A separate data hardware channel encryption device
By physically separating the encryption/decryption module from the storage medium and controlling it using a hardware data link with a switch, the problems of encryption/decryption and storage coupling, insufficient hardware link security, and data leakage prevention in existing technologies are solved, thereby improving data security and storage efficiency.
Patent Information
- Application Number
- CN202411723993.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-11-28
AI Technical Summary
Existing discrete hardware encryption technologies suffer from problems such as coupling encryption/decryption with storage, insufficient hardware link security, and inadequate data leakage prevention capabilities.
A separate data hardware path encryption device is adopted, which physically separates the encryption and decryption functions from the data storage functions. Data flow control is achieved by using a hardware data link with a switch, and key information is configured through an information management module for verification and isolation.
It improves data security, prevents data leakage during storage and transmission, enhances data protection capabilities in case of equipment malfunction or theft, and improves storage efficiency and the integrity of encrypted data.
Smart Images

Figure CN119577803B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer security hardware and data encryption technology, and more specifically, to a separate data hardware path encryption device. Background Technology
[0002] Data encryption is a core technology in the field of information security, used to protect the confidentiality and integrity of data during transmission and storage. Traditional data encryption systems typically rely on software encryption algorithms to encrypt and decrypt data within the computer system. However, software encryption methods often face limitations in computing power and potential security vulnerabilities.
[0003] To improve the efficiency and security of data encryption, many modern computer systems have begun to employ hardware encryption modules (e.g., dedicated encryption chips) to perform data encryption operations. Hardware encryption modules typically offer high processing speed and security because they can prevent interference from malware and attackers at the physical level. For example, decoupled hardware encryption technology aims to further enhance data security by separating encryption and decryption operations from the data storage medium. In this approach, data encryption and decryption are performed by a dedicated hardware module, while data storage is handled by a separate hardware medium. This separation design helps prevent data leakage during storage and transmission, offering a significant security advantage, especially against physical attacks.
[0004] Despite some progress in existing discrete hardware encryption technologies, the following problems remain: (1) Coupling of encryption / decryption and storage: In many existing technologies, encryption and storage operations are usually performed through tightly integrated hardware modules, which may compromise the physical security of the encryption module. If an attacker gains access to the storage medium, they may be able to bypass encryption protection. (2) Security of hardware links: Hardware links in existing technologies (such as data buses and interfaces) often lack sufficient protection measures. Modern links often use a combination of data and control paths, which has a low security level and may be exploited by attackers to steal or tamper with data. (3) Insufficient data leakage prevention: In the event of data loss or equipment theft, existing data protection measures may be insufficient to prevent the leakage of sensitive data. Summary of the Invention
[0005] To address the shortcomings of existing technologies, the purpose of this invention is to provide a separate data hardware path encryption device that physically separates encryption / decryption functions from data storage functions. This ensures that encryption / decryption operations are performed in a dedicated hardware module, while data storage occurs on an independent hardware medium. This design effectively avoids the risk of data being directly accessed and cracked during storage.
[0006] The above-mentioned technical objective of the present invention is achieved through the following technical solution: a separate data hardware path encryption device, comprising:
[0007] The host control module is used to encrypt written data and / or decrypt read data, and to control the data flow through a first hardware data link with a switch.
[0008] The system storage module is used to save encrypted data through storage hardware media and to control the data flow through a second hardware data link with a switch.
[0009] The information management module is used to generate key information based on the input configuration information;
[0010] The information management module configures key information to the host control module and the system storage module to enable the switch to be turned on and off.
[0011] Furthermore, the host control module and the system storage module transmit data through the first interface, and the host control module, the system storage module, and the information management module configure and verify key information through the second interface.
[0012] Furthermore, when the information management module and the host control module are connected via the second interface, the information management module configures the private key in the key information into the host control module;
[0013] When the information management module and the system storage module are connected via the second interface, the information management module configures the public key in the key information into the system storage module.
[0014] Furthermore, after receiving the user's instruction to request data, the host control module and the system storage module verify the pairing of public and private keys through the second interface;
[0015] When pairing verification is successful, the switches in both the first and second hardware data links are closed.
[0016] When pairing verification fails, the switches in both the first and second hardware data links are disconnected.
[0017] Furthermore, the host control module automatically generates instructions for user request data after power-on;
[0018] Additionally, after the initial pairing verification is successful, the host control module and the system storage module will periodically perform pairing verification.
[0019] Furthermore, the first interface is a SATA interface, and the second interface is a USB interface.
[0020] Furthermore, the host control module is equipped with a first MCU and a data encryption / decryption chip;
[0021] The data encryption / decryption chip is installed on the first hardware data link to encrypt written data and / or decrypt read data.
[0022] The first MCU is connected to a switch in the first hardware data link to output instructions to control the opening and closing of the corresponding switch;
[0023] Furthermore, the system storage module is equipped with a second MCU;
[0024] The second MCU is connected to a switch in the second hardware data link to output commands to control the opening and closing of the corresponding switch.
[0025] Furthermore, the switch is a network splitter.
[0026] Furthermore, the storage hardware medium is a solid-state drive or a hard disk drive.
[0027] Furthermore, the host control module, system storage module, and information management module are all equipped with a memory for storing module information.
[0028] Furthermore, both the host control module and the system storage module are equipped with download and burning pads for program updates.
[0029] Compared with the prior art, the present invention has the following beneficial effects:
[0030] 1. This invention provides a separate data hardware path encryption device, which improves data security and leakage prevention by physically separating the data encryption / decryption module from the data storage medium. In this separate hardware encryption technology, data encryption / decryption operations are performed by a dedicated hardware module, while data storage is handled by an independent hardware medium. This separation design helps prevent data leakage during storage and transmission, effectively avoiding the risk of data being directly accessed and cracked during storage.
[0031] 2. This invention controls the data flow through a hardware data link with a switch. The switch function can not only effectively isolate the direct connection between the encryption / decryption module and the storage medium, but also automatically disconnect the data link when the device is malfunctioning or problems occur during data transmission, further ensuring data security.
[0032] 3. By physically separating the data encryption / decryption module from the storage medium, this invention significantly improves data security. Even if the storage device is stolen or lost, the encryption / decryption function is not directly connected to the storage medium, greatly increasing the difficulty of cracking the data and reducing the risk of data leakage.
[0033] 4. In terms of storing encrypted target data, this invention adopts a storage scheme optimized for encrypted data, which not only improves storage efficiency but also ensures the integrity and efficient management of encrypted data, avoiding bottleneck problems in the data processing process. Attached Figure Description
[0034] The accompanying drawings, which are included to provide a further understanding of embodiments of the invention and form part of this application, do not constitute a limitation thereof. In the drawings:
[0035] Figure 1 This is a structural schematic diagram of the information management module in an embodiment of the present invention;
[0036] Figure 2 This is a schematic diagram of the host control module in an embodiment of the present invention;
[0037] Figure 3 This is a schematic diagram of the system storage module in an embodiment of the present invention. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0039] It should be noted that when a component is referred to as being "fixed to" or "set on" another component, it can be directly or indirectly attached to that other component. When a component is referred to as being "connected to" another component, it can be directly or indirectly connected to that other component.
[0040] It should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the present invention.
[0041] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0042] Example: A separate data hardware path encryption device includes a host control module, a system storage module, and an information management module. The host control module is used to encrypt written data and / or decrypt read data, and controls the data flow through a first hardware data link with a switch. The system storage module is used to store encrypted data through a storage hardware medium, and controls the data flow through a second hardware data link with a switch. The information management module is used to generate key information based on input configuration information.
[0043] Specifically, the information management module configures key information to the host control module and the system storage module to enable the switching on and off; and the host control module and the system storage module transmit data through a first interface, while the host control module, the system storage module and the information management module configure and verify key information through a second interface.
[0044] I. Information Management Module
[0045] Typically, the information management module is a device configured by administrators. After connecting the information management module to the administrator's computer, the administrator inputs configuration data through a dedicated interface, including information such as the user host number and external storage system number. Once configured, the information management module securely stores the information in its memory and performs authentication upon system startup.
[0046] System initialization and configuration: Install system software and configure the relational database on the administrator's computer. Clear old user configuration data from flash memory and read the device ID of each module.
[0047] Module number registration: Register and save the user's host control module number, external storage system module number, external interface module number, and external administrator module number to the database respectively.
[0048] Module Configuration: 1. User Host Control Module: Configure its number in flash memory. 2. External System Storage Module: (1) Set disk password. (2) Configure key information (including user, usage period, security level, matching external interface module ID, and the user host control module number). 3. External Interface Module: Configure its number in flash memory. 4. External Administrator Module: (1) Configure its number and host information in flash memory. (2) Configure system storage module and interface module information in flash memory.
[0049] Authentication and Startup: 1. The external storage module and interface module authenticate and connect. 2. After the user enters the disk password, a pop-up window displays key information, and the user confirms whether to continue startup.
[0050] like Figure 1 As shown, the information management module is configured with a key unit and a third MCU. The key unit can generate key information based on the configured information. The key information includes a paired public key and a private key.
[0051] When the information management module and the host control module are connected via the second interface, the third MCU configures the private key from the key information into the host control module; when the information management module and the system storage module are connected via the second interface, the third MCU configures the public key from the key information into the system storage module.
[0052] In this embodiment, the second interface is a USB interface.
[0053] II. Main Unit Control Module
[0054] like Figure 2 As shown, the host control module is configured with a first MCU and a data encryption / decryption chip; the data encryption / decryption chip is installed on the first hardware data link to encrypt written data and / or decrypt read data; the first MCU is connected to a switch in the first hardware data link to output instructions to control the opening and closing of the corresponding switch.
[0055] When a user requests data, the host control module receives the request and verifies the user's identity. The original data is then encrypted using a data encryption / decryption chip, generating an encrypted data stream. This encrypted data is transmitted to the storage module via a hardware data link with a switch.
[0056] III. System Storage Module
[0057] The system storage module is equipped with a second MCU; the second MCU is connected to a switch in the second hardware data link to output commands to control the opening and closing of the corresponding switch.
[0058] In this embodiment, the storage hardware medium is a solid-state drive or a hard disk drive, or other suitable storage devices.
[0059] In addition, both the host control module and the system storage module are equipped with download and burning pads for program updates.
[0060] After administrator configuration, the system starts. Users request data access and enter their disk password. The host control module verifies the user's identity and decrypts the data, ensuring only authorized users can access it. All operation logs are recorded in the module's Flash memory for subsequent auditing.
[0061] Specifically, after the host control module is powered on, it automatically generates a user request data instruction. The first MCU and the second MCU will then perform public and private key pairing and verification through the second interface (SATA interface). When the pairing and verification is successful, it means that the identity verification is successful. The first MCU will control the switch in the first hardware data link to close, and the second MCU will control the switch in the second hardware data link to close. When the pairing and verification is unsuccessful, the switches in both the first and second hardware data links will be disconnected.
[0062] The host control module transmits data to the system storage module via a hardware data link with a switch, ensuring that data is only transmitted after successful verification. The interaction between the system storage module and the information management module is primarily for log recording and configuration information updates.
[0063] Write data stream: Data is input from the application via an interface. The input data is encrypted using an HX0168 national cryptographic chip to ensure data security. When the host control module switch (ASW3410 network splitter) is in the ON state, the encrypted data is transmitted via the bus. When the storage module switch (ASW3410 network splitter) is in the ON state, data is transmitted via the SATA data cable and stored in the solid-state drive.
[0064] Read Data Stream: Data is read from the storage module. With the storage module switch (ASW3410 network splitter) on, data is transmitted to the bus via the SATA data cable. With the host control module switch (ASW3410 network splitter) on, the data is decrypted by the HX0168 national cryptographic chip, restoring it to its original state. The decrypted data is then transmitted to the application for further processing or display.
[0065] In this invention, the SM4 algorithm is used to protect the confidentiality and integrity of data.
[0066] Working principle: This invention improves data security and leakage prevention by physically separating the data encryption / decryption module from the data storage medium. In this separated hardware encryption technology, data encryption and decryption operations are performed by a dedicated hardware module, while data storage is handled by an independent hardware medium. This separation design helps prevent data leakage during storage and transmission, effectively avoiding the risk of data being directly accessed and cracked during storage.
[0067] In addition, the present invention controls the data flow through a hardware data link with a switch. The switch function can not only effectively isolate the direct connection between the encryption / decryption module and the storage medium, but also automatically disconnect the data link when the device is malfunctioning or problems occur during data transmission, thereby further ensuring data security.
[0068] This invention significantly improves data security by physically separating the data encryption / decryption module from the storage medium. Even if the storage device is stolen or lost, the encryption / decryption function is not directly connected to the storage medium, greatly increasing the difficulty of cracking the data and reducing the risk of data leakage.
[0069] In terms of storing encrypted target data, this invention adopts a storage scheme optimized for encrypted data, which not only improves storage efficiency but also ensures the integrity and efficient management of encrypted data, avoiding bottleneck problems in the data processing process.
[0070] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0071] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0072] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0073] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0074] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A separate data hardware path encryption device, characterized in that, include: The host control module is used to encrypt written data and / or decrypt read data, and to control the data flow through a first hardware data link with a switch. The system storage module is used to save encrypted data through storage hardware media and to control the data flow through a second hardware data link with a switch. The information management module is used to generate key information based on the input configuration information; The information management module configures key information to the host control module and the system storage module to enable the switch to be turned on and off. Furthermore, the host control module and the system storage module transmit data through the first interface, and the host control module, the system storage module, and the information management module configure and verify key information through the second interface.
2. The separate data hardware path encryption device according to claim 1, characterized in that, When the information management module and the host control module are connected via the second interface, the information management module configures the private key in the key information into the host control module; When the information management module and the system storage module are connected via the second interface, the information management module configures the public key in the key information into the system storage module.
3. The separate data hardware path encryption device according to claim 1, characterized in that, After receiving the user's instruction to request data, the host control module and the system storage module verify the pairing of public and private keys through the second interface. When pairing verification is successful, the switches in both the first and second hardware data links are closed. When pairing verification fails, the switches in both the first and second hardware data links are disconnected.
4. The separate data hardware path encryption device according to claim 3, characterized in that, The host control module automatically generates instructions for user request data after power-on. Additionally, after the initial pairing verification is successful, the host control module and the system storage module will periodically perform pairing verification.
5. The separate data hardware path encryption device according to claim 1, characterized in that, The first interface is a SATA interface, and the second interface is a USB interface.
6. The separate data hardware path encryption device according to claim 1, characterized in that, The host control module is equipped with a first MCU and a data encryption / decryption chip; The data encryption / decryption chip is installed on the first hardware data link to encrypt written data and / or decrypt read data. The first MCU is connected to a switch in the first hardware data link to output instructions to control the opening and closing of the corresponding switch; Furthermore, the system storage module is equipped with a second MCU; The second MCU is connected to a switch in the second hardware data link to output commands to control the opening and closing of the corresponding switch.
7. The separate data hardware path encryption device according to claim 1, characterized in that, The switch is a network splitter.
8. The separate data hardware path encryption device according to claim 1, characterized in that, The storage hardware medium is a solid-state drive or a hard disk drive.
9. A separate data hardware path encryption device according to claim 1, characterized in that, The host control module, system storage module, and information management module are all equipped with a memory for storing module information.
10. A separate data hardware path encryption device according to claim 1, characterized in that, Both the host control module and the system storage module are equipped with download and burning pads for program updates.
Citation Information
Patent Citations
Mobile hard disc enciphering system of FPGA control MEMS strong chain
CN101281499A
Data storage device
CN118466836A