USB flash disk security access method based on storage data block management and control

By performing data block-level security control on USB disks, including hardware key encryption, dynamic encryption and steganography, access permission management and self-destruction mechanisms, the problem that existing USB disk security technology cannot provide comprehensive and real-time protection is solved, and higher data security and attack resistance are achieved.

CN120012178APending Publication Date: 2025-05-16XIAN BECKONING NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510144987.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing USB disk security technologies lack fine-grained control and dynamic management of underlying data blocks, and cannot provide comprehensive and real-time protection, especially when facing high-intensity security threats.

Method used

By determining the storage data block structure of the USB flash drive, initializing hardware key encryption, configuring access control modules, loading security policies, assigning access permissions, detecting access behaviors, implementing dynamic encryption and steganography, setting up self-destruction mechanisms and data integrity verification, the refined security management of USB flash drive data blocks is realized.

Benefits of technology

It improves the security of data transmission and storage, provides real-time integrity verification and self-destruction mechanism, effectively prevents data tampering, illegal access and physical attacks, and meets application requirements in high security needs scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012178A_ABST
    Figure CN120012178A_ABST
Patent Text Reader

Abstract

The invention discloses a USB flash disk secure access method based on storage data block management and control, which relates to the technical field of data security and comprises the following steps of: determining a storage data block structure of a USB flash disk; initializing hardware key encryption of the storage data block; configuring an access control module of the USB flash disk; loading a security policy of the access device; allocating access permissions according to the types of the storage data blocks; detecting and recording a USB flash disk access behavior; dynamic encryption and data block steganography are implemented; setting a storage data block self-destruction mechanism; u disk data integrity verification is constructed; and implementing offline data backup and recovery. According to the method, through multiple security means such as hardware key encryption, data block category division access permission, dynamic encryption and steganography technology, data integrity verification and a self-destruction mechanism, refined security management at a data block level can be realized. The security of data transmission and storage is improved, a real-time integrity verification and self-destruction mechanism is provided, and data tampering, illegal access and physical attack are prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular to a USB flash drive security access method based on storage data block management and control. Background Art

[0002] With the widespread use of mobile storage devices, USB flash drives are widely used in various scenarios as a convenient data storage and transmission tool. However, the widespread use of USB flash drives also brings significant security risks, including data tampering, illegal access, malware injection, and even data loss. Existing USB flash drive security technologies mainly focus on basic encryption protection and access control, but these measures usually only work at the file system level and lack fine-grained control and dynamic management of underlying data blocks. Especially in the face of high-intensity security threats (such as malicious tampering, network attacks, and physical disassembly), traditional security mechanisms seem to be powerless and unable to provide comprehensive and real-time protection. Summary of the invention

[0003] In view of the deficiencies in the prior art, the present invention provides a USB flash drive secure access method based on storage data block management to solve the problems raised in the above background technology.

[0004] To achieve the above object, the present invention provides the following technical solution: a USB flash drive secure access method based on storage data block management and control, comprising the following steps: S1, determine the storage data block structure of the USB flash drive; S2, initializing hardware key encryption of storage data blocks; S3, configure the access control module of the USB flash drive; S4. Load the security policy of the access device; S5. Allocate access rights according to storage data block categories; S6. Detect and record USB access behavior; S7, implement dynamic encryption and data block steganography; S8, setting a storage data block self-destruction mechanism; S9, constructing USB disk data integrity verification; S10. Implement offline data backup and recovery.

[0005] To further optimize the technical solution, in step S1, the physical storage structure of the USB flash drive is analyzed, including a plurality of storage data blocks, each storage data block being provided with a unique physical address; Develop clear access and security policies for each storage data block, divide the USB storage into different security areas, and only allow specific operating systems or applications to access each area; At the same time, different encryption strategies are implemented for different storage data blocks to ensure that the data cannot be easily read even if the USB flash drive is physically accessed or copied.

[0006] To further optimize the technical solution, in step S2, a hardware-level encryption key is initialized in the hardware controller of the USB flash drive, and the key is used to encrypt the content stored in each data block of the USB flash drive; During initialization, the key is randomly generated and saved in the secure storage area of ​​the USB flash drive. Any illegal device or unauthorized access will cause encryption failure. Each time the USB flash drive is connected, the hardware key is used to perform data decryption and encryption operations.

[0007] To further optimize the technical solution, in step S3, before accessing the system, an access control module is configured inside the USB flash drive, and the module is responsible for verifying the accessed device; By integrating an authentication mechanism, such as multi-factor authentication or fingerprint-based authentication, the USB drive can only be accessed on authorized devices. Each time it is connected, the USB flash drive first verifies the identity of the connected device. If the device authentication fails, the USB flash drive will be locked or only provide read-only access.

[0008] To further optimize the technical solution, in step S5, different storage data blocks store different types of files, including configuration files, log files, and user data; Different access permissions are set for stored data blocks according to their categories. Sensitive data blocks are protected by encryption or mandatory user identity authentication. Access control is not only based on device type and device identity, but also dynamically adjusted based on specific file types or data block locations.

[0009] To further optimize the technical solution, in step S6, the system performs real-time detection and log recording of access behavior, and each U disk access, file reading and writing, and file operation behavior is recorded in detail and encrypted and stored; The system monitors in real time whether the files in the USB flash drive are accessed or tampered with by unauthorized programs, and issues a warning when an abnormality is found.

[0010] To further optimize the technical solution, in step S7, when the data is written to the USB flash drive, the system encrypts each storage data block in real time, and embeds the encryption key into the storage data block through steganography, without affecting normal data access; At the same time, only authenticated devices and users can correctly extract the key and decrypt the data.

[0011] To further optimize the technical solution, in step S8, once it is found that the device connected to the USB flash drive is in an untrusted state, or an abnormal security threat occurs, i.e., virus infection or network attack, the USB flash drive automatically starts the data block self-destruction mechanism; Sensitive data in the USB flash drive is completely deleted or encrypted in a short period of time and cannot be recovered; it is automatically executed when a threat is detected, either through a time delay preset in the USB flash drive's hardware controller or triggered by an external signal.

[0012] To further optimize the technical solution, in step S9, the system performs integrity verification before each data access, specifically including the following process: Each stored data block is verified through a hash algorithm or digital signature to ensure the consistency of the data block content. Any illegal data modification can be detected immediately during access and trigger a warning or prevent further access.

[0013] To further optimize the technical solution, in step S10, when the USB flash drive is connected, the system automatically backs up the files in the storage data block to a local encrypted storage device or cloud storage, providing a verification mechanism for data recovery; The backed-up data is encrypted and can only be restored in an authenticated environment. In addition, when tampering or damage to data blocks is detected, the system automatically restores the data from the backup and provides necessary security repair measures.

[0014] Compared with the prior art, the present invention provides a USB flash drive secure access method based on storage data block management and control, which has the following beneficial effects: This USB flash drive security access method based on storage data block management and control can achieve refined security management at the data block level through hardware key encryption, data block category division of access rights, dynamic encryption and steganography technology, data integrity verification and self-destruction mechanism and other security means. This method not only improves the security of data transmission and storage, but also provides real-time integrity verification and self-destruction mechanism to effectively prevent data tampering, illegal access and physical attacks. At the same time, through flexible management and dynamic encryption of different data blocks, stronger anti-attack capabilities and data confidentiality are achieved, meeting the application requirements in high-security demand scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 A schematic diagram of a flow chart of a USB flash drive secure access method based on storage data block management and control proposed by the present invention; Figure 2 A schematic diagram of a random key generation model in a USB flash drive secure access method based on storage data block management and control proposed by the present invention; Figure 3A flow chart of an access rights allocation model in a USB flash drive secure access method based on storage data block management and control proposed by the present invention; Figure 4 The present invention provides a flow chart of a dynamic encryption and data block steganography model in a USB flash drive secure access method based on storage data block management and control. DETAILED DESCRIPTION

[0016] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0017] Embodiment 1: See also Figure 1 , a USB flash drive secure access method based on storage data block management and control, comprising the following steps: S1. Determine the storage data block structure of the USB flash drive In this embodiment, the physical storage structure of the USB flash drive is analyzed, including multiple storage data blocks (e.g., file allocation table, data area, etc.), each storage data block is provided with a unique physical address; Develop clear access and security policies for each storage data block, divide the USB storage into different security areas, and only allow specific operating systems or applications to access each area; At the same time, different encryption strategies are implemented for different storage data blocks to ensure that the data cannot be easily read even if the USB flash drive is physically accessed or copied.

[0018] That is, establish a security classification of storage blocks and define the permissions and encryption methods of different types of storage data blocks.

[0019] S2. Initialize hardware key encryption of storage data blocks In this embodiment, a hardware-level encryption key is initialized in the hardware controller of the USB flash drive, and the key is used to encrypt the content stored in each data block of the USB flash drive; hardware encryption can not only effectively prevent data from being directly read or tampered with by external devices, but also provide additional security protection during data transmission.

[0020] During initialization, the key is randomly generated and saved in the secure storage area of ​​the USB flash drive. Any illegal device or unauthorized access will cause encryption failure. Therefore, each time the USB flash drive is connected, the hardware key will be used to perform data decryption and encryption operations.

[0021] S3. Configure the access control module of the USB disk In this embodiment, before accessing the system, an access control module is configured inside the USB flash drive, which is responsible for verifying the accessed device; By integrating an authentication mechanism, such as multi-factor authentication or fingerprint-based authentication, the USB drive can only be accessed on authorized devices. Each time the USB flash drive is connected, it first verifies the identity of the connected device. If the device identity verification fails, the USB flash drive will be locked or only provide read-only access. This control measure can effectively prevent the USB flash drive from being accessed or abused by malicious devices.

[0022] S4. Load the security policy of the access device In this embodiment, when the USB flash drive is connected to a computer or other device, the system will dynamically adjust the access rights of the USB flash drive according to the security policy of the access device. For example, if the device belongs to a trusted network environment, the USB flash drive can be allowed to perform write operations; if the device belongs to an untrusted network environment, only non-sensitive data in the USB flash drive can be read. These policies will be flexibly adjusted based on the device's operating system, network environment, current security situation, etc. By cooperating with the security environment of the access device, the USB flash drive can independently determine the access risk and perform corresponding policy processing.

[0023] S5. Allocate access rights according to storage data block categories In this embodiment, different storage data blocks store different types of files, including configuration files, log files, and user data; Different access permissions are set for stored data blocks according to their categories. Sensitive data blocks are protected by encryption or mandatory user identity authentication. Access control is not only based on device type and device identity, but also dynamically adjusted based on specific file types or data block locations.

[0024] This method can protect the data in the USB flash drive in a hierarchical and fine-grained manner, ensuring that sensitive data will not be misoperated or abused.

[0025] S6. Detect and record USB flash drive access behavior In this embodiment, the system performs real-time detection and log recording of access behaviors. Each USB flash drive access, file reading and writing, and file operation is recorded in detail and stored in encrypted form. These log records not only assist in subsequent security audits, but also provide a basis for tracing when abnormal situations occur.

[0026] The system monitors in real time whether the files in the USB flash drive are accessed or tampered by unauthorized programs, and issues a warning when an abnormality is found. This behavior monitoring mechanism can provide continuous protection for the secure access of the USB flash drive.

[0027] S7. Implement dynamic encryption and data block steganography In this embodiment, when data is written to the USB flash drive, the system encrypts each storage data block in real time and embeds the encryption key into the storage data block through steganography without affecting normal data access; At the same time, only authenticated devices and users can correctly extract the key and decrypt the data. This approach not only enhances the ability to prevent data leakage, but also effectively resists reverse engineering technology.

[0028] S8. Set up a self-destruct mechanism for storage data blocks In this embodiment, once it is found that the device connected to the USB flash drive is in an untrusted state, or an abnormal security threat occurs, i.e., virus infection or network attack, the USB flash drive automatically starts the data block self-destruction mechanism; Sensitive data in the USB flash drive is completely deleted or encrypted in a short period of time and cannot be recovered; it is automatically executed when a threat is detected through a preset time delay in the USB flash drive's hardware controller or an external signal trigger. This mechanism can effectively prevent data leakage or malicious tampering.

[0029] S9. Construct USB disk data integrity verification In this embodiment, the system performs integrity verification before each data access, which specifically includes the following process: Each stored data block is verified through a hash algorithm or digital signature to ensure the consistency of the data block content. Any illegal data modification can be detected immediately when accessed, triggering a warning or blocking further access. This mechanism can effectively prevent attacks such as data tampering and malware injection.

[0030] S10. Implement offline data backup and recovery In this embodiment, when a USB flash drive is connected, the system automatically backs up the files in the storage data block to a local encrypted storage device or cloud storage, providing a verification mechanism for data recovery; The backed-up data is encrypted and can only be restored in an authenticated environment. In addition, when tampering or damage to data blocks is detected, the system automatically restores the data from the backup and provides necessary security repair measures.

[0031] In this embodiment, the method can also perform mandatory updates and security audits on the access device. Each time a USB flash drive is connected, the system will enforce security updates on the device to ensure that the operating system, driver, and security software of the access device are in the latest version. This step can reduce the risk of the device being attacked due to security vulnerabilities, and at the same time, the audit mechanism records each access process in detail to ensure that all operations meet security requirements. Through this mandatory update and audit, it can be ensured that the device connected by the USB flash drive will not become a potential source of attack.

[0032] Embodiment 2: See also Figure 2-Figure 4 , based on the U disk security access method based on storage data block management described in Example 1, the method is specifically applied.

[0033] In step S2, we can build a random key generation formula model to generate an encryption key in the USB flash drive hardware controller. This key is used to encrypt and decrypt the data in each storage block.

[0034] The key random generation formula model is as follows: in, : The hardware key finally generated is used to encrypt and decrypt the data blocks in the USB flash drive.

[0035] : A cryptographic hash function that compresses all input data and generates a unique key. Common hash algorithms such as SHA-256 can be used here, but for greater security, we use a custom or improved hash function that makes it difficult to obtain the key through reverse or pre-calculation attacks.

[0036] and : These are two timestamps randomly collected based on the internal hardware characteristics of the USB flash drive, used to reflect small changes in the hardware status. They can be sampled from the clock signal of the USB flash drive microcontroller to represent the precise timing fluctuations when the USB flash drive is connected or started. and The differences will be minimal, but because they come from different modules of the hardware, they can provide unpredictable small deviations as the basis for randomness.

[0037] : is a combination of hardware features, depending on the unique physical properties of the USB flash drive when it is manufactured. Indicates the process differences caused by the manufacture of the USB flash drive (such as the initial state of the register, small differences in capacitance and resistance, etc.). Indicates environmental factors (such as current or temperature fluctuations when the device is plugged in). The UUID is a unique identifier for the device. ,These physical characteristics and environmental information are combined together to generate a ,specific hardware feature sequence for enhancing the uniqueness of key generation.

[0038] :It is a real-time random sampling function, based on the instantaneous random number generator (RNG) connected to the USB flash drive, which collects randomness from tiny electromagnetic noise, environmental thermal noise or natural fluctuations generated by other hardware. It is a dynamically changing parameter, ensuring that even the same device generates completely different keys at different times.

[0039] : is an exclusive OR operator that mixes the individual random and physical input values ​​so that even if one input changes slightly, the final key It will also change drastically, increasing the unpredictability of the key.

[0040] When used, the model includes: Initialize the hardware encryption key: When the USB flash drive is connected for the first time, the hardware controller will start the key generation process by collecting the physical characteristics of the USB flash drive and the state of the flash drive at the moment of connection. and , respectively grab two time points from the hardware clock signal to introduce randomness. Since the slight difference between the two timestamps comes directly from the physical layer, this timing fluctuation cannot be simulated or reproduced by software, which increases the uniqueness and unpredictability of hardware encryption.

[0041] Generate unique keys based on physical properties: We combine the physical characteristics formed during the hardware manufacturing process (such as the electrical characteristics of transistors, voltage fluctuations during startup, etc.) with the device's unique identifier (UUID) to ensure that the key generated for each USB flash drive is unique at the hardware level. Even USB flash drives produced in the same batch will have slight differences in these physical characteristics, so the same key will not be generated.

[0042] Enhance randomness and ensure security: At the same time, The introduction of ensures that the generated key is still random every time the device is accessed, even at the same time. By using the noise collected from the hardware level as the source of the random number generator, it ensures that even if an attacker obtains the internal information of the USB flash drive, it is impossible to predict or calculate the generated key in advance.

[0043] Hash compression and key generation: Ultimately, all of these inputs are passed through a hash function Compression is performed to ensure that the output key length is constant and that the keys generated by different inputs are significantly different (even if only a small number of input bits are changed). This makes each key generation highly random and unpredictable. The application of hash functions can also resist some common cryptographic attacks, such as collision attacks.

[0044] Key storage and use: After the key is generated, it is stored in the secure storage area of ​​the USB flash drive and encrypted by dedicated hardware. Every time a storage block is accessed, the hardware controller will decrypt and encrypt the data using this key to ensure security at the data block level. When an unauthorized device is connected, this key cannot be obtained by external means, thus preventing illegal access.

[0045] The above process ensures that even the most complex attack methods will find it difficult to reversely calculate the correct encryption key without hardware support, providing extremely high security for block-level encryption of USB flash drives.

[0046] In step S5, we build an access rights allocation model to dynamically generate access rights for each data block based on the specific attributes of the USB storage block, file type, device environment and other multi-dimensional information. We can implement strict and flexible permission control at the storage block level to ensure data security and access effectiveness.

[0047] The access rights allocation model is as follows: in, : Data Block This value determines whether the data block can be read, written, or executed, and even whether additional authentication or encryption operations are required.

[0048] : The main permission function takes into account the category, sensitivity, access policy, device environment and user identity of the data block to calculate the basic access rights.

[0049] : Data Block There are categories such as configuration files, log files, user data, system files, etc. This is determined by the type of data stored in the data block, and each category has a preset basic permission strategy.

[0050] : Data Block The sensitivity level of a data block is divided into multiple levels, such as low, medium, and high. The sensitivity level determines whether the data block requires mandatory encryption or a high level of access control.

[0051] : Data Block The access policy is a preset set of permission rules, such as read-only, read-write, execute-only, etc. This policy can be set when the system is initialized or adjusted according to dynamic needs.

[0052] : The environmental security level of the access device, which is a scalar representation of the security environment of the device to which the USB flash drive is connected. The device environment may include the network isolation level, the trust level of the device, whether it is a personal device or a public device, etc. If the device is in an untrusted environment, the permissions will be automatically reduced.

[0053] : User authentication level, which is used to indicate the authentication strength of the current visitor, such as ordinary user, administrator, multi-factor authentication, etc. Higher authentication requirements can provide higher levels of access rights to certain sensitive data blocks.

[0054] : Dynamic weight function, used to adjust the main authority function It takes into account the file characteristics, location and time factors of the data blocks.

[0055] : File characteristics, such as the file's creation time, size, format, etc. These characteristics can dynamically adjust permissions based on the latest status of the file, for example, old or expired files may restrict access.

[0056] : The logical location of a data block, indicating the physical location or partition location of the data block in the USB drive. For example, some areas may be dedicated to system files with stricter access control, while other areas store ordinary user data.

[0057] : Time factor, used to dynamically adjust permissions based on the timestamp or time range of the access. For example, higher permissions may be granted to specific data blocks during certain working hours, while access may be restricted during non-working hours.

[0058] When used, the model includes: Data block category identification and basic permission allocation: When a USB flash drive is connected to the system, the files in the storage block will be classified first. to identify the category of each storage block. For example, configuration files can be set to read-only, while user data can be set to read and write permissions. Next, based on the category, the system checks (sensitivity) and (Access Policy) to further refine the permission assignment. If the data block stores highly sensitive data, the permission will be automatically set to require a higher level of verification.

[0059] Dynamic adjustment of access device environment and user identity: When a USB flash drive is connected to a device, the system will detect the device's environmental security level , such as whether the network where the device is located is a trusted network, whether the device's operating system has known vulnerabilities, etc. If the device is not in a trusted environment, the system will automatically adjust permissions, such as setting sensitive data blocks to read-only or completely prohibiting access. At the same time, user identity authentication The permission level of the current user is evaluated. Only users with strong authentication (such as multi-factor authentication) can access sensitive data blocks, while ordinary users may be restricted to low permission levels.

[0060] Dynamic weight adjustment function: After the main permission function determines the basic permissions, the system will use The function dynamically adjusts permissions. For example, if the file features Indicates that a file is outdated, and the system will further restrict its access rights to prevent expired data from being modified. , these partitions may be pre-set to have a higher security level (such as the area storing the operating system boot files), and the permissions will be elevated. It also has a dynamic impact on permissions. For example, access rights to data blocks can be restricted during non-working hours according to security policies, or certain files can only be accessed during specific time periods.

[0061] Actual access control enforcement: Ultimately, Represents the actual access rights of each data block. This value controls access behavior in real time, ensuring that data blocks can be correctly read, written, or executed only when the conditions are met. The system recalculates the access rights based on the current conditions at each access operation. , to ensure the dynamic adaptability of permissions. In this way, even if the environment, time, and user identity change during the use of the USB flash drive, the access permissions will be automatically adjusted to ensure the security of the data block.

[0062] This model is different from the traditional static access control strategy. It integrates multiple factors such as data block category, file characteristics, device environment and user identity authentication. It can flexibly adjust the permission control of data blocks according to multiple conditions, providing a fine-grained, highly adaptable and dynamically adjusted access control mechanism, effectively improving the data security during the USB flash drive access process.

[0063] In step S7, the goal of implementing dynamic encryption and data block steganography is to provide strong security protection at the data block level, while ensuring the confidentiality of the steganographic information and the normal accessibility of the data. In order to achieve this goal, a dynamic encryption and data block steganography model is designed to combine encryption and steganography together, ensuring that while the data block is encrypted, the encryption key is embedded into the data itself through steganography technology, making it impossible for unauthorized users to identify and decrypt the data.

[0064] The dynamic encryption and data block steganography model is as follows: in, : Encrypted and steganographic data block .

[0065] : For the original data block Function to perform encryption, using encryption key .

[0066] : Steganographic function, used to convert the key Steganography to storage data blocks The steganographic method is to cleverly embed the key into the irrelevant or redundant bits of the data block to ensure that it does not affect the normal reading of the original data.

[0067] :The steganographic strategy changes dynamically with different data blocks, ensuring that the steganographic process cannot be detected by patterning. It is determined by the characteristics of the data block (such as size, type, access frequency, etc.), making the steganographic scheme highly random and adaptable.

[0068] : Each data block The unique encryption key is generated by the hardware key mechanism or other encryption algorithm generated in the previous step. This key is not only used for data encryption, but also embedded in the data block through steganography technology to ensure that the key cannot be directly obtained without affecting the normal transmission and storage of data.

[0069] When used, the model includes: Data block encryption process: When a data block When written to a USB drive, the unique encryption key is first used Encrypt it. This encryption key can be obtained from the hardware key generation process mentioned in the previous step to ensure the randomness and uniqueness of the key. This means that even if the data block is read by an external attacker, it is difficult to restore the original data through conventional means.

[0070] Key Steganography Process: While data is being encrypted, the key It needs to be stored securely for subsequent decryption. At this time, the steganographic function comes into play. This function selects the key according to the characteristics of each data block. Steganography in data blocks Some redundant bits or non-critical bits, such as the least significant bits of pixels or audio samples, or some data bits used for verification. is the steganographic strategy, which defines the specific location and mode of steganography. It is dynamically generated, based on the specific characteristics of the data block, which ensures the randomness and unpredictability of the steganography and prevents the steganographic pattern from being recognized or detected.

[0071] Dynamic adjustment of steganography strategy: steganography strategy It is not fixed, but will be dynamically adjusted according to different characteristics of the data block, such as the size, format, access frequency, sensitivity and other factors of the data. For example, a data block storing a text file may choose to steganographically store the least significant bit of its character encoding, while for image or audio files, the steganographic strategy may involve using the color of the data or irrelevant bits in the audio waveform. The dynamic nature of the steganographic strategy ensures that different types of files can flexibly adapt to different steganographic schemes, while enhancing the anti-analysis ability of steganography.

[0072] Access and decryption process: When an authorized user or device needs to read the data in the USB flash drive, it must first pass device authentication or user identity authentication to unlock the steganographic key. Authenticated devices and users can access the data block Extract the steganographic key from , and then use the key to decrypt the encrypted content. This decryption process is transparent to the user and does not require additional steps, ensuring a good user experience.

[0073] Resistant to reverse engineering and attacks: Even if an attacker can obtain the encrypted data blocks in the USB flash drive, , because the key Has been hidden inside the data block, and the steganographic mode Being highly random, they are difficult to extract the key through reverse engineering.

[0074] Security improvements of dynamic encryption and steganography: Since data is constantly encrypted during transmission or storage, even if an attacker obtains part of the encrypted data, the next data transmission may use a different encryption key. and steganographic strategies , making it difficult for attacks to continue. Each generation of encryption keys and steganographic patterns is based on real-time hardware characteristics and dynamic strategies, so each generated encryption and steganographic method is unique and difficult to reproduce.

[0075] In step S8, the USB flash drive can rely on two methods: a preset time delay and an external signal trigger. Through these two triggering methods, we can ensure that the data can be destroyed quickly and safely to avoid leakage in the event of external threats or abnormal situations.

[0076] The preset time delay is a timer-based triggering method that can be used to manage the countdown after the USB flash drive is connected to the device. Once the set time point is reached and no legal access or authorization is detected within the time, the mechanism will automatically trigger the self-destruction of the data block. In order to ensure the flexibility and adaptability of the time trigger mechanism, a dynamic time delay scheme can be designed.

[0077] External signal triggering is a more proactive and flexible method that relies on the device's real-time monitoring system. Once the USB flash drive detects an abnormal event, such as virus infection, network attack, illegal access or physical disassembly attempt, it will immediately activate the self-destruct mechanism. To achieve this, the hardware controller and firmware inside the USB flash drive can continuously monitor various external signals and decide whether to activate the self-destruct mechanism based on different signal levels.

[0078] The beneficial effects of the present invention are: This USB flash drive security access method based on storage data block management and control can achieve refined security management at the data block level through hardware key encryption, data block category division of access rights, dynamic encryption and steganography technology, data integrity verification and self-destruction mechanism and other security means. This method not only improves the security of data transmission and storage, but also provides real-time integrity verification and self-destruction mechanism to effectively prevent data tampering, illegal access and physical attacks. At the same time, through flexible management and dynamic encryption of different data blocks, stronger anti-attack capabilities and data confidentiality are achieved, meeting the application requirements in high-security demand scenarios.

[0079] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0080] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A USB flash drive secure access method based on storage data block management and control, characterized in that: The following steps are involved: S1, determine the storage data block structure of the USB flash drive; S2, initializing hardware key encryption of storage data blocks; S3, configure the access control module of the USB flash drive; S4. Load the security policy of the access device; S5. Allocate access rights according to storage data block categories; S6. Detect and record USB access behavior; S7, implement dynamic encryption and data block steganography; S8, setting a storage data block self-destruction mechanism; S9, build USB disk data integrity verification; S10. Implement offline data backup and recovery.

2. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In the step S1, the physical storage structure of the USB flash drive is analyzed, including a plurality of storage data blocks, each storage data block being provided with a unique physical address; Develop clear access and security policies for each storage data block, divide the USB storage into different security areas, and only allow specific operating systems or applications to access each area; At the same time, different encryption strategies are implemented for different storage data blocks to ensure that the data cannot be easily read even if the USB flash drive is physically accessed or copied.

3. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S2, a hardware-level encryption key is initialized in the hardware controller of the USB flash drive, and the key is used to encrypt the content stored in each data block of the USB flash drive; During initialization, the key is randomly generated and saved in the secure storage area of ​​the USB flash drive. Any illegal device or unauthorized access will cause encryption failure. Each time the USB flash drive is connected, the hardware key is used to perform data decryption and encryption operations.

4. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S3, before accessing the system, an access control module is configured inside the USB flash drive, which is responsible for verifying the accessed device; By integrating an authentication mechanism, such as multi-factor authentication or fingerprint-based authentication, the USB drive can only be accessed on authorized devices. Each time it is connected, the USB flash drive first verifies the identity of the connected device. If the device authentication fails, the USB flash drive will be locked or only provide read-only access.

5. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S5, different storage data blocks store different types of files, including configuration files, log files, and user data; Different access permissions are set for stored data blocks according to their categories. Sensitive data blocks are protected by encryption or mandatory user identity authentication. Access control is not only based on device type and device identity, but also dynamically adjusted based on specific file types or data block locations.

6. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S6, the system detects and logs the access behavior in real time. Each USB access, file reading and writing, and file operation behavior is recorded in detail and encrypted and stored. The system monitors in real time whether the files in the USB flash drive are accessed or tampered with by unauthorized programs, and issues a warning when an abnormality is found.

7. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S7, when the data is written to the USB flash drive, the system encrypts each storage data block in real time and embeds the encryption key into the storage data block through steganography without affecting normal data access; At the same time, only authenticated devices and users can correctly extract the key and decrypt the data.

8. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S8, once it is found that the device connected to the USB flash drive is in an untrusted state, or an abnormal security threat occurs, i.e., virus infection or network attack, the USB flash drive automatically starts the data block self-destruction mechanism; Sensitive data in the USB flash drive is completely deleted or encrypted in a short period of time and cannot be recovered; it is automatically executed when a threat is detected, either through a time delay preset in the USB flash drive's hardware controller or triggered by an external signal.

9. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In step S9, the system performs integrity verification before each data access. The following processes are included: Each stored data block is verified through a hash algorithm or digital signature to ensure the consistency of the data block content. Any illegal data modification can be detected immediately during access and trigger a warning or prevent further access.

10. A USB flash drive secure access method based on storage data block management and control according to claim 1, characterized in that: In the step S10, when the USB flash drive is connected, the system automatically backs up the files in the storage data block to a local encrypted storage device or cloud storage, providing a verification mechanism for data recovery; The backed-up data is encrypted and can only be restored in an authenticated environment. In addition, when tampering or damage to data blocks is detected, the system automatically restores the data from the backup and provides necessary security repair measures.