Method, device, computer storage medium and solid state hard disk for implementing key processing

By using physical random sources to generate the key during key processing and masking the key through multiple hard encryption processing, the problem of leakage risks in the generation, storage and use of the key is solved, and efficient security protection for KEK and MEK is achieved.

CN115842628BActive Publication Date: 2025-05-16HEFEI DATANG STORAGE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211529312.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2025-05-16
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

In the prior art, the key encryption key (KEK) and data encryption key (MEK) are at risk of leakage during generation, storage and use, and it is difficult to effectively resist side channel attacks, resulting in insufficient security.

Method used

The initial KEK and MEK are generated through preset physical random sources, and during generation, storage and use, the KEK and MEK are masked through multiple hard encryption processing to prevent physical cracking and side channel attacks.

Benefits of technology

Improve the randomness and security of KEK and MEK, effectively prevent physical cracking and side channel attacks, and improve the overall security of key applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115842628B_ABST
    Figure CN115842628B_ABST
Patent Text Reader

Abstract

Disclosed herein are a method, device, computer storage medium, and solid-state hard disk for implementing key processing. In an embodiment of the present invention, a key encryption key (KEK) and a data encryption key (MEK) are generated from a physical random source, thereby improving the randomness of the initially generated KEK and MEK. During the generation, storage, and use processes, KEK and MEK are masked and protected by hard encryption, thereby preventing physical cracking, improving the performance of KEK and MEK in resisting side-channel attacks, and improving the security of key application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This article relates to but is not limited to information security technology, and in particular to a method, device, computer storage medium and solid-state hard disk for implementing key processing. Background Art

[0002] With the continuous development of security attack technology, information security in the field of data storage has received more and more attention. The emergence of encrypted hard disks has played a certain role in promoting data storage security; however, with the continuous maturity of attack technologies such as side channels, key encryption keys (KEK, Key Encryption Key) and data encryption keys (MEK, Message Encryption Key) have gradually become targets that attackers can exploit; currently, there is a risk of leakage in the generation, storage and use of KEK and MEK. How to improve the performance of KEK and MEK in resisting side channel attacks and improve the security of KEK and MEK applications has become a problem to be solved. Summary of the invention

[0003] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.

[0004] The embodiments of the present invention provide a method, device, computer storage medium and solid-state hard disk for implementing key processing, which can improve the performance of key encryption keys and data encryption keys in resisting side-channel attacks and improve the security of key application.

[0005] An embodiment of the present invention provides a method for implementing key processing, including:

[0006] When receiving a preset encapsulation instruction, generating a first preset value of an initial key encryption key KEK and a second preset value of a data encryption key MEK through a preset physical random source TRNG;

[0007] Performing a first hard encryption on each initial KEK using a first random number, and writing all the first hard-encrypted initial KEKs as first KEKs into a one-time programmable password (OTP) memory;

[0008] Performing a second hard encryption on the first KEK by using the second random number and the first random number in sequence, and writing the first KEK after the second hard encryption as the second KEK into a random access memory RAM storing a key;

[0009] Performing a third hard encryption on the second KEK by using a third random number and a second random number in sequence, and writing the third hard-encrypted second KEK as a third KEK into the key buffer;

[0010] Using the third KEK as the key, perform symmetric encryption operations on each generated MEK, and write all MEKs that have undergone symmetric encryption operations as encrypted MEKs into the OTP memory;

[0011] Wherein, the first random number is a fixed random number.

[0012] On the other hand, an embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium stores a computer program, and when the computer program is executed by a processor, the method for implementing key processing is implemented.

[0013] In another aspect, an embodiment of the present invention further provides a terminal, comprising: a memory and a processor, wherein the memory stores a computer program; wherein:

[0014] The processor is configured to execute the computer program in the memory;

[0015] When the computer program is executed by the processor, the method for implementing key processing as described above is implemented.

[0016] In another aspect, an embodiment of the present invention further provides a solid state drive for implementing key processing, comprising: a generation unit, a first hard encryption unit, a second hard encryption unit, a third hard encryption unit and an encryption processing unit; wherein,

[0017] The generating unit is configured to: upon receiving a preset encapsulation instruction, generate a first preset value of initial key encryption keys KEK and a second preset value of data encryption keys MEK through a preset physical random source TRNG;

[0018] The first hard encryption unit is configured to: perform first hard encryption on each initial KEK using a first random number, and write all the first hard-encrypted initial KEKs into the OTP memory as first KEKs;

[0019] The second hard encryption unit is configured to: perform second hard encryption on the first KEK by using the second random number and the first random number in sequence, and write the first KEK after the second hard encryption as the second KEK into a random access memory RAM storing a key;

[0020] The third hard encryption unit is configured to: perform a third hard encryption on the second KEK by using a third random number and a second random number in sequence, and write the third hard-encrypted second KEK into the key buffer as the third KEK;

[0021] The encryption processing unit is configured to: use the third KEK as a key, perform symmetric encryption operation on each generated MEK respectively, and write all MEKs that have undergone symmetric encryption operation as encrypted MEKs into the OTP memory;

[0022] Wherein, the first random number is a fixed random number.

[0023] The technical solution of the present application includes: when a preset encapsulation instruction is received, a first preset value of initial key encryption keys (KEK) and a second preset value of data encryption keys (MEK) are generated through a preset physical random source (TRNG); each initial KEK is first hard-encrypted by a first random number, and all the initial KEKs that have undergone the first hard encryption are written as first KEKs into a one-time programmable password (OTP) memory; the first KEK is second hard-encrypted by a second random number and a first random number in sequence, and the first KEK that has undergone the second hard encryption is written as a second KEK into a random access memory (RAM) storing keys; the second KEK is third hard-encrypted by a third random number and a second random number in sequence, and the second KEK that has undergone the third hard encryption is written as a third KEK into a key buffer; using the third KEK as a key, symmetric encryption operations are performed on each generated MEK, and all MEKs that have undergone the symmetric encryption operations are written as encrypted MEKs into the OTP memory; wherein the first random number is a fixed random number. The embodiment of the present invention generates a key encryption key and a data encryption key from a physical random source, thereby improving the randomness of the initially generated KEK and MEK. During the generation, storage and use processes, the KEK and MEK are masked and protected by hard encryption, thereby preventing physical cracking, improving the performance of the KEK and MEK in resisting side-channel attacks, and improving the security of key application.

[0024] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The accompanying drawings are used to provide a further understanding of the technical solution of the present invention and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present invention and do not constitute a limitation on the technical solution of the present invention.

[0026] Figure 1 A flowchart of a method for implementing key processing according to an embodiment of the present invention;

[0027] Figure 2 A structural block diagram of a solid-state hard disk that implements key processing according to an embodiment of the present invention;

[0028] Figure 3 The figure is a schematic diagram of the structure of a solid state hard disk according to an application example of the present invention. DETAILED DESCRIPTION

[0029] In order to make the purpose, technical solution and advantages of the present invention more clear, the embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other arbitrarily without conflict.

[0030] The steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. Also, although a logical sequence is shown in the flowchart, in some cases, the steps shown or described can be performed in a sequence different from that shown here.

[0031] Figure 1 Flow chart of a method for implementing key processing according to an embodiment of the present invention, as shown in FIG. Figure 1 As shown, including:

[0032] Step 101: upon receiving a preset encapsulation instruction, a first preset value of an initial key encryption key (KEK) and a second preset value of a data encryption key (MEK) are generated by a preset physical random source (TRNG);

[0033] Step 102: Perform first hard encryption on each initial KEK using a first random number, and write all the first hard-encrypted initial KEKs as first KEKs into a one-time programmable password (OTP) memory;

[0034] Step 103: perform a second hard encryption on the first KEK using the second random number and the first random number in sequence, and write the second hard-encrypted first KEK into a random access memory (RAM) storing keys as the second KEK;

[0035] Step 104: perform a third hard encryption on the second KEK using the third random number and the second random number in sequence, and write the third hard-encrypted second KEK into the key buffer as the third KEK;

[0036] Step 105: Use the third KEK as the key to perform symmetric encryption operation on each generated MEK, and write all MEKs that have undergone symmetric encryption operation into the OTP memory as encrypted MEKs;

[0037] Among them, the first random number is a fixed random number.

[0038] The embodiment of the present invention generates a key encryption key and a data encryption key from a physical random source, thereby improving the randomness of the initially generated KEK and MEK. During the generation, storage and use processes, the KEK and MEK are masked and protected by hard encryption, thereby preventing physical cracking, improving the performance of the KEK and MEK in resisting side-channel attacks, and improving the security of key application.

[0039] In an exemplary embodiment, a first preset number of initial KEKs that have undergone first hard encryption in an embodiment of the present invention are connected in sequence to obtain a first KEK.

[0040] In an exemplary embodiment, the MEKs that have undergone symmetric encryption operations in the embodiment of the present invention are connected in sequence to obtain the encrypted MEK.

[0041] In an exemplary embodiment, the first preset value of the embodiment of the present invention may be predetermined by a person skilled in the art; the second preset value may be predetermined by a person skilled in the art according to a usage scenario of the encrypted MEK;

[0042] In an exemplary embodiment, the location where the first KEK is written into the OTP memory and the location where the encrypted MEK is written into the OTP memory in the embodiment of the present invention can be set with reference to related technologies, which will not be described in detail here.

[0043] In an exemplary embodiment, in the embodiment of the present invention, the first hard encryption includes a first XOR operation; the second hard encryption includes a second XOR operation; and the third hard encryption includes a third XOR operation. In an exemplary embodiment, the first hard encryption is performed on the first KEK by using the second random number and the first random number, including: after performing a first XOR operation on the first KEK by using the second random number, performing a first XOR operation on the first KEK after the first XOR operation by using the first random number; it should be noted that the above two first XOR operations in the first hard encryption may be the same or different; similarly, the XOR operations included in the second hard encryption process may be the same or different; the XOR operations included in the third hard encryption process may be the same or different;

[0044] In an exemplary embodiment, the specific algorithms of the first XOR operation, the second XOR operation, and the third XOR operation in the embodiment of the present invention may be the same or different. In an exemplary embodiment, the first hard encryption, the second hard encryption, and the third hard encryption in the embodiment of the present invention may include other linear operations except the XOR operation.

[0045] In an exemplary embodiment, the second random number in the embodiment of the present invention is a temporarily generated random number, or a fixed random number.

[0046] In an exemplary embodiment, the third random number in the embodiment of the present invention is a temporarily generated random number or a fixed random number.

[0047] In an exemplary embodiment, the symmetric encryption operation in the embodiment of the present invention includes any one of the following algorithms: Advanced Encryption Standard Algorithm (AES), National Secret Algorithm (SM4) or Data Encryption Standard Algorithm (DES).

[0048] In an exemplary embodiment, after all MEKs that have undergone symmetric encryption operations are written into the OTP memory as encrypted MEKs, the method of the embodiment of the present invention further includes:

[0049] When receiving the preset decapsulation instruction, read the encrypted MEK and the first KEK from the OTP memory;

[0050] Performing a fourth hard encryption on the first KEK using the first random number and the second random number in sequence, and writing the fourth hard-encrypted first KEK into the RAM as the fourth KEK;

[0051] performing fifth hard encryption on the fourth KEK by using the second random number and the third random number in sequence, and writing the fourth KEK that has undergone the fifth hard encryption as the fifth KEK into the key buffer;

[0052] Using the obtained fifth KEK as a key, performing a decryption operation on the read encrypted MEK to obtain a decryption operation result;

[0053] The second preset value of decryption operation results are sequentially hard-encrypted using the second random number and the third random number to obtain a decrypted MEK written into the RAM.

[0054] In an exemplary embodiment, the embodiment of the present invention can be implemented by the firmware for processing the key running in the main control chip of the solid state drive. In an exemplary embodiment, the generation, packaging, decapsulation, storage and use of KEK and MEK in the embodiment of the present invention are all completed inside the main control chip of the solid state drive.

[0055] An embodiment of the present invention further provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method for realizing key processing is implemented.

[0056] The embodiment of the present invention further provides a terminal, comprising: a memory and a processor, wherein a computer program is stored in the memory; wherein:

[0057] The processor is configured to execute the computer program in the memory;

[0058] When the computer program is executed by a processor, the method for implementing key processing as described above is implemented.

[0059] Figure 2 The structural block diagram of the solid state drive for implementing key processing in an embodiment of the present invention is as follows: Figure 2 As shown, it includes: a generation unit, a first hard encryption unit, a second hard encryption unit, a third hard encryption unit and an encryption processing unit; wherein,

[0060] The generating unit is configured to: upon receiving a preset encapsulation instruction, generate a first preset value of initial key encryption keys KEK and a second preset value of data encryption keys MEK through a preset physical random source TRNG;

[0061] The first hard encryption unit is configured to: perform first hard encryption on each initial KEK using a first random number, and write all the first hard-encrypted initial KEKs into the OTP memory as first KEKs;

[0062] The second hard encryption unit is configured to: perform second hard encryption on the first KEK by using the second random number and the first random number in sequence, and write the first KEK after the second hard encryption as the second KEK into a random access memory RAM storing a key;

[0063] The third hard encryption unit is configured to: perform a third hard encryption on the second KEK by using a third random number and a second random number in sequence, and write the third hard-encrypted second KEK into the key buffer as the third KEK;

[0064] The encryption processing unit is configured to: use the third KEK as a key, perform symmetric encryption operation on each generated MEK respectively, and write all MEKs that have undergone symmetric encryption operation as encrypted MEKs into the OTP memory;

[0065] Among them, the first random number is a fixed random number.

[0066] In an exemplary embodiment, the second random number in the embodiment of the present invention is a temporarily generated random number, or a fixed random number.

[0067] In an exemplary embodiment, the third random number in the embodiment of the present invention is a temporarily generated random number or a fixed random number.

[0068] In an exemplary embodiment, the symmetric encryption operation in the embodiment of the present invention includes any one of the following algorithms: Advanced Encryption Standard Algorithm (AES), National Secret Algorithm (SM4) or Data Encryption Standard Algorithm (DES).

[0069] In an exemplary embodiment, the device of the embodiment of the present invention further includes a reading unit and a decryption processing unit; wherein,

[0070] The reading unit is configured to: read the encrypted MEK and the first KEK from the OTP memory upon receiving a preset decapsulation instruction;

[0071] The second hard encryption unit is further configured to: perform fourth hard encryption on the first KEK by sequentially using the first random number and the second random number, and write the fourth hard-encrypted first KEK into the RAM as the fourth KEK;

[0072] The third hard encryption unit is further configured to: perform fifth hard encryption on the fourth KEK by sequentially using the second random number and the third random number, and write the fourth KEK that has undergone the fifth hard encryption as the fifth KEK into the key buffer;

[0073] The decryption processing unit is also configured to: use the obtained fifth KEK as the key to perform a decryption operation on the read encrypted MEK to obtain a decryption operation result; perform a sixth hard encryption on the second preset value of decryption operation results through the second random number and the third random number in sequence to obtain the decrypted MEK written into the RAM.

[0074] The following briefly describes the embodiments of the present invention through application examples. The application examples are only used to illustrate the embodiments of the present invention and are not used to limit the protection scope of the embodiments of the present invention.

[0075] Application Examples

[0076] Figure 3 This is a schematic diagram of the structure of the solid-state hard disk of the application example of the present invention. The application example of the present invention reduces the risk of key leakage during the entire life cycle of the encrypted solid-state hard disk by performing security protection on the key generation, key storage and key use links in the encrypted solid-state hard disk. Specifically, KEK and MEK are generated by the physical random source (TRNG) of the main control chip inside the encrypted solid-state hard disk, and do not need to be generated and imported from the outside; after KEK and MEK are generated, they are encrypted and stored in the OTP memory inside the encrypted solid-state hard disk; during use, KEK and MEK are encrypted and stored in the RAM (or register) storing the key inside the encrypted solid-state hard disk, and the key encryption key KEK is also encrypted and transmitted on the path from OTP to RAM (or key register); KEK in ciphertext form participates in the key encapsulation or key decapsulation process of MEK; the coprocessor (Engine) is used to perform symmetric encryption or decryption operations; the application example of the present invention is performed by the firmware for processing the key on the main control chip of the solid-state hard disk to perform the key processing of the embodiment of the present invention.

[0077] KEK generation process:

[0078] The firmware triggers the physical random source (TRNG) to generate a true random number (the first preset value of the initial KEK), the initial KEK is first hard-encrypted with the first random number (Mask R1), and the obtained (KEK R1) is written to the specified address of the OTP memory for storage; wherein, Mask R1 is a fixed random number solidified inside the chip;

[0079] Repeat the above process for a first preset number of initial KEKs until the first number of initial KEKs are all first hard-encrypted and stored in the OTP;

[0080] Packaging process:

[0081] The firmware triggers the key encapsulation to start, and the main control chip loads the first KEK from the OTP to the RAM that stores the key. During the loading process, the first KEK is first hard-encrypted by Mask R2 to obtain KEK ∧ R1 ∧ R2, and then hard encrypts it with Mask R1 to get KEK ∧ R2, the above hard encryption process is the processing process of the second hard encryption of the embodiment of the present invention, and the second hard encryption does not expose the KEK plaintext. The second KEK after the second hard encryption is protected by Mask R2 and stored in RAM; application example of the present invention, the above hard encryption includes but is not limited to XOR operation, and Mask R2 is a temporarily generated random number;

[0082] The firmware triggers the key loading process, and the main control chip will be protected by the second KEK (KEK ∧ R2) is loaded from RAM to the register. During the loading process, the KEK is first hard-encrypted through Mask R3. ∧ R2 ∧ R3, and then hard encrypts it through Mask R2 to obtain the third KEK (KEK ∧ R3), the above hard encryption process is the third hard encryption processing process of the embodiment of the present invention, and the third hard encryption process does not expose the KEK plaintext. The KEK after hard encryption is protected by Mask R3 and stored in Register; wherein the above hard encryption includes but is not limited to XOR operation, and Mask R2 is a temporarily generated random number.

[0083] The firmware triggers a physical random source (TRNG) to generate and a second preset value of MEKs, and outputs the generated MEKs to the coprocessor (Engine);

[0084] The firmware triggers the key encapsulation operation. The Engine uses KEK^R3 as the key and each MEK as plain text to perform symmetric encryption operations with mask protection.

[0085] The firmware uses the result of the symmetric encryption operation as the encrypted MEK, reads it from the register and writes all encrypted MEKs into the OTP memory;

[0086] Decapsulation process:

[0087] The firmware triggers the key decapsulation to start, and the main control chip loads the first KEK from the OTP to the RAM. During the loading process, it is first hard-encrypted by Mask R2, and then hard-encrypted by Mask R1 to obtain the fourth KEK. The hard encryption process does not expose the KEK plaintext. The above hard encryption process is the fourth hard encryption in the embodiment of the present invention. The KEK after the fourth hard encryption is protected by Mask R2 and stored in RAM; wherein the fourth hard encryption includes but is not limited to XOR operation;

[0088] The firmware triggers the key loading process, and the hardware automatically loads the fourth KEK from RAM to Register. During the loading process, it is first hard-encrypted by Mask R3, and then hard-encrypted by Mask R2 to obtain the fifth KEK. The hard encryption process does not expose the KEK plaintext. The above hard encryption process is the fifth hard encryption in the embodiment of the present invention. The KEK after the fifth hard encryption is protected by Mask R3 and stored in Register; wherein the fifth hard encryption includes but is not limited to XOR operation;

[0089] The firmware reads the encrypted MEK from the OTP through symmetric encryption and outputs it to the Engine;

[0090] The firmware triggers the key decapsulation operation. The Engine uses KEK^R3 as the key and the encrypted MEK as the ciphertext to perform the decryption operation with mask protection.

[0091] The firmware reads the decryption operation result with the R3 mask from the register and writes it into the RAM; during the writing process, it is first hard-encrypted through Mask R2 and then hard-encrypted through Mask R3, and the hard encryption process does not expose the MEK plaintext; the above hard encryption process is the sixth hard encryption in the embodiment of the present invention. After the sixth hard encryption, the MEK is protected by the Mask R2 mask and stored in the RAM; wherein, the sixth hard encryption includes but is not limited to an XOR operation.

[0092] According to the actual length of the MEK, the above decapsulation process is repeated for a second preset number of times until all the decrypted MEKs are obtained for use in the subsequent data encryption process.

[0093] The application example of the present invention considers the entire process of key generation, storage, and use, and provides security protection for the key throughout its entire life cycle. The entire life cycle of the key is inside the main control chip of the solid-state drive to prevent physical cracking. In addition, the generation, storage, and use processes are all protected by masks; the second random number and the third random number in the embodiment of the present invention can be temporarily generated random numbers; when the second random number and the third random number are temporarily generated random numbers, each key encapsulation and key decapsulation process can be changed, which can effectively resist various side channel attacks. While realizing the basic functions of key encapsulation and decapsulation, this application example improves the data security of the encrypted solid-state drive.

[0094] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

Claims

1. A method for implementing key processing, comprising: When receiving a preset encapsulation instruction, generating a first preset value of an initial key encryption key KEK and a second preset value of a data encryption key MEK through a preset physical random source TRNG; Performing a first hard encryption on each initial KEK using a first random number, and writing all the first hard-encrypted initial KEKs as first KEKs into a one-time programmable password (OTP) memory; Performing a second hard encryption on the first KEK by using the second random number and the first random number in sequence, and writing the first KEK after the second hard encryption as the second KEK into a random access memory RAM storing a key; Performing a third hard encryption on the second KEK by using a third random number and a second random number in sequence, and writing the third hard-encrypted second KEK as a third KEK into the key buffer; Using the third KEK as the key, perform symmetric encryption operations on each generated MEK, and write all MEKs that have undergone symmetric encryption operations as encrypted MEKs into the OTP memory; Wherein, the first random number is a fixed random number.

2. The method according to claim 1, characterized in that: The first hard encryption includes a first XOR operation; The second hard encryption includes a second XOR operation; The third hard encryption includes a third XOR operation.

3. The method according to claim 1, characterized in that The second random number is a temporarily generated random number or a fixed random number.

4. The method according to claim 1, characterized in that: The third random number is a temporarily generated random number or a fixed random number.

5. The method according to claim 1, characterized in that: The symmetric encryption operation includes any one of the following algorithms: Advanced Encryption Standard algorithm AES, National Encryption Algorithm SM4 or Data Encryption Standard algorithm DES.

6. The method according to any one of claims 1 to 5, characterized in that: After all MEKs that have undergone symmetric encryption operations are written as encrypted MEKs into the OTP memory, the method further includes: When receiving a preset decapsulation instruction, reading the encrypted MEK and the first KEK from the OTP memory; sequentially performing a fourth hard encryption on the first KEK using the first random number and the second random number, and writing the fourth hard-encrypted first KEK into the RAM as a fourth KEK; performing fifth hard encryption on the fourth KEK by using the second random number and the third random number in sequence, and writing the fourth KEK that has undergone the fifth hard encryption as the fifth KEK into the key buffer; Using the obtained fifth KEK as a key, performing a decryption operation on the read encrypted MEK to obtain a decryption operation result; The second preset value of the decryption operation results are sequentially hard-encrypted using the second random number and the third random number to obtain a decrypted MEK written into the RAM.

7. A computer storage medium, wherein a computer program is stored in the computer storage medium, and when the computer program is executed by a processor, the method for implementing key processing according to any one of claims 1 to 6 is implemented.

8. A terminal, comprising: A memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for implementing key processing according to any one of claims 1 to 6 is implemented.

9. A solid state hard disk for implementing key processing, comprising: generating unit, a first hard encryption unit, a second hard encryption unit, a third hard encryption unit and an encryption processing unit; wherein, The generating unit is configured to: upon receiving a preset encapsulation instruction, generate a first preset value of initial key encryption keys KEK and a second preset value of data encryption keys MEK through a preset physical random source TRNG; The first hard encryption unit is configured to: perform first hard encryption on each initial KEK using a first random number, and write all the first hard-encrypted initial KEKs into the OTP memory as first KEKs; The second hard encryption unit is configured to: perform second hard encryption on the first KEK by using the second random number and the first random number in sequence, and write the first KEK after the second hard encryption as the second KEK into a random access memory RAM storing a key; The third hard encryption unit is configured to: perform a third hard encryption on the second KEK by using a third random number and a second random number in sequence, and write the third hard-encrypted second KEK into the key buffer as the third KEK; The encryption processing unit is configured to: use the third KEK as a key, perform symmetric encryption operation on each generated MEK respectively, and write all MEKs that have undergone symmetric encryption operation as encrypted MEKs into the OTP memory; Wherein, the first random number is a fixed random number.

10. The solid state drive according to claim 9, wherein: The first hard encryption includes a first XOR operation; The second hard encryption includes a second XOR operation; The third hard encryption includes a third XOR operation.

Citation Information

Patent Citations

  • Cryptographic transmission system using key encryption key

    CN104247327A

  • Secure mobile storage device and implementation method thereof

    CN108052843A