Access method
By setting up a wireless communication module in the mobile storage device to verify the identity information and permissions of the mobile terminal, the problem of data leakage caused by the lack of security measures in the mobile storage device is solved, and the effect of improving security and reliability is achieved.
Patent Information
- Application Number
- CN202411889363.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-06
AI Technical Summary
Mobile storage devices lack effective security measures and are prone to internal data stolen, resulting in data leakage.
By setting up a wireless communication module in the mobile storage device, establishing a wireless connection with the mobile terminal, verifying the identity information and permissions of the mobile terminal, and performing operations only after obtaining legal permissions.
Only authorized terminals can access the contents of mobile storage devices, reduce access and theft of illegal devices, improve the security and reliability of mobile storage devices, and prevent data leakage.
Smart Images

Figure CN119939565A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of data security technology, and in particular, relates to an access method. Background Art
[0002] At present, when using mobile storage devices, operations can be directly performed on the mobile storage devices, such as reading, writing and deleting the contents of the mobile storage devices. Mobile storage devices lack effective security measures and are prone to internal data being stolen, resulting in data leakage. Summary of the invention
[0003] The embodiment of the present application provides an access method, which can solve the problem that the mobile storage device lacks effective security measures and the internal data is easily stolen, resulting in data leakage.
[0004] In a first aspect, an embodiment of the present application provides an access method, which is applied to a mobile storage device, wherein the mobile storage device is provided with a wireless communication module;
[0005] The method comprises:
[0006] After the mobile storage device establishes a connection with the electronic device, if an operation from the electronic device is received, the authority of the mobile terminal is verified according to the identity information of the mobile terminal to obtain a first authority verification result, wherein the identity information is obtained after the wireless communication module is successfully paired with the mobile terminal, and the mobile terminal is a management terminal or a temporary access terminal;
[0007] If the first permission verification result of the mobile terminal is legal, the operation is performed.
[0008] In one embodiment, when the mobile terminal is a temporary access terminal;
[0009] Before verifying the authority of the mobile terminal according to the identity information of the mobile terminal, the method further includes:
[0010] receiving authorization authority from the management terminal through the wireless communication module, and setting authority of the temporary access terminal according to the authorization authority, wherein the authorization authority is determined by the management terminal after the temporary access terminal communicates with the management terminal through the access credential;
[0011] Correspondingly, verifying the authority of the mobile terminal according to the identity information of the mobile terminal includes:
[0012] The authority of the temporary access terminal is verified according to the identity information of the temporary access terminal.
[0013] In one embodiment, when the operation is a read-write operation and the mobile terminal is a temporary access terminal;
[0014] If the first permission verification result of the mobile terminal is legal, performing the operation includes:
[0015] If the first permission verification result of the temporary access terminal is legal, and the read-write permission instruction and the first dynamic password are received from the management terminal through the wireless communication module, then based on the read-write permission instruction, the first dynamic password is used to encrypt or decrypt the file, and the read-write operation is performed;
[0016] The read / write permission instruction and the first dynamic password are generated after the management terminal receives the first read / write request from the temporary access terminal and verifies the legality of the authority of the temporary access terminal.
[0017] In one embodiment, when the operation is a read-write operation and the mobile terminal is a management terminal;
[0018] If the first permission verification result of the mobile terminal is legal, before performing the operation, the method includes:
[0019] Sending a second read / write request to the management terminal through the wireless communication module;
[0020] Correspondingly, if the first permission verification result of the mobile terminal is legal, performing the operation includes:
[0021] If the first permission verification result of the management terminal is legal, and the second dynamic password is received from the management terminal through the wireless communication module, the second dynamic password is used to encrypt or decrypt the file, and the read and write operations are performed;
[0022] The second dynamic password is generated by the management terminal according to the second read-write request.
[0023] In one embodiment, before receiving the operation from the electronic device, the method further includes:
[0024] After the mobile storage device is connected to the electronic device, if a configuration operation is received from the management terminal through the wireless communication module, the files and directories are displayed according to the configuration operation.
[0025] In a second aspect, an embodiment of the present application provides an access method, which is applied to a management terminal, including:
[0026] After the mobile storage device establishes a connection with the electronic device, when the wireless communication module of the mobile storage device is successfully paired with the mobile storage device, identity confirmation information is sent to the mobile storage device, the identity confirmation information is used to instruct the mobile storage device to set the authority of the management terminal, the authority of the management terminal is used to instruct the mobile storage device to perform the operation of the electronic device after verifying the legitimacy of the authority according to the identity information of the management terminal, and the identity information is obtained after the mobile storage device is successfully paired with the management terminal.
[0027] In one embodiment, the method further comprises:
[0028] generating an access credential so that the temporary access terminal can communicate with the management terminal through the access credential;
[0029] receiving an access request from the temporary access terminal, and determining, in response to the access request, an authorization authority of the temporary access terminal;
[0030] The authorization authority is sent to the mobile storage device, where the authorization authority is used to instruct the mobile storage device to set the authority for temporarily accessing the terminal according to the authorization authority.
[0031] In one embodiment, the method further comprises:
[0032] If a first read / write request is received from a temporary access terminal, verifying the authority of the temporary access terminal to obtain a second authority verification result;
[0033] If the second permission verification result is legal, generating a read / write permission instruction and a first dynamic password according to the first read / write request, and sending the read / write permission instruction and the first dynamic password to the mobile storage device, so that the mobile storage device encrypts or decrypts the file based on the read / write permission instruction and using the first dynamic password;
[0034] If a second read / write request is received from the mobile storage device, a second dynamic password is generated and sent to the mobile storage device, so that the mobile storage device uses the second dynamic password to perform encryption or decryption operations on the file.
[0035] In one embodiment, the method further comprises:
[0036] After the mobile storage device is connected to the electronic device, a configuration operation is sent to the mobile storage device, where the configuration operation is used to instruct the mobile storage device to display files and directories.
[0037] In a third aspect, an embodiment of the present application provides a mobile storage device, comprising a wireless communication module, a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a method as described in any one of the above-mentioned first aspects when executing the computer program.
[0038] In a fourth aspect, an embodiment of the present application provides a mobile terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a method as described in any one of the second aspects above when executing the computer program.
[0039] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0040] The mobile storage device of the embodiment of the present application is provided with a wireless communication module; after the mobile storage device establishes a connection with the electronic device, if an operation from the electronic device is received, the authority of the mobile terminal is verified according to the identity information of the mobile terminal, and a first authority verification result is obtained, and the identity information is obtained after the wireless communication module is successfully paired with the mobile terminal; if the first authority verification result of the mobile terminal is legal, the operation is executed to ensure that only authorized terminals can access the contents of the mobile storage device, thereby reducing the access and theft by illegal devices, improving the security and reliability of the mobile storage device, and preventing data leakage.
[0041] It can be understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 This is a schematic diagram of a first flow chart of an access method provided by an embodiment of the present application;
[0044] Figure 2 This is a second flow chart of the access method provided in one embodiment of the present application. DETAILED DESCRIPTION
[0045] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0046] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0047] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0048] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0049] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0050] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0051] When using a mobile storage device, you can directly operate the mobile storage device, such as reading, writing, and deleting the content of the mobile storage device. Mobile storage devices lack effective security measures, and internal data can be easily stolen, resulting in data leakage. In particular, if the mobile storage device is lost or stolen, the internal data of the mobile storage device is very easy to be illegally accessed.
[0052] In the digital society, data leakage incidents are increasing, posing a greater security threat to the data in mobile storage devices.
[0053] The embodiments of the present application provide a mobile storage device and an access method, which can reduce the access and theft of illegal devices, improve the security and reliability of the mobile storage device, prevent data leakage, and adapt to the increasingly complex network environment and the ever-changing data protection needs.
[0054] In one embodiment, the mobile storage device is provided with a wireless communication module. The mobile storage device may include a USB flash drive, a mobile hard disk, etc. The wireless communication module is a wireless integrated module. The wireless communication module may be a built-in Bluetooth module or an NFC module, which is used to provide a wireless link to wirelessly communicate with the mobile terminal.
[0055] Figure 1 This is a schematic diagram of the first flow of the access method provided by an embodiment of the present application. Figure 1 As shown, the access method is applied to a mobile storage device and includes:
[0056] S11: After the mobile storage device establishes a connection with the electronic device, if an operation from the electronic device is received, the authority of the mobile terminal is verified according to the identity information of the mobile terminal to obtain a first authority verification result.
[0057] The identity information is obtained after the wireless communication module is successfully paired with the mobile terminal, and the mobile terminal is a management terminal or a temporary access terminal.
[0058] The electronic device may be a desktop computer, notebook, PDA or other computing device. Operations include read, write, delete, format, etc. Permissions include permission / prohibition of read, write, delete, format, access time, geographic location, etc. The permissions of the management terminal and the temporary access terminal may be the same or different.
[0059] In the application, after the mobile storage device is inserted into the electronic device and a connection is established with the electronic device, the user of the mobile terminal can operate the files of the mobile storage device on the electronic device, and the corresponding mobile storage device receives the operation from the electronic device.
[0060] After the mobile storage device establishes a connection with the electronic device, the wireless communication module will be turned on. Based on the wireless communication module, the mobile terminal and the mobile storage device are paired. During the pairing process, the mobile terminal and the mobile storage device exchange information. After the pairing is successful, the mobile storage device obtains the identity information of the mobile terminal. After the pairing is successful, the mobile storage device and the mobile terminal are in a wireless communication state. The mobile storage device verifies the authority of the mobile terminal according to the identity information of the wirelessly connected mobile terminal and obtains the first authority verification result.
[0061] In a possible implementation, the identity information includes identification information and geographic information. The identification information may be a device number. Correspondingly, according to the identity information of the mobile terminal, the authority of the mobile terminal is verified, including:
[0062] Verify the authority of the mobile terminal based on the identification information and geographic information of the mobile terminal.
[0063] The mobile terminal can be accurately identified through identification information, and the access rights can be restricted to a specific geographical area through geographic information.
[0064] In a possible implementation manner, before receiving an operation from an electronic device, the method further includes:
[0065] After the mobile storage device is connected to the electronic device, if a configuration operation is received from the management terminal through the wireless communication module, the files and directories are displayed according to the configuration operation.
[0066] In the application, after the mobile storage device is connected to the electronic device, the management terminal is set to control the file display of the mobile storage device. The management terminal communicates wirelessly with the mobile storage device through the wireless communication module, and the management terminal sends a configuration operation to the mobile storage device through the wireless link to set the mobile storage device to open directories and files. The mobile storage device displays files and directories according to the configuration operation.
[0067] By receiving the configuration operation from the management terminal, the files and directories are displayed according to the configuration operation, and the mobile storage device can be used only under the control range of the management terminal, thereby further protecting the content of the mobile storage device.
[0068] S12: If the first permission verification result of the mobile terminal is legal, execute the operation.
[0069] In the application, if the first permission verification result of the mobile terminal is legal, it means that the operation of the user of the mobile terminal is allowed, and the mobile storage device executes the operation. If the first permission verification result of the mobile terminal is illegal, it means that the wirelessly connected mobile terminal is an illegal device, and the mobile storage device executes the data destruction operation.
[0070] In a possible implementation, the mobile storage device records the key operation logs such as the permission verification results and operation records of each mobile terminal, so that the user of the management terminal can monitor the operation and find abnormal operation, so as to timely find and handle security issues.
[0071] For example, a mobile phone is connected to a USB flash drive via the Bluetooth module of the USB flash drive. The user of the mobile phone reads and writes files on the USB flash drive on the computer. The USB flash drive verifies the authority of the mobile phone based on the identity information of the mobile phone. When the authority is verified to be legitimate, the USB flash drive reads and writes files.
[0072] It is understandable that the mobile storage device establishes a wireless connection with the mobile terminal, and the mobile storage device determines whether it has permission to operate based on the identity information, and adds security measures to the mobile storage device, so that only authorized users can access the mobile storage device, and ensure that only authorized users can use the mobile storage device, which can effectively reduce data leakage in various application scenarios, especially education, medical care, official business and other application scenarios with a large demand for the use of mobile storage devices, and at the same time can protect the content of the mobile storage device, especially important information, improve users' trust in the security of mobile storage devices, and enhance the practicality and portability of mobile storage devices. It can also provide a safe and efficient way to use files in remote work and instant file sharing.
[0073] The mobile storage device of this embodiment is provided with a wireless communication module; after the mobile storage device establishes a connection with the electronic device, if an operation from the electronic device is received, the authority of the mobile terminal is verified according to the identity information of the mobile terminal, and a first authority verification result is obtained, and the identity information is obtained after the wireless communication module is successfully paired with the mobile terminal; if the first authority verification result of the mobile terminal is legal, the operation is executed to achieve that only authorized terminals can access the contents of the mobile storage device, thereby reducing the access and theft by illegal devices, improving the security and reliability of the mobile storage device, and preventing data leakage.
[0074] In one embodiment, when the mobile terminal is a temporary access terminal.
[0075] Before verifying the authority of the mobile terminal according to the identity information of the mobile terminal, the following is also included:
[0076] The authorization authority is received from the management terminal through the wireless communication module, and the authority for temporary access to the terminal is set according to the authorization authority.
[0077] The authorization authority is determined by the management terminal after the temporary access terminal communicates with the management terminal through the access credential.
[0078] In the application, since mobile terminals are temporary access terminals, it is necessary to manage the terminals to pre-set access permissions and limit the permissions of temporary access terminals to reduce the possibility of data leakage when mobile storage devices are in a shared state.
[0079] The temporary access terminal communicates with the management terminal through the access credential, and the management terminal determines the authorization authority of the temporary access terminal. Then the management terminal sends the authorization authority to the mobile storage device through the wireless link, and the mobile storage device sets the authority of the temporary access terminal according to the authorization authority.
[0080] In a possible implementation manner, the identification information of the temporary access terminal may be an authorization code.
[0081] In one possible implementation, the access credential may be an access code or an authorized connection.
[0082] In a possible implementation, the mobile storage device determines that the received authorization authority comes from the management terminal through pre-marked device information.
[0083] Correspondingly, based on the identity information of the mobile terminal, the authority of the mobile terminal is verified, including:
[0084] The authority of the temporary access terminal is verified according to the identity information of the temporary access terminal.
[0085] In the application, the temporary access terminal establishes a wireless connection with the mobile storage device. The mobile storage device verifies the authority of the temporary access terminal based on the identity information of the temporary access terminal and determines whether the user of the temporary access terminal has the authority to operate the mobile storage device.
[0086] This embodiment receives authorization rights from the management terminal through the wireless communication module, sets the rights of the temporary access terminal according to the authorization rights, and implements the policy that only authorized terminals can access the contents of the mobile storage device, so that the temporary access terminal can operate the mobile storage device only under the control of the management terminal and with the permission, further reducing the access and theft of illegal devices, improving the security and reliability of the mobile storage device, and preventing data leakage.
[0087] In one embodiment, the security of the mobile storage device is further improved, and the files of the mobile storage device are stored in encrypted form, so that the contents cannot be directly read through physical access.
[0088] When the operation is a read-write operation and the mobile terminal is a temporary access terminal.
[0089] If the first permission verification result of the mobile terminal is legal, an operation is performed, including:
[0090] If the first permission verification result of the temporary access terminal is legal, and the read and write permission instruction and the first dynamic password are received from the management terminal through the wireless communication module, the file is encrypted or decrypted based on the read and write permission instruction, and the read and write operations are performed using the first dynamic password.
[0091] The read / write permission instruction and the first dynamic password are generated after the management terminal receives the first read / write request from the temporary access terminal and verifies the legality of the authority of the temporary access terminal.
[0092] In the application, if the user of the temporary access terminal wants to read and write files in the mobile storage device, he needs to request permission from the management terminal through the temporary access terminal, and send a file read and write request to the management terminal through the temporary access terminal. At this time, the temporary access terminal is in a wireless connection state with the mobile storage device. In response to the file read and write request, the management terminal queries the authority of the temporary access terminal, and after determining that the authority is legal, generates a read and write permission instruction and a first dynamic password. The management terminal sends the read and write permission instruction and the first dynamic password to the mobile storage device through a wireless link. Based on the read and write permission instruction, the mobile storage device uses the first dynamic password to encrypt or decrypt the file, and perform read and write operations.
[0093] The first dynamic password may be generated by a symmetric encryption algorithm or an asymmetric encryption algorithm or according to a timestamp or a random number.
[0094] In a possible implementation, the mobile storage device records logs of key operations such as passwords, so that users of management terminals can monitor operations and discover abnormal operations, thereby promptly discovering and handling security issues.
[0095] In a possible implementation, the dynamic password is transmitted via a secure transmission protocol.
[0096] It should be noted that each time the mobile storage device receives a read / write request from an electronic device, it needs to receive a read / write permission instruction and a first dynamic password from the management terminal before executing subsequent steps. In addition, the access of a temporary access terminal is generally time-limited and will become invalid after the time window has passed, ensuring the content security of the mobile storage device.
[0097] In this embodiment, the management terminal confirms that the temporary access terminal has read and write permissions before allowing the mobile storage device to encrypt or decrypt files, and perform read and write operations, so that the mobile storage device can only be used under the control of the management terminal and when the temporary access terminal has permission, further reducing the access and theft of illegal devices, improving the security and reliability of mobile storage devices, and preventing data leakage.
[0098] In one embodiment, when the operation is a read-write operation and the mobile terminal is a management terminal.
[0099] If the first permission verification result of the mobile terminal is legal, before executing the operation, the following steps are included:
[0100] A second read-write request is sent to the management terminal through the wireless communication module.
[0101] Correspondingly, if the first permission verification result of the mobile terminal is legal, an operation is performed, including:
[0102] If the first authority verification result of the management terminal is legal, and the second dynamic password is received from the management terminal through the wireless communication module, the second dynamic password is used to encrypt or decrypt the file, and the read and write operations are performed.
[0103] The second dynamic password is generated by the management terminal according to the second read-write request.
[0104] In the application, the management terminal establishes a wireless connection with the mobile storage device. The mobile storage device receives the read and write operation of the electronic device and sends a file read and write request to the management terminal through the wireless link. The management terminal responds to the file read and write request, confirms that it is a legally paired terminal, generates a second dynamic password, and sends the second dynamic password to the mobile storage device through the wireless link. The mobile storage device uses the second dynamic password to encrypt or decrypt the file, and performs read and write operations.
[0105] This embodiment can only encrypt or decrypt files and perform read and write operations after receiving the second dynamic password from the management terminal, so that the mobile storage device can be used only under the control of the management terminal, further improving the security and reliability of the mobile storage device and preventing data leakage.
[0106] In one embodiment, Figure 2 This is a second flow chart of the access method provided by an embodiment of the present application. Figure 2 As shown, the access method, applied to the management terminal, includes:
[0107] S21: After the mobile storage device is connected to the electronic device, when the wireless communication module of the mobile storage device is successfully paired with the mobile storage device, identity confirmation information is sent to the mobile storage device.
[0108] Among them, the identity confirmation information is used to instruct the mobile storage device to set the authority of the management terminal. The authority of the management terminal is used to instruct the mobile storage device to perform the operation of the electronic device after verifying the legitimacy of the authority according to the identity information of the management terminal. The identity information is obtained after the mobile storage device is successfully paired with the management terminal.
[0109] In the application, after the mobile storage device establishes a connection with the electronic device, the mobile storage device turns on the wireless communication module. When the mobile storage device is paired with a terminal for the first time, the terminal and the mobile storage device are paired and a wireless connection is established after the pairing is successful. The terminal sends identity confirmation information to the mobile storage device through a wireless link, so that the mobile storage device marks the terminal as a management terminal and records the device information of the management terminal.
[0110] The management terminal may instruct the mobile storage device that the authority of the management terminal is a default configuration.
[0111] In a possible implementation, it may be further configured that when the management terminal is replaced, the mobile storage device needs to be restored to factory settings, that is, the mobile storage device is formatted to ensure that the content of the mobile storage device is not easily lost.
[0112] This embodiment establishes a connection between the mobile storage device and the electronic device, and when the wireless communication module of the mobile storage device is successfully paired with the mobile storage device, identity confirmation information is sent to the mobile storage device, thereby ensuring that the management terminal has control over the mobile storage device and reducing the occurrence of illegal device access and theft.
[0113] In one embodiment, the method further comprises:
[0114] S22: Generate an access credential so that the temporary access terminal can communicate with the management terminal through the access credential.
[0115] In the application, when someone else wants to access the mobile storage device, they can request it through the terminal used (temporary access terminal). The management terminal generates access credentials, and the temporary access terminal requests access rights from the management terminal through the access credentials.
[0116] For example, the access credential may be an access QR code or an authorization link. The temporary access terminal scans the QR code or clicks the authorization link to communicate with the management terminal.
[0117] S23: receiving an access request from a temporary access terminal, and determining authorization authority of the temporary access terminal in response to the access request.
[0118] S24: Sending the authorization authority to the mobile storage device, where the authorization authority is used to instruct the mobile storage device to set the authority for temporary access to the terminal according to the authorization authority.
[0119] In the application, the mobile storage device is authorized via a wireless link. The management terminal can also feed back the authorization result to the temporary access terminal so that the temporary access terminal can obtain the authorization information.
[0120] During use, when the user of the management terminal finds the risk of content leakage of the mobile storage device, all temporary access rights can be revoked, so that when the temporary access terminal requests to access the mobile storage device, the management terminal rejects the request.
[0121] In a possible implementation, the management terminal records the usage status, operation records, and permissions and requests of each mobile terminal of the mobile storage device, so that the user of the mobile terminal can monitor the operation and detect abnormal operation, and timely discover and handle security issues.
[0122] This embodiment generates access credentials so that the temporary access terminal can communicate with the management terminal through the access credentials, receives an access request from the temporary access terminal, determines the authorization authority of the temporary access terminal in response to the access request, and sends the authorization authority to the mobile storage device. The authorization authority is used to instruct the mobile storage device to set the authority of the temporary access terminal according to the authorization authority, so that only authorized terminals can access the content of the mobile storage device, so that the temporary access terminal can operate the mobile storage device under the control of the management terminal and only after obtaining the authority, further reducing the access and theft of illegal devices, improving the security and reliability of the mobile storage device, and preventing data leakage.
[0123] In one embodiment, the method further comprises:
[0124] S25: If a first read / write request is received from the temporary access terminal, the authority of the temporary access terminal is verified to obtain a second authority verification result.
[0125] In the application, when the user of the temporary access terminal wants to read or write files in the mobile storage device, the temporary access terminal sends a file read or write request to the management terminal. At this time, the temporary access terminal and the mobile storage device are in a wireless connection state.
[0126] The management terminal queries the authority of the temporary access terminal in response to the file read / write request.
[0127] S26: If the second permission verification result is legal, generate a read / write permission instruction and a first dynamic password according to the first read / write request, and send the read / write permission instruction and the first dynamic password to the mobile storage device, so that the mobile storage device encrypts or decrypts the file based on the read / write permission instruction using the first dynamic password.
[0128] In the application, after the management terminal determines that the authority is legal, it generates a read and write permission instruction and a first dynamic password. The management terminal establishes a wireless connection with the mobile storage device and sends the read and write permission instruction and the first dynamic password to the mobile storage device through the wireless link.
[0129] S27: If a second read / write request is received from the mobile storage device, a second dynamic password is generated, and the second dynamic password is sent to the mobile storage device, so that the mobile storage device uses the second dynamic password to perform encryption or decryption operations on the file.
[0130] In the application, when the user of the management terminal performs a read / write operation on the mobile storage device through an electronic device, the mobile storage device sends a file read / write request to the management terminal through a wireless link. The management terminal responds to the file read / write request, confirms that it is a legally paired terminal, generates a second dynamic password, and sends the second dynamic password to the mobile storage device through a wireless link.
[0131] In a possible implementation, a secure transmission protocol is used to transmit the dynamic password, thereby reducing the possibility that the dynamic password is stolen during the transmission process.
[0132] In a possible implementation, the management terminal records the key so that the user of the management terminal can monitor the operation and discover abnormal operation, so as to timely discover and handle security issues.
[0133] In this embodiment, the mobile storage device can only encrypt or decrypt files and perform read and write operations when the management terminal confirms that the read and write operations of the mobile storage device are legal, so that the mobile storage device can only be used under the control range of the management terminal, further improving the security and reliability of the mobile storage device and preventing data leakage.
[0134] In one embodiment, the method further comprises:
[0135] After the mobile storage device establishes a connection with the electronic device, a configuration operation is sent to the mobile storage device, where the configuration operation is used to instruct the mobile storage device to display files and directories.
[0136] In this embodiment, the mobile storage device can display content on the electronic device only after being permitted by the management device, so that the mobile storage device can be used only under the control range of the management terminal, thereby further protecting the content of the mobile storage device.
[0137] In one embodiment, the method further comprises:
[0138] A file deletion instruction and / or a formatting instruction is sent to the mobile storage device, wherein the file deletion instruction is used to instruct the mobile storage device to delete the file, and the formatting instruction is used to instruct the mobile storage device to format.
[0139] In the application, a file deletion instruction and / or a formatting instruction is sent to the mobile storage device via a wireless link.
[0140] In a possible implementation, the management terminal may also be configured to perform a formatting operation after the mobile storage device is powered on for a period of time exceeding a preset period of time.
[0141] This embodiment can remotely control the mobile storage device to delete files or format, thereby preventing data leakage, by sending a file deletion instruction and / or a formatting instruction to the mobile storage device.
[0142] In one embodiment, to further improve the security of the mobile storage device, the method further includes:
[0143] Generate keys periodically.
[0144] The legitimacy of the wireless link is verified according to the key, and the link verification result is obtained.
[0145] If the link verification result is illegal, the permissions of each mobile terminal will be revoked.
[0146] In the application, the key can be a dynamic password. The key generation cycle can be set according to the actual scenario requirements. After the management device establishes a wireless connection with the mobile storage device, a key is generated periodically to verify the legitimacy of the wireless link based on the key.
[0147] This embodiment periodically generates keys, verifies the legitimacy of wireless links based on the keys, and obtains link verification results. If the link verification results are illegal, the permissions of each mobile terminal are revoked. Illegal communication links can be discovered in a timely manner, permissions can be revoked in a timely manner, and the security and reliability of mobile storage devices can be further improved, the content of mobile storage devices can be further protected, and data leakage can be prevented.
[0148] In the method described in the above embodiment, the user can operate the application on the terminal to enable the mobile terminal to perform the above operation.
[0149] By using the method described in the above embodiment, multi-level security protection measures are set for the mobile storage device, which can effectively prevent data leakage.
[0150] It should be understood that the order of execution of the steps in the above embodiments does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. In addition, the data collection in the above embodiments is compliant, and its use or implementation does not involve any infringement on the public interest.
[0151] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0152] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0153] An embodiment of the present application also provides a mobile storage device, including a wireless communication module, a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps in the above-mentioned method embodiments applied to the mobile storage device when executing the computer program.
[0154] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0155] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile storage device, the mobile storage device can implement the steps in the above-mentioned various method embodiments when executing the computer program product.
[0156] An embodiment of the present application provides a mobile terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps in the above-mentioned various method embodiments applied to the mobile terminal when executing the computer program.
[0157] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera / terminal device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some cases, the computer-readable medium cannot be an electric carrier signal and a telecommunication signal.
[0158] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0159] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0160] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0161] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0162] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. An access method, characterized in that: Applied to a mobile storage device, the mobile storage device is provided with a wireless communication module; The method comprises: After the mobile storage device establishes a connection with the electronic device, if an operation from the electronic device is received, the authority of the mobile terminal is verified according to the identity information of the mobile terminal to obtain a first authority verification result, wherein the identity information is obtained after the wireless communication module is successfully paired with the mobile terminal, and the mobile terminal is a management terminal or a temporary access terminal; If the first permission verification result of the mobile terminal is legal, the operation is performed.
2. The method according to claim 1, characterized in that When the mobile terminal is a temporary access terminal; Before verifying the authority of the mobile terminal according to the identity information of the mobile terminal, the method further includes: receiving authorization authority from the management terminal through the wireless communication module, and setting authority of the temporary access terminal according to the authorization authority, wherein the authorization authority is determined by the management terminal after the temporary access terminal communicates with the management terminal through the access credential; Correspondingly, verifying the authority of the mobile terminal according to the identity information of the mobile terminal includes: The authority of the temporary access terminal is verified according to the identity information of the temporary access terminal.
3. The method according to claim 1, characterized in that When the operation is a read-write operation and the mobile terminal is a temporary access terminal; If the first permission verification result of the mobile terminal is legal, performing the operation includes: If the first permission verification result of the temporary access terminal is legal, and the read-write permission instruction and the first dynamic password are received from the management terminal through the wireless communication module, then based on the read-write permission instruction, the first dynamic password is used to encrypt or decrypt the file, and the read-write operation is performed; The read / write permission instruction and the first dynamic password are generated after the management terminal receives the first read / write request from the temporary access terminal and verifies the legality of the authority of the temporary access terminal.
4. The method according to claim 1, characterized in that: When the operation is a read-write operation and the mobile terminal is a management terminal; If the first permission verification result of the mobile terminal is legal, before performing the operation, the method includes: Sending a second read / write request to the management terminal through the wireless communication module; Correspondingly, if the first permission verification result of the mobile terminal is legal, performing the operation includes: If the first permission verification result of the management terminal is legal, and the second dynamic password is received from the management terminal through the wireless communication module, the second dynamic password is used to encrypt or decrypt the file, and the read and write operations are performed; The second dynamic password is generated by the management terminal according to the second read-write request.
5. The method according to any one of claims 1 to 4, characterized in that: Before receiving the operation from the electronic device, the method further includes: After the mobile storage device is connected to the electronic device, if a configuration operation is received from the management terminal through the wireless communication module, the files and directories are displayed according to the configuration operation.
6. An access method, characterized in that: Applicable to management terminals, including: After the mobile storage device establishes a connection with the electronic device, when the wireless communication module of the mobile storage device is successfully paired with the mobile storage device, identity confirmation information is sent to the mobile storage device, the identity confirmation information is used to instruct the mobile storage device to set the authority of the management terminal, the authority of the management terminal is used to instruct the mobile storage device to perform the operation of the electronic device after verifying the legitimacy of the authority according to the identity information of the management terminal, and the identity information is obtained after the mobile storage device is successfully paired with the management terminal.
7. The method according to claim 6, characterized in that Also includes: generating an access credential so that the temporary access terminal can communicate with the management terminal through the access credential; receiving an access request from the temporary access terminal, and determining, in response to the access request, an authorization authority of the temporary access terminal; The authorization authority is sent to the mobile storage device, where the authorization authority is used to instruct the mobile storage device to set the authority for temporarily accessing the terminal according to the authorization authority.
8. The method according to claim 6 or 7, characterized in that: Also includes: If a first read / write request is received from a temporary access terminal, verifying the authority of the temporary access terminal to obtain a second authority verification result; If the second permission verification result is legal, generating a read / write permission instruction and a first dynamic password according to the first read / write request, and sending the read / write permission instruction and the first dynamic password to the mobile storage device, so that the mobile storage device encrypts or decrypts the file based on the read / write permission instruction and using the first dynamic password; If a second read / write request is received from the mobile storage device, a second dynamic password is generated and sent to the mobile storage device, so that the mobile storage device uses the second dynamic password to perform encryption or decryption operations on the file.
9. The method according to claim 6, characterized in that Also includes: After the mobile storage device is connected to the electronic device, a configuration operation is sent to the mobile storage device, where the configuration operation is used to instruct the mobile storage device to display files and directories.
10. A mobile storage device, comprising a wireless communication module, a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.