Encryption method of mobile hard disk, computer storage medium and mobile hard disk
By synchronously capturing fingerprint pattern data and subcutaneous finger vein infrared image data in the fingerprint mobile hard drive to generate a temporary key, and combining the quantum entropy source chip and the hardware unique root key for encryption and decryption, the security problem of the fingerprint mobile hard drive is solved and the security and convenience of data storage are improved.
Patent Information
- Application Number
- CN202510827915.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-09-19
AI Technical Summary
Existing fingerprint mobile hard drives have security flaws such as static fingerprint templates being easy to forge, being unable to resist deep fake attacks, insecure encryption key storage, and being unable to protect data integrity during violent disassembly.
A temporary key is generated by synchronously capturing fingerprint pattern data and subcutaneous finger vein infrared image data, which is encrypted and decrypted using a composite hash algorithm. It is also encrypted using a quantum entropy source chip and a hardware-unique root key to improve key complexity and security.
It improves the security of mobile hard disks, reduces the risk of key forgery, enhances the security and ease of use of data storage, and prevents data leakage.
Smart Images

Figure CN120671207A_ABST
Abstract
Description
Technical Field
[0001] This article relates to storage security technology, particularly a mobile hard disk encryption method, computer storage media and mobile hard disk. Background Art
[0002] Fingerprint mobile hard drives are mobile storage devices that integrate fingerprint recognition technology. They use fingerprint authentication to encrypt data and control access, significantly improving data security and convenience. Using fingerprint as the sole unlocking method eliminates the risk of password cracking or forgetting, preventing data leaks. Many products utilize AES hardware encryption to encrypt the entire drive's data stream, ensuring data security. Some products support multiple fingerprint inputs (e.g., 10) for convenient multi-person or multi-finger authorization management. No complex passwords need to be memorized; the device unlocks with a single touch of a fingerprint. Some products also feature an indicator light to indicate current status. Fingerprint mobile hard drives are mobile storage devices that integrate fingerprint recognition technology. They use fingerprint authentication to encrypt data and control access, significantly improving data security and convenience. Their high security, portability, and ease of use have made them a preferred solution for secure data storage for both individuals and businesses. As fingerprint recognition and hardware encryption technologies mature, related products are becoming increasingly popular, meeting growing data security needs.
[0003] Fingerprint mobile hard drives in related technologies have the following security flaws: fingerprint information is often stored in plain text or one-way hashes, static fingerprint templates are easy to forge (such as 3D-printed fingerprint films), and cannot resist deep fake attacks; relying solely on fingerprint recognition, they may be forced to authorize access in hijacking scenarios; encryption keys are stored in the main control chip Flash and can be easily extracted through physical detection, making key storage unsafe; data integrity cannot be protected in the event of violent disassembly.
[0004] In summary, how to improve the security of fingerprint mobile hard drives has become a problem to be solved. Summary of the Invention
[0005] The embodiment of the present application provides a method for encrypting a mobile hard disk, including: When the mobile hard disk is powered on and captures two or more biometric data, a temporary key is generated based on the two or more biometric data captured, wherein the two or more biometric data include: fingerprint pattern data and subcutaneous finger vein infrared image data captured synchronously; Encrypt and decrypt the mobile hard disk according to the generated temporary key; The encryption and decryption processing includes: encrypting the mobile hard disk when the mobile hard disk is not encrypted; and decrypting the mobile hard disk when the mobile hard disk is encrypted.
[0006] On the other hand, an embodiment of the present application further provides a computer storage medium, wherein the computer storage medium stores a computer program, and when the computer program is executed by a processor, the encryption method of the mobile hard disk is implemented.
[0007] On the other hand, an embodiment of the present application further provides a mobile hard disk, comprising: a memory and a processor, wherein the memory stores a computer program; wherein The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the above-mentioned mobile hard disk encryption method is implemented.
[0008] When two or more biometric data are captured after the mobile hard disk is powered on, the embodiment of the present disclosure generates a temporary key based on the two or more captured biometric data. Compared with generating a temporary key based on a single biometric feature of fingerprint, the complexity of the key is improved; the two or more biometric data include synchronously captured fingerprint pattern data and subcutaneous finger vein infrared image data, which reduces the risk of the key being forged; the mobile hard disk is encrypted and decrypted based on the temporary key generated by the two or more biometric data, thereby improving the security of the mobile hard disk.
[0009] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. Other advantages of the present application can be realized and obtained by the solutions described in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The accompanying drawings are used to provide an understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.
[0011] Figure 1 The figure is a flow chart of the encryption method of the mobile hard disk according to the embodiment of the present disclosure. DETAILED DESCRIPTION
[0012] This application describes multiple embodiments, but this description is exemplary rather than restrictive, and it will be apparent to those skilled in the art that there may be more embodiments and implementations within the scope of the embodiments described herein. Although many possible feature combinations are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with any other feature or element in any other embodiment, or may replace any other feature or element in any other embodiment.
[0013] The present application includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The embodiments, features, and elements disclosed in this application may also be combined with any conventional features or elements to form a unique inventive solution. Any features or elements of any embodiment may also be combined with features or elements from other inventive solutions to form another unique inventive solution. Therefore, it should be understood that any feature shown and / or discussed in this application may be implemented individually or in any appropriate combination. Therefore, except for the limitations made according to the appended claims and their equivalents, the embodiments are not subject to other limitations. In addition, various modifications and changes may be made within the scope of protection of the appended claims.
[0014] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described herein, the method or process should not be limited to the steps in the specific order described. As will be understood by those skilled in the art, other orders of steps are also possible. Therefore, the specific order of the steps set forth in the specification should not be interpreted as a limitation to the claims. In addition, the claims for the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can readily understand that these orders can be changed and still remain within the spirit and scope of the embodiments of the present application.
[0015] Figure 1 This is a flow chart of the encryption method for a mobile hard disk according to an embodiment of the present disclosure. Figure 1 Shown, including: Step 101: When two or more biometric data are captured after the mobile hard disk is powered on, a corresponding temporary key is generated through a preset user front end and a preset system back end based on the two or more biometric data captured, wherein the two or more biometric data include: fingerprint pattern data and subcutaneous finger vein infrared image data captured simultaneously; Step 102: Perform service authentication on the user accessing the mobile hard disk based on the temporary key generated by the user front end and the system back end; Step 103: When the user passes the service authentication, the mobile hard disk is encrypted and decrypted using the temporary key generated by the user front end; The encryption and decryption processing includes: encrypting the mobile hard disk when the mobile hard disk is not encrypted; and decrypting the mobile hard disk when the mobile hard disk is encrypted.
[0016] When two or more biometric data are captured after the mobile hard disk is powered on, the embodiment of the present disclosure generates a temporary key based on the captured two or more biometric data. Compared with generating a temporary key based on a single biometric feature of fingerprint, the complexity of the key is improved; the two or more biometric data include synchronously captured fingerprint pattern data and subcutaneous finger vein infrared image data, which reduces the risk of the key being forged; based on the temporary key generated by the two or more biometric data, the user accessing the mobile hard disk is authenticated, and when the user passes the service authentication, the mobile hard disk is encrypted and decrypted, thereby improving the security of the mobile hard disk.
[0017] The subcutaneous finger vein infrared image in the disclosed embodiments uses near-infrared imaging technology to capture images of the subcutaneous venous network in the finger. This technology exploits the strong absorption of near-infrared light by deoxyhemoglobin in blood vessels, making the veins appear as distinct dark lines in the image, thereby visualizing the venous structure. While the subcutaneous finger vein infrared image data exhibits some variability when generating temporary keys, within a reasonable technical framework, it can meet the stability requirements for key generation and decryption. It should be noted that subcutaneous finger vein infrared images may be affected by temperature, user finger movement, and other factors during use. Temperature changes may affect finger vein infrared images. When the ambient temperature is low, the body's peripheral blood vessels contract to reduce heat loss, which may cause the finger veins to become thinner, manifesting as decreased clarity and contrast in the infrared image. For example, in a cold outdoor environment, where fingers are exposed for a long time, finger vein infrared images captured at this time may have difficulty clearly displaying vascular details compared to images captured in a warm indoor environment. Conversely, in a high-temperature environment, blood vessels may dilate. Although vascular patterns will be more visible, noise may be introduced due to factors such as skin moisture evaporation, which interferes with image quality. The disclosed embodiments may employ corresponding image enhancement algorithms to address such changes. For example, an adaptive histogram equalization algorithm can be used to enhance the contrast of images captured under different temperature environments, making vascular features more prominent and ensuring the accuracy of feature extraction during key generation and decryption comparison. User finger movement can significantly affect finger vein infrared images: if the finger moves or shakes during the acquisition process, the captured image will appear blurry or ghosting. For example, if a user hastily places their finger in the capture area and moves it quickly, the vascular patterns in the captured image may not be accurately focused, blurring the key feature points. This is extremely detrimental to the generation of temporary keys and the decryption process, as the feature extraction algorithm may not be able to accurately identify stable features. The disclosed embodiments can apply anti-shake and positioning algorithms from related technologies to detect the position and posture of the finger. When the finger position is unstable or there is significant movement, the user can be prompted to reposition the finger to ensure that the finger is relatively still during image capture, thereby ensuring stable image quality. Other factors include physiological status and imaging device aging. For example, if the user is in a special physiological state, such as being sick or after exercise, changes in blood circulation can also affect finger vein images. For example, after strenuous exercise, blood circulation accelerates, and the blood flow rate and filling degree of the finger veins change, which may cause the captured image to differ from the normal state. However, because the finger vein recognition system focuses on relatively stable features such as the distribution structure of the blood vessels, as long as there are no long-term physiological changes that seriously affect the vascular structure, recognition accuracy can generally be guaranteed.Finger vein infrared imaging equipment that has been used for a long time may experience a decrease in the intensity of its infrared light source, and the lens may become worn or dirty. This can lead to a decrease in image quality, dark images, and increased noise. In these cases, regular maintenance and calibration of the equipment, such as replacing aging light sources and cleaning the lens, can be performed to ensure stable image acquisition.
[0018] The present disclosure embodiment acquires and processes an image of a finger's subcutaneous venous network, which may include: Finger vein acquisition equipment uses near-infrared light to illuminate the finger. Since deoxyhemoglobin in venous blood strongly absorbs near-infrared light, a CCD camera on the other side of the finger can capture an image of the subcutaneous venous network of the finger formed by the difference in light absorption. The acquisition time is usually completed within a few hundred milliseconds. The original images of the subcutaneous venous network of a finger often contain noise, uneven lighting, and other issues. Therefore, the disclosed embodiments can pre-process the original images. The disclosed embodiments can include: denoising, which can remove random noise from the image and smooth the image using algorithms such as Gaussian filtering; after denoising, the image can be enhanced using methods such as histogram equalization to increase the contrast between the blood vessels and surrounding tissue, making the vascular lines clearer; for example, a finger vein image with dark areas due to uneven lighting can be used to make the originally blurred vascular details clearer after histogram equalization, facilitating subsequent feature extraction.
[0019] The feature vector of the finger vein is extracted from the preprocessed image of the subcutaneous venous network of the finger. Generally, a method based on structural features is adopted, such as extracting characteristic information such as the bifurcation points, intersection points, and vascular direction of the blood vessels. The vascular image is refined into a single pixel width through a refinement algorithm to accurately identify the topological structural characteristics of the blood vessels. For example, after processing by the feature extraction algorithm, a series of coordinate points and vector information representing the characteristics of the finger vein can be obtained, and this information constitutes a feature vector.
[0020] The extracted feature vector is then used to generate a temporary key through a pre-defined encryption algorithm. For example, a hash algorithm is used to convert the feature vector into a fixed-length hash value, which serves as the temporary key. Due to the uniqueness of the finger vein feature, the generated temporary key is also unique and can be used for subsequent authentication and decryption operations. The disclosed embodiment uses a composite hash calculation based on an image of the subcutaneous venous network and a fingerprint image to obtain the temporary key.
[0021] During the decryption process, the generation method for the temporary key used for decryption is consistent with the processing process for the temporary key used for encryption. During the comparison, the feature vector of the decrypted temporary key can be compared with the feature vector of the encrypted temporary key. For example, the similarity between the two feature vectors can be calculated using algorithms such as Euclidean distance and cosine similarity. For example, if the Euclidean distance is less than a set threshold, the two are considered a match, indicating that the current user's identity has been authenticated, and decryption can be performed. If the distance is greater than the threshold, authentication fails and decryption cannot be performed. Assuming the set Euclidean distance threshold is 0.5, when the calculated Euclidean distance between the feature vector to be compared and the stored feature vector is 0.3, it indicates a high degree of similarity, authentication has been passed, and decryption is allowed. Decryption operation: If the comparison is successful, the system uses the encryption algorithm used when previously generating the temporary key, combined with the currently authenticated feature information, to decrypt the encrypted data and obtain the original data. Although subcutaneous finger vein infrared image data can be affected by various factors, the disclosed embodiments can extract and compare image features through the above method, effectively ensuring stability and accuracy during the generation of temporary keys and decryption comparison process.
[0022] In an exemplary embodiment, the fingerprint pattern data in the embodiment of the present disclosure may include 400dpi-600dpi data, for example, 500dpi data.
[0023] In an exemplary embodiment, the subcutaneous finger vein infrared image data in the embodiment of the present disclosure may include image data with a wavelength of 750nm-950nm, for example, image data with a wavelength of 850nm.
[0024] In an exemplary embodiment, the user front-end and the system back-end of the embodiment of the present disclosure respectively generate a temporary key through the following processes: Performing a composite hash calculation on two or more captured biometric data to obtain biometric composite hash data; Generate a temporary key based on the obtained biometric composite hash data.
[0025] The embodiments of the present disclosure may refer to the related methods of composite hashing to perform calculations and processing on two or more captured biometric data, and the embodiments of the present disclosure are not limited to this.
[0026] In an exemplary embodiment, the present disclosure generates a temporary key based on the obtained biometric composite hash data, including: Processing the biometric composite hash data according to a pre-set first processing logic to obtain a temporary key; The first processing logic includes: splitting, combining, and logical operations.
[0027] In an exemplary embodiment, before generating a temporary key based on two or more captured biometric data, the method of the embodiment of the present disclosure further includes: Generate random numbers through a pre-set random number generation function; Processing the captured two or more biometric data according to the second processing logic based on the generated random number; The second processing logic includes one or any combination of the following: splitting, combining, and XOR operation, etc.
[0028] In an exemplary embodiment, the embodiment of the present disclosure can generate the above-mentioned random numbers through a pre-set quantum entropy source chip.
[0029] In an exemplary embodiment, the present disclosure generates corresponding temporary keys based on two or more captured biometric data through a preset user front end and a system back end, including: Load and run the same random number generation function (e.g., quantum random number generator (QRNG)) on both the user front-end and the system back-end; The user front end processes the captured two or more biometric data according to the second processing logic based on the first random number generated by the random number generation function loaded and calculated by itself; the system back end processes the captured two or more biometric data according to the second processing logic based on the second random number generated by the random number generation function loaded and calculated by itself; The user front end generates a temporary key of the user front end based on the two or more biometric feature data processed according to the second processing logic based on the first random number; The system backend generates a temporary key of the system backend based on the two or more biometric feature data processed according to the second processing logic based on the second random number.
[0030] The disclosed embodiment can generate the above-mentioned random numbers in real time based on the photon noise of the CMOS image sensor that collects biometric data through a quantum entropy source chip.
[0031] The embodiment of the present disclosure loads and runs the same random number generation function on the user front end and the system back end, including: loading and running the same random number generation function on the user front end and the system back end respectively.
[0032] In the embodiment of the present disclosure, the temporary keys generated by the user front-end and the system back-end are matched and processed with reference to related technologies. When the match succeeds, it is determined that the user accessing the mobile hard disk has passed the service authentication.
[0033] In an exemplary embodiment, the embodiment of the present disclosure performs encryption and decryption processing on a mobile hard disk using a temporary key generated by a user front end, including: The hard disk partition table of the mobile hard disk is encrypted and decrypted according to the temporary key generated by the user front end.
[0034] A hard disk partition table is a data area stored on a disk that describes basic information about each partition on the disk. It determines how the disk is identified and used by the operating system and is a core structure of disk management. Common partition table types include the Master Boot Record (MBR) and the GUID Partition Table (GPT). A hard disk partition table describes the starting location, size, type, and other information of each partition; it determines the number of partitions on the disk and the purpose of each partition (e.g., system drive, data drive, etc.); and it influences operating system startup and disk compatibility. The disclosed embodiment can encrypt the hard disk partition table once it is determined to be unencrypted. Subsequent access to the removable hard disk requires decrypting the hard disk partition table before accessing the data stored on the removable hard disk. This encryption and decryption of the hard disk partition table provides security protection for accessing data stored on the removable hard disk.
[0035] The embodiment of the present disclosure performs encryption and decryption processing on the hard disk partition table of the mobile hard disk according to the temporary key generated by the user front end, including: When it is determined that the hard disk partition table of the mobile hard disk is not encrypted, the hard disk partition table is encrypted according to the temporary key generated by the current user front end, and a random number of the temporary key for performing the encryption process is stored in the ciphertext file containing the encrypted hard disk partition table; When it is determined that the hard disk partition table is encrypted, the random number of the temporary key generated by the current user front end is replaced with the random number stored in the ciphertext file. The temporary key for decrypting the hard disk partition table is generated by using the replaced random number and two or more biometric data of the temporary key generated by the current user front end, and the decryption processing of the hard disk partition table is performed.
[0036] In an exemplary embodiment, the method of the present disclosure further includes: When the hard disk partition table is updated, the updated hard disk partition table is encrypted according to the temporary key generated by the current user front end, and the random number of the temporary key for encrypting the updated hard disk partition table is stored in the ciphertext file containing the encrypted hard disk partition table, so that when the hard disk partition table is decrypted, the temporary key for decrypting the updated hard disk partition table is generated according to the stored random number.
[0037] The current moment in the embodiment of the present disclosure refers to the moment when two or more biometric data are captured and a temporary key is generated.
[0038] In an exemplary embodiment, after generating a temporary key based on two or more captured biometric data, the method of the embodiment of the present disclosure further includes: Encrypt the temporary key according to the hardware-unique root key of the mobile hard disk; Among them, the hardware-unique root key includes: the key generated by the static random access memory physically unclonable function (SRAM PUF) unit integrated on the main control chip of the mobile hard disk.
[0039] In an exemplary embodiment, the embodiment of the present disclosure encrypts the temporary key based on the hardware-unique root key of the mobile hard disk, which may include: encrypting the temporary key based on the HMAC-SHA-512 algorithm, the HMAC-SHA-512 + AES-256-CMAC algorithm, or an algorithm in other related technologies.
[0040] The following example illustrates the process of authenticating users accessing a mobile hard drive and encrypting and decrypting the hard drive based on two types of biometric data, a random number, and a hardware-unique root key. The examples include: Two or more types of biometric data captured; The random number generation function of the user front end generates a first random number, processes the captured two or more biometric data according to the second processing logic, performs a composite hash calculation on the processed two or more biometric data to obtain biometric composite hash data; and generates a temporary key for the user front end based on the obtained biometric composite hash data. A random number generation function at the system backend generates a second random number, processes the captured two or more biometric data according to the second processing logic, performs a composite hash calculation on the processed two or more biometric data to obtain biometric composite hash data; and generates a temporary key at the system backend based on the obtained biometric composite hash data. For regular users of mobile terminals, the above processing is performed based on the user front-end and system back-end within the mobile terminal. If the random number generation function is the same, the first and second random numbers generated at the same time are identical. Therefore, the temporary key generated by the user front-end and the temporary key generated by the system back-end are identical. At this point, when matching the temporary keys with reference to related technologies, it is determined that the user accessing the mobile hard drive has passed service authentication. In this disclosed embodiment, the generated temporary key is encrypted using the mobile hard drive's hardware-unique root key (e.g., using the HMAC-SHA-512 + AES-256-CMAC algorithm). In this disclosed embodiment, the ciphertext file containing the encrypted hard drive partition table may be composed of the following: ciphertext = [Nonce (12 bytes)] + [Tag (16 bytes)] + [Encrypted hard drive partition table data (N bytes)]; where Nonce represents the random number of the current temporary key; and Tag represents the authentication tag in GCM mode, used to verify data integrity. When the embodiment of the present disclosure decrypts the mobile hard disk, since the timestamp when the hard disk partition table of the mobile hard disk was encrypted is different, the random number used to generate the temporary key of the user front end is different. Therefore, the temporary key of the user terminal used during encryption is different from the temporary key of the user terminal generated at the time of decryption. In order to realize the decryption processing of the hard disk partition table, the embodiment of the present disclosure extracts the random number of the temporary key stored in the previous encryption processing from the ciphertext file containing the encrypted hard disk partition table, that is, separates the ciphertext file into: Nonce, Tag and encrypted partition table data; the separated random number is combined with the biometric data for currently generating the temporary key of the user terminal to generate the temporary key for decrypting the hard disk partition table, and performs the decryption processing of the hard disk partition table. In the disclosed embodiment, even if the user's biometric data is the same, the random number differs due to the timestamp. Referring to the above method, different random numbers result in different temporary keys. Therefore, the temporary key currently generated for the user terminal cannot decrypt the previously encrypted hard disk partition table. To implement decryption, the random number can be stored in a ciphertext file. When the service authentication is passed, the random number is extracted from the ciphertext file. The extracted random number is combined with the biometric data used to generate the current user terminal encryption key, and the temporary key for decrypting the hard disk partition table is obtained by referring to the method of the embodiment of the present invention. During the decryption process of the disclosed embodiment, the AES-GCM-Decrypt function can be called to obtain plaintext = AES-GCM-Decrypt (new temporary key, Nonce, Cipertext, Tag). If the decryption is successful, the original hard disk partition table data is returned; if it fails (e.g., the Tag does not match), a decryption error is fed back. For decryption to succeed, the generated temporary key must completely match the Nonce used during encryption and the encryption algorithm parameters used.In the disclosed embodiment, if an attacker attempts to decrypt the new ciphertext (including the new Nonce) of the mobile hard disk using the old temporary key, the decryption will inevitably fail because the new Nonce is not involved in the generation of the old temporary key.
[0041] In an exemplary embodiment, before generating corresponding temporary keys through a preset user front end and a system back end based on two or more captured biometric data, the method of the embodiment of the present disclosure further includes: Based on blood flow dynamic characteristics (such as venous pulsation frequency) and changes in capacitance impedance, determine whether the finger inputting two or more biometric data is the real user's finger; When it is determined that the finger inputting two or more biometric data is a real user's finger, a process of generating a temporary key according to the captured two or more biometric data is triggered.
[0042] When the embodiment of the present disclosure determines that the finger inputting two or more biometric data is a fake user finger, the process of generating the temporary key is terminated. At the same time as terminating the process of generating the temporary key, the embodiment of the present disclosure can execute related processes such as locking the mobile hard disk and / or issuing an alarm.
[0043] The disclosed embodiment combines liveness detection of real user fingers with temporary keys generated based on two or more biometric data, further avoiding forgery attacks including forged fingerprint films, reducing the success rate of forgery attacks to near 0, and further improving the data storage security of the mobile hard disk.
[0044] In an exemplary embodiment, the method of the present disclosure further includes: When it is detected that the force of holding the mobile hard disk is greater than a preset holding force threshold, or when it is detected that the tapping frequency received by the mobile hard disk is greater than a preset tapping frequency threshold, one or any combination of the following processes is performed: Return false data based on a pre-stored false key (false password mode can be set, i.e. switch to false password mode); Sending the mobile hard drive's location data (e.g., GPS location data) and / or real-time ambient audio to a pre-defined secure terminal; The LED indicator on the external hard drive shows an abnormality (for example, flashing red).
[0045] Through the above-mentioned processing, the embodiment of the present disclosure performs data security protection processing when it is detected that the mobile hard disk may be stolen, thereby preventing the real data from being accessed, and further improving the data storage security of the mobile hard disk.
[0046] In the embodiment of the present disclosure, the gripping force threshold and the tapping frequency threshold can be set and adjusted by technicians, for example, the gripping force threshold can be set to 50 Newtons and the tapping frequency threshold can be set to 5 Hz.
[0047] In an exemplary embodiment, the method of the present disclosure further includes: When a physical attack is detected on the mobile hard drive, the SRAM PUF unit is burned out through a high-voltage pulse; Among them, physical attacks include detection of any of the following situations: shell cracking, low temperature attack or ultraviolet radiation.
[0048] In an exemplary embodiment, the physical attacks on the mobile hard disk of the embodiment of the present disclosure include detection of shell cracking, low temperature attack (the ambient temperature of the mobile hard disk is less than -40°C) or ultraviolet radiation. The physical attacks can be detected using glass substrate packaging technology and related technologies.
[0049] In an exemplary embodiment, the method of the present disclosure further includes: When the main control chip of the mobile hard drive is detected to be damaged, the mobile hard drive is awakened by receiving NFC radio frequency power from the mobile phone through the NFC tag and energy collection circuit built into the mobile hard drive; When the pre-set decryption key is received after the mobile hard disk is awakened, the preset data is exported through the emergency module pre-set in the mobile hard disk.
[0050] The preset data in the embodiment of the present disclosure may be pre-determined core data; the embodiment of the present disclosure may set the transmission rate of the preset data to 20 KB / s.
[0051] This disclosed embodiment assumes that a user uses a mobile hard drive to store customer transaction records. If the hard drive is detected as stolen, the hijacker presses the hard drive firmly, triggering the LED indicator to indicate an abnormality, leading the hijacker to mistakenly believe the hard drive is damaged. When the hard drive is retrieved by the user, the NFC tag and energy harvesting circuit receive the phone's NFC radio frequency power wake-up function and, after receiving a pre-set decryption key, export the core data, thus preventing data leakage. If the hard drive is subjected to physical attacks, including detection of a cracked housing, a low-temperature attack (when the hard drive is located in an environment with a temperature below -40°C), or ultraviolet radiation, a high-voltage pulse burns out the SRAM PUF unit, permanently corroding the NAND chips and rendering the data irrecoverable, thus ensuring data security. Through testing, the disclosed embodiments have demonstrated that the system response time for burning the SRAM PUF unit via a high-voltage pulse is less than 10ms, and the data unrecoverable rate is >99.9%. The false trigger rate of the pressure-sensing lock that detects a user pressing on a mobile hard drive is less than 0.01%, and the success rate of disguising and concealing hard drive abnormalities via an LED indicator is >90%. The disclosed embodiments can be used to implement the power-on wake-up function for mobile hard drives, as long as the mobile phone has NFC radio frequency functionality.
[0052] The embodiment of the present disclosure further provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, the above-mentioned mobile hard disk encryption method is implemented.
[0053] The embodiment of the present disclosure further provides a mobile hard disk, comprising: a memory and a processor, wherein the memory stores a computer program; The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the above-mentioned encryption method for the mobile hard disk is implemented.
[0054] The embodiment of the present disclosure further provides a terminal, comprising: a memory and a processor, wherein a computer program is stored in the memory; The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the above-mentioned encryption method for the mobile hard disk is implemented.
[0055] Those skilled in the art will appreciate that all or some of the steps, systems, and functional modules / units in the methods, systems, and devices disclosed above may be implemented as software, firmware, hardware, or any combination thereof. In hardware implementations, the division between functional modules / units described above does not necessarily correspond to the division between physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on computer-readable media, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is well known to those skilled in the art, the term "computer storage media" encompasses volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
Claims
1. A method for encrypting a mobile hard disk, characterized in that: include: When the mobile hard disk is powered on and captures two or more biometric data, a corresponding temporary key is generated through a pre-set user front end and a system back end respectively based on the two or more biometric data captured, wherein the two or more biometric data include: fingerprint pattern data and subcutaneous finger vein infrared image data captured simultaneously; Perform business authentication on users accessing mobile hard drives based on temporary keys generated through the user front-end and system back-end; When the user passes the business authentication, the mobile hard disk is encrypted and decrypted using the temporary key generated by the user front end; The encryption and decryption processing includes: encrypting the mobile hard disk when the mobile hard disk is not encrypted; and decrypting the mobile hard disk when the mobile hard disk is encrypted.
2. The encryption method according to claim 1, wherein: The user front end and the system back end respectively generate a temporary key through the following processing, including: Performing a composite hash calculation on the two or more captured biometric data to obtain biometric composite hash data; Generate a temporary key based on the obtained biometric composite hash data.
3. The encryption method according to claim 2, wherein: Generating a temporary key based on the obtained biometric composite hash data includes: Processing the biometric composite hash data according to a preset first processing logic to obtain the temporary key; The first processing logic includes one or any combination of the following: splitting, combining, and logical operation.
4. The encryption method according to claim 2, wherein: Before generating a temporary key based on the two or more captured biometric data, the method further includes: Generate random numbers through a pre-set random number generation function; Processing the captured two or more biometric data according to the second processing logic based on the generated random number; The second processing logic includes one or any combination of the following: splitting, combining, and XOR operation.
5. The encryption method according to claim 4, wherein: The method of generating corresponding temporary keys based on the captured two or more biometric data through a preset user front end and a system back end respectively includes: Loading and running the same random number generation function on the user front end and the system back end; The user front end processes the captured two or more biometric feature data according to the second processing logic based on the first random number generated by the random number generation function loaded and run by the user front end; The system backend processes the captured two or more biometric data according to the second processing logic based on the second random number generated by the random number generation function loaded and run by the system backend; The user front end generates a temporary key of the user front end based on the two or more biometric feature data processed according to the second processing logic based on the first random number; The system backend generates a temporary key of the system backend based on the two or more biometric feature data processed according to the second processing logic based on the second random number.
6. The encryption method according to claim 1, wherein: The encryption and decryption process of the mobile hard disk according to the temporary key generated by the user front end includes: The hard disk partition table of the mobile hard disk is encrypted and decrypted according to the temporary key generated by the user front end.
7. The encryption method according to claim 6, wherein: The encryption and decryption of the hard disk partition table of the mobile hard disk according to the temporary key generated by the user front end includes: When it is determined that the hard disk partition table of the mobile hard disk is not encrypted, encrypting the hard disk partition table according to the temporary key currently generated by the user front end, and storing a random number of the temporary key for performing the encryption process in a ciphertext file containing the encrypted hard disk partition table; When it is determined that the hard disk partition table is encrypted, the random number of the temporary key currently generated by the user front end is replaced with the random number stored in the ciphertext file, and a temporary key for decrypting the hard disk partition table is generated by using the replaced random number and two or more biometric data of the temporary key currently generated by the user front end, and the decryption processing of the hard disk partition table is performed.
8. The encryption method according to claim 7, wherein: The method further comprises: When the hard disk partition table is updated, the updated hard disk partition table is encrypted according to the temporary key generated by the current user front end, and the random number of the temporary key for encrypting the updated hard disk partition table is stored in the ciphertext file containing the encrypted hard disk partition table, so that when the hard disk partition table is decrypted, the temporary key for decrypting the updated hard disk partition table is generated according to the stored random number.
9. The encryption method according to any one of claims 1 to 8, characterized in that: After generating corresponding temporary keys based on the captured two or more biometric data through the preset user front end and system back end, the encryption method further includes: The temporary key is encrypted according to the hardware unique root key of the mobile hard disk; wherein the hardware unique root key includes: a key generated by a static random access memory physical unclonable function SRAM PUF unit integrated on the main control chip of the mobile hard disk.
10. The encryption method according to any one of claims 1 to 8, characterized in that: The encryption method further includes performing one or any combination of the following processes: Before generating corresponding temporary keys based on the two or more captured biometric data through the pre-set user front end and system back end, the system determines whether the finger inputting the two or more biometric data is an authentic user finger based on the blood flow dynamic characteristics and the change in capacitance impedance; when it is determined that the finger inputting the two or more biometric data is an authentic user finger, the process of generating the temporary key based on the two or more captured biometric data is triggered; When it is detected that the force of holding the mobile hard disk is greater than a preset holding force threshold, or when it is detected that the mobile hard disk receives a tapping frequency greater than a preset tapping frequency threshold, one or any combination of the following processes is performed: returning false data based on a pre-stored false key, sending the positioning data and / or real-time ambient audio of the mobile hard disk to a pre-set security terminal, and driving the LED indicator of the mobile hard disk to indicate that the hard disk is abnormal; When the mobile hard disk is detected to be under physical attack, the SRAM PUF unit integrated in the main control chip of the mobile hard disk is burned out by a high-voltage pulse, wherein the physical attack includes detecting any of the following types of situations: shell cracking, low temperature attack or ultraviolet radiation; When the main control chip of the mobile hard drive is detected to be damaged, the NFC tag and energy collection circuit built into the mobile hard drive receive NFC radio frequency power from the mobile phone to wake up the mobile hard drive; after waking up the mobile hard drive and receiving the pre-set decryption key, the preset data is exported through the emergency module pre-set in the mobile hard drive.
11. A computer storage medium, wherein a computer program is stored in the computer storage medium, and when the computer program is executed by a processor, the method for encrypting a mobile hard disk according to any one of claims 1 to 10 is implemented.
12. A mobile hard disk comprising: A memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the encryption method for the mobile hard disk according to any one of claims 1 to 10 is implemented.