Data Storage Device and Method to Access Logical Block Range
A data storage device includes a storage medium to store user data where logical block ranges are associated with the storage medium. The data storage device also includes at least one processor configured to receive ATA security protocol commands from a host device. The security protocol command includes a parameter list, which includes a reserved field used to include a first identifier that, in turn, is associated with a selected first logical block range, which enables identification of the selected first logical block range associated with the ATA security protocol command. The parameter list also includes a first password in a password field of the parameter list. The first password enables access to the first logical block range. The processor verifies the password with an authentication data set to enable one or more functions, such as an unlock function, associated with the selected first logical block range.
1 . A method of a data storage device communicating with a host device, the method comprising:
receiving, from the host device, an ATA security protocol command;
determining, from a reserved field in a parameter list of the ATA security protocol command, a first identifier associated with a first logical block range of a plurality of logical block ranges associated with a storage medium;
determining, from a password field in the parameter list of the ATA security protocol command, a first password;
verifying the first password with an authentication data set; and
responsive to verifying the first password, selectively enabling one or more functions associated with the first logical block range, and wherein one or more functions associated with at least one other logical block ranges in the plurality of logical block ranges are disabled.
2 . A method according to claim 1 , further comprising;
determining from a security protocol specific field in the ATA security protocol command, the one or more functions.
3 . A method according to claim 1 , wherein the one or more functions comprises an unlock function to enable reading, writing, modifying, or erasing user data stored in the first logical block range.
4 . A method according to claim 1 , wherein the authentication data set includes a record associating a plurality of enrolled passwords with a respective plurality of identifiers and/or the plurality of logical block ranges, and wherein verifying the first password further includes verifying both the first password and corresponding first identifier (with the authentication data set.
5 . A method according to claim 1 further comprising:
determining, based on a range table associating a plurality of identifiers corresponding to the plurality of logical block ranges, the first logical block range corresponding to the first identifier.
6 . A method according to claim 5 wherein the first identifier includes at least one, or more of:
a number associated with the first logical block range;
a username, or other text, associated with the first logical block range;
an alphanumeric associated with the first logical block range; and
a representation of the first logical block range.
7 . A method according to claim 1 , wherein the reserved field in the parameter list of the ATA security protocol command includes:
bit 1 , bit 2 , and bit 3 of byte 0 of the parameter list; or
one or more bits in byte 0 of the parameter list; or
one or more bits in byte 1 of the parameter list; or
bits in both byte 0 and byte 1 of the parameter list.
8 . A method according to claim 1 , wherein the password field in the parameter list of the ATA security protocol command includes:
one or more of bytes 2 to byte 33 of the parameter list.
9 . A method according to claim 4 , further comprising:
determining, from the password field and selection of a master password field in a parameter list of the ATA security protocol command, a master password;
verifying the master password with the authentication data set; and
responsive to verifying the master password, selectively enabling one or more administrator functions associated with the data storage device.
10 . A method according to claim 9 , wherein the one or more administrator functions comprises at least one or more of:
modifying the authentication data set to associate a new password with an identifier in the plurality of enrolled passwords and the plurality of identifiers;
modifying the authentication data set to associate a new master password;
configuring a number and/or size of the plurality of logical block ranges; and
erasing data stored in one or more of the plurality of logical block ranges.
11 . A method according to claim 1 , wherein in an enrolment mode the method comprises:
receiving, from the host device, a set password ATA security command;
determining, from a reserved field of the parameter list in the set password ATA security command, a selected identifier for a selected logical block range;
determining, from a password field in the set password ATA security protocol command, a further password; and
modifying the authentication data set by associating the selected logical block range or selected identifier with the further password.
12 . A method according to claim 1 , wherein the ATA security protocol command is in accordance with SAT-5 (SCSI/ATA Translation—5).
13 . A data storage device comprising:
a storage medium configured to store user data, wherein a plurality of logical block ranges are associated with the storage medium;
at least one processor configured, individually or in combination, to:
receive, from a host device, an ATA security protocol command;
determine, from a reserved field in a parameter list of the ATA security protocol command, a first identifier associated with a first logical block range of the plurality of logical block ranges;
determine, from a password field in the parameter list of the ATA security protocol command, a first password;
verify the first password with an authentication data set; and
in response to verification of the first password, selectively enable one or more functions associated with the first logical block range, wherein one or more functions associated with other logical block ranges in the plurality of logical block ranges are disabled.
14 . A data storage device according to claim 13 , wherein the at least one processor is further configured, individually or in combination, to:
determine from a security protocol specific field in the ATA security protocol command, the one or more functions.
15 . A data storage device according to claim 13 , wherein the one or more functions comprises an unlock function to enable reading, writing, modifying, or erasing user data stored in the first logical block range.
16 . A data storage device according to claim 13 , further comprising a configuration memory configured to store the authentication data set,
wherein the authentication data set includes a record to associate a plurality of enrolled passwords with a respective plurality of identifiers and/or the plurality of logical block ranges, and
wherein the at least one processor is further configured to verify both the first password and corresponding first identifier with the authentication data set.
17 . A data storage device according to claim 13 , further comprising a configuration memory configured to store a range table associating a plurality of identifiers corresponding to the plurality of logical block ranges,
wherein the at least one processor is further configured to determine, based on the range table, the first logical block range corresponding to the first identifier.
18 . A data storage device according to claim 17 , wherein the first identifier includes at least one, or more of:
a number associated with the first logical block range;
a username, or other text, associated with the first logical block range;
an alphanumeric associated with the first logical block range; and
a representation of the first logical block range.
19 . A data storage device according to claim 13 , wherein the reserved field in the parameter list of the ATA security protocol command includes:
bit 1 , bit 2 , and bit 3 of byte 0 of the parameter list; or
one or more bits in byte 0 of the parameter list; or
one or more bits in byte 1 of the parameter list; or
bits in both byte 0 and byte 1 of the parameter list.
20 . A computing device comprising:
means for receiving a request to access a first logical block range in a storage medium;
means for determining, based on the request to access the first logical block
range, a first identifier associated with the first logical block range;
means for receiving, from a user interface, a first password associated with the first logical block range; and
means for sending, to a data storage device, an ATA security protocol command to enable one or more functions associated with a first logical block range, wherein:
a reserved field in a parameter list of the ATA security protocol command includes the first identifier associated with the first logical block range; and
a password field in the parameter list of the ATA security protocol command includes the first password.