IP Library › Granted Patent US 12,524,245
Granted Patent B2
US 12,524,245 · App. 18/396,430 · Granted Jan 13, 2026

Storage device, operating method of storage device, and processor of storage device

Inventors: Younsung Chu (Suwon-si, KR); Jisoo Kim (Suwon-si, KR)
Assignee: Samsung Electronics Co., LTD.
G06F9/4403G06F21/575G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,245
App. No.
18/396,430
Granted
Jan 13, 2026
Kind
B2
Abstract

A storage device includes a device identification module configured to generate a device identifier, a bootloader configured to generate a device identification key pair based on the device identifier and perform booting of the storage device, attester firmware configured to generate a device certificate based on the device identification key pair and report security information on the device to a host, and a measurement manager configured to perform a measurement operation for the device identification module, the bootloader, and the attester firmware, store a first measurement value of the device identification module in response to determining that the first measurement value matches first information, determine whether a second measurement value of the bootloader matches second information in response to storing the first measurement, store the second measurement value in response to determining that the second measurement value matches the second information, determine whether a third measurement value of the attester firmware matches third information in response to the second measurement value being stored, store the third measurement value in response to determining that the second measurement value matches the second information, and transmit the stored first measurement value, the stores second measurement value, and the stored third measurement value to the attester firmware.

Claims (91)

1 . A storage device comprising:

a device identification module configured to generate a device identifier;

a bootloader configured to generate a device identification key pair based on the device identifier and perform booting of the storage device;

attester firmware configured to

generate a device certificate based on the device identification key pair, and

report security information on the storage device to a host; and

a measurement manager configured to

perform a measurement operation for the device identification module, the bootloader, and the attester firmware,

store a first measurement value of the device identification module in response to determining that the first measurement value matches first information,

determine whether a second measurement value of the bootloader matches second information in response to storing the first measurement value,

store the second measurement value in response to determining that the second measurement value matches the second information,

determine whether a third measurement value of the attester firmware matches third information in response to the second measurement value being stored,

store the third measurement value in response to determining that the third measurement value matches the third information, and

transmit the stored first measurement value, the stored second measurement value, and the stored third measurement value to the attester firmware.

2 . The storage device of claim 1 , further comprising:

a first register configured to store the first measurement value;

a second register configured to store the second measurement value; and

a third register configured to store the third measurement value.

3 . The storage device of claim 2 , wherein the measurement manager is configured to prohibit a write operation for the first register in response to the first measurement value being stored in the first register, and

the device identification module is configured to

request the second measurement value from the measurement manager, and

generate the device identifier in response to receiving the second measurement value.

4 . The storage device of claim 2 , wherein the measurement manager is configured to prohibit a write operation for the second register in response to the second measurement value being stored in the second register, and

the bootloader is configured to

request the third measurement value from the measurement manager, and

generate the device identification key pair based on the generated device identifier in response to receiving the third measurement value.

5 . The storage device of claim 2 , wherein the measurement manager is configured to prohibit a write operation for the third register in response to the third measurement value being stored in the third register, and

the attester firmware is configured to

receive a request for measurement operations for a plurality of components from the host, and

request the measurement manager to perform measurement operations for a plurality of pieces of firmware based on the request from the host.

6 . The storage device of claim 1 , wherein the device identification key pair includes at least one of a device ID key pair or an alias key pair.

7 . The storage device of claim 6 , further comprising:

a first security register configured to store the device identifier;

a second security register configured to store the device ID key pair generated based on the device identifier; and

a third security register configured to store the alias key pair generated based on the device identifier.

8 . The storage device of claim 7 , wherein

the measurement manager is configured to

receive a first security signature generated by the attester firmware from a device security key of the device ID key pair and a second security signature generated by the attester firmware from an alias security key of the alias key pair, and

transmit the received first security signature and the received second security signature to the attester firmware.

9 . The storage device of claim 1 , further comprising:

a fourth register configured to store measurement values of a plurality of pieces of firmware,

wherein the measurement manager is further configured to transmit the measurement values stored in the fourth register to the attester firmware.

10 . The storage device of claim 1 , wherein

the security information includes at least one of the first measurement value, the second measurement value, the third measurement value, or a fourth measurement value,

the attester firmware is further configured to transmit a measurement value response including the security information to the host, and

the host is configured to perform verification of the storage device based on the measurement value response.

11 . An operating method of a storage device, the operating method comprising:

performing measurement of a plurality of components according to a request from a host for a measurement operation for the plurality of components of the storage device;

performing secure booting based on a result of the measurement of the plurality of components;

storing a first measurement value of a device identification module in a first register in response to determining that the first measurement value matches first information;

determining whether a second measurement value of a bootloader matches second information in response to the first measurement value being stored;

storing the second measurement value in a second register in response to determining that the second measurement value matches the second information;

determining whether a third measurement value of attester firmware matches third information in response to the second measurement value being stored;

storing the third measurement value in a third register in response to determining that the third measurement value matches the third information;

transmitting the first information, the second information, and the third information, to an attester firmware; and

reporting the first information, the second information, and the third information to the host.

12 . The operating method of claim 11 , wherein the performing the measurement of the plurality of components includes,

performing a write prohibition operation for the first register in response to the first measurement value being stored in the first register, and

generating a device identifier based on the second measurement value.

13 . The operating method of claim 11 , wherein the performing the measurement of the plurality of components comprises:

performing a write prohibition operation for the second register in response to the second measurement value being stored in the second register; and

generating a device identification key pair based on a device identifier.

14 . The operating method of claim 11 , wherein the performing the measurement of the plurality of components comprises:

performing a write prohibition operation for the third register in response to the third measurement value being stored in the third register;

receiving a request for a measurement operation for the plurality of components from the host; and

performing a measurement operation for a plurality of pieces of firmware based on the request from the host.

15 . The operating method of claim 11 , wherein the performing the measurement of the plurality of components comprises:

storing a device identifier in a first security register;

storing a device ID key pair generated based on the device identifier in a second security register; and

storing an alias key pair generated based on the device identifier in a third security register.

16 . The operating method of claim 15 , wherein the performing the measurement of the plurality of components comprises:

receiving a first security signature generated from a device security key of the device ID key pair and a second security signature generated from an alias security key of the alias key pair; and

transmitting the received first security signature and the received second security signature to the attester firmware.

17 . The operating method of claim 11 , wherein the performing the measurement of the plurality of components comprises:

storing measurement values for a plurality of pieces of firmware in a fourth register; and

transmitting the measurement values stored in the fourth register to the attester firmware.

18 . The operating method of claim 11 , wherein the reporting the first information, the second information, and the third information to the host comprises:

transmitting a measurement value response including the first measurement value, the second measurement value, the third measurement value, and a fourth measurement value to the host.

19 . The operating method of claim 18 , further comprising:

performing, by the host, verification of the storage device based on the measurement value response.

20 . A processor of a storage device configured to receive a request for a measurement operation for a plurality of components of the storage device from a host and perform the measurement operation for the plurality of components, the processor comprising:

a first register;

a second register; and

a third register,

the processor configured to

store a first measurement value of a device identification module in the first register in response to determining that the first measurement value matches first information;

determine whether a second measurement value of a bootloader matches second information in response to the first measurement value being stored,

store the second measurement value in response to determining that the second measurement value matches second information,

determine whether a third measurement value of attester firmware matches third information in response to the second measurement value being stored,

store the third measurement value in the third register in response to determining that the third measurement value matches the third information, and

transmit the first information, the second information, and the third information to the attester firmware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2023
From: CHU, YOUNSUNG; KIM, JISOO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 065973/0349 →
Priority Claims (1)
KR 10-2022-0186380 · Dec 27, 2022 · national
Continuity (1)
Related Publication 20240211272A1 · Jun 27, 2024
References Cited (17)
US 7971048B2 · Datta et al. · 2011 [cited by applicant]
US 9059855B2 · Johnson et al. · 2015 [cited by applicant]
US 9081954B2 · Forristal · 2015 [cited by applicant]
US 11416370B2 · Dewan et al. · 2022 [cited by applicant]
US 11445027B2 · Ponnuru · 2022 [cited by examiner]
US 20130318343A1 · Bjarnason · 2013 [cited by examiner]
US 20170337380A1 · Domke · 2017 [cited by examiner]
US 20210336930A1 · Vessels · 2021 [cited by examiner]
US 20220198018A1 · Wentz · 2022 [cited by examiner]
US 20220237295A1 · Hu et al. · 2022 [cited by applicant]
US 20220292203A1 · Severns-Williams · 2022 [cited by examiner]
Birnstill et al., “Introducing remote attestation and hardware-based cryptography to OPC UA”, 2017 22nd IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), Date of Conference: (Year: Se… [cited by examiner]
‘Hardware Requirements for a Device Identifier Composition Engine’, Family “2.0”, Level 00 Revision 78, Device Identifier Composition Engine, TCG Published, 2018, pp. 1-8. [cited by applicant]
‘DICE Layering Architecture’ Version 1.0, Revision 0.19, Trusted Computing Group, 2020, pp. 1-29. [cited by applicant]
‘DICE Endorsement Architecture for Devices’, Version 1.0, Revision 0.38, Trusted Computing Group, 2022, pp. 1-73. [cited by applicant]
‘TCG DICE Concise Evidence Binding for SPDM’, Trusted Computing Group, Version 1.00, Revision 0.53, 2023, pp. 1-50. [cited by applicant]
‘Security Protocol and Data Model (SPDM) Specification’, Document Identifier: DSP0274, Version 1.2.1, 2022, pp. 1-191. [cited by applicant]