Solid state disk encryption authentication method and solid state disk
Patent Information
- Application Number
- CN202210728738.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-24
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2042-06-24
AI Technical Summary
但是,由于加密认证模块是一个硬件模块,其可以被拆解、替换、破解、篡改或者复制,使得一方面,通过硬件认证模块的认证程序被复制,非法固态硬盘也能通过身份认证,比如,将某一块已经通过身份认证固态硬盘的认证模块内容复制烧写到另一块固态硬盘上,则另一块固态硬盘也会被成功通过身份认证;另一方面已经通过身份认证的固态硬盘的认证模块被替换,由于该固态硬盘已经被通过身份认证,该固态硬盘只要中间不断开连接则一直处于可读写状态;又一方面,固态硬盘的硬件认证模块被更换或移除时,计算机并不能立即得到相应的响应
[0067] According to a third aspect of the present invention, a solid-state drive is provided, comprising: one or more processors; and a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs including instructions for performing any of the methods in the solid-state drive encryption authentication methods described above.
Smart Images

Figure CN117332386B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encryption technology, and in particular to encryption authentication methods, devices, storage media, and solid-state drives in storage controllers. Background Technology
[0002] Solid-state drives (SSDs), as storage devices, provide data storage services. To enhance the security of the data stored on SSDs, encryption can be applied. Access to the SSD requires encrypted authentication, and only those who pass authentication are allowed access to the SSD.
[0003] In existing technologies, SSD encryption can be implemented through a hardware authentication module. For example, an encryption authentication module can be set up within the SSD, and encrypted authentication data can be set within this module to perform encryption authentication. However, because the encryption authentication module is a hardware module, it can be disassembled, replaced, cracked, tampered with, or copied. This means that, on the one hand, if the authentication program of the hardware authentication module is copied, an unauthorized SSD can also pass authentication. For example, copying the authentication module content of an already authenticated SSD and burning it to another SSD will also allow the other SSD to successfully pass authentication. On the other hand, if the authentication module of an already authenticated SSD is replaced, since the SSD has already passed authentication, it will remain in a read / write state as long as the connection is not broken. Furthermore, when the hardware authentication module of an SSD is replaced or removed, the computer does not immediately respond. This not only reduces the security of SSDs but also harms the economic interests of SSD manufacturers and, in the long run, damages the innovation environment.
[0004] Therefore, in order to improve the security of solid-state drives and protect the rights and interests of manufacturers, it is hoped that appropriate technical means will be adopted to prevent the disassembly, replacement, cracking, tampering or copying of the encryption authentication module. Summary of the Invention
[0005] Therefore, the present invention provides a solid-state drive encryption authentication method and a solid-state drive, in an attempt to solve or at least alleviate at least one of the above-mentioned problems.
[0006] According to a first aspect of this application, a first solid-state drive (SSD) encryption authentication method is provided, wherein the SSD is equipped with an encryption authentication module, the encryption authentication module stores encryption authentication data, and the method includes:
[0007] In response to the power-on of the solid-state drive, first encrypted authentication data is acquired, the first encrypted authentication data including the software batch number of the encryption authentication module and the digest value of the encrypted data generated by the encryption algorithm;
[0008] Based on the first encrypted authentication data, the accessibility status information of the solid-state drive and the second encrypted authentication data are obtained through the authentication information. The second encrypted authentication data includes the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module, and the digest value of the encrypted data is generated by the encryption algorithm.
[0009] Based on the accessibility status information of the solid-state drive and the second encryption authentication data, the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data are obtained. The third encryption authentication data includes the digest value of the encrypted data generated by the encryption algorithm from the first internal random number of the solid-state drive.
[0010] Based on the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data through the authentication information, the encrypted data stored on the solid-state drive and the fourth encryption authentication data are obtained. The fourth encryption authentication data includes the decryption key of the encrypted data stored on the solid-state drive.
[0011] Based on the decryption key corresponding to the fourth encryption authentication data, the encrypted data stored in the solid-state drive is decrypted to obtain the data information of the solid-state drive and the working status information of the encryption authentication module detected at a set time frequency.
[0012] According to the first solid-state drive encryption authentication method of the first aspect of this application, a second solid-state drive encryption authentication method is provided. The encryption authentication module includes multiple storage spaces, each storage space including multiple data storage areas; wherein, one of the storage spaces stores the software batch number of the encryption authentication module; one of the storage spaces includes eight data storage areas; and one of the storage spaces stores the first encryption authentication data.
[0013] According to the first or second solid-state drive encryption authentication method of the first aspect of this application, a third solid-state drive encryption authentication method is provided, which, in response to the power-on of the solid-state drive, acquires first encryption authentication data, including:
[0014] In response to the power-on of the solid-state drive, the startup information of the encryption authentication module is obtained;
[0015] Based on the startup information of the encryption authentication module, obtain the successful detection information of the encryption authentication module;
[0016] Based on the successful detection information of the encryption authentication module, the data information stored in the encryption authentication module is obtained;
[0017] Based on the data information stored in the encryption authentication module, the first encryption authentication data is obtained.
[0018] According to any one of the first to third solid-state drive encryption authentication methods of the first aspect of this application, a fourth solid-state drive encryption authentication method is provided, wherein obtaining the accessibility status information of the solid-state drive and the second encryption authentication data based on the first encryption authentication data and authentication information includes:
[0019] Obtain the software batch number of the encryption authentication module and the encryption public key used by the first encryption authentication data;
[0020] Based on the software batch number of the encryption authentication module and the encryption public key used in the first encryption authentication data, the first comparison data generated using the software batch number of the encryption authentication module is obtained through the first encryption algorithm;
[0021] Based on the first comparison data and the second internal random number of the solid-state drive, obtain the response value of the first comparison data;
[0022] Based on the second internal random number of the solid-state drive, obtain the response value of the first encrypted authentication data;
[0023] Based on the response value of the first comparison data and the response value of the first encrypted authentication data, obtain the authentication information of the first encrypted authentication data;
[0024] Based on the first encrypted authentication data and the authentication information, the accessibility status information of the solid-state drive is obtained;
[0025] Based on the accessibility status information of the solid-state drive, the second encryption authentication data is obtained.
[0026] According to any one of the first to fourth solid-state drive encryption authentication methods of the first aspect of this application, a fifth solid-state drive encryption authentication method is provided. The step of obtaining compatibility information between the solid-state drive and the encryption authentication module, and third encryption authentication data, based on the accessibility status information of the solid-state drive and the second encryption authentication data authentication information, includes:
[0027] Obtain the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the encryption public key used by the second encryption authentication data;
[0028] Based on the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the encryption public key used in the second encryption authentication data, the second comparison data is generated by obtaining the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module through the first encryption algorithm.
[0029] Based on the second comparison data and the third internal random number of the solid-state drive, obtain the response value of the second comparison data;
[0030] Based on the response value of the second comparison data and the second encrypted authentication data, obtain the authentication information of the second encrypted authentication data;
[0031] Based on the second encrypted authentication data and the authentication information, the compatibility information between the solid-state drive and the encrypted authentication module is obtained;
[0032] The third encryption authentication data is obtained based on the compatibility information between the solid-state drive and the encryption authentication module.
[0033] According to any one of the first to fifth solid-state drive encryption authentication methods of the first aspect of this application, a sixth solid-state drive encryption authentication method is provided, wherein the step of obtaining the encrypted data stored on the solid-state drive and the fourth encryption authentication data based on the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data through authentication information, includes:
[0034] Obtain the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module;
[0035] Based on the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module, the first hash value is obtained through the first encryption algorithm;
[0036] Based on the first hash value and the third encrypted authentication data, the third comparison data is obtained through the second encryption algorithm;
[0037] Obtain the fourth comparison data stored in the solid-state drive, and obtain the third encryption authentication data authentication information based on the comparison result between the third comparison data and the fourth comparison data;
[0038] Based on the third encryption authentication data, the encrypted data stored in the solid-state drive and the fourth encryption authentication data are obtained through the authentication information.
[0039] According to any one of the first to sixth solid-state drive encryption authentication methods of the first aspect of this application, a seventh solid-state drive encryption authentication method is provided, wherein the step of generating the first encryption authentication data includes:
[0040] Obtain the software batch number of the encryption authentication module;
[0041] Based on the software batch number of the encryption authentication module and the first encryption algorithm, obtain the first encryption algorithm operation value of the software batch number;
[0042] Based on the first encryption algorithm operation value of the software batch number, obtain the digest value of the first encryption algorithm operation value of the software batch number;
[0043] The first encrypted authentication data is obtained based on the digest value of the first encryption algorithm operation value of the software batch number.
[0044] According to any one of the first to seventh solid-state drive encryption authentication methods of the first aspect of this application, an eighth solid-state drive encryption authentication method is provided, wherein the steps for generating the second encryption authentication data include:
[0045] Obtain the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module;
[0046] Based on the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the first encryption algorithm, obtain the first encryption algorithm operation value of the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module.
[0047] Based on the software batch number of the encryption authentication module and the first encryption algorithm operation value of the data storage area number of the encryption authentication module, a digest value of the software batch number of the encryption authentication module and the first encryption algorithm operation value of the data storage area number of the encryption authentication module is obtained.
[0048] The second encryption authentication data is obtained based on the digest value of the first encryption algorithm operation value of the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module.
[0049] According to any one of the sixth to eighth solid-state drive encryption authentication methods of the first aspect of this application, a ninth solid-state drive encryption authentication method is provided, wherein the step of generating the third encryption authentication data includes:
[0050] Obtain the first internal random number generated by the true random number generator of the solid-state drive;
[0051] Based on the first internal random number generated by the true random number generator of the solid-state drive, a first keyword is obtained, wherein the first keyword is the digest value of the first internal random number after being processed by the first encryption algorithm;
[0052] Obtain the serial number of the solid-state drive and the software batch number of the encryption authentication module;
[0053] Based on the serial number of the solid-state drive and the software batch number of the encryption authentication module, a second hash value is obtained. The second hash value is the digest value of the serial number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm.
[0054] The third encrypted authentication data is obtained based on the first keyword and the second hash value. The third encrypted authentication data is obtained by performing a second encryption algorithm operation on the first keyword using the second hash value.
[0055] Obtain the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module, and obtain the first hash value. The first hash value is the digest value of the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm.
[0056] Based on the first hash value and the third encrypted authentication data, the fourth comparison data is obtained and stored in the solid-state drive. The fourth comparison data is obtained by processing the first hash value and the third encrypted authentication data using a second encryption algorithm.
[0057] According to any one of the first to ninth solid-state drive encryption authentication methods of the first aspect of this application, a tenth solid-state drive encryption authentication method is provided, wherein the step of generating the fourth encryption authentication data includes:
[0058] Obtain the serial number of the solid-state drive and the software batch number of the encryption authentication module;
[0059] Based on the serial number of the solid-state drive and the software batch number of the encryption authentication module, a second hash value is obtained. The second hash value is the digest value of the serial number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm.
[0060] Based on the second hash value and the third encrypted authentication data, a first keyword is obtained, which is obtained by decrypting the second hash value and the third encrypted authentication data using a second encryption algorithm.
[0061] Obtain the fifth internal random number of the solid-state drive;
[0062] Based on the fifth internal random number of the solid-state drive, a third hash value is obtained, wherein the third hash value is the digest value of the fifth internal random number after being processed by the first encryption algorithm;
[0063] The fourth encrypted authentication data is obtained based on the first keyword and the third hash value. The fourth encrypted authentication data is obtained by encrypting the first keyword with the third hash value using the second encryption algorithm.
[0064] According to a second aspect of the present invention, a solid-state drive (SSD) encryption authentication device is provided, wherein the SSD is provided with an encryption authentication module, the encryption authentication module storing encryption authentication data, characterized in that the device comprises:
[0065] An authentication execution module is configured to, in response to the power-on information of the solid-state drive (SSD), acquire first encrypted authentication data, which includes a digest value of encrypted data generated by an encryption algorithm from the software batch number of the encryption authentication module; based on the first encrypted authentication data and authentication information, acquire accessibility status information of the SSD and second encrypted authentication data, which includes a digest value of encrypted data generated by an encryption algorithm from the software batch number and data storage area number of the encryption authentication module; based on the accessibility status information of the SSD and authentication information from the second encrypted authentication data, acquire compatibility information between the SSD and the encryption authentication module, and third encrypted authentication data, which includes a digest value of encrypted data generated by an encryption algorithm from a first internal random number of the SSD; based on the compatibility information between the SSD and the encryption authentication module and authentication information from the third encrypted authentication data, acquire encrypted data stored on the SSD and fourth encrypted authentication data, which includes a decryption key for the encrypted data stored on the SSD.
[0066] The data decryption module is used to decrypt the encrypted data stored in the solid-state drive based on the decryption key of the fourth encryption authentication data, to obtain the data information of the solid-state drive, and the working status information of the encryption authentication module detected at a set time frequency.
[0067] According to a third aspect of the present invention, a solid-state drive is provided, comprising: one or more processors; and a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs including instructions for performing any of the methods in the solid-state drive encryption authentication methods described above.
[0068] According to the solid-state drive (SSD) encryption authentication method of the present invention, in response to the power-on of the SSD, first encryption authentication data is acquired; based on the authentication information obtained from the first encryption authentication data, accessibility status information and second encryption authentication data of the SSD are acquired; based on the accessibility status information and the authentication information obtained from the second encryption authentication data, compatibility information between the SSD and the encryption authentication module, and third encryption authentication data are acquired; based on the compatibility information between the SSD and the encryption authentication module, and the authentication information obtained from the third encryption authentication data, encrypted data stored on the SSD and fourth encryption authentication data are acquired; based on the decryption key corresponding to the fourth encryption authentication data, the encrypted data stored on the SSD is decrypted to obtain the data information of the SSD and the working status information of the encryption authentication module detected at a set time frequency. This application can achieve encryption authentication of solid-state drives. Attached Figure Description
[0069] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0070] Figure 1 This is a schematic diagram of an application scenario according to an embodiment of the present invention; and
[0071] Figure 2 This is a structural block diagram of a solid-state drive according to an embodiment of the present invention; and
[0072] Figure 3 A flowchart of a solid-state drive encryption authentication method 300 according to an embodiment of the present invention; and
[0073] Figure 4 This application illustrates a schematic diagram of authenticating encrypted authentication data KEYA according to an embodiment of the present application; and
[0074] Figure 5 This application provides a schematic diagram illustrating ZoneKey authentication of encrypted authentication data; and
[0075] Figure 6 This application illustrates a process for generating encrypted authentication data C_Primary_Key according to an embodiment of the present application; and
[0076] Figure 7 This application illustrates a schematic diagram of an authentication process for encrypted authentication data C_Primary_Key provided by an embodiment of this application; and
[0077] Figure 8 This illustration shows a process for generating encrypted authentication data Media_Key according to an embodiment of this application. Detailed Implementation
[0078] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0079] Figure 1 This is a schematic diagram illustrating an application scenario of an embodiment of the present invention. The solid-state drive encryption and authentication method provided by the present invention can be applied to, for example... Figure 1The application environment shown illustrates this solid-state drive (SSD) encryption authentication method applied to the SSD. The application scenario includes a host 110 and an SSD 120. Users store data in the SSD 120 or retrieve data from the SSD 120 via the host 110. The host 110 is an information processing device, such as a personal computer, tablet, server, laptop, network switch, router, cellular phone, personal digital assistant, etc. The SSD 120 provides storage capacity for the host 110. The host 110 and the SSD 120 are interconnected, and the connection methods include, but are not limited to, SATA (Serial Advanced Technology Attachment), SCSI (Small Computer System Interface), SAS (Serial Attached SCSI), IDE (Integrated Drive Electronics), USB (Universal Serial Bus), PCIe (Peripheral Component Interconnect Express), Ethernet, Fibre Channel, and wireless communication networks. Therefore, host 110 and solid-state drive 120 may be the same physical device connected by a wire, or solid-state drive 120 may be a remote device on the same local area network (LAN) or wide area network (WAN) as host 110.
[0080] Figure 2 A structural block diagram of a solid-state drive (SSD) provided in an embodiment of the present invention is shown. The SSD 202 includes an interface 203, a control unit 204, one or more NVM chips 205, and DRAM (Dynamic Random Access Memory) 210.
[0081] Interface 203 can be adapted to exchange data with the host via methods such as SATA, IDE, USB, PCIe, NVMe, SAS, Ethernet, and Fibre Channel.
[0082] The control unit 204 is used to control data transmission between the interface 203, the NVM chip 205, and the DRAM 210. The control unit 204 can be implemented in various ways, such as software, hardware, firmware, or a combination thereof. For example, the control unit 204 can be in the form of an FPGA (Field-programmable gate array), an ASIC (Application Specific Integrated Circuit), or a combination thereof.
[0083] The control unit 204 is coupled to the interface 203 to receive host commands (such as read / write commands) through the interface 203, process the received host commands, cache the data indicated by the host commands in the DRAM 210, and write the data indicated by the host commands to the NVM chip 205 or read the data indicated by the host commands from the NVM chip 205 through coupling with the NVM chip 205.
[0084] In order to perform security certification, Figure 2 The solid-state drive (SSD) shown also includes an encryption authentication module 211. This encryption authentication module 211 is coupled to the control unit 204, such as via an I2C bus. The encryption authentication module 211 stores encryption authentication data. During the encryption authentication process, the control unit 204 performs security authentication based on the encryption authentication data stored in the encryption authentication module 211, and sets the SSD to an accessible state after successful authentication, allowing the user to access the SSD. In practical applications, the encryption authentication data stored in the encryption authentication module is pre-programmed. The control unit 204 sets the SSD's state by verifying multiple encryption authentication data sets in the encryption authentication module. However, pre-programming the encryption authentication data does not mean it can be done at any time. For example, encryption authentication data can be programmed into the encryption authentication module during the SSD manufacturing stage (i.e., before leaving the factory) or during the repair stage.
[0085] As an example, the encryption authentication module 211 is an EEPROM chip, and its configuration space is shown in Table 1. The EEPROM chip includes 8 storage spaces, each containing 8 storage areas. Storage space address 00 stores the software batch number of the EEPROM chip, storage space address 08 stores the user-mode file system FUSE and user serial number, storage space address 10 stores the product code and product key list, and storage space address 18 stores the zone interface mode. Storage space addresses 20 and 28 store encryption authentication data KEYA. KEYA is used to verify whether the encryption authentication module can be accessed. For example, KEYA includes the software batch number of the encryption authentication module, which is used to generate a digest value of the encrypted data using an encryption algorithm. In addition, the encryption authentication module 211 also stores encryption authentication data ZoneKey (not shown in 1) and encryption authentication data C_Primary_Key. The encryption authentication data ZoneKey is the digest value of the encrypted data generated by the encryption algorithm from the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module, which is used to verify whether the encryption authentication module has been replaced. The encryption authentication data C_Primary_Key is the digest value of the encrypted data generated by the encryption algorithm from the random number RandomC.
[0086] Table 1
[0087]
[0088]
[0089] Furthermore, in order to conduct security certification, Figure 2 The solid-state drive shown also includes a NOR flash memory chip 212. This NOR flash memory chip 212 is coupled to the control unit 204 and is used to store data that is compared with the encrypted authentication data, in order to assist in verifying the encrypted data of the encryption authentication module.
[0090] As can be seen from the above, the encryption authentication of solid-state storage devices involves at least the following stages: The first stage is to burn encryption authentication data into the encryption authentication module before accessing the solid-state storage device, either before it leaves the factory or during maintenance; the second stage is that after the encryption authentication data is burned, the user needs to power on the solid-state drive for encryption authentication; the third stage is that after the solid-state drive completes authentication, the data in the solid-state drive is encrypted / decrypted. The following describes... Figure 3 This document provides a brief overview of the process by which users perform encrypted authentication on a solid-state drive (SSD) after the encrypted authentication data has been burned into the drive.
[0091] Figure 3A flowchart of a solid-state drive encryption authentication method 300 according to an embodiment of the present invention is shown, which is applied to... Figure 2 The control unit 204 is shown. Method 300 begins at step S310, in response to the power-on of the solid-state drive, by acquiring encrypted authentication data KEYA (as shown in Table 1).
[0092] For example, after a solid-state drive (SSD) is powered on, its various modules begin to operate, such as the control unit, EEPROM chip, NVM chip, NORFLASH chip, and encryption / authentication module. At this time, Figure 2 The control unit shown detects the presence of an encryption authentication module in the solid-state drive (SSD). For example, if an encryption authentication module exists, it generates startup information upon boot and sends it to the control unit. The control unit detects the presence of the encryption authentication module based on whether it receives this startup information. If the encryption authentication module is present, the control unit accesses the various encryption authentication data stored within it and performs step-by-step authentication according to a pre-defined authentication process. Since the encryption authentication data KEYA is used to verify accessibility of the encryption authentication module, the control unit first verifies KEYA. If KEYA fails verification, the encryption verification fails, and the control unit cannot access other encryption authentication data stored in the encryption authentication module. Furthermore, in response to KEYA's failure to authenticate, the control unit sets the NVM chip to an inaccessible state. In this state, the host cannot access the SSD; for example, the host cannot read or write data to the SSD's NVM chip.
[0093] It should be noted that the encryption authentication data KEYA is burned into the encryption authentication module before the solid-state drive (SSD) leaves the factory. For ease of understanding, the following is a brief description of the process of burning the encryption authentication data KEYA into the encryption authentication module before accessing the SSD, before the SSD leaves the factory, or during maintenance.
[0094] As an example, before a solid-state storage device leaves the factory or during repair, the software batch number of the encryption authentication module is obtained. For instance, the solid-state drive stores the software batch number EEPROM_SN and the encryption public key used for the encryption authentication data KEYA on external storage. The control unit retrieves this information from the external storage, which refers to the storage located outside the control unit within the solid-state drive. Then, based on the software batch number and encryption algorithm (such as SM3), the encryption algorithm operation value of the software batch number is obtained. Next, the encryption algorithm operation value of the software batch number is calculated to obtain a digest value. Then, based on the digest value of the encryption algorithm operation value of the software batch number, the encryption authentication data KEYA is obtained, for example, this digest value is used as the encryption authentication data KEYA. Furthermore, after obtaining the encryption authentication data KEYA, the manufacturer or repair personnel use a preset programming tool to program the encryption authentication data KEYA into the encryption authentication module.
[0095] Furthermore, after the solid-state drive (SSD) leaves the factory and is powered on, the control unit responds by receiving the startup information of the encryption authentication module, confirming the presence of the encryption authentication module on the SSD, and receiving information indicating that the encryption authentication module has been successfully detected. After successful detection, the control unit can read the encryption authentication data KEYA stored internally within the encryption authentication module and authenticate the KEYA data. For other encryption authentication data stored internally within the encryption authentication module, the control unit can authenticate the stored encryption authentication data according to a pre-defined authentication process to enable host access to the SSD. Additionally, since the encryption authentication module is a component within the SSD, it can be considered replaceable or removed after the SSD leaves the factory; therefore, verifying the existence of the encryption authentication module is necessary along with verifying its legitimacy. Since the encrypted authentication data KEYA is a digest value of encrypted data generated by the encryption algorithm from the software batch number of the encryption authentication module, and the software batch number of the encryption authentication module on each solid-state drive is unique, each encrypted authentication data KEYA is also unique for the encryption authentication module of that solid-state drive. Therefore, the legitimacy of the encryption authentication module can be verified by using this unique encrypted authentication data KEYA and the software batch number of the encryption authentication module corresponding to the encrypted authentication data KEYA.
[0096] Figure 4 This illustration shows a schematic diagram of authenticating encrypted authentication data KEYA according to an embodiment of this application.
[0097] For example, such as Figure 4As shown, to authenticate the encrypted authentication data KEYA, the control unit needs to generate comparison data KEYB based on the data used to generate KEYA (such as the software batch number of the encryption authentication module and the public key used), the process, and the encryption algorithm. The generated comparison data KEYB is then compared with the encrypted authentication data KEYA to authenticate it. Since the same encryption algorithm and the same public key are used, if the software batch number EEPROM_SN used to generate KEYA and KEYB is the same, then KEYB will definitely be the same as KEYA, and authentication will pass, continuing the subsequent process. If they are different, it means that the software batch number EEPROM_SN of the current encryption authentication module is inconsistent with the software batch number EEPROM_SN of the encryption authentication module corresponding to the encrypted authentication data, authentication fails, and subsequent operations are prohibited.
[0098] The control unit obtains the software batch number EEPROM_SN of the encryption authentication module and the encryption public key used by the encryption authentication data KEYA, such as the SM3 public key. Based on the software batch number EEPROM_SN of the encryption authentication module and the encryption public key used by the encryption authentication data KEYA, it uses an encryption algorithm to generate comparison data KEYB using the software batch number EEPROM_SN of the encryption authentication module. Then, it calls the Lib_HostAuth program and calculates the response value Response_1 of the comparison data KEYB based on the comparison data KEYB and the random number Random A. Here, the random number Random A is random data generated by the TRNG module, a true random number generator inside the solid-state drive. Furthermore, the calculation of the response value for the encrypted authentication data KEYA is similar to the calculation of the response value for the comparison data KEYB. The control unit calls the DX8_HostAuth program to send the random number Random A to the EEPROM chip of the encryption authentication module. It then calls the lib_hostauth program to calculate the response value Response_2 of the encrypted authentication data KEYA using Random A and the encrypted authentication data KEYA. The response value Response_1 of the comparison data KEYB is then compared with the response value Response_2 of the encrypted authentication data KEYA. If Response_1 and Response_2 match, then the encrypted authentication data KEYA is authenticated. In response to the successful authentication, the control unit sets the solid-state drive to an accessible state based on the authentication information of the encrypted authentication data KEYA.
[0099] In response to the successful authentication of the encryption authentication data KEYA, the control unit executes step S320, which obtains the accessibility status information of the solid-state drive and the encryption authentication data ZoneKey based on the successful authentication information of the encryption authentication data KEYA. The encryption authentication data ZoneKey includes the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module, which are used to generate a digest value of the encrypted data through an encryption algorithm.
[0100] Once the encryption authentication data KEYA stored in the encryption authentication module is verified, the encryption authentication module is considered legitimate, or its software serial number is valid. This means the host is allowed to access the SSD. It's important to note that this permission does not mean the host is allowed to read or write data on the SSD; it simply confirms the SSD's legitimacy and allows the host to connect. Whether the host is allowed to read or write data on the SSD still requires further verification. For example, after the SSD leaves the factory, a user might replace the legitimate encryption authentication module with an illegitimate one. If the SSD's legitimacy is determined solely by verifying the encryption authentication module's software serial number, an illegitimate SSD could be mistakenly recognized as legitimate in such a replacement scenario, which is clearly unreasonable. To prevent the encryption authentication module from being replaced, further verification is necessary. For instance, after the encryption authentication data KEYA is verified, the control unit further verifies the encryption authentication data ZoneKey stored in the encryption authentication module to confirm whether the encryption authentication module has been replaced. Additionally, it should be noted that the encryption authentication data ZoneKey is burned into the encryption authentication module before the solid-state drive (SSD) leaves the factory. For ease of understanding, the process of burning the encryption authentication data ZoneKey into the encryption authentication module before accessing the SSD, before the SSD leaves the factory, or during maintenance is briefly described below.
[0101] For example, before a solid-state storage device leaves the factory or during maintenance, the software batch number and data storage area number of the encryption authentication module are obtained. Then, based on the software batch number, data storage area number, and encryption algorithm, the encryption algorithm operation value of the software batch number and the data storage area number of the encryption authentication module is calculated. Specifically, the software batch number and the storage area number of the encryption authentication data ZoneKey are encrypted using an encryption algorithm to obtain this operation value; for example, the encryption algorithm is the SM3 encryption algorithm. Next, based on the encryption algorithm operation value of the software batch number and data storage area number of the encryption authentication module, a digest value of the encryption algorithm operation value of the software batch number and data storage area number of the encryption authentication module is obtained. And based on the digest value of the encryption algorithm operation value of the software batch number and data storage area number of the encryption authentication module, the encryption authentication data ZoneKey is obtained; for example, the digest value of the encryption algorithm operation value of the software batch number and data storage area number of the encryption authentication module is used as the encryption authentication data ZoneKey. Before a solid-state drive leaves the factory or during the repair process, the manufacturer or repair personnel use specific tools to burn the encryption authentication data ZoneKey into the encryption authentication module in one go.
[0102] In addition, as mentioned above, after the solid-state drive leaves the factory, users need to perform encryption authentication on the solid-state drive when it is powered on. This authentication includes not only the encryption authentication data KEYA stored in the encryption authentication module, but also the encryption authentication data ZoneKey.
[0103] Figure 5 This illustration shows a schematic diagram of ZoneKey authentication for encrypted authentication data provided by this application.
[0104] As an example, in Figure 5 In the process of authenticating encrypted authentication data using ZoneKey, the authentication process is similar to... Figure 4The authentication principle for the encrypted authentication data KEYA is similar. The control unit needs to generate a comparison data ZoneKey_1 based on the data used to generate the encrypted authentication data ZoneKey (such as the software batch number, storage area number, and public key used in the encrypted authentication module), the process, and the encryption algorithm. The generated comparison data ZoneKey_1 is then compared with the encrypted authentication data ZoneKey to authenticate the encrypted data ZoneKey. Since the encrypted authentication data ZoneKey is related to the data storage area number of the encrypted authentication module, as shown in Table 1, and because the encrypted authentication module includes multiple storage spaces, each storage space consisting of multiple storage areas, and the encrypted authentication data ZoneKey is stored in a designated storage area, and each solid-state drive stores the encrypted authentication module in a different data storage area number, when the encrypted authentication module is replaced, the control unit can verify whether the encrypted authentication module has been replaced using the storage area number and software batch number of the encrypted authentication data ZoneKey.
[0105] Specifically, the control unit obtains the software batch number EEPROM_SN of the encryption authentication module, the data storage area number Zone of the encryption authentication module, and the encryption public key used by the encryption authentication data ZoneKey. For example, the solid-state drive also stores the software batch number EEPROM_SN of the encryption authentication module, the data storage area number Zone of the encryption authentication module, and the encryption public key used by the encryption authentication data ZoneKey through external storage. The control unit obtains this information by accessing the external storage. Next, based on the software batch number EEPROM_SN of the encryption authentication module, the data storage area number Zone of the encryption authentication module, and the encryption public key used by the encryption authentication data ZoneKey, comparison data ZoneKey_1 is generated by using an encryption algorithm (such as SM3) to obtain the software batch number EEPROM_SN of the encryption authentication module and the data storage area number Zone of the encryption authentication module. Then, the DX8_VERIFYZON NE program is called to calculate the response value Response_3 of the comparison data ZoneKey_1 based on the comparison data ZoneKey_1 and the random number RandomB. Here, the random number RandomB is random data generated by the true random number generator inside the solid-state drive. The true random number generator is a random number generation module on the control unit of the solid-state drive. Next, the control unit calls a designated program to calculate the corresponding response value Response_4 based on the random number RandomB and the encrypted authentication data ZoneKey stored in the encryption authentication module. It then compares Response_3 with Response_4 and obtains the authentication information (pass or fail) of the encrypted authentication data ZoneKey based on the comparison result. Next, based on the successful authentication of the encrypted authentication data ZoneKey, it obtains the compatibility information between the solid-state drive (SSD) and the encryption authentication module. Specifically, if the encrypted authentication data ZoneKey passes authentication, it indicates that the SSD and the encryption authentication module are compatible, meaning that the encryption authentication module of the current SSD has not been replaced after setup, and the compatibility relationship between the two remains unchanged, allowing subsequent operations to continue. If authentication fails, it indicates that the encryption authentication module of the current SSD has been replaced, the SSD and the encryption authentication module are incompatible, the SSD is invalid, the host cannot perform read / write operations on the SSD, and subsequent operations are prohibited.
[0106] After the control unit responds to the successful authentication of the encrypted authentication data ZoneKey, it further executes step S330, which, based on the accessibility status information of the solid-state drive and the authentication information of the encrypted data ZoneKey, obtains the compatibility information between the solid-state drive and the encrypted authentication module, as well as the encrypted authentication data C_Primary_Key. The encrypted authentication data C_Primary_Key is a digest value of the encrypted data generated by an encryption algorithm from the random number RandomC.
[0107] Specifically, once the ZoneKey encryption authentication data is successfully authenticated, it confirms that the SSD and encryption authentication module are compatible. This prepares the computer for further access to the data in the SSD's NVM chip. The C_Primary_Key encryption authentication data is the key used to encrypt and decrypt the data stored in the NVM chip. Therefore, the host can only read and write data stored in the SSD's NVM chip after the C_Primary_Key encryption authentication data has been verified. It's also worth noting that the C_Primary_Key encryption authentication data is burned into the encryption authentication module before the SSD leaves the factory. For clarity, the process of burning the C_Primary_Key encryption authentication data into the encryption authentication module before accessing the SSD, before the SSD leaves the factory, or during repair is briefly described below.
[0108] Figure 6 This illustration shows a process for generating encrypted authentication data C_Primary_Key according to an embodiment of this application.
[0109] For example, before a solid-state storage device leaves the factory or during repair, a random number, RandomC, is obtained. The control unit generates RandomC by calling its internal true random number generator, TRNG. Then, the digest value of RandomC is obtained by processing it with an encryption algorithm (such as SM3), and a keyword is extracted from this digest value. For example, the keyword might be primary_key[127:0], where primary_key[127:0] is a 128-bit string. Additionally, the solid-state drive's serial number, SSD_ID, and the encryption authentication module's software batch number, EEPROM_SN, also need to be obtained. These two serial numbers are unique, allowing for unique binding between the solid-state drive and the encryption authentication module, thus enabling the retrieval of data stored on the solid-state drive provided the solid-state drive and encryption authentication module are compatible. Then, based on the SSD serial number SSD_ID and the encryption authentication module software batch number EEPROM_SN, the hash value Mid_Hash[127:0] is calculated. Mid_Hash[127:0] is the digest value obtained by performing logical operations (such as logical addition) and encryption algorithms on the SSD serial number SSD_ID and the encryption authentication module software batch number EEPROM_SN. Mid_Hash[127:0] is a 128-bit string. Next, encryption operations (such as SM4 operations) are performed on the keyword primary_key[127:0] and the hash value Mid_Hash[127:0] to obtain the encryption authentication data C_Primary_Key. The manufacturer or repair personnel then use specific tools to burn the encryption authentication data C_Primary_Key into the encryption authentication module in one go.
[0110] As another example, before a solid-state storage device leaves the factory or during maintenance, comparison data Compare_Data_1 related to the encryption authentication data C_Primary_Key is also generated. During the process of generating the encryption authentication data C_Primary_Key, the control unit also obtains a random number LOC_TRNG_2, and performs a calculation on the software batch number EEPROM_SN of the encryption authentication module and the random number LOC_TRNG_2 to obtain a hash value LTRNG_Hash_2[127:0]. The hash value LTRNG_Hash_2[127:0] is the digest value obtained by performing logical operations (such as logical addition) and encryption algorithms (such as SM3) on the random number LOC_TRNG_2 and the software batch number EEPROM_SN of the encryption authentication module. The random number LOC_TRNG_2 is stored in the off-chip memory of the solid-state drive, such as the NORFLASH chip of the solid-state drive. It is not random data generated by a true random number generator, but is pre-programmed and stored in the NORFLASH chip. The hash value LTRNG_Hash_2[127:0] is a 128-bit string. Next, the control unit performs encryption operations (such as SM4) on the hash value and the encrypted authentication data C_Primary_Key to obtain the comparison data Compare_Data, and stores the comparison data Compare_Data_1 in the off-chip memory. The comparison data Compare_Data_1 is the data related to the authentication of the encrypted authentication data C_Primary_Key.
[0111] Figure 7 This illustration shows a schematic diagram of the authentication process for encrypted authentication data C_Primary_Key provided by an embodiment of this application.
[0112] As an example, in Figure 7In this process, the control unit obtains the random number LOC_TRNG_2 and the software batch number EEPROM_SN of the encryption authentication module. Then, it performs a logical AND operation and an encryption operation (such as SM3) on the random number LOC_TRNG_2 and the software batch number EEPROM_SN of the encryption authentication module to obtain the hash value LTRNG_Hash_2
[1270] . The hash value LTRNG_Hash_2
[1270] is a 128-bit string. Then, it obtains the encryption authentication data C_Primary_Key from the encryption authentication module and performs an encryption operation (such as SM4) on the hash value LTRNG_Hash_2
[1270] and the encryption authentication data C_Primary_Key to obtain the comparison data. Next, the pre-programmed comparison data Compare_Data_1 is retrieved from the external storage of the solid-state drive. Compare Compare_Data_1 is compared with Compare Data. When Compare Compare_Data_1 and Compare Data are consistent, the data comparison is considered to be successful, and the compatibility information between the solid-state drive and the encryption authentication module is obtained.
[0113] At this point, the encryption authentication process for the user's solid-state drive (SSD) upon power-on is complete. The next stage, after SSD authentication, involves encrypting / decrypting the data on the SSD. The control unit will execute steps S340 and S350. In step S340, based on the compatibility information between the SSD and the encryption authentication module, and the encryption authentication data C_Primary_Key, the encrypted data stored on the SSD and the encryption authentication data Media_Key are obtained through the authentication information. The encryption authentication data Media_Key includes the decryption key for the encrypted data stored on the SSD.
[0114] Specifically, once the ZoneKey encryption authentication data is successfully authenticated, the compatibility verification between the SSD and the encryption authentication module is also completed. At this point, the C_Primary_Key encryption authentication data is verified. The C_Primary_Key verifies whether the computer allows access to the data stored on the NVM chip via the corresponding control unit of the SSD. If the C_Primary_Key verification is successful, access to the data on the NVM chip is permitted; otherwise, access is prohibited, and subsequent operations are disabled. After the C_Primary_Key verification is successful, subsequent operations continue, and the host can access the data on the SSD's NVM chip. Since the data stored on the NVM chip is encrypted, the Media_Key encryption authentication data (decryption key) is obtained to convert the encrypted data into its original plaintext content.
[0115] It's important to note that the encryption authentication data Media_Key is not burned into the encryption authentication module by the manufacturer before the SSD leaves the factory or during repair. Instead, it is generated based on the successfully authenticated encryption authentication data C_Primary_Key after successful authentication.
[0116] Figure 8 This illustration shows a process for generating encrypted authentication data Media_Key according to an embodiment of this application.
[0117] For example, such as Figure 8 As shown, after the control unit successfully authenticates the encrypted authentication data C_Primary_Key, it obtains the serial number SSD_ID of the solid-state drive and the software batch number EEPROM_SN of the encryption authentication module, for example, by obtaining SSD_ID and EEPROM_SN from external memory; then it performs a logical AND operation and an encryption operation (such as SM3 operation) on the serial number SSD_ID of the solid-state drive and the software batch number EEPROM_SN of the encryption authentication module to obtain the hash value MID_Hash[127:0]; then it performs an encryption operation (such as SM4 operation) on the authenticated encrypted authentication data C_Primary_Key and the hash value MID_Hash[127:0] to obtain the keyword Primary_Key; in addition, the control unit also obtains the random number LOC_TRNG_3; where the random number LOC_TRNG_3 is a random number stored in the NORFLASH chip of the solid-state drive, and the random number LOC_TRNG_3 is pre-programmed into the NORFLASH chip. The random number LOC_TRNG_3 is encrypted (e.g., SM3 operation) to obtain the hash value Loc_THash_3[255:0]. The keyword Primary_Key and the hash value Loc_THash_3[255:0] are encrypted (e.g., SM4 operation) to obtain the encrypted authentication data Media_Key. The encrypted authentication data Media_Key is the decryption key. The control unit can use the encrypted authentication data Media_Key to decrypt the ciphertext data in the NVM chip to obtain the plaintext data.
[0118] Step S350: Obtain the decryption key based on the encrypted authentication data Media_Key, decrypt the encrypted data stored on the solid-state drive, obtain the data information of the solid-state drive, and the working status information of the encryption authentication module detected according to the set time frequency.
[0119] Specifically, the encryption authentication data Media_Key is the encryption key used to encrypt the data stored in the NVM chip of the solid-state drive. Therefore, when the encryption authentication data Media_Key is authenticated, it is the process of decrypting the encrypted data stored in the NVM chip. After the encrypted data is decrypted, the original data information stored in the solid-state drive can be obtained.
[0120] As another example, to ensure the encryption authentication module functions correctly throughout the entire operation of the SSD, its operating status needs to be checked at a set frequency, such as every three seconds. This ensures the module is working properly. From the authentication process of the four encryption authentication data, we can see that for an SSD connected to a computer, once the encryption authentication data KEYA is verified, the encryption authentication module is considered legitimate; once the encryption authentication data ZoneKey is verified, the encryption authentication module is considered unaltered, meaning it is compatible with the SSD; once the encryption authentication data C_Primary_Key is verified, the computer is allowed to access data from the SSD's NVM chip; and once the encryption authentication data Media_Key is verified, the host can decrypt the ciphertext data stored in the NVM chip into plaintext data. These four verification steps are merely identity verification and do not involve data processing. In principle, although the fourth encryption authentication data involves data decryption, once the decryption key of the ciphertext data is obtained, the ciphertext data can be decrypted. Therefore, after the verification of the encryption authentication data is completed, the data exchange between the host and the NVM chip of the solid-state drive no longer depends on the operation of the encryption authentication module. In other words, once the four encryption authentication data are authenticated, even if the encryption authentication module is damaged, malfunctions, removed, or replaced, it will not affect the computer's reading and writing of data to the NVM chip. It will only affect the next authentication process of the solid-state drive. If the host continues to work with the solid-state drive, there will be certain security risks. Therefore, it is necessary to continuously monitor the working status of the encryption authentication module to ensure that the encryption authentication module is not illegally replaced or removed.
[0121] According to the solid-state drive encryption authentication method of the present invention, during the user's use of the solid-state drive, the actions of disassembling, replacing, cracking, tampering with or copying the encryption authentication module are verified by the encryption authentication data KEYA, the encryption authentication data ZoneKey and the encryption authentication data C_Primary_Key, respectively, thereby improving the security of the solid-state drive and protecting the rights and interests of the producer.
[0122] It should be understood that although the steps in the flowcharts in the accompanying drawings are shown sequentially as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order in which these steps are performed, and they can be performed in other orders. Furthermore, Figure 4 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.
[0123] It should be understood that, in order to streamline the disclosure of this invention and aid in understanding one or more of the various inventive aspects, features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof in the above description of exemplary embodiments of the invention. However, this method of disclosure should not be construed as reflecting an intention that the claimed invention requires more features than expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of the invention.
[0124] Those skilled in the art will understand that modules, units, or components of the devices disclosed in the examples herein can be arranged in the devices described in this embodiment, or alternatively, can be located in one or more devices different from the devices in this example. The modules in the foregoing examples can be combined into a single module or, in addition, can be divided into multiple sub-modules.
[0125] Those skilled in the art will understand that modules in the device of the embodiments can be adaptively changed and placed in one or more devices different from that embodiment. Modules, units, or components in the embodiments can be combined into a single module, unit, or component, and further, they can be divided into multiple sub-modules, sub-units, or sub-components. Except where at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or units of any method or device so disclosed. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.
[0126] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application. Clearly, those skilled in the art can make various alterations and variations to this application without departing from its spirit and scope. Thus, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A solid-state drive (SSD) encryption authentication method, wherein the SSD is equipped with an encryption authentication module, and the encryption authentication module stores encryption authentication data, characterized in that, The method includes: In response to the power-on of the solid-state drive, first encrypted authentication data is acquired, the first encrypted authentication data including the software batch number of the encryption authentication module and the digest value of the encrypted data generated by the encryption algorithm; Based on the first encrypted authentication data, the accessibility status information of the solid-state drive and the second encrypted authentication data are obtained through the authentication information. The second encrypted authentication data includes the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module, and the digest value of the encrypted data is generated by the encryption algorithm. Based on the accessibility status information of the solid-state drive and the second encryption authentication data, the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data are obtained. The third encryption authentication data includes the digest value of the encrypted data generated by the encryption algorithm from the first internal random number of the solid-state drive. Based on the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data through the authentication information, the encrypted data stored on the solid-state drive and the fourth encryption authentication data are obtained. The fourth encryption authentication data includes the decryption key of the encrypted data stored on the solid-state drive. Based on the decryption key corresponding to the fourth encryption authentication data, the encrypted data stored in the solid-state drive is decrypted to obtain the data information of the solid-state drive and the working status information of the encryption authentication module detected at a set time frequency.
2. The solid-state drive encryption authentication method according to claim 1, characterized in that, In response to the power-on of the solid-state drive, the first encrypted authentication data is obtained, including: In response to the power-on of the solid-state drive, the startup information of the encryption authentication module is obtained; Based on the startup information of the encryption authentication module, obtain the successful detection information of the encryption authentication module; Based on the successful detection information of the encryption authentication module, the data information stored in the encryption authentication module is obtained; Based on the data information stored in the encryption authentication module, the first encryption authentication data is obtained.
3. The solid-state drive encryption authentication method according to claim 1, characterized in that, The step of obtaining the accessibility status information of the solid-state drive and the second encrypted authentication data based on the first encrypted authentication data and the authentication information includes: Obtain the software batch number of the encryption authentication module and the encryption public key used by the first encryption authentication data; Based on the software batch number of the encryption authentication module and the encryption public key used in the first encryption authentication data, the first comparison data generated using the software batch number of the encryption authentication module is obtained through the first encryption algorithm; Based on the first comparison data and the second internal random number of the solid-state drive, obtain the response value of the first comparison data; Based on the second internal random number of the solid-state drive, obtain the response value of the first encrypted authentication data; Based on the response value of the first comparison data and the response value of the first encrypted authentication data, obtain the authentication information of the first encrypted authentication data; Based on the first encrypted authentication data and the authentication information, the accessibility status information of the solid-state drive is obtained; Based on the fact that the solid-state drive is in an accessible state, the second encrypted authentication data is obtained.
4. The solid-state drive encryption authentication method according to any one of claims 1-3, characterized in that, The step of obtaining the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data, based on the accessibility status information of the solid-state drive and the second encryption authentication data, includes: Obtain the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the encryption public key used by the second encryption authentication data; Based on the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the encryption public key used in the second encryption authentication data, the second comparison data is generated by obtaining the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module through the first encryption algorithm. Based on the second comparison data and the third internal random number of the solid-state drive, obtain the response value of the second comparison data; Based on the response value of the second comparison data and the second encrypted authentication data, obtain the authentication information of the second encrypted authentication data; Based on the second encrypted authentication data and the authentication information, the compatibility information between the solid-state drive and the encrypted authentication module is obtained; The third encryption authentication data is obtained based on the compatibility information between the solid-state drive and the encryption authentication module.
5. The solid-state drive encryption authentication method according to any one of claims 1-3, characterized in that, The step of obtaining the encrypted data stored on the solid-state drive and the fourth encrypted authentication data based on the compatibility information between the solid-state drive and the encryption authentication module, and the third encryption authentication data through authentication information, includes: Obtain the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module; Based on the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module, the first hash value is obtained through the first encryption algorithm; Based on the first hash value and the third encrypted authentication data, the third comparison data is obtained through the second encryption algorithm; Obtain the fourth comparison data stored in the solid-state drive, and obtain the third encryption authentication data authentication information based on the comparison result between the third comparison data and the fourth comparison data; Based on the third encryption authentication data, the encrypted data stored in the solid-state drive and the fourth encryption authentication data are obtained through the authentication information.
6. The solid-state drive encryption authentication method according to any one of claims 1-3, characterized in that, The steps for generating the first encrypted authentication data include: Obtain the software batch number of the encryption authentication module; Based on the software batch number of the encryption authentication module and the first encryption algorithm, obtain the first encryption algorithm operation value of the software batch number; Based on the first encryption algorithm operation value of the software batch number, obtain the digest value of the first encryption algorithm operation value of the software batch number; The first encrypted authentication data is obtained based on the digest value of the first encryption algorithm operation value of the software batch number.
7. The solid-state drive encryption authentication method according to any one of claims 1-3, characterized in that, The steps for generating the second encrypted authentication data include: Obtain the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module; Based on the software batch number of the encryption authentication module, the data storage area number of the encryption authentication module, and the first encryption algorithm, obtain the first encryption algorithm operation value of the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module. Based on the software batch number of the encryption authentication module and the first encryption algorithm operation value of the data storage area number of the encryption authentication module, a digest value of the software batch number of the encryption authentication module and the first encryption algorithm operation value of the data storage area number of the encryption authentication module is obtained. The second encryption authentication data is obtained based on the digest value of the first encryption algorithm operation value of the software batch number of the encryption authentication module and the data storage area number of the encryption authentication module.
8. The solid-state drive encryption authentication method according to claim 5, characterized in that, The steps for generating the third encrypted authentication data include: Obtain the first internal random number generated by the true random number generator of the solid-state drive; Based on the first internal random number generated by the true random number generator of the solid-state drive, a first keyword is obtained, wherein the first keyword is the digest value of the first internal random number after being processed by the first encryption algorithm; Obtain the serial number of the solid-state drive and the software batch number of the encryption authentication module; Based on the serial number of the solid-state drive and the software batch number of the encryption authentication module, a second hash value is obtained. The second hash value is the digest value of the serial number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm. The third encrypted authentication data is obtained based on the first keyword and the second hash value. The third encrypted authentication data is obtained by performing a second encryption algorithm operation on the first keyword using the second hash value. Obtain the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module, and obtain the first hash value. The first hash value is the digest value of the fourth internal random number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm. Based on the first hash value and the third encrypted authentication data, the fourth comparison data is obtained and stored in the solid-state drive. The fourth comparison data is obtained by processing the first hash value and the third encrypted authentication data using a second encryption algorithm.
9. The solid-state drive encryption authentication method according to any one of claims 1-3, characterized in that, The steps for generating the fourth encrypted authentication data include: Obtain the serial number of the solid-state drive and the software batch number of the encryption authentication module; Based on the serial number of the solid-state drive and the software batch number of the encryption authentication module, a second hash value is obtained. The second hash value is the digest value of the serial number of the solid-state drive and the software batch number of the encryption authentication module after being processed by the first encryption algorithm. Based on the second hash value and the third encrypted authentication data, a first keyword is obtained, which is obtained by decrypting the second hash value and the third encrypted authentication data using a second encryption algorithm. Obtain the fifth internal random number of the solid-state drive; Based on the fifth internal random number of the solid-state drive, a third hash value is obtained, wherein the third hash value is the digest value of the fifth internal random number after being processed by the first encryption algorithm; The fourth encrypted authentication data is obtained based on the first keyword and the third hash value. The fourth encrypted authentication data is obtained by encrypting the first keyword with the third hash value using the second encryption algorithm.
10. A solid-state drive (SSD), wherein the SSD is provided with an encryption authentication module, the encryption authentication module storing encryption authentication data, characterized in that, The solid-state drive includes one or more processors and memory, wherein the memory is used to store one or more programs; When the processor executes the one or more programs, the processor performs the method as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Solid state disk as well as method and device for secure access control thereof
CN102163267A
Real-time dynamic authentication method for multi-user secure storage
CN112084472A