Authenticator, authenticatee and authentication method
5 claims: 5 independent, 0 dependent
- 1外部 コントローラによりコントロールされるメモリ装置であって、 第1 鍵情報 と前記メモリ装置固有に割り当てられた第1 識別情報 とが格納され、前記メモリ装置外からのリードが制限される第1領域と、 前記第1 識別情報 が暗号化されて生成された暗号化第1 識別情報 が格納され、リード可能な第2領域と、 を備え、 前記第1 鍵情報 と 、 外部 装置 から受けた 該外部装置に割り当てられた第2識別情報 とを用い て暗 号化処理を行うことにより、第2 鍵情報を 生成 し 、 前記第2 鍵情報 と前記外部 装置 から受けた 乱数情報 とを用い て暗 号化処理を行うことにより、第3 鍵情報を 生成 し 、 前記第3 鍵情報 と前記第1 識別情報 とを用いて一方向性変換処理を行うことにより、 前記 外部装置との認証に用いられる 一方向性変換識別情報を 生成 し、前記外部装置に認証され るように構成されたメモリ装置。
- 2コントローラと、該コントローラによりコントロールされるメモリ装置とを含むストレージメディアであって、前記メモリ装置は、 第1鍵情報と前記メモリ装置固有に割り当てられた第1識別情報とが格納され、前記メモリ装置外からのリードが制限される第1領域と、 前記第1識別情報が暗号化されて生成された暗号化第1識別情報が格納され、リード可能な第2領域と、 を備え、前記メモリ装置は、 前記第1鍵情報と、外部装置から受けた該外部装置に割り当てられた第2識別情報とを用いて暗号化処理を行うことにより、第2鍵情報を生成し、 前記第2鍵情報と前記外部装置から受けた乱数情報とを用いて暗号化処理を行うことにより、第3鍵情報を生成し、 前記第3鍵情報と前記第1識別情報とを用いて一方向性変換処理を行うことにより、前記外部装置との認証に用いられる一方向性変換識別情報を生成し、前記外部装置に認証されるように構成されたストレージメディア。
- 3メモリ装置固有に割り当てられた第1識別情報が格納されるとともに リードが制限される 第1領域 と、 前記第1識別情報が暗号化されて生成された暗号化第1識別情報が格納されるとともにリード可能な第2領域 とが設けられ 、外部コントローラによりコントロールされる メモリ装置との間で認証処理を実行可能なホスト装置であって、 前記ホスト装置は、 第1鍵情報と、 セッ トと して記録され るとともに前記ホスト装置に割り当てられた第2識別情報としての 第2 鍵情報 と 、 を有し、 前記 第2領域 に格納された 前記 暗号化第1 識別情報 をリードし、前記第 1鍵情報 を用いた処理により得た 情報 によって、前記暗号化 第1識別情報 を復号し、 前記 第2領域 に格納され たイ ンデックス 情報 をリードし、前記セッ トの 中から、 該イ ンデックス 情報 に対応する前記第 2鍵情報 を選び、 前記選ばれた第 2鍵情報 を用いて 乱数情報を 暗号化 する ことにより第3 鍵情報 を生成し、 前記第3 鍵情報 と、前記暗号化第1 識別情報 が復号されて 新たに 生成された第1 識別情報 とを入力値とした一方性変換処理を行い、検証 情報 を生成するように構成されたホスト装置。
- 4外部コントローラによりコントロールされるメモリ装置と、該メモリ装置との間で認証処理を実行可能なホスト装置とを含むシステムであって、 前記メモリ装置は、 第1鍵情報と前記メモリ装置固有に割り当てられた第1識別情報とが格納され、前記メモリ装置外からのリードが制限される第1領域と、 前記第1識別情報が暗号化されて生成された暗号化第1識別情報が格納され、リード可能な第2領域と、を備え、前記メモリ装置は、 前記第1鍵情報と、前記ホスト装置から受けた該ホスト装置に割り当てられた第2識別情報とを用いて暗号化処理を行うことにより、第2鍵情報を生成し、 前記第2鍵情報と前記ホスト装置から受けた乱数情報とを用いて暗号化処理を行うことにより、第3鍵情報を生成し、 前記第3鍵情報と前記第1識別情報とを用いて一方向性変換処理を行うことにより、前記ホスト装置との認証に用いられる一方向性変換識別情報を生成し、前記ホスト装置に認証されるように構成され、 前記ホスト装置は、 第1ホスト鍵情報と、前記ホスト装置に割り当てられた前記第2識別情報と、を有し、 前記第2領域に格納された前記暗号化第1識別情報をリードし、前記第1ホスト鍵情報を用いた処理により得た情報によって、前記暗号化第1識別情報を復号し、 前記乱数情報を暗号化することにより前記第3鍵情報を生成し、 前記第3鍵情報と、前記暗号化第1識別情報が復号されて新たに生成された第1識別情報とを入力値とした一方性変換処理を行い、検証情報を生成するように構成されたシステム。
- 5コントローラと、該コントローラによりコントロールされるメモリ装置とを含むストレージメディアと、該ストレージメディアとの間で認証処理を実行可能なホスト装置とを含むシステムであって、 前記メモリ装置は、 第1鍵情報と前記メモリ装置固有に割り当てられた第1識別情報とが格納され、リードが制限される第1領域と、 前記第1識別情報が暗号化されて生成された暗号化第1識別情報が格納され、リード可能な第2領域と、を備え、前記メモリ装置は、 前記第1鍵情報と、前記ホスト装置から受けた該ホスト装置に割り当てられた第2識別情報とを用いて暗号化処理を行うことにより、第2鍵情報を生成し、 前記第2鍵情報と前記ホスト装置から受けた乱数情報とを用いて暗号化処理を行うことにより、第3鍵情報を生成し、 前記第3鍵情報と前記第1識別情報とを用いて一方向性変換処理を行うことにより、前記ホスト装置との認証に用いられる一方向性変換識別情報を生成し、前記ホスト装置に認証されるように構成され、 前記ホスト装置は、 第1ホスト鍵情報と、前記ホスト装置に割り当てられた前記第2識別情報と、を有し、 前記第2領域に格納された前記暗号化第1識別情報をリードし、前記第1ホスト鍵情報を用いた処理により得た情報によって、前記暗号化第1識別情報を復号し、 前記乱数情報を暗号化することにより前記第3鍵情報を生成し、 前記第3鍵情報と、前記暗号化第1識別情報が復号されて新たに生成された第1識別情報とを入力値とした一方性変換処理を行い、検証情報を生成するように構成されたシステム。
Independent claims5
302 paragraphs, as filed
0001It relates to an authentication device, an authenticated device, and an authentication method thereof.
0002Generally, in fields requiring information security, a method using confidential information shared with each other and a cipher is adopted as a means of proving one's own legitimacy.
0003For example, in an IC card (Smart Card) used for electronic payment, the IC in the card holds an ID and confidential information for individualizing the IC card, and the IC card is based on the ID and confidential information. It has a cryptographic processing function for authentication. In another example, in content copyright protection, the Content Protection for Recordable Media (CPRM) defines an authentication method as a means of proving the validity of an SD (registered trademark) card.
0004When constructing a security system such as authentication, it is necessary to assume that the device that performs the authentication process will be attacked and the confidential information will be extracted, and the extracted confidential information will be invalidated. The method of Revoke is also important. In the Advanced Access Content System (AACS), which is a protection technology specified to protect the content recorded on the CPRM and Blu-ray Disc mentioned above, the Media Key Block is used to invalidate the device key, which is confidential information. It uses a technology called (MKB), and the method that uses a public key cryptography-based protocol uses a list of public key certificates (Revocation List) that is paired with leaked private key information.
0005Taking as an example a system that plays video data recorded on an SD (registered trademark) card with video playback software installed on a PC, the CPRM processing inside the SD (registered trademark) card is implemented in hardware. It is very difficult to illegally extract the confidential information, but it is often easier as an attack to extract the confidential information from the playback software. In reality, there are many softwares on the market that illegally decrypt protected DVDs and Blu-ray video contents, and the malicious software uses confidential information extracted from legitimate software players.
0006In addition, it may be necessary to take measures to prevent counterfeit software and counterfeit SD cards, such as using confidential information extracted from the software to impersonate an SD (registered trademark) card and deceive a legitimate software player. For example, by making it so that the encryption key used for content encryption can be easily read from the imitation SD (registered trademark) card, it can be used as an imitation SD (registered trademark) card using a legitimate video recording device. The recorded video content can be easily decrypted later.
0007Here, the authentication device is provided as a program (software) that can be executed not only by a dedicated hardware device such as a consumer device but also by, for example, a PC (personal computer), and the software becomes a substantial authentication device. In some cases. On the other hand, the authenticated device is, for example, a recording medium, and even if a program called firmware is involved in the operation of the hardware constituting the recording medium, important processing and information are stored in the hardware in the cell array. It is stored in a secret state. Therefore, in reality, for example, when the software executed on the PC is an authenticated device, there is a concern that the tamper resistance (resistance to attack) will be lower than that of the authenticated device such as a recording medium. To.
0008Therefore, by attacking an authentication device with low tamper resistance, it is feared that confidential information hidden in the authenticated device with high tamper resistance will be exposed and pretended to be a device with high tamper resistance. .. In this way, there is a tendency that prevention of unauthorized use of confidential information is required.
0009Further, in recent years, the above demands have become stronger even in an environment where circuit scale restrictions such as public key cryptography processing and MKB processing, which require a relatively large circuit scale, are difficult to implement at the same time. There is also a tendency.
<p num="0010"><nplcit num="1"><text>Content Protection for Recordable Media (CPRM), http://www.4centity.com/</text></nplcit><nplcit num="2"><text>Media Identifier Management Technology (MIMT), http://www.4ecntity.com/</text></nplcit></p>
<p num="0011"> A memory device that is advantageous in preventing unauthorized use of confidential information,<u style="single">Storage media,</u>A host device and a system are provided.</p>
<p num="0012"> According to the memory device of the embodiment<u style="single">External</u>A memory device controlled by a controller, the first<u style="single">Key information</u>And the first assigned uniquely to the memory device<u style="single">Identification information</u>Is stored, and the first area in which reads from outside the memory device are restricted and the first area<u style="single">Identification information</u>Encrypted and generated encryption No. 1<u style="single">Identification information</u>Is stored and includes a second region that can be read, and the first<u style="single">Key information</u>And external<u style="single">apparatus</u>Received from<u style="single">Identification information assigned to the external device</u>With and<u style="single">Dark</u>By performing the numbering process, the second<u style="single">Key information</u>Generate<u style="single">Shi</u>, Said second<u style="single">Key information</u>And the outside<u style="single">apparatus</u>Received from<u style="single">Random number information</u>With and<u style="single">Dark</u>By performing the numbering process, the third<u style="single">Key information</u>Generate<u style="single">Shi</u>, Said third<u style="single">Key information</u>And the first<u style="single">Identification information</u>By performing the one-way conversion process using and<u style="single">Said</u>Used for authentication with external devices<u style="single">One-way conversion identification information</u>Generate<u style="single">And authenticate to the external device</u>Is configured to be.</p>
0013<figref num="1">The block diagram which shows the configuration example of the memory system which concerns on 1st Embodiment.</figref><figref num="2">The flow diagram which shows the authentication flow of the memory system which concerns on 1st Embodiment.</figref><figref num="3">The figure which shows the configuration example of the encrypted LotID bundle (SELID) which concerns on 1st Embodiment.</figref><figref num="4">The block diagram which shows the configuration example of the memory system which concerns on 2nd Embodiment.</figref><figref num="5">The flow diagram which shows the authentication flow of the memory system which concerns on 2nd Embodiment.</figref><figref num="6">The figure which shows the configuration example of the encrypted LotID bundle (SELID) which concerns on 2nd Embodiment.</figref><figref num="7">The block diagram which shows the configuration example of the memory system which concerns on 3rd Embodiment.</figref><figref num="8">The flow diagram which shows the authentication flow of the memory system which concerns on 3rd Embodiment.</figref><figref num="9">The block diagram which shows the configuration example of the memory system which concerns on 4th Embodiment.</figref><figref num="10">The flow diagram which shows the authentication flow of the memory system which concerns on 4th Embodiment.</figref><figref num="11">The block diagram which shows the configuration example of the memory system which concerns on 5th Embodiment.</figref><figref num="12">The flow diagram which shows the authentication flow of the memory system which concerns on 5th Embodiment.</figref><figref num="13">The block diagram which shows the configuration example of the memory system which concerns on 6th Embodiment.</figref><figref num="14">The flow diagram which shows the authentication flow of the memory system which concerns on 6th Embodiment.</figref><figref num="15">The block diagram which shows the configuration example of the memory system which concerns on 7th Embodiment.</figref><figref num="16">The flow diagram which shows the authentication flow of the memory system which concerns on 7th Embodiment.</figref><figref num="17">The figure which shows the configuration example of the encrypted LotID bundle (SELID) which concerns on 7th Embodiment.</figref><figref num="18">The block diagram which shows the configuration example of the memory system which concerns on 8th Embodiment.</figref><figref num="19">The flow diagram which shows the authentication flow of the memory system which concerns on 8th Embodiment.</figref><figref num="20">The figure which shows the configuration example of the encrypted ChipID bundle (SECID) which concerns on 8th Embodiment.</figref><figref num="21">The block diagram which shows the configuration example of the memory system which concerns on 9th Embodiment.</figref><figref num="22">The flow diagram which shows the authentication flow of the memory system which concerns on 9th Embodiment.</figref><figref num="23">The figure which shows the structural example of the encrypted ChipID bundle (SECID) which concerns on 9th Embodiment.</figref><figref num="24">The block diagram which shows the configuration example of the memory system which concerns on tenth Embodiment.</figref><figref num="25">The flow diagram which shows the authentication flow of the memory system which concerns on 10th Embodiment.</figref><figref num="26">The block diagram which shows the configuration example of the memory system which concerns on eleventh embodiment.</figref><figref num="27">The flow diagram which shows the authentication flow of the memory system which concerns on eleventh embodiment.</figref><figref num="28">The block diagram which shows the configuration example of the memory system which concerns on 12th Embodiment.</figref><figref num="29">The figure which shows the authenticated apparatus before writing the SECID according to the twelfth embodiment.</figref><figref num="30">The block diagram which shows the system which downloads the SECID according to the twelfth embodiment.</figref><figref num="31">The flow diagram which shows the flow of downloading the SECID according to the twelfth embodiment.</figref><figref num="32">The block diagram which shows the memory system which concerns on 13th Embodiment.</figref><figref num="33">The block diagram which shows the NAND type flash memory which concerns on 14th Embodiment.</figref><figref num="34">The equivalent circuit diagram which shows the block (BLOCK) which concerns on 14th Embodiment.</figref>
0014Hereinafter, embodiments will be described with reference to the drawings. In this description, a memory system is given as an example of an authentication device, an authenticated device, and an authentication method thereof, but the present invention is not limited to this. In this description, common reference numerals are given to common parts throughout the drawings.
0015[First Embodiment] The authentication device, the authenticated device, and the authentication method thereof according to the first embodiment will be described.
0016<1. Configuration example (memory system)> First, a configuration example of the memory system according to the first embodiment will be described with reference to FIG.
0017As shown in the figure, the memory system according to the first embodiment includes a NAND flash memory 10 which is an authenticated device, a host device 20 which is an authentication device, and a controller 19 which mediates both. The host device 20 accesses the NAND flash memory 10 by the controller 19.
0018Here, the manufacturing process of semiconductor products such as the NAND flash memory 10 will be briefly described. The manufacturing process of semiconductor products is mainly divided into a pre-process for forming a circuit on a substrate wafer and a post-process for wiring and encapsulating a resin package after cutting the wafer into individual pieces. Here, when the controller 19 is configured to be included in the NAND flash memory 10 in the previous process, and is not included in the previous process but is configured to be included in the same package in the subsequent process, NAND There are various cases such as when the chip form is different from that of the type flash memory 10. In the following, including FIG. 1, the case where the controller 19 adopts a chip form different from that of the NAND flash memory 10 is taken as an example. Hereinafter, unless otherwise specified, in most cases, the controller 19 mediates the exchange of data and instructions between the host device 20 and the NAND flash memory 10. Even in this case, the controller 19 does not change the essential contents of the above-mentioned data and instructions, and therefore the details may be omitted. A detailed description of the configuration examples of the NAND flash memory 10 and the controller 19 will be described later.
0019When the host device 20 is composed of dedicated hardware such as a consumer device, not only when the host device 20 is composed of a combination of the dedicated hardware and the firmware for operating the host device 20, but also the function of the device operates on the PC. It may consist of software programs.
0020In the following, each component and data processing shown in FIG. 1 will be described below. In this example, the identification information such as ChipID and LotID recorded in the NAND flash memory 10 which is the authenticated device is read out from a third party in a concealed state, and the data read from the above-mentioned authenticated device 10 is used. A method for surely confirming the existence and a configuration example when the method is applied to the NAND flash memory 10 are shown.
00211-1. NAND flash memory Next, the NAND flash memory 10 which is the authenticated device will be described. The NAND flash memory 10 according to this example includes the cell array 11, the data cache 12 arranged in the peripheral area of the cell array 11, the data generation circuits (Generate) 13, 16, the data coupling circuit (Concatenate) 14, and the random number generator (Random number generator). It is equipped with RNG) 15, exclusive OR circuit (EXOR) 17, encrypter (Encrypt) 18, and so on.
0022In the cell array 11, a plurality of memory cells are arranged in a matrix at the intersections of bit lines and word lines (not shown). The memory cell sequentially includes a tunnel insulating film, a floating gate, an interlayer insulating film, and a control gate connected to a word line on the semiconductor substrate. The current paths of the memory cells in the bit line direction are connected in series to form a cell unit. The cell unit is selected by a selection transistor connected to a bit line and a source line. A plurality of memory cells in the word line direction form one page (Page), which is a unit for reading and writing data. In addition, a plurality of pages form a block, which is a unit of data erasure. Details will be described later.
0023Further, the cell array 11 includes a general area (User area) 11-1, a hidden area (Hidden area) 11-2, a ROM area (ROM area) 11-3, and the like.
0024The general area (User area) 11-1 is an area in which both data recording and data reading are freely possible. A SELID (Set of Encrypted Lot ID), which is a bundle of encrypted LotIDs, is recorded in the general area 11-1. In addition, content data such as photographs, videos, music, and electronic books are recorded in the general area 11-1. A configuration example of SELID in this example will be described later in FIG.
0025The hidden area 11-2 is an area where not only data recording but also data reading is prohibited outside the NAND flash memory 10 (Read / Program inhibit). In the secret area 11-2 according to this example, NKey (first key information), which is secret information used by the NAND flash memory 10 in the above authentication, is recorded. As will be described later, the second key information (HKey) is generated from the first key information (NKey). On the other hand, the first key information (NKey) is not generated from the second key information (HKey).
0026ROM area 11-3 is an area where data recording from the outside is prohibited and data reading is permitted. The chip ID (Chip ID) and lot ID (Lot ID), which are identification information, are recorded in the ROM area 11-3 according to this example. When recording these Chip IDs and Lot IDs, they are generally recorded in an error correction coded state so that the correct identification information can be read even if an error occurs in the data, but an error. The correction coding / decoding process is not particularly shown. Here, the chip ID (Chip ID) refers to a unique ID assigned to each chip of the NAND flash memory 10. The lot ID (LotID) is an ID that is assigned differently for each number in the manufacturing process of the NAND flash memory 10. For example, LotID may be changed for each predetermined quantity such as 1 million pieces, or may be changed for each manufacturing time such as one month or half a year. Further, when it is desired to keep these ChipIDs and LotIDs secret from the outside, they may be recorded in the secret area instead of the ROM area.
0027The ROM area 11-3, the secret area 11-2, and the general area 11-2 in the above may be realized by different physical configurations, or the NAND type flash memory has the same physical configuration. It may be realized by logical control within 10. Here, the logical control is when an identifier that controls access from outside the NAND flash memory 10 is provided for each area, and the identifier is held, and the NAND flash memory 10 receives access to the area from the outside. There is a method such as performing access control by the same identifier.
0028In addition, the individual memory cells constituting the cell array (Cell array) 11 may be those that store a plurality of bits (MLC: Multi Level Cell) or those that record one bit (SLC: Single Level Cell). It may be. Further, the ROM area 11-3 and the secret area 11-2 may be configured to be used in the SLC, and the general area 11-1 may be configured to be used in the MLC. At this time, the physical configuration of the cell array may be different between the SLC area and the MLC area, and only some bits of the memory cell that can be used as the MLC are used and used as a pseudo SLC area. Is also good.
0029The data cache 12 temporarily stores the data read from the cell array 11.
0030The data generation circuits (Generate) 13 and 16 are circuits that generate output data from a plurality of input data by a predetermined operation. The data generation circuit 13 receives information (HC) from the host device 20.<sub>j</sub>) Is converted using the above-mentioned first secret information NKey to obtain HKey.<sub>j</sub>Generate (second key information). In this way, on the NAND flash memory 10 side, the first key information (NKey) to the second key information (HKey)<sub> j</sub>) Can be generated.
0031The data generation circuit 16 receives a random number RN from the host device 20.<sub>h</sub>And the random number RN generated by the NAND flash memory 10 itself<sub>c</sub>The combined data of the above HKey<sub>j</sub>By converting using, the session key SKey<sub>j</sub>To generate. For example, the data generation circuits 13 and 16 can use an AES (Advanced Encryption Standard) encryption device or the like.
0032The data generation circuits (Generate) 13 and 16 are circuits that output new data from a plurality of input information. In order to reduce the overall circuit scale, it is possible to configure a circuit that is the same as or diverted from the encryption device 18. Similarly, the two data generation circuits 13 and 16 shown as different components to make the data processing procedure easier to understand can use the same circuit repeatedly.
0033The data concatenate circuit (Concatenate) 14 has two input data (random number RN).<sub>h</sub>, Random number RN<sub>c</sub>) Is combined, and the combined data is output to the data generation circuit 16.
0034Random number generator (RNG) 15 is a random number RN used for authentication.<sub>c</sub>To generate.
0035The exclusive OR circuit (EXOR) 17 takes two identification information (ChipID, LotID) read from the ROM area 11-3 as inputs, calculates the exclusive OR of these two input data, and outputs the result. To do. When the identification information is recorded in the secret area instead of the ROM area as described above, the identification information which is the input data of the exclusive OR circuit is read out from the secret area.
0036The Encryptor 18 is a circuit that encrypts the input data with the separately input key data and outputs the encrypted input data. In this embodiment, the key data SKey generated by the data generation circuit 16 is the result of calculation by the exclusive OR circuit 17 of the two identification information (ChipID, LotID) read from the ROM area 11-3.<sub>j</sub>Encrypt using, encryption identification information Enc-ID = Enc (SKey)<sub>j</sub>, ChipID (+) LotID) is generated. As described above, the encryption device 18 can also be used as a data generation circuit in order to reduce the overall hardware circuit scale. Here, (+) represents the exclusive OR.
0037Further, although not shown here, for example, an output unit that outputs data sent to the host device 20 via the controller 19 is actually arranged as a component.
0038It should be noted that components such as the data cache 12 other than the cell array 11 can be similarly arranged in the memory controller (Controller) 19, for example.
00391-2. Host device Next, the host device (Host) 20 according to this example will be described. The host device 20 includes a memory (Memory) 23, a random number generation unit (RNG) 25, a data concatenation unit (Concatenate) 26, an exclusive OR unit (EXOR) 24 and 29, a data selection unit (Select) 21, and a data generation unit. It is equipped with (Generate) 27 and decryption units (Decrypt) 22, 28 and the like.
0040The memory (Memory) 23 is the secret information HKey required to execute the authentication process of the present embodiment.<sub>j</sub>And host constant HC<sub>j</sub>Remember. Especially confidential information HKey<sub>j</sub>Must be memorized by means that are not exposed to the outside. Therefore, for example, in the case of a host device such as a consumer device configured by using dedicated hardware, it is recorded in a dedicated memory completely blocked from the outside, or an encryption process prepared by the host device (not shown) is performed. It is desirable to use a means such as recording in memory after being encrypted using. For example, in the case of program software that runs on a PC, the confidential information HKey can be protected by protecting the program itself using anti-tamper software technology.<sub>j</sub>Can also be strictly protected.
0041The random number generator (RNG: Random Number Generator) 25 is the RN used for authentication.<sub>h</sub>To generate.
0042The data concatenate 26 is two input random number data (RN) generated from the random number generators 15 and 25.<sub>h</sub>, RN<sub>c</sub>) Combine and output the combined data.
0043The exclusive OR parts (EXOR) 24 and 29 calculate the exclusive OR of the two input data and output the result.
0044The data selection unit (Select) 21 is a secret information HKey hidden by the host device 20 from the encrypted LotID bundle (SELID) read from the NAND flash memory 10.<sub>j</sub>Encrypted LotID data that can be decrypted using the secret information HKey<sub>j</sub>Select using the index information j of. For example, the secret information HKey<sub>j</sub>Is recorded in the internal dedicated memory after being encrypted by the manufacturer's own method if it is a consumer device, or kept in a state that can be protected from unauthorized analysis by tamper resistant software (TRS) technology if it is a software program. If it is installed or has a built-in security module, it will be concealed after taking measures such as concealing it by using the function of the security module.
0045The data generation unit (Generate) 27 is an arithmetic unit that generates output data from a plurality of input data by a predetermined operation, and performs the same arithmetic processing as the data generation circuit 16 provided in the NAND flash memory. The data generation unit 27 of this example is a random number RN generated by the host device 20 itself.<sub>h</sub>And the random number RN received from the NAND flash memory 10.<sub>c</sub>Confidential information HKey that the host device 20 keeps the combined data<sub>j</sub>By converting using, the session key SKey<sub>j</sub>To generate. The data generation unit 27 can also use an AES encryption operation or the like.
0046The decryption units (Decrypt) 22 and 28 decode the input data with the separately input key data, and output the decoded input data. In this embodiment, the decryption unit 22 uses the secret information HKey hidden by the host device.<sub>j</sub>And if necessary, the confidential information HKey<sub>j</sub>The encrypted LotID data selected by the data selection unit 21 is decrypted using the result of calculating the index information j for identifying the data in the exclusive OR unit as the key information, and is used to obtain the LotID. The decryption unit 28 outputs the encryption identification information Enc-ID received from the NAND flash memory 10 from the data generation unit 27 to the SKey.<sub>j</sub>Decode using and output to exclusive OR 29. As a result of these decoding processes, the host device 20 can obtain data of two identification information, ChipID and LotID.
0047As described above, the host device 20 obtains the LotID from the decoding unit 22 in the first stage. Further, with respect to the obtained LotID and the output data of the decoding unit 28 in the second stage, the ChipID can also be obtained from the calculation result by the exclusive OR 29. Furthermore, the key data SKey shared by the encryption identification information Enc-ID<sub>j</sub>By encrypting using the above, it is confirmed that the identification information (ChipID, LotID) is correctly read from the NAND flash memory 10 authenticated by the host device 20.
0048In addition to this, an error correction processing unit (not shown) is also provided as a component as necessary.
0049<2. Authentication flow> Next, the authentication flow of the memory system in the configuration shown in FIG. 1 will be described with reference to FIG.
0050First, when authentication is started (Start), the host device 20 reads the encrypted LotID bundle (SELID: Set of Encrypted LotID) from the NAND flash memory 10 (Step S11).
0051Subsequently, the host device 20 performs selection processing from the read SELID by the selection unit 21, and reads the encrypted LotID data that can be decrypted by the host device 20. In addition, confidential information HKey that is kept secret<sub>j</sub>The decoding unit 22 performs the above decoding process using the above method to obtain a LotID (Step S12).
0052Subsequently, the host device 20 uses the random number RN required when requesting authentication.<sub>h</sub>To generate. Random number RN for authentication process<sub>h</sub>By using, it is possible to use a different shared key with the NAND flash memory 10 each time by the following processing (Step S13).
0053Subsequently, the host device 20 holds a host constant (HC) in advance together with an authentication request (Request authentication).<sub>j</sub>) And the random number RN<sub>h</sub>To the NAND flash memory 10 (Step S14).
0054Subsequently, the NAND flash memory 10 receives the authentication request, loads the NKey to be concealed in the concealed area 11-2, and holds it in the data cache 12 (Step S15).
0055Next, the NAND flash memory 10 is subjected to the random number RN required for authentication by the random number generator 15.<sub>c</sub>Is generated and sent to the host device (Step S16).
0056Here, in parallel with the processing of Step S16, the host device 20 uses the random number RN generated in Step S13.<sub>h</sub>And the random number RN received in Step S15<sub>c</sub>As a result of the above data binding process by the joining unit 26 using, the joining data RN<sub>h</sub> || RN<sub>c</sub>To generate. In addition, the secret information HKey that was kept secret in advance<sub>j</sub>And the combined data RN<sub>h</sub> || RN<sub>c</sub>By the above data generation process by the generation unit 27, SKey<sub>j</sub> (= Generate (HKey)<sub>j</sub>, RN<sub>h</sub> || RN<sub>c</sub>)) Is generated (Step S17).
0057Next, the NAND flash memory 10 uses the loaded NKey and the host constant HC received in Step S14.<sub>j</sub>By the above data generation processing circuit 13, HKey<sub>j</sub>To generate. Furthermore, the random number RN received in Step S14<sub>h</sub>And the random number RN generated in Step S15<sub>c</sub>From the data coupling processing circuit 14 described above, the coupling data RN<sub>h</sub> || RN<sub>c</sub>To generate. Furthermore, the HKey<sub>j</sub>And the combined data RN<sub>h</sub> || RN<sub>c</sub>The key data SKey by the above data generation process of the data generation circuit 16 using<sub>j</sub>(= Generate (HKey)<sub>j</sub>, RN<sub>h</sub> || RN<sub>c</sub>)) Is generated (Step S18).
0058Subsequently, the host device 20 sends an ID request (Request ID) to the NAND flash memory 10 (Step S19).
0059Subsequently, the NAND flash memory 10 reads the ChipID and LotID from the ROM area 11-3 (Step S21).
0060Subsequently, the NAND flash memory 10 calculates the exclusive OR (ChipID (+) LotID) of ChipID and LotID by the exclusive OR circuit 17. Furthermore, the key data SKey generated in Step S18 by the encryption device 18<sub>j</sub>Encrypted with, encryption identification information Enc-ID (= Enc (SKey)<sub>j</sub>, ChipID (+) LotID)) is generated, and the generated encryption identification information Enc-ID is sent to the host device 20 (Step S22).
0061Subsequently, the host device 20 generates the received encryption identification information Enc-ID by the decryption unit 28 in Step S17, and the key data SKey.<sub>j</sub>Decrypt using to get ID = ChipID (+) LotID (Step S11).
0062Subsequently, the host device 20 obtains the Chip ID by obtaining the exclusive OR of the ID and the LotID obtained in Step S12 by the exclusive OR unit 29 (Step S24).
0063By the above operation, the authentication flow according to the first embodiment is terminated (End).
0064<3. About SELID> Next, the SELID according to this example will be described with reference to FIG. In order to generate a SELID suitable for the NAND flash memory in which the LotID is recorded, the second key information bundle (HKey), which is secret information prepared in advance, is used.<sub>j</sub> Second key information for each (j = 1, ..., n) (Set of HKeys) HKey<sub>j</sub>Encrypt LotIDs one by one using. That is, SELID is the encrypted LotID.<sub>j</sub>(E-LotID<sub>j</sub>) = Encrypt (HKey)<sub>j</sub>, LotID), and this set of encrypted LotIDs is called an encrypted LotID bundle.
0065At the time of encryption, each second key information HKey is required.<sub>j</sub>Uses the result of exclusive OR operation with each index information j as an encryption key, and the encryption LotID at that time.<sub>j</sub>Is calculated as: E-LotID<sub>j</sub> = Encrypt (HKey)<sub>j</sub> (+) j, LotID).
0066Here, the above example is HKey<sub>j</sub> This is an example of using (+) j as an encryption key, but the present invention is not limited to this, and for example, a cyclic shift operation may be used. The cyclic shift operation is to move a bit and move the bit that has exceeded the digit by moving it to the opposite side. Taking the left cyclic shift operation as an example, if 11010101 is cyclically shifted to the left three times in binary notation, it becomes 10101110. You may calculate the encryption key using the formula shown below: E-LotID<sub>j</sub> = Encrypt (CyclicLeftShift (HKey)<sub>j</sub> , j), LotID). Here, CyclicLeftShift (HKey)<sub>j</sub> , j) is HKey<sub>j</sub>Represents a j-turn shift to the left. In this case, the exclusive OR portion 24 in FIG. 1 may be replaced with a left cyclic shift unit that performs a left cyclic shift operation. These matters are the same in other embodiments described later.
0067The SELID configuration is not limited to this example. For example, a specific HKey<sub>j</sub>If is exposed, the HKey<sub>j</sub>In order to prevent the host device 20 that holds the LotID from decrypting the LotID from the encrypted LotID bundle, the secret information HKey<sub>j</sub>When using the NAND flash memory 10 that records the newly configured SELID by deleting the encrypted LotID that can be decrypted in, the host device must obtain (decrypt) the correct LotID and ChipID. It is also possible to prevent this from happening. By doing so, the confidential information HKey<sub>j</sub>It is also possible to provide a function of disabling the host device 20 that holds the above.
0068<4. Action effect> According to the authentication device, the authenticated device, and the authentication method thereof according to the first embodiment, at least the following effects (1) and (2) can be obtained.
0069(1) Even if the secret information is leaked from the host device 20, it is possible to prevent unauthorized use of the secret information of the NAND flash memory 10 using the leaked information. Here, the host device 20, which is an authentication device, is provided not only as a dedicated hardware device such as a consumer device but also as a program (software) that can be executed by, for example, a PC (personal computer), and the software is substantially used. It may be a host device. On the other hand, the NAND flash memory 10 which is the authenticated device is a recording medium, and important processing and information are concealed in the hardware in the cell array 11 even when a program called firmware intervenes. It is remembered in. Therefore, in reality, for example, software executed on a PC may have lower tamper resistance (attack resistance) than recording media. Therefore, by attacking the host device (authentication device) 20 with low tamper resistance, the secret information hidden in the NAND flash memory 10 (authentication device) with high tamper resistance is also exposed, and the tamper resistance is high. There is concern that it will be masqueraded as an expensive device.
0070Therefore, in the configuration and the authentication method according to the first embodiment, as described above, the NAND flash memory 10 having a relatively high tamper resistance has the first key information (NKey) to the second key information (HKey). The first key information (NKey) that generates the above is concealed in the cell array 11. On the other hand, the host device 20, which has a relatively low tamper resistance, does not generate the first key information (NKey) from the second key information (HKey). Only the second key information (HKey) is concealed in the memory 23. ..
0071Therefore, the NAND flash memory 10 uses the original information (HC) received from the host device 20 and the first key information (NKey) concealed by itself, and the second key information (HKey) concealed by the authentication device. To generate. The NAND flash memory 10 has second key information (HKey) and random number information (RN).<sub>h</sub>, RN<sub>c</sub>) And generate a session key (SKey).
0072The host device 20 has a secret second key information (HKey) and random number information (RN).<sub>h</sub>, RN<sub>c</sub>) And generate a session key (SKey'). As a result, the NAND flash memory 10 and the host device 20 both share a session key having the same value.
0073As described above, in this example, the secret level of the information concealed by the NAND flash memory (authenticated device) 10 and the secret level of the information concealed by the host device (authentication device) 20 can be made asymmetric. For example, in this example, the secret level of the information hidden by the NAND flash memory 10 having a relatively high tamper resistance is set higher than the secret level of the information hidden by the host device 20 having a relatively low tamper resistance. can do.
0074Therefore, even if the information concealed by the host device 20 is leaked, the confidentiality level of the information concealed by the NAND flash memory 10 having a relatively high tamper resistance is higher, so that the leaked information is used for NAND. Cannot "impersonate" the type flash memory 10. Therefore, it is advantageous in that it is possible to prevent unauthorized use of the confidential information of the NAND flash memory 10 using the leaked information. As a result, for example, it is possible to surely confirm that the ID information read from the authentication device is the information read from the target authenticated device, and invalidate the unauthorized use of the other party.
0075(2) It is advantageous in implementation. In a configuration like this example, there are simultaneous circuit scale restrictions such as difficulty in implementing hardware for public key cryptography and MKB processing, which require a relatively large circuit scale.
0076However, according to this example, it is not necessary to use public key cryptography, which requires a relatively large circuit scale although the key information is asymmetric. Furthermore, as described above, by making the secret level of the information hidden by the host device (authentication device) 20 and the NAND flash memory (authenticated device) 10 asymmetric, the information leaked from one device is no longer sufficient. An authentication means that cannot be impersonated by one device is performed, and the session key (SKey), which is confidential information, is shared between the authentication device and the authenticated device.
0077Therefore, it can be said that it is advantageous in implementation even in a harsh environment where the above restrictions are imposed.
0078Further, as described above, it is possible to make the circuit scale relatively small by performing the same processing on the data generation circuit and the encryption device constituting the memory system.
0079[Second embodiment (an example including a plurality of NKeys)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the second embodiment will be described. This embodiment relates to an example including a plurality of NKeys (first key information). In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0080<Configuration example (memory system)> First, a configuration example according to the second embodiment will be described with reference to FIG. As shown in the figure, in the configuration example according to the second embodiment, a plurality of secret information NKeys are set in the hidden area 11-2 in the cell array 11 of the NAND flash memory 10.<sub>i</sub> (i = 1, ..., m) It differs from the first embodiment above in that it is concealed. Furthermore, the secret information NKey that is kept secret according to the index information i received from the host device (authentication device).<sub>i</sub>From (i = 1, ..., m) to NKey<sub>i</sub>A selection unit 31 for selecting is further provided.
0081Further, in the host device 20, the memory 23 is the secret information NKey in the NAND flash memory 10.<sub>i</sub>Corresponding confidential information HKey<sub>i, j</sub>The index information i indicating whether or not is concealed is concealed.
0082In the above configuration, the host device 20 uses the index information i for designating the secret information together with the index information j by the selection unit 21 at the time of executing the authentication process, and the host device itself can decrypt the code from the SELECT ID. Select LotID.
0083At the same time, the host device 20 transmits the index information i to the NAND flash memory 10.
0084The NAND type flash memory 10 has secret information NKey that is kept secret by the selection unit 31.<sub>i</sub>NKey corresponding to the index information i received from (i = 1, ..., m)<sub>i</sub>Select.
0085<Authentication flow> Next, the authentication flow according to the second embodiment will be described with reference to FIG. As shown in the figure, in this example, the secret information NKey hidden in the NAND flash memory at the time of the authentication request (Request authentication) in step S14.<sub>i</sub>The index information i required for selecting the above is further transmitted from the host device 20 to the NAND flash memory 10.
0086Further, at the time of step S18, in the NAND flash memory 10, the second key information HKey<sub>i, j</sub>The index information i is used to generate.
0087Since the other authentication flows are substantially the same as those in the first embodiment, detailed description thereof will be omitted.
0088<About SELID> Next, SELID according to the second embodiment will be described with reference to FIG. As shown in (a) and (c), in the second embodiment, since the index information for specifying NKey and HKey is i and j, it is a two-dimensional matrix. ..
0089Others are substantially the same as those of the first embodiment, and thus detailed description thereof will be omitted.
0090<Action effect> According to the authentication device, the authenticated device, and the authentication method thereof according to the second embodiment, it is possible to obtain the same effects as those of the first embodiment of the above (1) and (2).
0091Further, in the second embodiment, a plurality of NKeys are set in the hidden area 11-2 in the cell array 11 of the NAND flash memory 10.<sub>i</sub> (i = 1, ..., m) Keep it secret.
0092Therefore, the host device 20 corresponding to this also hides the secret information HKey that differs for each purpose, so even if the HKey or NKey distributed for a specific use is exposed, it can be used for other purposes. Is even more advantageous in that it does not have an adverse effect.
0093For example, if you assign the first secret information NKey for the video player and the second secret information NKey for the e-book, the secret information HKey assigned for the video player<sub>1, j</sub>/ NKey<sub>1</sub>Even if is exposed, the confidential information HKey that was exposed<sub>1, j</sub>/ NKey<sub>1</sub>Cannot be used to configure an e-book reader. Alternatively, if different HKey / NKeys are assigned to each host device manufacturer, even if the secret information is exposed from the host device of the manufacturer A, the host device of the manufacturer B cannot be configured. Therefore, it is possible to newly manufacture and provide the NAND type flash memory 10 in which only the specific maker A whose confidential information has been exposed cannot correctly read the LotID and ChipID.
0094[Third embodiment (an example in which a plurality of NKeys are provided for each Lot)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the third embodiment will be described. This embodiment relates to an example in which a plurality of NKeys (first key information) are provided for each Lot (for each NAND manufacturer). In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0095<Configuration example (memory system)> First, a configuration example according to the third embodiment will be described with reference to FIG. 7. As shown in the figure, in the configuration example according to the third embodiment, a plurality of NKeys are set in the hidden area 11-2 of the NAND flash memory 10.<sub>i</sub> One secret information NKey selected from (i = 1, ..., m)<sub>i</sub>Is recorded. Furthermore, in the ROM area 11-3, the secret information NKey<sub>i</sub>It differs from the first embodiment in that the index information i for specifying the above is recorded.
0096Further, the host device 20 has m secret information NKeys.<sub>i</sub> Which NKey in (i = 1, ..., m)<sub>i</sub>Confidential information HKey so that authentication processing can be executed even with the NAND type flash memory 10 that hides<sub>i</sub> Keep all (i = 1, ..., m) secret.
0097In the above configuration, the host device 20 reads the index information i from the NAND flash memory 10 when executing the authentication process, and hides the HKey.<sub>i</sub> Corresponding HKey from (i = 1, ..., m)<sub>i</sub>Select. Further, similarly, the encrypted LotID that can be decrypted by the host device 20 itself is selected from the encrypted LotID bundle (SELID) read from the NAND flash memory 10.
0098<Authentication flow> Next, the authentication flow according to the third embodiment will be described with reference to FIG. In this example, the NAND flash memory 10 has the secret information NKey in the ROM area 11-3 at the time of step S32.<sub>i</sub>Further load the index information i to identify.
0099At step S33, the host device 20 reads the encrypted LotID bundle (SELID) from the NAND flash memory 10 and secret information NKey hidden in the NAND flash memory.<sub>i</sub>The index information i for specifying is further read.
0100Subsequently, the host device 20 keeps secret information HKey according to the read index i in step S17.<sub>i</sub> Corresponding HKey from (i = 1, ..., m)<sub>i</sub>Decrypt LotID from SELID using.
0101Further, the host device 20 uses the index information i received in the above process to set the secret information set HKey.<sub>i, j</sub> Key data from (i = 1, ..., m) SKey<sub>i, j</sub>HKey required to generate<sub>i, j</sub>Select.
0102In the processing flow shown in the figure, the indexes i and SELID are read in this order, but the reading order is not particularly limited.
0103<About SELID> Also in this embodiment, there are two index information for specifying HKey, i and j. Therefore, the SELECT ID is the same as that of the second embodiment shown in FIG. 6 above.
0104Others are substantially the same as those of the first embodiment, and thus detailed description thereof will be omitted.
0105<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the third embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0106Further, in the third embodiment, a plurality of NKeys (first key information) are stored in the secret area 11-2 of the NAND flash memory 10 for each Lot (for each NAND manufacturer). Furthermore, in the ROM area 11-3, the secret information NKey<sub>i</sub>Record the index information i to identify.
0107In this way, by changing the NKey to be kept secret for each NAND flash memory maker, the information management of a specific NAND flash memory maker was insufficient, so the NKey, which is particularly important secret information, leaked. Even if the secret information NKey is leaked due to insufficient information concealment method in the sold NAND flash memory, the NAND flash memory manufactured by other NAND flash memory makers can be used. It is advantageous in that it will continue to be available.
0108[Fourth embodiment (an example of recording SELI D in a protected area)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the fourth embodiment will be described. This embodiment relates to an example of recording a SELID in a protected area. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0109<Configuration example (memory system)> First, a configuration example according to the fourth embodiment will be described with reference to FIG. As shown in the figure, in the fourth embodiment, the encrypted LotID bundle (SELID) is recorded in the protected area 11-4 of the cell array 11 of the NAND flash memory 10. Different from the embodiment. The protected area 11-4 is an area where data write / read processing is permitted only when the authentication process separately implemented in the controller 19 is successful for external access.
0110Such a protected area 11-4 is an area currently in circulation, for example, an area provided in an SD (registered trademark) card or the like, and the data recorded in the protected area 11-4 is with the controller 19. Not only can it be kept secret from other than the legitimate host device 20 that can execute the authentication process, but it is also possible to prevent the user from accidentally rewriting / deleting the data. Therefore, it is also an area for storing information indispensable for data reproduction processing.
0111Therefore, the SELECT according to this example is transmitted to the host device 20 after establishing the secure channel 33 in which the authentication process separately prepared with the controller 19 is executed.
0112<Authentication flow> Next, the authentication flow according to the fourth embodiment will be described with reference to FIG.
0113As shown in the figure, in step S35, the host device 20 establishes a secure channel by executing an authentication process separately prepared with the controller 19.
0114Therefore, during step S35, the host device 20 obtains access permission to the protected area 11-4 and reads the encrypted LotID bundle (SELID) through the established secure channel.
0115The SELID according to the fourth embodiment is the same as that shown in FIG.
0116Since other configurations and the like are the same as those of the first embodiment, detailed description thereof will be omitted.
0117<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the fourth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0118Further, in the fourth embodiment, the encrypted LotID bundle (SELID) is recorded in the protected area 11-4 of the cell array 11. Therefore, it is possible to prevent troubles such as being unable to read ChipID and LotID caused by the user mistakenly rewriting / deleting the SELID.
0119[Fifth embodiment (an example in which the NAND is not provided with a random number generator)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the fifth embodiment will be described. This embodiment relates to an example in which the NAND flash memory 10 is not provided with the random number generator 15. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0120<Configuration example (memory system)> A configuration example according to the fifth embodiment will be described with reference to FIG.
0121As shown in the figure, in the configuration example according to the fifth embodiment, the NAND flash memory 10 is not provided with the random number generator (RNG) 15.
0122Instead, the fixed value index information (i-NAND) prepared in advance for each NAND flash memory 10 is held in the ROM area 11-3 in the cell array. This i-NAND is a random number RN in the first embodiment.<sub>c</sub>Key data instead of SKey<sub>j</sub>It is a value used when generating a NAND flash memory, and various generation means such as a random value generated in advance when manufacturing a NAND flash memory, a hash value of ChipID or LotID, and a value obtained by encrypting ChipID or LotID with a specific value. The value generated in can be used.
0123Therefore, the NAND flash memory 10 further includes a data cache 12B.
0124<Authentication flow> Next, the authentication flow according to the fifth embodiment will be described with reference to FIG. As shown in the figure, when the NAND flash memory 10 receives an authentication request (Request authentication) from the host device 20 in step S16, the NAND flash memory 10 is fixed from the ROM area 11-3 instead of generating a random number by the random number generator. The value index information (i-NAND) is read and sent to the host device 20.
0125The host device 20 and the NAND flash memory 10 have key data SKey.<sub>j</sub>Random number RN generated by the host device when generating<sub>h</sub>And the i-NAND combined data RN<sub>h</sub> || i-NAND and HKey<sub>j</sub>Perform the above data generation process using (SKey)<sub>j</sub> = Generate (HKey<sub>j</sub>, RN<sub>h</sub> || i-NAND)).
0126The SELID according to the fifth embodiment is the same as that shown in FIG.
0127Since the other parts are substantially the same as those of the first embodiment, detailed description thereof will be omitted.
0128<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the fifth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0129Further, in the fifth embodiment, the NAND flash memory 10 does not include the random number generator (RNG) 15 shown in FIG. Therefore, the scale of the mounting circuit of the NAND flash memory 10 can be made smaller, which is more advantageous for miniaturization.
0130[Sixth Embodiment (an example of generating a Token)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the sixth embodiment will be described. This embodiment relates to an example of generating verification data (Token). In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0131<Configuration example (memory system)> A configuration example according to the sixth embodiment will be described with reference to FIG.
0132As shown in the figure, in the configuration example according to the sixth embodiment, the data generation circuits (Generate) 16 and 26 are used on both the NAND flash memory 10 side and the host device 20 side, and the secret information HKey.<sub>j</sub>And the combined data RN of two random numbers<sub>h</sub> || RN<sub>c</sub>From key data SKey<sub>j</sub>The same key data SKey between the host device and the NAND flash memory<sub>j</sub>It differs from the above embodiment in that the verification data (Token) for confirming that the above-mentioned can be generated is generated.
0133The verification data (Token) is the session key SKey.<sub>j</sub>The data may be calculated based on the values shared by the host device 20 and the NAND flash memory 10. In this embodiment, the value RN in which the combination order of the two random numbers is exchanged.<sub>c</sub> || RN<sub>h</sub>Token (= Generate (SKey)) obtained using<sub>j</sub>, RN<sub>c</sub>|| RN<sub>h</sub>)) Is used as an example. In the figure, Generate () is described as G () due to space limitations.
0134The session key SKey<sub>j</sub>The data generation circuit used for generation and the data generation circuit used for token generation are shown as the same circuit. However, since the purpose is to generate the same data in the host device 20 and the NAND flash memory 10, the above two data generation circuits do not necessarily have to be the same data generation circuit, and even if they are configured by different circuits. Good.
0135The generated verification data Token is sent from the NAND flash memory to the host device.
0136The host device 20 determines in the comparator 35 whether or not the received verification data Token and the verification data calculated by the host device itself match. If the verification data Token value is the same (Yes), the gate 36 is the session key SKey.<sub>j</sub>Is output to the decryption unit (Decrypt) 28, and the subsequent processing is continued in the same manner as in the first embodiment. On the other hand, if the verification data Token value is different (No), the subsequent processing is stopped (Abort).
0137<Authentication flow> Next, the authentication flow according to the sixth embodiment will be described with reference to FIG. In the sixth embodiment, the key data SKey in the first embodiment<sub>j</sub>After generating, the following processing is added.
0138The host device 20 generated the key data SKey during step S36.<sub>j</sub>And two random numbers RN<sub>h</sub>And RN<sub>c</sub>Verification data from Token = Generate (SKey)<sub>j</sub>, RN<sub>c</sub>|| RN<sub>h</sub>) Is calculated.
0139Similarly, the NAND flash memory also has the key data SKey generated during step S37.<sub>j</sub>And two random numbers RN<sub>h</sub>And RN<sub>c</sub>Verification data from Token = Generate (SKey)<sub>j</sub>, RN<sub>c</sub>|| RN<sub>h</sub>) Is calculated and the Token is sent to the host device.
0140Then, at the time of step S39, the host device confirms whether the received Token and the Token generated by the host device itself match, and if they match, the subsequent authentication process is continued, and if they do not match, the subsequent authentication process is continued. Cancels the subsequent authentication process.
0141The SELID according to the sixth embodiment is the same as that shown in FIG.
0142Others are the same as those in the first embodiment, and thus detailed description thereof will be omitted.
0143<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the sixth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0144Further, in the sixth embodiment, the same key data SKey is used between the host device and the NAND flash memory.<sub>j</sub>The verification data (Token) for confirming that the is generated is generated, and this match is judged.
0145Therefore, it can be confirmed that the key sharing process by authentication is performed correctly between the two parties, and it is possible to easily confirm that an error or falsification has occurred in the data in an unauthorized authentication partner or an intermediate path of the authentication process. In that respect, it is further advantageous.
0146[Seventh embodiment (an example of using another set of ID Keys for SELECT ID encryption)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the seventh embodiment will be described. This embodiment relates to an example in which another set of ID Keys is used for SELECT ID encryption. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0147<Configuration example (memory system)> A configuration example according to the seventh embodiment will be described with reference to FIG.
0148As shown in the figure, in the configuration example according to the seventh embodiment, the encryption key used for generating the encrypted LotID bundle (SELID) is changed to an encryption key IDKey different from the HKey derived from NKey. Different from the embodiment. However, the components of the NAND flash memory 10 according to this example include There are no substantial changes.
0149The host device 20 according to this example has a new secret information IDKey in the memory 23.<sub>k</sub>Is concealed, and the IDKey is used for decryption processing of the SELID read from the NAND flash memory 10.<sub>k</sub>The difference is that it uses. However, there is no change in the decryption process itself.
0150<Authentication flow> Next, the authentication flow according to the seventh embodiment will be described with reference to FIG. As shown in the figure, the host device 20 is set to the secret information IDKey during step S12.<sub>k</sub>It differs from the above embodiment in that the encrypted LotID bundle (SELID) read from the NAND flash memory 10 is decrypted by using the index information k and the index information k.
0151Further, as described above, since the key data used for LotID encryption has been changed, a configuration example of SELID in this example is shown as shown in FIG.
0152Since the other parts are substantially the same as those of the first embodiment, detailed description thereof will be omitted.
0153<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the seventh embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0154Further, in the seventh embodiment, even if the secret information NKey hidden in the NAND flash memory is used, the SELID cannot be decrypted and the LotID cannot be obtained. Therefore, even if the secret information NKey is exposed from the NAND flash memory 10 or the secret information NKey is leaked from the manufacturer of the NAND flash memory 10, the LotID and ChipID can be decrypted using the SELID. It is even more advantageous in that the host device can be eliminated.
0155[Eighth embodiment (an example in which ChipID transmission is a one-way function)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the eighth embodiment will be described. This embodiment relates to an example in which the operation at the time of ChipID transmission is a one-way function. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0156<Configuration example (memory system)> A configuration example according to the eighth embodiment will be described with reference to FIG. As shown in the figure, in the configuration example according to the eighth embodiment, ChipID instead of LotID is encrypted in the general area (User area) 11-1 in the cell array (Cell array) 11 of the NAND flash memory 10. It differs from the above embodiment in that the configured encrypted ChipID bundle (SECID) is recorded and only the ChipID is recorded in the ROM area 11-3.
0157Further, the NAND flash memory 10 and the host device 20 have a session key SKey.<sub>j</sub>It is equipped with one-way converters (Oneway) 38 and 39 for performing one-way operations instead of encrypting the ID by.
0158The host device 20 reads the SECID from the NAND flash memory 10 and reads the HKey.<sub>j</sub>And the decoding unit 22 similar to the first embodiment for obtaining the ChipID from the SECID using the index information j.
0159The host device 20 is a value obtained by unidirectionally converting the ChipID received from the NAND flash memory 10 (Oneway (SKey)).<sub>j</sub>, ChipID)) and a data verification unit 40 that determines the verification verification result of the one-way conversion value of ChipID calculated by the host device 20 itself.
0160<Authentication flow> Next, the authentication flow according to the eighth embodiment will be described with reference to FIG. As shown in the figure, when authentication is started (Start), the host device 20 first reads the encrypted Chip ID bundle (SECID: Set of Encrypted Chip ID) from the NAND flash memory 10 (Step S11).
0161Subsequently, the host device 20 performs the above selection process from the read SECID, reads the encrypted ChipID data that can be decrypted by the host device, and secretly hides the secret information HKey.<sub>j</sub>The Chip ID is obtained by decoding by the above decoding process using the above (Step S12).
0162Subsequently, the host device 20 uses the random number RN required when requesting authentication.<sub>h</sub>To generate. By using a random number in the authentication process, a different shared key is used each time with the NAND flash memory in the following process (Step S13).
0163Subsequently, the host device 20 holds a host constant (HC) in advance together with an authentication request (Request authentication).<sub>j</sub>) And the random number RN<sub>h</sub>Is sent to the NAND flash memory 10 (Step S14).
0164Next, the NAND flash memory 10 has a random number RN required for authentication.<sub>c</sub>Is generated and sent to the host device (Step S15).
0165Next, the NAND flash memory 10 uses the hidden NKey and the HC received in Step S14.<sub>j</sub>HKey by the above data generation process using<sub>j</sub>Random number RN received in Step S14<sub>h</sub>And the random number RN generated in Step S15<sub>c</sub>Combined data RN by the above data combination process<sub>h</sub> || RN<sub>c</sub>Is generated and the above HKey<sub>j</sub>And the combined data RN<sub>h</sub> || RN<sub>c</sub>Key data SKey by the above data generation process using<sub>j</sub>(= Generate (HKey)<sub>j</sub>, RN<sub>h</sub> || RN<sub>c</sub>)) Is generated (Step S16) In parallel with the processing in step S16, the host device 20 generates a random number RN.<sub>h</sub>And the received random number RN<sub>c</sub>Combined data RN by the above data combination process<sub>h</sub> || RN<sub>c</sub>Confidential information HKey that was generated and kept secret in advance<sub>j</sub>And the combined data RN<sub>h</sub> || RN<sub>c</sub>SKey by the above data generation process using<sub>j</sub>(= Generate (HKey)<sub>j</sub>, RN<sub>h</sub> || RN<sub>c</sub>)) Is generated (Step S17).
0166Subsequently, the host device 20 sends an ID request (Request ID) to the NAND flash memory (Step S19).
0167Subsequently, the NAND flash memory 10 reads the ChipID from the ROM area (Step S21).
0168Next, the NAND flash memory 10 uses the key data SKey that generated the ChipID.<sub>j</sub>Performs one-way conversion using, and one-way conversion data Oneway-ID (= Oneway (SKey)<sub>j</sub>, ChipID)) and send the generated one-way conversion data Oneway-ID to the host device (Step S38).
0169Subsequently, the host device 20 uses the key data SKey that generated the ChipID.<sub>j</sub>Perform one-way conversion using and obtain the one-way conversion data Oneway-ID (Step S39).
0170Subsequently, the host device 20 confirms that the received one-way conversion data Oneway-ID matches the obtained one-way conversion data, and if they match, determines that the ChipID is the correct ChipID. If they do not match, it is determined that the Chip ID is an invalid ID (Step S40). By the above operation, the authentication flow according to the eighth embodiment is terminated (End).
0171Similarly, a configuration example of SECID, which is a bundle of encrypted ChipIDs, is shown as shown in FIG.
0172Others are substantially the same as those in the first embodiment.
0173<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the eighth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0174Further, in the eighth embodiment, an encrypted ChipID bundle configured by encrypting ChipID instead of LotID in the general area (User area) 11-1 in the cell array 11 of the NAND flash memory 10. (SECID) is recorded, and only ChipID is recorded in ROM area 11-3.
0175Therefore, the amount of ID information that the NAND flash memory 10 must hold can be reduced.
0176[9th embodiment (an example of a combination of the 7th and 8th embodiments)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the ninth embodiment will be described. This embodiment relates to an example of a combination of the seventh and eighth embodiments. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0177<Configuration example (memory system)> A configuration example according to the ninth embodiment will be described with reference to FIG.
0178As shown in the figure, the present embodiment includes modifications of both the seventh and eighth embodiments in addition to the first embodiment. That is, the main difference from the first embodiment is the introduction of the ID Key and the change of the SELI D to the SECID.
0179<Authentication flow> FIG. 22 shows the authentication flow according to the ninth embodiment.
0180As shown in the figure, the authentication flow is also a combination of the authentication flow of the seventh embodiment and the authentication flow of the eighth embodiment.
0181Similarly, a configuration example of SECID, which is a bundle of encrypted ChipIDs, is shown as shown in FIG.
0182Others are substantially the same as those in the first embodiment.
0183<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the ninth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0184Further, in the ninth embodiment, it is possible to obtain both the effects added in the seventh embodiment and the eighth embodiment.
0185[10th embodiment (an example of a combination of the 3rd, 7th, and 8th embodiments)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the tenth embodiment will be described. This embodiment relates to an example of combining the third, seventh, and eighth embodiments. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0186<Configuration example (memory system)> A configuration example according to the tenth embodiment will be described with reference to FIG. 24.
0187As shown in the figure, the present embodiment includes differences added to the third, seventh, and eighth embodiments. That is, the main differences from the first embodiment are the introduction of the ID Key, the change from SECID to SECID, and the fact that the host device conceals a plurality of confidential information HKeys.
0188<Authentication flow> Next, the authentication flow according to the tenth embodiment will be described with reference to FIG. 25.
0189As shown in the figure, the authentication flow is also different in that the following processing flow is added to the authentication flow of the ninth embodiment.
0190First, the host device 20 makes a request authentication at the time of step S14.
0191Subsequently, the host device 20 receives the random number RN at the time of step S33.<sub>h</sub>And host constant HC<sub>j</sub>NKey hidden in NAND flash memory after sending<sub>i</sub>The index information i of is read from the ROM area of the NAND flash memory. Furthermore, the host device is a random number RN from the NAND flash memory.<sub>c</sub>Is received, and then the secret information set HKey is used using the index information i received in the above process.<sub>i, j</sub> Key data from (i = 1, ..., m) SKey<sub>i, j</sub>HKey required to generate<sub>i, j</sub>Select.
0192However, the processing flow shown in FIG. 25 is an example, and reading index information i and HKey<sub>i, j</sub>The selection process and the like are not limited to this process flow as long as the data required for each process can be obtained in advance.
0193Similarly, a configuration example of SECID, which is a bundle of encrypted ChipIDs, is shown as shown in FIG.
0194Others are substantially the same as those in the first embodiment.
0195<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the tenth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0196Further, according to the tenth embodiment, it is possible to obtain the effects of the third, seventh, and eighth embodiments.
0197[11th embodiment (an example without a random number generator)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the eleventh embodiment will be described. This embodiment relates to an example in which the NAND flash memory 1 does not include the random number generator 15 in the tenth embodiment. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0198<Configuration example (memory system)> A configuration example according to the eleventh embodiment will be described with reference to FIG. 26.
0199As shown in the figure, the tenth embodiment is different from the tenth embodiment in that the random number generator (RNG) 15 provided in the NAND flash memory is not provided.
0200In the tenth embodiment, two random numbers RN<sub>h</sub>And RN<sub>c</sub>Combined data and secret data HKey<sub>i, j</sub>And from session key data SKey<sub>i, j</sub>Was generated, but in this embodiment, the random number RN<sub>h</sub>And secret data HKey<sub>i, j</sub>And from session key data SKey<sub>i, j</sub>To generate.
0201Hereinafter, details of the configuration example according to the eleventh embodiment will be described. In the embodiment, the identification information ChipID recorded in the NAND flash memory, which is the authenticated device, is read out from a third party in a concealed state, and the data is surely read from the above-mentioned authenticated device. The confirmation method and the configuration when the same method is applied to the NAND flash memory are shown.
0202NAND flash memory As described above, the NAND flash memory 10 is an authenticated device.
0203As shown in the figure, the NAND flash memory 10 according to this example includes the cell array 11, the data caches 12A and 12B arranged in the peripheral area of the cell array, the data generators (Generate) 13 and 16, and the random number generator (RNG). 15, equipped with one-way converter (Oneway) 38, etc.
0204The cell array (Cell array) 11 is a ROM area (ROM area) 11-3, a hidden area (Hidden area) 11-2, and a general area (User area) 11-.<u style="single">1</u>Etc. ROM area 11-3 is an area where data recording from the outside is prohibited and data reading is permitted. The ROM area 11-3 according to this example contains the ChipID, which is the identification information, and the secret information NKey, which is recorded in the hidden area.<sub>i</sub>The index information i (index of N Key) for indicating is recorded. However, even if an error occurs in the data when recording the Chip ID or index i, it is generally recorded in an error correction coded state so that the correct identification information can be read. , Here, the error correction coding / decoding process is not particularly shown. The hidden area 11-2 is an area where not only data recording but also data reading is prohibited from the outside of the NAND flash memory 10 (Read / Program inhibit). The secret area 11-2 according to this example is the NKey, which is the secret information used by the NAND flash memory 10 in the above authentication.<sub>i</sub>Is recorded. Further, when the ChipID is to be kept secret from the outside at all times, it may be recorded in the secret area instead of the ROM area. User area 11-<u style="single">1</u>Is an area where both data recording and data reading are freely possible. General area 11-<u style="single">1</u>SECID (Set of Encrypted ChipID), which is a bundle of encrypted ChipIDs, is recorded in, and other content data such as photographs, videos, music, and electronic books are recorded in the. The configuration example of the SECID, which is the encrypted ChipID, is the same as that shown in FIG. 23 above.
0205The data caches 12A and 12B temporarily store the data read from the cell array 11.
0206The data generation circuits 13 and 16 are circuits that output new data from a plurality of input information, and are the same as or unidirectional converters as the above-mentioned unidirectional converters in order to reduce the overall circuit scale. It is also possible to configure it with a circuit. Similarly, two data generation circuits, shown as different components to make the data processing procedure easier to understand, can use the same circuit repeatedly.
0207The data generation circuits (Generate) 13 and 16 are circuits that generate output data from a plurality of input data by a predetermined operation, and information received from the host device 20 (HC).<sub>j</sub>) Is the above-mentioned secret information NKey<sub>i</sub>HKey by converting using<sub>i, j</sub>And the random number RN received from the host device<sub>h</sub>The previous term HKey<sub>j</sub>SKey by converting with<sub>i, j</sub>It is also possible to use an AES (Advanced Encryption Standard) encrypter or the like.
0208The one-way converter (Oneway) 38 is a circuit that performs unidirectional conversion on input data and separately input key data, and outputs unidirectionally converted input data. In this embodiment, the identification information ChipID read from the ROM area is used as the key data SKey generated by the data generation circuit.<sub>i, j</sub>Converted by a one-way function using, one-way conversion identification information Oneway-ID (= Oneway (SKey)<sub>i, j</sub>, ChipID)) is generated. As in the first embodiment, when the identification information ChipID is recorded in the secret area instead of the ROM area, the identification information ChipID which is the input data of the one-way converter is in the secret area. Read from.
0209Further, as described above, the unidirectional converter 38 can also be used as the data generation circuit in order to reduce the overall hardware circuit scale.
0210Further, although not shown, an output unit or the like that outputs data sent to the host device 20 via the controller 19 may actually be arranged as a component.
0211Host device As shown in the figure, the host device (Host) 20 according to this example includes a random number generation unit (RNG) 25, an exclusive OR unit (EXOR) 24, a data selection unit (Select) 21-1, 21-2, and decoding. It is provided with a unit (Decrypt) 22, a data generation unit (Generate) 27, a unidirectional conversion unit (Oneway) 39, a data verification unit (Verify) 40, and the like. In addition to this, an error correction processing unit (not shown) can be provided as a component as needed.
0212The random number generator (RNG: Random Number Generator) 25 is the RN used for authentication.<sub>h</sub>To generate.
0213The exclusive OR section (EXOR) 24 calculates the exclusive OR of the two input data and outputs the result.
0214Two data selection units (Select) 21-1 and 21-2 are arranged. The data selection unit (Select1) 21-1 of the first stage is the secret information IDKey that the host keeps secret from the encrypted ChipID bundle (SECID) read from the NAND flash memory 10.<sub>k</sub>Encrypted ChipID data that can be decrypted using the secret information HKey<sub>j</sub>Select using the index information k of.
0215In the second stage data selection section (Select2) 21-2, the secret information NKey read from the NAND flash memory 10<sub>i</sub>Confidential information set HKey hidden by the host device 20 using the index information i of<sub>i, j</sub> (i = 1, ..., m. Note that j is the relevant HKey.<sub>i, j</sub>The secret information required for the authentication process with the NAND flash memory 10 is HKey.<sub>i, j</sub>Select.
0216The secret information IDKey<sub>k</sub>, HKey<sub>i, j</sub>Is recorded in the internal dedicated memory after being encrypted by the manufacturer's own method if it is a consumer device, or kept in a state that can be protected from unauthorized analysis by tamper resistant software (TRS) technology if it is a software program. If it is installed or has a built-in security module, it will be concealed after taking measures such as concealing it by using the function of the security module.
0217The decryption unit (Decrypt) 22 decodes the input data with the separately input key data, and outputs the decoded input data. In this embodiment, the secret information IDKey hidden by the host device<sub>k</sub>And if necessary, the secret information IDKey<sub>k</sub>The encrypted ChipID data selected in the first data selection unit is decrypted using the result of calculating the index information k for identifying the data in the exclusive OR unit as the key information, and is used to obtain the ChipID.
0218The data generation unit (Generate) 27 is an operation unit that generates output data from a plurality of input data by a predetermined operation, and is a random number RN generated by the host device 20 itself.<sub>h</sub>Confidential information HKey that the host device keeps secret<sub>i, j</sub>SKey by converting with<sub>i, j</sub>Is used to generate, and it is also possible to use AES encryption operation or the like.
0219The one-way conversion unit (Oneway) 39 outputs the ChipID output from the decoding unit to the SKey output from the data generation unit.<sub>i, j</sub>Is converted by a one-way function using, and one-way conversion identification information Oneway-ID is generated.
0220The data verification unit (Verify) 40 compares the one-way conversion identification information Oneway-ID received from the NAND flash memory 10 with the one-way conversion identification information obtained from the one-way conversion unit in the host device. If both values match, it is determined that the ChipID obtained by the decoding unit is the correct ChipID, and if they do not match, it is determined that the ChipID is an invalid ID.
0221Similarly, in addition to this, an error correction processing unit (not shown) can be provided as a component as needed.
0222<2. Authentication flow> Next, the authentication flow of the memory system according to the eleventh embodiment will be described with reference to FIG. 27.
0223As shown in the figure, when authentication is started (Start), the host device 20 reads the encrypted Chip ID bundle (SECID: Set of Encrypted Chip ID) from the NAND flash memory 10 (Step S11).
0224Subsequently, the host device 20 performs data selection processing from the read SECID by the above data selection unit (Select1) 21-1, reads the encrypted ChipID data that can be decrypted by the host device 20, and keeps the secret information secret. IDKey<sub>k</sub>The Chip ID is obtained by decoding by the decoding processing unit 22 using the above (Step S12).
0225Subsequently, the host device 20 uses the random number RN required when requesting authentication.<sub>h</sub>Is generated (Step S13). By using a random number in the authentication process, a different shared key is used each time with the NAND flash memory in the following process.
0226Subsequently, the host device holds a host constant (HC) in advance together with an authentication request (Request authentication).<sub>j</sub>) And the random number RN<sub>h</sub>To the NAND flash memory (Step S14).
0227Next, in the NAND flash memory 10, the host device 20 sets the secret information HKey.<sub>i, j</sub> HKey required for authentication with NAND flash memory from (i = 1, ..., m)<sub>i, j</sub>Reads the NKey index information i required to select, and sends it to the host device 20 (Step S15, S33).
0228Next, the NAND flash memory 10 is a secret NKey.<sub>i</sub>Received HC<sub>j</sub>By the data generation process in the above data generation circuit using<sub>i, j</sub>Is generated and the received random number RN<sub>h</sub>Key data SKey by data generation processing in the above data generation circuit using<sub>i, j</sub> (= Generate (HKey)<sub>i, j</sub>, RN<sub>h</sub>)) Is generated (Step S18).
0229In parallel with the process of Step S32, the host device 20 uses the received index information i to keep the secret information set HKey secret in advance.<sub>i, j</sub> Confidential information required for authentication processing with the NAND flash memory 10 from (i = 1, ..., m) HKey<sub>i, j</sub>Select (Step S33).
0230Subsequently, the host device 20 sets the selected secret information HKey.<sub>i, j</sub>And the generated random number RN<sub>h</sub>By the data generation process in the above data generation unit 27 using the session key SKey<sub>i, j </sub>(= Generate (HKey)<sub>i, j</sub>, RN<sub>h</sub>)) Is generated (Step S17).
0231Subsequently, the host device 20 sends an ID request (Request ID) to the NAND flash memory 10 (Step S19).
0232Subsequently, the NAND flash memory 10 reads the ChipID from the ROM area (Step S21).
0233Next, the NAND flash memory 10 uses the key data SKey that generated the ChipID.<sub>i, j</sub>The unidirectional conversion process in the unidirectional converter 38 is performed using the unidirectional conversion data Oneway-ID (= Oneway (SKey)).<sub>i, j</sub>, ChipID)) and send the generated one-way conversion data Oneway-ID to the host device (Step S38).
0234Subsequently, the host device 20 uses the key data SKey that generated the ChipID.<sub>i, j</sub>The one-way conversion process in the one-way conversion unit 39 is performed using the above, and the one-way conversion data Oneway-ID is obtained (Step S39).
0235Subsequently, the host device 20 confirms that the received one-way conversion data Oneway-ID and the obtained one-way conversion data match, and if they match, determines that the ChipID is the correct ChipID. If they do not match, it is determined that the Chip ID is an invalid ID (Step S40).
0236By the above operation, the authentication flow according to the eleventh embodiment is terminated (End).
0237<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the eleventh embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0238Further, in the eleventh embodiment, it is not necessary to implement the random number generator 15 in the NAND flash memory 11. Therefore, it is advantageous in that the operation and effect of the first embodiment and the operation and effect added in the tenth embodiment can be similarly realized, and the mounting circuit scale of the NAND flash memory can be made smaller. is there.
0239[Twelfth embodiment (an example in which the ID-index is written)] Next, the authentication device, the authenticated device, and the authentication method thereof according to the twelfth embodiment will be described. This embodiment relates to an example in which the index information ID-index required for specifying the Chip ID is written. In this description, detailed description of the portion overlapping with the first embodiment will be omitted.
0240<Configuration example (memory system)> A configuration example according to the twelfth embodiment will be described with reference to FIG. 28.
0241As shown in FIG. 23, in this example, the index information ID-index required to identify the ChipID is written in the ROM area 11-3 of the NAND flash memory 10, and the ChipID is a hidden area. It differs from the eleventh embodiment in that it is recorded in 11-2 and is provided with a data cache (Data Cache) 12B or the like as needed for reading the Chip ID.
0242The configuration example of the SECID, which is the encrypted ChipID, is the same as that shown in FIG. 23 above.
0243<Authentication flow> The NAND flash memory 10 reads the ChipID from the concealed area via the data cache as needed, but the other processing flows are substantially the same as those of the eleventh embodiment.
0244<About writing SECID> The writing of the encrypted ChipID bundle (SECID) will be described with reference to FIG. 29.
0245Here, when the encrypted ChipID bundle (SECID) is written at the time of manufacturing the NAND flash memory 10, it is not particularly necessary. However, when the NAND flash memory 10 and the controller 19 are combined and obtained by a general user as a storage media product such as an SD (registered trademark) card and written later in the market when the card is used, the SECID Writing process is required.
0246FIG. 29 shows the case of data recorded on the storage media in the unrecorded state as described above.
0247As shown in the figure, the NAND flash memory 10 has confidential information NKey.<sub>i</sub>And the identification information ChipID are recorded in the secret area 11-2, and the secret information NKey<sub>i</sub>The index information i required to specify the above and the index information ID-index required to specify the identification information ChipID are written in the ROM area 11-3. However, the SECID has not yet been written to the NAND flash memory 10.
0248A case where the SECID is downloaded from the server and recorded on the storage medium 10 in which the SECID is not recorded will be described with reference to FIG. 30.
0249As shown in the figure, in this case, the data cache 12 is arranged in the NAND flash memory 10 as needed.
0250The server 60 according to this example has a ChipID generator (Generate ChipID) 62 for generating a ChipID from an ID-index, an encryption unit (Encrypt) 63, and an IDKey database (Set of IDKey).<sub>i</sub> It has s (i = 1, ..., x)) 61.
0251Various conversions can be used as a method for generating ChipID from ID-index, and an example thereof is shown below. (Conversion example) First, the conversion key K distributed in advance to each manufacturer of the NAND flash memory 10.<sub>m</sub>The ID-index is the value obtained by encrypting the ChipID by encryption using. The ID-index is shown as follows.
0252ID-index = Encrypt (K<sub>m</sub>, ChipID) The ID-index is sent to the server 60 via the Internet 50.
0253The server 60 obtains a Chip ID by decoding the received ID-index using the conversion key Km by the generation unit 62. ChipID is shown as follows.
0254ChipID = Decrypt (K<sub>m</sub>, ID-index) The conversion key K<sub>m</sub>Is not only common to all manufacturers of the NAND flash memory 10, but can also be set to a different value for each manufacturer of the NAND flash memory 10.
0255The host device 20 has a function of determining whether new writing of the SECID is necessary and requesting the SECID from the server if necessary.
0256<SECID write flow> Next, a flow of downloading an encrypted ChipID bundle (SECID) from the server 60 and writing it to the NAND flash memory 10 will be described with reference to FIG. 31.
0257As shown in the figure, first, the host device 20 determines that the SECID download is necessary, so that the SECID writing is started (Start), and the host device 20 issues a SECID request to the server 60 (Step S55).
0258Subsequently, the server 60 requests the NAND flash memory 10 for the index information ID-index required to specify the Chip ID (Step S60).
0259Subsequently, the NAND flash memory 10 reads the ID-index from the ROM area 11-3 and sends the ID-index to the server (Step S61).
0260Subsequently, the server 60 generates a Chip ID using the ID-index received by the Chip ID generation unit 62 (Step S62).
0261Next, the server 60 has a secret IDKey.<sub>i</sub> Read (i = 1, ..., x) and each IDKey<sub>i</sub>The ChipID generated using 61 is encrypted to generate an encrypted ChipID bundle (SECID) (Step S63).
0262Subsequently, the server 60 sends the formed encrypted ChipID bundle (SECID) to the NAND flash memory (Step S64).
0263Subsequently, the NAND flash memory 10 writes and records the received encrypted ChipID bundle (SECID) in the general area 11-1 (Step S65).
0264By the above operation, the encrypted ChipID bundle (SECID) download flow according to the twelfth embodiment is terminated (End).
0265Other configurations, operations, and the like are substantially the same as those in the eleventh embodiment.
0266<Action effect> According to the authentication device, the authenticated device, and the authentication method according to the twelfth embodiment, the same effects (1) and (2) as those of the first embodiment can be obtained.
0267Further, as in the twelfth embodiment, it can be applied even when the SECID is written later.
0268[13th Embodiment (Example of Memory, Controller, Host)] Next, the thirteenth embodiment will be described with reference to FIG. A thirteenth embodiment relates to an example of the NAND flash memory 10, the controller 19, and the host device 20 applicable to the embodiment. In this example, an SD (registered trademark) card is taken as an example as a memory card.
0269As shown in the figure, the functional block of the host device connected to the memory card is also shown in this example. Each functional block can be realized as hardware, computer software, or a combination of both. For this reason, it is generally described below in terms of their function so that it becomes clear that each block is any of these. Whether such a function is executed as hardware or software depends on a specific embodiment or design constraints imposed on the entire system. Those skilled in the art can realize these functions by various methods for each specific embodiment, and any method of realizing them is included in the scope of the present invention.
0270The host device 20 includes software 211 such as an application and an operating system. Software 211 is instructed by the user to write data to the memory card and read data from the memory card. Software 211 directs the file system 212 to write and read data. The file system 212 is a mechanism for managing the file data recorded in the storage medium to be managed, records the management information in the storage area of the storage medium, and manages the file data using this management information. ..
0271The host device 20 has an SD interface 213. The SD interface 213 is composed of hardware and software necessary for performing interface processing between the host device 20 and the memory card. The host device 20 communicates with the memory card via the SD interface 213. The SD interface 213 defines various arrangements necessary for the host device 20 and the memory card to communicate with each other, and includes various command sets that can be mutually recognized with the SD interface 231 of the memory card described later. The SD interface 213 also includes a hardware configuration (pin arrangement, number, etc.) that can be connected to the SD interface 231 of the memory card.
0272The memory card has a NAND flash memory 10 and a controller 19 for controlling the memory 10. The memory card receives power when it is connected to the host device 20 and when the host device 20 is turned on while it is inserted in the host device 20 in the off state, and after performing the initialization operation, the host 1 Performs processing according to access from.
0273The NAND memory 10 stores data non-volatilely, and writes and reads data in units called pages composed of a plurality of memory cells. Each page is assigned a unique physical address. Further, the memory 10 erases data in units called physical blocks (erasure blocks) composed of a plurality of pages. A physical address may be assigned in units of physical blocks.
0274The controller 19 manages the storage state of data in the memory 10. Storage state management is the relationship between which physical address page (or physical block) holds data at which logical address, and which physical address page (or physical block) is in the erased state (write nothing). It includes managing whether or not the data is not available or holds invalid data.
0275The controller 19 includes an SD interface 31, an MPU (micro processing unit) 32, a ROM (read only memory) 33, a RAM (random access memory) 34, and a NAND interface 35.
0276The SD interface 131 consists of the hardware and software required to perform the interface processing between the host device 20 and the controller 19, and like the SD interface 13, defines various arrangements that enable communication between the two. It has a set of commands and includes the configuration on the hardware (pin arrangement, number, etc.). The memory card (controller 22) communicates with host 1 via SD interface 131. SD interface 131 includes register 136.
0277The MPU132 controls the operation of the entire memory card. For example, when the memory card is supplied with power, the MPU 132 reads the firmware (control program) stored in the ROM 133 onto the RAM 134 and executes a predetermined process. The MPU 132 creates various tables on the RAM 134 according to the control program, and executes a predetermined process on the memory according to the command received from the host 20.
0278The ROM 133 stores a control program and the like controlled by the MPU 132. The RAM 134 is used as a work area for the MPU 132 and temporarily stores control programs and various tables. Such a table includes a translation table (argument table) of the physical address of the page that actually stores the data having the logical address assigned to the data by the file system 212. The NAND interface 135 performs interface processing between the controller 19 and the memory 10.
0279The storage area in the NAND flash memory 10 is, for example, a general area (User area), a hidden area (Hidden area), a protected area (Protected area), and a ROM, as described above, depending on the type of data to be stored. Includes area (ROM area) etc. The controller 19 secures a part of the general area and stores the control data (discussion table, etc.) necessary for its own operation.
0280[14th Embodiment (NAND Flash Memory Configuration Example)] Next, as a specific configuration example of the NAND flash memory 10, the 14th embodiment will be described.
0281<Overall configuration example> A specific overall configuration example of the NAND flash memory 10 is shown as shown in FIG. 33.
0282As shown in the figure, the NAND flash memory 10 according to this example includes a memory cell array 11, a control circuit 19, an authentication circuit 151, a bit line control circuit 152, a column decoder 153, a data input / output buffer 154, and a data input / output terminal 155. It is equipped with a word line drive circuit 156, a control signal input terminal 158, and a power generation circuit 159.
0283The memory cell array 11 is composed of a plurality of blocks (BLOCK1 to BLOCKn). Each of the plurality of blocks (BLOCK1 to BLOCKn) includes a plurality of memory cells arranged at intersections of word lines and bit lines. For example, BLOCK1 is the ROM area 11-3. For example, BLOCK2 is the secret area 11-2. Other blocks are the general area (User area) 11-1 etc. that can be used from the host device 20.
0284ROM area 11-3 is, for example, an OTP (One Time Program) block, and only one write is allowed. After writing, the block decoder is controlled by means such as electric fuse, laser fuse, and ROM fuse to prohibit the erasing operation. The concealed area 11-2 is set to a state in which it cannot be selected by decoding an external address, for example, and is an area that can be read only by the control circuit 19 inside the NAND flash memory.
0285The authentication circuit 151 includes, for example, the data cache 12, the generation circuits 13, 16, the coupling circuit 14, the random number generation circuit 15, the exclusive OR circuit 17, the encryption device 18, and the like, and is controlled by the control circuit 19.
0286The bit line control circuit 152 reads the data of the memory cell in the memory cell array 11 via the bit line, and detects the state of the memory cell in the memory cell array 11 via the bit line. Further, the bit line control circuit 152 applies a write control voltage to the memory cells in the memory cell array 11 via the bit lines to write to the memory cells.
0287A data storage circuit such as the page buffer (not shown) is provided in the bit line control circuit 152, and this data storage circuit is selected by the column decoder 153. The data of the memory cell read into the data storage circuit is output from the data input / output terminal 155 to the outside via the data input / output buffer 154.
0288The data input / output terminal 155 is connected to, for example, an external host device 20 or the like. The data input / output terminal 155 has a bus width of, for example, 8 bits or 16 bits. The NAND flash memory 10 may support high-speed interface standards such as a toggle mode interface. In the toggle mode interface, for example, data transfer via the data input / output terminal 155 is performed in synchronization with both rising and falling edges of the data strobe signal (DQS).
0289The host device 20 is, for example, a microcomputer or the like, and receives data output from the data input / output terminal 155. The host device 20 outputs various commands CMD (write command, read command, erase command, status read command, etc.), address ADD, and data DT that control the operation of the NAND flash memory 10. The write data DT input from the host device 20 to the data input / output terminal 155 is supplied to the data storage circuit (not shown) selected by the column decoder 153 via the data input / output buffer 154. On the other hand, the command CMD and the address ADD are supplied to the control circuit 19.
0290The word line drive circuit 156 selects a word line in the memory cell array 11 under the control of the control circuit 19, and applies a voltage required for reading, writing, or erasing to the selected word line.
0291The voltage generation circuit 159 supplies the voltage required for the operation of the connected constituent circuits shown in the drawing according to the control of the control circuit 19. For example, the voltage generating circuit 159 boosts the external voltage supplied from the host device to generate a voltage applied to the word line during reading, writing, or erasing.
0292The control circuit (Controller) 19 provides a control signal and a control voltage required for each circuit to be connected in order to control the overall operation of the NAND flash memory 10. The control circuit 19 is connected to a memory cell array 11, an authentication circuit 151, a bit line control circuit 152, a column decoder 153, a data input / output buffer 154, a word line drive circuit 156, and a voltage generation circuit 159. The connected configuration circuit is controlled by the control circuit 19.
0293The control circuit 19 is connected to the control signal input terminal 158 and is input from the host device 20 via the control signal input terminal 158. WE (write enable) signal, RE (read enable) signal, ALE (address latch). -Controlled by a combination of control signals such as enable) signal and CLE (command latch enable) signal.
0294Here, functionally expressed, the word line drive circuit 156, the bit line control circuit 152, the column decoder 153, and the control circuit 19 constitute a data writing circuit, a data reading circuit, and a data erasing circuit. The host device 20 detects whether or not the NAND flash memory 10 is executing internal operations such as writing, reading, and erasing by monitoring the RY / BY (ready / busy) signal output terminal (not shown). To do. The control circuit 19 outputs a RY / BY signal via the RY / BY signal output terminal.
0295<BLOCK configuration example> Next, a configuration example of a block (BLOCK) constituting the memory cell array will be described with reference to FIG. 34. Here, BLOCK1 in FIG. 33 will be described as an example. Here, since the memory cells in this block BLOCK1 are collectively erased, the block is a data erasure unit.
0296Block BLOCK1 is composed of a plurality of memory cell units MU arranged in the word line direction (WL direction). The memory cell unit MU is arranged in the bit line direction (BL direction) intersecting the WL direction, and is a NAND string (memory cell string) consisting of eight memory cells MC0 to MC7 in which current paths are connected in series, and a NAND string. It is composed of a selection transistor S1 on the source side connected to one end of the current path of the NAND string and a selection transistor S2 on the drain side connected to the other end of the current path of the NAND string.
0297In this example, the memory cell unit MU is composed of eight memory cells MC0 to MC7, but may be composed of two or more memory cells, for example, 56, 32, etc., 8 It is not limited to individuals.
0298The other end of the current path of the selection transistor S1 on the source side is connected to the source line SL. The other end of the current path of the selection transistor S2 on the drain side is provided above the memory cell unit MU corresponding to each memory cell unit MU, and is connected to the bit line BLm-1 extending in the BL direction.
0299The word lines WL0 to WL7 extend in the WL direction and are commonly connected to the control gate electrodes of a plurality of memory cells in the WL direction. The selection gate line SGS extends in the WL direction and is commonly connected to a plurality of selection transistors S1 in the WL direction. The selection gate line SGD also extends in the WL direction and is commonly connected to a plurality of selection transistors S2 in the WL direction.
0300In addition, there is a page (PAGE) for each word line WL0 to WL7. For example, as shown by the broken line in the figure, the word line WL7 has page 7 (PAGE 7). Since the data read operation and the data write operation described later are performed for each page (PAGE), the page (PAGE) is a data read unit and a data write unit.
0301Although some embodiments of the present invention have been described above, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other embodiments, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and modifications thereof are included in the scope and gist of the invention, and are also included in the scope of the invention described in the claims and the equivalent scope thereof.<u style="single"> The scope of claims at the time of filing the application of the present application is described below.</u><u style="single">[1] This is an authentication method in which the authentication device authenticates the device to be authenticated.</u><u style="single"> The authenticated device holds the secret first key information (NKey) and holds it.</u><u style="single"> The authentication device holds the original information (HC) and the secret second key information (HKey).</u><u style="single"> A step in which the authenticated device generates a third key information (HKey') based on the original information (HC) and the first key information (NKey).</u><u style="single"> A step in which the authenticated device generates a first session key (SKey) based on the third key information (HKey') and random number information.</u><u style="single"> An authentication method in which the authentication device includes a step of generating a second session key (SKey') based on a secret second key information (HKey) and random number information.</u><u style="single">[2] The device to be authenticated further includes a step of encrypting the ID information held by the first session key and transmitting the encrypted ID information to the authentication device [1]. Authentication method.</u><u style="single">[3] The authentication device records the entire pre-encrypted ID information (ChipID and LotID) or a partial ID information (LotID or ChipID) which is a part thereof in the recording area.</u><u style="single"> The authentication device reads the pre-encrypted ID information or the pre-encrypted partial ID information from the recording area of the authenticated device, and at the same time, the pre-encrypted ID information or the pre-encrypted ID information. ID information or partial ID information is acquired by decrypting using the second key information (HKey) that conceals the partial ID information, and the decrypted ID information or partial ID information is the ID from the authenticated device. The authentication method according to [2], further comprising a step of confirming that the information is all or part of the information.</u><u style="single">[4] The authentication device includes a step of decrypting the ID information encrypted with the first session key transmitted from the authenticated device with the second session key to obtain the ID information.</u><u style="single"> The authentication device uses a part of the ID information obtained by decoding using the second key information and the ID information obtained by decoding using the second session key, and is authenticated. The authentication method according to [3], further comprising a step of acquiring device identification information (Chip ID).</u><u style="single">[5] A cell array that stores the secret first key information (NKey),</u><u style="single"> A first data generation circuit that generates second key information (HKey) using the original information (HC) of the authentication device and the first key information (NKey).</u><u style="single"> An authenticated device including a second data generation circuit that generates a session key (SKey) using the generated second key information (HKey) and random number information.</u><u style="single"> The second key information (HKey) is generated from the first key information (NKey), but the first key information (NKey) is not generated from the second key information (HKey).</u><u style="single">[6] The cell array further stores the identification information (ChipID) of the authenticated device.</u><u style="single"> The authenticated device according to [5], further comprising a one-way converter that converts the identification information (Chip ID) by a one-way function using the session key (SKey).</u><u style="single">[7] An authentication device that authenticates an authenticated device that holds confidential first key information (NKey), and the authentication device is</u><u style="single"> A memory that stores the secret second key information (HKey),</u><u style="single"> A random number generator that generates random number information and</u><u style="single"> It is provided with a data generation circuit that generates a session key (SKey) using the second key information (HKey) and the random number information.</u><u style="single"> The second key information (HKey) is generated from the first key information (NKey), but the first key information (NKey) is not generated from the second key information (HKey).</u><u style="single">[8] The authentication device according to [7], further comprising a one-way converter that converts the identification information (Chip ID) received from the authenticated device by a one-way function using the session key (SKey).</u><u style="single">[9] The authentication device obtains the whole (ChipID and LotID) of the pre-encrypted ID information or a part of the pre-encrypted partial ID information (LotID or ChipID) from the authenticated device. reading,</u><u style="single"> The authentication device obtains a third key information (ID Key) different from the second key information (HKey), which is necessary for decrypting the pre-encrypted ID information or the pre-encrypted partial ID information. Further stored in the memory</u><u style="single"> The authentication device acquires the ID information or the partial ID information by decrypting the pre-encrypted ID information or the pre-encrypted partial ID information with the third key information (ID Key) [ The authentication device described in 7] or [8].</u>
030210 ... authenticated device (NAND flash memory), 19 ... controller, 20 ... authenticated device (host device), 11 ... cell array, 23 ... memory, NKey ... 1st key Information, HKey ... 2nd key information, SKey ... session key information.
34 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2013118616A | Cited by | Japan | Examiner |
| JP2009100394A | Cites | Japan | – |
| WO2011064883A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| JP2000122931A | Cites | Japan | – |
| JP2008506317A | Cites | Japan | – |
| JP08204702A | Cites | Japan | – |
| US04757468A | Cites | United States of America | – |
| JP2001209305A | Cites | Japan | – |
| JP2010028485A | Cites | Japan | – |
| DAVID HOFF, et al.,System and software security via authentication handshake in EPROM,1985 Proceedings of the National Computer Conference,[online],1985年,p.203-209,[2012年11月2日検索],URL,http://www.computer.org/csdl/proceedings/afips/1985/5092/00/50920203-abs.html | Non-patent | – | – |
21 members in 6 offices
Members21
| Document | Office | Kind | |
|---|---|---|---|
| US2013054961A1 | United States of America | A1 | |
| WO2013031270A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2013055370A | Japan | A | |
| JP5214782B2This record | Japan | B2 | |
| US8661527B2 | United States of America | B2 | |
| US2014089675A1 | United States of America | A1 | |
| KR20140043135A | Republic of Korea | A | |
| CN103718185A | China | A | |
| EP2751732A1 | European Patent Office (EPO) | A1 | |
| KR101536086B1 | Republic of Korea | B1 | |
| US9225513B2 | United States of America | B2 | |
| US2016080147A1 | United States of America | A1 | |
| CN103718185B | China | B | |
| US9887841B2 | United States of America | B2 | |
| US2018097623A1 | United States of America | A1 | |
| US2018227123A1 | United States of America | A1 | |
| EP2751732B1 | European Patent Office (EPO) | B1 | |
| EP3454236A1 | European Patent Office (EPO) | A1 | |
| US10361850B2 | United States of America | B2 | |
| US10361851B2 | United States of America | B2 | |
| EP3454236B1 | European Patent Office (EPO) | B1 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313111S111 | S111 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313111S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of patent or utility model registrationJAPANESE INTERMEDIATE CODE: R151R151 | R151 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 5214782
- Application
- 189979
Titles2
- Japanese
- メモリ装置、ストレージメディア、ホスト装置、及びシステム
- English
- Memory devices, storage media, host devices, and systems
Classification
- CPC, 21
- G06F21/42
- G06F21/44
- H04L9/0869
- G06F21/30
- G06F21/73
- H04L9/0861
- H04L9/3242
- H04L2209/605
- G06F2221/2129
- G06F2221/2107
- G06F2221/2103
- H04L9/3271
- H04L2209/16
- G06F21/62
- G06F21/72
- G06F21/31
- G06F21/34
- G06F21/6218
- H04L9/0816
- H04L9/14
- H04L2209/24
- IPC, 3
- H04L9 32
- G06F21 79
- G06F21 44
