IP Library Granted Patent US 12,379,877
Granted Patent B2
US 12,379,877 · App. 18/490,364 · Granted Aug 5, 2025

Read-protected storage device with sequential logging

Inventors: Julian Vlaiko (Kfar Saba, IL); Judah Gamliel Hahn (Ofra, IL); Aki Bleyer (Givatayim, IL); Shay Benisty (Beer Sheva, IL); Alexander Bazarsky (Holon, IL); Ariel Navon (Revava, IL)
Assignee: Sandisk Technologies, Inc.
G06F3/0659G06F3/0622G06F3/064G06F3/0679
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,379,877
App. No.
18/490,364
Granted
Aug 5, 2025
Kind
B2
Abstract

Instead of incorporating a single interface towards the host for transferring data, utilizing a designated write-only storage logging device. The write-only storage logging device can accept sequential streams and automatically overwrite. The controller will read the log material in a secure manner using a different and separate physical connection than the one used for write. The storage device may have LBA ranges that work as write-only as well as other LBA ranges, which are normal (both reads and writes are enabled). Both options will allow for a traditional file system as well as sharing the storage, but will still protect the log areas that would be used for events that should not be read out.

Claims (42)

1. A data storage device, comprising:

a memory device, wherein the memory device comprises:

a first namespace accessible via a first interface; and

a second namespace accessible via a second interface, wherein the first namespace and the second namespace are distinct; and

a controller coupled to the memory device, wherein the controller is configured to:

receive a first request to write data to the memory device, wherein the first request is transmitted through the first interface;

write data to the memory device; and

receive a second request to read data from the memory device, wherein the second request is received through the second interface, and wherein the second interface is physically distinct from the first interface, and wherein the second namespace is a secure namespace that can only be read through requests transmitted through the second interface.

2. The data storage device of claim 1 , wherein the second interface and the first interface are physically distinct.

3. The data storage device of claim 1 , wherein the controller is configured to set first logical block addresses (LBAs) and second LBAs, wherein the first LBAs can be read from requests transmitted through the first interface, and wherein the second LBAs can be read only from requests transmitted through the second interface.

4. The data storage device of claim 1 , wherein the controller comprises a security validation module.

5. The data storage device of claim 4 , wherein the security validation module is coupled to the first interface and the second interface.

6. The data storage device of claim 5 , wherein read requests cannot be processed through the first interface.

7. The data storage device of claim 1 , wherein the controller is configured to perform authentication for requests through the second interface.

8. The data storage device of claim 1 , wherein the controller is configured to detect a connection established through the second interface.

9. The data storage device of claim 1 , wherein the first interface uses a host interface module (HIM) and the second interface uses a physical interface.

10. The data storage device of claim 9 , wherein the second interface is a secure interface module (SIM).

11. A data storage device, comprising:

a memory device, wherein the memory device comprises:

a first namespace accessible via a first interface; and

a second namespace accessible via a second interface, wherein the first namespace and the second namespace are distinct; and

a controller coupled to the memory device, wherein the controller comprises:

the first interface, wherein the first interface configured to receive commands to write data to the memory device; and

the second interface, wherein the second interface is configured to receive commands to read data from the memory device, wherein the first interface and the second interface are physically distinct, wherein the controller is configured to ignore read commands received through the first interface, wherein the second namespace can only be read through requests transmitted through the second interface.

12. The data storage device of claim 11 , wherein the controller includes a security validation module configured to validate read requests received, and wherein read requests are validated by the security validation module before accessing the second namespace.

13. The data storage device of claim 11 , wherein the controller is configured to receive instructions to enable or disable security parameters associated with accessing the memory device, wherein the instructions are configured to be received through the second interface and not the first interface.

14. The data storage device of claim 11 , wherein the controller is configured to receive power through the second interface.

15. The data storage device of claim 11 , wherein the controller is configured to have a first host device physically connected to the first interface and a second, distinct host device physically connected to the second interface while the first host device remains connected to the first interface.

16. A data storage device, comprising:

means to store data, wherein the means to store data comprises:

a first namespace accessible via a first interface; and

a second namespace accessible via a second interface, wherein the first namespace and the second namespace are distinct, and wherein the first interface and the second interface are physically distinct; and

a controller coupled to the means to store data, wherein the controller is configured to:

receive a request to read data from the means to store data;

determine that the data corresponding to the request is disposed in a restricted partition of the means to store data;

authenticate whether the request arrived via the first or the second interface, wherein the first interface is a interface through which commands to write the data to the means to store data are received;

determine that the request to read data disposed in the restricted partition was received via the second interface; and

read the data if the request to read data disposed in the restricted partition was received via the second interface.

17. The data storage device of claim 16 , wherein the controller is configured to restrict reads to non-restricted partitions of the means to store data such that reads to non-restricted partitions are requested through a different interface.

18. The data storage device of claim 16 , wherein the means to store data comprises a first namespace and a second namespace distinct from the first namespace, wherein the second namespace comprises the restricted partition of the means to store data.

19. The data storage device of claim 16 , wherein the controller is configured to receive a request to write data to the means to store data, wherein the request to write data is received through the first interface, and wherein the controller is configured to reject requests to read data received through the first interface.

20. The data storage device of claim 16 , wherein the controller is configured to define first logical block addresses (LBAs) as write only LBAs and second LBAs as read and write enabled LBAs.

Assignments (8)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL Recorded Nov 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065657/0158 →
PATENT COLLATERAL AGREEMENT- A&R Recorded Nov 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065656/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2023
From: VLAIKO, JULIAN; HAHN, JUDAH GAMLIEL; BLEYER, AKI; BENISTY, SHAY; BAZARSKY, ALEXANDER; NAVON, ARIEL
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 065522/0097 →
Continuity (1)
Related Publication 20250130738A1 · Apr 24, 2025
References Cited (8)
US 9489507B2 · Torres · 2016 [cited by applicant]
US 11061566B2 · Chung · 2021 [cited by applicant]
US 11294581B2 · Harrison et al. · 2022 [cited by applicant]
US 12086450B1 · Lazier · 2024 [cited by examiner]
US 20170286325A1 · Singh et al. · 2017 [cited by applicant]
US 20210373799A1 · Yan · 2021 [cited by examiner]
US 20220197817A1 · Yoshida et al. · 2022 [cited by applicant]
US 20230043303A1 · Lee · 2023 [cited by examiner]