IP Library Granted Patent US 8,464,073
Granted Patent B2
US 8,464,073 · App. 11/520,014 · Granted Jun 11, 2013

Method and system for secure data storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,464,073
App. No.
11/520,014
Granted
Jun 11, 2013
Kind
B2
Abstract

A secure storage device includes a storage medium configured to securely store data received from a host. The storage device further includes a host interface configured to transfer data between the host and the storage device and an encryption engine. The encryption engine is configured to encrypt data received from a host using a key and provide the encrypted data to the storage medium for storage. The encryption engine is further configured to decrypt encrypted data received from the storage medium and provide the data to the host via the host interface. In response to a predetermined condition, the storage device is configured to disable the encryption engine thereby preventing the encrypted data stored thereon from being decrypted.

Claims (46)

1. A storage device comprising:

a host interface configured to transfer data between a host and said storage device;

a storage medium configured to store data transferred from the host;

a seed interface configured to access a seed value; and

an encryption engine configured to receive data from the host via said host interface, access the seed value via the seed interface, generate a key based on the seed value, encrypt the data using the key, and provide the encrypted data to said storage medium for storage, said encryption engine further configured to receive the encrypted data from said storage medium, decrypt the encrypted data using the key, and provide the data to the host via said host interface,

wherein the storage device is configured to instruct the seed interface to become inoperable, in response to a predetermined condition corresponding to a security risk to the storage device,

wherein said storage device further comprises a storage location for storing the seed value,

wherein said storage device is further configured to erase the seed value from said storage location in response to the predetermined condition, and

wherein said storage device is configured to disable at least part of the key in response to the predetermined condition.

2. The storage device of claim 1 , wherein said encryption engine is configured to generate the key based on a password.

3. The storage device of claim 2 , wherein the password is received from the host via said host interface.

4. The storage device of claim 1 , wherein the key is generated by said encryption engine for each access by the host to said storage device.

5. The storage device of claim 1 , wherein said encryption engine comprises a plurality of functional logic blocks, wherein said encryption engine is further configured to modify one or more of the functional logic blocks in response to the predetermined condition.

6. The storage device of claim 1 , wherein said encryption engine comprises executable code, wherein said encryption engine is further configured to modify a portion of the executable code in response to the predetermined condition.

7. The storage device of claim 1 , wherein said storage medium is a Flash memory.

8. A secure storage system, comprising:

a host; and

a storage device, said storage device further comprising:

a host interface configured to transfer data between said host and said storage device;

a storage medium configured to store data transferred from said host;

a seed interface configured to access a seed value; and

an encryption engine configured to receive data from the host via said host interface, access the seed value via the seed interface, generate a key based on the seed value, encrypt the data using the key, and provide the encrypted data to said storage medium for storage, said encryption engine further configured to receive the encrypted data from said storage medium, decrypt the encrypted data using the key, and provide the data to the host via said host interface,

wherein the storage device is configured to instruct the seed interface to become inoperable, in response to a predetermined condition corresponding to a security risk to the storage device,

wherein said storage device further comprises a storage location for storing the seed value,

wherein said storage device is further configured to erase the seed value stored in said storage location in response to predetermined condition, and

wherein said storage device is configured to disable at least part of the key in response to the predetermined condition.

9. The secure storage system of claim 8 , wherein said encryption engine is configured to generate the key based on a password.

10. The secure storage system of claim 9 , wherein the password is received from said host via said host interface.

11. The secure storage system of claim 8 , wherein the key is generated by said encryption engine for each access by said host to said storage device.

12. The secure storage system of claim 8 , wherein said encryption engine comprises a plurality of functional blocks, wherein said encryption engine is further configured to modify one or more of the functional blocks in response to the predetermined condition.

13. The secure storage system of claim 8 , wherein said encryption engine comprises executable code, wherein said encryption engine is further configured to modify a portion of the executable code in response to the predetermined condition.

14. The secure storage system of claim 8 , wherein said storage medium is a Flash memory.

15. A method for securely storing data, the method comprising the steps of:

receiving a command from a host;

accessing a seed value via a seed interface;

generating a key based on the seed value;

if the command is a read command, decrypting encrypted data retrieved from a storage medium using the key and providing the decrypted data to the host;

if the command is a write command, encrypting data received from the host using the key and storing the encrypted data within a storage medium; instructing the seed interface to become inoperable, in response to a predetermined condition corresponding to a security risk to storage;

storing the seed value in a storage location;

erasing the seed value stored in the storage location in response to the predetermined condition; and

disabling at least part of the key in response to the predetermined condition.

16. The method of claim 15 , wherein the key is generated based on a password.

17. The method of claim 15 , wherein the key is generated for each read and write command received from the host.

18. The method of claim 15 , further comprising the step of modifying, in response to the predetermined condition, at least one of a plurality of functional blocks used to encrypt and decrypt data.

19. The method of claim 15 , further comprising the step of modifying, in response to the predetermined condition, at least one portion of software used to encrypt and decrypt data.

20. The method of claim 15 , wherein the storage medium is Flash memory.

Assignments (11)
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2018
From: HGST TECHNOLOGIES SANTA ANA, INC.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 046174/0446 →
CHANGE OF NAME Recorded Jul 1, 2015
From: STEC, INC.
To: HGST TECHNOLOGIES SANTA ANA, INC.
Reel/Frame 036042/0390 →
MERGER AND CHANGE OF NAME Recorded Jun 12, 2007
From: SIMPLETECH, INC.
To: STEC, INC.
Reel/Frame 019440/0517 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2006
From: SALESSI, NADER
To: SIMPLETECH, INC.
Reel/Frame 018289/0549 →