Memory controller, storage device including the same
Patent Information
- Application Number
- KR1020200003885
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-01-10
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2040-01-10
Smart Images

Figure R1020200003885_ABST
Abstract
Description
Technology Field
[0001] The technical concept of the present disclosure relates to a storage device, and more specifically, to a memory controller that supports self-encryption and a storage device including the same. Background Technology
[0002] As a non-volatile memory, flash memory retains stored data even when the power is cut off, and storage devices containing flash memory, such as Solid State Drives (SSDs) and memory cards, are widely used. Recently, with the increasing demand for data security, security features are being developed to safely store critical data requiring security and to prevent data leakage even if storage devices are discarded or stolen. Among the security features of storage devices, self-encrypting drives (SEDs) can provide high data protection by encrypting data to make it lighter and decrypting and reading the encrypted data.
[0003] However, since the security functions provided by the storage device may operate dependently on commands from the host device, the security functions of the storage device cannot be utilized if the host device does not support the transmission of commands that configure the use of the storage device's security functions. Therefore, there is an increasing need for storage devices that can operate under the control of a wider variety of host devices. Prior art literature
[65535] Prior Art 1: U.S. Patent Application Publication US2016-0241552 (August 18, 2016) Prior Art 2: U.S. Patent Application Publication US2014-0359758 (December 4, 2014) The problem to be solved
[0004] The technical concept of the present disclosure is to provide a memory controller capable of providing security functions for a storage device even when the storage device is connected to various types of host devices, and a storage device including the same. means of solving the problem
[0005] A memory controller that controls data writing and reading of a non-volatile memory including a security area in which encrypted user data is stored according to the technical concept of the present disclosure may include: a security access control module that converts biometric authentication data received from a biometric recognition module into security setting data having a data format according to a security standard protocol, and performs authorization registration and authorization authentication for user rights set for access control of the security area based on the security setting data; and a data processing unit that performs encryption of user data received from a host device or decryption of the encrypted user data read from the security area when access to the security area is allowed.
[0006] Additionally, a storage device according to the technical concept of the present disclosure includes a non-volatile memory comprising a secure area in which encrypted user data is stored, and a memory controller that controls the writing and reading of data in the non-volatile memory, wherein when the storage device is connected to a first host device, the memory controller performs authorization for a user having access rights to the secure area based on a password received from the first host device according to a security protocol set for communication with the first host device, and when the storage device is connected to a second host device, the memory controller can perform authorization based on biometric authentication data received from a biometric recognition module. Effects of the invention
[0007] According to the technical concept of the present disclosure, a memory controller independently performs the setting of a security function according to a security standard protocol based on biometric authentication data received from a biometric recognition module without the control of a host device, so that the storage device can provide a security function even if it is connected to a host device that does not provide a security command according to a security standard protocol. Brief explanation of the drawing
[0008] FIG. 1 is a block diagram showing a storage device and a storage system according to an exemplary embodiment of the present disclosure. FIGS. 2a and 2b are drawings illustrating a method in which a memory controller performs user authorization authentication according to a connected host device in a storage device according to an exemplary embodiment of the present disclosure. FIG. 3 is a drawing showing the management targets of a security access control module according to an exemplary embodiment of the present disclosure. FIGS. 4a and 4b show examples of implementations of feature set tables set by a security access control module according to an exemplary embodiment of the present disclosure. FIG. 5 is a block diagram schematically illustrating a memory controller according to an exemplary embodiment of the present disclosure. FIG. 6 is a flowchart illustrating a method of operation of a storage device based on received biometric authentication data according to an exemplary embodiment of the present disclosure. Figure 7 illustrates an exemplary data format according to a security standard protocol. FIGS. 8a and 8b are flowcharts illustrating a method for authenticating user rights of a storage system according to an exemplary embodiment of the present disclosure. FIG. 9 illustrates a method in which a security access control module according to an exemplary embodiment of the present disclosure controls a lock state and an unlock state for a non-volatile memory. FIGS. 10a and FIGS. 10b exemplarily illustrate a plurality of user rights accessible to a secure area of non-volatile memory according to an exemplary embodiment of the present disclosure. FIG. 11 is a flowchart illustrating a method for registering user rights of a storage system according to an exemplary embodiment of the present disclosure. FIG. 12 is a flowchart illustrating a method for deleting user rights of a storage system according to an exemplary embodiment of the present disclosure. FIG. 13 is a block diagram showing one embodiment of a biometric recognition module according to an exemplary embodiment of the present disclosure. FIG. 14 is a block diagram showing a storage device and a storage system according to an exemplary embodiment of the present disclosure. FIG. 15 is a block diagram showing a storage device and a storage system according to an exemplary embodiment of the present disclosure. FIG. 16 is a block diagram showing an electronic system according to an exemplary embodiment of the present disclosure. FIG. 17 is a block diagram showing an SSD and an SSD system including the same according to an exemplary embodiment of the present disclosure. Specific details for implementing the invention
[0009] FIG. 1 is a block diagram showing a storage device and a storage system including the same according to an exemplary embodiment of the present disclosure.
[0010] Referring to FIG. 1, the storage system (10) may include a storage device (100), a host device (200), and a biometric module (300), and the storage device (100) may include a memory controller (110) and a non-volatile memory (120, NVM).
[0011] The storage system (10) may be implemented as, for example, a PC (personal computer), a data server, network-linked storage, an IoT (Internet of Things) device, or a portable electronic device. The portable electronic device may be a laptop computer, a mobile phone, a smartphone, a tablet PC, a PDA (personal digital assistant), an EDA (enterprise digital assistant), a digital still camera, a digital video camera, an audio device, a PMP (portable multimedia player), a PND (personal navigation device), an MP3 player, a handheld game console, an e-book, a wearable device, etc.
[0012] In some embodiments, the storage device (100) may be internal memory embedded in the electronic device. For example, the storage device (100) may be an SSD, an embedded Universal Flash Storage (UFS) memory device, or an embedded Multi-Media Card (eMMC). In some embodiments, the storage device (10) may be external memory that is detachable from the electronic device. For example, the storage device (10) may be a portable SSD, a UFS memory card, a Compact Flash (CF) card, a Secure Digital (SD) card, a Micro Secure Digital (Micro-SD) card, a Mini Secure Digital (Mini-SD) card, an Extreme Digital (xD) card, or a Memory Stick.
[0013] A host device (200) (or referred to as a host) may communicate with a storage device (100) through various interfaces, transmit a command (CMD) and / or data (DT) to be stored in non-volatile memory (120) to the storage device (100), and receive a response (RES) and / or data (DT) read from the non-volatile memory (120) from the storage device (100). For example, the host device (120) may be implemented as an Application Processor (AP) or a System-On-a-Chip (SoC). Additionally, for example, the host device (120) may be implemented as an integrated circuit, a motherboard, or a database server, but is not limited thereto.
[0014] In an embodiment, the host device (200) and the storage device (100) can communicate when electrically connected via a cable using a hot-pluggable interface.
[0015] The storage device (100) can, in response to a command (CMD) received from the host device (200), store data (DT) (hereinafter referred to as user data) received from the host device (200) in the non-volatile memory (120), or read the user data (DT) stored in the non-volatile memory (120) and transmit the user data (DT) to the host device (200).
[0016] A storage device (100) can communicate with a host device (200) via a security standard protocol, and the security function of the storage device (100) can be configured according to the control of the host device (200). In the present disclosure, the configuration of a security function refers to a configuration related to the use of a security function for the security function to be performed. The host device (200) can provide a command (SCMD) (hereinafter referred to as a security command) according to a security standard protocol for configuring the security function of the storage device (100) to the storage device (100), and receive a response (RES) to the security command (SCMD) from the storage device (100).
[0017] Security commands (SCMD) and responses (RES) may have a data format according to a security standard protocol, and security commands (SCMD) may include requests and configuration values related to the configuration of security functions. In an embodiment, the configuration values may include a password for user authorization authentication. For example, a storage device (100) may communicate with a host device (200) via a Trusted Computing Group (TCG) protocol. Security commands (SCMD) and responses (RES) having a data format according to the TCG protocol may be transmitted and received between the storage device (100) and the host device (200). For example, security commands (SCMD) and responses (RES) may be 512-byte data blocks (or referred to as data packets). However, it is not limited to this, and security standard protocols provided by various interface methods, such as ATA (Advanced Technology Attachment) interface and SATA (Serial Advanced Technology Attachment) interface, may be applied between the host device (200) and the storage device (100).
[0018] Meanwhile, some of the various devices that can be implemented as the host device (200) cannot set the security function of the storage device (100). For example, a security standard protocol may not be applied between the host device (200) and the storage device (100), and the host device (200) may not be able to provide a security command (SCMD) to the storage device (100). In such cases, the storage device (100) according to the embodiment of the present disclosure can set the security function by independently determining a feature set according to the security standard protocol based on biometric authentication data (BAD) received from the biometric recognition module (300). For example, the storage device (100) can independently determine the setting value received from the host device (200) based on the biometric authentication data (BAD). In an embodiment, the storage device (100) generates security configuration data corresponding to a security command (SCMD) based on biometric authentication data (BAD), that is, security configuration data having a data format according to a security standard protocol, and can set a security function based on the security configuration data. Accordingly, the security function of the storage device (100) can be performed. This will be described in detail later.
[0019] Non-volatile memory (120) may refer to a memory module or memory device having the characteristic that stored data is retained even when the power is cut off. In one embodiment, the non-volatile memory (120) may include a flash memory device, for example, a NAND flash memory device. In an embodiment, the non-volatile memory (120) may include a vertical NAND flash (VNAND; VNAND) memory device having a three-dimensional array structure. However, it is not limited thereto, and the non-volatile memory (120) may include a resistive memory device such as ReRAM (resistive RAM), PRAM (phase change RAM), or MRAM (magnetic RAM). In addition, the non-volatile memory (120) may be implemented as a magnetic disk device as well as a semiconductor memory device. For convenience of explanation, the non-volatile memory (120) is described below as a NAND flash memory device, but it will be understood that the technical concept of the present disclosure is not limited thereto. In the embodiment, the non-volatile memory (120) may include a plurality of non-volatile memory chips, and the plurality of non-volatile memory chips may communicate with the memory controller (110) through a plurality of channels.
[0020] According to the characteristics of the non-volatile memory (120), which retains stored data even when the power is cut off, the data stored in the non-volatile memory (120) needs to be maintained in a secure state. For example, when the storage device (100) is reused or discarded, or when the storage device (100) is used by an unauthorized user, the leakage of data requiring security stored in the storage device (100) must be prevented. To this end, the storage device (100) may support a self-encryption function. The storage device (100) may encrypt data (DT) (hereinafter referred to as user data) received from the host device (200) and store the encrypted user data (EDT) in the secure area (SA) of the non-volatile memory (120). Since the encrypted user data (EDT) stored in the secure area (SA) of the non-volatile memory (120) remains in an encrypted state, it can be maintained in a secure state even when the power supplied to the storage device (100) is cut off. In this way, a storage device (100) that supports a self-encryption function may be referred to as a SED (Self-Encrypting Device or Self-Encrypting Drive).
[0021] The memory controller (110) can control the overall operation of the storage device (100) and can control data writing and reading to the non-volatile memory (120). Additionally, the memory controller (110) can support security functions of the storage device (100), such as a self-encryption function. The memory controller (110) can encrypt user data (DT) received from the host device (200) and store the encrypted user data (EDT) in the user area (SA) of the non-volatile memory (120). Additionally, the memory controller (110) can read the encrypted user data (EDT) from the non-volatile memory (120), decrypt the encrypted user data (EDT), and provide the user data (DT) to the host device (200).
[0022] The memory controller (110) can control access to the security area (SA) of the non-volatile memory (120), that is, the setting of security functions. The memory controller (110) can register user rights for a user who can access the security area (SA) of the non-volatile memory (120), and if authentication of user rights (i.e., user rights authentication) is successful, access to the security area (SA) of the non-volatile memory (120) can be allowed. In other words, if user rights authentication performed by the memory controller (110) is successful, the host device (200) can access the security area (SA) of the non-volatile memory (120) for writing and / or reading user data (DT).
[0023] The memory controller (110) may include a security access control module (SACM) and a data processing unit (DPU). The security access control module (SACM) can set up security functions by managing user rights for users who have access rights to the security area (SA) of the non-volatile memory (SA). For example, the security access control module (SACM) can perform registration, authentication, and deletion of user rights. The data processing unit (DPU) can encrypt user data (DT) received from the host device (200) based on a security key (SKEY) or decrypt encrypted user data (EDT) read from the security area (SA) of the non-volatile memory (120). The security key (SKEY) may be generated based on a random characteristic key generated by hardware logic inside the storage device (100), or may be generated based on a combination of the random characteristic key and a unique key provided from the outside (e.g., the host device (200)). For example, the security access control module (SACM) can set the storage device (100) to a locked state or an unlocked state by encrypting or decrypting a security key (SKEY) based on a unique value (or password) used for the registration and authentication of user rights. Specifically, the security access control module (SACM) can set the security area (SA) of the non-volatile memory (120) to a locked state or an unlocked state in relation to read and / or write operations. By the security access control module (SACM) encrypting and storing the security key (SKEY) based on a unique value, the security area (SA) of the non-volatile memory (120) can be set to a locked state where access for read and / or write is not allowed. When user authorization is successful, the security access control module (SACM) decrypts the encrypted security key (SKEY), thereby setting the security area (SA) of the non-volatile memory (120) to an unlocked state where access for reading and / or writing is allowed.The data processing unit (DPU) can encrypt user data (DT) to be stored in the security area (SA) based on a security key (SKEY) or decrypt encrypted user data (EDT) read from the security area (SA).
[0024] As described above, a security standard protocol may be applied between the host device (200) and the storage device (100) to provide security functions for the storage device (100), and the host device (200) may transmit a security command (SCMD) to the storage device (100) based on the security standard protocol. For example, the host device (200) may transmit a password for user authority registration and user authority authentication as a security command (SCMD) to the storage device (100), and may also provide a user authority activation request, a setting value for setting the non-volatile memory (120) to a locked or unlocked state, etc., as a security command (SCMD). The setting value may be defined in the security standard protocol and may be field values of a feature set according to the security standard protocol for user authority. For example, the host device (200) may generate a security command (SCMD) according to the TCG (Trusted Computing Group) protocol and provide it to the storage device (100). At this time, the security command (SMCD) is packetized (or command tokenized) according to the data format of the security standard protocol, and the host device (200) can transmit the packetized command (e.g., data packet) to the host device (200), specifically to the memory controller (110). The security access control module (SACM) can perform registration, authentication, and deletion of user rights by setting field values of a feature set for user rights based on the security command (SMCD) received from the host device (200), and can also set the non-volatile memory (120) to a locked state or an unlocked state.
[0025] As described above, in the storage device (100) according to the embodiment of the present disclosure, the memory controller (110) can set security functions under the control of the host device (200), that is, based on a security command (SCMD) from the host device (200), and can also set security functions independently based on biometric authentication data (BAD) received from the biometric recognition module (300). For example, the memory controller (110) can manage user rights according to a security standard protocol based on the biometric authentication data (BAD). The security access control module (SACM) can perform registration, authentication, and deletion of user rights based on the biometric authentication data (BAD). In the embodiment, the security access control module (SACM) can convert the biometric authentication data (BAD) into security setting data having a data format according to a security standard protocol, and perform registration, authentication, and deletion of user rights based on the security setting data.
[0026] The security access control module (SACM) can set field values of a feature set according to a security standard protocol for user rights based on biometric authentication data (BAD) received from the biometric recognition module (300). In an embodiment, the security access control module (SACM) can set credential values of user rights based on the biometric authentication data (BAD). Accordingly, user rights can be registered. Additionally, when the storage device (100) is connected to the host device (200), the security access control module (SACM) can receive biometric authentication data (BAD) from the biometric recognition module (300) and perform user rights authentication based on the biometric authentication data (BAD). If user rights authentication is successful, the security access control module (SACM) can set the non-volatile memory (120) (specifically, the security area (SA) of the non-volatile memory (120)) to a locked state or an unlocked state. In an embodiment, the security access control module (SACM) registers user rights based on a command (CMD) requesting registration of user rights received from a host device (200) and biometric authentication data (BAD) received from a biometric recognition module (300), and subsequently, can perform user rights authentication independently based on the biometric authentication data (BAD) without receiving a security command (SCMD) from the host device (200).
[0027] In this way, the memory controller (110) can manage user rights according to a security standard protocol (e.g., user rights authentication, user rights registration, and user rights deletion) based on biometric authentication data (BAD) without control of the host device (200), and set the non-volatile memory (120) to a locked or unlocked state, so that even if the storage device (100) is connected to a host device (200) that does not provide a security command (SMCD), the security function of the storage device (100) can be used (i.e., activated). The memory controller (110) can perform user rights authentication based on a user password received from the host device (200) and perform encryption and decryption (i.e., self-encryption) upon successful user rights authentication, and can also perform user rights authentication based on biometric authentication data (BAD) received from the biometric recognition module (300) even if a user password is not received from the host device (200).
[0028] The biometric recognition module can sense the user's biological information to acquire biometric data, such as fingerprints, iris patterns, voice, etc., and provide biometric authentication data (BAD) based on the biometric data to the memory controller (110). The biometric recognition module (300) can be implemented as a recognition module capable of acquiring the user's biometric data, such as a fingerprint recognition module, an iris recognition module, a facial recognition module, a vein recognition module, or a voice recognition module.
[0029] In an embodiment, the biometric recognition module (300) can convert biometric data into biometric information based on a set data format and store and manage the biometric information. The biometric recognition module (300) can store biometric information for each user with registered user rights in a non-volatile memory provided internally. The biometric recognition module (300) can generate a unique value based on the biometric information and transmit a biometric authentication message and the unique value to the memory controller (110) as biometric authentication data (BAD). In the biometric information registration step, the biometric recognition module (300) can transmit a biometric information registration message and the unique value to the memory controller (110). When the memory controller (110) receives a biometric information registration completion message, it can perform user right registration based on the unique value. Subsequently, in the user right authentication step, the biometric recognition module (300) acquires the user's biometric data, and if the biometric information based on the acquired biometric data matches the biometric information stored in advance, it can generate a unique value based on the matched biometric information and transmit a biometric authentication success message and the unique value to the memory controller (110). When a biometric authentication success message is received, the memory controller (110) can perform user authorization based on a unique value.
[0030] For example, if the biometric recognition module (300) is a fingerprint recognition module, the fingerprint recognition module can scan the user's fingerprint to obtain a fingerprint image as biometric data and convert the fingerprint image into fingerprint information based on a set format. The fingerprint recognition module can generate a unique value based on the fingerprint information and transmit a fingerprint information registration message or a fingerprint authentication success message and the unique value to the memory controller (110) as biometric authentication data (BAD). The memory controller (110), specifically the security access control module (110), can register user rights by setting a credential value of user rights based on the unique value, or perform user rights authentication based on the unique value. As an example, the access control module (110) can register user rights by hashing the unique value to generate a hash value and setting the hash value as a credential value. When performing user rights authentication, the access control module (110) can perform user rights authentication by comparing the hash value generated by hashing the received unique value with the credential value.
[0031] In an embodiment, the biometric recognition module (300) may provide biometric data, or biometric information converted from biometric data into a preset data format, to the memory controller (110) as biometric authentication data (BAD), and the memory controller (110) may perform user authorization registration and user authorization authentication based on the biometric data or biometric information.
[0032] A storage device (100) can be connected to various types of host devices (200) and can operate under the control of the host devices (200). When the security function of the storage device (100) is activated based on a security command (SMCD) received from the host device (200), if the host device (200) cannot provide a security command (SCMD), in other words, if a security standard protocol is not applied to the host device (200), the security function of the storage device (100) cannot be utilized. However, the storage device (100) according to the embodiment of the present disclosure can set security functions by the memory controller (110) setting a feature set according to a security standard protocol based on a security command (SMCD) from the host device (200) under the control of the host device (200), that is, based on a security command (SMCD) from the host device (200), and can also set security functions by independently determining a feature set according to a security standard protocol based on biometric authentication data (BAD) received from the biometric recognition module (300) without the control of the host device (200). For example, even if the storage device (100) does not receive a user authorization authentication request and a password from the host device (200) as a security command (SCMD), it can generate security setting data corresponding to the security command (SCMD) based on the biometric authentication data (BAD) and perform user authorization authentication using the security setting data, so the storage device (200) can provide security functions even if it is connected to a host device (200) that does not provide a security command (SMCD). Therefore, even if the storage device (100) is connected to various types of host devices (200), the security function of the storage device (100) can be utilized.
[0033] FIGS. 2a and 2b are drawings illustrating a method in which a memory controller performs user authorization authentication according to a connected host device in a storage device according to an exemplary embodiment of the present disclosure.
[0034] Referring to FIG. 2a, in a storage system (10a), a storage device (100) may be connected to a first host device (200a), and the storage device (100) and the first host device (200a) may communicate according to a security standard protocol, such as the TCG protocol. The first host device (200a) may control the settings of the security functions of the storage device (100). The first host device (200a) may execute software to control the security functions of the storage device (100), such as a self-encryption function (SED).
[0035] The first host device (200a) can transmit a security command (SCMD) containing a user authorization authentication request and a password (PW) for user authorization to the storage device (100). The security access control module (SACM) of the memory controller (110) can respond to the security command (SCMD) and perform authorization authentication for user authorization based on the password (PW), i.e., user authorization authentication. The security access control module (SACM) can determine that authorization authentication is successful if the received password (PW) is a password that is set as the credential value of the user authorization when the authorization for user authorization is registered. Upon successful authorization, a session for a locking security provider (e.g., SP2 in FIG. 3) can be opened. The storage device (100) can transmit a response (RES) indicating that the session has been opened to the first host device (200a), and the first host device (200a) can transmit a setting value to the storage device (100) to set the security area (SA) of the non-volatile memory (120) to a locked state or an unlocked state. The access control module (SACM) can change the security area (SA) of the non-volatile memory (120) from a locked state to an unlocked state by setting a feature set according to a security standard protocol based on the received setting value. In this way, the first host device (200a) provides a security command (SCMD) to the storage device (100), and the memory controller (110) of the storage device (100) can set a lock state or an unlock state (hereinafter referred to as a lock / unlock state) for the security area (SA) of the non-volatile memory (120) based on the security command (SCMD) received from the first storage device (200a), thereby enabling the security function of the storage device (100).
[0036] Referring to FIG. 2b, in a storage system (10b), a storage device (100) may be connected to a second host device (200b), and the second host device (200b) may not be able to communicate with the storage device (100) according to a security standard protocol. In other words, the second host device (200b) may not provide security commands to the storage device (100).
[0037] The security access control module (SACM) can perform authorization for user rights based on biometric authentication data (BAD) received from the biometric recognition module (300) without control from the second host device (200b) (e.g., without receiving the security command (SCMD) of FIG. 2a).
[0038] When the storage device (100) is connected to the second host device (200b), the security access control module (SACM) can transmit a trigger signal (TRIG) to the biometric recognition module (300). In an embodiment, the trigger signal (TRIG) may be a signal requesting the biometric recognition module (300) to perform biometric authentication. The biometric recognition module (300) may perform biometric authentication in response to the biometric authentication trigger signal (TRIG). The biometric recognition module (300) may sense the user's biometric data to obtain biometric data and perform biometric authentication based on the biometric data. If biometric authentication is successful, the biometric recognition module (300) may transmit biometric authentication data (BAD), including a unique value and a biometric authentication success message, to the memory controller (110). In an embodiment, the trigger signal (TRIG) may be a signal requesting the biometric recognition module (300) to sense the user's biometric data to obtain biometric data. The biometric recognition module (300) can transmit biometric data or biometric information generated based on biometric data to the memory controller (110) as biometric authentication data (BAD).
[0039] The Security Access Control Module (SACM) can independently set the security function of the storage device (100) based on biometric authentication data (BAD). The Security Access Control Module (SACM) can perform authorization authentication for user rights based on biometric authentication data (BAD). The Security Access Control Module (SACM) can determine that authorization authentication is successful if the biometric authentication data (BAD) contains authentication data corresponding to the credential value of the user rights, for example, if the unique value included in the received biometric authentication data (BAD) is the same as the unique value used when setting the credential value of the user rights. If authorization authentication is successful, a session for the locking SP (e.g., SP2 in FIG. 3) can be opened. The Security Access Control Module (SACM) can change the security area (SA) of the non-volatile memory (120) from a locked state to an unlocked state through the opened session. An access control module (SACM) can set a locked or unlocked state by determining a setting value corresponding to a field value of a feature set according to a security standard protocol indicating a locked or unlocked state for a security area (SA) of non-volatile memory (120). In this way, the storage device (100) can set a lock / unlocked state for the security area (SA) of non-volatile memory (120) based on biometric authentication data (BAD) received from the biometric recognition module (300) without control by the second storage device (200b), thereby setting the security function of the storage device (100). FIG. 3 is a diagram showing the management target of a security access control module according to an exemplary embodiment of the present disclosure.
[0040] Referring to FIG. 3, a storage device (100 of FIG. 1) may include a plurality of security providers (SP1, SP2) according to a security standard protocol, and a security access control module (SACM) may manage the plurality of security providers (SP) (SP1, SP2). The storage device (100) may include a first SP (SP1) and a second SP (SP2), wherein the first SP (SP1) is an administrative SP and the second SP (SP2) is a locking SP. The administrative SP controls the information and configuration of the storage device (100) and may issue other SPs. The locking SP may control the lock / unlock status of the security area (SA) of the non-volatile memory (110). However, it is not limited thereto, and the number of multiple SPs and their configuration may be changed.
[0041] Each of the first SP (SP1) and the second SP (SP2) may include feature set tables (e.g., the authorization table (ATB) and the locking table (LTB) of FIG. 4a) that include feature sets related to authorization control for administrators and / or users and lock / unlock status control.
[0042] A security access control module (SACM) can set (or change) the field values of the feature sets based on a security command received from a host device (200 in FIG. 1) according to a security standard protocol, e.g., the TCG protocol, or determine the field values of the feature sets based on biometric authentication data (BAD) received from a biometric recognition module (300 in FIG. 1), and set (or change) the field values based on the determined values.
[0043] FIGS. 4a and 4b show examples of implementations of feature set tables set by a security access control module according to an exemplary embodiment of the present disclosure.
[0044] FIG. 4a shows an example of an implementation of an authorization table (ATB), and FIG. 4b shows an example of an implementation of a locking table (LTB). The authorization table (ATB) and the locking table (LTB) may each include a plurality of fields (FDs) and at least one feature set (FS) that includes a set value corresponding to each of the plurality of fields (FDs).
[0045] Referring to FIG. 4a, a plurality of fields (FDs) of the authorization table (ATB) may include, for example, a unique identifier field (UID), a name field (NM), an authorization enable field (EN), an action field (OP), and a credential field (CRD), and the authorization table (ATB) may include other types of fields. The unique identifier field (UID) represents a setting value for identifying an object (target of a feature set) within the table, for example, the authorization table (ATB) and the SP containing said table, and may be, for example, an 8-byte identifier. The name field (NM) represents the name of the object, and in the authorization table (ATB), the object may represent users, for example, a first administrator (Admin1), a first user (User1), and a second user (User2). The authorization enable field (EN) indicates whether the authorization is enabled and may be set to true (T) or false (F). The operation field (OP) represents an authentication method based on credentials (CRD). For example, if a password is set in the operation field (OP), authorization authentication based on the password method can be performed based on the credentials set in the credentials field (CRD). The credentials field (CRD) represents authentication information for authenticating an object used with authorization. For example, personal identification numbers for users (C_PIN_Admin1, C_PIN_User1, C_PIN_User2) can be set as credentials. As described above with reference to FIGS. 2a and 2b, credentials can be set based on a unique value included in a password (PW) received from a host device (200a in FIG. 2) or biometric authentication data (BAD) received from a biometric recognition module (300).
[0046] Referring to FIG. 4b, a plurality of fields (FDs) of the locking table (LTB) may include, for example, a unique identifier field (UID), a name field (NM), a range field (RNG), a read / write lock enable field (RWEN), a read / write lock field (RWL), etc., and the locking table (LTB) may include other types of fields. The range field (RNG) represents a range in which read / write locks and unlocks are controlled within a security area (SA) of non-volatile memory (110 in FIG. 1), and may be represented as a range of logical block addresses (hereinafter LBA), for example, as shown in FIG. 4b. In an embodiment, for each user, for example, a first administrator (Admin1), a first user (User1), and a second user (User2), the range in which read / write locks and unlocks are controlled may be set differently as shown. However, this is not limited to, and read / write locks and unlocks may be controlled for the entire security area (SA) for at least one user.
[0047] The Read / Write Lock Enable field (RWEN) indicates whether a lock for read and / or write to an object is enabled, and the Read / Write Lock field (RWL) indicates a locked or unlocked state for read and / or write. The Read / Write Lock Enable field (RWEN) and the Read / Write Lock field (RWL) can be set to True (T) or False (F), and when the Read / Write Lock field (RWL) is set to True (T), read and / or write to the range is set to a locked state, and access for read and / or write to the range may be blocked.
[0048] For example, according to the setting values of the feature set (FS) of the third column in the locking table (LTB) of FIG. 4b, for the second user (User2), the read / write lock is enabled by setting the read / write lock enable (RWEN) to true (T) for the range corresponding to the 5th LBA (LBA5) to the 8th LBA (LBA8) in the security area (SA) of the non-volatile memory (120), and the read / write lock (RWL) is set to false (F), so that the read / write is in an unlocked state.
[0049] Referring to FIGS. 4a and 4b, an authorization table (ATB) and a locking table (LTB) have been described by way of example. However, the feature set tables that can be set by the security access control module (SACM) according to the embodiment of the present disclosure are not limited thereto, and the security access control module (SACM) can set various types of feature set tables based on security standard protocols, and can also determine the field values of the feature set during the authorization authentication step.
[0050] Referring further to FIG. 3, for example, when a security function of a storage device (100) is configured under the control of a host device (200), the security access control module (SACM) may receive a security command (e.g., a security command for registration of authority) from the host device (200) during the user authority registration step, which includes a user authority registration request and setting values, and may configure feature sets for user authority based on the setting values, such as a feature set (FS1) of the authority table (ATB) in FIG. 4a and a feature set (FS2) of the locking table (LTB) in FIG. 4b. The received configuration values may include, for example, values for the unique identifier field (UID), name field (NM), authorization enable field (EN), and operation field (OP) of the feature set (FS1) of the authorization table (ATB) of FIG. 4a, and the unique identifier field (UID), name field (NM), range field (RNG), read / write lock enable field (RWEN), and read / write lock field (RWL) of the feature set (FS2) of the locking table (LTB) of FIG. 4b. At this time, the security access control module (SACM) may set the credential value of the credential (CRD) based on the password received from the host device (200) and set the read / write lock field (RWL) to true (T). The security access control module (SACM) can receive a request for authorization, a setting value for a unique identifier field (UID), and a password from the host device (200) as a security command requesting user authorization during the user authorization authentication step.The security access control module (SACM) performs user authorization authentication based on a password, and when user authorization authentication is successful, receives a setting value for the read / write lock field (RWL) from the host device (200) as a security command (e.g., a setting value indicating false (F)), and by setting the read / write lock (RWL) of the locking table (LTB) to false (F) based on the setting value, it can allow access for the user's read and / or write to the range (RNG) set for the user associated with the received password.
[0051] When the storage device (100) sets the security function itself, the security access control module (SACM) receives a command for registration of authority from the host device (200) (or other input / output device) during the user authority registration step, and in response to this, receives biometric authentication data (BAD in FIG. 1) from the biometric recognition module (300 in FIG. 1), and determines the field values of feature sets for user authority, such as the feature set (FS1) of the authority table (ATB) in FIG. 4a and the feature set (FS2) of the locking table (LTB) in FIG. 4b, based on the biometric authentication data (BAD), and can set the feature sets based on the determined values. At this time, the security access control module (SACM) can set the credential value of the credential (CRD) based on the biometric authentication data (BAD) received from the biometric recognition module (300), and set the read / write lock field (RWL) to true (T). However, if the range is set differently for each user, the setting value for the range field (RNG) may be received from the host (200) (or other input / output device), and the security access control module (SACM) may set the range field (RNG) based on the received setting value.
[0052] The security access control module (SACM) receives biometric authentication data (BAD) from the biometric recognition module (300) during the user authorization authentication step, performs user authorization authentication based on the biometric authentication data, and if user authorization authentication is successful, sets the read / write lock field (RWL) of the locking table (LTB) to false (F), thereby allowing access for the user's read and / or write to the range of the security area (SA) set for the user of the received biometric authentication data (BAD).
[0053] As described above, the storage device (100) according to an embodiment of the present disclosure has a security access control module (SACM) that can set (or change) field values of feature sets according to a security standard protocol, and even if the host device (200) does not provide setting values including a password, the security access control module (SACM) can determine field values of feature sets according to a security standard protocol based on biometric authentication data (BAD) received from a biometric recognition module (300), and set (or change) field values of feature sets based on the determined values.
[0054] FIG. 5 is a block diagram schematically illustrating a memory controller according to an exemplary embodiment of the present disclosure.
[0055] Referring to FIG. 5, the memory controller (110a) may include a processor (11), memory (12), a security key storage unit (13), a host interface (14), a peripheral device interface (15), a data processing unit (16), and a non-volatile memory interface (17) (hereinafter referred to as the NVM interface). In an embodiment, the components of the memory controller (110a), such as the processor (11), memory (12), security key storage unit (13), host interface (14), peripheral device interface (15), data processing unit (16), and NVM interface (17), may communicate with each other via a system bus (18). In an embodiment, the memory controller (110a) may further include other components, such as a ROM (Read Only Memory), an error correction circuit, a buffer, etc.
[0056] The processor (11) may include a central processing unit (CPU) or a microprocessor, and may control the overall operation of the memory controller (110a). In one embodiment, the processor (110) may be implemented as a multi-core processor, for example, as a dual-core processor or a quad-core (quad) processor.
[0057] The memory (12) may be implemented as a volatile memory such as DRAM or SRAM or a non-volatile memory, and firmware may be loaded into the memory (12). The firmware (FW) may include program code (or instructions) in which the operation algorithm of the aforementioned security access control module (SACM) is implemented. The firmware may be stored in non-volatile memory located inside or outside the memory controller (110a), such as ROM (R), EEPROM (Electrically Erasable Programmable Read-Only Memory), PRAM (Phase-change Memory), flash memory, etc., or in non-volatile memory (120), and may be loaded into memory (12) when the storage device (100 of FIG. 1) is powered on. By the processor (11) executing the firmware loaded into memory (12), such as a security access control module (SACM), the security function of the storage device (100) may be performed. For example, the security access control module (SACM) may encrypt or decrypt a security key, and
[0058] The security key storage unit (13) can store encrypted security keys. In an embodiment, when multiple user rights are registered, multiple encrypted security keys can be stored based on multiple unique values corresponding to each of the multiple user rights or each of the multiple passwords. The security key storage unit (13) can be implemented as a non-volatile memory such as a register, PRAM, or flash memory.
[0059] The host interface (14) can provide an interface between the host device (200) and the memory controller (110a), and, for example, the host interface (14) can be implemented as one of various interfaces such as a USB (Universal Serial Bus) interface, a USF (Universal Flash Storage) interface, a MMC (Multimedia Controller) interface, an eMMC (embedded MMC) interface, a PCIe (Peripheral Component Interconnect Express) interface, an ATA (Advanced Technology Attachment) interface, a SATA (Serial Advanced Technology Attachment) interface, a PATA (Parallel Advanced Technology Attachment) interface, a SCSI (Small Computer System Interface), a SAS (Serial Attached SCSI), an ESDI (Enhanced Small Disk Interface), an IDE (Integrated Drive Electronics) interface, etc.
[0060] The peripheral interface (15) can provide an interface between the memory controller (110a) and the biometric authentication module (300). For example, the peripheral interface (15) can provide communication interfaces such as a UART (Universal Asynchronous Receiver Transmitter) interface, an I2C (inter integrated circuit) interface, a SPI (serial peripheral interface), a MIPI (Mobile industry processor interface), an eDP (embedded display port) interface, etc.
[0061] The peripheral device interface (15) can transmit a trigger signal (e.g., a biometric authentication trigger signal or a biometric registration trigger signal) to operate the biometric recognition module (300). Additionally, the peripheral device interface (15) can receive a biometric authentication message and a unique value from the biometric recognition module (300). For example, a biometric information registration message or a biometric authentication result message (biometric authentication failure or biometric authentication success) may be received as a biometric authentication message.
[0062] The data processing unit (16) can perform encryption or decryption on user data. The data processing unit (16) can perform encryption or decryption on user data based on a security key. The data processing unit (16) can perform encryption on user data received from the host device (200) based on a security key. For example, the data processing unit (16) can scramble user data based on a security key. The encrypted user data can be stored in non-volatile memory (120). The data processing unit (16) can perform decryption on the encrypted user data read from the non-volatile memory (120) based on a security key. For example, the data processing unit (16) can descramble the encrypted user data based on a security key. The decrypted user data can be transmitted to the host device (200).
[0063] The NVM interface (17) can provide an interface between the memory controller (110a) and the non-volatile memory (120). Encrypted user data can be transmitted and received between the memory controller (110a) and the non-volatile memory (120) through the non-volatile memory interface (17). In one embodiment, the number of NVM interfaces (17) may correspond to the number of non-volatile memory chips included in the storage device (10) or the number of channels between the memory controller (100a) and the non-volatile memory (120).
[0064] FIG. 6 is a flowchart illustrating a method of operation of a storage device based on received biometric authentication data according to an exemplary embodiment of the present disclosure, and FIG. 7 illustrates an exemplary data format according to a security standard protocol.
[0065] The operation method of Fig. 6 can be performed on the storage device (100) of Fig. 1, and the above description regarding the storage device (100) can be applied to the present embodiment.
[0066] Referring to FIGS. 1 and FIGS. 6, a storage device (100) can receive biometric data (BAD) from a biometric recognition module (300) (S10). The biometric data (BAD) may include biometric data generated by sensing a user's biometric data, or biometric information generated based on biometric data. Alternatively, the biometric data (BAD) may include a unique value and a biometric authentication result based on biometric information.
[0067] The storage device (100) can convert biometric data (BAD) into security configuration data (e.g., SCSD of FIG. 7) in a data format according to a security standard protocol (S20). The security configuration data may have the same data format as a security command that can be received from a host device (200). The security access control module (SACM) of the memory controller (110) can function as a parser to generate security configuration data (SCSD) based on the biometric data (BAD).
[0068] Referring to FIG. 7, a data format according to a security standard protocol, such as the TCG protocol, may have a data block composed of multiple bytes. For example, a data format according to the TCG protocol may include 16 rows (R) (e.g., 0000 to 01F0 expressed in hexadecimal), and each row may contain 16 bytes of data. Thus, security configuration data (SCSD) and security commands may be a 512-byte data block (referred to as a data packet). The meaning (purpose) represented by each of the single-byte or multi-byte data values included in each row is defined in the security standard protocol and may represent field values of a feature set according to the security standard protocol.
[0069] For example, when the security configuration data (SCSD) corresponds to a security command requesting a session open for the locking SP, the security access control module (SACM) can set a total of 17 bytes of data value, consisting of the lower 5 bytes (6 bytes on the right) of the 6th row (0050) and the upper 12 bytes (12 bytes on the left) of the 7th row (0060), based on the unique value of the biometric data (BAD), namely "3C 41 64 6D 69 6E 31 5F 70 61 73 73 77 6F 72 64 3E", as a password according to the security standard protocol.
[0070] Referring further to FIG. 6, the storage device (100) can perform user authentication based on security configuration data (SCSD) (S30). The security access control module (SACM) can determine that authorization authentication is successful if the password in the security configuration data (SCSD) matches the credential value of the user authority set when registering the user authority. The storage device (100) can open a session (S40). For example, if authorization authentication for the user authority is successful, the security access control module (SACM) can open (start) a session for the locking SP.
[0071] The storage device (100) can set the lock / unlock status of the security area (SA) of the non-volatile memory (120) (S50). For example, the security access control module (SACM) can set the lock / unlock status by determining the field value (setting value) of the read / write lock field (RWL) through the session.
[0072] The storage device (100) can set up master boot record shadowing (S60). For example, the security access control module (SACM) can set up a master boot record table so that a master boot record included in a security zone (SA) is read through a session (referred to as un-shadowing of the master boot record) or set up a master boot record table so that a master boot record included in a non-security zone is read (referred to as shadowing of the master boot record).
[0073] For example, the security access control module (SACM) can set the storage device (100) to an unlocked state by setting the setting value of the read / write lock field (RWL) to false (F) in step S50 and setting the master boot record table so that the master boot record included in the security area is read in step S60.
[0074] The storage device (100) can terminate the session (S70). After the security access control module (SACM) sets the security function, for example, the storage device (100) can be set to an unlocked state and the session can be terminated.
[0075] FIGS. 8a and 8b are flowcharts illustrating a method for authenticating user rights of a storage system according to an exemplary embodiment of the present disclosure.
[0076] FIG. 8a illustrates a case in which a memory controller (110) provided in a storage device (100 of FIG. 1) sets up a security function by performing user authorization authentication independently without the control of a host device (200), and FIG. 8b illustrates a case in which a memory controller (110) sets up a security function by performing user authorization authentication under the control of a host device (200a). For example, the host device (200b) of FIG. 2b may operate as the host device (200) of FIG. 6, and the host device (200a) of FIG. 2a may operate as the host device (200) of FIG. 6b.
[0077] Referring to FIG. 8a, a host device (200) and a storage device (100 in FIG. 1) are connected (or linked) (S111), and at this time, the storage device (100) may be set to a locked state (S112). When the storage device (100) is disconnected from the host device (200) or the power of the storage device (100) is turned off, the storage device (100) may be set to a locked state, and even if the storage device (100) is subsequently connected to the host device (200) as in step S111, the storage device (100) may maintain the locked state. When the storage device (100) is in a locked state, the memory controller (110) may set the read and / or write state for the secure area of the non-volatile memory (120) to a locked state and provide information about the non-secure area (e.g., Shadow Master Boot Record) to the host device (200). For example, the memory controller (110) can set the read and / or write state of the secure area of the non-volatile memory (120) to a locked state by setting the field value of the read / write lock field (RWL) of the locking table (LTB) of FIG. 4b to false (F), and can set the value of the master boot record table to indicate a shadow master boot record stored in the non-secure area. The host device (200) can access the non-secure area based on the shadow master boot record.
[0078] The memory controller (110) can transmit a biometric authentication trigger signal requesting biometric authentication to the biometric recognition module (300) (S113). When the host device (100) and the storage device (200) are connected, the memory controller (110) can automatically transmit the biometric authentication trigger signal to the biometric recognition module (300), that is, regardless of control from the host device (100).
[0079] The biometric recognition module (300) can perform biometric authentication in response to a biometric authentication trigger signal (S121). The biometric recognition module (300) can sense the user's biometric data to acquire biometric data. In an embodiment, the biometric recognition module (300) generates biometric information based on the biometric data, and if the biometric information matches the previously stored biometric information, it can determine that biometric authentication has been successful.
[0080] The biometric recognition module (300) can transmit biometric authentication data to the memory controller (110). The user's biometric data (or biometric information) may be transmitted to the memory controller (110) as biometric authentication data, or a unique value generated based on the biometric information and a biometric authentication success message may be transmitted to the memory controller (110) as biometric authentication data. For example, as described in step S121, if the biometric recognition module (300) determines whether biometric authentication is successful based on whether the biometric information generated based on the acquired biometric data matches the previously stored biometric information, a unique value and a biometric authentication success message may be transmitted to the memory controller (110) as biometric authentication data.
[0081] The memory controller (110) can perform user authorization based on biometric authentication data (S114). For example, the memory controller (110) can perform user authorization based on a unique value. As described with reference to FIG. 6, the memory controller (110) can generate security configuration data having a data format according to a security standard protocol based on biometric authentication data, such as a unique value, and perform user authorization based on the security configuration data.
[0082] The memory controller (110) can determine whether user authorization authentication is successful (S115). The memory controller (110) can determine that authorization authentication is successful if the password of the security setting data generated based on the biometric authentication data matches the credential value of the user authorization set when registering the user authorization. At this time, the password of the security setting data may be the hash value of the unique value of the biometric authentication data.
[0083] If user authorization authentication is successful (pass), the memory controller (110) can set the storage device (100) to an unlocked state (S116). The memory controller (110) can set the read and / or write state of the security area of the non-volatile memory (120) to an unlocked state and provide information about the security area to the host device (200). For example, the memory controller (110) can set the read and / or write state of the security area of the non-volatile memory (110) (or a specific range corresponding to a unique value within the security area) to an unlocked state by setting the field value of the read / write lock field (RWL) of the locking table (LTB) of FIG. 4b to True (T), and can set the value of the master boot record table to indicate the master boot record stored in the security area. The host device (200) can access the security area of the non-volatile memory (120) based on the master boot record. The host device (200) transmits a command to the memory controller (110) requesting to write or read out a security area where user authorization authentication has been performed, and the memory controller (110) encrypts and stores user data to be stored in the said areas based on a security key, and performs decryption based on the security key on the encrypted user data read out from the said areas, and transmits the decrypted user data to the host device (200).
[0084] In an embodiment, when the storage device (100) changes from a locked state to an unlocked state, a relink is performed between the host device (200) and the storage device (100), and subsequently, the host device (200) can access the secure area of the non-volatile memory (120).
[0085] If user authorization fails, the storage device (100) may be set to a locked state (S112). In other words, the storage device (100) remains in a locked state, and the host device (200) can access the non-secure area of the non-volatile memory (120), but cannot access the secure area.
[0086] Referring to FIG. 8b, a host device (200) and a storage device (100 in FIG. 1) are connected (S211), and at this time, the storage device (100) can be set to a locked state (S212).
[0087] The host device (200) can run software to provide security functions for the storage device (100) (S231). For example, the operating system of the host device (200) can run self-encrypting drive support software (SED support software) for the storage device (100). Accordingly, the host device (200) can communicate with the storage device (100) according to a security standard protocol.
[0088] The host device (200) may transmit a security command including a user authorization authentication request and a password to the memory controller (110) (S232). The security command may be a command defined by a security standard protocol, and the password may be a value generated by user input. For example, the security command may be a command requesting a session open according to a security standard protocol. The security command may be a 512-byte data block (or data packet).
[0089] The memory controller (110) can perform user authorization based on a password received from the host device (200) (S213). The memory controller (110) can determine whether user authorization is successful (S214). The memory controller (110) can determine whether the received password is the same as the password used when setting the credential value for user authorization.
[0090] If user authorization is successful (passed), the memory controller (110) can send a response corresponding to the security command to the host device (200) (S215). For example, the response may indicate that a session has been opened.
[0091] The host device (200) can transmit a security command containing a setting value for setting the storage device to an unlocked state to the memory controller (110) (S233). The storage device (100) can set the storage device (100) to an unlocked state based on the received security command (S216). If user authorization authentication fails, the storage device (100) can be set to a locked state (S212). In other words, the storage device (100) can maintain a locked state.
[0092] As described with reference to FIGS. 8a and 8b, when the storage device (100) is connected to the host device (200), the memory controller (110) converts biometric authentication data from the biometric recognition module (300) into security setting data having a data format according to a security standard protocol, and can perform user authorization authentication without the control of the host device (200) based on the security setting data. Alternatively, the memory controller (110) can perform user authorization authentication based on a security command from the host device (200) that includes a password. In this way, the storage device (100) can not only set security functions by performing user authorization authentication under the control of the host device (200) through a security standard protocol, but also set security functions independently without the control of the host device (200) by performing user authorization authentication based on biometric authentication data from the biometric recognition module (300), thereby increasing the usability of the security functions of the storage device (100).
[0093] FIG. 9 illustrates a method in which a security access control module according to an exemplary embodiment of the present disclosure sets a lock state and an unlock state for non-volatile memory. FIG. 9 illustrates a method in which a security access control module sets a lock state and an unlock state by setting master boot shadowing.
[0094] Referring to FIG. 9, the non-volatile memory (120) may include a secure area (SA) and a non-secure area (NSA). The secure area (SA) may be referred to as a user area as an area where encrypted user data is stored. The secure area (SA) may be divided into a plurality of user areas (e.g., a plurality of partitions or volumes). The non-secure area (NSA) may be referred to as a reserved area as a specific area that is pre-set. In an embodiment, a plurality of ranges may be set for each area of the secure area (SA) and the non-secure area (NSA) based on a logical block address (LBA). A master boot record (hereinafter referred to as MBR) containing information about the area (e.g., partition or volume information, boot code for booting, etc.) may be stored in each of the secure area (SA) and the non-secure area (NSA). In the present disclosure, MBR refers to a first MBR stored in a secure area (SA), and SMBR (shadow MBR) may refer to a second MBR stored in a non-secure area (NSA).
[0095] The secure area (SA) can be accessed when it is unlocked after user authorization is successful, and the non-secure area (NSA) can be accessed regardless of user authorization. Before user authorization is performed in the initial state where the storage device (100) is connected to the host device (200), the non-volatile memory (120) may be in a locked state, and the security access control module (SACM) may set the MBR table so that the SMBR of the non-secure area (NSA) is read. For example, the setting value of the MBR table may indicate the location of the pointer in the non-volatile memory (120), and in the locked state, the pointer may indicate the LBA where the SMBR is stored. Accordingly, the SMBR is loaded into the memory controller (110 in FIG. 1), and based on the information contained in the SMBR, the host device (200) can read the data stored in the non-secure area (NSA). For example, the non-secure area (NSA) may store SMBR and software (e.g., software supporting user configuration or self-encrypting drive support software (SED support software)).
[0096] Meanwhile, if user authorization is successful, the security area (SA) can be set to an unlocked state, and the security access control module (SACM) can set the MBR table so that the MBR of the security area (SA) is read. For example, depending on the setting value of the MBR table, a pointer can indicate the LBA where the MBR is stored. Accordingly, the MBR is loaded into the memory controller (110 in FIG. 1), and based on the information contained in the MBR, the host device (200) can read data stored in the security area (NSA), such as user data.
[0097] FIGS. 10a and FIGS. 10b exemplarily illustrate a plurality of user rights accessible to a secure area of non-volatile memory according to an exemplary embodiment of the present disclosure.
[0098] Referring to FIGS. 10a and 10b, the security area (SA) of the non-volatile memory (120) can be accessed by multiple users with user rights set, and the area that each user can access can be set to be the same or different.
[0099] Referring to FIG. 10a, User 1 and User 2 may have user rights to access the entire security area (SA), for example, the global range. When user rights authentication of User 1 or User 2 is successful, for example, when user rights authentication is successful based on the biometric authentication data of User 1 or User 2, read and / or write access to the entire security area (SA) is set to an unlocked state, and upon a request from the host device (200 in FIG. 1), the memory controller (110 in FIG. 1) may access the security area (SA) for read and / or write access.
[0100] Referring to FIG. 10b, User 1 may have user rights to access range 1, User 2 may have user rights to access range 2, and User 3 may have user rights to access ranges 2 and 3. When User 1's user rights authentication is successful, read and / or write to range 1 may be set to an unlocked state, when User 2's user rights authentication is successful, read and / or write to range 2 may be set to an unlocked state, and when User 3's user rights authentication is successful, read and / or write to ranges 2 and 3 may be set to an unlocked state.
[0101] FIG. 11 is a flowchart illustrating a method for registering user rights in a storage system according to an exemplary embodiment of the present disclosure. The method of FIG. 11 is a method for registering user rights based on biometric authentication data and can be performed in the storage system of FIG. 1. It will be described with reference to FIG. 1.
[0102] Referring to FIG. 11, the host device (200) can transmit a registration command requesting user authority registration to the memory controller (110) (S331). In response to the registration command, the memory controller (110) can transmit a registration trigger signal requesting biometric information registration to the biometric recognition module (300) (S311).
[0103] The biometric recognition module (300) can store the user's biometric information (S321). The biometric recognition module (300) can sense the user's biometric data in response to a registration trigger signal, acquire biometric data, and generate biometric information based on the biometric data. By storing the biometric information, the biometric recognition module (300) can register the user's biometric information. In other words, the biometric recognition module (300) can manage the user's biometric information.
[0104] The biometric recognition module (300) can transmit biometric authentication data to the memory controller (110) (S322). The biometric recognition module (300) can transmit a message indicating the completion of biometric information registration and a unique value corresponding to the biometric information (e.g., a hash value of the biometric information) as biometric authentication data.
[0105] The memory controller (110) can set user rights based on biometric authentication data (S312). As described with reference to FIG. 3, the security access control module (SACM) can determine field values of feature sets for user rights based on biometric authentication data, such as the feature set (FS1) of the authority table (ATB) in FIG. 4a and the feature set (FS2) of the locking table (LTB) in FIG. 4b, and set the feature sets based on the determined values. For example, the security access control module (SACM) can set a name for user rights and set credential values for user rights based on the unique value of the biometric authentication data. In an embodiment, the security access control module (SACM) can generate security setting data having a data format according to a security standard protocol based on biometric authentication data and set user rights using the security setting data.
[0106] The memory controller (110) can enable user rights (S313). For example, the security access control module (SACM) can enable user rights by setting the permission enable field (EN) of the permission table (ATB) to true (T). Then, the memory controller (110) can set the storage device (110) to a locked state (S314). For example, the security access control module (SACM) can set the read / write lock field (RWL) of the locking table (LTB) to true (T). The memory controller (110) can send a registration completion response to the host device (200) (S315). Thus, user rights registration can be completed.
[0107] Meanwhile, in step S321, it was described that the biometric recognition module (300) stores the user's biometric information, but it is not limited thereto. In the embodiment, the biometric recognition module (300) may sense the user's biometric data to acquire biometric data and transmit the biometric data to the memory controller (110) as biometric authentication data. The biometric recognition module (300) does not store biometric data or biometric information. In this case, the biometric recognition module (300) only performs the function of acquiring the user's biometric data, and the memory controller (110) may generate biometric information based on the biometric data and store the biometric information. In other words, the memory controller (110) may register and manage the user's biometric information. The memory controller (110) may generate a unique value based on the generated biometric information and set a credential value based on the unique value.
[0108] In this embodiment, the memory controller (110) is illustrated as performing user authority registration in response to a request from the host device (200), but is not limited thereto. In the embodiment, the memory controller (110) may perform user authority registration in response to a request from an input / output device provided in a storage system other than the host device (200). For example, the storage device (100) may include an input / output device equipped with a user interface. In step S331, the memory controller (110) receives a signal requesting user authority registration from an input / output device other than the host device (200), and in step S315, the memory controller (110) may transmit a registration completion response to the input / output device.
[0109] FIG. 12 is a flowchart illustrating a method for deleting user rights in a storage system according to an exemplary embodiment of the present disclosure. The method of FIG. 10 is a method for deleting user rights and can be performed in the storage system of FIG. 1. It will be described with reference to FIG. 1.
[0110] Referring to FIG. 12, a host device (200) may transmit a deletion command requesting the deletion of user rights to a memory controller (110) (S431). In response to the deletion command, the memory controller (110) may transmit a deletion trigger signal requesting the deletion of biometric information to a biometric recognition module (300) (S411). If the biometric recognition module (300) has stored multiple biometric information, the deletion command transmitted by the host device (200) to the memory controller (110) may include an index representing the biometric information to be deleted, and the memory controller (110) may transmit the index along with the deletion trigger signal to the biometric recognition module (300).
[0111] The biometric recognition module (300) can delete stored biometric information in response to a deletion trigger signal (S421). The biometric recognition module (300) can delete biometric information represented by an index among a plurality of biometric information. The biometric recognition module (300) can transmit a deletion completion message to the memory controller (110) (S422).
[0112] The memory controller (110) can disable user rights (S412). For example, the security access control module (SACM) can disable user rights by setting the permission enable field (EN) of the permission table (ATB) to false (F). Then, the memory controller (110) can delete user rights by deleting the name of the user rights (S413). The memory controller (110) can send a deletion completion response to the host device (200) (S424). This completes the registration of user rights.
[0113] Meanwhile, in this embodiment, the memory controller (110) is shown to perform user authority deletion in response to a request from the host device (200), but is not limited thereto. In the embodiment, the memory controller (110) may perform user authority deletion in response to a request from an input / output device provided in a storage system other than the host device (200), and transmit a response indicating completion of user authority deletion to the input / output device.
[0114] FIG. 13 is a block diagram showing one embodiment of a biometric recognition module according to an exemplary embodiment of the present disclosure.
[0115] Referring to FIG. 11, the biometric recognition module (300a) may include a sensor (310), a controller (320), a storage unit (330), and an interface (340).
[0116] The sensor (310) can sense the user's biological data to acquire biological data. For example, if the sensor (310) is implemented as a fingerprint sensor, the fingerprint sensor can sense the user's finger fingerprint to generate (or acquire) a fingerprint image. When the sensor (310) receives a trigger signal, such as a biometric authentication trigger signal or a biometric registration trigger signal, from the memory controller (110), the sensor (310) can acquire the user's biological data.
[0117] The controller (320) can generate and manage biometric information (AUIF). The controller (320) can store, manage, and delete biometric information (AUIF). Additionally, the controller (320) can perform biometric authentication. The controller (330) can convert biometric data into template data, i.e., biometric information (AUIF), based on a set data format. In the user authorization registration step of the storage device (100 in FIG. 1), the controller (320) can register the biometric information (AUIF) by storing the biometric information (AUIF) in the storage unit (330).
[0118] The storage unit (330) can be implemented as a non-volatile memory and can maintain the stored biometric information (AUIF_R) even when the power applied to the biometric recognition module (300a) is cut off. When biometric information registration is performed for multiple users, the storage unit (330) can store biometric information (AUIF_R) for each of the multiple users.
[0119] When performing user authorization, the controller (320) performs biometric authentication based on biometric information (AUIF) generated by sensing the user's biometrics, and when biometric authentication is successful, it can transmit biometric authentication data based on the biometric information (AUIF) to the memory controller (110). The controller (320) determines whether there is a match by comparing the biometric information (AUIF) with the biometric information (AUIF_R) stored in the storage unit (330), and if the biometric information (AUIF) matches one of the stored biometric information (AUIF_R), the controller (320) can determine that biometric authentication has been successful.
[0120] The controller (320) can also generate a unique value (UNQV) based on biometric information (AUIF). For example, the controller (320) can generate a unique value (UNQV) by encoding the biometric information (AUIF). The unique value (UNQV) has a data format that the biometric recognition module (300a) and the memory controller (110) can mutually recognize, and for example, the unique value (UNQV) may contain hash data of tens of bytes.
[0121] The controller (320) can delete the user's biometric data when it receives a trigger signal requesting the deletion of biometric information from the memory controller (110). In an embodiment, when a plurality of biometric information (AUIF_R) is stored in the storage unit (330), the controller (320) can delete the corresponding biometric information (AUIF_R) based on an index representing the biometric information (AUIF_R) to be deleted, which is received along with the trigger signal.
[0122] The controller (320) can be implemented as a combination of a processor such as an MCU (Micro Control Unit) or CPU (Central Processing Unit) and firmware, or as hardware logic such as an FPGA (Field Programmable Gate Array).
[0123] The interface (340) receives a trigger signal, such as a biometric information registration trigger signal or a biometric authentication trigger signal, from the memory controller (110), and can transmit a biometric authentication message (MSG) and a unique value (UNQV) from the memory controller (110). For example, the interface (340) can provide a communication interface such as a UART (Universal Asynchronous Receiver Transmitter) interface, an I2C (inter integrated circuit) interface, a SPI (serial peripheral interface), a MIPI (Mobile industry processor interface), an eDP (embedded display port) interface, etc.
[0124] FIG. 14 is a block diagram showing a storage device and a storage system according to an exemplary embodiment of the present disclosure.
[0125] Referring to FIG. 14, the storage system (10c) may include a storage device (100c) and a host device (200). The storage device (100c) may include a memory controller (110), a non-volatile memory (120), and a biometric module (300).
[0126] The configuration and operation of the storage system (10c) are similar to the configuration and operation of the storage system (10) of FIG. 1. However, in this embodiment, a biometric recognition module (300) may be provided within the storage device (100c). In this embodiment, the biometric recognition module (300a) of FIG. 13 may be applied as the biometric recognition module (300). The biometric recognition module (300) stores and manages biometric information and may provide biometric authentication data containing a unique value based on biometric information to the memory controller (110) during the user authority registration step and the user authority authentication step. However, it is not limited thereto, and the biometric recognition module (300) may sense the user's biometric information to acquire biometric data and provide the biometric data to the memory controller (110). The memory controller (110) may convert the biometric data into biometric information and store and manage the biometric information. The memory controller (110) may generate a unique value used during biometric authority registration and user authority authentication based on the biometric information.
[0127] FIG. 15 is a block diagram showing a storage device and a storage system according to an exemplary embodiment of the present disclosure.
[0128] Referring to FIG. 13, the storage system (10d) may include a storage device (100d) and a host device (200), and the storage device (100d) may include a memory controller (110), a non-volatile memory (120), and an input / output device (130). The configuration and operation of the storage system (10d) are similar to the configuration and operation of the storage system (10) of FIG. 1. However, in this embodiment, the storage device (100d) is equipped with an input / output device (130), and security functions can be set based on user input and / or biometric authentication data received through the input / output device (130) without control by the host device (100d).
[0129] The input / output device (130) can receive user input and transmit the user input to the memory controller (110). For example, the input / output device (130) may be implemented as a touch screen, or a screen including user biometric data (e.g., fingerprint, iris, face, etc.) or sensing functions. A user's password may be received or biometric authentication data may be obtained through the input / output device (130), and the input / output device (130) may transmit the password or biometric authentication data to the memory controller (110). The security access control module (SACM) can set security functions by setting user rights and performing user rights authentication based on the received password or biometric authentication data.
[0130] In an embodiment, the input / output device (130) can receive a user request, such as user right registration, user right authentication, or user right deletion, through a user interface, and can transmit the user request to the memory controller (110), and the memory controller (110) can perform user right registration, user right authentication, or user right deletion in response to the user request.
[0131] FIG. 16 shows an electronic system according to an exemplary embodiment of the present disclosure.
[0132] Referring to FIG. 16, the computing system (1000) may include a memory system (1100), a processor (1200), RAM (1300), an input / output device (1400), a power supply (1500), and a biometric recognition module (1600). Meanwhile, although not shown in FIG. 14, the computing system (1000) may further include ports capable of communicating with a video card, sound card, memory card, USB device, etc., or with other electronic devices. The computing system (1000) may be implemented as a personal computer, as a portable electronic device such as a laptop computer, mobile phone, PDA (personal digital assistant), and camera, etc., or as an electronic device for a vehicle equipped in an automobile, airplane, ship, etc.
[0133] The processor (1200) can perform specific calculations or tasks. According to an embodiment, the processor (1200) may be a microprocessor or a central processing unit (CPU). The processor (1200) can communicate with the RAM (1300), input / output device (1400), and memory system (1100) through a bus (1700), such as an address bus, a control bus, and a data bus. The processor (1200) may also be connected to an expansion bus, such as a Peripheral Component Interconnect (PCI) bus.
[0134] The memory system (1100) and the biometric recognition module (1600) may be implemented using the storage device and biometric recognition module exemplified in FIGS. 1 and FIG. 12. The memory system (1100) may be a storage device that supports self-encryption. The memory system (1100) may perform user authority registration and user authority authentication based on the security command and setting value (e.g., password) received from the processor (1200) when the processor (1200) can provide a security command and setting value according to a security standard protocol. Additionally, the memory system (1100) may perform user authority registration and user authority authentication independently based on biometric authentication data received from the biometric authentication module (1600) when the processor (1200) cannot provide a security command and setting value.
[0135] RAM (1300) can store data required for the operation of the computing system (1000). For example, RAM (1300) can be implemented as DRAM, mobile DRAM, SRAM, PRAM, FRAM, RRAM, and / or MRAM. Input / output devices (1400) may include input means such as a keyboard, keypad, mouse, etc., and output means such as a printer, display, etc. Power supply devices (1500) can supply operating voltage required for the operation of the computing system (1000).
[0136] FIG. 17 is a block diagram showing an SSD and an SSD system including the same according to an exemplary embodiment of the present disclosure.
[0137] Referring to FIG. 17, the SSD system (2000) may include a host device (2100), an SSD (2200), and a biometric module (2300). In an embodiment, the biometric module (2300) may be mounted within the SSD (2200).
[0138] The SSD (2200) can exchange signals (SGL) with the host device (1100) through the signal connector (SC) and receive power (PWR) from the host device (2100) through the power connector (PC).
[0139] The SSD (2200) may include an SSD controller (2210) and a plurality of non-volatile memories (2220, 2230, 2240). The storage devices (100, 100c, 100d) of FIGS. 1, FIGS. 14 and FIGS. 15 may be applied to the SSD (2200), and the memory controller (110) may be applied as the SSD controller (2210). The SSD controller (2210) may communicate with the non-volatile memories (2220, 2230, 2240) through a plurality of channels (CH1, CH2, CHn). The SSD controller (2210) can set security functions under the control of the host device (2100) or independently set security functions based on biometric authentication data received from the biometric recognition module (2300) by performing user authorization registration or user authorization authentication based on security commands and setting values received from the host device (2100). Accordingly, the SSD (2200) can provide security functions by communicating according to a security standard protocol, not only when connected to a host device (2100) that can provide security commands and setting values related to security functions, but also when connected to a host device (2100) that cannot provide security commands and setting values.
[0140] The storage system (10, 10c, 10d) according to the embodiment of the present disclosure described above can be installed or applied not only to an SSD system (2000), but also to a memory card system, a computing system, a UFS, etc.
[0141] As described above, exemplary embodiments have been disclosed in the drawings and specification. Although specific terms have been used to describe the embodiments in this specification, they are used only for the purpose of explaining the technical concept of this disclosure and are not intended to limit the meaning or the scope of this disclosure as defined in the claims. Therefore, those skilled in the art will understand that various modifications and equivalent alternative embodiments are possible therefrom. Accordingly, the true technical scope of protection of this disclosure should be determined by the technical concept of the appended claims. Explanation of the symbols
[0142] 10: Storage System 100, 100a, 100b, 100c, 100d: Storage Device 200, 200a, 200b: Host devices 110: Memory controller 120: Non-volatile memory device 130: Biometric module
Claims
Claim 1 A memory controller for controlling data writing and reading of a non-volatile memory including a secure area where encrypted user data is stored, comprising: a secure access control module that performs authorization registration and authorization authentication for user rights set for access control of the secure area; And when access to the security area is permitted, the system includes a data processing unit that performs encryption of user data received from a host device or decryption of the encrypted user data read from the security area; the security access control module generates first security setting data having a data format according to a security standard protocol based on first biometric authentication data including a biometric authentication result and a first unique value received from a biometric recognition module, and performs the registration of the user authority by setting field values of a feature set according to the security standard protocol based on the first security setting data; when the storage device including the memory controller and the host device are connected, the system transmits a biometric recognition trigger signal to the biometric recognition module; when the system receives second biometric authentication data including a biometric authentication success message and a second unique value from the biometric recognition module, it converts the second unique value into second security setting data having a data format according to the security standard protocol, and by comparing a password included in the second security setting data with a credential value among the field values of the feature set set according to the security standard protocol, the user authority A memory controller that performs the above-mentioned authorization authentication. Claim 2 delete Claim 3 A memory controller according to claim 1, characterized in that the security setting data is implemented as a 512-byte data block according to the security standard protocol. Claim 4 A memory controller according to claim 1, wherein the security access control module opens a session by performing authorization authentication based on the biometric authentication data, sets a lock / unlock for a security area of the non-volatile memory through the session, and sets master boot record shadowing. Claim 5 A memory controller according to claim 1, wherein the security access control module transmits an authentication trigger signal to the biometric recognition module when a storage device including the memory controller is connected to the host device, and performs the authorization authentication based on the biometric authentication data received from the biometric recognition module. Claim 6 delete Claim 7 A memory controller according to claim 1, wherein the security access control module allows access to the security area by setting the write and read states of the security area to an unlock state when the authorization authentication is successful. Claim 8 A memory controller according to claim 1, wherein the security access control module transmits a registration trigger signal to the biometric recognition module in response to the receipt of a user authority registration request, causing the biometric recognition module to store the user's biometric data, sets the credentials of the user authority based on the biometric authentication data, and activates the user authority. Claim 9 A memory controller according to claim 1, wherein the security access control module transmits a deletion trigger signal to the biometric recognition module to cause the biometric recognition module to delete the user's biometric data in response to the receipt of a request to delete a user authority, and when a deletion completion message is received from the biometric recognition module, the user authority is deactivated and the name information of the user authority is deleted. Claim 10 A non-volatile memory comprising a secure area where encrypted user data is stored in a storage device; and includes a memory controller that controls data writing and reading of the non-volatile memory, wherein the memory controller generates first security setting data having a data format according to a security standard protocol based on first biometric authentication data including a biometric authentication result based on user biometric data received from a biometric recognition module and a first unique value, and performs authorization registration for user rights set for access control of the security area by setting field values of a feature set according to the security standard protocol based on the first security setting data, and when the storage device is connected to a first host device, performs authorization for the user rights based on a first password received from the first host device according to the security standard protocol set for communication with the first host device, and when the storage device is connected to a second host device, transmits a biometric recognition trigger signal to the biometric recognition module, and when receives second biometric authentication data including a biometric authentication success message and a second unique value from the biometric recognition module, converts the second unique value into second security setting data having a data format according to the security standard protocol, and the second password included in the second security setting data A storage device that performs authorization authentication for the user authority without control of the second host device by comparing with a credential value among the field values of the feature set configured according to the above security standard protocol.
Citation Information
Patent Citations
Memory system having secure storage device and method of managing secure area thereof
KR1020090067649A
Secure data protecting memory device, data protecting method using the secure data
KR1020130085536A
Storage unit for offering security function and method thereof
KR1020150032970A
Systems and Methods for Use in Authenticating Users in Connection With Network Transactions
US20190019190A1
Integrated Security Information Management System andIts Method
KR1020050054081A