A password verification method, a solid-state drive, and a host computer

By using asymmetric key encryption technology and random number processing between solid-state drives and host computers, the problem of insufficient security of password verification mechanism in the existing technology is solved, and protection against playback attacks and man-in-the-middle attacks is achieved, and the security of user data is improved.

CN114297673BActive Publication Date: 2025-07-11HEFEI DATANG STORAGE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111543549.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-07-11
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

The password verification mechanism of existing solid-state drives is poor in security and cannot prevent replay attacks and man-in-the-middle attacks. Especially in the TCG OPAL standard, the security strength of the password verification mechanism and PIN verification process is low.

Method used

Asymmetric key encryption technology is used to protect the public key and public key signature by exchanging passwords between the solid-state drive and the host computer, random numbers are generated for ciphertext password verification, and reverse security processing is performed to obtain plaintext passwords, combining random numbers and logical operations to prevent playback attacks.

Benefits of technology

Improve the security of password verification, prevent man-in-the-middle attacks and replay attacks, and enhance the protection ability of user data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297673B_ABST
    Figure CN114297673B_ABST
Patent Text Reader

Abstract

An embodiment of the present application discloses a password verification method, a solid-state drive, and a host computer. The method includes: after the solid-state drive is placed in the host computer, sending the initial verification data stored in the solid-state drive during the card opening stage of the solid-state drive to the host computer; the initial verification data includes: a password protection public key and a password protection public key signature; so that the host computer verifies the legality of the password protection public key; when the verification result is that the password protection public key is legal, generating a random number according to the instruction of the host computer and sending the random number to the host computer, so that the host computer verifies the encrypted password verification data according to the random number; receiving the encrypted password verification data sent by the host computer, and decrypting according to the password verification data and the password protection private key to obtain password processing data; performing reverse security processing on the password processing data to obtain the plaintext password. Through the solution of this embodiment, the security of the password verification process is improved, man-in-the-middle attacks can be prevented, and replay attacks can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of solid - state drives, and particularly to a password verification method, a solid - state drive, and a host computer. Background Art

[0002] In solid - state drive products, user passwords are used for access control of user data. Currently, the security standard in the field of solid - state drives is TCG OPAL. The password verification mechanism in this standard has poor security. It only performs pbkdf (a hash operation that can be calculated multiple times) processing on user passwords and cannot prevent replay attacks and man - in - the - middle attacks. In addition, the PIN (Personal Identification Number) verification process of other products uses a symmetric encryption algorithm, with low security strength and is easily cracked. Summary of the Invention

[0003] Embodiments of the present application provide a password verification method, a solid - state drive, and a host computer, which can improve the security of the password verification process, prevent man - in - the - middle attacks, and prevent replay attacks.

[0004] Embodiments of the present application provide a password verification method applied to the solid - state drive side. The method may include:

[0005] After the solid - state drive is placed in the host computer, send the initial verification data stored in the solid - state drive during the card - opening stage to the host computer; the initial verification data includes: a password - protected public key and a password - protected public key signature; so that the host computer verifies the legality of the password - protected public key;

[0006] When the verification result of the host computer is that the password - protected public key is legal, generate a random number according to the received instruction of the host computer, and send the random number to the host computer, so that the host computer verifies the ciphertext password verification data according to the random number;

[0007] Receive the ciphertext password verification data sent by the host computer, and decrypt it according to the password verification data and the password - protected private key to obtain the password processing data;

[0008] Perform reverse security processing on the password processing data to obtain the plain - text password.

[0009] In an exemplary embodiment of the present application, after obtaining the plain - text password, the method may further include:

[0010] Check the strength of the personal identification number (PIN) of the plain - text password; and,

[0011] Compare the obtained plain - text password with the plain - text password stored in the solid - state drive itself.

[0012] In an exemplary embodiment of the present application, the reverse security processing of the password processing data may include:

[0013] Using the random number as a key to decrypt the password processing data; or,

[0014] Performing a preset logical operation on the random number and the password processing data; the logical operation includes an exclusive OR operation.

[0015] In an exemplary embodiment of the present application, the method may further include:

[0016] After the solid-state drive is powered on for the first time, generating a password-protected asymmetric key pair and storing it in the solid-state drive; the password-protected asymmetric key pair includes: a password-protected public key and a password-protected private key.

[0017] In an exemplary embodiment of the present application, the method may further include:

[0018] Sending the password-protected asymmetric key pair and the first hard disk serial number stored in the solid-state drive itself to a preset card-opening tool, so that the card-opening tool sends the password-protected public key and the first hard disk serial number to a preset server, and using the root private key stored in the server itself to sign the password-protected public key and the first hard disk serial number to obtain the password-protected public key signature;

[0019] Receiving the initial verification data returned by the card-opening tool; the initial verification data includes: the password-protected public key signature.

[0020] An embodiment of the present application also provides a solid-state drive, which may include a first processor and a first computer-readable storage medium. Instructions are stored in the first computer-readable storage medium, and when the instructions are executed by the first processor, the password verification method applied to the solid-state drive side described in any one of the above is implemented.

[0021] An embodiment of the present application also provides a password verification method, which is applied to the host computer side. The method includes:

[0022] Obtaining, from the solid-state drive, the initial verification data stored in the solid-state drive during the card-opening stage of the solid-state drive; the initial verification data includes: a password-protected public key and a password-protected public key signature;

[0023] Verifying the legitimacy of the password-protected public key;

[0024] When the verification result is that the password-protected public key is legal, obtaining a random number from the solid-state drive; the random number is generated by the solid-state drive according to the received instruction;

[0025] Perform security processing on the random number and a preset plaintext password to obtain password processing data;

[0026] Encrypt the password processing data using the password protection public key to obtain ciphertext password verification data;

[0027] Send the ciphertext password verification data to the solid-state drive, so that the solid-state drive decrypts the ciphertext password verification data according to the password protection private key, obtains the password processing data, and performs reverse security processing on the password processing data to obtain the plaintext password.

[0028] In an exemplary embodiment of the present application, the initial verification data may further include: a first hard disk serial number; before obtaining the random number from the solid-state drive, the method may further include:

[0029] Compare the obtained first hard disk serial number with a second hard disk serial number set on the pre-stored solid-state drive; determine whether the first hard disk serial number is consistent with the second hard disk serial number.

[0030] In an exemplary embodiment of the present application, the initial verification data may further include: when the verification result is that the password protection public key is illegal, exit the operation process of the solid-state drive.

[0031] In an exemplary embodiment of the present application, the performing security processing on the random number and a preset plaintext password may include:

[0032] Use the random number as a key to encrypt the plaintext password; or,

[0033] Perform a preset logical operation on the random number and the plaintext password; the logical operation includes an exclusive OR operation.

[0034] An embodiment of the present application further provides a host computer, which may include a second processor and a second computer-readable storage medium. Instructions are stored in the second computer-readable storage medium. When the instructions are executed by the second processor, the password verification method applied to the host computer side described in any one of the above is implemented.

[0035] Compared with the related art, the embodiments of the present application may include: after the solid-state drive is placed in the host computer, sending the initial verification data stored in the solid-state drive during the card opening stage of the solid-state drive to the host computer; the initial verification data includes: a password protection public key and a password protection public key signature; so that the host computer verifies the legality of the password protection public key; when the verification result of the host computer is that the password protection public key is legal, generating a random number according to the received instruction of the host computer, and sending the random number to the host computer, so that the host computer verifies the ciphertext password verification data according to the random number; receiving the ciphertext password verification data sent by the host computer, and decrypting according to the password verification data and the password protection private key to obtain the password processing data; performing reverse security processing on the password processing data to obtain the plaintext password. Through the solution of this embodiment, the security of the password verification process is improved, man-in-the-middle attacks can be prevented, and replay attacks can be prevented.

[0036] Other features and advantages of the embodiments of the present application will be described in the following description, and, in part, will be obvious from the description, or will be understood by implementing the present application. Other advantages of the present application can be realized and obtained through the solutions described in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The drawings are used to provide an understanding of the technical solutions of the present application, and constitute a part of the description, and are used together with the embodiments of the present application to explain the technical solutions of the present application, and do not constitute a limitation to the technical solutions of the present application.

[0038] Figure 1 It is a flowchart of the password verification method applied to the solid-state drive side in the embodiments of the present application;

[0039] Figure 2 It is a block diagram of the composition of the solid-state drive in the embodiments of the present application;

[0040] Figure 3 It is a flowchart of the password verification method applied to the host computer side in the embodiments of the present application;

[0041] Figure 4 It is a block diagram of the composition of the host computer in the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] This application describes multiple embodiments, but the description is exemplary rather than restrictive, and it will be obvious to those of ordinary skill in the art that there can be more embodiments and implementation solutions within the scope covered by the embodiments described in this application. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically restricted, any feature or element of any embodiment can be combined with any other feature or element in any other embodiment, or can replace any other feature or element in any other embodiment.

[0043] This application includes and contemplates combinations with features and elements known to those of ordinary skill in the art. The embodiments, features, and elements disclosed in this application can also be combined with any conventional features or elements to form unique inventive solutions defined by the claims. Any feature or element of any embodiment can also be combined with features or elements from other inventive solutions to form another unique inventive solution defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this application can be implemented alone or in any suitable combination. Therefore, the embodiments are not subject to other limitations except those made in accordance with the appended claims and their equivalents. In addition, various modifications and changes can be made within the scope of the appended claims.

[0044] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not depend on the specific order of the steps described herein, the method or process should not be limited to the specific order of steps described. As will be understood by those of ordinary skill in the art, other step orders are possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation on the claims. In addition, the claims directed to the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can easily understand that these orders can vary and still remain within the spirit and scope of the embodiments of this application.

[0045] The embodiments of this application provide a password verification method, which is applied to the solid-state drive side. As Figure 1 shown, the method may include steps S101 - S104:

[0046] S101. After the solid-state drive is placed in the host computer, send the initial verification data stored in the solid-state drive during the card opening stage of the solid-state drive to the host computer; the initial verification data includes: a password protection public key and a password protection public key signature; so that the host computer verifies the legitimacy of the password protection public key;

[0047] S102. When the verification result of the host computer indicates that the password-protected public key is legal, generate a random number according to the instruction received from the host computer, and send the random number to the host computer so that the host computer verifies the data with the ciphertext password based on the random number;

[0048] S103. Receive the ciphertext password verification data sent by the host computer, and decrypt it according to the password verification data and the password-protected private key to obtain the password processing data;

[0049] S104. Perform reverse security processing on the password processing data to obtain the plaintext password.

[0050] In an exemplary embodiment of the present application, the method may further include:

[0051] After the solid-state drive is powered on for the first time, generate a password-protected asymmetric key pair and save it in the solid-state drive; the password-protected asymmetric key pair includes: a password-protected public key and a password-protected private key.

[0052] In an exemplary embodiment of the present application, the solid-state drive needs to perform a card-opening operation when leaving the factory. After the solid-state drive is powered on for the first time, a pair of password-protected asymmetric key pairs, such as SM2 key pairs, are generated and saved in the solid-state drive.

[0053] In an exemplary embodiment of the present application, the method may further include:

[0054] Send the password-protected asymmetric key pair and the first hard disk serial number stored in the solid-state drive itself to a preset card-opening tool, so that the card-opening tool sends the password-protected public key and the first hard disk serial number to a preset server, and use the root private key stored in the server itself to sign the password-protected public key and the first hard disk serial number to obtain the password-protected public key signature;

[0055] Receive the initial verification data returned by the card-opening tool; the initial verification data includes: the password-protected public key signature.

[0056] In an exemplary embodiment of the present application, the solid-state drive performs a card opening operation at the time of leaving the factory, mainly for importing the password protection public key signature. The card opening tool obtains the password protection public key and the solid-state drive serial number (i.e., the above-mentioned first hard disk serial number) from the solid-state drive, and sends the password protection public key and the first hard disk serial number to a preset server, so that the server uses the root private key (the root private key is generally stored in the server, and the root public key is stored in the card opening tool) to sign the password protection public key and the first hard disk serial number and then return them to the card opening tool. The root key pair (which may include the root public key and the root private key) is the key pair of a company or a product. Generally, when signing, the password protection public key and the serial number (i.e., the first hard disk serial number) can be subjected to a hash operation to obtain a hash value, and then the hash value is signed.

[0057] In an exemplary embodiment of the present application, when the card opening tool imports the password protection public key signature into the solid-state drive, the card opening ends.

[0058] In an exemplary embodiment of the present application, during the use stage of the solid-state drive, the program of the host computer can obtain the password protection public key, the hard disk serial number (i.e., the above-mentioned first hard disk serial number), and the password protection public key signature from the solid-state drive. The host computer here can be a host system program or a BIOS (Basic Input / Output System), etc.

[0059] In an exemplary embodiment of the present application, the program of the host computer can use the root public key to verify the legality of the obtained password protection public key [Generally, the hard disk serial number read (i.e., the above-mentioned first hard disk serial number) can also be compared with the hard disk serial number (the second hard disk serial number) pasted on the solid-state drive to further ensure the information source.]. If the verification of the password protection public key fails, it means that the solid-state drive is an illegal solid-state drive or there is a risk of man-in-the-middle attack. At this time, the operation process of the solid-state drive can be exited. If the verification of the password protection public key passes, it means that the solid-state drive is a legal solid-state drive and there is no man-in-the-middle attack.

[0060] In an exemplary embodiment of the present application, after verifying that the solid-state drive is a legal solid-state drive, the host computer obtains a random number from the solid-state drive. The random number can be generated after the solid-state drive receives an instruction and is temporarily stored in the RAM (Random Access Memory) of the solid-state drive; the host computer can perform security processing on the random number and the plaintext password. For example, use the random number as a key to encrypt the plaintext password; or perform an exclusive OR operation on the random number and the plaintext password, etc., to obtain password processing data. The host computer encrypts the obtained password processing data with the password protection public key to obtain encrypted password verification data (denoted as ciphertext password verification data); the host computer sends the ciphertext password verification data to the solid-state drive.

[0061] In an exemplary embodiment of the present application, after receiving the ciphertext password verification data, the solid-state drive decrypts the ciphertext password verification data using the password-protected private key. If the decryption fails, the current usage process of the solid-state drive is terminated; if the decryption is successful and password processing data is obtained, then reverse security processing is performed on the password processing data according to the random number stored in the RAM.

[0062] In an exemplary embodiment of the present application, the reverse security processing of the password processing data may include:

[0063] Using the random number as a key to decrypt the password processing data; or,

[0064] Performing a preset logical operation on the random number and the password processing data; the logical operation includes an exclusive OR operation.

[0065] In an exemplary embodiment of the present application, a plaintext password (or plaintext user password) can be obtained by performing reverse security processing on the password processing data.

[0066] In an exemplary embodiment of the present application, after obtaining the plaintext password, the method may further include:

[0067] Checking the strength of the personal identification number (PIN) of the plaintext password; and,

[0068] Comparing the obtained plaintext password with the plaintext password stored in the solid-state drive itself.

[0069] In an exemplary embodiment of the present application, as needed, the solid-state drive can perform security processing such as weak PIN [Personal Identification Number, which refers to the personal identification password of the SIM (Subscriber Identity Module) card] check on the obtained plaintext password; it can also perform a plaintext password comparison operation on the solid-state drive. Generally, the plaintext password is stored in the solid-state drive after being hashed, so during comparison, the plaintext password of the user can be hashed first, and then compared with the hash value corresponding to the plaintext password stored in the solid-state drive. This comparison process can be implemented according to the existing comparison algorithms. Thus, the verification process of the user's plaintext password is completed.

[0070] An embodiment of the present application also provides a solid-state drive 1, as Figure 2 shown, which may include a first processor 11 and a first computer-readable storage medium 12. Instructions are stored in the first computer-readable storage medium 12, and when the instructions are executed by the first processor 11, the password verification method applied to the solid-state drive side described in any one of the above is implemented.

[0071] In an exemplary embodiment of the present application, any of the foregoing password verification methods applied to the solid-state drive side is applicable to this solid-state drive embodiment, and will not be elaborated herein one by one.

[0072] An embodiment of the present application further provides a password verification method, which is applied to the host side, as Figure 3 shown, the method may include steps S201-S206:

[0073] S201. Obtain initial verification data stored in the solid-state drive during the card-opening stage of the solid-state drive from the solid-state drive; the initial verification data includes: a password protection public key and a password protection public key signature;

[0074] S202. Verify the legitimacy of the password protection public key;

[0075] S203. When the verification result is that the password protection public key is legal, obtain a random number from the solid-state drive; the random number is generated by the solid-state drive according to the received instruction;

[0076] S204. Perform security processing on the random number and a preset plaintext password to obtain password processing data;

[0077] S205. Encrypt the password processing data using the password protection public key to obtain ciphertext password verification data;

[0078] S206. Send the ciphertext password verification data to the solid-state drive, so that the solid-state drive decrypts the ciphertext password verification data according to the password protection private key, obtains the password processing data, and performs reverse security processing on the password processing data to obtain the plaintext password.

[0079] In an exemplary embodiment of the present application, during the use stage of the solid-state drive, the program of the host can obtain the password protection public key, the hard disk serial number (i.e., the foregoing first hard disk serial number), and the password protection public key signature from the solid-state drive. The host here can be a host system program or a BIOS (Basic Input / Output System), etc.

[0080] In an exemplary embodiment of the present application, the program of the host can verify the legitimacy of the obtained password protection public key using the root public key. If the verification of the legitimacy of the password protection public key fails, it indicates that the solid-state drive is an illegal solid-state drive or there is a risk of man-in-the-middle attack. At this time, the operation process of the solid-state drive can be exited. If the verification of the password protection public key passes, it indicates that the solid-state drive is a legal solid-state drive and there is no man-in-the-middle attack.

[0081] In an exemplary embodiment of the present application, the initial verification data may further include: the first hard disk serial number; before obtaining the random number from the solid-state drive, the method may further include:

[0082] Compare the obtained first hard disk serial number with the second hard disk serial number set on the pre-stored solid-state drive; determine whether the first hard disk serial number is consistent with the second hard disk serial number.

[0083] In an exemplary embodiment of the present application, generally, when verifying the legality of the obtained password-protected public key, it can also be compared by the read hard disk serial number (i.e., the above-mentioned first hard disk serial number) and the hard disk serial number (second hard disk serial number) pasted on the solid-state drive to further ensure the information source.

[0084] In an exemplary embodiment of the present application, the initial verification data may further include: when the verification result is that the password-protected public key is illegal, exit the operation process for the solid-state drive.

[0085] In an exemplary embodiment of the present application, if the verification of the password-protected public key fails, it indicates that the solid-state drive is an illegal solid-state drive or there is a risk of man-in-the-middle attack. At this time, the operation process can be exited.

[0086] In an exemplary embodiment of the present application, if the verification of the password-protected public key passes, it indicates that the solid-state drive is a legal solid-state drive and there is no man-in-the-middle attack. After verifying that the solid-state drive is a legal solid-state drive, the host computer obtains a random number from the solid-state drive. This random number can be generated after the solid-state drive receives the instruction and will be temporarily stored in the RAM (random access memory) of the solid-state drive; the host computer can perform a security process on this random number and the plaintext password.

[0087] In an exemplary embodiment of the present application, the security process of the random number and the preset plaintext password may include:

[0088] Use the random number as a key to encrypt the plaintext password; or,

[0089] Perform a preset logical operation on the random number and the plaintext password; the logical operation includes an exclusive OR operation.

[0090] In an exemplary embodiment of the present application, after the host computer performs a security process on the random number and the plaintext password, password processing data can be obtained. The host computer encrypts the obtained password processing data with the password-protected public key to obtain the encrypted password verification data (denoted as ciphertext password verification data); the host computer sends the ciphertext password verification data to the solid-state drive.

[0091] In an exemplary embodiment of the present application, after the solid-state drive receives the ciphertext password verification data, it decrypts the ciphertext password verification data using the password-protected private key. If the decryption fails, the current usage process of the solid-state drive is exited; if the decryption is successful and password processing data is obtained, then reverse security processing is performed on the password processing data according to the random number stored in the RAM.

[0092] In an exemplary embodiment of the present application, the reverse security processing of the password processing data may include:

[0093] Using the random number as a key to decrypt the password processing data; or,

[0094] Performing a preset logical operation on the random number and the password processing data; the logical operation includes an exclusive OR operation.

[0095] In an exemplary embodiment of the present application, the plaintext password (or plaintext user password) can be obtained by performing reverse security processing on the password processing data.

[0096] In an exemplary embodiment of the present application, after obtaining the plaintext password, the method may further include:

[0097] Checking the strength of the personal identification number PIN of the plaintext password; and,

[0098] Comparing the obtained plaintext password with the plaintext password stored in the solid-state drive itself.

[0099] In an exemplary embodiment of the present application, as needed, the solid-state drive can perform security processing such as weak PIN checking on the obtained plaintext password; it can also perform a plaintext password comparison operation on the solid-state drive. Generally, the plaintext password will be hashed and stored in the solid-state drive, so when comparing, the plaintext password of the user can be hashed first, and then compared with the hash value corresponding to the plaintext password stored in the solid-state drive. This comparison process can be implemented according to the existing comparison algorithms. Thus, the verification process of the user's plaintext password ends.

[0100] An embodiment of the present application also provides a host computer 2, as Figure 4 shown, which may include a second processor 21 and a second computer-readable storage medium 22. Instructions are stored in the second computer-readable storage medium 22, and when the instructions are executed by the second processor 21, the password verification method applied to the host computer side described in any one of the above is implemented.

[0101] In an exemplary embodiment of the present application, any of the embodiments of the password verification method applied to the host computer side described above are applicable to this host computer embodiment, and will not be elaborated here one by one.

[0102] In an exemplary embodiment of the present application, the detailed processes of the card opening stage and the trial use stage of the solid-state drive are given below respectively.

[0103] The card opening stage includes steps 1-1-1-4:

[0104] 1-1. After the solid-state drive is powered on for the first time, a pair of password-protected asymmetric key pairs, such as SM2 key pairs, are generated and stored in the solid-state drive.

[0105] 1-2. The card opening tool obtains the password-protected public key and the solid-state drive serial number (the first hard disk serial number) from the solid-state drive, and signs the protected public key and the serial number with the root private key.

[0106] 1-3. The card opening tool imports the protected public key signature into the solid-state drive.

[0107] 1-4. The card opening stage ends.

[0108] The use stage includes steps 2-1-2-11:

[0109] 2-1. The host computer program obtains the password-protected public key, the hard disk serial number (the first hard disk serial number), and the password-protected public key signature from the solid-state drive.

[0110] 2-2. The host computer program performs a legality verification on the password-protected public key with the root public key; it can also compare the read hard disk serial number (the first hard disk serial number) with the hard disk serial number (the second hard disk serial number) pasted on the hard disk to further ensure the information source.

[0111] 2-3. If the verification of the password-protected public key fails, the operation process is exited.

[0112] 2-4. If the verification of the password-protected public key passes, the host computer obtains a random number from the solid-state drive. This random number is generated after the solid-state drive receives the instruction and will be temporarily stored in the RAM of the solid-state drive.

[0113] 2-5. The host computer performs a security process on the random number and the plaintext password. For example, use the random number as the key to encrypt the password; or perform an exclusive OR operation on the random number and the plaintext password, etc., to obtain the password processing data.

[0114] 2-6. The host computer encrypts the password processing data with the password-protected public key to obtain the encrypted password verification data, denoted as the ciphertext password verification data.

[0115] 2-7. The host computer sends the ciphertext password verification data to the solid-state drive.

[0116] 2-8. After receiving it, the solid-state drive decrypts the ciphertext password verification data with the password-protected private key.

[0117] 2-9. If decryption fails, exit the usage process; if decryption is successful, obtain the password processing data and perform reverse processing on the password processing data according to the random number stored in the RAM. For example, use the random number as the key to decrypt the password processing data; or, perform an exclusive OR operation on the random number and the password processing data to obtain the plaintext password.

[0118] 2-10. As needed, the solid-state drive can perform security processing such as weak PIN check on the password; and / or, after obtaining the plaintext password, the solid-state drive performs a password comparison operation.

[0119] 2-11. The user password verification process ends.

[0120] In an exemplary embodiment of the present application, the solution of the embodiment of the present application at least includes the following advantages:

[0121] 1. The password verification process uses asymmetric key encryption to improve the security strength.

[0122] 2. Verify the legitimacy of the public key of the solid-state drive to prevent man-in-the-middle attacks.

[0123] 3. Add a random number to the verification process to prevent replay attacks.

[0124] 4. Use the digital envelope scheme to process the user plaintext and the random number. The solid-state drive can obtain the user plaintext password and can perform security checks such as weak PIN check on the password.

[0125] 5. By using means such as asymmetric key encryption, participation of random numbers, and verification of the legitimacy of the public key, the user password verification process is securely fortified, effectively preventing security risks such as replay attacks and man-in-the-middle attacks by attackers, and further protecting the security of user data.

[0126] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof. In the hardware implementation, the division of functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may be executed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include but are not limited to RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that a communication medium typically contains computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and may include any information delivery medium.

Claims

1. A password verification method, characterized in that, Applied to the solid - state drive side, the method includes: After the solid - state drive is placed in the host computer, send the initial verification data stored in the solid - state drive during the card - opening stage of the solid - state drive to the host computer; the initial verification data includes: a password - protected public key and a password - protected public key signature; so that the host computer verifies the legality of the password - protected public key; When the verification result of the host computer is that the password - protected public key is legal, generate a random number according to the received instruction of the host computer, and send the random number to the host computer, so that the host computer generates ciphertext password verification data according to the random number; wherein, the host computer generating ciphertext password verification data according to the random number includes: performing a security process on the random number and the plaintext password to obtain password - processing data; encrypting the password - processing data with the password - protected public key to obtain the ciphertext password verification data; Receive the ciphertext password verification data sent by the host computer, and decrypt it according to the password verification data and the password - protected private key to obtain password - processing data; Perform a reverse security process on the password - processing data to obtain the plaintext password.

2. The password verification method according to claim 1, wherein The performing a reverse security process on the password - processing data includes: Using the random number as a key to decrypt the password - processing data; or, Performing a preset logical operation on the random number and the password - processing data; the logical operation includes an exclusive - OR operation.

3. The password verification method according to claim 1 or 2, characterized in that The method further includes: After the solid - state drive is powered on for the first time, generate a password - protected asymmetric key pair and save it in the solid - state drive; the password - protected asymmetric key pair includes: a password - protected public key and a password - protected private key.

4. The password verification method according to claim 3, wherein The method further includes: Send the password - protected asymmetric key pair and the first hard - disk serial number stored in the solid - state drive itself to a preset card - opening tool, so that the card - opening tool sends the password - protected public key and the first hard - disk serial number to a preset server, and uses the root private key stored in the server itself to sign the password - protected public key and the first hard - disk serial number to obtain the password - protected public key signature; Receive the initial verification data returned by the card - opening tool; the initial verification data includes: the password - protected public key signature.

5. A solid state drive, characterized in that, It includes a first processor and a first computer - readable storage medium, and instructions are stored in the first computer - readable storage medium. When the instructions are executed by the first processor, the password verification method described in any one of claims 1 - 4 is implemented.

6. A password verification method, characterized in that Applied to the host computer side, the method includes: Obtain the initial verification data stored in the solid - state drive during the card - opening stage of the solid - state drive from the solid - state drive; the initial verification data includes: a password - protected public key and a password - protected public key signature; Verify the legality of the password - protected public key; When the verification result is that the password - protected public key is legal, obtain a random number from the solid - state drive; the random number is generated by the solid - state drive according to the received instruction; Perform a security process on the random number and a preset plaintext password to obtain password - processing data; Encrypt the password - processing data with the password - protected public key to obtain ciphertext password verification data; Send the ciphertext password verification data to the solid-state drive, so that the solid-state drive decrypts the ciphertext password verification data according to the password-protected private key, obtains the password processing data, and performs reverse security processing on the password processing data to obtain the plaintext password.

7. The password verification method according to claim 6, wherein The initial verification data further includes: a first hard disk serial number; before obtaining a random number from the solid-state drive, the method further includes: Compare the obtained first hard disk serial number with a second hard disk serial number set on the pre-stored solid-state drive; determine whether the first hard disk serial number is consistent with the second hard disk serial number.

8. The password verification method according to claim 6 or 7, characterized in that The initial verification data further includes: when the verification result is that the password-protected public key is illegal, exit the operation process of the solid-state drive.

9. The password verification method according to claim 6 or 7, characterized in that, The security processing of the random number and the preset plaintext password includes: Using the random number as a key to encrypt the plaintext password; or, Performing a preset logical operation on the random number and the plaintext password; the logical operation includes an exclusive OR operation.

10. An upper computer, characterized in that, It includes a second processor and a second computer-readable storage medium, and instructions are stored in the second computer-readable storage medium. When the instructions are executed by the second processor, the password verification method described in any one of claims 6-9 is implemented.

Citation Information

Patent Citations

  • User password processing method and device and internal control safety supervision system

    CN108390758A

  • Key generation method, acquisition method, private key update method, chip and server

    CN111344996A