A storage encryption gateway and an encryption and decryption method
By adopting the receiving and sending end isolation architecture of a dual computing environment in the IP SAN encryption gateway, and using the encryption module to encrypt and decrypt the data, the problems of high resource consumption, low encryption efficiency and data security risks in the existing technology are solved, and more efficient data security and performance are achieved.
Patent Information
- Application Number
- CN202510446757.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The existing IP SAN encryption gateways consume a lot of system resources, low encryption efficiency, and have a great impact on performance. At the same time, there is a security risk that data will be stored in an IP SAN without encryption.
The receiving and sending end isolation architecture of a dual computing environment is adopted, and the data is encrypted and decrypted through the encryption module to ensure that the data must be processed through the encryption module during transmission and cannot be bypassed.
Improve data security, avoid the risk of data being sent out without encryption, enhance data storage performance, and reduce the consumption of system resources.
Smart Images

Figure CN119945679B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security storage, and more specifically, it relates to a storage encryption gateway and an encryption and decryption method. Background Art
[0002] IP SAN is a centralized data storage device based on Ethernet network. Due to the universality of Ethernet network and the rapid development of bandwidth, it is widely used in the construction of data centers and information systems.
[0003] To protect the data security in IP SAN devices, storage encryption gateways have been developed to encrypt and protect the data to be stored. As Figure 5 shown, the current IP SAN encryption gateway products mainly simulate the IP SAN storage service on the gateway device, remap the original IP SAN storage space, and encrypt and decrypt the data through the block device driver during the remapping process.
[0004] As Figure 6 shown, this way of service remapping needs to implement a complete iSCSI and SCSI protocol stack as well as a virtual disk encryption module, which has the problems of consuming a lot of system resources, low encryption efficiency, and great impact on performance.
[0005] As Figure 7 shown, the existing encryption method adopts a call - type encryption and decryption mode. In the same computing device, the data is transmitted to the encryption card, and after the encryption card completes the data encryption, the data is returned to the system memory and then written into the IP SAN storage space. This encryption mode has the security risk that the data is not sent to the encryption card for encryption but directly stored on the IP SAN. Summary of the Invention
[0006] The purpose of the present invention is to provide a storage encryption gateway and an encryption and decryption method, with a receiving - end and sending - end isolation architecture in a dual - computing environment. One end is responsible for receiving data, the encryption module is responsible for encrypting data, and the other end is responsible for sending data. The data must pass through the encryption module to be written or read, and the encryption process cannot be bypassed, which can avoid the risk that the data is sent out without being encrypted after being received in the same computing environment and improve data security.
[0007] The above technical purpose of the present invention is achieved through the following technical solutions: A storage encryption gateway includes: a receiving computing module, an encryption module, and a sending computing module;
[0008] A receiving calculation module, configured to receive a request data packet sent by an application server, parse the request data packet, assign a key to the storage volume ID in the request data packet, encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and send the first private protocol packet to an encryption module; the receiving calculation module is further configured to parse the fourth private protocol packet, and then encapsulate the fourth private protocol packet into a standard protocol packet and send the standard protocol packet to the application server;
[0009] An encryption module, configured to store keys; parse the first private protocol packet, and directly encapsulate the first private protocol packet according to the request type, or encapsulate the first private protocol packet after encrypting the first private protocol packet with a key, to obtain a second private protocol packet and send the second private protocol packet to a sending calculation module; the encryption module is further configured to parse the third private protocol packet, and directly encapsulate the third private protocol packet or encapsulate the third private protocol packet after decrypting the third private protocol packet with a key according to the request type, to obtain a fourth private protocol packet, and send the fourth private protocol packet to the receiving calculation module;
[0010] A sending calculation module, configured to parse the second private protocol packet and then re-encapsulate the second private protocol packet into a data packet, and then send the data packet to a memory; the sending calculation module is further configured to parse the response data packet returned by the memory, re-encapsulate the response data packet into a third private protocol packet and send the third private protocol packet to the encryption module.
[0011] As a preferred technical solution of the present invention, the storage encryption gateway further includes a PUF module; the PUF module is configured to generate an initiator PUF fingerprint value and a target PUF fingerprint value before the storage encryption gateway is applied, and import the initiator PUF fingerprint value and the target PUF fingerprint value into the encryption module; the PUF module is further configured to generate a PUF fingerprint value when receiving a challenge from an initiator, and send the PUF fingerprint value to the initiator;
[0012] The receiving calculation module is configured to, after parsing the request data packet, initiate a challenge to the PUF module to obtain an initiator PUF fingerprint value, calculate a first check value for the parsed protocol header, and encapsulate the first check value into the first private protocol packet; the receiving calculation module is further configured to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module to obtain a PUF fingerprint value, calculate a seventh check value for the protocol header, and compare the seventh check value with a sixth check value. If they are consistent, the receiving calculation module encapsulates the fourth private protocol packet into a standard protocol packet and sends the standard protocol packet to the application server. If they are inconsistent, the receiving calculation module performs special processing;
[0013] The encryption module is further configured to store the imported initiator PUF fingerprint value and target PUF fingerprint value; the encryption module is configured to, after parsing the first private protocol packet, use the imported initiator PUF fingerprint value to calculate a second check value for the parsed protocol header, and compare the second check value with the first check value; if they are inconsistent, the encryption module performs special processing; if they are consistent, the encryption module uses the imported target PUF fingerprint value to calculate a third check value for the parsed protocol header, and encapsulates the third check value in the second private protocol packet; the encryption module is further configured to, after parsing the third private protocol packet, use the imported target PUF fingerprint value to calculate a fifth check value for the protocol header, compare the fifth check value with a fourth check value, and perform special processing if they are inconsistent. If they are consistent, the encryption module uses the imported initiator PUF fingerprint value to calculate a sixth check value for the protocol header, and encapsulates the sixth check value in the fourth private protocol packet;
[0014] The sending calculation module is used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the second private protocol packet, calculate the fourth check value for the parsed protocol header, and compare it with the third check value. If they are consistent, it is encapsulated in the target protocol packet; if not, special processing is performed. It is also used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the response data packet, calculate the fourth check value for the protocol header, and encapsulate it in the third private protocol packet.
[0015] As a preferred technical solution of the present invention, after obtaining the PUF fingerprint value, the check value calculated for the protocol header is an integrity check value.
[0016] As a preferred technical solution of the present invention, the special processing is: discarding the current data, recording an alarm log, and returning the alarm log to the application server.
[0017] As a preferred technical solution of the present invention, the request data packet is an iSCSI protocol packet.
[0018] As a preferred technical solution of the present invention, the request types of the request data packet include write requests and non-write requests; when the request data packet is a non-write request, the second private protocol packet is directly encapsulated; when the request data packet is a write request, it is encrypted with a key and then encapsulated to obtain the second private protocol packet;
[0019] The request types of the response data packet include read requests and non-read requests; when the request data packet is a non-read request, the fourth private protocol packet is directly encapsulated; when the request data packet is a read request, it is decrypted with a key and then encapsulated to obtain the fourth private protocol packet.
[0020] A method for encrypting and decrypting a storage encryption gateway includes the following steps:
[0021] S1. Obtain a key and import it into the encryption module;
[0022] S2. In response to a data transmission instruction, receive and parse a request data packet from the application server through the receiving calculation module, allocate a key for the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet and send it to the encryption module;
[0023] S3. Parse the first private protocol packet through the encryption module, and directly encapsulate it or encrypt it with a key and then encapsulate it according to the request type to obtain a second private protocol packet and send it to the sending calculation module;
[0024] S4. Through the sending calculation module, re-encapsulate the second private protocol packet into a data packet after parsing and then send it to the memory;
[0025] S5. Through the sending calculation module, parse the response data packet returned by the memory, repackage it into a third private protocol packet and send it to the encryption module;
[0026] S6. Through the encryption module, parse the third private protocol packet, and according to the request type, directly encapsulate it or decrypt it with a key and then encapsulate it to obtain a fourth private protocol packet, and send it to the receiving calculation module;
[0027] S7. Through the receiving calculation module, parse the fourth private protocol packet, and then repackage it into a standard protocol packet and send it to the application server.
[0028] As a preferred technical solution of the present invention, in S1, before importing the key into the encryption module, obtain the IP address mapping relationship and access permission information of the memory and the application server, and configure them in the storage encryption gateway.
[0029] As a preferred technical solution of the present invention, in S1, control the encryption module to interact with the PUF module to generate the initiating end PUF fingerprint value and the target end PUF fingerprint value, and import them into the encryption module;
[0030] In S2, the data packet content parsed by the receiving calculation module includes: protocol header and protocol payload; after the receiving calculation module assigns a key to the storage volume ID, initiate a challenge to the PUF module to obtain the PUF fingerprint value, and use the PUF fingerprint value to calculate the first check value for the protocol header; then encapsulate the parsed protocol header, protocol payload, the key corresponding to the storage volume ID, and the first check value into a first private protocol packet and send it to the encryption module;
[0031] In S3, the encryption module parses out the protocol header, protocol payload, the key corresponding to the storage volume ID, and the first check value from the first private protocol packet, uses the imported initiating end PUF fingerprint value to calculate the second check value for the protocol header parsed from the first private protocol packet, and compares it with the first check value; if they are inconsistent, perform special processing; if they are consistent, use the imported target end PUF fingerprint value to calculate the third check value for the protocol header parsed from the first private protocol packet, and directly encapsulate it or decrypt it with a key and then encapsulate it in the second private protocol packet;
[0032] In S4, the sending calculation module parses out from the second private protocol packet: protocol header, protocol payload, the key corresponding to the storage volume ID, and the third check value, initiate a challenge to the PUF module to obtain the PUF fingerprint value, use the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compare it with the third check value. If they are consistent, encapsulate it in the target protocol packet; if they are inconsistent, perform special processing;
[0033] In S5, the sending calculation module parses the protocol header, protocol payload, and the key corresponding to the storage volume ID from the response data packet, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol packet;
[0034] In S6, the encryption module parses the third private protocol packet to obtain: protocol header, protocol payload, key corresponding to the storage volume ID, and the fourth check value. Using the imported PUF fingerprint value of the target end, it calculates the fifth check value for the protocol header, compares the fifth check value with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, using the imported PUF fingerprint value of the initiating end, it calculates the sixth check value for the protocol header and directly encapsulates it or decrypts it using the key and then encapsulates it in the fourth private protocol packet;
[0035] In S7, the receiving calculation module parses the fourth private protocol packet to obtain the protocol header, protocol payload, key corresponding to the storage volume ID, and the sixth check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh check value for the protocol header, and compares it with the sixth check value. If they are consistent, it is encapsulated into a standard protocol packet and sent to the application server. If they are inconsistent, special processing is performed.
[0036] In summary, the present invention has the following beneficial effects:
[0037] The receiving and sending end isolation architecture in a dual-computing environment, where one end is responsible for receiving data, the encryption module is responsible for encrypting data, and the other end is responsible for sending data. Data must pass through the encryption module to be written or read, and the encryption process cannot be bypassed, which can avoid the risk of data being sent out without encryption after being received in the same computing environment and improve data security.
[0038] The encryption module is interconnected with the receiving and sending ends through private protocols, effectively improving the transmission efficiency and avoiding the risk of illegal intrusion caused by using conventional communication methods such as Ethernet.
[0039] Through the integrity verification mechanism of the PUF unique fingerprint value and the iSCSI protocol header, the identities of the receiving and sending ends and the encryption module are legally authenticated to ensure data security.
[0040] The receiving calculation module, the sending calculation module, and the encryption module perform integrity verification on the iSCSI protocol header through the PUF unique fingerprint value to ensure that the data packet must have been processed by the encryption and decryption modules, avoiding the mistransmission of data that has not been encrypted and decrypted.
[0041] The receiving calculation module for the service end, the sending calculation module for the storage end, and the encryption and decryption module are an integrated device, which is easier to manage and maintain and has higher security compared to a device with separate computing and encryption. Brief Description of the Drawings
[0042] Figure 1 is a schematic diagram of the storage encryption gateway of the present invention;
[0043] Figure 2 is a flowchart of the encryption and decryption method of the present invention;
[0044] Figure 3 is a schematic diagram of the encryption and decryption process of the present invention;
[0045] Figure 4 is a schematic diagram of the connection among the storage encryption gateway, the application server, and the IP SAN array of the present invention;
[0046] Figure 5 is a schematic diagram of an existing encryption gateway product;
[0047] Figure 6 is a schematic diagram of an existing encryption server;
[0048] Figure 7 is a schematic diagram of an existing encryption mode. Detailed Description of the Invention
[0049] The present invention will be further described in detail below with reference to the accompanying drawings.
[0050] As Figure 1 shown, the present invention provides a storage encryption gateway, based on the iSCSI protocol, for storing data in an IP SAN array, including: a receiving and computing module, an encryption module, and a sending and computing module;
[0051] The receiving and computing module is connected to the Initiator end of the application server;
[0052] The sending and computing module is connected to the Target end of the IP SAN array.
[0053] The receiving and computing module is configured to receive and parse the request data packet sent by the application server, allocate a key for the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet and send it to the encryption module; it is also configured to parse the fourth private protocol packet, and then encapsulate it into a standard protocol packet and send it to the application server; wherein, the request data packet is an iSCSI protocol packet.
[0054] The encryption module is configured to store keys; parse the first private protocol packet, and directly encapsulate it according to the request type, or encapsulate it after encrypting with the key, to obtain a second private protocol packet and send it to the sending and computing module; it is also configured to parse the third private protocol packet, and directly encapsulate it or encapsulate it after decrypting with the key according to the request type to obtain a fourth private protocol packet, and send it to the receiving and computing module;
[0055] A sending calculation module, which is used to repackage the second private protocol packet into a data packet after parsing and then send it to the memory; it is also used to parse the response data packet returned by the memory, repackage it into a third private protocol packet and send it to the encryption module.
[0056] Example 1 is as Figure 2 shown; the specific implementation manner of the red-black isolation data encryption method based on the iSCSI protocol layer is as follows:
[0057] Deploy an iSCSI protocol encryption gateway. The sending calculation module of the encryption gateway is connected to the IP SAN disk array through an Ethernet network, and the receiving calculation module of the encryption gateway is connected to the application server side through an Ethernet network;
[0058] Create an iSCSI Target on the IP SAN array and configure the output storage volume to provide data storage space for users, and at the same time configure the access control rights of the application server;
[0059] Import the IP SAN array address information and access right information on the iSCSI encryption gateway and initialize the encryption key;
[0060] The application server side initiates a connection request to the IP SAN array iSCSI Target through the iSCSI Initiator and establishes an iSCSI session connection;
[0061] The receiving calculation module captures the iSCSI protocol packets exchanged between the application server and the IP SAN array, obtains the storage volume identifier by parsing the protocol packets, and allocates an encryption key for the volume according to the storage volume identifier. The encryption key is locked by three elements: the application server Initiator name, the iSCSI Target on the IP SAN array side, and the volume ID. The application server and the iSCSI encryption gateway interact in plaintext, and the key is used to encrypt and decrypt the iSCSI data payload in the iSCSI session protocol interaction. The iSCSI encryption gateway and the IP SAN array transmit data in ciphertext,
[0062] As Figure 3 shown, the specific encryption process is as follows:
[0063] A1. The receiving calculation module receives the iSCSI protocol packet sent by the application server iSCSI Initiator and parses it;
[0064] A2. Package the parsed iSCSI protocol header and iSCSI payload into a private protocol and send it to the encryption module;
[0065] A3. The encryption module receives the private protocol packet of the receiving calculation module, unpacks it, and checks whether it is a legal iSCSI command word.
[0066] A4. The encryption module forwards the private protocol packet of the iSCSI protocol header to the sending calculation module, encrypts the iSCSI protocol payload with the key M, and encapsulates the encrypted iSCSI protocol payload into a private protocol packet and sends it to the sending calculation module.
[0067] A5. The sending calculation module receives the private protocol packet sent by the encryption module, unpacks it, and encapsulates it into an iSCSI protocol packet and sends it to the IP SAN array iSCSI Target.
[0068] As Figure 3 shown, the specific decryption process is as follows:
[0069] B1. The sending calculation module receives the iSCSI protocol packet sent by the IP SAN array iSCSI Target and parses it.
[0070] B2. Encapsulate the parsed iSCSI protocol header and iSCSI payload into a private protocol and send it to the encryption module.
[0071] B3. The encryption module receives the private protocol packet of the sending calculation module, unpacks it, and checks whether it is a legal iSCSI command word.
[0072] B4. The encryption module forwards the private protocol packet of the iSCSI protocol header to the receiving calculation module, decrypts the iSCSI protocol payload with the key M, and encapsulates the decrypted iSCSI protocol payload into a private protocol packet and sends it to the receiving calculation module.
[0073] B5. The receiving calculation module receives the private protocol packet sent by the encryption module, unpacks it, and encapsulates it into an iSCSI protocol packet and sends it to the application server iSCSI Initiator.
[0074] As Figure 4 shown, in this embodiment, the iSCSI encryption gateway is connected to the application server and the IP SAN array respectively through the Ethernet network. The IP SAN array is used to provide the original data storage volume. The application server accesses and stores data in the storage volume of the IP SAN array through the iSCSI protocol. The iSCSI encryption gateway captures the iSCSI protocol packet, decrypts and encrypts the iSCSI payload data after parsing, and repackages it into an iSCSI protocol packet and sends it, so as to ensure that the data on the IP SAN array is saved in ciphertext form.
[0075] Embodiment 2. A PUF module is further introduced in the storage encryption gateway; the specific application process is as follows:
[0076] The PUF module is used to generate the receiver PUF fingerprint value and the sender PUF fingerprint value before storing the encrypted gateway application, and import them into the encryption module; it is also used to generate the PUF fingerprint value when receiving a challenge from the initiator and send it to the initiator;
[0077] The receiving calculation module is used to, after parsing the request data packet, initiate a challenge to the PUF module to obtain the receiver PUF fingerprint value, calculate the first check value for the parsed protocol header, and encapsulate it into the first private protocol packet; it is also used to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module to obtain the PUF fingerprint value, calculate the seventh check value for the protocol header, and compare it with the sixth check value. If they are the same, it is encapsulated into a standard protocol packet and sent to the application server. If they are different, special processing is performed;
[0078] The encryption module is also used to store the imported receiver PUF fingerprint value and sender PUF fingerprint value; it is used to, after parsing the first private protocol packet, use the imported receiver PUF fingerprint value to calculate the second check value for the parsed protocol header and compare it with the first check value; if they are different, special processing is performed; if they are the same, use the imported sender PUF fingerprint value to calculate the third check value for the parsed protocol header and encapsulate it in the second private protocol packet; it is also used to, after parsing the third private protocol packet, use the imported sender PUF fingerprint value to calculate the fifth check value for the protocol header, compare the fifth check value with the fourth check value, perform special processing if they are different, and if they are the same, use the imported receiver PUF fingerprint value to calculate the sixth check value for the protocol header and encapsulate it in the fourth private protocol packet;
[0079] The sending calculation module is used to, after parsing the second private protocol packet, initiate a challenge to the PUF module to obtain the PUF fingerprint value, calculate the fourth check value for the parsed protocol header, and compare it with the third check value. If they are the same, it is encapsulated in the target protocol packet. If they are different, special processing is performed; it is also used to, after parsing the response data packet, initiate a challenge to the PUF module to obtain the PUF fingerprint value, calculate the fourth check value for the protocol header, and encapsulate it in the third private protocol packet
[0080] Specifically, after obtaining the PUF fingerprint value, the check value calculated for the protocol header is the integrity check value
[0081] The special processing is: discarding the current data, recording the alarm log, and returning the alarm log to the application server.
[0082] Corresponding to the above storage encryption gateway, the present invention also provides a method for encrypting and decrypting the storage encryption gateway, including the following steps:
[0083] S1. Obtain the key and import it into the encryption module;
[0084] Specifically, before importing the key into the encryption module, obtain the IP address mapping relationship and access permission information of the memory and the application server, that is, the IP SAN array Target and the server-side Initiator IP address, and configure them in the storage encryption gateway.
[0085] When importing the key, also control the interaction between the encryption module and the PUF module to generate the receiver PUF fingerprint value and the sender PUF fingerprint value, and import them into the encryption module;
[0086] In this step, after importing the key, the receiver PUF fingerprint value, and the sender PUF fingerprint value into the encryption module, initialize the encryption module.
[0087] S2. In response to the data transfer instruction, receive the request data packet, that is, the iSCSI protocol packet, from the application server through the receiving and computing module, and parse it. Allocate a key for the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into the first private protocol packet, and send it to the encryption module;
[0088] In S2, the data packet content parsed by the receiving and computing module includes: the iSCSI protocol header and the iSCSI payload; after the receiving and computing module allocates a key for the storage volume ID, initiate a challenge to the PUF module to obtain the PUF fingerprint value, and use the PUF fingerprint value to calculate the first check value for the protocol header; then encapsulate the parsed protocol header, protocol payload, the key corresponding to the storage volume ID, and the first check value into the first private protocol packet and send it to the encryption module;
[0089] S3. Parse the first private protocol packet through the encryption module, and directly encapsulate it according to the request type, or encrypt it with the key and then encapsulate it to obtain the second private protocol packet and send it to the sending and computing module;
[0090] In S3, the encryption module parses the protocol header, protocol payload, the key corresponding to the storage volume ID, and the first check value from the first private protocol packet, uses the imported receiver PUF fingerprint value to calculate the second check value for the protocol header parsed from the first private protocol packet, and compares it with the first check value; if they are inconsistent, perform special processing, that is, discard the data, record the alarm log, and return; if they are consistent, use the imported sender PUF fingerprint value to calculate the third check value for the protocol header parsed from the first private protocol packet, and directly encapsulate it or decrypt it with the key and then encapsulate it in the second private protocol packet;
[0091] The request types of the request data packet include write requests and non-write requests; when the request data packet is a non-write request, directly encapsulate it to obtain the second private protocol packet; when the request data packet is a write request, encrypt it with the key and then encapsulate it to obtain the second private protocol packet;
[0092] S4, parsing the second private protocol packet through the sending calculation module, repackaging it into a data packet, and then sending it to the storage device, that is, the IP SAN array end;
[0093] In S4, the sending calculation module parses the following from the second private protocol packet: the protocol header, the protocol payload, the key corresponding to the storage volume ID, and the third check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compares it with the third check value. If they are consistent, it is encapsulated in the target protocol packet. If they are inconsistent, special processing is performed;
[0094] S5, parsing the response data packet returned by the memory through the sending calculation module, repackaging it into a third private protocol packet and sending it to the encryption module;
[0095] In S5, the sending calculation module parses the response data packet to obtain the protocol header, protocol payload, and storage volume ID corresponding key, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol package;
[0096] S6. Parse the third private protocol packet through the encryption module, and directly encapsulate or decrypt using the key to obtain a fourth private protocol packet according to the request type, and send it to the receiving calculation module;
[0097] In S6, the encryption module parses the third private protocol packet to obtain: a protocol header, a protocol payload, a key corresponding to the storage volume ID, and a fourth check value. The fifth check value is calculated for the protocol header using the imported sender PUF fingerprint value. The fifth check value is compared with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, the sixth check value is calculated for the protocol header using the imported receiver PUF fingerprint value, and is directly encapsulated or decrypted using the key and encapsulated in the fourth private protocol packet.
[0098] The request types of the response data packet include read request and non-read request; when the request data packet is a non-read request, it is directly encapsulated to obtain the fourth private protocol packet; when the request data packet is a read request, it is decrypted using a key and then encapsulated to obtain the fourth private protocol packet.
[0099] S7. Parse the fourth private protocol packet through the receiving calculation module, encapsulate it into a standard protocol packet and send it to the application server.
[0100] In S7, the receiving and calculating module parses the fourth private protocol packet to obtain the protocol header, protocol payload, storage volume ID corresponding key, and the sixth verification value, initiates a challenge to the PUF module, obtains the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh verification value for the protocol header, and compares it with the sixth verification value. If they are consistent, it is encapsulated into a standard protocol package and sent to the application server. If they are inconsistent, special processing is performed.
[0101] The above solution can reduce the software stack level of the encryption gateway, effectively improve the processing performance, and combine PUF (Physical Unclonable Functions) technology to authenticate the legitimacy of the red and black ends. At the same time, it ensures that data must pass through the encryption module before being transmitted to the IP SAN array end. The encryption method cannot be bypassed, thereby effectively ensuring data security.
[0102] The advantages of the encryption and decryption method of the storage encryption gateway of the present invention are:
[0103] 1) Linear encryption and decryption of data is implemented directly at the iSCSI protocol layer on the network path, without the need to remap the IP SAN storage volume, reducing the construction process of iSCSI, SCSI protocol software stacks and encryption and decryption drivers, effectively improving data encryption and decryption efficiency, improving data storage performance, and reducing the read and write delays caused by encryption and decryption to storage.
[0104] 2) Transparent encryption and decryption at the protocol layer, compatible with native iSCSI protocols, and supports the MPIO deployment mode of IP SAN storage volumes. That is, each iSCSI path between the application server and the IP SAN storage volume can be connected to the encryption gateway to achieve multi-path load balancing and fault takeover.
[0105] 3) The receiving and sending ends of the dual computing environment are isolated from each other. One end is responsible for receiving data, and the encryption module is responsible for encrypting the data. The other end is responsible for sending data. Data must pass through the encryption module to be written or read. The encryption process cannot be bypassed. This can avoid the risk of data being sent out without encryption after being received in the same computing environment, thereby improving data security.
[0106] 4) The encryption module is interconnected with the receiving end and the sending end respectively through a private protocol, which effectively improves the transmission efficiency and avoids the risk of illegal intrusion caused by the use of conventional communication methods such as Ethernet.
[0107] 5) Through the PUF unique fingerprint value and the integrity verification mechanism of the iSCSI protocol header, the legitimacy of the receiving end, the sending end and the encryption module identity are authenticated to ensure data security.
[0108] 6) The receiving calculation module, the sending calculation module, and the encryption module perform integrity verification on the iSCSI protocol header through the PUF unique fingerprint value to ensure that the data packet must have been processed by the encryption and decryption module, avoiding the mistransmission of data that has not been encrypted and decrypted.
[0109] 7) The receiving calculation module for the service side, the sending calculation module for the storage side, and the encryption and decryption module are an integrated device. Compared with the computing and encryption separate devices, it is easier to manage and maintain and has higher security.
[0110] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A storage encryption gateway, characterized by: include: Receiving calculation module, encryption module, sending calculation module, PUF module; A receiving and computing module is used to receive and parse the request data packet sent by the application server, allocate a key to the storage volume ID in the request data packet, and then encapsulate the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and send it to the encryption module; it is also used to parse the fourth private protocol packet, and then encapsulate it into a standard protocol packet and send it to the application server; The encryption module is used to store the key; parse the first private protocol packet, and encapsulate it directly or encrypt it with the key according to the request type to obtain the second private protocol packet and send it to the sending calculation module; and parse the third private protocol packet, and encapsulate it directly or decrypt it with the key according to the request type to obtain the fourth private protocol packet and send it to the receiving calculation module; The sending calculation module is used to parse the second private protocol packet, re-encapsulate it into a data packet, and then send it to the memory; it is also used to parse the response data packet returned by the memory, re-encapsulate it into a third private protocol packet and send it to the encryption module; The PUF module is used to generate the initiator PUF fingerprint value and the target PUF fingerprint value before storing the encryption gateway application, and import them into the encryption module; It is also used to generate a PUF fingerprint value upon receiving a challenge from the initiator and send it to the initiator; A receiving and calculating module is used to, after parsing the request data packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value of the initiator, calculate the first check value for the parsed protocol header, and encapsulate it into the first private protocol packet; and is also used to, after parsing the fourth private protocol packet, initiate a challenge to the PUF module, obtain the PUF fingerprint value, calculate the seventh check value for the protocol header, and compare it with the sixth check value. If they are consistent, encapsulate it into a standard protocol packet and send it to the application server. If they are inconsistent, perform special processing; The encryption module is also used to store the imported initiator PUF fingerprint value and the target PUF fingerprint value; and is used to calculate the second check value for the parsed protocol header using the imported initiator PUF fingerprint value after parsing the first private protocol packet, and compare it with the first check value; If they are inconsistent, special processing is performed; If they are consistent, the imported target PUF fingerprint value is used to calculate the third check value for the parsed protocol header and encapsulate it in the second private protocol package; It is also used to calculate a fifth check value for the protocol header using the imported target end PUF fingerprint value after parsing the third private protocol packet, compare the fifth check value with the fourth check value, and perform special processing if they are inconsistent. If they are consistent, use the imported initiator end PUF fingerprint value to calculate a sixth check value for the protocol header, and encapsulate it in the fourth private protocol packet; The sending calculation module is used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the second private protocol packet, calculate the fourth verification value for the parsed protocol header, and compare it with the third verification value. If they are consistent, it is encapsulated in the target protocol packet; if they are inconsistent, special processing is performed; it is also used to initiate a challenge to the PUF module to obtain the PUF fingerprint value after parsing the response data packet, calculate the fourth verification value for the protocol header, and encapsulate it in the third private protocol packet.
2. A storage encryption gateway according to claim 1, characterized in that: After the PUF fingerprint value is obtained, the check value calculated for the protocol header is the integrity check value.
3. A storage encryption gateway according to claim 1, characterized in that: Special processing is: discard current data, record alarm log, and return alarm log to application server.
4. The storage encryption gateway according to claim 1, characterized in that: The request data packet is an iSCSI protocol packet.
5. The storage encryption gateway according to claim 1, characterized in that: The request type of the request data packet includes a write request and a non-write request; when the request data packet is a non-write request, it is directly encapsulated to obtain a second private protocol packet; when the request data packet is a write request, it is encrypted using a key and then encapsulated to obtain a second private protocol packet; The request types of the response data packet include read request and non-read request; when the request data packet is a non-read request, it is directly encapsulated to obtain the fourth private protocol packet; when the request data packet is a read request, it is decrypted using a key and then encapsulated to obtain the fourth private protocol packet.
6. A method for encryption and decryption of a storage encryption gateway, characterized in that: The steps include: S1. Obtain the key and import it into the encryption module; S2. In response to the data transmission instruction, the receiving computing module receives and parses the request data packet from the application server, allocates a key to the storage volume ID in the request data packet, and then encapsulates the original data packet content and the key corresponding to the storage volume ID into a first private protocol packet, and sends it to the encryption module; S3. The first private protocol packet is parsed by the encryption module, and encapsulated directly or after encryption with a key according to the request type, to obtain a second private protocol packet and send it to the sending calculation module; S4, parsing the second private protocol packet through the sending calculation module, repackaging it into a data packet, and then sending it to the storage; S5, parsing the response data packet returned by the memory through the sending calculation module, repackaging it into a third private protocol packet and sending it to the encryption module; S6. Parse the third private protocol packet through the encryption module, and directly encapsulate or decrypt using the key to obtain a fourth private protocol packet according to the request type, and send it to the receiving calculation module; S7, parsing the fourth private protocol packet through the receiving calculation module, encapsulating it into a standard protocol packet and sending it to the application server; In S1, the encryption module is controlled to interact with the PUF module, the initiator PUF fingerprint value and the target PUF fingerprint value are generated, and imported into the encryption module; In S2, the data packet content parsed by the receiving calculation module includes: a protocol header and a protocol payload; after the receiving calculation module assigns a key to the storage volume ID, it challenges the PUF module to obtain a PUF fingerprint value, and uses the PUF fingerprint value to calculate a first check value for the protocol header; then the parsed protocol header, protocol payload, storage volume ID corresponding key seal and the first check value are encapsulated into a first private protocol packet and sent to the encryption module; In S3, the encryption module parses the protocol header, protocol payload, key seal corresponding to the storage volume ID, and the first check value from the first private protocol package, uses the imported initiator PUF fingerprint value, calculates the second check value for the protocol header parsed from the first private protocol package, and compares it with the first check value; if they are inconsistent, special processing is performed; if they are consistent, the imported target PUF fingerprint value is used to calculate the third check value for the protocol header parsed from the first private protocol package, and directly encapsulates it or decrypts it with the key and encapsulates it in the second private protocol package; In S4, the sending calculation module parses the following from the second private protocol packet: the protocol header, the protocol payload, the key corresponding to the storage volume ID, and the third check value, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header parsed from the second private protocol packet, and compares it with the third check value. If they are consistent, it is encapsulated in the target protocol packet. If they are inconsistent, special processing is performed; In S5, the sending calculation module parses the response data packet to obtain the protocol header, protocol payload, and storage volume ID corresponding key, initiates a challenge to the PUF module to obtain the PUF fingerprint value, uses the PUF fingerprint value to calculate the fourth check value for the protocol header, and encapsulates it in the third private protocol package; In S6, the encryption module parses the third private protocol packet to obtain: a protocol header, a protocol payload, a key corresponding to the storage volume ID, and a fourth check value. The fifth check value is calculated for the protocol header using the imported target end PUF fingerprint value. The fifth check value is compared with the fourth check value. If they are inconsistent, special processing is performed. If they are consistent, the imported initiator end PUF fingerprint value is used to calculate the sixth check value for the protocol header, and the sixth check value is directly encapsulated or decrypted using the key and encapsulated in the fourth private protocol packet. In S7, the receiving and calculating module parses the fourth private protocol packet to obtain the protocol header, protocol payload, storage volume ID corresponding key, and the sixth verification value, initiates a challenge to the PUF module, obtains the PUF fingerprint value, uses the PUF fingerprint value to calculate the seventh verification value for the protocol header, and compares it with the sixth verification value. If they are consistent, it is encapsulated into a standard protocol package and sent to the application server. If they are inconsistent, special processing is performed.
7. The encryption and decryption method of a storage encryption gateway according to claim 6 is characterized in that: In S1, before importing the key into the encryption module, the IP address mapping relationship and access permission information of the storage and application server are obtained and configured in the storage encryption gateway.
Citation Information
Patent Citations
System for managing Internet Protocol -Asymmetric / Very high data rate Digital Subscriber Linedivice
KR1020040104766A