Dynamic flash partition real-time encryption method, device and storage medium

CN116880751BActive Publication Date: 2026-09-15XIAMEN JINXUN SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310838700.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-10
Publication Date
2026-09-15
Estimated Expiration
2043-07-10

AI Technical Summary

Technical Problem

[0003]针对上述技术问题,本申请的目的在于提供一种动态Flash分区实时加密方法、设备及存储介质,旨在解决现有技术对保护的分区是固定的,不能调整的技术问题,实现在设备没有断电的情况下,黑客无法通过软件解密加密的分区

Benefits of technology

[0050]The dynamic Flash partition real-time encryption method provided in this application first deprotects the Flash partition of the first electronic device, which is in a protected state, through a second electronic device. Then, in the deprotected state, it is determined whether the first electronic device supports re-encryption. Only after determining that the first electronic device supports re-encryption is the user redirected to a configurable encryption interface to input the start and end addresses of the Flash partition to be encrypted. In this way, the Flash encrypted partition can be adjusted, solving the technical problem that the protected partition in the prior art is fixed and cannot be adjusted. It should be understood that since the protected partition in the prior art cannot be adjusted, it can be considered static. However, this application realizes the adjustment of the Flash encrypted partition. Therefore, it can be considered that the Flash encrypted partition of this application can be dynamically adjusted in real time. In addition, since the encryption mechanism adopted in this application is such that the software cannot decrypt the protected encryption mechanism when the first electronic device is not powered off, hackers cannot decrypt the encrypted partition through software when the first device is not powered off.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116880751B_ABST
    Figure CN116880751B_ABST
Patent Text Reader

Abstract

The application relates to the field of encryption technology, and provides a dynamic Flash partition real-time encryption method. The dynamic Flash partition real-time encryption method provided by the application first protects the Flash partition in a protection state of a first electronic device through a second electronic device, then judges whether the first electronic device supports re-encryption in the protection state, and only jumps to a configurable encryption interface to input the start address and the end address of the Flash partition needing to be encrypted by a user after judging that the first electronic device supports re-encryption, so that real-time dynamic adjustment of the Flash encryption partition is realized, and the technical problem that the partition to be protected is fixed and cannot be adjusted in the prior art is solved. In addition, since the encryption mechanism adopted by the application is an encryption mechanism that cannot be removed by software in the case that the first electronic device does not power off, hackers cannot decrypt the encrypted partition through software in the case that the first electronic device does not power off.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of encryption technology, and in particular to a method, device and storage medium for real-time encryption of dynamic Flash partitions. Background Technology

[0002] With the development of information technology, the amount of user data stored on smart devices is becoming increasingly rich, including photos, videos, and chat logs. This data often contains users' private information, and if the storage device is lost or compromised, it could lead to the leakage of user privacy data. Therefore, how to protect user data security has always been one of the important considerations in the design of smart devices. Currently, there are two main types of common data protection technologies: one is encryption technology, which uses cryptographic algorithms to encrypt data before storage by enabling full-disk encryption or partition encryption on the storage device, increasing the difficulty of data theft; the other technology uses secure partitions, storing sensitive data in specific secure partitions and then restricting access to those partitions. Both technologies have their advantages and can effectively protect data security. However, both technologies are software-based and susceptible to being cracked by hackers. Furthermore, the protected partitions are fixed and cannot be adjusted. Summary of the Invention

[0003] To address the aforementioned technical problems, the purpose of this application is to provide a method, device, and storage medium for real-time encryption of dynamic Flash partitions, aiming to solve the technical problem that the protected partitions are fixed and cannot be adjusted in the prior art, and to enable hackers to decrypt the encrypted partitions through software even when the device is not powered off.

[0004] In a first aspect, this application provides a method for real-time encryption of dynamic Flash partitions, applied to a real-time encryption system for dynamic Flash partitions. The real-time encryption system for dynamic Flash partitions includes a first electronic device, a second electronic device, and a server. The first electronic device is communicatively connected to the second electronic device, and the second electronic device is communicatively connected to the server. The method includes:

[0005] While the first electronic device is powered off, the second electronic device writes encrypted text to the first electronic device;

[0006] After the first electronic device is powered on, the first electronic device verifies the encrypted text;

[0007] After the ciphertext verification is successful, the first electronic device deprotects the Flash partition that is in a protected state.

[0008] The second electronic device sends a request to the first electronic device to enter the encryption authorization mode. In response to the request to enter the encryption authorization mode, the first electronic device encrypts the serial number of the first electronic device and sends the encrypted serial number to the second electronic device.

[0009] The second electronic device forwards the encrypted serial number to the server;

[0010] The server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0011] The second electronic device forwards the decrypted serial number to the first electronic device;

[0012] The first electronic device determines whether the decrypted serial number is the serial number of the first electronic device. If so, it sends an instruction to the second electronic device to jump to the configurable encryption interface.

[0013] The second electronic device jumps to the configurable encryption interface according to the instruction to jump to the configurable encryption interface, which is used to provide the user with input of the start address and end address of the partition to be encrypted;

[0014] The second electronic device sends a confirmation encryption command, the start address and the end address entered by the user to the first electronic device;

[0015] The first electronic device responds to the encryption command by controlling the system restart of the first electronic device, and during the system restart process, it encrypts the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0016] Furthermore, after the first electronic device verifies the ciphertext, the method further includes:

[0017] If the encrypted message fails to be verified, the first electronic device keeps the Flash partition in a protected state.

[0018] Furthermore, after the step of the server decrypting the encrypted serial number and comparing the decrypted serial number with each serial number stored in the server, the method further includes:

[0019] If the comparison fails, the server sends a serial number error message to the second electronic device.

[0020] The second electronic device forwards the error message for the serial number to the first electronic device;

[0021] The first electronic device displays an error message indicating the serial number.

[0022] Furthermore, the step of the first electronic device determining whether the decrypted serial number is the serial number of the first electronic device includes:

[0023] Obtain the serial number of the first electronic device from its memory;

[0024] The decrypted serial number is compared with the serial number of the first electronic device;

[0025] If they are the same, then the decrypted serial number is determined to be the serial number of the first electronic device;

[0026] If they are not the same, it is determined that the decrypted serial number is not the serial number of the first electronic device.

[0027] Furthermore, the first electronic device, in response to the encryption command, controls a system restart, and during the system restart process, encrypts the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address, including the following steps:

[0028] In response to the encryption command, the first electronic device controls the system to restart, and during the system restart process, it encrypts the corresponding Flash partition using the eMMC POWP mechanism according to the start address and the end address.

[0029] Furthermore, the step of the second electronic device writing ciphertext to the first electronic device includes:

[0030] The second electronic device writes RSA ciphertext to the first electronic device using a testing tool.

[0031] Secondly, embodiments of this application provide a real-time encryption method for dynamic Flash partitions, applied to a first electronic device, the method comprising:

[0032] While powered off, it receives encrypted text written by a second electronic device;

[0033] After powering on, verify the encrypted text;

[0034] After the ciphertext verification is successful, the Flash partition that is in a protected state is deprotected;

[0035] Receive a request from the second electronic device to enter the encryption authorization mode;

[0036] In response to the request to enter the encryption authorization mode, the serial number of the first electronic device is encrypted;

[0037] The encrypted serial number is sent to the second electronic device, so that the second electronic device sends the encrypted serial number to the server for decryption. The server compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0038] The device receives the decrypted serial number sent by the second electronic device, determines whether the decrypted serial number is the serial number of the first electronic device, and if so, sends an instruction to the second electronic device to jump to the configurable encryption interface, so that the second electronic device jumps to the configurable encryption interface, which is used to provide the user with input of the start address and end address of the partition to be encrypted;

[0039] Receive encryption instructions sent by the second electronic device, and the start and end addresses entered by the user;

[0040] In response to the encryption command, the system of the first electronic device is restarted, and during the system restart process, the corresponding Flash partition is encrypted using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0041] Secondly, embodiments of this application provide a real-time encryption method for dynamic Flash partitions, applied to a second electronic device, the method comprising:

[0042] When the first electronic device is powered off, ciphertext is written to the first electronic device so that after the first electronic device is powered on, the first electronic device verifies the ciphertext and, after the ciphertext is successfully verified, the first electronic device deprotects the Flash partition that is in a protected state.

[0043] A request to enter the encryption authorization mode is sent to the first electronic device, so that the first electronic device, in response to the request to enter the encryption authorization mode, encrypts the serial number of the first electronic device and sends the encrypted serial number to the second electronic device;

[0044] The system receives the encrypted serial number sent by the first electronic device, forwards the encrypted serial number to the server, so that the server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0045] The system receives the decrypted serial number sent by the server and forwards the decrypted serial number to the first electronic device, so that the first electronic device can determine whether the decrypted serial number is the serial number of the first electronic device. If so, it sends an instruction to the second electronic device to jump to the configurable encrypted interface.

[0046] The system receives the instruction to jump to the configurable encryption interface sent by the first electronic device, and jumps to the configurable encryption interface according to the instruction to jump to the configurable encryption interface. The configurable encryption interface is used to provide the user with input of the start address and end address of the partition to be encrypted.

[0047] Send a confirmation encryption command, a user-input start address, and an end address to the first electronic device, so that the first electronic device responds to the encryption command and controls the system restart of the first electronic device. During the system restart process, the corresponding Flash partition is encrypted using a specified encryption mechanism based on the start address and the end address. The specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0048] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps of the method described in any of the above-mentioned embodiments.

[0049] Fourthly, embodiments of this application provide a computer device, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor executes the computer program to implement the steps of the method described in any of the above-mentioned embodiments.

[0050] The dynamic Flash partition real-time encryption method provided in this application first deprotects the Flash partition of the first electronic device, which is in a protected state, through a second electronic device. Then, in the deprotected state, it is determined whether the first electronic device supports re-encryption. Only after determining that the first electronic device supports re-encryption is the user redirected to a configurable encryption interface to input the start and end addresses of the Flash partition to be encrypted. In this way, the Flash encrypted partition can be adjusted, solving the technical problem that the protected partition in the prior art is fixed and cannot be adjusted. It should be understood that since the protected partition in the prior art cannot be adjusted, it can be considered static. However, this application realizes the adjustment of the Flash encrypted partition. Therefore, it can be considered that the Flash encrypted partition of this application can be dynamically adjusted in real time. In addition, since the encryption mechanism adopted in this application is such that the software cannot decrypt the protected encryption mechanism when the first electronic device is not powered off, hackers cannot decrypt the encrypted partition through software when the first device is not powered off. Attached Figure Description

[0051] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0052] Figure 1 This is a flowchart illustrating a real-time encryption method for dynamic Flash partitions provided in an embodiment of this application;

[0053] Figure 2 This is a signaling diagram of a real-time encryption method for dynamic Flash partitions provided in an embodiment of this application;

[0054] Figure 3 This is a flowchart illustrating a real-time encryption method for dynamic Flash partitions provided in another embodiment of this application;

[0055] Figure 4 This is a flowchart illustrating a real-time encryption method for dynamic Flash partitions provided in another embodiment of this application;

[0056] Figure 5 This is a schematic block diagram of the structure of the computer device provided in the embodiments of this application. Detailed Implementation

[0057] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0058] Those skilled in the art will understand that, unless explicitly stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this application’s specification means the presence of features, integers, steps, operations, elements, modules, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, modules, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any modules and all combinations of one or more associated listed items.

[0059] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0060] Example 1:

[0061] like Figure 1 , 2 The present application provides a method for real-time encryption of dynamic Flash partitions, applied to a real-time encryption system for dynamic Flash partitions. The system includes a first electronic device, a second electronic device, and a server. The first electronic device is communicatively connected to the second electronic device, and the second electronic device is communicatively connected to the server. The method includes steps S1-S11:

[0062] S1. When the first electronic device is powered off, the second electronic device writes encrypted text to the first electronic device.

[0063] In step S1, the first electronic device is the terminal that needs to be encrypted, which can be a smart terminal such as a mobile phone or tablet computer. The second electronic device can be a PC (personal computer) or an electronic device with writing function and network connectivity. After the first electronic device and the second electronic device establish a communication connection, the second electronic device can write ciphertext to the backup area of ​​the first electronic device. The ciphertext can be RSA ciphertext. RSA ciphertext is ciphertext formed by encryption using the RSA algorithm. The RSA algorithm is an asymmetric encryption algorithm. The RSA encryption process is as follows: (1) A generates a pair of keys (public key and private key). The private key is not public and is kept by A. The public key is public and can be obtained by anyone. (2) A transmits its public key to B, and B uses A's public key to encrypt the message. (3) A receives the encrypted message from B and decrypts the message using its own private key. In this process, there are only two transmission processes. The first is A transmitting the public key to B, and the second is B transmitting the encrypted message to A. Even if both are intercepted by the enemy, there is no danger because only A's private key can decrypt the message, preventing the leakage of the message content. Therefore, after the first electronic device establishes a communication connection with the second electronic device, the first electronic device generates a pair of private and public keys, then retains the private key and sends the public key to the second electronic device. The second electronic device uses the public key to encrypt the plaintext, obtaining RSA ciphertext.

[0064] S2. After the first electronic device is powered on, the first electronic device verifies the encrypted text.

[0065] In step S2, when the ciphertext is RSA ciphertext, the first electronic device decrypts the ciphertext using its private key to obtain the plaintext. It should be understood that the plaintext refers to the content before encryption. Then, the plaintext is verified. If the plaintext is the same as the plaintext pre-stored in the first electronic device, the verification is successful. The plaintext can be a string of numbers, letters, and symbols.

[0066] S3. After the ciphertext verification is successful, the first electronic device deprotects the Flash partition that is in a protected state.

[0067] In step S3, the specified Flash partition in the first electronic device is in a protected state. If the protected Flash partition needs to be redefined, it must first be deprotected before it can be redefined.

[0068] S4. The second electronic device sends a request to the first electronic device to enter the encryption authorization mode. In response to the request to enter the encryption authorization mode, the first electronic device encrypts its serial number and sends the encrypted serial number to the second electronic device.

[0069] S5. The second electronic device forwards the encrypted serial number to the server.

[0070] S6. The server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0071] In steps S4-S6, the second electronic device can be a network-connected smart device such as a PC, and the first electronic device can be a mobile phone. The Flash partition of the first electronic device (e.g., a mobile phone) in a protected state is redefined by manually operating the second electronic device (e.g., a PC). A second electronic device (PC) is connected to a first electronic device (mobile phone) using a USB (Universal Serial Bus) cable. The second electronic device (PC) is connected to a server via the internet. The server generates a public key and a private key pair, retains the private key, and sends the public key to the first electronic device through the second electronic device. Then, the user enters the encrypted authorization mode. At this time, the first electronic device uses the public key sent by the second electronic device to encrypt its serial number (SN). The first electronic device then sends the encrypted serial number and public key to the second electronic device, which forwards them to the server. Since the server stores many public and private keys, it needs to match the corresponding private key with the public key and use that private key to decrypt the serial number, obtaining the decrypted serial number. As described above, the encryption algorithm used for the serial number in this embodiment is an asymmetric encryption algorithm. Because only the private key can decrypt the serial number, and the private key is not transmitted, even if the public key is obtained during transmission, the serial number cannot be decrypted, thus improving data security.

[0072] S7. The second electronic device forwards the decrypted serial number to the first electronic device.

[0073] S8. The first electronic device determines whether the decrypted serial number is the serial number of the first electronic device. If so, it sends an instruction to the second electronic device to jump to the configurable encryption interface.

[0074] S9. The second electronic device jumps to the configurable encryption interface according to the instruction to jump to the configurable encryption interface, which is used to provide the user with input of the start address and end address of the partition to be encrypted.

[0075] In step S9, the start and end addresses input by the user are obtained, which enables real-time partitioning of the flash memory. This allows for customized design of the adjusted partitions in real time, making it more user-friendly and improving the user experience.

[0076] S10, the second electronic device sends a confirmation encryption command, the start address and the end address entered by the user to the first electronic device.

[0077] In steps S7 and S10, when the decrypted serial number is the serial number of the first electronic device, the second electronic device can normally enter the encryption authorization mode and open the configurable encryption interface. The user can enter the start address and end address of the partition to be encrypted in the configurable encryption interface. When the user clicks the encryption button in the configurable encryption interface, the second electronic device will write the start address and end address of the partition to be encrypted entered by the user into the backup area of ​​the first electronic device.

[0078] It should be noted that the second electronic device in steps S4-S10 can be another third electronic device. That is, the second electronic device in step S1 and the second electronic device in steps S4-10 are not the same electronic device. This makes the multi-terminal configuration more flexible and the security higher.

[0079] S11. The first electronic device responds to the encryption command by controlling the system restart of the first electronic device, and during the system restart process, it encrypts the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0080] In step S11, after the second electronic device writes the start and end addresses of the partition to be encrypted, input by the user, into the backup area of ​​the first electronic device, the first electronic device simultaneously restarts its system. During the restart initialization process, the first electronic device reads the start and end addresses from the backup area and encrypts the corresponding Flash partition based on these addresses. Since the encryption mechanism used is one that cannot be decrypted by software without power loss, hackers cannot decrypt the encrypted partition using software while the first electronic device is powered on.

[0081] The dynamic Flash partition real-time encryption method provided in this application first deprotects the Flash partition of the first electronic device, which is in a protected state, using a second electronic device. Then, in the deprotected state, it is determined whether the first electronic device supports re-encryption. Only after determining that the first electronic device supports re-encryption does it redirect to a configurable encryption interface for the user to input the start and end addresses of the Flash partition to be encrypted. This achieves adjustment of the Flash encrypted partition, solving the technical problem in existing technologies where the protected partition is fixed and cannot be adjusted. It should be understood that since existing technologies cannot adjust the protected partition, they can be considered static, while this application achieves adjustment of the Flash encrypted partition. Therefore, the Flash encrypted partition of this application can be considered dynamically and in real-time adjustable. Furthermore, since the encryption mechanism used in this application is one that cannot be deprotected by software when the first electronic device is powered on, hackers cannot decrypt the encrypted partition through software when the first electronic device is not powered off.

[0082] In some embodiments, after the first electronic device verifies the ciphertext, the method further includes:

[0083] If the encrypted message fails to be verified, the first electronic device keeps the Flash partition in a protected state.

[0084] In this embodiment, after the first electronic device verifies the ciphertext, there are two possibilities: successful verification (as in step S3) and unsuccessful verification. In the case of unsuccessful verification, the first electronic device may not respond, and the Flash partition in the protected state will remain protected. The first electronic device may also display the unsuccessful verification information on itself and / or the second electronic device.

[0085] In some embodiments, after the server decrypts the encrypted serial number and compares the decrypted serial number with the serial numbers stored in the server, the method further includes:

[0086] If the comparison fails, the server sends a serial number error message to the second electronic device.

[0087] The second electronic device forwards the error message for the serial number to the first electronic device;

[0088] The first electronic device displays an error message indicating the serial number.

[0089] In this embodiment, after comparing the decrypted serial number with the serial numbers stored on the server, there are two possibilities: a successful comparison (as in step S6) and a failed comparison (where no matching serial number is found on the server). In the latter case, the server may not respond. Alternatively, the server may send a serial number error message to the second electronic device; the second electronic device forwards the error message to the first electronic device; and the first electronic device displays the error message. This embodiment does not impose any limitations on these possibilities.

[0090] In some embodiments, the step of the first electronic device determining whether the decrypted serial number is the serial number of the first electronic device includes:

[0091] Obtain the serial number of the first electronic device from its memory;

[0092] The decrypted serial number is compared with the serial number of the first electronic device;

[0093] If they are the same, then the decrypted serial number is determined to be the serial number of the first electronic device;

[0094] If they are not the same, it is determined that the decrypted serial number is not the serial number of the first electronic device.

[0095] In this embodiment of the application, by comparing the decrypted serial number with the serial number of the real first electronic device, it can be determined whether the decrypted serial number is the serial number of the first electronic device.

[0096] In some embodiments, the first electronic device responds to the encryption command by controlling a system restart of the first electronic device, and during the system restart process, the step of encrypting the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address includes:

[0097] In response to the encryption command, the first electronic device controls the system to restart, and during the system restart process, it encrypts the corresponding Flash partition using the eMMC POWP mechanism according to the start address and the end address.

[0098] In this embodiment, the power-off write protection (POWP) mechanism of the eMMC (embedded Multi Media Card) is used to protect user data from tampering when power is off. This protection is inaccessible to software without power loss, thus preventing data damage by hackers. Besides this mechanism, other mechanisms can also be used to encrypt the corresponding Flash partition, as long as the mechanism ensures that software cannot remove the protection without power loss.

[0099] In one embodiment, the step of the second electronic device writing ciphertext to the first electronic device includes:

[0100] The second electronic device writes RSA ciphertext to the first electronic device using a testing tool.

[0101] In this embodiment, the testing tool can be simba, which is used for calibration, writing serial numbers (SNs), IMEIs (International Mobile Equipment Identity), RSA ciphertext, etc., for production line testing current or other production line testing functions. RSA ciphertext is ciphertext formed using the RSA algorithm, an asymmetric encryption algorithm that has been described above and will not be repeated here.

[0102] Example 2:

[0103] This application also provides a method for real-time encryption of dynamic Flash partitions, applied to a first electronic device, such as... Figure 3 As shown, the method includes:

[0104] S101. In the power-off state, receive the ciphertext written by the second electronic device;

[0105] S102. After powering on, verify the encrypted text;

[0106] S103. After the ciphertext verification is successful, the Flash partition in the protected state is deprotected.

[0107] S104. Receive a request from the second electronic device to enter the encryption authorization mode;

[0108] S105. In response to the request to enter the encryption authorization mode, the serial number of the first electronic device is encrypted;

[0109] S106. The encrypted serial number is sent to the second electronic device, so that the second electronic device sends the encrypted serial number to the server for decryption. The server compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0110] S107. Receive the decrypted serial number sent by the second electronic device, determine whether the decrypted serial number is the serial number of the first electronic device, and if so, send an instruction to the second electronic device to jump to the configurable encryption interface, so that the second electronic device jumps to the configurable encryption interface, the configurable encryption interface is used to provide the user with input of the start address and end address of the partition to be encrypted;

[0111] S108. Receive the encryption instruction sent by the second electronic device, and the start address and end address input by the user;

[0112] S109. In response to the encryption command, control the system of the first electronic device to restart, and during the system restart process, encrypt the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0113] In some embodiments, after the step of verifying the ciphertext upon power-on, the method further includes:

[0114] If the encrypted message fails to be verified, the Flash partition in the protected state remains in the protected state.

[0115] In some embodiments, after the step of comparing the decrypted serial number with each serial number stored in the server, the method further includes:

[0116] If the comparison fails, the server sends a serial number error message to the second electronic device.

[0117] The first electronic device receives and displays an error message about the serial number forwarded by the second electronic device.

[0118] In some embodiments, the step of determining whether the decrypted serial number is the serial number of the first electronic device includes:

[0119] Obtain the serial number of the first electronic device from its memory;

[0120] The decrypted serial number is compared with the serial number of the first electronic device;

[0121] If they are the same, then the decrypted serial number is determined to be the serial number of the first electronic device;

[0122] If they are not the same, it is determined that the decrypted serial number is not the serial number of the first electronic device.

[0123] In some embodiments, the step of controlling the system restart of the first electronic device in response to the encryption command, and encrypting the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address during the system restart process includes:

[0124] In response to the encryption command, the system of the first electronic device is restarted, and during the system restart process, the corresponding Flash partition is encrypted using the eMMC POWP mechanism according to the start address and the end address.

[0125] Example 3:

[0126] Please see Figure 4 This application provides a method for real-time encryption of dynamic Flash partitions, applied to a second electronic device. The method includes steps S201-S206:

[0127] S201. When the first electronic device is powered off, ciphertext is written to the first electronic device so that after the first electronic device is powered on, the first electronic device verifies the ciphertext and, after the ciphertext is successfully verified, the first electronic device deprotects the Flash partition that is in a protected state.

[0128] S202. Send a request to the first electronic device to enter the encryption authorization mode, so that the first electronic device responds to the request to enter the encryption authorization mode, encrypts the serial number of the first electronic device, and sends the encrypted serial number to the second electronic device.

[0129] S203. Receive the encrypted serial number sent by the first electronic device, forward the encrypted serial number to the server, so that the server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device.

[0130] S204. Receive the decrypted serial number sent by the server, and forward the decrypted serial number to the first electronic device so that the first electronic device can determine whether the decrypted serial number is the serial number of the first electronic device. If so, send an instruction to the second electronic device to jump to the configurable encrypted interface.

[0131] S205. Receive the instruction to jump to the configurable encryption interface sent by the first electronic device, and jump to the configurable encryption interface according to the instruction to jump to the configurable encryption interface. The configurable encryption interface is used to provide the user with input of the start address and end address of the partition to be encrypted.

[0132] S206. Send a confirmation encryption command, the user-input start address, and the end address to the first electronic device, so that the first electronic device responds to the encryption command, controls the system restart of the first electronic device, and during the system restart process, encrypts the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

[0133] It should be noted that the difference between Embodiments 2 and 3 and Embodiment 1 lies in the execution subject. The execution subject of Embodiment 1 is the various devices in the dynamic Flash partition real-time encryption system, while the execution subject of Embodiment 2 is the first electronic device, and the execution subject of Embodiment 3 is the second electronic device. However, the schemes of the three are actually the same. Therefore, the explanation of Embodiment 1 applies to the explanation of Embodiment 2. Therefore, this application will not elaborate further here.

[0134] Example 3:

[0135] Reference Figure 5 This application also provides a computer device whose internal structure can be as follows: Figure 5 As shown. The computer device includes a processor, memory, network interface, and database connected via a system bus. The processor is designed to provide computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores operating devices, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores data from any of the embodiments one to three above. The network interface is used to communicate with external terminals via a network connection. Furthermore, the computer device may also include an input device and a display screen. When the computer program is executed by the processor, it implements the dynamic Flash partition real-time encryption method described in any of the embodiments one to three above; that is, the computer can be a dynamic Flash partition real-time encryption system, or a first electronic device or a second electronic device. Those skilled in the art will understand that... Figure 5The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer equipment on which the present application is applied.

[0136] One embodiment of this application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a real-time encryption method for dynamic Flash partitions as described in any one of embodiments one to three.

[0137] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media provided in this application and in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-speed SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0138] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.

[0139] The above description is only a preferred embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural changes made based on the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A dynamic flash partition real-time encryption method, characterized in that, A method for applying to a real-time encryption system for dynamic Flash partitions, the system comprising a first electronic device, a second electronic device, and a server, wherein the first electronic device is communicatively connected to the second electronic device, and the second electronic device is communicatively connected to the server, the method comprising: While the first electronic device is powered off, the second electronic device writes encrypted text to the first electronic device; After the first electronic device is powered on, the first electronic device verifies the encrypted text; After the ciphertext verification is successful, the first electronic device deprotects the Flash partition that is in a protected state. The second electronic device sends a request to the first electronic device to enter the encryption authorization mode. In response to the request to enter the encryption authorization mode, the first electronic device encrypts the serial number of the first electronic device and sends the encrypted serial number to the second electronic device. The second electronic device forwards the encrypted serial number to the server; The server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device. The second electronic device forwards the decrypted serial number to the first electronic device; The first electronic device determines whether the decrypted serial number is the serial number of the first electronic device. If so, it sends an instruction to the second electronic device to jump to the configurable encryption interface. The second electronic device jumps to the configurable encryption interface according to the instruction to jump to the configurable encryption interface, which is used to provide the user with input of the start address and end address of the partition to be encrypted; The second electronic device sends a confirmation encryption command, the start address and the end address entered by the user to the first electronic device; The first electronic device responds to the encryption command by controlling the system restart of the first electronic device, and during the system restart process, it encrypts the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address; the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

2. The dynamic Flash partition real-time encryption method of claim 1, wherein, After the first electronic device verifies the ciphertext, the method further includes: If the ciphertext fails to be verified, the first electronic device keeps the Flash partition in a protected state.

3. The dynamic Flash partition real-time encryption method of claim 1, wherein, After the server decrypts the encrypted serial number and compares the decrypted serial number with the serial numbers stored on the server, the method further includes: If the comparison fails, the server sends a serial number error message to the second electronic device. The second electronic device forwards the error message for the serial number to the first electronic device; The first electronic device displays an error message indicating the serial number.

4. The dynamic Flash partition real-time encryption method of claim 1, wherein, The step of the first electronic device determining whether the decrypted serial number is the serial number of the first electronic device includes: Obtain the serial number of the first electronic device from its memory; The decrypted serial number is compared with the serial number of the first electronic device; If they are the same, then the decrypted serial number is determined to be the serial number of the first electronic device; If they are not the same, it is determined that the decrypted serial number is not the serial number of the first electronic device.

5. The dynamic Flash partition real-time encryption method of claim 1, wherein, In response to the encryption command, the first electronic device controls a system restart, and during the system restart process, the steps of encrypting the corresponding Flash partition using a specified encryption mechanism based on the start address and the end address include: In response to the encryption command, the first electronic device controls the system to restart, and during the system restart process, it encrypts the corresponding Flash partition using the eMMC POWP mechanism based on the start address and the end address.

6. The dynamic Flash partition real-time encryption method of claim 1, wherein, The steps of the second electronic device writing ciphertext to the first electronic device include: The second electronic device writes RSA ciphertext to the first electronic device using a testing tool.

7. A dynamic flash partition real-time encryption method, characterized in that, Applied to a first electronic device, the method includes: While powered off, it receives encrypted text written by a second electronic device; After powering on, verify the encrypted text; After the ciphertext verification is successful, the Flash partition that is in a protected state is deprotected; Receive a request from the second electronic device to enter the encryption authorization mode; In response to the request to enter the encryption authorization mode, the serial number of the first electronic device is encrypted; The encrypted serial number is sent to the second electronic device, so that the second electronic device sends the encrypted serial number to the server for decryption. The server compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device. The device receives the decrypted serial number sent by the second electronic device, determines whether the decrypted serial number is the serial number of the first electronic device, and if so, sends an instruction to the second electronic device to jump to the configurable encryption interface, so that the second electronic device jumps to the configurable encryption interface, which is used to provide the user with input of the start address and end address of the partition to be encrypted; Receive encryption instructions sent by the second electronic device, and the start and end addresses entered by the user; In response to the encryption command, the system of the first electronic device is restarted, and during the system restart process, the corresponding Flash partition is encrypted using a specified encryption mechanism based on the start address and the end address; wherein, the specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

8. A method for real-time encryption of dynamic Flash partitions, characterized in that, Applied to a second electronic device, the method includes: When the first electronic device is powered off, ciphertext is written to the first electronic device so that after the first electronic device is powered on, the first electronic device verifies the ciphertext and, after the ciphertext is successfully verified, the first electronic device deprotects the Flash partition that is in a protected state. A request to enter the encryption authorization mode is sent to the first electronic device, so that the first electronic device, in response to the request to enter the encryption authorization mode, encrypts the serial number of the first electronic device and sends the encrypted serial number to the second electronic device; The system receives the encrypted serial number sent by the first electronic device, forwards the encrypted serial number to the server, so that the server decrypts the encrypted serial number and compares the decrypted serial number with each serial number stored in the server. If the comparison is successful, the server sends the decrypted serial number to the second electronic device. The system receives the decrypted serial number sent by the server and forwards the decrypted serial number to the first electronic device, so that the first electronic device can determine whether the decrypted serial number is the serial number of the first electronic device. If so, it sends an instruction to the second electronic device to jump to the configurable encrypted interface. The system receives the instruction to jump to the configurable encryption interface sent by the first electronic device, and jumps to the configurable encryption interface according to the instruction to jump to the configurable encryption interface. The configurable encryption interface is used to provide the user with input of the start address and end address of the partition to be encrypted. Send a confirmation encryption command, a user-input start address, and an end address to the first electronic device, so that the first electronic device responds to the encryption command and controls the system restart of the first electronic device. During the system restart process, the corresponding Flash partition is encrypted using a specified encryption mechanism based on the start address and the end address. The specified encryption mechanism is an encryption mechanism that cannot be de-protected by software when the first electronic device is powered on.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Equipment, high-security encryption method thereof and storage medium

    CN111309512A

  • Data protection method and device

    CN116127468A