IP Library Granted Patent US 8,239,691
Granted Patent B2
US 8,239,691 · App. 12/079,699 · Granted Aug 7, 2012

Data storage device and management method of cryptographic key thereof

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,239,691
App. No.
12/079,699
Granted
Aug 7, 2012
Kind
B2
Abstract

Embodiments of the present invention help to securely manage a data cryptographic key in a data storage device. In an embodiment of the present invention, a cryptographic processor for encrypting and decrypting data is located between a host interface and a memory manager. In parts of the hard disk drive (HDD), except for the host interface, the HDD handles user data in an encrypted state. A data cryptographic key which the cryptographic processor uses to encrypt and decrypt the user data is encrypted and stored in a magnetic disk. A multiprocessing unit (MPU) decrypts the data cryptographic key using a password and a random number to supply it to the cryptographic processor. Using the password and the random number, the HDD can manage the data cryptographic key with more security.

Claims (27)

1. A hard disk drive data storage device comprising:

an enclosure;

a spindle motor fixedly coupled within said enclosure;

at least one magnetic disk fixedly coupled with said spindle motor, said at least one magnetic disk being a medium for storing encrypted data;

a key cryptographic processor for generating a key cryptographic key using external key generation data received from a host and internal key generation data stored inside the data storage device, and decrypting a data cryptographic key stored inside the data storage device in encrypted a data cryptographic key using the key cryptographic key;

a data cryptographic processor for performing a cryptographic operation on data in the medium using decrypted said the data cryptographic key; and

an authentication processor for performing authentication using the external key generation data as a password, wherein the key cryptographic processor generates the key cryptographic key using the password used in the authentication if the authentication has been normally performed, wherein if the password is changed, the key cryptographic processor generates the key cryptographic key with changed the password and renewed the internal key generation data, and encrypts the data cryptographic key using generated said the key cryptographic key.

2. The data storage device according to claim 1 , further comprising

a random number generator, wherein the internal key generation data is a random number generated by the random number generator.

3. The data storage device according to claim 1 , wherein the key cryptographic processor renews the key cryptographic key changing the internal key generation data.

4. The data storage device according to claim 3 , wherein if the encrypted and stored data cryptographic key is accessed from an external, the key cryptographic processor renews the key cryptographic key changing the internal key generation data.

5. The data storage device according to claim 1 , wherein

a data storage region of the medium has a plurality of divided sections; and

plural data cryptographic keys corresponding to each of the plurality of divided sections are encrypted and stored inside the data storage device using plural key cryptographic keys generated from each different plural internal key generation data.

6. A management method of a data cryptographic key in a hard disk drive data storage device performing a cryptographic operation of data in a medium, said method comprising:

providing an enclosure;

fixedly coupling a spindle motor within said enclosure;

fixedly coupling at least one magnetic disk with said spindle motor, said at least one magnetic disk being a medium for storing encrypted data;

receiving external key generation data from a host;

generating a key cryptographic key using the external key generation data and internal key generation data stored inside the data storage device;

decrypting the data cryptographic key stored inside the data storage device in encrypted the data cryptographic key using the key cryptographic key;

performing the cryptographic operation of data in the medium using the decrypted data cryptographic key; and

performing authentication using the external key generation data as a password, wherein if the authentication has been normally performed, the key cryptographic key is generated using the password used in the authentication, wherein if the password is changed, the key cryptographic key is generated with changed the password and renewed the internal key generation data, and the data cryptographic key is encrypted using generated said the key cryptographic key.

7. The management method according to claim 6 , wherein the data storage device further comprises a random number generator; and the internal key generation data are a random number generated by the random number generator.

8. The management method according to claim 6 , wherein the key cryptographic key is changed by renewing the internal key generation data.

9. The management method according to claim 8 , wherein if the encrypted and stored data cryptographic key is accessed from the external, the key cryptographic key is changed by renewing the internal key generation data.

10. The management method according to claim 6 , wherein a data storage region in the medium has a plurality of divided sections; and plural data cryptographic keys corresponding to each of the plurality of divided sections are encrypted by using plural key cryptographic keys generated from each different plural internal key generation data and is stored inside the data storage device.

Assignments (7)
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 040826/0821 →
CHANGE OF NAME Recorded Oct 25, 2012
From: HITACHI GLOBAL STORAGE TECHNOLOGIES NETHERLANDS B.V.
To: HGST NETHERLANDS B.V.
Reel/Frame 029341/0777 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2008
From: WATANABE, YOSHIJU; KAKIHARA, TOSHIO
To: HITACHI GLOBAL STORAGE TECHNOLOGIES NETHERLANDS B.V.
Reel/Frame 020871/0508 →