the participants in the multi-party computation.
20. A host device, comprising: Host memory; as well as A host security manager is configured to manage the security of the host device and perform mutual authentication with the device security manager of the storage device, wherein the storage device is configured to send and receive data with the host device. The host security manager is also configured as follows: Send a triplet request to the device security manager; and Receive a triplet or a partial triplet generated based on the triplet from the device security manager, and The triple comprises a set of numbers, the set of numbers containing three numbers used to perform multiplication through multi-party computation in the host device, and The partial triples include a secret shared value of the triples, which is distributed to the participants in the multi-party computation.