A Solid State Drive Access Control Circuit, System, and Solid State Drive
By introducing key memory and random number generator into the solid state drive, combining hash calculation and dynamic digest value verification, the problem of SSD vulnerability to replay attacks is solved, and data security and access control protection capabilities are improved.
Patent Information
- Application Number
- CN202210989710.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-18
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-08-18
AI Technical Summary
The access control methods of existing solid-state drives are vulnerable to "replay attacks", resulting in poor data security.
The key memory, key reading control circuit, digest value calculation circuit, random number generator and comparison circuit are used to generate dynamic digest values through hash calculation for verification, combining the host serial number and random number to increase the difficulty of attack.
Effectively resist "replay attacks", improve data security, prevent illegal access, ensure that the random numbers in each authentication process are different, and risk is managed through blacklists.
Smart Images

Figure CN115310110B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of storage technologies, and in particular, to a solid-state drive access control circuit, a system, and a solid-state drive. Background Art
[0002] A solid-state drive (SSD) is a replacement for a traditional mechanical hard disk. In a typical solid-state drive, its internal circuit includes a main control chip, DDR memory particles, NAND Flash memory chip particles, SPI Flash particles, etc. In some application scenarios, there are requirements for the data security of the solid-state drive, that is, to ensure that only authorized personnel are allowed to access the data in the solid-state drive, and access requests from illegal users should be rejected. Currently, a security access method adopted is to use a fixed authorization code and a fixed system ID (Identity document) value, and its security is poor and cannot resist "replay attacks". As long as an attacker can monitor a normal access process by illegal means once, and then use the same authorization code and the same ID value, the security system of the solid-state drive can be deceived to achieve cracking.
[0003] Therefore, there is a need for an access control method that can better resist "replay attacks" currently. Summary of the Invention
[0004] In view of the above problems, the present invention provides a solid-state drive access control circuit, a system, and a solid-state drive, which can effectively resist "replay" attacks and improve the data security of the hard disk.
[0005] In a first aspect, the present application provides the following technical solution through an embodiment:
[0006] A solid-state drive access control circuit includes: a key memory, a key reading control circuit, a digest value calculation circuit, a first input control circuit, a random number generator, a second input control circuit, and a comparison circuit; the key memory is connected to the key reading control circuit; the key reading control circuit, the first input control circuit, and the random number generator are all connected to the digest value calculation circuit; the digest value calculation circuit and the second input control circuit are both connected to the comparison circuit;
[0007] The key memory is configured to store the original key; the first input control circuit is configured to receive the serial number of the host accessing the hard disk; the random number generator is configured to generate a random number; the digest value calculation circuit is configured to perform a hash calculation based on the original key and the serial number to obtain a first digest value; and is further configured to perform a hash calculation based on the first digest value and the random number to obtain a second digest value; the second input control circuit is configured to receive a third digest value input by the host accessing the hard disk; the third digest value is obtained by performing a hash calculation based on the first digest value and the random number; the comparison circuit is configured to compare whether the second digest value and the third digest value are the same; and is further configured to, if the second digest value and the third digest value are the same, output an authentication passed signal to enable the hard disk to respond to the read / write request of the host; if the second digest value and the third digest value are different, output a determination failed signal to cause the hard disk not to respond to the read / write request of the host.
[0008] Optionally, the digest value calculation circuit includes: a first hashing algorithm circuit and a second hashing algorithm circuit; the input end of the first hashing algorithm circuit is connected to the key reading control circuit and the first input control circuit; the output end of the first hashing algorithm circuit is connected to the input end of the second hashing algorithm circuit, and the input end of the second hashing algorithm circuit is further connected to the random number generator; the output end of the second hashing algorithm circuit is connected to the input end of the comparison circuit; the first hashing algorithm circuit is configured to perform a hash calculation based on the original key and the serial number to obtain a first digest value; the second hashing algorithm circuit is configured to perform a hash calculation based on the first digest value and the random number to obtain a second digest value.
[0009] Optionally, it further includes a first cache register, and the first hashing algorithm circuit is connected to the second hashing algorithm circuit through the first cache register.
[0010] Optionally, the digest value calculation circuit includes: a first selector, a second selector, a third selector, and a third hashing algorithm circuit; the first input end of the first selector is connected to the key reading control circuit, the second input end of the first selector is connected to the first output end of the third selector, and the output end of the first selector is connected to the input end of the third hashing algorithm circuit; the first input end of the second selector is connected to the first input control circuit, the second input end of the second selector is connected to the random number generator, and the output end of the second selector is connected to the input end of the third hashing algorithm circuit; the output end of the third hashing algorithm circuit is connected to the input end of the third selector; the second output end of the third selector is connected to the input end of the comparison circuit;
[0011] The first selector is configured to select the original key and output it to the third hashing algorithm circuit during a first time period; the second selector is configured to select the serial number and output it to the third hashing algorithm circuit during the first time period; the third hashing algorithm circuit is configured to perform a hashing calculation based on the original key and the random number to obtain a first digest value; the third selector is configured to output the first digest value to the first selector; the first selector is further configured to select the first digest value and output it to the third hashing algorithm circuit during a second time period; the second selector is further configured to select the random number and output it to the third hashing algorithm circuit during the second time period; the third hashing algorithm circuit is further configured to perform a hashing calculation based on the first digest value and the random number to obtain a second digest value; the third selector is further configured to output the second digest value to the comparison circuit.
[0012] Optionally, it further includes a second buffer register, and the third hashing algorithm circuit is connected to the third selector through the second buffer register.
[0013] Optionally, it further includes a key writing control circuit; the key writing control circuit is connected to the key memory; the key writing control circuit is configured to write the original key into the key memory.
[0014] Optionally, it further includes a main control state machine; the main control state machine is respectively connected to the key memory, the key reading control circuit, the digest value calculation circuit, the first input control circuit, the random number generator, the second input control circuit, and the comparison circuit for control connection.
[0015] Optionally, it further includes a third buffer register and a fourth buffer register; the first input control circuit is connected to the digest value calculation circuit through the third buffer register, and the random number generator is connected to the digest value calculation circuit through the fourth buffer register.
[0016] In a second aspect, based on the same inventive concept, the present application provides the following technical solution through an embodiment:
[0017] A solid-state drive includes the solid-state drive access control circuit according to any one of the foregoing first aspects.
[0018] In a third aspect, based on the same inventive concept, the present application provides the following technical solution through an embodiment:
[0019] A solid-state drive access control system, comprising: a host and the solid-state drive described in the second aspect above; the solid-state drive includes an interface circuit, and the interface circuit is connected to the comparison circuit; the host includes a serial number memory, a fourth hashing algorithm circuit, and an output interface circuit; the serial number memory is respectively connected to the first input control circuit and the fourth hashing algorithm circuit, the fourth hashing algorithm circuit is connected to the output interface circuit, and the output interface circuit is connected to the second input control circuit;
[0020] The serial number memory is configured to store a serial number and a first digest value; the fourth hashing algorithm circuit is configured to perform a hashing calculation based on the first digest value and the random number to obtain a third digest value.
[0021] In a solid-state drive access control circuit, system, and solid-state drive according to an embodiment of the present invention, a random number generator is added. Even if an attacker cracks a certain random number, it is difficult to pass the verification in the next verification process because each random number is different; in addition, in this embodiment, when calculating the digest value, the original key and the serial number of the host are used to calculate a first digest value; then, the first digest value and the random number are used to calculate a second digest value for comparison and verification; in this way, the characteristics of the host can be covered in the second digest value. Even if an attacker cracks a certain host for verification and can forge a host with the serial number, the serial number of the host can also be added to the blacklist at the hard disk end, thereby avoiding the spread of risks and improving the security of the data in the solid-state drive.
[0022] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the description. And in order to make the above and other objects, features, and advantages of the present invention more obvious and understandable, the following specific embodiments of the present invention are specifically given. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0024] Figure 1 is a schematic structural diagram of a solid-state drive access control circuit according to an embodiment of the present invention;
[0025] Figure 2 is another schematic structural diagram of a solid-state drive access control circuit according to an embodiment of the present invention;
[0026] Figure 3Schematic diagram of the structure of the solid-state drive in the embodiment of the present invention;
[0027] Figure 4 Schematic diagram of the structure of the solid-state drive access control system in the embodiment of the present invention;
[0028] Figure 5 Schematic diagram of the authentication interaction principle of the solid-state drive access control system in the embodiment of the present invention.
[0029] Reference numerals:
[0030] 10 - Solid-state drive; 100 - Solid-state drive access control circuit; 300 - Solid-state drive access control system; 20 - Host; 101 - Main control state machine; 103 - Key writing control circuit; 105 - Key memory; 107 - Key reading control circuit; 109 - First hash algorithm circuit; 111 - Second hash algorithm circuit; 113 - First input control circuit; 115 - Random number generator; 117 - Output control circuit; 119 - Second input control circuit; 121 - Comparison circuit; 123 - First cache register; 125 - Third cache register; 127 - Fourth cache register; 129 - Fifth cache register; 131 - Sixth cache register; 112 - First selector; 114 - Second selector; 116 - Third selector; 118 - Third hash algorithm circuit; 120 - Second cache register; 141 - Processor; 143 - Interface circuit; 145 - DRAM controller; 147 - Flash memory controller; 151 - DRAM memory; 153 - Flash memory array; 201 - Serial number memory; 203 - Fourth hash algorithm circuit; 205 - Output interface circuit; 207 - Seventh cache register. Detailed implementation manners
[0031] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0032] Please refer to Figure 1, in an embodiment of the present invention, a solid-state drive access control circuit 100 is provided, including: a key memory 105, a key reading control circuit 107, a digest value calculation circuit, a first input control circuit 113, a random number generator 115, a second input control circuit 119, and a comparison circuit 121; the key memory 105 is connected to the key reading control circuit 107; the key reading control circuit 107, the first input control circuit 113, and the random number generator 115 are all connected to the digest value calculation circuit; the digest value calculation circuit and the second input control circuit 119 are both connected to the comparison circuit 121.
[0033] The key memory 105 is configured to store the original key; the first input control circuit 113 is configured to receive the serial number of the host accessing the hard disk; the random number generator 115 is configured to generate a random number; the digest value calculation circuit is configured to perform a hash calculation based on the original key and the serial number to obtain a first digest value; and is further configured to perform a hash calculation based on the first digest value and the random number to obtain a second digest value; the second input control circuit 119 is configured to receive a third digest value input by the host accessing the hard disk; the third digest value is obtained by performing a hash calculation based on the first digest value and the random number; the comparison circuit 121 is configured to compare whether the second digest value and the third digest value are the same; and is further configured to, if the second digest value and the third digest value are the same, output an authentication passed signal to enable the hard disk to respond to the read / write request of the host; if the second digest value and the third digest value are different, output a recognition failure signal to enable the hard disk not to respond to the read / write request of the host.
[0034] It can be understood that in this embodiment, the random number generator 115 is added. Even if an attacker cracks the random number of a certain time, it is difficult to pass the verification in the next verification process because the random numbers are all different each time; in addition, in this embodiment, when calculating the digest value, the original key and the serial number of the host are used to perform a digest value calculation once to obtain the first digest value; then, the first digest value and the random number are used to perform a digest value calculation once to obtain the second digest value for comparison and verification; in this way, the characteristics of the host can be covered in the second digest value. Even if an attacker cracks a certain host for verification and can forge a host with the serial number, the serial number of this host can also be added to the blacklist at the hard disk end to avoid the spread of risks and improve the security of the hard disk data.
[0035] In some alternative implementations, the digest value calculation circuit includes: a first hashing algorithm circuit 109 and a second hashing algorithm circuit 111; the input end of the first hashing algorithm circuit 109 is connected to the key reading control circuit 107 and the first input control circuit 113; the output end of the first hashing algorithm circuit 109 is connected to the input end of the second hashing algorithm circuit 111, and the input end of the second hashing algorithm circuit 111 is also connected to the random number generator 115; the output end of the second hashing algorithm circuit 111 is connected to the input end of the comparison circuit 121; the first hashing algorithm circuit 109 is configured to perform hashing calculation based on the original key and the serial number to obtain a first digest value; the second hashing algorithm circuit 111 is configured to perform hashing calculation based on the first digest value and the random number to obtain a second digest value.
[0036] In this implementation, a first buffer register 123 can also be set to temporarily store the first digest value calculated by the first hashing algorithm circuit 109. That is to say, the first hashing algorithm circuit 109 is connected to the second hashing algorithm circuit 111 through the first buffer register 123.
[0037] It can be understood that the digest value in this embodiment is the hash value; the hashing algorithm is also called the "digest algorithm" or "hash algorithm", and its calculation result is a hash value, that is, the "digest value". Common hashing algorithms include: SHA1, SHA3, SHA256, SM3, MD5, etc. The host can be a personal computer (PC), and the serial number can be the unique identification number of the host, such as the serial number of the motherboard, the physical address of the network card, the factory serial number of the PC, the authorization number of the operating system, etc.
[0038] Furthermore, when two hashing algorithm circuits are used in the digest value calculation circuit, although the second digest value can be generated, it will cause a large amount of circuit area to be occupied, which is not conducive to the design of a smaller-sized hard disk. Therefore, a circuit design with one hashing algorithm circuit is also provided in this embodiment; specifically:
[0039] Please refer to Figure 2, the digest value calculation circuit may include: a first selector 112, a second selector 114, a third selector 116, and a third hashing algorithm circuit 118; a first input terminal of the first selector 112 is connected to the key reading control circuit 107, a second input terminal of the first selector 112 is connected to a first output terminal of the third selector 116, and an output terminal of the first selector 112 is connected to an input terminal of the third hashing algorithm circuit 118; a first input terminal of the second selector 114 is connected to the first input control circuit 113, a second input terminal of the second selector 114 is connected to the random number generator 115, and an output terminal of the second selector 114 is connected to an input terminal of the third hashing algorithm circuit 118; an output terminal of the third hashing algorithm circuit 118 is connected to an input terminal of the third selector 116; a second output terminal of the third selector 116 is connected to an input terminal of the comparison circuit 121. The first selector 112 is configured to select the original key and output it to the third hashing algorithm circuit 118 during the first time period; the second selector 114 is configured to select the serial number and output it to the third hashing algorithm circuit 118 during the first time period; the third hashing algorithm circuit 118 is configured to perform a hashing calculation based on the original key and the random number to obtain a first digest value; the third selector 116 is configured to output the first digest value to the first selector 112; the first selector 112 is further configured to select the first digest value and output it to the third hashing algorithm circuit 118 during the second time period; the second selector 114 is further configured to select the random number and output it to the third hashing algorithm circuit 118 during the second time period; the third hashing algorithm circuit 118 is further configured to perform a hashing calculation based on the first digest value and the random number to obtain a second digest value; the third selector 116 is further configured to output the second digest value to the comparison circuit 121. The selector circuit in this embodiment may be implemented by an existing logic circuit without limitation.
[0040] It can be understood that the first selector 112, the second selector 114, and the third selector 116 are respectively controlled by the timing control signal. During the first time period, the original key and the serial number are input to the third hashing algorithm circuit 118, and the first digest value can be calculated; then, during the second time period, the random number and the first digest value are input to the third hashing algorithm circuit 118, and the second digest value can be calculated. This design only adds timing control, effectively reduces the circuit hardware, reduces the overall circuit area, and lowers the cost.
[0041] Further, the hard disk access control circuit 100 may further include a second buffer register 120, and the third hashing algorithm circuit 118 is connected to the third selector 116 through the second buffer register 120. The second buffer register 120 can temporarily store the second digest value calculated by the third hashing algorithm circuit 118.
[0042] In the solid - state drive access control circuit 100 in this embodiment, it may further include a key writing control circuit 103; the key writing control circuit 103 is connected to the key memory 105; the key writing control circuit 103 is configured to write an original key into the key memory 105. In some cases, an administrator may also write a new original key into the key memory 105 through the key writing control circuit 103 to replace the original original key, so as to prevent the risk of original key leakage. The key memory 105 in this embodiment may be an EEPROM (Electrically Erasable Programmable Read - Only Memory).
[0043] In addition, the solid - state drive access control circuit 100 may further include a third cache register 125 and a fourth cache register 127; the first input control circuit 113 is connected to the digest value calculation circuit through the third cache register 125; the third cache register 125 may be configured to temporarily store the serial number passed in by the first input control circuit 113 and pass it into the digest value calculation circuit when the digest value calculation circuit needs to use it, or be called by the digest value calculation circuit. The random number generator 115 is connected to the digest value calculation circuit through the fourth cache register 127; the fourth cache register 127 is configured to temporarily store the random number generated by the random number generator 115 so that it can be passed into the digest value calculation circuit when the digest value calculation circuit needs to use it, or be called by the digest value calculation circuit.
[0044] Furthermore, the solid - state drive access control circuit 100 may further include a fifth cache register 129 and a sixth cache register 131. The second input control circuit 119 is connected to the comparison circuit 121 through the fifth cache register 129; the fifth cache register 129 is configured to temporarily store the third digest value passed in from the host side. The digest value calculation circuit may be connected to the comparison circuit 121 through the sixth cache register 131 and may be configured to cache the second digest value obtained by the processing of the digest value calculation circuit, so as to facilitate the comparison circuit 121 to compare the second digest value and the third digest value.
[0045] The solid-state drive access control circuit 100 may further include a host master state machine 101. The host master state machine 101 is respectively connected to the key memory 105, the key reading control circuit 107, the digest value calculation circuit, the first input control circuit 113, the random number generator 115, the second input control circuit 119, the comparison circuit 121, the key writing control circuit 103, and any one or more of the respective cache registers for control connection; in the drawings, only the control connection relationship between the host master state machine 101 and the key writing control circuit 103 and the second hashing algorithm circuit 111 is shown, and other parts are not shown. To achieve control over the entire circuit's complete working process. For example, the random number generator 115 may generate random numbers under the control of the host master state machine 101.
[0046] It can be understood that the signal output by the comparison circuit 121 can be transmitted to the interface circuit 143 of the hard disk to enable the interface circuit 143 to respond or not respond to the read / write requests of the host. Additionally, the signal output by the comparison circuit 121 can also be transmitted to the host master state machine 101, and the host master state machine 101 controls whether the interface circuit 143 responds to the host.
[0047] The solid-state drive access control circuit 100 may further include an output control circuit 117. The input end of the output control circuit 117 is connected to the random number generator 115, and the output end of the output control circuit 117 is configured to output the random numbers generated by the random number generator 115 to the corresponding host side.
[0048] Please refer to Figure 3 , based on the same inventive concept, in another embodiment of the present invention, a solid-state drive 10 is further provided. The solid-state drive 10 includes: the solid-state drive access control circuit 100 in any one of the foregoing embodiments.
[0049] The solid-state drive 10 may further include a processor 141, an interface circuit 143, a DRAM controller 145, a flash memory controller 147, and a flash memory array 153. Among them, the interface circuit 143 may be a PCIe interface, a SATA interface, a PCI interface, etc., without limitation. The DRAM controller 145 may be controllably connected to the DRAM memory 151, and the flash memory controller 147 may be controllably connected to the flash memory array 153. The flash memory array 153 may be a NAND Flash memory array. It can be understood that the interface circuit 143 may belong to the controller chip part of the solid-state drive 10. The controller chip part of the solid-state drive 10 may include a processor (CPU) 141, a DRAM (Dynamic Random Access Memory) controller, and a flash memory controller 147. In addition, the storage part of the solid-state drive 10 may include a DRAM memory 151 and a flash memory array (such as a NAND Flash memory array), without limitation. The structures not described in detail above are all prior arts known to those skilled in the art. For example, the specific implementation of the processor 141, the flash memory controller 147, the DRAM controller 145, etc. can be referred to in the book "SSD In-Depth" published by China Machine Press, which will not be elaborated in this embodiment.
[0050] It should be noted that the solid-state drive 10 in this embodiment adopts the solid-state drive access control circuit 100 in the foregoing embodiment. The beneficial effects thereof can be referred to the description of the solid-state drive access control circuit 100 in the foregoing embodiment, which will not be elaborated in this embodiment.
[0051] Please refer to Figure 4 , based on the same inventive concept, a solid-state drive access control system 300 provided in an embodiment of the present invention includes: a host 20 and the solid-state drive 10 in the foregoing embodiment. The solid-state drive 10 includes an interface circuit 143, and the interface circuit 143 is connected to a comparison circuit 121. The host 20 includes a serial number memory 201, a fourth hashing algorithm circuit 203, and an output interface circuit 205. The serial number memory 201 is respectively connected to a first input control circuit 113 and the fourth hashing algorithm circuit 203. The fourth hashing algorithm circuit 203 is connected to the output interface circuit 205, and the output interface circuit 205 is connected to a second input control circuit 119. The serial number memory 201 is configured to store a serial number and a first digest value. The fourth hashing algorithm circuit 203 is configured to perform a hashing calculation based on the first digest value and a random number to obtain a third digest value. Further, the fourth hashing algorithm circuit 203 may be connected to the output interface circuit 205 through a seventh cache register 207.
[0052] If an attacker cannot obtain the random number even after stealing the first digest value, and even if the first digest value on the host 20 side is stolen, since the first digest value is obtained by hashing the original key and the serial number, the administrator can invalidate the stolen first digest value by adjusting the original key on the solid-state drive 10 side, thereby ensuring the security of the solid-state drive 10.
[0053] On the host 20 side, to ensure the consistency of the calculation results, the fourth hashing algorithm circuit 203 should be the same as the second hashing algorithm circuit 111 and the third hashing algorithm circuit 118.
[0054] Please refer to Figure 5 , and the principles of the solid-state drive access control circuit 100, system 300, and solid-state drive 10 of the present invention will be described below by way of a specific example:
[0055] Before deploying the application to the solid-state drive 10, an initialization operation is first performed; first, construct 1 original key (Root Key) and write it into the key memory 105 (EEPROM memory) of the solid-state drive 10. Then, the user designates 1 serial number (Serial Number) for each host 20 (computer), and the serial numbers of different hosts 20 are different. Then, the user writes the serial number into the serial number memory 201 in the host 20 (EEPROM memory).
[0056] For each serial number (Serial Number), it is combined with the original key (Root Key) and operated using the digest algorithm, and the result is the diversified key (Diversified Key). If the host 20 and the solid-state drive 10 match, this diversified key is the first digest value; since the serial numbers (Serial Numbers) of each computer are different, the diversified keys (Diversified Keys) of each computer are also different. Write each diversified key (Diversified Key) into the serial number memory 201 of the corresponding host 20.
[0057] Furthermore, when deploying the solid-state drive 10 to the host 20, it needs to be authenticated and authorized; if it is an "illegal" host 20, the authentication process cannot be completed, and the solid-state drive 10 will not respond to the data read and write access of the PC; if it is a "legal" host 20, it can pass the authentication process, and the host 20 can read and write the solid-state drive 10 normally. The authentication and authorization process is as follows:
[0058] The authentication starts. The main control state machine 101 inside the solid-state drive 10 controls the key reading control circuit 107 to read the original key (Root Key) in the key memory 105. Then, the serial number (Serial Number) saved in the key memory 105 is read from the computer side. And it controls the digest value calculation circuit to perform a hashing operation on the original key (Root Key) and the serial number (Serial Number), and the calculation result is the first digest value. If it is a "legitimate" host 20, then this first digest value is exactly the same as the diversified key value in the serial number memory 201 in the computer.
[0059] Next, the random number generator inside the solid-state drive 10 generates a random number A, uses it as a Challenge, and sends it to the PC side. The solid-state drive 10 starts the hashing algorithm circuit based on the random number A and the first digest value, and calculates the second digest value C.
[0060] After receiving the random number A on the host 20 side, it calls the hashing algorithm in combination with the diversified key in its internal serial number memory 201 to calculate the third digest value D. The host 20 outputs the third digest value D to the solid-state drive 10 side. After receiving the third digest value D, the solid-state drive 10 compares the third digest value D with the second digest value C. If the second digest value and the third digest value are the same, it means the host 20 is "legitimate", then the communication interface (such as: PCIe, SATA or PCI) is enabled, and the host 20 is allowed to access the data in the solid-state drive 10; otherwise, it means the host 20 is an illegal host, then the communication interface is deactivated, and the read and write access requests of the solid-state drive 10 from the host 20 are not responded to.
[0061] As can be seen from the above example, to achieve successful authentication, it is necessary to ensure that the same first digest value calculated by the solid-state drive 10 is stored at the host 20 side; however, the calculation of the first digest value only exists in the solid-state drive 10, and the first digest value on the host 20 side is preset and stored. Therefore, it is difficult to achieve cracking only from the host 20 side; further improving security. Secondly, to achieve cracking, it is also necessary to be able to determine the random number generated by the random number generator 115 each time; however, the random number is different in each authentication process and is sent by the solid-state drive 10. Even if the random number of any authentication process is intercepted, it is impossible to achieve cracking; even if the same random number generator is obtained, the solid-state drive 10 can also add malicious hosts by means of a blacklist. The blacklist can be written into the key memory 105 through the key writing control circuit 103, and the implementation of blacklist recognition can be achieved through the first input control circuit 113 and the main control state machine 101. For example, if the main control state machine 101 determines that the serial number received by the first input control circuit 113 exists in the blacklist, it controls the first input control circuit 113 not to write into the third cache register 125, thereby preventing attacks and further improving the security of the solid-state drive 10. Therefore, the solid-state drive access control circuit 100, the system 300, and the solid-state drive 10 in this embodiment can effectively resist "replay" attacks and ensure the data security of the solid-state drive 10.
[0062] In the specification provided herein, a large number of specific details are set forth. It is, however, understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been shown in detail so as not to obscure the understanding of this description.
[0063] Similarly, it should be understood that in order to streamline this disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of exemplary embodiments of the invention, various features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, the disclosed method should not be interpreted as reflecting an intention that: the claimed invention requires more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive aspects lie in less than all the features of a single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the invention.
[0064] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature providing the same, equivalent or similar purpose.
[0065] In addition, those skilled in the art can understand that although some of the embodiments herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
[0066] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In a unit claim listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.
Claims
1. A solid-state drive access control circuit, characterized in that, Including: A key memory, a key reading control circuit, a digest value calculation circuit, a first input control circuit, a random number generator, a second input control circuit, and a comparison circuit; The key memory is connected to the key reading control circuit; the key reading control circuit, the first input control circuit, and the random number generator are all connected to the digest value calculation circuit; the digest value calculation circuit and the second input control circuit are both connected to the comparison circuit; The key memory is configured to store an original key; The first input control circuit is configured to receive the serial number of a host accessing the hard disk; The random number generator is configured to generate a random number; The digest value calculation circuit is configured to perform a hash calculation based on the original key and the serial number to obtain a first digest value; It is also configured to perform a hash calculation based on the first digest value and the random number to obtain a second digest value; The second input control circuit is configured to receive a third digest value input by the host accessing the hard disk; The third digest value is obtained by performing a hash calculation based on the first digest value and the random number; The comparison circuit is configured to compare whether the second digest value and the third digest value are the same; it is also configured to, if the second digest value and the third digest value are the same, output an authentication passed signal to enable the hard disk to respond to the read / write request of the host; if the second digest value and the third digest value are different, output a determination failure signal to cause the hard disk not to respond to the read / write request of the host.
2. The solid-state drive access control circuit according to claim 1, wherein The digest value calculation circuit includes: a first hashing algorithm circuit and a second hashing algorithm circuit; the input end of the first hashing algorithm circuit is connected to the key reading control circuit and the first input control circuit; the output end of the first hashing algorithm circuit is connected to the input end of the second hashing algorithm circuit, and the input end of the second hashing algorithm circuit is also connected to the random number generator; the output end of the second hashing algorithm circuit is connected to the input end of the comparison circuit; The first hashing algorithm circuit is configured to perform a hash calculation based on the original key and the serial number to obtain a first digest value; The second hashing algorithm circuit is configured to perform a hash calculation based on the first digest value and the random number to obtain a second digest value.
3. The solid-state drive access control circuit according to claim 2, wherein, It further includes a first buffer register, and the first hashing algorithm circuit is connected to the second hashing algorithm circuit through the first buffer register.
4. The solid state drive access control circuit according to claim 1, wherein The abstract value calculation circuit includes: a first selector, a second selector, a third selector, and a third hashing algorithm circuit; a first input end of the first selector is connected to the key reading control circuit, a second input end of the first selector is connected to a first output end of the third selector, and an output end of the first selector is connected to an input end of the third hashing algorithm circuit; a first input end of the second selector is connected to the first input control circuit, a second input end of the second selector is connected to the random number generator, and an output end of the second selector is connected to the input end of the third hashing algorithm circuit; an output end of the third hashing algorithm circuit is connected to an input end of the third selector; a second output end of the third selector is connected to an input end of the comparison circuit; The first selector is configured to select the original key and output it to the third hashing algorithm circuit during a first time period; The second selector is configured to select the serial number and output it to the third hashing algorithm circuit during a first time period; The third hashing algorithm circuit is configured to perform hashing calculation based on the original key and the serial number to obtain a first abstract value; The third selector is configured to output the first abstract value to the first selector; The first selector is further configured to select the first abstract value and output it to the third hashing algorithm circuit during a second time period; The second selector is further configured to select the random number and output it to the third hashing algorithm circuit during a second time period; The third hashing algorithm circuit is further configured to perform hashing calculation based on the first abstract value and the random number to obtain a second abstract value; The third selector is further configured to output the second abstract value to the comparison circuit.
5. The solid-state drive access control circuit according to claim 4, wherein It further includes a second buffer register, and the third hashing algorithm circuit is connected to the third selector through the second buffer register.
6. The solid state drive access control circuit according to claim 1, wherein It further includes a key writing control circuit; the key writing control circuit is connected to the key memory; the key writing control circuit is configured to write the original key into the key memory.
7. The solid-state drive access control circuit according to claim 1, wherein It further includes a main control state machine; the main control state machine is respectively connected to the key memory, the key reading control circuit, the abstract value calculation circuit, the first input control circuit, the random number generator, the second input control circuit, and the comparison circuit for control connection.
8. The solid-state drive access control circuit according to claim 1, characterized in that It further includes a third buffer register and a fourth buffer register; the first input control circuit is connected to the abstract value calculation circuit through the third buffer register, and the random number generator is connected to the abstract value calculation circuit through the fourth buffer register.
9. A solid-state drive, characterized in that, It includes: The solid-state drive access control circuit according to any one of claims 1-8.
10. A solid-state drive access control system, characterized in that, It includes: A host and the solid-state drive according to claim 9; the solid-state drive includes an interface circuit, and the interface circuit is connected to the comparison circuit; the host includes a serial number memory, a fourth hashing algorithm circuit, and an output interface circuit; the serial number memory is respectively connected to the first input control circuit and the fourth hashing algorithm circuit, the fourth hashing algorithm circuit is connected to the output interface circuit, and the output interface circuit is connected to the second input control circuit; The serial number memory is configured to store a serial number and a first digest value; The fourth hashing algorithm circuit is configured to perform a hashing calculation based on the first digest value and the random number to obtain a third digest value.
Citation Information
Patent Citations
Solid state disk and solid state disk access control system
CN217640204U