IP Library Patent Application 12390956
Patent Application
App. No. 12/390,956

SYSTEMS AND METHODS OF SECURITY FOR AN OBJECT BASED STORAGE DEVICE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/390,956
Abstract

The disclosure is related to systems and methods of security for a data storage device and in particular embodiments, an object based data storage device. In a particular embodiment, a system comprises an object based data storage device adapted to store objects received from a host The object based data storage device may be adapted to encrypt and decrypt objects without allowing access to an encryption key or decryption key from external to the object based data storage device.

Claims (49)

1 . A device comprising:

an object based data storage device adapted to store objects received from a host, where each object comprises user data, metadata, and data identifying an attribute of the object, the object based data storage device adapted to encrypt and decrypt objects without transmitting an encryption or decryption key external to the object based data storage device, the object based data storage device comprising:

an interface adapted to receive an object from the host, assign a unique identifier to the object, and transmit the unique identifier back to the host;

an encryption module coupled to the interface and adapted to encrypt a selected object to produce an encrypted object based on an encryption key;

a controller coupled to the encryption module, a memory, and a data storage medium, the controller adapted to:

store the encrypted object to the data storage medium and store the encryption key to the memory;

retrieve the encryption key from the memory and the encrypted object from the data storage medium when a read command containing a unique identifier associated with the selected object is received from the host; and

a decryption module coupled to the controller, the decryption module adapted to decrypt the encrypted object based on the encryption key to produce the selected object and provide the selected object to the interface for transfer to the host.

2 . The device of claim 1 wherein the encryption and decryption occurs independent of any command from the host and the encryption key is not provided from the data storage device to the host.

3 . The device of claim 1 wherein the selected object is not encrypted when received from the host at the interface, the selected object is encrypted when stored on the data storage medium, and the selected object is not encrypted when provided back to the host.

4 . The device of claim 1 wherein the selected object is already encrypted with a first encryption when received from the host at the interface, the selected object is encrypted a second time with a second encryption by the encryption module, the selected object with the second encryption is stored on the data storage medium, and the selected object is only encrypted with the first encryption when provided back to the host.

5 . The device of claim 1 further comprising the controller adapted to, in response to a command received from the host to delete the selected object, delete the encryption key stored in the memory instead of deleting the encrypted object stored on the data storage medium, and notify the host via the interface that the selected object was deleted.

6 . The device of claim 5 further comprising the controller adapted to delete the encryption key in response to a trigger condition being detected.

7 . The device of claim 6 wherein the trigger condition comprises at least one of a number of invalid password attempts, a detected hacking attempt, an unauthorized command, detection of inconsistent commands from the host, detection of an unauthorized host, detection of an unauthorized user, a time expiration, and a change in programs executed at the host.

8 . The device of claim 1 further comprising the encryption module adapted to encrypt multiple objects based on a single encryption key; and the controller adapted to, in response to a command received from the host to delete the multiple objects, delete the single encryption key, not delete the encrypted objects from the data storage medium, and notify the host via the interface that the multiple objects were deleted.

9 . The device of claim 1 further comprising the encryption module adapted to encrypt multiple objects, each object being encrypted based on a unique encryption key; and the controller adapted to, in response to a command received from the host to delete the multiple objects, delete each unique encryption key associated with the multiple objects, not delete the encrypted objects, and notify the host via the interface that the multiple objects were deleted.

10 . An object based data storage device comprising:

an interface adapted to receive an object from a host, each object comprising user data, metadata, and data identifying an attribute of the object, the interface further adapted to provide a unique identifier that is associated with the object to the host;

a controller coupled to the interface and comprising a security module adapted to:

encrypt the object based on an encryption key to produce an encrypted object;

store the encrypted object to a data storage medium;

store the encryption key to a memory; and

delete the encryption key stored in the memory in response to a trigger without decrypting the encrypted object stored on the data storage medium.

11 . The object based data storage device of claim 10 further comprising the data storage medium, wherein the data storage medium is at least one of a magnetic disc, a magneto-optical disc, an optical disc, or a solid state non-volatile memory.

12 . The object based storage device of claim 10 further comprising the controller comprising a decryption module adapted to decrypt the encrypted object based on the encryption key to produce the object and provide the object to the interface for transfer to the host.

13 . The object based data storage device of claim 12 further comprising multiple objects and the controller is further adapted to encrypt each of the multiple objects based on a unique key associated with each of the multiple objects.

14 . The object based data storage device of claim 13 wherein each of the unique encryption keys are stored in a secure area of the object based data storage device, the secure area being configured to restrict access to the secure area from external to the object based data storage device.

15 . The object based data storage device of claim 13 wherein the attribute comprises a designation of a level of importance for each of the multiple data objects and the controller is further adapted to:

when a first level of importance is designated by the attribute, encrypt each of the unique encryption keys associated with objects having the first level of importance using a first encryption key;

when a second level of importance is designated by the attribute, encrypt each of the unique encryption keys having the second level of importance using a second encryption key; and

encrypt both the first encryption key and the second encryption key using third encryption key.

16 . The object based data storage device of claim 10 wherein each of the unique encryption keys are stored in a secure area of the object based data storage device, the secure area configured to restrict access to the secure area from external to the object based data storage device.

17 . A controller comprising:

an encryption module adapted to:

generate an encryption key that is not accessible by a host and is based upon a random number from a random number generator;

encrypt an object intended for storage on an object based data storage device, the encrypting based on an encryption key to produce an encrypted object;

a data storage module adapted to:

store the encrypted object to a data storage medium;

store the encryption key to a memory;

retrieve the encrypted object from the data storage medium when a read command is received from a host, the read command including a unique object based storage identifier;

retrieve the encryption key from the memory;

a decryption module adapted to:

decrypt the encrypted object based on the encryption key to produce the object;

a deletion module adapted to:

delete the encryption key stored in the memory in response to a trigger; and

notify the host that the object has been deleted from the object based data storage device.

18 . The controller of claim 17 wherein the trigger comprises a timer value associated with the object, the timer value indicating when the object is to be automatically deleted without a delete command being subsequently received from the host.

19 . The controller of claim 20 further comprising the random number generator.

20 . The controller of claim 19 further comprising the encryption module adapted to generate the encryption key based on a user supplied input and the random number generator.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Jul 23, 2025
From: THE BANK OF NOVA SCOTIA
To: SEAGATE TECHNOLOGY PUBLIC LIMITED COMPANY; SEAGATE TECHNOLOGY; SEAGATE TECHNOLOGY HDD HOLDINGS; I365 INC.; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL; SEAGATE HDD CAYMAN; SEAGATE TECHNOLOGY (US) HOLDINGS, INC.
Reel/Frame 072193/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jul 19, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT AND SECOND PRIORITY REPRESENTATIVE
To: SEAGATE TECHNOLOGY LLC; EVAULT INC. (F/K/A I365 INC.); SEAGATE TECHNOLOGY INTERNATIONAL; SEAGATE TECHNOLOGY US HOLDINGS, INC.
Reel/Frame 030833/0001 →
SECURITY AGREEMENT Recorded Mar 24, 2011
From: SEAGATE TECHNOLOGY LLC
To: THE BANK OF NOVA SCOTIA, AS ADMINISTRATIVE AGENT
Reel/Frame 026010/0350 →
RELEASE Recorded Jan 19, 2011
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: SEAGATE TECHNOLOGY HDD HOLDINGS; MAXTOR CORPORATION; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL
Reel/Frame 025662/0001 →
SECURITY AGREEMENT Recorded May 15, 2009
From: MAXTOR CORPORATION; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND FIRST PRIORITY REPRESENTATIVE; WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT AND SECOND PRIORITY REPRESENTATIVE
Reel/Frame 022757/0017 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2009
From: GOODWILL, WILLIAM PRESTON; ANDERSON, DAVE B.
To: SEAGATE TECHNOLOGY LLC
Reel/Frame 022297/0727 →