A hardware-software co-operated secure AI NAS storage system and access authentication method

Through a hardware-software co-engineering architecture and multi-layered security mechanisms, the system addresses the security shortcomings of traditional NAS systems, enabling fine-grained access control, rapid data recovery, and efficient threat response, thereby improving the overall security and compliance of the system.

CN122120003APending Publication Date: 2026-05-29QUANTUM CORE CLOUD (BEIJING) MICROELECTRONICS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
QUANTUM CORE CLOUD (BEIJING) MICROELECTRONICS TECH CO LTD
Filing Date
2026-04-07
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Traditional NAS systems suffer from insufficient data encryption, lax access control, lack of security auditing, lack of multi-factor authentication, disconnect between hardware and software security, and lack of zero-trust architecture, resulting in inadequate system security and an inability to effectively resist physical attacks and complex network threats.

Method used

It adopts a hardware-software co-engineering architecture, including a hardware security layer, a lobster security core module, a mandatory authentication gateway, an encrypted storage engine, an intelligent access control module, and a security audit and monitoring module. Through hardware root of trust, multi-layered security mechanisms, and mandatory authentication, it achieves fine-grained permission management, abnormal behavior detection, and data protection.

Benefits of technology

It achieves inherent security enhancements, eliminates unauthorized access, prevents key leakage, supports rapid data recovery, meets regulatory requirements, and improves operational efficiency and threat response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120003A_ABST
    Figure CN122120003A_ABST
Patent Text Reader

Abstract

The application provides a soft and hard cooperative security AI NAS storage and calculation system and an access authentication method, and belongs to the technical field of network storage. The system comprises a hardware security layer, a lobster security core module, a compulsory authentication gateway, an encrypted storage engine, an intelligent access control module and a security audit and monitoring module. The hardware security layer comprises a lobster security chip and a hardware root of trust module. The lobster security chip is an independent security processor, and is internally provided with a true random number generator, an encryption acceleration engine and a security storage area. The hardware root of trust module is used for system startup verification and root key hardware protection. Through the soft and hard cooperative architecture and the compulsory authentication mechanism, the application realizes a complete trust chain from the hardware root of trust to the application layer, can effectively prevent ransomware attacks and data leakage risks, and improves data operation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network storage technology, specifically to a network attached storage (NAS) system with enhanced security features and its data protection method, which is particularly suitable for enterprise-level storage scenarios, government agency data storage, and financial institution data management, where data security requirements are high. Background Technology

[0002] With the rapid growth of enterprise and personal data volumes, Network Attached Storage (NAS) devices are widely used in data storage and sharing scenarios. However, traditional NAS systems suffer from the following security issues:

[0003] First, data encryption is insufficient; most NAS devices only support transport layer encryption (such as HTTPS), with weak encryption capabilities for data at rest. Even if encryption is supported, the keys are usually stored in software configuration files, making them vulnerable to theft or leakage. The lack of hardware-level key protection mechanisms makes them susceptible to physical and side-channel attacks.

[0004] Second, access control is coarse-grained; traditional NAS systems lack sufficient granularity in permission management, typically supporting only coarse-grained permission control based on users / user groups, making it difficult to achieve fine-grained access control at the file or field level. Authentication mechanisms are easily bypassed, posing a risk of privilege escalation vulnerabilities.

[0005] Third, security audits are lacking; there is a lack of complete operation logs and abnormal behavior detection mechanisms. Even if logs are recorded, the logs themselves are easily tampered with or deleted, and cannot serve as a reliable basis for tracing security incidents.

[0006] Fourth, ransomware protection is weak; it lacks effective data protection and recovery capabilities when facing ransomware attacks. Traditional backup mechanisms can be encrypted simultaneously by ransomware, leading to permanent data loss.

[0007] Fifth, multi-factor authentication is lacking; reliance on a single password authentication poses a risk of credential leakage. Once the password is stolen or brute-forced, attackers can gain full access.

[0008] Sixth, there is a disconnect between software and hardware security; existing solutions lack deep collaboration between software and hardware security modules, failing to form a complete trust chain. Software security strategies can be bypassed by software vulnerabilities, and hardware security capabilities are not fully utilized.

[0009] Seventh, the lack of a zero-trust architecture; traditional NAS adopts a "perimeter protection" approach, and internal network access usually does not require strict authentication. Once the perimeter is breached, the internal system is completely exposed, and attackers can move laterally to steal data.

[0010] While some NAS manufacturers have introduced basic security features in existing technologies, they lack a systematic security architecture design and are unable to cope with increasingly complex cybersecurity threats. In particular, the lack of a mandatory authentication mechanism based on a hardware root of trust allows attackers to bypass security protections through software vulnerabilities.

[0011] Therefore, there is an urgent need for an inherently secure NAS storage system that integrates hardware and software and enforces authentication to solve the aforementioned technical problems. Summary of the Invention

[0012] The purpose of this invention is to provide a hardware-software co-operated secure NAS storage system and access authentication method based on the Lobster architecture. Through multi-layered security mechanisms and hardware-enforced authentication, it solves the technical defects of traditional NAS systems in data protection, access control, and security auditing, and achieves inherent security improvement.

[0013] The present invention adopts the following technical solution:

[0014] A hardware-software co-operated secure AI NAS storage system and access authentication method are characterized by comprising: the system includes a hardware security layer, a lobster security core module, a mandatory authentication gateway, an encrypted storage engine, an intelligent access control module, and a security audit and monitoring module.

[0015] The hardware security layer includes a lobster security chip and a hardware root trust module. The lobster security chip is an independent security processor with a built-in true random number generator, encryption acceleration engine and secure storage area. The hardware root trust module is used for system startup verification and root key hardware protection.

[0016] The lobster security core module runs on the lobster security chip and is used to formulate and execute security policies and manage the key lifecycle.

[0017] The mandatory authentication gateway intercepts all access requests, and unauthenticated access is blocked at the hardware level.

[0018] The encrypted storage engine is used to encrypt static data and transmitted data, and the key is generated and protected by the lobster security chip.

[0019] The intelligent access control module is used to implement fine-grained permission management based on roles and attributes;

[0020] The security audit and monitoring module is used to record operation logs and detect abnormal behavior. The logs are signed by a security chip to prevent tampering.

[0021] The aforementioned computing power collaboration utilizes the Lobster Security Core to call upon large models for inference and training, thereby improving data processing efficiency through computing power collaboration.

[0022] The mandatory authentication gateway supports multi-factor authentication, including at least two combinations of password, hardware key (FIDO2), biometrics, and dynamic token, and the authentication process has no software bypass path.

[0023] The lobster security core module adopts a hierarchical key management mechanism, including three layers: root key, master key, and data key. The root key is stored in the hardware trust root, while the master key and data key are managed by the lobster security chip, which supports automatic key rotation.

[0024] The system supports dual-stack of Chinese national cryptographic algorithms and international algorithms. The Chinese national cryptographic algorithms include SM2, SM3, and SM4, while the international algorithms include RSA, AES, and SHA-256.

[0025] The intelligent access control module supports multi-dimensional access policies based on time, location, device type, and network environment, and can dynamically adjust permissions based on user behavior analysis, triggering secondary authentication for sensitive operations.

[0026] The security audit and monitoring module integrates machine learning algorithms to identify abnormal access patterns, ransomware behavior, and risks of data leakage.

[0027] The system employs a zero-trust architecture, rejecting all access requests by default, periodically re-verifying user identity during sessions, and immediately terminating sessions upon detecting abnormal behavior. It also includes a data snapshot and recovery module for creating immutable snapshots. Snapshot metadata is signed by a Lobster security chip, supporting one-click recovery to any point in time.

[0028] The hardware root of trust module verifies the integrity of the bootloader, kernel, and security module sequentially during system startup. If the verification fails, the system is prevented from starting.

[0029] The secure storage access authentication method of the system includes the following steps:

[0030] Step 1: Receive access requests initiated by users or clients;

[0031] Step 2: Force the authentication gateway to intercept the request and check the authentication status;

[0032] Step 3: If unauthenticated or session expired, perform multi-factor authentication;

[0033] Step 4: Verify the device fingerprint and compare it with the bound device;

[0034] Step 5: The Lobster Security Core generates a session token, which contains the user ID, permission list, validity period, and device fingerprint, and is signed by the security chip's private key.

[0035] Step 6: Verify access policies based on user permissions and target resources;

[0036] Step 7: Generate temporary access credentials and establish an encrypted data transmission channel;

[0037] Step 8: Record the complete audit log, which is signed by the security chip;

[0038] Step 9: Periodically re-verify user identity and detect abnormal behavior during the session.

[0039] In step 3, multi-factor authentication includes at least two of the following: first-factor password verification, second-factor device push verification, and third-factor biometric or hardware key verification.

[0040] In step 9, the session renewal verification interval is 10-60 minutes. If abnormal behavior is detected, the session will be terminated immediately and an alert will be issued. It also includes ransomware protection steps, which automatically block suspicious processes, trigger data snapshot protection, and support one-click restoration to the pre-infection state when abnormal file encryption behavior is detected.

[0041] In step 5, the session token is valid for 30 minutes to 24 hours, and can be dynamically adjusted according to the security policy.

[0042] The lobster security chip communicates with the main processor via a security bus, which uses an encrypted channel to prevent man-in-the-middle attacks.

[0043] The encrypted storage engine supports two modes: full-disk encryption and file-level encryption. The key is bound to the user's identity, and different users' data are encrypted using different keys.

[0044] The security audit and monitoring module supports remote log synchronization. The log synchronization channel uses two-way authentication and encrypted transmission to prevent log tampering and leakage. It also includes an emergency response module that automatically executes preset emergency response strategies when a security threat is detected, including isolating infected devices, freezing suspicious accounts, and triggering data protection snapshots.

[0045] The system supports distributed deployment, with multiple NAS nodes sharing the same Lobster Security Core, enabling unified management of security policies and collaborative key protection across nodes.

[0046] The hardware root of trust module supports remote authentication and can verify the system integrity status to third parties, making it suitable for cloud environments and trusted computing scenarios. Attached Figure Description

[0047] Figure 1 This is a system architecture diagram of the present invention. Detailed Implementation

[0048] The following specific embodiments illustrate the implementation of the present invention. Those skilled in the art can understand the advantages and effects of the present invention from the content disclosed in this specification. The present invention can be implemented or applied through other different specific embodiments, and various details in this specification can also be modified and changed based on different viewpoints and applications without departing from the spirit of the present invention. Furthermore, the accompanying drawings of the present invention are for simple illustrative purposes only and are not depictions of actual dimensions; this is stated beforehand. The following embodiments will further describe the relevant technical content of the present invention in detail, but the disclosed content is not intended to limit the scope of protection of the present invention.

[0049] Compared with the prior art, the present invention has the following beneficial effects:

[0050] 1. Enhanced inherent security: The hardware-software co-engineering architecture enforces security policies through hardware, making them impossible to bypass via software vulnerabilities. Even if the main operating system is compromised, the security core can still protect keys and data.

[0051] 2. Mandatory Authentication Guarantee: All access must be authenticated, and hardware-level blocking of bypass attempts prevents unauthorized access. Multi-factor authentication significantly reduces the risk of credential leakage.

[0052] 3. Complete Trust Chain: A complete verification chain from the hardware root of trust to the application layer ensures system integrity. Failure to verify at startup prevents system boot and safeguards against malicious firmware attacks.

[0053] 4. Enhanced Key Security: Keys remain within hardware security boundaries throughout the entire process, preventing key leakage and side-channel attacks. Layered key management reduces the risk of single points of leakage.

[0054] 5. Enhanced Compliance: Supports national cryptographic algorithms and meets the requirements of GDPR, Cybersecurity Classified Protection 2.0, and Commercial Cryptography Regulations. Complete audit logs support security incident tracing.

[0055] 6. Improved operational efficiency: Automated security policies and key rotation reduce manual intervention. Automatic detection and blocking of abnormal behavior lowers the burden of security operations.

[0056] 7. Data Reliability Guarantee: Immutable snapshots ensure data recovery and effectively defend against ransomware. One-click recovery can complete data recovery in minutes.

[0057] 8. Timely Threat Response: Real-time detection and automatic blocking reduce security incident losses. Supports remote alerts and emergency response for rapid handling of security threats.

[0058] Example 1: Deployment of Enterprise-Grade Secure NAS with Hardware and Software Collaborative Security AI

[0059] 1. Hardware Configuration

[0060] NAS server: configured with Intel Xeon or AMD EPYC CPU, 64GB memory, and 8 x 8TB enterprise-grade hard drives (RAID 6 configuration);

[0061] Lobster security chip: Independent ARM TrustZone security processor, 800MHz clock speed, built-in 512KB secure SRAM, supports AES-256 / RSA-4096 / SM2 / SM3 / SM4 hardware acceleration;

[0062] TPM 2.0 module: used for system startup verification and root key storage, compliant with TCG specifications;

[0063] Secure storage media: Supports self-encrypting hard drives (SEDs) with hardware-level AES-256 encryption;

[0064] 2. System Architecture

[0065] Specifically, the system architecture is as follows: Figure 1 As shown.

[0066] 3. Mandatory Authentication Workflow

[0067] Step S1: The user / client initiates an access request (read / write / management / deletion, etc.).

[0068] Requests can be initiated through web interfaces, mobile apps, desktop clients, API interfaces, SMB / NFS protocols, etc.

[0069] Step S2: Force the authentication gateway to intercept the request and check the authentication status.

[0070] The mandatory authentication gateway runs on the security chip and intercepts all inbound requests. It checks whether the request carries a valid session token.

[0071] If no valid session is found, the process will redirect to S3 for authentication.

[0072] If a session exists but has expired, redirect to S4 to verify session renewal.

[0073] If the session is valid, proceed to S6;

[0074] Step S3: Multi-factor authentication

[0075] The user enters a username and password (first factor);

[0076] The system pushes an authentication request to the user's bound device (second factor), and the user confirms via push notification;

[0077] Optional third factor: biometrics (fingerprint / face) or hardware key (FIDO2);

[0078] The authentication result is returned to the authentication gateway; if the authentication fails, access is denied and an audit log is logged.

[0079] Step S4: Device fingerprint verification

[0080] Collect device hardware information: MAC address, hard drive serial number, TPM identifier, CPU ID, motherboard serial number, etc.

[0081] Generate a device fingerprint hash and compare it with the bound device fingerprint;

[0082] If the device is incompatible, access will be denied and an alert will be issued, notifying the administrator of suspicious login attempts.

[0083] Step S5: Lobster Security Core generates session tokens

[0084] The token contains: user ID, permission list, validity period, device fingerprint hash, and session ID;

[0085] The token is signed with a secure chip private key (ECDSA P-256 or SM2) to prevent forgery;

[0086] The token is encrypted and stored in a secure area on the client (browser secure storage / application sandbox).

[0087] The token is valid for 30 minutes by default, but this can be adjusted according to security policies.

[0088] Step S6: Access Policy Verification

[0089] Lobster Security Core performs policy matching based on user permissions and target resources;

[0090] Check the time policy (whether access is allowed during this time period);

[0091] Check the location policy (whether the IP address / geographical location is within the allowed range);

[0092] Check the equipment policy (whether the equipment type meets the requirements);

[0093] Check the network policy (whether it comes from a trusted network);

[0094] Sensitive operations (deletion, batch export, permission modification) trigger two-factor authentication;

[0095] Step S7: Authorize Access

[0096] Generate a temporary access credential (valid for 5-30 minutes);

[0097] Establish an encrypted data transmission channel (TLS 1.3);

[0098] Access requests are permitted, and data read and write operations are processed by the encrypted storage engine;

[0099] Step S8: Audit Log Recording

[0100] Record the complete access chain: user ID, device fingerprint, timestamp, operation type, target resource, and access result;

[0101] The logs are signed with the private key of the security chip to prevent tampering;

[0102] Logs are synchronized to a remote log server in real time (two-way authentication + encrypted transmission).

[0103] Real-time alerts for abnormal behavior (SMS / email / push notifications);

[0104] Step S9: Continuous Session Verification

[0105] User identity is re-verified periodically (default 30 minutes) during the session;

[0106] Verification methods: push notification confirmation, biometric identification, or silent device fingerprint verification;

[0107] Abnormal behavior (such as abnormal time access, abnormal location access, high frequency operation) is detected and the session is terminated immediately;

[0108] The token expires automatically after the session ends and cannot be reused.

[0109] 4. Ransomware Protection Process

[0110] When the system detects abnormal file encryption behavior:

[0111] 1) Threat Identification: The security audit and monitoring module identifies ransomware characteristics (frequent file modification, batch changes to file extensions, abnormal entropy values, etc.);

[0112] 2) Automatic blocking: Immediately block suspicious processes and freeze related accounts;

[0113] 3) Snapshot Protection: Triggers data snapshot protection, creating an immutable snapshot;

[0114] 4) Alarm Notification: Send alarm notifications to the administrator (SMS / email / push notification);

[0115] 5) Recovery Support: Supports one-click restoration to the pre-infection state, with data recovery completed in minutes.

[0116] Example 2: Secure NAS Deployment for Government Agencies

[0117] To address the high security requirements of government agencies, the following features are added to Implementation Example 1:

[0118] 1. Priority given to national cryptographic algorithms: The default algorithm used is SM2 / SM3 / SM4, which complies with commercial cryptographic regulations;

[0119] 2. Separation of three roles: The system administrator, security administrator, and audit administrator have separate authority and checks and balances.

[0120] 3. Offline Key Backup: The root key supports offline backup to the smart IC card, which is kept by a designated person.

[0121] 4. Enhanced Secure Boot: BIOS / UEFI Secure Boot allows only signed firmware to run;

[0122] 5. Network isolation: The management network and business network are physically isolated to prevent lateral movement.

[0123] 6. Compliance Audit: Meets Level 3 requirements of the Cybersecurity Classified Protection Scheme 2.0 and supports automatic generation of compliance reports;

[0124] Example 3: Home / Small Office Deployment

[0125] For home / small office scenarios, a simplified configuration is provided:

[0126] 1. Integrated Device: The Lobster security chip is integrated into the NAS motherboard, reducing deployment costs.

[0127] 2. Simplified authentication: Supports two-factor authentication (password + mobile push notification), requiring no additional hardware.

[0128] 3. Automatic Backup: Configure automatic cloud backup for off-site data disaster recovery.

[0129] 4. Mobile Management: Provides a mobile app to support remote monitoring and management.

[0130] 5. Intelligent Alarm: Abnormal access will automatically push alarms to your mobile phone.

[0131] Those skilled in the art will understand that the above embodiments are for illustrative purposes only and are not intended to limit the invention. The following substitutions may be made without departing from the spirit and scope of the invention:

[0132] 1. The lobster security chip can adopt other security processor architectures (such as Intel SGX, AMD SEV).

[0133] 2. Multi-factor authentication can be replaced by other authentication methods (such as SMS verification code, email verification code).

[0134] 3. The encryption algorithm can be adjusted according to requirements (e.g., using ChaCha20-Poly1305 instead of AES-GCM).

[0135] 4. Other types of storage media can be used (such as NVMe SSD, cloud storage).

[0136] 5. Deployment scenarios can be extended to cloud NAS, hybrid cloud storage, etc.

[0137] This invention can be widely applied in the following scenarios:

[0138] 1. Enterprise Data Storage: Protecting core enterprise data assets and preventing data breaches.

[0139] 2. Government agencies: Meet compliance requirements such as Cybersecurity Classified Protection 2.0 and trade secret regulations.

[0140] 3. Financial institutions: Protecting sensitive customer information and meeting financial regulatory requirements.

[0141] 4. Medical institutions: Protect patient privacy data and comply with HIPAA and other regulations.

[0142] 5. Educational institutions: Protecting research data and information on teachers and students.

[0143] 6. Individual users: Protect personal photos, documents, and other private data.

Claims

1. A hardware-software co-operated secure AI NAS storage system and access authentication method, characterized in that, include: The system includes a hardware security layer, a lobster security core module, a mandatory authentication gateway, an encrypted storage engine, an intelligent access control module, and a security audit and monitoring module. The hardware security layer includes a lobster security chip and a hardware root trust module. The lobster security chip is an independent security processor with a built-in true random number generator, encryption acceleration engine and secure storage area. The hardware root trust module is used for system startup verification and root key hardware protection. The lobster security core module runs on the lobster security chip and is used to formulate and execute security policies and manage the key lifecycle. The mandatory authentication gateway intercepts all access requests, and unauthenticated access is blocked at the hardware level. The encrypted storage engine is used to encrypt static data and transmitted data. The key is generated and protected by the Lobster security chip. The encrypted storage engine supports two modes: full-disk encryption and file-level encryption. The key is bound to the user's identity, and different users' data are encrypted using different keys. The intelligent access control module is used to implement fine-grained permission management based on roles and attributes; The security audit and monitoring module is used to record operation logs and detect abnormal behavior. The logs are signed by a security chip to prevent tampering. The aforementioned computing power collaboration utilizes the Lobster Security Core to call upon large models for inference and training, thereby improving data processing efficiency through computing power collaboration.

2. The system according to claim 1, characterized in that: The mandatory authentication gateway supports multi-factor authentication, including at least two combinations of password, hardware key (FIDO2), biometrics, and dynamic token, and the authentication process has no software bypass path.

3. The system according to claim 1, characterized in that: The lobster security core module adopts a hierarchical key management mechanism, including three layers: root key, master key, and data key. The root key is stored in the hardware trust root, while the master key and data key are managed by the lobster security chip, which supports automatic key rotation. The lobster security chip communicates with the main processor via a security bus, which uses an encrypted channel to prevent man-in-the-middle attacks. The system supports distributed deployment, with multiple NAS nodes sharing the same Lobster Security Core, enabling unified management of security policies and collaborative key protection across nodes.

4. The system according to claim 1, characterized in that: The system supports dual-stack of Chinese national cryptographic algorithms and international algorithms. The Chinese national cryptographic algorithms include SM2, SM3, and SM4, while the international algorithms include RSA, AES, and SHA-256.

5. The system according to claim 1, characterized in that: The intelligent access control module supports multi-dimensional access policies based on time, location, device type, and network environment, and can dynamically adjust permissions based on user behavior analysis, triggering secondary authentication for sensitive operations.

6. The system according to claim 1, characterized in that: The security audit and monitoring module integrates machine learning algorithms to identify abnormal access patterns, ransomware behavior, and risks of data leakage. The security audit and monitoring module supports remote log synchronization. The log synchronization channel uses two-way authentication and encrypted transmission to prevent log tampering and leakage.

7. The system according to claim 1, characterized in that: The system adopts a zero-trust architecture, where all access requests are rejected by default, user identity is periodically re-verified during the session, and the session is terminated immediately upon detection of abnormal behavior.

8. The system according to claim 1, characterized in that: It also includes a data snapshot and recovery module for creating immutable snapshots. The snapshot metadata is signed by the Lobster Security Chip and supports one-click recovery to any point in time. It also includes an emergency response module that automatically executes preset emergency response strategies when a security threat is detected, including isolating infected devices, freezing suspicious accounts, and triggering data protection snapshots.

9. The system according to claim 1, characterized in that: The hardware root of trust module verifies the integrity of the bootloader, kernel, and security module sequentially during system startup; if the verification fails, it prevents the system from starting. The hardware root of trust module supports remote authentication and can verify the system integrity status to third parties, making it suitable for cloud environments and trusted computing scenarios.

10. A secure storage access authentication method based on the system of any one of claims 1-9, characterized in that, Includes the following steps: Step 1: Receive access requests initiated by users or clients; Step 2: Force the authentication gateway to intercept the request and check the authentication status; Step 3: If unauthenticated or session expired, perform multi-factor authentication; Step 4: Verify the device fingerprint and compare it with the bound device; Step 5: The Lobster Security Core generates a session token, which contains the user ID, permission list, validity period, and device fingerprint, and is signed by the security chip's private key. Step 6: Verify access policies based on user permissions and target resources; Step 7: Generate temporary access credentials and establish an encrypted data transmission channel; Step 8: Record the complete audit log, which is signed by the security chip; Step 9: Periodically re-verify user identity and detect abnormal behavior during the session; In step S3, multi-factor authentication includes at least two of the following: first-factor password verification, second-factor device push verification, and third-factor biometric or hardware key verification. In step S9, the session renewal verification interval is 10-60 minutes. When abnormal behavior is detected, the session is terminated immediately and an alarm is triggered. In step S5, the validity period of the session token is 30 minutes to 24 hours, which can be dynamically adjusted according to the security policy; It also includes ransomware protection steps, which automatically block suspicious processes, trigger data snapshot protection, and support one-click restoration to the pre-infection state when abnormal file encryption behavior is detected.