IP Library Granted Patent US 11,556,665
Granted Patent B2
US 11,556,665 · App. 16/706,780 · Granted Jan 17, 2023

Unlocking a data storage device

Inventors: Brian Edward Mastenbrook (Fremont, CA); David Robert Arnold (Toronto, CA)
Assignee: Western Digital Technologies, Inc.
G06F21/6218G06F13/1668G06F16/22G06F21/44G06F21/72H04L9/3226H04L9/3263H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,556,665
App. No.
16/706,780
Granted
Jan 17, 2023
Kind
B2
Abstract

Disclosed herein is a data storage device comprising a data path and an access controller. The data path comprises a data port configured to transmit data between a host computer and the data storage device. The data storage device is configured to register with the host computer as a block data storage device. A non-volatile storage medium stores encrypted user content data and a cryptography engine is connected between the data port and the storage medium and uses a cryptographic key to decrypt the encrypted user content data. The access controller generates a challenge for an authorized device; sends the challenge to the authorized device; receives a response to the challenge from the authorized device over the communication channel; calculates the cryptographic key based on the response; and provides the cryptographic key to the cryptography engine to decrypt the encrypted user content data stored on the storage medium.

Claims (66)

1. A data storage device comprising:

a data path comprising:

a data port configured to transmit data between a host computer system and the data storage device, wherein the data storage device is configured to register with the host computer system as a block data storage device;

a non-volatile storage medium configured to store encrypted user content data; and

a cryptography engine connected between the data port and the non-volatile storage medium, wherein the cryptography engine is configured to use a cryptographic key to decrypt the encrypted user content data stored on the non-volatile storage medium in response to a request from the host computer system; and

an access controller configured to:

store, in an authorization data record for an authorized device, an encrypted user key, wherein:

the authorized device is a first device; and

the host computer system is a second device;

generate a challenge for the authorized device;

send the challenge to the authorized device over a communication channel that is different from the data path;

receive a response to the challenge from the authorized device over the communication channel;

decrypt, using the response, the encrypted user key;

determine, based at least partly on the decrypted user key, the cryptographic key; and

provide the cryptographic key to the cryptography engine to decrypt the encrypted user content data stored on the non-volatile storage medium of the data storage device for access by the host computer system.

2. The data storage device of claim 1 , wherein the challenge is based on elliptic curve cryptography.

3. The data storage device of claim 1 , wherein the challenge is based on a public key of the data storage device.

4. The data storage device of claim 3 , wherein the public key of the data storage device is associated with a private key that is discarded after generating the public key.

5. The data storage device of claim 3 , wherein:

the access controller is further configured to generate a blinding value for each challenge; and

the challenge is based on the public key of the data storage device multiplied by the blinding value.

6. The data storage device of claim 5 , wherein the access controller is further configured to:

calculate an inverse of the blinding value;

multiply the response with the inverse of the blinding value to determine an unlock secret; and

use the unlock secret to decrypt the encrypted user key.

7. The data storage device of claim 1 , wherein the response is based on a private key stored in a secure hardware module in the authorized device.

8. The data storage device of claim 1 , wherein the access controller is further configured to:

receive a certificate from the authorized device, the certificate comprising certificate data;

query a data store for the authorization data record for the authorized device using the certificate data; and

generate the challenge based on the authorization data record.

9. The data storage device of claim 1 , further comprising a data store configured to store authorization data record entries associated with respective authorized devices, each authorization data record entry comprising metadata associated with one of the respective authorized devices.

10. The data storage device of claim 9 , wherein the metadata is stored in the data store in encrypted form using a cryptographic key contained in a certificate issued by the data storage device and received from the authorized device.

11. The data storage device of claim 10 , wherein the metadata comprises an identifier of one of the respective authorized devices.

12. The data storage device of claim 9 , wherein each authorization data record entry comprises the encrypted user key decryptable based on the response.

13. The data storage device of claim 12 , wherein the encrypted user key decryptable based on the response is identical for multiple authorized devices.

14. The data storage device of claim 12 , wherein the encrypted user key decryptable based on the response enables decryption of the encrypted user content data.

15. The data storage device of claim 14 , wherein decryption of the encrypted user content data comprises decryption of one or more further keys in a chain of keys to a user content encryption key configured to decrypt the encrypted user content data.

16. The data storage device of claim 9 , wherein the authorization data record entries stored in the data store are indexed based on an identifier of the authorized device.

17. The data storage device of claim 1 , wherein the response is based on a pass phrase received by the authorized device.

18. The data storage device of claim 17 , wherein a private key that is used to calculate the response is derived from the pass phrase.

19. The data storage device of claim 1 , wherein the data storage device is further configured to:

responsive to being in a locked state, register with the host computer system as a mass data storage device without a storage medium present; and

responsive to being in an unlocked state, register with the host computer system as a mass data storage device with a storage medium present.

20. A method for accessing data on a data storage device, the method comprising:

storing, by the data storage device and in an authorization data record for an authorized device, an encrypted user key;

generating, by the data storage device, a challenge for the authorized device;

sending, by the data storage device, the challenge to the authorized device over a communication channel that is different from a data path that connects a storage medium of the data storage device to a host computer system through a cryptography engine, wherein:

the authorized device is a first device; and

the host computer system is a second device;

receiving, by the data storage device, a response to the challenge from the authorized device over the communication channel;

decrypting, by the data storage device and using the response, the encrypted user key;

determining, by the data storage device and based at least partly on the decrypted user key, a cryptographic key; and

providing, by the data storage device, the cryptographic key to the cryptography engine to decrypt encrypted user content data stored on the storage medium of the data storage device for access by the host computer system.

21. A data storage device comprising:

a data port configured to transmit data between a host computer system and the data storage device;

a non-volatile storage medium configured to store encrypted user content data;

a cryptography engine connected between the data port and the non-volatile storage medium;

means for storing an encrypted user key;

means for generating a challenge for an authorized device, wherein:

the authorized device is a first device; and

the host computer system is a second device;

means for sending the challenge to the authorized device over a communication channel that is different from a data path that connects the non-volatle storage medium of the data storage device to the host computer system through the cryptography engine;

means for receiving a response to the challenge from the authorized device over the communication channel;

means for decrypting, using the response, the encrypted user key;

means for determining, based at least partly on the decrypted user key, a cryptographic key; and

means for providing the cryptographic key to the cryptography engine to decrypt encrypted user content data stored on the non-volatile storage medium of the data storage device for access by the host computer system.

Assignments (10)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052025 FRAME 0088 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058965/0699 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2020
From: MASTENBROOK, BRIAN EDWARD; ARNOLD, DAVID ROBERT
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 052957/0261 →
SECURITY INTEREST Recorded Feb 26, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052025/0088 →