A processing method and apparatus

By combining biometric identification and hardware encryption circuits, the problem of SSDs being easily disassembled and having their data stolen is solved, achieving dual-layer protection and improved security for data storage.

CN114090988BActive Publication Date: 2026-01-23LENOVO (BEIJING) LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111265950.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-28
Publication Date
2026-01-23
Estimated Expiration
2041-10-28

AI Technical Summary

Technical Problem

In existing technologies, solid-state drive (SSD) data protection solutions are easily compromised when the device is disassembled, and the encryption of passwords or server keys is ineffective.

Method used

The system employs biometric identification combined with hardware encryption circuitry. Once the biometric controller confirms a successful biometric match, a matching message is generated and transmitted to the data storage device via the hardware encryption circuitry integrated into the data storage device and the biometric controller. This process adjusts the encryption status of the data stored within the device.

Benefits of technology

It achieves dual-layer protection based on biometric identification and hardware encryption, which improves the security of data storage and ensures that the data remains safe even when the SSD is removed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114090988B_ABST
    Figure CN114090988B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a processing method and device, wherein the processing method comprises: in response to an input operation instruction associated with a data memory, acquiring biological information; transmitting the biological information to a biological information controller to enable the biological information controller to determine whether the biological information matches preset information successfully and generate a matching message; and transmitting the matching message from the biological information controller to the data memory through a target transmission channel to enable the data memory to adjust the encryption state of internal stored data; the target transmission channel is generated by a hardware encryption circuit integrated in the data memory and the biological information controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a processing method and apparatus. Background Technology

[0002] Information security has always been a major hidden danger in the Internet age; among related technologies, commonly used passwords or server keys are used to protect relevant information, but the encryption effect is not good. Summary of the Invention

[0003] In view of this, embodiments of this application provide a processing method and apparatus.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides a processing method, the method comprising:

[0006] Responding to input operation commands associated with the data storage, biological information is acquired;

[0007] The biological information is transmitted to a biological information controller, which then determines whether the biological information matches preset information and generates a matching message.

[0008] The matching message is transmitted from the bioinformatics controller to the data storage via a target transmission channel, so that the data storage adjusts the encryption state of the internally stored data; the target transmission channel is generated by a hardware encryption circuit integrated into the data storage and the bioinformatics controller.

[0009] This application provides a processing apparatus, including:

[0010] An interface for receiving operation commands associated with the data storage;

[0011] A bioinformatics collector is used to acquire bioinformatics in response to the operation command sent by the interface;

[0012] A bioinformatics controller is used to receive the bioinformatics sent by the bioinformatics collector, determine whether the bioinformatics successfully matches preset information, and generate a matching message.

[0013] A data storage device for adjusting the encryption state of internally stored data in response to the matching message transmitted through the target transmission channel;

[0014] The target transmission channel is generated by a hardware encryption circuit integrated into the data storage and the bio-information controller.

[0015] This application provides a processing method and apparatus. First, in response to an input operation command associated with a data storage device, biological information is acquired. Then, the biological information is transmitted to a biological information controller, which determines whether the biological information matches preset information and generates a matching message. Finally, the matching message is transmitted from the biological information controller to the data storage device through a target transmission channel, causing the data storage device to adjust the encryption state of its internally stored data. The target transmission channel is generated by a hardware encryption circuit integrated into the data storage device and the biological information controller. Thus, based on biological information recognition and underlying hardware encryption transmission, dual-layer protection is provided for data storage, thereby improving data storage security. Attached Figure Description

[0016] In the accompanying drawings (which are not necessarily drawn to scale), similar reference numerals may describe similar parts in different views. The drawings illustrate, by way of example and not limitation, the various embodiments discussed herein.

[0017] Figure 1 A flowchart illustrating the first processing method provided in this application embodiment;

[0018] Figure 2 A flowchart illustrating the second processing method provided in this application embodiment;

[0019] Figure 3 A flowchart illustrating the third processing method provided in this application embodiment;

[0020] Figure 4 A partial structural schematic diagram of a processing device corresponding to the processing method provided in the embodiments of this application;

[0021] Figure 5 A partial structural schematic diagram of another processing device corresponding to the processing method provided in the embodiments of this application;

[0022] Figure 6 This is a schematic diagram of a processing device provided in an embodiment of this application. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0024] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0025] If the application documents contain similar descriptions such as "first, second, third", the following explanation shall be added: In the following description, the terms "first, second, third" are used only to distinguish similar objects and do not represent a specific order of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0027] To better understand the embodiments of this application, the shortcomings of the related technologies will first be explained.

[0028] When using solid state drives (SSDs) to store data, password-protected disk protection schemes or server key protection schemes are usually used to protect the data stored on the SSD. However, this means that if the SSD is disassembled, information may be stolen.

[0029] To address the problems existing in related technologies, this application provides a processing method applied to a processing device. The processing method provided in this embodiment can be implemented by a computer program, which, when executed, completes each step of the processing method provided in this embodiment. In some embodiments, the computer program can be executed by a processor in the processing device. Figure 1 A flowchart illustrating the first processing method provided in this application embodiment is shown below. Figure 1 As shown, the method includes:

[0030] Step S101: In response to the input operation command associated with the data storage, acquire biological information.

[0031] In the embodiments of this application, the data storage device can be a memory component used to store data and instructions, and can be any form of memory, such as main memory and auxiliary memory; in one feasible implementation, the data storage device can be an SSD.

[0032] The data stored in the data storage device can be any information within the processing device, such as: login account and password of any application running on the processing device, temporary data generated during the operation of any application running on the processing device, or related document information stored on the processing device.

[0033] In the embodiments of this application, the operation instructions associated with the data storage device may be sent by other devices capable of interacting with the processing device, or may be input by the user operating the processing device; at the same time, the operation instructions include, but are not limited to: decryption instructions or encryption instructions, and may also be read instructions, editing instructions (deletion instructions, change instructions or addition instructions), etc.

[0034] In this embodiment, the biometric information can be biometric information related to the user input by the user operating the processing device; wherein, the biometric information includes, but is not limited to: fingerprint information, facial information, iris information, palm print information, and voice information. It can be any one of the above biometric information, or a combination of two or more biometric information.

[0035] It should be noted that the operation instructions associated with the data storage device can be operation instructions generated by the user of the operation processing device clicking the icon associated with the data storage device.

[0036] Step S102: Transmit the biological information to the biological information controller so that the biological information controller can determine whether the biological information is successfully matched with preset information and generate a matching message.

[0037] In this embodiment, the acquired biological information is transmitted to a biological information controller. This may involve performing preliminary verification of the biological information after receiving it, and then transmitting the biological information to the biological information controller. This preliminary verification may include verifying the biological characteristics and acquisition duration of the biological information.

[0038] The processing device can collect the biological information based on an internally integrated biological information collector or a biological information collector connected to it via wired or wireless signals, and transmit the collected biological information to a biological information controller that can interact with it. At the same time, after the biological information controller receives the biological information, it uses preset information to match the biological information to determine whether the match is successful. If successful, a matching message is generated; if unsuccessful, a matching failure message is generated.

[0039] It should be noted that during the matching process between the bioinformatics controller and the biological information using preset information, the preset information can be stored internally within the bioinformatics controller, or stored in the central processor within the processing device, or in other storage devices (not shown) connected to the central processor. Simultaneously, when the preset information is stored in the central processor of the processing device or other storage devices connected to the central processor, after the bioinformatics controller obtains the biological information, it sends a request message to the central processor so that the central processor can issue the preset information.

[0040] In one feasible implementation, the bio-information controller matches bio-information with preset information, which can be done by matching the feature information of the two.

[0041] The matching message can be presented in any form, such as graphics, text, or code.

[0042] Step S103: The matching message is transmitted from the bioinformatics controller to the data storage through the target transmission channel, so that the data storage adjusts the encryption state of the internally stored data.

[0043] The target transmission channel is generated by a hardware encryption circuit integrated into the data storage and the bio-information controller.

[0044] In this embodiment of the application, after generating a matching message, the bioinformatics controller transmits the matching message to the data storage through a target transmission channel. The target transmission channel is generated by a hardware encryption circuit integrated into the data storage and the bioinformatics controller. That is, the data storage and the bioinformatics controller inside the processing device each have integrated hardware encryption circuits, and the information transmission between the data storage and the bioinformatics controller is carried out through the target transmission channel generated by the hardware encryption circuit, i.e., the encrypted transmission channel.

[0045] It should be noted that the target transmission channel generated based on hardware encryption circuitry encrypts the transmitted information; that is, the target transmission channel is an encrypted transmission channel implemented based on underlying hardware encryption circuitry. In some embodiments, the target transmission channel may also include a dedicated data connection line between the data storage device and the bioinformatics controller.

[0046] In this embodiment, the matching message transmitted between the bioinformatics controller and the data storage is transmitted through a low-level hardware encryption channel; this improves the security of data transmission. Furthermore, the encrypted transmission channel generated by the hardware encryption circuit offers a higher security level compared to the software-encrypted transmission channel. The method of information transmission through the target transmission channel is not limited in this embodiment.

[0047] It should be noted that after the data storage device receives the matching message, it will adjust the encryption state of the internally stored data based on the matching message; wherein, it may be a control unit inside the data storage device used for data security management, which adjusts the encryption state of the internally stored data in response to the matching message.

[0048] The data stored inside the data storage device can be entirely encrypted or partially encrypted. In this embodiment, based on the matching message and the operation instructions associated with the data storage device, all encrypted data in the data storage device can be decrypted, or only partially encrypted data in the data storage device can be decrypted.

[0049] In the embodiments of this application, adjusting the encryption state of data stored internally in the data storage device can be achieved by decrypting data that is currently encrypted or by encrypting data that is currently decrypted. In the following other embodiments of this application, the example described is adjusting the data stored internally in the data storage device from an encrypted state to a decrypted state.

[0050] The encryption method for data stored in the data storage device can be bio-information encryption.

[0051] It should be noted that, in this embodiment, the encryption state of the data stored inside the data storage device is adjusted based on the encrypted transmission channel generated by biometric identification and hardware encryption circuitry. Thus, a dual-layer protection scheme is adopted: biometric identification plus hardware encryption transmission, to jointly improve the security of data storage.

[0052] This application provides a processing method that, firstly, in response to an input operation command associated with a data storage device, acquires biological information; then, transmits the biological information to a biological information controller, enabling the controller to determine whether the biological information matches preset information and generate a matching message; finally, transmits the matching message from the biological information controller to the data storage device via a target transmission channel, causing the data storage device to adjust the encryption state of its internally stored data; the target transmission channel is generated by a hardware encryption circuit integrated into the data storage device and the biological information controller. This provides dual-layer protection for data storage based on biological information recognition and underlying hardware encryption, thereby improving data storage security.

[0053] Based on the foregoing embodiments, this application also provides a processing method applied to a processing device. Figure 2 A flowchart illustrating the second processing method provided in this application embodiment is shown below. Figure 1 and Figure 2 As shown, the method includes the following steps:

[0054] Step S201: In response to the input operation command, determine the preset information for encrypting the stored data in the data memory.

[0055] In this embodiment of the application, the processing device responds to the input operation command and determines preset information for encrypting the data stored in the data memory associated with the operation command; wherein, the operation command may be sent to the processing center of the processing device, that is, the central processor of the processing device, also known as the central processing unit (CPU), and the preset information for encrypting the data stored in the data memory is determined based on the central processor.

[0056] The preset information for encrypting the stored data in the data storage device can refer to the verification information required when performing operations such as reading, modifying, adding, or deleting the stored data. This preset information can be a password, biometric information, etc.

[0057] Step S202: In response to the preset information including biological characteristics, start the biological information collector to collect the biological information.

[0058] In this embodiment of the application, in response to the preset information including biometrics, that is, when the processing device determines that the information used to encrypt the data stored in the data storage device is information carrying biometrics, the biometric information collector is activated to collect biometric information.

[0059] In one feasible implementation, the biometric data collector can be a sensor within a processing device used to collect biometric information. For example, when the biometric information is fingerprint information, the biometric data collector can be a fingerprint sensor.

[0060] In another feasible implementation, the bio-information collector can be an image acquisition device in the processing device. For example, when the bio-information is facial information, the bio-information collector can be a camera device in the processing device.

[0061] It should be noted that when the processing device starts the bio-information collector to collect bio-information, it is usually set with a preset collection time and preset bio-features. When information matching the preset bio-features is obtained within the preset collection time, the information is identified as the acquired bio-information; if the preset time is not reached and / or the input bio-features do not match the preset bio-features, it will be assumed that no valid bio-information has been obtained.

[0062] In this embodiment of the application, a preset information for encrypting the stored data in the data storage device is used to determine whether to activate the bioinformatics collector to collect bioinformatics; thus, the accuracy and efficiency of obtaining bioinformatics can be improved.

[0063] Here, the acquired biological information is transmitted to the biological information controller so that the biological information controller can verify the biological information. That is, step S102 provided in the above embodiment can be implemented by the following steps S203 and S204:

[0064] Step S203: In the bio-information controller, the preset information is matched with the bio-information to determine whether the bio-information matches the preset information successfully.

[0065] In this embodiment of the application, the bio-information controller is used to perform feature matching between preset information and acquired bio-information to determine whether the bio-information matches the preset information successfully.

[0066] Step S204: In response to the successful matching of the biological information with the preset information, generate the matching message.

[0067] In this embodiment of the application, after the biological information is successfully matched with the preset information, a matching message corresponding to the successful match can be generated; at the same time, after the biological information fails to match the preset information, a matching failure message corresponding to the failed match can also be generated.

[0068] Here, the bio-information controller matches the acquired bio-information with preset information, which is the information used to encrypt the data stored inside the data storage device. This allows bio-information identification to be performed before any operations are performed on the data stored inside the data storage device, thereby improving the security of data storage.

[0069] Simultaneously, after generating the matching message, the bioinformatics controller transmits the matching message to the data storage device through a specific transmission channel, such as a transmission channel generated by a hardware encryption circuit, so that the data storage device can adjust the encryption state of the internally stored data; thus, transmitting the corresponding message based on the transmission channel generated by the hardware encryption circuit can further improve the security of data storage. That is, step S103 provided in the above embodiment can be implemented by the following step S205:

[0070] Step S205: After the matching message is transmitted from the bio-information controller to the data storage through the target transmission channel, in response to the data storage receiving the matching message, the stored data in the data storage is adjusted to be in a decrypted state.

[0071] In this embodiment, the matching message is transmitted between the bioinformatics controller and the data storage via a target transmission channel generated by the hardware encryption circuit. Simultaneously, after the data storage receives the matching message, it adjusts the data stored inside to a decrypted state based on the matching message, so that the data in the decrypted state can be operated on subsequently based on the operation instructions.

[0072] It should be noted that in this embodiment, a target transmission channel generated based on a hardware encryption circuit is used to transmit the matching message, which ensures the security of the matching message transmission. Furthermore, the encrypted transmission channel generated based on the hardware encryption circuit has a higher security level than a software-based encrypted transmission channel. Thus, responding to operation instructions on the data stored internally in the data storage device while simultaneously performing biometric identification and transmitting the relevant biometric results through the encrypted transmission channel corresponding to the hardware encryption circuit improves the security of the data stored in the data storage device.

[0073] The processing method provided in this application embodiment, in response to an operation instruction associated with the data storage device, first performs biometric identification based on the biometric controller, and then transmits the biometric identification result through an encrypted transmission channel generated by the hardware encryption circuit; thus, the dual protection based on biometric identification and the hardware encryption channel can improve the security of the data stored in the data storage device.

[0074] Based on the foregoing embodiments, this application also provides a processing method applied to a processing device. Figure 3 A flowchart illustrating the third processing method provided in this application embodiment is shown below. Figure 1 and Figure 3 As shown, the method includes the following steps:

[0075] If the stored data in the data storage device includes account data matching the application identifier, the acquisition of biometric information in response to an input operation command associated with the data storage device can be achieved through the following steps S301:

[0076] Step S301: In response to an input read instruction associated with the data storage and carrying the application identifier, the biological information is obtained.

[0077] In this embodiment of the application, the biometric information is obtained in response to an input read instruction associated with the data storage device and carrying an application identifier; wherein, the read instruction is a read instruction for reading account data inside the data storage device that matches the application identifier.

[0078] The application identifier can be any information associated with the application. Meanwhile, the account data matching the application identifier can include the login account and password used before running the application.

[0079] Here, the biological information obtained in step S301 can be transmitted to the biological information controller, that is, step S102 provided in the aforementioned embodiment is executed, that is, the biological information is transmitted to the biological information controller so that the biological information controller can determine whether the biological information is successfully matched with the preset information and generate a matching message.

[0080] Simultaneously, the processing device executes step S103, which involves transmitting the matching message from the bioinformatics controller to the data storage via the target transmission channel to adjust the encryption state of the stored data in the data storage. This can be achieved through the following step S302:

[0081] Step S302: The matching message is transmitted from the biometric controller to the data storage through the target transmission channel, so that the data storage adjusts the account data stored internally that matches the application identifier to account data in a decrypted state.

[0082] In this embodiment, the matching message is transmitted via a target transmission channel between the bioinformatics controller and the data storage device, so that the data storage device can obtain the matching message and then adjust the encryption status of the account data that matches the application identifier stored internally based on the matching message, for example, adjusting the account data that is in an encrypted state to the account data that is in a decrypted state.

[0083] It should be noted that, in the embodiments of this application, the decryption of some data inside the data storage device can be achieved based on biometric identification and an encrypted transmission channel generated by hardware encryption circuitry; thus, the security of data stored in the data storage device can be improved.

[0084] In one feasible implementation, after the processing device performs the above step S302, that is, after adjusting the account data matching the application identifier to account data in a decrypted state, it can also perform the following step S303:

[0085] Step S303: Based on the read instruction, read the account data in the data storage that is in the decrypted state.

[0086] In this embodiment, the processing device can also read account data that is already in a decrypted state based on the read instruction. Correspondingly, when the operation instruction is an editing instruction, including a change operation, a deletion operation, or an addition operation, the account data in the decrypted state can be changed, deleted, or added accordingly.

[0087] It should be noted that, in this embodiment, in response to a read instruction for account data matching the application identifier in the data storage, the account data matching the application identifier in the data storage can be decrypted based on the biometric identification and the encrypted transmission channel generated by the hardware encryption circuit, and the account data can be read based on the read instruction. This improves the security of storing account data matching the application identifier.

[0088] In one feasible implementation, the biometric information obtained in the processing method provided in this application embodiment may include at least one of the following: fingerprint information, facial information, iris information, palm print information, and voice information.

[0089] In this embodiment of the application, data stored inside the data storage device is protected based on various biological information, which can improve the security of data storage.

[0090] Based on this, such as Figure 4 The diagram shown is a partial structural schematic of a processing device corresponding to the processing method provided in the embodiments of this application; wherein, 401 is a bio-information collector, 402 is a bio-information controller, 403 is a data storage device, and 404 is a central processor; wherein, 402 and 403 can respectively interact with 404.

[0091] Based on the processing method provided in this application embodiment, where 401 is a fingerprint sensor, 402 is a fingerprint controller, 403 can be an SSD, and 404 is a central processor (CPU), a hardware encryption channel can be established between 402 and 403 to achieve information communication between them. Specifically, a hardware encryption circuit is integrated into both 402 and 403. The encryption channel also includes a dedicated data connection line between the data storage device and the biometric controller.

[0092] Based on this, when the processing device receives a user's operation command for 403, and 403 is a fingerprint-encrypted data storage device, 401 will acquire the fingerprint information input by the user and transmit it to 402. Simultaneously, 402 will compare this fingerprint information, possibly with pre-stored encrypted fingerprint information, and after a successful comparison, will transmit the comparison result to the SSD in 403 via a hardware encryption channel. The SSD's internal data security management unit 4031 will adjust the data stored in the corresponding space according to the operation command. That is, 402 will handshake with 403 through a hardware handshake channel, and then 403 will release the encrypted space to achieve the decryption operation of the SSD's internal space. 403 may include multiple data storage units.

[0093] Thus, the internal storage data in SSD 403 is in a decrypted state, and the user can view the contents of SSD space in SSD 403. When the user closes SSD 403, SSD automatically re-enters encrypted state, awaiting the next decryption operation. Furthermore, if SSD is removed from the device, the removed SSD lacks the fingerprint handshake protocol communication component, ensuring that the encrypted space selected by the user cannot be stolen, and the data remains securely stored within the SSD space.

[0094] If a user requests to open part of the SSD space in 403, the corresponding unlock interface will pop up based on the above operations, requiring the user to unlock the encrypted space in 403 with their fingerprint.

[0095] It should be noted that the data stored in a portion of the SSD space in the 403 can be encrypted in advance, or the data stored in the entire space can be encrypted. Furthermore, the hardware encryption circuitry in the 403 can also be integrated into the corresponding circuitry of the data security management unit 4031.

[0096] Based on the above example, by establishing a fingerprint recognition and encryption hardware channel between 402 and 403, the security of data stored internally in the SSD can be improved. Simultaneously, it ensures that the encrypted space remains secure even after the SSD is disassembled, protecting user privacy. This, in turn, enhances data storage security and user experience through ease of operation.

[0097] In related technologies, fingerprint information can be used to implement system login solutions, including website login and various account logins. However, when fingerprints replace password logins, it is necessary to record the user's website account and password, as well as account information for other applications. The security of this sensitive information is extremely important; once leaked, it poses a significant threat to user privacy. Therefore, such as... Figure 5 The diagram shown is a partial structural schematic of another processing device corresponding to the processing method provided in the embodiments of this application; it can be used to achieve secure storage of user privacy data.

[0098] Among them, based on Figure 4 As shown, Figure 4 The 402 and 403 are integrated in the same device, such as Figure 5 As shown, the system includes a fingerprint sensor 501, a security controller 502, and a central processor 503. The security controller 502 includes a fingerprint controller 5021 and an encrypted memory 5022. Furthermore, the fingerprint controller 5021 and the encrypted memory 5022 can communicate via a hardware encrypted channel.

[0099] When the encrypted storage 5022 stores the user-confirmed fingerprint login URL and user login account information, in response to receiving a user's read instruction for the URL-related information, 501 acquires the fingerprint information input by the user and transmits the fingerprint information to 502 so that the fingerprint controller 5021 in 502 can match the fingerprint. After successful fingerprint matching, the controller retrieves the corresponding data from 5022, i.e., performs URL matching. After successful URL matching, the controller reads the user login account information corresponding to the URL. The user login account information includes, but is not limited to, username and password.

[0100] In 502, the fingerprint controller 5021 communicates with the encrypted storage through a hardware encryption channel; it can also store the user's password in the encrypted storage controller through the hardware encryption channel when the user chooses fingerprint login instead of account password login.

[0101] In one embodiment, encapsulating the fingerprint controller and the encryption memory into a single chip, such as a security controller, can further improve data storage security.

[0102] Based on the foregoing embodiments, this application also provides a processing device 600, which can be applied to... Figures 1 to 3 In one processing method provided in the corresponding embodiment, referring to Figure 6 As shown, the processing device may include: an interface 601, a bio-information collector 602, a bio-information controller 603, and a data storage device 604, wherein:

[0103] Interface 601 is used to receive operation instructions associated with the data storage;

[0104] The bioinformation collector 602 is used to acquire bioinformation in response to the operation command sent by the interface;

[0105] The bio-information controller 603 is used to receive the bio-information sent by the bio-information collector, determine whether the bio-information matches the preset information, and generate a matching message.

[0106] Data storage 604 is used to adjust the encryption state of internally stored data in response to the matching message transmitted through the target transmission channel;

[0107] The target transmission channel is generated by a hardware encryption circuit integrated into the data storage and the bio-information controller.

[0108] In some embodiments, the bioinformatics controller and data storage within the processing device can be integrated into the same device; that is, the bioinformatics controller and data storage are packaged in a single chip. This further improves the security of data storage in the data storage and saves space within the processing device.

[0109] In some embodiments, the bioinformatics controller integrates hardware circuitry for data encryption, while the data storage integrates hardware circuitry for data decryption.

[0110] The bioinformatics controller encrypts the generated matching message using internal hardware circuitry for data encryption, and transmits the encrypted matching message to the data storage via a target transmission channel generated by the hardware encryption circuitry integrated into the data storage and the bioinformatics controller. Upon receiving the encrypted matching message, the data storage decrypts it using internal hardware circuitry for data decryption, enabling subsequent operations based on the matching message, such as decrypting encrypted data using internal hardware circuitry for data control.

[0111] In some embodiments, the matching message is first encrypted and then transmitted using an encrypted transmission channel generated based on hardware encryption circuitry, which can further improve the security of the matching message transmission.

[0112] It should be noted that the specific implementation process of the steps performed by each component in this embodiment can be referred to Figures 1 to 3 The implementation process of the processing method provided in the corresponding embodiments will not be described in detail here.

[0113] The processing apparatus provided in this application embodiment performs biometric identification based on a biometric controller and transmits the biometric identification results through a target transmission channel generated by a hardware encryption circuit integrated into the data storage and the biometric controller, thereby enabling operations on the data stored in the data storage. In this way, based on biometric identification and underlying hardware encryption transmission, dual-layer protection is provided for data storage, thereby improving the security of data storage.

[0114] Based on the foregoing embodiments, embodiments of this application provide a computer-readable storage medium storing one or more programs, which can be executed by one or more processors to achieve the following: Figures 1 to 3 The corresponding implementation provides the processing method.

[0115] It should be noted that the aforementioned computer-readable storage media can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc-read-only memory (CD-ROM), etc.; or it can be various electronic devices that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0116] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0117] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0119] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0120] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0121] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0122] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A processing method, the method comprising: Responding to input operation commands associated with the data storage, biological information is acquired; The operation instructions include at least: decryption instructions, encryption instructions, read instructions, or edit instructions; The biological information is transmitted to a biological information controller, which then determines whether the biological information matches preset information and generates a matching message. The matching message is transmitted from the bioinformatics controller to the data storage via a target transmission channel, so that the data storage adjusts the encryption state of the internally stored data; the target transmission channel is an encrypted transmission channel generated based on the hardware encryption circuit of the data storage and the hardware encryption circuit of the bioinformatics controller, and the data storage and the bioinformatics controller are packaged in the same chip.

2. The method according to claim 1, wherein acquiring biological information in response to an input operation instruction associated with the data storage includes: In response to the input operation command, the preset information for encrypting the stored data in the data memory is determined; In response to the preset information including biometrics, the biometric information collector is activated to collect the biometric information.

3. The method according to claim 2, wherein transmitting the biological information to a biological information controller, so that the biological information controller determines whether the biological information successfully matches preset information and generates a matching message, includes: In the bio-information controller, the preset information is matched with the bio-information to determine whether the bio-information matches the preset information successfully; In response to a successful match between the biological information and the preset information, the matching message is generated.

4. The method according to claim 1, wherein transmitting the matching message from the bioinformatics controller to the data storage via a target transmission channel, so as to adjust the encryption state of the internally stored data in the data storage, comprises: After the matching message is transmitted from the bioinformatics controller to the data storage via the target transmission channel, in response to the data storage receiving the matching message, the stored data in the data storage is adjusted to be in a decrypted state.

5. The method according to claim 1, wherein the stored data in the data storage device includes account data matching the application identifier, the step of acquiring biometric information in response to an input operation instruction associated with the data storage device includes: In response to an input read command associated with the data storage and carrying the application identifier, the biological information is acquired; The step of transmitting the matching message from the bioinformatics controller to the data storage via the target transmission channel to adjust the encryption state of the stored data in the data storage includes: The matching message is transmitted from the biometric controller to the data storage via the target transmission channel, so that the data storage adjusts the account data stored internally that matches the application identifier to account data in a decrypted state.

6. The method according to claim 5, further comprising: Based on the read instruction, the account data in the decrypted state in the data storage is read.

7. The method according to any one of claims 1 to 6, wherein the biometric information includes at least one of the following: fingerprint information, facial information, iris information, palm print information, and voice information.

8. A processing apparatus, comprising: An interface for receiving operation commands associated with the data storage; The operation instructions include at least: decryption instructions, encryption instructions, read instructions, or edit instructions; A bioinformatics collector is used to acquire bioinformatics in response to the operation command sent by the interface; A bioinformatics controller is used to receive the bioinformatics sent by the bioinformatics collector, determine whether the bioinformatics successfully matches preset information, and generate a matching message. A data storage device for adjusting the encryption state of internally stored data in response to the matching message transmitted through the target transmission channel; The target transmission channel is an encrypted transmission channel generated based on the hardware encryption circuit of the data storage device and the hardware encryption circuit of the bioinformatics controller, wherein the data storage device and the bioinformatics controller are packaged in the same chip.

9. The apparatus according to claim 8, wherein the bioinformatics controller integrates hardware circuitry for data encryption; and the data storage unit integrates hardware circuitry for data decryption.

Citation Information

Patent Citations

  • AES-based network information encryption IP core design and implementation method

    CN105933106A

  • Content encryption method and device and electronic equipment

    CN112270004A