Storage device security protection method and system supporting multi-scene switching and medium

By initializing configuration information and operation characteristics in the storage device and supporting authentication of multiple unlocking methods, the problem of not being able to support multi-scene switching in the prior art is solved, and a safer and more flexible storage device security protection solution is achieved.

CN119989437APending Publication Date: 2025-05-13成都芯盛集成电路有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510189112.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing storage device security protection solution cannot support multi-scenario switching, resulting in complex operations, high maintenance costs, and a single unlocking method.

Method used

By importing configuration information, operation characteristics and mirror files into the storage device for production line initialization, setting project characteristics and establishing media information binding relationships, it supports multiple unlocking methods (such as Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, face recognition unlocking) for authentication, realizing multi-scene switching and encryption and decryption operations.

Benefits of technology

It realizes rapid operation of multi-scenario switching, improves security, reduces development and maintenance costs, meets users' multi-function needs, and provides higher safety and reliability through a combination of multiple unlocking methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989437A_ABST
    Figure CN119989437A_ABST
Patent Text Reader

Abstract

The invention discloses a storage device security protection method and system supporting multi-scene switching and a medium, and belongs to the technical field of storage security. The method comprises the following steps: initializing a production line; setting current project characteristics, and establishing a binding relationship with the medium information; switching item characteristics of different media, and starting the item characteristics; after power-on and power-off are conducted again, an authentication system is entered for target medium authentication, and a user system is entered after target medium authentication is passed; after entering the user system, performing item characteristic authentication according to the item characteristics of the target medium, and decrypting the target disk after the item characteristic authentication is passed; and the target medium authentication and the item characteristic authentication can be configured to pass verification in various unlocking modes or pass verification in one of the various unlocking modes. The system is safer, the cost of early-stage development, production and later-stage maintenance is saved, and the free combination of multiple scenes can more easily meet user requirements; the combination of software and hardware in various unlocking modes is safer and more reliable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of storage security technology, and in particular to a storage device security protection method, system and medium supporting multi-scenario switching. Background Art

[0002] The mobile phone Bluetooth function unlocking and authentication system is a separate solution, the UKey unlocking and authentication system is a separate solution, the Ukey unlocking hidden partition of the system disk is a separate solution, and so on. However, some users need to combine the functions among them, which will face the problem of being unable to meet the user's multi-functional needs, and the separate and independent solutions will increase the development and maintenance costs, and are prone to errors.

[0003] The existing technology has the following problems: 1. Currently, a solution can only support one scenario operation, with large workload and high maintenance cost.

[0004] 2. One solution does not support switching between multiple scenes.

[0005] 3. One solution limits the switching range of multiple scenes and is complex to operate.

[0006] 4. There is only one unlocking method, which is not safe. Summary of the invention

[0007] The purpose of the present invention is to overcome the deficiencies of the prior art and to provide a storage device security protection method, system and medium that support multi-scenario switching.

[0008] The object of the present invention is achieved through the following technical solutions: The first aspect of the present invention provides: a storage device security protection method supporting multi-scenario switching, comprising the following steps: Import configuration information, supported operating features, and image files into storage devices to initialize the production line; Set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; Switch project features for different media and enable project features; After powering on and off again, enter the authentication system to authenticate the target medium, and enter the user system after passing; After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target medium, and the target disk is decrypted after passing; The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

[0009] Preferably, the production line initialization comprises the following steps: Through the SDK, the configuration information, default authentication passwords, and supported operating characteristics are stored in the hidden storage area of ​​the SSD; Set the SSD hard disk key; Use the SSD hard disk key to import the authentication system image file into the MBR shadow area of ​​the hard disk.

[0010] Preferably, when the user terminal performs the initialization operation, the following steps are included: Use the SDK to update the configuration information, updated user authentication password, and current project features to the hidden storage area of ​​the SSD using the default authentication password; Set the key for the SSD; According to the characteristics of the current project, the media information related to it is bound; The media information is written into the hidden storage area of ​​the SSD for two-way binding and authentication.

[0011] Preferably, when the user terminal performs switching and starts N scene feature operations, the following steps are included: Through the SDK, using the user authentication password, all current unlocking methods will be disabled, and the current project characteristics in the SSD hidden storage area will be set to empty; Disable SSD encryption. Update the current project features and ensure that the updated project features are within the range of features supported by the project, and set and enable the encryption function corresponding to the updated project features; Enable the unlocking method corresponding to the updated project features.

[0012] Preferably, when the authentication system performs a secure unlocking SSD operation, the following steps are included: When the SSD is in encrypted state and the authentication system function is turned on, the authentication system will be entered after booting; Get the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the SSD is unlocked; After the unlocking is successful, call the restart command. After the restart, the unlocked SSD disk will jump to the user's operating system interface. Preferably, when the system disk or the data disk performs the hidden partition unlocking SSD operation, the following steps are included: After entering the user operating system, obtain the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the corresponding hidden partition is unlocked or encrypted.

[0013] Preferably, the Ukey unlocking is to unlock the SSD after inserting the UKey medium, or to encrypt and hide the system disk or data disk after pulling out the Ukey medium; the password unlocking is to unlock the SSD by the user entering the unlock password; the trusted startup unlocking is to perform binding verification of the host hardware and network information after entering the authentication system or the user system in the hidden partition. If only this unlocking method is used, the unlocking is performed if the verification passes; the mobile phone unlocking is to automatically connect the mobile phone Bluetooth to the computer Bluetooth for communication verification; the face recognition unlocking is verified by the face recognition function in the authentication system or the user operating system.

[0014] A second aspect of the present invention provides: a storage device security protection system supporting multi-scenario switching, which is used to implement any of the above-mentioned storage device security protection methods supporting multi-scenario switching, including: Initialization module, used to import configuration information, supported operating characteristics and image files into the storage device for production line initialization; The characteristic binding module is used to set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; The authentication module is used to switch the project characteristics of different media and enable the project characteristics. After powering on and off again, the authentication system is entered to authenticate the target media, and after passing, the user system is entered. After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target media, and the target disk is decrypted after passing. The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

[0015] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned storage device security protection methods supporting multi-scenario switching is implemented.

[0016] The beneficial effects of the present invention are: 1) The multiple scene switching solution of the present invention realizes the rapid switching of multiple scenes through simple operation, which is safer and saves the cost of early development, production and later maintenance. The free combination of multiple scenes can more easily meet the needs of users; the combination of software and hardware of multiple unlocking methods is safer and more reliable. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1A flow chart of a storage device security protection method that supports multi-scenario switching; Figure 2 Initialize the operation flow chart for the production line; Figure 3 The overall operation flow chart of the method; Figure 4 This is a schematic diagram for unlocking. DETAILED DESCRIPTION

[0018] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0019] First, some explanations of terms in the present invention: Authentication password: the key for super administrator authority, set and stored in the SSD hidden storage space during initialization, used for interaction between UKEY and disk, importing authentication system, etc., and can be updated.

[0020] Image file: A disk image file used for pre-boot authentication, which contains the necessary programs, configurations, and resources to support the pre-boot authentication process. It is used to verify the identity authentication before the system starts, ensuring that the system is trusted during the boot process. During the import image file operation, the image file is imported into the MBR shadow area of ​​the hard disk.

[0021] Configuration information: Send instructions to the hard disk SSD to read or store settings in the hard disk hidden storage during initialization. The main configuration includes: 1. The currently readable configuration version 2. The current operation event 3. The steps of the current operation event. Configuration information includes: 1. Features supported by the project. 2. Current features. 3. Authentication password. 4. SSD key. 5. PBA mini-system version number. 6. Trusted boot hash value (32 bits).

[0022] See also Figure 1-Figure 3 The first aspect of the present invention provides: a storage device security protection method supporting multi-scenario switching, comprising the following steps: Import configuration information, supported operating features, and image files into storage devices to initialize the production line; Set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; Switch project features for different media and enable project features; After powering on and off again, enter the authentication system to authenticate the target medium, and enter the user system after passing; After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target medium, and the target disk is decrypted after passing; The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

[0023] In this embodiment, before the finished product leaves the factory, it is necessary to perform a "production line initialization" operation on the production line. Figure 4 As shown, the unlocking methods include UKey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. You can configure multiple unlocking methods to be verified or one of the multiple unlocking methods to be verified.

[0024] In some embodiments, the production line initialization includes the following steps: Through the SDK, the configuration information, default authentication passwords, and supported operating characteristics are stored in the hidden storage area of ​​the SSD; Set the SSD hard disk key; Use the SSD hard disk key to import the authentication system image file into the MBR shadow area of ​​the hard disk.

[0025] In some embodiments, when the user terminal performs an initialization operation, the following steps are included: Use the SDK to update the configuration information, updated user authentication password, and current project features to the hidden storage area of ​​the SSD using the default authentication password; Set the key for the SSD; According to the characteristics of the current project, the media information related to it is bound; The media information is written into the hidden storage area of ​​the SSD for two-way binding and authentication.

[0026] In some embodiments, when the user terminal switches and turns on N scene feature operations, the following steps are included: Through the SDK, using the user authentication password, all current unlocking methods will be disabled, and the current project characteristics in the SSD hidden storage area will be set to empty; Disable SSD encryption. Update the current project features and ensure that the updated project features are within the range of features supported by the project, and set and enable the encryption function corresponding to the updated project features; Enable the unlocking method corresponding to the updated project features.

[0027] In some embodiments, when the authentication system performs a secure unlocking SSD operation, the following steps are included: When the SSD is in encrypted state and the authentication system function is turned on, the authentication system will be entered after booting; Get the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the SSD is unlocked; After the unlocking is successful, call the restart command. After the restart, the unlocked SSD disk will jump to the user's operating system interface. In some embodiments, when the system disk or the data disk performs a hidden partition unlocking SSD operation, the following steps are included: After entering the user operating system, obtain the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the corresponding hidden partition is unlocked or encrypted.

[0028] In some embodiments, the Ukey unlocking is to unlock the SSD after inserting the UKey medium, or to encrypt and hide the system disk or data disk after pulling out the Ukey medium; the password unlocking is to unlock the SSD by the user entering the unlock password; the trusted startup unlocking is to perform binding verification of the host hardware and network information after entering the authentication system or the user system in the hidden partition. If only this unlocking method is used, the unlocking is performed if the verification passes; the mobile phone unlocking is to automatically connect the mobile phone Bluetooth to the computer Bluetooth for communication verification; the face recognition unlocking is verified by the face recognition function in the authentication system or the user operating system.

[0029] A second aspect of the present invention provides: a storage device security protection system supporting multi-scenario switching, which is used to implement any of the above-mentioned storage device security protection methods supporting multi-scenario switching, including: Initialization module, used to import configuration information, supported operating characteristics and image files into the storage device for production line initialization; The characteristic binding module is used to set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; The authentication module is used to switch the project characteristics of different media and enable the project characteristics. After powering on and off again, the authentication system is entered to authenticate the target media, and after passing, the user system is entered. After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target media, and the target disk is decrypted after passing. The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

[0030] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned storage device security protection methods supporting multi-scenario switching is implemented.

[0031] The above is only a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be modified within the scope of the concept described herein through the above teachings or the technology or knowledge of the relevant field. The changes and modifications made by those skilled in the art shall not deviate from the spirit and scope of the present invention, and shall be within the scope of protection of the claims attached to the present invention.

Claims

1. A storage device security protection method supporting multi-scenario switching, characterized in that: The following steps are involved: Import configuration information, supported operating features, and image files into storage devices to initialize the production line; Set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; Switch project features for different media and enable project features; After powering on and off again, enter the authentication system to authenticate the target medium, and enter the user system after passing; After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target medium, and the target disk is decrypted after passing; The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

2. The storage device security protection method supporting multi-scenario switching according to claim 1 is characterized in that: The production line initialization includes the following steps: Through the SDK, the configuration information, default authentication passwords, and supported operating characteristics are stored in the hidden storage area of ​​the SSD; Set the SSD hard disk key; Use the SSD hard disk key to import the authentication system image file into the MBR shadow area of ​​the hard disk.

3. The storage device security protection method supporting multi-scenario switching according to claim 1, characterized in that: When the user terminal performs initialization operation, the following steps are included: Use the SDK to update the configuration information, updated user authentication password, and current project features to the hidden storage area of ​​the SSD using the default authentication password; Set the key for the SSD; According to the characteristics of the current project, the media information related to it is bound; The media information is written into the hidden storage area of ​​the SSD for two-way binding and authentication.

4. The storage device security protection method supporting multi-scenario switching according to claim 1, characterized in that: When the user terminal switches and turns on N scene feature operations, the following steps are included: Through the SDK, using the user authentication password, all current unlocking methods will be disabled, and the current project characteristics in the SSD hidden storage area will be set to empty; Disable SSD encryption. Update the current project features and ensure that the updated project features are within the range of features supported by the project, and set and enable the encryption function corresponding to the updated project features; Enable the unlocking method corresponding to the updated project features.

5. The storage device security protection method supporting multi-scenario switching according to claim 1, characterized in that: When the authentication system performs a secure unlocking of the SSD, the following steps are included: When the SSD is in encrypted state and the authentication system function is turned on, the authentication system will be entered after booting; Get the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the SSD is unlocked; After the unlocking is successful, call the restart command. After the restart, the unlocked SSD disk will jump to the user's operating system interface.

6. The storage device security protection method supporting multi-scenario switching according to claim 1, characterized in that: When the system disk or data disk performs the hidden partition unlock SSD operation, the following steps are included: After entering the user operating system, obtain the current authentication system unlocking method and connect to the corresponding unlocking medium; After the unlock media verification is passed, the SSD key is obtained and the corresponding hidden partition is unlocked or encrypted.

7. The storage device security protection method supporting multi-scenario switching according to any one of claims 1 to 6, characterized in that: The Ukey unlocking is to unlock the SSD after inserting the UKey medium, or to encrypt and hide the system disk or data disk partition after unplugging the Ukey medium; The password unlocking is to unlock the SSD by the user entering the unlock password; the trusted startup unlocking is to perform binding verification of the host hardware and network information after entering the authentication system or the user system in the hidden partition. If only this unlocking method is used, the unlocking will be performed if the verification passes; the mobile phone unlocking is to automatically connect the mobile phone Bluetooth to the computer Bluetooth for communication verification; the face recognition unlocking is verified by the face recognition function in the authentication system or the user operating system.

8. A storage device security protection system supporting multi-scenario switching, characterized in that: A method for implementing a storage device security protection method supporting multi-scenario switching as claimed in any one of claims 1 to 7, comprising: Initialization module, used to import configuration information, supported operating characteristics and image files into the storage device for production line initialization; The characteristic binding module is used to set the current project characteristics, store the media information related to the current project characteristics into the configuration information of the storage device, and establish a binding relationship; The authentication module is used to switch the project characteristics of different media and enable the project characteristics. After powering on and off again, the authentication system is entered to authenticate the target media, and after passing, the user system is entered. After entering the user system, the project characteristics authentication is performed according to the project characteristics of the target media, and the target disk is decrypted after passing. The target media authentication and project feature authentication include at least one unlocking method among Ukey unlocking, password unlocking, trusted startup unlocking, mobile phone unlocking, and face recognition unlocking. When multiple unlocking methods are set for authentication, all unlocking methods must pass for authentication to pass.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are loaded and executed by the processor, the storage device security protection method supporting multi-scenario switching as described in any one of claims 1-7 is implemented.