Secret key processing method of hard disk and electronic equipment
By storing and protecting the unlocking key of the second electronic device on the partition of the first electronic device, the problem that the self-encrypted hard disk cannot securely backup the unlocking key is solved, and the reliability of hard disk unlocking is improved.
Patent Information
- Application Number
- CN202510217523.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-30
AI Technical Summary
The existing self-encrypted hard disk cannot securely back up the unlock key without deploying KMIP and encryption chips, resulting in insufficient reliability of hard disk unlocking.
By storing the unlocking key of the second electronic device on the first partition of the first electronic device and protecting the key using a data signature, the second electronic device is provided for hard disk unlocking.
It is realized that without deploying KMIP and encryption chips, the unlocking key of the second electronic device can be safely backed up and used, thereby improving the reliability of hard disk unlocking.
Smart Images

Figure CN120066996A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a method for processing a key of a hard disk and an electronic device. Background Art
[0002] Currently, in order to improve data security, self-encrypting hard disks can be deployed. There are various types of self-encrypting hard disks.
[0003] Different types of self-encrypting hard disks use different methods to back up the unlocking key. For example, a self-encrypting hard disk can deploy the Key Management Interoperability Protocol (KMIP), and the unlocking key is backed up by a remote server. Alternatively, a self-encrypting hard disk can deploy an encryption chip to back up the unlocking key.
[0004] Therefore, hard disks without KMIP and encryption chips cannot securely back up the unlocking key. Summary of the Invention
[0005] In view of this, this application provides a method for processing a key of a hard disk and an electronic device, as follows:
[0006] A method for processing a key of a hard disk includes:
[0007] A first electronic device obtains the unlocking keys of at least one second electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers;
[0008] The first electronic device stores the unlocking keys of the second electronic device in a first partition of the first electronic device, and the first partition protects the stored data based on a data signature;
[0009] Wherein, the unlocking keys in the first partition are used to be provided to the second electronic device, and the second electronic device uses the unlocking keys to unlock a target hard disk.
[0010] In the above method, preferably, the first electronic device obtains the unlocking keys of at least one second electronic device, including:
[0011] The first electronic device generates the unlocking keys of the second electronic device according to the group password corresponding to the device group and the device identifier of the second electronic device;
[0012] Or, the first electronic device generates the unlocking keys of the second electronic device according to the group password, the device identifier of the second electronic device, and the passcode corresponding to the second electronic device;
[0013] Wherein, the group password is set by the first electronic device for the device group.
[0014] In the above method, preferably, the first electronic device obtains the unlocking keys of at least one second electronic device, including:
[0015] The first electronic device receives the unlocking keys sent by the second electronic device;
[0016] Wherein, the second electronic device generates the unlocking keys according to the group password corresponding to the device group and the device identifier of the second electronic device;
[0017] Or, the second electronic device generates the unlocking keys according to the group password, the device identifier of the second electronic device, and the passcode corresponding to the second electronic device;
[0018] Wherein, the group password is set by the first electronic device for the device group and sent to the second electronic device.
[0019] In the above method, preferably, the first electronic device stores the unlocking keys of the second electronic device in the first partition of the first electronic device, including:
[0020] The first electronic device encrypts the unlocking keys of the second electronic device using the group password to obtain a target key;
[0021] The target key is stored in the first partition of the first electronic device.
[0022] In the above method, preferably, the first electronic device encrypts the unlocking keys of the second electronic device using the group password to obtain a target key, including:
[0023] The first electronic device performs a hash calculation on the group password to obtain a target hash value;
[0024] The unlocking keys of the second electronic device are encrypted using the target hash value to obtain a target key.
[0025] In the above method, preferably, the method further includes:
[0026] In response to a target message indicating that the unlocking of the target hard disk on the second electronic device fails, the first electronic device reads the target key corresponding to the second electronic device from the first partition;
[0027] The target key corresponding to the second electronic device is sent to the second electronic device; the second electronic device decrypts the target key using the group password to obtain the unlocking keys of the second electronic device.
[0028] A method for processing keys of a hard disk, including:
[0029] The second electronic device receives the unlocking key of the second electronic device sent by the first electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition of the first electronic device; the first partition protects the stored data based on data signature;
[0030] The second electronic device stores the unlocking key of the second electronic device in the second partition of the second electronic device, and the second partition protects the stored data based on data signature;
[0031] In response to a power-on instruction, the second electronic device reads the unlocking key from the second partition and sends the unlocking key to the target hard disk in the second electronic device, and the target hard disk is unlocked using the unlocking key.
[0032] In the above method, preferably, the unlocking key in the second partition is encrypted and stored based on a group password; the group password is set by the first electronic device for the device group and sent to the second electronic device;
[0033] Wherein, the method further includes:
[0034] The second electronic device creates a new key for unlocking the target hard disk;
[0035] Update the new key to the second partition, and send the new key to the first electronic device, and the first electronic device updates the new key of the second electronic device to the first partition.
[0036] An electronic device, when the electronic device is used as the first electronic device, includes:
[0037] A first partition and a baseboard management controller;
[0038] Wherein, the baseboard management controller obtains the unlocking keys of at least one second electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; store the unlocking keys of the second electronic device in the first partition, and the first partition protects the stored data based on data signature;
[0039] The unlocking key in the first partition is used to be provided to the second electronic device, and the second electronic device uses the unlocking key to unlock the target hard disk.
[0040] An electronic device, when the electronic device is used as the second electronic device, includes:
[0041] A target hard disk, a second partition, and a baseboard management controller;
[0042] Wherein, the baseboard management controller receives the unlocking key of the second electronic device sent by the first electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition of the first electronic device; the first partition protects the stored data based on a data signature; the unlocking key of the second electronic device is stored in the second partition, and the second partition protects the stored data based on a data signature; in response to a power-on instruction, the unlocking key is read from the second partition and sent to the target hard disk, and the target hard disk uses the unlocking key to unlock.
[0043] A computer device / system, comprising: a memory, a processor, and a computer program stored on the memory, wherein the processor executes the computer program to implement the key processing method of the hard disk described in any one of the above.
[0044] A computer-readable storage medium, on which a computer program / instructions are stored, and when the computer program / instructions are executed by a processor, the key processing method of the hard disk described in any one of the above is implemented.
[0045] A computer program product, comprising computer program / instructions, and when the computer program / instructions are executed by a processor, the key processing method of the hard disk described in any one of the above is implemented.
[0046] As can be seen from the above technical solutions, in a key processing method of a hard disk and an electronic device disclosed in the present application, an unlocking key for a second electronic device is stored on a first partition of a first electronic device for providing the second electronic device to unlock the hard disk. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device, and the storage of the unlocking key of the second electronic device is realized through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking. Description of the Drawings
[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 It is a flowchart of a key processing method of a hard disk provided by an embodiment of the present application;
[0049] Figure 2 It is a schematic diagram of the architecture of the device group in the embodiment of the present application;
[0050] Figure 3 It is a schematic diagram of the device group composed of the master node and the slave node in the embodiment of the present application;
[0051] Figure 4 It is a schematic diagram of processing the unlocking key between the master node and the slave node in the embodiment of the present application;
[0052] Figure 5 It is another schematic diagram of processing the unlocking key between the master node and the slave node in the embodiment of the present application;
[0053] Figure 6 It is yet another schematic diagram of processing the unlocking key between the master node and the slave node in the embodiment of the present application;
[0054] Figure 7 It is another schematic diagram of processing the unlocking key between the master node and the slave node in the embodiment of the present application;
[0055] Figure 8 It is yet another schematic diagram of the device group composed of the master node and the slave node in the embodiment of the present application;
[0056] Figure 9 It is a flowchart of the implementation of a method for processing the key of a hard disk provided in the embodiment of the present application;
[0057] Figure 10 It is a schematic structural diagram of a device for processing the key of a hard disk provided in the embodiment of the present application;
[0058] Figure 11 It is another schematic structural diagram of a device for processing the key of a hard disk provided in the embodiment of the present application;
[0059] Figure 12 It is a schematic structural diagram of another device for processing the key of a hard disk provided in the embodiment of the present application;
[0060] Figure 13 It is another schematic structural diagram of a device for processing the key of a hard disk provided in the embodiment of the present application;
[0061] Figure 14 It is a schematic structural diagram of an electronic device provided in the embodiment of the present application;
[0062] Figure 15 It is a schematic structural diagram of another electronic device provided in the embodiment of the present application;
[0063] Figure 16 It is a schematic diagram of a device group including multiple servers in the embodiment of the present application. Detailed implementation manners
[0064] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0065] Refer to Figure 1 As shown, it is a flowchart of the implementation of a method for processing the unlocking key of a hard disk provided by an embodiment of the present application. This method can be applied to a first electronic device that can establish a connection with at least one second electronic device and can perform data processing, such as Figure 2 shown. A master-slave relationship is formed between the first electronic device and the second electronic device. The first electronic device serves as the master node, and the second electronic device serves as the slave node. The master node provides a backup of the unlocking key for the slave node. The technical solutions in this embodiment are mainly used to improve the reliability of hard disk unlocking.
[0066] Specifically, the method in this embodiment may include the following steps:
[0067] Step 101: The first electronic device obtains the unlocking keys of at least one second electronic device.
[0068] Among them, the second electronic device and the first electronic device are divided into the same device group through their respective Baseboard Management Controllers (BMCs). For example, according to business requirements, the user sets the first electronic device and multiple second electronic devices so that the first electronic device and the second electronic device are divided into the same device group through their respective BMCs.
[0069] In one implementation, the first electronic device can obtain the corresponding unlocking key for each second electronic device.
[0070] For example, as Figure 3 shown, electronic devices A, B, C, D, and E are divided into the same device group. Electronic device C is set as the master node, and electronic devices A, B, D, and E are set as slave nodes. The master node C obtains the corresponding unlocking keys for the slave nodes A, B, D, and E respectively.
[0071] Step 102: The first electronic device stores the unlocking keys of the second electronic device in the first partition of the first electronic device.
[0072] Among them, the first partition protects the stored data based on a data signature. The unlocking key in the first partition is used to be provided to a second electronic device. The second electronic device can use the unlocking key to unlock a target hard disk. The target hard disk is deployed in the second electronic device. For example, the target hard disk can be a hard disk that needs to be locked to protect the stored data, such as a self-encrypting hard disk. The second electronic device can also receive the unlocking key of the second electronic device sent by the first electronic device, store the received unlocking key in the second partition of the second electronic device, and the second partition protects the stored data based on a data signature. The second electronic device can, in response to a power-on instruction, read the unlocking key from the second partition and send the unlocking key to the target hard disk in the second electronic device, and the target hard disk uses the unlocking key to unlock.
[0073] In one implementation, the first partition can be a Replay Protected Memory Block (RPMB) in the first electronic device. The RPMB partition is a partition with security features in an Embedded MultiMedia Card (eMMC). The RPMB can authenticate write operations, and the data stored in the RPMB is encrypted before being stored. Based on this, in this embodiment, storing the unlocking key of each second electronic device in the RPMB of the first electronic device can ensure the security of the unlocking key.
[0074] It can be seen from the above technical solution that in a key processing method for a hard disk provided in an embodiment of the present application, the unlocking key for the second electronic device is stored on the first partition of the first electronic device and is used to be provided to the second electronic device for hard disk unlocking. In this way, there is no need to deploy a Key Management Interoperability Protocol (KMIP) or an encryption chip on the second electronic device. The storage of the unlocking key of the second electronic device is achieved through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking.
[0075] In one implementation, the first electronic device obtaining the unlocking keys of at least one second electronic device in step 101 can be achieved by the following method:
[0076] The first electronic device generates the unlocking key of the second electronic device according to the group password corresponding to the device group and the device identifier of the second electronic device.
[0077] Among them, the device identifier of the second electronic device can include the machine type (MT) and the serial number (SN) of the electronic device, and the group password corresponding to the device group can be represented by GroupPwd.
[0078] It should be noted that the group password corresponding to the device group can be set for the device group by the first electronic device.
[0079] For example, Figure 3 taking as an example, in the scenario of initial formation of the device group or the scenario where the unlocking key needs to be updated after the creation of the device group, the master node C sets the group password GroupPwd for the device group and sends it to each slave node. Each slave node sends its machine model MT and device serial number SN to the master node C. As Figure 4 shown, on the master node C, for each slave node, the unlocking key for the corresponding slave node is generated respectively according to the group password, the machine model MT and the device serial number SN of the slave node. After that, the master node C sends the unlocking key of each slave node to the corresponding slave node.
[0080] In another implementation manner, the first electronic device obtaining the unlocking keys of at least one second electronic device in step 101 can be achieved in the following way:
[0081] The first electronic device generates the unlocking key of the second electronic device according to the group password, the device identifier of the second electronic device and the passcode corresponding to the second electronic device.
[0082] Among them, the passcode of the second electronic device can be set for the second electronic device by the first electronic device and sent to the second electronic device for recording. The passcode can be represented by passphrase.
[0083] For example, Figure 3 taking as an example, in the scenario of initial formation of the device group or the scenario where the unlocking key needs to be updated after the creation of the device group, the master node C sets the group password GroupPwd for the device group and sets the passcode passphrase for each slave node. Each slave node sends its machine model MT and device serial number SN to the master node C. As Figure 5 shown, on the master node C, for each slave node, the unlocking key for the corresponding slave node is generated respectively according to the group password, the machine model MT and the device serial number SN of the slave node and the passcode passphrase. After that, the master node C sends the unlocking key of each slave node to the corresponding slave node.
[0084] In another implementation manner, the first electronic device in step 101 can also receive the unlocking keys sent by the second electronic devices to obtain the unlocking keys of each second electronic device.
[0085] In one case, the second electronic device can generate the unlocking key of the second electronic device according to the group password corresponding to the device group and the device identifier of the second electronic device.
[0086] Among them, the group password corresponding to the device group can be set by the first electronic device for the device group and sent to the second electronic device. After the second electronic device generates the unlocking key, it is sent to the first electronic device, and the first electronic device can receive the unlocking keys of each second electronic device.
[0087] For example, Figure 3 Take as an example. In the case of initial formation of the device group, or when the unlocking key needs to be updated after the creation of the device group, the master node C sets the group password GroupPwd for the device group and sends the group password to each slave node. As Figure 6 shown, each slave node generates the corresponding unlocking key according to the group password, its own machine type MT and device serial number SN, and then sends the unlocking key to the master node C.
[0088] In another case, the second electronic device can generate the unlocking key of the second electronic device according to the group password, the device identifier of the second electronic device, and the passcode corresponding to the second electronic device.
[0089] Among them, the passcode of the second electronic device can be set by the first electronic device for the second electronic device and sent to the second electronic device for recording. The passcode can be represented by "passphrase".
[0090] For example, Figure 3 Take as an example. In the case of initial formation of the device group, or when the unlocking key needs to be updated after the creation of the device group, the master node C sets the group password GroupPwd for the device group and sets the passcode "passphrase" for each slave node, and sends the group password and the passcode corresponding to the slave node to the slave node. As Figure 7 shown, each slave node generates the corresponding unlocking key of the slave node according to the group password, the machine type MT and device serial number SN of the slave node, and the passcode "passphrase", and then sends the unlocking key to the master node C.
[0091] It should be noted that the first electronic device can set a group password according to the group configuration information of the device group, and send a group entry request to each second electronic device based on the multicast message received from the second electronic device. The multicast message may include the node account and node password of the second electronic device, and the group entry request may include the node account and node password of the second electronic device, the group password, and a passcode, where the passcode is the passcode set by the first electronic device for each second electronic device. Each second electronic device records the passcode sent by the first electronic device and sends a group entry message to the first electronic device, where the group entry message indicates that the second electronic device determines to enter the same device group as the first electronic device. The first electronic device can generate an unlocking key for the second electronic device according to the implementation method described above or receive the unlocking key generated by the second electronic device and store it in the first partition, and the second electronic device saves the unlocking key generated by itself or received from the first electronic device in the second partition.
[0092] In one implementation, when the first electronic device stores the unlocking key of the second electronic device in the first partition of the first electronic device in step 102, it can first encrypt the unlocking key of the second electronic device with the group password to obtain a target key, and then store the target key in the first partition of the first electronic device.
[0093] For example, Figure 3 taking the main node C as an example, it encrypts the unlocking key of each slave node with the group password GroupPwd to obtain a target key, and then stores the target key in the RPMB.
[0094] In a possible implementation, the first electronic device can first calculate the hash value of the group password to obtain a target hash value, and then encrypt the unlocking key of the second electronic device with the target hash value to obtain a target key.
[0095] In a possible implementation, the first electronic device can encrypt the group password with an encryption key to obtain an encrypted string, and then encrypt the unlocking key of the second electronic device with the encrypted string to obtain a target key.
[0096] Based on the above implementation, the first electronic device can, in response to a target message indicating that the unlocking of the target hard disk on the second electronic device fails, read the target key corresponding to the second electronic device from the first partition; then, send the target key corresponding to the second electronic device to the second electronic device. And the second electronic device can decrypt the target key according to the group password to obtain the unlocking key of the second electronic device.
[0097] Among them, when using the unlocking key to unlock the target hard disk on the second electronic device, there may be a situation where the unlocking fails. For example, replacing the motherboard of the second electronic device causes the unlocking key to fail to unlock the target hard disk. At this time, the second electronic device sends a target message to the first electronic device. In response to the target message, the first electronic device reads the encrypted unlocking key corresponding to the second electronic device from the first partition, and then sends the encrypted unlocking key to the second electronic device. Since the unlocking key is encrypted, the security of the unlocking key can be guaranteed during the transmission process. After that, after receiving the encrypted unlocking key, the second electronic device can use the group password to decrypt the encrypted unlocking key to obtain the decrypted unlocking key. Finally, the second electronic device can store the unlocking key in the second partition such as RPMB to facilitate unlocking the target hard disk with the unlocking key.
[0098] For example, Figure 3 take the case where the unlocking of the target hard disk using the unlocking key by the slave node A fails. The slave node A sends a target message indicating the unlocking failure to the master node C. In response to the target message, the master node C reads the unlocking key encrypted by the group password corresponding to the slave node A from the RPMB and sends it to the slave node A. After receiving the encrypted unlocking key, the slave node A uses the group password to decrypt the encrypted unlocking key to obtain the unlocking key of the slave node A. The slave node A saves the unlocking key to the RPMB of the slave node A. When it is necessary to unlock the target hard disk, the slave node A can read the unlocking key from the RPMB and then use the unlocking key to unlock the target hard disk.
[0099] In one implementation, the first electronic device can back up the unlocking key in the first partition to the third partition of the third electronic device. The third partition protects the stored data based on data signatures. The third electronic device and the first electronic device are in the same device group. The third electronic device can be one of the second electronic devices, or the third electronic device can be other electronic devices different from the second electronic device.
[0100] Based on this, when the first electronic device fails, the third electronic device can replace the first electronic device to provide the unlocking key for the second electronic device.
[0101] For example, Figure 3 take the case where the backup node B is the backup of the master node A. As Figure 8 shown, the unlocking keys of each slave node such as A, D, and E sent by the master node A are stored in the RPMB of the backup node B. It should be noted that the unlocking keys are encrypted by the group password. When the master node C fails, the backup node B can replace the master node C as the new master node to provide the unlocking key for the slave nodes A, D, and E.
[0102] Reference Figure 9 , which is a flowchart of the implementation of a key processing method for a hard disk provided by an embodiment of the present application. This method can be applied to a second electronic device that can be connected to a first electronic device and is deployed with a target hard disk, as shown in Figure 2 . A master-slave relationship is formed between the first electronic device and the second electronic device. The first electronic device serves as the master node, and the second electronic device serves as the slave node. The master node provides a backup of the unlocking key for the slave node. The technical solution in this embodiment is mainly used to improve the reliability of hard disk unlocking.
[0103] Specifically, the method in this embodiment may include the following steps:
[0104] Step 901: The second electronic device receives the unlocking key of the second electronic device sent by the first electronic device.
[0105] Among them, the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers. The unlocking key of the second electronic device is stored in the first partition of the first electronic device. The first partition protects the stored data based on data signatures, such as RPMB.
[0106] Step 902: The second electronic device stores the unlocking key of the second electronic device in the second partition of the second electronic device.
[0107] Among them, the second partition protects the stored data based on data signatures, such as RPMB.
[0108] It should be noted that the received unlocking key of the second electronic device can be an encrypted key. In this way, the second electronic device can directly store the unlocking key in the second partition after receiving it.
[0109] Step 903: In response to the power-on instruction, the second electronic device reads the unlocking key from the second partition and sends the unlocking key to the target hard disk in the second electronic device.
[0110] Among them, the target hard disk is unlocked using the unlocking key.
[0111] It should be noted that the unlocking key in the second partition is encrypted. Based on this, after the second electronic device reads the unlocking key from the second partition, it can first decrypt the unlocking key to obtain the decrypted unlocking key, and then send the unlocking key to the target hard disk of the second electronic device.
[0112] As can be seen from the above technical solution, in a key processing method for a hard disk provided by an embodiment of the present application, an unlocking key is stored for a second electronic device on a first partition of a first electronic device. The second electronic device can store the unlocking key sent by the first electronic device in a second partition. When starting up, the unlocking key can be read from the second partition and provided to the target hard disk. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device, and the storage of the unlocking key of the second electronic device is realized through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking.
[0113] In one implementation, the unlocking key in the second partition is encrypted and stored based on the group password of the device group where the second electronic device is located. The group password is set by the first electronic device for the device group and sent to the second electronic device.
[0114] For example, Figure 3 taking [example], the master node C generates a group password and sends the group password to each slave node such as A, B, D, and E.
[0115] Based on this, a new key for unlocking the target hard disk can be recreated on the second electronic device, then the new key is updated to the second partition, and the new key is sent to the first electronic device. The first electronic device updates the new key of the second electronic device to the first partition.
[0116] Among them, the second electronic device can generate an unlocking key according to the group password corresponding to the device group and the device identifier of the second electronic device, or can generate an unlocking key according to the group password, the device identifier of the second electronic device, and the passcode corresponding to the second electronic device. Then, the second electronic device encrypts the unlocking key using the group password, stores the encrypted unlocking key in the second partition, and synchronously updates the encrypted unlocking key to the first partition of the first electronic device.
[0117] Alternatively, on the second electronic device, a new key for unlocking the target hard disk recreated by the first electronic device can be received, and the new key is updated to the second partition.
[0118] For example, Figure 3 taking [example], when the slave node A needs to update the unlocking key, it can generate the unlocking key of the corresponding slave node A according to the group password, the machine model MT and device serial number SN of the slave node A, and the passphrase. The slave node A encrypts the unlocking key using the group password and stores the encrypted unlocking key in the RPMB of the slave node A, and synchronously updates it to the RPMB of the master node C.
[0119] In a specific implementation, each time the second electronic device is powered on, after the Basic Input Output System (BIOS) starts, the Self-Encrypting Drive (SED) management driver of the BIOS sends a read request to the BMC. The BMC reads the target key (i.e., the unlock key encrypted by the group password) from the RPMB, then decrypts the target key according to the group password, and returns the decrypted unlock key to the BIOS. The BIOS sends the unlock key to the target hard disk, and the target hard disk can use the unlock key to calculate the hash value of the feature data, and compare the calculated hash value with the existing hash value of the target hard disk. If the comparison is consistent, the target hard disk can be determined to be unlocked.
[0120] In the case where the second electronic device fails to unlock the target hard disk, a target message is generated and sent to the first electronic device. The first electronic device reads the unlock key of the second electronic device from the first partition in response to the target message and sends it to the second electronic device, and the second electronic device updates the unlock key to the second partition and uses the unlock key in the second partition to unlock the target hard disk. Alternatively, the first electronic device sends a prompt message in response to the target message, and the prompt message is used to prompt the user of the first electronic device to manually send the unlock key to the second electronic device.
[0121] When the unlock key needs to be updated, each second electronic device can regenerate the unlock key and send it to the first electronic device, and the first electronic device saves the unlock key to the first partition; or the first electronic device generates the unlock key for each second electronic device and saves it to the first partition.
[0122] Furthermore, in the case where the first electronic device fails, the third electronic device replaces the first electronic device as the new first electronic device to provide the unlock key for each second electronic device.
[0123] For example, as Figure 8As shown, electronic devices A, B, C, D, and E are divided into the same device group. Electronic device C is set as the master node, electronic device B is the backup node, and electronic devices A, D, and E are set as slave nodes. The master node C sets the group password GroupPwd for the device group and sends it to each slave node. Each slave node sends its machine model MT and device serial number SN to the master node C. On the master node C, for each slave node, the unlocking key for the corresponding slave node is generated respectively according to the group password, the machine model MT, and the device serial number SN of the slave node. Or, the master node C sets the group password GroupPwd for the device group and sends the group password to each slave node. Each slave node generates the corresponding unlocking key according to the group password, its own machine model MT, and device serial number SN, and then sends the unlocking key to the master node C. The master node C encrypts the unlocking key of each slave node using the group key to obtain the target key of each slave node. The target key of each slave node is stored in the RPMB of the master node C. At the same time, the master node C synchronously backs up these target keys to the RPMB of the backup node B.
[0124] Based on this, taking slave node A as an example, when slave node A boots up, after the BIOS of slave node A starts, it sends a read request to the BMC. The BMC reads the target key (i.e., the unlocking key encrypted by the group password) from the RPMB, then decrypts the target key according to the group password, and returns the decrypted unlocking key to the BIOS of slave node A. The BIOS of slave node A sends the unlocking key to the target hard disk. The target hard disk can use the unlocking key to calculate the hash value of the feature data, and compare the calculated hash value with the existing hash value of the target hard disk. If the comparison is consistent, slave node A can determine to unlock the target hard disk.
[0125] In the case where slave node A fails to determine to unlock the target hard disk, a target message is generated and sent to the master node C. The master node C reads the unlocking key of slave node A from the RPMB in response to the target message and sends it to slave node A, and slave node A updates the unlocking key to its own RPMB and uses the unlocking key in the RPMB to unlock the target hard disk. Or, in response to the target message, the master node C sends a prompt message, which is used to prompt the user of the master node C to manually send the unlocking key to slave node A.
[0126] When the unlocking key of slave node A needs to be updated, slave node A can regenerate the unlocking key and send it to the master node C, and the master node C saves the unlocking key to its own RPMB; or, the master node C generates the unlocking key for slave node A and saves it to the RPMB of the master node C.
[0127] Furthermore, in the case where the master node C fails, the backup node B replaces the master node C as the new master node to provide the unlocking key for each slave node.
[0128] Reference Figure 10 , which is a schematic structural diagram of a key processing device for a hard disk provided in an embodiment of the present application. This device can be applied to a first electronic device that can establish a connection with at least one second electronic device and can perform data processing, such as Figure 2 as shown in. A master-slave relationship is formed between the first electronic device and the second electronic device. The first electronic device serves as the master node, and the second electronic device serves as the slave node. The master node provides a backup of the unlock key for the slave node. The technical solution in this embodiment is mainly used to improve the reliability of hard disk unlocking.
[0129] Specifically, the device in this embodiment may include the following units:
[0130] A key acquisition unit 1001, configured to acquire the unlock keys of at least one second electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers;
[0131] A key storage unit 1002, configured to store the unlock keys of the second electronic device in a first partition of the first electronic device, and the first partition protects the stored data based on data signatures;
[0132] Among them, the unlock keys in the first partition are used to be provided to the second electronic device, and the second electronic device uses the unlock keys to unlock the target hard disk.
[0133] It can be seen from the above technical solution that in a key processing device for a hard disk provided in an embodiment of the present application, the unlock keys of the second electronic device are stored in the first partition on the first electronic device for the second electronic device to use for hard disk unlocking. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device. The unlock keys of the second electronic device are stored through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlock keys will not occur, thereby improving the reliability of hard disk unlocking.
[0134] In one implementation, the key acquisition unit 1001 is specifically configured to: generate the unlock key of the second electronic device according to the group password corresponding to the device group and the device identifier of the second electronic device; or, generate the unlock key of the second electronic device according to the group password, the device identifier of the second electronic device, and the passcode corresponding to the second electronic device; wherein, the group password is set by the first electronic device for the device group.
[0135] In one implementation, the key acquisition unit 1001 is specifically configured to: The first electronic device receives the unlocking key sent by the second electronic device; wherein, the second electronic device generates the unlocking key according to the group password corresponding to the device group and the device identifier of the second electronic device; or, the second electronic device generates the unlocking key according to the group password, the device identifier of the second electronic device, and the access code corresponding to the second electronic device; wherein, the group password is set by the first electronic device for the device group and sent to the second electronic device.
[0136] In one implementation, the key storage unit 1002 is specifically configured to: Encrypt the unlocking key of the second electronic device using the group password to obtain a target key; Store the target key in the first partition of the first electronic device.
[0137] Wherein, when the key storage unit 1002 encrypts the unlocking key of the second electronic device using the group password to obtain a target key, it is specifically configured to: Perform a hash calculation on the group password to obtain a target hash value; Encrypt the unlocking key of the second electronic device using the target hash value to obtain a target key.
[0138] In one implementation, the device in this embodiment may further include the following units, as Figure 11 shown in:
[0139] The key reading unit 1003 is configured to, in response to a target message that the target hard disk unlocking of the second electronic device fails, read the target key corresponding to the second electronic device from the first partition; Send the target key corresponding to the second electronic device to the second electronic device; The second electronic device decrypts the target key according to the group password to obtain the unlocking key of the second electronic device.
[0140] It should be noted that the specific implementation manners of the units in this embodiment may refer to the corresponding content in the foregoing text, and will not be elaborated here.
[0141] Refer to Figure 12 , which is a schematic structural diagram of a key processing device for a hard disk provided by an embodiment of the present application. This device can be applied to a second electronic device that can be connected to the first electronic device and is deployed with a target hard disk, as Figure 2 shown in. A master-slave relationship is formed between the first electronic device and the second electronic device. The first electronic device serves as the master node, and the second electronic device serves as the slave node. The master node provides a backup of the unlocking key for the slave node. The technical solution in this embodiment is mainly used to improve the reliability of hard disk unlocking.
[0142] Specifically, the device in this embodiment may include the following units:
[0143] A key receiving unit 1201, configured to receive the unlocking key of the second electronic device sent by the first electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition of the first electronic device; the first partition protects the stored data based on data signature.
[0144] A key storage unit 1202, configured to store the unlocking key of the second electronic device into the second partition of the second electronic device, and the second partition protects the stored data based on data signature.
[0145] A key reading unit 1203, configured to, in response to a power-on instruction, read the unlocking key from the second partition and send the unlocking key to a target hard disk in the second electronic device, and the target hard disk unlocks using the unlocking key.
[0146] It can be seen from the above technical solution that in a key processing device for a hard disk provided by an embodiment of the present application, an unlocking key for a second electronic device is stored in a first partition on a first electronic device. The second electronic device can store the unlocking key sent by the first electronic device into a second partition. When starting up, the unlocking key can be read from the second partition and provided to the target hard disk. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device. The unlocking key of the second electronic device is stored through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking.
[0147] In one implementation, the unlocking key in the second partition is encrypted and stored based on a group password; the group password is set by the first electronic device for the device group and sent to the second electronic device.
[0148] Among them, the device in this embodiment may further include the following units, as Figure 13 shown in
[0149] A key updating unit 1204, configured to create a new key for unlocking the target hard disk; update the new key to the second partition, and send the new key to the first electronic device, and the first electronic device updates the new key of the second electronic device to the first partition.
[0150] Alternatively, the key update unit 1204 is configured to receive a new key recreated by the first electronic device for unlocking the target hard disk, and update the new key to the second partition. After the new key recreated by the first electronic device for unlocking the target hard disk, the new key is updated to the first partition.
[0151] It should be noted that the specific implementation manners of the units in this embodiment may refer to the corresponding content in the foregoing, which will not be elaborated here.
[0152] Reference Figure 14 , which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As the first electronic device, the electronic device may include the following structures:
[0153] A first partition 1401 and a baseboard management controller 1402;
[0154] Wherein, the baseboard management controller 1402 obtains an unlocking key of at least one second electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition 1401, and the first partition 1401 protects the stored data based on data signature;
[0155] The unlocking key in the first partition 1401 is used to be provided to the second electronic device, and the second electronic device uses the unlocking key to unlock the target hard disk.
[0156] As can be seen from the above technical solutions, in an electronic device provided by an embodiment of the present application, an unlocking key for a second electronic device is stored on a first partition of a first electronic device and is used to be provided to the second electronic device for hard disk unlocking. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device, and the storage of the unlocking key of the second electronic device is realized through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking.
[0157] Reference Figure 15 , which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As the second electronic device, the electronic device may include the following structures:
[0158] A target hard disk 1501, a second partition 1502 and a baseboard management controller 1503;
[0159] Among them, the baseboard management controller 1503 receives the unlocking key of the second electronic device sent by the first electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition of the first electronic device; the first partition protects the stored data based on data signature; the unlocking key of the second electronic device is stored in the second partition 1502, and the second partition 1502 protects the stored data based on data signature; in response to the power-on instruction, the unlocking key is read from the second partition 1502 and sent to the target hard disk 1501, and the target hard disk 1501 uses the unlocking key to unlock.
[0160] As can be seen from the above technical solution, in an electronic device provided in an embodiment of the present application, an unlocking key is stored for a second electronic device on a first partition of a first electronic device. The second electronic device can store the unlocking key sent by the first electronic device in a second partition. When starting up, the unlocking key can be read from the second partition and provided to the target hard disk. In this way, there is no need to deploy KMIP or an encryption chip on the second electronic device. The unlocking key of the second electronic device is stored through the first partition of the first electronic device, so that the situation where the second electronic device cannot securely back up the unlocking key will not occur, thereby improving the reliability of hard disk unlocking.
[0161] Take Figure 16 the device group including multiple servers shown as an example, and the technical solution of the present application will be illustrated as follows:
[0162] (1) Centralized backup and recovery management of the unlocking key AK (Access Key) of the SED by the primary master in the federation group, such as node C.
[0163] (2) The AKs of the slave nodes are uniformly backed up in the RPMB partition of the master. The master can select some backup nodes, such as the secondary master node B, for redundant backup.
[0164] (3) The slave supports single-node local generation and generation of AKs, and stores them in the RPMB of the EMMC.
[0165] (4) Automatic backup does not require user operation, and recovery has no single point of failure.
[0166] The following describes the process of the primary node creating AKs and backups for the slave nodes:
[0167] (1) The Master invites group members, namely the slaves, by sending a group entry request to the slave nodes. The group entry request includes the group member password, such as the node account and node password of the invited slave node, and also the passphrase (optional).
[0168] (2) The Master sets the group password GroupPwd (nodes in the same device group use the same group password). The Master generates the AK and identifier ID (Identifier) for the slave nodes. The AK can be generated by the Master according to MT / SN + GroupPwd or MT / SN + GroupPwd + passphrase.
[0169] (3) The Master sets the AK for the slave. At the same time, the Master symmetrically encrypts it with GroupPwd and stores it in its own RPMB partition.
[0170] (4) The Slave accepts the AK and symmetrically encrypts it and stores it in its own RPMB partition.
[0171] (5) The Master continues to invite the next slave.
[0172] (6) The Master regularly selects the backup node, the secondary master, or several slave nodes, and stores the encrypted AKs of all group members in the RPMB partitions of these nodes as redundant backups.
[0173] The following describes the process of the slave node using the AK:
[0174] (1) The process of the slave node obtaining the AK: The unified extensible firmware interface UEFI (Unified Extensible Firmware Interface) driver of the SED -> the system UEFI requests the AK -> the BMC reads and decrypts the AK from the RPMB and returns it to the UEFI.
[0175] (2) If the BMC fails to obtain / decrypt the AK, it marks the status and the failure event, and the Master displays the key error of the SED of the slave in the group management.
[0176] (3) Once the Master discovers the AK error of the slave's SED, it can automatically restore the AK saved in the RPMB to the slave according to the set policy. Or prompt the user to perform a manual operation.
[0177] The following describes the process of updating the AK:
[0178] First, the Master initiates the rekey update process (by slave node) as follows:
[0179] (1) Create a new AK for the slave and retain the original AK.
[0180] (2) Send the new AK to the slave and notify the slave to initiate the rekey update process.
[0181] (3) When the query of the slave's rekey update process is completed, the master deletes the old AK and synchronizes the redundant backup.
[0182] Secondly, the Slave initiates the rekey update process as follows:
[0183] (1) The Slave completes the rekey update process, marks the status and event.
[0184] (2) The Master learns that the rekey update is completed, obtains the new AK from the slave, saves it in its own RPMB partition, and synchronizes the redundant backup.
[0185] It can be seen that the technical solution of this application utilizes the centralized backup and recovery logic of the keys of the server group. This application proposes to use the BMC security partition of the Master in the group to save the keys of the group. The Master sets the group password and sets the AK within the group, and each slave node also saves its own AK simultaneously. During recovery, the Master is used to recover the AK of the slave nodes within the group or the information of the group AK is updated after the Slave performs the update rekey.
[0186] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0187] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0188] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in a software module executed by a processor, or in a combination thereof. The software module may be disposed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0189] The foregoing description of the disclosed embodiments enables those skilled in the art to make or use the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Thus, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A hard disk key processing method, comprising: The first electronic device obtains an unlocking key of at least one second electronic device; The second electronic device and the first electronic device are divided into the same device group through respective baseboard management controllers; The first electronic device stores the unlocking key of the second electronic device in a first partition of the first electronic device, wherein the first partition protects the stored data based on a data signature; The unlocking key in the first partition is used to provide to the second electronic device, and the second electronic device uses the unlocking key to unlock the target hard disk.
2. The method according to claim 1, wherein the first electronic device obtains an unlocking key of at least one second electronic device, comprising: The first electronic device generates an unlocking key for the second electronic device according to the group password corresponding to the device group and the device identification of the second electronic device; Or, the first electronic device generates an unlocking key for the second electronic device according to the group password, the device identification of the second electronic device and a pass code corresponding to the second electronic device; The group password is set by the first electronic device for the device group.
3. The method according to claim 1, wherein the first electronic device obtains an unlocking key of at least one second electronic device, comprising: The first electronic device receives the unlocking key sent by the second electronic device; The second electronic device generates the unlocking key according to the group password corresponding to the device group and the device identification of the second electronic device; Or, the second electronic device generates the unlocking key according to the group password, the device identification of the second electronic device and the pass code corresponding to the second electronic device; The group password is set by the first electronic device for the device group and sent to the second electronic device.
4. The method according to claim 1, wherein the first electronic device stores the unlocking key of the second electronic device in the first partition of the first electronic device, comprising: The first electronic device uses the group password to encrypt the unlocking key of the second electronic device to obtain a target key; The target key is stored in a first partition of the first electronic device.
5. The method according to claim 4, wherein the first electronic device uses the group password to encrypt the unlocking key of the second electronic device to obtain the target key, comprising: The first electronic device performs a hash calculation on the group password to obtain a target hash value; The unlocking key of the second electronic device is encrypted using the target hash value to obtain a target key.
6. The method according to claim 4, further comprising: The first electronic device reads the target key corresponding to the second electronic device from the first partition in response to a target message on the second electronic device indicating that unlocking of the target hard disk has failed; The target key corresponding to the second electronic device is sent to the second electronic device; the second electronic device decrypts the target key according to the group password to obtain an unlocking key of the second electronic device.
7. A hard disk key processing method, comprising: The second electronic device receives the unlocking key of the second electronic device sent by the first electronic device; The second electronic device and the first electronic device are divided into the same device group through respective baseboard management controllers; The first partition of the first electronic device stores an unlocking key of the second electronic device; The first partition protects stored data based on a data signature; The second electronic device stores the unlocking key of the second electronic device in a second partition of the second electronic device, wherein the second partition protects the stored data based on the data signature; In response to the power-on instruction, the second electronic device reads the unlocking key from the second partition and sends the unlocking key to a target hard disk in the second electronic device, and the target hard disk is unlocked using the unlocking key.
8. The method according to claim 7, wherein the unlocking key in the second partition is encrypted and stored based on a group password; The group password is set by the first electronic device for the device group and sent to the second electronic device; in, The method further comprises: The second electronic device creates a new key for unlocking the target hard disk; The new key is updated to the second partition, and the new key is sent to the first electronic device, and the first electronic device updates the first partition with the new key of the second electronic device.
9. An electronic device, the electronic device as a first electronic device comprising: a first partition and a baseboard management controller; The baseboard management controller obtains an unlocking key of at least one second electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition, and the first partition protects the stored data based on the data signature; The unlocking key in the first partition is used to be provided to the second electronic device, and the second electronic device uses the unlocking key to unlock the target hard disk.
10. An electronic device, the electronic device serving as a second electronic device comprising: a target hard disk, a second partition, and a baseboard management controller; Among them, the baseboard management controller receives the unlocking key of the second electronic device sent by the first electronic device; the second electronic device and the first electronic device are divided into the same device group through their respective baseboard management controllers; the unlocking key of the second electronic device is stored in the first partition of the first electronic device; the first partition protects the stored data based on the data signature; the unlocking key of the second electronic device is stored in the second partition, and the second partition protects the stored data based on the data signature; in response to the power-on instruction, the unlocking key is read from the second partition and sent to the target hard disk, and the target hard disk is unlocked using the unlocking key.