IP Library Granted Patent US 9,304,941
Granted Patent B2
US 9,304,941 · App. 14/191,687 · Granted Apr 5, 2016

Self-encrypting flash drive

Inventors: Ashwin Kamath (Cedar Park, TX); Paul E. Prince (Lago Vista, TX); Trevor Smith (Austin, TX)
Assignee: Mangstor, Inc.
G06F12/1408H04L9/0637H04L9/0894H04L9/3242G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,304,941
App. No.
14/191,687
Granted
Apr 5, 2016
Kind
B2
Abstract

A method comprises receiving a plaintext message (m), encrypting the plaintext message and generating a cipher text (c) and authentication data (t), storing the cipher text in a user data portion of a data storage device, and storing the authentication data in a meta data portion of the data storage device.

Claims (55)

1. A method for storing user data in a flash storage device to enable detection of subsequent tampering, comprising:

receiving a plaintext comprising at least a portion of the user data;

receiving a user key;

reading stored first metadata associated with a sector of the flash storage device, wherein the first metadata comprises at least one attribute associated with a physical location;

generating an initialization vector based on the at least one attribute;

encrypting the plaintext based on the user key and the initialization vector to generate a cipher text and first authentication data;

storing the cipher text in the sector of the flash storage device; and

storing the first authentication data as second metadata associated with the sector of the flash storage device.

2. The method of claim 1 , further comprising:

receiving a logical address for storing the at least a portion of the user data;

mapping the logical address to the physical location.

3. The method of claim 1 , wherein the at least one attribute comprises at least one of an age attribute, utilization information, and erase count.

4. The method of claim 1 , wherein:

the first metadata relates to flash storage device maintenance functions; and

the first authentication data is usable to detect tampering of the cipher text and the first metadata.

5. The method of claim 1 , wherein the at least one attribute comprises sector maintenance metadata pertaining to the sector.

6. A method for detecting occurrence of tampering with data stored in a flash storage device, comprising:

determining a physical location in a sector of the flash storage device corresponding to encrypted user data to be read;

reading cipher text from the physical location, where the cipher text comprises the encrypted user data;

reading metadata associated with the sector of the flash storage device, the metadata comprising first authentication data and at least one attribute associated with the physical location; and

generating an initialization vector based on the at least one attribute;

decrypting the cipher text based on a user key and the initialization vector to generate a plaintext and second authentication data;

determining the occurrence of tampering based on the first authentication data and the second authentication data.

7. The method of claim 6 , wherein determining a physical location comprises receiving a logical address corresponding to the encrypted user data to be read; and mapping the logical address to the physical location.

8. The method of claim 6 , wherein the initialization vector is generated based on the physical location and the at least one attribute.

9. The method of claim 6 , wherein the at least one attribute comprises at least one of an age attribute, utilization information, and erase count.

10. The method of claim 6 , wherein the at least one attribute comprises sector maintenance metadata pertaining to the sector.

11. A flash storage device comprising:

a memory configured in a plurality of sectors, each sector comprising storage for user data and for first and second metadata associated with the particular sector;

an encryption machine configured to:

receive first plaintext, a user key, and an initialization vector; and

encrypt the plaintext based on the user key and the initialization vector to generate a cipher text and an authentication tag; and

a memory controller configured to:

generate the initialization vector based on at least one attribute associated with a sector of the flash storage device;

store the cipher text as user data in the sector of the flash storage device; and

store the authentication tag as second metadata associated with the sector of the flash storage device.

12. The flash storage device of claim 11 , wherein the memory controller is further configured to:

receive a logical address corresponding to user data to be stored; and

map the logical address to a physical location associated with the sector of the flash storage device.

13. The flash storage device of claim 11 , wherein the at least one attribute comprises at least one of an age attribute, utilization information, and erase count.

14. The flash storage device of claim 11 , wherein the at least one attribute comprises sector maintenance metadata pertaining to the sector.

15. A flash storage device comprising:

a memory configured in a plurality of sectors, each sector comprising storage for user data and for first and second metadata associated with the particular sector;

a memory controller configured to:

read cipher text from a physical location in a sector of the flash storage device, wherein the cipher text comprises encrypted user data;

read metadata associated with the sector of the flash storage device, the metadata comprising first authentication data and at least one attribute associated with the physical location;

generate an initialization vector based on the at least one attribute; and

a decryption machine configured to:

receive the cipher text, a user key, and the initialization vector;

decrypt the cipher text based on the user key and the initialization vector to generate a plaintext and second authentication data; and

determine the occurrence of tampering based on the first authentication data and the second authentication data.

16. The flash storage device of claim 15 , wherein the memory controller is further configured to determine the physical location by:

receiving a logical address corresponding to encrypted user data to be read; and mapping the logical address to the physical location associated with the sector of the flash storage device.

17. The flash storage device of claim 16 , wherein the at least one attribute comprises at least one of an age attribute, utilization information, and erase count.

18. The flash storage device of claim 16 , wherein the at least one attribute comprises sector maintenance metadata pertaining to the sector.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2020
From: EXTEN TECHNOLOGIES, INC.
To: OVH US LLC
Reel/Frame 054013/0948 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISTAKEN INCLUSION OF PATENT NUMBER 9141527 PREVIOUSLY RECORDED ON REEL 053438 FRAME 0968. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 12, 2020
From: WESTERN ALLIANCE BANK
To: EXTEN TECHNOLOGIES, INC.
Reel/Frame 053480/0993 →
RELEASE OF SECURITY INTEREST Recorded Aug 8, 2020
From: WESTERN ALLIANCE BANK
To: EXTEN TECHNOLOGIES, INC.
Reel/Frame 053438/0968 →
CHANGE OF NAME Recorded Jul 25, 2018
From: MANGSTOR, INC.
To: EXTEN TECHNOLOGIES, INC.
Reel/Frame 046628/0576 →
SECURITY INTEREST Recorded Jun 30, 2016
From: MANGSTOR, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 039059/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2014
From: KAMATH, ASHWIN; PRINCE, PAUL E.; SMITH, TREVOR
To: MANGSTOR, INC.
Reel/Frame 034364/0077 →
Continuity (1)
Related Publication 20150242332A1 · Aug 27, 2015