A method for controlling encryption and decryption of a storage device based on a virtual disk
By using pseudo disk and pseudo file technologies in encrypted storage devices, users are prompted to enter security codes, and the security risk problem of loading unexamined programs in the existing technology is solved, and an encrypted and decrypted storage device with high security and convenient use is achieved.
Patent Information
- Application Number
- CN202310216549.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-02
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-03-02
AI Technical Summary
Existing encrypted storage devices need to load unsecured encryption and decryption programs before use, which poses security risks and is difficult to meet the needs of highly secure computers.
The pseudo disk-based storage device encryption and decryption control method is adopted. Through virtual pseudo disks and simulated initial pseudo files, the user is prompted to enter a security code to avoid loading additional programs and ensure security.
It enables the secure use of encrypted storage devices without loading additional programs, reduces computer security risks, and improves usage efficiency and security.
Smart Images

Figure CN116305325B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for controlling encryption and decryption of a storage device based on a virtual disk, and belongs to the field of information security. Background Art
[0002] With the development of the information society, various work-sensitive information and personal privacy information in work and life need to be simply and conveniently stored in encrypted storage devices, such as encrypted USB flash drives, encrypted hard disks, or encrypted disks. Most existing encrypted storage devices need to install encryption and decryption programs, and some storage devices provide non-encrypted operating programs by themselves. Before using an encrypted storage device, a user needs to first run an encryption and decryption program that may not have been security-reviewed to read or parse the content of the encrypted partition of the storage device. Before logging in to the encrypted area of the "USB Flash Drive Security Encryption Management Method" (application publication number CN 106372541 A), a login display program needs to be logged in, and the security protection of this login display program lacks an explanation. "An Encrypted USB Flash Drive" (application publication number CN 110765501 A) uses a random number generated by a random number generator as a key.
[0003] For a secure computer, running other programs is dangerous, especially programs that have not been security-reviewed. To meet the needs of high-security computers using encrypted storage devices, it is very necessary to design an encryption and decryption storage device control method that does not require loading additional programs. Summary of the Invention
[0004] To meet the needs of high-security computers using secure encryption and decryption storage devices, the present invention designs a method for controlling encryption and decryption of a storage device based on a virtual disk. The present invention uses the method of virtualizing a pseudo-disk of the storage device and simulating an initial-state pseudo-file, and prompts the user to input a security code, which can avoid the security risks caused by starting the encryption and decryption operations using an additionally loaded program to the computer.
[0005] The present invention designs various types of security codes to meet the security requirements of different application scenarios. Users who pass various security code validations use the encrypted storage device designed by the present invention to store sensitive information. The data encryption and decryption operations are transparent to the user, which can ensure security while facilitating the use of the encryption and decryption storage device quickly and improving efficiency. The one-time hash calculation result of the security code designed by the present invention is stored in the volatile memory of the encryption and decryption control unit, which can ensure that the one-time hash calculation result of the security code disappears after power-off, ensuring that the encryption and decryption key is not illegally used. At the same time, the secondary hash calculation result of the security code is stored in the non-volatile storage area, which can ensure the validity of user identity verification when the storage device is in an operating state.
[0006] The steps of the method for controlling encryption and decryption of a storage device based on a virtual disk according to the present invention include:
[0007] Step A: Determine the status of the storage device
[0008] After the storage device (USB flash drive, hard disk, magnetic disk, etc.) is connected to the computer, determine the device status recorded inside the storage device, which is divided into the initial state and the running state. If it is the initial state, execute Step B; if it is the running state, execute Step C. The status of the storage device when it leaves the factory for sale is the initial state.
[0009] Step B: Initial state control process
[0010] (B-1) When the storage device (USB flash drive, hard disk, magnetic disk, etc.) is in the initial state and connected to the computer, the central control unit of the storage device starts the pseudo-disk program therein. This program is pre-designed and implemented and burned into the control chip of the storage device before leaving the factory. After running this pseudo-disk program, a virtual pseudo-disk can be formed. A virtual initial-state pseudo-file is emulated in the pseudo-disk. In the initial-state pseudo-file, the user is prompted in text or graphics to enter the security code of the storage device in the pseudo-file, and the functions of these security codes are shown in text or diagrams.
[0011] (B-2) When the user selects to open the initial-state pseudo-file, the prompt information in the pseudo-file can be seen, and the security code can be entered at the relevant position in the pseudo-file, including the control codes of each disk of the storage device. After the user saves the security code of the pseudo-file, the central control unit of the storage device obtains the security code entered by the user through the saved pseudo-file of the user and determines the validity of these security codes. If the security code entered by the user in the pseudo-file is valid, the status of the storage device is modified to the running state. The one-time hash result of the security code is used as the key, and the calculation result of the second hash value of these security codes is stored in the security area of the storage device; otherwise, return to Step (B-1).
[0012] The above security codes include the reset code, security questions, and control codes of each disk. If the user sets the reset code, when the user needs to re-initialize the storage device, enter the reset code. Without the correct reset code, the storage device cannot be re-initialized. When security questions are set, the correct security questions can be used to reset the reset code. The control code of the disk is used to control the encrypted and decrypted reading and writing of the disk.
[0013] The above disk control codes include the read-only code and the read-write code. The user enters a qualified read-only code to ensure that only the disk files can be read but not rewritten or added. The correct read-only code plus the read-write code can read and write the entire disk.
[0014] The result of the first hash calculation of the above security code is obtained by merging the security code with an internal value of the disk, such as the disk serial number, and then performing a single hash calculation using the hash algorithm. The result of the second hash calculation of the security code is obtained by merging the result of the first hash calculation of the security code with another internal value of the disk and then performing another calculation.
[0015] The above hash algorithm is the SM3 algorithm.
[0016] C. Running state control process:
[0017] (C-1) When the storage device is in the running state, the central control unit starts the pseudo-disk program therein to form a virtual pseudo-disk. A running-state pseudo-file is emulated in the pseudo-disk. In this pseudo-file, the user is prompted in text or graphics to enter the control code of the disk within the file, and the function of the control code is shown in text or illustration.
[0018] (C-2) When the user selects and opens the pseudo-file, the information in the pseudo-file can be seen, and the user can enter the disk control code set in the initial state at the relevant position in the pseudo-file. After the user saves the pseudo-file, the central control unit of the storage device obtains the control code entered by the user through the saved pseudo-file and determines whether the result of the second hash calculation of these control codes is the same as the result saved in the initial state. If they are the same, the result of the first hash calculation of these control codes is sent to the encryption / decryption control unit and step (C-3) is entered; otherwise, step (C-1) is returned.
[0019] (C-3) After the encryption / decryption control unit obtains the result of the first hash calculation of the control code, it checks the correctness of the result. If it is correct, the stored content is encrypted / decrypted using these calculation results. The central control unit stops the operation of the pseudo-disk program and directly displays the decrypted stored data to the user. At this time, the user sees a complete disk and can read and write the content of the decrypted storage device.
[0020] The above result of the first hash calculation is only stored in the volatile memory of the encryption / decryption control unit and is transformed into the encryption / decryption key, which will disappear when the power is off.
[0021] A counter is provided in the above central control unit. When the number of consecutive incorrect input times of the security code reaches the set number, the user access is ended, the disk is locked, and it enters the locked state, and subsequent accesses of the same type are not allowed.
[0022] When the storage device in the running state cannot be encrypted or decrypted for use, the user can input the reset code in the security code. After correctly inputting the reset code, the central control unit formats the storage device and sets the state of the storage device to the initial state. If the storage device is in the locked state, the correct reset code will unlock the disk and enter the running state.
[0023] The above encryption and decryption control unit can store the check bits of the key, and check whether the control code is correct by calculating the check bits of the key during loading. The above pseudo-file type can be files such as txt and html.
[0024] A method for encrypting and decrypting control of a storage device based on a pseudo disk proposed by the present invention has the following characteristics and advantages:
[0025] 1. The method for encrypting and decrypting control of a storage device based on a pseudo disk proposed by the present invention uses the method of virtual pseudo disks and emulated initial-state pseudo files of the storage device to prompt the user to input a security code, which can avoid the security risks caused by using an extra-loaded program to the computer. Compared with the encrypted storage device that requires installing an extra program, the method of pseudo disks and emulated initial-state pseudo files of the present invention has stronger security and can meet the needs of high-security-level computers using external storage devices. At the same time, for cross-machine data exchange, encrypted files can be exchanged without installing any program.
[0026] 2. The method for encrypting and decrypting control of a storage device based on a pseudo disk proposed by the present invention designs various types of security codes, including reset codes, security questions, and control codes for each disk, which can meet the security requirements of different application scenarios. For users who pass various security code verifications, using the encrypted storage device designed by the present invention to store sensitive information, the data encryption and decryption operations are transparent to the user, which can ensure security while facilitating the use of the encrypted and decrypted storage device quickly and improving efficiency.
[0027] 3. The method for encrypting and decrypting control of a storage device based on a pseudo disk proposed by the present invention stores the one-time hash calculation result of the security code in the volatile memory of the encryption and decryption control unit, which can ensure that the one-time hash calculation result of the security code disappears after power-off, ensuring that the encryption and decryption key is not illegally used. At the same time, the two-time hash calculation result of the security code is stored in the non-volatile storage area, which can ensure the correctness of verifying the security code input by the user when the storage device is in the running state. Description of the Drawings
[0028] Figure 1 It is a flowchart of a method for encrypting and decrypting control of a storage device based on a pseudo disk. Detailed Embodiments
[0029] A method for encrypting and decrypting control of a storage device based on a pseudo disk proposed by the present invention, as Figure 1As shown in the figure, the specific implementation steps of the present invention are as follows:
[0030] 1. Determine the status of the storage device according to step A
[0031] After the storage device (USB flash drive, hard disk, disk, etc.) is connected to the computer, determine the device status recorded inside the storage device, which is divided into the initial state and the running state.
[0032] If the storage device is in the initial state, execute step B. The status of the storage device when it leaves the factory for sale is the initial state.
[0033] If the storage device is in the running state, execute step C.
[0034] 2. Step B: Initial state control process
[0035] (B-1) When the storage device (USB flash drive, hard disk, disk, etc.) is in the initial state and connected to the computer, the central control unit of the storage device starts the virtual disk program therein. This program is pre-designed and burned into the control chip of the storage device before leaving the factory. After running this virtual disk program, a virtual pseudo-disk can be formed. A virtual initial-state pseudo-file is emulated in the pseudo-disk. In the pseudo-file, the user is prompted in text to enter the security code of the storage device set by the user, and the functions of these security codes are shown in text or diagrams.
[0036] (B-2) When the user selects to open the pseudo-file, the prompt information in the pseudo-file can be seen, and the relevant security codes, including the reset code, security question, and control codes for each disk, can be entered at the position in the pseudo-file.
[0037] When the user sets the reset code, the disk reset requires entering this code. Otherwise, the disk cannot be used without the correct disk control code. When a security question is set, the reset code can be reset with the correct security question. The control code of the disk is used to control the encrypted and decrypted reading and writing of the disk. The disk control code includes a read-only code and a read-write code. The user enters a qualified read-only code to ensure that only the disk files can be read but not rewritten or added. The correct read-only code plus the read-write code can read and write the entire disk.
[0038] After the user saves the pseudo-file, the central control unit of the storage device obtains the security codes entered by the user through the saved pseudo-file and judges the validity of these security codes.
[0039] If the security codes entered by the user in the pseudo-file are valid, modify the status of the storage device to the running state. The first hash result of the security code is used as the key, and the calculation result of the second hash value of these security codes is stored in the security area of the storage device. Otherwise, return to step (B-1).
[0040] The result of the first hash calculation of the above security code is obtained by merging the security code with an internal value of the disk, such as the disk serial number, and then performing a single hash calculation using a hash algorithm. The result of the second hash calculation of the security code is obtained by merging the result of the first hash calculation of the security code with another internal value of the disk and then performing another calculation.
[0041] The above hash algorithm is the SM3 algorithm.
[0042] C. Running state control process:
[0043] (C-1) When the storage device is in the running state, the central control unit starts the pseudo-disk program therein to form a virtual pseudo-disk. A running-state pseudo-file is emulated in the pseudo-disk. In this pseudo-file, the user is prompted in text to enter the control code of the disk within the file, and the function of the control code is shown in text or diagrams.
[0044] (C-2) When the user selects and opens the file, the information in the pseudo-file can be seen, and the user can enter the disk control code set in the initial state at the relevant position in the file. After the user saves the file, the central control unit of the storage device obtains the control code entered by the user through the saved pseudo-file and determines whether the result of the second hash calculation of these control codes is the same as the result saved in the initial state.
[0045] If they are the same, the result of the first hash calculation of these control codes is sent to the encryption / decryption control unit and step C-3 is entered. If they are different, return to step C-1.
[0046] (C-3) After the encryption / decryption control unit obtains the result of the first hash calculation of the control code, it checks the correctness of the result.
[0047] If it is correct, the stored content is encrypted / decrypted using these calculation results. The central control unit stops the operation of the pseudo-disk program and directly displays the decrypted stored data to the user. At this time, the user sees a complete disk and can read and write the content of the decrypted storage device.
[0048] The above result of the first hash calculation is only stored in the volatile memory of the encryption / decryption control unit, and is transformed into an encryption / decryption key, which will disappear when the power is off.
[0049] The above security code is provided with an error counter, and when the number of consecutive incorrect inputs reaches a certain amount, the relevant functions will be locked.
[0050] When the storage device in the running state cannot be used for encryption / decryption, the user can enter the reset code in the security code. After correctly entering the reset code, the central control unit formats the storage device and sets the state of the storage device to the initial state.
[0051] The above encryption and decryption control unit can store the check bits of the key, and check whether the control code is correct by calculating the check bits of the key during loading.
[0052] The above pseudo-file types can be files such as txt and html.
[0053] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for controlling encryption and decryption of a storage device based on a pseudo disk, the steps of which include: A) After the storage device is connected to a computer, judge the device state recorded in the storage device. If it is the initial state, execute step B); if it is the running state, execute step C); a pseudo disk program is set in the storage device; B) Initial state control process: (B-1) The central control unit of the storage device starts the pseudo disk program to form a virtual pseudo disk. A virtual initial state pseudo file is simulated in the pseudo disk and displayed to the user, for prompting the user to input the security code set by the user in the initial state pseudo file; (B-2) When the user selects to open the initial state pseudo file, receive the security code input by the user according to the prompt information in the initial state pseudo file and save it to the initial state pseudo file. The security code includes the control codes of each disk of the storage device; the central control unit obtains the security code typed by the user through the saved initial state pseudo file and judges the validity of the security code. If the security code is valid, modify the state of the storage device to the running state; use the first hash value of the security code as the key, and store the second hash value of the security code in the security area of the storage device. If the security code is invalid, return to step (B-1); C) Running state control process: (C-1) The central control unit of the storage device starts the pseudo disk program to form a virtual pseudo disk. A running state pseudo file is simulated in the pseudo disk and displayed to the user, for prompting the user to input the control code of the corresponding disk in the running state pseudo file and prompting the function of the control code; (C-2) When the user opens the running state pseudo file, receive the control code input by the user and save it to the running state pseudo file. The central control unit obtains the control code typed by the user through the running state pseudo file and judges whether the second hash value thereof is the same as the corresponding result saved in the initial state pseudo file. If it is the same, send the first hash value of the control code to the encryption and decryption control unit and enter step (C-3); otherwise, return to step (C-1); (C-3) The encryption and decryption control unit checks whether the first hash value of the control code is correct. If it is correct, encrypt or decrypt the specified storage content in the storage device by using the first hash value of the control code; otherwise, return to step (C-1).
2. The method according to claim 1, wherein, the security code further includes a reset code and a security question; when the user needs to reset the control code, input the reset code; when a security question is set, reset the reset code with the correct security question.
3. The method according to claim 2, wherein, when the file in the storage device cannot be encrypted or decrypted, prompt the user to input the reset code; after the central control unit receives the correct reset code, format the storage device and set the state of the storage device to the initial state.
4. The method according to claim 1, characterized in that, the control code includes a read-only code and a read-write code; when the user inputs the read-only code, the central control unit only allows the user to read the files in the storage device; when the user inputs the read-only code and the read-write code, the central control unit allows the user to read and write the files in the storage device.
5. The method according to claim 1, characterized in that, the one-time hash value of the control code is transformed into an encryption and decryption key and is only stored in the volatile memory of the encryption and decryption control unit.
6. The method according to claim 1 or 5, characterized in that, the encryption and decryption control unit stores the check bits of the key, and checks whether the control code is correct by calculating the check bits of the key.
7. The method according to claim 1, characterized in that, the one-time hash value of the security code is obtained by calculating once using a hash algorithm after merging the security code with an internal value of a disk i; the two-time hash value of the security code is obtained by calculating once using a hash algorithm after merging the one-time hash value of the security code with another internal value of the disk i.
8. The method according to claim 7, characterized in that, the hash algorithm is the SM3 algorithm.
9. The method according to claim 1, characterized in that, a counter is provided in the central control unit, and when the number of consecutive incorrect inputs of the control code reaches a set number of times, the same access of any user is stopped.
10. The method according to claim 1, characterized in that, the types of the initial state pseudo-file and the running state pseudo-file are txt files or html files.
Citation Information
Patent Citations
U disk security encryption management method
CN106372541A
Encrypted USB flash disk
CN110765501A
Data protection method of USB storage device based on magnetic disc virtual technology
CN102567233A
Data encryption mobile storage management method based on virtual disk
CN103065102A