Data processing method, device and equipment and readable storage medium

By introducing logical disk operation and authentication code encryption mechanisms into the RAID card, the problem that ordinary hard drives cannot encrypt storage is solved, thus achieving the security and reliability of hard drive data and preventing data leakage.

CN120929020APending Publication Date: 2025-11-11SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511398432.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In existing technologies, hard drives without SED characteristics cannot achieve encrypted data storage, resulting in a lack of data security and confidentiality.

Method used

By introducing a RAID card between the host and the hard drive, the system utilizes logical disk operation requests to set the status and performs encryption and decryption processing on the data based on authentication codes and encryption codes, thus achieving encrypted storage of ordinary hard drives.

Benefits of technology

Secure and reliable data storage is achieved on hard drives without encryption capabilities, preventing data leaks and ensuring data security even if the hard drive is stolen.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120929020A_ABST
    Figure CN120929020A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method, device and equipment and a readable storage medium, and the method comprises the steps: setting the state of a logic disk through employing a logic disk operation request sent by a host, and determining a corresponding authentication code and an encryption code under the condition that the encryption and decryption functions of the logic disk are enabled; receiving a data writing request sent by the host, and determining a target logic disk corresponding to the writing position and target data to be written; authenticating the data writing request by using the authentication code of the target logic disk; under the condition that the authentication is passed and the current state of the target logic disk is encryption and decryption starting, encrypting the target data by using an encryption code of the target logic disk to obtain target encrypted data; and writing the target encrypted data into a hard disk space having a mapping relationship with the target logic disk in the redundant array of independent disks. According to the method and the device, the reliability and the security of data stored on the hard disk without an encryption function can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of storage technology, and in particular to a data processing method, apparatus, device, and readable storage medium. Background Technology

[0002] In a hard drive encryption storage solution with SED (Secure Data Encryption) features, data is stored in encrypted form on the SED hard drive after the user creates a unique key. Once the SED hard drive is removed from the RAID card storage environment, it automatically locks, preventing the user from directly reading the data. Only after unlocking the SED hard drive by entering the correct user key can the user read and write data normally, thus ensuring data security and confidentiality.

[0003] However, for hard drives that do not have SED (i.e., self-encrypting hard drives), encrypted storage cannot be achieved, resulting in a lack of data security and confidentiality.

[0004] In conclusion, issues such as how to perform encrypted storage on ordinary hard drives are technical problems that urgently need to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of this application is to provide a data processing method, apparatus, device, and readable storage medium that enables encrypted data storage on a regular hard disk.

[0006] To solve the above-mentioned technical problems, this application provides the following technical solution:

[0007] A data processing method, comprising:

[0008] The logical disk status is set using the logical disk operation request sent by the host, and the corresponding authentication code and encryption code are determined when the logical disk encryption and decryption function is enabled;

[0009] Receive the data write request sent by the host, and determine the target logical disk corresponding to the write location and the target data to be written;

[0010] The data write request is authenticated using the authentication code of the target logical disk;

[0011] If authentication is successful and the target logical disk is currently in the state of enabled encryption / decryption, the target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data.

[0012] The target encrypted data is written into a hard disk space in a redundant array of independent disks that is mapped to the target logical disk.

[0013] Preferably, it further includes:

[0014] Receive the data read request sent by the host and determine the specified logical disk corresponding to the read location;

[0015] If the current state of the specified logical disk is that encryption and decryption are enabled, the data read request is authenticated using the authentication code of the specified logical disk;

[0016] If authentication is successful, encrypted data is read from the hard disk space corresponding to the designated logical disk in the independent redundant disk array.

[0017] The encrypted data is decrypted using the encryption key corresponding to the specified logical disk to obtain the decrypted data;

[0018] The decrypted data is then sent back to the host.

[0019] Preferably, the target data is encrypted using the encryption key of the target logical disk to obtain encrypted target data, including:

[0020] Read the encrypted ciphertext from the hard disk space corresponding to the target logical disk in the independent redundant disk array;

[0021] The ciphertext is decrypted using an encryption system to obtain the encryption key for the target logical disk;

[0022] The target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data.

[0023] Preferably, the target data is encrypted using the encryption key of the target logical disk to obtain encrypted target data, including:

[0024] The target data is encrypted using the encryption key of the target logical disk and a no-padding block encryption method to obtain the target encrypted data.

[0025] Preferably, setting the state of a logical disk using a logical disk operation request sent by the host includes:

[0026] If the logical disk operation request is to enable encryption, then set the status of the corresponding logical disk to enable encryption / decryption.

[0027] If the logical disk operation request is to disable encryption, then set the status of the corresponding logical disk to disabled encryption / decryption.

[0028] If the logical disk operation request is to lock, then set the state of the corresponding logical disk to locked;

[0029] If the logical disk operation request is to unlock, then set the status of the corresponding logical disk to unlock;

[0030] If the logical disk operation is to modify the authentication code, then if the input authentication code is confirmed to be correct, the authentication code of the corresponding logical disk will be changed.

[0031] If the logical disk operation is a fast and secure erase, then the encryption password of the corresponding logical disk will be changed if the input authentication code is confirmed to be correct.

[0032] Preferably, after receiving the data write request sent by the host, the process includes:

[0033] When the target logical disk is currently in a state of disabled encryption, the target data is written to the hard disk space corresponding to the target logical disk in the independent disk redundancy array;

[0034] If the target logical disk is currently locked, a write failure message is sent to the host.

[0035] Preferably, after changing the encryption password of the corresponding logical disk, if the input authentication code is confirmed to be correct, the method further includes:

[0036] Receive a data read request sent by the host and determine the specified logical disk corresponding to the read location;

[0037] If the current state of the specified logical disk is that encryption and decryption are enabled, determine whether the data to be read is encrypted data written before the encryption password was changed;

[0038] If so, a message indicating that the data has been deleted is sent to the host.

[0039] A data processing apparatus, comprising:

[0040] The logical disk setting module is used to set the state of the logical disk using the logical disk operation request sent by the host, and to determine the corresponding authentication code and encryption code when the logical disk encryption and decryption function is enabled;

[0041] The request parsing module is used to receive the data write request sent by the host and determine the target logical disk corresponding to the write location and the target data to be written.

[0042] The authentication request module is used to authenticate the data write request using the authentication code of the target logical disk;

[0043] The data encryption module is used to encrypt the target data using the encryption key of the target logical disk when authentication is successful and the current state of the target logical disk is enabled for encryption and decryption, so as to obtain the target encrypted data.

[0044] The data write-to-disk module is used to write the target encrypted data into the hard disk space of the independent redundant disk array that has a mapping relationship with the target logical disk.

[0045] An electronic device, comprising:

[0046] Memory, used to store computer programs;

[0047] A processor is used to implement the steps of the above-described data processing method when executing the computer program.

[0048] A readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described data processing method.

[0049] Applying the method provided in the embodiments of this application, the state of the logical disk is set using a logical disk operation request sent by the host, and the corresponding authentication code and encryption code are determined when the logical disk encryption and decryption function is enabled; a data write request sent by the host is received, and the target logical disk and the target data to be written are determined corresponding to the write location; the data write request is authenticated using the authentication code of the target logical disk; if the authentication is successful and the current state of the target logical disk is that encryption and decryption are enabled, the target data is encrypted using the encryption code of the target logical disk to obtain the target encrypted data; the target encrypted data is written to the hard disk space in the independent disk redundancy array that has a mapping relationship with the target logical disk.

[0050] In this application, hard drives in an independent redundant disk array can be mapped to a host as logical drives. Then, based on logical drive operation requests sent by the host, the state of the logical drive can be set, and the corresponding authentication code and encryption code can be determined if logical drive encryption / decryption is enabled. Upon receiving a data write request from the host, the target logical drive corresponding to the write location and the target data to be written can be determined. To ensure the security and reliability of data in the independent redundant disk array, the data write request is first authenticated based on the authentication code of the target logical drive. Only if authentication is successful and the target logical drive's current characteristic is that encryption / decryption is enabled, the target data is encrypted using the target logical drive's encryption code to obtain the encrypted target data. Finally, the encrypted target data can be written to the hard drive space corresponding to the target logical drive in the independent disk array.

[0051] In other words, this application allows for the mapping of a hard drive to the host, enabling authentication of requests and encryption of written data based on the logical drive's status, authentication code, and encryption password. Access to the hard drive requires authentication, allowing even hard drives without encryption capabilities to store encrypted data. Because hard drive data writing requires authentication and the written data is encrypted, even if the hard drive is stolen, there is no need to worry about data leakage, thus ensuring the reliability and security of data stored on hard drives without encryption capabilities.

[0052] Accordingly, embodiments of this application also provide data processing apparatus, devices, and readable storage media corresponding to the above-described data processing methods, which have the aforementioned technical effects, and will not be elaborated further here. Attached Figure Description

[0053] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0054] Figure 1 This is a flowchart illustrating the implementation of a data processing method in an embodiment of this application.

[0055] Figure 2 This is a schematic diagram of an encryption generation method in an embodiment of this application;

[0056] Figure 3 This is a schematic diagram of an unlocking process in an embodiment of this application;

[0057] Figure 4 This is a schematic diagram illustrating the specific implementation architecture of a data processing method in this application embodiment;

[0058] Figure 5 This is a schematic diagram of the logical architecture of a data processing method in an embodiment of this application;

[0059] Figure 6 This is a schematic diagram of the structure of a data processing device according to an embodiment of this application;

[0060] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application;

[0061] Figure 8 This is a schematic diagram of the specific structure of an electronic device in an embodiment of this application. Detailed Implementation

[0062] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0063] A RAID card is a hardware device used to manage and control multiple hard drives (HDDs or SSDs), enabling them to be combined into a RAID (Redundant Array of Independent Disks) system. Through this combination, the RAID card not only provides data redundancy to enhance the reliability of the storage system but also improves performance. Its core objectives are to optimize storage performance and ensure data security.

[0064] Please refer to Figure 1 , Figure 1 This is a flowchart of a data processing method according to an embodiment of the present application. The method can be applied to a RAID controller (such as a RAID card) and includes the following steps.

[0065] S101. Set the state of the logical disk using the logical disk operation request sent by the host, and determine the corresponding authentication code and encryption code when the logical disk encryption and decryption function is enabled.

[0066] In this embodiment of the application, the hard disks in the independent disk redundant array can be mapped to the host as logical disks, so that the host can operate and set the storage status of the hard disks through the logical disks, thereby meeting the actual data storage needs.

[0067] Specifically, it can receive logical disk operation requests sent by the host, and set the state of the logical disk according to the logical disk operation request. When it is clear that the logical disk encryption and decryption function needs to be enabled, it can match the corresponding authentication code and encryption password.

[0068] The authentication code can be a specific password used for authentication, such as APIN (authentication PIN); the encryption password can be a specific password used for encryption, such as EPIN (encryption PIN). The authentication code can be specified by the host, while the encryption password can be randomly generated. APIN (authentication PIN): Used to control the encryption function of the block (logical disk) mapped from the RAID group to the host. EPIN (encryption PIN): The core security credential of the encryption system (ESYS) and decryption system (DSYS), used for encrypting and decrypting user data. By dynamically generating and storing encrypted PIN values, EPIN ensures that data remains protected during storage and transmission, effectively preventing unauthorized access or leakage risks. PIN stands for Personal Identification Number, a digital code used to verify a user's identity; it can be a sequence of multiple digits.

[0069] In this embodiment, the state based on the logical disk may include states such as enabling encryption / decryption function, disabling encryption / decryption function, locking, and unlocking.

[0070] In one specific embodiment of this application, setting the state of a logical disk using a logical disk operation request sent by the host includes:

[0071] If the logical disk operation request is to enable encryption, then set the status of the corresponding logical disk to enable encryption / decryption.

[0072] If the logical disk operation request is to disable encryption, then set the status of the corresponding logical disk to disabled encryption / decryption.

[0073] If the logical disk operation request is locked, then set the status of the corresponding logical disk to locked;

[0074] If the logical disk operation request is to unlock, then set the status of the corresponding logical disk to unlock;

[0075] If the logical disk operation involves modifying the authentication code, then, provided that the entered authentication code is correct, the authentication code of the corresponding logical disk will be changed.

[0076] If the logical disk operation is a fast and secure erase, then the encryption password of the corresponding logical disk will be changed after confirming that the entered authentication code is correct.

[0077] For example, if the logical drive remains in the following state:

[0078] BEENABLE: Enables encryption, indicating that the encryption function of BLOCK is enabled;

[0079] BEDISABLE: Encryption is off, indicating that the encryption function of BLOCK is disabled;

[0080] BELOCK: Locked state, indicating that the BLOCK is locked and read / write operations cannot be performed correctly;

[0081] BEUNLOCKw: Unlocked state, indicating that the BLOCK is unlocked and encryption / decryption / read / write operations can be performed normally;

[0082] Based on the support for the above states, the host can perform the following operations on the logical disk:

[0083] ENABLE: Enables encryption and decryption, setting the encryption function of BLOCK to the enabled state;

[0084] DISABLE: Disables encryption and decryption functions, setting the encryption function of BLOCK to a disabled state;

[0085] MODITY: Change PIN. Successful modification will not affect the normal reading and writing of already stored encrypted user data.

[0086] LOCK: Locks the block, preventing read and write operations. The hard drive automatically enters the BELOCK state after power loss.

[0087] UNLOCK: Unlocks the block, allowing encryption, decryption, read, and write operations;

[0088] SECURITYERASE: Fast and secure erase, used to quickly clear data in the block, ensuring that the data cannot be recovered.

[0089] In other words, the host can set the current status of the logical disks, such as whether they can be used, whether encryption and decryption data storage and reading are required, and set the encryption and authentication codes for each logical disk.

[0090] S102. Receive the data write request sent by the host, and determine the target logical disk corresponding to the write location and the target data to be written.

[0091] After the RAID controller receives a data write request from the host, it can determine the logical disk corresponding to the write location. For ease of distinction, in this embodiment, the logical disk corresponding to the write location requested by the data write request is referred to as the target logical disk, and the data that the host needs to write to the hard disk is referred to as the target data.

[0092] S103. Authenticate the data write request using the authentication code of the target logical disk.

[0093] To ensure the reliability and security of hard drive data, data write requests can be authenticated based on the authentication code of the target logical disk, that is, to determine whether the current user has the permission to write data to the target logical disk.

[0094] For example, the authentication code entered by the user is compared with the authentication code of the target logical drive. If they match, authentication is successful; if they do not match, authentication fails. In the case of authentication failure, a message indicating that authentication failed can be sent to the host.

[0095] S104. If authentication is successful and the target logical disk is currently in the state of enabled encryption / decryption, the target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data.

[0096] After successful authentication, the current state of the target logical drive can be obtained. If the current state is that encryption / decryption is enabled, the target data can be encrypted using the encryption key of the target logical drive, thus obtaining the encrypted target data. In other words, the target data has now changed from plaintext to ciphertext.

[0097] When encrypting target data, hardware-based encryption can be implemented directly based on the hardware resources on the RAID card. Since it is hardware-based encryption, the encryption time is very short and will not cause excessive increase in the delay of request processing.

[0098] In one specific embodiment of this application, the RAID controller is connected to an external encryption / decryption device. When encryption or decryption is required, the controller sends the data to be encrypted or decrypted to the external encryption / decryption device, receives encrypted or decrypted data from the device, writes the encrypted data to the hard drive, and sends the decrypted data back to the host. This reduces the hardware resource usage on the RAID card during data encryption or decryption.

[0099] In one specific embodiment of this application, target data is encrypted using the encryption key of the target logical disk to obtain encrypted target data, including:

[0100] Read the encrypted ciphertext from the hard disk space corresponding to the target logical disk in the independent redundant disk array;

[0101] The encryption system is used to decrypt the ciphertext to obtain the encryption key for the target logical disk;

[0102] The target data is encrypted using the encryption key of the target logical drive to obtain the encrypted target data.

[0103] To prevent the loss of encryption ciphers and ensure the security of data on the hard drive, the encryption cipher can be encrypted and stored in a redundant array of disks corresponding to the target logical drive. When the cipher is needed, it can be read from the hard drive and decrypted using an encryption system to obtain the encryption cipher for the target logical drive. This cipher can then be used to encrypt the target data, thus retrieving the encrypted data.

[0104] For example, after the APIN and EPIN are determined by the host-based operation request, the APIN and EPIN are stored in memory. To prevent the EPIN from being lost, ESYS can be used to encrypt the EPIN to generate the EEPIN (encrypted ciphertext), and the EEPIN (encrypting the EPIN using the APIN as the PIN) can be stored to the member disk (HDD or SSD) of the RAID group.

[0105] In one specific embodiment of this application, the target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data, including: encrypting the target data using the encryption key of the target logical disk and employing a no-padding block encryption method to obtain the target encrypted data.

[0106] As a hardware storage device, a RAID card primarily manages SSDs and HDDs to store user data. Typically, the LBA address of an SSD or HDD is 512 bytes or 4 KB. To ensure that the storage space occupied by encrypted user data is the same as that before encryption, a no-padding block encryption algorithm can be used to encrypt data in blocks of 512 bytes. This ensures that the encrypted data is also 512 bytes, and user data will not occupy more storage space due to encryption.

[0107] S105. Write the target encrypted data into the hard disk space of the independent disk redundancy array that has a mapping relationship with the target logical disk.

[0108] After encrypting the target data to obtain the target encrypted data, the target encrypted data can be written to the hard disk space in the independent redundant disk array that has a mapping relationship with the target logical disk.

[0109] In other words, when the encryption / decryption function of the logical drive is enabled, encrypted data can be written to a hard drive that does not have encryption capabilities.

[0110] Applying the method provided in the embodiments of this application, the state of the logical disk is set using a logical disk operation request sent by the host, and the corresponding authentication code and encryption code are determined when the logical disk encryption and decryption function is enabled; a data write request sent by the host is received, and the target logical disk and the target data to be written are determined corresponding to the write location; the data write request is authenticated using the authentication code of the target logical disk; if the authentication is successful and the current state of the target logical disk is that encryption and decryption are enabled, the target data is encrypted using the encryption code of the target logical disk to obtain the target encrypted data; the target encrypted data is written to the hard disk space in the independent disk redundancy array that has a mapping relationship with the target logical disk.

[0111] In this application, hard drives in an independent redundant disk array can be mapped to a host as logical drives. Then, based on logical drive operation requests sent by the host, the state of the logical drive can be set, and the corresponding authentication code and encryption code can be determined if logical drive encryption / decryption is enabled. Upon receiving a data write request from the host, the target logical drive corresponding to the write location and the target data to be written can be determined. To ensure the security and reliability of data in the independent redundant disk array, the data write request is first authenticated based on the authentication code of the target logical drive. Only if authentication is successful and the target logical drive's current characteristic is that encryption / decryption is enabled, the target data is encrypted using the target logical drive's encryption code to obtain the encrypted target data. Finally, the encrypted target data can be written to the hard drive space corresponding to the target logical drive in the independent disk array.

[0112] In other words, this application allows for the mapping of a hard drive to the host, enabling authentication of requests and encryption of written data based on the logical drive's status, authentication code, and encryption password. Access to the hard drive requires authentication, allowing even hard drives without encryption capabilities to store encrypted data. Because hard drive data writing requires authentication and the written data is encrypted, even if the hard drive is stolen, there is no need to worry about data leakage, thus ensuring the reliability and security of data stored on hard drives without encryption capabilities.

[0113] It should be noted that, based on the above embodiments, the embodiments of this application also provide corresponding improvement schemes. In the preferred / improved embodiments, the same or corresponding steps as in the above embodiments can be referred to each other, and the corresponding beneficial effects can also be referred to each other; however, these will not be elaborated upon in the preferred / improved embodiments herein.

[0114] In one specific embodiment of this application, it further includes:

[0115] Receive data read requests sent by the host and determine the specified logical disk corresponding to the read location;

[0116] If the current state of the specified logical disk is that encryption and decryption are enabled, the authentication code of the specified logical disk is used to authenticate the data read request.

[0117] If authentication is successful, read encrypted data from the hard disk space corresponding to the specified logical disk in the independent redundant disk array;

[0118] The encrypted data is decrypted using the encryption key corresponding to the specified logical disk to obtain the decrypted data;

[0119] The decrypted data is then sent back to the host.

[0120] In other words, when the host needs to read data from the hard drive, it sends a data read request to the PAID card. The RAID controller can then determine the logical disk corresponding to the read location based on this request. For clarity, the logical disk corresponding to the read location is referred to as the designated logical disk.

[0121] Once the specified logical disk is identified, its current state can be obtained. If the current state is that encryption and decryption are enabled, the authentication code of the specified logical disk can be used to authenticate the data read request.

[0122] After successful authentication, encrypted data can be read from the hardware space corresponding to the specified logical disk in the independent redundant disk array. Then, the encrypted data is encrypted again based on the encryption cipher of the specified logical disk to obtain the decrypted data, which is finally sent back to the host.

[0123] After authentication fails, a message indicating the failure can be sent to the host.

[0124] Thus, legitimate users can obtain the plaintext data by decrypting the encrypted data using the correct authentication code. Unauthorized users, unable to provide the correct authentication code, cannot obtain the plaintext data corresponding to the encrypted data on the hard drive, thereby effectively protecting the data.

[0125] In one specific embodiment of this application, after receiving a data write request sent by the host, the process includes:

[0126] If the target logical disk is currently in a state of disabled encryption, write the target data to the hard disk space corresponding to the target logical disk in the independent disk redundancy array;

[0127] If the target logical disk is currently locked, send a message to the host indicating that the write operation failed.

[0128] In other words, when the target logical disk is currently in a state of decryption, writing target data can skip the encryption process and directly write to the hard disk space; correspondingly, for data ownership, if the current state is in a state of decryption, reading data also skips the decryption process and directly feeds the data read from the hard disk space back to the host.

[0129] If the target logical disk is locked, access to the corresponding hard disk space is prohibited, meaning both writing and reading are prohibited. When the target logical disk is unlocked, access to the corresponding hard disk space is allowed, meaning both writing and reading are permitted. Whether encryption or decryption is required for writing and reading depends on whether encryption / decryption is enabled on the target logical disk.

[0130] In one specific embodiment of this application, after determining that the input authentication code is correct and changing the encryption password of the corresponding logical disk, the method further includes:

[0131] Receive data read requests sent by the host and determine the specified logical disk corresponding to the read location;

[0132] If the current state of the specified logical disk is that encryption and decryption are enabled, determine whether the data to be read is encrypted data written before the encryption password was changed;

[0133] If so, a message indicating that the data has been deleted will be sent to the host.

[0134] In other words, by entering the correct APIN, the user changes the EPIN to a newly generated random EPIN. At this point, the stored user data cannot be decrypted, thus completing the secure and fast erasure of the user data. The new EPIN is then used to generate a new EEPIN using the APIN, and the new EEPIN is stored on the hard drive.

[0135] To facilitate those skilled in the art to better understand and implement the data processing method provided in the embodiments of this application, the data processing method will be described in detail below with reference to specific examples.

[0136] ENABLE: By setting APIN on the BLOCK disk, the user enables the BLOCK's encryption function. At this time, the BLOCK is in the BEENABLE state, and an EPIN is randomly generated. The APIN and EPIN are stored in memory. To prevent the EPIN from being lost, ESYS is used to encrypt the EPIN to generate an EEPIN, and the EEPIN (using APIN as the PIN to encrypt the EPIN) is stored to the member disks (HDD or SSD) of the RAID group.

[0137] DISABLE: When the user enters the correct APIN, the DISABLE BLOCK encryption function is enabled. At this point, the BLOCK is in a BEDISABLE state, and reading and writing data will no longer involve encryption or decryption. Stored encrypted user data cannot be read correctly. Simultaneously, the APIN, EPIN, and EEPIN stored in the system are deleted.

[0138] MODITY: Users modify their APIN by entering the correct APIN. The new APIN is then used as the PIN to encrypt the EPIN, generating a new EEPIN, which is then stored on the hard drive.

[0139] LOCK: After the user enters the correct APIN and LOCKs, both the APIN and EPIN stored in memory are deleted, and read / write requests to BLOCK fail. Additionally, if the RAID card system restarts, it will automatically LOCK, at which point the BLOCK will be in the BELOCK state.

[0140] UNLOCK: Users can decrypt the EEPIN and recover the EPIN by entering the correct APIN, which is then used to encrypt and decrypt user data.

[0141] SECURITYERASE: By entering the correct APIN, the user modifies the EPIN to a newly generated random EPIN. At this point, the stored user data cannot be decrypted, thus completing the secure and fast erasure of user data. The new EPIN is used to generate a new EEPIN using the APIN, and the new EEPIN is stored on the hard drive.

[0142] Please refer to Figure 2 Users enable BLOCK's encryption function by entering APIN. The system automatically generates a random number EPIN, which serves as the root key for encrypting and decrypting user data. ESYS uses APIN to encrypt the EPIN and generate EEPIN.

[0143] Please refer to Figure 3 When BLOCK is in BELOCK state, after the user enters APIN, DSYS uses APIN to decrypt EEPIN and recover EEPIN. The recovered EEPIN is used as the root key for encrypting and decrypting user data.

[0144] Please refer to Figure 4 The user creates encrypted blocks 1 through 10, using APIN1, APIN2, ..., APINn as the user's PIN. The RAID card randomly generates EPIN1, EPIN2, ..., EPINn. The encrypted PIN (EPIN1) for encrypted block 1 is stored on a member disk of encrypted RAID group 1. When a write request is initiated to block 1, the RAID card's ESYS uses the EPIN1 code to encrypt the data in 512-byte blocks, and then stores the encrypted data in encrypted RAID group 1. When a read request is initiated to block 1, the RAID card reads the data from encrypted RAID group 1, DSYS uses the EPIN1 code to decrypt the data, and then transmits the decrypted plaintext data to the user.

[0145] Please refer to Figure 5 After applying the data processing method provided in the embodiments of this application, the encrypted data storage process includes: initializing the encryption module, enabling encryption by user input of APIN, and automatically generating a random encryption key EPIN on the RAID card; secure key storage, such as using APIN to encrypt the EPIN to generate an EEPIN, and securely storing the EEPIN to a hard disk (HDD / SSD). The data writing process involves receiving a user data write request, encrypting the user data in real time using the EPIN, storing the encrypted data to the hard disk, and receiving a user data read request, reading the encrypted data from the hard disk, decrypting it using the EPIN, and returning it to the user.

[0146] For the key management process, the APIN update mechanism is as follows: after verifying the old APIN, the new APIN is input, the EPIN is re-encrypted using the new APIN to generate a new EEPIN, and the EEPIN storage on the hard drive is updated. For secure data erasure, after verifying the APIN, an erasure operation is triggered, immediately clearing the EPIN from memory and generating and storing a new key set (EPIN+EEPIN).

[0147] For system security mechanisms, hardware migration protection is provided, and the system automatically locks (BELOCK state) during system restart or hard drive migration. It can only be unlocked by APIN verification. The system unlocking process is as follows: enter the correct APIN to unlock the encryption module, decrypt the EEPIN to restore the EPIN, restore data encryption and decryption functions, disable encryption functions, disable encryption after verifying the APIN, and securely clear all keys (APIN / EPIN / EEPIN).

[0148] As can be seen, the data processing method provided in this application embodiment can achieve the following technical effects in practical applications.

[0149] End-to-end data encryption protection: Through RAID card hardware-level encryption technology, all user data written to the hard drive is stored in encrypted form. Data read and write operations are only permitted after the correct APIN authentication code is entered, preventing unauthorized access at the storage source and ensuring data security.

[0150] Hardware-level lockout to prevent data loss: Even if the hard drive is physically lost, the encrypted data remains unbreakable. The system uses an APIN code binding mechanism; data is permanently locked if authentication fails, effectively addressing the risk of hardware loss or theft and meeting enterprise-level data leakage prevention requirements.

[0151] Millisecond-level secure erase technology: Addressing the issue of low efficiency in traditional HDD formatting, it innovatively adopts key destruction-based erasure: By clearing the encryption key (rather than physically overwriting the data), secure erasure can be completed in milliseconds, improving efficiency by more than 100 times, and meeting the unrecoverable security standard.

[0152] Significantly reduces storage costs compared to the SED (Self-Encrypting Hard Drive) solution: Cost advantage: Directly uses ordinary hard drives, saving 20%~30% of hardware procurement costs; Lossless performance: Encryption / decryption is accelerated by RAID card hardware, avoiding the performance overhead of SED disks.

[0153] Flexible adaptation to all scenarios and solution compatibility: Hardware layer: Supports HDD / SSD hybrid storage architecture; Scenario layer: Suitable for enterprise-level storage environments such as RAID arrays, storage servers, and backup systems, with high scalability.

[0154] Corresponding to the above method embodiments, this application also provides a data processing apparatus, and the data processing apparatus described below can be referred to in correspondence with the data processing method described above.

[0155] See Figure 6 As shown, the device includes the following modules:

[0156] The logical disk setting module 101 is used to set the state of the logical disk using the logical disk operation request sent by the host, and to determine the corresponding authentication code and encryption code when the logical disk encryption and decryption function is enabled.

[0157] The request parsing module 102 is used to receive data write requests sent by the host and determine the target logical disk corresponding to the write location and the target data to be written.

[0158] The authentication module 103 is used to authenticate the data write request using the authentication code of the target logical disk.

[0159] The data encryption module 104 is used to encrypt the target data using the encryption key of the target logical disk when authentication is successful and the current state of the target logical disk is enabled for encryption and decryption, so as to obtain the target encrypted data.

[0160] The data write-to-disk module 105 is used to write the target encrypted data into the hard disk space of the independent redundant disk array that has a mapping relationship with the target logical disk.

[0161] Using the apparatus provided in this application embodiment, the state of the logical disk is set by a logical disk operation request sent by the host, and the corresponding authentication code and encryption code are determined when the logical disk encryption and decryption function is enabled; a data write request sent by the host is received, and the target logical disk and the target data to be written are determined corresponding to the write location; the data write request is authenticated using the authentication code of the target logical disk; if the authentication is successful and the current state of the target logical disk is that encryption and decryption are enabled, the target data is encrypted using the encryption code of the target logical disk to obtain the target encrypted data; the target encrypted data is written to the hard disk space in the independent disk redundancy array that has a mapping relationship with the target logical disk.

[0162] In this application, hard drives in an independent redundant disk array can be mapped to a host as logical drives. Then, based on logical drive operation requests sent by the host, the state of the logical drive can be set, and the corresponding authentication code and encryption code can be determined if logical drive encryption / decryption is enabled. Upon receiving a data write request from the host, the target logical drive corresponding to the write location and the target data to be written can be determined. To ensure the security and reliability of data in the independent redundant disk array, the data write request is first authenticated based on the authentication code of the target logical drive. Only if authentication is successful and the target logical drive's current characteristic is that encryption / decryption is enabled, the target data is encrypted using the target logical drive's encryption code to obtain the encrypted target data. Finally, the encrypted target data can be written to the hard drive space corresponding to the target logical drive in the independent disk array.

[0163] In other words, this application allows for the mapping of a hard drive to the host, enabling authentication of requests and encryption of written data based on the logical drive's status, authentication code, and encryption password. Access to the hard drive requires authentication, allowing even hard drives without encryption capabilities to store encrypted data. Because hard drive data writing requires authentication and the written data is encrypted, even if the hard drive is stolen, there is no need to worry about data leakage, thus ensuring the reliability and security of data stored on hard drives without encryption capabilities.

[0164] In one specific embodiment of this application, it includes:

[0165] The request parsing module is specifically used to receive data read requests sent by the host and determine the specified logical disk corresponding to the read location;

[0166] The authentication request module is specifically used to authenticate data read requests using the authentication code of the specified logical disk when the current state of the specified logical disk is that encryption and decryption are enabled.

[0167] The data reading module is used to read encrypted data from the hard disk space corresponding to the specified logical disk in the independent disk redundancy array after authentication is passed.

[0168] The data decryption module is used to decrypt encrypted data using the encryption key corresponding to the specified logical disk, and obtain decrypted data.

[0169] The response module is used to send the decrypted data back to the host.

[0170] In one specific embodiment of this application, the data encryption module is specifically used to read encrypted ciphertext from the hard disk space corresponding to the target logical disk in the independent disk redundant array; decrypt the ciphertext using the encryption system to obtain the encryption key of the target logical disk; and encrypt the target data using the encryption key of the target logical disk to obtain the target encrypted data.

[0171] In one specific embodiment of this application, the data encryption module is specifically used to encrypt the target data using the encryption cipher of the target logical disk and a no-padding block encryption method to obtain the target encrypted data.

[0172] In one specific embodiment of this application, the logical disk setting module is specifically used to: if the logical disk operation request is to enable encryption, set the state of the corresponding logical disk to enabled encryption / decryption; if the logical disk operation request is to disable encryption, set the state of the corresponding logical disk to disabled encryption / decryption; if the logical disk operation request is to lock, set the state of the corresponding logical disk to locked; if the logical disk operation request is to unlock, set the state of the corresponding logical disk to unlock; if the logical disk operation is to modify the authentication code, change the authentication code of the corresponding logical disk if the input authentication code is correct; if the logical disk operation is to perform a fast and secure erase, change the encryption code of the corresponding logical disk if the input authentication code is correct.

[0173] In one specific embodiment of this application, it includes:

[0174] The unencrypted response module is used to receive a data write request sent by the host and, if the current state of the target logical disk is the disabled encryption state, write the target data to the hard disk space corresponding to the target logical disk in the independent disk redundancy array.

[0175] The locking module is used to receive a data write request from the host and, if the target logical disk is currently in a locked state, to send a write failure message back to the host.

[0176] In one specific embodiment of this application, the response module is used to receive a data read request sent by the host after changing the encryption password of the corresponding logical disk when the input authentication code is confirmed to be correct, and to determine the specified logical disk corresponding to the read location; if the current state of the specified logical disk is that encryption and decryption are enabled, to determine whether the data to be read is encrypted data written before the encryption password was changed; if so, to send a prompt message to the host that the data has been deleted.

[0177] Corresponding to the above method embodiments, this application also provides an electronic device. The electronic device described below and the data processing method described above can be referred to each other.

[0178] See Figure 7 As shown, the electronic device includes:

[0179] Memory 332 is used to store computer programs;

[0180] The processor 322 is used to implement the steps of the data processing method in the above method embodiments when executing a computer program.

[0181] For details, please refer to Figure 8 , Figure 8This is a schematic diagram of the specific structure of an electronic device provided in this embodiment. The electronic device can vary significantly due to differences in configuration or performance. It may include one or more central processing units (CPUs) (e.g., one or more processors) and a memory 332. The memory 332 stores one or more computer programs 342 or data 344. The memory 332 can be temporary or permanent storage. The program stored in the memory 332 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the data processing device. Furthermore, the processor 322 may be configured to communicate with the memory 332 and execute the series of instruction operations stored in the memory 332 on the electronic device 301.

[0182] Electronic device 301 may also include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341.

[0183] The steps in the data processing method described above can be implemented by the structure of an electronic device.

[0184] Corresponding to the above method embodiments, this application also provides a readable storage medium. The readable storage medium described below can be referred to in conjunction with the data processing method described above.

[0185] A readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the data processing method described in the above method embodiments.

[0186] The readable storage medium can specifically be a USB flash drive, external hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, or any other readable storage medium capable of storing program code.

[0187] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0188] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0189] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0190] Finally, it should be noted that in this document, relationships such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "include," "contain," or any other variations are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.

[0191] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data processing method, characterized in that, include: The logical disk status is set using the logical disk operation request sent by the host, and the corresponding authentication code and encryption code are determined when the logical disk encryption and decryption function is enabled; Receive the data write request sent by the host, and determine the target logical disk corresponding to the write location and the target data to be written; The data write request is authenticated using the authentication code of the target logical disk; If authentication is successful and the target logical disk is currently in the state of enabled encryption / decryption, the target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data. The target encrypted data is written into a hard disk space in a redundant array of independent disks that is mapped to the target logical disk.

2. The method according to claim 1, characterized in that, Also includes: Receive the data read request sent by the host and determine the specified logical disk corresponding to the read location; If the current state of the specified logical disk is that encryption and decryption are enabled, the data read request is authenticated using the authentication code of the specified logical disk; If authentication is successful, encrypted data is read from the hard disk space corresponding to the designated logical disk in the independent redundant disk array. The encrypted data is decrypted using the encryption key corresponding to the specified logical disk to obtain the decrypted data; The decrypted data is then fed back to the host.

3. The method according to claim 1, characterized in that, The target data is encrypted using the encryption key of the target logical disk to obtain encrypted target data, including: Read the encrypted ciphertext from the hard disk space corresponding to the target logical disk in the independent redundant disk array; The ciphertext is decrypted using an encryption system to obtain the encryption key for the target logical disk; The target data is encrypted using the encryption key of the target logical disk to obtain the target encrypted data.

4. The method according to claim 1, characterized in that, The target data is encrypted using the encryption key of the target logical disk to obtain encrypted target data, including: The target data is encrypted using the encryption key of the target logical disk and a no-padding block encryption method to obtain the target encrypted data.

5. The method according to any one of claims 1 to 4, characterized in that, The logical disk status is set using logical disk operation requests sent by the host, including: If the logical disk operation request is to enable encryption, then set the status of the corresponding logical disk to enable encryption / decryption. If the logical disk operation request is to disable encryption, then set the status of the corresponding logical disk to disabled encryption / decryption. If the logical disk operation request is to lock, then set the state of the corresponding logical disk to locked; If the logical disk operation request is to unlock, then set the status of the corresponding logical disk to unlock; If the logical disk operation is to modify the authentication code, then if the input authentication code is confirmed to be correct, the authentication code of the corresponding logical disk will be changed. If the logical disk operation is a fast and secure erase, then if the input authentication code is confirmed to be correct, the encryption password of the corresponding logical disk will be changed.

6. The method according to claim 5, characterized in that, After receiving the data write request sent by the host, the process includes: When the current state of the target logical disk is in the off encryption state, the target data is written to the hard disk space corresponding to the target logical disk in the independent disk redundancy array; If the target logical disk is currently locked, a write failure message is sent to the host.

7. The method according to claim 5, characterized in that, After confirming that the entered authentication code is correct, and changing the encryption password for the corresponding logical drive, the process also includes: Receive a data read request sent by the host and determine the specified logical disk corresponding to the read location; If the current state of the specified logical disk is that encryption and decryption are enabled, determine whether the data to be read is encrypted data written before the encryption password was changed; If so, a message indicating that the data has been deleted is sent to the host.

8. A data processing apparatus, characterized in that, include: The logical disk setting module is used to set the state of the logical disk using the logical disk operation request sent by the host, and to determine the corresponding authentication code and encryption code when the logical disk encryption and decryption function is enabled; The request parsing module is used to receive the data write request sent by the host and determine the target logical disk corresponding to the write location and the target data to be written. The authentication request module is used to authenticate the data write request using the authentication code of the target logical disk; The data encryption module is used to encrypt the target data using the encryption key of the target logical disk when authentication is successful and the current state of the target logical disk is enabled for encryption and decryption, so as to obtain the target encrypted data. The data write-to-disk module is used to write the target encrypted data into the hard disk space of the independent redundant disk array that has a mapping relationship with the target logical disk.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the data processing method as described in any one of claims 1 to 7.

10. A readable storage medium, characterized in that, The readable storage medium stores a computer program that, when executed by a processor, implements the steps of the data processing method as described in any one of claims 1 to 7.