IP Library Granted Patent US 12,118,103
Granted Patent B2
US 12,118,103 · App. 17/689,817 · Granted Oct 15, 2024

Certificates in data storage devices

Inventors: Brian Edward Mastenbrook (Fremont, CA); John So (San Jose, CA); David Robert Arnold (Toronto, CA)
Assignee: Sandisk Technologies, Inc.
G06F21/606G06F21/602H04L9/3268G06F2221/2129
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,118,103
App. No.
17/689,817
Granted
Oct 15, 2024
Kind
B2
Abstract

Disclosed herein is a data storage device. A data port transmits data between a host computer system and the data storage device. A non-volatile storage medium stores encrypted user content data and a cryptography engine connected between the data port and the storage medium uses a cryptographic key to decrypt the encrypted user content data. The access controller generates an authorization request for a manager device. The authorization request comprises a certificate. The certificate comprising key data. In response to receiving the key data in a response to the authorization request generated by the manager device, the access controller generates configuration data based on the key data to register the device to be authorized as an authorized device.

Claims (108)

1. A data storage device comprising:

a non-volatile memory;

a data path comprising:

a data port configured to transmit data between a host computer system and the data storage device;

a non-volatile storage medium configured to store encrypted user content data; and

a cryptography engine connected between the data port and the storage medium, wherein the cryptography engine is configured to use a cryptographic key to decrypt the encrypted user content data stored on the storage medium in response to a request from the host computer system; and

an access controller configured to, responsive to a device to be authorized requesting to be registered as an authorized device:

generate an authorization request to be sent to a manager device, wherein:

the authorization request comprises a certificate;

the certificate comprises key data;

the key data in the certificate comprises a blinded public ephemeral unlock key; and

the certificate further comprises an encrypted blinding factor used to blind the blinded public ephemeral unlock key;

discard the blinding factor responsive to blinding the blinded public ephemeral unlock key:

receive a response to the authorization request, wherein:

the response is generated by the manager device;

the response comprises:

the blinded public ephemeral unlock key multiplied by a private key stored on the manager device; and

the encrypted blinding factor; and

the private key corresponds to a public key stored in the non-volatile memory;

generate a shared secret by decrypting the encrypted blinding factor in the response to unblind the blinded public ephemeral unlock key multiplied by the private key; and,

generate, using the shared secret as a key, configuration data based on the key data to register the device to be authorized as an authorized device, wherein:

the host computer system is a first device;

the manager device is a second device; and

the device to be authorized is a third device.

2. The data storage device of claim 1 , wherein the access controller is further configured to generate a signature for the certificate to enable authentication of the certificate by the manager device.

3. The data storage device of claim 2 , wherein the access controller is further configured to generate the signature using a private logical identity key that corresponds to a public logical identity key, the public logical identity key being authenticated by a further certificate stored on the manager device.

4. The data storage device of claim 3 , wherein the access controller is further configured to create the further certificate and send the further certificate to the manager device upon registering the manager device as a manager device with the data storage device.

5. The data storage device of claim 1 , wherein:

an authorization file certificate comprises a second public key corresponding to a second private key stored on the device to be authorized; and

the access controller is further configured to, responsive to receiving the second public key in the response generated by the manager device; generate a search index; and

use the search index to locate authorization request data stored in the non-volatile memory and corresponding to the device to be authorized.

6. The data storage device of claim 5 , wherein:

generating the search index is based on a private device identification key that is encrypted using a manager key stored in encrypted form in the non-volatile memory; and

the access controller is further configured to use the shared secret to decrypt the manager key.

7. The data storage device of claim 1 , wherein:

the access controller is further configured to encrypt the authorization request using an authorization file key derived from an identity key of the data storage device;

the identity key of the data storage device is stored on the manager device to enable the manager device to identify the data storage device as an origin of the authorization request; and

the manager device is configured to, responsive to the authorization request, attempt to decrypt the authorization request with one or more authorization file keys derived from one or more respective stored identity keys including the identity key of the data storage device.

8. The data storage device of claim 7 , wherein:

the response generated by the manager device is encrypted using the authorization file key derived from the identity key of the data storage device to enable the device to be authorized to identify the data storage device as an origin of the authorization request; and

the device to be authorized is configured to, responsive to receiving the response from the manager device and for identifying the data storage device as the origin of the authorization request to receive the response, attempt to decrypt the response with the one or more authorization file keys derived from the one or more respective identity keys including the identity key of the data storage device.

9. The data storage device of claim 7 , wherein the identity key is obtainable from the data storage device by unauthorized devices that are in proximity of the data storage device.

10. The data storage device of claim 1 , wherein:

the authorization request comprises a second public key corresponding to a second private key stored in the non-volatile memory;

the response is encrypted using an authorization response key based on;

the second public key; and

a third private key generated by the manager device;

the response comprises a third public key corresponding to the third private key generated by the manager device;

the access controller is further configured to:

generate the authorization response key using the third public key included in the response and the second private key stored on the non-volatile memory of the data storage device; and

decrypt the response using the authorization response key.

11. The data storage device of claim 1 , wherein:

the response to the authorization request comprises a response value that is indicative of one of multiple response options;

the multiple response options comprise an option to erase the data storage device; and

the access controller is further configured to, upon receiving a response value that is indicative of the option to erase the data storage device, erase the data storage device.

12. The data storage device of claim 11 , wherein erasing the data storage device comprises generating new key data that enables access to the data storage device to make previously stored encrypted user content data permanently inaccessible.

13. The data storage device of claim 11 , wherein erasing the data storage device comprises registering the device to be authorized as an only user device.

14. The data storage device of claim 11 , wherein the access controller is further configured to:

authenticate the response by verifying that the response was generated by a registered manager device; and

upon successfully authenticating the response, erase the data storage device.

15. The data storage device of claim 1 , wherein the response further comprises a user attestation certificate, signed by a second private key stored on the manager device, the user attestation certificate comprising:

a second public key corresponding to a third private key stored on the device to be authenticated; and

a value indicative of how a user of the device to be authenticated has been validated.

16. A method comprising:

generating, by an access controller of a data storage device and responsive to a device to be authorized requesting to be registered as an authorized device, an authorization request for a manager device, wherein:

the authorization request comprises a certificate;

the certificate comprises key data;

the key data in the certificate comprises a blinded public ephemeral unlock key;

the certificate further comprises an encrypted blinding factor used to blind the blinded public ephemeral unlock key; and

the data storage device comprises a data path comprising:

a data port configured to transmit data between a host computer system and the data storage device;

a non-volatile storage medium configured to store encrypted user content data; and

a cryptography engine connected between the data port and the storage medium, wherein the cryptography engine is configured to use a cryptographic key to decrypt the encrypted user content data stored on the storage medium in response to a request from the host computer system;

discarding, by the access controller, the blinding factor responsive to blinding the blinded public ephemeral unlock key;

receiving, by the access controller, a response to the authorization request, wherein:

the response is generated by the manager device;

the response comprises:

the blinded public ephemeral unlock key multiplied by a private key stored on the manager device; and

the encrypted blinding factor; and

the private key corresponds to a public key stored in a non-volatile memory of the data storage device;

generating, by the access controller, a shared secret by decrypting the encrypted blinding factor in the response to unblind the blinded public ephemeral unlock key multiplied by the private key; and

generating, by the access controller and using the shared secret as a key, configuration data based on the key data to register the device to be authorized as an authorized device, wherein:

the host computer system is a first device;

the manager device is a second device; and

the device to be authorized is a third device.

17. A data storage device comprising:

a non-volatile memory;

a data path comprising:

a data port configured to transmit data between a host computer system and the data storage device;

a non-volatile storage medium configured to store encrypted user content data; and

a cryptography engine connected between the data port and the storage medium, wherein the cryptography engine is configured to use a cryptographic key to decrypt the encrypted user content data stored on the storage medium in response to a request from the host computer system;

means for generating, responsive to a device to be authorized requesting to be registered as an authorized device, an authorization request for a manager device, wherein:

the authorization request comprises a certificate;

the certificate comprises key data;

the key data in the certificate comprises a blinded public ephemeral unlock key; and

the certificate further comprises an encrypted blinding factor used to blind the blinded public ephemeral unlock key;

means for discarding the blinding factor responsive to blinding the blinded public ephemeral unlock key;

means for receiving a response to the authorization request, wherein:

the response is generated by the manager device;

the response comprises:

the blinded public ephemeral unlock key multiplied by a private key stored on the manager device; and

the encrypted blinding factor; and

the private key corresponds to a public key stored in the non-volatile memory;

means for generating a shared secret by decrypting the encrypted blinding factor in the response to unblind the blinded public ephemeral unlock key multiplied by the private key; and

means for generating, using the shared secret as a key, configuration data based on the key data to register the device to be authorized as an authorized device, wherein

the host computer system is a first device;

the manager device is a second device; and

the device to be authorized is a third device.

Assignments (8)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2022
From: MASTENBROOK, BRIAN EDWARD; SO, JOHN; ARNOLD, DAVID ROBERT
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059509/0722 →
Continuity (1)
Related Publication 20230289456A1 · Sep 14, 2023