IP Library Granted Patent US 11,657,163
Granted Patent B2
US 11,657,163 · App. 16/282,491 · Granted May 23, 2023

Memory system and method of controlling nonvolatile memory

Inventor: Shinichi Kanno (Ota, JP)
Assignee: Kioxia Corporation
G06F21/602G06F3/0604G06F3/0658G06F3/0679G06F21/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,657,163
App. No.
16/282,491
Granted
May 23, 2023
Kind
B2
Abstract

According to one embodiment, a memory system includes a nonvolatile memory and a controller. In response to receiving from a host a write request designating a first address for identifying data to be written, the controller encrypts the data with the first address and a first encryption key, and writes the encrypted data to the nonvolatile memory together with the first address. In response to receiving from the host a read request designating a physical address indicative of a physical storage location of the nonvolatile memory, the controller reads both the encrypted data and the first address from the nonvolatile memory on the basis of the physical address, and decrypts the read encrypted data with the first encryption key and the read first address.

Claims (41)

1. A memory system connectable to a host, comprising:

a nonvolatile memory including a plurality of blocks; and

a controller electrically connected to the nonvolatile memory and configured to:

in response to receiving from the host a write request that designates at least a first logical address for identifying data to be written, encrypt the data with the first logical address and a first encryption key, write the encrypted data to a first location in a first block of the nonvolatile memory, and write the first logical address to a second location in the first block, the second location being different from the first location; and

in response to receiving from the host a read request that designates at least an identifier of the first block, read both the encrypted data and the first logical address from the first location and the second location in the first block, respectively, and decrypt the read encrypted data with the first encryption key and the read first logical address, wherein

the write request further designates the identifier of the first block, and

the controller is further configured to:

manage correspondence between a plurality of encryption keys and a plurality of regions obtained by logically dividing the nonvolatile memory;

when receiving the write request, select an encryption key associated with a region to which the first block belongs, as the first encryption key, on the basis of the identifier of the first block designated by the write request; and

when receiving the read request, select an encryption key associated with the region to which the first block belongs, as the first encryption key on the basis of the identifier of the first block designated by the read request.

2. The memory system of Cairn wherein

the controller is configured to write the first logical address in plain text to the second location in the first block.

3. The memory system of Cairn 1 , wherein

the controller is configured to encrypt the first logical address with a specific encryption key which is different from the first encryption key and which is used commonly for encryption and decryption of all logical addresses for identifying data to be written, and write the encrypted first logical address to the second location in the first block.

4. The memory system of claim 1 , wherein

the controller is further configured to:

manage a table for managing correspondence between the plurality of blocks and the plurality of encryption keys; and

when copying the encrypted data from the first block to a copy destination block in the nonvolatile memory, copy both the encrypted data and the first logical address from the first block to the copy destination block, without decrypting or re-encrypting the encrypted data; and

update the table to associate an encryption key associated with the first block, with the copy destination block.

5. The memory system of claim 1 , wherein

the controller is further configured to:

manage a table for managing correspondence between a plurality of encryption keys and theme plurality of regions obtained by logically dividing the nonvolatile memory; and

when copying the encrypted data to a copy destination block in the nonvolatile memory belonging to a same region as a region to which the first block belongs, copy both the encrypted data and the first logical address from the first block to the copy destination block, without decrypting or re-encrypting the encrypted data.

6. A memory system connectable to a host, comprising:

a nonvolatile memory including a plurality of blocks; and

a controller electrically connected to the nonvolatile memory and configured to:

in response to receiving from the host a write request that designates at least a first logical address for identifying data to be written and an identifier of a first block of the nonvolatile memory, encrypt the data with the first logical address and a first encryption key, write the encrypted data to a first location in the first block, and write the first logical address to a second location in the first block, the second location being different from the first location; and

in response to receiving from the host a read request that designates at least an identifier of the first block and an in-block physical address indicative of the first location in the first block, read both the encrypted data and the first logical address from the first location and the second location in the first block, respectively, on the basis of the identifier of the first block and the in-block physical address, and decrypt the read encrypted data with the first encryption key and the read first logical address, wherein

the write request further designates the identifier of the first block, and

the controller is further configured to:

manage correspondence between a plurality of encryption keys and a plurality of regions obtained by logically dividing the nonvolatile memory;

when receiving the write request, select an encryption key associated with a region to which the first block belongs, as the first encryption key, on the basis of the identifier of the first block designated by the write request; and

when receiving the read request, select an encryption key associated with the region to which the first block belongs, as the first encryption key, on the basis of the identifier of the first block designated by the read request.

7. A method of controlling a nonvolatile memory including a plurality of blocks, the method comprising:

in response to receiving from a host a write request that designates at least a first logical address for identifying data to be written, encrypting the data with the first logical address and a first encryption key, writing the encrypted data to a first location in a first block of the nonvolatile memory, and writing the first logical address to a second location in the first block, the second location being different from the first location: and

in response to receiving from the host a read request that designates at least an identifier of the first block, reading both the encrypted data and the first logical address from the first location and the second location in the first block, respectively, and decrypting the read encrypted data with the first encryption key and the read first logical address, wherein

the write request further designates the identifier of the first block and

the method further comprises:

managing correspondence between a plurality of encryption keys and a plurality of regions obtained by logically dividing the nonvolatile memory;

when receiving the write request, selecting an encryption key associated with a region to which the first block belongs, as the first encryption key, on the basic of the identifier of the first block designated by the write request; and

when receiving the read request, selecting an encryption key associated with the region to which the first block belongs, as the first encryption key, on the basis of the identifier of the first block designated by the read request.

Assignments (2)
CHANGE OF NAME Recorded Jan 11, 2022
From: TOSHIBA MEMORY CORPORATION
To: KIOXIA CORPORATION
Reel/Frame 058725/0932 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2019
From: KANNO, SHINICHI
To: TOSHIBA MEMORY CORPORATION
Reel/Frame 048405/0045 →
Priority Claims (1)
JP JP2018-097908 · May 22, 2018 · national
Continuity (1)
Related Publication 20190362081A1 · Nov 28, 2019