WO2015084522A1 - Device initiated auto freeze lock - Google Patents
Device initiated auto freeze lock Download PDFInfo
- Publication number
- WO2015084522A1 WO2015084522A1 PCT/US2014/063853 US2014063853W WO2015084522A1 WO 2015084522 A1 WO2015084522 A1 WO 2015084522A1 US 2014063853 W US2014063853 W US 2014063853W WO 2015084522 A1 WO2015084522 A1 WO 2015084522A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- storage device
- processing logic
- criteria
- command
- storage
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/30—Arrangements for executing machine instructions, e.g. instruction decode
- G06F9/30003—Arrangements for executing specific machine instructions
- G06F9/3004—Arrangements for executing specific machine instructions to perform operations on memory
Definitions
- a computing device may use one or more storage systems to store information.
- the information may include, for example, data and/or executable instructions.
- the storage systems may include a primary storage and a secondary storage.
- a primary storage may be a storage that is directly accessible to a processor that may be contained in the computing device.
- the processor may access the primary storage via a memory bus that may contain provisions for transferring information between the processor and the primary storage.
- a secondary storage may be a storage that may not be directly accessible to the processor.
- information may be transferred between the processor and the secondary storage via one or more input/output (I/O) channels that may be part of an I/O bus.
- I/O input/output
- FIG. 1 illustrates a block diagram of an example embodiment of a computing device
- FIG. 2 illustrates an example embodiment of a storage device that may be contained in a secondary storage associated with a computing device
- FIG. 3 illustrates a flow diagram of example acts that may be performed by a storage device to automatically freeze lock the storage device.
- a computing device may include a processor and a storage device.
- the processor may use the storage device to store information that is to survive after power is lost to the computing device.
- the information may include, for example, data and/or computer-executable instructions.
- a computing device such as, for example, a smart phone, tablet, or ultrabook may contain a processor and a storage device such as, for example, a solid-state disk (SSD), hard disk drive, or a thumb drive.
- the storage device may provide a non-volatile storage for the computing device.
- the processor may use the storage device to store information for the computing device that is to persist after power is lost to the computing device.
- the information may include, for example, data and/or applications that may be used by the computing device.
- the processor may retrieve the persisted information from the storage device after power is restored to the computing device.
- a storage device may include control logic which may, inter alia, provide support for various security-related commands associated with the storage device.
- the security-related commands may be used to implement various security-related features associated with the storage device.
- ATA8-ACS Working Draft Project American National Standard T13/1699-D, Revision 6, June 24, 2008
- ATA standard includes definitions for various security-related commands that may be used to invoke various security-related features associated with a storage device.
- These commands include a SECURITY SET PASSWORD command which may be used to associate a password with a storage device.
- the password may be used to control access to the storage device.
- the SECURITY SET PASSWORD command may be used to password protect a storage device.
- a computing device includes a processor and a storage device. Now suppose the processor issues a SECURITY SET PASSWORD command along with a password to password protect the storage device. Access to the storage device may be restricted until the password is provided.
- the security-related commands supported by the storage control logic may be wrapped within other commands for transport to/from the storage control logic.
- SCSI Small Component System Interface
- a SECURITY SET PASSWORD command may be wrapped within a SECURITY PROTOCOL OUT command for transport to the storage device via a SCSI interface.
- the SECURITY SET PASSWORD command may be wrapped within a SECURITY SEND command for transport to the storage device via a Peripheral Component Interface Express (PCIe) interface utilizing the Non- volatile Memory Express (NVMe) protocol.
- PCIe Peripheral Component Interface Express
- NVMe Non- volatile Memory Express
- the SECURITY SEND command is defined in the "NVM Express" specification, Revision l.Oe, January 23, 2013, available from the NVM Work Group (herein "NVMe specification").
- Security-related features supported by a storage device may include provisions for locking the storage device from further processing security-related commands. These provisions may be referred to as a "freeze lock".
- a storage device that has been freeze locked may be referred to as being in a frozen security state. While in a frozen security state, the storage device may decline processing some or all security-related commands. The storage device may remain in the frozen security state until a particular event occurs.
- the ATA standard also includes a definition for a SECURITY FREEZE
- LOCK command that may be used to direct a storage device to enter a frozen security state. While in the frozen security state, the storage device may no longer process security-related commands such as, for example, the above-described SECURITY SET PASSWORD command. The storage device may stay in the frozen security state until an event, such as for example the storage device is reset or power cycled, occurs.
- a problem may arise when an unauthorized password is associated with a storage device before the storage device is placed in a frozen security state.
- a computing device includes a processor and a storage device. Further suppose that the storage device supports the above-described SECURITY SET PASSWORD and SECURITY FREEZE LOCK commands.
- the processor does not issue a SECURITY FREEZE LOCK command to the non- volatile storage device. Since the non-volatile storage device is not in frozen security state, the storage device may still process security-related commands. This may make the storage device vulnerable to an attack by an unauthorized program (e.g., malware) executing on the processor.
- an unauthorized program e.g., malware
- an unauthorized program may "hijack" the storage device by issuing a SECURITY SET PASSWORD command to the storage device to associate the storage device with an unauthorized password.
- the storage device may then be held “hostage” and made inaccessible until the password is provided.
- Techniques described herein may obviate situations where, for example, a storage device may be made inaccessible by unauthorized means (e.g., hijacked).
- the techniques may include, for example, determining whether the storage device has entered a frozen security state; if the storage device has not entered the frozen security state, determining whether certain criteria is met; and if the criteria is met, automatically placing the storage device in a frozen security state.
- the acts may be performed by control logic that may be contained, for example, within the storage device, thereby enabling the storage device to enter the frozen security state
- FIG. 1 illustrates a block diagram of an example embodiment of a computing device 100.
- computing device 100 may include various components such as, for example, processing logic 120, primary storage 130, secondary storage 150, one or more input devices 160, one or more output devices 170, and one or more communication interfaces 180.
- FIG. 1 illustrates an example embodiment of computing device 100.
- Other embodiments of computing device 100 may include more components or fewer components than the components illustrated in FIG. 1. Further, the components may be arranged differently than as illustrated in FIG. 1.
- a portion of secondary storage 150 may be contained at a remote site that provides "cloud" storage. The site may be accessible to computing device 100 via a communications network, such as, for example, the Internet.
- a communication interface 180 may be used to interface the computing device 100 with the communications network.
- computing device 100 may be distributed among the components differently than as described herein.
- Computing device 100 may include an input/output (I/O) bus 110 that may enable communication among components in computing device 100, such as, for example, processing logic 120, secondary storage 150, one or more input devices 160, one or more output devices 170, and one or more communication interfaces 180.
- the communication may include, among other things, transferring, for example, control signals and/or data between the components.
- I/O busses that may be used to implement I/O bus 110 may include, for example, serial AT attachment (SATA), peripheral component interconnect (PCI), PCI express (PCI-e), universal serial bus (USB), small computer system interface (SCSI), serial attached SCSI (SAS), or some other I/O bus.
- SATA serial AT attachment
- PCI peripheral component interconnect
- PCI-e PCI express
- USB universal serial bus
- SCSI small computer system interface
- SAS serial attached SCSI
- Computing device 100 may include a memory bus 190 that may enable information, which may be stored in primary storage 130, to be transferred between processing logic 120 and primary storage 130.
- the information may include computer-executable instructions and/or data that may be executed, manipulated, and/or otherwise processed by processing logic 120.
- Processing logic 120 may include logic for interpreting, executing, and/or otherwise processing information.
- the information may include information that may be stored in, for example, primary storage 130 and/or secondary storage 150.
- the information may include information that may be acquired (e.g., read, received) by one or more input devices 160 and/or communication interfaces 180.
- Processing logic 120 may include a variety of heterogeneous hardware.
- the hardware may include some combination of one or more processors, microprocessors, field programmable gate arrays (FPGAs), application specific instruction set processors (ASIPs), application specific integrated circuits (ASICs), complex programmable logic devices (CPLDs), graphics processing units (GPUs), and/or other types of processing logic that may, for example, interpret, execute, manipulate, and/or otherwise process the information.
- Processing logic 120 may comprise a single core or multiple cores. Examples of processors that may be used to implement processing logic 120 include, but are not limited to, the Intel® Xeon® processor and Intel® AtomTM brand processors which are available from Intel Corporation, Santa Clara, California.
- Input devices 160 may include one or more devices that may be used to input information into computing device 100.
- the devices may include, for example, a keyboard, computer mouse, microphone, camera, trackball, gyroscopic device (e.g., gyroscope), mini-mouse, touch pad, stylus, graphics tablet, touch screen, joystick (isotonic or isometric), pointing stick, accelerometer, palm mouse, foot mouse, puck, eyeball controlled device, finger mouse, light pen, light gun, neural device, eye tracking device, steering wheel, yoke, jog dial, space ball, directional pad, dance pad, soap mouse, haptic device, tactile device, neural device, multipoint input device, discrete pointing device, and/or some other input device.
- gyroscopic device e.g., gyroscope
- mini-mouse touch pad
- stylus graphics tablet
- touch screen touch screen
- joystick isotonic or isometric
- pointing stick e.g., accelerometer,
- the information may include spatial (e.g., continuous, multi-dimensional) data that may be input into computing device 100 using, for example, a pointing device, such as a computer mouse.
- the information may also include other forms of data, such as, for example, text that may be input using a keyboard.
- Output devices 170 may include one or more devices that may output information from computing device 100.
- the devices may include, for example, a cathode ray tube (CRT), plasma display device, light-emitting diode (LED) display device, liquid crystal display (LCD) device, vacuum florescent display (VFD) device, surface-conduction electron-emitter display (SED) device, field emission display (FED) device, haptic device, tactile device, printer, speaker, video projector, volumetric display device, plotter, touch screen, and/or some other output device.
- Output devices 170 may be directed by, for example, processing logic 120, to output the information from computing device 100.
- Outputting the information may include presenting (e.g., displaying, printing) the information on an output device 170.
- the information may include, for example, text, graphical user interface (GUI) elements (e.g., windows, widgets, and/or other GUI elements), audio (e.g., music, sounds), and/or other information that may be outputted by output devices 170.
- GUI graphical user interface
- Communication interfaces 180 may include logic for interfacing computing device 100 with, for example, one or more communications networks and enable computing device 100 to communicate with one or more entities (e.g., nodes) coupled to the communications networks.
- the communications networks may include, for example, the Internet, wide-area networks (WANs), local area networks (LANs), 3G and/or 4G networks.
- Communication interfaces 180 may include one or more transceiver-like mechanisms that may enable computing device 100 to communicate with entities coupled to the communications networks. Examples of
- communication interfaces 180 may include a built-in network adapter, network interface card (NIC), Personal Computer Memory Card International Association (PCMCIA) network card, card bus network adapter, wireless network adapter, Universal Serial Bus (USB) network adapter, modem, and/or other device suitable for interfacing computing device 100 to a communications network.
- NIC network interface card
- PCMCIA Personal Computer Memory Card International Association
- USB Universal Serial Bus
- Primary storage 130 and secondary storage 150 may include one or memory devices.
- a memory device may support, for example, serial or random access to information contained in the memory device.
- a memory device that supports serial access to information stored in the memory device may be referred to as a serial memory device.
- a memory device that supports random access to information stored in the memory device may be referred to as a random access memory (RAM) device.
- RAM random access memory
- a memory device may be, for example, a volatile or non- volatile memory device.
- a volatile memory device may be a memory device that may lose information stored in the device when power is removed from the device.
- a non- volatile memory device may be a memory device that may retain information stored in the device when power is removed from the device.
- Examples of memory devices may include dynamic RAM (DRAM) devices, flash memory devices, static RAM (SRAM) devices, zero-capacitor RAM (ZRAM) devices, twin transistor RAM (TTRAM) devices, read-only memory (ROM) devices, ferroelectric transistor RAM (FeTRAM) devices, magneto-resistive RAM (MRAM) devices, phase change memory (PCM) devices, PCM and switch (PCMS) devices, nanowire-based devices, resistive RAM devices (RRAM), serial electrically erasable programmable ROM (SEEPROM) devices, serial flash devices, and/or other types of memory devices.
- DRAM dynamic RAM
- SRAM static RAM
- ZRAM zero-capacitor RAM
- TTRAM twin transistor RAM
- ROM read-only memory
- FeTRAM ferroelectric transistor RAM
- MRAM magneto-resistive RAM
- PCM phase change memory
- PCM phase change memory
- PCM phase change memory
- PCM phase change memory
- PCM phase change memory
- PCM phase change memory
- Primary storage 130 may be accessible to processing logic 120 via memory bus 190.
- Primary storage 130 may store computer-executable instructions and/or data that may implement operating system (OS) 132 and application (APP) 134.
- OS operating system
- APP application
- the computer-executable instructions may be executed, interpreted, and/or otherwise processed by processing logic 120.
- Primary storage 130 may be implemented using one or more memory devices that may store information for processing logic 120.
- the information may include executable instructions that may be executed by processing logic 120.
- the information may also include data that may be manipulated by processing logic 120.
- the memory devices may include volatile and/or non- volatile memory devices.
- OS 132 may be a conventional operating system that may implement various conventional operating system functions. These functions may include, for example, (1) scheduling one or more portions of APP 134 to run on (e.g., be executed by) the processing logic 120, (2) managing primary storage 130, and (3) controlling access to various components in computing device 100 (e.g., input devices 160, output devices 170, communication interfaces 180, secondary storage 150) and information received and/or transmitted by these components.
- functions may include, for example, (1) scheduling one or more portions of APP 134 to run on (e.g., be executed by) the processing logic 120, (2) managing primary storage 130, and (3) controlling access to various components in computing device 100 (e.g., input devices 160, output devices 170, communication interfaces 180, secondary storage 150) and information received and/or transmitted by these components.
- Examples of operating systems that may be used to implement OS 132 may include the Linux operating system, Microsoft Windows operating system, the Symbian operating system, Mac OS operating system, iOS operating system, Chrome OS and the Android operating system.
- a distribution of the Linux operating system that may be used is Red Hat Linux available from Red Hat Corporation, Raleigh, North Carolina. Versions of the Microsoft Windows operating system that may be used include Microsoft Windows Mobile, Microsoft Windows 8.1, Microsoft Windows 8, Microsoft Windows 7, Microsoft Windows Vista, and Microsoft Windows XP operating systems available from Microsoft Inc., Redmond, Washington.
- the Symbian operating system is available from Accenture PLC, Dublin, Ireland.
- the Mac OS and iOS operating systems are available from Apple, Inc., Cupertino, California.
- the Chrome OS and Android operating systems are available from Google, Inc., Menlo Park, California.
- APP 134 may be a software application that may run (execute) under control of OS 132 on computing device 100.
- APP 134 and/or OS 132 may contain provisions for processing transactions that may involve storing information in secondary storage 150. These provisions may be implemented using data and/or computer-executable instructions contained in APP 134 and/or OS 132.
- Secondary storage 150 may include one or more storage devices, such as storage device 200.
- the storage devices may be accessible to processing logic 120 via I/O bus 110.
- the storage devices may store information (e.g., data, computer-executable instructions). The information may be executed, interpreted, manipulated, and/or otherwise processed by processing logic 120.
- One or more of the storage devices may implement one or more embodiments of the invention.
- the storage devices may be volatile or non-volatile.
- Storage devices that may be included in secondary storage 150 may include, for example, magnetic disk drives, optical disk drives, random-access memory (RAM) disk drives, flash drives, thumb drives, SSDs, hybrid drives, and/or other storage devices.
- the information may be stored on one or more non-transitory tangible computer-readable media contained in the storage devices. Examples of non-transitory tangible computer-readable media that may be contained in the storage devices may include magnetic discs, optical discs, volatile memory devices, and or non- volatile memory devices.
- Storage device 200 may be a storage device that may store information for computing device 100.
- storage device 200 may be a hard disk drive, an optical drive, a flash drive, an SSD, a hybrid drive, or some other type of storage device that may store information for computing device 100.
- FIG. 2 illustrates an example embodiment of storage device 200.
- storage device 200 may include device processing logic 220, local storage 230, and a storage 240.
- the device processing logic 220 may interpret, execute, manipulate and/or otherwise process information contained in local storage 230.
- Device processing logic 220 may include some combination of one or more processors, microprocessors, FPGAs, ASIPs, ASICs, CPLDs, and/or other types of processing logic that may interpret, execute, manipulate, and/or otherwise process the information.
- Local storage 230 may include a tangible non-transitory volatile and/or non- volatile storage that may be used to store the information for device processing logic 220.
- the information may include data and/or computer-executable instructions that may be associated with an operation of storage device 200.
- Local storage 230 may include information that may be used to implement a freeze lock feature for storage device 200.
- the freeze lock feature may freeze lock storage device 200 and cause storage device 200 to decline processing, for example, security-related commands.
- storage device 200 may provide support for the SECURITY FREEZE LOCK command as defined by the ATA standard.
- Local storage 230 may include executable code (e.g., firmware) that when executed by device processing logic 220 may implement functionality associated with the SECURITY FREEZE LOCK command such as described above. This functionality may include, for example, causing storage device 200 to no longer process security- related commands (e.g., SECURITY SET PASSWORD command) until the storage device 200 is reset or power cycled.
- security- related commands e.g., SECURITY SET PASSWORD command
- Storage 240 may include provisions for storing information for storage device 200.
- Storage 240 may contain, for example, one or more volatile and/or non- volatile memory devices that may be used to store the information. Examples of memory devices that may be used include, but are not limited to, flash memory and DRAM devices.
- storage 240 may include one or more rotating disks (platters) that may be used to store the information.
- the platters may include a coating that may enable the information to be stored, for example, magnetically.
- processing logic 120 may execute one or more computer- executable instructions contained in primary storage 130.
- the executed instructions may generate one or more commands that may be used to perform various functions associated with storage device 200. These functions may include, for example, storing information into and/or retrieving information from storage 240.
- the commands may be sent to storage device 200 via bus 110.
- Storage device 200 may receive the commands and process them.
- processing a command may include executing various computer-executable instructions stored in local storage 230 to perform one or more operations associated with the command.
- Device processing logic 220 may process the command by executing one or more instructions contained in local storage 230 to read the information from storage 240. After reading the information from storage 240, device processing logic 220 may execute one or more instructions in local storage 230 to transfer the information via bus 110 to processing logic 120.
- storage device 200 is an SSD and bus 110 is a PCIe interface.
- Storage device 200 may be compliant with the NVMe specification. This compliance may include supporting various vendor specific commands such as, for example, SECURITY SEND and SECURITY RECEIVE.
- Device processing logic 220 may receive one or more of these vendor specific commands via bus 110 and process the received commands.
- processing may include performing various operations that may be defined by a vendor of storage device 200.
- Freeze lock processing 232 may include logic to automatically freeze lock storage device 200.
- freeze lock processing 232 may include one or more computer-executable instructions that when executed by device processing logic 220 may determine whether storage device 200 should be automatically freeze locked and, if so, automatically freeze lock storage device 200, thereby placing storage device 200 in a frozen security state.
- FIG. 3 illustrates a flow diagram of example acts that may be used to automatically freeze lock a storage device such as, for example, storage device 200.
- the storage device is powered on or reset. Powering on the storage device may include applying power to the storage device. Resetting the storage device may include forcing the device to a known state. The device may be forced to a known state, for example, by issuing a command to the storage device that causes the storage device to enter the known state. For example, a command may be issued to storage device 200 to reset the storage device 200.
- Storage device 200 may receive the command and enter a predefined state which may be defined as an initial state for the storage device 200.
- Entering the predefined known state may include, for example, device processing logic 220 executing code contained in local storage 230 to initialize various state in storage device 200 to a known state.
- power may be applied to storage device 200 and device processing logic 220 may execute code that may initialize storage device 200 to a predefined known state after power-up.
- a check is performed to determine whether the storage device should be automatically freeze locked.
- the determination may be made, for example, based on whether certain criteria has been met.
- the determination may, for example, generate a result.
- the result may be used, for example, to identify an action to be taken after the determination.
- the storage device may be automatically freeze locked.
- “Automatically” here may refer to the storage device 200 entering a freeze lock state autonomously (i.e., on its own accord) and without outside intervention (e.g., without having to receive a command from processing logic 120).
- freeze lock processing 232 may include one or more executable instructions that when executed by device processing logic 220 after storage device has been powered on or reset.
- the instructions when executed may determine whether storage device 200 should be automatically freeze locked.
- the instructions when executed may also cause storage device 200 to automatically enter a frozen security state based on a result of the determination.
- Criteria that may be used to determine whether the storage device should be automatically freeze locked may be time based. For example, a timer may be implemented in storage device 200 that is used to determine whether storage device 200 should be freeze locked. If the timer reaches a predetermined value before certain criteria is met to suspend the timer, the device processing logic 220 may place storage device 200 in a frozen security state.
- the timer may be reset to zero and periodically counted up towards the predetermined value. If the counter reaches the predetermined value before criteria is met to suspend the timer (e.g., a freeze lock command is received by the storage device 200 from an outside source (e.g., processing logic 120)), the device processing logic 220 may place storage device 200 into a frozen security state.
- a freeze lock command is received by the storage device 200 from an outside source (e.g., processing logic 120)
- the device processing logic 220 may place storage device 200 into a frozen security state.
- the timer may be preset with a value and periodically counted down towards the predetermined value (e.g., zero). If the counter reaches the predetermined value before criteria is met to suspend the timer (e.g., a freeze lock command is received by the storage device 200 from an outside source), the device processing logic 220 may automatically place the storage device 200 into a frozen security state.
- the predetermined value e.g., zero
- certain events may trigger starting the timer.
- the timer may be started shortly after the storage device 200 is powered up or reset.
- the timer may be started after any command or a certain type of command (e.g., a security-related command) has been received by the storage device 200.
- Other criteria that may be used to determine whether the storage device should be placed in a frozen security state may include receipt of certain commands, certain types of commands, and/or command sequences.
- device processing logic 120 may issue various commands to storage device 200. These commands may include certain administrative commands that may be used to set up, for example, I/O queues associated with storage device 200.
- device processing logic 220 may place storage device 200 in a frozen security state.
- device processing logic 220 may place storage device 200 in a frozen security state after receiving certain I/O commands (e.g., read, write, and/or seek commands), certain vendor specific commands (e.g., SECURITY SEND, SECURITY RECEIVE), and/or certain sequences thereof.
- I/O commands e.g., read, write, and/or seek commands
- vendor specific commands e.g., SECURITY SEND, SECURITY RECEIVE
- Still other criteria that may be used to determine whether the storage device should be placed in a frozen security state may include, for example, non-receipt of specific commands, certain types of commands, and/or command sequences. For example, in computing device 100, if storage device 200 fails to receive certain security commands (e.g., a freeze lock command) before certain events (e.g., before I/O queues for storage device 200 are set up), device processing logic 220 may place storage device 200 in a frozen security state.
- certain security commands e.g., a freeze lock command
- certain events e.g., before I/O queues for storage device 200 are set up
- the term "user”, as used herein, is intended to be broadly interpreted to include, for example, a computing device (e.g., fixed computing device, mobile computing device) or a user of a computing device, unless otherwise stated.
- a computing device e.g., fixed computing device, mobile computing device
- a user of a computing device unless otherwise stated.
- certain features of the invention may be implemented using computer-executable instructions that may be executed by processing logic such as, for example, device processing logic 220.
- the computer-executable instructions may be stored on one or more non-transitory tangible computer-readable storage media.
- the media may be volatile or non-volatile and may include, for example, DRAM, SRAM, flash memories, removable disks, non-removable disks, and so on.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Retry When Errors Occur (AREA)
- Lock And Its Accessories (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201480060965.8A CN105683992A (en) | 2013-12-06 | 2014-11-04 | Device initiated auto freeze lock |
| BR112016010189A BR112016010189A2 (en) | 2013-12-06 | 2014-11-04 | device-initiated auto-freeze lock |
| KR1020167011625A KR101780615B1 (en) | 2013-12-06 | 2014-11-04 | Device initiated auto freeze lock |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/098,978 US20150161404A1 (en) | 2013-12-06 | 2013-12-06 | Device initiated auto freeze lock |
| US14/098,978 | 2013-12-06 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015084522A1 true WO2015084522A1 (en) | 2015-06-11 |
Family
ID=53271474
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2014/063853 Ceased WO2015084522A1 (en) | 2013-12-06 | 2014-11-04 | Device initiated auto freeze lock |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20150161404A1 (en) |
| KR (1) | KR101780615B1 (en) |
| CN (1) | CN105683992A (en) |
| BR (1) | BR112016010189A2 (en) |
| WO (1) | WO2015084522A1 (en) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11038887B2 (en) | 2017-09-29 | 2021-06-15 | Fisher-Rosemount Systems, Inc. | Enhanced smart process control switch port lockdown |
| KR102899096B1 (en) | 2019-12-18 | 2025-12-10 | 삼성전자주식회사 | Storage device and storage system including the same |
| CN111796771B (en) * | 2020-06-30 | 2024-01-26 | 深圳大普微电子科技有限公司 | Flash memory controller, solid state drive and its controller, flash memory command management method |
| US11954239B2 (en) * | 2021-12-27 | 2024-04-09 | Dell Products L.P. | Data storage system using selective encryption and port identification in communications with drive subsystem |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030046593A1 (en) * | 2001-08-28 | 2003-03-06 | Xie Wen Xiang | Data storage device security method and apparatus |
| US20030163487A1 (en) * | 2002-02-28 | 2003-08-28 | Lanzatella Thomas W. | System and method for characterizing logical storage devices |
| US6757695B1 (en) * | 2001-08-09 | 2004-06-29 | Network Appliance, Inc. | System and method for mounting and unmounting storage volumes in a network storage environment |
| US20050015353A1 (en) * | 2003-07-14 | 2005-01-20 | Sun Microsystems, Inc. | Read/write lock transaction manager freezing |
| US7111321B1 (en) * | 1999-01-25 | 2006-09-19 | Dell Products L.P. | Portable computer system with hierarchical and token-based security policies |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO1995033239A1 (en) * | 1994-05-26 | 1995-12-07 | The Commonwealth Of Australia | Secure computer architecture |
| TW519651B (en) * | 2000-06-27 | 2003-02-01 | Intel Corp | Embedded security device within a nonvolatile memory device |
| JP2004038569A (en) * | 2002-07-03 | 2004-02-05 | Toshiba Lsi System Support Kk | Non-volatile memory data protection system |
| US7979658B2 (en) * | 2008-03-25 | 2011-07-12 | Spansion Llc | Secure management of memory regions in a memory |
| KR20090109345A (en) * | 2008-04-15 | 2009-10-20 | 삼성전자주식회사 | Non-volatile memory device using a resistor, memory system comprising the same |
| US20100031349A1 (en) * | 2008-07-29 | 2010-02-04 | White Electronic Designs Corporation | Method and Apparatus for Secure Data Storage System |
| US8590033B2 (en) * | 2008-09-25 | 2013-11-19 | Fisher-Rosemount Systems, Inc. | One button security lockdown of a process control network |
| US8346305B2 (en) * | 2009-09-25 | 2013-01-01 | Intel Corporation | Theft deterrent techniques and secure mobile platform subscription for wirelessly enabled mobile devices |
| CN101790155A (en) * | 2009-12-30 | 2010-07-28 | 中兴通讯股份有限公司 | Method, device and system for updating security algorithm of mobile terminal |
| JP5419776B2 (en) * | 2010-03-30 | 2014-02-19 | ルネサスエレクトロニクス株式会社 | Semiconductor device and data processing method |
| US20130082974A1 (en) * | 2011-09-30 | 2013-04-04 | Apple Inc. | Quick Access User Interface |
| US9398144B2 (en) * | 2013-10-24 | 2016-07-19 | Cellco Partnership | Mobile device mode of operation for visually impaired users |
-
2013
- 2013-12-06 US US14/098,978 patent/US20150161404A1/en not_active Abandoned
-
2014
- 2014-11-04 WO PCT/US2014/063853 patent/WO2015084522A1/en not_active Ceased
- 2014-11-04 CN CN201480060965.8A patent/CN105683992A/en active Pending
- 2014-11-04 BR BR112016010189A patent/BR112016010189A2/en not_active Application Discontinuation
- 2014-11-04 KR KR1020167011625A patent/KR101780615B1/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7111321B1 (en) * | 1999-01-25 | 2006-09-19 | Dell Products L.P. | Portable computer system with hierarchical and token-based security policies |
| US6757695B1 (en) * | 2001-08-09 | 2004-06-29 | Network Appliance, Inc. | System and method for mounting and unmounting storage volumes in a network storage environment |
| US20030046593A1 (en) * | 2001-08-28 | 2003-03-06 | Xie Wen Xiang | Data storage device security method and apparatus |
| US20030163487A1 (en) * | 2002-02-28 | 2003-08-28 | Lanzatella Thomas W. | System and method for characterizing logical storage devices |
| US20050015353A1 (en) * | 2003-07-14 | 2005-01-20 | Sun Microsystems, Inc. | Read/write lock transaction manager freezing |
Also Published As
| Publication number | Publication date |
|---|---|
| BR112016010189A2 (en) | 2017-08-08 |
| CN105683992A (en) | 2016-06-15 |
| US20150161404A1 (en) | 2015-06-11 |
| KR20160067148A (en) | 2016-06-13 |
| KR101780615B1 (en) | 2017-09-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR102794916B1 (en) | Electronic device and method for restoring application being deleted by factory data reset operation | |
| US10133668B2 (en) | Technologies for providing cross data storage device communications | |
| US9043777B2 (en) | Transferring files to a baseboard management controller (‘bmc’) in a computing system | |
| US9678760B2 (en) | Memory card and storage system having authentication program and method for operating thereof | |
| KR102763870B1 (en) | Power button override for persistent memory enabled platforms | |
| US20150089287A1 (en) | Event-triggered storage of data to non-volatile memory | |
| US20140095767A1 (en) | Storage device trimming | |
| US10153015B2 (en) | Managing disturbance induced errors | |
| KR20150074550A (en) | Data storage device and data processing system including the same | |
| TW201428761A (en) | Power shutdown prediction for non-volatile storage devices | |
| US20150161404A1 (en) | Device initiated auto freeze lock | |
| US9569382B2 (en) | Inhibition device, method for controlling inhibition device, device under control, electronic equipment, and computer readable storage medium | |
| CN111290836A (en) | Virtual machine snapshot creating method and device, storage medium and computer equipment | |
| CN110008159A (en) | PCIE width automatic adaptation method, device and electronic equipment and storage medium | |
| KR102213665B1 (en) | Memory card and storage system having authentication program and method for operating thereof | |
| US9015404B2 (en) | Persistent log operations for non-volatile memory | |
| US9015388B2 (en) | Controlling access to storage in a computing device | |
| CN105556479A (en) | Methods, systems, and computer readable media for partition and cache restore | |
| US9703497B2 (en) | Storage system and storage control method | |
| US9513803B2 (en) | Tagging in a storage device | |
| US9606853B2 (en) | Protecting a memory device from becoming unusable | |
| CN120077357A (en) | Host-independent formatting operations for USB-based storage devices | |
| TWI554891B (en) | Storage control devices and method therefor to invoke address thereof | |
| CN104793765A (en) | Pen gestures for navigation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14866928 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 20167011625 Country of ref document: KR Kind code of ref document: A |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112016010189 Country of ref document: BR |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14866928 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 112016010189 Country of ref document: BR Kind code of ref document: A2 Effective date: 20160505 |