Identity authentication and access control system, method and device based on encrypted hard disk

Through an identity authentication and access control system based on an encrypted hard disk, combined with an encrypted hard disk and a USB flash drive, the problem of encrypted storage in the existing technology being affected by the host system increases the cost of Yamato Ukey unlocking, realizing the security and reliability of important data, while reducing system costs.

CN114662164BActive Publication Date: 2025-09-02HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210238849.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-09-02
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

The encrypted storage methods of existing solid-state drives are greatly affected by the host system, software encryption is easily stolen by malware, and the Ukey unlocking method increases system costs, how to maximize the security of important storage data and reduce system costs.

Method used

The identity authentication and access control system based on an encrypted hard disk is adopted, combined with an encrypted hard disk and a USB flash drive, and user identity authentication and device verification are performed through authentication and control units to realize file data transmission between an encrypted hard disk and a USB flash drive.

Benefits of technology

Effectively ensure the security and reliability of important data and files, reduce system usage costs, and improve data protection strength through multiple authentication and encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114662164B_ABST
    Figure CN114662164B_ABST
Patent Text Reader

Abstract

This application relates to an identity authentication and access control system, method, and device based on an encrypted hard drive. The system includes an encrypted hard drive, a USB flash drive, an information storage unit, and an authentication and control unit. The encrypted hard drive is used to store motherboard information, system programs, and file data; the USB flash drive is used to save user file data; the information storage unit is used to store user registration information and USB flash drive identification information; and the authentication and control unit is used to receive login information input by the user, perform user identity authentication based on the user registration information, and after successful authentication, perform device verification on the encrypted hard drive and the USB flash drive based on the motherboard information and the USB flash drive identification information, and after successful verification, control the transfer of file data between the USB flash drive and the encrypted hard drive. This system effectively ensures the security of important stored data and reduces the cost of using the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of computer technology, and specifically relates to an identity authentication and access control system based on an encrypted hard disk. Background Art

[0002] With the rapid development of semiconductor and Flash technologies, solid-state drives (SSDs) are gradually replacing traditional mechanical hard drives (HDDs) as a new generation of high-capacity storage devices, widely used in fields such as the internet, healthcare, and transportation. Compared to traditional HDDs, SSDs primarily consist of a control chip and storage modules, offering significant advantages in read / write speeds, noise, size, power consumption, and vibration resistance.

[0003] As storage technology rapidly advances, information security has become a crucial issue. Currently, there are two main types of security technologies for solid-state drives (SSDs). One is encrypted storage, where data is encrypted before being stored on the drive. The encrypted data is then decrypted and displayed in plaintext upon reading. The other is authentication, where data is stored in plaintext and an authentication barrier is added before data is read to protect sensitive resources.

[0004] In terms of encrypted storage, software encryption is based on the host system, so its encryption speed is greatly affected by the system, and the encryption key of software encryption runs in the memory and is extremely vulnerable to theft by malicious network software; in terms of identity authentication, the Ukey unlocking method requires the addition of a Ukey, which will increase the cost of the system.

[0005] In summary, how to maximize the security of important stored data and reduce system costs has become a technical problem that needs to be solved urgently. Summary of the Invention

[0006] (1) Technical issues to be resolved

[0007] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present application provides an identity authentication and access control system, method and device based on an encrypted hard disk.

[0008] (2) Technical solution

[0009] To achieve the above objectives, this application adopts the following technical solutions:

[0010] In a first aspect, an embodiment of the present application provides an identity authentication and access control system based on an encrypted hard disk, the system comprising an encrypted hard disk, a USB flash drive, an information storage unit, and an authentication and control unit;

[0011] The encrypted hard disk is used to store motherboard information, system programs and file data;

[0012] The USB flash drive is used to store user file data;

[0013] The information storage unit is used to store user registration information and USB flash drive identification information;

[0014] The authentication and control unit is used to receive login information input by the user, perform user identity authentication based on the user registration information, and after successful authentication, perform device verification on the encrypted hard disk and the USB flash drive based on the motherboard information and the USB flash drive identification information respectively, and control file data transmission between the USB flash drive and the encrypted hard disk after the verification is passed.

[0015] Optionally, the encrypted hard disk is a solid-state hard disk, including a main control module and a storage medium. The main control module is connected to the host and the storage medium and is used to encrypt and decrypt data.

[0016] Optionally, the storage medium includes a public area, a secure area accessible to users after identity authentication, and a hidden area accessible to administrators after identity authentication;

[0017] The public area is used to store publicly accessible file data of the MBR boot program, operating system and application software;

[0018] The security zone is used to store file data of authenticated users;

[0019] The hidden area is used to store hard disk configuration information and operation log data.

[0020] Optionally, the main control module encrypts the data stored in the storage medium through full disk data encryption.

[0021] In a second aspect, an embodiment of the present application provides an identity authentication and access control method based on an encrypted hard disk, the method comprising:

[0022] S10, receiving login information input by the user, and performing user identity authentication according to the user registration information preset in the information storage unit;

[0023] S20: After successful authentication, perform device verification on the encrypted hard disk connected to the mainboard and the USB flash drive inserted into the mainboard according to the mainboard information preset in the encrypted hard disk and the USB flash drive identification information preset in the information storage unit;

[0024] S30: After verification is passed, control the file data transmission between the USB flash drive and the encrypted hard disk.

[0025] Optionally, before S10, the following steps are further included:

[0026] Initializing the encrypted hard disk and binding the encrypted hard disk to the mainboard;

[0027] Register the USB flash drive.

[0028] Optionally, initialize the encrypted hard disk and bind it to the motherboard, including:

[0029] After the encrypted hard disk is inserted into the motherboard for the first time, reading the serial number of the motherboard;

[0030] The serial number is written into the encrypted hard disk as motherboard information.

[0031] Optionally, registering the USB flash drive includes:

[0032] Reading the universal unique identification code of the USB flash drive;

[0033] A correspondence between the universal unique identification code and pre-generated user registration information is established.

[0034] Optionally, before registering the USB flash drive, the method further includes:

[0035] Generate user registration information, which includes basic user information, user name and password.

[0036] In a third aspect, an embodiment of the present application provides an electronic device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the identity authentication and access control method based on an encrypted hard disk as described in any one of the second aspects above are implemented.

[0037] (3) Beneficial effects

[0038] The beneficial effects of the present application are as follows: the present application proposes an identity authentication and access control system, method and device based on an encrypted hard disk, wherein the system includes an encrypted hard disk, a USB flash drive, an information storage unit, and an authentication and control unit; the encrypted hard disk is used to store motherboard information, system programs and file data; the information storage unit is used to store user registration information and USB flash drive identification information; the authentication and control unit is used to receive login information input by the user, perform user identity authentication according to the user registration information, and after successful authentication, perform device verification on the encrypted hard disk and the USB flash drive according to the motherboard information and the USB flash drive identification information respectively, and control the file data transmission between the USB flash drive and the encrypted hard disk after the verification is passed. Through the identity authentication and access control system based on the encrypted hard disk of the present application, the encrypted storage with the encrypted hard disk as the core and the identity authentication method with the hard disk hard unlocking method as the core are combined, which can effectively ensure the security and reliability of important data and files and reduce the cost of using the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The present application is described with the aid of the following drawings:

[0040] Figure 1 This is a schematic diagram of the structure of an identity authentication and access control system based on an encrypted hard disk in one embodiment of the present application;

[0041] Figure 2 This is a schematic diagram of encrypted hard disk partitions in another embodiment of the present application;

[0042] Figure 3 This is a flowchart of an identity authentication and access control method based on an encrypted hard disk in another embodiment of the present application;

[0043] Figure 4 This is a schematic diagram of the structure of an identity authentication and access control system based on an encrypted hard disk in yet another embodiment of the present application;

[0044] Figure 5 This is a schematic diagram of the hard disk binding and unbinding process in another embodiment of the present application;

[0045] Figure 6 This is a schematic diagram of a user registration process in yet another embodiment of the present application;

[0046] Figure 7 This is a flowchart of password modification in another embodiment of the present application;

[0047] Figure 8 This is a schematic diagram of the login times verification process in another embodiment of the present application;

[0048] Figure 9This is a flowchart of a password reset process in yet another embodiment of the present application;

[0049] Figure 10 This is a schematic diagram of a user change process in yet another embodiment of the present application;

[0050] Figure 11 This is a schematic diagram of a user logout process in yet another embodiment of the present application;

[0051] Figure 12 This is a schematic diagram of a file operation flow in yet another embodiment of the present application;

[0052] Figure 13 This is a schematic diagram of a log operation process in another embodiment of the present application;

[0053] Figure 14 This is a schematic diagram of the structure of an electronic device in Example 5 of the present application. DETAILED DESCRIPTION

[0054] To better explain the present invention and facilitate understanding, the present invention is described in detail below through specific embodiments in conjunction with the accompanying drawings. It should be understood that the specific embodiments described below are merely for explaining the relevant invention and are not intended to limit the invention. It should also be noted that the embodiments and features in the embodiments of this application can be combined with each other unless there is a conflict; for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0055] Example 1

[0056] Figure 1 This is a structural diagram of an identity authentication and access control system based on an encrypted hard disk in one embodiment of the present application. Figure 1 As shown, the system of this embodiment includes an encrypted hard disk 01, a USB flash drive 02, an information storage unit 03, and an authentication and control unit 04;

[0057] Encrypted hard disk 01, used to store motherboard information, system programs and file data;

[0058] USB flash drive 02, used to save user file data;

[0059] Information storage unit 03, used to store user registration information and USB flash drive identification information;

[0060] The authentication and control unit 04 is used to receive the login information input by the user, perform user identity authentication based on the user registration information, and after successful authentication, perform device verification on the encrypted hard disk 01 and USB flash disk 02 based on the motherboard information and USB flash disk identification information respectively. After the verification is passed, the file data transmission between the USB flash disk 02 and the encrypted hard disk 01 is controlled.

[0061] The identity authentication and access control system based on the encrypted hard disk of this embodiment combines the encrypted storage centered on the encrypted hard disk with the identity authentication method centered on the hard disk hard unlocking method, which can effectively ensure the security and reliability of important data and files and reduce the cost of using the system.

[0062] In order to better understand the present invention, each component in this embodiment is described below.

[0063] In this embodiment, the motherboard information may include a motherboard serial number, the system program may include an operating system and an application program, and the file data may be data contained in files of various formats.

[0064] In this embodiment, user registration information may include, but is not limited to, basic information, a user name, and a password. USB flash drive identification information may include, but is not limited to, the USB flash drive's universally unique identifier (UUID). The information storage unit may be a separate storage unit or a designated storage space in the host, which is not limited here.

[0065] In this embodiment, the login information entered by the user may include but is not limited to a user name and password. User identity authentication based on the user registration information may be performed by obtaining the login information entered by the user, reading the stored user registration information from the information storage unit, and comparing the login information with the registration information. If they are consistent, the identity authentication is successful.

[0066] Device verification is performed on the encrypted hard drive and USB flash drive based on the motherboard information and USB flash drive identification information, including:

[0067] Verify the encrypted hard drive based on the motherboard information;

[0068] Verify the USB flash drive based on its identification information.

[0069] When verifying the encrypted hard drive based on the motherboard information, the motherboard information is first read from the encrypted hard drive to determine whether the serial number of the current motherboard is consistent with the motherboard serial number in the motherboard information. If they are consistent, the encrypted hard drive verification is passed; otherwise, the hard drive verification fails and cannot be used.

[0070] When performing device verification on a USB flash drive based on the USB flash drive identification information, the pre-stored USB flash drive identification information is first read from the information storage unit, and the current USB flash drive is verified based on the USB flash drive identification information to determine whether the identification code of the current USB flash drive is consistent with the identification code in the USB flash drive identification information. If they are consistent, the USB flash drive verification is passed.

[0071] The file data transmission between the USB flash drive and the encrypted hard disk can be copying files from the USB flash drive to the encrypted hard disk, or copying files from the encrypted hard disk to the USB flash drive, which is not specifically limited in this embodiment.

[0072] Example 2

[0073] This embodiment provides a detailed introduction to the encrypted hard disk based on the first embodiment.

[0074] In this embodiment, the encrypted hard disk is a solid-state hard disk, which includes a main control module and a storage medium. The main control module is connected to the host and the storage medium and is used to encrypt and decrypt data.

[0075] Figure 2 This is a schematic diagram of encrypted hard disk partitions in another embodiment of the present application, such as Figure 2 As shown, the storage medium includes a public area, a secure area accessible to users after identity authentication, and a hidden area accessible to administrators after identity authentication;

[0076] The public area is used to store the Master Boot Record (MBR) boot program, operating system and application software and publicly accessible file data;

[0077] The secure area is used to store the file data of authenticated users;

[0078] Hidden area, used to store hard disk configuration information and operation log data.

[0079] By default, only the public partition is displayed upon power-on. The secure zone is only visible after entering the corresponding account and password and passing identity authentication. Access and operations on the data and files within it, including read, write, and delete operations, are permitted. The hidden zone is invisible to the system and is a storage area unrecognizable by the operating system. It is used to store log data to prevent malicious tampering. Data within it can only be read after passing identity authentication using an administrator account, thus preventing attacks from hackers, viruses, and spyware, further enhancing the security of important data.

[0080] By dividing into multiple partitions, diverse needs can be met and security can be improved.

[0081] The main control module encrypts the data stored in the storage medium through full disk data encryption.

[0082] The main control module here can be the main control chip of the solid-state drive, which has a built-in encryption engine that implements national secret algorithm encryption, thereby achieving double protection of data.

[0083] Example 3

[0084] Figure 3 This is a flowchart of an identity authentication and access control method based on an encrypted hard disk in another embodiment of the present application. Figure 3 As shown, the identity authentication and access control method based on the encrypted hard disk of this embodiment includes:

[0085] S10, receiving login information input by the user, and performing user identity authentication according to the user registration information preset in the information storage unit;

[0086] S20: After successful authentication, perform device verification on the encrypted hard disk connected to the mainboard and the USB flash drive inserted into the mainboard according to the mainboard information preset in the encrypted hard disk and the USB flash drive identification information preset in the information storage unit;

[0087] S30: After verification is passed, control the file data transmission between the USB flash drive and the encrypted hard disk.

[0088] The execution subject of the method provided in this embodiment can be the identity authentication and access control system in the above-mentioned system embodiment. Its implementation principle and technical effects can be found in the description of embodiment 1, and will not be repeated here in this embodiment.

[0089] In some other optional implementations, before S10, the following steps are further included:

[0090] Initialize the encrypted hard drive and bind it to the motherboard;

[0091] Register the USB flash drive.

[0092] Specifically, the encrypted hard disk is initialized and bound to the motherboard, including:

[0093] After the encrypted hard disk is inserted into the motherboard for the first time, reading the serial number of the motherboard;

[0094] The serial number is written into the encrypted hard disk as motherboard information.

[0095] Specifically, registering the USB flash drive includes:

[0096] Reading the universal unique identification code of the USB flash drive;

[0097] A correspondence between the universal unique identification code and pre-generated user registration information is established.

[0098] By binding the software to the USB flash drive, a one-to-one relationship is achieved when files in the secure zone are copied to the USB flash drive, and a one-to-many relationship is achieved when files in the USB flash drive are copied to the hidden zone, thus ensuring the security of important files.

[0099] In some other optional implementations, before registering the USB flash drive, the following steps are further included:

[0100] Generate user registration information, which includes basic user information, user name and password.

[0101] Example 4

[0102] This embodiment, based on the first, second and third embodiments, illustrates the system proposed in this application and describes in detail the specific implementation process of the method in this application in combination with the system.

[0103] This embodiment uses Hualan Micro's encrypted solid-state drive with a main control chip as the storage medium. Specifically, public partitions, secure partitions, and hidden partitions are designed according to its relevant principles to achieve encrypted storage of important data and files.

[0104] A solid-state drive (SSD) generally consists of an SSD main control chip and storage media. The SSD controller chip is responsible for connecting to the host interface and communication, while the storage module is the final location for data storage.

[0105] An SSD controller is an embedded microchip that issues all operational requests to the firmware algorithms, from actually reading and writing data to performing garbage collection and wear-leveling algorithms to ensure the speed and cleanliness of the SSD.

[0106] The encrypted hard drive used in this patent has full-disk data encryption and decryption capabilities, supports SATA-I / SATA-II / SATA-III interfaces, and can achieve speeds of up to 6Gbps. The storage interface uses the SD / eMMC interface. When connected to 80 external embedded MultiMediaCards (eMMC), the single-disk SSD capacity can reach 10TB. The chip has built-in hardware encryption algorithms, supporting encryption algorithms such as AES / SM2 / SM3 / SM4 / RSA, and can achieve data encryption and decryption with minimal impact on data read and write speeds.

[0107] The encrypted hard drive used in this embodiment adopts an eMMC chip as the data storage medium of the storage module. The chip has a single-chip capacity of 32GB and is packaged in 153FBGA. The chip includes MLC NAND Flash and an eMMC controller. The eMMC controller can perform a series of flash memory management operations including ECC error correction, wear leveling, and IOPS optimization, which also reduces the storage management pressure of the solid-state drive main controller.

[0108] On this basis, an application (Application, APP) suitable for domestic operating systems is developed based on the firmware to achieve visual management of security partitions. The application can also complete functions such as device binding, identity authentication, password reset and access control.

[0109] Figure 4 This is a structural diagram of an identity authentication and access control system based on an encrypted hard disk in another embodiment of the present application. Figure 4 As shown, the system is divided into four major functional modules: file management, log management, user management and system settings. Each functional module is further divided into multiple sub-modules. The sub-modules in each functional module and their functions are explained below.

[0110] File Management:

[0111] Document area: a) add, delete, read and write files; b) import files from the public area;

[0112] U disk: import and export files;

[0113] Favorites: Collect frequently used files;

[0114] Recycle Bin: Temporarily stores deleted files, which can be restored after deletion.

[0115] Log Management:

[0116] Login log: record user login;

[0117] File log: record the system operations;

[0118] Backup log: records backup-related operations;

[0119] Other logs: Other operation records besides the above.

[0120] User Management:

[0121] Hard disk binding: binding and unbinding;

[0122] U disk binding: bind and unbind;

[0123] Account maintenance: Create, change, cancel, unlock, reset and modify passwords for user accounts.

[0124] System Settings:

[0125] Basic settings: a) Language settings; b) Interface settings; c) Current version information; d) System default startup items; e) Version upgrade;

[0126] User information: general user information display and password modification;

[0127] Activate certification: Extend the date and use rights of the current version.

[0128] The following is a process design description of the system from seven functional points, including binding and unbinding of hard disk and motherboard, user registration and password modification, login failure and password reset, user change and logout, file export and import, security zone file editing and deletion, log recording and viewing.

[0129] a) Binding and unbinding of hard disk and motherboard

[0130] To prevent data leakage caused by hard drive loss or removal, you need to bind the hard drive to the host (PC or laptop). This will prevent the hard drive from being used when inserted into another host, thus ensuring the security of the hard drive data. Figure 5 This is a flowchart of hard disk binding and unbinding in another embodiment of the present application. Figure 5 (a) is a diagram of the hard drive binding process, and (b) is a diagram of the hard drive unbinding process.

[0131] Specific as Figure 5 As shown in (a), this operation is performed by the administrator. After inserting the hard drive for the first time, the administrator enters the operating system and logs into the app. After successful administrator authentication, the app background automatically reads the motherboard serial number and writes it to a hidden area on the hard drive. The app then returns information on whether the binding was successful. If successful, the motherboard serial number is displayed; if unsuccessful, the specific reason is reported. In some cases, manual intervention may be required to complete the binding operation.

[0132] If the host is damaged or otherwise unusable, the hard drive needs to be replaced with another host. In order to continue using the hard drive normally, the hard drive must be unbound.

[0133] Specific as Figure 5 As shown in (b), this operation is performed by the administrator. After entering the system, the administrator logs in to the app. After successful identity authentication, they enter the user management interface, click "Unbind Hard Drive," and confirm the operation to complete the hard drive unbinding. This process actually involves using the app to erase the motherboard serial number stored in a special area on the hard drive. Afterwards, the hard drive must be rebinded to ensure proper operation.

[0134] By binding the hard drive to the motherboard, a one-to-one relationship between the host and the hard drive is achieved, preventing data leakage caused by hard drive loss or theft and ensuring the security of sensitive data.

[0135] b) User registration and password modification

[0136] When ordinary users register for the first time, the administrator needs to initialize their basic information, user name and password, etc. Figure 6This is a user registration process diagram in another embodiment of the present application. Figure 6 As shown in the figure, when a new user needs to be added, the administrator logs in to the APP through the corresponding host. After the identity authentication is passed, the administrator enters the user management interface, adds a new user, enters the basic information, sets the initial user name and password, and sets the usage and read and write permissions; then, inserts a new USB flash drive, uses the APP to read its UUID, and stores it under the user information, thus completing the USB flash drive binding operation.

[0137] When the administrator or user needs to change the login password, this function is provided in the user management interface of the APP. Figure 7 FIG. 1 is a flowchart of a password modification process in another embodiment of the present application; Figure 7 As shown, after the administrator or user logs in to the app and passes identity authentication, they click Change Password on the user management interface. They are then asked to enter their original password. If authentication is successful, they can enter a new password and confirm it to complete the operation. Otherwise, the password change request is rejected.

[0138] c) Login failure and password reset

[0139] In order to prevent malicious users from brute-force cracking by continuously entering passwords, an upper threshold is set for the number of times a user can enter a password when logging into the APP. Figure 8 This is a flow chart of the number of login verification in another embodiment of the present application, specifically as follows Figure 8 As shown in the figure, if a user repeatedly enters an incorrect password, a corresponding prompt will be given; if one error is missing and the upper threshold is reached, a warning will be given that the user is about to be locked out. Once a user is locked out, only the administrator can unlock the user's login permissions and reset the user's login password. This method ensures the security of hard drive data.

[0140] By limiting the number of incorrect login attempts, malicious users are prevented from launching password guessing attacks, thus ensuring the security of sensitive data or files.

[0141] Figure 9 This is a flowchart of a password reset process in another embodiment of the present application. Figure 9 The administrator logs in to the app on the corresponding host, enters the user management interface, selects the corresponding user and resets their login password, and confirms the operation to complete the above steps.

[0142] d) User changes and cancellations

[0143] When a user no longer uses a particular host, he or she needs to deregister his or her user information. During this process, if a clear successor appears, the new user can be added by changing the previous user information.

[0144] Figure 10 This is a user change process diagram in another embodiment of the present application, such as Figure 10 As shown, the administrator logs in to the app on the corresponding host, enters the user management interface, selects the user to be changed, enters the new username, password, and other relevant information, and sets the read and write permissions for the new user. If a new USB flash drive is required, insert it and complete the binding operation to complete the user change.

[0145] Figure 11 This is a user logout process diagram in another embodiment of the present application. Figure 11 As shown, the administrator logs in to the APP on the corresponding host, enters the user management interface, selects the user to be deregistered, inserts the USB flash drive and unbinds it, then deletes the user's related information. After confirming the operation, the user's deregistration is completed.

[0146] By allocating ordinary user accounts and usage permissions by the administrator, the software can be operated safely and the security of sensitive data or files can be guaranteed.

[0147] e) File export and import

[0148] When files stored in the hard disk need to be exported to a USB flash drive, a one-to-one correspondence must be met, that is, the user exporting the file must use the USB flash drive bound to it to perform the operation, otherwise the file export will be rejected.

[0149] Figure 12 This is a schematic diagram of a file operation flow in another embodiment of the present application. Figure 12 (a) is a schematic diagram of the file export process. Figure 12 (b) is a schematic diagram of the file import process. Figure 12 (c) is a schematic diagram of the file editing process. Figure 12 (d) is a schematic diagram of the file deletion process.

[0150] like Figure 12 As shown in (a), the user first logs in to the app, inserts a USB drive after passing identity authentication, and enters the USB drive password. After the password is successfully verified, the app will check whether the USB drive is bound to the current user. After successful verification, the app selects the specified file and exports it to the USB drive. If the USB drive is not bound, the export operation is rejected.

[0151] When the files in the USB flash drive need to be imported into the hard disk, the correct USB flash drive password must be entered to complete the file import operation.

[0152] like Figure 12As shown in (b), the user first logs in to the app, inserts the USB drive storing the file after passing identity authentication, and then enters the USB drive password. After the password is successfully verified, the user selects the specified file and imports it to the specified location on the hard drive. If the USB drive password is incorrect, the import operation is rejected.

[0153] f) Editing and deleting files in the security zone

[0154] The editing and deletion of security zone files must be done through the APP, as follows Figure 12 As shown in (c) and (d).

[0155] The user first logs in to the app. After passing identity authentication, they enter the corresponding secure zone, select a specific file, open it, and close it after editing. Finally, the user needs to log out of the account and close the app. Deleting files follows a similar process, with a reminder displayed before the file is deleted to prevent accidental deletion.

[0156] e) Hidden area log recording and viewing

[0157] The recording and viewing of logs need to be achieved through the APP. Figure 13 This is a log operation flow diagram in another embodiment of the present application. Figure 13 (a) is a schematic diagram of the log recording process, and (b) is a schematic diagram of the log viewing process.

[0158] like Figure 13 As shown in (a) and (b), the logging module automatically starts after the user opens the app. When the user logs in to the app, the user name and current time are recorded. If the login fails, the number of failures and the corresponding time are recorded. After the user successfully logs in, the subsequent file creation, modification, and deletion operations and the corresponding time are recorded. When a USB flash drive is detected, the file export and import operations and the corresponding time are also recorded. When the user logs out of the account and closes the app, the logging ends and the log information is saved.

[0159] Logs can only be viewed through an administrator account. After logging into the app and passing identity authentication, the administrator enters the log management interface, where they can filter and view relevant log information. If an abnormality is found, the administrator records the action and the corresponding time. After completing the review, close the app. The abnormality must then be reported offline for further verification and processing.

[0160] Through administrator privileges, hidden area operation logs can be managed and audited to prevent malicious tampering of logs, issue warnings for improper operations in advance, and trace improper operations afterwards to ensure the security of sensitive data or files.

[0161] Example 5

[0162] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the computer program is executed by the processor, the steps of the identity authentication and access control method based on the encrypted hard disk as described in any one of the above embodiments are implemented.

[0163] Figure 14 This is a schematic diagram of the structure of an electronic device in another embodiment of the present application.

[0164] Figure 14 The electronic device shown may include: at least one processor 101, at least one memory 102, at least one network interface 104 and other user interfaces 103. The various components in the electronic device are coupled together via a bus system 105. It is understood that the bus system 105 is used to achieve connection and communication between these components. In addition to including a data bus, the bus system 105 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, the bus system 105 is not described in detail. Figure 14 Various buses are labeled as bus system 105 .

[0165] The user interface 103 may include a display, a keyboard, or a pointing device (eg, a mouse, a trackball, or a touchpad).

[0166] It is understood that the memory 102 in this embodiment can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 62 described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0167] In some embodiments, the memory 102 stores the following elements, executable units, or data structures, or a subset thereof, or an extended set thereof: an operating system 1021 and application programs 1022 .

[0168] The operating system 1021 includes various system programs, such as a framework layer, a core library layer, and a driver layer, for implementing various basic services and handling hardware-based tasks. Application programs 1022 include various application programs for implementing various application services. Programs implementing the methods of the embodiments of the present invention may be included in application programs 1022.

[0169] In an embodiment of the present invention, the processor 101 calls a program or instruction stored in the memory 102, specifically, a program or instruction stored in the application 1022, and the processor 101 is used to execute the method steps provided in the first aspect.

[0170] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 101. Processor 101 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be performed by hardware integrated logic circuits in processor 101 or by software instructions. Processor 101 may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, an off-the-shelf programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The methods, steps, and logic block diagrams disclosed in the embodiments of the present invention can be implemented or executed. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor or by a combination of hardware and software units in the decoding processor. The software units can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory 102. Processor 101 reads information from memory 102 and, in conjunction with its hardware, completes the steps of the above method.

[0171] In addition, in combination with the identity authentication and access control method based on the encrypted hard disk in the above embodiment, an embodiment of the present invention can provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, any one of the identity authentication and access control methods based on the encrypted hard disk in the above method embodiments is implemented.

[0172] It should be noted that in the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claim. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The present invention can be implemented by means of hardware comprising several distinct components and by means of a suitably programmed computer. The use of the words first, second, third, etc. is merely for convenience and does not imply any order. These words should be understood as part of the component name.

[0173] In addition, it should be noted that, in the description of this specification, the description of the terms "one embodiment", "some embodiments", "embodiment", "example", "specific example" or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and the features of different embodiments or examples, unless they are contradictory.

[0174] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments after learning the basic creative concept. Therefore, the claims should be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0175] Obviously, those skilled in the art may make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if such modifications and variations fall within the scope of the claims and their equivalents, the present invention shall also include such modifications and variations.

Claims

1. A method for identity authentication and access control based on an encrypted hard disk, characterized in that: The method includes: S10, receiving login information input by the user, and performing user identity authentication based on user registration information preset in the information storage unit; the information storage unit is a separate storage unit; S20: After successful authentication, perform device verification on the encrypted hard disk connected to the mainboard and the USB flash drive inserted into the mainboard according to the mainboard information preset in the encrypted hard disk and the USB flash drive identification information preset in the information storage unit; S30, controlling the file data transmission between the USB flash drive and the encrypted hard disk after the verification is passed; Controlling the file data transmission between the USB flash drive and the encrypted hard drive includes: copying the file data in the encrypted hard drive to the USB flash drive; or copying the file data in the USB flash drive to the encrypted hard drive; Prior to S10, this also included: Initializing the encrypted hard disk and binding the encrypted hard disk to the mainboard; Registering the USB flash drive; Initializing the encrypted hard disk and binding the encrypted hard disk to the mainboard includes: After the encrypted hard disk is inserted into the motherboard for the first time, reading the serial number of the motherboard; Writing the serial number as motherboard information into the encrypted hard disk; Registering the USB flash drive includes: Reading the universal unique identification code of the USB flash drive; Establishing a correspondence between the universal unique identification code and pre-generated user registration information; Among them, the identity authentication and access control method based on the encrypted hard disk is performed by the identity authentication and access control system based on the encrypted hard disk, and the system includes an encrypted hard disk, a USB flash drive, an information storage unit, and an authentication and control unit; The encrypted hard disk is used to store motherboard information, system programs and file data; The USB flash drive is used to store user file data; The information storage unit is used to store user registration information and USB flash drive identification information; The authentication and control unit is configured to receive login information input by a user, perform user identity authentication based on the user registration information, perform device verification on the encrypted hard disk and the USB flash drive based on the motherboard information and the USB flash drive identification information respectively after successful authentication, and control file data transmission between the USB flash drive and the encrypted hard disk after successful authentication; The encrypted hard disk is a solid-state hard disk, including a main control module and a storage medium. The main control module is connected to the host and the storage medium for encrypting and decrypting data; The storage medium includes a public area, a secure area accessible to users after identity authentication, and a hidden area accessible to administrators after identity authentication; The public area is used to store the MBR boot program, operating system and application software and publicly accessible file data; The security zone is used to store file data of authenticated users; The hidden area is used to store hard disk configuration information and operation log data; The USB flash drive identification information is a universal unique identification code; The file data transmission controlled by the authentication and control unit includes: copying the file data in the encrypted hard disk to the USB flash drive; or copying the file data in the USB flash drive to the encrypted hard disk; The security area is invisible by default before the user identity authentication is passed; the hidden area is a storage area that is not identifiable by the operating system; The main control module encrypts the data stored in the storage medium through full disk data encryption.

2. The identity authentication and access control method based on encrypted hard disk according to claim 1, characterized in that: Before registering the USB flash drive, the method further includes: Generate user registration information, which includes basic user information, user name and password.

Citation Information

Patent Citations

  • Hard disk control method and equipment and readable storage medium

    CN107688756A

  • A solid state hard disk data protection method based on USB disk authentication

    CN109190389A

  • Real-time dynamic authentication method for multi-user secure storage

    CN112084472A

  • USB flash disk system authentication method and device, electronic equipment and storage medium

    CN112613011A