A method and system for transparent encryption and decryption of DCS controller files

By inserting a transparent encryption and decryption driver module on the DCS controller and generating an encryption and decryption key, the problem of the DCS controller lacking transparent encryption and decryption function is solved, and efficient encryption and decryption of files is achieved, improving security and operation efficiency.

CN119696928BActive Publication Date: 2025-06-03XIAN THERMAL POWER RES INST CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510197240.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-03
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

The lack of transparent file encryption and decryption function on the DCS controller leads to a relatively insufficient security.

Method used

The transparent encryption and decryption driver module is inserted between the virtual file system layer and the file system layer of the DCS controller kernel, and the encryption and decryption key is generated through the password module, and the encryption and decryption information is added to the head of the file to realize transparent encryption and decryption of the file.

Benefits of technology

It improves the security of file encryption and decryption keys, effectively prevents important data from being stolen, ensures independent encryption and decryption keys for each file, and improves system operation efficiency and file security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696928B_ABST
    Figure CN119696928B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for transparent encryption and decryption of DCS controller files, belonging to the technical field of network industrial control security. The method includes: inserting a transparent encryption and decryption driver module between the file system layer and the virtual file system layer of the DCS controller kernel, generating an encryption and decryption key through a password module as the root key for file encryption and decryption, obtaining a ciphertext encryption and decryption key by encrypting a random number with the root key, the transparent encryption and decryption driver module appending encryption information to the encrypted file header, encrypting the file in blocks and then writing it to the disk; respectively managing the encryption and decryption key when reading and writing the encrypted file, and performing transparent decryption on the plaintext file on the disk. Through transparent encryption, the present invention prevents important data from being stolen, precisely controls each file by configuring encryption and decryption policies for individual files or directories, ensures that only files that need to be encrypted and protected are encrypted, and the general files are still stored in plaintext, improving the operation efficiency of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network industrial control security, and particularly relates to a method and system for transparent encryption and decryption of DCS controller files. Background Art

[0002] At present, general mainstream systems have their own methods for transparent encryption and decryption. For example, bitlocker for windows and LUKS (Linux Unified Key Setup) for the linux system, etc. Using these transparent encryption systems, specified disks and the like can be encrypted. Even if the disk is removed and inserted into other systems, since the entire file disk is encrypted and there is no decryption key, the data content of the disk cannot be read out, thus effectively improving the security of important assets and confidential data to a certain extent. However, for the real-time operating system SylixOS used by DCS (Distributed Control System) controllers, since there is no such mechanism that can perform transparent encryption and decryption, its security is relatively insufficient. Summary of the Invention

[0003] The present invention provides a method and system for transparent encryption and decryption of DCS controller files, aiming to solve the problem of the lack of file transparent encryption and decryption functions on DCS controllers.

[0004] The present invention provides a method for transparent encryption and decryption of DCS controller files, including the following steps:

[0005] S1. Insert a layer of transparent encryption and decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel;

[0006] S2. Initialize the transparent encryption and decryption driver module, generate an encryption and decryption key through the password module of the DCS controller, and store it in the secure storage area of the password module as the root key for file encryption and decryption;

[0007] S3. When configuring the encryption and decryption policy of the configuration file, the transparent encryption and decryption driver module calls the password module to generate a random number as the encryption and decryption key of the file, and encrypts the random number with the root key to obtain the ciphertext encryption and decryption key;

[0008] Among them, the transparent encryption and decryption driver module:

[0009] When configuring the encryption and decryption policy for a single file, the single file is encrypted and stored wherever it is moved;

[0010] When configuring the encryption and decryption policy for a directory, the files in the directory and the files in the recursive subdirectories are encrypted and stored, and each file corresponds to a key;

[0011] Decrypt the files moved out of the directory and write them to disk;

[0012] S4. The transparent encryption and decryption driver module appends encryption information to the encrypted file header, encrypts the file in chunks and writes it to disk; the encryption information includes the file size, the ciphertext encryption and decryption key, and the size of the encrypted data;

[0013] S5. When reading an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header, and reads the ciphertext encryption and decryption key of the encrypted file and the size of the encrypted data from it. Use the root key to decrypt the ciphertext encryption and decryption key to obtain the plaintext key of the file, and then decrypt the encrypted file in chunks until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is less than the actual size of the encrypted file, the unencrypted data is directly read out and returned;

[0014] When writing an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the encrypted file header, and extracts the ciphertext encryption and decryption key of the encrypted file from it. Use the root key to decrypt the ciphertext encryption and decryption key to obtain the plaintext key of the encrypted file, then encrypt the encrypted file in chunks and store it on disk, and store the actual size of the encrypted data in the field represented by the size of the encrypted data.

[0015] In some embodiments, in S2, the encryption and decryption root key is generated by the password module and stored in the secure storage area. The password module includes a trusted password module TCM or an encryption card of a third-party manufacturer.

[0016] In some embodiments, in S3, when configuring the transparent encryption policy for a single file or directory, each file under the single file or directory will have an independent encryption and decryption key. Each independent encryption and decryption key is based on a random number generated by the password module and is encrypted and protected by the root key.

[0017] In some embodiments, in S4, the encryption information appended to the file header is managed by the transparent encryption and decryption driver module.

[0018] In some embodiments, in S4, the files under the single file or directory configured with the encryption policy are initially encrypted, and the files are stored on disk as ciphertext after being encrypted; during the initial encryption, encryption information is appended to the file header, and the size of the encrypted data represents the actual size of the file. When decrypting, decrypt the actually encrypted content according to the size of the encrypted data, and the unencrypted content does not need to be decrypted.

[0019] In some embodiments, in S5, when reading an encrypted file, first read the encrypted information at the file header, and use the root key to decrypt the ciphertext encryption / decryption key stored in the file header to obtain the plaintext encryption / decryption key of the file. Then, read the size of the encrypted data in the file. When the size of the encrypted data is less than the actual size of the file, only decrypt the encrypted data to obtain the plaintext file and return it to the user.

[0020] In some embodiments, in S5, when writing an encrypted file, after obtaining the plaintext encryption / decryption key of the file, update the new total size information of the file into the encrypted information at the file header, and then perform block encryption on the file; for each block of data encrypted, update the size of the encrypted data in the encrypted information. Finally, encrypt all the data of the file and store it on the disk.

[0021] The present invention also provides a system for transparent encryption and decryption of DCS controller files, which is used to implement the method for transparent encryption and decryption of DCS controller files. The system includes a generation unit, an encryption / decryption policy configuration unit, an encryption unit, a reading unit, and a writing unit, where:

[0022] The generation unit is used to insert a layer of transparent encryption / decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel; initialize the transparent encryption / decryption driver module, generate an encryption / decryption key through the password module of the DCS controller, and store it in the secure storage area of the password module as the root key for file encryption and decryption;

[0023] The encryption / decryption policy configuration unit is used to, when configuring the encryption / decryption policy of the file, the transparent encryption / decryption driver module calls the password module to generate a random number as the encryption / decryption key of the file, and encrypts the random number with the root key to obtain the ciphertext encryption / decryption key;

[0024] The encryption unit is used to, for an encrypted file, the transparent encryption / decryption driver module appends encrypted information to the file header and writes the file to the disk after block encryption; the encrypted information includes the file size, the ciphertext encryption / decryption key, and the size of the encrypted data;

[0025] The reading unit is used to, when reading an encrypted file, the transparent encryption / decryption driver module reads the encrypted information from the file header, and reads the ciphertext encryption / decryption key and the size of the encrypted data of the encrypted file from it. After using the root key to decrypt the ciphertext encryption / decryption key to obtain the plaintext key of the file, perform block decryption on the encrypted file until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is less than the actual size of the encrypted file, the unencrypted data is directly read out and returned;

[0026] When writing an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the head of the encrypted file, extracts the ciphertext encryption and decryption key of the encrypted file from it, decrypts the ciphertext encryption and decryption key with the root key, and after obtaining the plaintext key of the encrypted file, performs block encryption on the encrypted file and stores it on the disk, and stores the actual size of the encrypted data in the field represented by the size of the encrypted data.

[0027] The present invention also provides a computer device, including a memory, a processor, and a computer program running on the memory. When the processor executes the computer program, the steps of the method for transparent encryption and decryption of DCS controller files as described above are implemented.

[0028] The present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the method for transparent encryption and decryption of DCS controller files as described above are implemented.

[0029] Compared with the prior art, a method and system for transparent encryption and decryption of DCS controller files of the present invention have the following beneficial effects:

[0030] In the initialization stage of the present invention, the DCS controller generates an encryption and decryption root key and stores it in the hardware password module. When configuring the policy of the file, a separate encryption and decryption key for the file is generated through a random number, and after being encrypted with the root key, the ciphertext encryption and decryption key of the file is stored in the encryption information at the head of the file, improving the security of the encryption and decryption key of the file. When initializing the file policy, the file is encrypted once with the key of the file, and the encrypted ciphertext is stored on the disk. Through transparent encryption, the present invention effectively prevents important data from being stolen. By configuring encryption and decryption policies for individual files or directories, each file can be precisely controlled to ensure that only important files that need to be encrypted and protected are encrypted, while general files are still stored in plaintext, improving the system operation efficiency. In addition, the present invention does not use the same key for all files, but each file has its own encryption and decryption key, and this key is encrypted and protected with the root key in the hardware password module, thus effectively protecting the security of the key. Even if the key of a certain file is leaked, other files are still secure, greatly improving the security of each file. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The accompanying drawings in the specification are used to provide a further understanding of the present invention, and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0032] Figure 1 It is a schematic flowchart of a method for transparent encryption and decryption of DCS controller files of the present invention;

[0033] Figure 2 It is a schematic diagram of the processing flow for reading / writing files in a method for transparent encryption and decryption of DCS controller files according to the present invention;

[0034] Figure 3 It is a schematic diagram of the architecture of a system for transparent encryption and decryption of DCS controller files according to the present invention;

[0035] Figure 4 It is a schematic diagram of a computer processing device according to the present invention. Detailed implementation manners

[0036] In order to make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.

[0037] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0038] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0039] In the description of the embodiments of the present invention, it should be noted that if terms such as "upper", "lower", "horizontal", "inner", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings or the orientation or positional relationship when the product of the present invention is normally placed. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be construed as a limitation of the present invention. In addition, terms such as "first", "second", etc. are only used for descriptive distinction and cannot be construed as indicating or implying relative importance.

[0040] In addition, if the term "horizontal" appears, it does not mean that the component is required to be absolutely horizontal, but it can be slightly inclined. For example, "horizontal" only means that its direction is more horizontal relative to "vertical", and does not mean that the structure must be completely horizontal, but it can be slightly inclined.

[0041] In the description of the embodiments of the present invention, it should also be noted that unless otherwise clearly specified and limited, if the terms "set", "install", "connected", "connected" are used, they should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0042] On the current DCS controller, using the kernel layer transparent encryption and decryption technology, a transparent encryption and decryption driver module is added between the virtual file system layer (VFS, Virtual File System) and the file system layer (ext4, ext3, ntfs, fat, etc.) of the kernel. For the files entering and leaving the disk, if the encryption and decryption policy is configured, encryption or decryption operations are performed. When the user reads a file, the file is read from the disk and returned to the user as plaintext after being decrypted by the transparent encryption and decryption driver module; when the user writes a file, the file is encrypted by the transparent encryption and decryption driver module and then stored on the disk. The whole process is transparent to the user. For the encryption and decryption keys of the files, they are not stored in a certain position of the partition like the encryption and decryption of ordinary files, and there is only one key for one partition. Instead, each file has an independent key, and after being encrypted with the key, it is stored in the encrypted information at the head of the file. Even if the file has problems, it will not affect other files.

[0043] Through transparent encryption, the present invention effectively prevents important data from being stolen. By configuring the encryption and decryption policy for the specified files or directories, each file can be precisely controlled to ensure that only the important files that need to be encrypted and protected are encrypted, while general files are still stored in plaintext, improving the system operation efficiency.

[0044] As Figure 1 and Figure 2 shown, the present invention provides a method for transparent encryption and decryption of DCS controller files, including the following steps:

[0045] S1. Insert a transparent encryption and decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel;

[0046] S2. Initialize the transparent encryption and decryption driver module, generate the encryption and decryption key through the password module of the DCS controller, and store it in the secure storage area of the password module as the root key for file encryption and decryption;

[0047] S3. When configuring the encryption and decryption policy for the configuration file, the transparent encryption and decryption driver module calls the password module to generate a random number as the encryption and decryption key for the file, and encrypts the random number with the root key to obtain the ciphertext encryption and decryption key;

[0048] Among them, the transparent encryption and decryption driver module:

[0049] When configuring the encryption and decryption policy for a single file, the single file is encrypted and stored anywhere it is moved.

[0050] When configuring the encryption and decryption policy for a directory, the files in the directory and the files in the recursive subdirectories are encrypted and stored, and each file corresponds to a key;

[0051] Decrypt and write to disk the files moved out of the directory;

[0052] S4. The transparent encryption and decryption driver module appends encryption information to the encrypted file header, encrypts the file in chunks and then writes it to the disk; the encryption information includes the file size, the ciphertext encryption and decryption key, and the size of the encrypted data;

[0053] When reading an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header, and reads the ciphertext encryption and decryption key of the encrypted file and the size of the encrypted data from it. It decrypts the ciphertext encryption and decryption key with the root key to obtain the plaintext key of the file, and then decrypts the encrypted file in chunks until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is less than the actual size of the encrypted file, the unencrypted data is directly read out and returned;

[0054] When writing to an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the encrypted file header, and extracts the ciphertext encryption and decryption key of the encrypted file from it. It decrypts the ciphertext encryption and decryption key with the root key to obtain the plaintext key of the encrypted file, then encrypts the encrypted file in chunks and stores it on the disk, and stores the actual size of the encrypted data in the field represented by the size of the encrypted data.

[0055] In some embodiments, in the initial state, all files stored on the disk are in plaintext. By configuring the policy for the specified file, the transparent encryption and decryption driver module will immediately encrypt and store the file.

[0056] The transparent encryption and decryption driver module of the present invention is responsible for managing the encrypted information of the file header; when configuring the encryption and decryption policy of the configuration file, the transparent encryption and decryption driver module calls the interface provided by the password module to generate a random number as the encryption and decryption key of the file, and encrypts it with the root key generated by S2 to obtain the encryption and decryption key of the ciphertext of the file, so as to protect the security of the encryption and decryption keys of the file; among them, the transparent encryption and decryption driver module can specify a single file to configure the encryption and decryption policy, or specify a directory to configure the encryption policy. In the case of configuring a directory, all files in the directory and files in the recursive subdirectories will be encrypted, and all newly created files in the directory will be automatically encrypted and stored. When configuring the encryption policy of the directory, the files in the directory will be automatically decrypted and stored after being moved out of the directory, that is, the files become plaintext, and the files outside the directory are moved into the directory, then they will be automatically encrypted and stored in ciphertext form.

[0057] Among them, the operation of encrypting and decrypting data with a key includes: first reading the ciphertext key of the file from the encrypted information of the file header, then decrypting the ciphertext key with the root key stored in the password module to obtain the plaintext key, and then using this plaintext key to encrypt and decrypt the data.

[0058] In some embodiments, the file with the specified encryption policy will undergo an initial encryption process to store the plaintext file as a ciphertext file on the disk. This process includes:

[0059] 1) The transparent encryption and decryption driver module uses the password module to generate a random number as the encryption and decryption key of the file, and encrypts the encryption and decryption key of the plaintext of the file with the root key to obtain the encryption key of the ciphertext of the file, avoiding key leakage;

[0060] 2) Read out the content and size information of the file, and create a structure for storing encrypted information. Store the encrypted encryption and decryption key of the ciphertext of the file, the file size, and the size information of the encrypted data of the file into the encrypted information, add this information to the file header, and store it on the disk;

[0061] 3) Perform block encryption on the file, encrypt one block and store it on the disk at a time, and at the same time update the value of the size of the encrypted data in the file header encryption information data. This value stores the actual size of the encrypted data. Until all data is encrypted, the initialization of the file is completed;

[0062] In some embodiments, when reading an encrypted file, the transparent encryption / decryption driver module first reads the encryption information from the file header to confirm whether the file is ciphertext. If so, it extracts the ciphertext encryption / decryption key, file size, and size of the encrypted data of the file from the encryption information data, and decrypts them using the root key in the hardware password module to obtain the plaintext encryption / decryption key of the file. Then, it uses this key to decrypt the read data until the decrypted data is equal to the recorded size of the encrypted data, and returns the plaintext data to the user;

[0063] In some embodiments, when writing an encrypted file, the transparent encryption / decryption driver module first reads the encryption information from the file header and extracts the ciphertext key of the file, decrypts it using the root key in the hardware password module to obtain the plaintext key of the file, and then encrypts the file block by block and stores it on the disk. At the same time, it updates the size of the encrypted data in the encryption information until the entire file is encrypted and written back to the disk.

[0064] Optionally, in some embodiments, in S2, an encryption / decryption root key is initialized. This key is generated by the password module and stored in the persistent storage space of the password module, and an interface is provided to connect to the password module. The password module uses a trusted password module TCM or an encryption card from a third-party manufacturer; this key is the encryption / decryption key for the encryption / decryption key of the file.

[0065] Optionally, in some embodiments, in S3, a transparent encryption policy is configured for a single file or directory. All files under the file or directory with the policy configured will have an independent encryption / decryption key for that file, which is a random number generated by the password module and encrypted and protected by the root key of the password module.

[0066] Optionally, in some embodiments, in S4, all files under the file or directory with the encryption policy configured need to be initially encrypted to make the file ciphertext and stored on the disk. During the initial encryption, encryption information is added to the file header, including the file size, ciphertext encryption / decryption key, and size information of the encrypted data. The size of the encrypted content represents the actual size of the encrypted data of the file. When decrypting, the actual encrypted content is decrypted according to the size of the encrypted data, and the unencrypted content does not need to be decrypted.

[0067] Optionally, in some embodiments, in S5, when reading an encrypted file, first read the encrypted information in the file header, and use the root key to decrypt the ciphertext encryption / decryption key of the file stored in the header to obtain the plaintext encryption / decryption key of the file. Then, read the size of the actually encrypted data of the file. When the size of the encrypted data is less than the actual size of the file, only decrypt the encrypted data, and the unencrypted data does not need to be decrypted, to obtain the plaintext file and return it to the user.

[0068] When writing an encrypted file, first read the encrypted information in the file header, and use the root key to decrypt the ciphertext encryption / decryption key of the file stored in the encrypted information to obtain the plaintext encryption / decryption key of the file, and update the new total size information of the file to the encrypted information in the file header. Encrypt the file in blocks according to the updated encrypted information. After encrypting each block of data, update the value of the encrypted data size in the encrypted information. Finally, all the data of the file is encrypted and stored on the disk.

[0069] In some embodiments, in S1, the root key is used to protect the security of the key. This key is not directly used to encrypt and decrypt files, but to encrypt and decrypt the encryption / decryption key of each file, and then use the key of the file to encrypt and decrypt the file.

[0070] In some embodiments, in S5, when encrypting a file, the size of the encrypted data is simultaneously recorded in the encrypted information in the file header to avoid sudden power failure during the encryption process, resulting in only partial data being encrypted. When decrypting, this value is used to decrypt the corresponding size of data, so as to ensure that the ciphertext can be correctly decrypted.

[0071] As an embodiment, specifically, the present invention provides a method for transparent encryption and decryption of DCS controller files. A root key for encryption and decryption is initialized and stored in a hardware password module. This key is not directly used for encrypting and decrypting files, but for encrypting and protecting the encryption and decryption keys of each file. An encryption policy is configured for a specified file or directory. After the configuration is completed, the encryption of the file is initialized and stored on the disk. During the encryption process, a random number is first generated by the hardware password module as the encryption key for the file, and the generated root key is used to encrypt it to obtain the encryption and decryption key for the ciphertext of the file, which is stored in the encryption information data at the file header. When encrypting and decrypting a file, first read the encryption and decryption key for the ciphertext of the file from the encryption information, and then use the root key to decrypt it to obtain the plaintext encryption and decryption key for the file. When reading an encrypted file, the transparent encryption and decryption driver module reads the encryption and decryption key for the ciphertext of the file from the encryption information at the file header, and then uses the root key to decrypt it to obtain the plaintext encryption and decryption key for the file. Then, read the size of the encrypted data from the encryption information, and then decrypt the specified file until the size of the decrypted data reaches the size of the encrypted data, which means that all the ciphertext has been decrypted. When writing an encrypted file, the transparent encryption and decryption driver module reads the encryption and decryption key for the ciphertext of the file from the encryption information at the file header, and then uses the root key to decrypt it to obtain the plaintext encryption and decryption key for the file. Then, the file is encrypted and stored block by block, and one block is stored after encryption, and the value of the size of the encrypted data stored in the encryption information at the file header is updated synchronously.

[0072] The method for transparent encryption and decryption of DCS controller files according to the present invention can, to a certain extent, ensure the data security of the disk on the trusted DCS controller. Even if the disk is removed by a violator or operator and inserted into other devices, since the important files on the disk are encrypted, and the encryption and decryption keys of the files are stored in the encryption information at the file header after being encrypted by the root key, and the root key for decrypting the encryption and decryption key of the ciphertext of the file is stored in the hardware password module of the original device, and there is no such root key information on the new device, the ciphertext key of the encrypted file cannot be decrypted, and the ciphertext file cannot be decrypted. The present invention can effectively protect data assets from being leaked, can well protect the configuration data on the controller, and improve its security.

[0073] In a method for transparent encryption and decryption of DCS controller files according to the present invention, a trusted controller main board integrates a hardware encryption module, which can generate and securely store an encryption key to protect the security of the key. This key is not used as the encryption key for files. For each encrypted file, a unique encryption key is randomly generated and encrypted and protected using the root key in the hardware password module and stored in the encryption information at the file header. Since each file has an independent key and is encrypted, it will only be decrypted when in use. Even if a certain file is leaked due to some reasons, it will not affect other encrypted files, effectively protecting the security of the system's encrypted files.

[0074] Furthermore, the data transparent encryption and decryption method of the present invention configures an encryption policy for each file instead of encrypting the disk partition. In this way, some files on the same disk are encrypted and some are in plain text. Users can configure encryption policies for important files according to their actual situations, and do not configure encryption policies for other unimportant files. Each file has an independent encryption key, and the encryption information of the file is stored at the head of each encrypted file, including the encryption and decryption key of the ciphertext of the file, the size of the encrypted data of the file, and the actual size information of the file. When encrypting and decrypting the data file, it is necessary to first extract the encryption and decryption key of the ciphertext of the file from the encryption information at the file header, and then use the root key to decrypt the encryption and decryption key of the ciphertext of the file to obtain the encryption and decryption key of the plaintext of the file before the file can be encrypted and decrypted, ensuring the security of the file. At the same time, in order to ensure that the file is not affected during normal decryption when the power suddenly fails during the encryption process and only part of the file is encrypted, to ensure the availability of the file, the size of the encrypted data of the file is also stored in the encryption information. Using this information, only the encrypted part can be decrypted, and the unencrypted part can be directly read, thus ensuring that the file content can be completely read out, greatly improving the fault tolerance and ensuring the availability of the file.

[0075] As Figure 3 shown, the present invention also provides a DCS controller file transparent encryption and decryption system, which includes a generation unit, an encryption and decryption policy configuration unit, an encryption unit, a reading unit, and a writing unit, where:

[0076] The generation unit is used to insert a transparent encryption and decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel; initialize the transparent encryption and decryption driver module, generate an encryption and decryption key through the password module of the DCS controller, and store it in the secure storage area of the password module as the root key for file encryption and decryption;

[0077] The encryption and decryption policy configuration unit is used to, when configuring the encryption and decryption policy of the file, the transparent encryption and decryption driver module calls the password module to generate a random number as the encryption and decryption key of the file, and encrypts the random number with the root key to obtain the ciphertext encryption and decryption key;

[0078] The encryption unit is used to append encryption information to the header of the encrypted file by the transparent encryption and decryption driver module for the encrypted file, and encrypt the file in blocks and then write it to the disk; the encryption information includes the file size, the ciphertext encryption and decryption key, and the size of the encrypted data.

[0079] The reading unit is used to, when reading the encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header, and reads the ciphertext encryption and decryption key of the encrypted file and the size of the encrypted data therefrom, decrypts the ciphertext encryption and decryption key using the root key, and after obtaining the plaintext key of the file, decrypts the encrypted file in blocks until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is less than the actual size of the encrypted file, the unencrypted data is directly read out and returned.

[0080] When writing to the encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header of the encrypted file, and extracts the ciphertext encryption and decryption key of the encrypted file therefrom, decrypts the ciphertext encryption and decryption key using the root key, and after obtaining the plaintext key of the encrypted file, encrypts the encrypted file in blocks and stores it on the disk, and stores the actual size of the encrypted data in the field represented by the size of the encrypted data.

[0081] The system of the present invention is used as a carrier for implementing the method of transparent encryption and decryption of DCS controller files.

[0082] As Figure 4 shown, the present invention also provides a computer device, including a memory, a processor, and a computer program running on the memory. When the processor executes the computer program, the steps of the method for transparent encryption and decryption of DCS controller files as described above are implemented.

[0083] The present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by the processor, the steps of the method for transparent encryption and decryption of DCS controller files as described above are implemented.

[0084] Finally, it should be noted that: the above is only a preferred embodiment of the present invention, and does not impose any form of limitation on the present invention; any ordinary technician in the industry can smoothly implement the present invention according to the instructions and the above; however, any minor changes, modifications, and equivalent changes made by those familiar with the professional technology within the scope of the technical solution of the present invention using the technical content disclosed above are equivalent embodiments of the present invention; at the same time, any equivalent changes, modifications, and evolutions made to the above embodiments based on the essential technology of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. A method for transparent encryption and decryption of DCS controller files, characterized in that: The steps include: S1. Insert a transparent encryption and decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel; S2. Initialize the transparent encryption and decryption driver module, generate encryption and decryption keys through the password module of the DCS controller, and store them in the secure storage area of ​​the password module as the root key for file encryption and decryption; S3. When configuring the encryption and decryption strategy of the file, the transparent encryption and decryption driver module calls the password module to generate a random number as the encryption and decryption key of the file, and encrypts the random number with the root key to obtain the ciphertext encryption and decryption key; Among them, transparent encryption and decryption driver module: When you configure encryption and decryption policies for a single file, the file will be encrypted wherever it is moved. When configuring encryption and decryption policies for a directory, the files in the directory and the files in the recursive subdirectories are encrypted and stored, and each file corresponds to a key; Decrypt the files removed from the directory and save them to disk; S4, the transparent encryption and decryption driver module adds encryption information to the encrypted file header, encrypts the file in blocks and writes it to the disk; the encryption information includes the actual size of the file, the ciphertext encryption and decryption key, and the size of the encrypted data; Initially encrypt a single file or files in a directory with an encryption policy configured, and store the file in ciphertext on disk. During initial encryption, add encryption information to the file header. During decryption, decrypt the actual encrypted content based on the size of the encrypted data, and unencrypted content does not need to be decrypted. S5. When reading an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header, and reads the ciphertext encryption and decryption key of the encrypted file and the size of the encrypted data therefrom, decrypts the ciphertext encryption and decryption key using the root key, and after obtaining the plaintext key of the file, decrypts the encrypted file in blocks until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is smaller than the actual size of the encrypted file, the unencrypted data is directly read out and returned; When writing an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the encrypted file header, and extracts the ciphertext encryption and decryption key of the encrypted file from it, decrypts the ciphertext encryption and decryption key using the root key, obtains the plaintext key of the encrypted file, encrypts the encrypted file in blocks and stores it on the disk, and stores the actual size of the encrypted data in the field representing the size of the encrypted data; When writing an encrypted file, after obtaining the plaintext encryption and decryption key of the file, the new total size information of the file is updated to the encryption information in the file header, and then the file is encrypted block by block; each time a block of data is encrypted, the size of the encrypted data in the encryption information is updated, and finally all the data of the file is encrypted and stored on the disk.

2. The method for transparent encryption and decryption of DCS controller files according to claim 1, characterized in that: In S2, the encryption and decryption root key is generated by a cryptographic module and stored in a secure storage area. The cryptographic module includes a trusted cryptographic module TCM or an encryption card of a third-party manufacturer.

3. The method for transparent encryption and decryption of DCS controller files according to claim 1, characterized in that: In the S3, when a transparent encryption policy is configured for a single file or directory, each single file or file under the directory will have an independent encryption and decryption key. Each independent encryption and decryption key is based on a random number generated by a cryptographic module and is encrypted and protected by a root key.

4. The method for transparent encryption and decryption of DCS controller files according to claim 1, characterized in that: In S4, the encryption information added to the file header is managed by the transparent encryption and decryption driver module.

5. The method for transparent encryption and decryption of DCS controller files according to claim 1, characterized in that: In S5, when reading an encrypted file, the encryption information in the file header is first read out, and the root key is used to decrypt the ciphertext encryption and decryption key stored in the file header to obtain the plaintext encryption and decryption key of the file, and then the size of the encrypted data of the file is read out. When the size of the encrypted data is smaller than the actual size of the file, only the encrypted data is decrypted to obtain the plaintext file and return it to the user.

6. A system for transparent encryption and decryption of DCS controller files, used to implement the method for transparent encryption and decryption of DCS controller files according to any one of claims 1 to 5, characterized in that: The system includes a generation unit, an encryption and decryption strategy configuration unit, an encryption unit, a reading unit, and a writing unit, wherein: The generation unit is used to insert a transparent encryption and decryption driver module between the virtual file system layer and the file system layer of the DCS controller kernel; initialize the transparent encryption and decryption driver module, generate encryption and decryption keys through the password module of the DCS controller, and store them in the secure storage area of ​​the password module as the root key for file encryption and decryption; The encryption and decryption strategy configuration unit is used to, when configuring the encryption and decryption strategy of the file, the transparent encryption and decryption driver module calls the password module to generate a random number as the encryption and decryption key of the file, and encrypts the random number with the root key to obtain the ciphertext encryption and decryption key; The encryption unit is used to add encryption information to the encrypted file header of the transparent encryption and decryption driver module, and write the encrypted file into disk after encrypting the file in blocks; the encryption information includes the actual size of the file, the ciphertext encryption and decryption key, and the size of the encrypted data; The reading unit is used for, when reading an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the file header, and reads the ciphertext encryption and decryption key of the encrypted file and the size of the encrypted data therefrom, decrypts the ciphertext encryption and decryption key using the root key, and after obtaining the plaintext key of the file, decrypts the encrypted file in blocks until the size of the decrypted data is equal to the size of the encrypted data. If the size of the encrypted data is smaller than the actual size of the encrypted file, the unencrypted data is directly read out and returned; When writing an encrypted file, the transparent encryption and decryption driver module reads the encryption information from the encrypted file header, and extracts the ciphertext encryption and decryption key of the encrypted file from it, uses the root key to decrypt the ciphertext encryption and decryption key, and after obtaining the plaintext key of the encrypted file, encrypts the encrypted file in blocks and stores it on the disk, and stores the actual size of the encrypted data in the field representing the size of the encrypted data.

7. A computer device comprising a memory, a processor and a computer program stored and executed on the memory, characterized in that: When the processor executes the computer program, the steps of the method for transparent encryption and decryption of DCS controller files according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of transparent encryption and decryption of a DCS controller file according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Software security protection method based on Linux system

    CN103065082A

  • Directory fine-grained encryption and decryption method and system

    CN110213051A