IP Library Granted Patent US 11,580,034
Granted Patent B2
US 11,580,034 · App. 15/814,679 · Granted Feb 14, 2023

Namespace encryption in non-volatile memory devices

Inventor: Alex Frolikov (San Jose, CA)
Assignee: Micron Technology, Inc.
G06F12/1408H04L9/0816H04L9/0866H04L9/0894H04L9/14G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,580,034
App. No.
15/814,679
Granted
Feb 14, 2023
Kind
B2
Abstract

A computer storage device having a host interface, a controller, non-volatile storage media, and firmware. The firmware instructs the controller to: limit a crypto key to be used in data access requests made in a first namespace allocated on the non-volatile storage media of the computer storage device; store data in the first namespace in an encrypted form that is to be decrypted using the crypto key; free a portion of the non-volatile storage media from the first namespace, the portion storing the data; and make the portion of the non-volatile storage media available in a second namespace without erasing the data stored in the portion of the non-volatile storage media.

Claims (46)

1. A computer storage device, comprising:

a host interface;

a controller;

non-volatile storage media;

a plurality of registers each storing a crypto key and configured to be limited with data access in only one namespace;

firmware containing instructions which, when executed by the controller, instruct the controller to at least:

limit a crypto key to be used in data access requests made in a first namespace allocated on the non-volatile storage media of the computer storage device;

store data in the first namespace in an encrypted form corresponding to the crypto key;

free a portion of the non-volatile storage media from the first namespace, the portion storing the data;

make the portion of the non-volatile storage media available in a second namespace without erasing the data stored in the portion of the non-volatile storage media; and

store a namespace map mapping blocks of logical addresses defined in the first namespace to blocks of logical addresses defined, independent of namespace, on a capacity of the non-volatile storage media;

wherein the crypto key is limited to be used with the namespace map in accessing the non-volatile storage media; and

wherein a crypto engine coupled to the registers to perform decryption using the crypto key for data access made in the first namespace, wherein the crypto key is generated by the crypto engine in response to a command to allocate the first namespace on the non-volatile storage media.

2. The computer storage device of claim 1 , wherein the crypto key is deleted from the computer storage device to perform a cryptographic erasure of data stored in the first namespace in response to a command to delete the namespace.

3. The computer storage device of claim 1 , wherein the crypto key is received for the first namespace in connection with a command to allocate the first namespace on the non-volatile storage media.

4. The computer storage device of claim 1 , wherein the crypto engine implements symmetric encryption using the crypto key.

5. The computer storage device of claim 1 , wherein the crypto key is a public key for non-symmetric encryption and is received from a host for encryption of data stored in the first namespace.

6. The computer storage device of claim 1 , wherein the crypto key is a first key of a key pair for non-symmetric encryption of data stored in the first namespace; and a second key of the key pair is provided for decryption of data retrieved from the first namespace.

7. The computer storage device of claim 1 , wherein the crypto engine generates the key pair in response to creation of the first namespace on the non- volatile storage media.

8. The computer storage device of claim 1 , wherein the portion of the non- volatile storage media storing the data is freed from the first namespace in response to a command to reduce a size of the first namespace.

9. The computer storage device of claim 1 , wherein the portion of the non- volatile storage media storing the data is freed in response to an adjustment in the namespace map.

10. The computer storage device of claim 9 , wherein before the adjustment:

the portion of the non-volatile storage media is identified by a first subset of the logical addresses defined, independent of namespace, on the capacity of the non-volatile storage media; and

the namespace map maps a subset of the logical addresses defined in the first namespace to the first subset of the logical addresses defined on the capacity of the non-volatile storage media.

11. The computer storage device of claim 10 , wherein after the adjustment, the subset of the logical addresses previously defined in the first namespace is no longer defined in the first namespace.

12. The computer storage device of claim 10 , wherein after the adjustment, the namespace map maps the subset of the logical addresses defined in the first namespace to a second subset of the logical addresses defined, independent of namespace, on the capacity of the non-volatile storage media.

13. The computer storage device of claim 12 , wherein a portion of the non-volatile storage media identified by the second subset of the logical addresses defined on the capacity of the non-volatile storage media is different from the portion of the non-volatile storage media identified by the first subset of the logical addresses defined on the capacity of the non-volatile storage media.

14. A method implemented in a computer storage device, the method comprising:

storing a namespace map mapping blocks of logical addresses defined in the first namespace to blocks of logical addresses defined, independent of namespace, on a capacity of the non-volatile storage media;

generating a crypto key, via a crypto engine, in response to a command to allocate a first namespace on a non-volatile storage media of the computer storage device;

limiting the crypto key to be used in data access requests made in the first namespace allocated on the non-volatile storage media;

storing data in the first namespace in an encrypted form corresponding to the crypto key;

performing decryption, via the crypto engine, using the crypto key for data access made in the first name space;

freeing a portion of the non-volatile storage media from the first namespace, the portion storing the data; and

making the portion of the non-volatile storage media available in a second namespace without erasing the data stored in the portion of the non-volatile storage media

wherein the crypto key is limited to be used with the namespace map in accessing the non-volatile storage media.

15. The method of claim 14 , wherein the freeing is in response to a command to reduce a size of the first namespace.

16. A non-transitory computer storage medium storing instructions which, when executed by a controller of a computer storage device, cause the controller to perform a method, the method comprising:

storing a namespace map mapping blocks of logical addresses defined in the first namespace to blocks of logical addresses defined, independent of namespace, on a capacity of the non-volatile storage media;

generating a crypto key, via a crypto engine, in response to a command to allocate a first namespace on a non-volatile storage media of the computer storage device;

limiting the crypto key to be used in data access requests made in the first namespace allocated on the non-volatile storage media;

storing data in the first namespace in an encrypted form corresponding to the crypto key;

performing decryption, via the crypto engine, using the crypto key for data access made in the first namespace;

freeing a portion of the non-volatile storage media from the first namespace, the portion storing the data; and

making the portion of the non-volatile storage media available in a second namespace without erasing the data stored in the portion of the non-volatile storage media;

wherein the crypto key is limited to be used with the namespace map in accessing the non-volatile storage media.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Nov 12, 2019
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.; MICRON SEMICONDUCTOR PRODUCTS, INC.
Reel/Frame 051028/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 050716/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: FROLIKOV, ALEX
To: MICRON TECHNOLOGY, INC.
Reel/Frame 046979/0929 →
SECURITY INTEREST Recorded Jul 13, 2018
From: MICRON TECHNOLOGY, INC.; MICRON SEMICONDUCTOR PRODUCTS, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 047540/0001 →
SUPPLEMENT NO. 7 TO PATENT SECURITY AGREEMENT Recorded Feb 6, 2018
From: MICRON TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 045267/0833 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2017
From: FROLIKOV, ALEX
To: MICRON TECHNOLOGY, INC.
Reel/Frame 044239/0998 →