会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明公开
    • Memory system with versatile content control
    • 存储系统具有通用性内容控制
    • EP2189922A3
    • 2010-06-02
    • EP10002604.6
    • 2005-12-21
    • Sandisk CorporationDiscretix Technologies Ltd.
    • Jogand-Coulumb, FabriceHoltzman, MichaelQawani, BahmanBarzilai, RonHagai, Bar-el
    • G06F21/02
    • G06F21/79G06F21/31G06F21/6218G06F2221/2103
    • The owner of proprietor interest is in a better position to control access to the encrypted content in the medium if the encryption-decryption key is stored in the medium itself and substantially inaccessible to external devices. Only those host devices with the proper credentials are able to access the key. An access policy may be stored which grants different permissions (e.g. to different authorized entities) for accessing data stored in the medium. A system incorporating a combination of the two above features is particularly advantageous. On the one hand, the content owner or proprietor has the ability to control access to the content by using keys that are substantially inaccessible to external devices and at the same time has the ability to grant different permissions for accessing content in the medium. Thus, even where external devices gain access, their access may still be subject to the different permissions set by the content owner or proprietor recorded in the storage medium. When implemented in a flash memory, the above features result in a particularly useful medium for content protection. Many storage devices are not aware of file systems while many computer host devices read and write data in the form of files. The host device provides a key reference or ID, while the memory system generates a key value in response which is associated with the key ID, which is used as the handle through which the memory retains complete and exclusive control over the generation and use of the key value for cryptographic processes, while the host retains control of files.
    • 2. 发明公开
    • Memory system with in-stream data encryption/decryption
    • 带有流内数据加密/解密的内存系统
    • EP2278518A1
    • 2011-01-26
    • EP10177325.7
    • 2005-12-21
    • SanDisk CorporationDiscretix Technologies Ltd.
    • Holtzman, MichaelCohen, Baruch BorisDeitcher, DavidBar-ElL, HagaiYeruchami, Aviram
    • G06F21/00
    • G06F21/78
    • The throughput of the memory system is improved where data in a data stream is cryptographically processed by a circuit without involving intimately any controller. The data stream is preferably controlled so that it has a selected data source among a plurality of sources and a selected destination among a plurality of destinations, all without involving the controller. The cryptographic circuit may preferably be configured to enable the processing of multiple pages, selection of one or more cryptographic algorithms among a plurality of algorithms to encryption and/or decryption without involving a controller, and to process data cryptographically in multiple successive stages without involvement of the controller. For a memory system cryptographically processing data from multiple data streams in an interleaved manner, when a session is interrupted, security configuration information may be lost so that it may become impossible to continue the process when the session is resumed. To retain the security configuration information, the controller preferably causes the security configuration information for the session to be stored before the interruption so that it is retrievable after the interruption.
    • 存储器系统的吞吐量在数据流中的数据由电路密码处理而不涉及任何控制器的情况下得到改善。 优选地控制数据流,使得其具有多个源中的选定数据源和多个目的地中的选定目的地,全部都不涉及控制器。 密码电路可以优选地被配置为使得能够处理多个页面,在多个算法中选择一个或多个密码算法以在不涉及控制器的情况下进行加密和/或解密,并且在多个连续阶段中以密码方式处理数据而不涉及 控制器。 对于以交错方式密码处理来自多个数据流的数据的存储器系统,当会话中断时,安全配置信息可能会丢失,使得当会话恢复时可能无法继续该过程。 为了保留安全配置信息,控制器优选地使会话的安全配置信息在中断之前被存储,以便在中断之后可被检索。
    • 4. 发明公开
    • Memory system with in-stream data encryption/decryption
    • Speichersystem mit In-Stream-Datenverschlüsselung/-Entschlüsselung
    • EP2330530A1
    • 2011-06-08
    • EP10182649.3
    • 2005-12-21
    • Sandisk CorporationDiscretix Technologies Ltd.
    • Holtzman, MichaelCohen, BaruchDeitcher, DavidBar-El, HagelYeruchami, Aviram
    • G06F21/00
    • G06F21/78
    • The throughput of the memory system is improved where data in a data stream is cryptographically processed by a circuit without involving intimately any controller. The data stream is preferably controlled so that it has a selected data source among a plurality of sources and a selected destination among a plurality of destinations, all without involving the controller. The cryptographic circuit may preferably be configured to enable the processing of multiple pages, selection of one or more cryptographic algorithms among a plurality of algorithms to encryption and/or decryption without involving a controller, and to process data cryptographically in multiple successive stages without involvement of the controller. For a memory system cryptographically processing data from multiple data streams in an interleaved manner, when a session is interrupted, security configuration information may be lost so that it may become impossible to continue the process when the session is resumed. To retain the security configuration information, the controller preferably causes the security configuration information for the session to be stored before the interruption so that it is retrievable after the interruption.
    • 在数据流中的数据由电路进行密码处理而不涉及任何控制器的情况下,存储器系统的吞吐量得到改善。 优选地控制数据流,使得其具有多个源中的选择的数据源和多个目的地中的所选择的目的地,全部不涉及控制器。 密码电路可以优选地被配置为能够处理多个页面,在多个算法之间选择一个或多个加密算法以加密和/或解密而不涉及控制器,并且在多个连续阶段以密码方式处理数据,而不涉及 控制器。 对于以交织方式从多个数据流加密处理数据的存储器系统,当会话被中断时,可能丢失安全配置信息,从而当会话被恢复时可能变得不可能继续该过程。 为了保持安全配置信息,控制器优选地在中断之前存储会话的安全配置信息,以便在中断之后可以检索会话的安全配置信息。
    • 5. 发明公开
    • Memory system with versatile content control
    • Speichersystem mit Vielseitiger Inhaltssteuerung
    • EP2189922A2
    • 2010-05-26
    • EP10002604.6
    • 2005-12-21
    • Sandisk CorporationDiscretix Technologies Ltd.
    • Jogand-Coulumb, FabriceHoltzman, MichaelQawani, BahmanBarzilai, RonHagai, Bar-el
    • G06F21/02
    • G06F21/79G06F21/31G06F21/6218G06F2221/2103
    • The owner of proprietor interest is in a better position to control access to the encrypted content in the medium if the encryption-decryption key is stored in the medium itself and substantially inaccessible to external devices. Only those host devices with the proper credentials are able to access the key. An access policy may be stored which grants different permissions (e.g. to different authorized entities) for accessing data stored in the medium. A system incorporating a combination of the two above features is particularly advantageous. On the one hand, the content owner or proprietor has the ability to control access to the content by using keys that are substantially inaccessible to external devices and at the same time has the ability to grant different permissions for accessing content in the medium. Thus, even where external devices gain access, their access may still be subject to the different permissions set by the content owner or proprietor recorded in the storage medium. When implemented in a flash memory, the above features result in a particularly useful medium for content protection. Many storage devices are not aware of file systems while many computer host devices read and write data in the form of files. The host device provides a key reference or ID, while the memory system generates a key value in response which is associated with the key ID, which is used as the handle through which the memory retains complete and exclusive control over the generation and use of the key value for cryptographic processes, while the host retains control of files.
    • 如果加密解密密钥存储在介质本身并且对外部设备基本不可访问,所有者感兴趣的所有者处于更好的位置以控制对介质中的加密内容的访问。 只有那些具有正确凭据的主机才能访问密钥。 可以存储访问策略,其允许用于访问存储在介质中的数据的不同许可(例如,到不同的授权实体)。 结合上述两个特征的组合的系统是特别有利的。 一方面,内容所有者或所有者具有通过使用外部设备基本上不可访问的密钥来控制对内容的访问的能力,并且同时具有授予访问媒体中的内容的不同权限的能力。 因此,即使在外部设备获得访问的情况下,他们的访问仍然可以受到由存储介质中记录的内容所有者或所有者设置的不同的许可。 当在闪存中实现时,上述特征导致用于内容保护的特别有用的介质。 许多存储设备不知道文件系统,而许多计算机主机设备以文件的形式读取和写入数据。 主机设备提供密钥参考或ID,而存储器系统生成响应中的键值,该密钥值与密钥ID相关联,该密钥ID用作存储器保留完整的句柄,并且专用于控制生成和使用 加密过程的关键值,而主机保留对文件的控制。
    • 7. 发明公开
    • Versatile content control with partitioning
    • 通过分区进行多功能内容控制
    • EP2284758A2
    • 2011-02-16
    • EP10190137.9
    • 2005-12-21
    • Sandisk Corporation
    • Jagond-Coulomb, FabriceHoltzman, MichaelQawami, BahmanBarzilai, Ron
    • G06F21/00
    • G06F21/6209G06F21/6218G06F21/78
    • In some mobile storage devices, content protection is afforded by dividing the memory into separate areas where access to protected areas requires prior authentication. While such feature does provide some protection, it does not protect against a user who obtained a password by illicit means. Thus, another aspect of the invention is based on the recognition that a mechanism or structure may be provided to divide a memory into partitions and so that at least some data in the partitions can be encrypted with a key, so that in addition to authentication that is required for accessing some of the partitions, access to one or more keys may be required to decrypt the encrypted data in such partitions. In some applications, it may be more convenient to the user to be able to log in the memory system using one application, and then be able to use different applications to access protected content without having to log in again. In such event, all of the content that the user wishes to access in this manner may be associated with a first account, so that all such content can be accessed via different applications (e.g. music player, email, cellular communication etc.) without having to log in multiple times. Then a different set of authentication information may then be used for logging in to access protected content that is in an account different from the first account, even where the different accounts are for the same user or entity.
    • 在一些移动存储设备中,内容保护通过将内存划分为单独的区域来提供,在这些区域中访问保护区需要事先验证。 尽管此功能确实提供了一些保护,但它不能防止以非法手段获取密码的用户。 因此,本发明的另一方面基于这样的认识,即可以提供一种机制或结构来将存储器划分成分区,并且使得分区中的至少一些数据可以用密钥加密,使得除了认证 是访问某些分区所必需的,则可能需要访问一个或多个密钥来解密这些分区中的加密数据。 在某些应用程序中,用户可以更方便地使用一个应用程序登录存储器系统,然后可以使用不同的应用程序访问受保护的内容,而无需再次登录。 在这种情况下,用户希望以这种方式访问​​的所有内容可以与第一账户相关联,使得所有这样的内容可以经由不同的应用(例如音乐播放器,电子邮件,蜂窝通信等)被访问,而无需 多次登录。 然后,不同的认证信息组然后可以被用于登录以访问与第一账户不同的账户中的受保护内容,即使在不同账户是针对同一用户或实体的情况下。
    • 8. 发明公开
    • Optimized non-volatile storage systems
    • 优秀人才
    • EP2386961A1
    • 2011-11-16
    • EP11176847.9
    • 2005-07-20
    • Sandisk Corporation
    • Elhamias, ReuvenTomlin, AndrewBrewer, Wesley G.Pinto, YosiHoltzman, Michael
    • G06F13/38
    • G06F3/0607G06F3/0632G06F3/0679G06F13/385Y02D10/14Y02D10/151
    • A memory card that adapts its operation according to the application to which it applied or the conditions under which it is operated. This allows the card to dynamical self optimize. In a first set of embodiments, the card uses host profiling where it will learn about the host during host-card interactions and the card's controller will optimize its algorithms accordingly. In another set of embodiments, the host and card will report to one another their capabilities for a quality of service negotiation. A further set of embodiments allows the storage device to memorize access sequences issued by the host under various predefined conditions, such as host reset or a power on boot sequence. The storage device can use this information to optimize operation for the expected commands. On deviation from an expected sequence, the device would memorize the new command sequence and save it, thus operating in a shelf-adoptive manner.
    • 一种存储卡,根据其应用的应用或操作条件来适应其操作。 这样可以让卡片进行动态自我优化。 在第一组实施例中,卡使用主机分析,其中将在主机卡交互期间了解主机,并且卡的控制器将相应地优化其算法。 在另一组实施例中,主机和卡将彼此报告其服务质量协商的能力。 另一组实施例允许存储设备在诸如主机复位或引导顺序的电源的各种预定条件下存储由主机发出的访问序列。 存储设备可以使用该信息来优化预期命令的操作。 在偏离预期序列的情况下,设备会记住新的命令序列并将其保存,从而以货架方式运行。
    • 9. 发明公开
    • Versatile content control with partitioning
    • 通用内容控制与分区
    • EP2284758A3
    • 2011-10-05
    • EP10190137.9
    • 2005-12-21
    • Sandisk Corporation
    • Jagond-Coulomb, FabriceHoltzman, MichaelQawami, BahmanBarzilai, Ron
    • G06F21/00
    • G06F21/6209G06F21/6218G06F21/78
    • In some mobile storage devices, content protection is afforded by dividing the memory into separate areas where access to protected areas requires prior authentication. While such feature does provide some protection, it does not protect against a user who obtained a password by illicit means. Thus, another aspect of the invention is based on the recognition that a mechanism or structure may be provided to divide a memory into partitions and so that at least some data in the partitions can be encrypted with a key, so that in addition to authentication that is required for accessing some of the partitions, access to one or more keys may be required to decrypt the encrypted data in such partitions. In some applications, it may be more convenient to the user to be able to log in the memory system using one application, and then be able to use different applications to access protected content without having to log in again. In such event, all of the content that the user wishes to access in this manner may be associated with a first account, so that all such content can be accessed via different applications (e.g. music player, email, cellular communication etc.) without having to log in multiple times. Then a different set of authentication information may then be used for logging in to access protected content that is in an account different from the first account, even where the different accounts are for the same user or entity.