US2008005460A1PendingUtilityA1

Disk drive, control method thereof and disk-falsification detection method

Assignee: HITACHI GLOBAL STORAGE TECHPriority: Jun 4, 2004Filed: Aug 23, 2007Published: Jan 3, 2008
Est. expiryJun 4, 2024(expired)· nominal 20-yr term from priority
Inventors:Tetsuya Uemura
G11B 20/1816G06F 21/64G11B 20/00086G06F 21/80G06F 2221/2129
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments of the invention provide a falsification detection method which is capable of recognizing the substance of a falsification, applicable to not only a specific file system, but any arbitrary application writing data with a logical structure, usable in a standalone environment and able to prevent its performance from deteriorating even for a very large data size. In one embodiment, data stored in the storage medium employed in a disk drive is divided into meta information expressing a data structure and contents. At a step, time transients of the meta information are analyzed whereas, at other steps, time transients of the contents are analyzed. By analyzing the data at two stages in this way, replacement of a file and replacement of contents of the file can be detected whereas the substance of a falsification can be recognized in the case of a file system. By providing every block in the storage medium employed in the disk drive with a flag area that can be updated by the disk drive but only referred to by a host, a falsification can be detected even if the falsification results from a write operation carried out by using an illegal access path.

Claims

exact text as granted — not AI-modified
1 - 6 . (canceled)  
   
   
       7 . A falsification detection method for a disk drive including a storage medium and a control unit configured to exchange a command and data with a host and controlling operations to write new data into a free area into the storage medium employed in said disk drive in accordance with said command received from said host so that said new data is not written over data already existing on said storage medium as well as operations to read out data from said storage medium in accordance with said command received from said host, the method comprising: 
 setting a logical structure of data recorded on said storage medium in said disk drive;    identifying data storing meta information used as information of said set logical structure of said data among pieces of data recorded on said storage medium in said disk drive on the basis of said logical structure;    analyzing a time transient of said identified meta information from an initial state of said meta information to a most recent state of said meta information; and    analyzing a time transient of contents of data specified by said meta information from an initial state of said contents to a most recent state of said contents at every stage in said analyzed said time transient of said meta information.    
   
   
       8 . A falsification detection method in accordance with  claim 7 , further comprising: 
 generating a time transient of said meta information in an opposite direction from said most recent state to said initial state on the basis of a result of analyzing said time transient of said meta information; and    generating a time transient of said contents in an opposite direction from said most recent state to said initial state on the basis of a result of analyzing said time transient of said contents.    
   
   
       9 . A falsification detection method in accordance with  claim 7 , further comprising: 
 allocating an area for saving an analysis result;    saving the present state of an analysis process in said allocated area;    checking said allocated area for data saved therein at the start of a falsification detection process and reading out said state of an analysis process in a case where said state has been saved in said area; and    starting an analysis process as a continuation of an immediately preceding analysis process from the last state of said preceding analysis process in a case where said last state of said preceding analysis process has been read out from said area, or starting an analysis process all over from the beginning if no state of said analysis process has been read out from said area.    
   
   
       10 . A falsification detection method in accordance with  claim 7 , further comprising: 
 recording an identifier of the contents into a flag area, which is provided on said storage medium for every smallest management unit, for a recording area included in said storage medium as an area in which contents of data specified by meta information are recorded by said disk drive.    
   
   
       11 . A falsification detection method in accordance with  claim 7 , further comprising: 
 identifying an address on said storage medium included in said disk drive as an address, at which meta information and contents have been recorded by maintaining consistency between said meta information and said contents, from a result of analyzing a time transient of said meta information and a result of analyzing a time transient of said contents; and    recording a check point, which shows that said meta information and said contents have been recorded by maintaining consistency, in said flag area corresponding to said specified address on said storage medium.    
   
   
       12 . A falsification detection method in accordance with  claim 7 , further comprising: 
 receiving an identifier entered by way of a console as the identifier of contents;    searching a result of analyzing a time transient of said meta information for said identifier and determining whether or not said contents have been replaced;    outputting information indicating the event of content replacement on said console in a case where said contents have been replaced;    searching a result of analyzing a time transient of said contents for said identifier and determining whether or not said contents have been renewed; and    outputting information indicating the event of content rewrites on said console in a case where said contents have been rewritten.    
   
   
       13 . A falsification detection method for in accordance with  claim 12 , further comprising: 
 receiving two arbitrary events entered to said console as events selected among pieces of information each output to said console to indicate the event of content replacement or pieces of information each output to said console to indicate the event of content rewrites;    computing a difference between meta information requested by one of said received events and meta information requested by the other received event and outputting said difference to said console; and    computing a difference between contents requested by one of said received events and contents requested by the other received event and outputting said difference to said console.    
   
   
       14 . A falsification detection method in accordance with  claim 12 , further comprising: 
 receiving an arbitrary event entered to said console as an event selected among pieces of information each output to said console to indicate the event of content replacement or pieces of information each output to said console to indicate the event of content rewrites; and    invalidating contents requested by said received event.    
   
   
       15 . A falsification detection method in accordance with  claim 14 , further comprising invalidating meta information and contents, which have the same identifier as contents identifier requested by said received event and have been recorded on said storage medium employed in said disk drive at and after a point of time said received event was generated.  
   
   
       16 . A falsification detection method in accordance with  claim 14 , further comprising invalidating all pieces of meta information and all contents, which have been recorded on said storage medium employed in said disk drive at and after a point of time said received event was generated.  
   
   
       17 . A falsification detection method in accordance with  claim 7  wherein said disk drive includes: 
 a flag-area generation module configured to provide a flag area for each unit of writing data into said storage medium as an area which said host can only refer to but said control unit can write information into;    an internal-state information generation module configured to generate internal-state information based on internal information of said disk drive to accompany execution of a write command; and    internal-state information write module configured to write said internal-state information generated by said internal-state information generation module into said flag area provided by said flag-area generation module; and    wherein said method further comprises:    checking consistency between the result of analyzing a time transient of meta information and information stored in said flag area; and    checking consistency between the result of analyzing a time transient of contents and information stored in said flag area.    
   
   
       18 . (canceled)  
   
   
       19 . A falsification detection method for a disk drive including a storage medium and a control unit configured to exchange a command data with hosts and control operations to write new data into a free area into the storage medium employed in said disk drive in accordance with said command received from one of said hosts so that said new data is not written over data already existing on said storage medium as well as operations to read out data from said storage medium in accordance with one of said command received from said hosts, a first one of said hosts writing data onto said storage medium, a second one of said hosts writing no data onto said storage medium or a management console of said disk drive performing said method including: 
 setting a logical structure of data written onto said storage medium employed in said disk drive;    identifying data storing meta information used as information of said set logical structure of said data selected among pieces of data written on said storage medium employed in said disk drive on the basis of said logical structure;    analyzing a time transient of said identified meta information from an initial state of said meta information to a most recent state of said meta information; and    analyzing a time transient of contents of data specified by said meta information from an initial state of said contents to a most recent state of said contents at every stage in said analyzed time transient of said meta information.    
   
   
       20 . A falsification detection method in accordance with  claim 19 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 generating a time transient of said meta information in an opposite direction from said most recent state to said initial state on the basis of the result of analyzing said time transient of said meta information; and    generating a time transient of said contents in an opposite direction from said most recent state to said initial state on the basis of the result of analyzing said time transient of said contents.    
   
   
       21 . A falsification detection method in accordance with  claim 19 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 allocating an area for saving an analysis result;    saving the present state of an analysis process in said allocated area;    checking said allocated area for data saved therein at the start of a falsification detection process and reading out said state of an analysis process in a case where said state has been saved in said area; and    starting an analysis process as a continuation of an immediately preceding analysis process from the last state of said preceding analysis process in a case where said last state of said preceding analysis process has been read out from said area, or starting an analysis process all over from the beginning if no state of said analysis process has been read out from said area.    
   
   
       22 . A falsification detection method in accordance with  claim 19 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including writing an identifier of the contents into a flag area, which is provided for every smallest management unit of said storage medium as an area in which contents of data specified by meta information are recorded by said disk drive.  
   
   
       23 . A falsification detection method in accordance with  claim 19 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 identifying an address on said storage medium included in said disk drive, at which meta information and contents have been recorded by maintaining consistency between said meta information and said contents, from the result of analyzing a time transient of said meta information and the result of analyzing a time transient of said contents; and    writing a check point, which shows that said meta information and said contents have been written by maintaining consistency, in said flag area corresponding to said specified address on said storage medium.    
   
   
       24 . A falsification detection method in accordance with  claim 19 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 receiving an identifier entered by way of a console as the identifier of contents;    searching the result of analyzing a time transient of meta information for said identifier and determining whether or not said contents have been replaced;    outputting information indicating the event of content replacement on said console in a case where said contents have been replaced;    searching a result of analyzing a time transient of said contents for said identifier and determining whether or not said contents have been rewritten; and    outputting information indicating an event of content rewrite on said console in a case where said contents have been rewritten.    
   
   
       25 . A falsification detection method in accordance with  claim 24 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 receiving two arbitrary events entered to said console as events selected among pieces of information each output to said console to indicate the event of content replacement or pieces of information each output to said console to indicate the event of content rewrite;    computing a difference between meta information requested by one of said received events and meta information requested by the other received event and outputting said difference to said console; and    computing a difference between contents requested by one of said received events and contents requested by the other received event and outputting said difference to said console.    
   
   
       26 . A falsification detection method in accordance with  claim 24 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including: 
 receiving an arbitrary event entered to said console as an event selected among pieces of information each output to said console to indicate the event of content replacement or pieces of information each output to said console to indicate the event of content rewrite; and    invalidating contents requested by said received event.    
   
   
       27 . A falsification detection method in accordance with  claim 26 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including invalidating meta information and contents, which have the same identifier as a content identifier requested by a received event and have been written on said storage medium employed in said disk drive at and after a point of time said received event was generated.  
   
   
       28 . A falsification detection method in accordance with  claim 26 , wherein said first host writing data onto said storage medium, said second host writing no data onto said storage medium or said management console of said disk drive further performs said method including invalidating all pieces of meta information and all contents, which have been written on a storage medium employed in said disk drive at and after a point of time said received event was generated.  
   
   
       29 . A disk drive including a storage medium and a control unit configured to exchange a command and data with a host and control operations to write data into the storage medium in accordance with said command received from said host as well as operations to read out data from said storage medium in accordance with said command received from said host, said disk drive comprising: 
 a flag-area generation module configured to provide a flag area, to which said host is capable of only referring but into which only said disk drive is capable of writing information, for every unit of an operation to write data into said storage medium;    an internal-state information generation module configured to generate internal-state information based on an internal state of said disk drive; and    an internal-state information write module configured to write internal-state information generated by said internal-state information generation module into said flag area provided by said flag-area generation module.    
   
   
       30 - 35 . (canceled)

Join the waitlist — get patent alerts

Track US2008005460A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.