Soft key oriented to different security levels
By designing soft key destruction programs for different security levels, and combining destruction mapping tables, destruction keys, full disk erasure, and overwriting, the shortcomings of existing soft key destruction technologies are solved, achieving flexible and reliable data destruction, reducing storage costs, and improving security.
Patent Information
- Application Number
- CN202411957006.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-29
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-12-29
AI Technical Summary
Existing soft key destruction technology is insufficient in terms of flexibility and security, and cannot effectively meet the data destruction needs of different security levels. In addition, traditional hard key destruction is costly and inconvenient to carry.
Design a soft key destruction method for different security levels. Through soft key destruction procedures such as destroying the mapping table, destroying the key, full disk erasure, and full disk overwrite, combined with command destruction and automatic destruction methods, it realizes flexible data destruction of the storage module, ensures effective execution of key destruction operations under different security levels, and displays the destruction status through status indicator lights.
It enables flexible and reliable data destruction at different security levels, reduces storage costs, improves device security and flexibility, and does not damage the storage media.
Smart Images

Figure CN119885229B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of information security, and particularly relates to a soft key destruction method for different security levels. BACKGROUND
[0002] With the rapid development of information technology, the security problem of electronic equipment is increasingly prominent. The traditional hard key destruction method has problems such as high cost and inconvenience to carry, while the soft key destruction technology realizes the destruction of the equipment through software instructions. However, the existing soft key destruction technology still has deficiencies in flexibility. Therefore, a soft key destruction method for different security levels is needed to improve the flexibility and security of the equipment. SUMMARY
[0003] Therefore, the application provides a soft key destruction method for different security levels, which realizes the destruction and erasure of data in the storage module in different application scenarios, ensures that the key destruction operation can be effectively performed under different security levels, and solves the risk of data leakage. At the same time, it can be performed without damaging the storage medium, so the storage cost of the user can be reduced.
[0004] Technical scheme of the application:
[0005] A soft key destruction method for different security levels, which executes a soft key destruction program corresponding to the security level of data for different security levels of data.
[0006] The soft key destruction program includes a destruction mapping table, a destruction key, a full-disk erasure, and a full-disk overwrite.
[0007] The starting mode of the soft key destruction program includes command destruction and automatic destruction.
[0008] The soft key destruction program is provided with a state indication, and the state indication includes a normal state, a destruction in progress state, and a destruction end state.
[0009] Further, the soft key destruction includes a storage module, and the storage module burns the soft key destruction program.
[0010] Further, the command destruction specifically refers to that the storage module executes data destruction of different security levels according to different instructions issued by the front-end Host / CPU.
[0011] The automatic destruction specifically refers to that the storage module end determines whether to execute data destruction according to the high and low of a level signal issued by the front-end Host / CPU.
[0012] Further, the soft key destruction is provided with a working indicator light, when the soft key destruction is in the normal state, the destruction state display pin outputs a low level signal, and the indicator light is always off.
[0013] When the destruction starts, the destruction state display pin outputs a 1Hz level jump signal, and the indicator blinks;
[0014] When the destruction ends, the destruction state display pin outputs a high level signal, and the indicator is always on.
[0015] Further, the soft destruction key is used to perform full disk erase and overwrite of all Flash memories with non-volatile characteristics on the storage module.
[0016] Further, the destruction mapping table is used to clear all logical mapping addresses.
[0017] Further, the destruction key is used to:
[0018] In the state of starting data encryption, the data received by the PCIe interface is encrypted by the main control hardware encryption module, and then the encrypted data is stored in the flash memory, and a key is generated. The soft destruction key program is used to delete the generated key.
[0019] Further, the full disk erase is used to:
[0020] By applying high voltage to the Flash memory, the electrons in the storage unit of the Flash memory are released, and the state of all storage units is 1.
[0021] Further, the full disk overwrite is used to write non-confidential data into the hard disk that previously stores sensitive data, specifically:
[0022] Based on meaningless data, the hard disk storing sensitive data is overwritten.
[0023] Further, the execution of the soft destruction program includes the following steps:
[0024] S101: According to the user's requirements for data security level, the corresponding soft destruction key program is solidified;
[0025] S102: The hardware circuit supports real-time detection of the destruction command and real-time detection of the destruction pin level. When the destruction command or the destruction pin is detected, further determine whether the destruction command is received or the destruction pin is pulled low;
[0026] S103: If it is determined that the destruction pin level is pulled low, continue to determine the length of time when the destruction pin level is low. If the low level time is less than 1s, it is judged as a false operation, and returns to S102 to continue to detect the destruction command and the destruction pin level; if the low level time is greater than or equal to 1s, it is judged as executing the destruction program, and enters the destruction process; if it is determined that the destruction command, it directly enters the destruction process.
[0027] S104: After entering the destruction program, the soft destruction key program solidified in S101 is automatically executed, and the execution state of the soft destruction key program is determined according to the destruction state indication signal.
[0028] Advantages of the present application:
[0029] 1. Simple and reliable circuit implementation;
[0030] 2. According to different application scenarios, the destruction start mode can be divided into two different types:
[0031] 3. Different security level data destruction can be executed. BRIEF DESCRIPTION OF DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0033] Figure 1 The present application is a soft destruction key implementation process diagram for different security levels. DETAILED DESCRIPTION
[0034] The embodiments of the present disclosure will be described in detail below with reference to the drawings.
[0035] The embodiments of the present disclosure will be described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present disclosure, not all the embodiments. The present disclosure can also be implemented or applied by other different specific embodiments, and the details in the specification can also be modified or changed based on different views and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present disclosure.
[0036] It is to be understood that the embodiments described herein are illustrative only and the scope of the disclosure should not be deemed limited thereto based on their description in the attached claims. As such, many changes and modifications can occur to those skilled in the art, to which the scope of the disclosure is directed, without departing from the true spirit and scope of the disclosure in its broadest form. Therefore, the scope of the disclosure is to be interpreted only from the claims. Similarly, any sums exemplified herein combined with any other aspect(s) described herein can be excluded. Furthermore, any feature or combination of features in the claims that fails to affirmatively enable the particular claims, then such claims should not be interpreted as being meant to limit the aspects.
[0037] It is also to be understood that the following description is only illustrative of the aspects of the present disclosure and that many modifications can be made by those skilled in the art, without departing from the scope of the present disclosure in its broadest form thereof. Accordingly, the specification is to be interpreted only as illustrative of the broadest aspects of the present disclosure and not in a limiting sense.
[0038] Furthermore, in the following description, numerous specific details are set forth in order to provide a thorough understanding of the examples. However, it will be recognized by one skilled in the art that the ubiquitous aspects can be practiced without these specific details.
[0039] In one embodiment of the present disclosure, a soft destruction key for different security levels is provided, referring to Figure 1 The soft destruction key executes a soft destruction key program corresponding to the security level of the data for data of different security levels.
[0040] The soft destruction key program includes destroying a mapping table, destroying a key, full-disk erasing, and full-disk overwriting.
[0041] The starting mode of the soft destruction key program includes command destruction and automatic destruction.
[0042] The soft destruction key program is provided with a state indication, and the state indication includes a normal state, a destruction in progress state, and a destruction end state.
[0043] In the embodiment, the soft destruction key includes a storage module, and the storage module burns the soft destruction key program.
[0044] In the embodiment, the command destruction specifically refers to that the storage module executes data destruction of different security levels according to different instructions issued by a front-end Host / CPU.
[0045] The automatic destruction specifically refers to that the storage module determines whether to execute data destruction according to the high and low of a level signal issued by the front-end Host / CPU.
[0046] In the embodiment, the soft destruction key is configured with an indicator light. When the soft destruction key is in a normal state, the destruction state display pin outputs a low-level signal, and the indicator light is always off.
[0047] When the destruction starts, the destruction state display pin outputs a 1Hz frequency level jump signal, and the indicator light blinks.
[0048] When the destruction ends, the destruction state display pin outputs a high-level signal, and the indicator light is always on.
[0049] In the embodiment, the soft destruction key is used to perform full-disk erasing and overwriting on all flash memories with non-volatility on the storage module.
[0050] In the embodiment, the destruction mapping table is used to clear all logical mapping addresses.
[0051] In the embodiment, the destruction key is used to:
[0052] In the state of starting data encryption, the data received by the PCIe interface is encrypted by the main control hardware encryption module, and then the encrypted data is stored in the flash memory, and a key is generated. The soft destruction key program is used to delete the generated key.
[0053] In the embodiment, the full-disk erasing is used to:
[0054] By applying high voltage to the flash memory, the electrons in the storage unit of the flash memory are released, and the state of all storage units is 1.
[0055] In the embodiment, the full-disk overwriting is used to write non-confidential data into a hard disk that previously stores sensitive data, specifically:
[0056] Based on meaningless data, the hard disk storing sensitive data is covered.
[0057] In the embodiment, the execution of the soft destruction program includes the following steps:
[0058] S101: According to different requirements of users for data security level, the corresponding soft destruction key program is solidified;
[0059] S102: The hardware circuit supports the functions of real-time detection of destruction command and real-time detection of destruction pin level. When the destruction command or the destruction pin is detected to be effective, it is further judged whether the destruction command is received or the destruction pin is pulled low;
[0060] S103: If it is determined that the destroy pin level is pulled low, continue to determine the length of time the destroy pin level is at a low level. If the length of time is less than 1s, it is determined to be a false operation, and the destroy command and the destroy pin level are detected again in S102. If the length of time is greater than or equal to 1s, it is determined to execute the destroy program, and the destroy process is entered. If it is determined to be a destroy command, the destroy process is directly entered.
[0061] S104: After entering the destroy program, the soft destroy key program solidified in S101 is automatically executed, and the execution state of the soft destroy key program is determined according to the destroy state indication signal.
[0062] Data destruction generally occurs in the destruction of data in a storage module in an emergency. According to different application scenarios, the destroy start mode of the embodiment can be divided into the following two types:
[0063] a. Command destruction: According to different instructions issued by the front-end Host / CPU, data destruction of different security levels can be executed;
[0064] b. Automatic destruction: The storage module end only needs a level signal, and data destruction is performed by determining the high and low of the level signal;
[0065] 2. Destroy state indication signal:
[0066] The destroy state indication signal is divided into three states: normal state, destroy in progress state, and destroy end state:
[0067] a. In the normal state, the destroy state display pin outputs a low-level signal, and the indicator light is always off.
[0068] b. After the destruction starts, the destroy state display pin outputs a 1Hz level jump signal, and the indicator light blinks.
[0069] c. After the destruction ends, the destroy state display pin outputs a high-level signal, and the indicator light is always on.
[0070] 3. Destruction scheme
[0071] The soft destruction technology is mainly based on the full disk erasing and overwriting of the Flash flash memory with all non-volatile characteristics on the storage module, so the soft destruction time is positively correlated with the capacity of the storage module. Considering the destruction time and security level requirements provided by the user, the destruction level can be divided into the following schemes:
[0072] a. Destroy the mapping table; clear all logical mapping addresses. After the address is cleared, the corresponding physical address data cannot be found. Advantage: short erasing time, can be completed within 100 milliseconds; but only the mapping relationship table is erased, the data on the flash memory block is not erased, the risk of recovering data is high, and the security level is low.
[0073] b. Destroy the key; after starting data encryption, the data received by the PCIe interface is encrypted by the master hardware encryption module, and then the encrypted data is stored in the flash memory, and the key is generated. This program deletes its encryption key, making it impossible to read encrypted data. The erase time is short and can be completed within 100 milliseconds, but only the encryption key is erased, and the risk of cracking the key and recovering data is high, with a low security level;
[0074] c. Full disk erase; the erase of flash memory block data is achieved by applying high voltage to the storage cells in the block to release the electrons in the storage cells, so that all the storage cells are in the state of "1", thereby achieving the purpose of data destruction. The possibility of data recovery is low, and the security level is high;
[0075] d. Full disk overwrite. Data overwrite is to write non-confidential data into a hard disk that previously stored sensitive data. The data on the hard disk is stored in binary "1" and "0" form. Using pre-defined meaningless and irregular information to repeatedly overwrite the original data stored on the hard disk, it is impossible to know whether the original data is "1" or "0", and the purpose of hard disk data erasure is achieved. Data overwrite can be divided into overwrite 0, overwrite 1 and random overwrite. Advantages: low possibility of data recovery, high security level;
[0076] The specific implementation method of the soft key destruction method for different security levels in this embodiment is as follows:
[0077] 1. First, according to the different requirements of users for data security level, the corresponding soft key destruction program is solidified. For example, for electronic disks with high security level requirements, the full disk erase program is solidified.
[0078] 2. The hardware circuit supports real-time detection of the destroy command and real-time detection of the destroy pin level. When the destroy command or the destroy pin is detected, it is further judged whether the destroy command is received or the destroy pin is pulled low.
[0079] 3. If it is judged that the destroy pin level is pulled low, it is necessary to judge whether the destroy pin level is in low level for less than 1s, and if it is judged as a false operation, return to the previous step to continue detecting the destroy command and the destroy pin level. If it is greater than or equal to 1s, it is judged as executing the destroy program, and enters the destroy process. If it is judged as the destroy command, it directly enters the destroy process.
[0080] 4. Upon entering the destruction process, the first step of solidifying the soft key program is automatically executed, and the current progress of the soft key program is determined based on the destruction status indication signal. The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A soft-compromise key method for different security levels, characterized by The soft key destruction method executes a soft key destruction program corresponding to the data security level for data of different security levels; The soft key destruction program includes destroying a mapping table, destroying a key, full-disk erasing, and full-disk overwriting; The soft key destruction program includes destroying a mapping table, destroying a key, full-disk erasing, and full-disk overwriting; The starting mode of the soft key destruction program includes a command destruction and automatic destruction; the command destruction specifically refers to that the storage module executes data destruction of different security levels according to different instructions issued by a front-end Host / CPU; the automatic destruction specifically refers to that the storage module end determines whether to execute data destruction according to a high or low level of a signal issued by the front-end Host / CPU; The soft key destruction program is provided with a state indication, and the state indication includes a normal state, a destruction in progress state, and a destruction end state; 2. The soft-compromise key method for different security levels as claimed in claim 1, wherein, The soft key is provided with a working indication lamp; when the soft key is in the normal state, a destruction state display pin outputs a low level signal, and the indication lamp is always off; after the destruction starts, the destruction state display pin outputs a level jump signal with a frequency of 1 Hz, and the indication lamp blinks; after the destruction ends, the destruction state display pin outputs a high level signal, and the indication lamp is always on.
3. The soft kill key method for different security levels as claimed in claim 1 wherein, The soft key includes a storage module, and the storage module burns the soft key destruction program.
4. The soft kill key method for different security levels as claimed in claim 3, wherein, The soft key is used to execute full-disk erasing and overwriting of all Flash memories with non-volatility characteristics on the storage module.
5. The soft kill key method for different security levels as claimed in claim 4, wherein, The destroyed mapping table is used to clear all logical mapping addresses. The destroyed key is used to: In a state where data encryption is started, data received by the PCIe interface is encrypted by a main control hardware encryption module, and then the encrypted data is stored in a flash memory, and a key is generated; 6. The soft kill key method for different security levels as claimed in claim 5 wherein, The soft key destruction program is used to delete the generated key. The full-disk erasing is used to:
7. The soft kill key method for different security levels as claimed in claim 6 wherein, Release the electrons in the storage units of the Flash memory by applying high voltage to the Flash memory, so that the state of all storage units is 1. The full-disk overwriting is used to write non-secret data into a hard disk that previously stores sensitive data, specifically:
8. The soft kill key method for different security levels according to claim 7, characterized in that, Cover the hard disk that stores sensitive data with meaningless data. The execution of the soft key destruction program includes the following steps: S101: According to different requirements of users for data security levels, the corresponding soft key destruction program is solidified; S102: The hardware circuit supports real-time detection of a destruction command and real-time detection of a destruction pin level; when the destruction command or the destruction pin is detected to be effective, it is further judged whether the destruction command is received or the destruction pin is pulled low; S103: If it is judged that the destruction pin level is pulled low, it is further judged whether the low level time of the destruction pin level is less than 1s, and if so, it is judged as a false operation, and the detection of the destruction command and the destruction pin level is returned to S102; if the low level time is greater than or equal to 1s, it is judged as executing the destruction program, and the destruction process is entered; if it is judged as the destruction command, the destruction process is directly entered; S104: After entering the destruction program, the soft key destruction program solidified in S101 is automatically executed, and the execution state of the soft key destruction program is determined according to a destruction state indication signal.
Citation Information
Patent Citations
Data destruction method and data destruction system of memory device
CN106156660A
Key data multi-dimensional grading destruction method
CN111460531A