Storage encryption gateway and encryption and decryption method
By adopting the receiving and sending end isolation architecture of a dual computing environment in the IP SAN encryption gateway, and using the encryption module to encrypt and decrypt the data, the problems of high resource consumption, low encryption efficiency and data transmission security risks in the existing technology are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510446757.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The existing IP SAN encryption gateways consume a lot of system resources, low encryption efficiency, and have a great impact on performance. At the same time, there is a security risk that data will be sent to storage without encryption.
The receiving and sending end isolation architecture of a dual computing environment is adopted, and the data is encrypted and decrypted through the encryption module to ensure that the data must be processed through the encryption module during transmission, avoiding the risk of data being transmitted without encryption.
Improve data security, avoid performance losses, and interconnect with the receiver and sending ends through private protocols, improve transmission efficiency and reduce the risk of illegal intrusion.
Smart Images

Figure CN119945679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security storage, and more specifically, to a storage encryption gateway and an encryption and decryption method. Background Art
[0002] IP SAN is a centralized data storage device based on Ethernet. Due to the versatility of Ethernet and the rapid development of bandwidth, it is widely used in data center and information system construction.
[0003] In order to protect the data security in IP SAN devices, a storage encryption gateway has been developed to encrypt the data to be stored. Figure 5 As shown, the current IP SAN encryption gateway products mainly simulate IP SAN storage services on the gateway device, remap the original IP SAN storage space, and encrypt and decrypt data through the block device driver during the remapping process.
[0004] like Figure 6 As shown, this service remapping method requires the implementation of a complete iSCSI and SCSI protocol stack and a virtual disk encryption module, which consumes a lot of system resources, has low encryption efficiency, and has a significant impact on performance.
[0005] like Figure 7 As shown, the existing encryption method adopts a call-based encryption and decryption mode, in which data is transmitted to the encryption card in the same computing device. After the encryption card completes the data encryption, it returns the data to the system memory, and then writes the data into the IP SAN storage space. This encryption mode has the security risk that the data is not sent to the encryption card for encryption but is directly stored on the IP SAN. Summary of the invention
[0006] The purpose of the present invention is to provide a storage encryption gateway and encryption and decryption method, a receiving end and a sending end isolation architecture of a dual computing environment, one end is responsible for receiving data, an encryption module is responsible for encrypting data, and the other end is responsible for sending data. Data must pass through the encryption module to be written or read, and the encryption process cannot be bypassed. The risk of data being sent out without encryption after being received in the same computing environment can be avoided, thereby improving data security.
[0007] The above technical purpose of the present invention is achieved through the following technical solutions: a storage encryption gateway, comprising: a receiving calculation module, an encryption module, and a sending calculation module; A receiving and computing module is used to receive and parse the request data packet sent by the application server, allocate a key to the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and send it to the encryption module; it is also used to parse the fourth private protocol packet, and then encapsulate it into a standard protocol packet and send it to the application server; The encryption module is used to store the key; parse the first private protocol packet, and encapsulate it directly or encrypt it with the key according to the request type to obtain the second private protocol packet and send it to the sending calculation module; and parse the third private protocol packet, and encapsulate it directly or decrypt it with the key according to the request type to obtain the fourth private protocol packet and send it to the receiving calculation module; The sending calculation module is used to parse the second private protocol packet, re-encapsulate it into a data packet, and then send it to the memory; it is also used to parse the response data packet returned by the memory, re-encapsulate it into a third private protocol packet and send it to the encryption module.
[0008] As a preferred technical solution of the present invention, the storage encryption gateway also includes a PUF module; the PUF module is used to generate an initiator PUF fingerprint value and a target PUF fingerprint value before the storage encryption gateway is applied, and import them into the encryption module; and is also used to generate a PUF fingerprint value when receiving a challenge from the initiator, and send it to the initiator; A receiving and calculating module is used to, after parsing the request data packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value of the initiator, calculate the first check value for the parsed protocol header, and encapsulate it into the first private protocol packet; and is also used to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value, calculate the seventh check value for the protocol header, and compare it with the sixth check value. If they are consistent, encapsulate it into a standard protocol packet and send it to the application server. If they are inconsistent, perform special processing; The encryption module is also used to store the imported initiator PUF fingerprint value and the target PUF fingerprint value; after parsing the first private protocol package, use the imported initiator PUF fingerprint value to calculate the second check value for the parsed protocol header, and compare it with the first check value; if they are inconsistent, special processing is performed; if they are consistent, use the imported target PUF fingerprint value to calculate the third check value for the parsed protocol header, and encapsulate it in the second private protocol package; it is also used to parse the third private protocol package, use the imported target PUF fingerprint value to calculate the fifth check value for the protocol header, compare the fifth check value with the fourth check value, and perform special processing if they are inconsistent. If they are consistent, use the imported initiator PUF fingerprint value to calculate the sixth check value for the protocol header, and encapsulate it in the fourth private protocol package; The sending calculation module is used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the second private protocol packet, calculate the fourth verification value for the parsed protocol header, and compare it with the third verification value. If they are consistent, it is encapsulated in the target protocol packet; if they are inconsistent, special processing is performed; it is also used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the response data packet, calculate the fourth verification value for the protocol header, and encapsulate it in the third private protocol packet.
[0009] As a preferred technical solution of the present invention, after obtaining the PUF fingerprint value, the check value calculated for the protocol header is the integrity check value.
[0010] As a preferred technical solution of the present invention, the special processing is: discarding the current data, recording the alarm log, and returning the alarm log to the application server.
[0011] As a preferred technical solution of the present invention, the request data packet is an iSCSI protocol packet.
[0012] As a preferred technical solution of the present invention, the request type of the request data packet includes a write request and a non-write request; when the request data packet is a non-write request, it is directly encapsulated to obtain a second private protocol packet; when the request data packet is a write request, it is encrypted using a key and then encapsulated to obtain a second private protocol packet; The request types of the response data packet include read request and non-read request; when the request data packet is a non-read request, it is directly encapsulated to obtain the fourth private protocol packet; when the request data packet is a read request, it is decrypted using a key and then encapsulated to obtain the fourth private protocol packet.
[0013] A method for encryption and decryption of a storage encryption gateway comprises the following steps: S1. Obtain the key and import it into the encryption module; S2. In response to the data transmission instruction, the receiving computing module receives and parses the request data packet from the application server, allocates a key to the storage volume ID in the request data packet, and then encapsulates the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and sends it to the encryption module; S3. The first private protocol packet is parsed by the encryption module, and encapsulated directly or after encryption with a key according to the request type, to obtain a second private protocol packet and send it to the sending calculation module; S4, parsing the second private protocol packet through the sending calculation module, repackaging it into a data packet, and then sending it to the storage; S5, parsing the response data packet returned by the memory through the sending calculation module, repackaging it into a third private protocol packet and sending it to the encryption module; S6. Parse the third private protocol packet through the encryption module, and directly encapsulate or decrypt using the key to obtain a fourth private protocol packet according to the request type, and send it to the receiving calculation module; S7. Parse the fourth private protocol packet through the receiving calculation module, encapsulate it into a standard protocol packet and send it to the application server.
[0014] As a preferred technical solution of the present invention, in S1, before importing the key into the encryption module, the IP address mapping relationship and access permission information of the storage and application server are obtained and configured in the storage encryption gateway.
[0015] As a preferred technical solution of the present invention, in S1, the encryption module is controlled to interact with the PUF module, the initiator PUF fingerprint value and the target PUF fingerprint value are generated, and are imported into the encryption module; In S2, the data packet content parsed by the receiving calculation module includes: a protocol header and a protocol payload; after the receiving calculation module assigns a key to the storage volume ID, it challenges the PUF module to obtain a PUF fingerprint value, and uses the PUF fingerprint value to calculate a first check value for the protocol header; then the parsed protocol header, protocol payload, storage volume ID corresponding key seal and the first check value are encapsulated into a first private protocol packet and sent to the encryption module; In S3, the encryption module parses the protocol header, protocol payload, key seal corresponding to the storage volume ID, and the first check value from the first private protocol package, uses the imported initiator PUF fingerprint value, calculates the second check value for the protocol header parsed from the first private protocol package, and compares it with the first check value; if they are inconsistent, special processing is performed; if they are consistent, the imported target PUF fingerprint value is used to calculate the third check value for the protocol header parsed from the first private protocol package, and directly encapsulates it or decrypts it with the key and encapsulates it in the second private protocol package; In S4, the sending calculation module parses the following from the second private protocol packet: the protocol header, the protocol payload, the key corresponding to the storage volume ID, and the third check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compares it with the third check value. If they are consistent, it is encapsulated in the target protocol packet. If they are inconsistent, special processing is performed; In S5, the sending calculation module parses the response data packet to obtain the protocol header, protocol payload, and storage volume ID corresponding key, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol package; In S6, the encryption module parses the third private protocol packet to obtain: a protocol header, a protocol payload, a key corresponding to the storage volume ID, and a fourth check value. The fifth check value is calculated for the protocol header using the imported target end PUF fingerprint value. The fifth check value is compared with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, the imported initiator end PUF fingerprint value is used to calculate the sixth check value for the protocol header, and the sixth check value is directly encapsulated or decrypted using the key and encapsulated in the fourth private protocol packet. In S7, the receiving and calculating module parses the fourth private protocol packet to obtain the protocol header, protocol payload, storage volume ID corresponding key, and the sixth verification value, initiates a challenge to the PUF module, obtains the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh verification value for the protocol header, and compares it with the sixth verification value. If they are consistent, it is encapsulated into a standard protocol package and sent to the application server. If they are inconsistent, special processing is performed.
[0016] In summary, the present invention has the following beneficial effects: The receiving and sending ends of the dual computing environment are isolated from each other. One end is responsible for receiving data, and the encryption module is responsible for encrypting the data. The other end is responsible for sending data. Data must pass through the encryption module to be written or read. The encryption process cannot be bypassed. This can avoid the risk of data being sent out without encryption after being received in the same computing environment, thereby improving data security.
[0017] The encryption module is interconnected with the receiving end and the sending end respectively through a private protocol, which effectively improves the transmission efficiency and avoids the risk of illegal intrusion caused by using conventional communication methods such as Ethernet.
[0018] Through the PUF unique fingerprint value and the integrity verification mechanism of the iSCSI protocol header, the legitimacy of the receiving end, the sending end and the encryption module identity is authenticated to ensure data security.
[0019] The receiving calculation module, sending calculation module, and encryption module perform integrity verification on the iSCSI protocol header through the PUF unique fingerprint value to ensure that the data packet has been processed by the encryption and decryption module, thus preventing the mistransmission of data that has not been encrypted and decrypted.
[0020] The receiving computing module for the business end, the sending computing module for the storage end, and the encryption and decryption module are all integrated devices. Compared with separate computing and encryption devices, they are easier to manage and maintain and have higher security. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the storage encryption gateway of the present invention; Figure 2 It is a flow chart of the encryption and decryption method of the present invention; Figure 3It is a schematic diagram of the encryption and decryption process of the present invention; Figure 4 It is a schematic diagram of the connection between the storage encryption gateway, application server, and IP SAN array of the present invention; Figure 5 This is a schematic diagram of existing encryption gateway products; Figure 6 It is a schematic diagram of an existing encryption server; Figure 7 This is a schematic diagram of the existing encryption mode. DETAILED DESCRIPTION
[0022] The present invention is further described in detail below in conjunction with the accompanying drawings.
[0023] like Figure 1 As shown, the present invention provides a storage encryption gateway, based on the iSCSI protocol, for IP SAN array storage data, including: a receiving calculation module, an encryption module, and a sending calculation module; The receiving computing module is connected to the Initiator end of the application server; The sending computing module is connected to the Target end of the IP SAN array.
[0024] The receiving and calculating module is used to receive and parse the request data packet sent by the application server, assign a key to the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and send it to the encryption module; it is also used to parse the fourth private protocol packet, and then encapsulate it into a standard protocol packet and send it to the application server; wherein the request data packet is an iSCSI protocol packet.
[0025] The encryption module is used to store the key; parse the first private protocol packet, and encapsulate it directly or encrypt it with the key according to the request type to obtain the second private protocol packet and send it to the sending calculation module; and parse the third private protocol packet, and encapsulate it directly or decrypt it with the key according to the request type to obtain the fourth private protocol packet and send it to the receiving calculation module; The sending calculation module is used to parse the second private protocol packet, re-encapsulate it into a data packet, and then send it to the memory; it is also used to parse the response data packet returned by the memory, re-encapsulate it into a third private protocol packet and send it to the encryption module.
[0026] Embodiment 1, as Figure 2 As shown; the specific implementation method of the red-black isolation data encryption method based on the iSCSI protocol layer is as follows: Deploy an iSCSI protocol encryption gateway. The sending calculation module of the encryption gateway is connected to the IP SAN disk array through the Ethernet network, and the receiving calculation module of the encryption gateway is connected to the application server through the Ethernet network; Create iSCSI Target on the IP SAN array and configure output storage volumes to provide data storage space for users, and configure access control permissions for application servers; Import IP SAN array address information and access permission information on the iSCSI encryption gateway and initialize the encryption key; The application server initiates a connection request to the IP SAN array iSCSI Target through the iSCSI Initiator and establishes an iSCSI session connection; The receiving computing module captures the iSCSI protocol packets interacting between the application server and the IP SAN array, obtains the storage volume identifier by parsing the protocol packets, and allocates an encryption key to the volume according to the storage volume identifier. The encryption key is locked by the application server Initiator name, the IP SAN array iSCSI Target, and the volume ID. The application server interacts with the iSCSI encryption gateway in plain text, and uses the key to encrypt and decrypt the iSCSI data payload in the iSCSI session protocol interaction. The iSCSI encryption gateway and the IP SAN array transmit data in cipher text. like Figure 3 As shown, the specific encryption process is as follows: A1, the receiving computing module receives the iSCSI protocol packet sent by the application server iSCSI Initiator and parses it; A2, encapsulating the parsed iSCSI protocol header and iSCSI payload into a private protocol and sending them to the encryption module; A3, the encryption module receives the private protocol packet of the receiving computing module, unpacks it and verifies whether it is a legal iSCSI command word; A4, the encryption module forwards the iSCSI protocol header private protocol packet to the sending calculation module, encrypts the iSCSI protocol payload with the key M, and encapsulates the encrypted iSCSI protocol payload into a private protocol packet and sends it to the sending calculation module; A5. The sending calculation module receives the private protocol packet sent by the encryption module, depackets it, encapsulates it into an iSCSI protocol packet, and sends it to the IP SAN array iSCSI Target.
[0027] like Figure 3 As shown, the specific decryption process is as follows: B1, the sending calculation module receives the iSCSI protocol packet sent by the IP SAN array iSCSI Target and parses it; B2, encapsulate the parsed iSCSI protocol header and iSCSI payload into a private protocol and send them to the encryption module; B3, the encryption module receives the private protocol packet sent by the computing module, unpacks it and verifies whether it is a legal iSCSI command word; B4, the encryption module forwards the iSCSI protocol header private protocol packet to the receiving calculation module, decrypts the iSCSI protocol payload with the key M, and encapsulates the decrypted iSCSI protocol payload into a private protocol packet and sends it to the receiving calculation module; B5. The receiving calculation module receives the private protocol packet sent by the encryption module, depackets it, encapsulates it into an iSCSI protocol packet, and sends it to the application server iSCSI Initiator.
[0028] like Figure 4 As shown, in this embodiment, the iSCSI encryption gateway is connected to the application server and the IP SAN array through an Ethernet network. The IP SAN array is used to provide raw data storage volumes. The application server accesses data in the storage volume of the IP SAN array through the iSCSI protocol. The iSCSI encryption gateway captures the iSCSI protocol packet, encrypts and decrypts the iSCSI payload data after parsing, and re-encapsulates it into an iSCSI protocol packet and sends it, thereby ensuring that the data on the IP SAN array is stored in ciphertext form.
[0029] In Example 2, a PUF module is also introduced into the storage encryption gateway; the specific application process is as follows: The PUF module is used to generate a receiving end PUF fingerprint value and a sending end PUF fingerprint value before storing the encryption gateway application, and import them into the encryption module; it is also used to generate a PUF fingerprint value when receiving a challenge from the initiator, and send it to the initiator; A receiving and calculating module is used to, after parsing the request data packet, initiate a challenge to the PUF module to obtain the PUF fingerprint value of the receiving end, calculate the first check value for the parsed protocol header, and encapsulate it into the first private protocol packet; and is also used to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module to obtain the PUF fingerprint value, calculate the seventh check value for the protocol header, and compare it with the sixth check value. If they are consistent, encapsulate it into a standard protocol packet and send it to the application server. If they are inconsistent, perform special processing; The encryption module is also used to store the imported receiving-end PUF fingerprint value and the sending-end PUF fingerprint value; after parsing the first private protocol package, use the imported receiving-end PUF fingerprint value to calculate the second check value for the parsed protocol header, and compare it with the first check value; if they are inconsistent, special processing is performed; if they are consistent, use the imported sending-end PUF fingerprint value to calculate the third check value for the parsed protocol header, and encapsulate it in the second private protocol package; it is also used to parse the third private protocol package, use the imported sending-end PUF fingerprint value to calculate the fifth check value for the protocol header, compare the fifth check value with the fourth check value, and perform special processing if they are inconsistent. If they are consistent, use the imported receiving-end PUF fingerprint value to calculate the sixth check value for the protocol header, and encapsulate it in the fourth private protocol package; The sending calculation module is used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the second private protocol packet, calculate the fourth check value for the parsed protocol header, and compare it with the third check value. If they are consistent, they are encapsulated in the target protocol packet. If they are inconsistent, special processing is performed; it is also used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the response data packet, calculate the fourth check value for the protocol header, and encapsulate it in the third private protocol packet Specifically, after obtaining the PUF fingerprint value, the check value calculated for the protocol header is the integrity check value. Special processing is: discard current data, record alarm log, and return alarm log to application server.
[0030] Corresponding to the above-mentioned storage encryption gateway, the present invention also provides an encryption and decryption method of the storage encryption gateway, comprising the following steps: S1. Obtain the key and import it into the encryption module; Specifically, before importing the key into the encryption module, the IP address mapping relationship and access permission information of the storage and application server, ie, the IP SAN array Target and the server-side Initiator IP address, are obtained and configured in the storage encryption gateway.
[0031] When importing the key, the encryption module is also controlled to interact with the PUF module, the receiving end PUF fingerprint value and the sending end PUF fingerprint value are generated, and imported into the encryption module; In this step, after importing the key, the receiving end PUF fingerprint value, and the sending end PUF fingerprint value into the encryption module, the encryption module is initialized.
[0032] S2, in response to the data transmission instruction, receiving a request data packet, i.e., an iSCSI protocol packet, from the application server through the receiving computing module, parsing it, assigning a key to the storage volume ID in the request data packet, and then encapsulating the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and sending it to the encryption module; In S2, the data packet content parsed by the receiving calculation module includes: iSCSI protocol header, iSCSI payload; after the receiving calculation module assigns a key to the storage volume ID, it challenges the PUF module to obtain the PUF fingerprint value, and uses the PUF fingerprint value to calculate the first check value for the protocol header; then the parsed protocol header, protocol payload, storage volume ID corresponding key seal and the first check value are encapsulated into a first private protocol packet and sent to the encryption module; S3. The first private protocol packet is parsed by the encryption module, and encapsulated directly or after encryption with a key according to the request type, to obtain a second private protocol packet and send it to the sending calculation module; In S3, the encryption module parses the protocol header, protocol payload, key seal corresponding to the storage volume ID, and the first check value from the first private protocol package, uses the imported receiving end PUF fingerprint value, calculates the second check value for the protocol header parsed from the first private protocol package, and compares it with the first check value; if they are inconsistent, special processing is performed, that is, discarding the data, recording the alarm log, and returning; if they are consistent, the imported sending end PUF fingerprint value is used to calculate the third check value for the protocol header parsed from the first private protocol package, and directly encapsulates it or encapsulates it in the second private protocol package after decryption using the key; The request type of the request data packet includes a write request and a non-write request; when the request data packet is a non-write request, it is directly encapsulated to obtain a second private protocol packet; when the request data packet is a write request, it is encrypted using a key and then encapsulated to obtain a second private protocol packet; S4, parsing the second private protocol packet through the sending calculation module, repackaging it into a data packet, and then sending it to the storage device, that is, the IP SAN array end; In S4, the sending calculation module parses the following from the second private protocol packet: the protocol header, the protocol payload, the key corresponding to the storage volume ID, and the third check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compares it with the third check value. If they are consistent, it is encapsulated in the target protocol packet. If they are inconsistent, special processing is performed; S5, parsing the response data packet returned by the memory through the sending calculation module, repackaging it into a third private protocol packet and sending it to the encryption module; In S5, the sending calculation module parses the response data packet to obtain the protocol header, protocol payload, and storage volume ID corresponding key, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol package; S6. Parse the third private protocol packet through the encryption module, and directly encapsulate or decrypt using the key to obtain a fourth private protocol packet according to the request type, and send it to the receiving calculation module; In S6, the encryption module parses the third private protocol packet to obtain: a protocol header, a protocol payload, a key corresponding to the storage volume ID, and a fourth check value. The fifth check value is calculated for the protocol header using the imported sender PUF fingerprint value. The fifth check value is compared with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, the sixth check value is calculated for the protocol header using the imported receiver PUF fingerprint value, and is directly encapsulated or decrypted using the key and encapsulated in the fourth private protocol packet. The request types of the response data packet include read request and non-read request; when the request data packet is a non-read request, it is directly encapsulated to obtain the fourth private protocol packet; when the request data packet is a read request, it is decrypted using a key and then encapsulated to obtain the fourth private protocol packet.
[0033] S7. Parse the fourth private protocol packet through the receiving calculation module, encapsulate it into a standard protocol packet and send it to the application server.
[0034] In S7, the receiving and calculating module parses the fourth private protocol packet to obtain the protocol header, protocol payload, storage volume ID corresponding key, and the sixth verification value, initiates a challenge to the PUF module, obtains the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh verification value for the protocol header, and compares it with the sixth verification value. If they are consistent, it is encapsulated into a standard protocol package and sent to the application server. If they are inconsistent, special processing is performed.
[0035] The above solution can reduce the software stack level of the encryption gateway, effectively improve the processing performance, and combine PUF (Physical Unclonable Functions) technology to authenticate the legitimacy of the red and black ends. At the same time, it ensures that data must pass through the encryption module before being transmitted to the IP SAN array end. The encryption method cannot be bypassed, thereby effectively ensuring data security.
[0036] The advantages of the encryption and decryption method of the storage encryption gateway of the present invention are: 1) Linear encryption and decryption of data is implemented directly at the iSCSI protocol layer on the network path, without the need to remap the IP SAN storage volume, reducing the construction process of iSCSI, SCSI protocol software stacks and encryption and decryption drivers, effectively improving data encryption and decryption efficiency, improving data storage performance, and reducing the read and write delays caused by encryption and decryption to storage.
[0037] 2) Transparent encryption and decryption at the protocol layer, compatible with native iSCSI protocols, and supports the MPIO deployment mode of IP SAN storage volumes. That is, each iSCSI path between the application server and the IP SAN storage volume can be connected to the encryption gateway to achieve multi-path load balancing and fault takeover.
[0038] 3) The receiving and sending ends of the dual computing environment are isolated from each other. One end is responsible for receiving data, and the encryption module is responsible for encrypting the data. The other end is responsible for sending data. Data must pass through the encryption module to be written or read. The encryption process cannot be bypassed. This can avoid the risk of data being sent out without encryption after being received in the same computing environment, thereby improving data security.
[0039] 4) The encryption module is interconnected with the receiving end and the sending end respectively through a private protocol, which effectively improves the transmission efficiency and avoids the risk of illegal intrusion caused by the use of conventional communication methods such as Ethernet.
[0040] 5) Through the PUF unique fingerprint value and the integrity verification mechanism of the iSCSI protocol header, the legitimacy of the receiving end, the sending end and the encryption module identity are authenticated to ensure data security.
[0041] 6) The receiving calculation module, sending calculation module, and encryption module perform integrity verification on the iSCSI protocol header through the PUF unique fingerprint value to ensure that the data packet has been processed by the encryption and decryption module to prevent the mistransmission of data that has not been encrypted and decrypted.
[0042] 7) The receiving computing module for the business end, the sending computing module for the storage end, and the encryption and decryption module are integrated devices. Compared with separate computing and encryption devices, they are easier to manage and maintain and have higher security.
[0043] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.
Claims
1. A storage encryption gateway, characterized by: include: Receiving calculation module, encryption module, sending calculation module; A receiving and computing module is used to receive and parse the request data packet sent by the application server, allocate a key to the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and send it to the encryption module; it is also used to parse the fourth private protocol packet, and then encapsulate it into a standard protocol packet and send it to the application server; The encryption module is used to store the key; parse the first private protocol packet, and encapsulate it directly or encrypt it with the key according to the request type to obtain the second private protocol packet and send it to the sending calculation module; and parse the third private protocol packet, and encapsulate it directly or decrypt it with the key according to the request type to obtain the fourth private protocol packet and send it to the receiving calculation module; The sending calculation module is used to parse the second private protocol packet, re-encapsulate it into a data packet, and then send it to the memory; it is also used to parse the response data packet returned by the memory, re-encapsulate it into a third private protocol packet and send it to the encryption module.
2. A storage encryption gateway according to claim 1, characterized in that: The storage encryption gateway also includes a PUF module; the PUF module is used to generate an initiator PUF fingerprint value and a target PUF fingerprint value before the storage encryption gateway is applied, and import them into the encryption module; it is also used to generate a PUF fingerprint value when receiving a challenge from the initiator, and send it to the initiator; A receiving and calculating module is used to, after parsing the request data packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value of the initiator, calculate the first check value for the parsed protocol header, and encapsulate it into the first private protocol packet; and is also used to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value, calculate the seventh check value for the protocol header, and compare it with the sixth check value. If they are consistent, encapsulate it into a standard protocol packet and send it to the application server. If they are inconsistent, perform special processing; The encryption module is also used to store the imported initiator PUF fingerprint value and the target PUF fingerprint value; and is used to calculate the second check value for the parsed protocol header using the imported initiator PUF fingerprint value after parsing the first private protocol packet, and compare it with the first check value; If they are inconsistent, special processing is performed; If they are consistent, the imported target PUF fingerprint value is used to calculate the third check value for the parsed protocol header and encapsulate it in the second private protocol package; It is also used to calculate a fifth check value for the protocol header using the imported target end PUF fingerprint value after parsing the third private protocol packet, compare the fifth check value with the fourth check value, and perform special processing if they are inconsistent. If they are consistent, use the imported initiator end PUF fingerprint value to calculate a sixth check value for the protocol header, and encapsulate it in the fourth private protocol packet; The sending calculation module is used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the second private protocol packet, calculate the fourth verification value for the parsed protocol header, and compare it with the third verification value. If they are consistent, it is encapsulated in the target protocol packet; if they are inconsistent, special processing is performed; it is also used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the response data packet, calculate the fourth verification value for the protocol header, and encapsulate it in the third private protocol packet.
3. A storage encryption gateway according to claim 2, characterized in that: After the PUF fingerprint value is obtained, the check value calculated for the protocol header is the integrity check value.
4. The storage encryption gateway according to claim 1, characterized in that: Special processing is: discard current data, record alarm log, and return alarm log to application server.
5. The storage encryption gateway according to claim 1, characterized in that: The request data packet is an iSCSI protocol packet.
6. A storage encryption gateway according to claim 1, characterized in that: The request type of the request data packet includes a write request and a non-write request; when the request data packet is a non-write request, it is directly encapsulated to obtain a second private protocol packet; when the request data packet is a write request, it is encrypted using a key and then encapsulated to obtain a second private protocol packet; The request types of the response data packet include read request and non-read request; when the request data packet is a non-read request, it is directly encapsulated to obtain the fourth private protocol packet; when the request data packet is a read request, it is decrypted using a key and then encapsulated to obtain the fourth private protocol packet.
7. A method for encryption and decryption of a storage encryption gateway, characterized in that: The steps include: S1. Obtain the key and import it into the encryption module; S2. In response to the data transmission instruction, the receiving computing module receives and parses the request data packet from the application server, allocates a key to the storage volume ID in the request data packet, and then encapsulates the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and sends it to the encryption module; S3. The first private protocol packet is parsed by the encryption module, and encapsulated directly or after encryption with a key according to the request type, to obtain a second private protocol packet and send it to the sending calculation module; S4, parsing the second private protocol packet through the sending calculation module, repackaging it into a data packet, and then sending it to the storage; S5, parsing the response data packet returned by the memory through the sending calculation module, repackaging it into a third private protocol packet and sending it to the encryption module; S6. Parse the third private protocol packet through the encryption module, and directly encapsulate or decrypt using the key to obtain a fourth private protocol packet according to the request type, and send it to the receiving calculation module; S7. Parse the fourth private protocol packet through the receiving calculation module, encapsulate it into a standard protocol packet and send it to the application server.
8. The encryption and decryption method of a storage encryption gateway according to claim 7 is characterized in that: In S1, before importing the key into the encryption module, the IP address mapping relationship and access permission information of the storage and application server are obtained and configured in the storage encryption gateway.
9. The encryption and decryption method of a storage encryption gateway according to claim 7 is characterized in that: In S1, the encryption module is controlled to interact with the PUF module, the initiator PUF fingerprint value and the target PUF fingerprint value are generated, and imported into the encryption module; In S2, the data packet content parsed by the receiving calculation module includes: a protocol header and a protocol payload; after the receiving calculation module assigns a key to the storage volume ID, it challenges the PUF module to obtain a PUF fingerprint value, and uses the PUF fingerprint value to calculate a first check value for the protocol header; then the parsed protocol header, protocol payload, storage volume ID corresponding key seal and the first check value are encapsulated into a first private protocol packet and sent to the encryption module; In S3, the encryption module parses the protocol header, protocol payload, key seal corresponding to the storage volume ID, and the first check value from the first private protocol package, uses the imported initiator PUF fingerprint value, calculates the second check value for the protocol header parsed from the first private protocol package, and compares it with the first check value; if they are inconsistent, special processing is performed; if they are consistent, the imported target PUF fingerprint value is used to calculate the third check value for the protocol header parsed from the first private protocol package, and directly encapsulates it or decrypts it with the key and encapsulates it in the second private protocol package; In S4, the sending calculation module parses the following from the second private protocol packet: the protocol header, the protocol payload, the key corresponding to the storage volume ID, and the third check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compares it with the third check value. If they are consistent, it is encapsulated in the target protocol packet. If they are inconsistent, special processing is performed; In S5, the sending calculation module parses the response data packet to obtain the protocol header, protocol payload, and storage volume ID corresponding key, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol package; In S6, the encryption module parses the third private protocol packet to obtain: a protocol header, a protocol payload, a key corresponding to the storage volume ID, and a fourth check value. The fifth check value is calculated for the protocol header using the imported target end PUF fingerprint value. The fifth check value is compared with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, the imported initiator end PUF fingerprint value is used to calculate the sixth check value for the protocol header, and the sixth check value is directly encapsulated or decrypted using the key and encapsulated in the fourth private protocol packet. In S7, the receiving and calculating module parses the fourth private protocol packet to obtain the protocol header, protocol payload, storage volume ID corresponding key, and the sixth verification value, initiates a challenge to the PUF module, obtains the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh verification value for the protocol header, and compares it with the sixth verification value. If they are consistent, it is encapsulated into a standard protocol package and sent to the application server. If they are inconsistent, special processing is performed.
Citation Information
Patent Citations
System for managing Internet Protocol -Asymmetric / Very high data rate Digital Subscriber Linedivice
KR1020040104766A
Relay method of encryption communication, gateway server, and program and program memory medium of encryption communication
US20060136724A1
Distribution of private session key and offloading a protocol stack to a network communication device for secured communications
US20240048541A1
Security protection method and device and storage medium
WO2022041186A1