Disk drive

The disk device encrypts and stores data in non-volatile memory during power-offs, addressing data backup challenges by ensuring secure and complete data backup.

JP2026069286APending Publication Date: 2026-04-23KK TOSHIBA +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
KK TOSHIBA
Filing Date
2024-10-11
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing disk devices face challenges in appropriately backing up data during power-offs, particularly when non-volatile storage is not feasible for security reasons and the amount of regenerative energy is limited.

Method used

A disk device with a volatile memory and non-volatile memory, where data being written is encrypted with an encryption key and stored in the non-volatile memory during power-off, ensuring secure and complete data backup.

Benefits of technology

Ensures secure and complete backup of data during power-offs by encrypting and storing data in non-volatile memory, maintaining data integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026069286000001_ABST
    Figure 2026069286000001_ABST
Patent Text Reader

Abstract

One embodiment aims to provide a disk device that can properly back up data. [Solution] According to one embodiment, a disk device is provided having a disk medium, volatile memory, and a controller. The disk medium is on which first data is written. The first data includes an encryption key. The volatile memory is capable of temporarily storing second data. The controller includes a processor and non-volatile memory. The processor encrypts the second data with the encryption key when the power is cut off. The non-volatile memory stores the encrypted second data when the power is cut off.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006] , , , , , , , ,

[0005] ,

[0001] This embodiment relates to a disk device.

Background Art

[0002] In a disk device, when a power-off occurs, data that has not been written may be backed up. In a disk device, it is desirable that data backup is appropriately performed.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0004] One embodiment aims to provide a disk device capable of appropriately backing up data.

Means for Solving the Problems

[0005] According to one embodiment, a disk device having a disk medium, a volatile memory, and a controller is provided. The disk medium has first data written thereon. The first data includes an encryption key. The volatile memory can temporarily store second data. The controller includes a processor and a non-volatile memory. The processor encrypts the second data with the encryption key when a power-off occurs. The non-volatile memory stores the encrypted second data when a power-off occurs.

Brief Description of the Drawings

[0006] [Figure 1] A diagram showing the schematic configuration of a disk device according to an embodiment. [Figure 2] A diagram showing the detailed configuration of the disk device in the embodiment. [Figure 3] A flowchart illustrating the operation related to power shutdown of a disk device according to an embodiment. [Figure 4] A diagram showing the contents of the address translation information registration in the embodiment. [Figure 5] A diagram showing the contents of the address translation information registration in the embodiment. [Figure 6] A flowchart illustrating the operation related to the power restoration of the disk device according to the embodiment. [Modes for carrying out the invention]

[0007] A disk device according to an embodiment will be described in detail below with reference to the attached drawings. However, the present invention is not limited to this embodiment.

[0008] (Embodiment) The disk device according to this embodiment backs up any unwritten data when a power outage occurs, and measures are taken to ensure that the data is backed up properly.

[0009] The disk drive 1 may be configured as shown in Figure 1. Figure 1 is a diagram showing the configuration of the disk drive 1.

[0010] Disk device 1 can be connected to host device 2 via a communication medium in a communicative manner. Disk device 1 is connected to host device 2 and functions as an external storage medium for host device 2.

[0011] The disk drive 1 includes a disk medium 11, a spindle motor (SPM) 12, a ramp 13, an actuator arm 15, a voice coil motor (VCM) 16, a power supply circuit 20, a servo controller (SVC) 21, a head 22, a host interface (host I / F) 31, a preamplifier 24, a volatile memory 29, a PLP (Power Loss Protection) regulator 42, and a controller 30.

[0012] The controller 30 comprehensively controls each part of the disk device 1. The controller 30 includes a hard disk controller (HDC) 23, a read / write channel (RWC) 25, a processor 26, and non-volatile memory 28. The controller 30 may be configured as a system-on-a-chip (SoC).

[0013] The disk medium 11 is a disk-type storage medium, and may be a magnetic disk or a magneto-optical disk. If the disk medium 11 is a magnetic disk, a magnetic layer is formed on its surface, and information can be recorded in the direction of magnetization.

[0014] The disk medium 11 is rotatably supported in the housing (not shown) of the disk drive 1 via the SPM 12.

[0015] The power supply circuit 20 distributes the power supplied from the host device 2 to each component of the disk device 1, as shown by the dashed arrows in Figure 1. While Figure 1 illustrates the SVC 21, processor 26, and PLP regulator 42 as recipients of power from the power supply circuit 20, power may also be supplied to other components. The power supply circuit 20 may perform voltage conversion depending on the power recipient. The power supply circuit 20 may also receive power from a power supply unit or from the grid instead of the host device 2.

[0016] SVC21 functions as a driver for SPM12 and VCM16. SVC21 may be composed of an integrated circuit.

[0017] The head 22 writes and reads information to and from the disk medium 11 by means of the light element 22w and the lead element 22r provided thereon. Also, the head 22 is attached to the tip of the actuator arm 15. The head 22 is moved in the radial direction of the disk medium 11 by a VCM 16 driven by an SVC 21. Note that either one or both of the light element 22w and the lead element 22r provided on the head 22 may be provided in plural for a single head 22.

[0018] When the rotation of the disk medium 11 stops, etc., the head 22 is moved onto the ramp 13. The ramp 13 is configured to hold the head 22 at a position separated from the disk medium 11.

[0019] The preamplifier 24 writes and reads data via the head 22. The preamplifier 24 may be constituted by an integrated circuit. During a read operation, the preamplifier 24 amplifies and outputs a signal read by the head 22 from the disk medium 11 and supplies it to the RWC 25. Also, during a write operation, the preamplifier 24 amplifies a signal corresponding to the data to be written supplied from the RWC 25 and supplies it to the head 22.

[0020] The volatile memory 29 is used as a buffer for data transmitted and received between the host device 2. That is, a cache area 291 is allocated in the volatile memory 29, and the volatile memory 29 functions as a cache memory. The cache area 291 is used to temporarily store data to be written that has been received from the host device 2 and has not yet been written to the disk medium 11. Also, the volatile memory 29 is used to temporarily store data read from the disk medium 11.

[0021] Furthermore, the volatile memory 29 is used by the processor 26 as operating memory. The volatile memory 29 is used as an area where firmware is loaded and an area where various management data is temporarily stored. The volatile memory 29 may also be DRAM (Dynamic Random Access Memory).

[0022] The non-volatile memory 28 stores information in a non-volatile manner. The management information storage area of ​​the non-volatile memory 28 may store firmware (program data) and various operating parameters. The firmware may be stored in the management information storage area of ​​the disk medium 11 instead of the non-volatile memory 28.

[0023] The processor 26 is connected to non-volatile memory 28 and volatile memory 29. When firmware is read from the non-volatile memory 28 or the management information storage area of ​​the disk medium 11, the processor 26 performs overall control of the disk device 1 according to the firmware.

[0024] For example, the processor 26 loads firmware from non-volatile memory 28 or disk medium 11 into volatile memory 29, and controls the SVC 21, preamplifier 24, RWC 25, HDC 23, etc., according to the firmware loaded into volatile memory 29. The processor 26 controls the rotation of the SPM 12 via the SVC 21. The processor 26 controls the driving of the VCM 16 via the SVC 21. The processor 26 may also include a CPU (Central Processing Unit).

[0025] The host I / F31 can be connected to the host device 2 via a communication medium. The host I / F31 functions as a communication interface with the host device 2.

[0026] HDC23 controls the transmission and reception of data between the host device 2 and the host I / F31, as well as the control of the volatile memory 29.

[0027] For example, when the disk device 1 is started up, the processor 26 reads address translation information 32 and 33 from the non-volatile memory 28 or the management information storage area of ​​the disk medium 11 and stores it in the cache area 291.

[0028] The address translation information 32 is information that associates a logical address with the physical address of the disk medium 11. The address translation information 32 may have a table-like data structure. The logical address is a logical address included in a command and can be specified by the host device 2.

[0029] The physical address of the disk medium 11 is a physical address that indicates a storage location on the disk medium 11 and can be assigned by the processor 26. The physical address includes, for example, a combination of a cylinder number and a sector number. The cylinder number is a number that identifies a cylinder. A cylinder is a unit of storage area that spans multiple tracks corresponding to the upper and lower parts of multiple disk media 11. The sector number is a number that identifies a sector location within a single track.

[0030] In other words, physical addresses are assigned sequentially for some of the information within each track and for each set of adjacent tracks on the disk medium 11. The physical addresses include the head number (recording surface number) and can also be assigned sequentially for multiple tracks that are vertically adjacent within the cylinder.

[0031] The address translation information 33 is information that associates a logical address with the physical address of the non-volatile memory 28. The address translation information 33 may have a table-like data structure. The logical address is a logical address included in a command and can be specified by the host device 2.

[0032] The physical address of the non-volatile memory 28 is a physical address that indicates a storage location in the non-volatile memory 28 and can be assigned by the processor 26. The physical address includes, for example, the memory package number, memory die number, block address, page address, and location within the page.

[0033] The non-volatile memory 28 includes multiple memory packages and controllers. Each memory package includes multiple memory dies. Each memory die includes multiple blocks. Each block includes multiple pages. On each memory die, data is written and read on a page-by-page basis, and data is erased on a block-by-block basis. The memory package number, memory die number, block address, page address, and position within a page are each assigned by the controller in the non-volatile memory 28, and the result of this assignment is notified to the controller 30 of the disk device 1.

[0034] HDC23 can receive access commands from host device 2 via host I / F31. Access commands include write commands and read commands. HDC23 supplies the received access commands to processor 26 and / or RWC25.

[0035] If the access command is a write command, the processor 26 processes the write command, which includes a write instruction, a logical address, and write data. In response to the write instruction, the processor 26 registers the logical address included in the write command in the address translation information 32. The processor 26 assigns a physical address on the disk medium 11 to that logical address and updates the address translation information 32 accordingly. This completes the command processing for the processor 26. Once the command processing is complete, the processor 26 accesses the location on the disk medium 11 corresponding to the physical address via the preamplifier 24 and the head 22 and writes the write data.

[0036] If the access command is a read command, the processor 26 processes the read instruction and the read command, which includes a logical address. In response to the read instruction, the processor 26 refers to the address translation information 32 on the cache area 291 and obtains the physical address corresponding to the logical address included in the read command. This completes the command processing for the processor 26. Once the command processing is complete, the processor 26 accesses the location on the disk medium 11 corresponding to the physical address via the preamplifier 24 and the head 22 and reads the data.

[0037] In response to a write instruction supplied from the HDC23 and / or processor 26, the RWC25 code-modulates the write data stored in the cache area 291 and writes the code-modulated data via the preamplifier 24 to a location on the disk medium 11 corresponding to a physical address.

[0038] In response to read instructions supplied from the HDC23 and / or processor 26, the RWC25 performs code demodulation, including error correction, on the signal read from the location corresponding to the physical address on the disk medium 11 and supplied from the preamplifier 24. The RWC25 outputs the code demodulated signal as digital data to the HDC23.

[0039] Disk drive 1 operates using power from host device 2, but the power supply from host device 2 may be interrupted. To address this, the disk drive has a PLP (Power Line Protection) function. The PLP function protects disk drive 1 to mitigate the impact of the power supply interruption from host device 2.

[0040] The PLP regulator 42 can supply power to the SVC 21 according to its PLP function, as shown by the dashed arrow in Figure 1.

[0041] If the power supply from the host device 2 is cut off, the disk drive 1 generates a signal indicating power cutoff and supplies it to the PLP regulator 42. The SPM 12 rotates by inertia and can generate regenerative energy from the back electromotive force produced by its rotation. The PLP regulator 42 receives regenerative energy from the SPM 12 in response to the signal indicating power cutoff. The PLP regulator 42 then generates power based on the regenerative energy and supplies the generated power to the SVC 21 and the processor 26. The PLP regulator 42 may further supply the generated power to other components in the disk drive 1.

[0042] In the PLP function, if a power interruption from the host device 2 is detected during a write operation, the data being written in the cache area 291 of the volatile memory 29 is saved to a non-volatile storage area, thereby preventing the loss of the data from the disk device 1.

[0043] Here, it is difficult to use disk media 11 as a non-volatile storage area. The amount of regenerative energy recovered by the PLP regulator 42 is limited because it relies on the rotation of disk media 11 due to its inertia. Therefore, if disk media 11, which takes a relatively long time to write, is chosen as the backup destination, there is a possibility that all data being written will not be saved.

[0044] For example, disk device 1 may be required not to save data to non-volatile memory 28 for security reasons. In this case, it is difficult to directly save the data in cache area 291 to non-volatile memory 28 as part of the PLP function's processing.

[0045] Therefore, in this embodiment, when the power supply is cut off in the disk device 1, the data being written is encrypted with the previously written encryption key and saved to the non-volatile memory 28, thereby achieving both security assurance and data saving during writing.

[0046] When the power is cut off, the controller 30 obtains at least a portion of the data D1 already written to the disk medium 11 as an encryption key. The controller 30 encrypts the data D2 being written with the encryption key. The controller 30 stores the encrypted data D2 in the non-volatile memory 28 within the controller 30. The controller 30 further stores the address information of data D1 and the address information of data D2 in the non-volatile memory 28. This ensures that the data D2 being written is saved to the non-volatile memory 28 while guaranteeing security, and allows for proper saving of data D2.

[0047] The disk drive 1 can be configured with respect to the PLP function as shown in Figure 2. Figure 2 is a diagram showing the detailed configuration of the disk drive 1. Figure 2 shows the configuration of the servo system and data circuit system of the disk drive 1.

[0048] SVC21 has a VCM drive circuit 211 and a power supply voltage drop detection circuit 212. PLP regulator 42 has a head retraction instruction circuit 421 and a switch 422. HDC23 has a write data generation circuit 231. RWC25 has a write signal processing circuit 251 and a servo signal processing circuit 252. Processor 26 has a CPU 261, a position detection circuit 262, a servo sector number detection circuit 263, a write data encryption circuit 264, a switch 265, a read signal processing circuit 266, an encryption / decryption circuit 267, and a SMART (Self-Monitoring Analysis and Reporting Technology) data retention circuit 268.

[0049] On the disk medium 11, physical addresses are specified in areas called tracks TR in the circumferential direction and sectors SC in the radial direction. Furthermore, sector SC is divided into a servo area SV for recording position information and a data area DR for recording user data. The disk medium 11 is rotated by the SPM 12. A head 22 is attached to one end of the actuator arm 15, and a VCM 16 is attached to the other end. The actuator arm 15 rotates about axis AX, and can seek the head 22 from the outer peripheral area to the inner peripheral area on the disk medium 11. The read element 22r reads information on the disk medium 11, and the servo signal processing circuit 252 and position detection circuit 262 detect the position of the head 2. After control calculations are performed by the CPU 261, a current instruction value is applied to the VCM drive circuit. The VCM drive circuit 211 generates current and drives the actuator arm 15.

[0050] The write data generation circuit 231 receives write data via the host interface 31, performs the necessary data modifications for magnetic recording, and supplies the modified data to the write signal processing circuit 251. The write signal processing circuit 251 drives the write element 22w to write the data to the disk medium 11. The SMART data retention circuit 268 monitors the health of the disk device 1 by recording the status of the write data, the head positioning data held by the CPU 261, and track sector information for each event, such as when an abnormality occurs.

[0051] The power supply voltage drop detection circuit 212 detects power outages and sends power outage notifications to each peripheral circuit. Switch 432 switches from a state where terminals T1 and T2 are connected (shown by a solid line) to a state where terminals T1 and T3 are connected (shown by a dotted line) in response to the power outage notification. Head retraction instruction circuit 421 generates a VCM operation amount to instruct head movement in response to the power outage notification and supplies it to VCM16 via switch 432. Switch 265 switches from a state where terminals T4 and T5 are disconnected (shown by a solid line) to a state where terminals T4 and T5 are connected (shown by a dotted line) in response to the power outage notification.

[0052] The controller 30 may be an integrated semiconductor chip called an SoC, on which various functions may be implemented. A non-volatile memory 28 is mounted as part of it. The non-volatile memory 28 only needs to have sufficient storage capacity for saving data, and may have a relatively small storage capacity.

[0053] During the light operation, the light data generation circuit 231 supplies the light data to the light data encryption circuit 264. The controller 30 retrieves the light data that was processed immediately before the current light data from the volatile memory 29. The light data encryption circuit 264 retrieves at least a portion of the light data that was processed immediately before the current light data and encrypts the current light data using the retrieved data as an encryption key.

[0054] The write data encryption circuit 264 saves the logical address of the encryption key, the encrypted data, and its logical address to the non-volatile memory 28 in the controller 30 when the power is cut off.

[0055] After power is restored, during the rewrite operation, the read signal processing circuit 266 obtains the logical address of the encryption key, the encrypted data, and its logical address from the non-volatile memory 28. The read signal processing circuit 266 reads the write data containing the encryption key from the disk medium 11 according to the logical address of the encryption key, and reconstructs the encryption key according to the read data. The read signal processing circuit 266 supplies the encryption key, the encrypted data, and its logical address to the decryption circuit 267. The decryption circuit 267 decrypts the encrypted data using the encryption key. If decryption is successful, the decryption circuit 267 supplies the decrypted data to the write signal processing circuit 251. The write signal processing circuit 251 generates a write signal according to the decrypted data and writes it to the disk medium 11 via the write element 22w. This completes the rewriting of the data that was saved in the non-volatile memory 28 to the disk medium 11.

[0056] If decryption fails, the encryption / decryption circuit 267 notifies the SMART data retention circuit 268 via the write signal processing circuit 251 of the failure and its logical address. The SMART data retention circuit 268 holds SMART data, which includes various diagnostic results regarding the status of the disk device 1. Upon receiving the notification, the SMART data retention circuit 268 updates the SMART data to reflect the failure to decrypt the decrypted data and its logical address. This manages that the data saved in the non-volatile memory 28 has been lost due to being undecryptable.

[0057] Disk drive 1 may perform the operations shown in Figure 3 regarding power cut-off. Figure 3 is a flowchart showing the operations of disk drive 1 regarding power cut-off.

[0058] For example, suppose the command processing of write command CM1, which includes logical address A1 and data D1, has been completed, and the write operation of data D1 to physical address PA1 on disk medium 11 has also been completed. At this time, the address translation information 32 of volatile memory 29 registers the logical address A1 and physical address PA1 of data D1, as shown in Figure 4(a). Figure 4 is a diagram showing the contents of the address translation information 32. The address translation information 33 of volatile memory 29 is empty, as shown in Figure 5(a). Figure 5 is a diagram showing the contents of the address translation information 33. Data D1 is temporarily stored in volatile memory 29.

[0059] The controller 30 waits until a write command is received (No in S1). When the controller 30 receives a write command (Yes in S1), it accesses the volatile memory 29 and updates the address translation information 32 according to the content of the write command. For example, when a write command CM2 containing logical address A2 and data D2 is received, the controller 30 registers logical address A2 in the address translation information 32, as shown in Figure 4(b). At this time, data D1 and data D2 are temporarily stored in the volatile memory 29. Information indicating that the logical addresses of data D1 and data D2 are A1 and A2, respectively, may be stored in the volatile memory 29.

[0060] The controller 30 determines the physical address PA2 of the write destination corresponding to the logical address A2 of data D2 (S2). As shown in Figure 4(c), the controller 30 registers the physical address PA2 in the address translation information 32, associating it with the logical address A2. This completes the command processing of the write command CM2.

[0061] The controller 30 refers to the address translation information 32 of the volatile memory 29 and identifies that the data written immediately before data D2 is D1 and its logical address is A1, as shown in Figure 4(c). The controller 30 retrieves data D1 and logical address A1 from the volatile memory 29 (S3).

[0062] The controller 30 uses at least a portion of the data D1 as the encryption key (S4). The controller 30 may use a portion of the beginning of the data D1 as the encryption key, or it may use the entire data D1 as the encryption key. In this case, the controller 30 sets the logical address of the encryption key to A1.

[0063] The controller 30 encrypts data D2 with an encryption key and generates encrypted data D2a (S5). The logical address A1 of the encryption key, encrypted data D2a, and logical address A2 are stored in volatile memory (S6). At this time, since there is a possibility that the encrypted data D2a will be saved to non-volatile memory 28, the controller 30 may register logical address A2 in the address translation information 33 of volatile memory 29, as shown in Figure 5(b).

[0064] The controller 30 determines whether or not a power outage has occurred (S7). For example, the controller 30 may determine that no power outage has occurred if the power supplied from the power supply circuit 20 exceeds a threshold, and determine that a power outage has occurred if the power supplied from the power supply circuit 20 is below the threshold.

[0065] If a power outage occurs (Yes in S7), the controller 30 determines the physical address FA2 of the backup destination corresponding to the logical address A2 of the encrypted data D2a (S8). As shown in Figure 5(c), the controller 30 associates the physical address FA2 with the logical address A2 and registers it in the address translation information 33. The controller 30 stores the address translation information 33 in the management information storage area of ​​the non-volatile memory 28 within the controller 30. At the same time, the controller 30 backs up the logical address A1 of the encryption key, the encrypted data D2a, the logical address A2, and the address translation information 32 to the storage area of ​​the non-volatile memory 28 (S9). The controller 30 stores the logical address A1 of the encryption key, the encrypted data D2a, the logical address A2, and the address translation information 32 in the physical address FA2 of the non-volatile memory 28. This allows the encrypted data D2a corresponding to the data D2 being written to be backed up non-volatilely.

[0066] If no power outage has occurred (No in S7), the controller 30 erases logical address A2 and physical address FA2 from the address translation information 33, returning it to the empty state shown in Figure 5(a), and writes data D2 to the disk medium 11 (S10). The controller 30 writes data D2 to physical address PA2 on the disk medium 11. This completes the write process for data D2.

[0067] Disk drive 1 may perform the operations shown in Figure 6 when it comes to restoring power. Figure 6 is a flowchart showing the operations of disk drive 1 when it comes to restoring power.

[0068] The controller 30 waits until power is restored (No in S11). The controller 30 may determine that power has not been restored if the power supplied from the power supply circuit 20 is below a threshold, or that power has been restored if the power supplied from the power supply circuit 20 exceeds a threshold.

[0069] When power is restored (Yes in S11), the controller 30 loads address translation information 33 from the management information storage area of ​​the non-volatile memory 28 within the controller 30 to the volatile memory 28. The controller 30 refers to the address translation information 33 and identifies the backup destination in the non-volatile memory 28 (S12). As shown in Figure 5(c), the controller 30 may identify the physical address of the non-volatile memory 28 as FA2 as the backup destination.

[0070] The controller 30 retrieves logical address A1, encrypted data D2a, logical address A2, and address translation information 32 from the backup location in the non-volatile memory 28 (S13). The controller 30 may load logical address A1, encrypted data D2a, logical address A2, and address translation information 32 from the physical address of the non-volatile memory 28 from FA2 to the volatile memory 28. The controller 30 recognizes logical address A2 as the logical address of encrypted data D2a and logical address A1 as the logical address of the encryption key, according to the address translation information 33.

[0071] The controller 30 determines the physical address PA1 corresponding to the logical address A1 of the encryption key, according to the address translation information 32 (S14).

[0072] The controller 30 accesses the physical address PA1 of the disk medium 11 and reads data D1 from the physical address PA1 of the disk medium 11 (S15).

[0073] The controller 30 reconstructs the encryption key using at least a portion of the data D1 (S16). If the controller 30 used the leading portion of the data D1 as the encryption key in S4, it reconstructs the leading portion of the read data D1 as the encryption key in S15. If the controller 30 used the entire data D1 as the encryption key in S4, it reconstructs the entire data D1 read as the encryption key in S15.

[0074] The controller 30 decrypts the encrypted data D2a using the encryption key regenerated in S16 (S17).

[0075] If the controller 30 is successful in decryption (Yes in S18), it obtains the decrypted data D2. The controller 30 determines the physical address PA2 of the write destination corresponding to the logical address A2 according to the address translation information 32 (S19).

[0076] The controller 30 accesses the physical address PA2 of the disk medium 11 and writes data D2 to the physical address PA2 of the disk medium 11 (S20). This completes the writing of data D2, which was saved when the power was cut off, to the disk medium 11.

[0077] If the controller 30 fails to decrypt (No in S18), it reflects the decryption failure in the SMART data (S21). This allows the loss of data D2 due to decryption failure to be managed.

[0078] As described above, in this embodiment, when the power supply to the disk device 1 is cut off, the data being written is encrypted with the previously written encryption key and saved to the non-volatile memory 28 in the controller 30. This ensures both security and the saving of data being written, and allows for proper data saving.

[0079] Furthermore, in this embodiment, the controller 30 in the disk device 1 is configured as a system-on-a-chip, and the non-volatile memory 28 is mounted within the controller 30 as part of the system-on-a-chip. This ensures that the non-volatile memory 28 cannot be physically accessed without destroying the system-on-a-chip, and that the encryption of the written data cannot be decrypted without using the data on the disk medium 11 as an encryption key, thereby reliably guaranteeing the security of the data being backed up.

[0080] While several embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents. [Explanation of Symbols]

[0081] 1 disk drive, 11 disk media, 26 processors, 28 non-volatile memory, 29 volatile memory, 30 controllers.

Claims

1. The first data is written to a disk medium, A volatile memory capable of temporarily storing the first data and the second data, A controller including a processor that acquires at least a portion of the first data as an encryption key when the power is cut off and encrypts the second data with the encryption key, and a non-volatile memory that stores the encrypted second data when the power is cut off, A disk drive equipped with a disk drive.

2. The controller is configured as a system-on-a-chip. The disk device according to claim 1.

3. The non-volatile memory further stores the address information of the first data and the address information of the second data when the power is cut off. The disk device according to claim 1.

4. The first data and the second data are both data after command processing has been completed. The volatile memory is further capable of storing address translation information including the logical address of the first data and the logical address of the second data. The first data is the data registered in the address translation information immediately before the second data. The disk device according to claim 3.

5. The non-volatile memory reads the encryption key from the disk medium, reads the encrypted second data from the non-volatile memory, and decrypts the encrypted second data using the encryption key when power is restored. The disk device according to claim 3.

6. The non-volatile memory writes the decoded second data to the disk medium when power is restored. The disk device according to claim 5.

Citation Information

Patent Citations

  • Efficient energy recovery in disk drive during power loss

    US10374528B2

  • Write data protection at emergency power off

    US10996740B2

  • Storage Device and Data Save Method

    US20170024297A1