IP Library › Granted Patent US 8,874,917
Granted Patent B2
US 8,874,917 · App. 13/731,574 · Granted Oct 28, 2014

Storage system in which fictitious information is prevented

Inventors: Yuji Nagai (Sagamihara, JP); Yasufumi Tsumagari (Kawasaki, JP); Shinichi Matsukawa (Tokyo, JP); Hiroyuki Sakamoto (Ome, JP); Hideki Mimura (Yokohama, JP)
Assignee: Kabushiki Kaisha Toshiba
G06F12/1408G06F12/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,874,917
App. No.
13/731,574
Granted
Oct 28, 2014
Kind
B2
Abstract

According to one embodiment, a storage system includes a host device and a secure storage. The host device and the secure storage produce a bus key which is shared only by the host device and the secure storage by authentication processing, and which is used for encoding processing. The host device produces a message authentication code including a message which can be stored in the secure storage based on the bus key, and sends the produced message authentication code to the secure storage. The secure storage stores the message included in the message authentication code in accordance with instructions of the host device. The host device verifies whether the message stored in the secure storage is intended contents.

Claims (36)

1. A storage system comprising:

a host device; and

a secure storage including:

a memory provided with a protected first storing region which stores secret information sent from the host device, and a second storing region which stores encoded contents; and

a controller configured to carry out authentication processing for accessing the first storing region, wherein

the host device and the secure storage produce a bus key which is shared only by the host device and the secure storage by the authentication processing, and which is used for encoding processing when information is sent and received between the host device and the secure storage,

the host device produces a message authentication code including a message which can be stored in the secure storage based on the bus key in a state where the authentication processing is completed, and sends the produced message authentication code to the secure storage,

the secure storage stores the message included in the message authentication code in accordance with instructions of the host device, and

the host device verifies whether the message stored in the secure storage is intended contents.

2. The system according to claim 1 , wherein

when the host device sends the message authentication code, the host device sends, to the secure storage, a flag indicative of whether the message should be stored in the secure storage.

3. The system according to claim 2 , wherein

the message includes a message body and an identifier configured to identify a format of the message body.

4. The system according to claim 1 , wherein

the host device measures time elapsed until a reply from the secure storage is received after the message authentication code including the message is sent to the secure storage.

5. A storage control method comprising:

producing a bus key which is shared only by a host device and a secure storage by authentication processing, and which is used for encoding processing when information is sent and received between the host device and the secure storage,

producing a message authentication code by the host device including a message which can be stored in the secure storage based on the bus key, in a state where the authentication processing is completed, and sending, by the host device, the produced message authentication code to the secure storage,

storing the message included in the message authentication code by the secure storage in accordance with instructions of the host device, and

verifying whether the message stored in the secure storage is intended contents by the host device.

6. The method according to claim 5 , wherein

when the host device sends the message authentication code, the host device sends, to the secure storage, a flag indicative of whether the message should be stored in the secure storage.

7. The method according to claim 6 , wherein

the message includes a message body and an identifier configured to identify a format of the message body.

8. The method according to claim 5 , wherein

the host device measures time elapsed until a reply from the secure storage is received after the message authentication code including the message is sent to the secure storage.

9. A storage system comprising:

a host device; and

a secure storage including:

a memory provided with a protected first storing region which stores secret information sent from the host device, and a second storing region which stores encoded contents; and

a controller configured to carry out authentication processing for accessing the first storing region, wherein

the host device and the secure storage produce a bus key which is shared only by the host device and the secure storage by the authentication processing, and which is used for encoding processing when information is sent and received between the host device and the secure storage,

the host device produces a message, and sends the produced message to the secure storage,

the secure storage stores the message in accordance with instructions of the host device, and

the secure storage sends the stored message with a message authentication code produced based on the bus key in a state where the authentication processing is completed, and

the host device verifies whether the message stored in the secure storage is intended contents.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2012
From: NAGAI, YUJI; TSUMAGARI, YASUFUMI; MATSUKAWA, SHINICHI; SAKAMOTO, HIROYUKI; MIMURA, HIDEKI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 029547/0527 →
Priority Claims (2)
JP 2012-166403 · Jul 26, 2012 · national
JP 2012-229623 · Oct 17, 2012 · national
Continuity (2)
Continuation In Part 13623318 · Sep 20, 2012
Related Publication 20140032934A1 · Jan 30, 2014