Storage Device Secure Command Protection via RPMB Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage systems lack a flexible and comprehensive method to protect various commands and memory regions securely, failing to provide adequate protection against malicious access to critical data.
Innovation Solution
The implementation of a secure command protect configuration block (SCPCB) within the storage device, which allows for setting a secure mode for multiple commands across different memory regions, using the replay protect memory block (RPMB) message, enabling secure mode settings in units of logical block addresses, logical units, or memory types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure mode is set for protecting important data in non-volatile memory, then data security is improved, but the system lacks flexibility to protect various commands and memory regions according to user intent
Solution Approach 1:
The patent segments the memory device into multiple replay protect memory blocks (RPMBs), each capable of independent secure mode setting. This allows different commands and memory regions to be protected independently, providing both security and flexibility. The host can set secure mode for specific RPMBs based on user intent, protecting only the necessary commands and memory regions.
Solution Approach 2:
The patent implements dynamic secure mode setting where the host can change the secure mode of RPMBs during operation. The secure mode can be set, changed, or cleared based on authentication results and user requirements. This dynamic capability allows the system to adapt to different security needs while maintaining protection for critical data.
2Reliability
If comprehensive protection for various commands and memory regions is implemented, then security coverage is improved, but the complexity of the storage system increases
Solution Approach 1:
The patent uses a universal RPMB structure that can be applied to protect different types of commands and memory regions. The same RPMB mechanism provides protection for read commands, write commands, and various memory regions, eliminating the need for separate protection mechanisms for each command type or region.
Solution Approach 2:
The host device performs authentication and secure mode setting operations itself, using the RPMB structure provided by the memory device. The host manages the security configuration, authentication keys, and mode settings, reducing the burden on the memory device while achieving comprehensive protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided is a storage device which communicates with a host device and configured to set a secure mode of a plurality of commands different in kind. An operating method of the storage device includes receiving a secure request indicating a protection of a first command and a protection of a second command of the plurality of commands, from the host device; setting a secure mode of the first and second commands, based on the secure request; receiving a first request indicating a request to execute the first command, from the host device; outputting a first response indicating failure of the first command to the host device, based on the first request; receiving a second request indicating a request to execute the second command, from the host device; and outputting a second response indicating failure of the second command to the host device, based on the second request.