IP Library › Granted Patent US 11,423,182
Granted Patent B2
US 11,423,182 · App. 17/213,756 · Granted Aug 23, 2022

Storage device providing function of securely discarding data and operating method thereof

Inventors: Brian Myungjune Jung (Suwon-si, KR); Daeok Kim (Yongin-si, KR); Moonwook Oh (Seoul, KR); Hyunsook Hong (Hwaseong-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F21/79G06F3/0652G06F21/78G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,423,182
App. No.
17/213,756
Granted
Aug 23, 2022
Kind
B2
Abstract

A storage device providing a function of securely discarding data and an operating method of the storage device are provided. The storage device includes a safety pin device removably mounted on the storage device, the safety pin device configured to store first encrypted information and second encrypted information, the first encrypted information encrypted using a first key associated with a first user, and the second encrypted information encrypted using a second key associated with a second user, security circuitry configured to, receive the first encrypted information from the safety pin device, decrypt the first encrypted information, and generate a data encryption key based on results of the decrypting the first encrypted information, and a nonvolatile memory configured to store data encrypted with the data encryption key.

Claims (63)

1. A storage device storing data, the storage device comprising:

a safety pin device removably mounted on the storage device, the safety pin device configured to store first encrypted information and second encrypted information, the first encrypted information encrypted using a first key associated with a first user, and the second encrypted information encrypted using a second key associated with a second user;

security circuitry configured to,

receive the first encrypted information from the safety pin device,

decrypt the first encrypted information, and

generate a data encryption key based on results of the decrypting the first encrypted information; and

a nonvolatile memory configured to store data encrypted with the data encryption key, wherein

the first encrypted information is generated by encrypting first unique information associated with the storage device and second unique information associated with the second user using the first key,

the second encrypted information is generated by encrypting the first unique information and the second unique information using the second key, and

the second encrypted information is used to determine whether the storage device has been properly discarded.

2. The storage device of claim 1 , wherein the storage device includes at least a solid state drive.

3. The storage device of claim 1 , wherein the second encrypted information is generated by the second user and stored in the safety pin device.

4. The storage device of claim 1 , wherein the first unique information includes a unique identifier corresponding to the storage device, and the second unique information includes a personal identification number associated with the second user.

5. The storage device of claim 1 , wherein the security circuitry is further configured to:

store the first key and a unique identifier corresponding to the storage device;

perform the decrypting of the first encrypted information using the first key;

extract the first unique information from the decrypted first encrypted information; and

authenticate the safety pin device based on the unique identifier corresponding to the storage device and the extracted first unique information.

6. The storage device of claim 5 , wherein

the security circuitry and the safety pin device are each further configured to connect to safety pin creation circuitry; and

the safety pin creation circuitry is caused to,

perform a setting operation on the safety pin device,

receive the unique identifier corresponding to the storage device stored in the security circuitry,

generate the first encrypted information and the second encryption information using the unique identifier corresponding to the storage device as the first unique information, and

transmit the generated first encrypted information and the generated second encrypted information to the safety pin device.

7. The storage device of claim 1 , wherein

the safety pin device includes an interface circuit configured to communicate with a safety pin tester device; and

the safety pin device is further configured to transmit the second encrypted information to the safety pin tester device through the interface circuit in a state where the safety pin device has been removed from the storage device.

8. The storage device of claim 7 , wherein the second encrypted information is generated by encrypting information identical to unique information corresponding to the second user stored in the safety pin tester device.

9. The storage device of claim 1 , further comprising:

a storage circuit configured to store third encrypted information generated by encrypting the data encryption key with a third key; and

wherein the security circuitry is further configured to,

derive the third key using, as an input, information extracted from the first encrypted information, and

generate the data encryption key by decrypting the third encrypted information using the third key.

10. The storage device of claim 9 , wherein the security circuitry is further configured to encrypt and/or decrypt the second user's data using the data encryption key.

11. A safety pin device removably mounted on at least one storage device configured to store data, the safety pin device comprising:

at least one storage circuit configured to store first encrypted information and second encrypted information, the first encrypted information encrypted using a first key, and the second encrypted information encrypted using a second key; and

a first interface circuit configured to output the second encrypted information to allow a second user to determine whether the storage device has been properly discarded after the safety pin device is removed from the storage device, wherein

the first encrypted information is generated by encrypting first unique information associated with the at least one storage device and second unique information associated with the second user using the first key,

the second encrypted information is generated by encrypting the first unique information and the second unique information using the second key, and

the second encrypted information is used to determine whether the storage device has been properly discarded.

12. The safety pin device of claim 11 , wherein

the first interface circuit is further configured to connect to a second user safety pin tester device associated with the second user; and

the second user safety pin tester device is configured to store the second key, and

receive the second encrypted information.

13. The safety pin device of claim 11 , wherein

the first interface circuit is further configured to connect to a first user safety pin tester device associated with a first user; and

the first user safety pin tester device is configured to store the first key, and

receive the first encrypted information to allow the first user to determine whether the storage device has been properly discarded.

14. The safety pin device of claim 11 , wherein

the first unique information associated with the at least one storage device is a unique identifier associated with the at least one storage device, and

the second unique information associated with the second user is a personal identification number associated with the second user.

15. The safety pin device of claim 14 , wherein the second encrypted information is generated by encrypting the unique identifier associated with the at least one storage device and the personal identification number using the second key.

16. The safety pin device of claim 15 , wherein the safety pin device is further configured to:

connect to safety pin creation circuitry external to the safety pin device; and

receive the first encrypted information from the safety pin creation circuitry.

17. The safety pin device of claim 15 , wherein the safety pin device is further configured to:

connect to safety pin creation circuitry external to the safety pin device; and

receive the second encrypted information through the safety pin creation circuitry.

18. The safety pin device of claim 11 , further comprising:

at least one second interface circuit configured to,

communicate with security circuitry included in the storage device; and

provide the first encrypted information to the security circuitry to enable the storage device to generate a data encryption key used for data encryption and/or decryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2021
From: JUNG, BRIAN MYUNGJUNE; KIM, DAEOK; OH, MOONWOOK
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 055791/0854 →
Priority Claims (1)
KR 10-2020-0051831 · Apr 28, 2020 · national
Continuity (1)
Related Publication 20210334416A1 · Oct 28, 2021