IP Library › Granted Patent US 12,411,961
Granted Patent B2
US 12,411,961 · App. 18/208,149 · Granted Sep 9, 2025

Use of ‘type’ encryption keys with key per IO-enabled devices

Inventor: Glen Alan Jaquette (Tucson, AZ)
Assignee: International Business Machines Corporation
G06F21/602G06F21/6209G06F21/64G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,961
App. No.
18/208,149
Granted
Sep 9, 2025
Kind
B2
Abstract

A device-implemented method, in accordance with one aspect of the present invention, includes receiving a command having an address field of predefined length. A first subset of bits in the address field identify an external key of a particular tenant, and a second subset of the bits in the address field corresponds to one of a plurality of type keys associated with different data types. The external key identified by the first subset of bits is retrieved. The type key corresponding to the second subset of bits is also retrieved. The tenant and type keys are combined to create a combined key for use in encrypting and/or decrypting data associated with the command.

Claims (43)

1. A device-implemented method, comprising:

receiving a command having an address field of predefined length, wherein a first subset of bits in the address field identify an external key of a particular tenant, wherein a second subset of the bits in the address field corresponds to one of a plurality of type keys associated with different data types;

retrieving the external key identified by the first subset of bits;

retrieving the type key corresponding to the second subset of bits; and

combining the tenant and type keys to create a combined key for use in encrypting and/or decrypting data associated with the command.

2. The device-implemented method of claim 1 , wherein the data types include privacy types.

3. The device-implemented method of claim 1 , wherein the data types include confidentiality types.

4. The device-implemented method of claim 1 , wherein the command is a Non-Volatile Memory Express (NVMe) compliant command.

5. The device-implemented method of claim 1 , wherein the device is configured as a Key per IO-enabled device.

6. The device-implemented method of claim 1 , comprising:

accessing an internal key stored within the device;

generating a unique media encryption key using the internal key and the combined key; and

using the media encryption key to encrypt and/or decrypt data associated with the command.

7. The device-implemented method of claim 6 , wherein the device is configured to prohibit transfer of the internal key in any form to outside of the device.

8. The device-implemented method of claim 1 , wherein several external keys are individually associated with unique data stored at different locations in a same logical block address range.

9. The device-implemented method of claim 1 , comprising performing crypto-erase of all data corresponding to the tenant by destroying the external key used by the tenant.

10. The device-implemented method of claim 1 , comprising performing crypto-erase of a particular type of data for all tenants by destroying the type key associated with the particular type of data.

11. The device-implemented method of claim 10 , wherein the type key is only stored on the device, wherein the device is configured to prohibit transfer of the type key in any form to outside of the device.

12. The device-implemented method of claim 1 , wherein a null sequence in the second subset of bits indicates setting and/or deletion of the external key.

13. The device-implemented method of claim 1 , wherein the type keys are generated external to the device.

14. The device-implemented method of claim 1 , wherein the type keys are generated within the device and stored only in the device.

15. A system, comprising:

a Key per IO-enabled device, the device having a hardware processor and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, the logic being configured to cause the device to:

receive, by the device, a command having an address field of predefined length, wherein a first subset of bits in the address field identify an external key of a particular tenant, wherein a second subset of the bits in the address field corresponds to one of a plurality of type keys associated with different data types;

retrieve, by the device, the external key identified by the first subset of bits;

retrieve, by the device, the type key corresponding to the second subset of bits; and

combine, by the device, the tenant and type keys to create a combined key for use in encrypting and/or decrypting data associated with the command.

16. A computer program product, the computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising:

program instructions to receive a command having an address field of predefined length, wherein a first subset of bits in the address field identify an external key of a particular tenant, wherein a second subset of the bits in the address field corresponds to one of a plurality of type keys associated with different data types;

program instructions to retrieve the external key identified by the first subset of bits;

program instructions to retrieve the type key corresponding to the second subset of bits; and

program instructions to combine the tenant and type keys to create a combined key for use in encrypting and/or decrypting data associated with the command.

17. The computer program product of claim 16 , wherein the data types include data types selected from the group consisting of: privacy types and confidentiality types.

18. The computer program product of claim 16 , wherein the command is a Non-Volatile Memory Express (NVMe) compliant command.

19. The computer program product of claim 16 , wherein a device that executes the program instructions is configured as a Key per IO-enabled device.

20. A device-implemented method, comprising:

generating a command having an address field of predefined length, wherein a first subset of bits in the address field identify an external key of a particular tenant, wherein a second subset of the bits in the address field corresponds to one of a plurality of type keys associated with different data types; and

sending the command to a Key per IO-enabled device configured to encrypt and/or decrypt data associated with the command using a combined key generated from the external key and the type key associated with the second subset of the bits.

21. The device-implemented method of claim 20 , wherein the data types include privacy types.

22. The device-implemented method of claim 20 , wherein the data types include confidentiality types.

23. The device-implemented method of claim 20 , wherein the command is a Non-Volatile Memory Express (NVMe) compliant command.

24. The device-implemented method of claim 20 , comprising requesting crypto-erase of all data corresponding to the tenant by requesting destruction of the external key stored in the Key per IO-enabled device.

25. The device-implemented method of claim 20 , comprising requesting crypto-erase of a particular type of data for all tenants by requesting destruction of the type key associated with the particular type of data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: JAQUETTE, GLEN ALAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063965/0451 →
Continuity (1)
Related Publication 20240411901A1 · Dec 12, 2024
References Cited (22)
US 11563570B2 · Benisty et al. · 2023 [cited by applicant]
US 11641276B2 · Benisty et al. · 2023 [cited by applicant]
US 20210083858A1 · Jaquette · 2021 [cited by applicant]
US 20210377017A1 · Benisty · 2021 [cited by examiner]
US 20220029793A1 · Kachare et al. · 2022 [cited by applicant]
US 20220191019A1 · Jaquette · 2022 [cited by examiner]
TW 200731224A · 2007 [cited by applicant]
TW 201203092A · 2012 [cited by applicant]
TW 202449639A · 2024 [cited by applicant]
WO 2024251556A1 · 2024 [cited by applicant]
Suhler et al., “Verifying SSD Sanitization,” Presentation, NVM Express Developers Day, May 1, 2018, 16 pages. [cited by applicant]
Kissel et al., “Guidelines for Media Sanitization,” NIST Special Publication 800-88, Revision 1, Dec. 2014, 64 pages. [cited by applicant]
Rubin et al., “Data Security by using the System Erase feature of iDRAC9 on PowerEdge servers,” Dell EMC, 2020, 1 page. [cited by applicant]
Apacer, “Trusted Computing Group Opal (TCG Opal), ” Apacer Technology Inc. White Paper, Version 1.2, Dec. 18, 2018, 12 pages. [cited by applicant]
Anonymous, “Securely Extending Boot ROM Storage using Processor SEEPROM,” IP.com Prior Art Database, Technical Disclosure No. IPCOM000266760D, Aug. 17, 2021, 5 pages. [cited by applicant]
Anonymous, “IOQ-Based Differential Security Model for NVMe Storage System,” IP.com Prior Art Database, Technical Disclosure No. IPCOM000265704D, May 7, 2021, 6 pages. [cited by applicant]
Jaquette, G., U.S. Appl. No. 17/122,956, filed Dec. 15, 2020. [cited by applicant]
Jaquette et al., U.S. Appl. No. 16/808,174, filed Mar. 3, 2020. [cited by applicant]
Naser, M., “NVMe Storage—Understanding the Protocol That Redefines Storage Architecture,” VEXXHOST, Inc., Oct. 29, 2020, 7 pages, retrieved from https://vexxhost.com/blog/nvme-storage-protocol-basics/. [cited by applicant]
Anonymous, “Generating cryptographic initialization vectors from SSD wear metrics,” IP.com Prior Art Database, Technical Disclosure No. IPCOM000256595D, Dec. 13, 2018, 5 pages. [cited by applicant]
Taiwan Patent Office, “Office action,” Jan. 15, 2025, 11 Pages, TW Application No. 113111430. [cited by applicant]
International Search Report and Written Opinion from PCT Application No. PCT/EP2024/064575, dated Sep. 3, 2024, 12 pages. [cited by applicant]