IP Library Granted Patent US 11,513,707
Granted Patent B2
US 11,513,707 · App. 17/154,185 · Granted Nov 29, 2022

Memory system and method of controlling nonvolatile memory

Inventor: Shinichi Kanno (Ota, JP)
Assignee: Kioxia Corporation
G06F3/064G06F3/062G06F3/0679G06F12/0246H04L9/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,513,707
App. No.
17/154,185
Granted
Nov 29, 2022
Kind
B2
Abstract

According to one embodiment, when data is to be written to a first physical storage location that is designated by a first physical address, a memory system encrypts the data with the first physical address and a first encryption key, and writes the encrypted data to the first physical storage location. When the encrypted data is to be copied to a second physical storage location, the memory system decrypts the encrypted data with the first physical address and the first encryption key, and re-encrypts the decrypted data with a second encryption key and a copy destination physical address indicative of the second physical storage location.

Claims (67)

1. A memory system, comprising:

a nonvolatile memory; and

a controller electrically connected to the nonvolatile memory and configured to:

in response to receiving, from a host, a write request that specifies a first address, encrypt data using the first address and a first encryption key, and write the encrypted data to a first location of the nonvolatile memory that corresponds to the first address; and

in response to receiving, from the host, a copy request that specifies the first address and a second address, the second address being different from the first address, decrypt the encrypted data using the first address and the first encryption key, re-encrypt the decrypted data using the second address and a second encryption key, and write the re-encrypted data to a second location of the nonvolatile memory that corresponds to the second address, the second location being different from the first location.

2. The memory system of claim 1 , wherein

the second encryption key is same as the first encryption key.

3. The memory system of claim 1 , wherein

the second encryption key is different from the first encryption key.

4. The memory system of claim 1 , wherein

the nonvolatile memory includes a plurality of blocks, and

the first address designates at least a block address of the first location and the second address designates at least a block address of the second location.

5. The memory system of claim 1 , wherein

the copy request specifies, as a copy source, an address range including the first address, and

the copy request specifies, as a copy destination, an address range including the second address.

6. The memory system of claim 1 , wherein

the controller is configured to:

in encrypting the data using the first address and the first encryption key, convert the data using the first address and then encrypt the converted data using the first encryption key; and

in re-encrypting the decrypted data using the second address and the second encryption key, convert the decrypted data using the second address and then re-encrypt the converted decrypted-data using the second encryption key.

7. The memory system of claim 6 , wherein

the controller is configured to:

convert the data by encrypting the data using the first address; and

convert the decrypted data by encrypting the decrypted data using the second address.

8. The memory system of claim 1 , wherein

the controller is configured to select the first encryption key and the second encryption key from a plurality of encryption keys.

9. The memory system of claim 8 , wherein

the controller is further configured to:

manage correspondence between the plurality of encryption keys and a plurality of regions obtained by logically dividing the nonvolatile memory;

select an encryption key associated with a first region to which the first location belongs, as the first encryption key; and

select an encryption key associated with a second region to which the second location belongs, as the second encryption key.

10. The memory system of claim 8 , wherein

the nonvolatile memory includes a plurality of blocks, and

the controller is further configured to:

manage correspondence between the plurality of encryption keys and the plurality of blocks;

select an encryption key associated with a first block to which the first location belongs, as the first encryption key; and

select an encryption key associated with a second block to which the second location belongs, as the second encryption key.

11. A method of controlling a nonvolatile memory, the method comprising:

in response to receiving, from a host, a write request that specifies a first address, encrypting data using the first address and a first encryption key, and writing the encrypted data to a first location of the nonvolatile memory that corresponds to the first address; and

in response to receiving, from the host, a copy request that specifies the first address and a second address, the second address being different from the first address, decrypting the encrypted data using the first address and the first encryption key, re-encrypting the decrypted data using the second address and a second encryption key, and writing the re-encrypted data to a second location of the nonvolatile memory that corresponds to the second address, the second location being different from the first location.

12. The method of claim 11 , wherein

the second encryption key is same as the first encryption key.

13. The method of claim 11 , wherein

the second encryption key is different from the first encryption key.

14. The method of claim 11 , wherein

the nonvolatile memory includes a plurality of blocks, and

the first address designates at least a block address of the first location and the second address designates at least a block address of the second location.

15. The method of claim 11 , wherein

the copy request specifies, as a copy source, an address range including the first address, and

the copy request specifies, as a copy destination, an address range including the second address.

16. The method of claim 11 , wherein

in encrypting the data using the first address and the first encryption key, the data is converted using the first address and then the converted data is encrypted using the first encryption key; and

in re-encrypting the decrypted data using the second address and the second encryption key, the decrypted data is converted using the second address and then the converted decrypted-data is re-encrypted using the second encryption key.

17. The method of claim 16 , wherein

the data is converted by encrypting the data using the first address; and

the decrypted data is converted by encrypting the decrypted data using the second address.

18. The method of claim 11 , wherein

the first encryption key and the second encryption key are selected from a plurality of encryption keys.

19. The method of claim 18 , further comprising:

managing correspondence between the plurality of encryption keys and a plurality of regions obtained by logically dividing the nonvolatile memory;

selecting an encryption key associated with a first region to which the first location belongs, as the first encryption key; and

selecting an encryption key associated with a second region to which the second location belongs, as the second encryption key.

20. The method of claim 18 , wherein

the nonvolatile memory includes a plurality of blocks, and

the method further comprises:

managing correspondence between the plurality of encryption keys and the plurality of blocks;

selecting an encryption key associated with a first block to which the first location belongs, as the first encryption key; and

selecting an encryption key associated with a second block to which the second location belongs, as the second encryption key.

Assignments (1)
CHANGE OF NAME Recorded Jan 11, 2022
From: TOSHIBA MEMORY CORPORATION
To: KIOXIA CORPORATION
Reel/Frame 058725/0932 →
Priority Claims (1)
JP JP2018-097907 · May 22, 2018 · national
Continuity (2)
Continuation 16282078 · Feb 21, 2019
Related Publication 20210165571A1 · Jun 3, 2021