IP Library Granted Patent US 11,726,672
Granted Patent B2
US 11,726,672 · App. 17/505,064 · Granted Aug 15, 2023

Operating method of storage device setting secure mode of command, and operating method of storage system including the storage device

Inventors: Daejin Jung (Suwon-si, KR); Dong-Min Kim (Hwaseong-si, KR); Jeong-Woo Park (Hwaseong-si, KR); Kyoung Back Lee (Hwaseong-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F3/0622G06F3/064G06F3/0629G06F3/0659G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,726,672
App. No.
17/505,064
Filed
Oct 19, 2021
Granted
Aug 15, 2023
Kind
B2
Art Unit
2136
USPC
711/163
Abstract

Provided is a storage device which communicates with a host device and configured to set a secure mode of a plurality of commands different in kind. An operating method of the storage device includes receiving a secure request indicating a protection of a first command and a protection of a second command of the plurality of commands, from the host device; setting a secure mode of the first and second commands, based on the secure request; receiving a first request indicating a request to execute the first command, from the host device; outputting a first response indicating failure of the first command to the host device, based on the first request; receiving a second request indicating a request to execute the second command, from the host device; and outputting a second response indicating failure of the second command to the host device, based on the second request.

Claims (79)

1. A method of operating a storage device to set a secure mode of a plurality of commands, the method comprising:

receiving a secure request indicating a protection of a first command and a protection of a second command, from a host device configured to communicate with the storage device, the first command and the second command being different in kind;

setting secure modes of the first command and the second command, based on the secure request;

receiving a first request indicating a request to execute the first command, from the host device;

outputting a first response indicating a failure of the first command to the host device, based on the first request;

receiving a second request indicating a request to execute the second command, from the host device; and

outputting a second response indicating a failure of the second command to the host device, based on the second request,

wherein a data field of the secure request includes a secure command protect configuration block, and

wherein the secure command protect configuration block includes an index, the index indicating a range in which the secure modes of the first command and the second command are to be set and whether the range to be set is in a unit corresponding to a logical block address (LBA), a logical unit (LU), or a memory type.

2. The method of claim 1 , wherein the secure request is based on a request message of a replay protect memory block (RPMB) message of a universal flash storage (UFS) standard, and the secure request supports a secure command protect configuration block (SCPCB).

3. The method of claim 1 , wherein the first command is one of a read command, a write command, a purge command, and an unmap command, and

wherein the second command is another one of the read command, the write command, the purge command, and the unmap command.

4. The method of claim 1 , wherein the secure request further indicates a protection of the first command in a first logical block address (LBA) and a non-protection of the first command in a second LBA different from the first LBA, and

wherein the first request further indicates a request to execute the first command in the first LBA.

5. The method of claim 4 , further comprising:

receiving a third request indicating a request to execute the first command in the second LBA, from the host device; and

executing the first command in the second LBA, based on the third request.

6. The method of claim 4 , wherein the secure request further indicates a non-protection of the second command in the first LBA and a protection of the second command in the second LBA,

wherein the second request further indicates a request to execute the second command in the second LBA, and

wherein the method further comprises:

receiving a fourth request indicating a request to execute the second command in the first LBA, from the host device; and

executing the second command in the first LBA, based on the fourth request.

7. The method of claim 1 , wherein the secure request further indicates a protection of the first command and a protection of the second command in a plurality of LBAs included in a first logical unit (LU),

wherein the first request further indicates a request to execute the first command in at least part of the plurality of LBAs, and

wherein the second request further indicates a request to execute the second command in at least part of the plurality of LBAs.

8. The method of claim 1 , wherein the secure request further indicates a protection of the first command in a plurality of first LBAs included in a first LU and a plurality of second LBAs included in a second LU and a protection of the second command in the plurality of first LBAs included in the first LU and the plurality of second LBAs included in the second LU,

wherein the first LU and the second LU are included in the same memory type,

wherein the first request further indicates a request to execute the first command in at least part of the plurality of first LBAs and the plurality of second LBAs, and

wherein the second request further indicates a request to execute the second command in at least part of the plurality of first LBAs and the plurality of second LBAs.

9. The method of claim 1 , wherein a request message type field of the secure request indicates a secure command protect configuration block write request.

10. The method of claim 9 , wherein the secure command protect configuration block further includes:

a secure command protect entry indicating whether to protect the first command and whether to protect the second command.

11. The method of claim 1 , wherein the index includes one of:

a first index code value indicating an LBA protection operation;

a second index code value indicating an LU protection operation; and

a third index code value indicating a memory type protection operation.

12. The method of claim 10 , wherein the secure command protect entry includes:

a command protect flag indicating whether to protect the first command and whether to protect the second command; and

a command protect type that defines a type of controlling the command protect flag.

13. The method of claim 12 , wherein the command protect type includes one of:

a first command protect type code value indicating that code values of an existing command protect flag are maintained after a power cycle or a hardware reset;

a second command protect type code value indicating that each of the code values of the command protect flag are set to a first code value after the power cycle or the hardware reset; and

a third command protect type code value indicating that each of the code values of the command protect flag are set to a second code value after the power cycle or the hardware reset.

14. The method of claim 12 , wherein the command protect flag includes a plurality of command fields respectively corresponding to the plurality of commands and each of the plurality of command fields indicating whether to protect a corresponding command,

wherein each of the plurality of command fields includes a first code value indicating an enabling of a secure mode of the corresponding command or a second code value indicating a disabling of the secure mode of the corresponding command,

wherein a first command field corresponding to the first command from among the plurality of command fields includes the first code value, and

wherein a second command field corresponding to the second command from among the plurality of command fields includes the first code value.

15. A method of operating a storage device to set a secure mode in a plurality of logical units (LUs), the method comprising:

receiving a secure request indicating a protection of a first command in a first LU and a second LU of the plurality of LUs, from a host device configured to communicate with the storage device;

setting a secure mode of the first command in the first LU and the second LU, based on the secure request;

receiving a first request indicating a request to execute the first command in the first LU, from the host device;

outputting a first response indicating a failure of the first command in the first LU to the host device, based on the first request;

receiving a second request indicating a request to execute the first command in the second LU, from the host device; and

outputting a second response indicating a failure of the first command in the second LU to the host device, based on the second request,

wherein a data field of the secure request includes a secure command protect configuration block, and

wherein the secure command protect configuration block includes an index, the index indicating a range in which the secure mode of the first command is to be set and whether the range to be set is in a unit corresponding to a logical block address (LBA), a logical unit (LU), or a memory type.

16. The method of claim 15 , further comprising:

receiving a third request indicating a request to execute the first command in a third LU of the plurality of LUs, from the host device; and

executing the first command in the third LU, based on the third request, and

wherein the first LU and the second LU are included in a first memory type, and the third LU is included in a second memory type.

17. The method of claim 15 , wherein the secure request further indicates a protection of a second command in the first LU and the second LU, and

wherein the setting the secure mode includes:

setting the secure mode of the first command and a secure mode of the second command in the first LU and the second LU, based on the secure request.

18. The method of claim 17 , wherein the first command is one of a read command, a write command, a purge command, and an unmap command, and

wherein the second command is another one of the read command, the write command, the purge command, and the unmap command.

19. A method of operating a storage system, which includes a host device and a storage device configured to communicate with the host device, to set a secure mode of a plurality of commands, the method comprising:

generating, by the host device, a secure request indicating a protection of a first command in a first logical block address (LBA) and a protection of a second command in a second LBA, the first command and the second command being different in kind;

setting, by the storage device, a secure mode based on the secure request;

generating, by the host device, a first request indicating a request to execute the first command in the first LBA;

generating, by the storage device, a first response indicating a failure of the first command, based on the first request;

generating, by the host device, a second request indicating a request to execute the second command in the second LBA; and

generating, by the storage device, a second response indicating a failure of the second command, based on the second request,

wherein a data field of the secure request includes a secure command protect configuration block, and

wherein the secure command protect configuration block includes an index, the index indicating a range in which the secure modes of the first command and the second command are to be set and whether the range to be set is in a unit corresponding to a logical block address (LBA), a logical unit (LU), or a memory type.

20. The method of claim 19 , further comprising:

generating, by the host device, a third request indicating a request to execute the first command in the second LBA;

executing, by the storage device, the first command in the second LBA, based on the third request;

generating, by the host device, a fourth request indicating a request to execute the second command in the first LBA; and

executing, by the storage device, the second command in the first LBA, based on the fourth request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2021
From: JUNG, DAEJIN; KIM, DONG-MIN; PARK, JEONG-WOO; LEE, KYOUNG BACK
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 057836/0884 →
Priority Claims (2)
KR 10-2020-0183559 · Dec 24, 2020 · national
KR 10-2021-0063018 · May 14, 2021 · national
Continuity (1)
Related Publication 20220206693A1 · Jun 30, 2022