Storage device and computing device including the same
A storage device includes a non-volatile memory, and a storage controller configured to read a non-encrypted command from a memory outside the storage device. The storage controller is also configured to transmit encrypted data to the non-volatile memory or the memory based on the non-encrypted command, and transmit a non-encrypted completion to the memory. The non-encrypted completion indicates a result of executing the non-encrypted command.
1 . A storage device comprising:
a non-volatile memory; and
a storage controller configured to:
read a non-encrypted command from a memory outside the storage device, wherein the non-encrypted command was written to the memory by a virtual machine of a processor via a memory controller of the processor,
transmit encrypted data to the non-volatile memory, based on the non-encrypted command, wherein the encrypted data was written to the memory from the virtual machine, and
transmit a non-encrypted completion to the memory,
wherein the non-encrypted completion indicates a result of executing the non-encrypted command.
2 . The storage device of claim 1 , wherein the storage controller is further configured to read the non-encrypted command from a non-encrypted area of the memory.
3 . The storage device of claim 1 , wherein the non-encrypted command is written in a non-encrypted area of the memory from the processor outside the storage device.
4 . The storage device of claim 1 , wherein the storage controller is further configured to, when the non-encrypted command is a write command:
read the encrypted data from the memory, and
write the encrypted data into the non-volatile memory.
5 . The storage device of claim 4 , wherein the encrypted data is written into an encrypted area of the memory from the processor outside the storage device.
6 . The storage device of claim 1 , wherein the storage controller is further configured to, when the non-encrypted command is a read command, read the encrypted data from the non-volatile memory and write the encrypted data into the memory.
7 . The storage device of claim 6 , wherein the storage controller is further configured to write the encrypted data into an encrypted area of the memory.
8 . The storage device of claim 1 , wherein the storage controller is further configured to write the non-encrypted completion into a non-encrypted area of the memory.
9 . A computing device comprising:
a memory;
a processor configured to:
generate data by a virtual machine of the processor,
generate encrypted data by encrypting the data,
write the encrypted data into the memory, and
write, by the virtual machine, a non-encrypted write command into the memory; and
a storage device comprising a non-volatile memory and a storage controller,
wherein the storage controller is configured to:
read the non-encrypted write command from the memory,
transmit the encrypted data to the non-volatile memory based on the non-encrypted write command, and
transmit a non-encrypted completion to the memory, and
wherein the non-encrypted completion indicates a result of executing the non-encrypted write command.
10 . The computing device of claim 9 , wherein the processor is further configured to generate the encrypted data by using a dedicated encryption key used inside the processor.
11 . The computing device of claim 9 , wherein the memory comprises:
an encrypted area storing the encrypted data; and
a non-encrypted area storing a non-encrypted command and the non-encrypted completion.
12 . The computing device of claim 11 , wherein the processor is further configured to:
write the encrypted data into the encrypted area of the memory, and
write the non-encrypted write command into the non-encrypted area of the memory.
13 . The computing device of claim 11 , wherein the storage controller is further configured to:
read the non-encrypted write command from the non-encrypted area of the memory,
read the encrypted data from the encrypted area of the memory, and
write the encrypted data into the non-volatile memory.
14 . The computing device of claim 11 , wherein the storage controller is further configured to write the non-encrypted completion into the non-encrypted area of the memory.
15 . A computing device comprising:
a memory;
a processor configured to:
generate data by a virtual machine of the processor,
generate encrypted data by encrypting the data by using a first encryption key,
write the encrypted data into the memory,
generate an encrypted write command by encrypting a write command by using a second encryption key, and
write, by the virtual machine, the encrypted write command into the memory; and
a storage device comprising a non-volatile memory and a storage controller,
wherein the storage controller is configured to:
read the encrypted write command from the memory,
generate the write command by decrypting the encrypted write command by using the second encryption key,
transmit the encrypted data to the non-volatile memory based on the write command, and
transmit an encrypted completion to the memory, and
wherein the encrypted completion indicates a result of executing the write command.
16 . The computing device of claim 15 , wherein the first encryption key is a dedicated encryption key used inside the processor, and
the second encryption key is a common encryption key used in the processor and in the storage controller.
17 . The computing device of claim 16 , wherein the processor is further configured to set the second encryption key to be different from the first encryption key and transmit the second encryption key to the storage device.
18 . The computing device of claim 15 , wherein the memory comprises:
a first encrypted area storing the encrypted data; and
a second encrypted area storing an encrypted command and the encrypted completion.
19 . The computing device of claim 18 , wherein the storage controller is further configured to:
generate a completion based on the result of executing the write command, and
generate the encrypted completion by encrypting the completion using the second encryption key.
20 . The computing device of claim 19 , wherein the storage controller is further configured to write the encrypted completion into the second encrypted area of the memory.