Data storage method and device, electronic equipment and chip

By establishing a data transmission channel between terminal devices and calculating channel keys using private keys and public keys, the problem of unused storage space between terminal devices and low security in centralized storage solutions is solved, and efficient and secure storage space sharing is achieved.

CN120045133APending Publication Date: 2025-05-27BEIJING X RING TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510089997.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Terminal devices such as mobile phones and tablets have problems with unused remaining storage space, while centralized storage solutions have problems with high cost and low security.

Method used

By establishing a data transmission channel between terminal devices, the channel key is calculated using the device's private key and the target device's public key to realize data storage and transmission across devices.

Benefits of technology

It realizes the sharing of storage space between terminal devices, makes full use of the remaining storage space of the device, reduces storage costs, and ensures the security of data during transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045133A_ABST
    Figure CN120045133A_ABST
Patent Text Reader

Abstract

The invention provides a data storage method and device, electronic equipment and a chip, and relates to the technical field of data storage. The method comprises the steps that a data storage instruction is received, and the storage instruction comprises to-be-stored data and a target storage area; sending a transmission channel establishment request in response to the fact that the target storage area is located in the second device; in response to the received second public key corresponding to the second equipment, determining a channel key based on the first private key and the second public key corresponding to the first equipment; and sending the to-be-stored data based on the channel key so as to store the to-be-stored data into the target storage area. According to the technical scheme, the residual storage space of the terminal equipment can be fully utilized, additional storage equipment is not needed, the storage cost is reduced, and the safety of the data in the transmission and storage process is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data storage, and in particular to a data storage method, device, electronic device and chip. Background Art

[0002] Terminal devices such as mobile phones and tablets have strong data storage capabilities. Users generally have multiple terminal devices at the same time, which often have a certain amount of residual storage space that is not effectively utilized. As the demand for data storage continues to grow, centralized storage will have problems such as high cost and low security. Therefore, an efficient, secure, private and user-friendly distributed storage solution for terminal devices is needed to improve the utilization rate of terminal device storage space. Summary of the invention

[0003] The present disclosure aims to solve one of the technical problems in the related art at least to some extent.

[0004] A first aspect of the present disclosure provides a data storage method, including:

[0005] Receiving a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area;

[0006] In response to the target storage area being located in the second device, sending a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device;

[0007] In response to receiving a second public key corresponding to the second device, determining a channel key based on a first private key corresponding to the first device and the second public key;

[0008] Based on the channel key, the data to be stored is sent to store the data to be stored in the target storage area.

[0009] A second aspect of the present disclosure provides a data storage method, including:

[0010] receiving a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device;

[0011] Sending a second public key corresponding to the second device;

[0012] Determine a channel key based on a second private key corresponding to the second device and the first public key;

[0013] Based on the channel key, data to be stored is received, and the data to be stored is stored in a shared storage area.

[0014] A third aspect of the present disclosure provides a data storage device, including:

[0015] A first receiving module, configured to receive a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area;

[0016] A first sending module, configured to send a transmission channel establishment request in response to the target storage area being located in the second device, wherein the transmission channel establishment request includes a first public key corresponding to the first device;

[0017] a first computing module, configured to determine a channel key based on a first private key corresponding to the first device and the second public key in response to receiving a second public key corresponding to the second device;

[0018] The second sending module is used to send the data to be stored based on the channel key, so as to store the data to be stored in the target storage area.

[0019] A fourth aspect of the present disclosure provides a data storage device, including:

[0020] A second receiving module, configured to receive a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key;

[0021] A third sending module, used to send a second public key corresponding to the second device;

[0022] A second calculation module, configured to determine a channel key based on a second private key corresponding to the second device and the first public key;

[0023] The storage module is used to receive the data to be stored based on the channel key, and store the data to be stored in the shared storage area.

[0024] The fifth aspect embodiment of the present disclosure proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the data storage method proposed in the first aspect embodiment of the present disclosure is implemented.

[0025] The sixth aspect embodiment of the present disclosure proposes a chip, which includes a processing circuit and an interface circuit; wherein the interface circuit is used to obtain instructions and send the instructions to the processing circuit, and the processing circuit is used to execute the instructions to implement the data storage method proposed in the first aspect embodiment of the present disclosure.

[0026] A seventh aspect embodiment of the present disclosure proposes a computer-readable storage medium storing computer execution instructions. When the computer execution instructions are executed by a processor, the data storage method proposed in the first aspect embodiment of the present disclosure is implemented.

[0027] An eighth aspect embodiment of the present disclosure proposes a computer program product, characterized in that it includes a computer program, which, when executed by a processor, implements the data storage method proposed in the first aspect embodiment of the present disclosure.

[0028] The data storage method, device, electronic device and chip provided by the present disclosure have the following beneficial effects:

[0029] In the disclosed embodiment, when receiving a storage instruction to store data across devices, the channel key is calculated using the private key of the device and the public key of the other device with which the data transmission channel is to be established, and then a transmission channel between the two devices is established based on the channel key, and the data to be stored in the current device is sent to the other device for storage. In this way, the storage space sharing between terminal devices can be realized, the remaining storage space of the terminal device can be fully utilized, no additional storage device is required, the storage cost is reduced, and the security of the data during transmission and storage is ensured.

[0030] Additional aspects and advantages of the present disclosure will be given in part in the following description and in part will be obvious from the following description or learned through practice of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The above and / or additional aspects and advantages of the present disclosure will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0032] Figure 1 A schematic diagram of a centralized storage solution for terminal device data;

[0033] Figure 2 A schematic diagram of a data storage method according to an embodiment of the present disclosure;

[0034] Figure 3 A schematic diagram of data transmission between two terminal devices;

[0035] Figure 4 A schematic diagram of a data storage method provided by another embodiment of the present disclosure;

[0036] Figure 5 A schematic diagram of negotiating a channel key between two terminal devices;

[0037] Figure 6 A schematic diagram of a data storage method provided by another embodiment of the present disclosure;

[0038] Figure 7a A schematic diagram of data encryption provided by the present disclosure;

[0039] Figure 7bA schematic diagram of encryption key derivation provided by the present disclosure;

[0040] Figure 8 A schematic diagram of a data storage method provided by another embodiment of the present disclosure;

[0041] Fig. 9 A schematic diagram of a data storage method provided by another embodiment of the present disclosure;

[0042] Fig.10 A schematic diagram of the storage space capacity shared by the same user account in different terminal devices;

[0043] Fig.11 A schematic diagram of a data storage method provided by another embodiment of the present disclosure;

[0044] Fig.12 A signaling interaction diagram of a data storage method provided by an embodiment of the present disclosure;

[0045] Fig.13 A schematic diagram of the structure of a data storage device provided by an embodiment of the present disclosure;

[0046] Fig.14 A schematic diagram of the structure of a data storage device provided by an embodiment of the present disclosure;

[0047] Fig.15 A block diagram of an exemplary electronic device suitable for implementing the embodiments of the present disclosure is shown;

[0048] Fig.16 It is a schematic diagram of the structure of a chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0049] Embodiments of the present disclosure are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present disclosure, and should not be construed as limiting the present disclosure.

[0050] The data storage method, device, electronic device and chip according to the embodiments of the present disclosure are described below with reference to the accompanying drawings.

[0051] Currently, the storage of user data (such as user photos, videos, etc.) in terminal devices is focused on centralized storage on a single device. When the storage demand for personal user data is large and the remaining storage space of a terminal device is insufficient, a centralized storage solution is often used, that is, the photos and videos that cannot be stored in the user device are transferred to network-attached storage (NAS) or cloud disk, etc. The schematic diagram of the storage solution is shown in the figure. Figure 1 As shown. Figure 1 It can be seen that this centralized storage solution usually requires users to purchase hard drives or services, and then upload data such as photos or videos to NAS or network disks through the Internet. The storage cost is relatively high, and this off-site storage solution often relies on the data security capabilities of hardware or cloud service providers, and there are also major security risks such as data leakage for users.

[0052] Therefore, in the present disclosure, distributed storage can be implemented among multiple terminal devices of a user to share the remaining available storage space among different devices. This can ensure the storage security of user data without the need to purchase additional storage devices, thereby reducing the user's storage costs and improving the storage space utilization of terminal devices.

[0053] Figure 2 A flowchart of a data storage method provided by an embodiment of the present disclosure.

[0054] It should be noted that the data storage method of the embodiment of the present disclosure can be applied to a data storage device. In some possible embodiments, the device can be configured in an electronic device or chip so that the electronic device or chip can perform the function of sharing storage space among multiple terminal devices.

[0055] like Figure 2 As shown, the data storage method may include the following steps:

[0056] Step 201: Receive a data storage instruction.

[0057] In the disclosed embodiment, the storage instruction includes data to be stored and a target storage area. In one possible implementation, the data to be stored and the target storage area are both triggered by the user and packaged in the same storage instruction; in another possible implementation, the data to be stored and the target storage area are triggered by the user and packaged in different storage instructions; in another possible implementation, the data to be stored needs to be stored during the operation of the device, and the device recommends the target storage area based on the relevance of the data storage space or triggered by the user.

[0058] In the embodiments of the present disclosure, the data to be stored refers to data that needs to be stored in the shared storage space of a terminal device so that it can be acquired by any terminal device that has established a sharing relationship with the terminal device, and can be data of types such as photos, videos, or files. The target storage area is a shared storage space divided from any terminal device, which is used to store the data to be stored in the instruction. The target storage area can be in the terminal device that receives the data storage instruction, or in other devices that can establish a data sharing relationship with the terminal device that receives the data storage instruction.

[0059] In one embodiment, the data to be stored may be data that is stored in the device for the first time. The user may select a device for the target storage area, that is, may select a storage path for the data to be stored, so as to receive a data storage instruction.

[0060] In one embodiment, the data to be stored may also be data that has been stored in a non-shared storage space of the device, and the user receives the data storage instruction by determining to transfer the data to be stored to the target storage area.

[0061] It should be noted that in the embodiments of the present disclosure, the execution entity that receives storage instructions, sends requests and data, etc. can be the first application in the terminal device for realizing storage area sharing between devices, or it can be the storage management service of the terminal device, and the present disclosure does not limit this.

[0062] In the disclosed embodiment, the terminal device that receives the data storage instruction is called the first device, and the first device can be any type of terminal device, such as a mobile phone, a tablet computer PAD, etc. By installing the first application in the first device, the first device can share storage space with other storage devices of any model and type, and the shared multiple devices are not limited to those from the same manufacturer. Alternatively, the storage management service between different devices can be called based on an open API interface, so that the data to be stored in the first device can be stored in other devices.

[0063] Step 202: In response to the target storage area being located in the second device, a transmission channel establishment request is sent.

[0064] The second device may be another terminal device that receives the data storage instruction, or any type of device, such as a mobile phone, a tablet computer PAD, etc. The second device is not a specific device, but any terminal device that can establish a data sharing relationship with the first device.

[0065] The transmission channel establishment request includes the first public key of the first device. By sending the first public key to the second device that stores the target data, the second device can clearly understand the identity information of the first device that currently needs to establish a transmission channel with each other, thereby ensuring the security of the transmission channel establishment. The first public key can be generated based on the public parameters agreed with the second device and the randomly selected first private key.

[0066] In the disclosed embodiment, after the first device receives the data storage instruction, it can first determine whether the target storage area contained in the data storage instruction is located in its own storage space. If the target storage area is located in the storage space of the first device, it can be directly stored in the target storage area. If the target storage area is not located in the storage space of the first device, but is located in the storage space of the second device, then in response to the target storage area being located in the second device, the first device needs to store the data to be stored in the second device across devices, and therefore needs to send a transmission channel establishment request containing the first public key of the first device to the second device to establish a data transmission channel between the first device and the second device to ensure the integrity and security of the data to be stored during transmission.

[0067] It should be noted that the request to establish the transmission channel can be sent and received by applications installed between the first device and the second device, or can be sent directly from the first device to the second device through the storage management service of the device itself. Step 203, in response to receiving the second public key corresponding to the second device, determine the channel key based on the first private key and the second public key corresponding to the first device.

[0068] In the embodiment of the present disclosure, after the second device receives the request to establish a transmission channel, the second device can send its second public key to the first device. When the first device receives the second public key corresponding to the second device, it can use the first private key and the second public key corresponding to the first device and adopt a preset calculation method such as multiplication to obtain the channel key.

[0069] It should be noted that in the disclosed embodiment, the key exchange algorithm Diffie-Hellman can be used to negotiate the key for establishing the transmission channel between the first device and the second device to ensure the security of the transmission channel. In the key exchange algorithm, the first device can calculate the first public key based on the randomly set first private key and the public parameters agreed upon by the first device and the second device. The first device can disclose the first public key to the second device when sending a channel establishment request to the second device. The second device can then use the randomly set second private key and the first public key to calculate the channel key. Thus, the first device and the second device can respectively determine the channel key by exchanging their respective public keys. It can be understood that when the first device and the second device are legal devices, the channel key of the first device is the same as the channel key of the second device, then the transmission channel established based on the channel key is secure, and the integrity of the transmitted data can be guaranteed.

[0070] It should be noted that since the channel key does not affect data encryption and decryption, the channel key can be randomly generated each time a secure channel is established, and there is no need for key management and secure storage.

[0071] Step 204: Send the data to be stored based on the channel key to store the data to be stored in the target storage area.

[0072] In the disclosed embodiment, a secure channel algorithm (such as SCP03) can be used to establish a transmission channel between the first device and the second device based on a channel key, and then the data to be stored is sent to the second device via the transmission channel to store the data to be stored in the target storage area.

[0073] In the disclosed embodiment, during the data transmission process, the data remains encrypted, and the message authentication code chaining mechanism MAC-Chaining is used to ensure the integrity of the data. Specifically, an initial value of a message authentication code (MAC) is set, and before the first device sends a data storage instruction to the second device through the transmission channel each time, a new MAC value is calculated using a predetermined MAC algorithm (such as AES-CMAC) based on the current MAC, the data to be stored in the data storage instruction, and other information. This new MAC value will then be used as part of the next data transmission, so that a series of data can be linked together to ensure the integrity and timing of the data. The transmission of the data to be stored can then be Figure 3 As shown, Figure 3 A schematic diagram of data transmission between two terminal devices.

[0074] Depend on Figure 3It can be seen that a transmission channel (i.e. Figure 3 SCP03 secure channel in the network) calculates MAC-Chaining to ensure data integrity when transmitting data in the channel. And when any device sends data and stores data in shared storage, it does not need to encrypt or decrypt the data, which can ensure the performance of data transmission and improve the efficiency of remote copying of user data. If the data itself is encrypted in the device, the data remains encrypted during transmission.

[0075] In this embodiment, when receiving a storage instruction to store data across devices, the channel key is calculated using the private key of the device receiving the storage instruction and the public key of other devices that need to establish a data transmission channel to store data, and then a transmission channel between devices is established based on the channel key, so that the data to be stored in the current device can be sent to other devices for storage. In this way, storage space sharing between terminal devices can be achieved, and the remaining storage space of the terminal device can be fully utilized without the need for additional storage devices, which reduces storage costs and ensures the security of data during transmission and storage.

[0076] It should be noted that in the embodiments of the present disclosure, the first device and the second device may be different devices of the same user. Or they may be terminal devices of different employees in an enterprise office scenario. Or they may be extended to an Internet of Things environment, where the first device and the second device are sensors or smart home devices. For example, a distributed storage network may be formed by multiple smart home devices to store important data in the home, such as photos, videos, etc.

[0077] Therefore, in the embodiment of the present disclosure, when the key exchange algorithm Diffie-Hellman is used to determine the channel key, since in different environments, the first device and the second device may be terminal devices of the same user or terminal devices of different users, the public parameters used to calculate the public keys of each device can be determined based on the account information of the same user, or can also be pre-configured in the device.

[0078] Figure 4 A schematic diagram of a data storage method provided by an embodiment of the present disclosure is shown in FIG. Figure 4 As shown, the data storage method may include the following steps:

[0079] Step 401: determine a common parameter based on user information associated with a first device according to a preset rule.

[0080] In the embodiment of the present disclosure, when the first device and the second device are different devices of the same user, the user information associated with the first device and the second device is the same. The common parameter can be determined directly according to the user information associated with the first device according to a preset rule.

[0081] It should be noted that the public parameters of the key exchange algorithm Diffie-Hellman can be composed of a large prime number q and a primitive root a of q. For example, the sum of all the numbers in the user information (or a prime number closest to the sum of the numbers) can be determined as a large prime number p, and then a primitive root with the smallest p is selected from all the numbers in the user information as g. Alternatively, p and g can also be calculated based on the user information through certain operation rules, which is not limited in the present disclosure.

[0082] Step 402: Determine a first public key based on the public parameter and a first private key of the first device.

[0083] The first private key is a number randomly selected in the first device and is kept confidential by the first device.

[0084] In the disclosed embodiment, the first public key can be obtained by certain calculation rules, such as multiplying the public parameter and the first private key.

[0085] In the disclosed embodiment, the public parameters of two devices transmitting data to each other are determined based on user information, and then the public key used to calculate the channel key is determined in combination with the randomly generated private key. This improves the personalization of the public parameter determination, simplifies the generation of the public key, and is conducive to improving the efficiency and security of establishing the transmission channel.

[0086] Combine the following Figure 5 An exemplary description is given of negotiating a channel key between two devices. Figure 5 Schematic diagram of generating channel keys for two end devices of the same user.

[0087] Depend on Figure 5 It can be seen that if two terminal devices are associated with the same user account information, then in the two terminal devices, the user information can be passed through the security engine respectively, the public parameters can be determined according to the same rules, and combined with the randomly selected private key to obtain the public key corresponding to the terminal device. Figure 5The TEE in the example is a Trusted Execution Environment, which can ensure the security of the computing process and data executed by the security engine. Then, the key exchange algorithm Diffie-Hellman can be used. Any terminal device can initiate a channel establishment request, send its first public key to another device, and get the second public key returned by the other device. After that, the channel key is determined by combining the second public key, its first private key, and public parameters to complete the key negotiation.

[0088] It should be noted that in office or IoT scenarios, devices that share storage space do not necessarily belong to the same user. At this time, it is impossible to determine a common parameter based on the user information associated with the device. Therefore, common parameters can be configured in advance in multiple devices that need to establish data sharing. Thus, the first public key can be determined based on the pre-configured public parameters and the first private key. It can ensure that the parameters used to generate public keys in terminal devices of different users are consistent, ensuring the feasibility of sharing storage space between devices in a public environment. By pre-configuring common parameters, the process of parameter determination can be simplified, thereby improving the efficiency of key negotiation.

[0089] Figure 6 A schematic diagram of a data storage method provided by an embodiment of the present disclosure; Figure 6 As shown, the data storage method may include the following steps:

[0090] Step 601: Receive a data storage instruction.

[0091] Step 602: In response to the target storage area being located in the second device, a transmission channel establishment request is sent.

[0092] Step 603: In response to receiving the second public key corresponding to the second device, determine a channel key based on the first private key and the second public key corresponding to the first device.

[0093] For detailed description of the above steps 601 to 603, please refer to the above embodiments of the present disclosure, which will not be repeated here.

[0094] Step 604: In response to the data to be stored being unencrypted and the data encryption key being stored in the first device, the data to be stored is encrypted based on the data encryption key to obtain encrypted data.

[0095] It should be noted that in the embodiment of the present disclosure, whether the data needs to be encrypted can be set by the user. If the user sets that the shared data does not need to be encrypted when creating a shared storage space, the data encryption key will not be stored in the first device. Then, when the data is stored across devices, the data encryption key will not be obtained, and the stored data will not be encrypted.

[0096] Combine the following Figure 7a Explain the data encryption process. Figure 7a A schematic diagram of data encryption provided by the present disclosure.

[0097] Depend on Figure 7a It can be seen that users can encrypt and decrypt shared storage data in any terminal device. When the data to be stored is written into the shared storage space, it is encrypted, and when the user reads the data in the storage space, it is decrypted. The data is not decrypted during transmission, and the encrypted transmission state is maintained. In other words, when the data to be stored in the first device needs to be transferred to the shared storage space for storage, and the data to be stored is not encrypted, the data encryption key can be obtained from the key storage of the first device in the TEE or security element (SE), and then the encrypted data is obtained through the security engine using the AES-GCM-256 data encryption algorithm.

[0098] exist Figure 7a In the data storage, A / B / C / D file storage is the non-shared storage space in the first device, and A / B / C / D data is the data classification method when the file-level encryption method is used. Class A is CDE (Credential Device Encrypted) data, that is, after the device is started, the user enters the personal identification number (PIN) to unlock the data, such as the user's privacy data. Class B is CCE data, which means that after the device is locked, it can still be written, such as email attachments downloaded in the background. Class C is CE (Credential Encrypted) data, that is, data that can only be unlocked after the user enters the PIN code to unlock the device, such as user data generated by third-party apps. Class D is DE (Device Encrypted) data, that is, data that can be accessed in direct startup mode and before the device is unlocked, such as some user settings, alarms, WIFI configurations, etc.

[0099] In the present disclosure, data placed in a shared storage space is referred to as Class E data, namely, SSE (Shared Stroge Encrypted) class.

[0100] It should be noted that a unified data encryption key is required for Class E data of multiple devices sharing storage space, so that such data can be written and read in any device sharing storage space, avoiding the need for frequent encryption and decryption during data transmission between devices.

[0101] Optionally, a data encryption key generation instruction may be received first, wherein the generation instruction includes a key derivation factor.

[0102] In the embodiment of the present disclosure, the user can set whether encryption is required when setting up a multi-device shared storage space, so that when it is determined that encryption is required, a data encryption key generation instruction is received.

[0103] It should be noted that since a unified data encryption and decryption key is required between devices that share storage space, the key derivation factor used to generate the key in each device should also be unified, and the user can input a unified key derivation factor, such as a string of specific characters, in these devices. In an enterprise office environment, this key derivation factor can be specified by the enterprise and uniformly set by the enterprise in each device that needs to be shared, or set by each employee in the device.

[0104] A data encryption key may then be generated based on the key derivation factor.

[0105] In the disclosed embodiment, a data encryption key may be generated based on a key derivation factor and in accordance with a predetermined algorithm. When generating the data encryption key, information such as a user account number may also be combined.

[0106] For example, in a personal terminal, the key derivation factor can be added to the user account and other information to derive the data encryption key according to the PBKDF2 algorithm. Alternatively, in an enterprise office environment, the key derivation factor can be added to the enterprise account and other information to derive the data encryption key according to the PBKDF2 algorithm, etc.

[0107] Afterwards, the data encryption key may be stored in a preset location in the first device.

[0108] The preset location refers to a location in the first device for storing the key.

[0109] Combine the following Figure 7b An example is given of how to generate encryption keys and how to store them. Figure 7b A schematic diagram of encryption key derivation provided by the present disclosure.

[0110] Depend on Figure 7b It can be seen that the user can enter the key derivation factor in the terminal device, and pass the key derivation factor and user account information through the security engine to derive the data encryption key according to the predetermined algorithm PBKDF2. The generated data encryption key is then stored in the key storage location, and the key is managed and protected by TEE or SE, which is not readable by the user. When the file needs to be encrypted or decrypted, the key is directly passed to the security engine for encryption and decryption calculations.

[0111] Step 605: Send the encrypted data based on the channel key.

[0112] In the embodiment of the present disclosure, after the encryption of the data to be stored is completed, the encrypted data can be sent to the target storage area in the second device based on the transmission channel established by the channel key.

[0113] In this embodiment, the data to be stored is encrypted using a data encryption key and then sent based on a channel key, thereby ensuring the security of the data during transmission and storage.

[0114] Figure 8 A schematic diagram of a data storage method provided by an embodiment of the present disclosure; Figure 8 As shown, the data storage method may include the following steps:

[0115] Step 801, receiving a data storage instruction.

[0116] For a detailed description of the above step 801, please refer to the above embodiments of the present disclosure, which will not be repeated here.

[0117] Step 802: In response to the target storage area being located in the second device, determine the storage space required for the data to be stored.

[0118] In the embodiment of the present disclosure, after determining that the target storage area is located in the second device, in order to avoid directly transferring the data to be stored to the second device but the remaining space of the second device cannot completely store the data to be stored, the storage space required for the data to be stored can be determined first. The size of the storage space required for the data to be stored can be determined based on the memory occupied by the data to be stored.

[0119] Step 803: determine the current remaining capacity of the shared storage space of the second device.

[0120] In the embodiment of the present disclosure, after determining the storage space required for the data to be stored, the first device can determine the current remaining capacity of the shared storage space in the second device by sending a query instruction for the remaining shared storage space capacity to the second device, and then compare the remaining capacity of the second device with the storage space required for the data to be stored.

[0121] It should be noted that when storage space is shared between devices, the shared storage space of each device may be used by multiple devices at the same time, so the remaining capacity can be synchronized between devices, thereby avoiding the device that wants to store data from executing a meaningless transmission channel establishment process, which wastes device power consumption and user time.

[0122] Optionally, a remaining capacity synchronization message may be received, wherein the synchronization message includes the current remaining capacity of the shared storage space in the second device.

[0123] It should be noted that when the storage space can be shared between the first device and multiple devices, the first device can receive the remaining capacity synchronization message sent by each device, so that the remaining capacity corresponding to all devices that can share the storage space can be displayed in the first device. Since the storage space sharing between devices can be mutual, the remaining capacity of the first device can also be synchronized in other devices.

[0124] Step 804: In response to the remaining capacity being greater than or equal to the storage space required for the data to be stored, a transmission channel establishment request is sent.

[0125] In the embodiment of the present disclosure, after determining the storage space required for the data to be stored and the current remaining capacity of the shared storage space of the second device, the required storage space and the remaining capacity can be compared. When it is determined that the remaining capacity is greater than or equal to the storage space required for the data to be stored, it means that the data to be stored can be stored in the target storage area of ​​the second device, which triggers the operation of sending a transmission channel establishment request to the second device.

[0126] In this embodiment, by establishing a transmission channel with the foreign device only when the space required for the data to be stored is less than or equal to the current remaining capacity of the second device, the problem of insufficient remaining space in the second device after the channel is established can be avoided, thereby avoiding wasting time and processing resources and improving the efficiency of storage space sharing.

[0127] Step 805 , in response to receiving the second public key corresponding to the second device, determining a channel key based on the first private key and the second public key corresponding to the first device.

[0128] Step 806: Send the data to be stored based on the channel key to store the data to be stored in the target storage area.

[0129] For detailed description of the above steps 804 to 805, please refer to the above embodiments of the present disclosure, which will not be repeated here.

[0130] It should be noted that, in some possible embodiments, in response to the remaining capacity being less than the storage space required for the data to be stored, a storage abnormality prompt may be first displayed on the display interface.

[0131] The storage abnormality prompt is used to prompt at least one of the following: insufficient remaining capacity of the second device and a third device identifier. The third device corresponding to the third device identifier should satisfy that the current remaining capacity is greater than the storage space required for the data to be stored.

[0132] In an embodiment of the present disclosure, the storage exception prompt displayed on the display interface may include the current remaining capacity of the shared storage space in the second device, the storage space required for the data to be stored, and a prompt message such as "insufficient current storage space". Moreover, in the display interface, the identifiers of other terminal devices that can share the storage space with the first device and whose remaining capacity is greater than or equal to the storage space required for the data to be stored, that is, the third device identifiers, can be displayed.

[0133] Then, in response to the selection of the third device identifier, a transmission channel establishment request may be sent to the third device. After that, in response to receiving the third public key corresponding to the third device, a channel key is determined based on the first private key corresponding to the first device and the third public key. Finally, based on the channel key, the data to be stored is sent to store the data to be stored in the third device.

[0134] Among them, the transmission channel establishment request includes the first public key corresponding to the first device, and the third device is different from the second device.

[0135] It should be noted that the process of establishing a transmission channel between the third device and the first device and sending the data to be stored is the same as the process of establishing a transmission channel between the second device and the first device and sending the data to be stored. The description in the above embodiment can be directly referred to, and details are not described herein again.

[0136] Fig. 9 It is a schematic flowchart of a data storage method provided by an embodiment of the present disclosure; as Fig. 9 shown, the data storage method may include the following steps:

[0137] Step 901, receiving a storage space sharing setting instruction.

[0138] Among them, the sharing setting instruction includes at least two device identifiers and the shared storage space capacity corresponding to each device.

[0139] In an embodiment of the present disclosure, a user or an enterprise can determine which devices need to share the storage space according to needs, and then the terminal devices that need to share the storage space can receive the storage space sharing setting instruction. The device identifiers included in the sharing setting instruction are used to identify at least two devices that can share the storage space with each other. In each device, the size of the storage space to be shared, that is, the shared storage space capacity, can be selected according to its own needs, and the shared space sizes corresponding to different devices can be the same or different.

[0140] For example, the shared storage space capacity of the same user account in different terminal devices can be as Fig.10 shown. In Fig.10In the example, the three devices that share the storage space are identified as "mobile phone", "PAD1" and "PAD2". The shared storage space capacity of each device is Fig.10 The size of the cylinder is used to represent that the shared storage space corresponding to PAD1 has the largest capacity. Fig.10 In this way, the shared storage space allocated to all devices is mapped under the same account on each terminal device.

[0141] Step 902: partition the storage area in the first device based on the shared storage space capacity corresponding to the first device to obtain the shared storage area corresponding to the first device.

[0142] In the embodiment of the present disclosure, after determining the shared storage space capacity corresponding to the first device, the storage area within the first device can be partitioned into a shared storage area and a non-shared storage area, and the capacity of the shared storage area is consistent with the shared storage space capacity corresponding to the first device.

[0143] Step 903: Add at least two device identifiers to the candidate data storage location.

[0144] The candidate data storage locations are used to specify the shared storage areas of the devices in which the data can be stored when the user selects the target storage location for the data to be stored.

[0145] In this embodiment, after receiving the storage space sharing setting instruction, the storage space of the device is divided into a shared storage area, and the identifiers of other shared devices of the device are used as candidates for data storage locations. This allows users to decide whether to share the storage space and choose to use the shared storage space on each device, making the storage space sharing operation between devices more flexible and convenient.

[0146] Fig.11 A schematic diagram of a data storage method provided by an embodiment of the present disclosure; Fig.11 As shown, the data storage method may include the following steps:

[0147] Step 1101: Receive a transmission channel establishment request.

[0148] The transmission channel establishment request includes a first public key corresponding to the first device.

[0149] It should be noted that the execution subject in the embodiments of the present disclosure is a second application in the second device for realizing storage area sharing between devices, or it may also be a storage management service of the second device, and the present disclosure does not limit this. Among them, the second device is a terminal device where the area where the user's target storage data is located, and it is two different devices from the first device, and can be any type of terminal device, such as a mobile phone, tablet computer PAD, etc. The second application is the same application as the first application in the above embodiment, and can be installed in the second device, so that the second device can share storage space with other devices of any model and type, and the shared multiple devices are not limited to those from the same manufacturer.

[0150] Step 1102: Send a second public key corresponding to the second device.

[0151] In the disclosed embodiment, the second public key can be obtained by using the public parameters agreed with the first device and the randomly selected second private key through certain operation rules such as multiplication. After receiving the transmission channel establishment request, the second public key corresponding to the second device can be sent to the first device. It should be noted that the method for determining the second public key should be the same as the method for determining the first public key.

[0152] Optionally, before sending the second public key, the second public key corresponding to the second device may be determined based on the public parameters and the second private key corresponding to the second device, wherein the public parameters are pre-configured or determined based on user information associated with the second device according to a preset rule.

[0153] In the embodiment of the present disclosure, for how to determine the public parameters and how to determine the second public key based on the public parameters and the second private key, reference can be made to the detailed description of the steps related to determining the first public key in the above embodiment of the present disclosure, which will not be repeated here.

[0154] Step 1103: Determine a channel key based on the second private key and the first public key corresponding to the second device.

[0155] In the embodiment of the present disclosure, the channel key may be calculated using the randomly set second private key and the first public key obtained in the transmission channel establishment request.

[0156] It is understandable that the method for calculating the channel key based on the second private key and the first public key should be the same as the method for calculating the channel key based on the first private key and the second public key. In the case where the first device and the second device are legitimate devices, the channel key calculated by the first device is the same as the channel key calculated by the second device, and the transmission channel established based on the channel key is secure and can ensure the integrity of the transmitted data.

[0157] Step 1104: receiving the data to be stored based on the channel key, and storing the data to be stored in the shared storage area.

[0158] In the disclosed embodiment, a secure channel algorithm (such as SCP03) may be used to establish a transmission channel with the first device based on a channel key, and then the data to be stored is received by the transmission channel and stored in the target storage area.

[0159] In this embodiment, after receiving the transmission channel establishment request, the public key of the current device is sent to the device that sends the transmission channel establishment request, and the channel key is calculated using the public key of the device that sends the transmission channel establishment request and the private key of the current device, and then the transmission channel between the two devices is established based on the channel key to receive the data to be stored and store it in the target storage area. In this way, the storage space sharing between terminal devices can be realized, the remaining storage space of the terminal device can be fully utilized, no additional storage device is required, the storage cost is reduced, and the security of data during transmission and storage is ensured.

[0160] It should be noted that when the user writes and reads the shared storage data in the second device, the data also needs to be encrypted and decrypted, so a data encryption key generation instruction can be received first, wherein the generation instruction includes a key derivation factor. Then, a data encryption key is generated based on the key derivation factor.

[0161] In the disclosed embodiment, the data encryption keys in different devices sharing the storage space are consistent. Therefore, the data encryption key generation process in this embodiment can refer to the detailed description of generating the data encryption key in the first device in the above embodiment, which will not be repeated here.

[0162] It should be noted that in order to avoid the device to store data from executing a meaningless transmission channel establishment process, which wastes the device's power consumption and the user's time, a remaining capacity synchronization message may be sent to the first device, wherein the synchronization message includes the current remaining capacity of the shared storage space in the second device. This allows the device sending shared data to obtain the available storage space in other devices more timely and accurately, thereby improving the performance of storage space sharing.

[0163] It should be noted that, in the second device, a storage space sharing setting instruction may also be received, wherein the sharing setting instruction includes at least two device identifiers and the shared storage space size corresponding to each device. Then, based on the shared storage space size corresponding to the second device, the storage area in the second device is partitioned to obtain the shared storage area corresponding to the second device. Afterwards, at least two device identifiers may be added to the candidate data storage location.

[0164] Fig.12 A signaling interaction diagram of a data storage method provided by an embodiment of the present disclosure; Fig.12 As shown, the data storage method may include the following steps:

[0165] Step 1201: A first device receives a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area.

[0166] Step 1202: In response to the target storage area being located in the second device, a transmission channel establishment request is sent to the second device, wherein the transmission channel establishment request includes a first public key corresponding to the first device.

[0167] Step 1203: The second device determines a channel key based on a second private key corresponding to the second device and the first public key, and sends the second public key corresponding to the second device to the first device.

[0168] Step 1204: In response to receiving the second public key corresponding to the second device, the first device determines a channel key based on the first private key and the second public key corresponding to the first device.

[0169] Step 1205: The first device sends the data to be stored based on the channel key.

[0170] Step 1206: The second device receives the data to be stored based on the channel key, and stores the data to be stored in the shared storage area.

[0171] It should be noted that for the detailed description of each step in this embodiment, reference can be made to the description in other embodiments of the present disclosure and will not be repeated here.

[0172] In this embodiment, through the interaction between the first device and the second device, storage space sharing between terminal devices can be achieved, and the remaining storage space of the terminal devices can be fully utilized without the need for additional storage devices, thereby reducing storage costs and ensuring the security of data during transmission and storage.

[0173] In order to implement the above embodiments, the present disclosure also provides a data storage device.

[0174] Fig.13 A schematic diagram of the structure of a data storage device provided in an embodiment of the present disclosure.

[0175] like Fig.13 As shown, the data storage device 1300 may include:

[0176] The first receiving module 1301 is used to receive a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area;

[0177] A first sending module 1302 is configured to send a transmission channel establishment request in response to the target storage area being located in the second device, wherein the transmission channel establishment request includes a first public key corresponding to the first device;

[0178] A first calculation module 1303, configured to determine a channel key based on a first private key and a second public key corresponding to the first device in response to receiving a second public key corresponding to the second device;

[0179] The second sending module 1304 is used to send the data to be stored based on the channel key, so as to store the data to be stored in the target storage area.

[0180] In some embodiments, the first sending module 1302 may also be used to:

[0181] Determining the common parameters based on the user information associated with the first device according to a preset rule;

[0182] A first public key is determined based on the public parameter and a first private key corresponding to the first device.

[0183] In some embodiments, the first sending module 1302 may also be used to:

[0184] A first public key is determined based on the preconfigured public parameters and a first private key corresponding to the first device.

[0185] In some embodiments, the second sending module 1304 may be specifically configured to:

[0186] In response to the data to be stored being unencrypted and the first device having the data encryption key, encrypting the data to be stored based on the data encryption key to obtain encrypted data;

[0187] Based on the channel key, the encrypted data is sent.

[0188] In some embodiments, the second sending module 1304 may also be used to:

[0189] receiving a data encryption key generation instruction, wherein the generation instruction includes a key derivation factor;

[0190] generating a data encryption key based on the key derivation factor;

[0191] The data encryption key is stored in a preset location in the first device.

[0192] In some embodiments, the first sending module 1302 may be specifically configured to:

[0193] Determine the storage space required for the data to be stored;

[0194] Determine the current remaining capacity of the shared storage space of the second device;

[0195] In response to the remaining capacity being greater than or equal to the storage space required for the data to be stored, a transmission channel establishment request is sent.

[0196] In some embodiments, the first sending module 1302 may also be used to:

[0197] In response to the remaining capacity being less than the storage space required for the data to be stored, displaying a storage abnormality prompt on the display interface;

[0198] In response to monitoring that the third device identifier is selected, sending a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device, and the third device is different from the second device;

[0199] In response to receiving a third public key corresponding to the third device, determining a channel key based on a first private key corresponding to the first device and the third public key;

[0200] Based on the channel key, the data to be stored is sent to store the data to be stored in the third device.

[0201] In some embodiments, the first sending module 1302 may also be used to:

[0202] A remaining capacity synchronization message is received, wherein the synchronization message includes a current remaining capacity of the shared storage space in the second device.

[0203] In some embodiments, the first receiving module 1301 may also be used to:

[0204] Receiving a storage space sharing setting instruction, wherein the sharing setting instruction includes at least two device identifiers and a shared storage space capacity corresponding to each device;

[0205] Partitioning a storage area in the first device based on a shared storage space capacity corresponding to the first device to obtain a shared storage area corresponding to the first device;

[0206] Add at least two device identifiers to the candidate data storage locations.

[0207] The functions and specific implementation principles of the above modules in the embodiments of the present disclosure can be referred to the above method embodiments, and will not be repeated here.

[0208] The data storage device of the disclosed embodiment calculates the channel key by using the private key of the device and the public key of other devices for establishing the data transmission channel when receiving the instruction to store data across devices, and then establishes the transmission channel between the two devices based on the channel key, and sends the data to be stored in the current device to the other device for storage. In this way, the storage space sharing between terminal devices can be realized, the remaining storage space of the terminal device can be fully utilized, no additional storage device is required, the storage cost is reduced, and the security of data during transmission and storage is ensured.

[0209] Fig.14 A schematic diagram of the structure of another data storage device provided in an embodiment of the present disclosure.

[0210] like Fig.14 As shown, the data storage device 1400 may include:

[0211] The second receiving module 1401 is configured to receive a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device;

[0212] The third sending module 1402 is used to send a second public key corresponding to the second device;

[0213] A second calculation module 1403, configured to determine a channel key based on a second private key and a first public key corresponding to the second device;

[0214] The storage module 1404 is used to receive the data to be stored based on the channel key, and store the data to be stored in the shared storage area.

[0215] In some embodiments, the third sending module 1402 may also be used to:

[0216] Based on the public parameter and the second private key corresponding to the second device, a second public key corresponding to the second device is determined, wherein the public parameter is pre-configured or determined based on user information associated with the second device according to a preset rule.

[0217] In some embodiments, the second receiving module 1401 may also be used to:

[0218] receiving a data encryption key generation instruction, wherein the generation instruction includes a key derivation factor;

[0219] Based on the key derivation factor, a data encryption key is generated.

[0220] In some embodiments, the third sending module 1402 may also be used to:

[0221] A remaining capacity synchronization message is sent, wherein the synchronization message includes the current remaining capacity of the shared storage space in the second device.

[0222] In some embodiments, the second receiving module 1401 may also be used to:

[0223] Receiving a storage space sharing setting instruction, wherein the sharing setting instruction includes at least two device identifiers and a shared storage space capacity corresponding to each device;

[0224] Partitioning the storage area in the second device based on the shared storage space capacity corresponding to the second device to obtain a shared storage area corresponding to the second device;

[0225] Add at least two device identifiers to the candidate data storage locations.

[0226] The functions and specific implementation principles of the above modules in the embodiments of the present disclosure can be referred to the above method embodiments, and will not be repeated here.

[0227] The data storage device of the disclosed embodiment sends the public key of the current device to the device that sends the transmission channel establishment request after receiving the transmission channel establishment request, and uses the public key of the device that sends the transmission channel establishment request and the private key of the current device to calculate the channel key, and then establishes a transmission channel between the two devices based on the channel key to receive the data to be stored and store it in the target storage area. In this way, the storage space sharing between terminal devices can be realized, the remaining storage space of the terminal device can be fully utilized, no additional storage device is required, the storage cost is reduced, and the security of data during transmission and storage is ensured.

[0228] In order to implement the above embodiments, the present disclosure further proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the data storage method proposed in the above embodiments of the present disclosure is implemented.

[0229] Fig.15 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Fig.15 The electronic device 12 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0230] like Fig.15 As shown, the electronic device 12 is in the form of a general purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 that connects various system components (including the system memory 28 and the processing unit 16).

[0231] The bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of a variety of bus structures. For example, these architectures include but are not limited to Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus and Peripheral Component Interconnection (PCI) bus.

[0232] The electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 12, including volatile and non-volatile media, removable and non-removable media.

[0233] The memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 34 may be used to read and write non-removable, non-volatile magnetic media ( Fig.15 not shown, usually called a "hard drive"). Although Fig.15 Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing a removable non-volatile optical disk (e.g., a compact disc read only memory (CD-ROM), a digital versatile disc read only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 via one or more data medium interfaces. The memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the various embodiments of the present disclosure.

[0234] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in the memory 28, such program modules 42 including but not limited to an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods of the embodiments described in the present disclosure.

[0235] The electronic device 12 may also communicate with one or more external devices 14 (e.g., keyboards, pointing devices, displays 24, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 12, and / or may communicate with any device that enables the electronic device 12 to communicate with one or more other computing devices (e.g., network cards, modems, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the electronic device 12 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with other modules of the electronic device 12 via a bus 18. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0236] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the methods mentioned in the above embodiments.

[0237] In order to implement the above embodiments, the present disclosure also proposes a chip, which includes a processing circuit and an interface circuit; wherein the interface circuit is used to obtain instructions and send the instructions to the processing circuit, and the processing circuit is used to execute instructions to implement the data storage method proposed in the above embodiments of the present disclosure.

[0238] Fig.16 is a schematic diagram of the structure of the chip proposed in the embodiment of the present disclosure. Fig.16 The structure of the chip 1600 is shown, but is not limited to this.

[0239] The chip 1600 includes a processing circuit 1601 , and the processing circuit 1601 is configured to execute any of the above methods.

[0240] In some embodiments, the chip 1600 further includes one or more interface circuits 1602. Optionally, the interface circuit 1602 is connected to the memory 1603. The interface circuit 1602 can be used to receive signals from the memory 1603 or other devices, and the interface circuit 1602 can be used to send signals to the memory 1603 or other devices. For example, the interface circuit 1602 can read instructions stored in the memory 1603 and send the instructions to the processing circuit 1601.

[0241] In some embodiments, the interface circuit 1602 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processing circuit 1601 performs other steps.

[0242] In some embodiments, terms such as interface circuit, interface, transceiver pin, and transceiver may be used interchangeably.

[0243] In some embodiments, the chip 1600 further includes one or more memories 1603 for storing instructions. Alternatively, all or part of the memory 1603 may be outside the chip 1600.

[0244] In order to implement the above embodiments, the present disclosure further proposes a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the data storage method proposed in the above embodiments of the present disclosure is implemented.

[0245] In order to implement the above embodiments, the present disclosure also proposes a computer program product, including a computer program, which implements the data storage method provided by the above embodiments when executed by a processor.

[0246] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0247] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, "plurality" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0248] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code that includes one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present disclosure includes additional implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present disclosure belong.

[0249] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute the instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways if necessary, and then stored in a computer memory.

[0250] It should be understood that the various parts of the present disclosure can be implemented in hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0251] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0252] In addition, each functional unit in each embodiment of the present disclosure may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0253] The storage medium mentioned above may be a read-only memory, a disk or an optical disk, etc. Although the embodiments of the present disclosure have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations of the present disclosure. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present disclosure.

Claims

1. A data storage method, characterized in that: include: Receiving a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area; In response to the target storage area being located in the second device, sending a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device; In response to receiving a second public key corresponding to the second device, determining a channel key based on a first private key corresponding to the first device and the second public key; Based on the channel key, the data to be stored is sent to store the data to be stored in the target storage area.

2. The method according to claim 1, characterized in that Before sending the transmission channel establishment request, the method further includes: Determining a common parameter based on user information associated with the first device according to a preset rule; The first public key is determined based on the public parameter and a first private key corresponding to the first device.

3. The method according to claim 1, characterized in that Before sending the transmission channel establishment request, the method further includes: The first public key is determined based on pre-configured public parameters and a first private key corresponding to the first device.

4. The method according to claim 1, characterized in that The sending the data to be stored based on the channel key includes: In response to the data to be stored being unencrypted and the first device having a data encryption key, encrypting the data to be stored based on the data encryption key to obtain encrypted data; Based on the channel key, the encrypted data is sent.

5. The method according to claim 4, characterized in that The method further comprises: receiving a data encryption key generation instruction, wherein the generation instruction includes a key derivation factor; generating the data encryption key based on the key derivation factor; The data encryption key is stored in a preset location in the first device.

6. The method according to any one of claims 1 to 5, characterized in that: The sending of the transmission channel establishment request comprises: Determining the storage space required for the data to be stored; Determine the current remaining capacity of the shared storage space of the second device; In response to the remaining capacity being greater than or equal to the storage space required for the data to be stored, a transmission channel establishment request is sent.

7. The method according to claim 6, characterized in that The method further comprises: In response to the remaining capacity being less than the storage space required for the data to be stored, displaying a storage abnormality prompt on the display interface; In response to the third device identifier being selected, sending a transmission channel establishment request, wherein the transmission channel establishment request includes the first public key, and the third device is different from the second device; In response to receiving a third public key corresponding to the third device, determining a channel key based on the first private key and the third public key; Based on the channel key, the data to be stored is sent to store the data to be stored in the third device.

8. The method according to claim 6, characterized in that The method further comprises any of the following: A remaining capacity synchronization message is received, wherein the synchronization message includes a current remaining capacity of the shared storage space in the second device.

9. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Receiving a storage space sharing setting instruction, wherein the sharing setting instruction includes at least two device identifiers and a shared storage space capacity corresponding to each of the devices; Partitioning a storage area in the first device based on a shared storage space capacity corresponding to the first device to obtain a shared storage area corresponding to the first device; The at least two device identifications are added to the candidate data storage locations.

10. A data storage method, characterized in that: include: receiving a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key corresponding to the first device; Sending a second public key corresponding to the second device; Determine a channel key based on a second private key corresponding to the second device and the first public key; Based on the channel key, data to be stored is received, and the data to be stored is stored in a shared storage area.

11. The method according to claim 10, characterized in that Before sending the second public key corresponding to the second device, the method further includes: Based on a public parameter and a second private key corresponding to the second device, a second public key corresponding to the second device is determined, wherein the public parameter is pre-configured or determined based on user information associated with the second device according to a preset rule.

12. The method according to claim 10, characterized in that Also includes: receiving a data encryption key generation instruction, wherein the generation instruction includes a key derivation factor; Based on the key derivation factor, a data encryption key is generated.

13. The method according to claim 10, characterized in that Also includes: Send a remaining capacity synchronization message, wherein the synchronization message includes the current remaining capacity of the shared storage space in the second device.

14. The method according to any one of claims 10 to 13, characterized in that: The method further comprises: Receiving a storage space sharing setting instruction, wherein the sharing setting instruction includes at least two device identifiers and a shared storage space capacity corresponding to each of the devices; Partitioning a storage area in the second device based on a shared storage space capacity corresponding to the second device to obtain a shared storage area corresponding to the second device; The at least two device identifications are added to the candidate data storage locations.

15. A data storage device, characterized in that: include: A first receiving module, configured to receive a data storage instruction, wherein the storage instruction includes data to be stored and a target storage area; A first sending module, configured to send a transmission channel establishment request in response to the target storage area being located in the second device, wherein the transmission channel establishment request includes a first public key corresponding to the first device; a first computing module, configured to determine a channel key based on a first private key corresponding to the first device and the second public key in response to receiving a second public key corresponding to the second device; The second sending module is used to send the data to be stored based on the channel key, so as to store the data to be stored in the target storage area.

16. A data storage device, characterized in that: include: A second receiving module, configured to receive a transmission channel establishment request, wherein the transmission channel establishment request includes a first public key; A third sending module, used to send a second public key corresponding to the second device; A second calculation module, configured to determine a channel key based on a second private key corresponding to the second device and the first public key; The storage module is used to receive the data to be stored based on the channel key, and store the data to be stored in the shared storage area.

17. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the data storage method according to any one of claims 1 to 14 is implemented.

18. A chip, characterized in that: The chip includes a processing circuit and an interface circuit; wherein the interface circuit is used to obtain instructions and send the instructions to the processing circuit, and the processing circuit is used to execute the instructions to implement the data storage method as described in any one of claims 1-14.

19. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the data storage method according to any one of claims 1 to 14 is implemented.

20. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the data storage method according to any one of claims 1 to 14.

Citation Information

Patent Citations

  • Method and apparatus for implementing key stream hierarchy

    CN103988465A

  • Equipment communication method and device and storage medium

    CN115022873A

  • Key determination method and device, electronic equipment and computer readable storage medium

    CN117560150A