NAS encryption storage system and method

By introducing dedicated isolation hardware into the NAS system to encrypt and decrypt I/O requests and responses, the problem of plaintext leakage caused by untrusted storage devices in traditional NAS is solved, and strict data security protection is achieved.

CN115857817BActive Publication Date: 2025-09-09HUNAN KYLIN XINAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211616544.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-15
Publication Date
2025-09-09
Estimated Expiration
2042-12-15

AI Technical Summary

Technical Problem

In traditional NAS, storage devices are deployed in untrusted or unreliable locations, which poses a risk of plaintext information leakage and cannot effectively protect data security.

Method used

A NAS encrypted storage system including a first subsystem, a second subsystem, dedicated isolation hardware and storage devices is used. The dedicated isolation hardware is used to encapsulate I/O requests and responses using a private protocol, and encryption and decryption operations are performed during transmission to isolate trusted areas from untrusted areas.

Benefits of technology

Effectively isolate ciphertext and plaintext, prevent plaintext from appearing in the same system environment, provide strict data security protection, and reduce the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115857817B_ABST
    Figure CN115857817B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data processing, and discloses a NAS encryption storage system and method. The system includes a first subsystem, a second subsystem, dedicated isolation hardware, and a storage device. The first subsystem is used to convert the user's file access request into a first dedicated isolation hardware frame and send it to the dedicated isolation hardware; the dedicated isolation hardware is used to receive the first dedicated isolation hardware frame, and perform encryption and transparent transmission processing to generate a second dedicated isolation hardware frame; the second subsystem is used to read the second dedicated isolation hardware frame, and convert it into a second I / O request, and implement the I / O operation to the storage device; the storage device is used to implement the I / O operation, return the generated first I / O response to the first subsystem, and return the generated file access response to the user. The I / O request and I / O response are transmitted through the dedicated isolation hardware, and encryption and decryption are performed during the transmission process, effectively isolating the trusted area and the untrusted area, providing strict data security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a NAS encrypted storage system and method. Background Art

[0002] NAS (Network Attached Storage) is a file-level computer data storage network server. NAS consists of storage devices and file services. Storage devices (such as disk arrays) act as data storage devices, providing storage capabilities for file services. File services are typically configured as devices that provide file services. Network user devices access files through network protocols (such as TCP / IP) and applications (such as the Network File System (NFS) or the Common Internet File System (CIFS).

[0003] Computers and the internet are essential tools for the management and operation of modern enterprises and institutions. Daily operations generate business data such as office documents and blueprints, as well as numerous personal documents. This data is typically stored on individual staff computers and servers, resulting in numerous issues such as difficulty in backing up and sharing, low security, and difficulty in scalability and upgrades. NAS addresses these issues by utilizing centralized network file access and sharing, thereby reducing system management costs and providing data backup and recovery capabilities.

[0004] Some enterprises and institutions with high security requirements also require NAS to provide information and data security features. This typically involves two aspects: first, data security, which refers to the use of modern cryptographic algorithms to protect data, such as data confidentiality, data integrity, and two-way strong identity authentication; second, data protection security, which refers to the active protection of data using modern information storage methods, such as disk arrays, data backup, and remote disaster recovery to ensure data security.

[0005] In traditional NAS, storage devices are directly connected to a file server as storage devices, which then provide file services within a network environment. Users send file access requests to the file server through network protocols and applications. The file server interprets these requests as local file I / O (Input / Output) through the file service program, and then executes these file I / O operations on the storage device. The file server can encrypt and decrypt files during the file I / O process, ensuring that the files stored on the storage device are encrypted. This prevents intruders from accessing plaintext file data, effectively protecting file data security.

[0006] However, the existing technology has a problem when using NAS: in some scenarios, the location where the storage device is deployed or the storage device itself is not trustworthy. If the storage device is directly connected to the trusted area where the user and the plaintext data are located, as in traditional NAS, there is a risk of plaintext information leakage. Summary of the Invention

[0007] In view of this, the purpose of the present invention is to overcome the deficiencies in the prior art and provide a NAS encryption storage system and method.

[0008] The present invention provides the following technical solutions:

[0009] In a first aspect, an embodiment of the present disclosure provides a NAS encrypted storage system, the system comprising a first subsystem, a second subsystem, dedicated isolation hardware, and a storage device;

[0010] The first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware via a system bus;

[0011] The first subsystem is used to convert the user's file access request into a first I / O request, and convert the first I / O request into a first dedicated isolation hardware frame, and send it to the dedicated isolation hardware;

[0012] The dedicated isolation hardware is used to receive the first dedicated isolation hardware frame, and perform encryption and transparent transmission processing to generate a second dedicated isolation hardware frame;

[0013] The second subsystem is used to read the second dedicated isolation hardware frame, convert it into a second I / O request, and implement the I / O operation in the storage device;

[0014] The storage device is used to implement the I / O operation of the second I / O request, return the generated first I / O response to the first subsystem through the second subsystem and the dedicated isolation hardware in sequence, and return the generated file access response to the user.

[0015] Furthermore, the first subsystem includes a file service and file system abstraction module, and the file system abstraction module includes an I / O interception layer, a first I / O protocol conversion layer, a first frame format conversion layer and a first driver layer;

[0016] The file service is used to convert the file access request of the user into the first I / O request;

[0017] The I / O interception layer is used to provide an I / O interface to intercept the first I / O request;

[0018] The first I / O protocol conversion layer is used to serialize the parameters of the first I / O request and encapsulate them into a first I / O protocol frame of a corresponding payload type according to the request type;

[0019] The first frame format conversion layer is used to add a dedicated isolation hardware frame header according to the payload type of the first I / O protocol frame to convert the frame into the first dedicated isolation hardware frame;

[0020] The first driver layer is used to send the first dedicated isolation hardware frame to the dedicated isolation hardware.

[0021] Furthermore, the second subsystem includes an I / O implementation module, and the I / O implementation module includes a second driver layer, a second frame format conversion layer, a second I / O protocol conversion layer, and a storage mapping layer;

[0022] The second driver layer is used to read the second dedicated isolation hardware frame and convert it into the second I / O request through the second frame format conversion layer and the second I / O protocol conversion layer;

[0023] The storage mapping layer is used to perform an I / O call on the storage device according to the second I / O request, and implement the I / O operation of the second I / O request to the storage device.

[0024] Furthermore, the second subsystem is further configured to convert the first I / O response into a third dedicated isolation hardware frame and send the frame to the dedicated isolation hardware;

[0025] The dedicated isolation hardware is further configured to receive the third dedicated isolation hardware frame, and perform decryption and transparent transmission processing according to a payload type of the frame to generate a fourth dedicated isolation hardware frame;

[0026] The first subsystem is further configured to read the fourth dedicated isolation hardware frame and convert it into the file access response to respond to the file access request of the user.

[0027] Furthermore, the second I / O protocol conversion layer is further configured to serialize the parameters of the first I / O response and encapsulate them into a second I / O protocol frame of a corresponding payload type according to the response type;

[0028] The second frame format conversion layer is further configured to add a dedicated isolation hardware frame header according to a payload type of the second I / O protocol frame, and convert the frame into the third dedicated isolation hardware frame;

[0029] The second driver layer is further configured to send the third dedicated isolation hardware frame to the dedicated isolation hardware.

[0030] Furthermore, the first driver layer is further configured to read the fourth dedicated isolation hardware frame, convert it into the second I / O response through the first frame format conversion layer, the I / O protocol conversion layer, and the I / O interception layer, and return the result to the file service.

[0031] The file service is further configured to generate the file access response according to the second I / O response, and respond to the file access request of the user.

[0032] In a second aspect, an embodiment of the present disclosure provides a NAS encrypted storage method, which is applied to a NAS encrypted storage system. The system includes a first subsystem, a second subsystem, dedicated isolation hardware, and a storage device. The first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware via a system bus. The method includes:

[0033] receiving a file access request from a user through the first subsystem, converting the file access request into a first I / O request, and converting the first I / O request into a first dedicated isolation hardware frame, and sending the frame to the dedicated isolation hardware;

[0034] Receiving the first dedicated isolation hardware frame through the dedicated isolation hardware, and performing encryption and transparent transmission processing to generate a second dedicated isolation hardware frame;

[0035] Reading the second dedicated isolation hardware frame through the second subsystem, converting the frame into a second I / O request, and implementing the I / O operation in the storage device;

[0036] The second subsystem performs an I / O call on the storage device according to the second I / O request, returns the generated first I / O response to the first subsystem through the dedicated isolation hardware, and returns the generated file access response to the user.

[0037] Furthermore, the first subsystem includes a file service and file system abstraction module, and the first subsystem receives a file access request generated by a user performing a file operation through an application, converts the file access request into a first I / O request, and converts the first I / O request into a first dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware, including:

[0038] receiving, through the file service, a file access request generated by the user performing a file operation through an application;

[0039] The file access request is intercepted by the file system abstraction module and converted into a first I / O request, the parameters of the first I / O request are serialized, and the first I / O protocol frame of the corresponding payload type is encapsulated according to the request type. A dedicated isolation hardware frame header is added according to the payload type of the first I / O protocol frame, and the frame is converted into the first dedicated isolation hardware frame and sent to the dedicated isolation hardware.

[0040] Furthermore, the second subsystem performs an I / O call on the storage device according to the second I / O request, returns the generated first I / O response to the first subsystem in sequence through the second subsystem and the dedicated isolation hardware, and returns the generated file access response to the user, including:

[0041] The second subsystem performs an I / O call on the storage device according to the second I / O request, generates a first I / O response, converts the first I / O response into a third dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware;

[0042] Receiving the third dedicated isolation hardware frame through the dedicated isolation hardware, and performing decryption and transparent transmission processing according to the payload type of the frame to generate a fourth dedicated isolation hardware frame;

[0043] The fourth dedicated isolation hardware frame is read by the first subsystem and converted into the file access response to respond to the file access request of the user.

[0044] Furthermore, the second subsystem includes an I / O implementation module. The second subsystem performs an I / O call on the storage device according to the second I / O request, generates a first I / O response, converts the first I / O response into a third dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware, including:

[0045] The I / O implementation module performs an I / O call on the storage device based on the second I / O request, generates a first I / O response, serializes the parameters of the first I / O response, encapsulates it into a second I / O protocol frame of the corresponding payload type according to the response type, adds a dedicated isolation hardware frame header according to the payload type of the second I / O protocol frame, converts it into the third dedicated isolation hardware frame, and sends it to the dedicated isolation hardware.

[0046] The embodiments of the present application have the following advantages:

[0047] An embodiment of the present application provides a NAS encrypted storage system, which includes a first subsystem, a second subsystem, dedicated isolation hardware and a storage device; the first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware through a system bus; the first subsystem is used to convert a user's file access request into a first I / O request, and convert the first I / O request into a first dedicated isolation hardware frame, and send it to the dedicated isolation hardware; the dedicated isolation hardware is used to receive the first dedicated isolation hardware frame, encrypt and transparently transmit it, and generate a second dedicated isolation hardware frame; the second subsystem is used to read the second dedicated isolation hardware frame, convert it into a second I / O request, and implement the I / O operation to the storage device; the storage device is used to implement the I / O operation of the second I / O request, return the generated first I / O response to the first subsystem through the second subsystem and the dedicated isolation hardware in sequence, and return the generated file access response to the user. The above system encapsulates I / O requests and I / O responses with private protocols, transmits them using dedicated isolation hardware, and performs encryption and decryption operations during the transmission process, ensuring that ciphertext and plaintext do not appear in the same system environment, effectively isolating trusted areas from untrusted areas, and providing strict data security protection.

[0048] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be considered as limiting the scope. A person of ordinary skill in the art can also derive other relevant drawings based on these drawings without inventive effort. Similar components are numbered similarly in the various drawings.

[0050] Figure 1 A schematic diagram of the structure of a NAS encrypted storage system provided in an embodiment of the present application is shown;

[0051] Figure 2 A schematic diagram of the structure of a file system abstraction module provided in an embodiment of the present application is shown;

[0052] Figure 3 A schematic diagram of the structure of an I / O implementation module provided in an embodiment of the present application is shown;

[0053] Figure 4 A flowchart of a NAS encrypted storage method provided in an embodiment of the present application is shown.

[0054] Description of main components symbols:

[0055] 1-First subsystem; 11-File service; 12-File system abstraction module; 121-I / O interception layer; 122-First I / O protocol conversion layer; 123-First frame format conversion layer; 124-First driver layer; 2-Dedicated isolation hardware; 3-Second subsystem; 31-I / O implementation module; 311-Second driver layer; 312-Second frame format conversion layer; 313-Second I / O protocol conversion layer; 314-Storage mapping layer; 4-Storage device. DETAILED DESCRIPTION

[0056] The following describes embodiments of the present invention in detail. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended only to explain the present invention and are not to be construed as limiting the present invention.

[0057] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may be an intermediate element. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be an intermediate element. Conversely, when an element is referred to as being "directly on" another element, there is no intermediate element. The terms "vertical," "horizontal," "left," "right," and similar expressions used herein are for illustrative purposes only.

[0058] In the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," "connect," "fixed," etc. should be understood broadly. For example, they may refer to fixed connection, detachable connection, or integration; mechanical connection or electrical connection; direct connection or indirect connection through an intermediate medium; internal communication between two components or interaction between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0059] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature identified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used in the template description herein are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0061] Example 1

[0062] like Figure 1 , which is a structural diagram of a NAS encrypted storage system in an embodiment of the present application, wherein the system includes a first subsystem 1, a second subsystem 3, dedicated isolation hardware 2 and a storage device 4.

[0063] The first subsystem 1 and the second subsystem 3 are respectively connected to the dedicated isolation hardware 2 via a system bus.

[0064] In this embodiment, the first subsystem 1 and the second subsystem 3 are two independent hardware platforms, each running a separate system. The dedicated isolation hardware 2 is a customized printed circuit board with functions such as data encryption and decryption and data transmission, deployed in the form of a system bus. The first subsystem 1 and the second subsystem 3 are respectively connected to the dedicated isolation hardware 2 via a system bus. The storage device 4 can be SAN storage, NAS storage, or DAS storage, etc., which is not limited in this embodiment of the application.

[0065] The first subsystem 1 is used to convert the user's file access request into a first I / O request, and convert the first I / O request into a first dedicated isolation hardware frame, and send it to the dedicated isolation hardware 2.

[0066] Specifically, if Figure 2As shown, the first subsystem includes a file service 11 and a file system abstraction module 12. The file system abstraction module 12 includes an I / O interception layer 121, a first I / O protocol conversion layer 122, a first frame format conversion layer 123, and a first driver layer 124. When a user accesses the file service 11 through an application (such as NFS, CIFS, FTP, etc.) of the file service 11, a file access request is generated. The file service 11 is used to convert the user's file access request into the first I / O request. The I / O interception layer 121 is used to provide an I / O interface to intercept the first I / O request. The first I / O protocol conversion layer 122 is used to serialize the parameters of the first I / O request and encapsulate it into a first I / O protocol frame of the corresponding payload type according to the request type. The first frame format conversion layer 123 is used to add a dedicated isolation hardware frame header according to the payload type of the first I / O protocol frame to convert it into the first dedicated isolation hardware frame. The first driver layer 124 is used to send the first dedicated isolation hardware frame to the dedicated isolation hardware.

[0067] The file system abstraction module 12 redirects the I / O of the file service by means of I / O interception, and can adapt to most existing file services, has wide applicability, and reduces the difficulty of development.

[0068] The dedicated isolation hardware 2 is used to receive the first dedicated isolation hardware frame, and perform encryption and transparent transmission processing according to the payload type of the frame to generate a second dedicated isolation hardware frame.

[0069] Furthermore, the dedicated isolation hardware 2 receives the first dedicated isolation hardware frame through the system bus, identifies the information in the frame header, encrypts and transparently transmits the data part of the frame containing the file data, and generates a second dedicated isolation hardware frame. The frame that does not contain the file data is not encrypted or transparently transmitted.

[0070] By encapsulating I / O requests and responses with a private protocol, transmitting them using dedicated isolation hardware 2, and performing encryption operations during the transmission process, it is ensured that ciphertext and plaintext will not appear in the same system environment, effectively isolating the trusted area and the untrusted area, and providing strict data security protection.

[0071] The second subsystem 3 is configured to read the second dedicated isolation hardware frame, convert it into a second I / O request, and implement the I / O operation in the storage device 4 .

[0072] Further, if Figure 3As shown, the second subsystem 3 includes an I / O implementation module 31, and the I / O implementation module 31 includes a second driver layer 311, a second frame format conversion layer 312, a second I / O protocol conversion layer 313 and a storage mapping layer 314; the second driver layer 311 is used to read the second dedicated isolation hardware frame through the system bus, and convert it into the second I / O request through the second frame format conversion layer 312 and the second I / O protocol conversion layer 313; the storage mapping layer 314 is used to perform an I / O call on the storage device 4 in the file system provided by the storage device 4 or using the I / O interface provided by the storage device 4 according to the second I / O request, and implement the I / O operation of the second I / O request to the storage device 4.

[0073] The I / O implementation module 31 implements the user's I / O request for file operation into the storage device 4 to implement the I / O call to the storage device 4 and generate an I / O response to return to the user.

[0074] The storage device 4 is used to provide an I / O interface for performing an I / O call, and returns the generated first I / O response to the user through the second subsystem 3, the dedicated isolation hardware 2 and the first subsystem 1 in sequence.

[0075] Further, if Figure 3 As shown, the second subsystem 3 is further used to convert the first I / O response into a third dedicated isolation hardware frame and send it to the dedicated isolation hardware 2. The second I / O protocol conversion layer 313 is further used to serialize the parameters of the first I / O response generated by the I / O call and encapsulate it into a second I / O protocol frame of the corresponding payload type according to the response type; the second frame format conversion layer 312 is further used to add a dedicated isolation hardware frame header according to the payload type of the second I / O protocol frame and convert it into the third dedicated isolation hardware frame; the second driver layer 311 is further used to send the third dedicated isolation hardware frame to the dedicated isolation hardware 2.

[0076] The dedicated isolation hardware 2 is also used to receive the third dedicated isolation hardware frame through the system bus, identify the information in the frame header, decrypt and transparently transmit the data part of the frame containing file data, and generate a fourth dedicated isolation hardware frame. The frame that does not contain file data will not be decrypted or transparently transmitted.

[0077] Furthermore, if Figure 2As shown, the first subsystem 1 is also used to read the fourth dedicated isolation hardware frame in the dedicated isolation hardware 2 and convert it into a file access response to respond to the user's file access request. The first driver layer 124 of the file system abstraction module 12 in the first subsystem 1 is also used to read the fourth dedicated isolation hardware frame in the dedicated isolation hardware through the system bus, and convert it into the second I / O response through the first frame format conversion layer 123, the first I / O protocol conversion layer 122 and the I / O interception layer 121, and return it to the file service 11; the file service 11 is also used to generate a file access response based on the second I / O response to respond to the user's file access request.

[0078] The storage device of the embodiment of the present application is adaptable to various back-end storage types, supports direct use of various file services of the original NAS storage (such as NFS, CIFS, etc.), SAN storage and DAS storage as storage devices, and has high adaptability and low migration cost.

[0079] The NAS encrypted storage system provided in an embodiment of the present application includes a first subsystem 1, a second subsystem 3, dedicated isolation hardware 2 and a storage device 4; the first subsystem 1 and the second subsystem 3 are respectively connected to the dedicated isolation hardware 2 through a system bus; the first subsystem 1 is used to convert the user's file access request into a first I / O request, and convert the first I / O request into a first dedicated isolation hardware frame, and send it to the dedicated isolation hardware 2; the dedicated isolation hardware 2 is used to receive the first dedicated isolation hardware frame, and encrypt and transparently process it according to the payload type of the frame to generate a second dedicated isolation hardware frame; the second subsystem 3 is used to read the second dedicated isolation hardware frame, and convert it into a second I / O request, and implement the I / O operation to the storage device 4; the storage device 4 is used to provide an I / O interface for I / O calls, and return the generated first I / O response to the first subsystem 1 through the second subsystem 3 and the dedicated isolation hardware 2 in sequence, and return the generated file access response to the user. The above system encapsulates I / O requests and I / O responses with private protocols, transmits them using dedicated isolation hardware, and performs encryption and decryption operations during the transmission process, ensuring that ciphertext and plaintext do not appear in the same system environment, effectively isolating trusted areas from untrusted areas, and providing strict data security protection.

[0080] Example 2

[0081] like Figure 4FIG. 1 is a flowchart of a NAS encrypted storage method according to an embodiment of the present application. The NAS encrypted storage method provided by the embodiment of the present application is applied to a NAS encrypted storage system. The system includes a first subsystem, a second subsystem, dedicated isolation hardware, and a storage device. The first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware via a system bus. The method includes the following steps:

[0082] Step S110: receiving a file access request from a user through the first subsystem, converting the file access request into a first I / O request, and converting the first I / O request into a first dedicated isolation hardware frame, and sending the frame to the dedicated isolation hardware.

[0083] Specifically, the first subsystem includes a file service and a file system abstraction module, and the file system abstraction module includes an I / O interception layer, a first I / O protocol conversion layer, a first frame format conversion layer and a first driver layer. The user performs file operations through an application (such as a CIFS client), and the application generates a file access request and sends it to the file service through a network protocol. When the file service receives the user's file access request, it will call the I / O interface provided by the I / O interception layer to generate a first I / O request; the first I / O protocol conversion layer serializes according to the parameters of the first I / O request, and encapsulates it into a first I / O protocol frame of the corresponding payload type according to the request type; the first frame format conversion layer adds a dedicated isolation hardware frame header according to the payload type of the first I / O protocol frame, converts it into the first dedicated isolation hardware frame, and sends it to the dedicated isolation hardware through the first driver layer.

[0084] The file system abstraction module of the first subsystem redirects the I / O of the file service by means of I / O interception, which can adapt to the vast majority of existing file services, has wide applicability, and reduces the difficulty of development.

[0085] Step S120: receiving the first dedicated isolation hardware frame through the dedicated isolation hardware, performing encryption and transparent transmission processing to generate a second dedicated isolation hardware frame.

[0086] Furthermore, after receiving the first dedicated isolation hardware frame, the dedicated isolation hardware identifies the information in the frame header and, based on the payload type of the frame, encrypts and transparently transmits the data portion of the frame containing the file data to generate a second dedicated isolation hardware frame. Frames that do not contain file data are not encrypted or transparently transmitted.

[0087] By encapsulating I / O requests with a private protocol, using dedicated isolation hardware for transmission, and performing encryption operations during the transmission process, it is ensured that ciphertext and plaintext will not appear in the same system environment, effectively isolating the trusted area and the untrusted area, and providing strict data security protection.

[0088] Step S130 : Read the second dedicated isolation hardware frame through the second subsystem, convert it into a second I / O request, and implement the I / O operation in the storage device.

[0089] Specifically, the second subsystem includes an I / O implementation module, which includes a second driver layer, a second frame format conversion layer, a second I / O protocol conversion layer, and a storage mapping layer. The I / O implementation module reads the second dedicated isolation hardware frame from the dedicated isolation hardware through the second driver layer, and converts it into a second I / O request through the second frame format conversion layer and the second I / O protocol conversion layer. The storage mapping layer makes an I / O call in the file system corresponding to the storage device or using the I / O interface provided by the storage device, and implements the I / O operation of the second I / O request of the file operation to the storage device.

[0090] By implementing the I / O operation of the second I / O request of the file operation in the storage device, higher adaptability and lower migration cost are achieved.

[0091] In step S140, the second subsystem performs an I / O call on the storage device according to the second I / O request, returns the generated first I / O response to the first subsystem through the dedicated isolation hardware, and returns the generated file access response to the user.

[0092] Furthermore, the I / O implementation module uses the I / O interface provided by the storage device to perform an I / O call on the storage device, generating a first I / O response. The second I / O protocol conversion layer serializes the parameters of the first I / O response and encapsulates it into a second I / O protocol frame of the corresponding payload type based on the response type. The second frame format conversion layer adds a dedicated isolation hardware frame header based on the payload type of the second I / O protocol frame, converts it into the third dedicated isolation hardware frame, and sends it to the dedicated isolation hardware through the second driver layer.

[0093] After receiving the third dedicated isolation hardware frame, the dedicated isolation hardware identifies the information in the frame header and, based on the payload type of the frame, decrypts and transparently transmits the data portion of the frame containing the file data to generate a fourth dedicated isolation hardware frame. Frames that do not contain file data are not decrypted or transparently transmitted.

[0094] After the file system abstraction module of the first subsystem reads the fourth dedicated isolated hardware frame through the first driver layer, it converts it into a second I / O response through the first frame format conversion layer and the first I / O protocol conversion layer. The first I / O interception layer returns the second I / O response to the file service. The file service generates a file access response based on the I / O call result to respond to the user's file access request.

[0095] By encapsulating I / O responses with a private protocol, using dedicated isolation hardware for transmission, and performing decryption operations during the transmission process, it is ensured that ciphertext and plaintext will not appear in the same system environment, effectively isolating the trusted area and the untrusted area, and providing strict data security protection.

[0096] The NAS encrypted storage method provided in an embodiment of the present application is applied to a NAS encrypted storage system, wherein the system includes a first subsystem, a second subsystem, dedicated isolation hardware and a storage device, wherein the first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware through a system bus; the method includes: receiving, by the first subsystem, a file access request generated by a user performing a file operation through an application, converting the file access request into a first I / O request, and converting the first I / O request into a first dedicated isolation hardware frame, and sending the frame to the dedicated isolation hardware; receiving, by the dedicated isolation hardware, the first dedicated isolation hardware frame and encrypting it to generate a second dedicated isolation hardware frame; reading, by the second subsystem, the second dedicated isolation hardware frame and converting it into a second I / O request, and implementing the I / O operation to the storage device; the second subsystem performing an I / O call on the storage device based on the second I / O request, returning the generated first I / O response to the first subsystem through the dedicated isolation hardware, and returning the generated file access response to the user. The above method is used to encapsulate I / O requests and I / O responses with a private protocol, transmit them using dedicated isolation hardware, and perform encryption and decryption operations during the transmission process. This ensures that ciphertext and plaintext do not appear in the same system environment, effectively isolates the trusted area from the untrusted area, and provides strict data security protection.

[0097] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and structure diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in an alternative implementation, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the structure diagram and / or flowchart, and the combination of boxes in the structure diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0098] In addition, the functional modules or units in the various embodiments of the present invention may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.

[0099] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a smart phone, a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0100] The above description is only a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed by the present invention, which should be covered by the scope of protection of the present invention.

Claims

1. A NAS encrypted storage system, characterized in that: The system includes a first subsystem, a second subsystem, dedicated isolation hardware, and a memory device; The first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware via a system bus; The first subsystem is used to convert the user's file access request into a first I / O request, and convert the first I / O request into a first dedicated isolation hardware frame, and send it to the dedicated isolation hardware; The dedicated isolation hardware is used to receive the first dedicated isolation hardware frame, and perform encryption and transparent transmission processing to generate a second dedicated isolation hardware frame; The second subsystem is used to read the second dedicated isolation hardware frame, convert it into a second I / O request, and implement the I / O operation in the storage device; The storage device is configured to implement the I / O operation of the second I / O request, return the generated first I / O response to the first subsystem via the second subsystem and the dedicated isolation hardware, and return the generated file access response to the user; The first subsystem includes a file service and a file system abstraction module, and the file system abstraction module includes an I / O interception layer, a first I / O protocol conversion layer, a first frame format conversion layer, and a first driver layer; The file service is used to convert the file access request of the user into the first I / O request; The I / O interception layer is used to provide an I / O interface to intercept the first I / O request; The first I / O protocol conversion layer is used to serialize the parameters of the first I / O request and encapsulate them into a first I / O protocol frame of a corresponding payload type according to the request type; The first frame format conversion layer is used to add a dedicated isolation hardware frame header according to the payload type of the first I / O protocol frame to convert the frame into the first dedicated isolation hardware frame; The first driver layer is used to send the first dedicated isolation hardware frame to the dedicated isolation hardware.

2. The NAS encrypted storage system according to claim 1, characterized in that: The second subsystem includes an I / O implementation module, and the I / O implementation module includes a second driver layer, a second frame format conversion layer, a second I / O protocol conversion layer and a storage mapping layer; The second driver layer is used to read the second dedicated isolation hardware frame and convert it into the second I / O request through the second frame format conversion layer and the second I / O protocol conversion layer; The storage mapping layer is used to perform an I / O call on the storage device according to the second I / O request, and implement the I / O operation of the second I / O request to the storage device.

3. The NAS encrypted storage system according to claim 2, characterized in that: The second subsystem is further configured to convert the first I / O response into a third dedicated isolation hardware frame and send the frame to the dedicated isolation hardware; The dedicated isolation hardware is further configured to receive the third dedicated isolation hardware frame, and perform decryption and transparent transmission processing according to a payload type of the frame to generate a fourth dedicated isolation hardware frame; The first subsystem is further configured to read the fourth dedicated isolation hardware frame and convert it into the file access response to respond to the file access request of the user.

4. The NAS encrypted storage system according to claim 3, wherein: The second I / O protocol conversion layer is further used to serialize the parameters of the first I / O response and encapsulate them into a second I / O protocol frame of a corresponding payload type according to the response type; The second frame format conversion layer is further configured to add a dedicated isolation hardware frame header according to a payload type of the second I / O protocol frame, and convert the frame into the third dedicated isolation hardware frame; The second driver layer is further configured to send the third dedicated isolation hardware frame to the dedicated isolation hardware.

5. The NAS encrypted storage system according to claim 4, characterized in that: The first driver layer is further configured to read the fourth dedicated isolated hardware frame, convert it into the second I / O response through the first frame format conversion layer, the first I / O protocol conversion layer, and the I / O interception layer, and return the result to the file service; The file service is further configured to generate the file access response according to the second I / O response, and respond to the file access request of the user.

6. A NAS encryption storage method, characterized in that: Applied to a NAS encrypted storage system, the system includes a first subsystem, a second subsystem, dedicated isolation hardware, and a storage device, the first subsystem and the second subsystem are respectively connected to the dedicated isolation hardware via a system bus; the method includes: receiving a file access request from a user through the first subsystem, converting the file access request into a first I / O request, and converting the first I / O request into a first dedicated isolation hardware frame, and sending the frame to the dedicated isolation hardware; Receiving the first dedicated isolation hardware frame through the dedicated isolation hardware, and performing encryption and transparent transmission processing to generate a second dedicated isolation hardware frame; Reading the second dedicated isolation hardware frame through the second subsystem, converting the frame into a second I / O request, and implementing the I / O operation in the storage device; The second subsystem performs an I / O call on the storage device according to the second I / O request, returns the generated first I / O response to the first subsystem through the dedicated isolation hardware, and returns the generated file access response to the user; The first subsystem includes a file service and file system abstraction module, and the first subsystem receives a file access request generated by a user performing a file operation through an application, converts the file access request into a first I / O request, and converts the first I / O request into a first dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware, including: receiving, through the file service, a file access request generated by the user performing a file operation through an application; The file access request is intercepted by the file system abstraction module and converted into a first I / O request, the parameters of the first I / O request are serialized, and the first I / O protocol frame of the corresponding payload type is encapsulated according to the request type. A dedicated isolation hardware frame header is added according to the payload type of the first I / O protocol frame, and the frame is converted into the first dedicated isolation hardware frame and sent to the dedicated isolation hardware.

7. The NAS encryption storage method according to claim 6, characterized in that: The second subsystem performs an I / O call on the storage device according to the second I / O request, returns the generated first I / O response to the first subsystem through the second subsystem and the dedicated isolation hardware in sequence, and returns the generated file access response to the user, including: The second subsystem performs an I / O call on the storage device according to the second I / O request, generates a first I / O response, converts the first I / O response into a third dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware; Receiving the third dedicated isolation hardware frame through the dedicated isolation hardware, and performing decryption and transparent transmission processing according to the payload type of the frame to generate a fourth dedicated isolation hardware frame; The fourth dedicated isolation hardware frame is read by the first subsystem and converted into the file access response to respond to the file access request of the user.

8. The NAS encryption storage method according to claim 7, characterized in that: The second subsystem includes an I / O implementation module. The second subsystem performs an I / O call on the storage device according to the second I / O request, generates a first I / O response, converts the first I / O response into a third dedicated isolation hardware frame, and sends the frame to the dedicated isolation hardware, including: The I / O implementation module performs an I / O call on the storage device based on the second I / O request, generates a first I / O response, serializes the parameters of the first I / O response, encapsulates it into a second I / O protocol frame of the corresponding payload type according to the response type, adds a dedicated isolation hardware frame header according to the payload type of the second I / O protocol frame, converts it into the third dedicated isolation hardware frame, and sends it to the dedicated isolation hardware.

Citation Information

Patent Citations

  • Independent network safety encryption isolator arranged on network cable and isolation method thereof

    CN101741818A

  • System and method for trusted storage of data

    CN103927489A