IP Library Granted Patent US 12,468,844
Granted Patent B2
US 12,468,844 · App. 18/349,797 · Granted Nov 11, 2025

Storage device and method for generating token

Inventor: Seung-Ho Lee (Suwon-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F21/6245G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,844
App. No.
18/349,797
Granted
Nov 11, 2025
Kind
B2
Abstract

A storage device includes: a nonvolatile memory storing data of a first user; and a storage controller configured to receive an access request from a second user to access the data of the first user, obtain access approval for accessing the data from the first user in response to the access request, generate a token granting access authority to the second user for accessing the data using an Embedded Certificate Authority (ECA) upon obtaining the access approval, and send the token to the second user.

Claims (43)

1 . A storage device comprising:

a nonvolatile memory storing data of a first user; and

a storage controller configured to receive an access request from a second user to access the data of the first user, obtain access approval for accessing the data from the first user in response to the access request, generate a token granting access authority to the second user for accessing the data using an Embedded Certificate Authority (ECA) upon obtaining the access approval, and send the token to the second user.

2 . The storage device of claim 1 , wherein the storage controller is configured to receive user information including a public key of the second user from the second user, and generate a user certificate including the user information and information of the ECA using a device private key of the storage device.

3 . The storage device of claim 2 , wherein the storage controller is configured to transmit a nonce and a device certificate to the second user, receive a value obtained by encrypting the nonce and the user certificate from the second user, verify the user certificate with a device public key paired with the device private key, decrypt the value with the public key of the second user included in the user certificate to generate a decrypted key, and compare the decrypted value with the nonce.

4 . The storage device of claim 1 , wherein the access request includes a data request format including identification information of the second user, information on the data, and a signature of the second user.

5 . The storage device of claim 4 , wherein the storage controller is configured to receive a data search request from the second user, and transmit a search result according to the data search request to the second user, and the information on the data of the data request format includes the search result.

6 . The storage device of claim 5 , wherein the data search request includes at least one of data tag information, file information, and folder information of the data.

7 . The storage device of claim 5 , wherein the search result includes at least one of the presence or absence of the data, the number of the data, a size of the data, a file name of the data, an address of the data, and information on an owner of the data.

8 . The storage device of claim 5 , wherein the access approval of the first user includes a semi-token including the data request format, identification information of the first user, a condition of the access approval, and a signature of the first user.

9 . The storage device of claim 8 , wherein the storage controller is configured to generate the token including a signature of the ECA generated by signing the semi-token and information of the ECA with a device private key of the storage device, the semi-token, and the information of the ECA.

10 . The storage device of claim 9 , wherein the storage controller is configured to receive the token from the second user, check whether the data is valid, and send the data to the second user when check indicates the data is valid.

11 . The storage device of claim 9 , wherein the storage controller is configured to receive the token from the second user, check whether the condition of the access approval is satisfied, and send the data to the second user when the check indicates the condition is satisfied.

12 . The storage device of claim 9 , wherein the storage controller is configured to receive the token from the second user, verify the signature of the ECA, and send the data to the second user when the signature is verified.

13 . The storage device of claim 12 , wherein the storage controller is configured to verify the signature of the ECA with a device public key paired with the device private key.

14 . A method for generating a token, comprising:

receiving a data request format requesting access to data of a first user stored in a storage device from a second user;

transmitting the data request format to the first user;

receiving an access approval of the first user approving the access to the data;

generating the token having access authority for the data based on the data request format using an Embedded Certificate Authority (ECA); and

sending the token to the second user.

15 . The method of claim 14 , further comprising:

receiving a data search request from the second user; and

transmitting a search result according to the data search request to the second user,

wherein the data request format includes the search result.

16 . The method of claim 14 , wherein the receiving of the access approval includes receiving a semi-token including the data request format, identification information of the first user, a condition of the access approval, and a signature of the first user, and the generating of the token includes generating the token including a signature of the ECA generated by signing the semi-token and information of the ECA with a device private key of the storage device, the semi-token, and the information of the ECA.

17 . The method of claim 16 , further comprising:

receiving the token from the second user;

verifying the signature of the ECA with a device public key paired with the device private key;

checking whether the data is valid;

checking whether the condition of the access approval is satisfied; and

sending the data to the second user when the checking indicates the data is valid and the condition is satisfied.

18 . The method of claim 14 , further comprising:

receiving user information including a public key of the second user from the second user; and

generating a user certificate including the user information and information of the ECA using a device private key of the storage device.

19 . The method of claim 18 , further comprising:

transmitting a nonce and a device certificate to the second user before the receiving of the data request format from the second user;

receiving a value obtained by encrypting the nonce and the user certificate from the second user;

verifying the user certificate with a device public key paired with the device private key; and

decrypting the value with the public key of the second user included in the user certificate to compare the decrypted value with the nonce.

20 . A storage controller comprising:

a certification module configured to issue certificates of a plurality of users using an Embedded Certificate Authority (ECA), verify a certificate among the certificates of a first user among the plurality of users, generate a token that grants access authority to data of a second user among the plurality of users using the ECA, and verify the token; and

a processor configured to provide the data of the second user to the first user when the token is verified.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2023
From: LEE, SEUNG-HO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 064203/0709 →
Priority Claims (1)
KR 10-2023-0000761 · Jan 3, 2023 · national
Continuity (1)
Related Publication 20240220651A1 · Jul 4, 2024
References Cited (10)
US 8042163B1 · Karr et al. · 2011 [cited by applicant]
US 9444822B1 · Borowiec et al. · 2016 [cited by applicant]
US 9648007B1 · Sterling et al. · 2017 [cited by applicant]
US 9805210B2 · Nord et al. · 2017 [cited by applicant]
US 11095706B1 · Ankam et al. · 2021 [cited by applicant]
US 20210314308A1 · Kalantri · 2021 [cited by examiner]
US 20230116751A1 · Chien · 2023 [cited by examiner]
US 20230163967A1 · Cannata, Jr. · 2023 [cited by examiner]
CN 111767527 · 2020 [cited by applicant]
JP 6721903 · 2020 [cited by applicant]