Method and device for generating encrypted operating system installation file
By encrypting the key files of the operating system layer by layer, and generating bootloader files based on hardware address mapping information and writing them to the storage medium, the problem of existing encryption technology reducing disk performance and decryption risks is solved, and efficient and comprehensive data protection is achieved.
Patent Information
- Application Number
- CN202510152277.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-11
Smart Images

Figure CN120012111A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to information security technology, and more particularly to a method and device for generating encrypted operating system installation files. Background Art
[0002] Linux is one of the world's mainstream operating systems. It originated from the Unix system. Linux is open sourced under the GNU General Public License (GPL) agreement, allowing users to freely disseminate and modify the software under the premise of complying with the license agreement. As open source software, Linux has a large developer community that continuously optimizes and improves system functions. At the same time, it has many different distributions, each with unique characteristics and advantages. Linux is well-known for its excellent stability, security and high customizability. Its main advantages include: 1) Security: Linux has excellent security and the risk of being attacked by viruses and malware is extremely low; 2) Flexibility: Users can customize the Linux system according to their own needs; 3) Free: Linux is completely free open source software and can be used and distributed without restrictions under the GPL agreement; 4) Rich software ecology: Linux has a large number of free and open source applications and tools that can meet a variety of application needs; 5) Excellent performance: Linux has efficient resource utilization, lower system latency, supports multi-threading and high throughput, can run stably for a long time, and is suitable for various critical and high-concurrency task scenarios.
[0003] With its wide range of application scenarios, Linux occupies an important position in all walks of life and is the preferred operating system solution in many fields. Its application scenarios mainly include: 1) Server field: Linux is most widely used in the server field; with its stability and security, it is widely used as a server system in various fields, and all kinds of enterprises use Linux-based servers to provide services; 2) Embedded field: The Linux kernel is widely used in embedded devices, such as routers, switches and network storage devices; its lightweight and customizable features make it the best choice for embedded systems. In particular, with the rapid development of the Internet of Things and artificial intelligence, Linux is becoming more and more popular in these fields, and many Internet of Things devices and artificial intelligence systems are built based on Linux; 3) Scientific computing and supercomputing fields: Linux occupies a dominant position in the field of supercomputers, and the vast majority of world-class supercomputers are driven by the Linux operating system; excellent scalability and computing efficiency, it is also more suitable for handling various complex scientific computing tasks; 4) Cloud computing field: Most cloud computing platforms, such as AWS, Google Cloud and Azure, customize and optimize their infrastructure based on the Linux operating system. These platforms use the stability and security of Linux to support a variety of services such as virtual machines, containers, and serverless computing to meet the needs of different users, thus occupying a dominant position in the market. 5) Personal desktop: Linux has multiple personal desktop distributions such as Ubuntu and Fedora. Users who pursue system security and privacy protection often choose such distributions as their personal desktop systems. In addition, Linux has an active community that can provide a lot of resources and technical support, allowing users to deeply optimize and customize their operating systems.
[0004] With the rapid development of science and technology and the increasing market competition, in the current era of high digitization and networking, enterprises often encounter the following problems in the process of producing and selling products: 1) Intellectual property theft: The innovative products and technologies of enterprises are easily imitated or misappropriated by competitors, especially in software products and codes. Unauthorized copying and secondary distribution seriously affect the market share and brand reputation of enterprises; 2) Data leakage risk: Enterprise decision-making is increasingly driven by data, and sensitive data stored in devices (such as customer information, trade secrets, etc.) has become the primary target of hacker attacks. Data leakage will not only lead to economic losses, but also trigger legal liabilities and user trust crises; 3) Software cracking: Hackers and malicious users often use reverse engineering to crack software. Using technology to crack product authorization will result in unlimited unauthorized use of the company's commercial products. This cracking behavior not only affects the rights and interests of authorized users and companies, but also leads to the emergence of counterfeit and imitation products, seriously damaging the company's image. 4) Compliance requirements: In many industries, especially in finance, medical care, government and industrial control, data security and privacy protection have strict legal and regulatory requirements. Enterprise products must take effective protective measures to ensure that their products and services comply with relevant laws and regulations. 5) Market competition pressure: Enterprises need to maintain their industry competitiveness through continuous technological innovation. However, the rapid iteration and update of technology makes the company's innovative achievements easy to be quickly imitated and copied by competitors. Effective protective measures must be taken to protect the company's return on investment.
[0005] Nowadays, smart products of enterprises are usually delivered and released in the form of software and hardware combination. The corresponding operating system and software will be built into the product hardware device. This combination of software and hardware is common in various industries, especially in the fields of Internet of Things (IoT), smart home, medical equipment and industrial automation. These built-in software and data are the core business secrets of enterprises. In order to better protect the software intellectual property rights and data security and other business secrets of enterprises, it is necessary to find a strong information protection solution. This is not only a necessary means for enterprises to protect their own interests, but also the key to sustainable development of enterprises. In order to protect the intellectual property rights of their own products, enterprises often use various data encryption technologies. The advantages of this type of protection solution mainly include: 1) Improving the confidentiality and integrity of software and data: ensuring that unauthorized users cannot access the content of the device and protecting the intellectual property security of the software; 2) Enhancing user privacy: users can safely store key data on the device without worrying about the data being stolen or leaked; 3) Eliminating the risk of data leakage after the device is stolen or lost: even if the device is stolen, the data in it cannot be maliciously stolen or restored, thereby protecting the security of the data; 4) Complying with industry and regulatory requirements: Encrypting software and data can ensure compliance with relevant laws and regulations and regulatory requirements of industry authorities. Protection measures using mainstream encryption technology can mitigate the risks of software intellectual property being plagiarized, core data being stolen, software products being cracked and illegally distributed. The mainstream encryption solutions in related technologies are as follows: 1) Disk encryption: Use system-level encryption technology to encrypt the entire operating system and disk data, such as BitLocker in Windows, FileVault in macOS, dm-crypt / LUKS in Linux, etc.; 2) File system encryption: Use file system encryption software to encrypt specific directories or files, such as EncryptingFileSystem in Windows platform, DataProtection in macOS platform, eCryptfs in Linux platform, etc.; 3) Container encryption: Use encrypted containers for data storage, such as VeraCrypt, DiskCryptor, etc.; 4) Application encryption: Use encryption software to encrypt specific programs and data generated by programs, such as document encryption in Microsoft Office, file encryption in 7-Zip software, etc. Among the above encryption technologies, the advantage of disk encryption technology is that it can fully protect the entire operating system and disk data; however, its disadvantage is that it will greatly reduce disk performance and have a negative impact on user experience. At the same time, there is also a risk of disk decryption. Hackers can use corresponding tools to brute force the disk key to decrypt the disk data.Several other types of encryption technologies except disk encryption technology can flexibly and selectively encrypt key file systems, software, and data, but they cannot fully protect the entire system and data. Other data except encrypted data still has the risk of leakage.
[0006] In summary, how to achieve system and data security protection without reducing disk performance has become a problem to be solved. Summary of the invention
[0007] The present application embodiment provides a method for generating an encrypted operating system installation file, including: Encrypt the kernel files, temporary file system files and root file system tool files used to build the operating system respectively; Generate a boot loader file according to the decrypted information of the kernel file and the predetermined first hardware address mapping information; Writing the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into the storage medium according to the second hardware address mapping information to obtain a storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the code of the boot loader program integrates the loading and decryption code of the kernel file; the code of the kernel integrates the loading and decryption code of the temporary file system; the code of the temporary file system integrates the loading and decryption code of the root file system tool file; one of the storage media is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the predetermined offset address information of the boot loader file, the encrypted kernel file, the temporary file system file and the root file system tool file.
[0008] On the other hand, an embodiment of the present application further provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method for generating an encrypted operating system installation file is executed.
[0009] On the other hand, an embodiment of the present application further provides a terminal, comprising: a memory and a processor, wherein the memory stores a computer program; wherein: The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for generating an encrypted operating system installation file as described above is executed.
[0010] In another aspect, the embodiment of the present application further provides a device for generating an encrypted operating system installation file, comprising: an encryption unit, a generation unit and a write processing unit; wherein: The encryption unit is set to: encrypt the kernel file, temporary file system file and root file system tool file for building the operating system respectively; The generating unit is configured to: generate a boot loader file according to the decrypted information of the kernel file and the predetermined first hardware address mapping information; The write processing unit is configured to: write the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into the storage medium according to the second hardware address mapping information to obtain the storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the code of the boot loader program integrates the loading and decryption code of the kernel file; the code of the kernel integrates the loading and decryption code of the temporary file system; the code of the temporary file system integrates the loading and decryption code of the root file system tool file; one of the storage media is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the predetermined offset address information of the boot loader file, the encrypted kernel file, the temporary file system file and the root file system tool file.
[0011] At the operating system level, the disclosed embodiment of the present invention encrypts the kernel files, temporary file system files, and root file system tool files required for running the operating system layer by layer. Only when the boot loader, kernel, temporary file system, and root file are sequentially decrypted during the system startup process on the target product hardware platform can the data in the root file system be finally accessed, thereby avoiding the risk of static decryption of one or more system files after being extracted, effectively protecting the storage medium data at the system level, and improving the security of the operating system; writing the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file according to the second hardware address mapping information avoids direct reading of the files by users without access rights, thereby improving data security; at the user interface level, users can only use product functions in a limited operating environment such as the HTTPS service, thereby avoiding users from having underlying permission access to the data in the root file system, thereby effectively protecting the storage medium data at the user level.
[0012] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by implementing the present application. Other advantages of the present application can be realized and obtained by the schemes described in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The accompanying drawings are used to provide an understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.
[0014] Figure 1 A flowchart of a method for generating an encrypted operating system installation file according to an embodiment of the present disclosure; Figure 2 A schematic diagram of a data structure of a storage medium according to an embodiment of the present disclosure; Figure 3 A structural block diagram of a device for generating an encrypted operating system installation file according to an embodiment of the present disclosure; Figure 4 The figure is a flowchart of an application example of the present disclosure. DETAILED DESCRIPTION
[0015] The present application describes multiple embodiments, but the description is exemplary rather than restrictive, and it is obvious to those skilled in the art that there may be more embodiments and implementations within the scope of the embodiments described in the present application. Although many possible feature combinations are shown in the drawings and discussed in the specific embodiments, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with any other feature or element in any other embodiment, or may replace any other feature or element in any other embodiment.
[0016] The present application includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The embodiments, features and elements disclosed in the present application may also be combined with any conventional features or elements to form a unique invention scheme. Any features or elements of any embodiment may also be combined with features or elements from other invention schemes to form another unique invention scheme. Therefore, it should be understood that any feature shown and / or discussed in the present application may be implemented individually or in any appropriate combination. Therefore, except for the limitations made according to the attached claims and their equivalents, the embodiments are not subject to other restrictions. In addition, various modifications and changes may be made within the scope of protection of the attached claims.
[0017] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described herein, the method or process should not be limited to the steps of the specific order described. As will be understood by those of ordinary skill in the art, other sequences of steps are also possible. Therefore, the specific sequence of the steps set forth in the specification should not be interpreted as a limitation to the claims. In addition, the claims for the method and / or process should not be limited to the steps of performing them in the order written, and those skilled in the art can easily understand that these sequences can be changed and still remain within the spirit and scope of the embodiments of the present application.
[0018] Figure 1 A flowchart of a method for generating an encrypted operating system installation file according to an embodiment of the present disclosure, such as Figure 1 As shown, including: Step 101: Encrypt the kernel file, temporary file system file and root file system tool file for constructing the operating system respectively; Step 102: Generate a boot loader file according to the decryption information of the kernel file and the predetermined first hardware address mapping information; Step 103: write the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into a storage medium according to the second hardware address mapping information to obtain a storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the boot loader code integrates the kernel file loading and decryption code; the kernel code integrates the temporary file system loading and decryption code; the temporary file system code integrates the root file system tool file loading and decryption code; a storage medium is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the offset address information of the predetermined boot loader file, encrypted kernel file, temporary file system file and root file system tool file.
[0019] At the operating system level, the disclosed embodiment encrypts the kernel file (Kernel), temporary file system file and root file system (Root Filesystem) file required for running the operating system layer by layer. Only when the boot loader, kernel, temporary file system and root file are sequentially decrypted during the system startup process on the target product hardware platform can the data in the root file system be finally accessed, thereby avoiding the risk of static decryption of one or more system files after being extracted, effectively protecting the storage medium data at the system level, and improving the security of the operating system; writing the boot loader file (Bootloader), the encrypted kernel file, the temporary file system file and the root file system tool file according to the second hardware address mapping information, avoiding users without access rights from directly reading the files, and improving data security; at the user interface level, users can only use product functions in limited operating environments such as HTTPS services, avoiding users from having underlying permission access to the data in the root file system, thereby effectively protecting the storage medium data at the user level.
[0020] The disclosed embodiment implements customization and editing of kernel files, temporary file system files, and root file system tool files required for the operation of the operating system based on steps 101 to 103, and obtains encrypted operating system operation files.
[0021] The disclosed embodiment has a built-in operating system installation file in the storage medium. The storage medium appears in an unrecognized RAW format and cannot locate and identify data. The mounted storage medium is identified as an uninitialized disk state and does not contain decrypted disk partition information. Physical protection is performed while maintaining disk performance, thereby preventing data in the storage medium from being decrypted. The installation files and running data of the loaded software are all stored in a directory of the encrypted root file system, thereby achieving security protection for the software and running data.
[0022] In an exemplary embodiment, the operating system in the embodiment of the present disclosure includes: a Linux operating system.
[0023] In an exemplary embodiment, the temporary system file in the embodiment of the present disclosure is mainly responsible for the initialization of various hardware devices and user file systems during the system startup process. The temporary file system file in the embodiment of the present disclosure includes: initializing RAM file system files.
[0024] The terminal users without access rights in the embodiment of the present disclosure include: local users and network users without operating system administrator rights.
[0025] In an exemplary embodiment, the method of the present disclosure further includes: Hiding and / or encrypting first hardware address mapping information of the kernel file in the boot loader file; when the boot loader file is running, decrypting the information corresponding to the hiding and / or encryption to obtain the first hardware address mapping information; Hide and / or encrypt third hardware address mapping information of the temporary file system file in the kernel file; when the kernel file is running, obtain the third hardware address mapping information by decrypting the information corresponding to the hiding and / or encryption by unhiding and decrypting; The fourth hardware address mapping information of the root file system tool file is hidden and / or encrypted in the temporary file system file; when the temporary file system file is running, the fourth hardware address mapping information is obtained by decrypting the unhiding and decrypting information corresponding to the hiding and / or encryption.
[0026] In an exemplary embodiment, the offset address information in the embodiment of the present disclosure includes: the offset address information of the storage medium determined by using a master boot record (MBR).
[0027] At the storage medium level, the disclosed example uses the offset address information of the storage medium determined by the master boot record (MBR) to implement a deformed MBR partition format structure. Compared with the MBR in the related art, only the MBR boot is used instead of the MBR partition format. The storage medium that does not contain any partition table and disk partition will be identified as an uninitialized disk when mounted. Compared with the MBR, GPT and other partition formats in the related art, the risk of the file partition information of the storage medium being identified is avoided, thereby effectively protecting the storage medium data at the physical layer.
[0028] See also Figure 2 The data structure of the storage medium of the embodiment of the present disclosure mainly includes: the hardware addresses and file sizes of the boot loader files, kernel files, temporary system files and root file system tool files in the storage medium; the starting hardware addresses and ending hardware addresses of all the above files in the embodiment of the present disclosure must be within the valid hardware address range of the storage medium, and cannot overlap with the hardware addresses of other files in the storage medium; the storage addresses of different files in the embodiment of the present disclosure can be set and adjusted based on the pre-set offset address information.
[0029] In an exemplary embodiment, the root file system tool file in the embodiment of the present disclosure can create a directory structure, copy service files and create a tool set; the tool set of the root file system tool file can be built using Busybox; BusyBox in the embodiment of the present disclosure integrates the executable files of common Unix tools and is a collection of tools; the embodiment of the present disclosure uses Busybox technology to achieve compatibility with various hardware platforms, especially embedded hardware. In an exemplary embodiment, the kernel file in the embodiment of the present disclosure can be generated by cross-compilation. The embodiment of the present disclosure configures kernel options according to the hardware requirements of the product with reference to related technologies.
[0030] In an exemplary embodiment, the boot loader file of the embodiment of the present disclosure can be generated by using GRUB. The embodiment of the present disclosure can also use other methods to generate the boot loader; for example, GRUB2 and Syslinux.
[0031] In an exemplary embodiment, the method of the present disclosure further includes: Configure the temporary file system to be integrated into the kernel file in the kernel option configuration; or, Configure the method for loading temporary file system files in the kernel options to load temporary file system files according to the configured method.
[0032] After the above processing, in the embodiment of the present disclosure, when the operating system starts, the boot loader is responsible for reading, decrypting, and loading the kernel files; the kernel executes the reading, decryption, and loading of the temporary file system files; when the kernel loads and runs the temporary file system, the temporary file system executes the custom code to realize the reading, decryption, and loading of the root file system.
[0033] In an exemplary embodiment, the method of the present disclosure further includes: Save the decryption key of the kernel file and the corresponding decryption algorithm in the boot loader file; Save the decryption key and corresponding decryption algorithm of temporary file system files in the kernel file; The decryption key and the corresponding decryption algorithm of the root file system tool file are stored in the temporary file system file.
[0034] The encryption processing performed in the above steps of the embodiment of the present disclosure can be implemented based on the following encryption algorithms and / or tools: Symmetric encryption algorithms: Advanced Encryption Standard (AES), Data Encryption Standard (DES), Blowfish and RC4 (Rivest Cipher 4), etc. Asymmetric encryption algorithms: RSA (Rivest-Shamir-Adleman), Elliptic Curve Cryptography (ECC), and ECCDSA (Digital Signature Algorithm), etc. Encryption tools: LUKS (Linux Unified Key Setup), VeraCrypt (open source disk file encryption software), Cryptsetup (a command line tool used to interact with dm-crypt to create, access and manage encrypted devices), Dm-crypt (a disk encryption subsystem in the Linux kernel) and Fscrypt (a disk encryption subsystem in the Linux kernel), etc.
[0035] In an exemplary embodiment, the method of the present disclosure further includes: The kernel file is hidden, and the code for unhiding the kernel file is integrated into the boot loader file; Hide temporary file system files, and integrate the code for unhiding temporary file system files in the kernel file; The root file system tool file is hidden, and the code for unhiding the temporary file system file is integrated into the temporary file system file. In an exemplary instance, the embodiment of the present disclosure physically connects the storage medium to the hardware of the product; different storage media are connected in different ways, for example, SATA devices are usually connected to the power supply and the motherboard, NVMe devices are usually connected to the M.2 slot, and CompactFlash devices are usually connected to the CF slot. The embodiment of the present disclosure can set the deployed storage medium as the only boot medium in the BIOS of the product's hardware; in addition, the embodiment of the present disclosure can also use one or more methods to secure the hardware startup configuration. For example: setting a BIOS password; disabling booting from external devices (USB, etc.); enabling the secure boot function; using a disposable label to prevent physical disassembly of the product, etc.
[0036] The operating system file generated by the method of the embodiment of the present disclosure can be applicable to various hardware platforms such as personal computers, servers, embedded devices, Internet of Things devices, including but not limited to various types of X86, AMD64, ARM and other CPU architecture hardware that can run the Linux operating system; such as smart home devices in the consumer electronics field, office equipment in the enterprise application field, medical equipment in the embedded field, monitoring equipment in the Internet of Things field, etc.; it is also applicable to permanent storage media that can be recognized by the Linux operating system, and corresponding protection is performed on the data in the storage media, such as SATA devices, NVMe devices and CompactFlash devices.
[0037] The embodiment of the present disclosure also provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method for generating an encrypted operating system installation file is executed.
[0038] The embodiment of the present disclosure further provides a terminal, comprising: a memory and a processor, wherein a computer program is stored in the memory; The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for generating the encrypted operating system installation file is executed.
[0039] Figure 3 A structural block diagram of a device for generating an operating system installation file according to an embodiment of the present disclosure, such as Figure 3 As shown, it includes: an encryption unit, a generation unit and a write processing unit; wherein, The encryption unit is set to: encrypt the kernel file, temporary file system file and root file system tool file for building the operating system respectively; The generating unit is configured to: generate a boot loader file according to the decrypted information of the kernel file and the predetermined first hardware address mapping information; The write processing unit is configured to: write the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into the storage medium according to the second hardware address mapping information to obtain the storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the boot loader code integrates the kernel file loading and decryption code; the kernel code integrates the temporary file system loading and decryption code; the temporary file system code integrates the root file system tool file loading and decryption code; a storage medium is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the offset address information of the predetermined boot loader file, encrypted kernel file, temporary file system file and root file system tool file.
[0040] In an exemplary embodiment, the generation unit of the embodiment of the present disclosure is further configured to: Hiding and / or encrypting first hardware address mapping information of the kernel file in the boot loader file; when the boot loader file is running, decrypting the information corresponding to the hiding and / or encryption to obtain the first hardware address mapping information; Hide and / or encrypt third hardware address mapping information of the temporary file system file in the kernel file; when the kernel file is running, obtain the third hardware address mapping information by decrypting the information corresponding to the hiding and / or encryption by unhiding and decrypting; The fourth hardware address mapping information of the root file system tool file is hidden and / or encrypted in the temporary file system file; when the temporary file system file is running, the fourth hardware address mapping information is obtained by decrypting the unhiding and decrypting information corresponding to the hiding and / or encryption.
[0041] In an exemplary embodiment, the offset address information of the embodiment of the present disclosure includes the offset address information of the storage medium determined by using a master boot record (MBR).
[0042] In an exemplary embodiment, the temporary file system file of the embodiment of the present disclosure includes: initializing the RAM file system file.
[0043] In an exemplary embodiment, the apparatus of the embodiment of the present disclosure further includes a kernel loading processing unit, which is configured to: Configure the temporary file system to be integrated into the kernel file in the kernel option configuration; or, Configure the method for loading temporary file system files in the kernel options to load temporary file system files according to the configured method.
[0044] In an exemplary embodiment, the generation unit of the embodiment of the present disclosure is further configured to: Save the decryption key of the kernel file and the corresponding decryption algorithm in the boot loader file; Save the decryption key and corresponding decryption algorithm of temporary file system files in the kernel file; The decryption key and the corresponding decryption algorithm of the root file system tool file are stored in the temporary file system file.
[0045] In an exemplary embodiment, the generation unit of the embodiment of the present disclosure is further configured to: The kernel file is hidden, and the code for unhiding the kernel file is integrated into the boot loader file; Hide temporary file system files, and integrate the code for unhiding temporary file system files in the kernel file; The root file system tool file is hidden, and the code for unhiding the temporary file system file is integrated into the temporary file system file.
[0046] The following briefly describes the embodiments of the present disclosure through application examples. The application examples are only used to illustrate the embodiments of the present disclosure and are not used to limit the protection scope of the embodiments of the present disclosure.
[0047] Application Examples The disclosed embodiments solve the security problems of operating systems and application software, protect operating systems and software from illegal access and injection, and can be used to ensure that the technological innovations and business secrets of enterprises are not stolen, cracked, or illegally distributed. Through the disclosed embodiment method, enterprises can solve the risks of software cracking, data leakage, unauthorized access, and secondary distribution, protect the core rights and interests of enterprises, and increase the industry competitiveness of enterprises.
[0048] The disclosed embodiment provides a user use environment that limits the underlying access; the user can access the services provided by the product in order to realize various product functions and meet business needs, but cannot access the underlying operating system and storage medium data of the product. This design of limiting the underlying access can not only ensure the convenience of user operation and protect the security of the user's underlying data, but also further protect the security of enterprise products and maintain the competitiveness of enterprise products. Compared with the current mainstream encryption protection technology, the disclosed embodiment is based on the operating system principle and combines a variety of hiding and encryption technologies to deeply customize the operating system, and the protection capability can cover the entire life cycle of the operating system, system applications and storage medium data. In the relevant schemes of software encryption protection, it is impossible to hide the disk partition information. Hackers can easily obtain the disk partition structure and perform further decryption operations by extracting the disk partition table information. The disclosed embodiment adopts a storage medium-free partitioning scheme. The storage medium will be identified as an uninitialized disk state when mounted in any system, thereby solving the problem of storage medium data being decrypted. In related hardware encryption protection schemes, dedicated hardware devices (such as security chips, hardware KEYs) are usually used to generate and store keys for encrypted data. Although hardware encryption schemes provide many security advantages, they also have some disadvantages, such as high cost, strong device dependence, poor compatibility, and lack of flexibility. At the same time, hardware keys also have the risk of being lost or stolen. Once lost or stolen, the data will be completely lost or stolen. The disclosed embodiment does not rely on any dedicated hardware module or chip, and can be implemented on any hardware platform running the Linux operating system. It has the advantages of no hardware dependence, high flexibility, strong compatibility, and natural anti-loss and anti-theft.
[0049] Design the data structure of the storage medium; use MBR partitioning technology to plan the data structure of the storage medium according to the total capacity of the storage medium and the size of the stored files; combine the physical address mapping information, the data structure distribution of the storage medium refers to Figure 2 ; Design a hardware address encryption algorithm; To further improve the data security of the storage medium, the disclosed embodiment hides and encrypts the hardware address mapping information. Correspondingly, during the startup process of the operating system, the hardware address mapping information is decrypted.
[0050] Figure 4 A flowchart of an example of an application of the present disclosure is shown in FIG. Figure 4 As shown, including: S401: Create a root file system tool file; In the embodiment of the present disclosure, the root file system tool file is created mainly in consideration of the compatibility of various hardware platforms, especially the compatibility of embedded hardware.
[0051] S402: Encrypt the root file system; use one of the encryption tools to encrypt the root file system tool file, and save the encryption key for subsequent use.
[0052] S403: configuring kernel options; configuring the kernel according to the hardware requirements of the product by cross-compiling, integrating the Initramfs temporary file system into the kernel options, and packaging the Initramfs file into the kernel file when the kernel is compiled.
[0053] S404: Create a temporary file system; this method uses the Initramfs file system as a temporary file system during the operating system startup process; during the system startup process, Initramfs will be responsible for completing the initialization of various hardware devices and the decryption and loading of the root file system in S202.
[0054] S405: Customize the root file system code: Since the root file system has been encrypted, the decryption code of the root file system tool file needs to be integrated into the kernel and Initramfs code. During the operating system startup process, after the kernel loads and runs the Initramfs temporary file system, the Initramfs executes the custom code to read, decrypt and load the root file system.
[0055] S406: encrypting the temporary file system; to further protect the Initramfs file and prevent the Initramfs file from being extracted by decompressing the kernel file, after the production of the Initramfs is completed, one of the aforementioned encryption algorithms may be used to encrypt the Initramfs file, and the encryption key may be saved for subsequent use.
[0056] S407: Customize temporary file system code: Since the temporary file system has been encrypted, the Initramfs file decryption code needs to be integrated into the kernel code. During the operating system startup process, when the kernel is loaded, the kernel executes the customized code to realize the reading, decryption and loading of Initramfs.
[0057] S408: Compile the kernel file; after completing all the above steps, compile and generate the kernel file by cross-compiling.
[0058] S409: Encrypt the kernel file; to further protect the kernel file and prevent the kernel file from being statically extracted by disk mounting or the like, after the kernel file is produced, one of the aforementioned encryption algorithms is used to encrypt the kernel file, and the encryption key is saved for subsequent use.
[0059] S410: Create a boot loader; use GRUB to create a boot loader for the operating system.
[0060] S411: Customize kernel code: Since the kernel file has been hidden and encrypted, it is necessary to integrate the kernel file loading and decryption code into the GRUB code. During the operating system startup process, GRUB first completes the decryption of the kernel file hardware address and the reading of the kernel file, then uses the key to decrypt the kernel file, and finally completes the loading of the kernel file.
[0061] S412: compile the boot loader; use tools such as make to compile the boot loader to generate the required boot loader file.
[0062] After the files required by the operating system are produced, the embodiment of the present disclosure further needs to write the generated operating system files into the storage medium to complete the production of the storage medium.
[0063] S413: writing the boot loader: the embodiment of the present disclosure writes the boot loader, the kernel file, and the root file system into the storage medium in sequence; for example, a tool such as dd (a command line tool widely used in Linux and Unix systems, mainly used to read, convert and output data) may be used to write the file; S414: Deploy storage media; physically connect the storage media to the hardware platform of the product.
[0064] S415: Setting the boot device of the product; setting the storage medium as the only boot medium in the BIOS of the product hardware.
[0065] The disclosed embodiments hide and encrypt the operating system and storage media, etc., in order to protect the applications and data therein, while limiting the user usage environment for underlying access, thereby further protecting the security of enterprise products and storage media data while ensuring user convenience. Through the disclosed embodiment method, the industry technical barriers of the enterprise can be better built, the core competitiveness of the enterprise's products can be maintained, and the data security of the enterprise's products can be protected. It should be noted that the disclosed embodiment method starts from the startup of the computer hardware and ends when the operating system is started. All the links in the middle are progressively customized and developed, and the full life cycle security protection of the operating system, software products and storage media data is achieved through layers of hiding and encryption technology.
[0066] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transient medium). As is known to those skilled in the art, the term "computer storage medium" includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
Claims
1. A method for generating an encrypted operating system installation file, characterized in that: include: Encrypt the kernel files, temporary file system files and root file system tool files used to build the operating system respectively; Generate a boot loader file according to the decrypted information of the kernel file and the predetermined first hardware address mapping information; Writing the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into the storage medium according to the second hardware address mapping information to obtain a storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the code of the boot loader program integrates the loading and decryption code of the kernel file; the code of the kernel integrates the loading and decryption code of the temporary file system; the code of the temporary file system integrates the loading and decryption code of the root file system tool file; one of the storage media is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the predetermined offset address information of the boot loader file, the encrypted kernel file, the temporary file system file and the root file system tool file.
2. The method according to claim 1, characterized in that The method further comprises: Hiding and / or encrypting the first hardware address mapping information of the kernel file in the boot loader file; obtaining the first hardware address mapping information by decrypting the information corresponding to the hiding and / or encryption when the boot loader file is running; Hiding and / or encrypting the third hardware address mapping information of the temporary file system file in the kernel file; obtaining the third hardware address mapping information by decrypting the decryption information corresponding to the hiding and / or encryption when the kernel file is running; The fourth hardware address mapping information of the root file system tool file is hidden and / or encrypted in the temporary file system file; when the temporary file system file is running, the fourth hardware address mapping information is obtained by decrypting the unhiding and decrypting information corresponding to the hiding and / or encryption.
3. The method according to claim 1, characterized in that The offset address information includes: the offset address information of the storage medium determined by using a master boot record MBR.
4. The method according to claim 1, characterized in that The temporary file system file includes: an initialization RAM file system file.
5. The method according to claim 1, characterized in that The root file system tool file is constructed using Busybox.
6. The method according to claim 1, characterized in that The method further comprises: Configuring the temporary file system to be integrated into the kernel file in the kernel option configuration; or, The method for loading the temporary file system file is configured in the kernel options, so as to load the temporary file system file according to the configured method.
7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: Saving the decryption key of the kernel file and the corresponding decryption algorithm in the boot loader file; Save the decryption key and corresponding decryption algorithm of the temporary file system file in the kernel file; The decryption key and the corresponding decryption algorithm of the root file system tool file are stored in the temporary file system file.
8. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: Performing a hiding process on the kernel file, and integrating a code for performing an unhiding process on the kernel file into the boot loader file; Performing a hiding process on the temporary file system file, and integrating a code for performing an unhiding process on the temporary file system file in the kernel file; The root file system tool file is hidden, and a code for unhiding the root file system tool file is integrated into the temporary file system file.
9. A computer storage medium, wherein a computer program is stored in the computer storage medium, and when the computer program is executed by a processor, the method for generating an operating system installation file according to any one of claims 1 to 8 is implemented.
10. A terminal, comprising: A memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for generating an operating system installation file according to any one of claims 1 to 8 is implemented.
11. A device for generating an operating system installation file, comprising: An encryption unit, a generation unit and a write processing unit; wherein, The encryption unit is set to: encrypt the kernel file, temporary file system file and root file system tool file for building the operating system respectively; The generating unit is configured to: generate a boot loader file according to the decrypted information of the kernel file and the predetermined first hardware address mapping information; The write processing unit is configured to: write the boot loader file, the encrypted kernel file, the temporary file system file, and the root file system tool file into the storage medium according to the second hardware address mapping information to obtain the storage medium containing the operating system, wherein the second hardware address information includes: the first hardware address mapping information, the third hardware address mapping information of the temporary file system file, and the fourth hardware address mapping information of the root file system tool file; Among them, the code of the boot loader program integrates the loading and decryption code of the kernel file; the code of the kernel integrates the loading and decryption code of the temporary file system; the code of the temporary file system integrates the loading and decryption code of the root file system tool file; one of the storage media is physically connected to a product and is used for system operation and data storage of the product hardware platform; the second hardware address mapping information contains the predetermined offset address information of the boot loader file, the encrypted kernel file, the temporary file system file and the root file system tool file.
Citation Information
Patent Citations
Embedded system and implementation method of secure operating system
CN103617128A
Encryption method and device for applying installation package
CN109062582A
Method and system for protecting security of embedded operating system
CN113961939A
Operation system tamper-proofing method and device, vehicle, equipment and storage medium
CN117171809A
Data encryption and decryption method and device based on hardware encryption card, medium and equipment
CN118568743A