US2017277916A1PendingUtilityA1

Secure control of self-encrypting storage devices

Assignee: INTEL CORPPriority: Nov 18, 2014Filed: Apr 7, 2017Published: Sep 28, 2017
Est. expiryNov 18, 2034(~8.3 yrs left)· nominal 20-yr term from priority
G06F 21/78G06F 21/6245G06F 2212/402G06F 2221/2111G06F 21/604G11B 20/0021H04L 9/0897G06F 21/73
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Generally, this disclosure provides systems, devices, methods and computer readable media for secure control of access control enablement and activation on self-encrypting storage devices. In some embodiments, the device may include a non-volatile memory (NVM) and a secure access control module. The secure access control module may include a command processor module configured to receive a request to enable access controls of the NVM from a user, and to enable the access controls. The secure access control module may also include a verification module configured to verify a physical presence of the user. The secure access control module may further include an encryption module to encrypt at least a portion of the NVM in response to an indication of success from the verification module.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 - 27 . (canceled) 
     
     
         28 . A storage device comprising:
 a non-volatile memory (NVM); and   secure access control circuitry to:
 store a Security Identifier (SID) having a first SID value; 
 receive a request to enable access controls of the NVM; 
 responsive to the received request to enable the access controls, set the SID to a second SID value; 
 receive a request to revert the SID to the first SID value; 
 responsive to the received request to revert the SID to the first SID value, verify a physical presence of a user using a Physical Security Identifier (PSID); 
 responsive to a successful verification of the physical presence of the user:
 set the SID to the first SID value; and 
 enable the access controls of the NVM; and 
 
 responsive to an unsuccessful verification of the physical presence of the user, deny the received request to revert the SID to the first SID value, wherein the SID remains the second SID value. 
   
     
     
         29 . The storage device of  claim 28 , wherein the secure access control module implements Opal Storage Specification access controls. 
     
     
         30 . The storage device of  claim 28 , wherein the second SID value is a randomly generated value. 
     
     
         31 . The storage device of  claim 30 , further comprising a random number generator to generate the randomly generated value. 
     
     
         32 . The storage device of  claim 28 , wherein the PSID is associated with the storage device. 
     
     
         33 . The storage device of  claim 32 , wherein the PSID is displayed on a housing of the storage device. 
     
     
         34 . The storage device of  claim 28 , wherein the access controls of the NVM enable encryption of at least part of the NVM. 
     
     
         35 . The storage device of  claim 28 , wherein the NVM is a solid state drive (SSD). 
     
     
         36 . The storage device of  claim 28 , wherein:
 the secure access control circuitry is further to store a Manufacturer Security Identifier (MSID) having a MSID value; and   the first SID value is the MSID value.   
     
     
         37 . The storage device of  claim 28 , wherein the secure access control circuitry communicates with a host system via interface circuitry and a storage bus, the interface circuitry to implement one of:
 a Serial Advanced Technology Attachment (SATA) interface;   a Serial Attached Small Computer System (SAS) Interface;   a Peripheral Component Interconnect Express (PCIe) interface;   a Universal Flash Storage (UFS) interface; or   an embedded Multimedia Controller interface (eMMC).   
     
     
         38 . A method for secure control of a storage device, the method comprising:
 receiving a request to enable access controls of a non-volatile memory (NVM) of the storage device;   responsive to the received request to enable access controls of the NVM, setting a Security Identifier (SID) to a first SID value;   receiving a request to revert the SID to a second SID value;   responsive to the received request to revert the SID to the second SID value, verifying a physical presence of a user using a Physical Security Identifier (PSID);   responsive to the verification of the physical presence of the user being successful:
 setting the SID to the second SID value; and 
 enabling the access controls of the NVM; and 
   responsive to the verification of the physical presence of the user not being successful, denying the received request to revert the SID to the second SID value, wherein the SID remains the first SID value.   
     
     
         39 . The method of  claim 38 , wherein the storage device implements Opal Storage Specification access controls. 
     
     
         40 . The method of  claim 38 , further comprising generating, via a random number generator, a randomly generated value, wherein the first SID value is the randomly generated value. 
     
     
         41 . The method of  claim 38 , wherein the PSID is displayed on a housing of the storage device. 
     
     
         42 . The method of  claim 38 , wherein the access controls of the NVM enable encryption of at least part of the NVM. 
     
     
         43 . A mobile platform, comprising:
 a processor;   a display element coupled to the processor; and   a solid state drive (SSD) storage device coupled to the processor, the SSD comprising:
 a non-volatile memory (NVM); and 
 secure access control circuitry to:
 store a Security Identifier (SID) having a first SID value; 
 receive a request to enable access controls of the NVM; 
 responsive to the received request to enable the access controls, set the SID to a second SID value; 
 receive a request to revert the SID to the first SID value; 
 responsive to the received request to revert the SID to the first SID value, verify a physical presence of a user using a Physical Security Identifier (PSID); 
 responsive to the verification of the physical presence of the user being successful:
 set the SID to the first SID value; and 
 enable the access controls of the NVM; and 
 
 responsive to the verification of the physical presence of the user not being successful, deny the received request to revert the SID to the first SID value, wherein the SID remains the second SID value. 
 
   
     
     
         44 . The mobile platform of  claim 43 , wherein the secure access control circuitry implements Opal Storage Specification access controls. 
     
     
         45 . The mobile platform of  claim 43 , further comprising a random number generator to generate a randomly generated value, wherein the second SID value is the randomly generated value. 
     
     
         46 . The mobile platform of  claim 43 , wherein the access controls of the NVM enable encryption of at least part of the NVM. 
     
     
         47 . The mobile platform of  claim 43 , wherein the secure access control circuitry communicates with the processor via interface circuitry and a storage bus, the interface circuitry to implement one of:
 a Serial Advanced Technology Attachment (SATA) interface;   a Serial Attached Small Computer System (SAS) Interface;   a Peripheral Component Interconnect Express (PCIe) interface;   a Universal Flash Storage (UFS) interface; or   an embedded Multimedia Controller interface (eMMC).

Join the waitlist — get patent alerts

Track US2017277916A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.