A Dynamic Encryption Method for Memory Based on Time Tags

By adopting a dynamic encryption method based on time tags in encrypted memory and using mobile apps to generate dynamic passwords, the problem of forgetting or losing passwords in existing encrypted memory is solved, and data cannot be recovered is achieved, and safe and convenient data access is achieved.

CN113836549BActive Publication Date: 2025-05-23BEIJING AEROSPACE QIXING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111067319.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-13
Publication Date
2025-05-23
Estimated Expiration
2041-09-13

AI Technical Summary

Technical Problem

Existing encrypted memory requires a fixed password when used. Once the password is forgotten or lost, the user needs to reset the password, resulting in the data being unable to be restored. At the same time, there is difficulty in memorizing the password and high hardware costs.

Method used

The time tag-based memory dynamic encryption method is adopted to generate dynamic passwords through mobile apps and add time tags to decrypt memory, achieving secure and convenient access without memory fixed passwords.

Benefits of technology

It solves the difficulty of entering a fixed password when using encrypted memory, and achieves data access without increasing hardware costs, no memory passwords, random passwords, and safe and convenient.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113836549B_ABST
    Figure CN113836549B_ABST
Patent Text Reader

Abstract

The present invention discloses a memory dynamic encryption method based on time tags, and the memory dynamic encryption method includes the following steps: S1 implants the same cryptographic algorithm in the mobile phone App and the memory client, and the mobile phone App is paired with the memory; S2 runs the memory read-only partition client program when in use; S3 uses the dynamic password generated by the mobile phone App as the decryption key of the memory, adds a time tag in the process of the mobile phone App generating the dynamic password, and verifies the memory key according to the password verification process. The memory dynamic encryption method of the invention can solve the problem that the current mainstream encrypted memory needs to enter a fixed password when in use, and the user needs to reset the password once the password cannot be retrieved, and the memory must be initialized, which causes the data to be unrecoverable, and achieves the purpose of not increasing hardware costs, not needing to remember passwords, random passwords, and being safe and convenient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security encryption, and in particular to a memory dynamic encryption method based on time tags. Background Art

[0002] With the popularization of mobile terminal information processing devices and storage devices, the information security of mobile devices in mobile environments is particularly important. At present, the encryption technologies used in encrypted storage products at home and abroad mainly include: digital passwords, encrypted Ukey, biometric technology, etc. Once the user loses the Ukey based on Ukey encryption, the data will be irreparably lost. The encryption mode based on digital passwords requires memorizing passwords. In today's digital age, people need to remember too many passwords: such as bank cards, emails, WeChat, QQ, computer startup passwords, etc., so it is easy to cause password confusion or forget passwords. Whether the Ukey is lost or the password is forgotten, it will cause significant losses such as the inability to read and retrieve data in the storage device. Storage based on biometric technologies such as fingerprint recognition, iris, and face recognition often requires higher hardware costs. Summary of the invention

[0003] In view of the above technical problems in the related art, the present invention proposes a memory dynamic encryption method based on time tags, which can overcome the above shortcomings of the prior art.

[0004] To achieve the above technical objectives, the technical solution of the present invention is implemented as follows: a memory dynamic encryption method based on time tags, comprising the following steps:

[0005] S1 implants the same password algorithm in the mobile app and the storage client. The mobile app and the storage are paired when the storage is connected to the PC and powered on for the first time.

[0006] When S2 is in use, run the storage read-only partition client program;

[0007] S3 uses the dynamic password generated by the mobile app as the decryption key of the storage. The mobile app adds a time tag during the process of generating the dynamic password. The time tag includes two elements: the current public time and the valid time range. After the storage client receives the dynamic password with the time tag, it first verifies the validity of the time tag, then verifies whether the password is correct, and verifies the key of the storage according to the verification process. If the verification is correct, the encrypted partition authorized by the password is opened, allowing reading and writing, and performing normal read and write operations. If the verification code is wrong, re-verify, and the verification is closed for a certain period of time when the allowed number of errors is reached.

[0008] Further, the process of pairing the mobile phone APP with the memory in S1 is as follows: The memory authorization software randomly generates a piece of text, passphrase, and generates a key identifier, passid. The memory authorization software generates a QR code based on passid and passphrase and displays a password verification input box on the PC side. The mobile phone APP scans the QR code to obtain passid and passphrase. The mobile phone APP calculates a one-time key according to the password verification algorithm. The mobile phone APP and the memory perform a password verification handshake. If the handshake is successful, the pairing is successful; if the handshake fails, the pairing fails and needs to be re-paired.

[0009] Further, the algorithm of the key in S3 is as follows: First, generate the key parameters of the password, the time tag timestamp and the preset key text passphrase. Timestamp is calculated based on the current public time, and passphrase is a piece of text set during the pairing of the mobile phone APP and the memory. Then, mix timestamp and passphrase according to the rule to get passtext, and calculate the result of passtext according to the HMAC algorithm to obtain a one-time password.

[0010] Further, the password verification process in S3 is as follows: The authorization software generates a digital password according to the key rule and displays an authorization interface. The interface includes a password input box and a QR code containing a password identifier. The password verification method is to input the one-time password of the mobile phone authorization APP or scan the authorization QR code with the mobile phone-side authorization APP, and then the memory authorization software verifies the password.

[0011] Further, the memory in S3 has the function of prohibiting unauthorized software from accessing. When the encrypted SSD receives a request for reading and writing data, it allows reading and writing for the application software within the whitelist, performs normal reading and writing operations, rejects operations for the application software within the blacklist, and for the application software not within the black and white lists, a prompt box pops up to let the user choose whether to allow the operation, and according to the user's needs, choose to allow during the current power-on period, allow reading and writing and add to the whitelist, or reject the operation and add to the blacklist.

[0012] The beneficial effects of the present invention: The dynamic encryption method of the memory of the present invention can solve the problem that the currently mainstream encrypted memory needs to input a fixed password during use. Once the user cannot retrieve the password and needs to reset the password, the memory must be initialized, resulting in data loss. And it achieves the purpose of not increasing the hardware cost, not requiring password memorization, random passwords, security, and convenience. Description of the Drawings

[0013] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0014] Figure 1 is a pairing flow chart of a memory dynamic encryption method according to an embodiment of the present invention;

[0015] Figure 2 is a flow chart of a memory dynamic encryption method according to an embodiment of the present invention;

[0016] Figure 3 is a flow chart of the password verification of the memory dynamic encryption method according to an embodiment of the present invention;

[0017] Figure 4 Schematic diagram of a key algorithm of a memory dynamic encryption method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0018] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field belong to the scope of protection of the present invention.

[0019] like Figure 2 As shown, the memory dynamic encryption method based on time tags according to an embodiment of the present invention includes the following steps:

[0020] S1 implants the same password algorithm in the mobile app and the storage client. The mobile app and the storage are paired when the storage is connected to the PC and powered on for the first time.

[0021] When S2 is in use, run the storage read-only partition client program;

[0022] S3 uses the dynamic password generated by the mobile app as the decryption key of the storage. The mobile app adds a time tag during the process of generating the dynamic password. The time tag includes two elements: the current public time and the valid time range. After the storage client receives the dynamic password with the time tag, it first verifies the validity of the time tag, then verifies whether the password is correct, and verifies the key of the storage according to the verification process. If the verification is correct, the encrypted partition authorized by the password is opened, allowing reading and writing, and performing normal read and write operations. If the verification code is wrong, re-verify, and the verification is closed for a certain period of time when the allowed number of errors is reached.

[0023] like Figure 1 As shown, the process of pairing the mobile phone APP and the storage in S1 described above is: the storage authorization software randomly generates a text passphrase and generates a key identifier passid, the storage authorization software generates a QR code according to the passid and passphrase and displays a password verification input box on the PC, the mobile phone APP scans the QR code to obtain the passid and passphrase, the mobile phone APP calculates the one-time key according to the password verification algorithm, the mobile phone APP and the storage perform a password verification handshake, if the handshake is successful, the pairing is successful, if the handshake fails, the pairing fails and needs to be re-paired.

[0024] like Figure 4 As shown, the algorithm of the key in S3 described above is: first, generate the key parameter timestamp of the password and the preset key text passphrase, where timestamp is calculated based on the current public time, and passphrase is a piece of text set when the mobile phone APP and the storage are paired, then mix timestamp and passphrase according to the rules to obtain passtext, calculate the result of passtext according to the HMAC algorithm, and obtain a one-time password.

[0025] like Figure 3 As shown, the password verification process in S3 described above is: the authorization software generates a digital password according to the key rule and displays the authorization interface. The interface includes a password input box and a QR code containing a password identifier. The password verification method is to enter the one-time password of the mobile phone authorization APP or scan the authorization QR code with the mobile phone authorization APP, and then the storage authorization software verifies the password.

[0026] The memory in S3 described above has the function of prohibiting unauthorized software from accessing it. When the encrypted SSD receives a request to read or write data, it allows reading and writing for application software in the whitelist and performs normal read and write operations, but refuses operations for application software in the blacklist. For application software that is not in the blacklist or whitelist, a prompt box pops up to let the user choose whether to allow the operation. According to user needs, choose to allow during this power-on period, allow reading and writing and add to the whitelist, or refuse the operation and add to the blacklist.

[0027] The storage medium of the above-mentioned encryption memory can be any storage medium such as magnetic storage or flash memory storage medium, and the interface can be a USB interface, a SATA interface, and other standard interfaces compatible with current computer peripherals.

[0028] In order to facilitate understanding of the above technical solutions of the present invention, the above technical solutions of the present invention are described in detail below through specific usage methods.

[0029] When in use, first implant the same password algorithm in the mobile app and the storage client. When the storage is connected to the PC for the first time, the mobile app and the storage are paired. When in use, the PC is powered on and the storage is connected to the computer and powered on. The dynamic password generated by the mobile app is used as the decryption key of the storage. The key of the storage is verified according to the password verification process. If the verification is correct, the encrypted partition authorized by the password is opened, allowing reading and writing, and performing normal read and write operations.

[0030] To sum up, with the help of the above-mentioned technical solution of the present invention, it is possible to solve the problem that the current mainstream encrypted storage requires a fixed password to be entered when in use, and once the password cannot be retrieved, the user needs to reset the password and must initialize the storage, which causes the data to be unrecoverable. It also achieves the purpose of not increasing hardware costs, not needing to remember passwords, random passwords, and being safe and convenient.

[0031] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A memory dynamic encryption method based on time tag, It is characterized in that The following steps are involved: S1 implants the same password algorithm in the mobile app and storage client. The mobile app and storage are paired when the storage is connected to the PC and powered on for the first time. The process of pairing the mobile phone APP and the storage device is as follows: the storage device authorization software randomly generates a text passphrase and generates a key identifier passid. The storage device authorization software generates a QR code based on the passid and passphrase and displays a password verification input box on the PC. The mobile phone APP scans the QR code to obtain the passid and passphrase. The mobile phone APP calculates the one-time key according to the password verification algorithm. The mobile phone APP and the storage device perform a password verification handshake. If the handshake is successful, the pairing is successful. If the handshake fails, the pairing fails and needs to be re-paired. When S2 is in use, run the storage read-only partition client program; S3 uses the dynamic password generated by the mobile app as the decryption key of the storage device. The mobile app adds a time tag during the process of generating the dynamic password. The time tag includes two elements: the current public time and the valid time range. After the storage device client receives the dynamic password containing the time tag, it first verifies the validity of the time tag, then verifies whether the password is correct, and verifies the key of the storage device according to the password verification process. If the verification is correct, the encrypted partition authorized by the password is opened, allowing reading and writing, and performing normal read and write operations. If the verification code is wrong, re-verify, and close the password verification for a certain period of time when the allowed number of errors is reached; the algorithm of the key in S3 is: first generate the key parameter time tag timestamp of the password and the preset key text passphrase, the timestamp is calculated based on the current public time, and the passphrase is a piece of text set when the mobile app and the storage device are paired, and then the timestamp and passphrase are mixed according to the rules to obtain the passtext, and the result of the passtext is calculated according to the HMAC algorithm to obtain a one-time password; The memory in S3 has the function of prohibiting unauthorized software from accessing it. When the encrypted SSD receives a request to read or write data, it allows reading and writing for application software in the whitelist and performs normal read and write operations, but refuses operations for application software in the blacklist. For application software that is not in the blacklist or the blacklist, a prompt box pops up to allow the user to choose whether to allow the operation. According to user needs, the user can choose to allow reading and writing and add the application software to the whitelist during this power-on period, or refuse the operation and add the application software to the blacklist.

2. The memory dynamic encryption method according to claim 1, It is characterized in that The password verification process in S3 is as follows: the authorization software generates a digital password according to the key rules and displays an authorization interface, which includes a password input box and a QR code containing a password identifier. The password verification method is to enter the one-time password of the mobile phone authorization APP or scan the authorization QR code with the mobile phone authorization APP, and then the storage authorization software verifies the password.

Citation Information

Patent Citations

  • Equipment pairing method, terminal and system

    CN103763786A

  • Authorized access method for browser client and server

    CN105721502A