Secure control of self-encrypting storage devices
Abstract
Generally, this disclosure provides systems, devices, methods and computer readable media for secure control of access control enablement and activation on self-encrypting storage devices. In some embodiments, the device may include a non-volatile memory (NVM) and a secure access control module. The secure access control module may include a command processor module configured to receive a request to enable access controls of the NVM from a user, and to enable the access controls. The secure access control module may also include a verification module configured to verify a physical presence of the user. The secure access control module may further include an encryption module to encrypt at least a portion of the NVM in response to an indication of success from the verification module.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 - 27 . (canceled)
28 . A storage device comprising:
a non-volatile memory (NVM); and secure access control circuitry to:
store a Security Identifier (SID) having a first SID value;
receive a request to enable access controls of the NVM;
responsive to the received request to enable the access controls, set the SID to a second SID value;
receive a request to revert the SID to the first SID value;
responsive to the received request to revert the SID to the first SID value, verify a physical presence of a user using a Physical Security Identifier (PSID);
responsive to a successful verification of the physical presence of the user:
set the SID to the first SID value; and
enable the access controls of the NVM; and
responsive to an unsuccessful verification of the physical presence of the user, deny the received request to revert the SID to the first SID value, wherein the SID remains the second SID value.
29 . The storage device of claim 28 , wherein the secure access control module implements Opal Storage Specification access controls.
30 . The storage device of claim 28 , wherein the second SID value is a randomly generated value.
31 . The storage device of claim 30 , further comprising a random number generator to generate the randomly generated value.
32 . The storage device of claim 28 , wherein the PSID is associated with the storage device.
33 . The storage device of claim 32 , wherein the PSID is displayed on a housing of the storage device.
34 . The storage device of claim 28 , wherein the access controls of the NVM enable encryption of at least part of the NVM.
35 . The storage device of claim 28 , wherein the NVM is a solid state drive (SSD).
36 . The storage device of claim 28 , wherein:
the secure access control circuitry is further to store a Manufacturer Security Identifier (MSID) having a MSID value; and the first SID value is the MSID value.
37 . The storage device of claim 28 , wherein the secure access control circuitry communicates with a host system via interface circuitry and a storage bus, the interface circuitry to implement one of:
a Serial Advanced Technology Attachment (SATA) interface; a Serial Attached Small Computer System (SAS) Interface; a Peripheral Component Interconnect Express (PCIe) interface; a Universal Flash Storage (UFS) interface; or an embedded Multimedia Controller interface (eMMC).
38 . A method for secure control of a storage device, the method comprising:
receiving a request to enable access controls of a non-volatile memory (NVM) of the storage device; responsive to the received request to enable access controls of the NVM, setting a Security Identifier (SID) to a first SID value; receiving a request to revert the SID to a second SID value; responsive to the received request to revert the SID to the second SID value, verifying a physical presence of a user using a Physical Security Identifier (PSID); responsive to the verification of the physical presence of the user being successful:
setting the SID to the second SID value; and
enabling the access controls of the NVM; and
responsive to the verification of the physical presence of the user not being successful, denying the received request to revert the SID to the second SID value, wherein the SID remains the first SID value.
39 . The method of claim 38 , wherein the storage device implements Opal Storage Specification access controls.
40 . The method of claim 38 , further comprising generating, via a random number generator, a randomly generated value, wherein the first SID value is the randomly generated value.
41 . The method of claim 38 , wherein the PSID is displayed on a housing of the storage device.
42 . The method of claim 38 , wherein the access controls of the NVM enable encryption of at least part of the NVM.
43 . A mobile platform, comprising:
a processor; a display element coupled to the processor; and a solid state drive (SSD) storage device coupled to the processor, the SSD comprising:
a non-volatile memory (NVM); and
secure access control circuitry to:
store a Security Identifier (SID) having a first SID value;
receive a request to enable access controls of the NVM;
responsive to the received request to enable the access controls, set the SID to a second SID value;
receive a request to revert the SID to the first SID value;
responsive to the received request to revert the SID to the first SID value, verify a physical presence of a user using a Physical Security Identifier (PSID);
responsive to the verification of the physical presence of the user being successful:
set the SID to the first SID value; and
enable the access controls of the NVM; and
responsive to the verification of the physical presence of the user not being successful, deny the received request to revert the SID to the first SID value, wherein the SID remains the second SID value.
44 . The mobile platform of claim 43 , wherein the secure access control circuitry implements Opal Storage Specification access controls.
45 . The mobile platform of claim 43 , further comprising a random number generator to generate a randomly generated value, wherein the second SID value is the randomly generated value.
46 . The mobile platform of claim 43 , wherein the access controls of the NVM enable encryption of at least part of the NVM.
47 . The mobile platform of claim 43 , wherein the secure access control circuitry communicates with the processor via interface circuitry and a storage bus, the interface circuitry to implement one of:
a Serial Advanced Technology Attachment (SATA) interface; a Serial Attached Small Computer System (SAS) Interface; a Peripheral Component Interconnect Express (PCIe) interface; a Universal Flash Storage (UFS) interface; or an embedded Multimedia Controller interface (eMMC).Join the waitlist — get patent alerts
Track US2017277916A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.