US2015235020A1PendingUtilityA1

Storage device, storage system, and authentication method

Assignee: TOSHIBA KKPriority: Apr 8, 2011Filed: Apr 29, 2015Published: Aug 20, 2015
Est. expiryApr 8, 2031(~4.7 yrs left)· nominal 20-yr term from priority
G06F 3/0679G06F 3/0637G06F 21/44G06F 3/0622G06F 21/79G11B 20/00673G11B 20/00666G11B 20/00478G11B 20/0021G11B 20/00137G11B 20/00086G06F 2221/2129
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

According to one embodiment, a storage device that has a nonvolatile semiconductor memory includes an authentication information storage unit that previously stores first apparatus authentication information to authenticate an authorized host device and first user authentication information to authenticate an authorized user. The storage device executes apparatus authentication on the basis of second apparatus authentication information received from a newly connected host device and the first apparatus authentication information in the authentication information storage unit and executes an invalidation process of user data stored in the nonvolatile semiconductor memory, when the apparatus authentication is failed.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A storage device comprising:
 a nonvolatile semiconductor memory;   an apparatus authenticator configured to execute apparatus authentication of a host device;   a portion key storage configured to store a first portion key;   a portion key writer configured to generate a third portion key on the basis of a second portion key received from a host device and the first portion key;   a user authenticator configured to execute user authentication on the basis of information received from the host device and the third portion key; and   a data read controller configured to output user data stored in the nonvolatile semiconductor memory to the host device if both of the apparatus authentication and user authentication are passed.   
     
     
         3 . The storage device according to  claim 2 , further comprising:
 an authentication information storage configured to store a first hash value of unique information of an authorized host device,   wherein the apparatus authenticator calculates a hash value of an apparatus authentication information received from the host device as a second hash value, collates the first hash value and the second hash value, and determines that the apparatus authentication is failed, if the first hash value and the second hash value are not matched with each other.   
     
     
         4 . The storage device according to  claim 2 ,
 wherein an apparatus authentication information received from the host device is unique information of the host device that is used as the second portion key, and   the second portion key is the unique information of the host device that is used as the apparatus authentication information.   
     
     
         5 . The storage device according to  claim 2 , further comprising:
 an authentication information storage configured to store a signature verification key of an authorized host device,   wherein an apparatus authentication information received from the host device includes a digital signature that is generated by a signature generation key of the host device and signature target data that is used for generation of the digital signature, and   the apparatus authenticator decrypts the digital signature on the basis of the signature verification key, collates obtained decryption data and a hash value calculated from the signature target data, and determines that the apparatus authentication is failed, if the decryption data and the hash value are not matched with each other.   
     
     
         6 . The storage device according to  claim 2 ,
 wherein the apparatus authenticator determines that the apparatus authentication is failed, if the apparatus authenticator detects that an authentication sequence of when the host device transmits an apparatus authentication information is different from a predetermined authentication sequence.   
     
     
         7 . The storage device according to  claim 2 , further comprising:
 a user data invalidator configured to execute an invalidation process for physically corrupting the user data stored in the nonvolatile semiconductor memory thereby the user data cannot be read out as its original form, if at least one of the apparatus authentication and user authentication is failed.   
     
     
         8 . A storage device comprising:
 a first authenticator configured to authenticate a host;   a storage configured to store a first key;   a generator configured to generate a third key based on a second key received from a host and the first key; and   a second authenticator configured to authenticate based on information received from the host and the third key.

Join the waitlist — get patent alerts

Track US2015235020A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.