FLASH MEMORY STORAGE SYSTEM, AND CONTROLLER AND ANTI-FALSIFYING METHOD THEREOF
A flash memory storage system having a flash memory controller, a flash memory chip and a smart card chip is provided. The flash memory chip is configured to store security data. The flash memory controller generates a signature corresponding to the security data according to, a private key and the security data with a one-way hash function, and stores the signature into the smart card chip.
1 . A flash memory storage system, comprising:
a flash memory controller, having a private key;
a flash memory chip, coupled to the flash memory controller, wherein the flash memory chip stores security data; and
a smart card chip, coupled to the flash memory controller,
wherein the flash memory controller generates a signature corresponding to the security data according to the private key and the security data with a one-way hash function, and stores the signature in the smart card chip.
2 . The flash memory storage system according to claim 1 ,
wherein the flash memory controller reads the security data from the flash memory chip, generates a comparison signature corresponding the read security data according to the private key and the read security data with the one-way hash function, reads the signature from the smart card chip and determines whether the read signature is identical to the generated comparison signature,
wherein the flash memory controller outputs a warning message when the read signature is not identical to the generated comparison signature.
3 . The flash memory storage system according to claim 2 , wherein the flash memory controller stores updated security data to replace the security data in the flash memory chip,
wherein the flash memory controller generates an updated signature corresponding to the updated security data according to the private key and the updated security data with the one-way hash function, and stores the updated signature to replace the signature in the smart card chip.
4 . The flash memory storage system according to claim 1 , wherein the smart card chip is a chip complied with a third or higher level of Federal Information Processing Standards (FIPS) 140-2 or a third or higher level of EMV EL.
5 . The flash memory storage system according to claim 1 , wherein the smart card chip couples to the flash memory controller through an interface, and the interface complies with ISO 7816 standards.
6 . A flash memory storage system, comprising:
a flash memory controller, having a private key;
a flash memory chip, coupled to the flash memory controller, wherein the flash memory chip stores security data; and
a smart card chip, coupled to the flash memory controller,
wherein the flash memory controller generates an eigenvalue corresponding to the security data and stores the eigenvalue in the smart card chip,
wherein the flash memory controller generates a signature corresponding to the security data and the eigenvalue according to the private key, the eigenvalue and the security data with a one-way hash function, and stores the signature in the flash memory chip.
7 . The flash memory storage system according to claim 6 ,
wherein the flash memory controller reads the security data and the signature from the flash memory chip, reads the eigenvalue from the smart card chip, generates a comparison signature corresponding the read security data and the read eigenvalue according to the private key, the read eigenvalue and the read security data with the one-way hash function, and determines whether the read signature is identical to the generated comparison signature,
wherein the flash memory controller outputs a warning message when the read signature is not identical to the generated comparison signature.
8 . The flash memory storage system according to claim 7 , wherein the flash memory controller stores updated security data to replace the security data in the flash memory chip,
wherein the flash memory controller generates an updated eigenvalue corresponding to the updated security data, and generates an updated signature corresponding to the updated security data and the updated eigenvalue according to the private key, the updated eigenvalue and the updated security data with the one-way hash function,
wherein the flash memory controller stores the updated signature to replace the signature in the flash memory chip,
wherein the flash memory controller stores the updated eigenvalue to replace the eigenvalue in the smart card chip.
9 . The flash memory storage system according to claim 6 , wherein the flash memory controller generates the eigenvalue based on a physical address for storing the security data in the flash memory chip, a random number corresponding to the security data or a counter value corresponding to the security data.
10 . A flash memory controller, for protecting security data stored in a flash memory chip, the flash memory controller comprising:
a microprocessor unit;
a flash memory interface unit, coupled to the microprocessor unit, and configured to couple to the flash memory chip;
a memory management unit, coupled to the microprocessor unit; and
a security data protection unit, coupled to the microprocessor unit and has a private key,
wherein the security data protection unit generates a signature corresponding to the security data according to the private key and the security data with a one-way hash function, and stores the signature in the smart card chip.
11 . The flash memory controller according to claim 10 ,
wherein when the memory management unit reads the security data from the flash memory chip, the security data protection unit reads the signature from the smart card chip, generates a comparison signature corresponding the read security data according to the private key and the read security data with the one-way hash function, and determines whether the read signature is identical to the generated comparison signature,
wherein the security data protection unit outputs a warning message when the read signature is not identical to the generated comparison signature.
12 . The flash memory controller according to claim 11 , wherein the memory management unit stores updated security data to replace the security data in the flash memory chip,
wherein the security data protection unit generates an updated signature corresponding to the updated security data according to the private key and the updated security data with the one-way hash function, and stores the updated signature to replace the signature in the smart card chip.
13 . A flash memory controller, for protecting security data stored in a flash memory chip, the flash memory controller comprising:
a microprocessor unit;
a flash memory interface unit, coupled to the microprocessor unit, and configured to couple to the flash memory chip;
a memory management unit, coupled to the microprocessor unit; and
a security data protection unit, coupled to the microprocessor unit and has a private key,
wherein the security data protection unit generates an eigenvalue corresponding to the security data and stores the eigenvalue in a smart card chip,
wherein the security data protection unit generates a signature corresponding to the security data and the eigenvalue according to the private key, the eigenvalue and the security data with a one-way hash function, and stores the signature in the flash memory chip.
14 . The flash memory controller according to claim 13 ,
wherein when the memory management unit reads the security data, the security data protection unit reads the signature from the flash memory chip, reads the eigenvalue from the smart card chip, generates a comparison signature corresponding the read security data and the read eigenvalue according to the private key, the read eigenvalue and the read security data with the one-way hash function, and determines whether the read signature is identical to the generated comparison signature,
wherein the security data protection unit outputs a warning message when the read signature is not identical to the generated comparison signature.
15 . The flash memory controller according to claim 14 , wherein the memory management unit stores updated security data to replace the security data in the flash memory chip,
wherein the security data protection unit generates an updated eigenvalue corresponding to the updated security data, and generates an updated signature corresponding to the updated security data and the updated eigenvalue according to the private key, the updated eigenvalue and the updated security data with the one-way hash function,
wherein the security data protection unit stores the updated signature to replace the signature in the flash memory chip,
wherein the security data protection unit stores the updated eigenvalue to replace the eigenvalue in the smart card chip.
16 . The flash memory controller according to claim 13 , wherein the security data protection unit generates the eigenvalue based on a physical address for storing the security data in the flash memory chip, a random number corresponding to the security data or a counter value corresponding to the security data.
17 . An anti-falsifying method, for protecting security data stored in a flash memory chip of a flash memory storage system, the anti-falsifying method comprising:
disposing a smart card chip in the flash memory storage system; and
generating a signature corresponding to the security data according to a private key and the security data with a one-way hash function, and storing the signature in the smart card chip.
18 . The anti-falsifying method according to claim 17 , further comprising:
when the security data is read from the flash memory chip, reading the signature from the smart card chip, generating a comparison signature corresponding the read security data according to the private key and the read security data with the one-way hash function, and determining whether the read signature is identical to the generated comparison signature; and
outputting a warning message when the read signature is not identical to the generated comparison signature.
19 . The anti-falsifying method according to claim 18 , further comprising:
storing updated security data to replace the security data in the flash memory chip;
generating an updated signature corresponding to the updated security data according to the private key and the updated security data with the one-way hash function; and
storing the updated signature to replace the signature in the smart card chip.
20 . An anti-falsifying method, for protecting security data stored in a flash memory chip of a flash memory storage system, the anti-falsifying method comprising:
disposing a smart card chip in the flash memory storage system;
generating an eigenvalue corresponding to the security data and storing the eigenvalue in the smart card chip; and
generating a signature corresponding to the security data and the eigenvalue according to a private key, the eigenvalue and the security data with a one-way hash function, and storing the signature in the flash memory chip.
21 . The anti-falsifying method according to claim 20 , further comprising:
when the security data is read from the flash memory chip, reading the signature from the flash memory chip, reading the eigenvalue from the smart card chip, generating a comparison signature corresponding the read security data and the read eigenvalue according to the private key, the read eigenvalue and the read security data with the one-way hash function, and determining whether the read signature is identical to the generated comparison signature; and
outputting a warning message when the read signature is not identical to the generated comparison signature.
22 . The anti-falsifying method according to claim 21 , further comprising:
storing updated security data to replace the security data in the flash memory chip;
generating an updated eigenvalue corresponding to the updated security data;
generating an updated signature corresponding to the updated security data and the updated eigenvalue according to the private key, the eigenvalue and the updated security data with the one-way hash function;
storing the updated signature to replace the signature in the flash memory chip; and
storing the updated eigenvalue to replace the eigenvalue in the smart card chip.
23 . The anti-falsifying method according to claim 20 , wherein the step of generating the eigenvalue corresponding to the security data comprises: generating the eigenvalue based on a physical address for storing the security data in the flash memory chip, a random number corresponding to the security data or a counter value corresponding to the security data.