IP Library Granted Patent US 12,596,815
Granted Patent B2
US 12,596,815 · App. 17/964,663 · Granted Apr 7, 2026

Verifying the authenticity of storage devices

Inventor: Victor Y. Tsai (Palo Alto, CA)
Assignee: SMART Modular Technologies, Inc.
G06F21/602G06F21/31G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,815
App. No.
17/964,663
Granted
Apr 7, 2026
Kind
B2
Abstract

Techniques for a host system or a user to verify the authenticity of a storage device or a logical sub-unit (e.g., a partition) of the storage device are disclosed. A storage device stores one or more first secret keys and a host device stores one or more second keys. A respective first secret key and a respective second key are used in a verification process that verifies the authenticity of the storage device prior to accessing the storage device.

Claims (60)

1 . A storage device, comprising:

a storage medium operable to store data therein;

a secure storage medium operable to store a shared secret; and

a processing device operably connected to the storage medium and the secure storage medium, the processing device operable to:

receive a plurality of shared secrets;

store the shared secrets in partitions in the secure storage medium, wherein respective shared secrets are associated with one or more subsets of the partitions of the secure storage medium, wherein a subset of the partitions of the secure storage medium is lower in number of partitions than all of the partitions of the secure storage medium;

receive a verification message comprising a single-use key;

access the shared secrets;

process the single-use key and the shared secrets to produce verification keys corresponding to each of the respective shared secrets for verifying the authenticity of the partitions of the storage device; and

transmit, to a host device, the verification keys to facilitate authentication of the storage device.

2 . The storage device of claim 1 , wherein the secure storage medium is located in the processing device.

3 . The storage device of claim 2 , wherein the secure storage medium is a one-time-programmable memory.

4 . The storage device of claim 1 , wherein:

the processing of the single-use key and the shared secrets to produce the verification keys comprises concatenating the single-use key and the shared secrets.

5 . The storage device of claim 4 , wherein the processing of the single-use key and the shared secrets to produce the verification keys further comprises generating proxies of the concatenated single-use key and the shared secrets.

6 . The storage device of claim 5 , wherein the proxies are hash values.

7 . The storage device of claim 4 , wherein the single-use key is a random number.

8 . The storage device of claim 1 , wherein the shared secrets comprise one or more of:

a password;

biometric data; or

a string of characters.

9 . A method of operating a storage device, the method comprising:

receiving a plurality of shared secrets;

storing the shared secrets in partitions in a secure storage medium, wherein respective shared secrets are associated with one or more of the partitions of the secure storage medium, wherein a subset of the partitions of the secure storage medium is lower in number of partitions than all of the partitions of the secure storage medium;

receiving a verification message, the verification message comprising a single-use key;

processing the single-use key and the shared secrets stored in the storage device to produce verification keys corresponding to each of the respective shared secrets; and

transmitting the verification keys to a host device to enable the host device to verify the authenticity of the one or more partitions of the storage device.

10 . The method of claim 9 , further comprising:

after verification of the authenticity of the one or more partitions of the storage device, receiving a read request; and

retrieving data associated with the read request.

11 . The method of claim 9 , further comprising:

after verification of the authenticity of the one or more partitions of the storage device, receiving a write request; and

storing data associated with the write request.

12 . The method of claim 9 , wherein processing the single-use key and the shared secrets comprises concatenating the single-use key and the shared secrets to produce string concatenations that are used as the verification keys.

13 . The method of claim 12 , wherein processing the single-use key and the shared secrets further comprises generating hash values based on the string concatenations.

14 . The method of claim 9 , further comprising retrieving, by the storage device, the shared secrets from a secure storage medium within the storage device.

15 . A system, comprising:

a storage device, comprising:

a storage medium operable to store data therein;

a secure storage medium operable to store a shared secret; and

a processing device operably connected to the storage medium and the secure storage medium, the processing device operable to:

receive a plurality of shared secrets;

store the shared secrets in partitions in the secure storage medium, wherein respective shared secrets are associated with one or more of the partitions of the secure storage medium, wherein a subset of the partitions of the secure storage medium is lower in number of partitions than all of the partitions of the secure storage medium;

receive a single-use key from a host device;

access the shared secrets;

process the single-use key and the shared secrets to produce verification keys corresponding to each of the respective shared secrets operable to verify the authenticity of the one or more partitions of the storage device; and

transmit, to the host device, the verification keys to facilitate authentication of the storage device.

16 . The system of claim 15 , wherein:

the processing device is a first processing device;

the secure storage medium is a first storage device;

the verification keys are first verification keys; and

the host device comprises:

a second secure storage medium operable to store the shared secrets; and

a second processing device operably connected to the second secure storage medium, the second processing device operable to:

transmit the single-use key to the storage device;

receive a first verification message;

process the single-use key and the shared secrets to produce second verification keys;

determine whether the first verification keys correspond to the second verification keys to verify the authenticity of the one or more partitions of the storage device; and

based on a successful verification of the authenticity of the one or more partitions of the storage device, enable access to at least a portion of the data stored in the storage medium in the one or more partitions of the storage device.

17 . The system of claim 15 , wherein the storage medium is a non-partitioned storage medium and the shared secrets are associated with and enables access to all of the data stored in the one or more partitions of the secure storage medium.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 30, 2025
From: CREELED, INC.; PENGUIN SOLUTIONS CORPORATION (DE); SMART EMBEDDED COMPUTING, INC.; SMART HIGH RELIABILITY SOLUTIONS LLC; SMART MODULAR TECHNOLOGIES, INC.; PENGUIN COMPUTING, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071755/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2022
From: TSAI, VICTOR Y.
To: SMART MODULAR TECHNOLOGIES, INC.
Reel/Frame 061948/0069 →
Continuity (1)
Related Publication 20240126894A1 · Apr 18, 2024
References Cited (24)
US 8918897B2 · Resch · 2014 [cited by examiner]
US 20020152377A1 · Bauman · 2002 [cited by examiner]
US 20040064729A1 · Yellepeddy · 2004 [cited by examiner]
US 20090193491A1 · Rao · 2009 [cited by examiner]
US 20090261172A1 · Kumar · 2009 [cited by examiner]
US 20090287933A1 · Beckwith · 2009 [cited by examiner]
US 20100095132A1 · Murray · 2010 [cited by examiner]
US 20110179478A1 · Flick · 2011 [cited by examiner]
US 20140032934A1 · Nagai · 2014 [cited by examiner]
US 20170150356A1 · Li · 2017 [cited by examiner]
US 20210263746A1 · Thom · 2021 [cited by examiner]
US 20220342581A1 · Cariello · 2022 [cited by examiner]
CN 108810063A · 2018 [cited by examiner]
CN 109643285A · 2019 [cited by examiner]
EP 3251284B1 · 2020 [cited by examiner]
JP 2008124987A · 2008 [cited by examiner]
KR 20100005413A · 2010 [cited by examiner]
WO WO2010054574A1 · 2010 [cited by examiner]
WO WO2020001078A1 · 2020 [cited by examiner]
WO WO2022212396A1 · 2022 [cited by examiner]
Arno Wagner et al, Frequently Asked Questions Cryptsetup/LUKS, Apr. 26, 2020, https://web.archive.org/web/20200427011448/ https://gitlab.com/cryptsetup/cryptsetup/-/wikis/FrequentlyAskedQuestions (Year: 2020). [cited by examiner]
Menezes, A.J., van Oorschot, P.C., & Vanstone, S.A. (1997). Handbook of Applied Cryptography (1st ed.). CRC Press. https://doi.org/10.1201/9780429466335, p. 321-355 (Year: 1997). [cited by examiner]
Menezes, A.J., van Oorschot, P.C., & Vanstone, S.A. (1997). Handbook of Applied Cryptography (1st ed.). CRC Press. https://doi.org/10.1201/9780429466335, p. 397-402 (Year: 1997). [cited by examiner]
TCG, “TCG Storage Architecture Core Specification,” Specification Version 2.01, Revision 1.00, Aug. 5, 2015, Trusted Computing Group, Incorporated, 306 pages. [cited by applicant]