IP Library Granted Patent US 12,499,010
Granted Patent B2
US 12,499,010 · App. 18/206,398 · Granted Dec 16, 2025

Cryptographic data integrity protection

Inventors: David Aaron Palmer (Boise, ID); Nadav Grosz (Broomfield, CO); Lance W. Dover (Fair Oaks, CA); Yoav Weinberg (Thornhill, CA)
Assignee: Micron Technology, Inc.
G06F11/1068G06F11/0772G06F11/3037G06F12/0246G06F12/1408G06F13/4221G06F21/64G06F2212/7201
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,010
App. No.
18/206,398
Granted
Dec 16, 2025
Kind
B2
Abstract

A storage device includes a memory storage region and a controller having a processor. The processor retrieves user data from the memory storage region using a physical block address corresponding to a logical block address (LBA), in response to a read command. The retrieved user data includes a first hash received through a host interface in a prior host data transmission. The processor further performs error correction on the user data to generate error-corrected user data. The processor further causes a cryptographic engine to produce a second hash of the error-corrected user data. The first hash is compared to the second hash associated with the error-corrected user data to determine a match result. A notification is generated in response to the match result.

Claims (64)

1 . A storage device that implements cryptographic validity checking, the storage device comprising:

a memory storage region; and

a controller having a processor configured to execute instructions stored on the storage device, wherein the instructions, when executed by the processor, cause the processor to perform operations comprising:

decoding a first write command received from a host to obtain a hash of user data, the hash generated based on a cryptographic key that is common between the host and the storage device;

decoding a second write command received from the host after the first write command, to obtain the user data associated with the hash;

retrieving hash metadata based on the hash, the hash metadata indicating a first storage address of the memory storage region;

storing the user data at the first storage address of the memory storage region; and

storing the hash with the hash metadata at a second storage address of the memory storage region.

2 . The storage device of claim 1 , wherein the operations comprise:

decoding the first write command to obtain logical block address (LBA) data, wherein the LBA data comprises a plurality of hash records associated with a corresponding plurality of hashes, and wherein at least one hash record of the plurality of hash records includes the hash of the user data and an LBA; and

storing the plurality of hash records in a dedicated memory of the controller.

3 . The storage device of claim 2 , wherein the operations comprise:

decoding the second write command to further obtain an LBA of the user data.

4 . The storage device of claim 2 , wherein the operations comprise:

retrieving the at least one hash record from the dedicated memory based on matching the LBA of the user data with the LBA in the at least one of the hash records that includes the hash of the user data; and

storing the user data and the hash subsequent to the retrieving of the at least one hash record.

5 . The storage device of claim 2 , wherein the operations comprise:

parsing the plurality of hash records to obtain a corresponding plurality of hashes and a corresponding plurality of LBAs associated with data used for generation of the plurality of hashes.

6 . The storage device of claim 5 , wherein the operations comprise:

decoding a third write command to obtain an LBA of second user data; and

detecting the LBA of the second user data is not included in the corresponding plurality of LBAs.

7 . The storage device of claim 6 , wherein the operations comprise:

generating a notification that the third write command is a failed write command.

8 . A method comprising:

decoding, by at least one hardware processor of a storage device, a first write command received from a host to obtain a hash of user data, the hash generated based on a cryptographic key that is common between the host and the storage device;

decoding a second write command received from the host after the first write command, to obtain the user data associated with the hash;

retrieving hash metadata based on the hash, the hash metadata indicating a first storage address of a memory storage region of the storage device;

storing the user data at the first storage address of the memory storage region; and

storing the hash with the hash metadata at a second storage address of the memory storage region.

9 . The method of claim 8 , further comprising:

decoding the first write command to obtain logical block address (LBA) data, wherein the LBA data comprises a plurality of hash records associated with a corresponding plurality of hashes, and wherein at least one hash record of the plurality of hash records includes the hash of the user data and an LBA; and

storing the plurality of hash records in a dedicated memory of the at least one hardware processor.

10 . The method of claim 9 , further comprising:

decoding the second write command to further obtain an LBA of the user data.

11 . The method of claim 9 , further comprising:

retrieving the at least one hash record from the dedicated memory based on matching the LBA of the user data with the LBA in the at least one of the hash records that includes the hash of the user data; and

storing the user data and the hash subsequent to the retrieving of the at least one hash record.

12 . The method of claim 9 , further comprising:

parsing the plurality of hash records to obtain a corresponding plurality of hashes and a corresponding plurality of LBAs associated with data used for generation of the plurality of hashes.

13 . The method of claim 12 , further comprising:

decoding a third write command to obtain an LBA of second user data; and

detecting the LBA of the second user data is not included in the corresponding plurality of LBAs.

14 . The method of claim 13 , further comprising:

generating a notification that the third write command is a failed write command.

15 . A machine-readable medium, comprising instructions, which when executed by a processor of a storage device, cause the processor to perform operations comprising:

decoding a first write command received from a host to obtain a hash of user data, the hash generated based on a cryptographic key that is common between the host and the storage device;

decoding a second write command received from the host after the first write command, to obtain the user data associated with the hash;

retrieving hash metadata based on the hash, the hash metadata indicating a first storage address of a memory storage region of the storage device;

storing the user data at the first storage address of the memory storage region; and

storing the hash with the hash metadata at a second storage address of the memory storage region.

16 . The machine-readable medium of claim 15 , further comprising:

decoding the first write command to obtain logical block address (LBA) data, wherein the LBA data comprises a plurality of hash records associated with a corresponding plurality of hashes, and wherein at least one hash record of the plurality of hash records includes the hash of the user data and an LBA; and

storing the plurality of hash records in a dedicated memory of the processor.

17 . The machine-readable medium of claim 16 , further comprising:

decoding the second write command to further obtain an LBA of the user data.

18 . The machine-readable medium of claim 16 , further comprising:

retrieving the at least one hash record from the dedicated memory based on matching the LBA of the user data with the LBA in the at least one of the hash records that includes the hash of the user data; and

storing the user data and the hash subsequent to the retrieving of the at least one hash record.

19 . The machine-readable medium of claim 16 , further comprising:

parsing the plurality of hash records to obtain a corresponding plurality of hashes and a corresponding plurality of LBAs associated with data used for generation of the plurality of hashes.

20 . The machine-readable medium of claim 19 , further comprising:

decoding a third write command to obtain an LBA of second user data;

detecting the LBA of the second user data is not included in the corresponding plurality of LBAs; and

generating a notification that the third write command is a failed write command.

Continuity (3)
Continuation 17014771 · Sep 8, 2020
Provisional Application 62955637 · Dec 31, 2019
Related Publication 20230315569A1 · Oct 5, 2023
References Cited (21)
US 7136995B1 · Wann · 2006 [cited by examiner]
US 8392798B2 · Flynn · 2013 [cited by examiner]
US 9152502B2 · Kalach et al. · 2015 [cited by applicant]
US 9606870B1 · Meiri et al. · 2017 [cited by applicant]
US 10254972B2 · Iwai · 2019 [cited by examiner]
US 11526300B2 · Segev · 2022 [cited by examiner]
US 11693732B2 · Palmer et al. · 2023 [cited by applicant]
US 20140056068A1 · Strasser et al. · 2014 [cited by applicant]
US 20140160591A1 · Sakamoto · 2014 [cited by examiner]
US 20140181575A1 · Kalach et al. · 2014 [cited by applicant]
US 20140317479A1 · Candelaria · 2014 [cited by applicant]
US 20210200631A1 · Palmer et al. · 2021 [cited by applicant]
CN 102317919 · 2012 [cited by applicant]
CN 105144302 · 2015 [cited by applicant]
CN 113127893A · 2021 [cited by applicant]
“Chinese Application Serial No. 202011534578.7, Decision of Rejection mailed Apr. 3, 2024”, with English translation, 14 pages. [cited by applicant]
“Chinese Application Serial No. 202011534578.7, Office Action mailed Oct. 16, 2023”, with English translation, 13 pages. [cited by applicant]
“Chinese Application Serial No. 202011534578.7, Response filed Feb. 27, 2024 to Office Action mailed Oct. 16, 2023”, with English claims, 182 pages. [cited by applicant]
“Chinese Application Serial No. 202011534578.7, Response filed Jun. 27, 2024 to Decision of Rejection mailed Apr. 3, 2024”, with English claims, 27 pages. [cited by applicant]
U.S. Appl. No. 19/030,342, filed Jan. 17, 2025, Cryptographic Data Integrity Protection. [cited by applicant]
U.S. Appl. No. 17/014,771 U.S. Pat. No. 11,693,732, filed Sep. 8, 2020, Cryptographic Data Integrity Protection. [cited by applicant]