Method and system for preventing file to be protected from being copied and storage medium

By using the anti-copy application and firmware in the edge computing device to operate in a coordinated manner, defining additional protection zones and executing data blocking procedures, the problems of performance impact, increased construction costs and high misjudgment rates in the prior art are solved, and data protection effects that are low-cost, do not affect performance, and avoid misjudgment are achieved.

CN120012050APending Publication Date: 2025-05-16INNODISK CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311520322.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing data protection technology has problems such as performance impact, increased construction cost and high misjudgment rate in edge computing devices.

Method used

Prevent the file to be protected from being copied by executing the application on the host side, defining additional protection zones, and executing the data blocking program using the firmware of the storage media.

Benefits of technology

It realizes data protection that is low-cost, does not affect performance, and avoids misjudgment, and supports cross-platform use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012050A_ABST
    Figure CN120012050A_ABST
Patent Text Reader

Abstract

The invention provides a method, a system and a storage medium for preventing a file to be protected from being copied, and the method comprises the following steps: executing a copy prevention application program at a host end to enable or disable a setting program, processing the file to be protected, and defining an additional protection area after the file to be protected is processed; the copy prevention application program of the host end informs firmware of the storage medium of a specific logic block address corresponding to the additional protection area in a communication connection mode so as to complete a set program for preventing the file to be protected from being copied; when a data access address read by the host end from the storage medium comprises a specific logic block address, the firmware executes a pre-stored data blocking program to prevent the file to be protected from being copied by the host end. Therefore, the data protection method can be applied to the edge operation device, and the problems that the efficiency is influenced, the building cost is increased and misjudgment is caused by the existing data protection technology are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and system for protecting specific files, and in particular to a method, system and storage medium for preventing the protected files from being copied. Background Art

[0002] In recent years, the Internet of Things (IoT) technology has developed rapidly in the industry and has greatly improved the production efficiency and yield of the manufacturing industry, while also reducing labor and time costs. With the development of IoT technology, machine-to-machine communication can be combined with automatic detection, optical image measurement, cloud computing, artificial intelligence and other technologies, further improving the reliability and efficiency of the manufacturing industry and bringing many conveniences to people's lives.

[0003] The above cloud computing technology is a process of computing through servers provided by cloud operators. Cloud operators can use cloud computing technology to provide different data processing functions (e.g., data computing, analysis, storage, etc.). The above servers are usually located in places with low space costs and electricity costs, and use high-speed networks (e.g., fiber optic networks) to transmit data to remote locations. However, the above data transmission process will inevitably cause transmission delays due to physical distance.

[0004] Therefore, in order to improve the transmission delay, edge computing devices are born. The edge computing device is a device that allows the computing, analysis, and storage capabilities of data to be closer to the location where the data is generated. In this way, the data processing process is transferred from a remote location to a location closer to the user. In addition to reducing the amount of computing performed remotely, it can also reduce bandwidth requirements, thereby providing faster and more real-time data processing capabilities.

[0005] However, the data stored in edge computing devices usually include applications with high commercial value, artificial intelligence models, or medical records that require privacy protection. Therefore, in order to protect the data stored in edge computing devices and prevent them from being illegally copied, some current data protection technologies use encryption or decryption of specific data, specific hardware circuits to identify legitimate users, specific characters or cyclic redundancy check (CRC) check codes, etc. to protect data. Summary of the invention

[0006] However, in the above-mentioned data protection technology: in terms of encryption or decryption, since it is necessary to occupy the computing resources of the edge computing device, there will be a problem of affecting performance; in terms of identification by specific hardware circuits, since additional hardware circuits are required, there will be a problem of increasing the construction cost of the edge computing device; in terms of specific characters or CRC check codes, for example, the parity check method has an error detection rate of only about 50%, so there may be a problem of misjudgment.

[0007] To solve the above problems, the present invention aims to provide a method for preventing a protected file from being copied, comprising the following steps: executing a copy protection application on a host side to enable or disable a setting program and process the protected file, and after processing the protected file, defining an additional protection zone; the copy protection application on the host side notifies the firmware of a storage medium of a specific logical block address (LBA) corresponding to the additional protection zone through a communication connection to complete the setting program for preventing the protected file from being copied; and when the data access address read by the host side from the storage medium includes the specific logical block address, the firmware executes a pre-stored data blocking program to prevent the protected file from being copied by the host side.

[0008] In some embodiments, the file to be protected is stored in at least one storage area of ​​a storage medium.

[0009] In some embodiments, the data blocking procedure includes: causing the firmware to send false data to the host end; causing the firmware to continue to send false data to the host end so that the host end cannot end the file copy operation; causing the storage medium to not respond to any command from the host end; deleting the data stored in at least one storage area; and / or partially or completely formatting the storage medium to clear the data stored in at least one storage area.

[0010] In some embodiments, the host side further notifies the firmware of the storage medium through the copy protection application to disable the setting program.

[0011] To solve the above problems, the present invention aims to provide a system for preventing protected files from being copied, comprising: a host end, on which a copy protection application is installed, for processing the protected files and defining an additional protection zone after processing the protected files; and a storage medium, which is communicatively connected to the host end, and the storage medium has firmware and at least one storage area, and the firmware allows the copy protection application to set the additional protection zone and the data blocking program, and the at least one storage area is used to store the protected files; wherein the copy protection application of the host end notifies the firmware of the specific logical block address corresponding to the additional protection zone through a communication connection to complete the setting procedure for preventing the protected files from being copied, and when the data access address read by the host end from the storage medium includes the specific logical block address, the firmware executes the pre-stored data blocking program to prevent the protected files from being copied by the host end.

[0012] To solve the above problems, the present invention aims to provide a storage medium for preventing protected files from being copied, which is suitable for communication connection with a host end installed with a copy protection application. The host end processes the protected files through the copy protection application and defines an additional protection zone after processing the protected files. The storage medium includes: firmware for allowing the copy protection application to set the additional protection zone and data blocking program; and at least one storage zone electrically connected to the firmware for storing the protected files; wherein the copy protection application on the host end notifies the firmware of the specific logical block address corresponding to the additional protection zone through a communication connection to complete the setting procedure for preventing the protected files from being copied. When the data access address read by the host end from the storage medium includes the specific logical block address, the firmware executes the pre-stored data blocking program to prevent the protected files from being copied by the host end.

[0013] In summary, the method, system and storage medium for preventing the protected files from being copied of the present invention utilize the coordinated operation of the copy prevention application and the storage medium to achieve the purpose of data protection. Since the present invention utilizes the existing firmware in the storage medium to set / cancel the program for preventing the protected files from being copied, compared with the prior art method of changing or adding hardware circuits, the cost of the storage medium will not be increased. In addition, compared with the prior art method of using encryption and decryption, the present invention will not occupy too many computing resources of the processor, so it will not affect the performance of the device. Furthermore, since the logical block address is unique and will not be repeated, it will not be different due to the operating system (Windows, Linux, etc.) or hardware architecture (X86, ARM, etc.), therefore, compared with the prior art method of using specific characters or CRC check codes, there will be no misjudgment, thereby avoiding the problem of misjudgment. In this way, the purpose of data protection with low cost, no impact on performance, no misjudgment, and support for cross-platform is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 It is a block diagram of a system for preventing a protected file from being copied according to an embodiment of the present invention.

[0015] Figure 2A It is a schematic diagram of processing the file to be protected according to an embodiment of the present invention.

[0016] Figure 2B It is a schematic diagram of executing operations on a file to be protected according to an embodiment of the present invention.

[0017] Figure 2C It is a schematic diagram of copying a file to be protected according to an embodiment of the present invention.

[0018] Figure 3 The figure is a flow chart of a method for preventing a protected file from being copied according to an embodiment of the present invention.

[0019] Reference numerals

[0020] 10 Host side

[0021] 100 System for preventing protected files from being copied

[0022] 12 Preventing the copying of applications

[0023] 20 Storage Media

[0024] 22 Firmware

[0025] 24 Storage Area

[0026] 240 Archives to be protected

[0027] 242 Additional protected areas

[0028] A The first file capacity

[0029] B Second file capacity

[0030] S300,S302,S304,S306 Steps

[0031] Steps S308, S310, S312 DETAILED DESCRIPTION

[0032] Please refer to Figure 1 , a block diagram of a system 100 for preventing a protected file from being copied according to an embodiment of the present invention is shown. The system 100 for preventing a protected file from being copied comprises: a host end 10 and a storage medium 20.

[0033] The host end 10 is installed with a copy protection application 12. The copy protection application 12 can be used to enable or disable the setting program, and process the file to be protected 240, and define the additional protection zone 242 after processing the file to be protected 240. The copy protection application 12 has the authority to access the firmware 22 of the storage medium 20, and is a specific application. For example, the copy protection application 12 can provide a user operation interface on the host end 10, allowing the user to freely select and specify the file to be stored in the storage medium 20 and to be protected, so as to define it as the file to be protected 240. Since the copy protection application 12 is a specific application that can be matched with the storage medium 20. Therefore, if only one of the copy protection application 12 or the storage medium 20 is obtained, it is impossible to perform the setting / cancellation program of preventing the file to be protected from being copied. In this way, it is prevented that the person who obtains the storage medium 20 by illegal means steals the file to be protected 240 stored in the storage medium 20, and the security of data protection is improved.

[0034] The host end 10 may have an operating system (e.g., Windows, Linux, Unix, QNX, etc.), a processor (e.g., x86 architecture, ARM architecture, MIPS architecture, CISC architecture, RISC architecture, NPU (Neural-network Processing Unit) architecture, etc.), a storage device (not shown) and a communication circuit (not shown) and other devices for data calculation, analysis, and storage basic functions. The processor may be, for example, a central processing unit (CPU), or other programmable general-purpose or special-purpose micro control unit (MCU), application specific integrated circuit (ASIC), graphics processing unit (GPU), image signal processor (ISP), image processing unit (IPU), microprocessor, digital signal processor (DSP), programmable controller, field programmable gate array (FPGA) or other similar components or combinations of the above components.

[0035] The storage medium 20 is connected to the host terminal 10 in communication. The communication connection may be, for example, wired transmission or wireless transmission. The wired transmission may be, for example, data transmission using communication standards or interfaces such as integrated circuits (IDE), universal serial bus (USB), small computer system interface (SCSI), serial advanced technology attachment (SATA), and peripheral component interconnect express (PCI Express). The wireless transmission may be, for example, data transmission using communication standards such as wireless network (Wi-Fi) technology.

[0036] The storage medium 20 may have a firmware 22 and one or more storage areas 24. In this embodiment, the firmware 22 may allow the copy protection application 12 installed on the host end 10 to set additional protection zones and data blocking programs. The firmware 22 may pre-store program codes of executable data blocking programs. The data blocking program may have priority to block and ignore commands from the host end 10 to prevent the protected file 240 from being copied by the host end 10. The one or more storage areas 24 may be used to store the protected file 240, the processed protected file 240 and / or data such as application programs and artificial intelligence models. The storage medium 20 may be, for example, a random access memory (RAM), a read-only memory (ROM), a flash memory, a hard disk drive (HDD), a solid state drive (SSD) or similar components or a combination of the above components. In this embodiment, SSD is used as an example for illustration. In addition, the storage medium 20 also has a communication circuit / interface matching the host end 10, which is well known to those skilled in the art and will not be described in detail here.

[0037] Please refer to Figure 2A , showing a schematic diagram of processing a file to be protected 240 according to an embodiment of the present invention. When the host end 10 executes the copy protection application 12 to process the file to be protected 240, the file to be protected 240 has a first file capacity A (for example, 5MB). After the processing of the file to be protected 240 is completed, an additional protection zone 242 is defined, and the additional protection zone 242 has a second file capacity B (for example, 1KB). The first file capacity A may be greater than or equal to the second file capacity B, but is not limited thereto. The additional protection zone 242 may correspond to a specific logical block address. The storage content of the additional protection zone 242 may be, for example, descriptive data that does not affect the program execution result. In this way, the additional protection zone 242 according to the embodiment of the present invention will not occupy too much storage space of the storage medium 20, and the purpose of data protection can be achieved.

[0038] Next, the host end 10 can notify the firmware 22 of the storage medium 20 of the specific logical block address corresponding to the additional protection zone 242 through the communication connection method through the copy prevention application 12 to complete the setting procedure for preventing the protected file from being copied. In some embodiments, the host end can notify the firmware 22 of the storage medium 20 through the copy prevention application 12 to disable the setting procedure. In other embodiments, the copy prevention application 12 of the embodiment of the present invention can also be specified or automatically specified to be set to the logical block address in the firmware 22 of the storage medium 20 as the specific logical block address. Since the logical block address is unique and will not be repeated, compared with the method of using specific characters or CRC check codes in the prior art, there will be no misjudgment, thereby avoiding the problem of misjudgment.

[0039] When the data access address read by the host end 10 from the storage medium 20 includes a specific logical block address, the firmware 22 executes a pre-stored data blocking program to prevent the protected file 240 from being copied by the host end 10. The data blocking program may, for example, cause the firmware 22 to transmit false data (e.g., blank data, randomly generated data, etc.) to the host end 10. In some embodiments, the data blocking program may, for example, cause the firmware 22 to continuously transmit false data to the host end 10 so that the host end 10 cannot end the file copying operation. In addition, in the above-mentioned embodiment of transmitting false data to the host end 10, only part or a small amount of the computing resources of the host end 10 will be occupied. In some embodiments, the data blocking program may, for example, cause the storage medium 20 to not respond to any command from the host end 10. In some embodiments, the data blocking program may, for example, delete the data stored in one or more storage areas 24. In some embodiments, the data blocking program may, for example, partially or completely format the storage medium 20 to clear the data stored in one or more storage areas 24. The above-mentioned data blocking programs may be executed in an overlapping manner or individually.

[0040] Please refer to Figure 2B , showing a schematic diagram of executing the protected file 240 according to an embodiment of the present invention. When the host end 10 performs an execution operation (for example, executing a file with a file extension of .exe, etc.), the host end 10 reads the logical block address of the protected file 240 within the original first file capacity A and does not touch the second file capacity B of the additional protection zone 242 (corresponding to Figure 2B ). Thus, the host end 10 can normally perform the required application execution operation.

[0041] Please refer to Figure 2C, showing a schematic diagram of copying a file to be protected according to an embodiment of the present invention. When the host end 10 performs a copy operation, the host end 10 reads the logical block address of the file to be protected 240 in addition to the original first file capacity A, and also adds the second file capacity B of the additional protection zone 242 (corresponding to Figure 2C At this time, the firmware 22 will immediately trigger the execution of the pre-stored data blocking program to prevent the protected file 240 from being copied by the host end 10.

[0042] Please refer to Figure 3 , showing a flow chart of a method for preventing a protected file from being copied according to an embodiment of the present invention. Step S300, executing the copy protection application 12 on the host 10 to process the protected file 240, and defining an additional protection zone 242 after processing the protected file 240.

[0043] In step S302, the copy protection application 12 of the host 10 notifies the firmware 22 of the storage medium 20 of the specific logical block address corresponding to the additional protection zone 242 through the communication connection to complete the setting procedure of preventing the protected file from being copied.

[0044] In step S304, it is determined whether the data access address read by the host end 10 from the storage medium 20 includes a specific logical block address. When it is determined that the data access address read by the host end 10 from the storage medium 20 includes a specific logical block address, the process proceeds to step S308. When it is determined that the data access address read by the host end 10 from the storage medium 20 does not include a specific logical block address, the process proceeds to step S306.

[0045] In step S306, the host end 10 can normally access data and / or operate the storage medium 20. Since the supplier of the device (e.g., edge computing device) can provide the device to the user after completing the setting procedure of preventing the protected file 240 from being copied, the user of the device does not need to change the operation behavior on the host end 10 because the device is equipped with the system 100 for preventing the protected file from being copied, and the convenience of using the device can still be maintained.

[0046] In step S308, the firmware 22 executes the pre-stored data blocking program to prevent the protected file 240 from being copied by the host end 10. Thus, when the host end 10 performs a copy operation, the copy operation can be determined to be an illegal behavior, and the data protection mechanism (i.e., the data blocking program) is immediately triggered, thereby preventing the protected file 240 from being stolen from the storage medium 20 to the host end 10.

[0047] In step S310, the host end 10 cancels the setting procedure for preventing the protected file from being copied. If it is confirmed that the host end 10 cancels the setting procedure for preventing the protected file from being copied, the process proceeds to step S312. If it is confirmed that the host end 10 does not cancel the setting procedure for preventing the protected file from being copied, the process returns to step S300.

[0048] In step S312, the host 10 notifies the firmware 22 of the storage medium 20 of the specific logical block address through the communication connection via the copy protection application 12 to disable the setting program. It is worth noting that the enabling or disabling of the setting program for preventing the protected file from being copied in the embodiment of the present invention can be performed at any time point, and does not need to be performed at a specific time point or within a specific period, thereby reducing the complexity of the operation and improving the convenience of the operation.

[0049] In summary, the method, system and storage medium for preventing the protected files from being copied of the present invention utilize the coordinated operation of the copy prevention application 12 and the storage medium 20 to achieve the purpose of data protection. Since the present invention utilizes the existing firmware 22 in the storage medium 20 to set / cancel the program for preventing the protected files from being copied, the cost of the storage medium 20 will not be increased compared to the prior art method of changing or adding hardware circuits. In addition, compared to the prior art method of using encryption and decryption, the present invention will not occupy too many computing resources of the processor, so it will not affect the performance of the device. Furthermore, since the logical block address is unique and will not be repeated, it will not be different due to the operating system (Windows, Linux, etc.) or hardware architecture (X86, ARM...), therefore, compared to the prior art method of using specific characters or CRC check codes, there will be no misjudgment, thereby avoiding the problem of misjudgment. In this way, the purpose of data protection with low cost, no impact on performance, no misjudgment, and support for cross-platform is achieved.

Claims

1. A method for preventing a protected file from being copied, characterized in that: The following steps are included: Executing a copy protection application program on a host to enable a setting program and process a file to be protected, and after processing the file to be protected, defining an additional protection zone; The copy protection application program on the host side notifies a firmware of a storage medium of a specific logical block address corresponding to the additional protection zone through a communication connection to complete the setting procedure for preventing the protected file from being copied; and When a data access address read by the host end from the storage medium includes the specific logical block address, the firmware executes a pre-stored data blocking program to prevent the protected file from being copied by the host end.

2. The method for preventing a protected file from being copied according to claim 1, characterized in that: The file to be protected is stored in at least one storage area of ​​the storage medium.

3. The method for preventing a protected file from being copied according to claim 2, characterized in that: The data blocking procedure includes: causing the firmware to transmit a false data to the host end; causing the firmware to continuously transmit the false data to the host end so that the host end cannot terminate a file copy operation; causing the storage medium to not respond to any command from the host end; deleting the data stored in the at least one storage area; and / or partially or completely formatting the storage medium to clear the data stored in the at least one storage area.

4. The method for preventing a protected file from being copied according to claim 1, characterized in that: The method further includes the host end notifying the firmware of the storage medium through the copy protection application program to disable the setting program.

5. A system for preventing a protected file from being copied, characterized in that: include: A host side is installed with a copy protection application program for enabling or disabling a setting program and processing a file to be protected, and after processing the file to be protected, an additional protection zone is defined; and A storage medium is connected to the host end in communication, the storage medium has a firmware and at least one storage area, the firmware allows the copy protection application to set the additional protection area and a data blocking program, and the at least one storage area is used to store the file to be protected; The host end notifies the firmware of the storage medium of a specific logical block address corresponding to the additional protection zone through a communication connection to complete the setting procedure for preventing the protected file from being copied. When a data access address read by the host end from the storage medium includes the specific logical block address, the firmware executes the pre-stored data blocking procedure to prevent the protected file from being copied by the host end.

6. The system for preventing protected files from being copied according to claim 5, characterized in that: The data blocking procedure includes: causing the firmware to transmit a false data to the host end; causing the firmware to continuously transmit the false data to the host end so that the host end cannot terminate a file copy operation; causing the storage medium to not respond to any command from the host end; deleting the data stored in the at least one storage area; and / or partially or completely formatting the storage medium to clear the data stored in the at least one storage area.

7. The system for preventing protected files from being copied according to claim 5, characterized in that: The method further includes the host notifying the firmware of the storage medium through the copy protection application to disable the setting program.

8. A storage medium for preventing a protected file from being copied, characterized in that: The storage medium is adapted to be connected to a host end having a copy protection application installed thereon, the host end enables or disables a setting program through the copy protection application, processes a file to be protected, and defines an additional protection zone after processing the file to be protected. The storage medium comprises: a firmware for allowing the copy protection application to set the additional protection zone and a data blocking process; and At least one storage area, electrically connected to the firmware, for storing the file to be protected; The copy protection application on the host side notifies the firmware via a communication connection of a specific logical block address corresponding to the additional protection zone to complete the setting procedure for preventing the protected file from being copied. When a data access address read by the host side from the storage medium includes the specific logical block address, the firmware executes the pre-stored data blocking program to prevent the protected file from being copied by the host side.

9. The storage medium for preventing a protected file from being copied according to claim 8, characterized in that: The data blocking procedure includes: causing the firmware to transmit a false data to the host end; causing the firmware to continuously transmit the false data to the host end so that the host end cannot terminate a file copy operation; causing the storage medium to not respond to any command from the host end; deleting the data stored in the at least one storage area; and / or partially or completely formatting the storage medium to clear the data stored in the at least one storage area.

10. The storage medium for preventing a protected file from being copied according to claim 8, characterized in that: The method further includes the host end notifying the firmware of the storage medium through the copy protection application program to disable the setting program.