A security key generation system for a solid-state drive host controller chip
The SSD main control chip security key generation system addresses CPU vulnerability by generating and integrating dual encryption keys based on SSD and external environment data, enhancing SSD security by adapting to environmental changes and reducing CPU reliance.
Patent Information
- Application Number
- CN202510517551.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-24
AI Technical Summary
In the prior art, the SSD master chip key information is read directly by the CPU, resulting in serious security risks when the host software is attacked and the key cannot be effectively protected from reading.
A solid-state hard disk master chip security key generation system is designed, including a monitoring center, data reading module, data processing module, data encryption module and key generation module. By building a data access link, a one- and two-fold encryption key is generated and fitted, the data access link is encrypted to ensure the security of the key.
It improves the security of the solid-state drive, prevents the key from being illegally accessed when the external environment changes, avoids dependence on traditional encryption keys, and enhances the protection ability during CPU software attacks.
Smart Images

Figure CN120030612B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and specifically to a security key generation system for a solid-state drive (SSD) main control chip. Background Art
[0002] SSD data storage has gradually become the main storage medium for consumer device data storage and cloud storage. As the "brain" of the SSD storage device, the security performance of the SSD main control chip directly determines the overall final security performance of the SSD hard disk. And the key, as the core of the entire security system, is the top priority of SSD data security. Currently, the configuration and operation of key information are still directly read by the CPU. This leads to the situation that once the software system of the CPU is hacked by hackers, the hackers can directly read all the key information through the CPU, posing a serious security risk.
[0003] How to optimize the security of the SSD main control chip key so that the key in the main control chip can be protected from being read when the host software is attacked is the problem we need to solve. For this purpose, a security key generation system for a solid-state drive main control chip is provided herein. Summary of the Invention
[0004] The purpose of the present invention is to provide a security key generation system for a solid-state drive main control chip.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A security key generation system for a solid-state drive main control chip includes a monitoring center, which is communicatively connected to a data reading module, a data processing module, a data encryption module, and a key generation module.
[0006] The data reading module is used to read the hard disk data information and external environment information in the solid-state drive.
[0007] The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid-state drive with the external environment through the data access link.
[0008] The data encryption module is used to encrypt the read hard disk data information and obtain a corresponding first-level encryption key.
[0009] The key generation module is used to generate a second-level encryption key according to the initial state of the externally connected entity, fit the second-level encryption key with the first-level encryption key to obtain a corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key.
[0010] Further, the process of the data reading module reading the hard disk data information in the solid-state drive includes:
[0011] Scan the solid-state drive to obtain each storage space within the solid-state drive and obtain the storage address corresponding to each storage space;
[0012] Read the data information stored in each storage space and associate the read data information with the corresponding storage address;
[0013] Fit the associated storage address and data information to obtain hard disk space data corresponding to each storage space;
[0014] Obtain the hard disk data information of the solid-state drive, where the hard disk data information includes the maximum hard disk capacity, the total amount of hard disk data stored, the storage addresses of each storage space, and the size of the hard disk space data corresponding to the storage space.
[0015] Further, the process by which the data reading module reads the external environment information includes:
[0016] Mark the host to which the solid-state drive is connected as an external access entity, and obtain the external environment information corresponding to the external access entity. The external environment information includes the network environment security information and the entity's own security information where the external access entity is located;
[0017] When there is a risk in either the network environment security information or the entity's own security information of the external access entity, the solid-state drive does not link with the external access entity;
[0018] When both the network environment security information and the entity's own security information of the external access entity are normal, mark the external access entity in the current state as the initial state.
[0019] Further, the process by which the data processing module constructs a corresponding data access link based on the read external environment information and links the solid-state drive with the external environment through the data access link includes:
[0020] Read the external environment information of the external access entity in the initial state and obtain the corresponding monitoring items and the status quantities corresponding to each monitoring item;
[0021] Integrate each monitoring item and the corresponding status quantity to obtain the external entity status data;
[0022] Construct a corresponding data access link composed of data interaction nodes with the same number as the monitoring items according to the external entity status data;
[0023] Link the solid-state drive with the external access entity through the data access link.
[0024] Further, the process by which the data encryption module encrypts the read hard disk data information and obtains the corresponding first-level encryption key includes:
[0025] According to the storage addresses of each storage space in the hard disk data information, and constructing blank cell items associated with the storage addresses;
[0026] Sort the blank cell items according to the hard disk space data size in the storage space corresponding to the associated storage address, and generate corresponding sequence codes in each blank cell item;
[0027] Integrate the obtained sequence codes to obtain the corresponding hard disk information sequence;
[0028] Bind the obtained hard disk information sequence to the hard disk data information node;
[0029] Convert the obtained hard disk information sequence into a data stream composed of several binary codes;
[0030] Set a polynomial and obtain the highest power of the set polynomial;
[0031] Then add the corresponding number of "0"s at the end of the data stream according to the highest power of the set polynomial to obtain the data stream to be processed;
[0032] Perform modulo-2 division on the obtained data stream to be processed by the set polynomial to obtain the corresponding data stream K1 and data stream K2;
[0033] According to the number of binary codes forming the data stream K2, divide the data stream K1 into several data stream segments. The binary unit codes of the data stream segments are the same as the number of binary codes of the data stream K2. If the number of divided data stream segments does not meet the number of binary codes of the data stream K2, add "0"s at the end of the corresponding data stream segments until the number of binary codes meets the requirement;
[0034] Perform exclusive OR operations on each data stream segment and the data stream K2 to obtain the corresponding exclusive OR codes, and convert the obtained exclusive OR codes into a number system with the same highest power as the set polynomial G(x), denoted as the key unit;
[0035] Integrate the obtained key units, and use the integration result as the first-level encryption key to encrypt the hard disk data information with the obtained round of encryption key.
[0036] Further, the process by which the key generation module generates the second-level encryption key according to the initial state of the externally connected entity includes:
[0037] According to the external entity status data of the external access entity in the obtained initial state, generate corresponding initial status codes according to the monitoring items in the external entity status data;
[0038] Combine the obtained initial status codes to obtain a data stream composed of binary codes with the same number as the monitoring items in the initial state of the external access entity;
[0039] Associate the obtained data stream with the corresponding initial permission code;
[0040] After adding the initial permission code to the front end of the data stream, use the obtained new data stream as the double encryption key.
[0041] Further, fit the double encryption key with the single encryption key to obtain the corresponding encryption key. The process of encrypting the data access link with the encryption key includes:
[0042] Import the generated single encryption key and double encryption key into each data interaction node in the data access link;
[0043] Convert the double encryption key into key units with the same base as the single encryption key, and add the obtained key units to the end of the single encryption key, so as to complete the fitting of the single encryption key and the double encryption key and obtain the corresponding encryption key;
[0044] Encrypt each data interaction node in the data access link with the obtained encryption key.
[0045] Compared with the prior art, the beneficial effects of the present invention are:
[0046] According to the hard disk data information of the solid-state drive and the external environment information of the external access entity connected to the solid-state drive, generate corresponding keys respectively, and then construct a data access link for connecting the solid-state drive and the external access entity according to each monitoring item in the initial state of the external access entity. After fitting the generated keys, encrypt the data access link, so that when the external environment information of the external access entity changes, the solid-state drive cannot be accessed through the constructed data access link, thus avoiding the problem that in the traditional sense, the protection of the solid-state drive data completely depends on the encryption key, and the encryption key completely depends on the CPU of the external access entity to directly read, thereby improving the security of the solid-state drive. Description of the Drawings
[0047] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0048] Figure 1 This is the schematic diagram of the present invention. Specific embodiments
[0049] As Figure 1 shown, a security key generation system for a solid-state drive master control chip includes a monitoring center, and the monitoring center is communicatively connected to a data reading module, a data processing module, a data encryption module, and a key generation module;
[0050] The data reading module is used to read the hard disk data information and external environment information in the solid-state drive;
[0051] The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid-state drive with the external environment through the data access link;
[0052] The data encryption module is used to encrypt the read hard disk data information and obtain a corresponding first-level encryption key;
[0053] The key generation module is used to generate a second-level encryption key according to the initial state of the externally connected entity, fit the second-level encryption key with the first-level encryption key to obtain a corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key.
[0054] It should be further noted that in the specific implementation process, the process of the data reading module reading the hard disk data information in the solid-state drive includes:
[0055] Scanning the solid-state drive to obtain each storage space in the solid-state drive and obtaining the storage address corresponding to each storage space;
[0056] Reading the data information stored in each storage space and associating the read data information with the corresponding storage address;
[0057] Fitting the associated storage address and data information to obtain the hard disk space data corresponding to each storage space;
[0058] Obtaining the hard disk data information of the solid-state drive, where the hard disk data information includes the maximum capacity of the hard disk, the total amount of hard disk data stored, the storage address of each storage space, and the size of the hard disk space data corresponding to the storage space.
[0059] It should be further noted that in the specific implementation process, the process of the data reading module reading external environment information includes:
[0060] Mark the host to which the solid-state drive is connected as an external access entity, obtain the external environment information corresponding to the external access entity, and the external environment information includes the network environment security information where the external access entity is located and the entity's own security information;
[0061] When there is a risk in any one of the network environment security information and the entity's own security information of the external access entity, the solid-state drive does not link with the external access entity;
[0062] When both the network environment security information and the entity's own security information of the external access entity are normal, mark the external access entity in the current state as the initial state.
[0063] It should be further noted that in the specific implementation process, the process of the data processing module constructing a corresponding data access link according to the read external environment information and linking the solid-state drive with the external environment through the data access link includes:
[0064] Read the external environment information of the external access entity in the initial state, and obtain the corresponding monitoring items and the status quantities corresponding to each monitoring item. The status quantities include "normal" and "risk", and the status quantities of each monitoring item in the initial state are all "normal";
[0065] Integrate each monitoring item and the corresponding status quantity to obtain the external entity status data;
[0066] Construct a corresponding data access link composed of data interaction nodes with the same number as the monitoring items according to the external entity status data;
[0067] Link the solid-state drive with the external access entity through the data access link.
[0068] It should be further noted that in the specific implementation process, the process of the data encryption module encrypting the read hard disk data information and obtaining the corresponding first-level encryption key includes:
[0069] According to the storage addresses of each storage space in the hard disk data information, construct blank unit items associated with the storage addresses;
[0070] Sort the blank unit items according to the hard disk space data size in the storage space corresponding to the associated storage address, and generate corresponding sequence codes in each blank unit item;
[0071] Integrate the obtained sequence codes to obtain the corresponding hard disk information sequence;
[0072] Bind the obtained hard disk information sequence to the hard disk data information node; it should be further noted that in the specific implementation process, after the hard disk information sequence is bound to the hard disk data information, the user can reset the data information in the solid-state hard disk to the hard disk data information bound to the hard disk information sequence according to the hard disk information sequence;
[0073] Convert the obtained hard disk information sequence into a data stream composed of several binary codes;
[0074] Set the polynomial G(x) and obtain the highest power of the set polynomial;
[0075] Then add the corresponding number of "0"s at the end of the data stream according to the highest power of the set polynomial to obtain the data stream to be processed;
[0076] Perform modulo-2 division on the obtained data stream to be processed by the set polynomial G(x) to obtain the corresponding data stream K1 and data stream K2, where K1 is the quotient and K2 is the remainder;
[0077] According to the number of binary codes constituting the data stream K2, divide the data stream K1 into several data stream segments, and the binary unit code of the data stream segment is the same as the number of binary codes of the data stream K2. If the number of divided data stream segments does not meet the number of binary codes of the data stream K2, add "0" at the end of the corresponding data stream segment until the number of binary codes meets the requirement;
[0078] Perform exclusive OR operation on each data stream segment and the data stream K2 to obtain the corresponding exclusive OR code, and convert the obtained exclusive OR code into a number system same as the highest power of the set polynomial G(x), denoted as the key unit;
[0079] Integrate the obtained key units, and use the integrated result as the first-level encryption key to encrypt the hard disk data information through the obtained round of encryption key.
[0080] It should be further noted that in the specific implementation process, the process of the key generation module generating the second-level encryption key according to the initial state of the external access entity includes:
[0081] According to the external entity state data of the external access entity in the obtained initial state, generate the corresponding initial state code according to the monitoring items in the external entity state data;
[0082] Among them, the initial state code is specifically "1" when the state quantity of the monitoring item is "normal", and "0" when the state quantity of the monitoring item is "risk";
[0083] Combine the obtained initial status codes to obtain a data stream composed of binary codes with the same number as the number of monitored items in the initial state of the external access entity, and all the binary codes constituting the data stream are "1";
[0084] Associate the obtained data stream with the corresponding initial permission code, and the initial permission code is "0";
[0085] After adding the initial permission code to the front end of the data stream, use the obtained new data stream as the double encryption key.
[0086] It should be further noted that in the specific implementation process, fitting the double encryption key with the single encryption key to obtain the corresponding encryption key, the process of encrypting the data access link through the encryption key includes:
[0087] Import the generated single encryption key and double encryption key into each data interaction node in the data access link;
[0088] Convert the double encryption key into a key unit with the same number system as the single encryption key, and add the obtained key unit to the end of the single encryption key, so as to complete the fitting of the single encryption key and the double encryption key and obtain the corresponding encryption key;
[0089] Encrypt each data interaction node in the data access link through the obtained encryption key.
[0090] It should be further noted that in the specific implementation process, after completing the encryption of each data interaction node in the data access link, when the external access entity needs to access the solid-state drive through the data access link, obtain whether the monitored items of the external access entity and the status quantities of the monitored items have changed. If neither the monitored items nor the status quantities of the monitored items have changed, the external access entity directly accesses the solid-state drive through the data access link. If either the monitored items or the status quantities of the monitored items have changed, adjust the access qualification of the data access link according to the change situation of the monitored items;
[0091] The change situation of the monitored items includes: the number of monitored items remains unchanged, the status quantities of the monitored items are all "normal", and the content changes, such as a certain original monitored item in the initial state changes to another monitored item, and this monitored item is different from any original detected item;
[0092] Then the data interaction node corresponding to the original monitored item in the data access link fails, and the access of the external access entity to the solid-state drive through this data access link is cut off, and the user needs to reconstruct the corresponding data access link according to the external entity status data of the external access entity in the current state;
[0093] The changes in the monitored items also include: if the number of monitored items decreases and the status quantities of the monitored items are all "normal", then the data interaction nodes corresponding to the missing monitored items in the data access link fail, and the access of the external access entity to the solid-state drive through this data access link is cut off. Then, the user needs to reconstruct the corresponding data access link according to the external entity status data of the external access entity in the current state.
[0094] The changes in the monitored items also include: if the number of monitored items increases and all the original monitored items are retained, and the status quantities of the monitored items are all "normal", then temporary data interaction nodes are generated according to the increased monitored items, and the temporary data interaction nodes are updated into the data access link;
[0095] Corresponding permission codes are generated according to the increased data interaction nodes, and the generated permission codes are added to the double encryption key, and a new encryption key is obtained. The new encryption key can only access the solid-state drive through the new data access link, and the original data access link has a higher permission than the new data access link. When the solid-state drive is attacked, the user can enter the solid-state drive through the original data access link and reset the solid-state drive to the state before the attack through the hard disk information sequence;
[0096] The user accesses the solid-state drive through the updated data access link.
[0097] The above is only a preferred embodiment of the present invention, and does not impose any form of limitation on the present invention. Although the present invention has been disclosed above with the preferred embodiment, it is not intended to limit the present invention. Any person skilled in the art can make some changes or modifications to the equivalent embodiments by using the disclosed technical content within the scope of the technical solution of the present invention. However, as long as it does not depart from the content of the technical solution of the present invention, any modification or equivalent replacement made to the above embodiments based on the technical essence of the present invention still falls within the scope of the technical solution of the present invention.
Claims
1. A security key generation system for a solid-state drive master control chip, including a monitoring center, characterized in that, The monitoring center is communicatively connected with a data reading module, a data processing module, a data encryption module, and a key generation module; The data reading module is used to read the hard disk data information and external environment information in the solid-state drive; The data processing module is used to construct a corresponding data access link according to the read external environment information, and link the solid-state drive with the external environment through the data access link; The data encryption module is used to encrypt the read hard disk data information and obtain a corresponding first-level encryption key; The key generation module is used to generate a second-level encryption key according to the initial state of the external access entity, fit the second-level encryption key with the first-level encryption key to obtain a corresponding encryption key, and encrypt the constructed data access link with the obtained encryption key; The process of the data reading module reading the external environment information includes: Mark the host to which the solid-state drive is connected as an external access entity, and obtain the external environment information corresponding to the external access entity. The external environment information includes the network environment security information and the entity's own security information where the external access entity is located; When there is a risk in any one of the network environment security information and the entity's own security information of the external access entity, the solid-state drive does not link with the external access entity; When both the network environment security information and the entity's own security information of the external access entity are normal, mark the external access entity in the current state as the initial state; The process of fitting the second-level encryption key with the first-level encryption key to obtain a corresponding encryption key and encrypting the data access link with the encryption key includes: Import the generated first-level encryption key and second-level encryption key into each data interaction node in the data access link; Convert the second-level encryption key into a key unit with the same number system as the first-level encryption key, and add the obtained key unit to the end of the first-level encryption key, so as to complete the fitting of the first-level encryption key and the second-level encryption key and obtain a corresponding encryption key; Encrypt each data interaction node in the data access link with the obtained encryption key.
2. The security key generation system for a solid-state drive master control chip according to claim 1, characterized in that, The process of the data reading module reading the hard disk data information in the solid-state drive includes: Scan the solid-state drive to obtain each storage space in the solid-state drive and obtain the storage address corresponding to each storage space; Read the data information stored in each storage space and associate the read data information with the corresponding storage address; Fit the associated storage address and data information to obtain the hard disk space data corresponding to each storage space; Obtain the hard disk data information of the solid-state drive. The hard disk data information includes the maximum hard disk capacity, the total amount of hard disk data stored, the storage address of each storage space, and the size of the hard disk space data corresponding to the storage space.
3. The security key generation system for a solid-state drive master control chip according to claim 2, characterized in that, The process of the data processing module constructing a corresponding data access link according to the read external environment information and linking the solid-state drive with the external environment through the data access link includes: Read the external environment information of the external access entity in the initial state, and obtain the corresponding monitoring items and the status quantities corresponding to each monitoring item; Integrate each monitoring item and the corresponding status quantity to obtain the external entity status data; Construct a corresponding data access link composed of data interaction nodes with the same number as the monitoring items according to the external entity status data; Link the solid-state drive with the external access entity through the data access link.
4. A secure key generation system for a solid state drive master control chip according to claim 3, characterized in that, The process by which the data encryption module encrypts the read hard disk data information and obtains the corresponding first-level encryption key includes: According to the storage addresses of each storage space in the hard disk data information, construct blank unit items associated with the storage addresses; Sort the blank unit items according to the size of the hard disk space data in the storage space corresponding to the associated storage address, and generate corresponding sequence codes in each blank unit item; Integrate the obtained sequence codes to obtain the corresponding hard disk information sequence; Bind the obtained hard disk information sequence to the hard disk data information node; Convert the obtained hard disk information sequence into a data stream composed of several binary codes; Set a polynomial and obtain the highest power of the set polynomial; Then add the corresponding number of "0"s at the end of the data stream according to the highest power of the set polynomial to obtain the data stream to be processed; Perform modulo 2 division on the obtained data stream to be processed by the set polynomial G(x) to obtain the corresponding data stream K1 and data stream K2, where K1 is the quotient and K2 is the remainder; According to the number of binary codes constituting the data stream K2, divide the data stream K1 into several data stream segments. The binary unit codes of the data stream segments are the same as the number of binary codes of the data stream K2. If the number of divided data stream segments does not meet the number of binary codes of the data stream K2, add "0" at the end of the corresponding data stream segment until the number of binary codes reaches the requirement; Perform an exclusive OR operation on each data stream segment and the data stream K2 to obtain the corresponding exclusive OR code, and convert the obtained exclusive OR code into a number with the same base as the highest power of the set polynomial G(x), denoted as the key unit; Integrate the obtained key units, and use the integration result as the first-level encryption key to encrypt the hard disk data information through the obtained first-level encryption key.
5. The security key generation system for a solid-state drive master control chip according to claim 4, characterized in that, The process by which the key generation module generates the second-level encryption key according to the initial state of the external access entity includes: According to the external entity status data of the external access entity in the obtained initial state, generate the corresponding initial state code according to the monitoring items in the external entity status data; Combine the obtained initial state codes to obtain a data stream composed of binary codes with the same number as the monitoring items when the external access entity is in the initial state; Associate the obtained data stream with the corresponding initial permission code; After adding the initial permission code to the front end of the data stream, use the obtained new data stream as the second-level encryption key.
Citation Information
Patent Citations
Secure processor with external memory using block chaining and block re-ordering
CA2249554A1
Hard drive data write / read method and device
CN102930224A