IP Library › Granted Patent US 8,516,264
Granted Patent B2
US 8,516,264 · App. 12/768,058 · Granted Aug 20, 2013

Interlocking plain text passwords to data encryption keys

Inventors: Jeffrey L. Munsil (Fort Collins, CO); Jeffrey L Williams (Rochester, MN)
Assignee: LSI Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,516,264
App. No.
12/768,058
Granted
Aug 20, 2013
Kind
B2
Abstract

Described embodiments provide for authenticating a user request for access to at least a portion of an encrypted storage device. First, the request for access to at least a portion of the encrypted storage device is received. The request includes a plaintext password. A hash module generates a hashed version of the received plaintext password based on an authentication hash key. A hashed value of the generated plaintext password is retrieved from a key storage. A hash comparator compares the hashed version of the received plaintext password with the retrieved hashed value of the generated plaintext password. If the hashed version of the received plaintext password and the retrieved hashed value of the generated plaintext password are equal, the user is authenticated for access to at least a portion of the encrypted storage device. Otherwise, the user is denied access to the encrypted storage device.

Claims (61)

1. A method of authenticating a user request for access to at least a portion of an encrypted storage device, the method comprising:

generating a unique password for authenticating a user for access to the encrypted storage device by the steps of:

generating, by a random number generator: i) a root key to encrypt and decrypt data; ii) a maker's password to generate other passwords; iii) an authentication hash key to generate hashed values of plaintext passwords; and iv) a random data key corresponding to the unique authentication hash key, wherein the root key is stored in a one-time programmable memory in an access control system of an encryption module and not accessible outside of the access control system;

generating, by the encryption module, an encrypted data key based on the random data key, the authentication hash key and the root key;

generating, by the encryption module, a unique plaintext password for the user based on a random number and the encrypted data key;

generating, by a hash module, a hashed value of the generated plaintext password based on the authentication hash key;

storing the hashed value of the plaintext password and the corresponding encrypted data key to a key storage; and

providing the plaintext password to the user;

receiving the request for access to at least a portion of the encrypted storage device, the request including the plaintext password;

generating, by the hash module, a hashed version of the received plaintext password based on the authentication hash key;

retrieving, from the key storage, a hashed value of a generated plaintext password;

comparing, by a hash comparator, the hashed version of the received plaintext password with the retrieved hashed value of the generated plaintext password; and

when the hashed version of the received plaintext password and the retrieved hashed value of the generated plaintext password are equal, authenticating the user for access to at least a portion of the encrypted storage device,

otherwise, denying the user access to the encrypted storage device;

changing the user's plaintext password, by the steps of:

receiving a desired plaintext password for the user;

extracting the authentication hash key and data key from the encrypted data key; and

generating, by the hash module, a hashed version of the desired plaintext password based upon the extracted authentication hash key and the root key.

2. The method of claim 1 , further comprising;

storing, to a key cache, one or more decrypted data keys.

3. The method of claim 1 , wherein the at least a portion of the encrypted storage device corresponds to one or more bands of the encrypted storage device.

4. The method of claim 2 , wherein a user password allows access to at least one corresponding hand of the storage device, and an administrative password allows access to one or more hands of the storage device.

5. The method of claim 1 , wherein the root key, the authentication hash key, the hashed version of the plaintext password and a corresponding unencrypted data key are accessible only within an encryption datapath of the storage device.

6. The method of claim 1 , wherein:

the root key is a pair of 256 hit keys, the plain text password is a 256 bit password, the authentication hash key is a 256 bit key, the random data key is one of a 128, 256 and 512 bit key, and the encrypted data key is one of a 448, 576 and 832 bit key.

7. A non-transitory machine-readable storage medium, having encoded thereon program code, wherein, when the program code is executed by a machine, the machine implements a method of authenticating a user request for access to at least a portion of an encrypted storage device, the method comprising:

generating a unique password for authenticating a user for access to the encrypted storage device by the steps of:

generating, by a random number generator: i) a root key to encrypt and decrypt data; ii) a maker's password to generate other passwords; iii) an authentication hash key to generate hashed values of plaintext passwords; and iv) a random data key corresponding to the unique authentication hash key, wherein the root key is stored in a one-time programmable memory in an access control system of an encryption module and not accessible outside of the access control system;

generating, by the encryption module, an encrypted data key based on the random data key, the authentication hash key and the root key;

generating, by the encryption module, a unique plaintext password for the user based on a random number and the encrypted data key;

generating, by a hash module, a hashed value of the generated plaintext password based on the authentication hash key;

storing the hashed value of the plaintext password and the corresponding encrypted data key to a key storage; and

providing the plaintext password to the user;

receiving the request for access to at least a portion of the encrypted storage device, the request including the plaintext password;

generating, by the hash module, a hashed version of the received plaintext password based on the authentication hash key;

retrieving, from the key storage, a hashed value of a generated plaintext password;

comparing, by a hash comparator, the hashed version of the received plaintext password with the retrieved hashed value of the generated plaintext password; and

when the hashed version of the received plaintext password and the retrieved hashed value of the generated plaintext password are equal, authenticating the user for access to at least a portion of the encrypted storage device,

otherwise, denying the user access to the encrypted storage device;

changing the user's plaintext password, by the steps of:

receiving a desired plaintext password for the user;

extracting the authentication hash key and data key from the encrypted data key; and

generating, by the hash module, a hashed version of the desired plaintext password based upon the extracted authentication hash key and the root key.

8. The non-transitory machine-readable storage medium of claim 7 , further comprising

storing, to a key cache, one or more decrypted data keys.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the at least a portion of the encrypted storage device corresponds to one or more bands of the encrypted storage device.

10. The non-transitory machine-readable storage medium of claim 9 , wherein a user password allows access to at least one corresponding band of the storage device, and an administrative password allows access to one or more bands of the storage device.

11. The non-transitory machine-readable storage medium of claim 7 , wherein the root key, the authentication hash key and the corresponding unencrypted data key are accessible only within an encryption datapath of the storage device.

12. An apparatus for authenticating a user for access to an encrypted storage device, the apparatus comprising:

a random number generator configured to generate: (i) a root key to encrypt and decrypt data; (ii) a maker's password to generate other passwords; (iii) an authentication hash key to generate hashed values of plaintext passwords; and (iv) a random data key corresponding to the unique plaintext password;

an encryption module configured to (i) generate an encrypted data key based on the random data key and the root key; (ii) generate a unique plaintext password for the user based on a random number and the encrypted data key, and (iii) extract the authentication hash key and data key from the encrypted data key, wherein the root key is stored in a one-time programmable memory in an access control system of an encryption module and not accessible outside of the access control system;

a hash module configured to generate (i) a hashed value of the generated plaintext password based on the authentication hash key; and (ii) a hashed version of the received plaintext password based on the authentication hash key;

a key storage configured to store the hashed value of the plaintext password and the corresponding encrypted data key;

a communication link configured to (i) providing the plaintext password to the user; and (ii) receive the request for access to at least a portion of the encrypted storage device, the request including the plaintext password; and

a hash comparator configured to compare the hashed version of the received plaintext password with the hashed value of the generated plaintext password, wherein, when the hashed version of the received plaintext password and the retrieved hashed value of the generated plaintext password are equal, the hash comparator is configured to authenticate the user for access to at least a portion of the encrypted storage device, otherwise, the hash comparator is configured to deny the user access to the encrypted storage device,

wherein the apparatus is configured to change the user's plaintext password, by receiving a desired plaintext password for the user, extracting the authentication hash key and data key from the encrypted data key, and generating, by the hash module, a hashed version of the desired plaintext password based upon the extracted authentication hash key and the root key.

13. The apparatus of claim 12 , further comprising:

a key cache configured to store one or more decrypted data keys.

14. The apparatus of claim 12 , wherein the encrypted storage device comprises one or more bands of the encrypted storage device, wherein a user password allows access to at least one corresponding hand of the storage device, and an administrative password allows access to one or more bands of the storage device.

15. The apparatus of claim 12 , wherein the root key, the authentication hash key and the corresponding unencrypted data key are accessible only within an encryption datapath of the storage device.

16. The apparatus of claim 12 , wherein the apparatus is implemented in a monolithic integrated circuit chip.

Assignments (11)
MERGER Recorded Mar 3, 2023
From: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED; BROADCOM INTERNATIONAL PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 062952/0850 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
To: BROADCOM INTERNATIONAL PTE. LTD.
Reel/Frame 053771/0901 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERROR IN RECORDING THE MERGER IN THE INCORRECT US PATENT NO. 8,876,094 PREVIOUSLY RECORDED ON REEL 047351 FRAME 0384. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 8, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 049248/0558 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE MERGER PREVIOUSLY RECORDED AT REEL: 047230 FRAME: 0910. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047351/0384 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047230/0910 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041710/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037808/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS (RELEASES RF 032856-0031) Recorded Feb 2, 2016
From: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
To: LSI CORPORATION; AGERE SYSTEMS LLC
Reel/Frame 037684/0039 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2015
From: LSI CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 035390/0388 →
PATENT SECURITY AGREEMENT Recorded May 8, 2014
From: LSI CORPORATION; AGERE SYSTEMS LLC
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032856/0031 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: MUNSIL, JEFFREY; WILLIAMS, JEFFREY
To: LSI CORPORATION
Reel/Frame 024293/0891 →
Continuity (4)
Provisional Application 61250055 · Oct 9, 2009
Provisional Application 61250047 · Oct 9, 2009
Provisional Application 61265109 · Nov 30, 2009
Related Publication 20110087890A1 · Apr 14, 2011