Storage device, operating method thereof, and system for providing application-by-application secure storage place
There is provided a method of operating a plurality of storage devices may include providing, by a first storage controller of a first storage device, resources required for execution of an application to a host device so that the host device executes the application; and allocating, by a second storage controller of a second storage device, a storage space to be used by the application executed in a trusted execution environment (TEE) area to the host device in units of applications based on identification information of the host device included in a allocation request.
1 . A method of operating a plurality of storage devices, the method comprising:
providing, by a first storage controller of a first storage device, resources required for execution of a first application to a host device so that the host device executes the first application;
receiving, by a second storage controller of a second storage device, an allocation request for a storage space corresponding to the first application from the host device; and
allocating, by the second storage controller, the storage space to be used by the first application executed in a trusted execution environment (TEE) area to the host device in units of grouped applications based on identification information of the host device included in the allocation request, a first unit of the grouped applications including the first application and a second application, the TEE area based on the first storage controller and the second storage controller,
the resources including at least one of a kernel, middleware, an application programming interface (API), or execution-related data of the first application.
2 . The method of claim 1 , wherein the allocating of the storage space comprises
providing, by the second storage controller, identification information of the second storage device requested by the host device to the host device; and
verifying identification information of the host device based on a response of the host device to the identification information of the second storage device.
3 . The method of claim 2 , wherein, based on the response of the host device to a certificate included in the identification information of the second storage device being that the certificate is a trusted certificate, the verifying of the identification information of the host device comprises
decrypting, by the second storage controller, identification information of the host device and required storage space information with a secret encryption key of the second storage device corresponding to a public encryption key wherein the identification information of the host device and the required storage space information are included in the response of the host device and encrypted by the host device with the public encryption key of the second storage device; and
allocating, by the second storage controller, the storage space to be used by the first application executed in the TEE area to the host device in the units of applications based on the decrypted identification information of the host device and the required storage space information.
4 . The method of claim 3 , wherein the allocating of the storage space comprises
determining, by the second storage controller, whether a self-encrypting drive (SED) unlock key included in the decrypted identification information of the host device corresponds to the SED unlock key of the second storage device.
5 . The method of claim 4 , wherein the allocating of the storage space comprises
generating, by the second storage controller, a hash value for the identification information of the host device and information on the allocated storage space based on a hash function; and
providing, by the second storage controller, the generated hash value to the host device.
6 . The method of claim 1 , further comprising:
receiving, by the second storage device, an unlock request for the second storage device from the host device;
determining, by the second storage controller, whether to unlock the second storage device based on a password input from a user of the first application included in the unlock request; and
providing, by the second storage controller, a determination result of whether or not to unlock the second storage device to the host device.
7 . The method of claim 6 , further comprising:
receiving, by the second storage controller, a read request for data stored in the second storage device, decrypting, by the second storage controller, based on the second storage device being unlocked, the read request for the data stored in the second storage device using a one-time password (OTP) as a key value, wherein the read request has been encrypted using the OTP as the key value, and
reading the data from the second storage device in response to the decrypted read request.
8 . The method of claim 7 , wherein the reading of the data further comprises
verifying, by the second storage controller, the decrypted read request based on identification information of the first application and a counter value before reading the data.
9 . The method of claim 6 , further comprising:
receiving, by the second storage controller, a write request for data to be written to the second storage device,
decrypting, by the second storage controller, based on the second storage device being unlocked, the write request for data to be written to the second storage device using a one-time-password (OTP) as a key value, wherein the write request has been encrypted using the OTP as the key value, and
writing the data to the second storage device in response to the decrypted write request.
10 . The method of claim 1 , wherein
the grouped applications includes a second unit including a third application, and
the storage space of the first unit and the storage space of the second unit are separate.
11 . A storage device comprising:
a first non-volatile memory,
a second non-volatile memory that is different from the first non-volatile memory, and
a storage controller configured to
provide a host device with resources required for execution of a first application from the first non-volatile memory so that the host device executes the first application,
receive an allocation request for a storage space corresponding the first application from the host device,
allocate the storage space to be used by the first application executed in a trusted execution environment (TEE) area to the host device in the second non-volatile memory in units of grouped applications based on identification information of the host device included in the allocation request, a first unit of the grouped applications including the first application and a second application, the TEE area based on the
storage controller, the resources includes at least one of a kernel, middleware, an application programming interface (API), or execution-related data of the first application.
12 . The storage device of claim 11 , wherein the storage controller is configured to
provide identification information of a non-volatile memory requested by the host device to the host device, and
verify the identification information of the host device based on a response of the host device to the identification information of the non-volatile memory.
13 . The storage device of claim 12 , wherein the storage controller, based on the response of the host device to a certificate included in the identification information of the non-volatile memory being a trusted certificate, is configured to
decrypt the identification information of the host device and information on a required storage space with a secret encryption key of the non-volatile memory corresponding to a public encryption key, the identification information of the host device and the information on the required storage space being encrypted by the host device with the public encryption key of the non-volatile memory, and
allocate the storage space to be used by the first application executed in the TEE area in the non-volatile memory to the host device in the units of applications based on the decrypted identification information of the host device and the information on the required storage space.
14 . The storage device of claim 12 , wherein the identification information of the host device is identification information of the first application to be run in the host device.
15 . The storage device of claim 13 , wherein the storage controller is configured to determine whether a self-encrypting drive (SED) unlock key included in the identification information of the decrypted host device corresponds to the SED unlock key of the non-volatile memory.
16 . The storage device of claim 15 , wherein the storage controller is configured to
generate a hash value for identification information of the host device and information on the allocated storage space based on a hash function, and
provide the generated hash value to the host device.
17 . The storage device of claim 11 , wherein the storage controller is configured to
receive an unlock request for the second non-volatile memory from the host device,
determine whether to unlock the second non-volatile memory based on a password input from a user of the first application included in the unlock request, and
provide the host device with a determination result of whether or not to unlock the second non-volatile memory.
18 . A host-storage system comprising:
a host device; and
a plurality of storage devices including a first storage device including a first storage controller, and a second storage device including a second storage controller,
the first storage controller of the first storage device being configured to
provide the host device with resources required for execution of a first application so that the host device executes the first application,
the second storage controller of the second storage device being configured to
receives an allocation request for a storage space corresponding to the first application from the host device,
allocate the storage space to be used by the first application executed in a trusted execution environment (TEE) area to the host device in units of grouped applications based on identification information of the host device included in the allocation request, a first unit of the grouped applications including the first application and a second application, the TEE area based on the first storage controller and the second storage controller,
the resources including at least one of a kernel, middleware, an application programming interface (API), or execution-related data of the first application.
19 . The host-storage system of claim 18 , wherein the second storage controller is configured to
provide identification information of the second storage device requested by the host device to the host device, and
verify the identification information of the host device based on a response of the host device to the identification information of the second storage device.
20 . The host-storage system of claim 19 , wherein the identification information of the host device is identification information of an application to be run in the host device.