Storage device and data management method thereof
By introducing multiple modes into the storage device and controlling mode switching using the matching of the tag information of the security chip and the memory chip, the problem of difficulty in taking into account both security and convenience in the reading and writing process of the storage device in the prior art is solved, and efficient data reading and writing under different security requirements is achieved.
Patent Information
- Application Number
- CN202510040619.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-09
AI Technical Summary
It is difficult for existing storage devices to take into account both security and convenience during reading and writing, especially during encryption and decryption. The consistent communication methods lead to inconvenient speed.
By introducing multiple modes into the storage device and using the matching of the tag information of the security chip and the memory chip to control mode switching, the encryption and decryption are adopted in different modes.
It realizes the convenience and speed of data reading and writing while ensuring data security, and is suitable for reading and writing requirements with different security requirements.
Smart Images

Figure CN119961994A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of storage technology, and in particular to a storage device and a data management method thereof. Background Art
[0002] In today's digital world, data security has become the primary concern of individual users and corporate organizations. During the reading and writing process of storage devices, sensitive data may face the risk of being stolen, leaked or tampered with. Storage devices represented by solid-state drives generally encrypt read and write data through built-in encryption algorithms, but encryption algorithms face problems such as key management and encryption algorithm vulnerabilities, which may cause data to be hacked during storage or transmission. In response to this, the industry has provided a storage device with an integrated security chip. As a hardware security module, the security chip is used to provide secure key storage and encryption operations. Its core advantage lies in hardware-level security, which can physically isolate the key for storing data, thereby preventing malicious attackers from cracking encrypted data through software means. However, during the data reading and writing process, the communication method with the security chip is the same every time encryption or decryption is performed, and keys need to be obtained from the security chip and identity authentication is required. For some reading and writing requirements with low security requirements, this will affect the data reading and writing speed and is not convenient enough.
[0003] Therefore, how to ensure that the storage device takes into account both security and convenience during the reading and writing process is an urgent problem to be solved. Summary of the invention
[0004] In view of this, the present application provides a storage device and a data management method thereof, which can improve the problem that it is difficult to balance security and convenience during the reading and writing process of the storage device.
[0005] The present application provides a data management method for a storage device, wherein the storage device includes a storage chip, a control chip, and a security chip connected to the control chip, and the method includes:
[0006] In response to the query instruction, obtaining label information of the security chip and the storage chip;
[0007] Determining whether the tag information of the security chip matches the tag information of the storage chip;
[0008] If they do not match, mode switching is prohibited;
[0009] If they match, then in response to the switching instruction, controlling the storage device to switch between a plurality of modes; and,
[0010] In response to the access instruction, the memory chip is accessed based on the switched mode.
[0011] A storage device provided in the present application includes a storage chip, a control chip, and a security chip connected to the control chip;
[0012] The control chip is used to obtain the tag information of the security chip and the storage chip in response to the query instruction, and to determine whether the tag information of the security chip and the storage chip matches;
[0013] If they do not match, mode switching is prohibited;
[0014] If they match, in response to a switch instruction, the storage device is controlled to switch between a plurality of modes; and in response to an access instruction, the storage chip is accessed based on the switched mode.
[0015] As described above, when the tag information of the security chip matches the tag information of the storage chip, the present application can control the storage device to switch between multiple modes (i.e., the first mode and the second mode), and access the storage chip based on the switched mode. The communication method between the storage chip and the security chip is different in multiple modes. Therefore, during the data reading and writing process, the storage device will not obtain the key from the security chip and perform identity authentication in the same mode, which is conducive to achieving a balance between security and convenience. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a flowchart of a data management method according to the first embodiment of the present application;
[0017] Figure 2 is a structural schematic diagram of a storage device provided in an embodiment of the present application;
[0018] Figure 3 yes Figure 2 A schematic structural diagram of an embodiment of a security chip shown;
[0019] Figure 4 yes Figure 2 A schematic structural diagram of a memory chip according to an embodiment of the present invention;
[0020] Figure 5 It is a schematic diagram of a process of mode switching provided by an embodiment of the present application;
[0021] Figure 6 is another schematic diagram of a process for switching modes provided in an embodiment of the present application;
[0022] Figure 7 This is a schematic diagram of a process for performing data backup provided by an embodiment of the present application;
[0023] Figure 8 This is another flowchart of data backup provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] In order to solve the above problems existing in the prior art, the present application provides a storage device and a data management method thereof. These several protection themes are based on the same concept, and the principles of solving the problems are basically the same or similar. The implementation methods of each protection theme can refer to each other, and the repeated parts will not be repeated.
[0025] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly described below in conjunction with specific embodiments and corresponding drawings. Obviously, the embodiments described below are only part of the embodiments of the present application, not all of the embodiments. In the absence of conflict, the following embodiments and their technical features can be combined with each other and also belong to the technical solutions of the present application.
[0026] Figure 1 It is a flow chart of the data management method of the first embodiment of the present application. The data management method can also be referred to as a "method", which is applicable to a storage device, and the execution subject of each step can be a storage device, or a storage medium, processor, controller, etc. with a data management function. The storage device includes a storage chip, a control chip, and a security chip connected to the control chip. The storage device includes but is not limited to an SSD (Solid State Disk or Solid State Drive), a USB flash drive, or an eMMC (embedded Multi Media Card).
[0027] like Figure 1 As shown, the method at least includes the following steps S1 to S4.
[0028] S1: Responding to the query instruction, obtaining the tag information of the security chip and the storage chip;
[0029] S2: Determine whether the tag information of the security chip matches the tag information of the storage chip;
[0030] If the tag information of the security chip does not match the tag information of the storage chip, then S31 is executed: mode switching is prohibited; then the process may return to continue to execute S1 and S2.
[0031] If the tag information of the security chip matches the tag information of the storage chip, then executing S32: in response to the switching instruction, controlling the storage device to switch between multiple modes; and,
[0032] S4: In response to the access instruction, access the memory chip based on the switched mode.
[0033] Combination Figures 2 to 4As shown, the storage device 2 includes a storage chip 21 and a security chip 22. It should be understood that the storage device 2, as a complete storage device, may also include a control chip 20, a cache chip 23 and a first ROM (Read-Only Memory) 24. The control chip 20 may be a chip, that is, the aforementioned control chip connected to the security chip.
[0034] The storage chip 21 includes a storage area 210, a first firmware 211, a second firmware 212, a marking area 213, a first business data storage area 214, and a backup marking area 215. The storage area 210 is used to store data read, written, and backed up by the storage device 2, and is also called an effective storage area; the first business data storage area 214 mainly includes a business data area, a communication data area, and a key data area, wherein the business data area is used to store communication data with the host, the communication data area is used to store communication data between various devices in the storage device 2, and the key data area is used to store data such as keys related to encryption and decryption; the marking area 213 is used to store label information indicating the current state of the storage chip 21.
[0035] The security chip 22 includes a controller 220, a memory 221 and a second ROM 222. The memory 221 includes a TPM (Trusted Platform Module) firmware 223, a second business data storage area 224 and a tag area 225. The structure and function of the second business data storage area 224 are similar to those of the first business data storage area 214. For example, the second business data storage area 224 may also include a business data area, a communication data area and a key data area. The business data area is used to store communication data with the control chip 20, the communication data area is used to store communication data between various devices in the storage device 2, and the key data area is used to store data such as keys related to encryption and decryption; the tag area 225 is used to store label information indicating the current state of the security chip 22.
[0036] In one example, step S1 may read the tag value F1 from the tag area 225 of the security chip 22, and read the tag value F2 from the tag area 213 of the storage chip 21; if the tag values F1 and F2 read from the security chip 22 and the storage chip are the same, step S2 determines a match; if the tag values F1 and F2 read from the security chip 22 and the storage chip 21 are different, step S2 determines a mismatch. In actual scenarios.
[0037] Combination Figure 2 As shown, the storage device 2 can communicate with a host (also called a host end, a host computer), and receive relevant instructions including query instructions and access instructions issued by a user from the host, and execute corresponding steps according to the relevant instructions.
[0038] First, the host powers on the storage device 2. The storage device 2 includes two power supply modes, namely, a first power supply and a second power supply. The first power supply is used to power on the security chip 22 first, and then the second power supply is used to power on the security chip 22. Figure 2 The other devices except the security chip 22 shown in the figure are powered on, and the security chip 22 is used to ensure the security of the data.
[0039] After the security chip 22 is powered on, the controller 220 of the security chip 22 starts up and communicates with the second ROM 222 to execute the startup program in the second ROM 222. The last section of the startup program is a jump instruction, which jumps to the TPM firmware 223 of the memory 221 in the security chip 22 through the bar instruction. The first command of the query instruction executed by the TPM firmware 223 is to query the tag information in the marking area 225 of the security chip 22. For example, if the tag value F1 is the first tag value, it means that the security chip 22 is currently in a blank state; if the tag value F1 is the second tag value, it means that the security chip 22 is currently in an initialized state.
[0040] After the other devices of the storage device 2 are powered on, the security chip 22 is waited to be started up. After the security chip 22 is started up, a startup instruction is sent to the control chip 20 of the storage device 2. The control chip 20 starts the startup program in the first ROM 24. The last section of the startup program is a jump instruction. Through the jump instruction, the jump instruction jumps to the storage chip 21, specifically to the first firmware 211 of the storage chip 21. The first section of the instruction in the first firmware 211 will query the marking area 213 of the storage chip 21 to obtain the label information, and query the label information in the marking area 225 of the security chip 22. For example, if the label value F2 is found to be the first label value, and the label value F1 is found to be the first label value in the marking area 225 of the security chip 22, it means that the storage chip 21 is currently in a normal state, and the first firmware 211 can continue to execute its own driver program (the first mode among multiple modes). If the tag value F2 is found to be the second tag value, and the tag value F1 is found to be the second tag value in the marking area 225 of the security chip 22, it means that the storage chip 21 is currently in a special state and can jump to the second firmware 212 area, and the second firmware 212 executes the relevant driver program (the second mode among multiple modes).
[0041] Before the storage device 2 switches modes, the host needs to first send a query instruction to the storage device 2. The storage device 2 queries the label value from the marking area according to the aforementioned method, and confirms whether the current states of the storage chip 21 and the security chip 22 match through its control chip 20. Alternatively, the storage device 2 can send the acquired label information to the host, and the host confirms whether the current states of the storage chip 21 and the security chip 22 match; wherein the label information represents the current state, and the current state of the storage chip 21 and the current state of the security chip 22 can be regarded as the current state of the storage device 2.
[0042] The storage device 2 may first query the current state of the security chip 21, and then query the current state of the storage chip 21. Of course, the storage device 2 may first query the current state of the storage chip 21, and then query the current state of the security chip 21, which is not limited here. If the tag value F1 of the security chip 22 is the first tag value, it represents a blank state, and the tag value F2 of the storage chip 21 is the first tag value, it represents a normal state. When the tag value F1 of the security chip 22 is the first tag value and the tag value F2 of the storage chip 21 is the first tag value, the storage device 2 determines that it is currently in the first mode. In the first mode, the storage device 2 uses the first key of the storage chip 21 by default.
[0043] If the tag value F1 of the security chip 22 is the second tag value, it represents an initialization state, and the tag value F2 of the storage chip 21 is the second tag value, it represents a special state. When the tag value F1 of the security chip 22 is the second tag value and the tag value F2 of the storage chip 21 is the second tag value, the storage device 2 determines that it is currently in the second mode. The storage device 2 uses the second key by default. When the tag values F1 and F2 are the same, the switching instruction of the storage device 2 to switch modes can be supported.
[0044] If the security chip 22 is currently in a blank state and the storage chip 21 is currently in a special state, or the security chip 22 is currently in an initialized state and the storage chip 21 is currently in a normal state, the storage device 2 considers that both situations are state errors. When any of these situations occurs, it means that the mode switching of the storage device 2 has failed. At this time, the storage device 2 can return an error code to the host and does not support other instructions.
[0045] It can be seen that only when the label values F1 and F2 of the security chip 22 and the storage chip 21 are the same, can the storage device 2 be started normally and support mode switching, which is equivalent to requiring dual authentication of the security chip 22 and the storage chip 21 for mode switching. Therefore, it can more effectively prevent malicious attackers from cracking encrypted data through software means, and the security is higher.
[0046] The first mode and the second mode in the multiple modes can be regarded as two modes with different encryption levels, and the encryption level of the first mode can be lower than that of the second mode. For example, the first mode can be called a normal mode to represent a mode started by the first firmware 211, and the second mode can be called a special mode to represent a mode started by the second firmware 212. Here, the storage device can support dual uses of one disk, that is, support switching the special mode to the normal mode, and switching the normal mode to the special mode.
[0047] Based on the above, when the tag information of the security chip 22 matches that of the storage chip 21, the present application can control the storage device to switch between different modes and access the storage chip 21 based on the switched mode. The communication method between the storage chip 21 and the security chip 22 is different in different modes. During the data reading and writing process, the storage device 2 will not obtain the key from the security chip 22 and perform identity authentication in the same mode, which is conducive to achieving a balance between security and convenience.
[0048] For example, in the first mode, the storage device uses the key of the storage chip by default, which can reduce the signaling interaction with the security chip, reduce the impact on data transmission, and ensure the convenience of data reading and writing; in the second mode, the storage device uses the key of the security chip by default, and the security chip is used to ensure the security of data reading and writing.
[0049] The following describes the implementation process and principle of switching between the first mode and the second mode of the present application.
[0050] The first one: switch from the first mode to the second mode
[0051] Combination Figure 5 As shown, step S32 can be performed as follows:
[0052] S3211: modifying the tag information of the storage chip from the first tag value to the second tag value;
[0053] S3212: Control the security chip to perform identity authentication;
[0054] S3213: After the security chip passes the identity authentication, modify the tag information of the security chip from the first tag value to the second tag value;
[0055] S3214: Control the storage device to power on again;
[0056] S3215: querying, through the first firmware of the storage chip, whether the tag information of the storage chip is a second tag value; and,
[0057] S3216: When it is found that the tag information of the storage chip is the second tag value, the storage chip is controlled to jump to the second firmware, and the storage device is started by the second firmware.
[0058] When it is found that the tag information of the storage chip is the first tag value, the process may return to step S3211 until it is found that the tag information of the storage chip is the second tag value.
[0059] The so-called first label value and the second label value can be understood as a label value of 0 and a label value of 1, respectively. For ease of description, this case takes the first label value of 0 and the second label value of 1 as an example, but this is not a limitation.
[0060] Combination Figures 2 to 4 As shown, after confirming that the current states of the storage chip 21 and the security chip 22 match, the control chip 20 of the storage device 2 modifies the tag value of the tag area 213 of the storage chip 21 from the first tag value (i.e., 0) to the second tag value (i.e., 1), and forwards the command to inform the security chip 22, so that the security chip 22 performs identity authentication. For example, the control chip 20 of the storage device 2 sends a command carrying a signature to the security chip 22, and the signature is used to identify the host communicating with the storage device 2, and then controls the security chip 22 to parse the command to obtain the signature, and verify the signature, that is, decrypt the signature, so as to protect the security of the storage device 2 and prevent the data of the storage device 2 from being maliciously tampered with. In the actual scenario, the command carries a signature based on SM2 (an encryption algorithm) from the host. After receiving the command, the security chip 22 parses the signature to obtain the signature, and then verifies the signature, that is, decrypts the signature. The encryption and decryption process based on SM2 can refer to the prior art in the field, which will not be described here. If the decryption is successful, indicating that the identity authentication is passed, the tag value of the marking area 225 in the security chip 22 is modified from the first tag value (ie, 0) to the second tag value (ie, 1), and then the storage device 2 is powered on again.
[0061] After the security chip 22 completes the startup as described above, the first instruction of the first firmware 211 of the storage chip 21 queries the tag information of the marking area 213. If the current tag value is 1, the first firmware 211 jumps to the second firmware 212, thereby completing the startup of the storage device 2, and the current mode is switched from the first mode to the second mode.
[0062] Second: Switch from the second mode to the first mode
[0063] Combination Figure 6 As shown, step S32 can be performed as follows:
[0064] S3221: modifying the tag information of the storage chip from the second tag value to the first tag value;
[0065] S3222: Control the security chip to perform identity authentication;
[0066] S3223: After the security chip passes the identity authentication, modify the tag information of the security chip from the second tag value to the first tag value;
[0067] S3224: Control the storage device to power on again;
[0068] S3225: querying, through the first firmware of the storage chip, whether the tag information of the storage chip is a first tag value; and,
[0069] S3226: When it is found that the tag information of the storage chip is the first tag value, the storage device is started by the first firmware.
[0070] When it is found that the tag information of the storage chip is the second tag value, the process may return to step S3221 until it is found that the tag information of the storage chip is the first tag value.
[0071] Combination Figures 2 to 4 As shown, after confirming that the current states of the storage chip 21 and the security chip 22 match, the control chip 20 of the storage device 2 changes the tag value of the 213 tag area of the storage chip 21 from 1 to 0, and forwards a command to inform the security chip 22. The command carries a signature based on SM2 from the host. After receiving the command, the security chip 22 parses the signature to obtain the signature, and then verifies the signature, that is, decrypts it. If the decryption is successful, it means that the identity authentication is passed, and the tag value of the tag area 225 is changed from 1 to 0. Subsequently, the storage device 2 is powered on again according to the above principle. At this time, the security chip 22 does not need to be powered on again. After the security chip 22 completes the startup according to the above, the first instruction of the first firmware 211 of the storage chip 21 queries the tag information of the tag area 213. If the current tag value is 0, the first firmware 211 does not jump, and continues to execute the subsequent instructions of the first firmware 211, thereby completing the startup of the storage device 2 and switching from the second mode to the first mode.
[0072] In any of the aforementioned switching situations, during the mode switching process, the storage device does not receive an access instruction from the host, or even if it receives an access instruction from the host, it does not perform an access operation.
[0073] In addition, during the switching process between the first mode and the second mode, the order of modifying the tag value of the storage chip 21 and the tag value of the security chip 22 in the above steps is not specifically limited, and any tag value may be modified first.
[0074] In step S4, accessing the storage chip 21 includes the host issuing a command to the control chip 20 to read data or write data, and the control chip 20 encrypting / decrypting the data to be read or written.
[0075] Example 1: Step S4 may be a step of controlling the chip 20 to encrypt / decrypt data to be read or written after the first mode is switched to the second mode:
[0076] S411: Sending a request for a first key to the security chip;
[0077] S412: Control the security chip to perform identity authentication;
[0078] S413: After the security chip passes the identity authentication, in response to receiving the first key from the security chip and caching the first key, encrypting or decrypting the read or written data using the first key.
[0079] Combination Figures 2 to 4 As shown, in the second mode, the encryption key and decryption key of the data are stored in the second business data storage area 224 of the security chip 22. The host issues a command corresponding to the signature based on SM2, and the storage device 2 forms a request with the signature and sends it to the security chip 22 to obtain the first key. The control chip 20 can decode the command through the NVMe protocol and send the command to the security chip 22 in the form of SPI (Serial Peripheral Interface). After receiving the request, the security chip 22 verifies the signature therein. If the signature verification passes, it means that the identity authentication is passed. The first key stored in the security chip 22 itself is transmitted to the control chip 20, and the control chip 20 temporarily stores the first key in the cache chip 23. Thereafter, the host can send a command to write data to the control chip 20 of the storage device 2 through the NVMe protocol. The control chip 20 receives and parses the command, and then stores the data in the storage area 210 of the storage chip 21 in an encrypted manner using the encryption algorithm of the first key (the encryption algorithm of SM4).
[0080] It should be noted that the first key used for SM4 encryption here comes from the second business data storage area 224 of the security chip 22. Similarly, the host can also send a command to read data to the control chip 20 of the storage device 2 through the NVMe protocol, and the control chip 20 receives and parses the command. The first key is cached in the cache chip 23, and then the data is taken out from the storage area 210 of the storage chip 21 through SM4 decryption. The first key used for the SM4 encryption and decryption is the same key. For the encryption and decryption process based on SM4, please refer to the prior art in the field, which will not be described here.
[0081] In step S413, after receiving the first key, the storage device only caches the first key, for example, in Figure 2In the cache chip 23 shown, the first key is not stored in the storage area 210 of the storage chip 21; in the second mode, in response to the storage device being powered off, the first key is discarded, and in response to the storage device being powered on, the step S411 is performed. That is, in the second mode, the storage device only uses the first key from the security chip and does not store the first key, and the storage device needs to re-acquire the first key each time it is powered on again.
[0082] The above-mentioned Example 1 can be regarded as data reading and writing after the first mode is switched to the second mode.
[0083] Example 2: Step S4 may be a step of controlling the chip 20 to encrypt / decrypt the data to be read or written after the second mode is switched to the first mode:
[0084] The second key is obtained from the storage chip 21 , and the data of the storage chip 21 is encrypted or decrypted by the second key.
[0085] Combination Figures 2 to 4 As shown, the host can send a command to write data to the control chip 20 of the storage device 2 through the NVMe protocol, the control chip 20 receives and parses the command, and then stores the data in the storage area 210 of the storage chip 21 through SM4 encryption. It should be noted that the second key used for SM4 encryption here comes from the first business data storage area 214 of the storage chip 21. Similarly, the host can also send a command to read data to the control chip 20 of the storage device 2 through the NVMe protocol, the control chip 20 receives and parses the command, and then takes the data out of the storage area 210 of the storage chip 21 through the second key and SM4 decryption. The second key used for SM4 encryption and decryption is the same key.
[0086] This example 2 can be regarded as data reading and writing after the second mode is switched to the first mode.
[0087] In step S32, it also includes backing up the data in the valid storage area of the storage chip 21, which is discussed in Example 3 and Example 4.
[0088] Example 3: Combination Figures 5 to 7 As shown, during the process of switching from the first mode to the second mode, the following steps may be performed after step S3213:
[0089] S32131: Obtain a second key from the storage chip, decrypt the ciphertext data of the storage chip into plaintext data using the second key, and write the plaintext data to the source address corresponding to the ciphertext data;
[0090] S32132: modifying the label information of the backup mark area of the storage chip from the third label value to the fourth label value;
[0091] S3214: Control the storage device to power on again;
[0092] S3215: querying whether the tag information of the storage chip is the second tag value through the first firmware of the storage chip; if not, executing the step S3211; if yes, executing step S3216;
[0093] S3216: When it is found that the tag information of the storage chip is the second tag value, control the storage chip to jump to the second firmware, and start the storage device through the second firmware;
[0094] S3217: Checking, by the second firmware, whether the label information of the backup mark area is the fourth label value;
[0095] S3218: If yes, a request for the first key is sent to the security chip, and the security chip is controlled to perform identity authentication; if no, step S32132 may be continued;
[0096] S3219: After the security chip passes the identity authentication, in response to receiving the first key from the security chip, cache the first key;
[0097] S3220: Encrypt the plaintext data using the first key and write it to the source address;
[0098] S3221: Modify the label information of the backup mark area from the fourth label value to the third label value.
[0099] Combination Figures 2 to 4 As shown, after the tag information of the security chip 22 is modified from the first tag value to the second tag value, the control chip 20 of the storage device 2 obtains the second key from the first business data storage area 214 of the storage chip 21, or caches it in the cache chip 23 after obtaining it, and then decrypts the ciphertext data in the storage area 210 into plaintext data through the second key, and writes the source address corresponding to the ciphertext data, which is the address of the ciphertext data in the storage area 210 before the mode is switched (i.e., in the first mode). The storage control chip 20 modifies the tag information of the backup mark area 215 from the third tag value (i.e., 0) to the fourth tag value (i.e., 1). The third tag value indicates that the data backup does not need to be encrypted, and the fourth tag value indicates that the data backup needs to be encrypted. Then the aforementioned steps S3214 to S3216 can be executed, and then the tag information of the backup mark area 215 is checked through the second firmware 212. If it is the fourth tag value, the first key is received from the authenticated security chip 22, and the plaintext data is encrypted with the first key, and finally written to the source address, thereby completing the data backup after this mode switching.
[0100] The so-called third label value and fourth label value can be understood as a label value of 0 and a label value of 1, respectively. For ease of description, this case takes the third label value of 0 and the fourth label value of 1 as an example, but this is not a limitation.
[0101] After the first mode is switched to the second mode and data backup is completed, the data reading and writing of the aforementioned example 1 may continue to be performed.
[0102] Example 4: Combination Figures 6 to 8 As shown, in the process of switching from the second mode to the first mode, the following steps may be performed after step S3223:
[0103] S32231: Sending a request for a first key to the security chip;
[0104] S32232: Control the security chip to perform identity authentication;
[0105] S32233: After the security chip passes the identity authentication, in response to receiving the first key from the security chip and caching the first key, decrypting the ciphertext data of the storage chip into plaintext data by using the first key, and writing the plaintext data into a source address corresponding to the ciphertext data;
[0106] S32234: modifying the label information of the backup mark area of the storage chip from the third label value to the fourth label value;
[0107] S3224: Control the storage device to power on again;
[0108] S3225: querying whether the tag information of the storage chip is the first tag value through the first firmware of the storage chip; if not, executing the step S3221; if yes, executing step S3226;
[0109] S3226: When it is found that the tag information of the storage chip is the first tag value, control the storage chip to jump to the first firmware, and start the storage device through the first firmware;
[0110] S3227: Checking, by the first firmware, whether the label information of the backup mark area is the fourth label value;
[0111] S3228: If yes, send a request for the second key to the storage chip; if no, continue to execute step S32234;
[0112] S3229: In response to receiving the second key from the storage chip, encrypt the plaintext data using the second key and write the data into the source address;
[0113] S3230: Modify the label information of the backup mark area from the fourth label value to the third label value.
[0114] Combination Figures 6 to 8As shown, after the tag information of the security chip 22 is modified from the second tag value to the first tag value, the control chip 20 of the storage device 2 sends a request for the first key to the security chip 22, and controls the security chip 22 to perform identity authentication. After the security chip 22 passes the identity authentication, in response to receiving the first key from the security chip 22 and caching the first key, the ciphertext data of the storage chip 21 is decrypted into plaintext data through the first key, and the source address corresponding to the ciphertext data is written, which is the address of the ciphertext data in the storage area 210 before the mode switching (i.e., in the second mode). The control chip 20 modifies the label information of the backup mark area 215 from the third label value to the fourth label value. The third label value indicates that the data backup does not need to be encrypted, and the fourth label value indicates that the data backup needs to be encrypted. Then the aforementioned steps S3224 to S3226 can be executed, and then the label information of the backup mark area 215 is checked through the first firmware 212. If it is the fourth label value, the control chip 20 of the storage device 2 obtains the second key from the first business data storage area 214 of the storage chip 21, and then encrypts the plaintext data in the storage area 210 into ciphertext data through the second key, and writes the source address corresponding to the plaintext data, thereby completing the data backup after this mode switching.
[0115] After the second mode is switched to the first mode and data backup is completed, the data reading and writing of the aforementioned example 2 may continue to be performed.
[0116] In steps 3221 and S3230, the tag information of the backup mark area 215 is modified from the fourth tag value to the third tag value, that is, the tag information is restored to the data backup without encryption after each backup, so as to facilitate the backup in the subsequent mode switching scenario or the backup in the mode not switching scenario.
[0117] It should be noted that the embodiments of the present application include multiple situations and multiple feasible implementation methods for a certain technical feature. Unless otherwise specified, they all mean that the corresponding technical feature can be implemented by adapting the combined settings. For example, the aforementioned mode switching, data backup in the effective storage area, and the implementation method of data reading and writing after switching modes can be combined to achieve access to the storage chip. Through the combination scheme, the corresponding technical features can be implemented more accurately and / or intelligently, thereby improving the accuracy of the implementation of the technical features and the user experience.
[0118] During the switching process between the first mode and the second mode, the data format of the effective storage area 210 in the storage chip 21 includes:
[0119] Step S3213: after the security chip 22 passes identity authentication, the tag information of the security chip 22 is modified from the first tag value to the second tag value.
[0120] S3223: After the security chip 22 passes the identity authentication, the tag information of the security chip 22 is modified from the second tag value to the first tag.
[0121] After step S3213 and step S3223, the control chip 20 which also includes the storage device 2 may format the storage area 210 of the storage chip 21, and then execute the steps corresponding to those after step S3213 and step S3223.
[0122] In the process of switching between the first mode and the second mode, re-powering the storage device 2 includes: re-powering the storage device 2 in step S3214 and step S3224, and the so-called re-powering can be understood as re-powering on other devices except the security chip 22, and the security chip 22 does not need to be re-powered. In the actual scenario, the storage device 2 can be provided with a first power supply and a second power supply, the first power supply is used to power the security chip 22, and the second power supply is used to power the devices except the security chip 22. Based on this, after responding to the switching instruction, the present application can control the first power supply of the storage device 2 to keep powering the security chip 22 and the second power supply to stop powering the devices except the security chip 22. Correspondingly, after re-powering, the second power supply is controlled to re-power the devices except the security chip 22. By setting the first power supply and the second power supply, the security chip 22 keeps powering during the re-powering process, which can improve the restart efficiency, and ensure the security of the data of the storage chip 21, and avoid malicious attacks during the re-powering process.
[0123] The embodiments of the present application also provide a controller that can run the method of any of the above embodiments to manage data in the storage device, so as to achieve a balance between security and convenience in the process of reading and writing data. Relevant descriptions can be found in the above embodiments and will not be repeated here.
[0124] The embodiment of the present application also provides a storage device, for example, the storage device may include a host interface and a controller; of course, it may also include a storage module, and the storage module and the controller may be connected via a storage interface. The host interface is used to connect to an external host (such as the host of the aforementioned method embodiment) to receive various requests and instructions from the external host; the controller is used to execute the steps of the data management method of any of the aforementioned embodiments, so as to achieve mode switching and access. For the specific principles, processes and beneficial effects, please refer to the above embodiments, which will not be repeated here.
[0125] The embodiment of the present application also provides another storage device, including a storage chip, a control chip, and a security chip connected to the control chip.
[0126] The control chip is used to obtain the tag information of the security chip and the storage chip in response to the query instruction, and to determine whether the tag information of the security chip and the storage chip matches;
[0127] If they do not match, the storage device is prohibited from switching modes;
[0128] If they match, in response to the switch instruction, the storage device is controlled to switch between multiple modes; and in response to the access instruction, the storage chip is accessed based on the switched mode.
[0129] In the example of determining whether the tag information of the security chip matches the tag information of the storage chip, the security chip and the storage chip are respectively provided with a tag area for storing corresponding tag values; the control chip reads the tag values from the tag areas of the security chip and the storage chip respectively, and determines whether the tag values of the two are the same. If they are the same, it is determined to be a match; if they are different, it is determined to be a mismatch.
[0130] In one example, the storage chip is provided with a second firmware;
[0131] The storage chip is used to modify its own label information from a first label value to a second label value;
[0132] The security chip is used to perform identity authentication, and after passing the identity authentication, changes its own tag information from the first tag value to the second tag value;
[0133] After the storage device is powered on again, the first firmware is used to query whether the tag information of the storage chip is the second tag value, and when the tag information is found to be the second tag value, jump to the second firmware to start the storage device through the second firmware.
[0134] In one example, the storage device further includes a cache chip, and the control chip is further configured to send a request for the first key to the security chip;
[0135] The security chip is used to perform identity authentication after receiving the request, and send a first key to the control chip after passing the identity authentication;
[0136] The control chip is used to receive the first key sent by the security chip and cache the first key in the cache chip; the storage chip is used to encrypt or decrypt data read or written by the control chip using the first key.
[0137] In one example, the storage device further includes a cache chip, the control chip is further used to obtain a second key of the storage chip, the storage chip is used to decrypt its own ciphertext data into plaintext data by using the second key, and write the source address corresponding to the ciphertext data; the storage chip is further used to modify the label information of its own backup mark area from the third label value to the fourth label value;
[0138] The second firmware is used to check whether the label information of the backup mark area is the fourth label value;
[0139] If so, the control chip is further used to send a first key request to the security chip, and the security chip is used to perform identity authentication after receiving the request, and after passing the identity authentication, send the first key to the control chip; the control chip is also used to receive the first key from the security chip, and cache the first key to the cache chip;
[0140] The storage chip is also used to encrypt its own plaintext data using the first key and write the data into the source address; the storage chip is also used to modify the label information of the backup mark area from the fourth label value to the third label value.
[0141] In one example, the storage chip is provided with a first firmware;
[0142] The storage chip is used to modify its own label information from the second label value to the first label value;
[0143] The security chip is used to perform identity authentication, and after passing the identity authentication, changes its own tag information from the second tag value to the first tag value;
[0144] After the storage device is powered on again, the first firmware is used to query whether the tag information of the storage chip is the first tag value, and when the tag information is found to be the first tag value, jump to the first firmware to start the storage device through the first firmware.
[0145] In one example, the storage chip is further used to encrypt or decrypt data read or written by the control chip using a second key.
[0146] In one example, the storage device further includes a cache chip, the control chip is further used to send a request for the first key to the security chip, the security chip is used to perform identity authentication after receiving the request, and send the first key to the control chip after passing the identity authentication;
[0147] The control chip is further used to receive the first key from the security chip and cache the first key to the cache chip; the storage chip is further used to decrypt its own ciphertext data into plaintext data by using the first key and write the source address corresponding to the ciphertext data; the storage chip is further used to modify the label information of its own backup mark area from the third label value to the fourth label value;
[0148] The first firmware checks whether the label information of the backup mark area is the fourth label value;
[0149] If so, the control chip is also used to send a request for a second key to the storage chip, and the storage chip encrypts the plaintext data using the second key and writes it into the source address; the storage chip is also used to modify the label information of the backup mark area from the fourth label value to the third label value.
[0150] In one example, the storage device further includes a first power supply and a second power supply; the storage device controls the first power supply to keep supplying power to the security chip and the second power supply to stop supplying power to devices other than the security chip;
[0151] The storage device controls the second power supply to re-supply devices other than the security chip.
[0152] The structure of the storage device of this embodiment can refer to the aforementioned Figure 2 The storage device 2 shown is used to execute the steps of the data management method of any of the above embodiments to achieve mode switching and access. The specific principles, processes and beneficial effects can be found in the above embodiments and will not be repeated here.
[0153] It should be understood that the storage device and controller provided in the embodiments of the present application are complete devices respectively, and also have the structure of corresponding known devices. Here, only the components related to data management (also known as storage management) in the device are described, and other components are not repeated.
[0154] The above are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. For ordinary technicians in this field, all equivalent structural changes made using the contents of this specification and drawings are also included in the patent protection scope of the present application.
[0155] This document uses step codes such as S1, S2, etc., the purpose of which is to express the corresponding content more clearly and concisely, and does not constitute a substantial limitation on the order. When implementing the step, a person skilled in the art may execute S31 first and then S1, etc., but these should all be within the scope of protection of this application.
[0156] Although the terms "first, second", etc. are used herein to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. In addition, the singular forms "one", "an", and "the" are intended to include plural forms as well. The terms "or" and "and / or" are interpreted as inclusive, or mean any one or any combination. Only when the combination of elements, functions, steps, or operations is inherently mutually exclusive in some way, an exception to this definition will occur.
Claims
1. A data management method for a storage device, characterized in that: The storage device includes a storage chip, a control chip, and a security chip connected to the control chip, and the method includes: In response to the query instruction, obtaining label information of the security chip and the storage chip; Determining whether the tag information of the security chip matches the tag information of the storage chip; If they do not match, mode switching is prohibited; If they match, then in response to the switching instruction, controlling the storage device to switch between multiple modes; and, In response to the access instruction, the memory chip is accessed based on the switched mode.
2. The data management method according to claim 1, characterized in that: The step of obtaining label information of the security chip and the storage chip includes: Reading a tag value from the tag area of the security chip; Reading a tag value from the tag area of the memory chip; The determining whether the tag information of the security chip matches the tag information of the storage chip includes: If the tag values read from the security chip and the storage chip are the same, a match is determined; If the tag values read from the security chip and the storage chip are different, a mismatch is determined.
3. The data management method according to claim 1, characterized in that: The control storage device switches between multiple modes, including: Modify the tag information of the storage chip from a first tag value to a second tag value; Controlling the security chip to perform identity authentication; After the security chip passes identity authentication, modifying the tag information of the security chip from the first tag value to the second tag value; Controlling the storage device to power on again; querying, through the first firmware of the storage chip, whether the tag information of the storage chip is the second tag value; When it is found that the tag information of the storage chip is the second tag value, the storage chip is controlled to jump to the second firmware, and the storage device is started by the second firmware.
4. The data management method according to claim 3, characterized in that: The accessing the storage chip based on the switched mode includes: Sending a request for a first key to the security chip, and controlling the security chip to perform identity authentication; After the security chip passes identity authentication, in response to receiving the first key from the security chip and caching the first key, the read or written data is encrypted or decrypted using the first key.
5. The data management method according to claim 3, characterized in that: The control storage device switches between multiple modes, including: Obtaining a second key from the storage chip, decrypting the ciphertext data of the storage chip into plaintext data using the second key, and writing the plaintext data to a source address corresponding to the ciphertext data; Modify the label information of the backup mark area of the storage chip from the third label value to the fourth label value; Checking, by the second firmware, whether the label information of the backup marking area is a fourth label value; If yes, sending a request for the first key to the security chip, and controlling the security chip to perform identity authentication; After the security chip passes identity authentication, in response to receiving the first key from the security chip, cache the first key; Encrypting the plaintext data using the first key and writing the data into the source address; The label information of the backup mark area is modified from the fourth label value to the third label value.
6. The data management method according to claim 1, characterized in that: Controls the storage device to switch between multiple modes, including: Modify the tag information of the storage chip from the second tag value to the first tag value; Controlling the security chip to perform identity authentication; After the security chip passes identity authentication, modifying the tag information of the security chip from the second tag value to the first tag value; Controlling the storage device to power on again; querying, through the first firmware of the storage chip, whether the tag information of the storage chip is a first tag value; When it is found that the tag information of the storage chip is the first tag value, the storage device is started by using the first firmware.
7. The data management method according to claim 6, characterized in that: The accessing the storage chip based on the switched mode includes: A second key is obtained from the storage chip, and the read or written data is encrypted or decrypted using the second key.
8. The data management method according to claim 6, characterized in that: Controls the storage device to switch between multiple modes, including: Sending a request for a first key to the security chip, and controlling the security chip to perform identity authentication; After the security chip passes the identity authentication, in response to receiving the first key from the security chip and caching the first key, decrypting the ciphertext data of the storage chip into plaintext data by using the first key, and writing the data into a source address corresponding to the ciphertext data; Modify the label information of the backup mark area of the storage chip from the third label value to the fourth label value; Checking, by the first firmware, whether the label information of the backup marking area is a fourth label value; If yes, sending a request for a second key to the storage chip; In response to receiving the second key from the storage chip, encrypting the plaintext data by using the second key and writing the data into the source address; The label information of the backup mark area is modified from the fourth label value to the third label value.
9. The data management method according to claim 3 or 6, characterized in that: Controlling the storage device to switch between multiple modes also includes: The storage area of the storage chip is formatted.
10. The data management method according to claim 3 or 6, characterized in that: The controlling the storage device to power on again includes: Control the first power supply of the storage device to keep supplying power to the security chip, and the second power supply to stop supplying power to devices other than the security chip; The second power supply is controlled to re-supply power to devices other than the security chip.
11. A storage device, characterized in that: It includes a storage chip, a control chip and a security chip connected to the control chip; The control chip is used to obtain the tag information of the security chip and the storage chip in response to the query instruction, and to determine whether the tag information of the security chip and the storage chip matches; If they do not match, mode switching is prohibited; If they match, in response to the switch instruction, controlling the storage device to switch between the plurality of modes; And, in response to the access instruction, accessing the memory chip based on the switched mode.
12. The storage device according to claim 11, characterized in that: The storage chip is provided with a second firmware; The storage chip is used to modify its own label information from a first label value to a second label value; The security chip is used to perform identity authentication, and after passing the identity authentication, changes its own tag information from the first tag value to the second tag value; After the storage device is powered on again, the first firmware is used to query whether the tag information of the storage chip is the second tag value, and when the tag information is found to be the second tag value, jump to the second firmware to start the storage device through the second firmware.
13. The storage device according to claim 12, characterized in that: The storage device further includes a cache chip, and the control chip is further configured to send a request for a first key to the security chip; The security chip is used to perform identity authentication after receiving the request, and send a first key to the control chip after passing the identity authentication; The control chip is used to receive the first key sent by the security chip, and cache the first key in the cache chip; The storage chip is used to encrypt or decrypt data read or written by the control chip using the first key.
14. The storage device according to claim 12, characterized in that: The storage device further includes a cache chip, the control chip is further used to obtain a second key of the storage chip, and the storage chip is used to decrypt its own ciphertext data into plaintext data by using the second key, and write the ciphertext data into a source address corresponding to the source address; The storage chip is also used to modify the label information of its own backup mark area from the third label value to the fourth label value; The second firmware is used to check whether the label information of the backup mark area is the fourth label value; If so, the control chip is further used to send a first key request to the security chip, and the security chip is used to perform identity authentication after receiving the request, and after passing the identity authentication, send the first key to the control chip; the control chip is also used to receive the first key from the security chip, and cache the first key to the cache chip; The storage chip is also used to encrypt its own plaintext data using the first key and write the data into the source address; the storage chip is also used to modify the label information of the backup mark area from the fourth label value to the third label value.
15. The storage device according to claim 11, characterized in that: The storage chip is provided with a first firmware; The storage chip is used to modify its own label information from the second label value to the first label value; The security chip is used to perform identity authentication, and after passing the identity authentication, changes its own tag information from the second tag value to the first tag value; After the storage device is powered on again, the first firmware is used to query whether the tag information of the storage chip is the first tag value, and when the tag information is found to be the first tag value, jump to the first firmware to start the storage device through the first firmware.
16. The storage device according to claim 15, characterized in that: The storage chip is also used to encrypt or decrypt data read or written by the control chip using a second key.
17. The storage device according to claim 15, characterized in that: The storage device further includes a cache chip, the control chip is further used to send a request for the first key to the security chip, the security chip is used to perform identity authentication after receiving the request, and send the first key to the control chip after passing the identity authentication; The control chip is further used to receive the first key from the security chip and cache the first key to the cache chip; the storage chip is further used to decrypt its own ciphertext data into plaintext data by using the first key and write the source address corresponding to the ciphertext data; the storage chip is further used to modify the label information of its own backup mark area from the third label value to the fourth label value; The first firmware checks whether the label information of the backup mark area is the fourth label value; If so, the control chip is also used to send a request for a second key to the storage chip, and the storage chip encrypts the plaintext data using the second key and writes it into the source address; the storage chip is also used to modify the label information of the backup mark area from the fourth label value to the third label value.
18. The storage device according to claim 12 or 15, characterized in that: The storage device further comprises a first power supply and a second power supply; the storage device controls the first power supply to keep supplying power to the security chip and the second power supply to stop supplying power to devices other than the security chip; The storage device controls the second power supply to re-supply devices other than the security chip.
Citation Information
Cited By
Storage device and data management method thereof
WO2026148958A1