Data security storage method and security storage system based on QNX system
By adopting a data security storage method based on QNX system in the automotive intelligent cockpit system, the problem of data storage security is solved, data integrity and confidentiality are achieved, and the security and flexibility of the system are improved.
Patent Information
- Application Number
- CN202510085099.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
AI Technical Summary
How to improve the security of data storage in the smart cockpit system of the car, prevent users from leaking private information and tampering with driving data, and ensure the accuracy of driving mileage.
The data security storage method based on the QNX system is adopted, and the application request is received through the storage service module, a unique client identification is allocated, and the preset security verification is performed, and the data to be stored is stored in the RPMB storage area or file system storage area in the QNX system in the form of a key-value pair.
Through a preset security verification mechanism, we ensure that the data storage complies with security specifications, prevent illegal storage requests, ensure the integrity and confidentiality of the data, and improve the security and flexibility of the system.
Smart Images

Figure CN119989436A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of automobile intelligent cockpits, and in particular to a data security storage method and a security storage system based on a QNX system. Background Art
[0002] As cars become more intelligent, the amount of data generated during use is increasing. The security of this data is extremely important. If it is not properly stored, it may lead to the leakage of user private information, tampering of driving data, and even affect the accuracy of driving mileage, causing serious losses to users.
[0003] Therefore, how to improve the security of data storage in the car's smart cockpit system has become a problem that needs to be solved. Summary of the invention
[0004] In view of this, the present disclosure provides a data security storage method and a security storage system based on the QNX system to solve the problem of how to improve the security of data storage in the automobile intelligent cockpit system.
[0005] On the one hand, the present disclosure provides a data security storage method based on a QNX system, which is applied to a secure storage system. The secure storage system includes: a storage service module and a data storage module. The method includes: the storage service module receives request information sent by an application, and based on the request information, allocates a unique corresponding client identifier to the application; the request information includes at least: a storage identifier, data to be stored, a data type, and a security level identifier; the storage service module establishes a corresponding relationship between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module; the data storage module stores the data to be stored and the data type in the form of key-value pairs in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
[0006] On the other hand, the present disclosure further provides a secure storage system, which includes a storage service module and a data storage module, wherein: the storage service module is used to receive request information sent by an application, and based on the request information, allocates a unique corresponding client identifier to the application; the request information at least includes: a storage identifier, data to be stored, a data type, and a security level identifier; the storage service module is used to establish a corresponding relationship between the storage identifier and the client identifier, perform a preset security check on the request information, and when the result of the preset security check is passed, distribute the data to be stored and the data type to the data storage module; the data storage module is used to store the data to be stored and the data type in the form of key-value pairs in the QNX system. Storage area or file system storage area.
[0007] On the other hand, the present disclosure further provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to enable a computer to implement the above-mentioned QNX system-based data security storage method.
[0008] On the other hand, the present disclosure further provides a computer program product, including computer instructions, where the computer instructions are used to enable a computer to execute the above-mentioned QNX system-based data security storage method.
[0009] Through the data security storage method and security storage system based on the QNX system of the above embodiment of the present disclosure, a preset security verification mechanism is used to ensure that the application complies with security specifications when storing data, prevent illegal storage requests, and ensure the integrity and confidentiality of the data. The storage service module allocates a unique client identifier based on the application's request information, and uniformly manages the corresponding relationship between the storage identifier and the client identifier to ensure that the data storage and reading operations of each application can be correctly processed and verified. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the related technologies, the drawings required for use in the specific embodiments or the related technical descriptions will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0011] Figure 1a An exemplary schematic diagram showing the architecture of a secure storage system applied to a QNX system-based data secure storage method according to an embodiment of the present disclosure;
[0012] Figure 1b It is a flowchart of a data security storage method based on a QNX system provided by an embodiment of the present disclosure;
[0013] Figure 2 An exemplary schematic diagram showing the architecture of another secure storage system applied by a QNX system-based data secure storage method according to an embodiment of the present disclosure;
[0014] Figure 3 is a structural diagram of another secure storage system provided by an embodiment of the present disclosure;
[0015] Figure 4 It is a structural diagram of another secure storage system provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0016] With the continuous development of automobile intelligent technology, modern cars not only have traditional driving functions, but also gradually add a variety of intelligent functions such as automatic driving, intelligent navigation, in-vehicle entertainment systems, and remote monitoring. The realization of these functions requires a large amount of data support. The security of this data is extremely important, often involving personal privacy (such as user location information, driving trajectory, etc.), driving safety (such as automatic driving data, vehicle status monitoring data, etc.) and commercial secrets (such as car owners' consumption habits, automobile manufacturers' technical data, etc.). If this data is not effectively protected, once it is leaked or tampered with, it may pose a serious threat to the user's personal privacy and even affect public safety.
[0017] To solve the above problems, various embodiments of the present disclosure provide a data security storage method based on a QNX system, which is applied to a secure storage system. The secure storage system includes: a storage service module and a data storage module. The method includes: the storage service module receives the request information sent by the application, and based on the request information, allocates a unique corresponding client identifier to the application; the request information includes at least: a storage identifier, data to be stored, a data type, and a security level identifier; the storage service module establishes a correspondence between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module; the data storage module stores the data to be stored and the data type in the form of key-value pairs in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.
[0019] Please refer to Figure 1a , Figure 1a An exemplary schematic diagram of the architecture of a secure storage system used in a data secure storage method based on a QNX system according to an embodiment of the present disclosure is shown. Figure 1a As shown, the secure storage system may include: a storage service module and a data storage module.
[0020] like Figure 1a As shown, the secure storage system can realize the complete process from data request reception, verification to final secure storage through the collaboration of the storage service module and the data storage module.
[0021] The storage service module may be the control core in the secure storage system, and may be used for request management and verification, data distribution, and client management. The data storage module may be the execution unit in the secure storage system, and is responsible for specific data storage operations.
[0022] In a possible implementation, the secure storage system may be a system using a client / server (C / S) architecture in a QNX system, wherein the storage service module and the data storage module are servers, and at least one application is a client.
[0023] Furthermore, the storage service module may be a process in the QNX system, used to receive request information sent by at least one application process of the client.
[0024] Further references Figure 1b , Figure 1b is a flow chart of a data security storage method based on a QNX system provided by an embodiment of the present disclosure, which is applied to the above Figure 1a The secure storage system shown in the figure may include the following steps:
[0025] Step S101: The storage service module receives request information sent by an application, and allocates a unique corresponding client identifier to the application based on the request information.
[0026] In this embodiment, the request information includes at least: a storage identifier, data to be stored, a data type, and a security level identifier.
[0027] Here, the storage identifier (storage_id) can be used to uniquely identify a storage requirement of an application, and can indicate the type of data stored by the application and the location to be stored. The data to be stored can indicate the data content that the application wants to write into the storage area, and can be a specific data entity. The data type can be used to describe the format or structure of the data to be stored. The security level identifier can be used to indicate the security requirements of the data to be stored.
[0028] The storage service module creates a resource manager in the QNX system, and the resource manager is equipped with at least one preset function interface.
[0029] Here, the resource manager may be a service process running on the microkernel of the QNX system, and may be used to manage access and operation of specific resources through a standardized preset functional interface, wherein the specific resource may refer to an application process.
[0030] In a possible implementation, the storage service module receives the request information sent by the application, and allocates a unique corresponding client identifier to the application based on the request information, which may include:
[0031] The storage service module monitors the registration interface in the preset function interface of the resource manager and waits for registration request information sent by at least one application through the function type interface;
[0032] The storage service module parses the registration request information and assigns a unique client identifier (client_id) to each newly registered application process.
[0033] Step S102, the storage service module establishes a corresponding relationship between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module.
[0034] In this embodiment, the storage service module establishes a correspondence between the client identifier and the storage identifier in the request information, so as to uniformly manage at least one storage requirement under the application based on the client identifier.
[0035] Here, the client identifier is used to manage the interaction relationship between the application and the storage service module.
[0036] As an example, the storage service module receives the request information sent by application A, parses the request information, determines that the storage identifier of application A is "sensor_data", assigns the client identifier "client_001" to application A, uniquely corresponds "client_001" to "sensor_data", and stores the corresponding relationship between "client_001" and "sensor_data". The storage service module can determine the storage identifier "sensor_data" corresponding to "client_001" by searching the client identifier "client_001" within the process, and then determine the relevant storage data of application A.
[0037] Furthermore, the storage service module performs a preset security check on the request information, which may include: the storage service module gradually checks each content in the request information to ensure the storage security of the data.
[0038] The storage service module distributes the data to be stored and the data type to the data storage module, which may include:
[0039] The storage service module packages the data to be stored and the data type into key-value pairs, and passes the key-value pairs and the corresponding storage location information to the data storage module.
[0040] For example, a key-value pair might be stored as "speed:100".
[0041] Step S103: The data storage module stores the data to be stored and the data type in the form of key-value pairs in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
[0042] In this embodiment, when the data storage module determines that the security level of the data to be stored is identified as 1, the key-value pair of the data to be stored is stored in the RPMB storage area in the QNX system; when the data storage module determines that the security level of the data to be stored is identified as 0, the key-value pair of the data to be stored is stored in the file system storage area in the QNX system.
[0043] Among them, the security level mark of the data to be stored being 1 can indicate that the security storage requirement of the data to be stored is relatively high; the security level mark of the data to be stored being 0 can indicate that the security storage requirement of the data to be stored is relatively low.
[0044] The replay protected memory block (RPMB) has the characteristics of anti-tampering and anti-replay attack, and can only be accessed by interfaces or programs with specific permissions, so it can be used to store data to be stored with relatively high security storage requirements. The file system storage area may refer to a storage area provided by a file system based on the QNX system, which is accessed through a standard file system interface (such as file read and write operations), so it can be used to store data to be stored with relatively low security storage requirements.
[0045] In one embodiment, the data storage module stores the data to be stored and the data type in the form of key-value pairs in the RPMB storage area or the file system storage area in the QNX system according to the security level identification, based on the following steps:
[0046] The data storage module parses the security level identifier, and when it is determined that the security level identifier is the first preset value, uses the storage identifier as a name in the RPMB storage area, creates a corresponding storage file for the application, and stores a key-value pair of the data to be stored and the data type in the storage file in the RPMB storage area;
[0047] The data storage module, when determining that the security level identifier is a second preset value, uses the storage identifier as a name in the file system storage area, creates a corresponding storage file for the application, and stores the key value in the storage file in the file system storage area.
[0048] Here, the first preset value is 1, and the second preset value is 0.
[0049] In the data security storage method and security storage system based on the QNX system of the above embodiment of the present disclosure, a preset security verification mechanism is used to ensure that the application complies with security specifications when storing data, prevent illegal storage requests, and ensure the integrity and confidentiality of the data. The storage service module allocates a unique client identifier according to the application's request information, and uniformly manages the corresponding relationship between the storage identifier and the client identifier to ensure that the data storage and reading operations of each application can be correctly processed and verified.
[0050] In a possible implementation of the above step S101, the storage service module receives the request information sent by the application and allocates a unique corresponding client identifier to the application, including:
[0051] The storage service module registers the storage service node and provides a preset function interface to the application based on the storage service node; the preset function interface includes at least: write function and registration function;
[0052] The storage service module receives the request information sent by the application, the request information also includes the process identifier and connection identifier of the application; the request information is determined by the application calling the preset function interface;
[0053] The storage service module allocates a unique corresponding client identifier to the application when receiving the registration request information of the application.
[0054] In this embodiment, the storage service module registers the storage service node and provides a preset function interface to the application based on the storage service node, which may include:
[0055] The storage service module creates a storage service node during the initialization process as an identifier of the storage service module; the storage service module exposes at least one preset functional interface to the outside world through the storage service node.
[0056] As an example, the storage service node may be dev / storage_service, and other applications may establish a connection with the storage service module by opening the storage service node.
[0057] Furthermore, the storage service module defines and implements at least one preset function interface through the resource manager. The preset function interface may include but is not limited to: a read function, a write function, and a registration function.
[0058] In a possible implementation, when the request information received is a read request information, the storage service module reads relevant data from the data storage module, verifies whether the application's request is legal, and returns relevant data. When the request information received is a write request information, the storage service module verifies the application's write request, determines the corresponding permissions, and then stores the data in the storage area specified in the data storage module. When the request information received is a registration request information, the storage service module assigns a unique client identifier to the application and associates the client identifier with the storage identifier.
[0059] The storage service module receives the request information sent by the application, which may include:
[0060] The storage service module receives the request information sent by the application and obtains the storage identifier, data to be stored, data type, security level identifier, process identifier and connection identifier in the request information.
[0061] The process identifier (pid) can represent the unique identifier of the application process that sends the request, and can be used to determine which application process the request information comes from. The connection identifier (coid) can represent the unique identifier of the communication session between the application and the storage service, and can be used to determine whether the communication session is valid and legal.
[0062] Here, the process identifier can be an identifier assigned by the QNX system when the application process is started, which is used to uniquely identify a process. The connection identifier can be an identifier assigned by the QNX system when the application process calls a preset function interface for inter-process communication, and the connection identifier remains valid during the communication until the connection is disconnected.
[0063] In the data security storage method and security storage system based on the QNX system of the above-mentioned embodiment of the present disclosure, by assigning a unique client identifier to each application, the storage service module can achieve unified management of different applications. The request of each application can be associated with its unique client identifier, thereby ensuring that data storage requests between applications will not be confused or misused. By registering storage service nodes and providing preset functional interfaces to applications, the storage service module can flexibly provide data storage functions. These interfaces allow applications to select different operation types, such as data writing or registration processes, which enhances the flexibility of the system. Through the unique mapping relationship between the client identifier and the storage identifier, the storage service module ensures that the data storage between different applications does not interfere with each other, and ensures the isolation of each application's data from other application data.
[0064] In a possible implementation of the above step S102, the storage service module establishes a corresponding relationship between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module based on the following steps:
[0065] The storage service module matches the client identifier with the storage identifier in the request information, so that the storage service module uniformly manages the request information of the application based on the client identifier;
[0066] The storage service module performs a first check on the process identifier in the request information to determine whether the process identifier is valid and registered;
[0067] The storage service module performs a second check on the connection identifier in the request information to determine whether the connection with the application is legal;
[0068] The storage service module performs a third check based on the storage identifier and the security level identifier in the request information to determine whether the application has the authority to perform the storage operation corresponding to the security level identifier;
[0069] The storage service module determines the storage location of the data to be stored in the request information when the verification results of the first verification, the second verification and the third verification are all passed, and distributes the data to be stored, the storage location and the data type to the data storage module.
[0070] In this embodiment, the storage service module performs a first check on the process identifier in the request information to determine whether the process identifier is valid and registered, which may include:
[0071] The storage service module checks the status of the application process to determine whether the application process is accessible and legal; if the application process is accessible and legal, the application process is determined to be valid;
[0072] The storage service module determines whether the process identifier has been registered based on a mapping table of the process identifier and the client identifier; when the process identifier is in the mapping table, it is determined that the application process has been registered.
[0073] Here, when the process identifier is valid and registered, the storage service module continues to perform subsequent operations; when the process identifier is invalid or unregistered, the storage service module rejects the request and returns an error message to the requesting application. For example, the error message may include "invalid process identifier" or "process unregistered".
[0074] The storage service module performs a second check on the connection identifier in the request information to determine whether the connection with the application is legal, which may include:
[0075] The storage service module queries the internal connection management table to determine whether the connection identifier corresponds to a successfully established connection and whether the communication connection is still in an open state; when the conditions are met, the validity of the connection identifier is determined;
[0076] The storage service module checks whether the connection identifier matches the previously registered client identifier to determine the legitimacy of the connection identifier.
[0077] Here, when the connection identifier is valid and legal, the storage service module continues to perform subsequent storage operations; when the connection identifier is invalid or illegal, the storage service module rejects the request information and returns an error message to the application, prompting the application that the connection is illegal.
[0078] The storage service module performs a third check based on the storage identifier and the security level identifier in the request information to determine whether the application has the authority to perform the storage operation corresponding to the security level identifier, which may include:
[0079] The storage service module will query the application whether it has the authority to perform storage operations at that security level based on the application's client ID and security level ID.
[0080] Here, if the application has the required permissions, the storage service module continues to process the request and sends the data storage operation to the data storage module; if the application does not have permissions, the storage service module rejects the request and returns an error message of insufficient permissions or no access to the application.
[0081] The storage service module, when the verification results of the first verification, the second verification and the third verification are all passed, determines the storage location of the data to be stored in the request information, and distributes the data to be stored, the storage location and the data type to the data storage module, which may include:
[0082] The storage service module, when the verification results of the first verification, the second verification and the third verification are all passed, determines the storage area of the data in the QNX system according to the storage identification and the security level identification; according to the preset storage strategy, determines the specific corresponding logical locations of different types of request data in the storage area, and distributes the data to be stored, the storage location and the data type to the data storage module.
[0083] In the data security storage method and security storage system based on the QNX system of the above-mentioned embodiment of the present disclosure, through the preset security verification mechanism, the storage service module can ensure that only legal and authorized application processes can initiate storage requests, effectively avoiding the interference of unauthorized applications or malicious processes with storage operations, thereby improving the security of the system. The system can flexibly allocate the data to be stored to the appropriate storage location according to the difference between the storage identifier and the security level identifier. This allows the system to adopt different storage strategies according to different security requirements, improving the flexibility and scalability of the system. After the verification is passed, the storage service module can determine the storage location of the data based on the storage identifier and the security level identifier, and accurately distribute the data and data type to the data storage module. The automation of this process ensures the accurate storage of data while avoiding the possibility of manual intervention or erroneous operation.
[0084] In a possible implementation of the above embodiment, the method further includes:
[0085] The storage service module continuously monitors the registered applications. When it is determined that an application has exited based on the preset system pulse, the exited application is determined according to the connection identifier contained in the preset system pulse, and preset data processing is performed on the exited application. The preset data processing is used to protect the data of the exited application.
[0086] The storage service module, in the case of exit, receives a reconnection request from the application and re-establishes a connection relationship with the application based on the reconnection request; the data contained in the reconnection request is the same as the data in the registration request information.
[0087] In this embodiment, the preset system pulse may refer to a system pulse sent by the QNX system kernel to the storage service module when the application is disconnected.
[0088] Specifically, when the storage service module receives a system pulse with a value of _PULSE_CODE_COIDDEATH, it can be determined that there is a disconnected application at this time. The connection identifier pulse.value.sival_int included in the preset system pulse can refer to the connection identifier of the disconnected application.
[0089] Further, determining the exited application according to the connection identifier included in the preset system pulse and performing preset data processing on the exited application may include:
[0090] The storage service module, when the disconnected application has unprocessed data to be stored, gives priority to ensuring that the data to be stored is not lost, and saves the data to be stored according to the client identifier and storage identifier of the application;
[0091] The storage service module searches for storage operation records associated with the connection identifier of the disconnected application to ensure that the above records have been processed and saved;
[0092] The storage service module deletes the client identifier associated with the connection identifier, updates the internal data structure, clears the association between the storage identifier and the client identifier, and releases other storage resources related to the application.
[0093] In a possible implementation, the application process also monitors the status of the storage service module. After the storage service module exits, the application process attempts to re-initiate a connection to the storage service module.
[0094] The storage service module receives the reconnection request of the application process again, re-establishes the connection relationship with the application based on the reconnection request, and re-updates the relationship between the process identifier and the storage identifier for subsequent reading and verification.
[0095] In a possible implementation, the method may further include:
[0096] The storage service module uniformly processes system sleep and wake-up requests. After receiving the sleep signal, it checks whether any application is performing memory read and write operations.
[0097] The storage service module, when determining that an application is executing a read or write request, monitors the currently executing application request, obtains the process identifier or request identifier that is accessing the memory, and blocks the application's read or write request;
[0098] The storage service module, when it is determined that no application is accessing the memory and all requests are effectively blocked, puts the system into a dormant state, allowing other applications to continue to perform read and write operations.
[0099] Specifically, blocking the read and write requests of the application may include: the storage service module actively blocking the current application's read and write requests to the memory; the storage service module notifying the application to suspend the current read and write operations, or allowing the application to continue execution after hibernation is completed.
[0100] In the data security storage method and security storage system based on the QNX system of the above-mentioned embodiment of the present disclosure, by continuously monitoring the registered applications, it can be ensured that the system can perform data protection in time after the application exits, avoiding data loss due to unprocessed exit operations. When the exited application reconnects, the storage service module can restore the connection relationship based on matching the reconnection request with the original registration request. Since the data contained in the reconnection request is the same as the registration request, it can be ensured that the restoration of the connection does not affect the security and consistency of the data. It prevents the system from failing to enter hibernation due to the application accessing the memory, and ensures that the memory data will not be accidentally modified or lost during hibernation, thereby improving the stability of the system.
[0101] In a specific embodiment, Figure 2 FIG. 1 is an exemplary schematic diagram showing the architecture of another secure storage system applied to a data secure storage method based on a QNX system according to an embodiment of the present disclosure. Figure 2 As shown, the QNX system includes at least one application process and a secure storage system. The storage service module in the secure storage system obtains request information of at least one application, and assigns a unique corresponding client identifier to the application based on the storage identifier in the request information; the storage service module performs preset security verification on the application based on the process identifier, connection identifier and security level identifier in the request information, and when the verification passes, sends the data to be stored and the data type to the data storage module, and stores the data to be stored of the application in the data storage module.
[0102] In one embodiment, a secure storage system 300 is provided, and the secure storage system 300 corresponds to the data secure storage method based on the QNX system in the above embodiment. Figure 3 As shown, the secure storage system 300 includes a storage service module 301 and a data storage module 302, wherein each functional module is described in detail as follows:
[0103] The storage service module 301 is used to receive the request information sent by the application, and allocate a unique corresponding client identifier to the application based on the request information; the request information at least includes: storage identifier, data to be stored, data type, and security level identifier;
[0104] The storage service module 301 is used to establish a corresponding relationship between the storage identifier and the client identifier, perform a preset security check on the request information, and when the result of the preset security check is passed, distribute the data to be stored and the data type to the data storage module;
[0105] The data storage module 302 is used to store the data to be stored and the data type in the form of key-value pairs in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
[0106] In one embodiment, the storage service module 301 is used to register the storage service node and provide a preset function interface to the application based on the storage service node; the preset function interface at least includes: a write function and a registration function;
[0107] The storage service module 301 is used to receive the request information sent by the application, the request information also includes the process identifier and the connection identifier of the application; the request information is determined by the application calling the preset function interface;
[0108] The storage service module 301 is used to allocate a unique corresponding client identifier to the application when receiving registration request information of the application.
[0109] In one embodiment, the storage service module 301 is used to correspond the client identifier to the storage identifier in the request information, so that the storage service module uniformly manages the request information of the application based on the client identifier;
[0110] The storage service module 301 is used to perform a first check on the process identifier in the request information to determine whether the process identifier is valid and registered;
[0111] The storage service module 301 is used to perform a second check on the connection identifier in the request information to determine whether the connection with the application is legal;
[0112] The storage service module 301 is used to perform a third check based on the storage identifier and the security level identifier in the request information to determine whether the application has the authority to perform the storage operation corresponding to the security level identifier;
[0113] The storage service module 301 is used to determine the storage location of the data to be stored in the request information when the verification results of the first verification, the second verification and the third verification are all passed, and distribute the data to be stored, the storage location and the data type to the data storage module.
[0114] In one embodiment, the data storage module 302 is used to parse the security level identifier, and when it is determined that the security level identifier is a first preset value, the storage identifier is used as a name in the RPMB storage area to create a corresponding storage file for the application, and a key-value pair of the data to be stored and the data type is stored in the storage file in the RPMB storage area;
[0115] The data storage module 302 is used to, when determining that the security level identifier is the second preset value, use the storage identifier as a name in the file system storage area, create a corresponding storage file for the application, and store the key value in the storage file in the file system storage area.
[0116] In one embodiment, the storage service module 301 is further used to continuously monitor the registered applications, and when it is determined that an application has exited based on the preset system pulse, the exited application is determined according to the connection identifier included in the preset system pulse, and preset data processing is performed on the exited application, and the preset data processing is used to protect the data of the exited application;
[0117] The storage service module 301 is also used to receive a reconnection request from the application in the case of exit, and re-establish a connection relationship with the application based on the reconnection request; the data contained in the reconnection request is the same as the data in the registration request information.
[0118] It should be noted that: the secure storage system provided in the above embodiment only uses the division of the above program modules as an example to illustrate when implementing the corresponding QNX system-based data security storage method. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the above system can be divided into different program modules to complete all or part of the above-described processing. Figure 1b The embodiments of the method shown belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0119] The present disclosure also provides a computer device having the above Figure 3 The secure storage system shown.
[0120] See also Figure 4 , Figure 4 is a schematic diagram of the structure of another secure storage system provided by an embodiment of the present disclosure, such as Figure 4 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.
[0121] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0122] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.
[0123] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0124] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0125] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 4 The example of connecting through bus is taken in the following.
[0126] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator bar, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0127] The computer device also includes a communication interface, which is used for the computer device to communicate with other devices or a communication network.
[0128] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium and downloaded through a network, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0129] A part of the present disclosure may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present disclosure through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in computer-readable media includes, but is not limited to, source files, executable files, installation package files, etc., and accordingly, the way in which computer program instructions are executed by a computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.
[0130] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A data security storage method based on QNX system, characterized in that: Applied to a secure storage system, the secure storage system includes: a storage service module and a data storage module, the method includes: The storage service module receives the request information sent by the application, and allocates a unique corresponding client identifier to the application based on the request information; the request information at least includes: a storage identifier, data to be stored, a data type, and a security level identifier; The storage service module establishes a corresponding relationship between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module; The data storage module stores the data to be stored and the data type in the form of a key-value pair in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
2. The method according to claim 1, characterized in that The storage service module receives the request information sent by the application and allocates a unique corresponding client identifier to the application, including: A storage service module registers a storage service node and provides a preset function interface to the application based on the storage service node; the preset function interface includes at least: a write function and a registration function; The storage service module receives the request information sent by the application, wherein the request information also includes the process identifier and the connection identifier of the application; the request information is determined by the application calling the preset function interface; The storage service module, when receiving the registration request information of the application, allocates a unique corresponding client identifier to the application.
3. The method according to claim 2, characterized in that The storage service module establishes a corresponding relationship between the storage identifier and the client identifier, performs a preset security check on the request information, and when the result of the preset security check is passed, distributes the data to be stored and the data type to the data storage module based on the following steps: The storage service module matches the client identifier with the storage identifier in the request information, so that the storage service module uniformly manages the request information of the application based on the client identifier; The storage service module performs a first check on the process identifier in the request information to determine whether the process identifier is valid and registered; The storage service module performs a second check on the connection identifier in the request information to determine whether the connection with the application is legal; The storage service module performs a third check based on the storage identifier and the security level identifier in the request information to determine whether the application has the authority to perform the storage operation corresponding to the security level identifier; The storage service module, when the verification results of the first verification, the second verification and the third verification are all passed, determines the storage location of the data to be stored in the request information, and distributes the data to be stored, the storage location and the data type to the data storage module.
4. The method according to claim 3, characterized in that The data storage module stores the data to be stored and the data type in the form of a key-value pair in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier, based on the following steps: A data storage module, parsing a security level identifier, and when determining that the security level identifier is a first preset value, using the storage identifier as a name in the RPMB storage area, creating a corresponding storage file for the application, and storing a key-value pair of the data to be stored and the data type in the storage file in the RPMB storage area; When determining that the security level identifier is a second preset value, the data storage module uses the storage identifier as a name in the file system storage area, creates a corresponding storage file for the application, and stores the key value in the storage file in the file system storage area.
5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: The storage service module continuously monitors the registered applications, and when it is determined based on the preset system pulse that an application has exited, determines the exited application according to the connection identifier included in the preset system pulse, and performs preset data processing on the exited application, wherein the preset data processing is used to protect the data of the exited application; The storage service module, in the case of exiting, receives a reconnection request from the application and re-establishes a connection relationship with the application based on the reconnection request; the data contained in the reconnection request is the same as the data in the registration request information.
6. A secure storage system, characterized in that: The secure storage system includes a storage service module and a data storage module, wherein: The storage service module is used to receive the request information sent by the application, and allocate a unique corresponding client identifier to the application based on the request information; the request information at least includes: storage identifier, data to be stored, data type, and security level identifier; The storage service module is used to establish a corresponding relationship between the storage identifier and the client identifier, perform a preset security check on the request information, and when the result of the preset security check is passed, distribute the data to be stored and the data type to the data storage module; The data storage module is used to store the data to be stored and the data type in the form of a key-value pair in the RPMB storage area or the file system storage area in the QNX system according to the security level identifier.
7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the QNX system-based data security storage method according to any one of claims 1 to 5.
8. A computer program product, characterized in that The method comprises computer instructions, wherein the computer instructions are used to enable a computer to execute the QNX system-based data security storage method according to any one of claims 1 to 5.