IP Library Granted Patent US 8,429,426
Granted Patent B2
US 8,429,426 · App. 12/253,414 · Granted Apr 23, 2013

Secure pipeline manager

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,426
App. No.
12/253,414
Granted
Apr 23, 2013
Kind
B2
Abstract

A method for data storage includes supplying data to and from a host to a storage memory via a secure data path. A first CPU is employed to control operation of the storage memory, and a second CPU is employed to control operation of the secure data path.

Claims (25)

1. A method and a device for data storage comprising:

performing in a data storage device that includes:

a storage memory,

a storage memory manager,

a host interface,

a secure data path between said host interface and said storage memory, said secure data path including two or more cryptographic processors (crypto-processors) arranged in series along the secure data path,

a main Central Processing Unit (CPU) configured to manage operations of the data storage device and to direct the storage memory manager to transfer data to and from the storage memory via the secure data path, and

a control CPU that is configured to consume less power than the main CPU, wherein the control CPU does not perform the operations of the main CPU and wherein the Control CPU is configured to control the two or more cryptographic processor;

transferring data to and from a host to said host interface by:

transferring data to and from the storage memory, under control of the main CPU via said storage memory manager, wherein the transferring is performed via the secure data path;

performing encryption operations under control of the control CPU, using the two or more cryptographic engines in series, wherein said control CPU has access to secret keys required to control operation of said secure data path and said main CPU does not have access to said secret keys; and

placing the main CPU in an idle mode such that the main CPU does not consume an appreciable amount of power for at least a period of time while encryption operations are performed under control of the control CPU.

2. The method for data storage according to claim 1 , wherein said secure data path includes software with one or more algorithms, including: AES (Advanced Encryption Standard), DES (Data Encryption Standard), 3DES (Triple DES), SHA1 (Secure Hash Algorithm 1), SHA256 (Secure Hash Algorithm 256), SHA384 (Secure Hash Algorithm 384), SHA512 (Secure Hash Algorithm 512) and RC4 (Rivest Cipher 4).

3. The method for data storage according to claim 1 , wherein the performing encryption operations using the two or more cryptographic engines in series comprises storing data in a Random Access Memory (RAM) and retrieving data from the RAM.

4. A device for data storage comprising:

a storage memory,

a storage memory manager,

a host interface,

a secure data path between said host interface and said storage memory;

two or more cryptographic processors (crypto-processors) arranged in series along the secure data path,

a main Central Processing Unit (CPU) configured to manage operations of the device and to direct the storage memory manager to transfer data to and from the storage memory via the secure data path, and

a control CPU that is configured to consume less power than the main CPU, wherein the control CPU does not perform the operations of the main CPU and wherein the Control CPU is configured to perform encryption operation on the data transferred via the secure data path using the two or more crypto-processors in series, wherein said control CPU has access to secret keys required to control operation of said secure data path and said main CPU does not have access to said secret keys;

wherein the main CPU is configured to operate in an idle mode such that the main CPU does not consume an appreciable amount of power for at least a period of time while the control CPU performs encryption operations.

5. The device for data storage according to claim 4 , further comprising:

a Random Access Memory (RAM) operative to store data output from a first crypto-processor and operative to provide input to a second crypto-processor.

Assignments (7)
CHANGE OF NAME Recorded Jun 10, 2025
From: WESTERN DIGITAL ISRAEL LTD.
To: SANDISK ISRAEL LTD.
Reel/Frame 071587/0836 →
PATENT COLLATERAL AGREEMENT (DDTL) Recorded Feb 22, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 066648/0206 →
PATENT COLLATERAL AGREEMENT (AR) Recorded Feb 22, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 066648/0284 →
THIS IS A MUTUAL RESCISSION AGREMENT OF A PREVIOUSLY RECORDED ASSIGNMENT AT REEL/FRAME: 066114/0481 Recorded Feb 6, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: WESTERN DIGITAL ISRAEL LTD.
Reel/Frame 066507/0538 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: WESTERN DIGITAL ISRAEL LTD.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 066114/0481 →
CHANGE OF NAME Recorded Aug 21, 2020
From: SANDISK IL LTD
To: WESTERN DIGITAL ISRAEL LTD
Reel/Frame 053574/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2008
From: MINZ, LEONID; MEIR, AVRAHAM; DOLGUNOV, BORIS; KROTMAN, ROY
To: SANDISK IL LTD.
Reel/Frame 021697/0874 →