Method, computer device and storage medium for enhancing security of system firmware data
By performing operation processing in an embedded storage device according to preset conditions, and obtaining and writing the area location of data, the problem that the system firmware data cannot be guaranteed to be stored in the pslc mode is solved, and the data security is improved.
Patent Information
- Application Number
- CN202510067044.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-01-16
AI Technical Summary
In the prior art, the system firmware data of embedded storage devices cannot be guaranteed to be stored in the pslc mode, resulting in poor data security.
By acquiring the data to be operated and performing the first operation process according to preset conditions (power-on period, number of P/E times, number of power-on times), the first information and area location of the data are obtained, and the data is written to the corresponding area.
It realizes automatic writing of key data into the pslc area, improving data security.
Smart Images

Figure CN119512471B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of firmware data, and particularly to a method, a computer device, and a storage medium for enhancing the security of system firmware data. Background Art
[0002] In the related art, the firmware data of an embedded storage device itself is generally stored in the physical Block (block storage) of the pslc, but the system firmware data on the host side cannot be guaranteed to be stored in the pslc (pseudo single-level cell). Currently, embedded storage devices based on MLC (multi-level cell flash memory), TLC (triple-level cell flash memory), or QLC (quadruple-level cell flash memory) provide a function of partitioning the enhance partition. Currently, the flash physical area where the enhance partition data is stored is fixed in the pslc mode. If the host does not set the enhance partition for the storage device, then the system data will be stored together with the ordinary data, and the security of the system data is relatively poor. Summary of the Invention
[0003] This application aims to at least solve one of the technical problems existing in the prior art. For this purpose, this application proposes a method, a computer device, and a storage medium for enhancing the security of system firmware data, aiming to achieve autonomous prediction for partitioning and improve the security of data.
[0004] In a first aspect, an embodiment of this application provides a method for enhancing the security of system firmware data, including:
[0005] Obtain the data to be operated;
[0006] When a preset condition is satisfied, perform a first operation process on the data to be operated, where the preset condition includes at least one of the following: the power-on cycle is less than a preset cycle, the number of P / E times is less than a preset number of P / E times, the power-on time is less than a preset power-on time, and the number of power-on times is less than a preset number of power-on times;
[0007] Obtain first information of the data to be operated according to the first operation and record the regional location of the data to be operated;
[0008] Write the data to be operated into the regional location according to the first information and the regional location.
[0009] According to some embodiments of this application, after performing the first operation on the data to be operated, it further includes:
[0010] When the logical address for executing the first operation ranges from the first logical address to the second logical address, the area location of the data to be operated on is the first area, and the power-on cycle for executing the first operation is the first power-on cycle, where the first area is from the first logical address to the second logical address.
[0011] According to some embodiments of the present application, the method further includes:
[0012] Performing a second operation on the data to be operated on;
[0013] Obtaining second information of the data to be operated on according to the second operation and recording the second area location of the data to be operated on, where the second area location of the data to be operated on is the second area;
[0014] When the overlap degree between the second area and the first area is greater than or equal to a first preset value, it is obtained that the second information of the data to be operated on is the same as the first information of the data to be operated on.
[0015] According to some embodiments of the present application, the method further includes:
[0016] Detecting the first area. When the second operation is performed within the first area and the logical address for executing the second operation ranges from the third logical address to the fourth logical address, it is obtained that the second area is from the third logical address to the fourth logical address and the power-on time for executing the second operation is the first power-on time.
[0017] According to some embodiments of the present application, the method further includes:
[0018] Performing a third operation on the data to be operated on;
[0019] Obtaining third information of the data to be operated on according to the third operation and recording the third area location of the data to be operated on, where the third area location of the data to be operated on is the third area;
[0020] When the third operation is not performed on the third area, it is obtained that the third information of the data to be operated on is the same as the first information of the data to be operated on.
[0021] According to some embodiments of the present application, within the second power-on cycle and the first power-on time, the method further includes:
[0022] Detecting the second area. When the third operation is performed within the second area and the logical address for executing the third operation ranges from the fifth logical address to the sixth logical address, it is obtained that the third area is from the fifth logical address to the sixth logical address.
[0023] According to some embodiments of the present application, when the power-on times of the data to be operated are greater than a first preset power-on time and less than a second preset power-on time, where the second preset power-on time is greater than the first preset power-on time, the method further includes:
[0024] When the regional position of the data to be operated is the target regional position and the power-on time of the data to be operated is less than the second preset power-on time, update the target regional position;
[0025] When the regional position of the data to be operated is the target regional position and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, end the update of the target regional position.
[0026] According to some embodiments of the present application, it further includes:
[0027] When the power-on times of the data to be operated are less than the first preset power-on time or greater than the second preset power-on time, recycle the data at the regional position.
[0028] In a second aspect, an embodiment of the present application provides a computer device, including:
[0029] At least one memory;
[0030] At least one processor;
[0031] At least one computer program;
[0032] The at least one computer program is stored in the at least one memory, and the at least one processor executes the at least one computer program to implement the method for improving the security of system firmware data described in the first aspect above.
[0033] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and the computer program is used to cause a computer to execute the method for improving the security of system firmware data described in the first aspect above.
[0034] According to the technical solution of the embodiment of the present application, it has at least the following beneficial effects: obtaining data to be operated; when a preset condition is satisfied, performing a first operation process on the data to be operated, where the preset condition includes at least one of the following: the power-on cycle is less than a preset cycle, the number of P / E times is less than a preset P / E number, the power-on time is less than a preset power-on time, and the number of power-on times is less than a preset number of power-on times; obtaining first information of the data to be operated according to the first operation and recording the regional location of the data to be operated; writing the data to be operated into the regional location according to the first information and the regional location. By obtaining the first information of the data to be operated according to the first operation and recording the regional location of the data to be operated within the preset condition, the embodiment of the present application writes the data to be operated into the corresponding regional location, thereby realizing automatically writing key data into the pslc area, realizing autonomous prediction for partitioning, and improving data security. Description of the Drawings
[0035] The drawings are used to provide a further understanding of the technical solution of the present application, and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application, and do not constitute a limitation to the technical solution of the present application.
[0036] Figure 1 It is a flowchart of a method for improving the data security of system firmware provided by an embodiment of the present application;
[0037] Figure 2 It is a flowchart of a method for performing a second operation provided by an embodiment of the present application;
[0038] Figure 3 It is a flowchart of a method for performing a third operation provided by an embodiment of the present application;
[0039] Figure 4 It is a schematic diagram of an area for performing a method for improving the data security of system firmware provided by an embodiment of the present application;
[0040] Figure 5 It is an overall flowchart of a method for improving the data security of system firmware provided by an embodiment of the present application;
[0041] Figure 6 It is a schematic diagram of the hardware structure of a computer device provided by an embodiment of the present application. Detailed Description of the Embodiment
[0042] The embodiments of the present application are described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions from beginning to end. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present application, and should not be construed as a limitation to the present application.
[0043] In the description of this application, it should be understood that for the orientation description, such as the orientation or positional relationship indicated by up, down, front, back, left, right, etc., it is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to this application.
[0044] In the description of this application, the meaning of "several" is one or more, the meaning of "multiple" is two or more. Understandings such as "greater than", "less than", "exceeding", etc. do not include the original number, and understandings such as "above", "below", "within", etc. include the original number. If there is a description of "first" and "second", it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or implicitly indicating the sequence relationship of the indicated technical features.
[0045] In the description of this application, unless otherwise clearly defined, words such as "set", "installed", "connected", etc. should be understood in a broad sense. Those skilled in the art can reasonably determine the specific meanings of the above words in this application in combination with the specific content of the technical solution.
[0046] First, parse several nouns involved in this application:
[0047] Flash (non-volatile storage technology): Flash memory can retain the data it stores even when powered off. Flash memory supports fast read and write operations, which makes it very suitable for use as auxiliary storage for computers and other devices. Each storage cell of Flash memory has a limited number of erase and write cycles, usually between several thousand and tens of thousands of times. Flash memory usually performs erase and write operations in units of blocks. This means that when updating data, the entire block must be erased first, and then new data can be written.
[0048] Block (block storage): It is a data storage method in which data is stored as blocks or sectors and can be accessed through a unique identifier (such as a logical unit number LUN). Block storage allows users to operate storage volumes like operating a hard disk, creating, deleting, and modifying files.
[0049] Pslc (Pseudo-Single Level Cell): It is a NAND flash memory technology that simulates the working mode of SLC (Single Level Cell) storage cells on MLC (Multi-Level Cell) or TLC (Triple-Level Cell) flash memory chips through special control algorithms and management methods.
[0050] P / E Cycles (Program / Erase cycles): It refers to the number of programming and erasing cycles of the flash memory in a solid-state drive (SSD). Each time the entire SSD is programmed (i.e., written) and erased once, it is counted as one P / E cycle.
[0051] The Firmware data of the embedded storage device itself is generally stored in the physical blocks of the pslc, but the system firmware data on the host side cannot be guaranteed to be stored in the pslc. Currently, the embedded storage devices based on MLC, TLC, or QLC provide a function to divide the enhance partition. Currently, the flash physical area where the enhance partition data is stored is fixed in the pslc mode. If the host does not set the enhance partition for the storage device, then the system data will be stored together with ordinary users. With the occurrence of the GC behavior, the data will be moved to the physical blocks outside the pslc, and the security of the system data is relatively poor.
[0052] The method, computer device, and storage medium for improving the security of system firmware data provided by the embodiments of the present application will be specifically described through the following embodiments. First, the method for improving the security of system firmware data in the embodiments of the present application will be described.
[0053] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, Artificial Intelligence (AI) is a theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.
[0054] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0055] The method, computer device, and storage medium for enhancing the security of system firmware data provided by the embodiments of the present application relate to the technical field of firmware data. The method for enhancing the security of system firmware data provided by the embodiments of the present application can be applied to a terminal, a server side, or software running on a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the method for enhancing the security of system firmware data, etc., but is not limited to the above forms.
[0056] The present application can be used in many general or specific computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0057] It should be noted that in each specific embodiment of the present application, when relevant processing needs to be performed based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of the present application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or redirecting to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the normal operation of the embodiments of the present application will be obtained.
[0058] Please refer to Figure 1 , Figure 1 is a schematic flowchart of a method for enhancing the security of system firmware data provided by the embodiments of the present application; asFigure 1 As shown in the figure, a method for improving the data security of system firmware provided by an embodiment of the present application includes, but is not limited to, steps S110 - S140. The following introduces each step in turn.
[0059] Step S110: Obtain the data to be operated on;
[0060] Step S120: When a preset condition is satisfied, perform a first operation process on the data to be operated on. The preset condition includes at least one of the following: the power - on cycle is less than a preset cycle, the number of P / E times is less than a preset number of P / E times, the power - on time is less than a preset power - on time, and the number of power - on times is less than a preset number of power - on times;
[0061] Step S130: Obtain the first information of the data to be operated on according to the first operation and record the area location of the data to be operated on;
[0062] Step S140: Write the data to be operated on into the area location according to the first information and the area location.
[0063] In one embodiment, after the system obtains the data to be operated on, the system checks whether the preset conditions are met. The preset conditions include that the power - on cycle is less than a preset cycle, the number of P / E times is less than a preset number of P / E times, the power - on time is less than a preset power - on time, and the number of power - on times is less than a preset number of power - on times. When the system meets one of the above conditions, the system will perform a first operation process on the obtained data. After performing the first operation process, the system will obtain the information of the data to be operated on. The system will also record the location information of the storage area where the data to be operated on should be written. The system writes the processed data into the previously recorded area location. The system can achieve autonomous prediction for partitioning according to the first operation, improving data security.
[0064] In one embodiment, after performing the first operation on the data to be operated on, when the logical address for performing the first operation is from the first logical address to the second logical address, the area location of the data to be operated on is the first area, and the power - on cycle for performing the first operation is the first power - on cycle, where the first area is from the first logical address to the second logical address.
[0065] See Figure 4 , Figure 4 is a schematic diagram of the area for implementing the method for improving the data security of system firmware in an embodiment of the present application.
[0066] In one embodiment, within the first 5 power - on times, when the maximum number of P / E times of the block in the flash is less than 3, and within 5 minutes from the start of power - on, a sequential write from logical address A to logical address B occurs. The storage device firmware records that this event occurs at the 3rd power - on, and its write area is from A to B.
[0067] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of a method for performing a second operation provided by an embodiment of the present application; as Figure 2 shown, a method for enhancing the security of system firmware data provided by an embodiment of the present application includes, but is not limited to, steps S210 - S230, and each step will be introduced in turn below.
[0068] Step S210: Perform a second operation on the data to be operated;
[0069] Step S220: Obtain second information of the data to be operated and record the second area location of the data to be operated according to the second operation, where the second area location of the data to be operated is the second area;
[0070] Step S230: When the overlap degree between the second area and the first area is greater than or equal to a first preset value, it is obtained that the second information of the data to be operated is the same as the first information of the data to be operated.
[0071] In one embodiment, the system performs a second processing on the data that has previously performed the first operation. After the second operation is completed, the system will obtain second information about the data, the system will also record the second area location of the data, and the system will compare the overlap degree between the second area and the first area. If the overlap degree is greater than or equal to a preset threshold (the first preset value), this indicates that there are enough common parts in the two areas, then the second information is the same as the first information.
[0072] It should be noted that within a predetermined power - on time, predictions are made according to read - write behaviors. Whether the read operation hits the recorded area significantly. If so, then the storage device determines that it is the host power - on to read system data, and further determines that the area stored in the recorded area is host system data.
[0073] In one embodiment, the first area is detected. When the second operation is located within the first area and the logical address of the second operation is from the third logical address to the fourth logical address, it is obtained that the second area is from the third logical address to the fourth logical address and the power - on time of the second operation is the first power - on time.
[0074] Refer to Figure 4 , Figure 4 which is a schematic diagram of an area for performing a method for enhancing the security of system firmware data according to an embodiment of the present application.
[0075] In one embodiment, during several subsequent power - on cycles, under predetermined conditions, read behaviors occurring between regions A - B are monitored and recorded. Records of the aforementioned write events have been made. And during the 3 power - on cycles from the 4th to the 6th, within 1 minute from the start of power - on, a read operation is detected between regions A and B, and the maximum read range is from C to D. The storage device records the read region as from C to D.
[0076] Please refer to Figure 3 , Figure 3 is a schematic flowchart of a method for performing a third operation provided by an embodiment of the present application; as Figure 3 shown, a method for enhancing the data security of system firmware provided by an embodiment of the present application includes, but is not limited to, steps S310 - S330. Each step will be introduced in turn below.
[0077] Step S310: Perform a third operation on the data to be operated on;
[0078] Step S320: Obtain third information of the data to be operated on according to the third operation and record the third region position of the data to be operated on, where the third region position of the data to be operated on is the third region;
[0079] Step S330: When the third operation has not been performed on the third region, it is obtained that the third information of the data to be operated on is the same as the first information of the data to be operated on.
[0080] In one embodiment, the system performs a third - time processing on data that has previously undergone the first and second operations. After the third operation is completed, the system will obtain new information (third information) about the data. The system will also record the third region of the data on the storage medium. The system will compare whether the third operation has been performed on the third region. If the third operation has not been performed on the third region, then the system will conclude that the third information is the same as the first information.
[0081] In one embodiment, according to the write operation behavior, it is judged whether the logical region of this record is overwritten and updated. If it is not overwritten, it conforms to the read - only feature of the system partition and is further confirmed as host system data.
[0082] In one embodiment, during the second power - on cycle and the first power - on time, the second region is detected. When the third operation is performed within the second region and the logical address of the third operation is from the fifth logical address to the sixth logical address, the third region is obtained as from the fifth logical address to the sixth logical address.
[0083] Refer to Figure 4 , Figure 4 is a schematic diagram of the region of a method for enhancing the data security of system firmware provided by an embodiment of the present application.
[0084] In one embodiment, records of the aforementioned write event and read event have occurred, and the read event can be repeatedly detected (within 1 minute after power-on and within the next 3 power-on cycles, a read operation can still be detected between regions A and B, and the maximum read range is from C to D). And the un-overwritten area within C to D is monitored as E to F. The storage device records the un-overwritten area as E to F (un-overwritten event).
[0085] In one embodiment, when the number of power-on times of the data to be operated is greater than a first preset number of power-on times and less than a second preset number of power-on times, where the second preset number of power-on times is greater than the first preset number of power-on times, it includes:
[0086] When the area position of the data to be operated is the target area position and the power-on time of the data to be operated is less than the second preset power-on time, update the target area position;
[0087] When the area position of the data to be operated is the target area position and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, end the update of the target area position.
[0088] In one embodiment, when the data to be operated has an area position, the system first checks whether the number of power-on times of the data to be operated falls between the first preset number of power-on times and the second preset number of power-on times. When the number of power-on times is greater than the first preset number of power-on times and less than the second preset number of power-on times, then the system will enter the next judgment. The system then checks whether the power-on time of the data to be operated is less than the second preset power-on time. When the area position of the data to be operated is the target area position and the power-on time is less than the second preset power-on time, then the system will update the target area position. The system can adopt different data processing strategies at different stages of device use, thereby improving efficiency and reliability.
[0089] In one embodiment, when the data to be operated has an area position, the system first checks whether the number of power-on times of the data to be operated falls between the first preset number of power-on times and the second preset number of power-on times. When the number of power-on times is greater than the first preset number of power-on times and less than the second preset number of power-on times, then the system will enter the next judgment. The system then checks whether the power-on time of the data to be operated is greater than or equal to the second preset power-on time. When the area position of the data to be operated is the target area position and the power-on time is greater than or equal to the second preset power-on time, then the system will end the update of the target area position.
[0090] In one embodiment, when the number of power-on times of the data to be operated is less than the first preset number of power-on times or greater than the second preset number of power-on times, recycle the data at the area position.
[0091] In one embodiment, the system sets two thresholds, namely the first preset power-on count and the second preset power-on count, where the second preset power-on count is greater than the first preset power-on count. These two thresholds define a range of "normal" power-on counts. The system will monitor the power-on count of the data to be operated on in real time, which can be achieved through a hardware counter. Each time the device is powered on, the counter increments. When it is detected that the power-on count exceeds the preset range, the system will perform a recycling operation on the data in the area where the data to be operated on is located.
[0092] See Figure 5 , Figure 5 is the overall flowchart of a method for improving the security of system firmware data provided by an embodiment of the present application. It includes but is not limited to steps S5001 - S5014, and each step will be introduced in turn below.
[0093] Step S5001: Start;
[0094] Step S5002: Determine whether there is no record of the target interval. If so, execute step S5003; if not, execute step S5009;
[0095] Step S5003: Determine whether the power-on count is less than the set threshold. If so, execute step S5004; if not, execute step S5014;
[0096] Step S5004: Determine whether the maximum number of PEs is less than the set threshold. If so, execute step S5005; if not, execute step S5014;
[0097] Step S5005: Determine whether it is a sequential write. If so, execute step S5006; if not, execute step S5014;
[0098] Step S5006: Determine whether the power-on time is less than the set threshold. If so, execute step S5007; if not, execute step S5014;
[0099] Step S5007: Record or update the start address and the target interval;
[0100] Step S5008: Record the power-on count N;
[0101] Step S5009: Determine whether the power-on count is less than the set threshold N + i. If so, execute step S5010; if not, execute step S5013;
[0102] Step S5010: Determine whether the read / write operation hits the recorded target interval. If so, execute step S5011; if not, execute step S5010;
[0103] Step S5011: Determine whether the power-on time is less than the set threshold 2. If yes, execute Step S5012; if no, execute Step S5014;
[0104] Step S5012: Update the target range according to the read / write operation;
[0105] Step S5013: Recycle the data in the target range to the block, mark the attribute, and it will not participate in the recycling hereafter;
[0106] Step S5014: End.
[0107] In one embodiment, first determine whether there is no record of the target range. If there is no record of the target range, then determine whether the power-on count is less than the set threshold. If there is a record of the target range, then determine whether the power-on count is less than the set threshold N+i. When the power-on count is less than the set threshold, continue to determine whether the maximum PE count is less than the set threshold. If the power-on count is greater than or equal to the set threshold, end. When the maximum PE count is less than the set threshold, continue to determine whether it is a sequential write. When the maximum PE count is greater than or equal to the set threshold, end. When it is determined to be a sequential write, continue to determine whether the power-on time is less than the set threshold. When the power-on time is less than the set threshold, record or update the starting address and the target range. When the power-on time is greater than or equal to the set threshold, end. After recording or updating the starting address and the target range, record the power-on count N. When the power-on count is less than the set threshold N+i, determine whether the read / write operation hits the recorded target range. When the power-on count is greater than or equal to the set threshold N+i, recycle the data in the target range to the block, mark the attribute, and it will not participate in the recycling hereafter. When the read / write operation hits the recorded target range, continue to determine whether the power-on time is less than the set threshold 2. When the read / write operation does not hit the recorded target range, re-judge. When the power-on time is less than the set threshold 2, update the target range according to the read / write operation, and then determine whether the read / write operation hits the recorded target range. When the power-on time is greater than or equal to the set threshold 2, end.
[0108] The embodiment of the present application further provides a computer device, which includes: at least one memory, at least one processor, at least one computer program, at least one computer program is stored in at least one memory, and at least one processor executes at least one computer program to implement the method for improving the data security of the system firmware in any one of the above embodiments. This computer device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0109] See Figure 6 , Figure 6 shows the hardware structure of a computer device in another embodiment. This computer device includes:
[0110] The processor 610 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;
[0111] The memory 620 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 520 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 620 and are called by the processor 610 to execute the method for enhancing the data security of the system firmware in the embodiments of the present application;
[0112] The input / output interface 630 is used to implement information input and output;
[0113] The communication interface 640 is used to implement communication interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);
[0114] The bus 650 transmits information between various components of the device (such as the processor 610, the memory 620, the input / output interface 630, and the communication interface 640);
[0115] Among them, the processor 610, the memory 620, the input / output interface 630, and the communication interface 640 achieve communication connections with each other inside the device through the bus 650.
[0116] The embodiments of the present application also provide a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method for enhancing the data security of the system firmware is implemented.
[0117] The memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0118] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0119] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or combine certain steps, or different steps.
[0120] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0121] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0122] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0123] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single items (items) or plural items (items). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0124] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0125] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0126] In addition, each functional unit in various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0127] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memories (ROM for short), random access memories (RAM for short), magnetic disks, or optical discs.
[0128] The preferred embodiments of the embodiments of this application have been described above with reference to the accompanying drawings, which does not limit the scope of the rights of the embodiments of this application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall be within the scope of the rights of the embodiments of this application.
Claims
1. A method for improving the security of system firmware data, characterized in that: include: Get the data to be operated; When a preset condition is met, a first operation process is performed on the data to be operated, wherein the preset condition includes at least one of the following: a power-on cycle is less than a preset cycle, a P / E number is less than a preset P / E number, a power-on time is less than a preset power-on time, and a power-on number is less than a preset power-on number; Obtaining, according to the first operation, first information of the data to be operated and a region location where the data to be operated is recorded; Writing the data to be operated into the regional position according to the first information and the regional position; After performing the first operation on the data to be operated, the method further includes: When the logical address for performing the first operation is from the first logical address to the second logical address, the region location of the data to be operated is obtained as the first region and the power-on cycle for performing the first operation is obtained as the first power-on cycle, wherein the first region is from the first logical address to the second logical address; Performing a second operation on the data to be operated; Obtaining second information of the data to be operated according to the second operation and recording a second area position of the data to be operated, wherein the second area position of the data to be operated is a second area; When the overlap between the second area and the first area is greater than or equal to a first preset value, the second information of the data to be operated is the same as the first information of the data to be operated; When the second information of the data to be operated is the same as the first information of the data to be operated, the data to be operated is obtained as host system data; The first operation is a sequential write operation, and the second operation is a read operation.
2. The method according to claim 1, characterized in that The method further comprises: The first area is detected, and when the second operation is executed within the first area and the logical address for executing the second operation is from the third logical address to the fourth logical address, it is obtained that the second area is from the third logical address to the fourth logical address and the power-on time for executing the second operation is the first power-on time.
3. The method according to claim 2, characterized in that The method further comprises: Performing a third operation on the data to be operated, wherein the third operation is a write operation; Obtaining third information of the data to be operated and recording a third area position of the data to be operated according to the third operation, wherein the third area position of the data to be operated is a third area; When the third operation is not performed on the third region, the third information of the data to be operated is the same as the first information of the data to be operated.
4. The method according to claim 3, characterized in that During the second power-on cycle and the first power-on time, the method further includes: The second area is detected, and when the third operation is performed within the second area and the logical address for performing the third operation is from the fifth logical address to the sixth logical address, the third area is obtained to be from the fifth logical address to the sixth logical address.
5. The method according to claim 1, characterized in that In a case where the power-on times of the data to be operated are greater than the first preset power-on times and less than the second preset power-on times, wherein the second preset power-on times are greater than the first preset power-on times, the method further includes: When the area position of the data to be operated is the target area position and the power-on time of the data to be operated is less than the second preset power-on time, updating the target area position; When the area position of the data to be operated is the target area position and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, the updating of the target area position is finished.
6. The method according to claim 1, characterized in that Also includes: When the power-on times of the data to be operated are less than the first preset power-on times or greater than the second preset power-on times, the data of the regional position is recovered.
7. A computer device, characterized in that: include: at least one memory; at least one processor; at least one computer program; The at least one computer program is stored in the at least one memory, and the at least one processor executes the at least one computer program to implement: the method according to any one of claims 1 to 6.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is used to make a computer execute: the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Storage device and fault processing method thereof
CN118484150A