Data verification method, device, electronic device and computer-readable storage medium
By verifying the UBI image at the system startup and creating a verification device node, delaying the data integrity verification until the system is started, the problem of extended startup time is solved, and the effect of reducing the startup time while ensuring data integrity is achieved.
Patent Information
- Application Number
- CN202111308084.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-05
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2041-11-05
AI Technical Summary
The prior art performs data integrity verification when the system is powered on and started, resulting in an extended startup time, so how to reduce the startup time while ensuring data integrity.
By building a UBI image and verifying it when the system starts, if it passes the verification, a verification device node based on the UBI image is created, and the data integrity verification is delayed until the system is completed after the startup is completed.
On the basis of ensuring data integrity, the extension of the startup time is reduced and the efficiency of system startup is improved.
Smart Images

Figure CN113987547B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of operating systems, and particularly to a data verification method, apparatus, electronic device, and computer-readable storage medium. Background Art
[0002] Modern various intelligent devices each have operating systems with various architectures. These intelligent devices have many common features, such as having a processor and a storage medium. After the intelligent device is activated by the power button, the processor can read data from the storage medium and perform preparatory work on each component according to the read data, and finally enter the running state.
[0003] In order to extend the service life of the storage medium, there appears a UBI (Unsorted Block Images, file system) image that can perform wear leveling protection on the storage medium. The UBI image not only has the function of wear leveling protection but also has the function of data integrity verification. The UBI image is enabled when the system starts, and the corresponding functions of the UBI image are executed. However, the UBI image takes a long time to perform data integrity verification, which will increase the system startup time.
[0004] It can be seen that how to reduce the startup time while ensuring data integrity is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a data verification method, apparatus, electronic device, and computer-readable storage medium, which can reduce the startup time while ensuring data integrity.
[0006] To solve the above technical problems, the embodiments of this application provide a data verification method, including:
[0007] Construct a UBI image;
[0008] When the system starts, mount the UBI image and verify the UBI image;
[0009] If the UBI image passes the verification, create a verification device node based on the UBI image;
[0010] After the system completes startup, use the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium.
[0011] Optionally, the constructing the UBI image includes:
[0012] Generate a file system image that supports mounting a verification device node according to the code compilation result;
[0013] Generate a corresponding identification table according to the file system image; wherein, the identification table includes the identification corresponding to each data block in the file system image and the parent identification of the file system image;
[0014] Perform a digital signature on the parent identification according to a set key to obtain a signature file including the key and the encrypted parent identification;
[0015] Use the file system image, the identification table, and the signature file as a UBI image, and set an identification for the UBI image not to start integrity verification.
[0016] Optionally, the verification of the UBI image includes:
[0017] Read the pre-stored key;
[0018] Determine whether the pre-stored key is consistent with the key included in the signature file;
[0019] If the pre-stored key is consistent with the key included in the signature file, determine that the UBI image passes the verification.
[0020] Optionally, it further includes:
[0021] If the pre-stored key is consistent with the key included in the signature file, decrypt the parent identification included in the signature file using the key;
[0022] Determine whether the decrypted parent identification is consistent with the parent identification included in the identification table;
[0023] If the decrypted parent identification is consistent with the parent identification included in the identification table, execute the step of creating a verification device node based on the UBI image.
[0024] Optionally, the creation of a verification device node based on the UBI image includes:
[0025] Create a UBI-based character device in the partition flashed with the UBI image;
[0026] Create a virtual block device based on UBI;
[0027] Mount the verification device node based on the virtual block device.
[0028] Optionally, before mounting the verification device node based on the virtual block device, it further includes:
[0029] Determine whether the UBI image meets the set boot verification requirements;
[0030] If the UBI image meets the set boot verification requirements, execute the step of mounting the verification device node based on the virtual block device.
[0031] Optionally, before using the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium, it further includes:
[0032] Read data from the storage medium;
[0033] Use the virtual block device to perform data recovery operations on the data;
[0034] Correspondingly, using the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium includes:
[0035] Use the verification device connected to the verification device node to perform integrity verification on the data after the data recovery operation is completed.
[0036] Optionally, the identification table further includes the identifications and parent identifications corresponding to other file data except the file system image;
[0037] Correspondingly, using the verification device connected to the verification device node to perform integrity verification on the data after the data recovery operation is completed includes:
[0038] According to the identifications and parent identifications included in the identification table, use the verification device connected to the verification device node to verify the identifications and parent identifications corresponding to the data after the data recovery operation is completed.
[0039] Optionally, when determining that the data after the data recovery operation passes the integrity verification, it further includes:
[0040] Store the data that passes the integrity verification in a set cache area.
[0041] The embodiment of the present application also provides a data verification device, including a construction unit, a mounting unit, an identity verification unit, a creation unit, and an integrity verification unit;
[0042] The construction unit is used to construct a UBI image;
[0043] The mounting unit is used to mount the UBI image when the system starts;
[0044] The identity verification unit is used to verify the UBI image;
[0045] The creation unit is used to create a verification device node based on the UBI image if the UBI image passes the verification;
[0046] The integrity verification unit is used to perform integrity verification on the data stored on the storage medium by using the verification device connected to the verification device node after the system completes startup.
[0047] Optionally, the construction unit includes a generation subunit, a signature subunit, an as subunit, and a setting subunit;
[0048] The generation subunit is used to generate a file system image that supports mounting the verification device node according to the code compilation result;
[0049] The signature subunit is used to generate a corresponding identification table based on the file system image; wherein, the identification table includes the identification corresponding to each data block in the file system image and the parent identification of the file system image;
[0050] The as subunit is used to digitally sign the parent identification according to the set key to obtain a signature file containing the key and the encrypted parent identification;
[0051] The setting subunit is used to use the file system image, the identification table, and the signature file as a UBI image and set an identification for the UBI image not to start integrity verification.
[0052] Optionally, the identity verification unit includes a reading subunit, a judgment subunit, and a determination subunit;
[0053] The reading subunit is used to read the pre-stored key;
[0054] The judgment subunit is used to judge whether the pre-stored key is consistent with the key included in the signature file;
[0055] The determination subunit is used to determine that the UBI image passes the verification if the pre-stored key is consistent with the key included in the signature file.
[0056] Optionally, it further includes a decryption unit and a judgment unit;
[0057] The decryption unit is used to decrypt the parent identification included in the signature file by using the key if the pre-stored key is consistent with the key included in the signature file;
[0058] The judgment unit is used to judge whether the decrypted parent identification is consistent with the parent identification included in the identification table; if the decrypted parent identification is consistent with the parent identification included in the identification table, the creation unit is triggered to execute the step of creating a verification device node based on the UBI image.
[0059] Optionally, the creation unit is configured to create a UBI-based character device in a partition brushed with a UBI image; create a UBI-based virtual block device; and mount the verification device node based on the virtual block device.
[0060] Optionally, it further includes a power-on verification unit;
[0061] The power-on verification unit is configured to determine whether the UBI image meets the set power-on verification requirements; if the UBI image meets the set power-on verification requirements, trigger the creation unit to execute the step of mounting the verification device node based on the virtual block device.
[0062] Optionally, it further includes a reading unit and a recovery unit;
[0063] The reading unit is configured to read data from the storage medium;
[0064] The recovery unit is configured to perform a data recovery operation on the data by using the virtual block device;
[0065] Correspondingly, the integrity verification unit is configured to perform an integrity verification on the data that has completed the data recovery operation by using the verification device connected to the verification device node.
[0066] Optionally, the identification table further includes identifiers and parent identifiers corresponding to other file data except for the file system image;
[0067] Correspondingly, the integrity verification unit is configured to verify the identifiers and parent identifiers corresponding to the data that has completed the data recovery operation by using the verification device connected to the verification device node according to the identifiers and parent identifiers included in the identification table.
[0068] Optionally, it further includes a cache unit;
[0069] The cache unit is configured to store the data that has passed the integrity verification into a set cache area.
[0070] An embodiment of the present application further provides an electronic device, including:
[0071] A memory, configured to store a computer program;
[0072] A processor, configured to execute the computer program to implement the steps of the data verification method as described above.
[0073] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data verification method as described above are implemented.
[0074] As can be seen from the above technical solution, build a UBI image; mount the UBI image when the system starts. To ensure the correctness of the UBI image, the UBI image can be verified. If the UBI image passes the verification, it indicates that the UBI image is legal. At this time, a verification device node based on the UBI image can be created. The verification device node is connected to a verification device, and the verification device can run after the system completes startup, and is used to perform integrity verification on data. That is, after the system completes startup, the verification device connected to the verification device node can be used to perform integrity verification on the data stored on the storage medium. In this technical solution, a verification device node based on the UBI image is created, and the verification device node can realize the connection with the verification device, and the verification device can be started after the system completes startup, so that the work of data integrity verification can be executed after the system completes startup, while ensuring data integrity and reducing the startup time. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] To more clearly illustrate the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0076] Figure 1 It is a flowchart of a data verification method provided by an embodiment of the present application;
[0077] Figure 2 It is a flowchart of a method for building a UBI image provided by an embodiment of the present application;
[0078] Figure 3 It is a flowchart of a method for creating a verification device node based on a UBI image provided by an embodiment of the present application;
[0079] Figure 4 It is a schematic structural diagram of a data verification device provided by an embodiment of the present application;
[0080] Figure 5 It is a structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0081] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the protection scope of the present application.
[0082] In the description and claims of this application and the above-mentioned drawings, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units that are not listed.
[0083] To enable those skilled in the art to better understand the solution of this application, the following further detailed description of this application will be given in conjunction with the drawings and specific implementation manners.
[0084] Next, a data verification method provided by an embodiment of this application will be introduced in detail. Figure 1 FIG. is a flowchart of a data verification method provided by an embodiment of this application, and this method includes:
[0085] S101: Construct a UBI image.
[0086] When the system starts up, it is necessary to mount the UBI image, and the work required to be executed when the system starts up is implemented based on the virtual block device of the UBI image. In the prior art, the work of data integrity verification is set in the virtual block device of the UBI image, and data integrity verification takes a long time, resulting in system startup delay.
[0087] Therefore, in specific implementation, the kernel code program for constructing the UBI image can be modified so that the constructed UBI image does not start the integrity verification function, but hands over the integrity verification function to the verification device. The verification device can be enabled after the system completes startup, so that the execution process of data integrity verification will not affect the system startup time.
[0088] In the embodiment of this application, the constructed UBI image may include a file system image, an identification table, a signature file, etc. The specific construction process can refer to the introduction in Figure 2 and will not be elaborated here.
[0089] S102: Mount the UBI image when the system starts up and verify the UBI image.
[0090] In the embodiment of this application, in order to ensure the legality of the UBI mapping, the identity of the UBI image can be verified. In specific implementation, the identity of the UBI image can be verified by setting an identity identifier.
[0091] Considering that a corresponding signature file is generated when constructing the UBI image, and the signature file contains a key for encrypting data. When the UBI mapping belongs to an illegally constructed UBI image, the key contained in its signature file often changes. Therefore, in practical applications, the key can also be used to verify the identity of the UBI image.
[0092] In a specific implementation, the key used by the signature file can be pre-stored. When the UBI image can be verified, the pre-stored key can be read; it is determined whether the pre-stored key is consistent with the key included in the signature file.
[0093] If the pre-stored key is consistent with the key included in the signature file, it indicates that the key included in the signature file of the UBI mapping is consistent with the key used when theoretically constructing the UBI mapping, that is, the UBI mapping belongs to a legally created UBI mapping. At this time, it can be determined that the UBI image passes the verification.
[0094] S103: If the UBI image passes the verification, a verification device node based on the UBI image is created.
[0095] The verification device node can be regarded as a virtual interface provided by the UBI mapping. Through the verification device node, the UBI image can be connected to the verification device, so that the verification device connected by the verification device node performs integrity verification on the data, and there is no need to perform integrity verification on the data through the UBI image.
[0096] S104: After the system completes startup, the verification device connected by the verification device node is used to perform integrity verification on the data stored on the storage medium.
[0097] Since the current UBI image does not start the integrity verification function, in order to implement the integrity verification of the data, a verification device node based on the UBI image can be created. The verification device connected by the verification device node is used to implement the work of data integrity verification.
[0098] In a specific implementation, the verification device can use DM verity. DM verity is an object (target) of DM (Device Mapper, an advanced volume management technology framework based on the kernel), which is specifically used for the verification of file systems. The feature of the DMverity technology is that it verifies whatever data is used, and it can verify the integrity of the data.
[0099] As can be seen from the above technical solution, build a UBI image; mount the UBI image when the system starts. To ensure the correctness of the UBI image, the UBI image can be verified. If the UBI image passes the verification, it means that the UBI image is legal. At this time, a verification device node based on the UBI image can be created. The verification device node is connected to a verification device, and the verification device can run after the system completes startup, and is used to perform integrity verification on data. That is, after the system completes startup, the verification device connected to the verification device node can be used to perform integrity verification on the data stored on the storage medium. In this technical solution, a verification device node based on the UBI image is created, and the verification device node can realize the connection with the verification device, and the verification device can be started after the system completes startup, so that the work of data integrity verification can be executed after the system completes startup, while ensuring data integrity, reducing the startup time.
[0100] Figure 2 The flowchart of a method for building a UBI image provided by an embodiment of the present application, the method includes:
[0101] S201: Generate a file system image that supports mounting a verification device node according to the code compilation result.
[0102] In the embodiment of the present application, the built UBI image can include three parts, namely a file system image, an identification table, and a signature file.
[0103] The file system image can realize the function of system startup by mounting a virtual block device. The identification table can be used to verify the correctness of the file system image, and the identification table is required to be relied on when performing data integrity verification. The signature file is used to verify the parent identification.
[0104] In specific implementation, the kernel code program for building the UBI image can be modified so that the file system image compiled based on the kernel code program can support mounting a verification device node.
[0105] S202: Generate a corresponding identification table according to the file system image.
[0106] In the system startup phase, to ensure the correctness of the mounted UBI image, an identification table will be generated when building the UBI image.
[0107] Among them, the identification table can include the identification corresponding to each data block in the file system image and the parent identification of the file system image.
[0108] In practical applications, a hash operation can be used to generate an identification table. The hash value of each data block serves as the identifier of the data block. A hash operation is performed on the hash values of all data blocks to obtain a root hash as the parent identifier of the file system image.
[0109] S203: Perform a digital signature on the parent identifier according to the set key to obtain a signature file containing the key and the encrypted parent identifier.
[0110] By encrypting the parent identifier and storing the encrypted parent identifier in the form of a signature file, the security of storing the parent identifier can be improved.
[0111] S204: Use the file system image, the identification table, and the signature file as a UBI image, and set an identifier for the UBI image not to start integrity verification.
[0112] In the embodiment of the present application, in order to prevent the UBI image from performing the data integrity verification function during the system startup phase, an identifier for not starting integrity verification can be set for the UBI image.
[0113] During the system startup phase, it will be judged whether the UBI image has an identifier for not starting integrity verification. When the UBI image has an identifier for not starting integrity verification, a verification device node based on the UBI image will be automatically created, so that the integrity verification of data can be performed by using the verification device connected to the verification device node, and the UBI image will no longer be used to perform the integrity verification of data.
[0114] In the embodiment of the present application, in order to reduce the startup time, the UBI image is improved so that the improved UBI image no longer performs the data integrity verification work during system startup, thereby shortening the system startup time. And in order to implement the integrity verification of data, a verification device node can be introduced. After the system startup is completed, the verification device connected to the verification device node performs the integrity verification of data. Therefore, the UBI image built based on the modified kernel code program can support mounting the verification device node.
[0115] Considering that in practical applications, in order to facilitate data processing, the file system image corresponding to the UBI image is sliced into multiple data blocks. Therefore, for each data block, a corresponding hash value can be calculated as the identifier of the data block. A root hash can be calculated based on the hash values of all data blocks, and this root hash can be used as the parent identifier of the UBI image.
[0116] In practical applications, after verifying the identity of the UBI mapping based on the key, the correctness of the UBI mapping can be verified based on the parent identifier.
[0117] In the case where the pre-stored key is consistent with the key included in the signature file, the key can be used to decrypt the parent identifier included in the signature file. Determine whether the decrypted parent identifier is consistent with the parent identifier included in the identifier table.
[0118] If the decrypted parent identifier is consistent with the parent identifier included in the identifier table, it indicates that the mounted UBI image is correct.
[0119] In the embodiments of the present application, based on the key included in the signature file in the UBI image, the verification of the UBI mapping legality can be realized. Decrypting the signature file with the key can obtain the correct parent identifier. When the decrypted parent identifier is consistent with the parent identifier included in the identifier table in the UBI image, it indicates that the UBI image has not been tampered with. Therefore, based on the parent identifier included in the identifier table in the UBI image, the verification of the UBI mapping correctness can be realized.
[0120] Such as Figure 3 shown is a flowchart of a method for creating a verification device node based on a UBI image provided by an embodiment of the present application. The method includes:
[0121] S301: Create a UBI-based character device in the partition flashed with the UBI image.
[0122] The UBI image includes a character device and a virtual block device. When creating the verification device node, it is necessary to first create the character device and the virtual block device of the UBI mapping.
[0123] In practical applications, the UBI image has its corresponding partition, and a UBI-based character device can be created in the partition flashed with the UBI image.
[0124] S302: Create a UBI-based virtual block device.
[0125] The virtual block device can be used to provide the management function of the UBI image. The mounting of the verification device node can be realized by using the virtual block device.
[0126] S303: Determine whether the UBI image meets the set boot verification requirements.
[0127] The boot verification requirements refer to that the UBI image does not perform data integrity verification and can support the mounting of the verification device node.
[0128] In the embodiments of the present application, the boot verification requirements may include determining whether the UBI image has set the function of not starting integrity verification, whether the UBI image includes a file system image, an identifier table, and a signature file.
[0129] When the function of not starting integrity verification is set in the UBI image, and the UBI image includes a file system image, an identification table, and a signature file, it indicates that the UBI image meets the set power-on verification requirements. At this time, S304 can be executed.
[0130] S304: Mount the verification device node based on the virtual block device.
[0131] The verification device connected to the verification device node can be used to perform integrity verification on the data stored on the storage medium after the system completes booting. In practical applications, the DM verity can be used as the verification device.
[0132] When the verification device performs data integrity verification, it can read data from the storage medium and perform integrity verification on the read data based on the verification process of the verification device.
[0133] In the embodiment of the present application, by setting the power-on verification requirements, it can be ensured that the UBI image supports the mounting of the verification device node, so that after the system completes booting, the data integrity verification work can be smoothly performed based on the verification device connected to the verification device node.
[0134] Considering that in practical applications, after the system completes booting, the virtual block device of the UBI image can continue to play a role in performing data recovery operations on the data. Therefore, before using the verification device connected to the verification device node to perform integrity verification on the data, the virtual block device can be used to perform data recovery operations on the data first; then use the verification device connected to the verification device node to perform integrity verification on the data that has completed the data recovery operation.
[0135] The data recovery operation can include automatically solving problems such as bad blocks, bit flips, and wear.
[0136] In practical applications, when there is no need to perform data recovery operations on the data, after reading the data, the verification device connected to the verification device node can be directly used to perform integrity verification on the data that has completed the data recovery operation.
[0137] In the embodiment of the present application, the identification table can also contain the identifications and parent identifications corresponding to other file data except the file system image. Correspondingly, using the verification device connected to the verification device node to perform integrity verification on the data that has completed the data recovery operation can include: verifying the identifications and parent identifications corresponding to the data that has completed the data recovery operation through the verification device connected to the verification device node according to the identifications and parent identifications included in the identification table.
[0138] Taking other file data except the file system image as an example, in specific implementation, it can be determined whether the identification value of the data that has completed the data recovery operation matches the identification value in the identification table.
[0139] The identification value can be a hash value. The data will be stored in the form of data blocks, and each data block has a corresponding hash value. The hash values of each data block are recorded in the identification table.
[0140] In practical applications, the hash value of the data for which the data recovery operation is completed can be calculated, and this hash value is compared with the hash value recorded in the identification table. When there is a hash value in the identification table that is the same as the calculated hash value, it indicates that the data has not been tampered with.
[0141] Considering that in practical applications, it is possible that the data stored on the storage medium has been tampered with, and the hash value corresponding to this data in the identification table has also been tampered with, resulting in the calculated hash value of this data being the same as the hash value in the identification table. Since the parent identification is determined based on the identification values of each data block, there is almost no situation where the data is tampered with and the calculated parent identification is the same as the parent identification recorded in the identification table. Therefore, in the embodiments of the present application, when the identification value of the data for which the data recovery operation is completed matches the identification value in the identification table, the parent identification to be verified can be determined based on the data for which the data recovery operation is completed and the remaining data in the storage medium. Determine whether the parent identification to be verified is the same as the parent identification included in the identification table.
[0142] If the parent identification to be verified is the same as the parent identification included in the identification table, it indicates that the data has not been tampered with. At this time, it can be determined that the data for which the data recovery operation is completed passes the integrity check.
[0143] After determining that the data for which the data recovery operation is completed passes the integrity check, the data that passes the integrity check can be stored in a set cache area, so as to facilitate the reading and calling of the data.
[0144] Figure 4 FIG. is a schematic structural diagram of a data verification device provided by an embodiment of the present application, including a construction unit 41, a mounting unit 42, an identity verification unit 43, a creation unit 44, and an integrity verification unit 45;
[0145] The construction unit 41 is used to construct a UBI image;
[0146] The mounting unit 42 is used to mount the UBI image when the system starts;
[0147] The identity verification unit 43 is used to verify the UBI image;
[0148] The creation unit 44 is used to create a verification device node based on the UBI image if the UBI image passes the verification;
[0149] The integrity verification unit 45 is used to perform integrity verification on the data stored on the storage medium by using the verification device connected to the verification device node after the system completes startup.
[0150] Optionally, the construction unit includes a generation subunit, a signature subunit, an as subunit, and a setting subunit;
[0151] The generation subunit is used to generate a file system image that supports mounting the verification device node according to the code compilation result;
[0152] The signature subunit is used to generate a corresponding identification table based on the file system image; wherein, the identification table includes the identification corresponding to each data block in the file system image and the parent identification of the file system image;
[0153] The as subunit is used to digitally sign the parent identification according to the set key to obtain a signature file containing the key and the encrypted parent identification;
[0154] The setting subunit is used to use the file system image, the identification table, and the signature file as a UBI image and set an identification for the UBI image not to start integrity verification.
[0155] Optionally, the identity verification unit includes a reading subunit, a judgment subunit, and a determination subunit;
[0156] The reading subunit is used to read the pre-stored key;
[0157] The judgment subunit is used to judge whether the pre-stored key is consistent with the key included in the signature file;
[0158] The determination subunit is used to determine that the UBI image passes the verification if the pre-stored key is consistent with the key included in the signature file.
[0159] Optionally, it further includes a decryption unit and a judgment unit;
[0160] The decryption unit is used to decrypt the parent identification included in the signature file by using the key if the pre-stored key is consistent with the key included in the signature file;
[0161] The judgment unit is used to judge whether the decrypted parent identification is consistent with the parent identification included in the identification table; if the decrypted parent identification is consistent with the parent identification included in the identification table, trigger the creation unit to execute the step of creating a verification device node based on the UBI image.
[0162] Optionally, the creation unit is used to create a UBI-based character device in the partition flashed with the UBI image; create a UBI-based virtual block device; mount the verification device node based on the virtual block device.
[0163] Optionally, it further includes a power-on verification unit;
[0164] The power-on verification unit is used to determine whether the UBI image meets the set power-on verification requirements; if the UBI image meets the set power-on verification requirements, it triggers the creation unit to execute the step of mounting the verification device node based on the virtual block device.
[0165] Optionally, it further includes a reading unit and a recovery unit;
[0166] The reading unit is used to read data from the storage medium;
[0167] The recovery unit is used to perform data recovery operations on the data using the virtual block device;
[0168] Correspondingly, the integrity verification unit is used to perform integrity verification on the data that has completed the data recovery operation using the verification device connected to the verification device node.
[0169] Optionally, the identification table further includes the identifications and parent identifications corresponding to other file data except the file system image;
[0170] Correspondingly, the integrity verification unit is used to verify the identifications and parent identifications corresponding to the data that has completed the data recovery operation through the verification device connected to the verification device node according to the identifications and parent identifications included in the identification table.
[0171] Optionally, it further includes a cache unit;
[0172] The cache unit is used to store the data that has passed the integrity verification into a set cache area.
[0173] Figure 4 For the descriptions of the features in the corresponding embodiments, reference can be made to Figure 1 、 Figure 2 and Figure 3 the relevant descriptions of the corresponding embodiments, which will not be elaborated here one by one.
[0174] As can be seen from the above technical solution, a UBI image is constructed; the UBI image is mounted at system startup. To ensure the correctness of the UBI image, the UBI image can be verified. If the UBI image passes the verification, it indicates that the UBI image is legal. At this time, a verification device node based on the UBI image can be created. The verification device node is connected to a verification device, and the verification device can run after the system completes startup, and is used to perform integrity verification on data. That is, after the system completes startup, the verification device connected to the verification device node can be used to perform integrity verification on the data stored on the storage medium. In this technical solution, a verification device node based on the UBI image is created, and the verification device node can realize the connection with the verification device, and the verification device can be turned on after the system completes startup, so that the work of data integrity verification can be executed after the system completes startup, while ensuring data integrity and reducing the startup time.
[0175] Figure 5 The structural diagram of an electronic device provided by an embodiment of the present application is shown as Figure 5 shown. The electronic device includes: a memory 20 for storing a computer program;
[0176] a processor 21 for implementing the steps of the data verification method in the above embodiment when executing the computer program.
[0177] The electronic device provided in this embodiment may include, but is not limited to, a smart phone, a tablet computer, a notebook computer, or a desktop computer, etc.
[0178] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.
[0179] The memory 20 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 20 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 20 is at least used to store the following computer program 201. After the computer program is loaded and executed by the processor 21, the relevant steps of the data verification method disclosed in any of the foregoing embodiments can be implemented. In addition, the resources stored in the memory 20 may further include an operating system 202 and data 203, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 202 may include Windows, Unix, Linux, etc. The data 203 may include, but is not limited to, the file system image, identification table, and signature file included in the UBI image, and the data stored on the storage medium, etc.
[0180] In some embodiments, the electronic device may further include a display screen 22, an input / output interface 23, a communication interface 24, a power supply 25, and a communication bus 26.
[0181] Those skilled in the art can understand that Figure 5 the structure shown in
[0182] It can be understood that if the data verification method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), electrically erasable programmable ROMs, registers, hard disks, removable disks, CD-ROMs, magnetic disks, or optical discs.
[0183] Based on this, the embodiments of the present invention further provide a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps of the data verification method as described above are implemented.
[0184] The functions of the functional modules of the computer-readable storage medium described in the embodiments of the present invention can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can refer to the relevant descriptions in the above method embodiments and will not be elaborated here.
[0185] The above has introduced in detail a data verification method, device, electronic device, and computer-readable storage medium provided by the embodiments of the present application. The embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, refer to the description of the method part.
[0186] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0187] The above has introduced in detail a data verification method, device, electronic device, and computer-readable storage medium provided by the present application. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principles of the present invention, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A data verification method, characterized in that, it includes: Construct a UBI image; When the system starts, mount the UBI image and verify the UBI image; If the UBI image passes the verification, create a verification device node based on the UBI image; After the system completes startup, use the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium; The constructing of the UBI image includes: Generate a file system image that supports mounting a verification device node according to the code compilation result; generate a corresponding identification table based on the file system image; wherein, the identification table includes the identification corresponding to each data block in the file system image and the parent identification of the file system image; perform digital signature on the parent identification according to a set key to obtain a signature file containing the key and the encrypted parent identification; use the file system image, the identification table and the signature file as the UBI image, and set an identification for the UBI image not to start integrity verification.
2. The data verification method according to claim 1, characterized in that, the verifying of the UBI image includes: Read the pre-stored key; Judge whether the pre-stored key is consistent with the key contained in the signature file; If the pre-stored key is consistent with the key contained in the signature file, determine that the UBI image passes the verification.
3. The data verification method according to claim 2, characterized in that, it further includes: If the pre-stored key is consistent with the key contained in the signature file, decrypt the parent identification contained in the signature file by using the key; Judge whether the decrypted parent identification is consistent with the parent identification contained in the identification table; If the decrypted parent identification is consistent with the parent identification contained in the identification table, execute the step of creating a verification device node based on the UBI image.
4. The data verification method according to claim 1, characterized in that, the creating of a verification device node based on the UBI image includes: Create a character device based on UBI in the partition where the UBI image is flashed; Create a virtual block device based on UBI; Mount the verification device node based on the virtual block device.
5. The data verification method according to claim 4, characterized in that, before mounting the verification device node based on the virtual block device, it further includes: Judge whether the UBI image meets the set startup verification requirements; If the UBI image meets the set startup verification requirements, execute the step of mounting the verification device node based on the virtual block device.
6. The data verification method according to claim 4, characterized in that, before using the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium, it further includes: Read data from the storage medium; Perform a data recovery operation on the data by using the virtual block device; Correspondingly, the using of the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium includes: Use the verification device connected to the verification device node to perform integrity verification on the data after the data recovery operation is completed.
7. A data verification device, characterized in that, it includes a construction unit, a mounting unit, an identity verification unit, a creation unit, and an integrity verification unit; The construction unit is used to construct a UBI image; The mounting unit is used to mount the UBI image when the system starts; The identity verification unit is used to verify the UBI image; The creation unit is used to create a verification device node based on the UBI image if the UBI image passes the verification; The integrity verification unit is used to use the verification device connected to the verification device node to perform integrity verification on the data stored on the storage medium after the system completes startup; The construction unit includes a generation subunit, a signature subunit, an as subunit, and a setting subunit; The generation subunit is used to generate a file system image that supports mounting a verification device node according to the code compilation result; The signature subunit is used to generate a corresponding identification table based on the file system image; wherein, the identification table includes the identification corresponding to each data block in the file system image and the parent identification of the file system image; The as subunit is used to perform a digital signature on the parent identification according to the set key to obtain a signature file containing the key and the encrypted parent identification; The setting subunit is used to use the file system image, the identification table, and the signature file as the UBI image, and set an identification for the UBI image not to start integrity verification.
8. An electronic device, characterized in that, it includes: a memory for storing a computer program; a processor for executing the computer program to implement the steps of the data verification method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the data verification method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
USB flash disk system authentication method and device, electronic equipment and storage medium
CN112613011A