IP Library › Granted Patent US 9,721,113
Granted Patent B2
US 9,721,113 · App. 14/657,006 · Granted Aug 1, 2017

Host controller and system-on-chip

Inventors: Ju-Hee Park (Seoul, KR); Seok-Min Park (Suwon-si, KR); Dong-Jin Park (Seoul, KR); Heon-Soo Lee (Hwaseong-si, KR); Hong-Mook Choi (Bucheon-si, KR); Sang-Hyun Park (Seoul, KR)
Assignee: Samsung Electronics Co., Ltd.
G06F21/6218G06F21/72G06F21/805G06F21/85G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,721,113
App. No.
14/657,006
Granted
Aug 1, 2017
Kind
B2
Abstract

A host controller that controls a storage device includes an encryption unit that is selectively configured in response to file encryption information and disk encryption information to encrypt data. The encryption unit encrypts the data using a file encryption operation based on the file encryption information and/or a disk encryption operation based on the disk encryption information.

Claims (44)

1. A host controller that receives a command from a processor and controls operation of a storage device in response to the command, the host controller comprising:

a system memory interface that communicates with a system memory;

a storage interface that communicates with the storage device; and

a controller configured to extract file encryption information and disk encryption information from the command and control operation of an encryption unit,

the encryption unit configured to receive data from the system memory via the system interface for storage in the storage device via the storage interface, and further configured in response to the file encryption information and the disk encryption information to selectively encrypt the data received from the system memory or not encrypt the data,

wherein the encryption unit is configured to selectively encrypt the data using a file-encryption operation based on the file encryption information, a disk encryption operation based on the disk encryption information, or an encryption operation including both the file encryption operation and the disk encryption operation, and

wherein the controller is configured to control the encryption unit to encrypt the data using the encryption operation including both the file encryption operation and the disk encryption operation when the file encryption information indicates that the file encryption operation is to be performed and the disk encryption information indicates that the disk encryption operation is to be performed.

2. The host controller of claim 1 , wherein the controller is configured to control the encryption unit to not encrypt the data when the file encryption information indicates that the file encryption operation is not to be performed and the disk encryption information indicates that the disk encryption operation is not to be performed.

3. The host controller of claim 1 , wherein the controller is configured to control the encryption unit to encrypt the data using only the file encryption operation when the file encryption information indicates that the file encryption operation is to be performed and the disk encryption information indicates that the disk encryption operation is not to be performed.

4. The host controller of claim 1 , wherein the controller is configured to control the encryption unit to encrypt the data using only the disk encryption operation when the file encryption information indicates that the file encryption operation is not to be performed and the disk encryption information indicates that the disk encryption operation is to be performed.

5. The host controller of claim 1 , wherein the command includes a physical region description table (PRDT) characterizing the data received from the system memory.

6. The host controller of claim 5 , wherein the PRDT comprises:

a data base address field indicating an address for the data received from the system memory;

a data byte count field indicating a number of bytes of the data;

a disk algorithm selector field indicating whether or not the disk encryption operation is to be performed; and

a file algorithm selector field indicating whether or not the file encryption operation is to be performed.

7. The host controller of claim 6 , wherein the disk algorithm selector field further indicates a type of encryption algorithm used during the disk encryption operation, and

the file algorithm selector field further indicates a type of encryption algorithm used during the file encryption operation.

8. The host controller of claim 6 , wherein the PRDT further comprises a disk key length (DKL) field indicating a length of an encryption key used during the disk encryption operation, and a disk initialization vector (Disk IV) field indicating an initialization vector used during the disk encryption operation.

9. The host controller of claim 6 , wherein the PRDT comprises a file key length (FKL) field indicating a length of an encryption key used during the file encryption operation, a file initialization vector (File IV) field indicating an initialization vector used during the file encryption operation, a file encryption key field indicating an encryption key used during the file encryption operation, and a file tweak key field indicating a tweak key used during the file encryption operation.

10. A host controller that receives a command from a processor and controls operation of a storage device in response to the command, the host controller comprising:

a system memory interface that communicates with a system memory;

a storage interface that communicates with the storage device;

a controller configured to extract file encryption information and disk encryption information from the command and control operation of an encryption unit,

the encryption unit configured to receive data from the system memory via the system interface for storage in the storage device via the storage interface, and further configured in response to the file encryption information and the disk encryption information to selectively encrypt the data received from the system memory or not encrypt the data,

wherein the encryption unit is configured to encrypt the data using at least one of a file encryption operation and a disk encryption operation, wherein the file encryption operation is based on the file encryption information and the disk encryption operation is based on the disk encryption information,

the encryption unit comprises a first encryption engine configured to perform the file encryption operation or the disk encryption operation, a second encryption engine configured to perform the file encryption operation or the disk encryption operation, and a data path forming unit configured to form a data path between the system memory interface and the storage interface, and

the first encryption engine and second encryption engine are connectable in series using the data path forming unit to perform the file encryption operation and the disk encryption operation, and

wherein the controller is configured to control the encryption unit to encrypt the data using both the file encryption operation and the disk encryption operation when the file encryption information indicates that the file encryption operation is to be performed and the disk encryption information indicates that the disk encryption operation is to be performed.

11. The host controller of claim 10 , wherein the controller is configured to control the encryption unit to encrypt the data using only the file encryption operation when the file encryption information indicates that the file encryption operation is to be performed and the disk encryption information indicates that the disk encryption operation is not to be performed, and

the first encryption engine and second encryption engine are connected in parallel using the data path forming unit to perform the file encryption operation.

12. The host controller of claim 10 , wherein the controller is configured to control the encryption unit to encrypt the data using only the disk encryption operation when the file encryption information indicates that the file encryption operation is not to be performed and the disk encryption information indicates that the disk encryption operation will be performed, and

the first encryption engine and second encryption engine are connected in parallel using the data path forming unit to perform the disk encryption operation.

13. The host controller of claim 10 , wherein the file encryption operation is first performed on the data using the first encryption engine to generate file-encrypted data, and the disk encryption operation is subsequently performed on the file-encrypted data using the second encryption engine.

14. The host controller of claim 10 , wherein the disk encryption operation is first performed on the data using the first encryption engine to generate disk-encrypted data, and the file encryption operation is subsequently performed on the disk-encrypted data using the second encryption engine.

15. A system-on-chip comprising: a processor providing a command to a host controller that controls a storage device in response to the command, wherein the host controller comprises:

a system memory interface that communicates with a system memory;

a storage interface that communicates with the storage device; and

a controller configured to extract file encryption information and disk encryption information from the command and control operation of an encryption unit;

the encryption unit configured to receive data from the system memory via the system interface for storage in the storage device via the storage interface, and further configured in response to the file encryption information and the disk encryption information to selectively encrypt the data received from the system memory or not encrypt the data,

wherein the encryption unit is configured to selectively encrypt the data using a file encryption operation based on the file encryption information, a disk encryption operation based on the disk encryption information, or an encryption operation including both the file encryption operation and the disk encryption operation, and

wherein the command includes a physical region description table (PRDT) characterizing the data received from the system memory, and the PRDT comprises a data base address field indicating an address for the data received from the system memory, a data byte count field indicating a number of bytes of the data, a disk algorithm selector field indicating whether or not the disk encryption operation is to be performed, and a file algorithm selector field indicating whether or not the file encryption operation is to be performed.

16. The system-on-chip of claim 15 , wherein the disk algorithm selector field further indicates a type of encryption algorithm used during the disk encryption operation, and the file algorithm selector field further indicates a type of encryption algorithm used during the file encryption operation.

17. The system-on-chip of claim 15 , wherein the storage device is one of a universal flash storage (UFS), a memory card, a solid state drive (SSD) and a hard disk drive (HDD).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2015
From: PARK, JU-HEE; KIM, SEOK-MIN; PARK, DONG-JIN; LEE, HEON-SOO; CHOI, HONG-MOOK; PARK, SANG-HYUN
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 035167/0055 →
Priority Claims (1)
KR 10-2014-0075099 · Jun 19, 2014 · national
Continuity (1)
Related Publication 20150371055A1 · Dec 24, 2015