Securing control setting values at memory device using replay protected memory block (RPMB) data frame
The RPMB data frame with an RPMB security protocol securely manages critical memory settings, enhancing data security and reducing latency and resource usage in memory devices.
Patent Information
- Application Number
- PCT/CN2024/073963
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-25
- Publication Date
- 2025-07-31
AI Technical Summary
Existing memory devices face challenges in securely managing critical or irreversible setting values, such as write protection modes, which can lead to irreversible data loss or non-bootable states, and current security measures increase latency and resource usage.
The use of a replay protected memory block (RPMB) data frame to encapsulate control setting value queries and responses, secured with an RPMB security protocol, ensuring only authorized parties can modify these settings by including a message authentication code (MAC) to prevent unauthorized access.
Enhances data security for critical settings while reducing latency and resource usage by preventing unauthorized modifications and eliminating the need for metadata checks, thus improving device performance.
Smart Images

Figure CN2024073963_31072025_PF_FP_ABST
Abstract
Description
SECURING CONTROL SETTING VALUES AT MEMORY DEVICE USING REPLAY PROTECTED MEMORY BLOCK (RPMB) DATA FRAMETECHNICAL FIELD
[0001] Aspects of the present disclosure relate generally to memory devices and more particularly to data security associated with memory devices.
[0002] INTRODUCTION
[0003] As the value and use of information continues to increase, individuals and businesses seek additional ways to process and store information. In addition, the use of information in various locations and desired portability of information is increasing. For this reason, users are increasingly turning towards the use of portable electronic devices, such as mobile phones, digital cameras, laptop computers and the like. Portable electronic devices generally employ a memory system using a memory device for storing data. A memory system may be used as a main memory or an auxiliary memory of a portable electronic device.
[0004] The memory device of the memory system may include one kind or a combination of kinds of storage. For example, magnetic-based memory systems, such as hard disk drives (HDDs) , store data by encoding data as a combination of small magnets. As another example, optical-based memory systems, such as digital versatile discs (DVDs) and Blu-ray media, store data by encoding data as physical bits that cause different reflections when illuminated by a light source. As a further example, electronic memory devices store data as collections of electrons that can be detected through voltage and / or current measurements.
[0005] Electronic memory devices can be advantageous in certain systems in that they may access data quickly and consume a small amount of power. Examples of an electronic memory device having these advantages include universal serial bus (USB) memory devices (sometimes referred to as “memory sticks” ) , a memory card (such as used in some cameras and gaming systems) , and solid state drive (SSDs) (such as used in laptop computers) . NAND flash memory is one kind of memory device that may be used in electronic memory devices. NAND flash memory is manufactured into memory cards or flash disks. Example memory cards include compact flash (CF) cards, multimedia cards (eMMCs) , smart media (SM) cards, and secure digital (SD) cards.
[0006] A memory system may, in some cases, be integrated with or otherwise connected to a host device, such as an electronic device. For example, memory systems may be integrated with host devices in a system on chip (SoC) . As one particular example, a flash memory system, which may be a universal flash storage (UFS) memory system, may be integrated into an electronic device, such as an access point (AP) , station (STA) , user equipment (UE) , base station, modem, camera, automobile, or other system.
[0007] One standard for organization and operation of electronic memory devices is the Universal Flash Storage (UFS) standard. The UFS standard was introduced as a successor to the eMMC (embedded MultiMediaCard) standard to offer higher performance and lower power consumption for mobile and other embedded devices. UFS provides support for a range of features such as multi-lane configurations, command queuing, and power-saving modes that enable high-speed data transfer rates, low latency, and long battery life. The UFS standard specifies many parameters for structuring, reading data from, and writing data to UFS-compliant memory devices. For example, UFS-compliant devices may include digital cameras, mobile phones, consumer electronic devices, and other devices with internal memory capacity. UFS-compliant memory may include memory embedded within electronic devices and removable memory cards, and UFS memory devices may implement NAND flash memory.
[0008] Some memories may store data that specifies permissions, configurations, and other parameters. Some such data may be associated with a “critical” or “irreversible” setting. For example, a UFS specification may specify certain attributes or flags that control whether a write protection mode is enabled or disabled. In some circumstances, changing the write protection mode may cause an irreversible loss of data at a memory. As further illustrative examples, changing some other attributes or flags may cause firmware updates of a memory to be disabled or may cause the memory to be non-bootable.
[0009] To reduce the ability of malicious entities (e.g., hackers) to gain access to such attributes and flags, some devices use additional metadata to indicate which attributes and flags at a memory should be not subject to change (or a set of conditions under which the attributes and flags may be changed) . Storing such additional metadata consumes storage space and processing resources. Further, such a technique may increase latency. For example, prior to modifying a flag or attribute, a device may need to check the metadata to ensure that modification of the flag or attribute is permitted. Checking the metadata may consume processing resources and processing cycles, increasing latency associated with modification of the flag or attribute.
[0010] BRIEF SUMMARY OF SOME EXAMPLES
[0011] In some aspects of the disclosure, an apparatus includes a processing system including one or more processors and one or more memories coupled to the one or more processors. The processing system is configured to send, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The processing system is further configured to receive, from the memory device, a response to the query request.
[0012] In some additional aspects, a method of operation of a host device includes sending, to a memory device, an RPMB data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The method further includes receiving, from the memory device, a response to the query request.
[0013] In some additional aspects, an apparatus includes a non-volatile memory and a memory controller coupled to the non-volatile memory. The memory controller is configured to receive, from a host device, an RPMB data frame that includes a data field. The data field includes a query request to be executed by the memory controller. The query request indicates one or more control setting values to be written to the non-volatile memory. The memory controller is further configured to send, to the host device, a response to the query request.
[0014] In some further aspects, a method of operation of a memory device includes receiving, at the memory device from a host device, an RPMB data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The method further includes sending, to the host device, a response to the query request.
[0015] While aspects and implementations are described in this application by illustration to some examples, those skilled in the art will understand that additional implementations and use cases may come about in many different arrangements and scenarios. Innovations described herein may be implemented across many differing platform types, devices, systems, shapes, sizes, packaging arrangements. For example, aspects and / or uses may come about via integrated chip implementations and other non-module-component based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, artificial intelligence (AI) -enabled devices, etc. ) . While some examples may or may not be specifically directed to use cases or applications, a wide assortment of applicability of described innovations may occur. Implementations may range in spectrum from chip-level or modular components to non-modular, non-chip-level implementations and further to aggregate, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more aspects of the described innovations. In some practical settings, devices incorporating described aspects and features may also necessarily include additional components and features for implementation and practice of claimed and described aspects. For example, transmission and reception of wireless signals necessarily includes a number of components for analog and digital purposes (e.g., hardware components including antenna, radio frequency (RF) -chains, power amplifiers, modulators, buffer, processor (s) , interleaver, adders / summers, etc. ) . It is intended that innovations described herein may be practiced in a wide variety of devices, chip-level components, systems, distributed arrangements, end-user devices, etc. of varying sizes, shapes, and constitution.BRIEF DESCRIPTION OF THE DRAWINGS
[0016] FIG. 1 is a block diagram illustrating a data processing system including a memory system according to some aspects of the disclosure.
[0017] FIG. 2 is a block diagram illustrating an example electronic device that may include the memory system of FIG. 1 according to one or more aspects of the disclosure.
[0018] FIG. 3 is a block diagram illustrating components for facilitating access to a flash memory device from a host device according to some aspects of the disclosure.
[0019] FIG. 4 is a block diagram illustrating an example of a system according to some aspects of the disclosure.
[0020] FIG. 5 is a timing diagram illustrating examples of operations according to some aspects of the disclosure.
[0021] FIG. 6 is a block diagram illustrating an example of a system according to some aspects of the disclosure.
[0022] FIG. 7 is a block diagram illustrating some additional features that may be associated with the system of FIG. 6 according to some aspects of the disclosure.
[0023] FIG. 8 is a timing diagram illustrating examples of operations according to some aspects of the disclosure.
[0024] FIG. 9 is a timing diagram illustrating examples of operations according to some aspects of the disclosure.
[0025] FIG. 10 is a flow chart illustrating an example of a method of operation of a host device according to some aspects of the disclosure.
[0026] FIG. 11 is a flow chart illustrating an example of a method of operation of a memory device according to some aspects of the disclosure.DETAILED DESCRIPTION
[0027] In some aspects of the disclosure, a device may use a replay protected memory block (RPMB) data frame as a container for one or more commands associated with one or more control setting values to be protected at a memory. For example, the one or more control setting values may include one or more of a flag or an attribute that may be associated with a “critical” or “irreversible” setting. In some examples, the one or more commands may include one or more of a query request to set the one or more control setting values at the memory, a query response read request to read one of more of the values from the memory, or a query response providing the one or more requested values.
[0028] In some implementations, the RPMB data frame may include a data field and a control field. The data field may include a command associated with one or more control setting values (such as the query request, the query response read request, or the query response to the query response read request) . The control field may include an opcode indicating that the data field includes an instruction be executed by the memory. Further, the RPMB data frame may include a credential associated with an RPMB security protocol, such as a message authentication code (MAC) that indicates that a source of the RPMB data frame has access to an RPMB authentication key (and is therefore trusted) .
[0029] By including such a command in an RPMB data frame, security associated with the one or more control setting values may be enhanced while improving device performance. For example, because the one or more control setting values are associated with the RPMB security protocol, only a party with access to the RPMB authentication key may be allowed to set the one or more control setting values. If, for example, a malicious entity issues a command to the memory to set the one or more control setting values, the memory may decline to execute the command based on the command not being included in an RPMB data frame that includes a valid MAC. Accordingly, the one or more control setting values may be secured at the memory without storing and accessing metadata indicating whether modification of the one or more control setting values is permitted. As a result, data security associated with the one or more control setting values may be increased while decreasing latency and device resource usage (such as utilization of device storage and processing cycles) .
[0030] Memory may be used in a computing system, such as illustrated in FIG. 1. FIG. 1 illustrates a data processing system 100, such as may be included in a mobile computing device or another device, according to one or more aspects of the disclosure. The data processing system 100 may include a host device 102 and a memory system 110. In some aspects of the disclosure, the host device 102 may send to the memory system 110 a replay protected memory block (RPMB) data frame 104 including a data field that includes a query request, as described further below.
[0031] The memory system 110 may be coupled to the host device 102 through one or more channels. For example, the host device 102 and memory system 110 may be coupled through a serial interface including a single channel for the transport of data or a parallel interface including two or more channels for the transport of data. In some aspects, control data may be transferred through the same channel (s) as the data or the control data may be transferred through additional channels. The host device 102 may be, for example, a portable electronic device such as a mobile phone, an MP3 player, a laptop computer, or a non-portable electronic device such as a desktop computer, a game player, a television (TV) , a media player, or a projector. As another example, the host device 102 may be an automotive computer system. In some examples, the memory system 110 may be included in the host device 102. Thus, the data processing system 100 may be any of the example host devices described herein including the memory system 110. Additional example host devices are illustrated and described with reference to Figure 6.
[0032] The memory system 110 may execute operations in response to commands (e.g., a request) from the host device 102. For example, the memory system 110 may store data provided by the host device 102 and the memory system 110 may also provide stored data to the host device 102. The memory system 110 may be used as a main memory, short-term memory, or long-term memory by the host device 102. As one example of main memory, the host device 102 may use the memory system 110 to supplement or replace a system memory by using the memory system 110 to store temporary data such as data relating to operating systems and / or threads executing in the operation system. As one example of short-term memory, the host device 102 may use the memory system 110 to store a page file for an operating system. As one example of long-term memory, the host device 102 may use the memory system 110 to store user files (e.g., documents, videos, pictures) and / or application files (e.g., word processing executable, gaming application) .
[0033] The memory system 110 may be implemented with any one of various storage devices, according to the protocol of a host interface for the one or more channels coupling the memory system 110 to the host device 102. The memory system 110 may be implemented with any one of various storage devices, such as a solid state drive (SSD) , a multimedia card (MMC) , an embedded MMC (eMMC) , a reduced size MMC (RS-MMC) , a micro-MMC, a secure digital (SD) card, a mini-SD, a micro-SD, a universal serial bus (USB) storage device, a universal flash storage (UFS) device, a compact flash (CF) card, a smart media (SM) card, or a memory stick.
[0034] The memory system 110 may include a memory module 150 and a controller 130 coupled to the memory module 150 through one or more channels. The memory module 150 may store and retrieve data in memory blocks 152, 154, and 156 under control of the controller 130, which may execute commands received from the host device 102. The controller 130 is configured to control data exchange between the memory module 150 and the host device 102. The storage components, such as blocks 152, 154, and 156 in the memory module 150 may be implemented as volatile memory device, such as, a dynamic random access memory (DRAM) and a static random access memory (SRAM) , or a non-volatile memory device, such as a read only memory (ROM) , a programmable ROM (PROM) , an erasable programmable ROM (EPROM) , an electrically erasable programmable ROM (EEPROM) , a ferroelectric random access memory (FRAM) , a phase-change RAM (PRAM) , a magnetoresistive RAM (MRAM) , a resistive RAM (SCRAM) , or a NAND flash memory.
[0035] The controller 130 and the memory module 150 may be formed as integrated circuits on one or more semiconductor dies (or other substrate) . In some aspects, the controller 130 and the memory module 150 may be integrated into one chip. In some aspects, the memory module 150 may include one or more chips coupled in series or parallel with each other and coupled to the controller 130, which is on a separate chip. In some aspects, the memory module 150 and controller 130 chips are integrated in a single package, such as in a package on package (PoP) system. In some aspects, the memory system 110 is integrated on a single chip with one or more or all of the components (e.g., application processor, system memory, digital signal processor, modem, graphics processor unit, memory interface, input / output interface, network adaptor) of the host device 102, such as in a system on chip (SoC) . The controller 130 and the memory module 150 may be integrated into one semiconductor device to form a memory card, such as, for example, a Personal Computer Memory Card International Association (PCMCIA) card, a compact flash (CF) card, a smart media card (SMC) , a memory stick, a multimedia card (MMC) , an RS-MMC, a micro-MMC, a secure digital (SD) card, a mini-SD, a micro-SD, an SDHC, and a universal flash storage (UFS) device.
[0036] The controller 130 of the memory system 110 may control the memory module 150 in response to commands from the host device 102. The controller 130 may execute read commands to provide the data from the memory module 150 to the host device 102. The controller 130 may execute write commands to store data provided from the host device 102 into the memory module 150. The controller 130 may execute other commands to manage data in the memory module 150, such as program and erase commands. The controller 130 may also execute other commands to manage control of the memory system 110, such as setting configuration registers of the memory system 110. By executing commands in accordance with the configuration specified in the configuration registers, the controller 130 may control operations of the memory module 150, such as read, write, program, and erase operations.
[0037] The controller 130 may include several components configured for performing the received commands. For example, the controller 130 may include a host interface (I / F) 132, a processor 134, an error correction code (ECC) unit 138, a power management unit (PMU) 140, a NAND flash controller (NFC) 142, and / or a memory 144. The power management unit (PMU) 140 may provide and manage power for components within the controller 130 and / or the memory module 150.
[0038] The host interface 132 may process commands and data provided from the host device 102, and may communicate with the host device 102, through at least one of various interface protocols such as universal serial bus (USB) , multimedia card (MMC) , peripheral component interconnect express (PCI-e) , serial attached SCSI (SAS) , serial advanced technology attachment (SATA) , parallel advanced technology attachment (PATA) , small computer system interface (SCSI) , enhanced small disk interface (ESDI) , and integrated drive electronics (IDE) . For example, the host interface 132 may be a parallel interface such as an MMC interface, or a serial interface such as an ultra-high speed class 1 (UHS-I) / UHS class 2 (UHS-II) or a universal flash storage (UFS) interface.
[0039] The ECC unit 138 may detect and correct errors in the data read from the memory module 150 during the read operation. The ECC unit 138 may not correct error bits when the number of the error bits is greater than a threshold number of correctable error bits, which may result in the ECC unit 138 outputting an error correction fail signal indicating failure in correcting the error bits. In some aspects, no ECC unit 138 may be provided or the ECC unit 138 may be configurable to be active for some or all of the memory module 150. The ECC unit 138 may perform an error correction operation using a coded modulation such as a low-density parity check (LDPC) code, a Bose-Chaudhuri-Hocquenghem (BCH) code, a turbo code, a Reed-Solomon (RS) code, a convolution code, a recursive systematic code (RSC) , a trellis-coded modulation (TCM) , or a Block coded modulation (BCM) .
[0040] The NFC 142 provides an interface between the controller 130 and the memory module 150 to allow the controller 130 to control the memory module 150 in response to a commands received from the host device 102. The NFC 142 may generate control signals for the memory module 150, such as signals for rowlines and bitlines, and process data under the control of the processor 134. Although NFC 142 is described as a NAND flash controller, other controllers may perform similar function for other memory types used as memory module 150.
[0041] The memory 144 may serve as a working memory of the memory system 110 and the controller 130. The memory 144 may store data for driving the memory system 110 and the controller 130. When the controller 130 controls an operation of the memory module 150 such as, for example, a read, write, program or erase operation, the memory 144 may store data which are used by the controller 130 and the memory module 150 for the operation. The memory 144 may be implemented with a volatile memory such as, for example, a static random access memory (SRAM) or a dynamic random access memory (DRAM) . In some aspects, the memory 144 may store address mappings, a program memory, a data memory, a write buffer, a read buffer, a map buffer, and the like.
[0042] The processor 134 may control the general operations of the memory system 110, and a write operation or a read operation for the memory module 150, in response to a write request or a read request received from the host device 102, respectively. For example, the processor 134 may execute firmware, which may be referred to as a flash translation layer (FTL) , to control the general operations of the memory system 110. The processor 134 may be implemented, for example, with a microprocessor or a central processing unit (CPU) , or an application-specific integrated circuit (ASIC) .
[0043] FIG. 2 is a block diagram illustrating an example electronic device 200 that may include the memory system 110 of FIG. 1 according to one or more aspects of the disclosure. The electronic device 200 may include a user interface 210, a memory 220, an application processor 230, a network adaptor 240, and a storage system 250 (which may include the memory system 110 of FIG. 1) . The application processor 230 may be coupled to one or more other components through a bus, such as a peripheral component interface (PCI) bus, including a PCI express (PCIe) bus. In some aspects of the disclosure, the application processor 230 may send (e.g., to the storage system 250) the RPMB data frame 104 including a data field that includes a query request, as described further below.
[0044] The application processor 230 may execute computer program code, including applications, drivers, and operating systems, to coordinate performing of tasks by components included in the electronic device 200. For example, the application processor 230 may execute a storage driver for accessing the storage system 250. The application processor 230 may be part of a system-on-chip (SoC) that includes one or more other components shown in electronic device 200.
[0045] The memory 220 may operate as a main memory, a working memory, a buffer memory or a cache memory of the electronic device 200. The memory 220 may include a volatile random access memory such as a dynamic random access memory (DRAM) , a synchronous dynamic random access memory (SDRAM) , a double data rate (DDR) SDRAM, a DDR2 SDRAM, a DDR3 SDRAM, a low power double data rate (LPDDR) SDRAM, an LPDDR2 SDRAM, an LPDDR3 SDRAM, an LPDDR4 SDRAM, an LPDDR5 SDRAM, or an LPDDR6 SDRAM, or a nonvolatile random access memory such as a phase change random access memory (PRAM) , a resistive random access memory (ReRAM) , a magnetic random access memory (MRAM) and a ferroelectric random access memory (FRAM) . In some aspects, the application processor 230 and the memory 220 may be combined using a package-on-package (POP) .
[0046] The network adaptor 240 may communicate with external devices. For example, the network adaptor 240 may support wired communications and / or various wireless communications such as code division multiple access (CDMA) , global system for mobile communication (GSM) , wideband CDMA (WCDMA) , CDMA-2000, time division multiple access (TDMA) , long term evolution (LTE) , worldwide interoperability for microwave access (WiMAX) , wireless local area network (WLAN) , ultra-wideband (UWB) , Bluetooth, wireless display (Wi-Di) , and so on, and may thereby communicate with wired and / or wireless electronic appliances, for example, a mobile electronic appliance.
[0047] The storage system 250 may store data, for example, data received from the application processor 230, and transmit data stored therein, to the application processor 230. The storage system 250 may be a non-volatile semiconductor memory device, such as a phase-change RAM (PRAM) , a magnetic RAM (MRAM) , a resistive RAM (ReRAM) , a NAND flash memory, a NOR flash memory, or a 3-dimensional (3-D) NAND flash memory. The storage system 250 may be a removable storage medium, such as a memory card or an external drive. For example, the storage system 250 may correspond to the memory system 110 described above with reference to FIG. 1 and may be a SSD, eMMC, UFS, or other flash memory system.
[0048] The user interface 210 provide one or more graphical user interfaces (GUIs) for inputting data or commands to the application processor 230 or for outputting data to an external device. For example, the user interface 210 may include user input interfaces, such as a virtual keyboard, a touch screen, a camera, a microphone, a gyroscope sensor, or a vibration sensor, and user output interfaces, such as a liquid crystal display (LCD) , an organic light emitting diode (OLED) display device, an active matrix OLED (AMOLED) display device, a light emitting diode (LED) , a speaker, or a haptic motor.
[0049] FIG. 3 is a block diagram illustrating components for facilitating access to a flash memory system from a host device according to some aspects of the disclosure. The host device 102 accesses the memory system 110 through a memory interface 310. The first interface may, for example, be a memory interface such as a physical interface (PHY) connecting the host device 102 to the memory system 110. The host device 102 may include physical layer access block 312, which is configured to generate signals for output to the memory interface 310 and process signals received through the memory interface 310. The memory system 110 includes a similarly-configured physical layer access block 322 for communicating on the memory interface 310. One example physical layer specification for communicating on the memory interface 310 is the MIPI M-PHYTM physical layer specification.
[0050] The host device 102 also includes a data link layer block 314 configured to format frames of data for transmission on the memory interface 310. The frames may be provided to the physical layer access block 312 for transmission. The data link layer block 314 may receive frames from the physical layer access block 312 and decode frames of data received on the memory interface 310. The memory system 110 includes a similarly-configured data link layer block 324 for processing frames transmitted on or received on the memory interface 310 by the physical layer access block 322. One example data link protocol for communicating on a MIPI M-PHYTM physical link is the MIPI UNIPROTM specification.
[0051] The memory system 110 includes N logical units 350a-n comprising logical memory blocks for storing information including user data (e.g., user documents, application data) and configuration data (e.g., information regarding operation of the memory system 110) . The logical units 350a-n may map to portions of the physical memory blocks 152, 154, and 156. Some of the logical units 350a-n or portions of the logical units 350a-n may be configured with write protection, with boot capability, as a specific memory type (e.g., default, system code, non-persistent, enhanced) , with priority access, or with replay protection as a replay protected memory block (RPMB) . The physical layer access block 322 and the data link layer block 324 perform operations of a memory controller for the memory system 110 for storing and retrieving data in logical units 350a-n.
[0052] The memory system 110 also includes configuration structures 352. The configuration structures 352 may include information such as configuration descriptors for boot enable (bBootEnable) , initial power mode (bInitPowerMode) , RPMB active (bRPMBRegionEnable) , and / or RPMB region sizes (bRPMBRegion1Size, bRPMBRegion2Size, bRPMBRegion3Size) . Such configuration structures and / or parameters may, for example, be configuration structures and / or parameters identified by the UFS standard.
[0053] The host device 102 may be configured to execute one or more applications 334, such as user applications executed by an operating system under the control of a user to receive user input and provide information stored in the memory system 110 to the user. The host device 102 may include several components for interfacing the application 334 to the memory system 110 through the memory interface 310. For example, a SCSI driver 332 and a UFS driver 330 may interface the application 334 to a host memory controller that includes the data link layer block 314 and the physical layer access block 312. The SCSI driver 332 may execute at an application layer for handling transactions requested by the application 334 with the memory system 110. The UFS driver 330 may execute at a transport layer and manage operation of the data link layer block 314, such as to operate the memory interface 310 at one of a plurality of modes of operations. The modes of operations may include two or more gear settings, such as one or more PWM-GEAR settings and four or more HS-GEAR settings specifying one bitrate from 182 MBps, 364 MBps, 728 MBps, and 1457 MBps.
[0054] The memory interface 310 may include one or more lines including a reset RST line, a reference clock REF_CLK line, a data-in DIN line (for data transmissions from the host device 102 to the memory system 110) , and a data-out DOUT line (for data transmissions from the memory system 110 to the host device 102) . The DIN and DOUT lines may be two separate conductors, or the DIN and DOUT lines may include multiple conductors. In some aspects, the DIN and DOUT lines may be asymmetric with the DIN line including N conductors and the DOUT line including M conductors, with N > M or M > N.
[0055] The UFS driver 330 may generate and decode packets to carry out transactions requested by the application 334. The packets are transmitted over the memory interface 310. The packets may be formatted as UFS Protocol Information Units (UPIUs) . In a transaction with the memory system 110, the host device 102 is an initiator and the memory system 110 is a target. The UFS driver 330, based on the type of transaction, may form one of several types of UPIUs for handling SCSI commands, data operations, task management operations, and / or query operations. Each transaction may include one command UPIU, zero or more DATA IN or DATA OUT UPIUs, and a response UPIU. Each UPIU may include a header followed by optional fields depending on the type of UPIU.
[0056] One example transaction is a read operation. A read transaction may include the initiator (e.g., host device 102) transmitting a command UPIU for causing the target (e.g., memory system 110) to perform a read operation requested by the application 334. The target provides one or more DATA IN UPIUs in response to the command UPIU, in which the DATA IN UPIUs include the requested data. The read transaction is completed by the target transmitting a Response UPIU.
[0057] Another example transaction is a write operation. A write operation may include the initiator (e.g., host device 102) transmitting a command UPIU for causing the target (e.g., memory system 110) to perform a write operation requested by the application 334. The target provides a Ready to Transfer UPIU signaling the initiator to begin transfer of write data. The initiator then transmits one or more DATA OUT UPIUs, which are followed by a Ready to Transfer UPIU signaling the initiator to continue transfer of the write data. The sequence of DATA OUT UPIUs and Ready to Transfer UPIU continues until all write data is provided to the target, after which the target provides a Response UPIU to the initiator.
[0058] A further example transaction is a query operation. A query operation may include the initiator (e.g., host device 102) requesting information about the target (e.g., memory system 110) . The initiator may transmit a Query Request UPIU to request information such as configuration, enumeration, device descriptor, flags, and / or attributes of the target. Example query operations includes read descriptor, write descriptor, read attribute, write attribute, read flag, set flag, clear flag, and / or toggle flag. Example descriptors include device, configuration, unit, interconnect, string, geometry, power, and / or device health. Example flags include fDeviceInit, fPermanenetWPEn, fPowerOnWPEn, fBackgroundOpsEn, fDeviceLifeSpanModeEn, fPurgeEnable, fRefreshEnable, fPhyResourceRemoval, fBusyRTC, and / or fPermanentlyDisableFwUpdate. Example attributes include bBootLunEn, bCurrentPowerMode, bActiveICCLevel, bOutOfORderDataEn, bBackgroundOpStatus, bPurgeStatus, bMaxDataInSize, bMaxDataOutSize, dDynCapNeeded, bRefClkFreq. Such flags may, for example, be flags identified by the UFS standard.
[0059] The example of FIG. 3 illustrates that the host device 102 may send, to the memory system 110, the RPMB data frame 104 including a data field that includes a query request. Certain examples that may be associated with such an RPMB data frame are described further with reference to FIG. 4.
[0060] FIG. 4 is a block diagram illustrating an example of a system 400 according to some aspects of the disclosure. The system 400 may include a host device 102 (such as the host device 102) and may further include a memory, such as the memory system 110. In some examples, at least a portion of the system 400 may include or may correspond to a system-on-chip (SoC) device. For example, the host device 102 may include or may correspond to a SoC device that is coupled to the memory system 110.
[0061] The host device 102 may include a processing system 402 that includes one or more processors 404 and one or more memories 406 coupled to the one or more processors 404. In some examples, the one or more memories 406 may store instructions 408 executable by the one or more processors 404 to initiate, perform, or control one or more operations of the host device 102 described herein.
[0062] The memory system 110 may include a memory controller 480 and a non-volatile memory 490 coupled to the memory controller 480. In some examples, the memory controller 480 may include or correspond to a processing system. For example, the memory controller 480 may include one or more processors 482 and one or more memories 486 coupled to the one or more processors 482. In some examples, the one or more memories 486 may store instructions 488 executable by the one or more processors 482 to initiate, perform, or control one or more operations of the memory system 110 described herein. In some examples, the non-volatile memory 490 may include an RPMB partition 492 and a non-RPMB region 494.
[0063] During operation, the host device 102 may write or modify one or more control setting values 426 at the memory system 110. In some examples, the one or more control setting values 426 may include one or more of a flag 422, an attribute 424, or one or more other values. In some examples, the one or more control setting values 426 may specify whether a “critical” or “irreversible” setting is enabled or disabled. As an illustrative example, the one or more control setting values 426 may specify whether a write protection mode associated with the memory system 110 is enabled or disabled. In some circumstances, changing the write protection mode may cause an irreversible loss of data at the memory system 110. As further illustrative examples, in some implementations, changing the one or more control setting values 426 may cause firmware updates of the memory system 110 to be disabled or may cause the memory system 110 (or the system 400) to be non-bootable.
[0064] To further illustrate, in some examples, the one or more control setting values 426 may include one or more of the configuration structures 352 of FIG. 3. For example, the one or more control setting values may include one or more configuration descriptors for boot enable (bBootEnable) , initial power mode (bInitPowerMode) , RPMB active (bRPMBRegionEnable) , RPMB region sizes (bRPMBRegion1Size, bRPMBRegion2Size, bRPMBRegion3Size) , one or more other configuration descriptors, or a combination thereof. Examples of the flag 422 may include fDeviceInit, fPermanenetWPEn, fPowerOnWPEn, fBackgroundOpsEn, fDeviceLifeSpanModeEn, fPurgeEnable, fRefreshEnable, fPhyResourceRemoval, fBusyRTC, fPermanentlyDisableFwUpdate, or another flag. Examples of the attribute 424 may include bBootLunEn, bCurrentPowerMode, bActiveICCLevel, bOutOfORderDataEn, bBackgroundOpStatus, bPurgeStatus, bMaxDataInSize, bMaxDataOutSize, dDynCapNeeded, bRefClkFreq, or another attribute. In some examples, one or more such configuration structures, flags, or attributes may be specified by, for example, the UFS standard.
[0065] In some aspects of the disclosure, one or more commands associated with the one or more control setting values 426 may be contained within an RPMB command so that the one or more control setting values 426 are associated with an RPMB security protocol. In some examples, the RPMB security protocol may secure the one or more control setting values 426 such that a key 484 associated with the RPMB security protocol is used to gain access to write the one or more control setting values 426 to the memory system 110, to modify the one or more control setting values 426 at the memory system 110, or both.
[0066] To illustrate, the host device 102 may send, to the memory system 110, an RPMB data frame 410 that includes a data field 418 including a query request 420. The query request 420 may indicate the one or more control setting values 426. In some examples, the RPMB data frame 410 may correspond to the RPMB data frame 104 of FIGS. 1-3.
[0067] In some examples, the RPMB data frame 410 may include a control field 414 having an opcode 416. The opcode 416 may indicate that the data field 418 is associated with an instruction type instead of a data type. For example, the opcode 416 may indicate, to the memory controller 480, that the contents of the data field 418 correspond to an instruction to be executed by the memory controller 480.
[0068] The RPMB data frame 410 may be associated with a first protocol, and the query request 420 may be associated with a second protocol different than the first protocol. In some examples, the first protocol may be an RPMB protocol, and the second protocol may be a universal flash storage (UFS) protocol. To illustrate, the RPMB data frame 410 may comply with the RPMB protocol, and the query request 420 may comply with the UFS protocol. In some examples, the query request 420 may correspond to a UFS protocol information unit (UPIU) that complies with the UFS protocol.
[0069] The example of FIG. 1 further indicates that the RPMB data frame 410 may include a message authentication code (MAC) 412. The host device 102 may generate the MAC 412 based at least in part on the key 484. For example, the MAC 412 may correspond to a hash, checksum, or digital signature generated based at least in part on the key 484. The RPMB protocol may specify operations performed to generate the MAC 412. Additionally, the RPMB protocol may specify operations performed to generate the key 484, such as via an authentication key programming procedure. The key 484 may be referred to as an authentication key.
[0070] The memory system 110 may receive the RPMB data frame 410. The memory system 110 may authenticate the RPMB data frame 410. For example, the memory system 110 may authenticate the RPMB data frame 410 based on the MAC 412, such as by using a verification procedure to determine that the MAC 412 was generated using the key 484.
[0071] The memory system 110 may determine (e.g., based on the opcode 416) that the data field 418 is associated with an instruction type instead of a data type. In some examples, based on determining that the data field 418 is associated with the instruction type, the memory system 110 may extract the query request 420 from the data field 418 and may execute the query request 420. In some examples, executing the query request 420 may include writing the one or more control setting values 426 to the non-volatile memory 490. Depending on the implementation, the memory system 110 may write the one or more control setting values 426 to the RPMB partition 492 or to the non-RPMB region 494.
[0072] In some examples, the host device 102 may read at least one control setting value 476 of the one or more control setting values 426. For example, after sending the RPMB data frame 410 to the memory system 110, the host device 102 may send, to the memory system 110, a query response read request 470 for the at least one control setting value 476. In some examples, the query response read request 470 may be included in a second RPMB data frame 460 having a data field 468 that includes the query response read request 470.
[0073] In some examples, the second RPMB data frame 460 may include a control field 464 having an opcode 466. The opcode 466 may indicate that the data field 468 is associated with an instruction type instead of a data type. For example, the opcode 466 may indicate, to the memory controller 480, that the contents of the data field 468 correspond to an instruction to be executed by the memory controller 480. The second RPMB data frame 460 may include a MAC 462. The host device 102 may generate the MAC 462 based at least in part on the key 484. In some examples, the second RPMB data frame 460 may comply with the first protocol described with reference to the RPMB data frame 410, and the query response read request 470 may comply with the second protocol described with reference to the query request 420.
[0074] The memory system 110 may receive the second RPMB data frame 460. The memory system 110 may authenticate the second RPMB data frame 460. For example, the memory system 110 may authenticate the second RPMB data frame 460 based on the MAC 462, such as by using a verification procedure to determine that the MAC 462 was generated using the key 484.
[0075] The memory system 110 may determine (e.g., based on the opcode 466) that the data field 468 is associated with an instruction type instead of a data type. In some examples, based on determining that the data field 468 is associated with the instruction type, the memory system 110 may extract the query response read request 470 from the data field 468 and may execute the query response read request 470. In some examples, executing the query response read request 470 may include reading the at least one control setting value 476 from the non-volatile memory 490.
[0076] The memory system 110 may send a query response 450 to the host device 102 based on the query response read request 470. The query response 450 may indicate the at least one control setting value 476. In some examples, the query response 450 may correspond to a UPIU that complies with a UFS protocol. The host device 102 may receive the query response 450 and may determine the at least one control setting value 476 based on the query response 450.
[0077] In some examples, the query response 450 may be included in a third data field of a third RPMB data frame, such as a data field 438 of a third RPMB data frame 430. Further, the third RPMB data frame 430 may include a MAC 432 and a control field 434 including an opcode 436. The opcode 436 may specify that the data field 438 includes the query response 450. The memory system 110 may generate the MAC 432 using the key 484. In some examples, the third RPMB data frame 430 may comply with the first protocol described with reference to the RPMB data frame 410, and the query response 450 may comply with the second protocol described with reference to the query request 420.
[0078] The example of FIG. 4 illustrates that the at least one control setting value 476 may be secured using an RPMB protocol. To illustrate, each of the RPMB data frame 410, the third RPMB data frame 430, and the second RPMB data frame 460 may include a respective MAC (such as the MAC 412, the MAC 432, and the MAC 462, respectively) that is associated with an authentication key associated with the RPMB protocol, such as the key 484. In some examples, a memory storage specification associated with the memory system 110 may specify that the at least one control setting value 476 are subject to RPMB-based authentication. As a result, if the memory system 110 receives another request to write, read, or modify the at least one control setting value 476, the memory system 110 may determine whether the request includes a MAC generated based on the key 484. If the request does not include such a MAC (such as if the request is received from a malicious entity that does not have access to the key 484) , the memory system 110 may reject the request (e.g., by returning a response that indicates failure associated with the request) . As a result, security associated with the at least one control setting value 476 may be enhanced.
[0079] To further illustrate some aspects of the disclosure, Table 1 provides examples of opcodes that may be included in control fields of RPMB data frames sent from the host device 102 to the memory system 110 in some implementations.
[0080] Table 1
[0081] In the example of Table 1, the opcode 416 of the RPMB data frame 410 may be set to “0010h” to indicate that the data field 418 includes the query request 420 (e.g., an authenticated query request) . Further, in the example of Table 1, the opcode 466 of the second RPMB data frame 460 may be set to “0011h” to indicate that the data field 468 includes the query response read request 470. The example of Table 1 is illustrative and non-limiting and other examples are also within the scope of the disclosure.
[0082] Table 2 provides examples of opcodes that may be included in control fields of RPMB data frames sent from the memory system 110 to the host device 102.
[0083] Table 2
[0084] In the example of Table 2, the opcode 436 of the third RPMB data frame 430 may be set to “1001h” to indicate that the data field 438 includes the query response 450 (e.g., an authenticated query response) . Further, in some implementations of an advanced RPMB mode, a message sent from the memory system 110 to the host device 102 may have an opcode of “1000h” to indicate an authenticated query request command response, as described further with reference to FIGS. 6 and 7. The example of Table 2 is illustrative and non-limiting and other examples are also within the scope of the disclosure.
[0085] FIG. 5 is a timing diagram illustrating examples of operations 500 according to some aspects of the disclosure. In some examples, the operations 500 may be performed by the host device 102 and the memory system 110 of FIG. 4. In the example of FIG. 5, the host device 102 may be associated with a UFS command set layer (UCS) 552 and a UFS transport layer (UTP) 554.
[0086] The operations 500 may include initiating an authenticated query request, at 502. In some examples, the authenticated query request may correspond to the query request 420 of FIG. 4.
[0087] The operations 500 may further include sending a command UPIU to the memory system, at 504. In some examples, the command UPIU may indicate to the memory system 110 that the host device 102 is to initiate a data transfer operation.
[0088] The operations 500 may further include providing a ready-to-transfer indication from the memory system 110 to the host device 102, at 506. The ready-to-transfer indication may be included in a UPIU. In some examples, the ready-to-transfer indication may indicate to the host device 102 that the memory system 110 is ready to perform the data transfer operation.
[0089] The operations 500 may further include sending a data out UPIU to the memory system, at 508. In some examples, the data out UPIU may include or may correspond to the query request 420 and may be included in the RPMB data frame 410.
[0090] The operations 500 may further include providing a response from the memory system 110 to the host device 102, at 510. In some examples, the response may correspond to or may be included in a response UPIU.
[0091] The operations 500 may further include providing a response from the UTP 554 to the UCS 552, at 511. The response may indicate completion of the authenticated query request.
[0092] The operations 500 may further include initiating a query response read request, at 512. In some examples, the query response read request may correspond to the query response read request 470 of FIG. 4.
[0093] The operations 500 may further include sending a command UPIU to the memory system, at 514. In some examples, the command UPIU may indicate to the memory system 110 that the host device 102 is to initiate a data transfer operation.
[0094] The operations 500 may further include providing a ready-to-transfer indication from the memory system 110 to the host device 102, at 516. The ready-to-transfer indication may be included in a UPIU. In some examples, the ready-to-transfer indication may indicate to the host device 102 that the memory system 110 is ready to perform the data transfer operation.
[0095] The operations 500 may further include sending a data out UPIU to the memory system, at 518.
[0096] The operations 500 may further include providing a response from the memory system 110 to the host device 102, at 520. The response may correspond to or may be included in a UPIU.
[0097] The operations 500 may further include providing a response from the UTP 554 to the UCS 552, at 521. The response may indicate completion of the query response read request.
[0098] The operations 500 may further include initiating a query response, at 522. In some examples, the query response may correspond to the query response 450 of FIG. 4.
[0099] The operations 500 may further include sending a command UPIU to the memory system, at 524. In some examples, the command UPIU may indicate to the memory system 110 that the host device 102 is to initiate a data transfer operation.
[0100] The operations 500 may further include receiving a data in UPIU from the memory system, at 528.
[0101] The operations 500 may further include providing a response from the memory system 110 to the host device 102, at 530. The response may correspond to or may be included in a UPIU.
[0102] The operations 500 may further include providing a response from the UTP 554 to the UCS 552, at 531. The response may indicate completion of the query response.
[0103] FIG. 6 is a block diagram illustrating an example of a system 600 according to some aspects of the disclosure. In some implementations, the system 400 of FIG. 4 may operate based on a first RPMB protocol, and the system 600 of FIG. 6 may operate based on a second RPMB protocol different than the first RPMB protocol. In some examples, the first RPMB protocol may be a primary RPMB protocol, and the second RPMB protocol may be an advanced RPMB protocol. In an example of the advanced RPMB mode, one or more messages may include an extra header segment (EHS) field. In some implementations, such an EHS field may indicate one or more opcodes described herein.
[0104] For example, the RPMB data frame 410 of FIG. 6 may be associated with an RPMB command frame 610 that includes the MAC 412 and that further includes an EHS field 612 that includes the opcode 416. Referring again to the example of Table 1, in some implementations, the opcode 416 of the EHS field may be set to “0010h” to indicate that the data field 418 includes the query request 420 (e.g., an authenticated query request) .
[0105] Further, in an example of the advanced RPMB mode, one or more messages may include an end to end cyclic redundancy check (E2ECRC) field with multiple data fields. Each of the multiple data fields may indicate, or may be configurable to indicate, a respective query request. In some examples, the RPMB data frame 410 may include an E2ECRC field 618 that may indicate the query request 420.
[0106] The memory system 110 may receive the RPMB data frame 410 and the RPMB command frame 610. The memory system 110 may send a response to the query request 420 to the host device 102. For example, the memory system 110 may send an authenticated query request command response 620 to the host device 102. The authenticated query request command response 620 may include a MAC 622 and an EHS field 624 indicating an opcode 626 (e.g., “1000h” ) . To illustrate, referring again to the example of Table 2, in some implementations, the opcode 626 of the EHS field 624 may be set to “1000h. ”
[0107] FIG. 7 is a block diagram illustrating some additional features that may be associated with the system 600 of FIG. 6 according to some aspects of the disclosure. In the example of FIG. 7, the second RPMB data frame 460 may include an E2ECRC field 718 that includes the query response read request 470. The second RPMB data frame 460 may be associated with an RPMB command frame 710 that includes the MAC 412 and an EHS field 712 indicating the opcode 466. Referring again to the example of Table 1, in some examples, the opcode 466 may be set to “0011h” to indicate that the second RPMB data frame 460 includes the query response read request 470.
[0108] The memory system 110 may receive the second RPMB data frame 460 and the RPMB command frame 710. The memory system 110 may send the third RPMB data frame 430 to the host device 102 indicating the query response 450 to the query response read request 470. The third RPMB data frame 430 may include an EHS field 724 indicating the opcode 436. Referring again to the example of Table 2, in some examples, the opcode 436 may be set to “1001h” to indicate that the third RPMB data frame 430 includes the query response 450.
[0109] FIG. 8 is a timing diagram illustrating examples of operations 800 according to some aspects of the disclosure. In some examples, the operations 800 may be performed by the host device 102 and the memory system 110 of FIG. 6.
[0110] The operations 800 may include providing a command UPIU with an EHS field, at 802. In some examples, the command UPIU may correspond to the RPMB command frame 610 of FIG. 6.
[0111] The operations 800 may further include sending a ready-to-transfer UPIU, at 804. In some examples, the ready-to-transfer UPIU may indicate to the host device 102 that the memory system 110 is ready to perform a data transfer operation.
[0112] The operations 800 may further include providing a data out UPIU, at 806. For example, the data out UPIU may correspond to the RPMB data frame 410 of FIG. 6. In some examples, the operations 804 and 806 may be looped, such as if an amount of data to be transferred exceeds a data size associated with the data out UPIU.
[0113] The operations 800 may further include providing a response UPIU, at 808. For example, the response UPIU may correspond to the authenticated query request command response 620 of FIG. 6.
[0114] FIG. 9 is a timing diagram illustrating examples of operations 900 according to some aspects of the disclosure. In some examples, the operations 900 may be performed by the host device 102 and the memory system 110 of FIG. 7.
[0115] The operations 900 may include providing a command UPIU with an EHS field, at 902. In some examples, the command UPIU may correspond to the RPMB command frame 710 of FIG. 7.
[0116] The operations 900 may further include providing a data in UPIU, at 906. For example, the data in UPIU may correspond to the third RPMB data frame 430 of FIG. 7. In some examples, the operation 906 may be looped, such as if an amount of data to be transferred exceeds a data size associated with the data in UPIU.
[0117] The operations 900 may further include providing a response UPIU, at 908. For example, the response UPIU may indicate receipt of the third RPMB data frame 430 of FIG. 7 by the host device 102.
[0118] One or more features described herein may increase data security while reducing device resource usage and latency. For example, by including command associated with the one or more control setting values 426 in an RPMB data frame, security associated with the one or more control setting values 426 may be enhanced while improving device performance. To illustrate, by associating the one or more control setting values 426 with an RPMB security protocol, only a party with access to RPMB authentication credentials (such as the key 484) may be allowed to set the one or more control setting values 426. If, for example, a malicious entity issues a command to the memory system 110 to set the one or more control setting values 426, the memory system 110 may decline to execute the command based on the command not being included in an RPMB data frame that includes a valid MAC. Accordingly, the one or more control setting values 426 may be secured at the memory system 110 without storing and accessing metadata indicating whether modification of the one or more control setting values 426 is permitted. As a result, data security associated with the one or more control setting values 426 may be increased while decreasing latency and device resource usage (such as utilization of device storage and processing cycles) .
[0119] FIG. 10 is a flow chart illustrating an example of a method 1000 of operation of a host device according to some aspects of the disclosure. In some examples, the method 1000 is performed by the host device 102 of one or more of FIGS. 1-9.
[0120] The method 1000 includes sending, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field, at 1002. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. To illustrate, the host device 102 may send, to the memory system 110, the RPMB data frame 104 or the RPMB data frame 410. In some examples, the data field may correspond to the data field 418, and the query request may correspond to the query request 420 indicating the one or more control setting values 426.
[0121] The method 1000 further includes receiving, from the memory device, a response to the query request, at 1004. In some examples, the response may be a UPIU associated with a first RPMB protocol (e.g., a primary RPMB protocol) , such as the response UPIU illustrated in FIG. 5 at 510. In some other examples, the response may be an authenticated query request command response associated with a second RPMB protocol (such as an advanced RPMB protocol) different than the first RPMB protocol. For example, the response may be the authenticated query request command response 620 of FIG. 6.
[0122] FIG. 11 is a flow chart illustrating an example of a method 1100 of operation of a memory device according to some aspects of the disclosure. In some examples, the method 1100 may be performed by the memory system 110 of one or more of FIGS. 1-9.
[0123] The method 1100 includes receiving, at the memory device from a host device, a replay protected memory device block (RPMB) data frame that includes a data field, at 1102. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. To illustrate, the memory system 110 may receive, from the host device 102, the RPMB data frame 104 or the RPMB data frame 410. In some examples, the data field may correspond to the data field 418, and the query request may correspond to the query request 420 indicating the one or more control setting values 426.
[0124] The method 1100 further includes sending, to the host device, a query to the query request, at 1102. In some examples, the response may be a UPIU associated with a first RPMB protocol (e.g., a primary RPMB protocol) , such as the response UPIU illustrated in FIG. 5 at 510. In some other examples, the response may be an authenticated query request command response associated with a second RPMB protocol (such as an advanced RPMB protocol) different than the first RPMB protocol. For example, the response may be the authenticated query request command response 620 of FIG. 6.
[0125] According to some further aspects, in a first aspect, an apparatus includes a processing system including one or more processors and one or more memories coupled to the one or more processors. The processing system is configured to send, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The processing system is further configured to receive, from the memory device, a response to the query request.
[0126] In a second aspect, in combination with the first aspect, the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.
[0127] In a third aspect, in combination with one or more of the first aspect or the second aspect, the RPMB data frame is associated with a first protocol, and the query request is associated with a second protocol different than the first protocol.
[0128] In a fourth aspect, in combination with one or more of the first aspect through the third aspect, the first protocol is an RPMB protocol, and the second protocol is a universal flash storage (UFS) protocol.
[0129] In a fifth aspect, in combination with one or more of the first aspect through the fourth aspect, the query response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.
[0130] In a sixth aspect, in combination with one or more of the first aspect through the fifth aspect, the processing system is further configured to send, to the memory device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values and to receive, from the memory device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.
[0131] In a seventh aspect, in combination with one or more of the first aspect through the sixth aspect, the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with the RPMB protocol.
[0132] In an eighth aspect, in combination with one or more of the first aspect through the seventh aspect, the one or more control setting values include one or more of a flag or an attribute.
[0133] In a ninth aspect, a method of operation of a host device includes sending, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The method further includes receiving, from the memory device, a response to the query request.
[0134] In a tenth aspect, in combination with the ninth aspect, the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.
[0135] In an eleventh aspect, in combination with one or more of the ninth aspect through the tenth aspect, the RPMB data frame is associated with a first protocol, and the query request is associated with a second protocol different than the first protocol.
[0136] In a twelfth aspect, in combination with one or more of the ninth aspect through the eleventh aspect, the first protocol is an RPMB protocol, and the second protocol is a universal flash storage (UFS) protocol.
[0137] In a thirteenth aspect, in combination with one or more of the ninth aspect through the twelfth aspect, the query response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.
[0138] In a fourteenth aspect, in combination with one or more of the ninth aspect through the thirteenth aspect, the method includes, after sending the RPMB data frame and after receiving the query response, sending, to the memory device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values and receiving, from the memory device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.
[0139] In a fifteenth aspect, in combination with one or more of the ninth aspect through the fourteenth aspect, the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with the RPMB protocol.
[0140] In a sixteenth aspect, in combination with one or more of the ninth aspect through the fifteenth aspect, the one or more control setting values include one or more of a flag or an attribute.
[0141] In a seventeenth aspect, an apparatus includes a non-volatile memory and a memory controller coupled to the non-volatile memory. The memory controller is configured to receive, from a host device, a replay protected memory device block (RPMB) data frame that includes a data field. The data field includes a query request to be executed by the memory controller. The query request indicates one or more control setting values to be written to the non-volatile memory. The memory controller is further configured to send, to the host device, a response to the query request.
[0142] In an eighteenth aspect, in combination the seventeenth aspect, the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.
[0143] In a nineteenth aspect, in combination with one or more of the seventeenth aspect through the eighteenth aspect, the RPMB data frame is associated with a first protocol, and the query request is associated with a second protocol different than the first protocol.
[0144] In a twentieth aspect, in combination with one or more of the seventeenth aspect through the nineteenth aspect, the first protocol is an RPMB protocol, and the second protocol is a universal flash storage (UFS) protocol.
[0145] In a twenty-first aspect, in combination with one or more of the seventeenth aspect through the twentieth aspect, the query response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.
[0146] In a twenty-second aspect, in combination with one or more of the seventeenth aspect through the twenty-first aspect, the memory controller is further configured to receive, from the host device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values and to send, to the host device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.
[0147] In a twenty-third aspect, in combination with one or more of the seventeenth aspect through the twenty-second aspect, the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with the RPMB protocol.
[0148] In a twenty-fourth aspect, a method of operation of a memory device includes receiving, at the memory device from a host device, a replay protected memory device block (RPMB) data frame that includes a data field. The data field includes a query request to be executed by the memory device. The query request indicates one or more control setting values to be written to the memory device. The method further includes sending, to the host device, a response to the query request.
[0149] In a twenty-fifth aspect, in combination with the twenty-fourth aspect, the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.
[0150] In a twenty-sixth aspect, in combination with one or more of the twenty-fourth aspect through the twenty-fifth aspect, the RPMB data frame is associated with a first protocol, and the query request is associated with a second protocol different than the first protocol.
[0151] In a twenty-seventh aspect, in combination with one or more of the twenty-fourth aspect through the twenty-sixth aspect, the first protocol is an RPMB protocol, and the second protocol is a universal flash storage (UFS) protocol.
[0152] In a twenty-eighth aspect, in combination with one or more of the twenty-fourth aspect through the twenty-seventh aspect, the query response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.
[0153] In a twenty-ninth aspect, in combination with one or more of the twenty-fourth aspect through the twenty-eighth aspect, the method includes, after receiving the RPMB data frame and after sending the query response, receiving, from the host device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values and sending, to the host device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.
[0154] In a thirtieth aspect, in combination with one or more of the twenty-fourth aspect through the twenty-ninth aspect, the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with the RPMB protocol.
[0155] Those of skill in the art would understand that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0156] One or more components, functional blocks, and the modules described herein may include processors, electronics devices, hardware devices, electronics components, logical circuits, memories, software codes, firmware codes, among other examples, or any combination thereof. Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, application, software applications, software packages, routines, subroutines, objects, executables, threads of execution, procedures, and / or functions, among other examples, whether referred to as software, firmware, middleware, microcode, hardware description language or otherwise. In addition, features discussed herein may be implemented via specialized processor circuitry, via executable instructions, or combinations thereof.
[0157] The various illustrative logics, logical blocks, modules, circuits, and processes described herein may be implemented using electronic hardware, computer software, or combinations of both. Such components may be described generally, in terms of functionality, and illustrated in the various illustrative components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware or software may depend upon the particular application and design of the overall system.
[0158] A hardware and data processing apparatus used to implement the various illustrative logics, logical blocks, modules and circuits described herein may be implemented or performed with a general purpose single-or multi-chip processor, a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, or, any conventional processor, controller, microcontroller, or state machine. In some implementations, a processor may be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. In some implementations, particular processes and methods may be performed by circuitry that is specific to a given function.
[0159] In one or more aspects, the functions described may be implemented in hardware, digital electronic circuitry, computer software, firmware, including the structures disclosed in this specification and their structural equivalents thereof, or in any combination thereof. Implementations of the subject matter described in this specification also may be implemented as one or more computer programs, which is one or more modules of computer program instructions, encoded on a computer storage media for execution by, or to control the operation of, data processing apparatus.
[0160] If implemented in software, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. A process disclosed herein may be implemented using a processor-executable software module which may reside on a computer-readable medium. Computer-readable media include computer storage media. A storage media may be any available media that may be accessed by a computer. By way of example, and not limitation, such computer-readable media may include random-access memory (RAM) , read-only memory (ROM) , electrically erasable programmable read-only memory (EEPROM) , CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that may be used to store desired program code in the form of instructions or data structures and that may be accessed by a computer. Disk and disc, as used herein, includes compact disc (CD) , laser disc, optical disc, digital versatile disc (DVD) , floppy disk, and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media. Additionally, the operations of a method or process may reside as one or any combination or set of codes and instructions on a machine readable medium and computer-readable medium, which may be incorporated into a computer program product.
[0161] Various modifications to the implementations described in this disclosure may be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to some other implementations without departing from the spirit or scope of this disclosure. Thus, the claims are not intended to be limited to the implementations shown herein, but are to be accorded the widest scope consistent with this disclosure, the principles and the novel features disclosed herein.
[0162] Additionally, a person having ordinary skill in the art will readily appreciate, opposing terms such as “upper” and “lower” or “front” and back” or “top” and “bottom” or “forward” and “backward” are sometimes used for ease of describing the figures, and indicate relative positions corresponding to the orientation of the figure on a properly oriented page, and may not reflect the proper orientation of any device as implemented.
[0163] Certain features that are described in this specification in the context of separate implementations also may be implemented in combination in a single implementation. Conversely, various features that are described in the context of a single implementation also may be implemented in multiple implementations separately or in any suitable subcombination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination may in some cases be excised from the combination, and the claimed combination may be directed to a subcombination or variation of a subcombination.
[0164] Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. Further, the drawings may schematically depict one or more example processes in the form of a flow diagram. However, other operations that are not depicted may be incorporated in the example processes that are schematically illustrated. For example, one or more additional operations may be performed before, after, simultaneously, or between any of the illustrated operations. In certain circumstances, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the implementations described above should not be understood as requiring such separation in all implementations, and it should be understood that the described program components and systems may generally be integrated together in a single software product or packaged into multiple software products. Additionally, some other implementations are within the scope of the following claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve desirable results.
[0165] As used herein, including in the claims, the term “or, ” when used in a list of two or more items, means that any one of the listed items may be employed by itself, or any combination of two or more of the listed items may be employed. For example, if a composition is described as containing components A, B, or C, the composition may contain A alone; B alone; C alone; A and B in combination; A and C in combination; B and C in combination; or A, B, and C in combination. Also, as used herein, including in the claims, “or” as used in a list of items prefaced by “at least one of” indicates a disjunctive list such that, for example, a list of “at least one of A, B, or C” means A or B or C or AB or AC or BC or ABC (that is A and B and C) or any of these in any combination thereof. The term “substantially” is defined as largely but not necessarily wholly what is specified (and includes what is specified; for example, substantially 90 degrees includes 90 degrees and substantially parallel includes parallel) , as understood by a person of ordinary skill in the art. In any disclosed implementations, the term “substantially” may be substituted with “within [a percentage] of” what is specified, where the percentage includes . 1, 1, 5, or 10 percent.
[0166] The previous description of the disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other variations without departing from the spirit or scope of the disclosure. Thus, the disclosure is not intended to be limited to the examples and designs described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1.An apparatus comprising:a processing system including one or more processors and one or more memories coupled to the one or more processors, the processing system configured to:send, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field, the data field including a query request to be executed by the memory device, the query request indicating one or more control setting values to be written to the memory device; andreceive, from the memory device, a response to the query request.2.The apparatus of claim 1, wherein the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.3.The apparatus of claim 1, wherein the RPMB data frame is associated with a first protocol, and wherein the query request is associated with a second protocol different than the first protocol.4.The apparatus of claim 3, wherein the first protocol is an RPMB protocol, and wherein the second protocol is a universal flash storage (UFS) protocol.5.The apparatus of claim 1, wherein the response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.6.The apparatus of claim 1, wherein the processing system is further configured to:send, to the memory device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values; andreceive, from the memory device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.7.The apparatus of claim 6, wherein the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with an RPMB protocol.8.The apparatus of claim 1, wherein the one or more control setting values include one or more of a flag or an attribute.9.A method of operation of a host device, the method comprising:sending, to a memory device, a replay protected memory device block (RPMB) data frame that includes a data field, the data field including a query request to be executed by the memory device, the query request indicating one or more control setting values to be written to the memory device; andreceiving, from the memory device, a response to the query request.10.The method of claim 9, wherein the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.11.The method of claim 9, wherein the RPMB data frame is associated with a first protocol, and wherein the query request is associated with a second protocol different than the first protocol.12.The method of claim 11, wherein the first protocol is an RPMB protocol, and wherein the second protocol is a universal flash storage (UFS) protocol.13.The method of claim 9, wherein the response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.14.The method of claim 9, further comprising:after sending the RPMB data frame and after receiving the response:sending, to the memory device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values; andreceiving, from the memory device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.15.The method of claim 14, wherein the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with an RPMB protocol.16.The method of claim 9, wherein the one or more control setting values include one or more of a flag or an attribute.17.An apparatus comprising:a non-volatile memory; anda memory controller coupled to the non-volatile memory, the memory controller configured to:receive, from a host device, a replay protected memory device block (RPMB) data frame that includes a data field, the data field including a query request to be executed by the memory controller, the query request indicating one or more control setting values to be written to the non-volatile memory; andsend, to the host device, a response to the query request.18.The apparatus of claim 17, wherein the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.19.The apparatus of claim 17, wherein the RPMB data frame is associated with a first protocol, and wherein the query request is associated with a second protocol different than the first protocol.20.The apparatus of claim 19, wherein the first protocol is an RPMB protocol, and wherein the second protocol is a universal flash storage (UFS) protocol.21.The apparatus of claim 17, wherein the query response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.22.The apparatus of claim 17, wherein the memory controller is further configured to:receive, from the host device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values; andsend, to the host device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.23.The apparatus of claim 22, wherein the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with an RPMB protocol.24.A method of operation of a memory device, the method comprising:receiving, at the memory device from a host device, a replay protected memory device block (RPMB) data frame that includes a data field, the data field including a query request to be executed by the memory device, the query request indicating one or more control setting values to be written to the memory device; andsending, to the host device, a response to the query request.25.The method of claim 24, wherein the RPMB data frame further includes a control field having an opcode that indicates that the data field is associated with an instruction type instead of a data type.26.The method of claim 24, wherein the RPMB data frame is associated with a first protocol, and wherein the query request is associated with a second protocol different than the first protocol.27.The method of claim 26, wherein the first protocol is an RPMB protocol, and wherein the second protocol is a universal flash storage (UFS) protocol.28.The method of claim 24, wherein the response is included in a universal flash storage (UFS) protocol information unit (UPIU) associated with a first RPMB protocol or in an authenticated query request command response associated with a second RPMB protocol different than the first RPMB protocol.29.The method of claim 24, further comprising:after receiving the RPMB data frame and after sending the response:receiving, from the host device, a second RPMB data frame that includes a second data field including a query response read request for at least one control setting value of the one or more control setting values; andsending, to the host device, a third RPMB data frame that includes a third data field including a query response indicating the at least one control setting value.30.The method of claim 29, wherein the RPMB data frame, the second RPMB data frame, and the third RPMB data frame each include a respective message authentication code (MAC) that is associated with an authentication key associated with an RPMB protocol.
Citation Information
Patent Citations
Data storage device and operating method thereof
CN114254402A
Memory device having RPMB reset function and RPMB management method thereof
CN117407327A
Data storage device and method of operating the same
US20220155976A1