An in-machine encryption storage system and encryption method
By introducing an on-device encrypted storage scheme that combines switching blades, compute blade storage, and network-attached storage into the storage system, and combining it with SM4 encryption technology, the shortcomings of existing storage systems in terms of data security are addressed. This enables fast and secure data encryption and key management, thereby improving the overall system security.
Patent Information
- Application Number
- CN202410764763.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-14
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-06-14
AI Technical Summary
Existing storage systems are inadequate in terms of data security and privacy protection. Especially in the complex international environment, there is an urgent need for an encrypted storage solution to improve the level of national information security.
The on-board encrypted storage system employs swap blade, compute blade storage, and network-attached storage, combined with SM4 encryption technology. It achieves hardware and software encryption of data through NVMe hard drives and offload cards, and supports password distribution and data protection.
It achieves improved data security and encryption speed while maximizing overall storage capacity and allowing for flexible expansion. The key can be hard-destroyed in an emergency, ensuring high data security.
Smart Images

Figure CN118364494B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer science, and specifically relates to an internal encrypted storage system and encryption method. Background Technology
[0002] Storage system design is a complex and comprehensive process, involving hardware selection, architecture configuration, data redundancy, backup strategies, and many other aspects. In the era of big data and distributed computing, networked data storage is an inevitable result of technological development and demand.
[0003] Currently, several mature storage system design solutions exist, including Direct Attached Storage (DAS), Storage Area Network (SAN), Network Attached Storage (NAS), and Redundant Array of Independent Disks (RAID). DAS is a storage architecture that directly connects storage devices to a host or server. SAN is a dedicated high-speed network architecture used to connect storage devices and servers, providing shared storage resources and supporting fast and reliable data access. NAS is a network-based storage device that provides file-level storage services by connecting to a server or host via a local area network. RAID is a data storage technology that combines multiple independent hard drives to provide data redundancy and reliable storage services.
[0004] With the development of information technology, data security and privacy protection have become increasingly important issues. Especially in the current complex international environment, having an independent and controllable encrypted storage system or encryption method can improve the level of national information security.
[0005] Therefore, there is an urgent need for an encrypted storage technology solution that can solve the above problems. Summary of the Invention
[0006] To address the shortcomings of the existing technology, this application provides an in-machine encrypted storage system and encryption method. Under the premise of maximizing the overall storage capacity and flexible expansion, it uses blade swapping to distribute passwords between the storage of each computing blade and the network-attached storage, and uses SM4 encryption technology to achieve security verification and data protection of the entire system.
[0007] The technical effect to be achieved in this application is accomplished through the following solution:
[0008] According to a first aspect of this application, an in-machine encrypted storage system is provided, comprising a switching blade, a computing blade storage, and network-attached storage, wherein the network-attached storage is connected to the switching blade, and a plurality of the computing blade storages are connected to the switching blade, wherein:
[0009] The computing blade storage uses an NVME hard drive as the storage controller chip, and performs encryption processing on the hardware modules and software encryption processing on the data.
[0010] The network-attached storage includes a storage blade, onboard storage mounted on the storage blade, and an offload card and USB extended storage connected to the storage blade. The onboard storage uses an NVMe hard drive as the storage controller chip, encrypts the hardware module, and performs software encryption on the data. The offload card stores the key of the NVMe hard drive and is capable of both soft and hard destruction.
[0011] The switching blade uses a PCIe controller that supports SM4 functionality to encrypt the network-attached storage.
[0012] Preferably, the NVMe hard drive includes an SM4 module, an SM3 module, and an SM2 module, wherein:
[0013] The SM2 module is used to perform public-key cryptography algorithms based on elliptic curve cryptography, including elliptic curve digital signatures, elliptic curve key exchange protocols, and elliptic curve public-key encryption algorithm implementations.
[0014] The SM3 module is used to perform cryptographic hash algorithms, including the generation and verification of digital signatures and authentication codes for verification messages, as well as the generation of random numbers.
[0015] The SM4 module is used to perform block symmetric cryptography algorithms, including data encryption and decryption operations.
[0016] Preferably, the onboard storage adopts RAID5 redundant storage, the small capacity area of the onboard storage uses NOR Flash, and the FPGA is used to manage the data and perform encryption and decryption on the application software.
[0017] Preferably, the storage blade is provided with a destruction control module, which is used to perform hardware destruction of the unloading card and the small capacity area of the onboard storage according to the externally input trigger signal. The small capacity area is used to store keys.
[0018] Preferably, the destruction control module includes a destruction voltage connected to the Flash chip and an operating voltage connected to the Flash chip via a protection diode. The destruction voltage is used to apply a 28V, 5A power supply to the Flash chip according to a trigger signal.
[0019] Preferably, the switching blade uses a CTC7132 chip as the main control chip. The main control chip is connected to the backplane VPX connector through a physical layer chip. The backplane VPX connector is equipped with 16 10G BASE-KR ports, 14 1000Base-T ports, 16 1000Base-X ports, 2 10GBase-X ports, 1 serial port, 1 management port, and 1 health management port.
[0020] According to a second aspect of this application, an on-machine encrypted storage method employing the above-described on-machine encrypted storage system is provided, comprising the following steps:
[0021] Step 1: Deploy the client of the password management software on the computing blade storage and the storage blade, deploy the server of the password management software on the storage blade, and store the key in the small capacity area of the offload card;
[0022] Step 2: The server obtains the key from the unloading card, encrypts the key, and sends it to the client; the client decrypts the encrypted key into a password, injects the password into the computing blade storage and the hardware layer of the storage blade, and realizes read and write operations on the hard disk through the password;
[0023] Step 3: After the client changes the password as required, it encrypts the changed password into a key and reports it to the server for storage.
[0024] Preferably, step 3 specifically includes:
[0025] The password and a random number inside the password are encrypted using SM3 and SM4 to obtain a hash value, which is then used as the key.
[0026] The key is reported to the server, which then sends the key to a small storage area on the offload card.
[0027] Preferably, the method further includes the following steps:
[0028] After the destruction signal is triggered at the client end, the destruction signal is sent to the server end;
[0029] The server parses the destruction signal and destroys the data of the corresponding computing blade storage and / or storage blade based on the parsing result.
[0030] Preferably, the data destruction includes hard destruction of the small capacity area of the unloading card, and soft destruction of the computing blade storage and storage blade.
[0031] According to one embodiment of this application, the beneficial effects of the in-machine encrypted storage system or method of this application are that the encryption speed is fast and the security is higher when using domestically produced security encryption chips. The key is directly embedded in the chip and the data is stored as ciphertext in the SSD. Password management can be performed on a specific namespace, thereby achieving partition protection where the operating system's namespace is not encrypted and the data's namespace is encrypted. The password is stored in a small capacity area of the unmount card, which can be hard-destroyed in an emergency, thus improving security. Attached Figure Description
[0032] To more clearly illustrate the embodiments of this application or the existing technical solutions, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 This is a structural block diagram of an in-machine encrypted storage system according to an embodiment of this application;
[0034] Figure 2 This is a schematic diagram of the destruction circuit in one embodiment of this application;
[0035] Figure 3 This is a flowchart of an in-machine encrypted storage method in one embodiment of this application. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0037] like Figure 1 As shown, an embodiment of the in-machine encrypted storage system of this application includes a switching blade, a computing blade storage, and a network-attached storage. The network-attached storage is connected to the switching blade, and a plurality of computing blade storages are connected to the switching blade, wherein:
[0038] The computing blade storage uses NVMe hard drives as the storage controller chip, and performs encryption processing on the hardware modules and software encryption processing on the data.
[0039] Network-attached storage includes storage blades, onboard storage mounted on the storage blades, and offload cards and USB extended storage connected to the storage blades. The onboard storage uses NVMe hard drives as the storage controller chip, encrypts the hardware modules, and performs software encryption on the data. The offload card stores the keys for the NVMe hard drives and can perform both soft and hard destruction.
[0040] The blade swapping system uses a PCIe controller that supports SM4 functionality to implement encryption for network-attached storage.
[0041] In one embodiment of this application, the computing blade storage uses a SATA interface and employs a Yixin NVMe hard drive that supports the national cryptographic encryption scheme to encrypt the data. This encryption function primarily encrypts the data written to the flash memory, i.e., it encrypts the hardware module. Furthermore, the written data can be encrypted at the application software layer to achieve software encryption of the data.
[0042] NVMe hard drives include SM4, SM3, and SM2 modules, among which:
[0043] The SM2 module is used for public-key cryptography algorithms based on elliptic curve cryptography, including SM2-1 elliptic curve digital signature, SM2-2 elliptic curve key exchange protocol, and SM2-3 elliptic curve public-key encryption algorithm, which are used for digital signature, key negotiation and data encryption functions, respectively, and the key length is 256 bits.
[0044] The SM3 module is used for cryptographic hash algorithms, including the generation and verification of digital signatures and authentication codes for verification messages in commercial cryptographic applications, as well as the generation of random numbers, meeting the security requirements of various cryptographic applications. It generates hash values of 256 bits, compared to the traditional MD5 output of 128 bits and the SHA-1 algorithm's output of 160 bits. Therefore, the SM3 algorithm offers higher security than MD5 and SHA-1, ensuring the security of the hash algorithm.
[0045] The SM4 module is used for block symmetric cryptography algorithms, including encryption and decryption operations, to ensure the confidentiality of data and information. The SM4 algorithm has the same key length and block length of 128 bits as the AES algorithm.
[0046] The Yixin NVMe hard drive adopts a layered design model to achieve security layering from the bottom chip to the middle firmware and then to the upper application. It also supports the isolation and encryption of the operating system and data disk, so that they do not interfere with each other.
[0047] In one embodiment of this application, the storage blade storage solution consists of three parts: onboard storage, an offloadable card, and USB extended storage. The onboard storage solution is consistent with the computing blade storage, featuring a built-in NVMe hard drive. Read and write operations on the hard drive are achieved using encrypted / decrypted passwords. The removable storage card stores the NVMe hard drive's key and has a hard-kill function, allowing for key destruction in emergencies and improving data storage security. The USB extended storage provides a USB expansion interface for the entire storage system, expanding its capacity.
[0048] The onboard storage disks include large-capacity and small-capacity areas. The large-capacity area uses an onboard key authentication scheme for encryption. Before booting, secure authentication is required. When using NVMe hard drives, a user password must be set to generate a key, which is then verified upon subsequent logins to use the system normally. This effectively prevents unauthorized users from bypassing the operating system to access sensitive information. RAID 5 redundant storage is used to improve data reliability.
[0049] The small-capacity onboard storage uses NOR Flash, and data management is achieved through FPGA. Application software encryption can be used, with encryption and decryption performed separately during software writing and reading.
[0050] The unloading card has a large-capacity area and a small-capacity area, and it is removable from the front panel of the chassis. For data security reasons, read / write operations must be stopped during insertion and removal. Furthermore, it involves local data management and external unloading device data management functions. At the application software layer, written data is encrypted to achieve software encryption. The small-capacity area is used to store the key, and it employs external thermal destruction to ensure physical destruction of the storage medium within 1 second.
[0051] Physical destruction is carried out through the destruction control module on the storage blade, which performs hardware destruction on the unloading card and the small capacity area of the onboard storage based on the externally input trigger signal.
[0052] The destruction control module includes a destruction voltage connected to the Flash chip and a working voltage connected to the Flash chip via a protection diode to prevent other circuits from being burned out by high voltage. The destruction voltage is used to apply a 28V, 5A power supply according to the trigger signal to sequentially destroy the core component Flash of the NAS shared storage small capacity area and the removable memory card.
[0053] like Figure 2As shown, the destruction circuit in the destruction control module applies a destruction voltage (VCC_P) to the Flash memory, using a high-voltage, high-current signal of 28V and 5A to cause irreversible physical damage to the chip. VCCF and VCCFQ are the voltages applied to the Flash memory during normal operation. The D15 and D16 connected in series in the circuit are unidirectional conductors to prevent the high voltage from damaging the power supply chip on the board and further affecting the power supply.
[0054] Soft erasure of flash memory involves the main controller of the electronic disk rapidly erasing the entire flash drive. This is done by executing the erasure operations on the flash storage nodes in parallel and in a pipelined manner, without significantly increasing power consumption, to achieve irreversible data destruction. Software erasure erases all user data, partition tables, and other information, but retains the disk's firmware. After repartitioning and formatting, the disk can still be used normally. The specific process is as follows:
[0055] The soft destroy software client triggers a soft destroy signal. Once the soft destroy signal is triggered, a soft destroy command is sent to the soft destroy software server. The soft destroy software server receives and parses the command, and transmits the destroy signal to the destroy circuit through GPIO in the corresponding operating system. The destroy signal triggers the electronic disk destroy function. Once the destroy signal is triggered, all data in the Flash memory of the electronic disk can be cleared to 0 within a short period of time.
[0056] The data destruction function will erase all user information on the SSD, but will not affect the controller firmware or damage any components within the SSD. Users can simply power it on again and format it to resume normal use. Based on actual testing, the data destruction time for compute nodes can be controlled within 10 seconds, and the destruction time for large-capacity shared storage areas on the NAS can be controlled within 20 seconds.
[0057] In one embodiment of this application, when a USB extended storage portion is connected to the USB 3.1 offload interface of the storage blade, the storage blade can automatically detect the access of the USB device, mount the storage block of the device to the system, and share it within the local area network with the support of NFS for access by other computing blades.
[0058] In this embodiment, the storage system design uses a switching blade to build a local area network (LAN) to achieve data transmission and sharing. The switching blade uses a CTC7132 chip as the main control chip, supporting SM4 (Chinese national cryptographic block symmetric cryptography algorithm). The main control chip is connected to the backplane VPX connector via a physical layer chip (PHY). The PHYs selected are YT8618, YT8614, and YT8521 from Yutai Automotive Technology Co., Ltd., and SF1204 from Nanfei Microelectronics Co., Ltd. The switching board provides 16 10G Base-KR ports, 14 1000Base-T ports, 16 1000Base-X ports, 2 10GBase-X ports, 1 serial port, 1 management port, 1 health management port, and PWM management to other slots via the backplane VPX connector. The front panel displays indicator lights. The entire board supports L2 and L3 switching, according to the single-board design specifications.
[0059] like Figure 3 As shown, one embodiment of this application discloses an on-machine encrypted storage method using the above-described on-machine encrypted storage system, comprising the following steps:
[0060] Step 1: Deploy the client of the password management software on the computing blade storage and the storage blade, deploy the server of the password management software on the storage blade, and store the key in the small capacity area of the offload card;
[0061] The client and server are both password management software, using a C / S architecture. After the system starts, it automatically completes the encryption and decryption operations on the hard drive. Communication between the various computing modules and storage modules is achieved through the TCP / IP protocol via a switch.
[0062] The client is used to receive the key reported by the server, i.e. the password distribution operation, and convert the key from ciphertext to plaintext password. Then, the password is injected into the hardware layer to complete the key transmission, decryption and injection functions. At the same time, the client acts as a password management UI to help users set, change and delete passwords (the modified password will be encrypted and sent to the server for processing).
[0063] The server is used to obtain the key for the small capacity area of the unloading card, encrypt the key and transmit it to the client in ciphertext. In addition, after receiving a new password, it is responsible for decrypting and storing the new password.
[0064] Step 2: The server obtains the key from the unloading card, encrypts the key, and sends it to the client; the client decrypts the encrypted key into a password, injects the password into the computing blade storage and the hardware layer of the storage blade, and realizes read and write operations on the hard disk through the password;
[0065] Step 3: After the client changes the password as required, it encrypts the changed password into a key and reports it to the server for storage.
[0066] Specifically: The password and a random number inside the password are encrypted using SM3 and SM4 to obtain a hash value, which is then used to form the key.
[0067] The encrypted key is reported to the server, which then sends the key to a small storage area on the offload card.
[0068] This method does not store the plaintext of the password. Instead, it calculates the hash of the password and an internal random number using Chinese cryptographic algorithms (SM2, SM3, and SM4) and only saves this hash value. Furthermore, the SM2, SM3, and SM4 calculations are performed using the hardware inside the chip and cannot be changed at the software level. Therefore, once a hash value is generated, the saved hash value is unique. When verifying the password, only the hash value generated by the correct password can be verified.
[0069] If you try to crack the disk using a brute-force approach, the disk will enter a permanent lock state on the 10th attempt, at which point the disk can no longer be unlocked using the set password.
[0070] In one embodiment of this application, the following steps are also included:
[0071] After the destruction signal is triggered on the client side, the destruction signal is sent to the server side;
[0072] The server parses the destruction signal and destroys the corresponding compute blade storage and / or storage blades based on the parsing results. Data destruction includes hard destruction of small capacity areas of the offload card and soft destruction of compute blade storage and storage blades.
[0073] In this embodiment, there are two types of passwords: ordinary user passwords and administrator passwords. Different passwords access corresponding physical partitions. If the password is incorrect, partitioning, reading, and writing operations on the encrypted disk are not possible; only with a correct password can normal access be granted.
[0074] There are 6 passwords for regular users, as follows:
[0075] Setting a password: In a newly created namespace or when the password has been deleted, you need to set a password.
[0076] Change Password: Once a password has been set and authentication has been successful, the password can be changed.
[0077] Delete Password: You can delete a password once it has been set and authentication has been successful.
[0078] Cancel authentication (also known as lock disk): This interface can be called to lock the namespace after a password has been set and authentication has been successful.
[0079] Authentication password (also known as unlock): After the disk is locked, an authentication password is required. Once the authentication is successful, the namespace will be unlocked.
[0080] Get password status: Get the current password status of the namespace.
[0081] There are two administrator passwords, as follows:
[0082] Change Password: The default administrator password is Starblaze-123, which can be changed by calling this API;
[0083] Delete Password: Used to delete passwords for all namespaces.
[0084] There are 5 password statuses, as follows:
[0085] No password status: The status of a newly created namespace or a namespace where the password has been deleted;
[0086] Unlocked status: The status after setting a password and successfully authenticating. The default status after setting a password is the successfully authenticated status. In this status, normal reading and writing are allowed.
[0087] Locked disk status: The disk is locked and authentication has been disabled. Read and write operations are not allowed in this state.
[0088] 10-Minute Locked State: This state is entered after five consecutive incorrect password attempts while the namespace is locked. Read and write operations are also disabled in this state. This state has two sub-states: First, if less than 10 minutes have passed since entering this state, password authentication is impossible. Second, if more than 10 minutes have passed since entering this state, password authentication can continue.
[0089] Permanent lock state: If the disk is locked for 10 minutes and the waiting time has expired, and you attempt to authenticate with 5 consecutive incorrect passwords, it will enter this state. Read and write operations are also disabled in this state.
[0090] The beneficial effects of the in-machine encrypted storage system or method of this application are that the encryption speed is fast and the security is higher when using domestic security encryption chips, and the key is directly embedded in the chip and the data is stored as ciphertext in the SSD;
[0091] Because it provides namespace-level password management, passwords can be managed individually for each namespace. This means that passwords can be set for partitions requiring encryption, while those without encryption can be used directly. This achieves partition protection where the operating system's namespace is unencrypted, but the data's namespace is encrypted.
[0092] The password is stored in a small area of the uninstallation card, which can be hard-destroyed in an emergency, thus enhancing security.
[0093] It should be noted that the above detailed descriptions are exemplary and intended to provide further explanation of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0094] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments according to this application. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0095] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that the embodiments of this application described herein can be implemented in sequences other than those illustrated or described herein.
[0096] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.
[0097] For ease of description, spatial relative terms such as "above," "on top of," "on the upper surface of," "above," etc., are used herein to describe the spatial positional relationship of a device or feature as shown in the figures to other devices or features. It should be understood that spatial relative terms are intended to encompass different orientations in use or operation beyond the orientation of the device as described in the figures. For example, if the device in the figures were inverted, a device described as "above" or "on top of" other devices or structures would subsequently be positioned as "below" or "under" other devices or structures. Thus, the exemplary term "above" can include both "above" and "below." The device may also be positioned in other different ways, such as rotated 90 degrees or in other orientations, and the spatial relative descriptions used herein will be interpreted accordingly.
[0098] In the detailed description above, reference has been made to the accompanying drawings, which form part of this document. In the drawings, similar symbols typically identify similar parts unless the context otherwise indicates otherwise. The illustrated embodiments described in the detailed specification, drawings, and claims are not intended to be limiting. Other embodiments may be used and other changes may be made without departing from the spirit or scope of the subject matter presented herein.
[0099] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. An in-machine encrypted storage system, characterized in that, This includes a switching blade, compute blade storage, and network-attached storage, wherein the network-attached storage is connected to the switching blade, and a plurality of compute blade storage units are connected to the switching blade, wherein: The computing blade storage uses an NVMe hard drive as the storage controller chip, and performs encryption processing on the hardware modules and software encryption processing on the data; the NVMe hard drive includes an SM4 module, an SM3 module, and an SM2 module, wherein: The SM2 module is used to perform public-key cryptography algorithms based on elliptic curve cryptography, including elliptic curve digital signatures, elliptic curve key exchange protocols, and elliptic curve public-key encryption algorithm implementations. The SM3 module is used to perform cryptographic hash algorithms, including the generation and verification of digital signatures and authentication codes for verification messages, as well as the generation of random numbers. The SM4 module is used to perform block symmetric cryptography algorithms, including data encryption and decryption operations; The network-attached storage includes a storage blade, onboard storage mounted on the storage blade, and an offload card and USB extended storage connected to the storage blade. The onboard storage uses an NVMe hard drive as the storage controller chip, encrypting the hardware module and the data via software encryption. The offload card stores the NVMe hard drive's key and is capable of both software and hardware destruction. The offload card is pluggable from the front panel of the chassis. The onboard storage uses RAID 5 redundancy, and its small capacity area uses NOR Flash. Data management and application software encryption / decryption are handled by an FPGA. A destruction control module is mounted on the storage blade to perform hardware destruction of the offload card and the small capacity area of the onboard storage based on an externally input trigger signal. The small capacity area stores the key and is destroyed using external thermal current. The destruction control module includes a destruction voltage connected to the Flash chip and an operating voltage connected to the Flash chip via a protection diode. The destruction voltage applies a 28V, 5A power supply to the Flash chip based on the trigger signal. The switching blade uses a PCIe controller supporting SM4 functionality to encrypt the network-attached storage; the switching blade uses a CTC7132 chip as the main control chip, which is connected to the backplane VPX connector through a physical layer chip. The backplane VPX connector is equipped with 16 10G BASE-KR ports, 14 1000Base-T ports, 16 1000Base-X ports, 2 10GBase-X ports, 1 serial port, 1 management port, and 1 health management port. In use, a client of password management software is deployed in the computing blade storage and the storage blade, and a server of password management software is deployed on the storage blade. The key is stored in a small capacity area of the offloading card. The server obtains the key from the offloading card, encrypts the key, and sends it to the client. The client decrypts the encrypted key into a password and injects the password into the hardware layer of the computing blade storage and the storage blade, thereby enabling read and write operations on the hard drive through the password.
2. An on-machine encrypted storage method using the on-machine encrypted storage system of claim 1, characterized in that, Includes the following steps: Step 1: Deploy the client of the password management software on the computing blade storage and the storage blade, deploy the server of the password management software on the storage blade, and store the key in the small capacity area of the offload card; Step 2: The server obtains the key from the uninstallation card, encrypts the key, and sends it to the client; The client decrypts the encrypted key into a password, injects the password into the computing blade storage and the hardware layer of the storage blade, and performs read and write operations on the hard drive through the password; Step 3: After the client changes the password as required, it encrypts the changed password into a key and reports it to the server for storage.
3. The in-machine encrypted storage method according to claim 2, characterized in that, Step 3 specifically involves: The password and a random number inside the password are encrypted using SM3 and SM4 to obtain a hash value, which is then used as the key. The key is reported to the server, which then sends the key to a small storage area on the offload card.
4. The in-machine encrypted storage method according to claim 2, characterized in that, It also includes the following steps: After the destruction signal is triggered at the client end, the destruction signal is sent to the server end; The server parses the destruction signal and destroys the data of the corresponding computing blade storage and / or storage blade based on the parsing result.
5. The in-machine encrypted storage method according to claim 4, characterized in that, The data destruction includes hard destruction of small capacity areas of the offload card, and soft destruction of compute blade storage and storage blades.
Citation Information
Patent Citations
Data encryption key acquisition and recovery method and data read-write method of solid state disk
CN112417491A
Storage blade and blade server
CN214846518U