A Two-Way Authentication Method for Encrypted Hard Disk-Host Based on Hash Algorithm
By using hashing algorithms and dividing the encryption key into three methods in encrypted hard disk-host bidirectional authentication, the problems of data leakage, high computing resource consumption and third-party certificate management in hardware encrypted hard disk technology are solved, and more efficient and secure encrypted hard disk authentication is achieved.
Patent Information
- Application Number
- CN202211557304.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-06
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-12-06
AI Technical Summary
Existing hardware encrypted hard disk technology is prone to leak important data stored in hard disk media, or the calculation amount is too large, the resource consumption is too large, and a secure third party needs to manage the certified certificate.
The two-way authentication method of encrypted hard disk-host based on hash algorithm is used to divide the encryption key into three copies, one is saved in the host, one is saved in the encrypted hard disk, and the other is saved in the authenticated UKey. The identity authentication protocol between the host, the authenticated UKey and the encrypted hard disk is designed through the hash algorithm.
It reduces computing performance losses, shortens the authentication time during power-on startup, ensures the physical separation of the encryption key and the protection data, and improves the security of the encrypted hard disk.
Smart Images

Figure CN115795433B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security, and particularly relates to a method for two-way authentication between an encrypted hard disk and a host based on a hash algorithm. Background Art
[0002] While storage technology is developing rapidly, information security has also become an important topic. Current research on secure storage technology mainly ensures the integrity, reliability, and non-disclosure of stored file data, and only legitimate users can access the corresponding data. To solve the above problems, two methods of data encryption and identity authentication are required. Encrypted storage means encrypting the data before it is stored on the hard disk and decrypting the ciphertext when reading the data to present it in plaintext. Identity authentication means adding a barrier of identity authentication before reading the data to protect sensitive resources.
[0003] Generally speaking, to ensure the security of the hard disk, identity authentication and hard disk encryption are usually combined. In identity authentication, digital certificates are generally used to authenticate legitimate users, and a corresponding certificate issuing authority is used for unified distribution and management of the certificates. In data encryption, some current hard disk encryption technologies on the market mostly store the encryption key in the hard disk itself. This method is not conducive to the centralized management and hierarchical protection of the key. To protect the data encryption key, it is usually split and stored. One part of the key component is stored in the encrypted hard disk, and the other part is stored in an external device such as a UKey to ensure the physical separation of the key from the encrypted data. After successful identity authentication, the key components are sent to the encrypted hard disk for combination to form a complete encryption key to protect the data.
[0004] Currently, some hardware encrypted hard disk technologies mostly store the key in the hard disk itself. This method is not conducive to the centralized management and hierarchical protection of the key, and it also enables attackers to obtain the key by means such as directly reading the hard disk when they master the key protection scheme, thus leaking important data stored in the hard disk medium. Another part of the encrypted hard disk technology stores some key components in an external device. After the external device is authenticated with the encrypted hard disk, it is transmitted to the encrypted hard disk for combination. However, the authentication method is mostly based on an asymmetric encryption algorithm and uses a public key certificate for identity authentication. This results in a relatively large computational amount and resource consumption when authenticating the hard disk, and a secure third party is required to manage the authentication certificate. Summary of the Invention
[0005] (1) Technical Problems to be Solved
[0006] The technical problem to be solved by the present invention is how to provide an encrypted hard disk-host bidirectional authentication method based on a hash algorithm to solve the problems that the existing hardware encrypted hard disk technology is prone to leaking important data stored in the hard disk medium, or has a large amount of calculation, consumes too many resources, and requires a secure third party to manage the authentication certificate.
[0007] (II) Technical solution
[0008] In order to solve the above technical problems, the present invention proposes an encrypted hard disk-host bidirectional authentication assembly method based on a hash algorithm, the method comprising the following steps:
[0009] S11. The administrator starts the key management system, enters the host ID and hard disk ID, and generates the corresponding hard disk encryption key K work , mutual authentication key K between the host and the hard disk pd , mutual authentication key K between the host and the authentication UKey ps and a key KEK for protecting the encryption key component;
[0010] S12, connect the assembled UKey to the key management system, and the key management system uses the digest algorithm to encrypt the encryption key K work Calculate the key verification code C and use the mutual authentication key K between the host and the hard disk pd XOR calculation with the hard disk identifier to obtain the mutual authentication key ciphertext K ’ pd , and the encryption key K work Divide into three parts to get K w1 , K w2 and K w3 , the corresponding assembly executable program Prog as , mutual authentication key K between the host and the hard disk pd , mutual authentication key K between the host and the authentication UKey ps , mutual authentication key ciphertext K ’ pd , encryption key protection key KEK, encryption key component K w1 , K w2 And the key verification code C is imported into the assembly UKey;
[0011] S13, connect the authentication UKey to the key management system, use the key protection key KEK and key component K w3 Perform XOR operation to obtain the key component ciphertext CT, and execute the corresponding authentication executable program Prog au , mutual authentication key K between the host and the authentication UKey ps and importing the encrypted key component ciphertext CT encrypted using the key protection key into the authentication UKey;
[0012] S14. The administrator inserts the assembled UKey into the host and starts the host. After the host starts, it detects the assembled UKey and reads the assembled executable program Prog in the assembled UKey to run in the host. as Read and run in the host;
[0013] S15. The assembled executable program Prog as Reads the configuration parameters in the assembled UKey and saves the encryption key component K w1 , the mutual authentication key K between the host and the hard disk pd , the mutual authentication key K between the host and the authentication UKey ps into the host, and saves the encryption key component K w2 , the encryption key protection key KEK, the ciphertext of the mutual authentication key K ’ pd and the key verification code C into the encrypted hard disk.
[0014] Further, the encrypted hard disk is used for secure encryption storage and decryption output of data, saves the encryption key component, installs an operating system, and can only be started after successful power-on authentication.
[0015] Further, the key management system is used to manage the encryption key and related authentication information of the encrypted hard disk, and imports and configures the executable program, authentication parameters and key components of the assembled UKey and the authentication UKey under the operation of the administrator.
[0016] Further, the host is used to load the hard disk, bind with the hard disk, store the component of the encryption key in the encrypted hard disk in the host, perform identity authentication with the encrypted hard disk and the authentication UKey when the host is powered on, and after passing, can send the key component to the hard disk to form an encryption key in the hard disk to perform encryption and decryption operations on the data.
[0017] Further, the assembled UKey is used to configure the password parameters in the host and the encrypted hard disk.
[0018] Further, the assembled executable program Prog as and the authentication executable program Prog au are respectively stored in the assembled UKey and the authentication UKey, and are used to be read and executed by the host BIOS when powered on to complete the authentication or assembly work.
[0019] Further, in step S12, the encryption key K work is evenly divided into three parts to obtain K w1 , K w2 and K w3 .
[0020] Further, the encryption key K work is 48 bytes in length. The first 16 bytes are used as K w1 , the middle 16 bytes are used as K w2 , and the last 16 bytes are used as K w3 .
[0021] The present invention also provides a hash algorithm-based encryption hard disk-host mutual authentication method, which includes the following steps:
[0022] S21. After inserting the authentication UKey, the host powers on and starts. After the host BIOS starts, it recognizes the authentication UKey and reads the authentication executable program Prog au in it;
[0023] S22. The host BIOS reads the authentication executable program Prog au into the host and runs the authentication executable program Prog au to read the mutual authentication key K ps in the authentication UKey, and compares it with the mutual authentication key stored in the host. If they are the same, the host and the authentication UKey pass the authentication, and the authentication executable program Prog au reads the ciphertext CT of the key component stored in the authentication UKey into the host;
[0024] S23. The authentication executable program Prog au generates a random number R B and sends R B to the encrypted hard disk;
[0025] S24. The encrypted hard disk generates a random number R A , decrypts it using the hard disk identifier to obtain the mutual authentication key K pd between the host and the hard disk, and uses the hash algorithm to calculate K pd and the random number R A to generate TOKEN AB =R A ||Hash(K pd ||R A ||R B ), and sends it to the authentication executable program Prog au ;
[0026] S25. The authentication executable program Prog au calculates and verifies TOKEN AB , calculates TOKEN BA =Hash(K pd ||R B ||R A ) and sends it to the encrypted hard disk;
[0027] S26. Encrypted hard drive calculates and verifies TOKEN BA = Hash(K pd ||R B ||R A ), and returns it to the authentication executable program Prog au Authentication success information;
[0028] S27. After authentication, the authentication executable program Prog au transmits the ciphertext CT of the key component and the key component K in the host w1 to the encrypted hard drive;
[0029] S28. The encrypted hard drive uses the encryption key to perform an exclusive OR operation on the key encryption key KEK and the ciphertext CT of the key component to decrypt and obtain K w3 , and combines K w1 , K w2 and K w3 into the complete encryption key K w , and uses the digest algorithm to calculate the encryption key K w . Compare the calculation result with the key verification code C to check if they are consistent. If they are consistent, the encryption and decryption operations can be performed normally.
[0030] (III) Beneficial effects
[0031] The present invention proposes a two-way authentication method for an encrypted hard drive-host based on the hash algorithm. The present invention designs an authentication protocol based on the hash algorithm among the host, the encrypted hard drive, and the authentication UKey, reducing the computational performance loss and shortening the authentication time during power-on startup. The present invention also divides the encryption key of the hard drive into three parts, one part is stored in the host, one part is stored in the encrypted hard drive, and one part is stored in the authentication UKey. Only after the authentication UKey, the host, and the encrypted hard drive pass the authentication during startup, the key components are sent to the hard drive to synthesize the complete key for decryption, ensuring the physical separation of the encryption key and the protected data. Compared with the prior art, the present invention proposes a two-way authentication method for an encrypted hard drive-host based on the hash algorithm, reducing the resource consumption caused by using public key certificates and improving the security of the encrypted hard drive. Brief description of the drawings
[0032] Figure 1 is the overall block diagram of the solution of the present invention;
[0033] Figure 2 is the assembly flow chart;
[0034] Figure 3 is the host startup flow chart. Detailed implementation manners
[0035] To make the objectives, content, and advantages of the present invention clearer, the following further describes in detail the specific implementation manners of the present invention in conjunction with the accompanying drawings and embodiments.
[0036] The objective of the present invention is to propose a method for secure authentication of an encrypted hard disk based on a hash algorithm. The encryption key of the encrypted hard disk is divided into three parts, one part is stored in the hard disk, one part is stored in the host, and one part is stored in the authentication UKey. When the computer system is powered on and starts up, lightweight identity authentication based on the hash algorithm is performed between the authentication UKey, the host, and the encrypted hard disk. After the authentication is completed, the encrypted key components are transmitted to the encrypted hard disk for combination to obtain the complete encryption key; and a key management system is designed to configure and manage the password parameters and encryption keys for authentication, and use the assembly UKey to configure the authentication parameters and encryption key components for the host and the encrypted hard disk. This method can improve the security of the computer system, reduce the computational overhead of identity authentication, and effectively prevent the leakage problem caused by the theft of storage devices.
[0037] A method for two-way authentication between an encrypted hard disk and a host based on a hash algorithm, which can be applied to occasions with high security requirements.
[0038] As Figure 1 shown, the solution includes an encrypted hard disk, a key management system, a host, an assembly UKey, and an authentication UKey; the encrypted hard disk can achieve secure encrypted storage and decryption output of data, and save the encrypted key components, and has an operating system installed, and can only be started after successful power-on authentication; the key management system is used to manage the encryption keys and related authentication information of the encrypted hard disk, and can import and configure executable programs, authentication parameters, and key components for the assembly UKey and the authentication UKey under the operation of the administrator; the host is used to load the hard disk and is bound to the hard disk, stores the components of the encryption key in the encrypted hard disk in the host, performs identity authentication with the encrypted hard disk and the authentication UKey when the host is powered on, and can send the key components to the hard disk after passing, and combines them into an encryption key in the hard disk to perform encryption and decryption operations on the data; the assembly UKey is used to configure the password parameters in the host and the encrypted hard disk; the authentication UKey is used to complete the identity authentication and key distribution with the host and the encrypted hard disk. Among them, the executable programs are stored in the assembly UKey and the authentication UKey, and are mainly used to be read and executed by the host BIOS during power-on to complete the authentication or assembly work.
[0039] As Figure 2 shown, the assembly operations of the authentication UKey, the encrypted hard disk, and the host include the following steps:
[0040] S11. The administrator starts the key management system, inputs the host identifier and the hard disk identifier, and generates the corresponding hard disk encryption key K work, the mutual authentication key K between the host and the hard disk pd , the mutual authentication key K between the host and the authentication UKey ps and the key KEK for protecting the encryption key components;
[0041] S12. Connect the assembly UKey to the key management system. The key management system uses a digest algorithm to calculate the key check code C for the encryption key K work . Calculate the mutual authentication key ciphertext K pd by performing an exclusive OR operation on the mutual authentication key K between the host and the hard disk ’ pd and the hard disk identifier, and divide the encryption key K work into three equal parts to obtain K w1 , K w2 and K w3 . Import the corresponding assembly executable program Prog as , the mutual authentication key K between the host and the hard disk pd , the mutual authentication key K between the host and the authentication UKey ps , the mutual authentication key ciphertext K ’ pd , the encryption key protection key KEK, the encryption key components K w1 , K w2 and the key check code C into the assembly UKey;
[0042] Among them, if the encryption key K work is 48 bytes in length, the first 16 bytes are one part, the middle 16 bytes are one part, and the last 16 bytes are one part.
[0043] S13. Connect the authentication UKey to the key management system. Perform an exclusive OR operation on the key protection key KEK and the key component K w3 to obtain the key component ciphertext CT. Import the corresponding authentication executable program Prog au , the mutual authentication key K between the host and the authentication UKey ps and the encrypted key component ciphertext CT encrypted with the key protection key into the authentication UKey.
[0044] S14. The administrator inserts the assembly UKey into the host and starts the host. After the host starts, it detects the assembly UKey and reads the assembly executable program Prog as in the assembly UKey into the host for running;
[0045] S15. The assembly executable program Prog as reads the configuration parameters in the assembly UKey and obtains the encryption key components K w1 , the mutual authentication key K between the host and the hard diskpd The mutual authentication key K between the host and the authentication UKey ps is saved in the host, and the encrypted key component K w2 , the encrypted key protection key KEK, the ciphertext of the mutual authentication key K ’ pd and the key verification code C are saved in the encrypted hard disk.
[0046] As Figure 3 shown, the startup process of the host loading the encrypted hard disk is as follows:
[0047] S21. After inserting the authentication UKey, the host powers on and starts. After the host BIOS starts, it recognizes the authentication UKey and reads the authentication executable program Prog au ;
[0048] S22. The host BIOS reads the authentication executable program Prog au into the host and runs the authentication executable program Prog au to read the mutual authentication key K in the authentication UKey ps , and compares it with the mutual authentication key stored in the host. If they are the same, the host and the authentication UKey pass the authentication, and the authentication executable program Prog au reads the ciphertext CT of the key component saved in the authentication UKey into the host;
[0049] S23. The authentication executable program Prog au generates a random number R B , and sends R B to the encrypted hard disk;
[0050] S24. The encrypted hard disk generates a random number R A , decrypts it using the hard disk identifier to obtain the mutual authentication key K between the host and the hard disk pd , and uses the hash algorithm to calculate K pd and the random number R A to generate TOKEN AB =R A ||Hash(K pd ||R A ||R B ), and sends it to the authentication executable program Prog au ;
[0051] S25. The authentication executable program Prog au calculates and verifies TOKEN AB , calculates TOKEN BA =Hash(K pd ||R B ||R A) Send to the encrypted hard disk;
[0052] S26. The encrypted hard disk calculates and verifies the TOKEN BA = Hash(K pd ||R B ||R A ), and returns it to the authentication executable program Prog au Authentication success information;
[0053] S27. After authentication, the authentication executable program Prog au Transmits the ciphertext CT of the key component and the key component K in the host w1 to the encrypted hard disk;
[0054] S28. The encrypted hard disk uses the encryption key to protect the key KEK and performs an exclusive OR operation on the ciphertext CT of the key component to decrypt and obtain K w3 , and uses K w1 , K w2 and K w3 to combine into the complete encryption key K w , and uses the digest algorithm to calculate the encryption key K w . Compare the calculation result with the key verification code C to check if they are consistent. If they are consistent, the encryption and decryption operations can be performed normally.
[0055] The present invention designs an identity authentication protocol among the host, the authentication UKey, and the encrypted hard disk based on the hash algorithm. On the basis of meeting the security authentication, it utilizes the simplicity of the exclusive OR operation to reduce the computational overhead brought by using symmetric algorithms or asymmetric algorithms and shorten the authentication time.
[0056] The present invention also realizes the management and protection of the authentication parameters and the encrypted key components in the host, the authentication UKey, and the encrypted hard disk by adding a key management system. The key management system generates corresponding authentication parameters and encryption keys, divides the encryption key into three parts, and configures the relevant authentication parameters and key components into the host, the authentication UKey, and the encrypted hard disk through the assembled UKey. After the configuration is completed, the user can use the authentication UKey to authenticate with the host and finally start the computer system.
[0057] Through the above functions, the present invention realizes the identity authentication of the encrypted hard disk, reduces the authentication time, and realizes the management and protection of the encryption key in the encrypted hard disk, enhances the security of the encrypted hard disk, can start the system faster, and is applicable to occasions with high requirements for performance and security.
[0058] The present invention designs an authentication protocol based on the hash algorithm among the host, the encrypted hard disk, and the authentication UKey, reducing the computational performance loss and shortening the authentication time during power-on startup. The present invention also divides the encryption key of the hard disk into three parts, one part is stored in the host, one part is stored in the encrypted hard disk, and one part is stored in the authentication UKey. Only after the authentication UKey, the host, and the encrypted hard disk pass the authentication during startup, the key components are sent to the hard disk to synthesize the complete key for decryption, ensuring the physical separation of the encryption key and the protected data. Compared with the prior art, the present invention proposes a two-way authentication method for the encrypted hard disk-host based on the hash algorithm, reducing the resource consumption caused by the use of public key certificates and improving the security of the encrypted hard disk.
[0059] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. An encryption hard disk-host two-way authentication assembly method, characterized in that, The method includes the following steps: The method includes the following steps: S11. The administrator starts the key management system, inputs the host identifier and the hard disk identifier, and generates the corresponding hard disk encryption key K work , the mutual authentication key K between the host and the hard disk pd , the mutual authentication key K between the host and the authentication UKey ps and the key KEK for protecting the encryption key components; S12. Connect the assembled UKey to the key management system. The key management system uses a digest algorithm to calculate the key verification code C for the encryption key K work . Calculate the mutual authentication key K pd between the host and the hard disk, and perform an exclusive OR operation with the hard disk identifier to obtain the mutual authentication key ciphertext K ’ pd . And divide the encryption key K work into three parts to obtain K w1 , K w2 and K w3 . Import the corresponding assembled executable program Prog as , the mutual authentication key K pd between the host and the hard disk, the mutual authentication key K ps between the host and the authentication UKey, the mutual authentication key ciphertext K ’ pd , the encryption key protection key KEK, the encryption key components K w1 , K w2 , and the key verification code C into the assembled UKey; S13. Connect the authentication UKey to the key management system, and perform an exclusive OR operation on the key protection key KEK and the key component K w3 to obtain the ciphertext CT of the key component. Import the corresponding authentication executable program Prog au , the mutual authentication key K ps between the host and the authentication UKey, and the ciphertext CT of the encrypted key component encrypted with the key protection key into the authentication UKey; S14. The administrator inserts the assembled UKey into the host and starts the host. After the host starts, it detects the assembled UKey and reads the assembled executable program Prog in the assembled UKey to run in the host; as S15. Assemble the executable program Prog as Read the configuration parameters in the assembled UKey, and save the encrypted key component K w1 , the mutual authentication key K pd between the host and the hard disk, and the mutual authentication key K ps between the host and the authentication UKey into the host, and save the encrypted key component K w2 , the encrypted key protection key KEK, the ciphertext of the mutual authentication key K ’ pd and the key check code C into the encrypted hard disk.
2. The encrypted hard disk-host two-way authentication assembly method according to claim 1, characterized in that An encrypted hard disk is used for secure encrypted storage and decryption output of data, and the encrypted key components are saved. It is installed with an operating system and can only be started after successful power-on authentication.
3. The encrypted hard disk-host two-way authentication assembly method according to claim 2, wherein, The key management system is used to manage the encrypted keys and related authentication information of the encrypted hard disk, and under the operation of the administrator, it imports and configures the executable programs, authentication parameters, and key components for the assembled UKey and the authentication UKey.
4. The encrypted hard disk-host two-way authentication assembly method according to claim 3, wherein The host is used to load the hard disk and is bound to the hard disk. The components of the encrypted key in the encrypted hard disk are stored in the host. When the host is powered on, it performs identity authentication with the encrypted hard disk and the authentication UKey. After passing, it can send the key components to the hard disk, and the key components are combined into an encrypted key in the hard disk to perform encryption and decryption operations on the data.
5. The encryption hard disk-host two-way authentication assembly method according to claim 4, characterized in that, The assembled UKey is used to configure the password parameters in the host and the encrypted hard disk.
6. The encryption hard disk-host two-way authentication assembly method according to claim 5, characterized in that, The authentication UKey is used to complete the identity authentication and key distribution with the host and the encrypted hard disk.
7. The encrypted hard disk-host two-way authentication assembly method according to claim 6, characterized in that, Assembly executable program Prog as and authentication executable program Prog au are respectively stored in the assembly UKey and the authentication UKey, and are used to be read and executed by the host BIOS when powering on to complete the authentication or assembly work.
8. The encrypted hard disk-host two-way authentication assembly method according to claim 7, characterized in that, In the step S12, the encryption key K work is evenly divided into three parts to obtain K w1 , K w2 and K w3 .
9. The encrypted hard disk-host two-way authentication assembly method according to claim 8, characterized in that, Encryption key K work is 48 bytes in length, with the first 16 bytes as K w1 , the middle 16 bytes as K w2 , and the last 16 bytes as K w3 .
10. An encryption hard disk-host two-way authentication method based on the hash algorithm of the assembly method according to any one of claims 1-9, characterized in that, The method includes the following steps: S21. After inserting the authentication UKey, the host powers on and starts. After the host BIOS starts, it recognizes the authentication UKey and reads the authentication executable program Prog therein. au ; S22. The host BIOS reads the authentication executable program Prog au into the host and runs the authentication executable program Prog au to read the mutual authentication key K in the authentication UKey ps , and compare it with the mutual authentication key stored in the host. If they are the same, the host and the authentication UKey pass the authentication, and the authentication executable program Prog au reads the ciphertext CT of the key component saved in the authentication UKey into the host; S23, Authentication Executable Program Prog au Generate random number R B , and send R to the encrypted hard drive B ; S24. The encrypted hard disk generates a random number R A , decrypts the hard disk identifier to obtain the mutual authentication key K between the host and the hard disk pd , and uses the hash algorithm to calculate K pd and the random number R A to generate TOKEN AB = R A || Hash(K pd || R A || R B ), and sends it to the authentication executable program Prog au ; S25, Authentication Executable Program Prog au Calculate Verification TOKEN AB , Calculate TOKEN BA = Hash(K pd ||R B ||R A ) and send it to the encrypted hard disk; S26. Encrypted hard drive calculates and verifies TOKEN BA =Hash(K pd ||R B ||R A ), and returns it to the authentication executable program Prog au Authentication success information; S27. After authentication is passed, the authentication executable program Prog au transmits the ciphertext CT of the key component and the key component K in the host w1 to the encrypted hard disk; S28. The encrypted hard disk uses the encryption key to perform an exclusive OR operation on the key encryption key KEK and the ciphertext CT of the key component to decrypt and obtain K w3 , and use K w1 , K w2 and K w3 to combine into the complete encryption key K w , and use the digest algorithm to calculate the encryption key K w . Compare whether the calculation result is consistent with the key verification code C. If they are consistent, the encryption and decryption operations can be performed normally.
Citation Information
Patent Citations
System and method for full disk encryption based on hardware
CN104951409A
Encryption device, decryption device, cryptography verifying device, encryption method, decryption method and program
JP2010049214A