IP Library › Granted Patent US 12,645,609
Granted Patent B2
US 12,645,609 · App. 18/356,295 · Granted Jun 2, 2026

Storage device deleting encryption key, method of operating the same, and method of operating electronic device including the same

Inventors: Changhwan Kim (Suwon-si, KR); Mingon Shin (Suwon-si, KR); Jisoo Kim (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
G06F12/1408G06F1/30G06F12/1441G06F13/1668
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,609
App. No.
18/356,295
Granted
Jun 2, 2026
Kind
B2
Abstract

A method of operating a storage device which communicates with a host device. The method including allocating a secure region and a user region, storing first data encrypted by using a first encryption key in a first data block of the secure region, receiving a first request indicating a first secure delete operation of the first data from the host device, decrypting at least one valid data of the first data block by using the first encryption key based on the first request, wherein the at least one valid data do not include the first data, encrypting the decrypted at least one valid data by using a second encryption key different from the first encryption key, storing the encrypted at least one valid data in a second data block of the secure region, and deleting the first encryption key.

Claims (87)

1 . A method of operating a storage device which communicates with a host device, the method comprising:

allocating a secure region and a user region in the storage device;

storing first data encrypted by using a first encryption key in a first data block of the secure region;

decrypting at least one valid data of the first data block using the first encryption key in response to receiving a first request from the host device, wherein the first request indicates a first secure delete operation of the first data and the at least one valid data does not include the first data;

encrypting the decrypted at least one valid data using a second encryption key, wherein the second encryption key is different from the first encryption key;

storing the encrypted at least one valid data in a second data block of the secure region; and

deleting the first encryption key,

wherein the first request includes a first set feature command of a non-volatile memory express (NVMe) standard, and the first set feature command includes a feature identifier indicating the first secure delete operation and an address range corresponding to the secure region.

2 . The method of claim 1 , further comprising:

storing second data in a user data block of the user region in response to receiving a second request from the host device, wherein the second request indicates a non-secure write operation of the second data and the second data is not encrypted.

3 . The method of claim 1 , wherein

the first data has a chunk size, and

the chunk size corresponds to a size of a logical block address (LBA) of the host device and is smaller than a unit of a physical erase operation of the storage device.

4 . The method of claim 1 , wherein the allocating of the secure region and the user region includes:

receiving a first command indicating setting of the secure region;

storing the address range based on the first command;

creating the first encryption key based on the first command; and

providing the host device with a response indicating that the setting of the secure region is done.

5 . The method of claim 4 , wherein

the first command is a second set feature command of the NVMe standard, and

the second set feature command includes a feature identifier indicating the setting of the secure region and the address range.

6 . The method of claim 1 , wherein

the first request is triggered by an operating system of the host device, and

the first request includes a trim command for deleting a mapping relationship of the first data in a mapping table of the storage device.

7 . The method of claim 1 , wherein the first request is triggered by an application of the host device.

8 . The method of claim 1 , further comprising:

receiving, from the host device, a third request indicating a second secure delete operation of third data among the encrypted at least one valid data of the second data block;

detecting a sudden power off (SPO) event while performing the second secure delete operation based on the third request; and

resuming the second secure delete operation after detecting the SPO event in response to a power supply voltage being supplied from the host device.

9 . The method of claim 8 , wherein the detecting of the SPO event includes

storing a start time point of the second secure delete operation in a log register in response to the third request, and the resuming the second secure delete operation includes

determining, in response to the power supply voltage, that the SPO event occurred while performing the second secure delete operation, with reference to the log register, and

resuming the second secure delete operation in response to the determination that the SPO event occurred while performing the second secure delete operation.

10 . The method of claim 8 , wherein

the encrypted at least one valid data of the second data block include fourth data, and the fourth data is valid data in the second secure delete operation, and

wherein the resuming of the second secure delete operation includes

decrypting the fourth data of the second data block using the second encryption key, based on the third request and the supply of the power supply voltage,

encrypting the fourth data using a third encryption key, wherein the third encryption key is different from the second encryption key,

storing the encrypted fourth data in a third data block of the secure region, and

deleting the second encryption key.

11 . The method of claim 1 , wherein the storing of the first data encrypted using the first encryption key includes

receiving, from the host device, a fourth request indicating a secure write operation of the first data,

receiving the first data from the host device,

encrypting, based on the fourth request, the received first data using the first encryption key; and

storing the encrypted first data in the first data block of the secure region.

12 . The method of claim 1 , further comprising:

loading the encrypted first data of the first data block in response to receiving a fifth request after the storing the encrypted first data and before the deleting the first encryption key, wherein the fifth request indicates a secure read operation of the first data from the host;

decrypting the loaded encrypted first data using the first encryption key; and

providing the decrypted first data to the host device.

13 . The method of claim 1 , further comprising:

disabling security features of the secure region based on a sixth request from the host device, the sixth request indicating a security disablement of the secure region; and

enabling, after the disabling the security features, the security features of the secure region in response to receiving a seventh request, the seventh request indicating a security enablement of the secure region.

14 . The method of claim 1 , further comprising:

deallocating the secure region in response to receiving an eighth request from the host device, the eighth request indicating a deallocation of the secure region.

15 . A method of operating an electronic device which includes a host device and a storage device, the method comprising:

providing, by the host device, a first request for allocation of the storage device;

allocating, by the storage device, a secure region and a user region in response to the first request;

providing, by the host device, a second request for a secure write operation of target data;

storing, by the storage device, first data encrypted by using a first encryption key in a first data block of the secure region in response to the second request;

providing, by the host device, a third request indicating a secure delete operation of the target data;

decrypting, by the storage device, at least one valid data of the first data block using the first encryption key in response to the third request, wherein the at least one valid data does not include the target data;

encrypting, by the storage device, the decrypted at least one valid data using a second encryption key different from the first encryption key;

storing, by the storage device, the encrypted at least one valid data in a second data block of the secure region; and

deleting, by the storage device, the first encryption key,

wherein the third request includes a set feature command of a non-volatile memory express (NVMe) standard, and the set feature command includes a feature identifier indicating the secure delete operation and an address range corresponding to the secure region.

16 . The method of claim 15 ,

wherein the third request is triggered by an application or an operating system of the host device.

17 . A storage device comprising:

a non-volatile memory device including a user region and a secure region; and

a storage controller configured to communicate with a host device and the non-volatile memory device,

wherein the storage controller is configured to

store target data encrypted using a first encryption key in a first data block of the secure region in response to receiving a first request from the host device,

wherein the first request indicates a secure write operation;

decrypt at least one valid data of the first data block using the first encryption key in response to receiving a second request from the host device, wherein the second request indicates a secure delete operation and the at least one valid data does not include first data;

encrypt the decrypted at least one valid data using a second encryption key, wherein the second encryption key is different from the first encryption key;

store the encrypted at least one valid data in a second data block of the secure region; and

delete the first encryption key,

wherein the second request includes a set feature command of a non-volatile memory express (NVMe) standard, and the set feature command includes a feature identifier indicating the secure delete operation and an address range corresponding to the secure region.

18 . The storage device of claim 17 , wherein the storage controller includes

a buffer memory configured to buffer the target data and the at least one valid data,

a mapping table configured to manage a mapping relationship between a logical address and a physical address of the target data, and

processing circuitry configured to process the first request and the second request based on communicating with the host device, the buffer memory, and the mapping table.

19 . The storage device of claim 18 , wherein the processing circuitry includes:

a command manager configured to process the first request and the second request;

an encryption manager configured to, under control of the command manager, encrypt the target data by using the first encryption key, to decrypt the at least one valid data by using the first encryption key, and to encrypt the decrypted at least one valid data by using the second encryption key;

a key manager configured to provide the first encryption key and the second encryption key to the encryption manager under control of the command manager; and

a log register configured to store logs of the secure delete operation of the second request under control of the command manager.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: KIM, CHANGHWAN; SHIN, MINGON; KIM, JISOO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 064454/0521 →
Priority Claims (2)
KR 10-2022-0115876 · Sep 14, 2022 · national
KR 10-2023-0030721 · Mar 8, 2023 · national
Continuity (1)
Related Publication 20240086336A1 · Mar 14, 2024
References Cited (13)
US 7581118B2 · McGovern · 2009 [cited by applicant]
US 8250380B2 · Guyot et al. · 2012 [cited by applicant]
US 8938624B2 · Obukhov et al. · 2015 [cited by applicant]
US 9311237B2 · Little et al. · 2016 [cited by applicant]
US 20090276514A1 · Subramanian · 2009 [cited by examiner]
US 20100217977A1 · Goodwill et al. · 2010 [cited by applicant]
US 20140068277A1 · Metzger · 2014 [cited by applicant]
US 20170185336A1 · Byun · 2017 [cited by examiner]
US 20200004993A1 · Volos · 2020 [cited by examiner]
US 20210405907A1 · Nagai · 2021 [cited by applicant]
US 20220164487A1 · Gyllenskog et al. · 2022 [cited by applicant]
US 20220283714A1 · Lee et al. · 2022 [cited by applicant]
KR 100591117B1 · 2006 [cited by applicant]