IP Library › Granted Patent US 12,380,225
Granted Patent B2
US 12,380,225 · App. 17/692,458 · Granted Aug 5, 2025

Storage device, host device and data transfer method thereof

Inventors: Youngsik Moon (Suwon-si, KR); Jiyoup Kim (Seoul, KR); Hongrak Son (Anyang-si, KR); Dongmin Shin (Seoul, KR); Junho Shin (Suwon-si, KR); Jaehun Jang (Hwaseong-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F21/602G06F13/1673G06F21/79H04L9/008H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,225
App. No.
17/692,458
Granted
Aug 5, 2025
Kind
B2
Abstract

A method of transmitting data in a storage device includes encrypting original data based on a homomorphic encryption algorithm to generate encrypted data, generating a parameter for regeneration of a ciphertext higher than an operation level of the encrypted data by using the encrypted data and a key value, and transmitting the encrypted data and the parameter to an external host device.

Claims (35)

1. A method of transmitting data in a storage device, the method comprising:

encrypting original data based on a homomorphic encryption algorithm to generate a first ciphertext, wherein the first ciphertext comprises a first operation level;

generating a parameter by using the first ciphertext and a key value,

wherein the key value is generated by performing a multiplication operation on a private key and a public key of the storage device; and

transmitting the first ciphertext and the parameter to a ciphertext regenerator of an external host device,

wherein the ciphertext regenerator generates one or more second ciphertexts having a second operation level, and wherein the second operation level of the one or more second ciphertexts is higher than the first operation level of the first ciphertext.

2. The method of claim 1 , wherein the homomorphic encryption algorithm is a fully homomorphic encryption algorithm, and the first ciphertext is a ciphertext of a first operation level incapable of performing ciphertext operations multiple times.

3. The method of claim 1 , wherein the encrypting comprises performing a multiplication operation on a private key of the storage device and a public key of the storage device to generate data of the multiplication operation.

4. The method of claim 3 , wherein the encrypting further comprises performing an addition operation on the original data, data of the multiplication operation, and a first random value.

5. The method of claim 3 , wherein the encrypting further comprises determining a magnitude of the original data.

6. The method of claim 5 , wherein the encrypting further comprises shifting a first random value by bits corresponding to the determined magnitude to generate a shifted first random value.

7. The method of claim 6 , wherein the encrypting further comprises performing an addition operation on the original data, data of the multiplication operation, and the shifted first random value.

8. The method of claim 1 , wherein a number of public keys of the storage device corresponds to the number of operation levels of a ciphertext corresponding to the number of possible operations of the ciphertext.

9. The method of claim 1 , wherein the parameter is transmitted to the host device only once, when encrypting and transmitting a plurality of original data.

10. The method of claim 9 , wherein the generating of the parameter comprises, determining an operation level of the one or more second ciphertexts; and generating the parameter according to the determined operation level.

11. A storage device comprising:

at least one non-volatile memory device; and a controller configured to control the at least one non-volatile memory device, wherein the controller includes control pins providing control signals to the at least one non-volatile memory device,

a security module configured to perform a homomorphic encryption operation,

a buffer memory configured to temporarily store data required for the homomorphic encryption operation, and

at least one processor configured to control an overall operation of the controller,

and wherein the security module encrypts original data into a first ciphertext of a first operation level based on a homomorphic encryption algorithm,

and generates a parameter using the first ciphertext and a key value, where the first ciphertext and the parameter are used regenerate one or more second ciphertexts having a second operation level, wherein the second operation level of the one or more second ciphertexts is higher than the first operation level of the first ciphertext,

and wherein the key value is generated by performing a multiplication operation on a private key and a public key of the storage device.

12. The storage device of claim 11 , wherein the security module performs a Self Encryption Disk (SED) function or a Trusted Computing Group (TCG) security function.

13. The storage device of claim 11 , wherein the security module determines a number of possible operations of the one or more second ciphertexts, and generates the parameter corresponding to the determined number of possible operations.

14. The storage device of claim 11 , wherein the parameter is generated using a private key of the storage device and a public key of the storage device.

15. The storage device of claim 11 , wherein the homomorphic encryption algorithm is one of a CKKS homomorphic algorithm and a BGV homomorphic algorithm.

16. A method of operating a host device, comprising:

receiving a first ciphertext and a parameter from a storage device, wherein the first ciphertext and the parameter having a first operation level;

regenerating, using the first ciphertext and the parameter, respective one or more second ciphertexts having a second operation level, wherein the second operation level of the one or more second ciphertexts is higher than the first operation level of the first ciphertext; and

performing a ciphertext operation using the regenerated one or more second ciphertexts.

17. The method of claim 16 , further comprising selecting one of a plurality of operation levels based on the parameter.

18. The method of claim 17 , wherein the regenerating of the one or more second ciphertexts includes generating a second ciphertext among the plurality of second ciphertexts corresponding to the selected operation level.

19. The method of claim 16 , wherein the parameter is homomorphically encrypted and received at the same operation level as an operation level of the first ciphertext.

20. The method of claim 16 , further comprising transmitting a value of the ciphertext operation to the storage device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2022
From: MOON, YOUNGSIK; KIM, JIYOUP; SON, HONGRAK; SHIN, DONGMIN; SHIN, JUNHO; JANG, JAEHUN
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 059279/0073 →
Priority Claims (1)
KR 10-2021-0102583 · Aug 4, 2021 · national
Continuity (1)
Related Publication 20230044214A1 · Feb 9, 2023
References Cited (37)
US 7679133B2 · Son et al. · 2010 [cited by applicant]
US 8553466B2 · Han et al. · 2013 [cited by applicant]
US 8559235B2 · Yoon et al. · 2013 [cited by applicant]
US 8654587B2 · Yoon et al. · 2014 [cited by applicant]
US 9331851B2 · Youn et al. · 2016 [cited by applicant]
US 9536970B2 · Seol et al. · 2017 [cited by applicant]
US 10075289B2 · Laine · 2018 [cited by examiner]
US 10211975B2 · Loftus et al. · 2019 [cited by applicant]
US 20100211787A1 · Bukshpun · 2010 [cited by examiner]
US 20140177828A1 · Loftus · 2014 [cited by examiner]
US 20140233727A1 · Rohloff et al. · 2014 [cited by applicant]
US 20140310527A1 · Veugen · 2014 [cited by examiner]
US 20160241389A1 · Le Saint · 2016 [cited by examiner]
US 20170147835A1 · Bacon · 2017 [cited by examiner]
US 20180375640A1 · Laine · 2018 [cited by examiner]
US 20190363872A1 · Shim · 2019 [cited by examiner]
US 20190394019A1 · Gao · 2019 [cited by applicant]
US 20210111864A1 · Gentry et al. · 2021 [cited by applicant]
US 20210119766A1 · Suresh et al. · 2021 [cited by applicant]
US 20210376996A1 · Moon et al. · 2021 [cited by applicant]
US 20220094521A1 · Moon et al. · 2022 [cited by applicant]
US 20230361985A1 · Raheman · 2023 [cited by examiner]
US 20230396409A1 · Joye · 2023 [cited by examiner]
US 20240022395A1 · Hoshizuki · 2024 [cited by examiner]
JP 2010141618A · 2010 [cited by applicant]
JP 2016090884A · 2016 [cited by applicant]
KR 101677114B1 · 2016 [cited by applicant]
KR 1020180013064A · 2018 [cited by applicant]
KR 102040106B1 · 2019 [cited by applicant]
KR 1020210147645A · 2021 [cited by applicant]
KR 1020220040309A · 2022 [cited by applicant]
Kim, Bongjun, et al. “Compiler-Assisted Semantic-Aware Encryption for Efficient and Secure Serverless Computing.” IEEE Internet of Things Journal, vol. 8, No. 7, pp. 5645-5656, Apr. 1, 2021. [cited by applicant]
Chillotti, Ilaria, et al. “TFHE: fast fully homomorphic encryption over the torus.” Journal of Cryptology 33.1, pp. 34-91, Apr. 25, 2019. [cited by applicant]
Mkhinini, Asma, et al. “HLS design of a hardware accelerator for homomorphic encryption.” 2017 IEEE 20th International Symposium on Design and Diagnostics of Electronic Circuits & Systems (DDECS). IEEE, Apr. 21, 2017. [cited by applicant]
Extended European Search Report dated Oct. 5, 2022 for corresponding European Application No. 22168764.3. [cited by applicant]
I. Chillotti, et al. ‘Faster Packed Homomorphic Operations and Efficient Circuit Bootstrapping for TFHE’ [cited by applicant]
Z. Brakerski, et al. ‘(Leveled) Fully Homomorphic Encryption without Bootstrapping’ [cited by applicant]
Cited By (1)
US 12,603,756