Data Encryption Reading and Writing Method, Device and Electronic Device for Solid State Drives

By using multiple keys and complex key management mechanisms on solid-state drives, the problem of poor data security in the prior art is solved, and higher data security and protection complexity are achieved.

CN119128932BActive Publication Date: 2025-06-17V & G INFORMATION SYSTEM CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411151439.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2025-06-17
Estimated Expiration
2044-08-21

AI Technical Summary

Technical Problem

Existing SSDs are usually protected with the same simple password when encrypting data, resulting in poor data security.

Method used

Multiple data are encrypted by using multiple keys on a solid state drive and encrypted and protected by the complex keys generated by the key management platform. The client obtains key transformation information in a sandbox environment and generates a second key to decrypt the data encryption key, thereby decrypting the encrypted data in the solid-state hard disk.

Benefits of technology

Improve data security, and by using multiple keys and complex key management mechanisms, the amount of data interaction between the key management platform and the client is reduced, and the complexity of data protection is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119128932B_ABST
    Figure CN119128932B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, and electronic device for encrypting and reading / writing data of a solid-state drive. The method includes: the solid-state drive stores encrypted data, and K pieces of encrypted data are encrypted using K data encryption keys. The K data encryption keys are encrypted using K second keys. The K second keys are generated based on a first key and key transformation information. The method includes: the client obtains a data usage request for the K pieces of encrypted data of the solid-state drive and uploads it; the key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive. The present invention uses the first key stored in the key management platform and the key transformation information stored in the client to generate multiple second keys to respectively encrypt and protect different data encryption keys, improving data security and reducing the amount of data exchanged between the key management platform and the client.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a method, device, and electronic device for encrypting and reading / writing data of a solid-state drive. Background Art

[0002] A solid-state drive is a device for storing data. Existing solid-state drives can store plaintext data and encrypted data, and users can encrypt data by setting a password.

[0003] Existing solutions usually use the same simple password to protect a large amount of data, resulting in poor data security. Summary of the Invention

[0004] The present invention provides a method, device, and electronic device for encrypting and reading / writing data of a solid-state drive, which can use multiple keys to encrypt multiple data respectively, thereby improving data security.

[0005] To solve the above technical problems, the present invention is implemented as follows:

[0006] In a first aspect, the present application provides a method for encrypting and reading / writing data of a solid-state drive. The solid-state drive stores encrypted data, and K pieces of encrypted data are encrypted using K data encryption keys. The K data encryption keys are encrypted and stored in a client using K second keys. The K second keys are generated based on a first key managed by a key management platform and key transformation information stored in the client. The method includes: the client obtains a data usage request for K pieces of encrypted data of the solid-state drive and uploads it to the key management platform; the key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive; the client obtains the key transformation information corresponding to the K pieces of encrypted data in a sandbox, and generates K second keys based on the first key and the K key transformation information; the client decrypts the K encrypted data encryption keys based on the K second keys in the sandbox, so as to decrypt the K pieces of encrypted data in the solid-state drive based on the K data encryption keys.

[0007] Preferably, the key management platform sends key-related information to the client according to the data usage request, including: the key management platform obtains the first key and a new first key for decrypting the K pieces of encrypted data next time according to the data usage request, takes them as key-related information, and sends them to the client; the method further includes: after the client decrypts the K encrypted data encryption keys based on the first key, the client encrypts the K data encryption keys based on the new first key in the sandbox and stores them in the client.

[0008] Preferably, the key management platform obtains a first key and a new first key for decrypting K encrypted data next time according to a data usage request as key-related information, including: the key management platform obtains a first key and a new first key for decrypting K encrypted data next time according to the data usage request; the key management platform encrypts the new first key with the first key to form encrypted information, so as to determine key-related information according to the first key and the encrypted information; the method further includes: the client extracts the first key and the encrypted information from the key-related information, and decrypts the encrypted information with the first key to obtain the first key and the new first key.

[0009] Preferably, the key management platform obtains a first key and a new first key for decrypting K encrypted data next time according to a data usage request as key-related information, including: the key management platform obtains a first key, a new first key for decrypting K encrypted data next time and a random number according to the data usage request, where the random number is used to decrypt the encrypted information in the key-related information sent by the key management platform next time; the key management platform encrypts the new first key with the first key and the random number in the key-related information sent to the client last time to form encrypted information, so as to determine key-related information according to the first key, the encrypted information and the random number.

[0010] Preferably, the method further includes: the client extracts the first key, the encrypted information and the random number from the key-related information; the client saves the random number and extracts the target random number in the key-related information received last time; the client decrypts the encrypted information with the target random number and the first key to obtain the first key and the new first key.

[0011] Preferably, the method further includes: if the client fails to find the target random number in the key-related information received last time after saving the random number, the client generates a first public key and a first private key through a sandbox and shares the first public key with the key management platform; the key management platform obtains the target random number, encrypts it with the first public key and returns it to the client; the client receives the target random number encrypted with the first public key and decrypts it with the first private key to obtain the target random number.

[0012] Preferably, the method further includes: the client obtains a data encryption request for N pieces of data and uploads it to the key management platform; the key management platform feeds back a first key to the client according to the data encryption request; the client receives a first key in the sandbox and generates N different key transformation information, so as to generate N second keys based on a first key and N different key transformation information; the client generates N data encryption keys in the sandbox, encrypts N pieces of data respectively to obtain N encrypted data, and saves them to the solid-state drive; the client encrypts N data encryption keys with N second keys in the sandbox and saves them on the client.

[0013] In a second aspect, the present application provides a data encryption read / write device for a solid-state drive. The solid-state drive stores encrypted data. K pieces of encrypted data are encrypted with K data encryption keys. K data encryption keys are encrypted and saved on the client with K second keys. The K second keys are generated based on a first key managed by the key management platform and key transformation information stored on the client. The device includes: a usage request acquisition module, configured to obtain a data usage request for K pieces of encrypted data of the solid-state drive through the client and upload it to the key management platform; a first key sending module, configured to send key-related information to the client through the key management platform according to the data usage request, and the key-related information includes the first key of the solid-state drive; a second key generation module, configured to obtain key transformation information corresponding to K pieces of encrypted data in the sandbox through the client, and generate K second keys based on the first key and K key transformation information; an encrypted data decryption module, configured to decrypt K encrypted data encryption keys in the sandbox through the client according to K second keys, so as to decrypt K pieces of encrypted data in the solid-state drive according to K data encryption keys.

[0014] In a third aspect, the present application provides an electronic device, including: a memory and at least one processor; the memory is used to store computer execution instructions; the at least one processor is used to execute the computer execution instructions stored in the memory, so that the at least one processor executes the method described in the first aspect.

[0015] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in the first aspect is implemented.

[0016] This application can be applied to the data management scenario of a solid-state drive. Multiple keys can be used to encrypt multiple data of the solid-state drive, and a relatively complex key generated by a key management platform is used to encrypt the key of the solid-state drive, thereby protecting the key and the data. Specifically, during the encryption process, the user can initiate an encryption request for K pieces of data. The client generates K data encryption keys and encrypts the K pieces of data respectively to form encrypted data. The client can also apply to the key management platform for a first key, and generate K second keys based on the first key and K key transformation information, and use the K second keys to encrypt the K data encryption keys to protect the K data encryption keys of the client. During decryption, the client obtains a data usage request for K encrypted data of the solid-state drive and uploads it to the key management platform. The key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive. The client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys based on the first key and the K key transformation information. The client decrypts the K encrypted data encryption keys based on the K second keys in the sandbox, and decrypts the K encrypted data in the solid-state drive based on the K data encryption keys. This solution uses the first key stored in the key management platform and the key transformation information stored in the client to generate multiple second keys to encrypt and protect different data encryption keys respectively, improving the security of the data and reducing the amount of data exchanged between the key management platform and the client. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The illustrative embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0018] Figure 1 is a flowchart of a data encryption and reading / writing method for a solid-state drive according to an embodiment of the present application;

[0019] Figure 2 is a schematic structural diagram of a data encryption and reading / writing device for a solid-state drive according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0021] This application can be applied to the data management scenario of a solid-state drive. Multiple keys can be used to encrypt multiple data of the solid-state drive, and a relatively complex key generated by the key management platform can be used to encrypt the keys of the solid-state drive, thereby protecting the keys and data. Specifically, during the encryption process, the user can initiate an encryption request for K pieces of data. The client generates K data encryption keys and encrypts the K pieces of data respectively to form encrypted data. The client can also apply to the key management platform for a first key, and generate K second keys based on the first key and K key transformation information, and use the K second keys to encrypt the K data encryption keys to protect the K data encryption keys of the client. During decryption, the client obtains a data usage request for K encrypted data of the solid-state drive and uploads it to the key management platform. The key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive. The client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys based on the first key and the K key transformation information. The client decrypts the K encrypted data encryption keys according to the K second keys in the sandbox, and decrypts the K encrypted data in the solid-state drive according to the K data encryption keys. This solution uses the first key stored in the key management platform and the key transformation information stored in the client to generate multiple second keys to encrypt and protect different data encryption keys respectively, improving the security of the data and reducing the amount of data exchanged between the key management platform and the client.

[0022] Specifically, an embodiment of this application provides a method for encrypting and reading / writing data of a solid-state drive. Among them, the solid-state drive stores encrypted data. The K encrypted data are encrypted using K data encryption keys. The K data encryption keys are encrypted and stored in the client using K second keys. The K second keys are generated based on the first key managed by the key management platform and the key transformation information stored in the client. As Figure 1 shown, the method includes:

[0023] Step 102: The client obtains a data usage request for K encrypted data of the solid-state drive and uploads it to the key management platform.

[0024] Step 104: The key management platform sends key-related information to the client according to the data usage request. The key-related information includes the first key of the solid-state drive.

[0025] Step 106: The client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys based on the first key and the K key transformation information.

[0026] Step 108: The client decrypts the K encrypted data encryption keys according to the K second keys in the sandbox, so as to decrypt the K encrypted data in the solid-state drive according to the K data encryption keys.

[0027] This application can be applied to the data management scenario of a solid-state drive. Multiple keys can be used to encrypt multiple data of the solid-state drive, and a relatively complex key generated by the key management platform is used to encrypt the key of the solid-state drive to form protection for the key and data. Specifically, in the encryption process, the user can initiate an encryption request for K data. The client generates K data encryption keys and encrypts the K data respectively to form encrypted data. The client can also apply to the key management platform for a first key, generate K second keys according to the first key and K key transformation information, and use the K second keys to encrypt the K data encryption keys to protect the K data encryption keys of the client. When decrypting, the client obtains the data usage request for the K encrypted data of the solid-state drive and uploads it to the key management platform; the key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive; the client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys according to the first key and the K key transformation information; the client decrypts the K encrypted data encryption keys according to the K second keys in the sandbox, so as to decrypt the K encrypted data in the solid-state drive according to the K data encryption keys. This solution uses the first key stored in the key management platform and the key transformation information stored in the client to generate multiple second keys to encrypt and protect different data encryption keys respectively, improving the security of the data and reducing the amount of data exchanged between the key management platform and the client.

[0028] In addition to sending the first key for decrypting the current data, the key management platform can also send a new first key for the next decryption, so that the key management platform sends different keys each time, and the second key of the client is also updated synchronously, thus better protecting the data encryption key. Specifically, as an optional embodiment, the key management platform sends key-related information to the client according to the data usage request, including: the key management platform obtains the first key and a new first key for decrypting the K encrypted data next time according to the data usage request, as the key-related information, and sends it to the client; the method further includes: after the client decrypts the K encrypted data encryption keys according to the first key, the client encrypts the K data encryption keys with the new first key in the sandbox and saves them in the client. The sandbox is a secure computing environment that can protect the data and computing process in the sandbox. This solution can re-encrypt and save according to the new first key after decrypting the data encryption key for use in the next decryption.

[0029] When the key management platform distributes the first key and the new first key, it can encrypt the new first key based on the first key to enhance data security. Specifically, as an optional embodiment, the key management platform obtains the first key and the new first key for decrypting the K encrypted data next time according to the data usage request as key-related information, including: the key management platform obtains the first key and the new first key for decrypting the K encrypted data next time according to the data usage request; the key management platform encrypts the new first key based on the first key to form encrypted information, so as to determine the key-related information based on the first key and the encrypted information; the method further includes: the client extracts the first key and the encrypted information from the key-related information, and decrypts the encrypted information based on the first key to obtain the first key and the new first key.

[0030] In addition to encrypting the new first key with the first key, this solution can also use a random number for encryption, and this random number has nothing to do with the random number carried by the key-related information this time, but is related to the random number carried by the previous key-related information, so as to enhance data security. Specifically, as an optional embodiment, the key management platform obtains the first key and the new first key for decrypting the K encrypted data next time according to the data usage request as key-related information, including: the key management platform obtains the first key, the new first key for decrypting the K encrypted data next time and a random number according to the data usage request, and the random number is used to decrypt the encrypted information in the key-related information sent by the key management platform next time; the key management platform encrypts the new first key based on the first key and the random number in the key-related information sent to the client last time to form encrypted information, so as to determine the key-related information based on the first key, the encrypted information and the random number.

[0031] After the client receives the key-related information, it can extract the random number from the key-related information received last time and participate in the decryption of the encrypted information of the current key-related information to obtain a new first key. Specifically, as an optional embodiment, the method further includes: the client extracts a first key, encrypted information, and a random number from the key-related information; the client saves the random number and extracts the target random number from the key-related information received last time; the client decrypts the encrypted information based on the target random number and the first key to obtain the first key and the new first key. If the client loses the target random number, the client cannot decrypt the new first key. In this solution, a key pair can be generated according to the sandbox. The key pair includes a public key and a private key, and the target random number can be obtained from the key management platform by means of public key encryption and private key decryption. Specifically, as an optional embodiment, the method further includes: if the client fails to find the target random number in the key-related information received last time after saving the random number, the client generates a first public key and a first private key through the sandbox and shares the first public key with the key management platform; the key management platform obtains the target random number, encrypts it with the first public key, and returns it to the client; the client receives the target random number encrypted with the first public key and decrypts it with the first private key to obtain the target random number.

[0032] During the encryption process, the user can initiate an encryption request for K pieces of data. The client generates K data encryption keys and encrypts the K pieces of data respectively to form encrypted data. The client can also apply to the key management platform for a first key to generate K second keys based on the first key and K key transformation information, and use the K second keys to encrypt the K data encryption keys to protect the K data encryption keys of the client. Specifically, as an optional embodiment, the method further includes: the client obtains the data encryption requests of N pieces of data and uploads them to the key management platform; the key management platform feeds back a first key to the client according to the data encryption request; the client receives a first key in the sandbox and generates N different key transformation information to generate N second keys based on a first key and N different key transformation information; the client generates N data encryption keys in the sandbox, encrypts the N pieces of data respectively to obtain N encrypted data, and saves them to the solid-state drive; the client encrypts the N data encryption keys with N second keys in the sandbox and saves them on the client.

[0033] Based on the above embodiments, an embodiment of the present application further provides a data encryption reading and writing device for a solid-state drive, which is characterized in that the solid-state drive stores encrypted data. The K pieces of encrypted data are encrypted with K data encryption keys. The K data encryption keys are encrypted and saved on the client with K second keys. The K second keys are generated based on the first key managed by the key management platform and the key transformation information stored on the client, asFigure 2 As shown, the device includes:

[0034] A usage request acquisition module 202, configured to obtain a data usage request for K encrypted data of the solid-state drive through a client and upload it to the key management platform.

[0035] A first key sending module 204, configured to send key-related information to the client through the key management platform according to the data usage request, where the key-related information includes a first key of the solid-state drive.

[0036] A second key generation module 206, configured to obtain key transformation information corresponding to the K encrypted data in a sandbox through the client, and generate K second keys according to the first key and the K key transformation information.

[0037] An encrypted data decryption module 208, configured to decrypt the K encrypted data encryption keys in the sandbox through the client according to the K second keys, so as to decrypt the K encrypted data in the solid-state drive according to the K data encryption keys.

[0038] The implementation manner of the embodiment of this application is similar to the implementation manner of the above method embodiment. The specific implementation manner can refer to the specific implementation manner of the above method embodiment, and will not be elaborated here.

[0039] This application can be applied to the data management scenario of a solid-state drive. Multiple keys can be used to encrypt multiple data of the solid-state drive, and a relatively complex key generated by a key management platform is used to encrypt the key of the solid-state drive to form protection for the key and data. Specifically, during the encryption process, the user can initiate an encryption request for K data. The client generates K data encryption keys and encrypts the K data respectively to form encrypted data. The client can also apply to the key management platform for a first key, and generate K second keys based on the first key and K key transformation information, and use the K second keys to encrypt the K data encryption keys to protect the K data encryption keys of the client. When decrypting, the client obtains a data usage request for the K encrypted data of the solid-state drive and uploads it to the key management platform; the key management platform sends key-related information to the client according to the data usage request, and the key-related information includes the first key of the solid-state drive; the client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys based on the first key and the K key transformation information; the client decrypts the K encrypted data encryption keys according to the K second keys in the sandbox, so as to decrypt the K encrypted data in the solid-state drive according to the K data encryption keys. This solution uses the first key stored in the key management platform and the key transformation information stored in the client to generate multiple second keys to encrypt and protect different data encryption keys respectively, improving the security of the data and reducing the amount of data exchanged between the key management platform and the client.

[0040] Based on the above embodiments, the present application further provides an electronic device, including: a memory and at least one processor; the memory is used to store computer execution instructions; the at least one processor is used to execute the computer execution instructions stored in the memory, so that the at least one processor executes the method as described in the above embodiments.

[0041] The embodiment of the present invention further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it realizes each process of the above data processing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium, such as a read-only memory (Read-Only Memory, abbreviated as ROM), a random access memory (Random ACGess Memory, abbreviated as RAM), a magnetic disk or an optical disc, etc.

[0042] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0043] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0044] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0045] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0046] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0047] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flashRAM). The memory is an example of computer-readable media.

[0048] A computer-readable medium includes permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0049] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.

[0050] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0051] The above are only embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A method for encrypting and reading data of a solid state drive, characterized in that: The solid state drive stores encrypted data, K encrypted data are encrypted using K data encryption keys, the K data encryption keys are encrypted using K second keys and stored on a client, the K second keys are generated based on a first key managed by a key management platform and key transformation information stored on the client, and the method includes: The client obtains a data usage request for K encrypted data on the SSD and uploads it to the key management platform; The key management platform sends key-related information to the client according to the data use request, and the key-related information includes the first key of the solid-state drive; The client obtains the key transformation information corresponding to the K encrypted data in the sandbox, and generates K second keys based on the first key and the K key transformation information; The client decrypts the K encrypted data encryption keys in the sandbox according to the K second keys, so as to decrypt the K encrypted data in the solid state drive according to the K data encryption keys; The key management platform sends key-related information to the client according to the data use request, including: The key management platform obtains the first key and a new first key for the next decryption of the K encrypted data as key-related information according to the data use request, and sends them to the client; The method further comprises: After the client decrypts the K encrypted data encryption keys according to the first key, the client uses the new first key in the sandbox to encrypt the K data encryption keys and stores them on the client; The key management platform obtains the first key and a new first key for decrypting the K encrypted data next time as key-related information according to the data use request, including: The key management platform obtains the first key, a new first key for decrypting the K encrypted data next time, and a random number based on the data use request, wherein the random number is used to decrypt the encrypted information in the key-related information issued by the key management platform next time; The key management platform encrypts the new first key according to the first key and the random number in the key-related information last sent to the client to form encrypted information, so as to determine the key-related information according to the first key, the encrypted information and the random number.

2. The method for reading and writing data encrypted by a solid state drive according to claim 1, characterized in that: The key management platform obtains the first key and a new first key for decrypting the K encrypted data next time as key-related information according to the data use request, including: The key management platform obtains the first key and a new first key for decrypting the K encrypted data next time according to the data use request; The key management platform encrypts the new first key according to the first key to form encrypted information, so as to determine the key-related information according to the first key and the encrypted information; The method further comprises: The client extracts the first key and the encrypted information from the key-related information, and decrypts the encrypted information according to the first key to obtain the first key and a new first key.

3. The method for reading and writing data encrypted by a solid state drive according to claim 2, characterized in that: The method further comprises: The client extracts the first key, encryption information and random number from the key-related information; The client saves the random number and extracts the target random number from the key-related information received last time; The client decrypts the encrypted information according to the target random number and the first key to obtain the first key and a new first key.

4. The method for encrypting and reading data of a solid state drive according to claim 3, characterized in that: The method further comprises: If the client fails to find the target random number in the key-related information received last time after saving the random number, the client generates a first public key and a first private key through the sandbox, and shares the first public key with the key management platform; The key management platform obtains the target random number and encrypts it with the first public key before returning it to the client; The client receives the target random number encrypted by the first public key and decrypts it using the first private key to obtain the target random number.

5. The data encryption reading and writing method of a solid state hard disk according to claim 1, characterized in that: The method further comprises: The client obtains the data encryption request for N data and uploads it to the key management platform; The key management platform feeds back a first key to the client based on the data encryption request; The client receives a first key in the sandbox and generates N different key transformation information, so as to generate N second keys according to the first key and the N different key transformation information; The client generates N data encryption keys in the sandbox, encrypts N data respectively, obtains N encrypted data, and saves them to the SSD; The client uses N second keys in the sandbox to encrypt N data encryption keys and stores them on the client.

6. A data encryption reading and writing device for a solid state hard disk, which executes the data encryption reading and writing method for a solid state hard disk according to any one of claims 1 to 5, characterized in that: The solid state drive stores encrypted data, K encrypted data are encrypted using K data encryption keys, the K data encryption keys are encrypted using K second keys and stored on the client, the K second keys are generated based on a first key managed by a key management platform and key transformation information stored on the client, and the device includes: A usage request acquisition module is used to obtain a data usage request for K encrypted data of the solid state drive through a client and upload it to the key management platform; A first key sending module, used to send key-related information to the client through the key management platform according to the data use request, where the key-related information includes a first key of the solid-state drive; A second key generation module, used to obtain key transformation information corresponding to K encrypted data in the sandbox through the client, and generate K second keys based on the first key and the K key transformation information; The encrypted data decryption module is used to decrypt K encrypted data encryption keys according to K second keys in the sandbox through the client, so as to decrypt K encrypted data in the solid state drive according to the K data encryption keys.

7. An electronic device, characterized in that: include: memory and at least one processor; The memory is used to store computer-executable instructions; The at least one processor is used to execute the computer execution instructions stored in the memory, so that the at least one processor executes the data encryption reading and writing method for the solid state drive according to any one of claims 1-5.

Citation Information

Patent Citations

  • Data encryption key acquisition and recovery method and data read-write method of solid state disk

    CN112417491A

  • Data encryption key management method and device, storage control card and storage medium

    CN117272350A

  • Data storage management method of solid state disk

    CN118839359A