Data Change Method, Device, Computer Equipment, Medium and Program Product

By performing two checksums on the data to be changed inside the device, dividing new sectors without resetting the read-only area, the problem of low security of the device data is solved, and data security and storage efficiency are improved.

CN119513935BActive Publication Date: 2025-06-13北京长擎量子技术有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411566300.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-06-13
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

In the prior art, the data security inside the device is low, and it is easy to cause important data leakage when the device is disassembled or the disk is mounted and read.

Method used

By performing two verifications on the changed data (legality checksum integrity checksum) to generate new mirror files, and without resetting the read-only area, new sectors are divided into the remaining space of the read-only area and writing new mirror files are burned to achieve data changes.

Benefits of technology

Ensures the security and integrity of data, prevents unauthorized tampering and data corruption, improves data storage efficiency, and provides a flexible data management method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119513935B_ABST
    Figure CN119513935B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer technologies, and discloses a data change method, device, computer equipment, medium and program product. The method includes: performing a first verification on the data to be changed, where the data to be changed is a burned image file; after the first verification of the data to be changed passes, dividing the data to be changed according to a preset data type to obtain at least one new data segment, where each new data segment corresponds to a preset data type; performing a second verification on each new data segment; after the second verification of each new data segment passes, generating a new image file and determining whether to reset the read-only area; when not resetting the read-only area, dividing a new sector in the remaining space of the read-only area and burning the new image file in the new sector to implement data change. Based on the technical solution of the present invention, it is possible to effectively prevent the device from being disassembled, the disk being mounted, and the data being read to modify the protected data, thereby improving the security of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a data change method, apparatus, computer device, medium and program product. Background Art

[0002] For the delivery of large projects, software and its operating hardware platform are often delivered together to form a simple and easy-to-use chassis box with a relatively closed operation entrance. In this way, all operations of users can be within a controllable range, forming a stable human-computer interaction function boundary. At the same time, only debugging interfaces for developers are reserved for the internal system of the device for maintenance and upgrade.

[0003] In the delivered device, for the system integrated in the chassis, an upgrade function is generally provided according to the provided service life. However, the protection of core data and application programs is generally achieved by the way of closing access rights of the built-in operating system. If the other party forcibly disassembles the machine, takes out the disk for mounting and reading, it will easily lead to the leakage of important data and cause property losses to the manufacturer.

[0004] Therefore, there is an urgent need for a data change method that can reduce data risks and improve data security. Summary of the Invention

[0005] Therefore, the technical problem to be solved by the present invention is to overcome the problem of low data security in related technologies.

[0006] To solve the above technical problem, a data change method provided by the present invention includes:

[0007] Perform a first verification on the data to be changed; the data to be changed is the burned image file; the first verification includes a legality verification;

[0008] After the first verification of the data to be changed passes, divide the data to be changed according to a preset data type to obtain at least one new data segment; each new data segment corresponds to a preset data type;

[0009] Perform a second verification on each new data segment; the second verification includes an integrity verification;

[0010] After the second verification of each new data segment passes, generate a new image file and determine whether to reset the read-only area;

[0011] When not resetting the read-only area, divide a new sector in the remaining space of the read-only area, and burn each new image file in the new sector to implement data change.

[0012] In an alternative embodiment, before the first verification of the data to be changed, the method further includes:

[0013] Download an upgrade package, transfer the downloaded upgrade package to the secure area; a firmware upgrade and maintenance module is provided in the secure area; process and analyze the upgrade package through the firmware upgrade module to determine the data to be changed;

[0014] Or, according to the partition where the data to be changed is currently located, call the data solidification module of the corresponding partition, and determine the data to be changed through the data solidification module; transfer the data to be changed determined by the data solidification module to the secure area; wherein, the data to be changed in the secure area is used for the first verification.

[0015] In an alternative embodiment, the preset data types include system kernel type, service data type, and application software type. The second verification of each newly added data segment includes:

[0016] Perform a second verification on the newly added data segments with the preset data type of system kernel type or service data type;

[0017] Determine whether the newly added data segments with the preset data type of application software type are external programs;

[0018] When the newly added data segments with the preset data type of application software type are not external programs, perform a second verification on the newly added data segments with the preset data type of application software type;

[0019] When the newly added data segments with the preset data type of application software type are external programs, perform a running condition integrity verification on the newly added data segments with the preset data type of application software type;

[0020] After the running condition integrity verification passes, perform a second verification on the newly added data segments with the preset data type of application software type.

[0021] In an alternative embodiment, the method further includes: when there are newly added data segments that fail the second verification among all the newly added data segments, enter a preset exception handling process and output exception information.

[0022] In an alternative embodiment, the determination of whether to reset the read-only area includes:

[0023] When it is determined to reset the read-only area, obtain the backup image file corresponding to the unchanged image file in the read-only area, format the read-only area, and perform the first write in the formatted read-only area; the first write is used to write the backup image file; wherein, new sectors are divided in the remaining space after the first write in the formatted read-only area;

[0024] Perform a second programming in the new sector; the second programming is used to program each newly added data segment.

[0025] In an alternative embodiment, after programming each newly added mirror file in the new sector, the method further includes: changing the device mounting configuration and the initialization script.

[0026] In a second aspect, the present invention provides a data change device, which includes:

[0027] A first processing module, configured to perform a first verification on the data to be changed; the data to be changed is the programmed mirror file; the first verification includes a legality verification;

[0028] A second processing module, configured to divide the data to be changed according to a preset data type after the first verification of the data to be changed passes, to obtain at least one newly added data segment; each newly added data segment corresponds to a preset data type;

[0029] A third processing module, configured to perform a second verification on each newly added data segment; the second verification includes an integrity verification;

[0030] A fourth processing module, configured to generate a newly added mirror file and determine whether to reset the read-only area after the second verification of each newly added data segment passes;

[0031] A fifth processing module, configured to divide a new sector in the remaining space of the read-only area when not resetting the read-only area, and program each newly added mirror file in the new sector to implement data change.

[0032] In a third aspect, the present invention provides a computer device, including: a memory and a processor, which are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the data change method according to the first aspect or any corresponding embodiment thereof.

[0033] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer instruction is stored, and the computer instruction is used to cause a computer to execute the data change method according to the first aspect or any corresponding embodiment thereof.

[0034] In a fifth aspect, the present invention provides a computer program product, including computer instructions, and the computer instructions are used to cause a computer to execute the data change method according to the first aspect or any corresponding embodiment thereof.

[0035] The technical solution provided by the present invention has the following technical effects: Through two - step verification (legality verification and integrity verification), the security and integrity of data are ensured, preventing unauthorized tampering and data corruption. Integrity verification ensures the consistency of data during transmission and storage, preventing data loss and damage. By presetting data types and adding new data segments, data can be managed and organized more effectively, facilitating data maintenance and upgrade. When not resetting the read - only area, new sectors are divided using the remaining space, optimizing the use of storage space and improving storage efficiency. Allowing data changes without resetting the read - only area provides a flexible data management method. By dividing new sectors and burning new data segments, expansion can be carried out as needed to adapt to different storage requirements. The technical solution of the present invention restricts the read - only permissions of key data and programs at the hardware level, effectively preventing tampering and damage by malicious programs. During normal use, there is no need to control read - write permissions through kernel or other application restrictions, improving the software operation efficiency and reducing computing resource consumption. It can effectively prevent the device from being disassembled, the disk being mounted, and data being read to modify the protected data, ensuring the integrity of the current component operation. During the upgrade process, personnel operations are separated, and core steps are encapsulated as atomic operations, reducing the risk of error introduction by implementers and the complexity of problems. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in related technologies, the following will briefly introduce the drawings required for use in the description of the specific embodiments or related technologies. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0037] Figure 1 It is a schematic diagram of the device data security protection mechanism framework according to an embodiment of the present invention;

[0038] Figure 2 It is a schematic flowchart of the data change method according to an embodiment of the present invention;

[0039] Figure 3 It is a schematic overall flowchart of the data change method according to an embodiment of the present invention;

[0040] Figure 4 It is a schematic diagram of the structure of the data change device according to an embodiment of the present invention;

[0041] Figure 5 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] In the computer field, the intellectual property protection and anti-tampering protection of commercial software are important measures for manufacturers to form a commercial closed-loop while providing software services to users.

[0044] For large project deliveries, software and the hardware platform on which it runs are often delivered together to form a simple and easy-to-use chassis box with a relatively closed operation entrance. This allows all operations of the user to be within a controllable range, forming a stable human-computer interaction function boundary. At the same time, only debugging interfaces for developers are reserved for the systems inside the device for maintenance and upgrade purposes.

[0045] In the delivered device, for the system integrated in the chassis, an upgrade function is generally provided according to the provided service life. However, the protection of core data and application programs is generally achieved by means of restricting access rights within the built-in operating system. If the other party forcibly disassembles the machine and takes out the disk for data reading by mounting, there is a risk of leakage of important commercial data, and the data security is poor.

[0046] In related technologies, the following are generally the methods for protecting device data security and corresponding upgrade and maintenance methods:

[0047] (1) All are achieved through the multi-user permission control of the operating system carried.

[0048] This method is the most common because the operating system itself has a user permission system. By presetting user permissions according to the operation needs of the device itself and providing the customer with specified ordinary user permissions during delivery, the access scope and operation boundary of the user to the built-in operating system can be controlled.

[0049] Correspondingly, when it comes to upgrade and maintenance, another dedicated user account can be used to obtain relatively high permissions to modify core data.

[0050] The disadvantage of this method is that it may lead to the loss of account information, and the boundary of human operation is uncontrollable. Especially the change of maintenance personnel and the change of products will increase the user account management cost and risk, resulting in data security risks from social engineering.

[0051] (2) It is achieved by controlling the user permissions of the operating system and secondary development of the interactive interface of the operating system.

[0052] This method is a supplement to the single use of the user permission system. Similarly, what is delivered to the user is a device equipped with a customized operating system. Not only is the user's access permission configured, but also the operation UI is separately customized and developed. The general operating system login and access interactive interface are blocked, allowing the user to interact on a specific UI interface.

[0053] Similarly, a set of operation UIs for maintenance personnel will also be separately developed, and a separate interaction boundary will be provided for maintenance personnel, which is only used for upgrading and maintenance.

[0054] This method is commonly found in devices with strong business nature and high function orientation, such as firewalls, switches, etc. Due to its professional industry usage scenarios and relatively fixed business operation boundaries. It enables developers to sort out the operation logic based on operation scenarios with little change and develop the UI interface. However, the disadvantages also become apparent, such as poor generality, high development cost, short update cycle, and it is only applicable to large-scale manufacturers in specific industries.

[0055] (3) It is achieved by combining user permission control with a permission verification component.

[0056] This method is based on the single control of user permissions and adds a permission verification component to avoid the implementation risk of key links in permission control introduced by social engineering of operators.

[0057] When delivering, a general standard device is provided, and a firmware device is provided as a token. The user's corresponding business function usage permissions and the operation permissions of upgrade and maintenance personnel are activated in the form of different tokens.

[0058] However, this method is essentially still a way of configuring the user permission system at the software level, and there is no control over the specific operations of various personnel and the protection of sensitive data.

[0059] The above protection mechanisms and corresponding upgrade and maintenance methods are all at the software level. If the device is directly disassembled and the disk is removed and mounted on other hosts to read data, the information of the device will be leaked, tampered with, and malicious programs will be implanted. When the device is reinstalled and used, there will be security risks.

[0060] The technical solution of the present invention is as follows Figure 1Under the framework of the "Device Data Security Protection Mechanism" shown, a technical solution for firmware upgrade and maintenance is implemented. The technical framework of the technical solution of the present invention is as follows: Store core data in the form of a CDROM (Compact Disc Read-Only Memory), and control the read-only permission in hardware form to prevent tampering. At the same time, the preparation and burning of IOS and image mirror components are built in, and the update and maintenance of the core file area and program firmware are controlled in software form.

[0061] As Figure 1 can be seen, the implementation of the upgrade and maintenance of the present invention is based on the different partitions of the hardware disk. The storage disk is divided into four types in the way of hardware customization: ordinary area, hidden area, security area, and CDROM read-only area.

[0062] Among them, the CDROM read-only area is the area where data, programs, system kernels, etc. that need to be solidified and anti-tampered are stored. This area is not a partition, but is realized by configuring multiple CDROMs according to the needs of the usage scenario, and will not be elaborated here. For upgrade and maintenance, the principle is to divide the data that needs to be solidified into the CDROM read-only area in each partition into different mirror directories according to organizational needs, then prepare different mirror files, and then burn them into the CDROM read-only area.

[0063] Therefore, the embodiments of the present invention provide a data change method, device, computer device, medium and program product to solve the above problems.

[0064] According to an embodiment of the present invention, an embodiment of a data change method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer device such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0065] Figure 2 is a flowchart of the data change method of the embodiment of the present invention.

[0066] As Figure 2 shown, an embodiment of the present invention provides a data change method, which is applied to the operating system of a device. The data change method includes:

[0067] S101: Perform a first verification on the data to be changed.

[0068] In this embodiment, the data to be changed is the burned mirror file. The first verification includes a legality verification.

[0069] In this embodiment, before performing the first verification on the data to be changed in S101, the data change method further includes:

[0070] Download the upgrade package and transfer the downloaded upgrade package to the secure area. The secure area is provided with a firmware upgrade and maintenance module. The upgrade package is processed and analyzed by the firmware upgrade module to determine the data to be changed.

[0071] Alternatively, according to the partition where the data to be changed is currently located, call the data solidification module of the corresponding partition, and determine the data to be changed through the data solidification module. Transfer the data to be changed determined by the data solidification module to the secure area.

[0072] In this embodiment, the data to be changed in the secure area is used for the first verification.

[0073] The above embodiments illustrate the data change scheme that triggers S101 - S105 in the presence of the above two scenarios.

[0074] In this embodiment, when a firmware upgrade request is obtained, generally, the implementer downloads the upgrade package, executes the upgrade operation, and runs the upgrade script. The upgrade package contains all the new codes and data required for system firmware upgrade or change. These contents can drive the update of drivers, the operating system kernel, system tools, or other system components. Execute the upgrade operation: by running the script or program in the upgrade package, the system can automatically execute the upgrade process, including processing and analyzing the upgrade package through the firmware upgrade module in the secure area to determine the data to be changed, as well as the technical solutions of S101 - S105, and also include installing new codes, configuring system settings, updating system components, etc. This embodiment illustrates one of the scenarios that trigger the change of solidified data, that is, how to update when the upgraded component is just solidified in the system.

[0075] In this embodiment, or during use, when key information needs to be solidified and protected, according to the partition where the data to be changed, that is, the key information, is currently located, call the data solidification module of the corresponding partition, organize the data files to be solidified, and obtain the data to be changed. This embodiment illustrates another scenario that triggers the update of solidified data, that is, some data of the user is expected not to be tampered with, and simply protected by the write permission in the operating system, which may be breached by privilege escalation. Therefore, according to the technical solution of the present invention, it can be directly solidified to prevent tampering.

[0076] In this embodiment, the storage disk is pre - divided into a normal area, a hidden area, a secure area, and a read - only area. The hidden area and the secure area are built - in with file read - write modules. Except for the normal area, the data read and write in the hidden area and the secure area are completed by the file read - write modules. Transfer the data to be changed corresponding to each partition to the secure area. The upgrade script of the upgrade package can call the corresponding API interface to transfer the upgrade package to the secure area for processing.

[0077] This embodiment introduces the processing before data solidification, which is carried out in the security area. Therefore, the security area is developed with an interface to pre-transfer the data to be changed in the hidden area and the normal area to the security area for pre-processing. At the same time, the upgrade package will also call the interface (i.e., API) to transfer the upgrade package into the security area through the interface.

[0078] In this embodiment, the security area is built-in with components required for upgrade and solidification. This component is functionally called the firmware upgrade module, which uniformly processes all the data to be changed that needs to be solidified into the read-only area (e.g., the optical disc area). The solidification process of the data to be changed is executed through the firmware upgrade module.

[0079] In this embodiment, the first verification is a legality verification. The data to be changed in the security area is verified for legality, specifically for malicious software, to prevent the intrusion of malicious software. Viruses and Trojans and other malicious software can be identified and blocked through scanning, protecting the system and data from damage. When the data is changed, upgraded, and solidified, anti-virus and anti-Trojan scanning are performed. The main purpose is to ensure that no malicious files are introduced, prevent sensitive data from being stolen or damaged by malicious software, and ensure the confidentiality, integrity, and availability of the data.

[0080] S102: After the first verification of the data to be changed passes, the data to be changed is divided according to the preset data type to obtain at least one new data segment.

[0081] In this embodiment, each new data segment corresponds to a preset data type. The preset data types can include system kernel types, business data types, and application software types. Corresponding to the system kernel image file, business data image file, and application software image file. The system kernel data image file usually includes the core components of the operating system, such as kernel files, system libraries, boot loaders, etc. They are the basis for the operation of the operating system. The business data image file usually contains the business logic and data required for the operation of the application, such as configuration files, user data, transaction records, etc. These files support the business operations of the application. The application software image file includes the application itself and all its dependencies, which may include executable files, resource files, library files, etc. These files enable the application to be installed and run independently of the operating system. In this embodiment, when the first verification of the data to be changed fails, the preset exception handling process is entered, and exception information is output.

[0082] In this embodiment, the preset exception handling process refers to a series of measures that the system will take to process these abnormal data when the legality verification fails during the data change, upgrade, and solidification process. The preset exception handling process usually includes the following steps:

[0083] Abnormal Information Recording: Once an abnormality is detected, record the abnormal information. The abnormal information usually includes key information such as the type of the abnormality, the location where it occurred, and the time. This information helps with subsequent problem diagnosis and repair.

[0084] Log Recording: The abnormal information will be written into the system log. The log records the specific details of the occurrence of the abnormality, including the timestamp, error code, error message, etc., which is crucial for subsequent analysis and debugging.

[0085] Abnormal Notification: In some cases, relevant personnel or teams may be notified through the monitoring and alarm mechanism to handle the abnormal situation as soon as possible.

[0086] Abnormal Handling: Different handling measures may be taken according to the type and severity of the abnormality. This may include deleting abnormal data, correcting errors, replacing data, or rolling back to the previous stable state.

[0087] Data Rectification: For data inconsistency problems caused by abnormal operations, data rectification is required to ensure the ultimate consistency of the data. This may involve a locking mechanism to handle concurrency issues and ensure the correctness of the rectification operation.

[0088] Subsequent Analysis: After handling the abnormality, subsequent analysis may still be required to determine the cause of the abnormality and take measures to prevent future abnormalities from occurring.

[0089] Abnormal information refers to information such as the type of the abnormality, the location and time where the abnormality occurred. It can be divided into defined abnormal information and undefined abnormal information. Defined abnormal information means that the software system or program has already stated the type of the abnormality and the handling method for some common abnormalities. Undefined abnormal information refers to abnormalities that are not within the expected range of the system or program. This type of abnormal information generally only indicates the location where the abnormality occurred and there is no abnormal handling method. This kind of information can also be called vulnerability information. Abnormal logs are part of the system logs and record the detailed information when the abnormality occurs, including the timestamp, error level, error message, etc. These logs are very important for post-event analysis, problem location, and system maintenance.

[0090] S103: Perform a second verification on each newly added data segment.

[0091] In this embodiment, the second verification includes integrity verification, specifically referring to static integrity verification. Specifically, each newly added data segment can be second-verified through a verification value. The verification value can specifically be the hash value generated before transmission from the upgrade package or the data solidification module. Integrity verification can ensure that the newly added data segment can perform its own business functions normally.

[0092] In this embodiment, when the preset data types include system kernel type, business data type, and application software type, a second verification is performed on each newly added data segment, which specifically includes:

[0093] Perform a second verification on the newly added data segments whose preset data types are system kernel type or business data type. That is to say, directly perform integrity verification on the system kernel image file or business data image file.

[0094] However, for the newly added data segments whose preset data type is application software type, it is necessary to determine whether the newly added data segments whose preset data type is application software type are external programs.

[0095] When the newly added data segments whose preset data type is application software type are not external programs, perform a second verification on the newly added data segments whose preset data type is application software type. That is to say, directly perform integrity verification on the newly added data segments whose preset data type is application software type and are not external programs.

[0096] However, when the newly added data segments whose preset data type is application software type are external programs, it is necessary to perform integrity verification on the operating conditions of the newly added data segments whose preset data type is application software type.

[0097] After the integrity verification of the operating conditions passes, a second verification will be performed on the newly added data segments whose preset data type is application software type. That is to say, for the newly added data segments whose preset data type is application software type and are external programs, integrity verification cannot be directly performed. It is necessary to first perform integrity verification on the operating conditions. After the integrity verification of the operating conditions passes, a second verification will be performed on the newly added data segments whose preset data type is application software type. The second verification actually refers to the static integrity verification of ordinary image files and the integrity verification of the dynamic operating environment of application program image files after sorting and partitioning. It is the second verification relative to the first legality verification. Through the two verifications, the legality and integrity of the data are ensured, and unauthorized data tampering is prevented.

[0098] In this embodiment, when the integrity verification of the operating conditions fails or there are newly added data segments that fail the second verification among all the newly added data segments, enter the preset exception handling process and output exception information. Through the preset exception handling process, it is ensured that abnormal situations during the data change process are properly handled, preventing data damage or loss. For the detailed content, refer to the technical solution when the first verification fails, which will not be elaborated here.

[0099] In this embodiment, considering that the mirror image files after being burned are in different partitions, for the execution components with independent functions (execution components with independent functions: refer to the modules with independent functions in the system, such as the system kernel (corresponding to the newly added data segment with the preset data type of system kernel type), driver programs (corresponding to the newly added data segment with the preset data type of service data type), application programs (corresponding to the newly added data segment with the preset data type of application software type), etc.), it is best to store them in the same read-only area (for example, the optical disc area) and call them using relative paths. When other components of the system are needed, they can be found through the connection form and the environment variables can be loaded. Therefore, after the first verification passes, the data to be changed is sorted, that is, the data to be changed is divided according to the preset data type to obtain at least one newly added data segment. If it is found that the solidified mirror image file has an application program and it is external (that is, the newly added data segment with the preset data type of application software type is an external program), independent running verification (that is, running condition integrity verification) needs to be done additionally to ensure that its use will not be affected by the partition path problem after burning the mirror image. To ensure that these execution components with independent functions can be correctly identified and called, they can be stored in the relative paths of the same partition. The advantage of doing this is to simplify path management and component calling, because the system only needs to know a basic path and can access all components through relative paths.

[0100] S104: After the second verification of each newly added data segment passes, generate a newly added mirror image file and determine whether to reset the read-only area.

[0101] In this embodiment, a newly added mirror image file can be generated according to the newly added data segment that passes the second verification, and it is determined whether to reset the read-only area. Specifically, the mirror image file can be prepared in the current directory structure where the newly added data segment is located.

[0102] S105: When not resetting the read-only area, divide new sectors in the remaining space of the read-only area and burn each newly added mirror image file in the new sectors to implement data change.

[0103] In this embodiment, the above technical solution is a specific implementation of optimizing the storage space of the CDROM read-only area. That is, for those that do not involve changes, the mirror image file can be directly burned. Because it is a re-burning, its sector address is in the front and there will be no waste of empty addresses. For those that are changed or newly added, the addresses are extended backward in an appended form.

[0104] In this embodiment, when determining to reset the read-only area, obtain the backup image file corresponding to the image file that has not changed in the read-only area, format the read-only area, and perform the first write in the formatted read-only area. The first write is used to write the backup image file. Among them, new sectors are divided in the remaining space after the first write in the formatted read-only area. The second write is performed in the new sectors. The second write is used to write each newly added data segment. By formatting the read-only area, the security of the data is ensured, preventing unauthorized access and tampering.

[0105] In this embodiment, the ISO image file is backed up in the partition, and the ISO image file is backed up separately in the partition. The reasons are as follows: Solidifying data in the form of CDROM is to prevent tampering while allowing the files inside to participate in the normal operation of the system business. Therefore, the focus is on preventing tampering rather than recovery after being tampered with. For the backed-up ISO image file, in the form of the ISO image file, it will not participate in the system business operation. Its significance is that before the next solidification, there is no need to export the ISO image file from the CDROM read-only area again, but directly retain the ISO image file prepared in the previous time. This saves the time for resetting the CDROM read-only area.

[0106] Before writing, it is necessary to determine whether the current change requires changing the entire CDROM read-only area. It can be determined whether to reset the read-only area through preset conditions. The preset conditions include: The newly added data segment is a change to an existing CDROM read-only area, the component memory size after being changed by the newly added data segment is greater than the remaining space capacity of the CDROM read-only area, the change process does not want to be carried out by the method of recycling the original partition and expanding the new partition, and the total capacity size of the CDROM read-only area does not meet the condition for expanding the partition backward. Generally speaking, if it is an operation to newly add solidified data, as long as the capacity is sufficient, only a new ISO image file needs to be generated and written to the corresponding sector of the CDROM in the form of appending backward. However, when any one of the four situations in the preset conditions occurs, it is necessary to find out the backup image file of the ISO image file that does not change in the CDROM read-only area, rearrange it, and then perform the second write.

[0107] If at least one of the above preset conditions is satisfied, it is determined to reset the read-only area. If each of the above preset conditions is satisfied, it is determined not to reset the read-only area.

[0108] When at least one of the above preset conditions is triggered, it is necessary to format the entire disk space of the current CDROM. Before that, it is necessary to find the ISO image file backed up corresponding to the partition.

[0109] Write the unchanged image file after formatting, and allocate new sectors in the remaining space to write the image file changed or newly added in this time.

[0110] In an alternative embodiment, after each new image file is burned in the new sector, the data change method further includes: changing the device mounting configuration and the initialization script. By changing the device mounting configuration and the initialization script, it is ensured that the system after the data change can correctly recognize and use the new data.

[0111] After the sector is updated, it is necessary to change the device mounting configuration and the initialization script of the file system so that the solidified file can be used in the file system as close as possible to the normal path, which is convenient for the upper-layer software to call and the user to use. Considering the change of the sector position of the CDROM, in the upper-layer application, in order to keep the original file system directory position unchanged, it is necessary to update the address mapping table, that is, the directory mapping relationship between the read-only area of the CDROM and the file system mounted in the operating system (changing the device mounting configuration of the file system). If there are changes to the operating system kernel and the boot file, it is necessary to update the boot program and restart the system to switch to the new kernel. This is a process that must be passed through whether the kernel or the boot program is updated. It can be analogously understood as: when the configuration file is updated, the corresponding process needs to reload the configuration file. When the application service is updated, the service process needs to be restarted. When the kernel program is updated, the new kernel needs to be loaded, and only by restarting the operating system can the new kernel be loaded.

[0112] The overall process of the technical solution of the present invention is as Figure 3 shown. The technical solution of the present invention restricts the read-only permissions of key data and programs at the hardware level, which can effectively prevent tampering and the destruction of malicious programs. Through built-in mirror preparation, mirror burning, and organizing directory partitions, after one update and organization, during normal use, there is no need to control the read and write permissions through the restrictions of the kernel or other application programs, which improves the software operation efficiency and reduces the consumption of computing resources. It can effectively prevent the device from being disassembled, the disk being mounted, and the protected data being modified by reading the data method, ensuring the integrity of the current component operation. During the upgrade process, the human operation is separated, the core steps are encapsulated and atomic operations, reducing the risk of error introduction and the complexity of problems for the implementers. The upgrade of the technical solution of the present invention involves the update after obtaining the upgrade package and does not involve how to obtain the upgrade package. The technical solution of the present invention involves file solidification, specifically involving file solidification based on burning the mirror into the read-only area of the CDROM, as well as the upgrade, update, and maintenance of the solidified files.

[0113] Considering that if a large ISO image is re-made and burned every time the data changes, it will inevitably waste computing resources and slow down the system for useless work. To avoid wasting computing resources, the technical solution of the present invention classifies the data to be changed, divides it into three major types according to functions, and divides the remaining space of the read-only area of the CDROM to determine its corresponding new sector. This helps to keep the irrelevant solidified data unchanged during data update and solidification, reducing unnecessary consumption.

[0114] It should be noted that the content not described in detail in the specification of the present invention belongs to the well-known technology in the art.

[0115] In this embodiment, a data change device is further provided. A single device is used to implement the above-mentioned embodiment and optional implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0116] Figure 4 It is a schematic structural diagram of the data change device according to the embodiment of the present invention.

[0117] The present invention provides a data change device, as Figure 4 shown, the data change device includes:

[0118] The first processing module 11 is used to perform a first verification on the data to be changed. The data to be changed is the burned image file. The first verification includes a legality verification.

[0119] The second processing module 12 is used to divide the data to be changed according to a preset data type after the first verification of the data to be changed is passed, so as to obtain at least one new data segment. Each new data segment corresponds to a preset data type.

[0120] The third processing module 13 is used to perform a second verification on each new data segment. The second verification includes an integrity verification.

[0121] The fourth processing module 14 is used to generate a new image file and determine whether to reset the read-only area after the second verification of each new data segment passes.

[0122] The fifth processing module 15 is used to divide new sectors in the remaining space of the read-only area when the read-only area is not reset, and burn each new image file in the new sectors to implement data change.

[0123] In an optional implementation manner, the data change device further includes: a data acquisition module.

[0124] The data acquisition module is used to download an upgrade package and transfer the downloaded upgrade package to the security area before performing the first verification on the data to be changed. The security area is provided with a firmware upgrade and maintenance module. The upgrade package is processed and analyzed by the firmware upgrade module to determine the data to be changed.

[0125] Alternatively, according to the partition where the data to be changed is currently located, call the data solidification module corresponding to the partition, and determine the data to be changed through the data solidification module. Pass the data to be changed determined by the data solidification module into the security area. Among them, the data to be changed in the security area is used for the first verification.

[0126] In an alternative embodiment, when the preset data types include system kernel type, business data type, and application software type, the third processing module 13 is specifically configured to perform a second verification on the newly added data segments of which the preset data type is the system kernel type or the business data type. Determine whether the newly added data segments of which the preset data type is the application software type are external programs. When the newly added data segments of which the preset data type is the application software type are not external programs, perform a second verification on the newly added data segments of which the preset data type is the application software type. When the newly added data segments of which the preset data type is the application software type are external programs, perform a running condition integrity verification on the newly added data segments of which the preset data type is the application software type. After the running condition integrity verification passes, perform a second verification on the newly added data segments of which the preset data type is the application software type.

[0127] In an alternative embodiment, the data change device further includes: an exception handling module. The exception handling module is configured to enter a preset exception handling process and output exception information when there are newly added data segments that fail the second verification among all the newly added data segments.

[0128] In an alternative embodiment, the data change device further includes: a sixth processing module. The sixth processing module is configured to, when determining to reset the read-only area, obtain the backup image file corresponding to the image file that has not changed in the read-only area, format the read-only area, and perform the first write in the formatted read-only area. The first write is used to write the backup image file. Among them, new sectors are divided in the remaining space after the first write in the formatted read-only area. The second write is performed in the new sectors. The second write is used to write each newly added data segment.

[0129] In an alternative embodiment, the data change device further includes: an update module. The update module is configured to change the device mounting configuration and initialization script after writing each newly added image file in the new sectors.

[0130] The further function descriptions of the above various modules and units are the same as those in the corresponding embodiments above, and will not be repeated here.

[0131] The data change device in this embodiment is presented in the form of a functional unit. Here, the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0132] An embodiment of the present invention further provides a computer device having the above-mentioned Figure 4 data change device.

[0133] Please refer to Figure 5 , Figure 5 which is a schematic diagram of the hardware structure of the computer device according to an embodiment of the present invention. As Figure 5 shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In an alternative embodiment, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a set of blade servers, or a multi-processor device). Figure 5 In

[0134] FIG. 1, one processor 10 is taken as an example.

[0135] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.

[0136] The memory 20 may include a program storage area and a data storage area. Among them, the program storage area can store the operating device and application programs required for at least one function. The data storage area can store data created according to the use of the computer device and the like. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In an alternative embodiment, the memory 20 may optionally include a memory remotely disposed relative to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0137] The memory 20 may include a volatile memory, for example, a random access memory. The memory may also include a non-volatile memory, such as a flash memory, a hard disk, or a solid-state drive. The memory 20 may also include a combination of the above types of memories.

[0138] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or communication networks.

[0139] The embodiments of the present invention also provide a computer-readable storage medium. The methods according to the embodiments of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the methods described herein can be stored in such software processes on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc. Further, the storage medium may also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the methods shown in the above embodiments are implemented.

[0140] A part of the present invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can call or provide the methods and / or technical solutions according to the present invention through the operations of the computer. Those skilled in the art should understand that the forms of existence of computer program instructions in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways for a computer to execute computer program instructions include, but are not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Herein, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.

[0141] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A data modification method, characterized in that: include: Performing a first check on the data to be changed; the first check includes a legality check; After the first verification of the data to be changed passes, the data to be changed is divided according to the preset data type to obtain at least one newly added data segment; each of the newly added data segments corresponds to a preset data type; Performing a second check on each newly added data segment; the second check includes an integrity check; After the second verification of each newly added data fragment passes, a new mirror file is generated to determine whether to reset the read-only area; When the read-only area is not reset, a new sector is divided in the remaining space of the read-only area, and each newly added image file is burned in the new sector to realize data change; The preset data types include system kernel types, business data types and application software types, and the second verification of each newly added data segment includes: Performing a second check on the newly added data fragments whose preset data type is a system kernel type or a business data type; Determine whether the newly added data segment whose preset data type is application software type is an external program; When the newly added data segment whose preset data type is the application software type is not an external program, a second verification is performed on the newly added data segment whose preset data type is the application software type; When the newly added data segment whose preset data type is application software type is an external program, the newly added data segment whose preset data type is application software type is subjected to running condition integrity check, wherein the running condition integrity check is an independent running verification to ensure that the newly added data segment will not be affected by the partition path problem after the image is burned, and can be correctly identified and called; After the running condition integrity check is passed, a second check is performed on the newly added data segment whose preset data type is the application software type.

2. The method according to claim 1, characterized in that Before performing the first verification on the data to be changed, the method further includes: Downloading an upgrade package, and transferring the downloaded upgrade package to a safe zone; the safe zone is provided with a firmware upgrade maintenance module; the upgrade package is processed and analyzed by the firmware upgrade maintenance module to determine the data to be changed; Or, according to the partition where the data to be changed is currently located, call the data solidification module of the corresponding partition, determine the data to be changed through the data solidification module; transfer the data to be changed determined by the data solidification module to the safe area; wherein the data to be changed in the safe area is used for the first verification.

3. The method according to claim 1, characterized in that The method further includes: when there is a new data segment that fails the second verification among all the new data segments, entering a preset exception processing flow and outputting exception information.

4. The method according to claim 1, characterized in that The step of determining whether to reset the read-only area comprises: When it is determined to reset the read-only area, a backup image file corresponding to the image file that has not been changed in the read-only area is obtained, the read-only area is formatted, and a first burn is performed in the formatted read-only area; the first burn is used to burn the backup image file; wherein a new sector is divided in the remaining space after the first burn in the formatted read-only area; A second programming is performed in the new sector; the second programming is used to program each newly added data segment.

5. The method according to claim 1, characterized in that After the new sector is burned with each newly added image file, the method further includes: changing the device mounting configuration and the initialization script.

6. A data changing device, characterized in that: include: A first processing module, used for performing a first check on the data to be changed; the first check includes a legality check; A second processing module is used to divide the data to be changed according to preset data types after the first verification of the data to be changed passes, so as to obtain at least one newly added data segment; each of the newly added data segments corresponds to a preset data type; A third processing module, configured to perform a second check on each newly added data segment; the second check includes an integrity check; A fourth processing module, configured to generate a new mirror file and determine whether to reset the read-only area after each new data segment passes the second verification; A fifth processing module, configured to divide a new sector from the remaining space of the read-only area when the read-only area is not reset, and burn each newly added image file in the new sector to realize data change; When the preset data type includes a system kernel type, a business data type and an application software type, the third processing module is specifically used to perform a second check on the newly added data segment whose preset data type is a system kernel type or a business data type; Determine whether the newly added data segment whose preset data type is application software type is an external program; When the newly added data segment whose preset data type is the application software type is not an external program, a second verification is performed on the newly added data segment whose preset data type is the application software type; When the newly added data segment whose preset data type is application software type is an external program, the newly added data segment whose preset data type is application software type is subjected to running condition integrity check, wherein the running condition integrity check is an independent running verification to ensure that the newly added data segment will not be affected by the partition path problem after the image is burned, and can be correctly identified and called; After the running condition integrity check is passed, a second check is performed on the newly added data segment whose preset data type is the application software type.

7. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the data changing method according to any one of claims 1 to 5 by executing the computer instructions.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the data changing method according to any one of claims 1 to 5.

9. A computer program product, characterized in that The method comprises computer instructions, wherein the computer instructions are used to cause a computer to execute the data changing method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Dynamic storage method of Flash memory

    CN101446921A

  • Program code protection method for microprocessor adopting flash memory

    CN104268448A

  • Firmware upgrading method and device, computer equipment and storage medium

    CN111176702A

  • Mirror image processing method, computer program product, device and storage medium

    CN118656036A