IP Library Granted Patent US 12,436,691
Granted Patent B2
US 12,436,691 · App. 18/439,107 · Granted Oct 7, 2025

Data storage device and method for hiding tweak generation latency

Inventors: Rasmus Madsen (Skovlunde, DK); Mark Myran (Trabuco Canyon, CA); Lunkai Zhang (Portland, OR); Martin Lueker-Boden (Fremont, CA)
Assignee: Sandisk Technologies, Inc.
G06F3/0623G06F3/0638G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,436,691
App. No.
18/439,107
Granted
Oct 7, 2025
Kind
B2
Abstract

A decryption engine can decrypt encrypted data read from a physical address in a memory of a data storage device. To decrypt the data, the decryption engine can use a tweak value that is generated from a logical address associated with the physical address. To reduce latency, the tweak value can be generated in parallel with the translation of the logical address to the physical address. The tweak value can be stored in a tweak buffer in the decryption engine until needed and can be indexed by a tag associated with a process in a host that is requesting the data. The tweak buffer can use static random-access memory (SRAM) or a content-addressable memory (CAM), for example. Other embodiments are provided.

Claims (66)

1. A data storage device comprising:

a memory;

a memory controller comprising one or more processors, individually or in combination, configured to read encrypted data stored in a physical address in the memory;

a logical-address-to-physical-address translator configured to:

receive a read request from a host, wherein the read request comprises a logical address and a request tag, wherein the logical address is in an unencoded format;

translate the logical address to the physical address in the memory; and

provide, to the memory controller, the read request with the physical address and the request tag; and

a decryption engine comprising:

a tweak buffer comprising a content-addressable memory (CAM);

a tweak generator configured to:

receive the logical address that is in the read request from the host;

calculate a tweak value from the logical address that is in the read request from the host, wherein the tweak value is calculated in parallel to the logical address being translated to the physical address, and wherein a latency to calculate the tweak value is less than a latency to translate the physical address from the logical address; and

store the tweak value and the request tag in the tweak buffer by:

verifying that there is no match for the request tag in the tweak buffer; and

in response to verifying that there is no match for the request tag in the tweak buffer, initializing a CAM entry in the tweak buffer that associates the tweak value with the request tag; and

a decrypter configured to:

receive the encrypted data and the request tag from the memory controller; and

in response to receiving the encrypted data and the request tag from the memory controller:

use the request tag to attempt to retrieve the tweak value from the tweak buffer;

in response to the attempt to retrieve the tweak value from the tweak buffer being successful:

 use the tweak value to decrypt the encrypted data; and

 reset the request tag of the CAM entry to an invalid value; and

in response to the attempt to retrieve the tweak value from the tweak buffer being unsuccessful, which indicates that the tweak calculation is not finished:

 re-attempt to retrieve the tweak value from the tweak buffer; and

 block decryption of the encrypted data until the re-attempt to retrieve the tweak value from the tweak buffer is successful.

2. The data storage device of claim 1 , wherein the decrypter comprises an AES-XTS decryption engine, wherein AES-XTS refers to Advanced Encryption Standard (AES) cryptography that uses an exclusive-or (XOR) Encrypt XOR (XEX) Tweakable Block Cipher with Ciphertext Stealing (XTS).

3. The data storage device of claim 1 , wherein the memory controller comprises ordering logic.

4. The data storage device of claim 1 , wherein the memory comprises magnetoresistive random-access memory (MRAM).

5. The data storage device of claim 1 , wherein the memory comprises a three-dimensional memory.

6. In a decryption engine in a data storage device, a method comprising:

receiving a read request from a host, wherein the read request comprises a logical address and a request tag, wherein the logical address is in an unencoded format;

translating the logical address to a physical address of a memory of the data storage device;

while the data storage device is translating the logical address to the physical address, using the logical address that is in the read request from the host to generate a value needed to decrypt encrypted data stored at the physical address in the memory, wherein a latency to calculate the value is less than a latency to translate the logical address to the physical address;

storing the value in a buffer in the decryption engine, wherein the buffer comprises a content-addressable memory (CAM), and wherein storing the value in the buffer comprises:

verifying that there is no match for the request tag in the buffer; and

in response to verifying that there is no match for the request tag in the buffer, initializing a CAM entry in the buffer that associates the value with the request tag;

receiving the encrypted data from the memory;

attempting to retrieve the value from the buffer;

in response to the attempt to retrieve the value from the buffer being successful:

using the value to decrypt the encrypted data; and

resetting the request tag of the CAM entry to an invalid value; and

in response to the attempt to retrieve the value from the buffer being unsuccessful, which indicates that generation of the value is not finished:

re-attempting to retrieve the value from the buffer; and

blocking decryption of the encrypted data until the re-attempt to retrieve the value from the tweak is successful.

7. The method of claim 6 , wherein the value comprises a tweak value.

8. The method of claim 6 , wherein the decryption engine is configured to decrypt the encrypted data using an AES-XTS algorithm, wherein AES-XTS refers to Advanced Encryption Standard (AES) cryptography that uses an exclusive-or (XOR) Encrypt XOR (XEX) Tweakable Block Cipher with Ciphertext Stealing (XTS).

9. The method of claim 6 , wherein the decryption engine comprises a tweak generator and a data decryptor.

10. The method of claim 6 , wherein the memory comprises magnetoresistive random-access memory (MRAM).

11. The method of claim 6 , wherein the memory comprises a three-dimensional memory.

12. A data storage device comprising:

a memory; and

means for:

receiving a read request from a host, wherein the read request comprises a logical address and a request tag, wherein the logical address is in an unencoded format;

translating the logical address to a physical address of a memory of the data storage device;

while the data storage device is translating the logical address to the physical address, using the logical address that is in the read request from the host to generate a value needed to decrypt encrypted data stored at the physical address in the memory, wherein a latency to calculate the value is less than a latency to translate the logical address to the physical address;

storing the value in a buffer in the decryption engine, wherein the buffer comprises a content-addressable memory (CAM), and wherein storing the value in the buffer comprises:

verifying that there is no match for the request tag in the buffer; and

in response to verifying that there is no match for the request tag in the buffer, initializing a CAM entry in the buffer that associates the value with the request tag;

receiving the encrypted data from the memory;

attempting to retrieve the value from the buffer;

in response to the attempt to retrieve the value from the buffer being successful:

using the value to decrypt the encrypted data; and

resetting the request tag of the CAM entry to an invalid value; and

in response to the attempt to retrieve the value from the buffer being unsuccessful. which indicates that generation of the value is not finished:

re-attempting to retrieve the value from the buffer; and

blocking decryption of the encrypted data until the re-attempt to retrieve the value from the tweak is successful.

Assignments (7)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT (AR) Recorded May 15, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 067417/0329 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2024
From: MADSEN, RASMUS; MYRAN, MARK; ZHANG, LUNKAI; LUEKER-BODEN, MARTIN
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 066451/0166 →
Continuity (1)
Related Publication 20250258616A1 · Aug 14, 2025
References Cited (27)
US 9002002B1 · Poo et al. · 2015 [cited by applicant]
US 11263153B1 · Cheng · 2022 [cited by applicant]
US 11301153B2 · Segev et al. · 2022 [cited by applicant]
US 11972822B2 · Hassner et al. · 2024 [cited by applicant]
US 20170054550A1 · Choi · 2017 [cited by applicant]
US 20190102577A1 · Gueron · 2019 [cited by examiner]
US 20190205244A1 · Smith · 2019 [cited by applicant]
US 20200169383A1 · Durham · 2020 [cited by examiner]
US 20210119780A1 · Hassan · 2021 [cited by examiner]
US 20220100911A1 · Trikalinou · 2022 [cited by examiner]
US 20220138329A1 · Kounavis · 2022 [cited by applicant]
US 20220171545A1 · Chritz · 2022 [cited by examiner]
US 20220171887A1 · Chritz · 2022 [cited by examiner]
US 20220283731A1 · Yoo · 2022 [cited by examiner]
US 20220343029A1 · Sultana · 2022 [cited by applicant]
US 20230027329A1 · Durham · 2023 [cited by applicant]
US 20240249000A1 · Srivastava · 2024 [cited by applicant]
EP 4156594A1 · 2023 [cited by applicant]
WO WO2018052577A1 · 2018 [cited by applicant]
U.S. Appl. No. 18/223,662, filed Jul. 19, 2023, entitled “Data Storage Device and Method for Hiding Tweak Generation Latency.”. [cited by applicant]
“AES-XTS Block Cipher Mode is used in Kingston's Encrypted USB Flash Drive”; Kingston Technology blog page; downloaded from the Internet on Jul. 18, 2023 at AES-XTS Block Cipher Mode is used in Kingston's best encrypted… [cited by applicant]
Non-final Office Action mailed Sep. 26, 2024 for U.S. Appl. No. 18/223,662; 10 pages. [cited by applicant]
“IEEE Standard for Wide-Block Encryption for Shared Storage Media”; in IEEE Std. 1619.2-2021 (Revision of IEEE Std. 1619.2-2010), pp. 1-88; Jun. 16, 2021. [cited by applicant]
Luo, C. et al.; “Side-channel power analysis of XTS-AES”; Design, Automation & Test in Europe Conference & Exhibition 2017, Lausanne, Switzerland; 2017; pp. 1330-1335. [cited by applicant]
Final Office Action mailed Nov. 8, 2024 for U.S. Appl. No. 18/223,662; 10 pages. [cited by applicant]
Meijer, C. et al.; “Self-Encrypting Deception: Weaknesses in the Encryption of Solid State Drives”; 2019 IEEE Symposium on Security and Privacy (SP); San Francisco, CA, USA; 2019; pp. 72-87. [cited by applicant]
Wilke, L. et al.; “SEVurity: No Security Without Integrity: Breaking Integrity-Free Memory Encryption with Minimal Assumptions”; 2020 IEEE Symposium on Security and Privacy (SP); San Francisco, CA, USA; 2020; pp. 1483-1… [cited by applicant]