IP Library Granted Patent US 11,650,937
Granted Patent B2
US 11,650,937 · App. 16/731,590 · Granted May 16, 2023

Storage system and method for secure host controller memory buffer access

Inventors: Shay Benisty (Beer Sheva, IL); Rajesh Koul (San Jose, CA)
Assignee: Western Digital Technologies, Inc.
G06F12/1458G06F3/0622G06F3/0637G06F3/0659G06F3/0679G06F9/45558G06F9/544G06F9/546G06F12/0246G06F12/0882G06F13/1642G06F13/1673G06F2009/45579
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,650,937
App. No.
16/731,590
Granted
May 16, 2023
Kind
B2
Abstract

A storage system and method for secure host controller memory buffer access are provided. In one embodiment, a storage system is provided comprising a storage area configured to store a database comprising a submission queue and a completion queue dedicated for use by an authorized host, and a controller. The controller is configured to: receive a request to access the storage area; determine whether the request is from the authorized host or from an unauthorized host; in response to determining that the request is from the authorized host, grant the request; and in response to determining that the request is from an unauthorized host, deny the request. Other embodiments are provided.

Claims (47)

1. A method for secure host access to a controller memory buffer in a storage system, the method comprising:

performing the following in a storage system comprising a controller with a controller memory buffer that is shared by a plurality of virtual machines, wherein the controller memory buffer stores a plurality of data structures, each data structure dedicated to a different virtual machine of the plurality of virtual machines and storing a submission queue and a completion queue of the virtual machine to which the data structure is dedicated:

receiving, from one virtual machine of the plurality of virtual machines, a request comprising an identifier of the one virtual machine and an address;

identifying one data structure of the plurality of data structures from the address in the request;

comparing the identifier of the one virtual machine with an identifier of the one data structure;

in response to the identifier of the one virtual machine matching the identifier of the one data structure, allowing the one virtual machine to access the one data structure; and

in response to the identifier of the one virtual machine not matching the identifier of the one data structure:

determining whether the one data structure is shared with the one virtual machine;

in response to determining that the one data structure is shared with the one virtual machine, allowing the one virtual machine to access the one data structure; and

in response to determining that the one data structure is not shared with the one virtual machine, denying the one virtual machine access to the one data structure.

2. The method of claim 1 , wherein the request is a direct access request.

3. The method of claim 1 , wherein the request is an indirect access request.

4. The method of claim 1 , wherein each data structure of the plurality of data structures is further configured to store a physical region page (PRP) list.

5. The method of claim 1 , wherein the plurality of data structures comprises a plurality of databases.

6. The method of claim 1 , wherein each of the plurality of data structures is further configured to store a scatter/gather list (SGL) segment.

7. The method of claim 1 , wherein each of the plurality of data structures is further configured to store a data buffer.

8. A storage system comprising:

a memory configured to be shared by a plurality of virtual machines, the memory configured to store a plurality of data structures, each data structure dedicated to a different virtual machine of the plurality of virtual machines and storing a submission queue and a completion queue of the virtual machine to which the data structure is dedicated; and

a controller configured to:

receive, from one virtual machine of the plurality of virtual machines, a request comprising an identifier of the one virtual machine and an address;

identify one data structure of the plurality of data structures from the address in the request;

compare the identifier of the one virtual machine with an identifier of the one data structure;

in response to the identifier of the one virtual machine matching the identifier of the one data structure, allow the one virtual machine to access the one data structure; and

in response to the identifier of the one virtual machine not matching the identifier of the one data structure:

determine whether the one data structure is shared with the one virtual machine;

in response to determining that the one data structure is shared with the one virtual machine, allow the one virtual machine to access the one data structure; and

in response to determining that the one data structure is not shared with the one virtual machine, deny the one virtual machine access to the one data structure.

9. The storage system of claim 8 , wherein the memory comprises a controller memory buffer in the controller.

10. The storage system of claim 8 , wherein the memory comprises a persistent memory region in non-volatile memory of the storage system.

11. The storage system of claim 10 , wherein the non-volatile memory comprises a three-dimensional memory.

12. The storage system of claim 8 , wherein the request is a direct access request.

13. The storage system of claim 8 , wherein the request is an indirect access request.

14. The storage system of claim 8 , wherein each data structure of the plurality of data structures further stores a physical region page (PRP) list.

15. The storage system of claim 8 , wherein the storage system is configured to be integrated in a host comprising the plurality of virtual machines.

16. The storage system of claim 8 , wherein the storage system is configured to be removably connected with a host comprising the plurality of virtual machines.

17. The storage system of claim 8 , wherein the plurality of data structures comprises a plurality of databases.

18. The storage system of claim 8 , wherein each data structure of the plurality of data structures further stores a scatter/gather list (SGL) segment.

19. The storage system of claim 8 , wherein each data structure of the plurality of data structures further stores a data buffer.

20. A storage system comprising:

a memory configured to be shared by a plurality of virtual machines, the memory configured to store a plurality of data structures, each data structure dedicated to a different virtual machine of the plurality of virtual machines and storing a submission queue and a completion queue of the virtual machine to which the data structure is dedicated;

means for receiving, from one virtual machine of the plurality of virtual machines, a request comprising an identifier of the one virtual machine and an address;

means for comparing the identifier of the one virtual machine with an identifier of a data structure;

means for allowing the one virtual machine access to the data structure in response to the identifier of the one virtual machine matching the identifier of the data structure; and

means for in response to the identifier of the one virtual machine not matching the identifier of the data structure:

determining whether the data structure is shared with the one virtual machine;

in response to determining that the data structure is shared with the one virtual machine, allowing the one virtual machine to access the data structure; and

in response to determining that the data structure is not shared with the one virtual machine, denying the one virtual machine access to the data structure.

Assignments (10)
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 052025 FRAME 0088 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058965/0699 →
SECURITY INTEREST Recorded Feb 26, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052025/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2019
From: BENISTY, SHAY; KOUL, RAJESH
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 051393/0705 →