Solid state disk main control chip security key generation system

By designing a security key generation system in the SSD main control chip, using data access links and encryption keys to protect the key information, the security risks caused by the SSD key information relying on CPU reading are solved, and the security of the SSD is improved.

CN120030612AActive Publication Date: 2025-05-23ZHEJIANG RUIZHAOXIN SEMICON TECH CO LTD
View PDF 15 Cites 0 Cited by

Patent Information

Application Number
CN202510517551.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-23
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

In the prior art, the key information of the solid-state hard disk (SSD) master control chip relies on the CPU to read directly, which poses serious security risks, especially when the host software is attacked, the key information is easily obtained by hackers.

Method used

Design a secure key generation system for solid-state hard disk master chip, including a monitoring center, data reading module, data processing module, data encryption module and key generation module. By reading information from the solid-state drive and external environment, a data access link is built and an encryption key is generated. The data access link is encrypted through the encryption key to ensure that the key information is not illegally accessed.

Benefits of technology

By generating and encrypting the key, the problem of traditional keys relying on CPU reading is solved, the security of the solid-state drive is improved, and the key information is prevented from being illegally obtained when the host software is attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030612A_ABST
    Figure CN120030612A_ABST
Patent Text Reader

Abstract

The invention discloses a security key generation system for a main control chip of a solid state disk, which relates to the technical field of data security, and respectively generates corresponding keys according to hard disk data information of the solid state disk and external environment information of an external access main body connected with the solid state disk, constructing a data access link for connecting the solid state disk and the external access main body according to each monitoring item in the initial state of the external access main body, fitting the generated secret key, and encrypting the data access link, so that the data access link is encrypted after the external environment information of the external access main body is changed. Therefore, the solid state disk cannot be accessed through the constructed data access link, so that the problems that the data of the solid state disk is protected by completely depending on an encryption key in the traditional sense, and the encryption key is directly read by completely depending on a CPU (Central Processing Unit) of an external access main body are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular to a solid state hard disk master control chip security key generation system. Background Art

[0002] SSD data storage has gradually become the main storage medium for consumer device data storage and cloud storage. The security performance of the SSD main control chip, as the brain of the SSD storage device, directly determines the overall security performance of the SSD hard disk. The key, as the core of the entire security system, is the top priority for SSD data security. At present, the configuration and calculation of key information are still directly read by the CPU. As a result, once the CPU software system is hacked, hackers can directly read all key information through the CPU, which poses a serious security risk. How to optimize the security of the SSD master chip key so that the key in the master chip can be protected from being read when the host software is attacked is a problem we need to solve. To this end, a solid state drive master chip security key generation system is now provided. Summary of the invention

[0003] The purpose of the present invention is to provide a solid state hard disk master chip security key generation system.

[0004] The object of the present invention can be achieved by the following technical solutions: A solid state hard disk master chip security key generation system, including a monitoring center, the monitoring center is communicatively connected with a data reading module, a data processing module, a data encryption module and a key generation module; The data reading module is used to read the hard disk data information and external environment information in the solid state hard disk; The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid state drive with the external environment through the data access link; The data encryption module is used to encrypt the hard disk data information read and obtain a corresponding encryption key; The key generation module is used to generate a double encryption key according to the initial state of the external access subject, and fit the double encryption key with the single encryption key to obtain the corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key.

[0005] Furthermore, the process of the data reading module reading hard disk data information in the solid state hard disk includes: Scan the solid state drive to obtain each storage space in the solid state drive and obtain the storage address corresponding to each storage space; Read the data information stored in each storage space, and associate the read data information with the corresponding storage address; Fitting the associated storage addresses and data information to obtain hard disk space data corresponding to each storage space; Obtain hard disk data information of the solid state disk, wherein the hard disk data information includes a maximum capacity of the hard disk, a total amount of hard disk data storage, a storage address of each storage space, and a size of hard disk space data corresponding to the storage space.

[0006] Furthermore, the process of the data reading module reading external environment information includes: Mark the host to which the solid-state hard disk is connected as an external access subject, and obtain external environment information corresponding to the external access subject, wherein the external environment information includes network environment security information of the external access subject and the subject's own security information; When there is a risk in any of the network environment security information of the external access subject and the subject's own security information, the solid-state drive will not be linked to the external access subject; When the network environment security information of the external access subject and the subject's own security information are normal, the external access subject in the current state is marked as the initial state.

[0007] Furthermore, the data processing module constructs a corresponding data access link according to the read external environment information, and links the solid state drive with the external environment through the data access link, including: Read the external environment information of the external access subject in the initial state, and obtain the corresponding monitoring items and the state quantity corresponding to each monitoring item; Integrate each monitoring item and the corresponding state quantity to obtain external subject state data; According to the external subject status data, a corresponding data access link consisting of data interaction nodes consistent with the number of monitoring items is constructed; The solid state hard disk is linked to the external access subject via the data access link.

[0008] Furthermore, the data encryption module encrypts the hard disk data information read and obtains a corresponding encryption key, which includes: According to the storage addresses of the storage spaces in the hard disk data information, a blank unit item associated with the storage address is constructed; Sorting the blank cell items according to the hard disk space data size in the storage space corresponding to the associated storage address, and generating a corresponding sequence code in each blank cell item; Integrate the obtained serial codes to obtain the corresponding hard disk information sequence; Binding the obtained hard disk information sequence to the hard disk data information node; Convert the obtained hard disk information sequence into a data stream composed of several binary codes; Set the polynomial and get the highest power of the set polynomial; Then, according to the highest power of the set polynomial, a corresponding number of "0"s are added to the end of the data stream to obtain a data stream to be processed; Perform modulo 2 division of the obtained data stream to be processed on the set polynomial to obtain corresponding data stream K1 and data stream K2; According to the number of binary codes constituting the data stream K2, the data stream K1 is divided into a plurality of data stream segments, the number of binary unit codes of the data stream segments being the same as the number of binary codes of the data stream K2; if the number of divided data stream segments does not meet the number of binary codes of the data stream K2, "0" is added to the end of the corresponding data stream segment until the number of binary codes meets the requirement; Perform an XOR operation on each data stream segment and the data stream K2 to obtain a corresponding XOR code, and convert the obtained XOR code into a number having the same base as the highest power of the set polynomial G(x), which is recorded as a key unit; The obtained key units are integrated, and the integrated result is used as a first encryption key, and the hard disk data information is encrypted by the obtained first round encryption key.

[0009] Furthermore, the process of the key generation module generating a double encryption key according to the initial state of the external access subject includes: According to the external subject state data of the external access subject in the initial state obtained, a corresponding initial state code is generated according to the monitoring items in the external subject state data; The obtained initial state codes are combined to obtain a data stream consisting of binary codes having the same number of monitoring items as that of the external access subject in the initial state; Associating the obtained data stream with a corresponding initial permission code; After the initial permission code is added to the front end of the data stream, the obtained new data stream is used as a double encryption key.

[0010] Furthermore, the double encryption key is fitted with the single encryption key to obtain a corresponding encryption key, and the process of encrypting the data access link by using the encryption key includes: Importing the generated primary encryption key and secondary encryption key into each data interaction node in the data access link; The double encryption key is converted into a key unit of the same base as the single encryption key, and the obtained key unit is added to the end of the single encryption key, thereby completing the fitting of the single encryption key and the double encryption key to obtain the corresponding encryption key; Each data interaction node in the data access link is encrypted using the obtained encryption key.

[0011] Compared with the prior art, the present invention has the following beneficial effects: According to the hard disk data information of the solid-state hard disk and the external environment information of the external access subject connected to the solid-state hard disk, corresponding keys are generated respectively, and then a data access link for connecting the solid-state hard disk and the external access subject is constructed according to various monitoring items in the initial state of the external access subject. After the generated key is fitted, the data access link is encrypted, so that when the external environment information of the external access subject changes, the solid-state hard disk cannot be accessed through the constructed data access link, thereby avoiding the problem of completely relying on encryption keys to protect the solid-state hard disk data in the traditional sense, and the encryption keys are completely dependent on the CPU of the external access subject to read directly, thereby improving the security of the solid-state hard disk. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0013] Figure 1 It is a schematic diagram of the present invention. DETAILED DESCRIPTION

[0014] like Figure 1 As shown, a solid state hard disk master chip security key generation system includes a monitoring center, and the monitoring center is communicatively connected with a data reading module, a data processing module, a data encryption module and a key generation module; The data reading module is used to read the hard disk data information and external environment information in the solid state hard disk; The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid state drive with the external environment through the data access link; The data encryption module is used to encrypt the hard disk data information read and obtain a corresponding encryption key; The key generation module is used to generate a double encryption key according to the initial state of the external access subject, and fit the double encryption key with the single encryption key to obtain the corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key.

[0015] It should be further explained that, in a specific implementation process, the process of the data reading module reading the hard disk data information in the solid state hard disk includes: Scan the solid state drive to obtain each storage space in the solid state drive and obtain the storage address corresponding to each storage space; Read the data information stored in each storage space, and associate the read data information with the corresponding storage address; Fitting the associated storage addresses and data information to obtain hard disk space data corresponding to each storage space; Obtain hard disk data information of the solid state disk, wherein the hard disk data information includes a maximum hard disk capacity, a total amount of hard disk data storage, a storage address of each storage space, and a size of hard disk space data corresponding to the storage space.

[0016] It should be further explained that, in a specific implementation process, the process of the data reading module reading the external environment information includes: Mark the host to which the solid-state hard disk is connected as an external access subject, and obtain external environment information corresponding to the external access subject, wherein the external environment information includes network environment security information of the external access subject and the subject's own security information; When there is a risk in any of the network environment security information of the external access subject and the subject's own security information, the solid-state drive will not be linked to the external access subject; When the network environment security information of the external access subject and the subject's own security information are normal, the external access subject in the current state is marked as the initial state.

[0017] It should be further explained that, in the specific implementation process, the data processing module constructs a corresponding data access link according to the read external environment information, and the process of linking the solid state drive with the external environment through the data access link includes: Read the external environment information of the external access subject in the initial state, and obtain the corresponding monitoring items and the state quantity corresponding to each monitoring item, wherein the state quantity includes "normal" and "risk", and the state quantity of each monitoring item in the initial state is "normal"; Integrate each monitoring item and the corresponding state quantity to obtain external subject state data; According to the external subject status data, a corresponding data access link consisting of data interaction nodes consistent with the number of monitoring items is constructed; The solid state hard disk is linked to the external access subject via the data access link.

[0018] It should be further explained that, in a specific implementation process, the data encryption module encrypts the hard disk data information read and obtains the corresponding encryption key, including: According to the storage addresses of the storage spaces in the hard disk data information, a blank unit item associated with the storage address is constructed; Sorting the blank cell items according to the hard disk space data size in the storage space corresponding to the associated storage address, and generating a corresponding sequence code in each blank cell item; Integrate the obtained serial codes to obtain the corresponding hard disk information sequence; Binding the obtained hard disk information sequence to the hard disk data information node; it should be further explained that, in the specific implementation process, after the hard disk information sequence is node-bound to the hard disk data information, the user can reset the data information in the solid state drive to the hard disk data information bound to the hard disk information sequence according to the hard disk information sequence; Convert the obtained hard disk information sequence into a data stream composed of several binary codes; Set the polynomial G(x) and get the highest power of the set polynomial; Then, according to the highest power of the set polynomial, a corresponding number of "0"s are added to the end of the data stream to obtain a data stream to be processed; Perform modulo 2 division of the obtained data stream to be processed on the set polynomial G(x) to obtain corresponding data stream K1 and data stream K2, where K1 is the quotient and K2 is the remainder; According to the number of binary codes constituting the data stream K2, the data stream K1 is divided into a plurality of data stream segments, the number of binary unit codes of the data stream segments being the same as the number of binary codes of the data stream K2; if the number of divided data stream segments does not meet the number of binary codes of the data stream K2, "0" is added to the end of the corresponding data stream segment until the number of binary codes meets the requirement; Perform an XOR operation on each data stream segment and the data stream K2 to obtain a corresponding XOR code, and convert the obtained XOR code into a number having the same base as the highest power of the set polynomial G(x), which is recorded as a key unit; The obtained key units are integrated, and the integrated result is used as a first encryption key, and the hard disk data information is encrypted by the obtained first round encryption key.

[0019] It should be further explained that, in a specific implementation process, the process in which the key generation module generates a double encryption key according to the initial state of the external access subject includes: According to the external subject state data of the external access subject in the initial state obtained, a corresponding initial state code is generated according to the monitoring items in the external subject state data; Specifically, the initial status code generates "1" when the status of the monitoring item is "normal", and generates "0" when the status of the monitoring item is "risk". The obtained initial state codes are combined to obtain a data stream composed of binary codes with the same number of monitoring items as the initial state of the external access subject, and the binary codes constituting the data stream are all "1"; Associating an initial permission code corresponding to the obtained data stream, wherein the initial permission code is "0"; After the initial permission code is added to the front end of the data stream, the obtained new data stream is used as a double encryption key.

[0020] It should be further explained that, in the specific implementation process, the double encryption key is fitted with the single encryption key to obtain the corresponding encryption key, and the process of encrypting the data access link by the encryption key includes: Importing the generated primary encryption key and secondary encryption key into each data interaction node in the data access link; The double encryption key is converted into a key unit of the same base as the single encryption key, and the obtained key unit is added to the end of the single encryption key, thereby completing the fitting of the single encryption key and the double encryption key to obtain the corresponding encryption key; Each data interaction node in the data access link is encrypted using the obtained encryption key.

[0021] It should be further explained that, in the specific implementation process, after completing the encryption of each data interaction node in the data access link, when the external access subject needs to access the solid-state hard disk through the data access link, the monitoring item of the external access subject and whether the state quantity of the monitoring item has changed are obtained. If neither the monitoring item nor the state quantity of the monitoring item has changed, the external access subject directly accesses the solid-state hard disk through the data access link. If either the monitoring item or the state quantity of the monitoring item has changed, the access qualification of the data access link is adjusted according to the change of the monitoring item. Changes in monitoring items include: the number of monitoring items remains unchanged, the status of monitoring items is "normal", and the content changes, such as a monitoring item in the initial state is changed to another monitoring item, and the monitoring item is different from any of the original monitoring items; Then the data interaction node corresponding to the original monitoring item in the data access link fails, and the external access subject's access to the solid-state hard disk through the data access link is cut off. Then the user needs to rebuild the corresponding data access link according to the external subject state data of the external access subject in the current state; Changes in monitoring items also include: the number of monitoring items decreases, and the status quantities of the monitoring items are all "normal", then the data interaction nodes corresponding to the missing monitoring items in the data access link fail, and the external access subject's access to the solid-state hard disk through the data access link is cut off. The user needs to rebuild the corresponding data access link based on the external subject status data of the external access subject in the current state.

[0022] The changes of monitoring items also include: if the number of monitoring items increases and all original monitoring items are retained and the status quantities of the monitoring items are all "normal", a temporary data interaction node is generated according to the added monitoring items, and the temporary data interaction node is updated to the data access link; Generate corresponding permission codes according to the added data interaction nodes, add the generated permission codes to the double encryption key, and obtain a new encryption key. The new encryption key can only access the SSD through the new data access link, and the original data access link has higher permissions than the new data access link. When the SSD is attacked, the user can access the SSD through the original data access link and reset the SSD to the state before the attack through the hard disk information sequence. The user accesses the solid state drive through the updated data access link.

[0023] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment as above, it is not used to limit the present invention. Any technical personnel in this field can make some changes or modify the technical contents disclosed above into equivalent embodiments with equivalent changes without departing from the scope of the technical solution of the present invention. However, any modification or equivalent replacement of the above embodiments made according to the technical essence of the present invention without departing from the content of the technical solution of the present invention still falls within the scope of the technical solution of the present invention.

Claims

1. A solid state hard disk master chip security key generation system, including a monitoring center, characterized in that: The monitoring center is communicatively connected to a data reading module, a data processing module, a data encryption module and a key generation module; The data reading module is used to read the hard disk data information and external environment information in the solid state hard disk; The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid state drive with the external environment through the data access link; The data encryption module is used to encrypt the hard disk data information read and obtain a corresponding encryption key; The key generation module is used to generate a double encryption key according to the initial state of the external access subject, and fit the double encryption key with the single encryption key to obtain the corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key.

2. A solid state drive master chip security key generation system according to claim 1, characterized in that: The process of the data reading module reading hard disk data information in the solid state hard disk includes: Scan the solid state drive to obtain each storage space in the solid state drive and obtain the storage address corresponding to each storage space; Read the data information stored in each storage space, and associate the read data information with the corresponding storage address; Fitting the associated storage addresses and data information to obtain hard disk space data corresponding to each storage space; Obtain hard disk data information of the solid state disk, wherein the hard disk data information includes a maximum hard disk capacity, a total amount of hard disk data storage, a storage address of each storage space, and a size of hard disk space data corresponding to the storage space.

3. A solid state drive master chip security key generation system according to claim 2, characterized in that: The process of the data reading module reading external environment information includes: Mark the host to which the solid-state hard disk is connected as an external access subject, and obtain external environment information corresponding to the external access subject, wherein the external environment information includes network environment security information of the external access subject and the subject's own security information; When there is a risk in any of the network environment security information of the external access subject and the subject's own security information, the solid-state drive will not be linked to the external access subject; When the network environment security information of the external access subject and the subject's own security information are normal, the external access subject in the current state is marked as the initial state.

4. A solid state drive master chip security key generation system according to claim 3, characterized in that: The data processing module constructs a corresponding data access link according to the read external environment information, and the process of linking the solid state drive with the external environment through the data access link includes: Read the external environment information of the external access subject in the initial state, and obtain the corresponding monitoring items and the state quantity corresponding to each monitoring item; Integrate each monitoring item and the corresponding state quantity to obtain external subject state data; According to the external subject status data, a corresponding data access link consisting of data interaction nodes consistent with the number of monitoring items is constructed; The solid state hard disk is linked to the external access subject via the data access link.

5. A solid state drive master chip security key generation system according to claim 4, characterized in that: The data encryption module encrypts the hard disk data information read and obtains the corresponding encryption key, which includes: According to the storage addresses of the storage spaces in the hard disk data information, a blank unit item associated with the storage address is constructed; Sorting the blank cell items according to the hard disk space data size in the storage space corresponding to the associated storage address, and generating a corresponding sequence code in each blank cell item; Integrate the obtained serial codes to obtain the corresponding hard disk information sequence; Binding the obtained hard disk information sequence to the hard disk data information node; Convert the obtained hard disk information sequence into a data stream composed of several binary codes; Set the polynomial and get the highest power of the set polynomial; Then, according to the highest power of the set polynomial, a corresponding number of "0"s are added to the end of the data stream to obtain a data stream to be processed; Perform modulo-2 division of the obtained data stream to be processed on the set polynomial to obtain corresponding data stream K1 and data stream K2; According to the number of binary codes constituting the data stream K2, the data stream K1 is divided into a number of data stream segments, the number of binary unit codes of the data stream segments is the same as the number of binary codes of the data stream K2. If the number of divided data stream segments does not meet the number of binary codes of the data stream K2, "0" is added to the end of the corresponding data stream segment until the number of binary codes meets the requirement; Perform an XOR operation on each data stream segment and the data stream K2 to obtain a corresponding XOR code, and convert the obtained XOR code into a number having the same base as the highest power of the set polynomial G(x), which is recorded as a key unit; The obtained key units are integrated, and the integrated result is used as a first encryption key, and the hard disk data information is encrypted by the obtained first round encryption key.

6. A solid state drive master chip security key generation system according to claim 5, characterized in that: The process of the key generation module generating a double encryption key according to the initial state of the external access subject includes: According to the external subject state data of the external access subject in the initial state obtained, a corresponding initial state code is generated according to the monitoring items in the external subject state data; The obtained initial state codes are combined to obtain a data stream composed of binary codes having the same number of monitoring items as that of the external access subject in the initial state; Associating the obtained data stream with a corresponding initial permission code; After the initial permission code is added to the front end of the data stream, the obtained new data stream is used as a double encryption key.

7. A solid state drive master chip security key generation system according to claim 6, characterized in that: The process of fitting the double encryption key with the single encryption key to obtain the corresponding encryption key and encrypting the data access link by using the encryption key includes: Importing the generated primary encryption key and secondary encryption key into each data interaction node in the data access link; The double encryption key is converted into a key unit of the same base as the single encryption key, and the obtained key unit is added to the end of the single encryption key, thereby completing the fitting of the single encryption key and the double encryption key to obtain the corresponding encryption key; Each data interaction node in the data access link is encrypted using the obtained encryption key.

Citation Information

Patent Citations

  • Secure processor with external memory using block chaining and block re-ordering

    CA2249554A1

  • Hard drive data write / read method and device

    CN102930224A

  • Method and system for controlling access to wireless apparatuses

    CN105594154A

  • Secret key information processing method, secret key information processing apparatus, electronic device and computer readable storage medium

    CN109412791A

  • Time-frequency DOA estimation method

    CN110046326A