IP Library Granted Patent US 11,386,203
Granted Patent B2
US 11,386,203 · App. 16/901,633 · Granted Jul 12, 2022

Detection of compromised storage device firmware

Inventors: Judah Gamliel Hahn (Ofra, IL); Shay Benisty (Beer Sheva, IL); Ariel Navon (Revava, IL)
Assignee: Western Digital Technologies, Inc.
G06F21/552G06F11/1068G06F12/10G06F13/1673G06F13/28G06F21/606G06F21/71G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,386,203
App. No.
16/901,633
Granted
Jul 12, 2022
Kind
B2
Abstract

An apparatus, system, and method for detecting compromised firmware in a non-volatile storage device. A control bus of a non-volatile storage device is monitored. The non-volatile storage device includes a processor and electronic components coupled to the control bus. Signal traffic on the control bus is analyzed for events and/or triggers related to storage operations initiated on the control bus by the processor. Storage operations include one or more commands directed to at least one of the electronic components. If the latency for the storage operation satisfies an alert threshold a host is notified of compromised firmware.

Claims (52)

1. A method, comprising:

monitoring a control bus of a non-volatile storage device comprising a processor coupled to the control bus and a plurality of electronic components each coupled to the control bus;

analyzing signal traffic on the control bus for events for a storage operation initiated on the control bus by the processor, the storage operation comprising one or more commands directed to at least one of the plurality of electronic components;

measuring a latency for the storage operation;

determining that the latency for the storage operation satisfies an alert threshold, wherein the determining comprises:

determining that the latency of the storage operation comprises a first anomaly in response to the latency satisfying an alert threshold for the storage operation and the storage operation comprises a predictable storage operation; and/or

determining that the latency of the storage operation comprises a second anomaly in response to the latency satisfying an anomaly detector for the storage operation and the storage operation comprises a semi-predictable storage operation; and

notifying a host of a compromised firmware in response to the storage operation satisfying the alert threshold.

2. The method of claim 1 , wherein detecting the storage operation comprises:

monitoring signal traffic between the processor and one or more of the plurality of electronic components;

determining that the signal traffic is associated with a target storage operation; and

identifying a start event for the target storage operation; and

identifying a stop event for the target storage operation.

3. The method of claim 2 , wherein measuring the latency further comprises measuring a time interval between the start event and the stop event and designating the time interval as the latency for the target storage operation, the method further comprising storing the latency for the target storage operation.

4. The method of claim 1 , further comprising receiving a firmware monitoring request from the host at a security chip coupled to the control bus, the security chip operating independent of the processor and independent of firmware executing on the processor, the security chip configured to notify the host of compromised firmware based on one or more target storage operations.

5. The method of claim 4 , wherein the firmware monitoring request designates one or more storage operations as target storage operations.

6. The method of claim 1 , wherein the anomaly detector comprises logic that implements one of:

a Support-Vector-Machine (SVM) linear variant method; a Gaussian-Mixture-Model (GMM) method;

a density-based variant detection method; a replicator neural network;

a cluster-based variant detection method; and a K-means detection method.

7. A method, comprising:

monitoring a control bus of a non-volatile storage device comprising a processor coupled to the control bus and a plurality of electronic components each coupled to the control bus;

analyzing signal traffic on the control bus for events for a storage operation initiated on the control bus by the processor, the storage operation comprising one or more commands directed to at least one of the plurality of electronic components;

measuring a latency for the storage operation;

determining that the latency for the storage operation satisfies an alert threshold;

notifying a host of a compromised firmware in response to the storage operation satisfying the alert threshold; and

receiving a firmware monitoring request from the host at a security chip coupled to the control bus, the security chip operating independent of the processor and independent of firmware executing on the processor, the security chip configured to notify the host of compromised firmware based on one or more target storage operations, wherein in response to receiving the firmware monitoring request, establishing a secure communication channel between the security chip and the host, the secure communication channel configured to be inaccessible to the firmware executing on the processor.

8. An apparatus, comprising:

a communication bus;

a memory coupled to the communication bus, the memory configured to store a storage security firmware image, an alert threshold, and a repository comprising latency data;

a processor coupled to the communication bus, the processor configured to execute the storage security firmware image comprising:

a monitor configured to generate latency data for a target storage operation, the target storage operation identified based on signal traffic on the communication bus;

a detector configured to:

determine an anomaly based on the latency data for the target storage operation, wherein the determining comprises:

determining that a latency of the storage operation comprises a first anomaly in response to the latency satisfying an alert threshold for the storage operation and the storage operation comprises a predictable storage operation; and/or

determining that the latency of the storage operation comprises a second anomaly in response to the latency satisfying an anomaly detector for the storage operation and the storage operation comprises a semi-predictable storage operation; and

a reporter configured to signal a host in response to the detector identifying the anomaly indicating a compromised storage controller firmware image; and

a communication module coupled to the communication bus and configured to communicate the anomaly to the host.

9. The apparatus of claim 8 , wherein the monitor comprises:

an analyzer configured to detect events in signal traffic traveling over the communication bus based on a trigger, the events characteristic of the target storage operation;

a tracker configured to measure a time interval between a start event and a stop event, the start event and stop event distinctively associated with the target storage operation.

10. The apparatus of claim 8 , wherein the communication module comprises a security module configured to establish a secure communication channel between the host and the communication module.

11. The apparatus of claim 8 , wherein the target storage operation comprises one of a flash logical block address translation operation, a firmware initialization operation, a host memory buffer initialization operation, a host memory buffer release operation, a power down operation, and a power on reset operation.

12. The apparatus of claim 8 , wherein the anomaly is indicative of the compromised storage controller firmware image.

13. The apparatus of claim 8 , wherein the detector comprises an anomaly detector configured to:

analyze a set of latency data over a historical time period;

tune the anomaly detector based on the analyzed set of latency data;

determine that the target storage operation comprises a semi-predictable storage operation;

determine that the latency data for the target storage operation indicates the anomaly; and

log the anomaly and the latency data.

14. The apparatus of claim 8 , wherein the communication module is configured to communicate exclusively with the host.

15. The apparatus of claim 8 , wherein the target storage operation is initiated by a storage processor coupled to the communication bus and the communication module couples to the communication bus such that no communication channel exists between the communication module and the storage processor.

Assignments (10)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 053926 FRAME 0446 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058966/0321 →
SECURITY INTEREST Recorded Sep 29, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 053926/0446 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2020
From: HAHN, JUDAH GAMLIEL; BENISTY, SHAY; NAVON, ARIEL
To: WESTERN DIGITAL TECHNOLOGIES INC.
Reel/Frame 053023/0915 →