IP Library Granted Patent US 8,996,851
Granted Patent B2
US 8,996,851 · App. 12/853,924 · Granted Mar 31, 2015

Host device and method for securely booting the host device with operating system code loaded from a storage device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,996,851
App. No.
12/853,924
Granted
Mar 31, 2015
Kind
B2
Abstract

A host device and method for securely booting the host device with operating system code loaded from a storage device are provided. In one embodiment, a host device is in communication with a storage device having a private memory area storing boot loader code and a public memory area storing operating system code. The host device instructs the storage device to initiate a boot mode and receives the boot loader code from the storage device. The host device executes the boot loader code which performs a security check and executes the operating system code loaded from the storage device only if the security check is successful.

Claims (37)

1. A method for securely booting a host device with operating system code loaded from a storage device, the method comprising:

performing in a host device in communication with a storage device having a private memory area storing boot loader code and a public memory area storing operating system code:

instructing the storage device to initiate a boot mode;

receiving the boot loader code from the storage device; and

executing the boot loader code, wherein, when executed, the boot loader code:

performs a security check, and

executes the operating system code loaded from the storage device only if the security check is successful.

2. The method of claim 1 , wherein the host device instructs the storage device to initiate the boot mode other than by sending a command to read from an address in the storage device.

3. The method of claim 1 , wherein the host device and the storage device communicate over an interface that comprises a command (CMD) line, and wherein the host device instructs the storage device to initiate the boot mode by holding the CMD line low for 74 clock cycles.

4. The method of claim 1 , wherein the host device and the storage device communicate over an interface that comprises a command (CMD) line, and wherein the host device instructs the storage device to initiate the boot mode by sending, on the CMD line, a CMD 0 command with argument 0xFFFFFFFA.

5. The method of claim 1 , wherein the security check is performed by attempting to verify the integrity of the operating system code.

6. The method of claim 1 , wherein the security check is performed by attempting to authenticate a user of the host device.

7. The method of claim 6 , wherein attempting to authenticate the user of the host device comprising requesting a user password.

8. The method of claim 1 , wherein the security check is performed by attempting to authenticate the host device.

9. The method of claim 7 , wherein attempting to authenticate the host device comprises authenticating a hardware parameter of the host device.

10. The method of claim 1 , wherein the host device is further in communication with a Subscriber Identity Module (SIM) card, and wherein the security check is performed by attempting to authenticate the SIM card.

11. The method of claim 1 , wherein the storage device comprises a storage device embedded in the host device.

12. The method of claim 1 , wherein the storage device comprises a storage device removably connectable to the host device.

13. The method of claim 1 , wherein the security check is performed by the boot loader code received from the storage device and not by code provisioned in the host device's controller during manufacturing of the host device.

14. A host device comprising:

an interface configured to communicate with a storage device having a private memory area storing boot loader code and a public memory area storing operating system code; and

a controller in communication with the interface, wherein the controller is configured to:

instruct the storage device to initiate a boot mode;

receive the boot loader code from the storage device; and

execute the boot loader code, wherein, when executed, the boot loader code:

performs a security check, and

executes the operating system code loaded from the storage device only if the security check is successful.

15. The host device of claim 14 , wherein the controller is configured to instruct the storage device to initiate the boot mode other than by sending a command to read from an address in the storage device.

16. The host device of claim 14 , wherein the interface comprises a command (CMD) line, and wherein the controller is configured to instruct the storage device to initiate the boot mode by holding the CMD line low for 74 clock cycles.

17. The host device of claim 14 , wherein the interface comprises a command (CMD) line, and wherein the controller is configured to instruct the storage device to initiate the boot mode by sending, on the CMD line, a CMD 0 command with argument 0xFFFFFFFA.

18. The host device of claim 14 , wherein the security check is performed by attempting to verify the integrity of the operating system code.

19. The host device of claim 14 , wherein the security check is performed by attempting to authenticate a user of the host device.

20. The host device of claim 14 , wherein the security check is performed by attempting to authenticate the host device.

21. The host device of claim 14 further comprising a Subscriber Identity Module (SIM) card in communication with the controller, and wherein the security check is performed by attempting to authenticate the SIM card.

22. The host device of claim 14 , wherein the storage device comprises a storage device embedded in the host device.

23. The host device of claim 14 , wherein the storage device comprises a storage device removably connectable to the host device.

24. The host device of claim 14 , wherein the security check is performed by the boot loader code received from the storage device and not by code provisioned in the host device's controller during manufacturing of the host device.

Assignments (11)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
SECURITY AGREEMENT (SUPPLEMENTAL) Recorded Nov 14, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069411/0486 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 069169/0572 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2024
From: WESTERN DIGITAL ISRAEL, LTD.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 066674/0153 →
PATENT COLLATERAL AGREEMENT (DDTL) Recorded Feb 22, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 066648/0206 →
PATENT COLLATERAL AGREEMENT (AR) Recorded Feb 22, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 066648/0284 →
THIS IS A MUTUAL RESCISSION AGREMENT OF A PREVIOUSLY RECORDED ASSIGNMENT AT REEL/FRAME: 066114/0481 Recorded Feb 6, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: WESTERN DIGITAL ISRAEL LTD.
Reel/Frame 066507/0538 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: WESTERN DIGITAL ISRAEL LTD.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 066114/0481 →
CHANGE OF NAME Recorded Aug 21, 2020
From: SANDISK IL LTD
To: WESTERN DIGITAL ISRAEL LTD
Reel/Frame 053574/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2010
From: DOLGUNOV, BORIS; ELHAMIAS, REUVEN; COHEN, EHUD
To: SANDISK IL LTD.
Reel/Frame 025364/0398 →