Grub-based disk data protection method, device, equipment and medium
By introducing a custom GRUB program into the SSD, setting offline and online states, and generating authentication private keys using key feature data, the problem of low SSD data security is solved, achieving the effect of preventing data leakage even on untrusted computers.
Patent Information
- Application Number
- CN202311609535.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2043-11-27
AI Technical Summary
SSDs have lower data security and pose a risk of data leakage if someone moves an SSD to another SSD.
By introducing a custom GRUB program into the SSD, setting both offline and online states, and generating an authentication private key using key feature data, the user's data storage area is unlocked only after successful authentication by switching to the online state.
Even if the SSD is installed on an untrusted computer, it can still prevent data access and improve data security.
Smart Images

Figure CN117592135B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of solid-state drive data protection, and in particular to a GRUB-based disk data protection method, apparatus, device, and medium. Background Technology
[0002] Data security is receiving increasing attention, making secure data storage devices increasingly important. Currently, regarding SSD (Solid State Drive) data security, there is a risk of unauthorized transfer of SSDs; taking an SSD is tantamount to taking all the information, making SSD data security relatively low. Summary of the Invention
[0003] To address the aforementioned technical problems, embodiments of this application provide a GRUB-based disk data protection method, apparatus, device, and computer-readable storage medium.
[0004] In a first aspect, embodiments of this application provide a disk data protection method based on GRUB, the method comprising:
[0005] The disk is set to a first state and a second state, and the disk includes a customized GRUB program;
[0006] When the disk is booted, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible.
[0007] The customized GRUB program verifies the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state, and the user data storage area of the disk is unlocked. If the identity authentication private key fails to authenticate, the disk remains in the first state.
[0008] In one embodiment, the customized GRUB program reads the key feature data, generates a second authentication private key, and stores the second authentication private key in a hidden storage area of the disk.
[0009] In one embodiment, the customized GRUB program verifies the first authentication private key, including:
[0010] The customized GRUB program verifies the first authentication private key and the second authentication private key. If the first authentication private key and the second authentication private key are the same, the verification passes.
[0011] In one embodiment, the first state is an offline state, and the second state is an online state.
[0012] In one embodiment, the hidden storage area is accessed via a private interface command, whether in the offline state or the online state.
[0013] In one embodiment, the disk is switched to the online state, and the customized GRUB program controls the operation of the operating system.
[0014] In one embodiment, the key feature data includes: motherboard serial number and disk serial number; generating a first authentication private key based on the key feature data includes: the customized GRUB program automatically calculating the first authentication private key based on the motherboard serial number and the disk serial number.
[0015] Secondly, embodiments of this application provide a disk data protection device based on GRUB, the device comprising:
[0016] The settings module is used to set a first state and a second state for the disk, and the first state includes a customized GRUB program.
[0017] The initial module is used to enter the first state when the disk is booted. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible.
[0018] The verification module is used by the customized GRUB program to verify the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state and the user data storage area of the disk is unlocked. If the identity authentication private key fails to authenticate, the disk remains in the first state.
[0019] Thirdly, embodiments of this application provide an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the computer program executes the GRUB-based disk data protection method provided in the first aspect when the processor is running.
[0020] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when run on a processor, executes the GRUB-based disk data protection method provided in the first aspect.
[0021] The disk data protection method based on GRUB provided in this application involves setting a first state and a second state for the disk. The disk includes a customized GRUB program. When the disk is booted, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first authentication private key based on the key feature data. The user data storage area of the disk is inaccessible in the first state. The customized GRUB program verifies the first authentication private key. If the first authentication private key is successfully authenticated, the disk switches to the second state, unlocking the user data storage area. If the authentication private key fails, the disk remains in the first state. Because the customized disk serial number (SN) is pre-bound to the motherboard serial number (SN) of a trusted computer, even if someone obtains the disk and installs it on an untrusted computer, the disk is initially offline and the first authentication fails, preventing access to the data on the disk, thus improving data security. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation on the scope of protection of this application. In the various drawings, similar components are numbered similarly.
[0023] Figure 1 This paper illustrates a flowchart of a disk data protection method based on GRUB provided in an embodiment of this application.
[0024] Figure 2 This paper illustrates another flowchart of the disk data protection method based on GRUB provided in an embodiment of this application.
[0025] Figure 3 A schematic diagram of the structure of a GRUB-based disk data protection device provided in an embodiment of this application is shown;
[0026] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown.
[0027] Icons: 300 - GRUB-based disk data protection device; 301 - Setup module; 302 - Initialization module; 303 - Verification module; 400 - Electronic device; 401 - Bus interface; 402 - Processor; 403 - Memory. Detailed Implementation
[0028] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0029] The components of the embodiments of this application described and illustrated in the accompanying drawings can be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of this application provided in the drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0030] In the following, the terms “comprising,” “having,” and their cognates, which may be used in various embodiments of this application, are intended only to indicate a particular feature, number, step, operation, element, component, or combination thereof, and should not be construed as excluding, firstly, the presence of one or more other features, numbers, steps, operations, elements, components, or combinations thereof, or adding the possibility of one or more features, numbers, steps, operations, elements, components, or combinations thereof.
[0031] Furthermore, the terms "first," "second," and "third" are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.
[0032] Unless otherwise specified, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which the various embodiments of this application pertain. Terms (such as those defined in commonly used dictionaries) shall be interpreted as having the same meaning as in their contextual meaning in the relevant technical field and shall not be construed as having an idealized or overly formal meaning, unless clearly defined in the various embodiments of this application.
[0033] Example 1
[0034] This application provides a disk data protection method based on GRUB.
[0035] See Figure 1 The GRUB-based disk data protection method includes steps S101-S103:
[0036] Step S101: Set a first state and a second state for the disk, wherein the disk includes a customized GRUB program.
[0037] In this embodiment, the disk is a custom disk, and the GRUB program is a custom GRUB (GRand Unified Bootloader) program. The first state is an offline state, and the second state is an online state. In the offline state, the user cannot access the user data storage area on the disk; in the online state, the user can access the user data storage area on the disk.
[0038] In one embodiment, the hidden storage area is accessed via a private interface command in either the offline or online state.
[0039] In this embodiment, the storage area can be divided into a hidden storage area and a user data storage area. Whether online or offline, the customized Grub program can access the hidden storage area through internal private interface commands. Offline, the user data storage area is inaccessible because the hard drive is locked. Online, the user data storage area is unlocked, and the user can only access it; the hidden area remains invisible and inaccessible. The hidden storage area is typically used to store sensitive or private user data; the user data storage area is used to store user-accessible documents, images, or audio / video files.
[0040] In one embodiment, the disk is switched to the online state, and the customized GRUB program loads and boots the operating system.
[0041] In this embodiment, the disk is locked in offline mode. When the hard drive loses power, it enters offline mode, and the user data storage area is automatically locked, making it inaccessible to the user.
[0042] Step S102: When the disk is started, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk cannot be accessed.
[0043] In this embodiment, the internal chip of the customized disk has a self-encryption and decryption function based on the SM4 national cryptographic algorithm. SM4 is a block cipher algorithm primarily used for data encryption / decryption operations to ensure data and information confidentiality. It employs a 32-round nonlinear iterative structure with a 128-bit key length and a 64-bit block length. The decryption algorithm is the same as the encryption algorithm, except that the order of the round keys is reversed; the decryption round keys are the reverse of the encryption round keys.
[0044] See Figure 2 Step S102 includes steps S1021-S1022:
[0045] Step S1021: When the disk is started, the first state is entered. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data.
[0046] In this embodiment, upon booting the disk, the disk enters a first state. The host BIOS detects and starts a customized GRUB program for the disk. The customized GRUB program reads the motherboard serial number (SN) and the disk serial number (SN), and automatically calculates the SM3 digest values of the motherboard serial number (SN) and the disk serial number (SN), thereby generating a first authentication private key. The SM3 digest value can be calculated by first calculating the SM3 digest values of the motherboard serial number (SN) and the disk serial number (SN) separately, then concatenating them before calculating the final SM3 digest value. The specific calculation process of the SM3 digest value is prior art and will not be described further here.
[0047] In step S1022, the customized GRUB program verifies the first authentication private key and the second authentication private key. If the first authentication private key and the second authentication private key are the same, the verification passes.
[0048] In this embodiment, the second authentication private key is an SM3 digest value obtained by pre-binding the motherboard serial number (SN) and the disk serial number (SN), stored in a hidden storage area of the customized disk. In this step, the customized GRUB program automatically verifies the first and second authentication private keys. If they are the same, the verification passes; otherwise, the verification fails.
[0049] In one embodiment, before the step of the customized GRUB program reading key feature data and generating a first authentication private key based on the key feature data when the disk is booted, the customized GRUB program generates a second authentication private key by reading the key feature data and stores the second authentication private key in the hidden storage area of the disk.
[0050] In this embodiment, before the customized GRUB program generates the second authentication private key by reading the key feature data, after the customized disk is installed on the trusted computer, the customized disk is an empty disk without an operating system installed. After the system is powered on, the customized disk is in the first state. The host BIOS detects and starts the customized GRUB program on the disk. The customized GRUB program reads the motherboard serial number (SN) and the customized disk serial number (SN) of the computer, binds them using the national cryptographic algorithm SM3, and generates the second authentication private key. The customized GRUB program stores the second authentication key in the hidden storage area of the customized disk. Then, the customized disk automatically unlocks the user data storage area, and the disk switches to the second state. At this time, the operating system is installed, realizing the binding of the customized disk serial number (SN) and the trusted computer motherboard serial number (SN).
[0051] In step S103, the customized GRUB program verifies the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state, and the user data storage area of the disk is unlocked. If the first identity authentication private key fails to authenticate, the disk remains in the first state.
[0052] In this embodiment, the customized GRUB program automatically calculates the SM3 digest values of the serial number SN of the customized disk and the serial number SN of the current computer motherboard, which are used as the first identity authentication private key and verified with the pre-bound and generated second identity authentication private key. If the verification is successful, the user data storage area is unlocked and the customized disk is switched to online status. If the first identity authentication private key fails, the customized disk is locked and the user cannot access it.
[0053] In one embodiment, the customized GRUB program reads data, generates a second authentication private key, and stores the second authentication private key in the hidden storage area.
[0054] In one embodiment, the disk is switched to the online state to control the operation of the operating system.
[0055] In this embodiment, the customized GRUB program first loads the operating system's bootloader, then transfers control to the bootloader, which continues to load and start the operating system.
[0056] In one embodiment, the customized GRUB program automatically calculates the first identity authentication private key based on the motherboard serial number and the disk serial number.
[0057] This embodiment provides a GRUB-based disk data protection method. The disk includes a customized GRUB program and is set to a first and second state. Upon booting the disk, it enters the first state. In this state, the customized GRUB program reads key feature data and generates a first authentication private key. The user data storage area of the disk is inaccessible in the first state. The customized GRUB program verifies the first authentication private key. If authentication is successful, the disk switches to the second state, unlocking the user data storage area. If authentication fails, the disk remains in the first state. Because the customized disk serial number (SN) is pre-bound to the motherboard serial number (SN) of a trusted computer, even if someone obtains the disk and installs it on an untrusted computer, the disk, being offline in its initial state and without successful first authentication, cannot access or obtain the data on the disk, thus improving data security.
[0058] Example 2
[0059] Furthermore, embodiments of this application provide a GRUB-based disk data protection device for use in electronic devices.
[0060] like Figure 3 As shown, the GRUB-based disk data protection device 300 includes:
[0061] Setting module 301 is used to set a first state and a second state for the disk, wherein the disk includes a customized GRUB program;
[0062] Initial module 302 is used to enter the first state when the disk is booted. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible.
[0063] The verification module 303 is used by the customized GRUB program to verify the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state and the user data storage area of the disk is unlocked. If the identity authentication private key fails to authenticate, the disk remains in the first state.
[0064] In one embodiment, the setting module 301 is further configured to, before the step of the customized GRUB program reading key feature data and generating a first authentication private key based on the key feature data when the disk is booted and entering the first state, store the second authentication private key in the hidden storage area of the disk by reading the key feature data.
[0065] In one embodiment, the initial module 302 is further configured to include the key feature data as: motherboard serial number and disk serial number; generating a first identity authentication private key based on the key feature data includes: the customized GRUB program automatically calculating the first identity authentication private key based on the motherboard serial number and the disk serial number.
[0066] In one embodiment, the verification module 303 is further configured to have the customized GRUB program verify the first identity authentication private key and the second identity authentication private key. If the first identity authentication private key and the second identity authentication private key are the same, the verification passes.
[0067] The GRUB-based disk data protection device 300 provided in this embodiment can implement the GRUB-based disk data protection method provided in Embodiment 1. To avoid repetition, it will not be described again here.
[0068] The GRUB-based disk data protection device provided in this embodiment sets a first state and a second state for the disk. When the disk, including the customized GRUB program, boots from the disk, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first authentication private key based on the key feature data. The user data storage area of the disk is inaccessible in the first state. The customized GRUB program verifies the first authentication private key. If the first authentication private key is successfully authenticated, the disk switches to the second state, unlocking the user data storage area. If the authentication private key fails, the disk remains in the first state. Because the customized disk serial number (SN) is pre-bound to the motherboard serial number (SN) of a trusted computer, even if someone obtains the disk and installs it on an untrusted computer, the disk is initially offline and the first authentication fails, preventing access to and retrieval of the data on the disk, thus improving data security.
[0069] Example 3
[0070] Furthermore, this application provides an electronic device including a memory and a processor. The memory stores a computer program, which executes the GRUB-based disk data protection method provided in Embodiment 1 when running on the processor.
[0071] For details, see Figure 4 The electronic device 400 includes a bus interface 401 and a processor 402. The processor 402 is used to set a first state and a second state for the disk, and the disk includes a customized GRUB program.
[0072] When the disk is booted, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible.
[0073] The customized GRUB program verifies the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state, and the user data storage area of the disk is unlocked. If the identity authentication private key fails to authenticate, the disk remains in the first state.
[0074] In one embodiment, the processor 402 is further configured to: generate a second authentication private key by binding the key feature data, and store the second authentication private key in a hidden storage area of the disk.
[0075] In one embodiment, the processor 402 is further configured to: verify the first authentication private key and the second authentication private key through the customized GRUB program; if the first authentication private key and the second authentication private key are the same, the verification passes.
[0076] In one embodiment, the first state is an offline state, and the second state is an online state.
[0077] In one embodiment, the hidden storage area is accessed via a private interface command in either the offline or online state.
[0078] In one embodiment, the processor 402 is further configured to: switch the disk to the online state, and the customized GRUB program controls the operation of the operating system.
[0079] In one embodiment, the processor 402 is further configured to: automatically calculate, based on the motherboard serial number and the disk serial number, the customized GRUB program to obtain the first identity authentication private key.
[0080] In this embodiment of the application, the electronic device 400 further includes a memory 403. Figure 4 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 402 and memory represented by memory 403 together. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 401 provides an interface. Processor 402 is responsible for managing the bus architecture and general processing, and memory 403 can store data used by processor 402 during operation. Specific forms of the electronic device include, but are not limited to, servers, computers, smart terminals, mobile terminals, mobile storage devices, solid-state drives, etc.
[0081] The electronic device 400 provided in this application embodiment can execute the steps of the disk data protection method based on GRUB provided in the above method embodiment 1. To avoid repetition, it will not be described again here.
[0082] The electronic device provided in this embodiment sets a first state and a second state for the disk, which includes a customized GRUB program. When the disk is booted, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible. The customized GRUB program verifies the first authentication private key. If the first authentication private key is successfully authenticated, the disk switches to the second state and unlocks the user data storage area of the disk. If the authentication private key fails, the disk remains in the first state. Because the customized disk serial number (SN) is pre-bound to the motherboard serial number (SN) of a trusted computer, even if someone obtains the disk and installs it on an untrusted computer, the disk cannot access and obtain the data on the disk if it is initially offline and the first authentication fails, thus improving the data security of the disk.
[0083] Example 4
[0084] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the GRUB-based disk data protection method provided in Embodiment 1.
[0085] In this embodiment, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0086] The computer-readable storage medium provided in this embodiment can implement the GRUB-based disk data protection method provided in Embodiment 1. To avoid repetition, it will not be described again here.
[0087] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal that includes that element.
[0088] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0089] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A disk data protection method based on GRUB, characterized in that, The method includes: The disk is set to a first state and a second state; the disk includes a customized GRUB program. When the disk is booted, it enters the first state. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible. The customized GRUB program verifies the first identity authentication private key. If the first identity authentication private key is successfully authenticated, the disk is switched to the second state, and the user data storage area of the disk is unlocked. If the first identity authentication private key fails to authenticate, the disk remains in the first state. The key feature data includes: motherboard serial number and disk serial number; Generating a first identity authentication private key based on the key feature data includes: The customized GRUB program automatically calculates the first authentication private key based on the motherboard serial number and the disk serial number. The customized GRUB program reads the motherboard serial number SN and the disk serial number SN, and automatically calculates the SM3 digest value of the motherboard serial number SN and the disk serial number SN to generate the first authentication private key. The SM3 digest value is calculated by calculating the SM3 digest value of the motherboard serial number SN and the disk serial number SN separately, concatenating them, and then calculating the SM3 digest value. Before the step of entering the first state when the disk is booted, and the customized GRUB program reading key feature data and generating a first identity authentication private key based on the key feature data in the first state, the following steps are included: The customized GRUB program reads the key feature data, generates a second authentication private key, and stores the second authentication private key in a hidden storage area of the disk. The storage area is divided into a hidden storage area and a user data storage area. The hidden storage area can be accessed through a private interface command in offline or online states. The disk is switched to the online state, and the customized GRUB program controls the operation of the operating system.
2. The disk data protection method based on GRUB according to claim 1, characterized in that, The customized GRUB program verifies the first identity authentication private key, including: The customized GRUB program verifies the first authentication private key and the second authentication private key. If the first authentication private key and the second authentication private key are the same, the verification passes.
3. The disk data protection method based on GRUB according to claim 1, characterized in that, The first state is offline, and the second state is online.
4. A disk data protection device based on GRUB, characterized in that, The device includes: The settings module is used to set a first state and a second state for the disk platter, which includes a customized GRUB program. The initial module is used to enter the first state when the disk is booted. In the first state, the customized GRUB program reads key feature data and generates a first identity authentication private key based on the key feature data. In the first state, the user data storage area of the disk is inaccessible. The key feature data includes: motherboard serial number and disk serial number; Generating a first identity authentication private key based on the key feature data includes: The customized GRUB program automatically calculates the first authentication private key based on the motherboard serial number and the disk serial number. Specifically, the customized GRUB program reads the motherboard serial number (SN) and the disk serial number (SN), and automatically calculates the SM3 digest values of both to generate the first authentication private key. The SM3 digest value is calculated by separately calculating the SM3 digest values of the motherboard serial number (SN) and the disk serial number (SN), concatenating them, and then calculating the final SM3 digest value. A verification module is used by the customized GRUB program to verify the first authentication private key. If the first authentication private key is successfully authenticated, the disk switches to the second state, unlocking the user data storage area of the disk. If the first authentication private key fails to authenticate, the disk remains in the first state. Before the step of entering the first state when the disk is booted, and the customized GRUB program reading key feature data and generating a first identity authentication private key based on the key feature data in the first state, the following steps are included: The customized GRUB program reads the key feature data, generates a second authentication private key, and stores the second authentication private key in a hidden storage area of the disk. The storage area is divided into a hidden storage area and a user data storage area. The hidden storage area can be accessed through a private interface command in offline or online states. The disk is switched to the online state, and the customized GRUB program controls the operation of the operating system.
5. An electronic device, characterized in that, The device includes a memory and a processor, wherein the memory stores a computer program that executes the GRUB-based disk data protection method according to any one of claims 1 to 3 when the processor is running.
6. A computer-readable storage medium, characterized in that, It stores a computer program that, when run on a processor, executes the GRUB-based disk data protection method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Copyright protection implementation method and copyright protection storage device
CN111143784A