IP Library Granted Patent US 8,677,092
Granted Patent B2
US 8,677,092 · App. 13/555,050 · Granted Mar 18, 2014

Secure memory devices and methods of managing secure memory devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,677,092
App. No.
13/555,050
Granted
Mar 18, 2014
Kind
B2
Abstract

A computing device and method for managing security of a memory or storage device without the need for administer privileges. To access the secure memory, a host provides a data block containing a control command and authentication data to the memory device. The memory device includes a controller for controlling access to a secure memory in the memory device. The memory device identifies the control command in the data block, authenticates the control command based on the authentication data, and executes the control command to allow the host device to access the secure memory.

Claims (36)

1. A memory device comprising:

a first memory;

a second memory; and

a controller coupled to the first memory and to the second memory, the controller configured to provide control instructions to a host device, receive at least one data block comprising a control command and authentication data from the host device, authenticate the at least one data block based on the authentication data, identify the control command, and set a mode of the memory device to control access to at least one of the first memory or the second memory by subsequent input-output commands from the host device based on the control command,

wherein the control instructions comprise an executable file and an initiation file,

wherein the executable file is executable by the host device to generate the at least one data block, and

wherein the initiation file identifies a first icon for display in association with the first memory when the memory device is in an unlocked mode, and further identifies a second icon for display in association with the second memory when the memory device is in a locked mode.

2. The memory device of claim 1 , wherein the first memory comprises a secure memory.

3. The memory device of claim 1 , wherein the second memory comprises a public memory.

4. The memory device of claim 1 , wherein the controller is further configured to initially prevent access to at least one of the first memory or the second memory, the controller further configured to execute the control command to allow access to at least one of the first memory or the second memory.

5. The memory device of claim 1 , wherein the authentication data includes a file signature.

6. The memory device of claim 1 , wherein the authentication data includes a password.

7. The memory device of claim 1 , wherein at least one of the first memory or the second memory is a flash memory.

8. The memory device of claim 1 , further comprising a third memory coupled to the controller, wherein the controller is further configured to control access to the third memory.

9. The memory device of claim 1 , further comprising a third memory coupled to the controller, the third memory comprising a first file allocation table for at least one of the first memory or the second memory, the controller further configured to control access to at least one of the first memory or the second memory by controlling access to the first file allocation table.

10. The memory device of claim 9 , wherein the controller is further configured to prevent access to at least one of the first memory or the second memory by preventing access to the first file allocation table.

11. A method of managing security of a memory device, comprising:

preventing a host device from accessing at least one of a first memory or a second memory of the memory device;

providing control instructions to the host device;

receiving at least one data block comprising a control command and authentication data from the host device,

wherein the control instructions comprise an executable file and an initiation file, wherein the executable file is executable by the host device to generate the at least one data block, and

wherein the initiation file identifies a first icon for display in association with the first memory when the memory device is in an unlocked mode, and further identifies a second icon for display in association with the second memory when the memory device is in a locked mode;

authenticating the at least one data block based on the authentication data;

identifying the control command in the at least one data block; and

executing the control command to set a mode of the memory device to allow the host device to access at least one of the first memory or the second memory using subsequent input-output commands.

12. The method of claim 11 , wherein the first memory comprises a secure memory.

13. The method of claim 11 , wherein the second memory comprises a public memory.

14. The memory device of claim 11 , wherein the authentication data includes a file signature.

15. The method of claim 11 , further comprising:

receiving an indicator in the memory device; and

preventing the host device from accessing at least one of the first memory or the second memory in response to receiving the indicator.

16. The method of claim 12 , wherein the indicator indicates that the memory device is disconnected from the host device.

17. The method of claim 11 , wherein the indicator indicates that power is cycled in the memory device.

18. The method of claim 11 , wherein authenticating the at least one data block based on the authentication data comprises authenticating a signature in the at least one data block.

19. The method of claim 11 , wherein at least one of the first memory or the second memory comprises flash memory.

20. The method of claim 11 , wherein the control command sets the mode of the memory device to the unlocked mode that allows access to at least one of the first memory or the second memory by the subsequent input-output commands.

Assignments (13)
SECURITY AGREEMENT (SUPPLEMENTAL) Recorded Nov 14, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069411/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2024
From: SANDISK TECHNOLOGIES, INC.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 069168/0273 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2018
From: HGST TECHNOLOGIES SANTA ANA, INC.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 046174/0446 →
MERGER AND CHANGE OF NAME Recorded Aug 23, 2016
From: SIMPLETECH, INC.; STEC, INC.
To: STEC, INC.
Reel/Frame 039512/0985 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2016
From: RAMEZANI, MEHRAN
To: SIMPLETECH, INC.
Reel/Frame 039490/0841 →
CHANGE OF NAME Recorded Jul 1, 2015
From: STEC, INC.
To: HGST TECHNOLOGIES SANTA ANA, INC.
Reel/Frame 036042/0390 →