IP Library Patent Application 15195371
Patent Application
App. No. 15/195,371

PROTECTING DATA IN A STORAGE DEVICE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/195,371
Abstract

A first data encryption key is stored on a storage device. The first data encryption key, a first key encryption key obtained from first information received from a host system, and second information that is received from a source other than the host system are used to generate a second data encryption key that can be used to encrypt and decrypt data stored on the storage device. The second information may be sent from the source to the storage device only if a condition is satisfied.

Claims (56)

1 . In a storage device, a method of protecting data stored on the storage device, the method comprising:

accessing a first data encryption key stored in storage media on the storage device; and

generating a second data encryption key that is used to encrypt and decrypt data stored in the storage media on the storage device using: the first data encryption key, a first key encryption key obtained from first information received from a host system that is communicatively coupled to the storage device, and second information that is received from a source other than the host system and that is communicatively coupled to the storage device.

2 . The method of claim 1 , wherein the second information is sent from the source to the storage device in response to a condition being satisfied.

3 . The method of claim 2 , wherein the condition is checked periodically and wherein the method further comprises discarding the second data encryption key unless the condition is satisfied.

4 . The method of claim 2 , wherein the condition is selected from the group consisting of: indication that a specified physical object is attached to the storage device; indication that a specified physical object is within a prescribed distance of the storage device; indication that the storage device is at a specified physical location; indication that the storage device is within a prescribed distance of a specified physical location; and indication that the storage device's operating environment matches an environmental condition within a specified tolerance.

5 . The method of claim 1 , wherein the second information comprises a second key encryption key and wherein said generating comprises:

unwrapping a wrapped version of the first data encryption key with the first key encryption key to generate an intermediary data encryption key comprising a wrapped version of the second data encryption key; and

unwrapping the intermediary data encryption key using the second key encryption key to generate the second data encryption key.

6 . The method of claim 5 , further comprising:

generating the second data encryption key with a key generator executed by the storage device, wherein the second data encryption key is used to encrypt data written to storage media on the storage device;

wrapping the second data encryption key with the second key encryption key and with the first key encryption key to generate the wrapped version of the first data encryption key; and

storing the wrapped version of the first data encryption key in the storage media on the storage device.

7 . The method of claim 1 , wherein said generating comprises:

unwrapping a wrapped version of the first data encryption key with the first key encryption key to generate an intermediary data encryption key comprising a first share of the second data encryption key, wherein the second information comprises a second share of the second data encryption key; and

combining the first share and the second share to generate the second data encryption key.

8 . The method of claim 7 , further comprising:

generating the second data encryption key with a key generator executed by the storage device, wherein the second data encryption key is used to encrypt data written to storage media on the storage device;

dividing the second data encryption key into the first share and the second share;

storing the second share on the source;

wrapping the first share with the first key encryption key to generate the wrapped version of the first data encryption key; and

storing the wrapped version of the first data encryption key in the storage media on the storage device.

9 . The method of claim 1 , wherein the second information comprises a third data encryption key and wherein said generating comprises:

unwrapping a wrapped version of the first data encryption key with the first key encryption key to generate an intermediary data encryption key; and

combining the intermediary data encryption key and the third data encryption key to generate the second data encryption key.

10 . The method of claim 9 , further comprising:

generating the intermediary data encryption key with a key generator executed by the storage device;

wrapping the intermediary data encryption key with the first key encryption key to generate the wrapped version of the first data encryption key; and

storing the wrapped version of the first data encryption key in the storage media on the storage device.

11 . A system, comprising:

a host comprising:

a processor; and

memory coupled to the processor; and

a storage device coupled to the host;

the storage device configured to access a first data encryption key stored in the storage media and to generate an intermediary data encryption key using the first data encryption key and a first key encryption key that is obtained from first information received from the host; and

the storage device further configured to generate a second data encryption key using the intermediary data encryption key and second information that is received from a source that is communicatively coupled to the storage device and that that bypasses the host when communicating with the storage device, wherein the second data encryption key is used to decrypt data stored in the storage media on the storage device.

12 . The system of claim 11 , wherein the second information is sent from the source to the storage device in response to a condition being satisfied, wherein the condition is selected from the group consisting of: indication that a specified physical object is attached to the storage device; indication that a specified physical object is within a prescribed distance of the storage device; indication that the storage device is at a specified physical location; indication that the storage device is within a prescribed distance of a specified physical location; and indication that the storage device's operating environment matches an environmental condition within a specified tolerance.

13 . The system of claim 11 , wherein the second information comprises a second key encryption key and the intermediary data encryption key comprises a wrapped version of the second data encryption key, wherein the storage device is configured to unwrap the intermediary data encryption key using the second key encryption key to generate the second data encryption key;

wherein the storage device is further configured to generate the second data encryption key, to wrap the second data encryption key with the second key encryption key to generate the intermediary data encryption key, and to wrap the intermediary data encryption key with the first key encryption key to generate a wrapped version of the first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

14 . The system of claim 11 , wherein the intermediary data encryption key comprises a first share of the second data encryption key and the second information comprises a second share of the second data encryption key, wherein the storage device is further configured to combine the first share and the second share to generate the second data encryption key;

wherein the storage device is further configured to generate the second data encryption key, to divide the second data encryption key into the first share and the second share, and to wrap the first share with the first key encryption key to generate a wrapped version of the first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

15 . The system of claim 11 , wherein the second information comprises a third data encryption key, wherein the storage device is further configured to combine the intermediary data encryption key and the third data encryption key to generate the second data encryption key;

wherein the storage device is further configured to generate the second data encryption key and to wrap the second data encryption key with the first key encryption key to generate a wrapped version of the first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

16 . A storage device, comprising:

a first module;

a second module coupled to the first module; and

storage media coupled to the first module;

the first module operable for accessing a first data encryption key stored in the storage media and for generating an intermediary data encryption key using the first data encryption key and a first key encryption key that is obtained from first information received from a host system that is communicatively coupled to the storage device; and

the second module operable for generating a second data encryption key using the intermediary data encryption key and second information that is received from a source that is communicatively coupled to the storage device and that bypasses the host system when communicating with the storage device, wherein the second data encryption key is used to decrypt data stored in the storage media on the storage device.

17 . The storage device of claim 16 , wherein the second information is sent from the source to the storage device in response to a condition being satisfied, and wherein the condition is selected from the group consisting of: indication that a specified physical object is attached to the storage device; indication that a specified physical object is within a prescribed distance of the storage device; indication that the storage device is at a specified physical location; indication that the storage device is within a prescribed distance of a specified physical location; and indication that the storage device's operating environment matches an environmental condition within a specified tolerance.

18 . The storage device of claim 16 , wherein the second information comprises a second key encryption key and wherein the intermediary data encryption key comprises a wrapped version of the second data encryption key, wherein the second module is operable for unwrapping the intermediary data encryption key using the second key encryption key to recover the second data encryption key;

wherein the storage device further comprises a third module coupled to the second module and operable for generating the second data encryption key, wherein the second module is further operable for wrapping the second data encryption key with the second key encryption key to generate the intermediary data encryption key and wherein the first module is further operable for wrapping the intermediary data encryption key with the first key encryption key to generate a wrapped version of the first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

19 . The storage device of claim 16 , wherein the second information comprises a first share of the second data encryption key and wherein the intermediary data encryption key comprises a second share of the second data encryption key, wherein the second module is further operable for combining the first share and the second share to recover the second data encryption key;

wherein the storage device further comprises a third module coupled to the second module and operable for generating the second data encryption key, wherein the second module is further operable for dividing the second data encryption key into the first share and the second share, and wherein the first module is further operable for wrapping the second share with the first key encryption key to generate a wrapped version of wrapped first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

20 . The storage device of claim 16 , wherein the second information comprises a third data encryption key, wherein the second module is further operable for combining the intermediary data encryption key and the third data encryption key to generate the second data encryption key;

wherein the storage device further comprises a third module coupled to the second module and operable for generating the second data encryption key, wherein the first module is further operable for wrapping the intermediary data encryption key with the first key encryption key to generate a wrapped version of the first data encryption key, wherein the wrapped version of the first data encryption key is unwrapped with the first key encryption key to generate the intermediary data encryption key.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT SERIAL NO 15/025,946 PREVIOUSLY RECORDED AT REEL: 040831 FRAME: 0265. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 15, 2017
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 043973/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 040831/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2016
From: HOWE, COLLIN; MCCAMBRIDGE, COLIN; GEML, ADAM
To: HGST NETHERLANDS B.V.
Reel/Frame 039031/0738 →