IP Library Granted Patent US 11,088,832
Granted Patent B2
US 11,088,832 · App. 16/739,051 · Granted Aug 10, 2021

Secure logging of data storage device events

Inventor: Brian Edward Mastenbrook (Fremont, CA)
Assignee: Western Digital Technologies, Inc.
H04L9/0825H04L9/0861H04L9/0894H04L9/14H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,088,832
App. No.
16/739,051
Granted
Aug 10, 2021
Kind
B2
Abstract

This disclosure relates to a data storage device comprising, a non-transitory storage medium configured to store user content data and a non-transitory data store configured to store a first log entry comprising first log data encrypted using one of a first public key and a corresponding first private key; a second public key different from the first public key; and a second log entry. The second log entry comprises the first public key, and second log data encrypted using one of the second public key and a corresponding second private key.

Claims (65)

1. A data storage device comprising: a non-transitory storage medium configured to store user content data; and a non-transitory data store configured to store:

a first log entry comprising first log data encrypted using one key of a first public key and a corresponding first private key;

a second public key different from the first public key; and

a second log entry comprising:

the first public key, and

second log data encrypted using one key of the second public key and a corresponding second private key.

2. The data storage device of claim 1 , further comprising a controller configured to create the first log entry and the second log entry.

3. The data storage device of claim 2 , wherein the controller is further configured to:

generate the second public key and the second private key;

encrypt the second log data using the second private key;

store the second public key; and

discard the second private key.

4. The data storage device of claim 2 , wherein:

the non-transitory data store is further configured to store a single logging public key for the first log entry and the second log entry;

the logging public key is accessible in response to an authorized device being connected to the data storage device, and

the controller is further configured to encrypt the second log data using the logging public key and the second private key.

5. The data storage device of claim 4 , wherein encrypting the second log data comprises determining a secret based on elliptic curve cryptography using the logging public key and the second private key.

6. The data storage device of claim 5 , wherein the non-transitory data store is further configured to store a logging private key corresponding to the logging public key.

7. The data storage device of claim 6 , wherein the logging private key is encrypted and accessible in response to a manager device being connected to the data storage device.

8. The data storage device of claim 7 , wherein the logging private key is encrypted using a manager key.

9. The data storage device of claim 6 , wherein the controller is further configured to decrypt the second log data using the private logging key and the second public key stored on the data store.

10. The data storage device of claim 9 , wherein the controller is further configured to decrypt the first log data using the private logging key and the first public key stored in the second log entry.

11. The data storage device of claim 9 , wherein decrypting the second log data comprises determining a secret based on elliptic curve cryptography using the logging private key and the second public key.

12. The data storage device of claim 1 , wherein:

the first log entry is encrypted using the first private key; and

the second log entry is encrypted using the second private key.

13. The data storage device of claim 1 , wherein:

the first private key and the first public key are unique for the first log entry; and

the second private key and the second public key are unique for the second log entry.

14. The data storage device of claim 1 , wherein the second public key is stored separate from the first log entry and the second log entry.

15. The data storage device of claim 1 , wherein the non-transitory data store is further configured to store:

a next log entry pointer indicative of a storage location of the second log entry; and

an initial log entry pointer indicative of a storage location of an initial log entry.

16. The data storage device of claim 15 , wherein the initial log entry pointer is encrypted and accessible in response to a manager device being connected to the data storage device.

17. The data storage device of claim 1 , wherein the first public key is encrypted together with the second log data.

18. The data storage device of claim 1 , further comprising:

a data path comprising:

a data port configured to transmit data between a host computer system and the data storage device that registers with the host computer system as a block storage device; and

a cryptography engine connected between the data port and the storage medium and configured to use a cryptographic key to decrypt encrypted user content data stored on the storage medium in response to a request from the host computer system;

an authorization data store configured to store multiple entries comprising authorization data associated with respective multiple devices; and

an access controller configured to:

receive from one device of the multiple devices a public key associated with a private key stored on the one device of the multiple devices;

determine, based on the public key, a role of manager device or authorized device;

in response to determining the role of authorized device, allow creating log entries and restrict reading log entries; and

in response to determining the role of manager device, allow reading log entries.

19. A method for logging on a data storage device, the method comprising:

creating first log data;

encrypting the first log data using one key of a first public key and a corresponding first private key;

storing a first log entry comprising the first log data encrypted using the one key of the first public key and the corresponding first private key;

storing a second public key different from the first public key;

creating second log data;

encrypting the second log data using one key of a second public key and a corresponding second private key; and

storing a second log entry, the second log entry comprising:

the first public key, and

the second log data encrypted using the one key of the second public key and the corresponding second private key.

20. A data storage device comprising:

means for creating first log data;

means for encrypting the first log data using one key of a first public key and a corresponding first private key;

means for storing a first log entry comprising the first log data encrypted using the one key of the first public key and the corresponding first private key;

means for storing a second public key different from the first public key;

means for creating second log data;

means for encrypting the second log data using one key of a second public key and a corresponding second private key; and

means for storing a second log entry, the second log entry comprising:

the first public key, and

the second log data encrypted using the one key of the second public key and the corresponding second private key.

Assignments (10)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052025 FRAME 0088 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058965/0699 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2020
From: MASTENBROOK, BRIAN EDWARD
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 052970/0019 →
SECURITY INTEREST Recorded Feb 26, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052025/0088 →
Continuity (1)
Related Publication 20210218556A1 · Jul 15, 2021
Cited By (1)
US 12,225,111