Storage device
The storage device enhances security by using encrypted keys and multiple password access to manage data encryption, ensuring secure data access and integrity.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-03
- Publication Date
- 2026-04-09
AI Technical Summary
Existing storage devices lack enhanced security measures for data encryption, particularly in the context of increasing personal information storage, necessitating improved security protocols.
A storage device with a non-volatile memory that stores encryption keys and data keys encrypted with these keys, and a storage controller that manages access using multiple passwords to generate and store encrypted encryption keys, ensuring secure data access and management.
The solution maintains an encrypted link between updated data keys and passwords, enhancing the security of the storage device by preventing unauthorized access and maintaining data integrity.
Smart Images

Figure 0007843157000001 
Figure 0007843157000002 
Figure 0007843157000003
Abstract
Description
Technical Field
[0001] The present invention relates to a storage device.
Background Art
[0002] A storage device is a device that stores data under the control of a host device such as a computer, a smartphone, a smart pad, etc. Storage devices include devices that store data on a magnetic disk such as a hard disk drive (HDD), devices that store data in a semiconductor memory, particularly a non-volatile memory, such as a solid state drive (SSD), a memory card, etc.
[0003] As data security issues are being emphasized, a function for encrypting data stored in a storage device is provided. As more and more personal information is stored in such devices, it is important to improve the security of storage devices that use encryption.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The present invention has been made in view of the above prior art, and an object of the present invention is to provide a storage device with improved or enhanced security.
Means for Solving the Problems
[0006] A storage device according to one aspect of the present invention, made to achieve the above objective, comprises: a non-volatile memory that stores an encryption key and a data key encrypted with the encryption key, and on which data is written using the data key and data is read using the data key; and a storage controller that receives a first security setting command that allows access to the data key using a first password, and in response to the first security setting command, generates a first key based on the first password, encrypts the encryption key with the first key to generate a first encrypted encryption key, encrypts the first key with the encryption key to generate an encrypted first key, and stores the first encrypted encryption key and the encrypted first key in the non-volatile memory.
[0007] To achieve the above objective, another embodiment of the present invention provides a storage device that stores an encrypted first key generated by encrypting a first key generated based on a first password with an encryption key, a first encrypted encrypted key generated by encrypting the encryption key with the first key, and an encrypted data key generated by encrypting a data key with the encryption key; and a storage controller that controls the operation of the nonvolatile memory, wherein the storage controller receives a first security setting command that blocks access to the data key using the first password, deletes the first encrypted encrypted key stored in the nonvolatile memory in response to the first security setting command, receives a second security setting command that allows access to the data key using the first password, and stores the first encrypted encrypted key in the nonvolatile memory in response to the second security setting command.
[0008] A storage device according to yet another aspect of the present invention made to achieve the above objectives includes: a non-volatile memory that stores a first encryption key and a first encrypted data key encrypted with the first encryption key, and on which data is written using the data key and data is read using the data key; and a storage controller that receives a first security setting command that enables access to the data key using a plurality of different first passwords, and in response to the first security setting command, generates a plurality of first keys based on each of the plurality of first passwords, encrypts the first encryption key with each of the plurality of first keys to generate a plurality of first encrypted encryption keys, encrypts each of the plurality of first keys with the first encryption key to generate a plurality of encrypted first keys, and stores the plurality of first encrypted encryption keys and the plurality of encrypted first keys in the non-volatile memory. [Effects of the Invention]
[0009] According to the storage device of the present invention, since the first key encrypted with the encryption key is stored, if the data key or encryption key is updated, the encrypted link between the updated data key and the first password is maintained using the encrypted first key. Therefore, the security of the storage device is improved or enhanced. [Brief explanation of the drawing]
[0010] [Figure 1] This is a diagram illustrating a storage system according to one embodiment. [Figure 2] This is a diagram illustrating the AES engine shown in Figure 1. [Figure 3] This is a diagram illustrating the operation of a storage device according to one embodiment. [Figure 4] This is a diagram illustrating the operation of a storage device according to one embodiment. [Figure 5] This is a diagram illustrating the operation of a storage device according to one embodiment. [Figure 6]It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 7] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 8] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 9] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 10] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 11] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 12] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 13] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 14] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 15] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 16] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 17] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 18] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 19] It is a diagram for explaining the operation of a storage device according to an embodiment. [Figure 20] It is a diagram for explaining a storage system according to an embodiment. [Figure 21a] It is a diagram for explaining a storage system according to an embodiment. [Figure 21b] It is a diagram for explaining a storage system according to an embodiment. [Figure 22] It is a diagram for explaining a storage system according to an embodiment. [Figure 23] It is a diagram for explaining a storage system according to an embodiment. [Figure 24] It is a diagram for explaining a storage system according to an embodiment. [Figure 25] It is a diagram for explaining a system to which a storage device according to an embodiment is applied.
Embodiments for Carrying Out the Invention
[0011] Hereinafter, specific examples of embodiments for carrying out the present invention will be described in detail while referring to the drawings.
[0012] FIG. 1 is a diagram for explaining a storage system according to an embodiment. FIG. 2 is a diagram for explaining the AES (Advanced Encryption Standard) engine of FIG. 1.
[0013] Referring to FIGS. 1 and 2, the storage system 1 includes a host 100 and a storage device 200. Further, the storage device 200 includes a storage controller 210 and a non-volatile memory (NVM) 22 The host 100 includes a host controller 110 and a host memory 120 according to an embodiment of the present invention. The host memory 120 functions as a buffer memory for temporarily storing data transmitted to the storage device 200 or data transmitted from the storage device 200.
[0014] The storage device 200 includes a storage medium for storing data in response to requests from the host 100. For example, the storage device 200 includes at least one of the following: an SSD (Solid State Drive), embedded memory, and removable external memory. If the storage device 200 is an SSD, it conforms to the NVMe (non-volatile memory express) standard. If the storage device 200 is embedded memory or external memory, it conforms to the UFS (universal flash storage) or eMMC (embedded multi-media card) standard. The host 100 and the storage device 200 generate and transmit packets according to their respective adopted standard protocols.
[0015] If the non-volatile memory 220 of the storage device 200 includes flash memory, the flash memory includes 2D NAND memory arrays and 3D (or vertical) NAND (VNAND) memory arrays. As another example, the storage device 200 includes various other types of non-volatile memory. For example, the storage device 200 may use MRAM (Magnetic RAM), Spin-Transfer Torgue MRAM, Conductive Bridging RAM (CBRAM), FeRAM (Ferroelectric RAM), PRAM (Phase RAM), Resistive RAM, and various other types of memory.
[0016] In one embodiment, the host controller 110 and the host memory 120 are implemented as separate semiconductor chips. Alternatively, in some embodiments, the host controller 110 and the host memory 120 are integrated on the same semiconductor chip. For example, the host controller 110 is one of many modules provided in an application processor, and the application processor is implemented as a system on a chip (SoC). The host memory 120 is either embedded memory provided within the application processor, or a non-volatile memory or memory module located outside the application processor.
[0017] The host controller 110 manages the operation of saving data from the buffer area 121 (e.g., recorded data) to the non-volatile memory 220, or saving data from the non-volatile memory 220 (e.g., read data) to the buffer area 121.
[0018] The storage controller 210 includes a host interface 211, a memory interface 212, and a CPU (central processing unit) 213. The storage controller 210 further includes working memory 214, a packet manager 215, buffer memory 216, an ECC (error correction code) 217 engine, and an AES (advanced encryption standard) 218 engine. The engines, controllers, modules, and managers described herein are implemented using hardware, hardware and firmware, or a selective combination of hardware and software with firmware, and are programmed and / or configured to perform the functions described herein.
[0019] The host interface 211 sends and receives packets with the host 100. Packets transmitted from the host 100 to the host interface 211 include commands or data recorded in the non-volatile memory 220, while packets transmitted from the host interface 211 to the host 100 include responses to commands or data read from the non-volatile memory 220. The memory interface 212 transmits data to be recorded in the non-volatile memory 220 or receives data read from the non-volatile memory 220. Such a memory interface 212 is implemented to comply with standard conventions such as Toggle or ONFI.
[0020] The working memory 214 operates in accordance with the control of the CPU 213 and is used as working memory, buffer memory, cache memory, etc. For example, the working memory 214 can be implemented as volatile memory such as DRAM or SRAM, or as non-volatile memory such as PRAM or flash memory.
[0021] The flash translation layer (FTL) 214a is loaded into the working memory 214. The CPU 213 controls data recording and reading operations to and from the non-volatile memory 220 by executing the flash translation layer 214a. The flash translation layer 214a performs various functions such as address mapping, wear leveling, and garbage collection. Address mapping is the operation of changing a logical address received from the host into a physical address used to actually store data in the non-volatile memory 220. Wear leveling is a technique to prevent excessive degradation of a particular block by ensuring that blocks in the non-volatile memory 220 are used uniformly, and is exemplified by firmware technology that balances the erase count of physical blocks. Garbage collection is a technique to secure usable capacity in the non-volatile memory 220 by erasing existing blocks after copying the valid data of a block to a new block.
[0022] The hash algorithm 214b is implemented in firmware or software and loaded into working memory 214. Alternatively, contrary to the diagram, the hash algorithm 214b is implemented in hardware. The hash algorithm 214b generates a hash value of the password provided by host 100. Various hash algorithms described here are performed using publicly known types of hash algorithms.
[0023] The packet manager 215 generates packets according to the interface protocol agreed upon with the host 100, or passes various information from packets received from the host 100. The buffer memory 216 temporarily stores data recorded in the non-volatile memory 220 or data read from the non-volatile memory 220. The buffer memory 216 is configured to be located within the storage controller 210, but it may also be located outside the storage controller 210.
[0024] The ECC engine 217 performs error detection and correction functions for read data read from the non-volatile memory 220. More specifically, the ECC engine 217 generates a parity bit for the data to be written to the non-volatile memory 220, and this generated parity bit is stored in the non-volatile memory 220 together with the data to be written. When reading data from the non-volatile memory 220, the ECC engine 217 corrects errors in the read data using the parity bit read from the non-volatile memory 220 along with the read data, and outputs the read data with the errors corrected.
[0025] The AES engine 218 performs at least one of the encryption and decryption operations on data input to the storage controller 210 using a symmetric-key algorithm. The AES engine 218 performs data encryption and decryption using the AES (Advanced Encryption Standard) algorithm and includes an encryption module 218a and a decryption module 218b. Figure 2 shows the encryption module 218a and decryption module 218b implemented as separate modules, but it is also possible to implement a single module within the AES engine 218 that can perform both encryption and decryption.
[0026] The non-volatile memory 220 includes a meta-area 222 and a user area 224. The meta-area 222 is an area where keys related to the security of the storage device 200 are stored. The meta-area 222 stores encryption keys encrypted with encryption key KEK or other keys, and data keys E_DEK encrypted with encryption key KEK. Alternatively, the meta-area 222 stores encryption keys encrypted with other keys and data keys E_DEK encrypted with encryption key KEK (except for storing encryption key KEK). The user area 224 is an area where data E_DATA encrypted with data keys is stored.
[0027] For example, the AES engine 218 receives data transmitted from the host 100. The encryption module 218a generates encrypted data E_DATA by encrypting the data transmitted from the host 100 using a data key. The encrypted data E_DATA is transmitted from the AES engine 218 to the non-volatile memory 220 and stored in the user area 224 of the non-volatile memory 220. Known types of AES encryption algorithms, for example, use fixed blocks of 128 bits and keys of 128, 192, or 256 bits for encryption performed by the various AES engines described herein.
[0028] The AES engine 218 receives the stored encrypted data E_DATA from the non-volatile memory 220. The decryption module 218b decrypts the encrypted data E_DATA transmitted from the non-volatile memory 220 using the data key and generates new data. The data is then transmitted from the AES engine 218 to the host 100.
[0029] Figures 3 to 8 are diagrams illustrating the operation of a storage device according to one embodiment.
[0030] The storage device 200 is set with a first password MPW (for example, a master password) by the manufacturer.
[0031] Referring to Figure 3, the storage device 200 according to this embodiment receives a security setting command CMD_1 that allows access to the data key DEK using the first password MPW (S110).
[0032] Specifically, the security setting command CMD_1 includes the security privileges for the second password UPW and the second password UPW (e.g., user password). The security privilege for the second password UPW is level 1. The security setting command CMD_1 also includes an identifier indicating the setting of the second password UPW.
[0033] If the security privilege of the second password UPW is at level 1 (High), the storage device 200 will be unlocked from the locked state by either the first password MPW or the second password UPW. Therefore, host 100 can read data stored in the storage device 200 or save data to the storage device 200. If the security privilege of the second password UPW is at level 2, the storage device 200 will be changed from the locked state to the unlocked state only by the second password UPW. That is, if the security privilege is at level 2, host 100 will use the first password MPW to change the storage device 200 to the unlocked state, preventing it from reading data stored in the storage device 200 or saving data to the storage device 200 using the first password MPW.
[0034] As described above, the storage controller 210 encrypts the data with the data key DEK and stores the encrypted data E_DATA in the non-volatile memory 220, and decrypts the data E_DATA encrypted with the data key DEK and reads the encrypted data E_DATA stored in the non-volatile memory 220. In other words, if the security privilege of the second password UPW is at level 1, access to the data key DEK is permitted using either the first password MPW or the second password UPW. If the security privilege of the second password UPW is at level 2, access to the data key DEK is blocked using the first password MPW, and access to the data key DEK is permitted using the second password UPW.
[0035] In one embodiment, the security setting command CMD_1 is implemented in the form of the SECURITY SET PASSWORD command shown in Figure 4, in accordance with the ATA (Advanced Technology Attachment) standard. Here, the first security level is High, and the second security level is Maximum. The detailed configuration of the SECURITY SET PASSWORD command is described in the ATA standard document, so a detailed explanation is omitted here.
[0036] In response to the security setting command CMD_1, the storage controller 210 generates a first encrypted encryption key E_MKEK, a second encrypted encryption key E_UKEK, an encrypted first key E_MKPK, and an encrypted second key E_UKPK, and stores the first encrypted encryption key E_MKEK, the second encrypted encryption key E_UKEK, and the encrypted first key E_MKPK in the meta area 222 of the non-volatile memory 220 (S120).
[0037] Specifically, referring to Figure 5, the hash algorithm 214b generates the second key UKPK based on the second password UPW (A). The second key UKPK is the hash value of the second password UPW. The AES engine 218 encrypts the encryption key KEK with the second key UKPK to generate the second encrypted encryption key E_UKEK (B). The second encrypted encryption key E_UKEK is stored in the meta-area 222 of the non-volatile memory 220. If the encryption key KEK is stored in the meta-area 222 of the non-volatile memory 220, the storage controller 210 deletes the encryption key KEK and stores the second encrypted encryption key E_UKEK.
[0038] As described above, the encrypted data key E_DEK is stored in the meta-area 222 of the non-volatile memory 220, and the encrypted data key E_DEK is generated by the AES engine 218 by encrypting the data key DEK with the encryption key KEK (C). Therefore, access to the data key DEK is permitted using the second password UPW.
[0039] The hash algorithm 214b generates the first key MKPK based on the first password MPW (D). The first key MKPK is the hash value of the first password MPW. The AES engine 218 encrypts the encryption key KEK with the first key MKPK to generate the first encrypted encryption key E_MKEK (E). The first encrypted encryption key E_MKEK is stored in the meta area 222 of the non-volatile memory 220. Therefore, access to the data key DEK is permitted using the first password MPW.
[0040] Furthermore, the AES engine 218 encrypts the first key MKPK with the encryption key KEK to generate an encrypted first key E_MKPK (F). The encrypted first key E_MKPK is stored in the meta area 222 of the non-volatile memory 220. That is, the first key MKPK is encrypted with the encryption key KEK, and the encryption key KEK is encrypted with the first key MKPK. Ordinal numbers such as "first," "second," and "third" are simply used as labels for specific elements, stages, etc., to distinguish them from one another. Terms that are not described using "first," "second," etc. in the specification may be referred to as "first" or "second" in the claims. Also, terms that are referred to as specific ordinal numbers (e.g., "first" in the claims) may be described elsewhere as other ordinal numbers (e.g., "second" in the specification or claims).
[0041] Figures 6 to 8 are diagrams illustrating the operation of the storage device after step S120.
[0042] Referring to Figures 6 and 7, the storage device 200 receives the first password MPW (S210). Next, the storage device 200 receives the data DATA and the write command CMD_W (S215).
[0043] In response to the write command CMD_W, the hash algorithm 214b generates the first key MKPK based on the first password MPW (S220_1). The AES engine 218 decrypts the first encrypted encryption key E_MKEK stored in the non-volatile memory 220 with the first key MKPK to generate the encryption key KEK (S230_1). The AES engine 218 decrypts the encrypted data key E_DEK stored in the non-volatile memory 220 with the encryption key KEK to generate the data key DEK (S240_1). The AES engine 218 encrypts the data DATA with the encryption key KEK and stores the encrypted data E_DATA in the non-volatile memory 220 (S270).
[0044] Referring to Figures 6 and 8, the storage device 200 receives the second password UPW (S210). Next, the storage device 200 receives the data DATA and the write command CMD_W (S215).
[0045] In response to the write command CMD_W, the hash algorithm 214b generates the second key UKPK based on the second password UPW (S220_2). The AES engine 218 decrypts the second encrypted encryption key E_UKEK stored in the non-volatile memory 220 using the second key UKPK to generate the encryption key KEK (S230_2). The AES engine 218 decrypts the encrypted data key E_DEK stored in the non-volatile memory 220 using the encryption key KEK to generate the data key DEK (S240_2). The AES engine 218 encrypts the data DATA with the encryption key KEK and stores the encrypted data E_DATA in the non-volatile memory 220 (S270).
[0046] Figures 9 to 13 are diagrams illustrating the operation of a storage device according to one embodiment. Figures 9 to 13 are diagrams illustrating the operation of the storage device after step S120.
[0047] Referring to Figures 9 to 11, the storage device 200 according to this embodiment receives a security release command CMD_2 from the host 100 that allows access to the data key DEK without using the first password MPW or the second password UPW (S130).
[0048] The security release command CMD_2 includes either the first password MPW or the second password UPW, and a value that identifies whether the one is the first password MPW or the second password UPW. The non-volatile memory 220 stores a first value generated based on the first password MPW and a second value generated based on the second password UPW. The storage controller 210 performs the security release operation based on the first password MPW and the first value included in the security release command CMD_2 if the security release command CMD_2 includes the first password MPW, and based on the second password UPW and the second value included in the security release command CMD_2 if the security release command CMD_2 includes the second password UPW.
[0049] In one embodiment, the security disable command CMD_2 is implemented in the form of the SECURITY DISABLE PASSWORD command shown in Figure 9, in accordance with the ATA standard. The detailed configuration of the SECURITY DISABLE PASSWORD command is described in the ATA standard document, so a detailed explanation is omitted here.
[0050] In response to the security release command CMD_2, the storage controller 210 deletes the second encrypted encryption key E_UKEK stored in the meta-area 222 of the non-volatile memory 220 (S140). As a result, access to the data key DEK using the second password UPW is blocked. For example, the second password UPW is deactivated or reset so that it is no longer used to access the data key (DEK). The first password MPW is not changed.
[0051] Furthermore, the storage controller 210 generates an encryption key KEK and stores it in the meta-area 222 of the non-volatile memory 220 (S150). In some embodiments, after generating and storing the encryption key KEK in the meta-area 222 in response to the security release command CMD_2, the first encrypted encryption key E_MKEK and the second encrypted encryption key E_UKEK stored in the meta-area 222 of the non-volatile memory 220 are all deleted.
[0052] If the security release command CMD_2 includes the first password MPW, the storage controller 210 generates the encryption key KEK using the first password MPW and the first encrypted encryption key E_MKEK (for example, before the first encrypted encryption key E_MKEK is deleted). If the security release command CMD_2 includes the second password UPW, the storage controller 210 generates the encryption key KEK using the second password UPW and the second encrypted encryption key E_UKEK (for example, before the first encrypted encryption key E_MKEK is deleted). Steps S140 and S150 occur simultaneously (for example, if the security release command CMD_2 includes the first password MPW, the first encrypted encryption key E_MKEK is deleted simultaneously while the encryption key KEK is generated, and if the security release command CMD_2 includes the second password UPW, the second encrypted encryption key E_UKEK is deleted simultaneously while the encryption key KEK is generated) or one of the two occurs first.
[0053] Alternatively, referring to Figures 12 and 13, the storage device 200 according to this embodiment receives a security deletion command CMD_2' from the host 100 to delete the data E_DATA stored in the non-volatile memory 220 (S150).
[0054] The security deletion command CMD_2' includes either the first password MPW or the second password UPW, and a value that identifies whether either one is the first password MPW or the second password UPW. The storage controller 210 performs the security deletion operation based on the first password MPW and the first value if the security deletion command CMD_2' includes the first password MPW, and based on the second password UPW and the second value if the security deletion command CMD_2' includes the second password UPW.
[0055] In one embodiment, the security deletion command CMD_2' is implemented in the form of the SECURITY ERASE UNIT command shown in Figure 13, in accordance with the ATA standard. The detailed configuration of the SECURITY ERASE UNIT command is described in the ATA standard document, so a detailed explanation is omitted here.
[0056] In response to the security deletion command CMD_2', the storage controller 210 deletes the second encrypted encryption key E_UKEK stored in the meta area 222 of the non-volatile memory 220 and the encrypted data E_DATA stored in the user area 224 of the non-volatile memory 220 (S160). The first password MPW is not changed.
[0057] Furthermore, in response to the security deletion command CMD_2', the storage controller 210 deletes the first encrypted encryption key E_MKEK and the encrypted data key E_DEK. The storage controller 210 generates a new data key and stores the new encrypted data key E_DEK', encrypted with the encryption key KEK, in the meta-area 222 of the non-volatile memory 220.
[0058] Figures 14 to 17 are diagrams illustrating the operation of a storage device according to one embodiment. Figures 14 to 17 are diagrams illustrating the operation of the storage device after step S140 or step S160.
[0059] Referring to Figures 14 to 16, the storage device 200 according to this embodiment receives a security setting command CMD_3 from the host 100 that allows access to the data key DEK using the first password MPW (S310).
[0060] The security setting command CMD_3 includes the second password UPW' and its security privileges. The security privilege for the second password UPW' is level 2. Therefore, as described above, access to the data key DEK is blocked using the first password MPW, and access to the data key DEK is permitted using the second password UPW'. The security setting command CMD_3 also includes an identifier indicating the setting of the second password UPW'.
[0061] In one embodiment, the security setting command CMD_3 is implemented in the form of the SECURITY SET PASSWORD command shown in Figure 15, in accordance with the ATA standard. Here, the first security level is High, and the second security level is Maximum. The detailed configuration of the SECURITY SET PASSWORD command is described in the ATA standard documentation, so a detailed explanation is omitted here.
[0062] In response to the security setting command CMD_3, the storage controller 210 generates a second encrypted encryption key E_UKEK' and encryption key KEK using the second key UKPK', stores the second encrypted encryption key E_UKEK' and encryption key KEK in the meta-area 222 of the non-volatile memory 220, and deletes the first encrypted encryption key E_MKEK stored in the meta-area 222 of the non-volatile memory 220 (S320).
[0063] Therefore, referring to Figure 17, the AES engine 218 does not generate the encryption key KEK using the first password MPW, and access to the data key DEK using the first password MPW is blocked. The first password MPW is not changed.
[0064] Figures 18 and 19 are diagrams illustrating the operation of a storage device according to one embodiment. Figures 18 and 19 are diagrams illustrating the operation of the storage device after steps S130 and S140 or S150 and S160 are performed after step S320, and the second encrypted encryption key E_UKEK' stored in the meta area 222 of the non-volatile memory 220 has been deleted.
[0065] Referring to Figures 18 and 19, the storage device 200 according to this embodiment receives a security setting command CMD_4 that allows access to the data key DEK using the first password MPW (S410). The security setting command CMD_4 includes the security privileges for the second password UPW" and the second password UPW". The security privilege for the second password UPW" is at level 1. Therefore, as described above, access to the data key DEK is permitted using the first password MPW and the second password UPW".
[0066] In response to the security setting command CMD_4, the storage controller 210 generates a second encrypted encryption key E_UKEK using the second key UKPK and encryption key KEK, generates the first key MKPK and the first encrypted encryption key E_MKEK, stores the second encrypted encryption key E_UKEK and the first encrypted encryption key E_MKEK in the meta-area 222 of the non-volatile memory 220, and deletes the encryption key KEK stored in the meta-area 222 of the non-volatile memory 220 (S420).
[0067] Specifically, referring to Figure 19, the hash algorithm 214b generates the second key UKPK" based on the second password UPW" (A). The second key UKPK" is the hash value of the second password UPW". The AES engine 218 encrypts the encryption key KEK with the second key UKPK" to generate the second encrypted encryption key E_UKEK" (B). The second encrypted encryption key E_UKEK" is stored in the meta-area 222 of the non-volatile memory 220. If the encryption key KEK is already stored in the meta-area 222 of the non-volatile memory 220, the storage controller 210 deletes the encryption key KEK and stores the second encrypted encryption key E_UKEK". Therefore, access to the data key DEK using the second password UPW" is permitted.
[0068] The AES engine 218 decrypts the encrypted first key E_MKPK with the encryption key KEK to generate the first key MKPK (F'). The AES engine 218 then encrypts the first key MKPK with the encryption key KEK to generate the encrypted first key E_MKPK (F). Therefore, access to the data key DEK is permitted using the first password MPW.
[0069] In one embodiment of the storage device, the first key MKPK is encrypted with the encryption key KEK, and the encryption key KEK is encrypted with the first key MKPK. Therefore, even if the state changes from one where access to the data key DEK is blocked in response to a security setting command to one where access to the data key DEK is allowed using the first password MPW, the encryption link between the encryption key KEK and the first key MKPK is re-established.
[0070] Furthermore, in one embodiment, the storage device stores the first key E_MKPK encrypted with the encryption key KEK. Therefore, when the data key DEK or encryption key KEK is updated, the encrypted link between the updated data key DEK and the first password MPW is maintained using the encrypted first key E_MKPK. As a result, the security of the storage device 200 is improved or enhanced.
[0071] Figures 20 to 22 are diagrams illustrating a storage system according to one embodiment. For the sake of explanation, the focus will be on the differences from the explanation using Figures 1 to 19.
[0072] Referring to Figures 20 and 21, in the storage system 2 according to this embodiment, the data key DEK is accessed using a plurality of first keys (KEY_1 to KEY_N). Each of the plurality of first keys (KEY_1 to KEY_N) is described here as a subkey or individual key. For example, it is referred to as a first subkey or first individual key.
[0073] The storage controller 210, in response to a security setting command that allows access to the data key DEK using the first keys (KEY_1 to KEY_N) for each of the multiple first keys (KEY_1 to KEY_N), encrypts the first keys (KEY_1 to KEY_N) with the encryption key KEK to generate encrypted first keys (E_KEY_1 to E_KEY_N) (A), and encrypts the encryption key KEK with the first keys (KEY_1 to KEY_N) to generate first encrypted encryption keys (E_KEK_1 to E_KEK_N) (B). Here, the encrypted data key E_DEK is generated by encrypting the data key DEK with the encryption key KEK (C). The storage controller 210 stores the first encrypted encryption keys (E_KEK_1 to E_KEK_N), the encrypted first keys (E_KEY_1 to E_KEY_N), and the encrypted data key E_DEK in the meta area 222 of the non-volatile memory 220.
[0074] Each of the multiple primary keys (KEY_1 to KEY_N) is generated from multiple primary passwords. Each specific password within the multiple primary passwords is described here as a sub-password or individual password.
[0075] The storage controller 210 deletes the first encrypted encryption keys (E_KEK_1 to E_KEK_N) for each of the multiple first keys (KEY_1 to KEY_N) in response to a security setting command that blocks access to the data key DEK using the first keys (KEY_1 to KEY_N).
[0076] The storage controller 210, in response to a security setting command that allows access to the data key DEK using each of the multiple primary keys (KEY_1 to KEY_N), generates an encryption key KEK using the encrypted primary keys (E_KEY_1 to E_KEY_N) and then generates the first encrypted encryption keys (E_KEK_1 to E_KEK_N) again. Each specific primary encrypted encryption key (E_KEK_1 to E_KEK_N) is described here as a subkey or individual key. For example, one primary encrypted encryption key is referred to as the second subkey or second individual key. Each specific encrypted primary key (E_KEY_1 to E_KEY_N) is described here as a subkey or individual key. For example, one encrypted primary key is referred to as the third subkey or third individual key.
[0077] In one embodiment of the storage system, the storage device 200 stores encrypted first keys (E_KEY_1 to E_KEY_N). Therefore, in response to a security setting command that allows or denies access to the data key DEK, the storage device 200 denies or again allows access from the first keys (KEY_1 to KEY_N) to the encryption key KEK.
[0078] Referring to Figure 22, the data key DEK is encrypted with multiple encryption keys (KEK_1~KEK_M) (C). Each of the multiple encryption keys (KEK_1~KEK_M) is encrypted with multiple primary keys (KEY_1_1~KEY_M_N) (A), and the multiple primary keys (KEY_1_1~KEY_M_N) are encrypted (B). In response to a security setting command that allows or denies access to the data key DEK, access from the multiple primary keys (KEY_1_1~KEY_M_N) to the multiple encryption keys (KEK_1~KEK_M) is either blocked or allowed.
[0079] The number of first keys (KEY_1_1~KEY_1_N) that form an encryption link with each encryption key (KEK_1~KEK_M) may be the same or different from each other. Furthermore, although this drawing shows one data key DEK, the present invention is not limited to this and may include multiple data keys. Each data key forms an encryption link with multiple encryption keys. Also, the number of multiple encryption keys that form an encryption link with each data key may be the same or different from each other.
[0080] Furthermore, unlike the diagram, each first key (KEY_1_1 to KEY_M_N) forms an encryption link with one encryption key (KEK_1 to KEK_M) or multiple encryption keys (KEK_1 to KEK_M). For example, first key KEY_1_1 forms an encryption link with encryption key KEK_1, first key KEY_1_2 forms an encryption link with encryption keys (KEK_1, KEK_2), and first key KEY_1_3 forms an encryption link with encryption keys (KEK_1, KEK_2, KEK_4).
[0081] Figures 23 and 24 are diagrams illustrating a storage system according to one embodiment. For the sake of explanation, the focus will be on the differences from the explanation using Figures 1 to 21.
[0082] Referring to Figures 23 and 24, the storage system 3 according to this embodiment includes a plurality of storage devices (200_1 to 200_N).
[0083] The storage device (200_1~200_N) includes a storage controller (210_1~210_N) and non-volatile memory (220_1~220_N). The storage controller (210_1~210_N) encrypts the first key (KEY_1~KEY_N) with the encryption key (KEK_1~KEK_N) to generate encrypted first keys (E_KEY_1~E_KEY_N) (A). The storage controller (210_1~210_N) encrypts the encryption key (KEK_1~KEK_N) with the first key (KEY_1~KEY_N) to generate encrypted encryption keys (E_KEK_1~E_KEK_N) (B). The storage controllers (210_1~210_N) encrypt the data keys (DEK_1~DEK_N) with the encryption keys (KEK_1~KEK_N) to generate encrypted data keys (E_DEK_1~E_DEK_N) (C).
[0084] The metadata area (222_1~222_N) of the non-volatile memory (220_1~220_N) stores encrypted encryption keys (E_KEK_1~E_KEK_N), encrypted primary keys (E_KEY_1~E_KEY_N), and encrypted data keys (E_DEK_1~E_DEK_N). The data area (224_1~224_N) of the non-volatile memory (220_1~220_N) stores encrypted data (E_DATA_1~E_DATA_N).
[0085] The storage devices (200_1~200_N) respond to security setting commands that allow or block access to data keys (DEK_1~DEK_N) by blocking or re-allowing access to encryption keys (KEK_1~KEK_N) from the first keys (KEY_1~KEY_N).
[0086] The number of encryption keys (KEK_1 to KEK_N) for storage devices (200_1 to 200_N) may be the same or different. Furthermore, the number of primary keys (KEY_1 to KEY_N) that form the encryption link with the encryption keys (KEK_1 to KEK_N) are all different.
[0087] Figure 25 is a diagram illustrating a system to which a storage device according to one embodiment is applied.
[0088] System 1000 in Figure 25 is basically a mobile system such as a mobile phone, smartphone, tablet PC, wearable device, healthcare device, or IoT (Internet of Things) device. However, System 1000 in Figure 25 is not necessarily limited to a mobile system and could be a personal computer, laptop computer, server, media player, or automotive device such as a navigation system.
[0089] Referring to Figure 25, the system 1000 includes a main processor 1100, memory (1200a, 1200b), and storage devices (1300a, 1300b), and further includes one or more of the following: optical input device 1410, user input device 1420, sensor 1430, communication device 1440, display 1450, speaker 1460, power supplying device 1470, and connecting interface 1480.
[0090] The main processor 1100 controls the overall operation of the system 1000, and more specifically, the operation of the other components that make up the system 1000. Such a main processor 1100 can be implemented as a general-purpose processor, a dedicated processor, or an application processor.
[0091] The main processor 1100 includes one or more CPU cores 1110 and further includes a controller 1120 for controlling memory (1200a, 1200b) and / or storage devices (1300a, 1300b). Depending on the embodiment, the main processor 1100 further includes an accelerator block 1130 which is dedicated circuitry for high-speed data computation such as AI (artificial intelligence) data computation. Such an accelerator block 1130 may include a GPU (Graphics Processing Unit), an NPU (Neural Processing Unit), and / or a DPU (Data Processing Unit), and may be implemented as a separate chip physically independent of the other components of the main processor 1100.
[0092] The memory (1200a, 1200b) is used as the main memory of system 1000 and includes volatile memory such as SRAM and / or DRAM, but may also include non-volatile memory such as flash memory, PRAM and / or RRAM. The memory (1200a, 1200b) can also be implemented in the same package as the main processor 1100.
[0093] The storage devices (1300a, 1300b) function as non-volatile storage devices that store data regardless of whether power is supplied, and have a relatively larger storage capacity compared to the memory (1200a, 1200b). The storage devices (1300a, 1300b) include storage controllers (1310a, 1310b) and non-volatile memory (NVM) storage devices (1300a, 1300b) that store data under the control of the storage controllers (1310a, 1310b). The non-volatile memory (1320a, 1320b) includes non-volatile memory of the same or different types.
[0094] The storage devices (1300a, 1300b) are either included in the system 1000 in a physically separate state from the main processor 1100, or they are implemented within the same package as the main processor 1100.
[0095] The storage device (1300a, 1300b) is one of the storage devices described using Figures 1 to 25.
[0096] The imaging device 1410 captures still or moving images and may be a camera, camcorder, and / or webcam.
[0097] The user input device 1420 receives various types of data input from the user of the system 1000, and includes touch pads, keypads, keyboards, mice, and / or microphones.
[0098] Sensor 1430 senses various types of physical quantities acquired from outside the system 1000 and converts the sensed physical quantities into electrical signals. Such sensors 1430 include temperature sensors, pressure sensors, illuminance sensors, position sensors, acceleration sensors, biosensors, and / or gyroscopes.
[0099] The communication device 1440 transmits and receives signals to and from other devices outside the system 1000 in accordance with various communication protocols. Such a communication device 1440 is implemented including an antenna, a transceiver, and / or a modem.
[0100] The display 1450 and speaker 1460 function as output devices that output visual and auditory information, respectively, to the user of the system 1000.
[0101] The power supply device 1470 appropriately converts power supplied from a battery (not shown) built into the system 1000 and / or an external power source and supplies it to each component of the system 1000.
[0102] The coupling interface 1480 provides a connection between system 1000 and external devices that are connected to system 1000 and can exchange data with system 1000. The coupling interface 1480 is implemented using a variety of interface methods, such as ATA (Advanced Technology Attachment), SATA (Serial ATA), e-SATA (external SATA), SCSI (Small Computer Small Interface), SAS (Serial Attached SCSI), PCI (Peripheral Component Interconnection), PCIe (PCI express), NVMe (NVM express), IEEE 1394, USB (universal serial bus), SD (secure digital) card, MMC (multi-media card), eMMC (embedded multi-media card), UFS (Universal Flash Storage), eUFS (embedded Universal Flash Storage), and CF (compact flash) card interfaces.
[0103] Although embodiments of the present invention have been described in detail above with reference to the drawings, the present invention is not limited to the embodiments described above, and can be modified and implemented in various ways without departing from the technical spirit of the present invention. [Explanation of Symbols]
[0104] 1, 2, 3 Storage Systems 100 hosts 110 Host Controller 120 Host Memory 121 Buffer area 200, 200_1~200_N, 1300a, 1300b Storage Devices 210, 210_1~210_N Storage Controllers 211 Host Interface 212 memory interface 213 CPU 214 Working Memory 214a Flash Conversion Layer (FTL) 214b Hash Algorithm 215 Packet Manager 216 buffer memory 217 ECC(error correction code) 218 AES (advanced encryption standard) 218a Encryption Module 218b Decoding Module 220, 220_1~220_N, 1320a, 1320b Non-volatile memory (NVM) 222, 222_1~222_N meta-region 224 User Area Data area 224_1~224_N 1000 System 1100 Main Processor 1110 CPU cores 1120 Controller 1130 Accelerator Block 1200a, 1200b memory 1310a, 1310b storage controllers 1410 Imaging device 1420 User Input Device 1430 Sensor 1440 Communication equipment 1450 displays 1460 Speakers 1470 Power supply equipment 1480 Linking Interface CMD_1, CMD_3, CMD_4 Security Configuration Commands CMD_2 Security Release Command CMD_2' Security Removal Command CMD_W Light Command DATA DEK, DEK_1~DEK_N Data Keys E_DATA, E_DATA_1~E_DATA_N Encrypted data E_DEK, E_DEK', E_DEK_1~E_DEK_N: Encrypted data keys E_KEK_1~E_KEK_N Encrypted encryption keys E_MKPK, E_KEY_1~E_KEY_N: Encrypted first key E_UKPK Encrypted second key E_MKEK First encrypted encryption key E_UKEK, E_UKEK', E_UKEK” Second encrypted encryption key KEK, KEK_1~KEK_M, KEK_1~KEK_N encryption keys MKPK, KEY_1~KEY_N, KEY_1_1~KEY_M_N First Key MPW Primary Password (Master Password) UKPK, UKPK', UKPK” Second Key UPW, UPW', UPW” Second password (user password)
Claims
1. A storage device comprising non-volatile memory and a storage controller, The non-volatile memory stores an encryption key and a data key encrypted with the encryption key, data is written using the data key, and data is read using the data key. The aforementioned storage controller A first security setting command is received that allows access to the data key using the first password. In response to the first security setting command, a first key is generated based on the first password, The encryption key is encrypted with the first key to generate the first encrypted encryption key. The first key mentioned above is encrypted with the encryption key to generate an encrypted first key. A storage device characterized by storing the first encrypted encryption key and the encrypted first key in the non-volatile memory.
2. The storage device according to claim 1, characterized in that the first key is a hash value of the first password.
3. The storage device according to claim 1, characterized in that the storage controller deletes the encryption key in response to the first security setting command.
4. The aforementioned storage controller Upon receiving a second security setting command that blocks access to the data key using the first password, The storage device according to claim 1, characterized in that, in response to the second security setting command, the first encrypted encryption key stored in the non-volatile memory is deleted.
5. The aforementioned storage controller A third security setting command is received that allows access to the data key using the first password. In response to the third security setting command, the encrypted first key stored in the non-volatile memory is decrypted to generate the first key. The encryption key is encrypted with the first key to generate the first encrypted encryption key. The storage device according to claim 4, characterized in that the first encrypted encryption key is stored in the non-volatile memory.
6. The storage device according to claim 1, characterized in that the first password is not changed by the first security setting command.
7. The first security setting command includes a second password different from the first password, and is a first security setting command that further allows access to the data key using the second password. The aforementioned storage controller In response to the first security setting command, a second key is generated based on the second password. The aforementioned encryption key is encrypted with the aforementioned second key to generate a second encrypted encryption key. The storage device according to claim 1, further characterized in that the second encrypted encryption key is stored in the non-volatile memory.
8. The storage device according to claim 7, characterized in that the storage controller further deletes the encryption key stored in the non-volatile memory in response to the first security setting command.
9. The storage device according to claim 7, characterized in that the second key is a hash value of the second password.
10. The aforementioned storage controller Upon receiving a security release command that allows access to the data key without using the first password or the second password, The storage device according to claim 7, characterized in that, in response to the security release command, the first encrypted encryption key and the second encrypted encryption key stored in the non-volatile memory are deleted.
11. The aforementioned storage controller In response to the first security setting command, the encryption key stored in the non-volatile memory is further deleted. The storage device according to claim 10, further characterized in that the encryption key is stored in the non-volatile memory in response to the security release command.
12. The aforementioned storage controller A security delete command is received that includes either the first password or the second password and deletes the data stored in the non-volatile memory. The storage device according to claim 7, characterized in that, in response to the security deletion command, the data stored in the non-volatile memory, the first encrypted encryption key, the second encrypted encryption key, and the encrypted data key are deleted.
13. The storage device according to claim 12, characterized in that the storage controller generates a new data key in response to the security deletion command, and stores the new data key in the non-volatile memory encrypted with the encryption key.
14. A storage device comprising a non-volatile memory and a storage controller that controls the operation of the non-volatile memory, The non-volatile memory stores an encrypted first key generated by encrypting a first key generated based on a first password with an encryption key, a first encrypted encrypted key generated by encrypting the encryption key with the aforementioned first key, and an encrypted data key generated by encrypting a data key with the aforementioned encryption key. The aforementioned storage controller Upon receiving a first security setting command that blocks access to the data key using the first password, In response to the first security setting command, the first encrypted encryption key stored in the non-volatile memory is deleted. Upon receiving a second security setting command that allows access to the data key using the first password, A storage device characterized by storing the first encrypted encryption key in the non-volatile memory in response to the second security setting command.
15. The aforementioned storage controller In response to the second security setting command, the encrypted first key stored in the non-volatile memory is decrypted to generate the first key. The encryption key is encrypted with the first key to generate the first encrypted encryption key. The storage device according to claim 14, characterized in that the first encrypted encryption key is stored in the non-volatile memory.
16. The aforementioned non-volatile memory is A user area where data is written using the aforementioned data key and where the data is read using the aforementioned data key, The storage device according to claim 14, comprising the encryption key, the first encrypted encryption key, and a meta area in which the encrypted first key is stored.
17. The first security setting command includes a second password different from the first password, and is a first security setting command that enables access to the data key using the second password. The second security setting command includes a third password different from the first password, and is a second security setting command that further enables access to the data key using the third password. The aforementioned storage controller In response to the first security setting command, a second key is generated based on the second password. The aforementioned encryption key is encrypted with the aforementioned second key to generate a second encrypted encryption key. The second encrypted encryption key is further stored in the non-volatile memory. In response to the second security setting command, a third key is further generated based on the third password. The aforementioned encryption key is encrypted with the aforementioned third key to generate a third encrypted encryption key. The storage device according to claim 14, further characterized in that the third encrypted encryption key is stored in the non-volatile memory.
18. A storage device comprising non-volatile memory and a storage controller, The non-volatile memory stores a first encryption key and a first encrypted data key encrypted with the first encryption key, data is written using the data key, and data is read using the data key. The aforementioned storage controller A first security setting command is received that allows access to the data key using multiple first passwords that are different from each other. In response to the first security setting command, a plurality of first keys are generated based on each of the plurality of first passwords, The first encryption key is encrypted with each of the plurality of first keys to generate a plurality of first encrypted encryption keys. Each of the aforementioned plurality of first keys is encrypted with the aforementioned first encryption key to generate a plurality of encrypted first keys. A storage device characterized by storing the plurality of first encrypted encryption keys and the plurality of encrypted first keys in the non-volatile memory.
19. The aforementioned multiple first passwords include a first sub-password, The plurality of first keys include first subkeys generated based on the first subpassword, The plurality of first encrypted encryption keys include a second subkey generated by encrypting the first encryption key with the first subkey, The aforementioned storage controller Upon receiving a second security setting command that blocks access to the data key using the first sub-password, The storage device according to claim 18, characterized in that it deletes the second subkey in response to the second security setting command.
20. The non-volatile memory further stores a second encryption key different from the first encryption key and a second encrypted data key encrypted with the second encryption key. The aforementioned storage controller A second security setting command is received that allows access to the data key using multiple second passwords that are different from each other. In response to the second security setting command, a plurality of second keys are generated based on each of the plurality of second passwords, The aforementioned second encryption key is encrypted with each of the aforementioned plurality of second keys to generate a plurality of second encrypted encryption keys. Each of the aforementioned plurality of second keys is encrypted with the aforementioned second encryption key to generate a plurality of encrypted second keys. The storage device according to claim 18, characterized in that the plurality of second encrypted encryption keys and the plurality of encrypted second keys are stored in the non-volatile memory.
Citation Information
Patent Citations
Data encryption device, data encryption program, and data encryption method
JP2015065615A
Key information controller, key information update device, program and recording medium, key information update method, key information update system
JP2015133589A
Information processing device, information processing system, and program
JP2015148902A
Information processor, cryptographic device, control method of information processor and program
JP2016181836A
Encryption key management system and encryption key management method
JP2016192715A