IP Library Granted Patent US 12,353,765
Granted Patent B2
US 12,353,765 · App. 18/447,770 · Granted Jul 8, 2025

Method and device for secure data transfer and storage

Inventors: Ramanathan Muthiah (Bangalore, IN); Sundararajan Rajagopal (Bangalore, IN)
Assignee: Sandisk Technologies, Inc.
G06F3/0659G06F3/0622G06F3/0679
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,765
App. No.
18/447,770
Granted
Jul 8, 2025
Kind
B2
Abstract

A data storage device comprising a data port, configured to transceive data via a wired communication channel, a control port, configured to transceive data via a peer-to-peer wireless communication channel, a non-volatile storage medium, and a controller. In response to receiving, from a user device, via the control port, a command to enable control channel access, the controller performs an unlocking process, and, in response to completing the unlocking process, transitions from a locked state to a control channel access state. In response to being in the control channel access state, and in response to receiving, from the user device, via the control port, a write command, the controller stores write data in the storage medium, and, in response to receiving, from a host computer, via the data port, a command to access the storage medium, the controller transmits, to the host computer, a locked state indication.

Claims (54)

1. A method for accessing data on a data storage device, the method performed by a controller of the data storage device, the method comprising:

in response to receiving, from a user device, via a control port, a command to enable control channel access, performing an unlocking process;

in response to completing the unlocking process, transition from a locked state to a control channel access state; and

in response to being in the control channel access state:

in response to receiving, from the user device, via the control port, a write command, the write command comprising write data, storing the write data in a non-volatile storage medium of the data storage device; and

in response to receiving, from a host computer, via a data port, a command to access the non-volatile storage medium, transmitting, to the host computer, via the data port, a locked state indication.

2. A data storage device comprising:

means for, in response to receiving, from a user device, via a control port, a command to enable control channel access, performing an unlocking process;

means for, in response to completing the unlocking process, transition from a locked state to a control channel access state; and

means for, in response to being in the control channel access state:

in response to receiving, from the user device, via the control port, a write command, the write command comprising write data, storing the write data in a non-volatile storage medium of the data storage device; and

in response to receiving, from a host computer, via a data port, a command to access the non-volatile storage medium, transmitting, to the host computer, via the data port, a locked state indication.

3. A data storage device comprising:

a data port, configured to transceive data via a wired communication channel, between a host computer system and the data storage device;

a control port, configured to transceive data via a peer-to-peer wireless communication channel, between a user device and the data storage device;

a non-volatile storage medium, configured to store user content data; and

a controller, configured to:

in response to receiving, from the user device, via the control port, a command to enable control channel access, perform an unlocking process;

in response to completing the unlocking process, transition from a locked state to a control channel access state; and

in response to being in the control channel access state:

in response to receiving, from the user device, via the control port, a write command, the write command comprising write data, store the write data in the non-volatile storage medium; and

in response to receiving, from the host computer system, via the data port, a command to access the non-volatile storage medium, transmit, to the host computer, via the data port, a locked state indication.

4. The data storage device of claim 3 , wherein the unlocking process comprises:

generating, by the controller, a challenge for the user device;

transmitting, to the user device, via the peer-to-peer wireless communication channel, the challenge; and

receiving, from the user device, via the peer-to-peer wireless communication channel, a response calculated by the user device based on the challenge.

5. The data storage device of claim 4 , wherein the challenge is based on elliptic curve cryptography.

6. The data storage device of claim 3 , wherein the locked state indication comprises an indication that there is no storage medium present in the data storage device.

7. The data storage device of claim 3 , wherein the command to access the non-volatile storage medium comprises one or more of: a read command; a write command; and a register command.

8. The data storage device of claim 3 , wherein, in response to being in the control channel access state, the controller is further configured to:

in response to receiving, from the user device, via the control port, a read command, the read command comprising an indication of a read data stored in the non-volatile storage medium, transmit the read data, via the control port, to the user device.

9. The data storage device of claim 3 , wherein the controller is further configured to, in response to receiving, from the user device, via the control port, a command to transition to an unlocked state:

perform an unlocking process; and

in response to completing the unlocking process, transition to the unlocked state.

10. The data storage device of claim 3 , in response to being in the control channel access state, the controller is further configured to:

in response to receiving, from the user device, an indication to cease control channel access, transition to an unlocked state.

11. The data storage device of claim 3 , wherein the data storage device is further configured to:

in response to being in a locked state, register with the host computer system as a mass data storage device without a storage medium present;

in response to being in the control channel access state, register with the host computer system as a mass data storage device without a storage medium present; and

in response to being in an unlocked state, register with the host computer system as a mass data storage device with a storage medium present.

12. The data storage device of claim 3 , wherein the data storage device is further configured to, in response to being in an unlocked state:

in response to receiving, from the host computer system, via the data port, a read command, the read command comprising an indication of read data stored in the non-valatile storage medium, transmit the read data, via the data port, to the host computer system; and

in response to receiving, from the host computer system, via the data port, a write command, the write command comprising write data, store the write data in the non-volatile storage medium.

13. The data storage device of claim 3 , wherein the data storage device is further configured to, responsive to being in the control channel access state, register with the user device as a mass data storage device with a storage medium present.

14. The data storage device of claim 3 , further comprising:

a cryptography engine, connected between the data port and the storage medium and configured to use a cryptographic key to decrypt encrypted user content data stored on the storage medium.

15. The data storage device of claim 14 , wherein the unlocking process further comprises:

calculating the cryptographic key based at least partly on a response from the user device; and

providing the cryptographic key to the cryptography engine to decrypt the user content data stored on the non-volatile storage medium of the data storage device.

16. The data storage device of claim 14 , wherein, in response to being in an unlocked state, the controller is configured to cause the cryptography engine to use the cryptographic key to decrypt the encrypted user content data stored on the non-volatile storage medium in response to a read command, receive via the data port, from the host computer system.

17. The data storage device of claim 14 , wherein, in response to being in a control channel access state, the controller is configured to cause the cryptography engine to use the cryptographic key to decrypt the encrypted user content data stored on the non-volatile storage medium in response to a read command, received via the control port, from the user device.

18. The data storage device of claim 3 , wherein the peer-to-peer wireless communication channel comprises a Bluetooth communication channel.

19. The data storage device of claim 3 , wherein the controller is further configured to establish the peer-to-peer wireless communication channel by performing a pairing process with the user device.

20. The data storage device of claim 3 , wherein the user device comprises an authorized user device.

Assignments (8)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL Recorded Nov 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065657/0158 →
PATENT COLLATERAL AGREEMENT- A&R Recorded Nov 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065656/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2023
From: MUTHIAH, RAMANATHAN; RAJAGOPAL, SUNDARARAJAN
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 064557/0434 →
Continuity (2)
Provisional Application 63523880 · Jun 28, 2023
Related Publication 20250004666A1 · Jan 2, 2025
References Cited (23)
US 8639873B1 · Jevans · 2014 [cited by examiner]
US 10348695B1 · Khassanov · 2019 [cited by examiner]
US 11556665B2 · Mastenbrook et al. · 2023 [cited by applicant]
US 20060039221A1 · Fukuda · 2006 [cited by examiner]
US 20100268878A1 · Matton · 2010 [cited by examiner]
US 20120246416A1 · Shiba · 2012 [cited by examiner]
US 20140295754A1 · Lortz · 2014 [cited by applicant]
US 20150171928A1 · Lee · 2015 [cited by examiner]
US 20150199684A1 · Maus · 2015 [cited by examiner]
US 20160028713A1 · Chui · 2016 [cited by examiner]
US 20190026727A1 · Wilson · 2019 [cited by examiner]
US 20190377505A1 · Yaghmour · 2019 [cited by examiner]
US 20210173561A1 · Mastenbrook · 2021 [cited by applicant]
US 20210218557A1 · Mastenbrook · 2021 [cited by applicant]
US 20220014918A1 · Mastenbrook · 2022 [cited by applicant]
US 20220035901A1 · Yun · 2022 [cited by examiner]
US 20220221990A1 · Srimal · 2022 [cited by applicant]
CN 105739906A · 2016 [cited by examiner]
KR 20240063736A · 2024 [cited by examiner]
Translation of CN-105739906-A. 2024. [cited by examiner]
Translation of KR-20240063736-A. 2024. [cited by examiner]
“ArmorLock User Manual: Encrypted NVMe SSD with Mobile and Desktop Apps”. https://documents.westerndigital.com/content/dam/doc-library/en_us/assets/public/sandisk-pro/product/portable-drives/armorlock/user-manual-armorl… [cited by applicant]
“Western Digital Whitepaper ArmorLock Security Platform”. https://documents.westerndigital.com/content/dam/doc-library/en_us/assets/public/western-digital/collateral/white-paper/white-paper-armorlock-security-platform.p… [cited by applicant]
Cited By (1)
US 12,591,376