Solid-state drive data security enhancement

US9501242B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9501242-B2
Application numberUS-201514606078-A
CountryUS
Kind codeB2
Filing dateJan 27, 2015
Priority dateJan 28, 2014
Publication dateNov 22, 2016
Grant dateNov 22, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the present disclosure provide a method and apparatus for storage control. The method comprises: in response to having received a data deletion command on sensitive data, marking a storage medium page where the sensitive data is located as invalid, and putting a storage medium block where the storage medium page is located in a garbage collection queue, wherein the storage medium block is a minimum unit of storage medium erasure in a SSD; determining a secure deletion time corresponding to the sensitive data; in response to a remaining time to a next garbage collection being longer than the secure deletion time corresponding to the sensitive data, setting a value of the remaining time as the secure deletion time; and triggering a garbage collection according to the remaining time. Using the solution according to the embodiment of the present disclosure, the security of the SSD can be enhanced.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for data storage control, comprising: in response to having received a data deletion command for sensitive data, marking a storage medium page where the sensitive data is located as invalid, and putting a storage medium block where the storage medium page is located in a garbage collection queue, wherein the storage medium block is a minimum unit of storage medium erasure in SSD; determining a secure deletion time corresponding to the sensitive data; in response to a remaining time to a next garbage collection being longer than the secure deletion time corresponding to the sensitive data, setting a value of the remaining time as the secure deletion time; and triggering a garbage collection according to the remaining time. 2. The method of claim 1 , further comprising: receiving a data write command, the data write command comprising data, and the data write command indicating whether the data is sensitive data; and in response to the data being sensitive data, storing the data in a storage medium block dedicated to storing sensitive data, wherein the storage medium block dedicated to storing sensitive data includes no valid storage medium page used for storing non-sensitive data. 3. The method of claim 1 , wherein the secure deletion time is set when deleting the sensitive data. 4. The method of claim 1 , wherein the secure deletion time is set when writing the sensitive data. 5. The method of claim 1 , wherein different modules are used to respectively process sensitive data and non-sensitive data. 6. An apparatus for storage control, comprising: a storage medium block processing module configured to, in response to having received a data deletion command on sensitive data, mark a storage medium page where the sensitive data is located as invalid, and put a storage medium block where the storage medium page is located in a garbage collection queue, wherein the storage medium block is a minimum unit of storage medium erasure in SSD; a secure deletion time determining module configured to determine a secure deletion time corresponding to the sensitive data; a remaining time setting module configured to, in response to a remaining time to a next garbage collection being longer than the secure deletion time corresponding to the sensitive data, set a value of the remaining time as the secure deletion time; and a triggering module configured to trigger a garbage collection according to the remaining time. 7. The apparatus of claim 6 , further comprising: a write command receiving module configured to receive a data write command, the data write command comprising data, and the data write command indicating whether the data is sensitive data; and a data storing module configured to, in response to the data being sensitive data, store the data in a storage medium block dedicated to storing sensitive data, wherein the storage medium block dedicated to storing sensitive data includes no valid storage medium page used for storing non-sensitive data. 8. The apparatus of claim 6 , wherein the secure deletion time is set when deleting the sensitive data. 9. The apparatus of claim 6 , wherein the secure deletion time is set when writing the sensitive data. 10. The apparatus of claim 6 , wherein different modules are used to respectively process sensitive data and non-sensitive data. 11. A computer program product for data storage control, the computer program product comprising a non-transitory computer-readable storage medium having program instructions embodied therewith, the program instructions executable by one or more processing circuits to cause the one or more processing circuits to perform a method comprising: in response to having received a data deletion command for sensitive data, marking a storage medium page where the sensitive data is located as invalid, and putting a storage medium block where the storage medium page is located in a garbage collection queue, wherein the storage medium block is a minimum unit of storage medium erasure in SSD; determining a secure deletion time corresponding to the sensitive data; in response to a remaining time to a next garbage collection being longer than the secure deletion time corresponding to the sensitive data, setting a value of the remaining time as the secure deletion time; and triggering a garbage collection according to the remaining time. 12. The computer program product of claim 11 , wherein the program instructions are executable to further cause the one or more processor circuits to: receive a data write command, the data write command comprising data, and the data write command indicating whether the data is sensitive data; and in response to the data being sensitive data, store the data in a storage medium block dedicated to storing sensitive data, wherein the storage medium block dedicated to storing sensitive data includes no valid storage medium page used for storing non-sensitive data. 13. The computer program product of claim 11 , wherein the program instructions are executable to further cause the one or more processor circuits to set the secure deletion time when deleting the sensitive data. 14. The computer program product of claim 11 , wherein the program instructions are executable to further cause the one or more processor circuits to set the secure deletion time when writing the sensitive data. 15. The computer program product of claim 11 , wherein the program instructions are executable to further cause the one or more processor circuits to use different modules to respectively process sensitive data and non-sensitive data.

Assignees

Inventors

Classifications

  • Non-volatile semiconductor memory device, e.g. flash memory, one time programmable memory [OTP] · CPC title

  • G06F3/0652Primary

    Erasing, e.g. deleting, data cleaning, moving of data to a wastebasket · CPC title

  • in semiconductor storage media, e.g. directly-addressable memories · CPC title

  • in relation to content · CPC title

  • Time limited access, e.g. to a computer or data · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9501242B2 cover?
Embodiments of the present disclosure provide a method and apparatus for storage control. The method comprises: in response to having received a data deletion command on sensitive data, marking a storage medium page where the sensitive data is located as invalid, and putting a storage medium block where the storage medium page is located in a garbage collection queue, wherein the storage medium…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F3/0652. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Nov 22 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).