A hard drive decryption method and computing device
By receiving and utilizing decryption keys and preset correspondences, batch decryption of multiple encrypted hard drives is achieved, solving the inefficiency problem caused by multiple manual key inputs in existing technologies and improving hard drive decryption efficiency.
Patent Information
- Application Number
- CN202311846165.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-12-28
AI Technical Summary
In existing technologies, when there are multiple hard drives encrypted with external keys in a computing device, the decryption key needs to be manually entered repeatedly for decryption, resulting in low decryption efficiency.
After receiving the first decryption key, based on the key identifier of the encrypted hard drive and the preset correspondence between the hard drives, all hard drives that need to be decrypted are identified, and the decryption key is used to decrypt multiple hard drives in batches.
This technology enables batch decryption of multiple encrypted hard drives after receiving a single decryption key, significantly improving the maintenance efficiency of storage servers for encrypted hard drives.
Smart Images

Figure CN117910059B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a hard disk decryption method and computing device. Background Technology
[0002] An encrypted hard drive (secure encryption device, SED) is a hard drive with a built-in encryption chip in its controller. An encrypted hard drive encrypts all data when it is written to the drive and decrypts all data when it is read from the drive. Data stored on an encrypted hard drive is always fully encrypted using an encryption key stored on the encryption chip, which is inaccessible to the host operating system or unauthorized users.
[0003] In related technologies, the encryption and decryption keys for encrypted hard drives can be centrally managed through a remote encryption server. When a computing device contains encrypted hard drives that the current decryption server cannot decrypt, the decryption key must be manually entered for decryption. When multiple encrypted hard drives exist that the current decryption server cannot decrypt, the decryption key must be manually entered for each hard drive individually, requiring multiple decryption operations, which is inefficient. Summary of the Invention
[0004] This application provides a hard disk decryption method and computing device, which solves the problem that when there are multiple hard disks encrypted with external keys in the computing device, it is necessary to manually input the external key for each encrypted hard disk repeatedly for decryption, resulting in low decryption efficiency.
[0005] To achieve the above technical solution, this application adopts the following technical solution:
[0006] A first aspect provides a hard disk decryption method, the method comprising: receiving a first decryption key, the first decryption key being used to decrypt a first encrypted hard disk; querying at least one second encrypted hard disk having the same first key identifier as the first encrypted hard disk; wherein the encrypted hard disks and key identifiers have a preset correspondence; and decrypting the first encrypted hard disk and at least one second encrypted hard disk based on the first decryption key.
[0007] The hard disk decryption method provided in this application embodiment can, after receiving the first decryption key, determine all second encrypted hard disks corresponding to the first key in the first decryption request based on the key identifier of the encryption key of the encrypted hard disk and the preset correspondence between the encrypted hard disks, and then use the first decryption key to decrypt the second encrypted hard disks in batches. Compared with the process of manually entering keys to decrypt each encrypted hard disk in related technologies, the hard disk decryption method provided in this application embodiment can decrypt the encrypted hard disks in batches by entering the decryption key only once, which greatly improves the maintenance efficiency of the storage server for encrypted hard disks.
[0008] In one possible implementation, the first key identifier is the key identifier of the encryption key corresponding to the first decryption key, and the encryption key is the encryption key of the first encrypted hard disk. Optionally, the first key identifier can also be the key identifier corresponding to the first decryption key; optionally, the embodiments of this application do not limit the specific form of the first key identifier, and the first key identifier is used to identify that the first encrypted hard disk and the second encrypted hard disk have the same encryption key or decryption key.
[0009] In one possible implementation, before receiving the first decryption key, the hard disk decryption method provided in this application further includes: obtaining the key identifier corresponding to each encrypted hard disk from the hard disk information of each encrypted hard disk. The encryption key of the encrypted hard disk is used to encrypt the encrypted hard disk. A preset correspondence is generated using each encrypted hard disk and its corresponding key identifier.
[0010] In this possible implementation, the key identifier of the encryption key of each encrypted hard drive is obtained from the hard drive information of each encrypted hard drive. A preset correspondence is generated by using the key identifier of the encryption key and the hard drive identifier of each encrypted hard drive. This allows the encrypted hard drive corresponding to the first decryption key in the decryption request to be determined according to the preset correspondence after receiving the user's decryption request, thereby improving the decryption efficiency of the encrypted hard drive.
[0011] In one possible implementation, before receiving the first key, the hard disk decryption method provided in this application embodiment further includes: generating prompt interface data if the target RAID card corresponding to the first encrypted hard disk fails to decrypt the first encrypted hard disk. The prompt interface data is sent to a display device so that the display device displays the prompt interface data. The prompt interface includes the hard disk identifier of the first encrypted hard disk and an input area for the first decryption key. The input area is used for the user to input the first decryption key.
[0012] In this possible implementation, if the target RAID card fails to decrypt the target encrypted hard drive, a prompt interface data is generated and sent to the display device. This allows the display device to display the prompt interface based on the displayed data, thus promptly notifying the user that the encrypted hard drive has failed to decrypt.
[0013] In one possible implementation, decrypting the first encrypted hard drive and at least one second encrypted hard drive based on a first decryption key includes: sending the first decryption key and a first decryption request to a target RAID card. The first decryption request instructs the target RAID card to decrypt the first encrypted hard drive and at least one second encrypted hard drive according to the first decryption key. The target RAID card is used to manage the first encrypted hard drive and at least one second encrypted hard drive.
[0014] In this possible implementation, sending a first decryption key and a first decryption request to the target RAID card can instruct the target RAID card to perform batch decryption of the first self-encrypting hard disk and at least one second self-encrypting hard disk based on the first decryption key, which can improve the maintenance efficiency of the storage server for encrypted hard disks.
[0015] In one possible implementation, a set of decryption keys stored in an encryption server is obtained, the set including at least one decryption key. A second decryption key corresponding to the target RAID card is obtained from the set and sent to the target RAID card. The target RAID card is used to manage a first encrypted hard drive and at least one second encrypted hard drive. If the first encrypted hard drive and at least one second encrypted hard drive are successfully decrypted using the first decryption key, the first key identifier corresponding to the first and second encrypted hard drives is replaced with the second key identifier.
[0016] In this possible implementation, a set of decryption keys stored in the encryption server is retrieved, and the set includes at least one decryption key. A second decryption key corresponding to the target RAID card is obtained from the set and sent to the target RAID card. If the first encrypted hard drive and at least one second encrypted hard drive are successfully decrypted using the first decryption key, the first key identifier in the preset mapping is replaced with the second key identifier corresponding to the target RAID card identifier. The preset mapping between the first encrypted hard drive and at least one second encrypted hard drive is updated using the second key identifier, ensuring that the updated preset mapping can be used for direct decryption the next time the first encrypted hard drive and at least one second encrypted hard drive are decrypted.
[0017] In one possible implementation, a second decryption request is sent to the target RAID card. This second decryption request instructs the target RAID card to decrypt at least one encrypted hard drive managed by the target RAID card using a second decryption key.
[0018] In this possible implementation, after replacing the first key identifier corresponding to the first encrypted hard drive and the second encrypted hard drive with the second key identifier, and sending the second decryption key and the second decryption request to the target RAID card, the target RAID card can use the second decryption key to decrypt at least one encrypted hard drive corresponding to the second key identifier, which facilitates the storage server to maintain and manage the encrypted hard drives.
[0019] Secondly, a hard disk decryption device is provided. This hard disk decryption device is used to perform any of the hard disk decryption methods provided in the first aspect above.
[0020] In one possible implementation, embodiments of this application can divide the memory error information acquisition device into functional modules according to the method provided in the first aspect above. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. For example, embodiments of this application can divide the memory error information acquisition device into a sending module, a reading module, and a generating module, etc., according to their functions. The descriptions of the possible technical solutions and beneficial effects of the various functional modules described above can be found in the technical solutions provided in the first aspect above or its corresponding possible implementations, and will not be repeated here.
[0021] Thirdly, embodiments of this application provide a computing device, including a controller and a plurality of encrypted hard disks. The plurality of encrypted hard disks includes a first encrypted hard disk and at least one second encrypted hard disk.
[0022] The controller is used to execute the hard disk decryption method in the first aspect or any implementation thereof.
[0023] Fourthly, a controller is provided, comprising: an interface and logic circuitry, the logic circuitry being used to implement the hard disk decryption method as described in the first aspect above.
[0024] Fifthly, embodiments of this application provide a computer-readable storage medium storing at least one computer program, which is loaded and executed by a processor to implement the hard disk decryption method as described in the first aspect above.
[0025] Sixthly, embodiments of this application provide a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the terminal to perform the hard disk decryption method provided in the various optional implementations of the first aspect described above.
[0026] For a detailed description of the second to sixth aspects and their various implementations in the embodiments of this application, please refer to the detailed description in the first aspect and its various implementations. Furthermore, for the beneficial effects of the second to sixth aspects and their various implementations, please refer to the beneficial effect analysis in the first aspect and its various implementations; these will not be repeated here.
[0027] These or other aspects of this application will become more readily apparent in the following description. Attached Figure Description
[0028] Figure 1 A schematic diagram of a computing device provided in an embodiment of this application;
[0029] Figure 2 A specific schematic diagram of the prompt interface provided in the embodiments of this application;
[0030] Figure 3 A flowchart of a method for hard disk decryption in the related technology provided in the embodiments of this application;
[0031] Figure 4 A system architecture diagram for hard disk decryption in the related technologies provided in the embodiments of this application;
[0032] Figure 5 A specific flowchart of a hard disk decryption method provided in this application embodiment;
[0033] Figure 6 Another specific flowchart of a hard disk decryption method provided in this application embodiment;
[0034] Figure 7 Another specific flowchart of a hard disk decryption method provided in this application embodiment;
[0035] Figure 8 Another specific flowchart of a hard disk decryption method provided in this application embodiment;
[0036] Figure 9 A schematic diagram of a hard disk decryption device provided in an embodiment of this application;
[0037] Figure 10 A schematic diagram of a controller provided in an embodiment of this application;
[0038] Figure 11 This is a schematic diagram of a chip system provided in an embodiment of this application. Detailed Implementation
[0039] First, some concepts involved in the hard disk decryption method and computing device provided in the embodiments of this application will be explained.
[0040] A key is a tool used to encrypt and decrypt data; it is a parameter input into algorithms that convert plaintext to ciphertext or vice versa. Keys can be categorized as symmetric keys and asymmetric keys. A symmetric key uses the same encryption and decryption keys to encrypt and decrypt plaintext. An asymmetric key uses an encryption key and a different decryption key to encrypt and decrypt plaintext. In the embodiments of this application, the encryption and decryption keys can be either symmetric or asymmetric keys.
[0041] The solutions shown in the embodiments of this application can be executed by a computing device, which may be a server. For example... Figure 1 As shown, Figure 1 This is a schematic diagram of a computing device 100 provided in an embodiment of this application. The computing device 100 may include: a controller 101, at least one redundant arrays of independent disks (RAID card) 102, and at least one encrypted hard disk 103.
[0042] The controller 101 can establish a communication connection with at least one RAID card 102, and one RAID card 102 can establish a communication connection with at least one encrypted hard disk 103.
[0043] For example, controller 101 may be deployed with a first RAID card (also known as a target RAID card), and under the first RAID card, a first encrypted hard disk and at least one second encrypted hard disk may be deployed.
[0044] For example, controller 101 can establish communication connections with RAID cards 102a, RAID cards 102b, ..., RAID cards 102n. RAID card 102a can establish communication connections with encrypted hard drives 103a, RAID cards 103b, ..., RAID cards 103n.
[0045] The controller 101 can be used for monitoring and managing components in the computing device 100. In this embodiment, the computing device is a storage server. The controller 101 can monitor the operating status of various devices in the storage server, such as RAID cards, including their operating temperature and voltage. Furthermore, the controller 101 can be used for system configuration, firmware upgrades, and fault diagnosis. In some embodiments, the controller 101 can be an electronic component with data processing capabilities, such as a central processing unit or microprocessor. In some embodiments, the controller 101 can specifically be a baseboard management controller (BMC), a core component in the server management system defined by the Intelligent Platform Management Interface (IPMI), integrated into the hardware manager of servers, network devices, and other computer systems. For example, in this embodiment, the baseboard management controller is integrated into the computing device. Its function is to monitor the hardware status of the computing device, perform remote management operations, and provide monitoring and control functions for the computing device. It should be noted that different equipment manufacturers may use different names for the baseboard management controller. For example, some baseboard management controllers are called Integrated Lights-Out (iLO), while others are called Integrated Dell Remote Access Controller (iDRAC). Regardless of whether it is BMC, iLO, or iDRAC, they can all be understood as the baseboard management controller in the embodiments of this invention. In this application embodiment, the baseboard management controller is referred to as BMC as an example.
[0046] This application uses RAID card 102a as an example, which can be used to manage and maintain encrypted hard drives. One RAID card 102a can manage and maintain multiple encrypted hard drives. The RAID card 102a stores hard drive information, environmental parameters, read / write parameters, etc., of the encrypted hard drives. The hard drive information may include the key identifier of the encryption key, and may also include the interface type, manufacturer, serial number, media type, firmware status, shadow address space (SAS), supported speed, power status, location status, remaining wear rate, reconstruction status, encryption status, health status, model, firmware version, temperature, capacity, negotiation speed, hot standby status, cumulative power-on time, logical type, and inspection status of the encrypted hard drive.
[0047] This application uses an encrypted hard drive 103a as an example. The encrypted hard drive 103a can be used to store data, and the data on the hard drive is dynamically encrypted to prevent data leakage. For example, the encrypted hard drive includes an onboard encryption chip and flash memory media. The onboard encryption chip encrypts the data before writing it to the flash memory media of the encrypted hard drive and decrypts the data before reading it from the flash memory media. Since this encryption process does not involve the server, it ensures that the storage server will not suffer performance loss due to data encryption. When the encrypted hard drive is encrypted for the first time, the RAID card sends the obtained encryption key to the onboard encryption chip. The onboard encryption chip uses the encryption key to encrypt the data. When the storage server boots up, the encrypted hard drive requests a decryption key. At this time, after the storage server writes the correct decryption key into the encrypted hard drive, it decrypts the contents of the encrypted hard drive and grants the storage server data access permissions. The hard drive media of the encrypted hard drive can include a hard disk drive (HDD) or a solid-state drive (SSD).
[0048] In some embodiments, the RAID card 102 is optional. The controller 101 can directly control the encrypted hard disk 103.
[0049] In some embodiments, as Figure 1 As shown, the computing device provided in this application embodiment may further include a display device 104 and an input device 105.
[0050] The display device 104 can establish a communication connection with the controller 101. The input device can also establish a communication connection with the controller 101.
[0051] Display device 104 can be used to display the user interface to the user after receiving user interface data sent by controller 101. The user interface includes a prompt interface, which can be generated by controller 101 in the event that the RAID card corresponding to the encrypted hard drive fails to decrypt the encrypted hard drive.
[0052] For example, such as Figure 2 As shown, Figure 2This is a specific example of the prompt interface. This prompt interface displays the hard drive information for Disk10 of Logical Drive 239 under the PCIe Card 4 bus. This hard drive information includes interface type, manufacturer, serial number, media type, firmware status, SAS address, supported speeds, power status, location status, remaining wear rate, reconstruction status, encryption status, health status, model, firmware version, temperature, capacity, negotiation speed, hot standby status, cumulative power-on time, logical type, inspection status, and the key identifier for the encryption key. Disk10's encryption status is in the first state, indicating that Disk10 cannot be decrypted at this time. The user can unlock Disk10 by clicking the input box and entering the decryption key through input device 105.
[0053] Input device 105 can be used to provide interactive functionality for the user. The user can input data and information into the controller 101 of the computing device via input device 105. For example, the user can manually input the decryption key for the encrypted hard drive into the controller 101 of the computing device via input device 105.
[0054] To improve key security and reduce vulnerability to Level 2 attacks, one approach is to store the keys on an encryption server. For example... Figure 3 As shown in the embodiments of this application, the computing device can also establish a communication connection with an encryption server. The encryption server can be used to store the encryption key and decryption key of the encrypted hard disk.
[0055] One possible implementation involves the controller sending an encryption key retrieval request to the encryption server upon power-up. Upon receiving the request, the encryption server sends its stored set of encryption keys to the controller. The controller then uses this decryption key to decrypt the encrypted hard drive. This method ensures the key is invisible to the user, resulting in enhanced data security. The encryption process does not affect the performance of the storage server and cannot be shut down; devices without the decryption key cannot access the data.
[0056] However, when the storage server contains encrypted hard drives that the corresponding encryption server cannot decrypt, an external key needs to be manually entered for decryption on each encrypted hard drive. When there are multiple encrypted hard drives on the storage server that the corresponding encryption server cannot decrypt, an external key needs to be manually entered for decryption on each encrypted hard drive individually, requiring multiple decryption operations, which is inefficient.
[0057] For example, such as Figure 4As shown, storage server 1 is currently deployed in region a. When encrypted hard drive 1 is moved from region b to region a (i.e., encrypted hard drive 1 originally deployed in region b is moved to region a and then deployed in storage server 1), the encryption server corresponding to storage server 1 does not have the decryption key for encrypted hard drive 1. Storage server 1 cannot decrypt encrypted hard drive 1 and cannot read the data on it. The user needs to manually enter the decryption key for encrypted hard drive 1 to decrypt it. When there are multiple encrypted hard drives on storage server 1 that have been moved from other regions to region a, the user needs to manually enter the decryption key for each encrypted hard drive individually, requiring multiple decryption operations, which is inefficient.
[0058] Based on this, embodiments of this application provide a hard disk decryption method, applied to a controller, such as... Figure 5 As shown, in this hard drive decryption method, the controller receives a first decryption key, which is used to decrypt the first encrypted hard drive. It then queries at least one second encrypted hard drive that has the same first key identifier as the first encrypted hard drive. The encrypted hard drives and key identifiers have a preset correspondence. The controller decrypts the first encrypted hard drive and at least one second encrypted hard drive based on the first decryption key.
[0059] Therefore, the hard disk decryption method provided in this application embodiment can, upon receiving the first decryption key, determine all encrypted hard disks corresponding to the first key based on a preset correspondence between encrypted hard disks and encryption keys, and then use the first decryption key to perform batch decryption of the encrypted hard disks. Compared to the process of manually entering keys to decrypt each encrypted hard disk in related technologies, the hard disk decryption method provided in this application embodiment only requires inputting a decryption key once to perform batch decryption of encrypted hard disks, significantly improving the maintenance efficiency of storage servers for encrypted hard disks.
[0060] Figure 6 This is a flowchart illustrating a hard disk decryption method provided in an embodiment of this application. Figure 6 As shown, the method may include the following steps:
[0061] S601, the controller receives the first decryption key.
[0062] The first decryption request is used to decrypt the first encrypted hard drive.
[0063] Specifically, the first decryption key can be obtained by the user selecting the first encrypted hard drive and entering the first decryption key in the prompt interface displayed by the display device connected to the controller, and the controller receiving the first decryption key entered by the user.
[0064] Among them, Figure 2As shown, the prompt interface includes the hard drive identifier of the first encrypted hard drive and an input area for the first decryption key. The user can enter the first decryption key in the input area of the prompt interface.
[0065] S602, the controller determines the first key identifier based on the first encrypted hard disk.
[0066] The first key identifier is the key identifier of the encryption key corresponding to the first decryption key. The encryption key of the first encrypted hard disk is used to encrypt the data in the first encrypted hard disk.
[0067] It should be noted that the first key identifier can be the decryption key identifier of the first decryption key or the hard disk identifier of the first encrypted hard disk. This application does not limit the type of the first key identifier.
[0068] Specifically, the controller can determine the first key identifier of the first encrypted hard drive by reading the hard drive information from the target RAID card. The target RAID card is the RAID card among multiple RAID cards in the computing device used to manage the first encrypted hard drive.
[0069] S603, the controller queries at least one second encrypted hard disk that has the same first key identifier as the first encrypted hard disk.
[0070] The encrypted hard drive and the key identifier have a preset correspondence.
[0071] Specifically, the preset mapping relationship includes the mapping relationship between the target key identifier and the target hard drive identifier, where the target hard drive identifier is the hard drive identifier of the target hard drive corresponding to the target key identifier. In the preset mapping relationship, the target key identifier is the key identifier of the encryption key corresponding to the target hard drive identifier. The encryption key corresponding to the target key identifier is used to encrypt the encrypted hard drive corresponding to the target hard drive identifier.
[0072] For example, as shown in Table 1, the preset correspondence can be a list generated from the correspondence between the target key identifier and each target hard disk identifier. Specifically, key identifier 01a corresponds to hard disk identifiers b01 and b02. Key identifier a02 corresponds to hard disk identifiers b03 and b04. It should be noted that this correspondence list is merely an example of the representation of the preset correspondence, and the embodiments of this application do not limit the representation of the preset correspondence.
[0073] Table 1
[0074] Key identifier Hard drive identification a01 b01 a01 b02 a02 b03 a02 b04
[0075] Specifically, when the storage server powers on and the operating system (OS) of the storage server completes hard drive decryption, the controller retrieves the key identifier of the encryption key for each encrypted hard drive from the hard drive information. A preset correspondence is then established between the key identifier of the encryption key for each encrypted hard drive and the respective encrypted hard drive.
[0076] S604, the controller decrypts the first encrypted hard disk and at least one second encrypted hard disk based on the first decryption key.
[0077] Specifically, the controller sends a first decryption key and a second decryption request to the target RAID card. The second decryption request instructs the target RAID card to decrypt the first encrypted hard drive and at least one second encrypted hard drive using the first decryption key. The target RAID card is one of multiple RAID cards in the computing device used to manage the first encrypted hard drive and at least one second encrypted hard drive.
[0078] After receiving the first decryption key and the second decryption request, the target RAID card decrypts the first encrypted hard disk and at least one encrypted hard disk according to the first decryption key.
[0079] The hard disk decryption method provided in this application embodiment can, upon receiving a first decryption key, determine all encrypted hard disks corresponding to the first decryption key based on a preset correspondence between encrypted hard disks and key identifiers, and then use the first decryption key in the first decryption request to perform batch decryption of the encrypted hard disks. Compared to the process of manually entering keys to decrypt each encrypted hard disk in related technologies, the hard disk decryption method provided in this application embodiment can perform batch decryption of encrypted hard disks by entering a decryption key only once, greatly improving the maintenance efficiency of storage servers for encrypted hard disks.
[0080] In some embodiments, as Figure 7 As shown, the method provided in this application embodiment may further include S701-S705. For example, S701-S705 may be executed before S601.
[0081] S701, the controller obtains the decryption key set.
[0082] The decryption key set includes at least one decryption key.
[0083] In some implementations, after the storage server powers on, the controller sends a request to the encryption server to retrieve the encryption key set. Upon receiving the request, the encryption server sends the encryption key set stored in the encryption server to the controller.
[0084] In some implementations, the controller obtains decryption keys from each encrypted hard drive to obtain a set of decryption keys.
[0085] S702, for any RAID card, the controller determines the second decryption key corresponding to the target RAID card from the decryption key set and sends the second decryption key to the target RAID card.
[0086] One RAID card manages at least one encrypted hard drive. A pre-defined key identifier corresponds to each RAID card and its decryption key. The decryption key corresponding to the RAID card is used to decrypt the encrypted hard drive managed by the RAID card.
[0087] Taking the target RAID card of the computing device as an example, the RAID card identifier of the target RAID card corresponds to the second key identifier of the encryption key. The controller determines the second key identifier of the encryption key corresponding to the RAID card identifier based on the target RAID card identifier. The controller then determines the second decryption key corresponding to the second key identifier from the decryption key set. This second decryption key is the decryption key corresponding to the encryption key corresponding to the second key identifier. The controller sends the second decryption key to the target RAID card.
[0088] S703, the controller sends a third decryption request to the target RAID card corresponding to the first encrypted hard drive.
[0089] The third decryption request includes the identifier of the first hard drive. This third decryption request instructs the target RAID card to decrypt the first encrypted hard drive using the second decryption key.
[0090] After receiving the third decryption request, the target RAID card uses the second decryption key to decrypt the first encrypted hard drive.
[0091] S704: The controller generates a prompt interface when the target RAID card fails to decrypt the first encrypted hard drive.
[0092] The prompt interface data indicates that the target RAID card failed to decrypt the first encrypted hard drive.
[0093] For example, when the target RAID card fails to decrypt the first encrypted hard drive, it can set the encryption status in the hardware information of the first encrypted hard drive to a first state to generate a prompt interface. This first state is used to indicate that the target RAID card has failed to decrypt the first encrypted hard drive.
[0094] S705, the controller sends the prompt interface data to the display device so that the display device can display the prompt interface data according to the prompt interface data.
[0095] For example, the controller sends interface data to the display device, and after receiving the prompt interface data, the display device can display the encryption status of the first encrypted hard drive to the user.
[0096] In some embodiments, such as Figure 8 As shown, the method provided in this application embodiment may further include S801-S804. For example, S801-S804 may be executed after S604 is executed to decrypt the first encrypted hard disk and all second encrypted hard disks using the first decryption key.
[0097] S801, the controller obtains the set of decryption keys stored in the encryption server.
[0098] The decryption key set includes at least one decryption key.
[0099] In some real-time methods, after the controller is powered on again, it sends a request to the encryption server to obtain the decryption key set stored in the encryption server.
[0100] S802, the controller obtains the second decryption key corresponding to the target RAID card from the decryption key set and sends the second decryption key to the target RAID card.
[0101] The target RAID card is used to manage the first encrypted hard drive and at least one second encrypted hard drive.
[0102] It should be noted that the process of the controller obtaining the second decryption key corresponding to the target RAID card from the decryption key set and sending the second decryption key to the target RAID card is the same as the process in S702 where, for any RAID card, the controller determines the second decryption key corresponding to the target RAID card from the decryption key set and sends the second decryption key to the target RAID card. This application will not elaborate on this process.
[0103] S803, if the controller successfully decrypts the first encrypted hard disk and at least one second encrypted hard disk using the first decryption key, the controller replaces the first key identifier corresponding to the target RAID card in the preset correspondence with the second key identifier.
[0104] Specifically, when the controller successfully decrypts the first encrypted hard disk and at least one second encrypted hard disk using the first decryption key, the controller replaces the first key identifier in the preset correspondence with the second key identifier corresponding to the target RAID card, thereby obtaining a new preset correspondence between the second key identifier corresponding to the target RAID card and the first encrypted hard disk and at least one second encrypted hard disk.
[0105] For example, referring to Table 1 above, the hard drive identifier of the first encrypted hard drive is b01, the hard drive identifier of the second encrypted hard drive is b0, the key identifier of the first decryption key is a01, and the key identifier corresponding to the target RAID card is a02. If the controller successfully decrypts the first and second encrypted hard drives using the first decryption key, the controller replaces the key identifier a01 of the first and second encrypted hard drives with the key identifier a02 corresponding to the target RAID card, resulting in Table 2.
[0106] Table 2
[0107] Key identifier Hard drive identification a02 b01 a02 b02 a02 b03 a02 b04
[0108] S804, the controller sends a second decryption request to the target RAID card.
[0109] The second decryption request is used to instruct the target RAID card to decrypt at least one encrypted hard drive managed by the target RAID card according to the second decryption key.
[0110] In this embodiment of the application, when the controller successfully decrypts the first encrypted hard disk and at least one second encrypted hard disk using the first decryption key, the controller replaces the first key identifier in the preset correspondence with the key identifier corresponding to the target RAID card, thereby updating the new preset correspondence between the key identifier corresponding to the target RAID card and the first encrypted hard disk and at least one second encrypted hard disk. This allows the controller to perform batch decryption of encrypted hard disks based on the new preset correspondence when decrypting encrypted hard disks with the same key identifier, requiring only one decryption key input.
[0111] The above describes the solution provided by the embodiments of this application from a methodological perspective. The hard disk decryption method described above can be applied to the computing device described above. In terms of hardware implementation, the computing device can be implemented as a chip deployed in the CPU. In terms of software, the computer system may include an OS and a BIOS that communicates with the OS, wherein the OS is used to execute the hard disk decryption method in the above embodiments.
[0112] The foregoing mainly describes the solutions provided by the embodiments of this application from the perspective of methods and systems. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0113] This application embodiment can divide the hard disk decryption device into functional modules according to the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0114] Figure 9 A schematic diagram of the hard disk decryption device 900 provided in an embodiment of this application is shown. This hard disk decryption device is used to execute the aforementioned hard disk decryption method and can be applied to a computing device. For example, executing... Figures 6-8 The hard disk decryption method is shown. For example, the hard disk decryption device 900 may include a receiving module 901, a processing module 902, a query module 903, a decryption module 904, an acquisition module 905, a sending module 906, a generation module 907, and a replacement module 908.
[0115] The receiving module 901 is used to receive the first decryption key.
[0116] For example, the receiving module 901 can be used to perform... Figure 6 S601 is shown.
[0117] Processing module 902 is used to determine the first key identifier based on the first encrypted hard disk.
[0118] The processing module 902 can also be used to determine the second decryption key corresponding to the RAID card from the decryption key set for any RAID card.
[0119] For example, processing module 902 can be used to execute Figure 6 S602 or S603 shown Figure 7 The S702 shown.
[0120] The query module 903 can be used to query at least one second encrypted hard disk that has the same first key identifier as the first encrypted hard disk.
[0121] For example, query module 903 can be used to execute... Figure 6 The S603 shown.
[0122] The decryption module 904 is used to decrypt the first encrypted hard disk and at least one second encrypted hard disk based on the first decryption key.
[0123] For example, decryption module 904 can be used to execute Figure 6 The S604 shown.
[0124] The acquisition module 905 is used to acquire the set of decryption keys stored in the encryption server.
[0125] For example, module 905 can be used to execute Figure 7 The S701 shown.
[0126] The sending module 906 is used to send the second decryption key to the RAID card.
[0127] The sending module 906 can also be used to send a first decryption request to the target RAID card corresponding to the first encrypted hard disk.
[0128] The sending module 906 can also be used to send the prompt interface data to the display device, so that the display device can display the prompt interface data according to the prompt interface data.
[0129] For example, the sending module 906 can be used to perform... Figure 7 The S702, S703, or S705 shown.
[0130] The generation module 907 is used to generate prompt interface data when the target RAID card fails to decrypt the first encrypted hard drive.
[0131] For example, generation module 907 can be used to execute Figure 7 The S704 shown.
[0132] The replacement module 908 is used to replace the first key identifier in the preset correspondence with the encryption key corresponding to the second decryption key identifier when the controller successfully decrypts the first encrypted hard disk and at least one second encrypted hard disk using the first decryption key.
[0133] For example, replacement module 908 can be used to execute Figure 8 The S801 shown.
[0134] The solution shown in this application embodiment can be executed by controller 1000. For example... Figure 10 As shown, the controller 1000 may include an interface 1001 and a logic circuit 1002.
[0135] Interface 1001 is used to support communication between controller 1000 and other hardware. For example, it supports communication between the controller and the processor.
[0136] The logic circuit 1002 is used to execute the hard disk decryption method provided in this application embodiment. It reads information from the first register by sending a read instruction and the address information of the first register to the processor to obtain memory error information. The processor includes the first register. The read instruction is used to request the reading of information from the first register.
[0137] In one exemplary embodiment, a computer-readable storage medium is also provided for storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement all or part of the steps in the above-described hard disk decryption method. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, or an optical data computing device, etc.
[0138] In one exemplary embodiment, a computer program product or computer program is also provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computing device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computing device to perform the aforementioned actions. Figures 6-8 All or part of the steps of the method shown in any of the embodiments.
[0139] In some embodiments, the methods shown in this application can be implemented as computer program instructions encoded in a machine-readable format on a computer-readable storage medium or on other non-transitory media or articles of art.
[0140] This application also provides a chip system 1100, such as... Figure 11 As shown, the chip system 1100 includes at least one processor 1101 and at least one interface circuit 1102.
[0141] As an example, when the chip system 1100 includes a processor and an interface circuit, the processor can be... Figure 11 The processor 1101 shown in the solid box (or the processor 1101 shown in the dashed box) can be an interface circuit. Figure 11 The interface circuit 1102 is shown in the solid box (or the interface circuit 1102 shown in the dashed box). When the chip system 1100 includes two processors and two interface circuits, then the two processors include... Figure 11 The processor 1101 shown in the solid box and the processor 1101 shown in the dashed box, these two interface circuits include Figure 11 Interface circuit 1102 shown in solid boxes and interface circuit 1102 shown in dashed boxes. No limitations are imposed on this.
[0142] Processor 1101 and interface circuit 1102 can be interconnected via a line. For example, interface circuit 1102 can be used to receive signals. Alternatively, interface circuit 1102 can be used to send signals to other devices (e.g., processor 1101). For instance, interface circuit 1102 can read computer instructions stored in memory and send those instructions to processor 1101. Processor 1101 executes the instructions and, in conjunction with input / output devices, implements the various steps in the above embodiments, such as implementing... Figures 3-5 The steps performed in any of the method embodiments shown herein. Of course, the chip system may also include other discrete devices, and this application embodiment does not specifically limit this.
[0143] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0144] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0145] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units, meaning it can be located in one place or distributed across multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0146] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially or in other words, the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A hard disk decryption method, characterized in that, The method includes: Receive a first decryption key, which is used to decrypt the first encrypted hard disk; Query at least one second encrypted hard disk that has the same first key identifier as the first encrypted hard disk; wherein, the encrypted hard disk and the key identifier have a preset correspondence; The first decryption key and the first decryption request are sent to the target RAID card; the first decryption request is used to instruct the target RAID card to decrypt the first encrypted hard disk and the at least one second encrypted hard disk according to the first decryption key; the target RAID card is used to manage the first encrypted hard disk and the at least one second encrypted hard disk.
2. The hard disk decryption method according to claim 1, characterized in that, The first key identifier is the key identifier of the encryption key corresponding to the first decryption key, and the encryption key is the encryption key used to encrypt the first encrypted hard disk.
3. The hard disk decryption method according to claim 1 or 2, characterized in that, Before receiving the first decryption key, the method further includes: Obtain the key identifier corresponding to each encrypted hard drive from the hard drive information of each encrypted hard drive; The preset correspondence is generated by using the hard drive identifier of each encrypted hard drive and the key identifier corresponding to each encrypted hard drive.
4. The hard disk decryption method according to claim 1, characterized in that, Before receiving the first decryption key, the method further includes: If the target RAID card corresponding to the first encrypted hard drive fails to decrypt the first encrypted hard drive, a prompt interface data is generated; The prompt interface data is sent to the display device so that the display device displays the prompt interface data; the prompt interface includes the hard drive identifier of the first encrypted hard drive and an input area for the first decryption key; the input area is used for the user to input the first decryption key.
5. The hard disk decryption method according to claim 1, characterized in that, The method further includes: Obtain the set of decryption keys stored in the encryption server, the set of decryption keys including at least one decryption key; Obtain a second decryption key corresponding to the target RAID card from the decryption key set, and send the second decryption key to the target RAID card; the target RAID card is used to manage the first encrypted hard drive and the at least one second encrypted hard drive; If the first encrypted hard disk and the at least one second encrypted hard disk are successfully decrypted using the first decryption key, the first key identifier corresponding to the first encrypted hard disk and the second encrypted hard disk is replaced with the second key identifier corresponding to the second decryption key.
6. The hard disk decryption method according to claim 5, characterized in that, The method further includes: A second decryption request is sent to the target RAID card; the second decryption request is used to instruct the target RAID card to decrypt at least one encrypted hard drive managed by the target RAID card according to the second decryption key.
7. A computing device, characterized in that, include: The controller and multiple encrypted hard drives; the multiple encrypted hard drives include a first encrypted hard drive and a second encrypted hard drive; The controller is used to execute the hard disk decryption method according to any one of claims 1-6.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the hard disk decryption method as described in any one of claims 1-6.
Citation Information
Patent Citations
Data transmission method and device and electronic equipment
CN114844632A