IP Library › Granted Patent US 12,504,892
Granted Patent B2
US 12,504,892 · App. 17/402,107 · Granted Dec 23, 2025

Memory system with enhanced security access to parital storage areas

Inventor: Mari Hikichi (Yokohama Kanagawa, JP)
Assignee: KIOXIA CORPORATION
G06F3/0622G06F1/14G06F3/0637G06F3/0679G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,504,892
App. No.
17/402,107
Granted
Dec 23, 2025
Kind
B2
Abstract

According to one embodiment, a memory system includes a nonvolatile memory and a controller. The controller enables a first access authority to a first storage area which is at least a partial storage area of the nonvolatile memory and sets a first time limit at which the first access authority becomes disabled. The first access authority is assigned to first user identification information. The controller disables the first access authority in a case where current time exceeds the first time limit.

Claims (71)

1 . A memory system connectable to a host, the memory system comprising:

a nonvolatile memory; and

a controller including an access controller configured to:

control an access to the nonvolatile memory;

manage one or more ranges obtained by logically dividing a storage area of the nonvolatile memory; and

manage a temporary authority table and first authentication information that corresponds to a first user ID, the temporary authority table including information on an access authority to access at least one of the one or more ranges,

the access controller configured to:

receive, from the host, a first access time limit setting command issued with an administrator authority, the first access time limit setting command requesting enabling a first access authority assigned to the first user ID, requesting setting information on the first access authority in the temporary authority table, and including information that indicates the first user ID, a first range of the ranges, and a first time limit of an access period in which the first access authority to access the first range is enabled;

in accordance with the received first access time limit setting command, set, in the temporary authority table, the first user ID, information indicating that access to the first range is enabled, and the first time limit;

acquire a first current time;

while the first current time does not exceed the first time limit set in the temporary authority table, enable the first access authority; and

when the first current time has exceeded the first time limit set in the temporary authority table, disable the first access authority, update the temporary authority table to indicate that the access to the first range is disabled, and change the first authentication information corresponding to the first user ID.

2 . The memory system of claim 1 , wherein

the access controller is further configured to:

receive an access request from the host, the access request being a request for accessing the first range and being associated with the first user ID;

in a case where the first access authority is enabled, execute a process related to access to the first range in accordance with the access request; and

in a case where the first access authority is disabled, notify the host of an error without executing the process related to access to the first range in accordance with the access request.

3 . The memory system of claim 2 , wherein

the access controller is further configured to:

receive a first authentication request from the host, the first authentication request including second authentication information associated with the first user ID;

in a case where the first access authority is enabled, execute an authentication process of the first user ID using the second authentication information; and

in a case where the first access authority is disabled, notify the host of an error without executing the authentication process of the first user ID using the first-second authentication information.

4 . The memory system of claim 3 , wherein

the access controller is further configured to:

in a case where the first access authority is enabled and the executed authentication process is successful, execute the process related to access to the first range in accordance with the access request; and

in a case where the first access authority is enabled and the executed authentication process is not successful, notify the host of an error without executing the process related to access to the first range in accordance with the access request.

5 . The memory system of claim 1 , wherein

the access controller is further configured to

encrypt data to be written into the nonvolatile memory using a first encryption key, and decrypt data read from the nonvolatile memory using the first encryption key, and

the access controller is further configured to:

receive a read request from the host, the read request being a request for reading data from the first range and is being associated with the first user ID;

in a case where the first access authority is enabled, read first data corresponding to the read request from the first range, decrypt the read first data using the first encryption key, and transmit the decrypted first data to the host; and

in a case where the first access authority is disabled, notify the host of an error without reading the first data from the first range.

6 . The memory system of claim 5 , wherein

the access controller is further configured to:

encrypt the first encryption key using a second encryption key to acquire a third encryption key, the second encryption key being associated with the first authentication information corresponding to the first user ID; and

in a case where the first access authority is enabled, acquire the second encryption key using the first authentication information, decrypt the third encryption key using the acquired second encryption key to acquire the first encryption key, and decrypt the read first data using the first encryption key.

7 . The memory system of claim 6 , wherein

the access controller is further configured to

discard the third encryption key without discarding the first encryption key in a case where the first access authority becomes disabled.

8 . The memory system of claim 7 , wherein

the access controller is further configured to:

encrypt the first encryption key using a fourth encryption key to acquire a fifth encryption key, the fourth encryption key being associated with second authentication information that is different from the first authentication information; and

acquire the fourth encryption key using the second authentication information, decrypt the fifth encryption key using the acquired fourth encryption key to acquire the first encryption key, and decrypt the read first data using the first encryption key.

9 . The memory system of claim 1 , further comprising:

a real-time clock; and

a power storage device capable of supplying power to the real-time clock,

wherein the access controller is further configured to acquire the first current time from the real-time clock.

10 . The memory system of claim 1 , wherein

the access controller is further configured to:

receive a first authentication request from the host, the first authentication request being associated with an ID of an administrator having the administrator authority;

execute an authentication process of the administrator using authentication information that is included in the first authentication request; and

in a case where the executed authentication process of the administrator is successful, set in the temporary authority table, the first user ID, the information indicating that the access to the first range is enabled, and the first time limit, in accordance with the first access time limit setting command.

11 . The memory system of claim 1 , wherein

the access controller is further configured to

encrypt data to be written into the nonvolatile memory using a first encryption key, and decrypt data read from the nonvolatile memory using the first encryption key, and

the access controller is further configured to:

receive a write request from the host, the write request being a request for writing second data into the first range and being associated with the first user ID;

in a case where the first access authority is enabled, encrypt the second data using the first encryption key, and write the encrypted second data into the first range; and

in a case where the first access authority is disabled, notify the host of an error without writing the second data into the first range.

12 . The memory system of claim 11 , wherein

the access controller is further configured to:

encrypt the first encryption key using a second encryption key to acquire a third encryption key, the second encryption key being associated with the first authentication information corresponding to the first user ID; and

in a case where the first access authority is enabled, acquire the second encryption key using the first authentication information, decrypt the third encryption key using the acquired second encryption key to acquire the first encryption key, and encrypt the second data using the first encryption key.

13 . The memory system of claim 12 , wherein

the access controller is further configured to

discard the third encryption key without discarding the first encryption key in a case where the first access authority becomes disabled.

14 . The memory system of claim 13 , wherein

the access controller is further configured to:

encrypt the first encryption key using a fourth encryption key to acquire a fifth encryption key, the fourth encryption key being associated with second authentication information that is different from the first authentication information; and

acquire the fourth encryption key using the second authentication information, decrypt the fifth encryption key using the acquired fourth encryption key to acquire the first encryption key, and encrypt the second data using the first encryption key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: HIKICHI, MARI
To: KIOXIA CORPORATION
Reel/Frame 064871/0112 →
Priority Claims (1)
JP 2021-021773 · Feb 15, 2021 · national
Continuity (1)
Related Publication 20220261162A1 · Aug 18, 2022
References Cited (48)
US 9083581B1 · Addepalli · 2015 [cited by examiner]
US 9342703B2 · Simoncelli · 2016 [cited by examiner]
US 10162977B2 · Toillon · 2018 [cited by examiner]
US 11810079B2 · Haldenby · 2023 [cited by examiner]
US 20030077074A1 · Okamoto et al. · 2003 [cited by applicant]
US 20050038757A1 · Wada · 2005 [cited by applicant]
US 20050210187A1 · Yamamoto · 2005 [cited by applicant]
US 20060190426A1 · Kanazawa · 2006 [cited by examiner]
US 20060242066A1 · Jogand-Coulomb · 2006 [cited by examiner]
US 20070169172A1 · Backes · 2007 [cited by examiner]
US 20100100948A1 · Delia · 2010 [cited by examiner]
US 20100161928A1 · Sela · 2010 [cited by examiner]
US 20100332834A1 · Fu · 2010 [cited by examiner]
US 20120005435A1 · Emaru · 2012 [cited by examiner]
US 20120072735A1 · Fukawa · 2012 [cited by examiner]
US 20120124183A1 · Long · 2012 [cited by examiner]
US 20120229838A1 · Mogaki · 2012 [cited by examiner]
US 20130167205A1 · Michener · 2013 [cited by examiner]
US 20140304836A1 · Velamoor · 2014 [cited by examiner]
US 20150163206A1 · McCarthy et al. · 2015 [cited by applicant]
US 20160164878A1 · Nakano · 2016 [cited by examiner]
US 20160218875A1 · Le Saint · 2016 [cited by examiner]
US 20160246980A1 · Toillon · 2016 [cited by examiner]
US 20170168851A1 · Lin · 2017 [cited by examiner]
US 20170323114A1 · Egorov · 2017 [cited by examiner]
US 20180129611A1 · Parker et al. · 2018 [cited by applicant]
US 20190141041A1 · Bhabbur · 2019 [cited by examiner]
US 20200293206A1 · Isozaki · 2020 [cited by examiner]
US 20210232499A1 · Yong · 2021 [cited by examiner]
US 20210289576A1 · Cheaz · 2021 [cited by examiner]
US 20210303674A1 · Wood · 2021 [cited by applicant]
US 20210352064A1 · Tsarfati · 2021 [cited by examiner]
US 20220014528A1 · Gambhir · 2022 [cited by examiner]
US 20220239480A1 · Hetzler · 2022 [cited by examiner]
US 20230281294A1 · Oswal · 2023 [cited by examiner]
CA 3126072A1 · 2020 [cited by examiner]
CA 2930281C · 2021 [cited by examiner]
CN 101004717A · 2007 [cited by applicant]
CN 102750113A · 2012 [cited by applicant]
CN 6690733B2 · 2024 [cited by examiner]
DE 112011103666B4 · 2021 [cited by examiner]
JP 2002251819A · 2002 [cited by applicant]
JP 2005267701A · 2005 [cited by applicant]
TW 200813746A · 2008 [cited by applicant]
TW 201710902A · 2017 [cited by applicant]
TW 202036342A · 2020 [cited by applicant]
WO WO2006069274A2 · 2006 [cited by examiner]
WO WO2021112918A1 · 2021 [cited by examiner]