Hard disk encryption method, hard disk lock system, hard disk encryption device and storage medium
By detecting the hard disk encryption status of enterprise devices and encrypting the encrypted devices according to the generated hard disk password configuration policy, the data security risks caused by hard disk encryption methods in the prior art are solved, and the security of the device's hard disk is significantly improved.
Patent Information
- Application Number
- CN202010578307.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-19
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-06-19
AI Technical Summary
Existing hard disk encryption methods can easily lead to data security risks for enterprise equipment hard disks, and poor security of equipment hard disks.
By detecting the hard disk encryption status of the enterprise device, obtaining the hard disk password configuration policy, and encrypting the encrypted device according to the policy's password requirements strength, validity period and alarm level.
It enhances the efficiency of controlling the passwords of enterprise equipment hard disks, avoids the security risks of data due to changes in encryption status or the password strength is too low, and improves the security of equipment hard disks.
Smart Images

Figure CN111723410B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial technology (Fintech), and in particular to a hard disk encryption method, a hard disk lock system, a hard disk encryption device and a computer-readable storage medium. Background Art
[0002] With the development of computer technology, more and more technologies are being applied in the financial field. The traditional financial industry is gradually transforming into financial technology (Fintech). However, due to the security and real-time requirements of the financial industry, higher requirements are also placed on technology.
[0003] At present, since most financial enterprises have not purchased commercial hard disk encryption products, the hard disk encryption method commonly used by various financial enterprises is mainly based on the free encryption solution integrated with the TPM (Trust Platform Module) security chip (referring to the security chip that complies with the TPM (Trusted Platform Module) standard) of the equipment manufacturer, and the hard disk password of the enterprise equipment is encrypted, that is, through the user's own operation or through the IT desktop (a series of equipment used by enterprise employees for information processing, communication and computing at work) support personnel to assist the user to enter the BIOS (Basic Input Output System) settings, and then configure the encryption password of the hard disk based on the user's own configuration. After the configuration operation is completed, the IT desktop support personnel will add a "hard disk encrypted" label to the asset information of the device where the user's encrypted hard disk is located in the EAM (Enterprise Asset Management) system for security compliance inspection.
[0004] However, due to the existing encryption method for hard disks, the hard disk encryption password based on user self-configuration is not strong enough and can be easily cracked maliciously. Moreover, after setting the BIOS hard disk password, the user can still cancel the encryption by himself. All of the above will put the data in the enterprise device hard disk at security risk, and the security of the enterprise device hard disk is poor. Summary of the invention
[0005] The main purpose of the present invention is to provide a hard disk encryption method, a hard disk lock system, a hard disk encryption device and a computer-readable storage medium, aiming to solve the technical problem that the existing hard disk encryption method easily puts the data in the enterprise device hard disk at security risk and the device hard disk has poor security.
[0006] To achieve the above object, the present invention provides a hard disk encryption method, which is applied to a client in a hard disk lock system, and includes:
[0007] Detecting the hard disk encryption status of each enterprise device, and determining the device to be encrypted in each enterprise device according to the hard disk encryption status;
[0008] Obtaining a hard disk password configuration policy of the device to be encrypted, wherein the hard disk password configuration policy is generated by a server connected to the client according to device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period, and password warning level;
[0009] The device to be encrypted is encrypted according to the password requirement strength, password validity period and password warning level of the hard disk password configuration policy.
[0010] Optionally, the step of encrypting the device to be encrypted according to the password requirement strength, password validity period, and password warning level of the hard disk password configuration policy includes:
[0011] Outputting preset encryption prompt information and receiving the password to be configured for the device to be encrypted;
[0012] Detecting the complexity of the password to be configured, and determining whether the password to be configured meets the password strength requirement according to the complexity;
[0013] If so, the password to be configured is associated with the password validity period and the password warning level and stored in the security chip of the device to be encrypted.
[0014] Optionally, before the step of obtaining the hard disk password configuration policy of the device to be encrypted, the method further includes:
[0015] Extracting a first device ID and a machine code of the client, and performing access authentication according to the first device ID and the machine code;
[0016] The step of obtaining the hard disk password configuration policy of the device to be encrypted includes:
[0017] After access authentication is passed according to the first device ID and the machine code, reading the second device ID of the device to be encrypted;
[0018] Obtain the hard disk password configuration policy of the device to be encrypted from a preset policy database according to the second device ID.
[0019] Optionally, the hard disk encryption status includes: unencrypted and password expired, and the step of determining the device to be encrypted in each of the enterprise devices according to the hard disk encryption status includes:
[0020] If it is detected that the hard disk encryption state of each first device in the enterprise device is unencrypted, then each first device is determined as the device to be encrypted; and / or,
[0021] If it is detected that the hard disk encryption status of each second device in the enterprise device is that the password has expired, each second device is determined as the device to be encrypted.
[0022] Optionally, the step of detecting the hard disk encryption status of the enterprise device includes:
[0023] Detecting the hard disk encryption status of the enterprise device according to a preset time period;
[0024] After the step of detecting the hard disk encryption status of the enterprise device, the method further includes:
[0025] The encryption status of the hard disk is formatted and the encryption status of the hard disk after formatting is reported to the server.
[0026] In addition, to achieve the above purpose, the present invention also provides a hard disk encryption method, which is applied to a server in a hard disk lock system, and the server is connected to a client in the hard disk lock system. The hard disk encryption method includes:
[0027] Obtain device information of devices to be encrypted in each enterprise device;
[0028] Generate a hard disk password configuration policy for the device to be encrypted according to the device information and store the hard disk password configuration policy in a preset policy database, wherein the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0029] The hard disk encryption status of each enterprise device is received, and the hard disk encryption status of the device to be encrypted is synchronously updated.
[0030] Optionally, the device information includes: device type, subordinate position and subordinate department, and the step of obtaining the device information of the device to be encrypted in each enterprise device includes:
[0031] Obtaining the equipment type, subordinate position and subordinate department of each of the enterprise equipment from the asset database of the enterprise resource management system;
[0032] The step of synchronously updating the encryption status of the hard disk of the device to be encrypted comprises:
[0033] In the asset database, field information corresponding to the hard disk encryption status is added for the device to be encrypted, so as to synchronously update the hard disk encryption status of the device to be encrypted.
[0034] Optionally, after the step of receiving the hard disk encryption status of each enterprise device and synchronously updating the hard disk encryption status of the device to be encrypted, the method further includes:
[0035] A viewing instruction for the hard disk encryption status is received, and the hard disk encryption status of each of the enterprise devices is extracted and output according to the viewing instruction.
[0036] In addition, to achieve the above-mentioned purpose, the present invention further provides a hard disk lock system, the hard disk lock system comprising: a client and a server, the client is connected to the server, wherein the client comprises:
[0037] A device determination module, used to detect the hard disk encryption status of each enterprise device, and determine the device to be encrypted in each enterprise device according to the hard disk encryption status;
[0038] A policy acquisition module, used to acquire the hard disk password configuration policy of the device to be encrypted, wherein the hard disk password configuration policy is generated by the server according to the device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0039] A password configuration module, used to encrypt the device to be encrypted according to the password requirement strength, password validity period and password alarm level of the hard disk password configuration policy;
[0040] The server includes:
[0041] An information acquisition module is used to obtain device information of devices to be encrypted in each enterprise device;
[0042] A policy generation module, used to generate a hard disk password configuration policy of the device to be encrypted according to the device information and store the hard disk password configuration policy in a preset policy database, wherein the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0043] The synchronous update module is used to receive the hard disk encryption status of each enterprise device and synchronously update the hard disk encryption status of the device to be encrypted.
[0044] In addition, to achieve the above-mentioned purpose, the present invention also provides a hard disk encryption device, which includes: a memory, a processor, and a hard disk encryption program stored in the memory and executable on the processor, and the hard disk encryption program implements the steps of the hard disk encryption method described above when executed by the processor.
[0045] In addition, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium, on which a hard disk encryption program is stored, and when the hard disk encryption program is executed by a processor, the steps of the hard disk encryption method described above are implemented.
[0046] The present invention provides a hard disk encryption method, a hard disk lock system, a hard disk encryption device and a computer-readable storage medium. The method detects the hard disk encryption status of each enterprise device and determines the device to be encrypted in each enterprise device according to the hard disk encryption status; obtains the hard disk password configuration policy of the device to be encrypted, wherein the hard disk password configuration policy is generated by a server connected to the client according to the device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period and password alarm level; and encrypts the device to be encrypted according to the password requirement strength, password validity period and password alarm level of the hard disk password configuration policy.
[0047] The present invention is based on monitoring the hard disk encryption status of enterprise equipment. Once a device to be encrypted that needs to be encrypted is determined based on the hard disk encryption status, a hard disk password configuration policy corresponding to the device to be encrypted, which is generated based on the device information of the enterprise equipment and includes password requirement strength, password validity period and password alarm level, is obtained. Then, a hard disk password of the corresponding password requirement strength is configured for the device to be encrypted based on the hard disk password configuration policy, thereby enhancing the management and control efficiency of the hard disk password of the enterprise equipment, avoiding the problem that the data in the hard disk of the enterprise equipment is at security risk due to changes in the hard disk encryption status or too low password strength configured on the hard disk, and improving the security of the device hard disk. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 A schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present invention;
[0049] Figure 2 This is a flow chart of a first embodiment of a hard disk encryption method according to the present invention;
[0050] Figure 3 It is a schematic diagram of the functional modules of the first embodiment of the hard disk lock system of the present invention.
[0051] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0052] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0053] Reference Figure 1 , Figure 1The figure is a schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present invention.
[0054] The hard disk encryption device in the embodiment of the present invention may be a smart phone, or may be a terminal device such as a PC (Personal Computer), a tablet computer, or a portable computer.
[0055] like Figure 1 As shown, the hard disk encryption device may include: a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed RAM memory, or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0056] Those skilled in the art will understand that Figure 1 The hard disk encryption device structure shown in the figure does not constitute a limitation on the hard disk encryption device, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.
[0057] like Figure 1 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a hard disk encryption program.
[0058] exist Figure 1 In the terminal shown, the network interface 1004 is mainly used to connect to the backend server and communicate data with the backend server; the user interface 1003 is mainly used to connect to the client and communicate data with the client; and the processor 1001 can be used to call the hard disk encryption program stored in the memory 1005 and perform the following operations:
[0059] Detecting the hard disk encryption status of each enterprise device, and determining the device to be encrypted in each enterprise device according to the hard disk encryption status;
[0060] Obtaining a hard disk password configuration policy of the device to be encrypted, wherein the hard disk password configuration policy is generated by a server connected to the client according to device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period, and password warning level;
[0061] The device to be encrypted is encrypted according to the password requirement strength, password validity period and password warning level of the hard disk password configuration policy.
[0062] Furthermore, the processor 1001 may call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0063] Outputting preset encryption prompt information and receiving the password to be configured for the device to be encrypted;
[0064] Detecting the complexity of the password to be configured, and determining whether the password to be configured meets the password strength requirement according to the complexity;
[0065] If so, the password to be configured is associated with the password validity period and the password warning level and stored in the security chip of the device to be encrypted.
[0066] Furthermore, the processor 1001 may call the hard disk encryption program stored in the memory 1005, and before executing to obtain the hard disk password configuration policy of the device to be encrypted, further perform the following operations:
[0067] Extracting a first device ID and a machine code of the client, and performing access authentication according to the first device ID and the machine code;
[0068] The processor 1001 may call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0069] After access authentication is passed according to the first device ID and the machine code, reading the second device ID of the device to be encrypted;
[0070] Obtain the hard disk password configuration policy of the device to be encrypted from a preset policy database according to the second device ID.
[0071] Furthermore, the hard disk encryption status includes: unencrypted and password expired, and the processor 1001 can call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0072] If it is detected that the hard disk encryption state of each first device in the enterprise device is unencrypted, then each first device is determined as the device to be encrypted; and / or,
[0073] If it is detected that the hard disk encryption status of each second device in the enterprise device is that the password has expired, each second device is determined as the device to be encrypted.
[0074] Furthermore, the processor 1001 may call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0075] Detecting the hard disk encryption status of the enterprise device according to a preset time period;
[0076] The processor 1001 may call the hard disk encryption program stored in the memory 1005, and after executing the hard disk encryption status detection of the enterprise device, further perform the following operations:
[0077] The encryption status of the hard disk is formatted and the encryption status of the hard disk after formatting is reported to the server.
[0078] Furthermore, the processor 1001 may call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0079] Obtain device information of devices to be encrypted in each enterprise device;
[0080] Generate a hard disk password configuration policy for the device to be encrypted according to the device information and store the hard disk password configuration policy in a preset policy database, wherein the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0081] The hard disk encryption status of each enterprise device is received, and the hard disk encryption status of the device to be encrypted is synchronously updated.
[0082] Furthermore, the device information includes: device type, subordinate position and subordinate department. The processor 1001 can call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0083] Obtaining the equipment type, subordinate position and subordinate department of each of the enterprise equipment from the asset database of the enterprise resource management system;
[0084] The processor 1001 may call the hard disk encryption program stored in the memory 1005, and further perform the following operations:
[0085] In the asset database, field information corresponding to the hard disk encryption status is added for the device to be encrypted, so as to synchronously update the hard disk encryption status of the device to be encrypted.
[0086] Further, the processor 1001 may call the hard disk encryption program stored in the memory 1005, and after receiving the hard disk encryption status of each enterprise device and synchronously updating the hard disk encryption status of the device to be encrypted, further perform the following operations:
[0087] A viewing instruction for the hard disk encryption status is received, and the hard disk encryption status of the enterprise device is extracted and output according to the viewing instruction.
[0088] Based on the above hardware structure, various embodiments of the hard disk encryption method of the present invention are proposed.
[0089] The present invention provides a hard disk encryption method, which is applied to the client in the hard disk lock system. Figure 2 , Figure 2 FIG. 1 is a flow chart of a first embodiment of a hard disk encryption method according to the present invention.
[0090] In this embodiment, the hard disk encryption method includes:
[0091] Step S10, detecting the hard disk encryption status of each enterprise device, and determining the device to be encrypted in each enterprise device according to the hard disk encryption status;
[0092] The client of the hard disk lock system cyclically detects the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected according to the pre-configured detection cycle. Then, based on the hard disk encryption status, the client of the hard disk lock system regularly confirms the enterprise devices with the detected hard disk encryption status that need to be encrypted.
[0093] Furthermore, step S10 may include:
[0094] Step S101, detecting the hard disk encryption status of the enterprise device according to a preset time period;
[0095] It should be noted that, in the present embodiment, the preset time period may specifically be a time independently defined by the staff of the hard disk lock system based on design requirements. For example, the staff sets 0:00 a.m. of each day as the time period. Then, during this time period, the client of the hard disk lock system will check the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected at 0:00 a.m. of each day.
[0096] Furthermore, in one embodiment, after the above step S10, the hard disk encryption method of the present invention may further include:
[0097] Step A: formatting the encryption status of the hard disk and reporting the encryption status of the hard disk after formatting.
[0098] The client in the hard disk lock system will periodically detect the hard disk encryption status of the obtained enterprise equipment and format the field, and then upload the field-formatted hard disk encryption status to the server connected to the client in the current hard disk lock system, so that the server can synchronously record or update the hard disk encryption status of each enterprise equipment.
[0099] Specifically, at 0:00 a.m. every day, the client detects the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected. After obtaining the hard disk encryption status of each enterprise device, the client formats the hard disk encryption status of the enterprise device into the following fields:
[0100] [{
[0101] deviceId:"L3"
[0102] Manufacturer:"LENOVO_X250"
[0103] LastCheckDate:"2020-03-18 09:22:30"
[0104] IsEncryption:"1"
[0105] …
[0106] },
[0107] {
[0108] deviceId:"L4"
[0109] Manufacturer:"LENOVO_X1"
[0110] LastCheckDate:"2020-03-18 10:33:17"
[0111] IsEncryption:"0"
[0112] …
[0113] },
[0114] {
[0115] deviceId:"L5"
[0116] Manufacturer: "DELL_4930"
[0117] LastCheckDate:"2020-03-18 17:25:59"
[0118] IsEncryption:"1"
[0119] …
[0120] }]
[0121] Then, when there is a communication response from the connected server, the client immediately reports the field obtained by formatting the encryption status of the hard disk of each enterprise device to the server.
[0122] Furthermore, in another embodiment, if the server connected to the client in the current hard disk lock system is temporarily unable to communicate, the client will automatically compress the fields obtained by formatting the hard disk encryption state, and the format after compressing each field is:
[0123] [[deviceId,Manufacturer,LastCheckDate,IsEncryption],[L3,LENOVO_X250,2020-03-18 09:22:30,1,…],[L4,LENOVO_X1,2020-03-1810:33:17,0,…],[L5,DELL_4930,2020-03-18 17:25:59,1,…]]
[0124] Then, after the client resumes communication with the server, it reports the compressed field to the server. The client compresses and formats the hard disk encryption status to obtain the field and then reports it, which effectively reduces the server load and improves the efficiency of reporting the hard disk encryption status of each enterprise device.
[0125] Step S20, obtaining the hard disk password configuration policy of the device to be encrypted;
[0126] It should be noted that, in this embodiment, the hard disk password configuration policy of the device to be encrypted is that the server that establishes a connection with the client in the hard disk lock system collects device information of the enterprise device, and then generates and stores it in a database for storing the hard disk password configuration policy of each device to be encrypted based on the device information.
[0127] The client of the hard disk lock system regularly confirms the enterprise devices whose hard disk encryption status is detected and the devices to be encrypted that need to be encrypted, and matches and obtains the hard disk password configuration policy of each device to be encrypted from the database of the hard disk password configuration policy of each device to be encrypted stored on the connected server in a random polling manner according to the device ID (Identity document, ID card identification number, unique code or exclusive number) of each device to be encrypted.
[0128] Step S30, encrypting the device to be encrypted according to the password requirement strength, password validity period and password warning level of the hard disk password configuration policy.
[0129] The client of the hard disk lock system matches and obtains the hard disk password configuration policy of each device to be encrypted from the database of the hard disk password configuration policy of each device to be encrypted stored in the connected server in a polling manner at random time, caches the hard disk password configuration policy, and then runs the hard disk password configuration policy at a specified time, so as to configure a hard disk password with the corresponding password requirement strength for the device to be encrypted according to the password requirement strength, password validity period and password alarm level in the hard disk password configuration policy.
[0130] The embodiment of the present invention provides a hard disk encryption method, which detects the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected cyclically according to a pre-configured detection cycle through a client of a hard disk lock system, and then the client of the hard disk lock system regularly confirms the enterprise devices with hard disk encryption status that need to be encrypted among the detected enterprise devices, and matches and obtains the hard disk password configuration policy of each device to be encrypted from a database storing the hard disk password configuration policy of each device to be encrypted from a connected server according to the device ID of each device to be encrypted obtained through the confirmation in a polling manner at a random time; after the client obtains the hard disk password configuration policy of each device to be encrypted, the hard disk password configuration policy is cached, and then the hard disk password configuration policy is run at a specified time, so that according to the password requirement strength, password validity period and password alarm level in the hard disk password configuration policy, a hard disk password with a corresponding password requirement strength is configured for the device to be encrypted.
[0131] The present invention is based on monitoring the hard disk encryption status of enterprise equipment. Once a device to be encrypted that needs to be encrypted is determined based on the hard disk encryption status, a hard disk password configuration policy corresponding to the device to be encrypted, which is generated based on the device information of the enterprise equipment and includes password requirement strength, password validity period and password alarm level, is obtained. Then, a hard disk password of the corresponding password requirement strength is configured for the device to be encrypted based on the hard disk password configuration policy, thereby enhancing the management and control efficiency of the hard disk password of the enterprise equipment, avoiding the problem that the data in the hard disk of the enterprise equipment is at security risk due to changes in the hard disk encryption status or too low password strength configured on the hard disk, and improving the security of the device hard disk.
[0132] Furthermore, based on the above first embodiment, a second embodiment of the hard disk encryption method of the present invention is proposed.
[0133] In this embodiment, the client in the hard disk lock system detects the hard disk encryption status of the enterprise device cyclically according to the pre-configured detection cycle, including but not limited to: unencrypted and password expired. After the client in the hard disk lock system detects the hard disk encryption status of each enterprise device cyclically according to the pre-configured detection cycle, it determines whether each enterprise device is a device to be encrypted that needs to be encrypted based on the hard disk encryption status.
[0134] In the above step S10, the step of "determining the device to be encrypted in each of the enterprise devices according to the hard disk encryption status" may include:
[0135] Step S102, if it is detected that the hard disk encryption state of each first device in the enterprise device is unencrypted, then each first device is determined as the device to be encrypted;
[0136] The client in the hard disk lock system detects that there is a first device in the enterprise device whose hard disk encryption status is unencrypted, and the client then determines the first device as a device to be encrypted that needs to be encrypted.
[0137] Specifically, for example, if the client cyclically detects the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected according to a pre-configured detection cycle, when it detects that the currently detected enterprise device is not configured with a BIOS (Basic Input Output System, an industry-standard firmware interface) hard disk password, the current enterprise device is immediately marked as the first device. Then, after completing the detection of the hard disk encryption status of all enterprise devices, the client determines each first device in all the enterprise devices as a device to be encrypted that needs to be encrypted.
[0138] Step S2012: If it is detected that the hard disk encryption status of each second device in the enterprise device is that the password has expired, each second device is determined as the device to be encrypted.
[0139] The client in the hard disk lock system detects that there is a second device in the enterprise device whose hard disk encryption status is that the password has expired, and the client then determines the second device as a device to be encrypted that needs to be encrypted.
[0140] It should be noted that, in the present embodiment, the password has expired specifically means that, from the time when the enterprise device completes the encryption configuration, if the system time exceeds the password validity period specified by the hard disk password configuration policy corresponding to the enterprise device, the hard disk encryption status of the enterprise device is determined to be the password has expired.
[0141] Specifically, for example, if the client cyclically detects the hard disk encryption status of all enterprise devices registered in the enterprise asset management system to which the current hard disk lock system is connected according to a pre-configured detection cycle, when it detects that the currently detected enterprise device has been configured with a BIOS hard disk password, it continues to detect whether the current BIOS hard disk password has expired. If it has expired, the current enterprise device is immediately marked as the second device. Then, after completing the detection of the hard disk encryption status of all enterprise devices, the client determines each second device in all enterprise devices as a device to be encrypted that needs to be reconfigured for encryption.
[0142] Furthermore, in one embodiment, if the client detects that the currently detected enterprise device has been configured with a BIOS hard disk password, and also detects that the current BIOS hard disk password has not expired, the detection result is directly cached as the hard disk encryption status of the current enterprise device to be reported to the connected server.
[0143] In this embodiment, the hard disk encryption status of the enterprise device is periodically detected by the client in the hard disk lock system, and whether the detected enterprise device is an encryption device that needs to be encrypted and configured according to whether the hard disk encryption status is unencrypted or the password has expired is determined. This realizes real-time monitoring and control of the encryption status of each hard disk of the enterprise device, increases the efficiency of control over the hard disk password of the enterprise device, avoids the problem of data in the hard disk of the enterprise device being at security risk due to re-encryption configuration due to changes in the hard disk encryption status, and improves the security of the device hard disk.
[0144] Furthermore, based on the above first embodiment, a third embodiment of the hard disk encryption method of the present invention is proposed.
[0145] In this embodiment, before the above step S20, obtaining the hard disk password configuration policy of the device to be encrypted, the hard disk encryption method of the present invention may further include:
[0146] Step S40: extract the first device ID and the machine code of the client, and perform access authentication according to the first device ID and the machine code.
[0147] The client in the hard disk lock system communicates with the connected server in a random time polling manner. Before each communication between the client and the server, the first device ID and machine code of the current client are extracted, and the first device ID and machine code are sent to the server in real time for access authentication by the server.
[0148] Furthermore, the above step S20, obtaining the hard disk password configuration policy of the device to be encrypted, may include:
[0149] Step S201, after the access authentication is passed according to the first device ID and the machine code, the second device ID of the device to be encrypted is read;
[0150] Step S202: Obtain the hard disk password configuration policy of the device to be encrypted from a preset policy database according to the second device ID.
[0151] The client in the hard disk lock system extracts the first device ID and machine code of the current client, and sends the first device ID and machine code to the server in real time for the server to perform access authentication. After the server authenticates and passes, the client extracts the second device ID of each device to be encrypted that needs to be encrypted, and then matches and obtains the hard disk password configuration policy with the same ID identifier as each second device ID in the preset policy database of the connected server for storing the hard disk password configuration policy of each device to be encrypted.
[0152] It should be noted that, in this embodiment, the preset policy database is a database used by the server in the hard disk lock system to store the hard disk password configuration policy corresponding to each enterprise device. The server in the hard disk lock system performs risk scoring on each enterprise device according to the device information of each enterprise device registered in the connected enterprise asset management system, and then formulates a hard disk password configuration policy of a corresponding level for each enterprise device based on the risk score, and finally identifies each hard disk password configuration policy with the ID of each enterprise device and stores it in the database.
[0153] It should be noted that, in the present embodiment, the hard disk password configuration strategy includes but is not limited to: password requirement strength, password validity period and password alarm level, wherein the password requirement strength is used to control the complexity of the password entered by the user when the user configures encryption of the hard disk of the encrypted device, so as to avoid the phenomenon that the set password is too simple and easy to be maliciously cracked; the password validity period is used to control the maximum time that the hard disk is protected by the same password, and also to avoid the phenomenon that the set password is easy to be maliciously cracked due to the long usage period; the password alarm level is used to remind the user to re-set the alarm level of the password of the enterprise device hard disk after detecting that the password usage time of the enterprise device hard disk exceeds the above password validity period.
[0154] In addition, in other embodiments, the hard disk password configuration strategy may also include a hard disk encryption status synchronization time, which is used for the client in the hard disk lock system to periodically detect the hard disk encryption status of the corresponding enterprise device according to the synchronization time and report it. Specifically, in the hard disk password configuration strategy of the current enterprise device, the hard disk encryption status synchronization time is set to 10 minutes, then the client in the hard disk lock system detects the hard disk encryption status of the current enterprise device every 10 minutes and caches it, and then reports the hard disk encryption status to the connected server.
[0155] Furthermore, the above step S30, encrypting the device to be encrypted according to the password requirement strength, password validity period and password warning level of the hard disk password configuration policy, may include:
[0156] Step S301, outputting preset encryption prompt information and receiving the password to be configured of the device to be encrypted;
[0157] It should be noted that, in the present embodiment, the preset encryption prompt information may specifically be information independently defined by the staff of the current hard disk lock system based on design requirements to prompt the user of the enterprise equipment to encrypt the hard disk of the current enterprise equipment. It should be understood that the hard disk encryption method of the present invention does not specifically limit the information content of the preset encryption prompt information.
[0158] After obtaining the hard disk password configuration policy of the device to be encrypted, the client in the hard disk lock system outputs preset encryption prompt information to the user of the device to be encrypted, prompting the user to perform encryption configuration operations on the hard disk of the current device to be encrypted. The user then performs encryption configuration of the device to be encrypted based on the prompt information.
[0159] Specifically, for example, after the client in the hard disk lock system passes the access authentication of the connected server and matches and obtains the hard disk password configuration policy of the device to be encrypted from the server, the client's local BIOS hard disk encryption configuration module is enabled, and preset encryption prompt information is output to the user through a pop-up window and / or email notification to remind the user of the device to be encrypted to encrypt the BIOS hard disk password of the device, and then receives the password setting entered by the user based on the preset encryption prompt information, and calls the WMI (Windows Management Instrumentation, whose main function is to access some information and services of the local host) function of the hard disk lock system to read the hard disk password configuration in the BIOS to obtain the password to be configured for the current device to be encrypted.
[0160] Step S302, detecting the complexity of the password to be configured, and determining whether the password to be configured meets the password strength requirement according to the complexity;
[0161] It should be noted that, in this embodiment, the password requirement strength includes but is not limited to "strong", "medium", "weak" and "none".
[0162] After receiving the password to be configured for the device to be encrypted based on the preset encryption prompt information fed back by the user, the client in the hard disk lock system detects the complexity of the password to be configured, and then determines whether the password to be configured currently fed back by the user meets the password requirement strength specified in the hard disk password configuration policy of the current device to be configured based on the complexity.
[0163] Specifically, for example, in the hard disk password configuration policy of the client's current device to be encrypted in the hard disk lock system, the password requirement strength is "strong", then the corresponding requirement is that the password set by the user for the hard disk of the current device to be encrypted should include: uppercase letters, lowercase letters and numbers. After the client reads the hard disk password configuration in the BIOS through the WMI function to obtain the password to be configured input by the user for the hard disk of the current device to be encrypted, the client determines whether the password to be configured meets the password requirement strength in the hard disk password configuration policy of the current device to be encrypted based on detecting whether the password to be configured includes uppercase letters, lowercase letters and numbers.
[0164] Step S303: associate the password to be configured with the password validity period and the password warning level and store them in the security chip of the device to be encrypted.
[0165] After the client in the hard disk lock system confirms that the password to be configured reported by the user meets the password strength requirement specified in the hard disk password configuration policy of the current device to be configured, the client associates the password validity period and password alarm level in the hard disk password configuration policy of the encryption device with the password to be configured and stores them in the security chip of the current device to be encrypted, thereby completing the encryption configuration of the device to be encrypted.
[0166] Specifically, for example, after the client determines that the password to be configured meets the password strength requirement in the hard disk password configuration policy of the current device to be encrypted based on detecting whether the password to be configured includes uppercase letters, lowercase letters and numbers, the client stores the password to be configured in the TPM module of the device to be encrypted, and associates the password validity period and password alarm level in the hard disk password configuration policy of the device to be encrypted with the password to be configured, so as to synchronously store them on the device to be encrypted, thereby completing the encryption configuration of the hard disk of the device to be encrypted.
[0167] Furthermore, in another embodiment, if the client confirms that the password to be configured fed back by the user does not meet the password strength requirement specified in the hard disk password configuration policy of the current device to be configured, the client re-outputs a prompt message to the user of the current device to be encrypted for the user to re-enter the password to be configured until the password to be configured fed back by the user meets the specified password strength requirement.
[0168] In this embodiment, the client in the hard disk lock system communicates with the connected server in a random time polling manner. Before each communication between the client and the server, the first device ID and machine code of the current client are extracted, and the first device ID and machine code are sent to the server in real time for access authentication by the server, thereby ensuring the security of the hard disk lock system as a whole in performing encryption configuration operations on the hard disk of the enterprise device. In addition, when configuring the hard disk password of the device to be encrypted in interaction with the customer, it is detected whether the password to be configured input by the user based on the output encryption prompt information meets the password strength requirement in the hard disk password configuration policy of the device to be encrypted, thereby avoiding the problem that the set password is too simple and easy to be maliciously deciphered, resulting in the data in the hard disk being at security risk, thereby improving the security of the hard disk of the enterprise device.
[0169] Furthermore, the present invention also provides a hard disk encryption method, which is applied to a server in a hard disk lock system. The hard disk encryption method of the present invention comprises:
[0170] Step S50, obtaining device information of the device to be encrypted in each enterprise device;
[0171] The server in the hard disk lock system obtains the device information of all enterprise devices registered in the enterprise asset management system from the connected enterprise asset management system.
[0172] Specifically, for example, after detecting that an enterprise device registered in a connected enterprise asset management system is updated, the server in the hard disk lock system reads various equipment information of the updated enterprise device from the enterprise asset database of the enterprise asset management system.
[0173] It should be noted that, in this embodiment, the device information of the enterprise device obtained by the server includes but is not limited to: device type, subordinate position and subordinate department. Further, step S50 may include:
[0174] Step S501, obtaining the equipment type, subordinate position and subordinate department of each enterprise equipment from the asset database of the enterprise resource management system.
[0175] Specifically, for example, when the server in the hard disk lock system detects that a new enterprise device has been registered in the enterprise asset management system to which the staff member is connected, the device information data of the enterprise device in the asset database of the enterprise resource management system is updated. The server then reads the device type, affiliated position, affiliated department and other information of the newly registered enterprise device by the staff member from the asset database.
[0176] Step S60, generating a hard disk password configuration policy for the device to be encrypted according to the device information and storing the hard disk password configuration policy in a preset policy database;
[0177] It should be noted that, in this embodiment, the server in the hard disk lock system generates a hard disk password configuration policy based on the device information of each enterprise device registered in the connected enterprise asset management system, including but not limited to: password requirement strength, password validity period and password alarm level.
[0178] The server in the hard disk lock system performs risk scoring on each enterprise device according to the device information of each enterprise device registered in the connected enterprise asset management system, and then matches each enterprise device with a hard disk password configuration policy with a corresponding level of password requirement strength, password validity period, and password alarm level based on the risk score. Finally, each hard disk password configuration policy is identified with the device ID of each enterprise device and stored in the preset policy database, so that the connected client can obtain the hard disk password configuration policy of each enterprise device from the preset policy database for encryption configuration in a random polling manner.
[0179] Specifically, for example, the server in the hard disk lock system combines the device type, user position information and department information to preset risk scores, and then automatically matches and formulates corresponding password policy levels for different risk scores:
[0180]
[0181]
[0182] Step S70, receiving the hard disk encryption status of each enterprise device, and synchronously updating the hard disk encryption status of the device to be encrypted.
[0183] After passing the access authentication of the connected client, the server in the hard disk lock system receives the hard disk encryption status of the enterprise device reported by the client, and then synchronizes the hard disk encryption status to the connected enterprise asset management system to record or update the hard disk encryption status of the enterprise device.
[0184] Furthermore, in step S70, “synchronously updating the encryption status of the hard disk of the device to be encrypted” may include:
[0185] Step S701: In the asset database, field information corresponding to the hard disk encryption status is added for the device to be encrypted, so as to synchronously update the hard disk encryption status of the device to be encrypted.
[0186] Specifically, for example, the client in the hard disk lock system will periodically detect and obtain the hard disk encryption status of each enterprise device, format the field and report it. After the server receives the field-formatted hard disk encryption status, the server will add field information identifying the hard disk encryption status to the information data corresponding to the device to be encrypted in the asset database of the enterprise asset management system to which the server is connected, thereby completing the synchronous recording or updating of the hard disk encryption status of the enterprise device detected by the client in the enterprise asset management system.
[0187] Furthermore, in one embodiment, after the above step S70, the hard disk encryption method of the present invention may further include:
[0188] Step S80, receiving a viewing instruction for the hard disk encryption status, extracting and outputting the hard disk encryption status of each of the enterprise devices according to the viewing instruction.
[0189] After the server in the hard disk lock system synchronizes the received hard disk encryption status to the connected enterprise asset management system to record or update the hard disk encryption status of the enterprise equipment, if it receives a viewing instruction for the hard disk encryption status based on staff triggering or automatic triggering, the server reads the status parameter information carried by the viewing instruction and outputs the hard disk encryption status of each enterprise equipment recorded in the asset database of the enterprise asset management system.
[0190] Specifically, for example, when the server in the hard disk lock system detects that the enterprise security personnel triggers a viewing instruction to view the hard disk encryption status of the enterprise device through the server or the enterprise asset management system to which the server is connected, the server reads the enterprise device, time and other parameters specified in the viewing instruction, and then reads the corresponding hard disk encryption status from the asset database based on the parameters, and then outputs it through the front-end visualization interface.
[0191] In this embodiment, by automatically matching the enterprise equipment with a hard disk password configuration policy of a corresponding level, so that the enterprise equipment's hard disk encryption configuration can be performed based on the policy later, the intelligence and flexibility of encrypting the enterprise equipment's hard disk are improved; in addition, by synchronously recording or updating the hard disk encryption status of the enterprise equipment detected periodically, it is convenient to monitor and control the hard disk encryption status of the enterprise equipment, thereby enhancing the efficiency of controlling the enterprise equipment's hard disk password and ensuring the security of data in the equipment's hard disk.
[0192] The invention also provides a hard disk lock system.
[0193] Reference Figure 3 , Figure 3 It is a schematic diagram of the functional modules of the first embodiment of the hard disk lock system of the present invention.
[0194] like Figure 3 As shown, the hard disk lock system includes: a client and a server, the client is connected to the server, wherein the client includes:
[0195] The device determination module 10 is used to detect the hard disk encryption status of each enterprise device and determine the device to be encrypted in each enterprise device according to the hard disk encryption status;
[0196] A policy acquisition module 20 is used to acquire a hard disk password configuration policy of the device to be encrypted, wherein the hard disk password configuration policy is generated by the server according to the device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0197] A password configuration module 30, configured to encrypt the device to be encrypted according to the password requirement strength, the password validity period and the password warning level of the hard disk password configuration policy;
[0198] The server includes:
[0199] The information acquisition module 40 is used to obtain the device information of the device to be encrypted in each enterprise device;
[0200] A policy generation module 50 is used to generate a hard disk password configuration policy of the device to be encrypted according to the device information and store the hard disk password configuration policy in a preset policy database, wherein the hard disk password configuration policy includes: password requirement strength, password validity period and password warning level;
[0201] The synchronous updating module 60 is used to receive the hard disk encryption status of each enterprise device and synchronously update the hard disk encryption status of the device to be encrypted.
[0202] Furthermore, the password configuration module 30 includes:
[0203] An acquisition unit, used for outputting preset encryption prompt information and receiving a password to be configured for the device to be encrypted;
[0204] A detection unit, used to detect the complexity of the password to be configured, and determine whether the password to be configured meets the password strength requirement according to the complexity;
[0205] The configuration unit is used to associate the password to be configured with the password validity period and the password warning level and store them in the security chip of the device to be encrypted.
[0206] Furthermore, the client of the hard disk lock system also includes:
[0207] The access authentication module is used to extract the first device ID and the machine code of the client, and perform access authentication according to the first device ID and the machine code.
[0208] Furthermore, the strategy acquisition module 20 also includes:
[0209] A reading unit, configured to read a second device ID of the device to be encrypted after access authentication is passed according to the first device ID and the machine code;
[0210] The acquiring unit is used to acquire the hard disk password configuration policy of the device to be encrypted from a preset policy database according to the second device ID.
[0211] Furthermore, the hard disk encryption status includes: unencrypted and password expired, and the device determination module 10 includes:
[0212] A first determining unit, configured to determine each first device as the device to be encrypted if it is detected that the hard disk encryption state of each first device in the enterprise device is unencrypted;
[0213] The second determining unit is configured to determine each of the second devices as the device to be encrypted if it is detected that the hard disk encryption status of each of the second devices in the enterprise device is that the password has expired.
[0214] Furthermore, the device determination module 10 further includes:
[0215] A detection unit, used to detect the hard disk encryption status of the enterprise device according to a preset time period;
[0216] The client of the hard disk lock system also includes:
[0217] The log reporting module is used to format the encryption status of the hard disk and report the encryption status of the hard disk after formatting.
[0218] Furthermore, the equipment information includes: equipment type, subordinate position and subordinate department, and the information acquisition module 40 is also used to obtain the equipment type, subordinate position and subordinate department of the enterprise equipment from the asset database of the enterprise resource management system.
[0219] Furthermore, the synchronous update module 60 is further used to: in the asset database, add field information corresponding to the hard disk encryption status for the device to be encrypted, so as to synchronously update the hard disk encryption status of the device to be encrypted.
[0220] Furthermore, the server of the hard disk lock system also includes:
[0221] The status output module is used to receive a viewing instruction for the hard disk encryption status, extract the hard disk encryption status of the enterprise device according to the viewing instruction, and output it.
[0222] Among them, the functional implementation of each module in the above-mentioned hard disk lock system corresponds to each step in the above-mentioned hard disk encryption method embodiment, and its functions and implementation processes are no longer repeated here.
[0223] The present invention also provides a computer-readable storage medium on which a hard disk encryption program is stored. When the hard disk encryption program is executed by a processor, the steps of the hard disk encryption method described in any of the above embodiments are implemented.
[0224] The specific embodiments of the computer-readable storage medium of the present invention are substantially the same as the embodiments of the hard disk encryption method described above, and are not described in detail herein.
[0225] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0226] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0227] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0228] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A hard disk encryption method, It is characterized in that The hard disk encryption method is applied to a client in a hard disk lock system, and the hard disk encryption method includes: Detect the hard disk encryption status of each enterprise device, and determine the enterprise device whose hard disk encryption status is not encrypted or the password has expired as a device to be encrypted; Obtaining a hard disk password configuration policy of the device to be encrypted from a preset policy database, wherein the hard disk password configuration policy is generated by a server connected to the client after risk scoring based on device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period, and password alarm level; the device information includes device type, affiliated position, and affiliated department; the password policy level of the hard disk password configuration policy is positively correlated with the risk score of the enterprise device; Outputting preset encryption prompt information and receiving a password to be configured for the device to be encrypted fed back by the user based on the preset encryption prompt information; Calling the Windows Management Instrumentation (WMI) function of the hard disk lock system to read the hard disk password configuration in the basic input and output system BIOS to obtain the password to be configured for the current device to be encrypted; Detecting the complexity of the password to be configured, and when it is determined that the complexity of the password to be configured reaches the password strength requirement, storing the password to be configured in a security chip of a trusted platform module TPM of the current device to be encrypted, and associating the password validity period and the password alarm level with the password to be configured; When it is determined that the complexity of the password to be configured does not meet the password strength requirement, a prompt message is output again to the user of the current device to be encrypted for the user to re-enter the password to be configured until the password to be configured fed back by the user meets the password strength requirement.
2. The hard disk encryption method according to claim 1, It is characterized in that Before the step of acquiring the hard disk password configuration policy of the device to be encrypted from the preset policy database, the method further includes: Extracting a first device ID and a machine code of the client, and performing access authentication according to the first device ID and the machine code; The step of obtaining the hard disk password configuration policy of the device to be encrypted from the preset policy database includes: After access authentication is passed according to the first device ID and the machine code, reading the second device ID of the device to be encrypted; Obtain the hard disk password configuration policy of the device to be encrypted from a preset policy database according to the second device ID.
3. The hard disk encryption method according to claim 1, It is characterized in that The step of detecting the hard disk encryption status of each enterprise device includes: Detecting the hard disk encryption status of the enterprise device according to a preset time period; After the step of detecting the hard disk encryption status of each enterprise device, the method further includes: The encryption status of the hard disk is formatted and the encryption status of the hard disk after formatting is reported to the server.
4. A hard disk encryption method, It is characterized in that The hard disk encryption method is applied to the server of the hard disk lock system, and the server is connected to the client of the hard disk lock system. The hard disk encryption method includes: Obtain device information of the device to be encrypted in each enterprise device; wherein the device information includes device type, subordinate position and subordinate department; the device to be encrypted is an enterprise device whose hard disk encryption status is unencrypted or the password has expired; Performing a risk score on the device to be encrypted according to the device information, and generating a hard disk password configuration policy for the device to be encrypted according to the risk score; wherein the hard disk password configuration policy includes: password requirement strength, password validity period, and password alarm level; the password policy level of the hard disk password configuration policy is positively correlated with the risk score of the enterprise device; The hard disk password configuration policy is stored in a preset policy database, so that the client in the hard disk lock system obtains the hard disk password configuration policy of the device to be encrypted from the preset policy database, and encrypts the device to be encrypted according to the hard disk password configuration policy; wherein the encryption process includes: outputting preset encryption prompt information and receiving the password to be configured of the device to be encrypted fed back by the user based on the preset encryption prompt information; calling the Windows Management Instrumentation WMI function of the hard disk lock system to read the hard disk password configuration in the basic input and output system BIOS to obtain the password to be configured of the current device to be encrypted; detecting the complexity of the password to be configured, and when it is determined that the complexity of the password to be configured reaches the password requirement strength, storing the password to be configured in the security chip of the trusted platform module TPM of the current device to be encrypted, and associating the password validity period and the password warning level with the password to be configured; when it is determined that the complexity of the password to be configured does not reach the password requirement strength, re-outputting prompt information to the user of the current device to be encrypted for the user to re-enter the password to be configured, until the password to be configured fed back by the user reaches the password requirement strength; The hard disk encryption status of each enterprise device is received, and the hard disk encryption status of the device to be encrypted is synchronously updated.
5. The hard disk encryption method according to claim 4, It is characterized in that The step of obtaining device information of the device to be encrypted in each enterprise device includes: Obtaining the equipment type, subordinate position and subordinate department of each of the enterprise equipment from the asset database of the enterprise resource management system; The step of synchronously updating the encryption status of the hard disk of the device to be encrypted comprises: In the asset database, field information corresponding to the hard disk encryption status is added for the device to be encrypted, so as to synchronously update the hard disk encryption status of the device to be encrypted.
6. The hard disk encryption method according to claim 4, It is characterized in that After the step of receiving the hard disk encryption status of each enterprise device and synchronously updating the hard disk encryption status of the device to be encrypted, the method further includes: A viewing instruction for the hard disk encryption status is received, and the hard disk encryption status of each of the enterprise devices is extracted and output according to the viewing instruction.
7. A hard disk lock system, It is characterized in that The hard disk lock system includes: a client and a server, wherein the client is connected to the server, wherein the client includes: A device determination module, used to detect the hard disk encryption status of each enterprise device, and determine the enterprise device whose hard disk encryption status is not encrypted or the password has expired as a device to be encrypted; A policy acquisition module is used to acquire the hard disk password configuration policy of the device to be encrypted from a preset policy database, wherein the hard disk password configuration policy is generated by the server after risk scoring based on the device information of the enterprise device, and the hard disk password configuration policy includes: password requirement strength, password validity period and password alarm level; the device information includes device type, affiliated position and affiliated department; A password configuration module, used for outputting preset encryption prompt information and receiving the password to be configured of the device to be encrypted fed back by the user based on the preset encryption prompt information; calling the Windows Management Instrumentation WMI function of the hard disk lock system to read the hard disk password configuration in the basic input and output system BIOS to obtain the password to be configured of the current device to be encrypted; detecting the complexity of the password to be configured, and when it is determined that the complexity of the password to be configured reaches the password requirement strength, storing the password to be configured in the security chip of the Trusted Platform Module TPM of the current device to be encrypted, and associating the password validity period and the password alarm level with the password to be configured; when it is determined that the complexity of the password to be configured does not reach the password requirement strength, re-outputting prompt information to the user of the current device to be encrypted for the user to re-enter the password to be configured, until the password to be configured fed back by the user reaches the password requirement strength; The server includes: An information acquisition module is used to acquire device information of the device to be encrypted in each enterprise device; wherein the device information includes device type, subordinate position and subordinate department; the device to be encrypted is an enterprise device whose hard disk encryption status is unencrypted or the password has expired; A policy generation module is used to perform a risk score on the device to be encrypted according to the device information, and generate a hard disk password configuration policy for the device to be encrypted according to the risk score; wherein the hard disk password configuration policy includes: password requirement strength, password validity period and password alarm level; the password policy level of the hard disk password configuration policy is positively correlated with the risk score of the enterprise device; the hard disk password configuration policy is stored in a preset policy database, so that the client in the hard disk lock system obtains the hard disk password configuration policy of the device to be encrypted from the preset policy database, and encrypts the device to be encrypted according to the hard disk password configuration policy; wherein the encryption process includes: outputting preset encryption prompt information and receiving the device to be encrypted feedback from the user based on the preset encryption prompt information the password to be configured; calling the Windows Management Instrumentation WMI function of the hard disk lock system to read the hard disk password configuration in the basic input and output system BIOS to obtain the password to be configured of the current device to be encrypted; detecting the complexity of the password to be configured, and when it is determined that the complexity of the password to be configured reaches the password requirement strength, storing the password to be configured in the security chip of the trusted platform module TPM of the current device to be encrypted, and associating the password validity period and the password alarm level with the password to be configured; when it is determined that the complexity of the password to be configured does not reach the password requirement strength, re-outputting prompt information to the user of the current device to be encrypted for the user to re-enter the password to be configured, until the password to be configured fed back by the user reaches the password requirement strength; The synchronous update module is used to receive the hard disk encryption status of each enterprise device and synchronously update the hard disk encryption status of the device to be encrypted.
8. A hard disk encryption device, It is characterized in that The hard disk encryption device includes: a memory, a processor, and a hard disk encryption program stored in the memory and executable on the processor. When the hard disk encryption program is executed by the processor, the steps of the hard disk encryption method according to any one of claims 1 to 3 or 4 to 6 are implemented.
9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a hard disk encryption program, and when the hard disk encryption program is executed by the processor, the steps of the hard disk encryption method according to any one of claims 1 to 3 or 4 to 6 are implemented.
Citation Information
Patent Citations
Method and system for centrally managing code to enterprise hard disk
CN1983291A