Rapid encryption method and device for system partition data, equipment and product

By reducing and encrypting the file system and physical partitions during the system initrd startup stage, and expanding and decrypting the system in the full startup stage, the problem that the existing technology cannot encrypt and protect the system data after the system is installed is solved, and efficient encryption and protection of the data after the system is installed is achieved.

CN120068129AActive Publication Date: 2025-05-30KYLIN CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510564516.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-05-30
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

The prior art cannot effectively encrypt and protect the system data after the system is installed, resulting in the inability to implement encryption protection of the system data after installation.

Method used

During the system initrd startup stage, the file system and physical partitions are reduced to make the set capacity of the physical partition equal to the used capacity, and the reduced data is encrypted. During the full startup stage of the system, the decrypted data is expanded to restore the physical partition to the original set capacity.

Benefits of technology

It realizes encryption protection of the data after the system is installed, improves the speed of data encryption, and does not affect the user's needs for data usage operation space in the later stage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068129A_ABST
    Figure CN120068129A_ABST
Patent Text Reader

Abstract

The invention discloses a rapid encryption method and device for system partition data, equipment and a product, and the method comprises the steps: carrying out the capacity reduction of a file system at a system initrd starting stage, and carrying out the capacity reduction of a physical partition, so that the set capacity of the physical partition is equal to a first used capacity; encrypting the data in the physical partition after the volume reduction; the invention discloses a method, a device, equipment and a product for quickly encrypting system partition data, which can be used for quickly encrypting the system partition data in a file system in which the set capacity of a physical partition corresponding to decrypted data is expanded to enable the set capacity of the physical partition to be equal to a first set capacity and the decrypted data is expanded at a system complete starting stage. According to the method, encryption protection can also be achieved, and through capacity reduction processing in the system initrd starting stage and capacity expansion processing in the system complete starting stage, the data encryption speed is effectively improved, and meanwhile the requirement of a user for a data use operation space in the later period is not affected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of system data encryption, and in particular relates to a method, device, equipment and product for quickly encrypting system partition data. Background Art

[0002] With the continuous development of information technology, people's requirements for data security are getting higher and higher, especially the growing demand for the security protection of system data. In a computer system, system data usually stores the operating system and important application software. If this data is leaked or tampered with, it will pose a serious security threat to the computer system.

[0003] Under the existing technical conditions, for the encryption protection of system data, it is usually adopted that at the system installation stage, the disk for storing system data is first formatted at the block device level such as LUKS, and then the system data to be encrypted is stored on this encrypted disk device, so as to complete the encryption protection of system data. This commonly used encryption protection method can only complete the encryption protection of system data at the system installation stage, and for the system data that has been installed, effective data encryption protection cannot be carried out anymore. Summary of the Invention

[0004] In view of this, the present invention aims to overcome the defects in the prior art and proposes a method, device, equipment and product for quickly encrypting system partition data.

[0005] In a first aspect, the present invention discloses a method for quickly encrypting system partition data, including: In the system initrd startup stage: Obtain the first set capacity and the first used capacity of the physical partitions in the system; Shrink the file system and shrink the physical partitions so that the set capacity of the physical partitions is equal to the first used capacity; Encrypt the data in the shrunk physical partitions; In the system full startup stage: Expand the physical partitions corresponding to the decrypted data so that the set capacity of the physical partitions is equal to the first set capacity, and expand the file system of the decrypted data.

[0006] In an embodiment of the present invention, encrypting the data in the shrunk physical partitions includes: If the ratio of the total used capacity to the total set capacity in the system partitions is greater than the set threshold, then use the LUKS data-by-block encryption method for encryption; If the ratio of the total used capacity to the total set capacity in the system partitions is less than or equal to the set threshold, then use the LUKS formatted migration data encryption method for encryption.

[0007] In one embodiment of the present invention, the method further includes: if the system uses the Logical Volume Manager (LVM) for partitioning, before reducing the capacity of the physical partition so that the set capacity of the physical partition is equal to the first used capacity, it further includes: obtaining the second set capacity and the second used capacity of the logical volume, and reducing the capacity of the logical volume so that the set capacity of the logical volume is equal to the second used capacity; If the system uses the Logical Volume Manager (LVM) for partitioning, after expanding the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, it further includes: expanding the logical volume so that the set capacity of the logical volume is equal to the second set capacity.

[0008] In one embodiment of the present invention, when using the LUKS data block-by-block encryption method for encryption, it includes: creating a temporary space in the metadata area of the LUKS header, and storing in the temporary space the position of the data block currently being encrypted, which is used to resume the encryption of subsequent data blocks after an abnormal interruption during the encryption process.

[0009] In one embodiment of the present invention, when using the LUKS formatted migration data encryption method for encryption, it includes: establishing a configuration table, and storing in the configuration table the position of the data block currently being encrypted, which is used to resume the encryption of subsequent data blocks after an abnormal interruption during the encryption process.

[0010] In one embodiment of the present invention, after encrypting the data in the reduced-capacity physical partition, it includes: updating the encryption configuration file, which is used to decrypt the encrypted data after the system is fully started.

[0011] In a second aspect, the present invention discloses a fast encryption device for system partition data, and the device includes: An initrd startup module, which is used in the system initrd startup stage: obtaining the first set capacity and the first used capacity of the physical partition in the system; reducing the capacity of the file system and reducing the capacity of the physical partition so that the set capacity of the physical partition is equal to the first used capacity; encrypting the data in the reduced-capacity physical partition; A system full startup module, which is used in the system full startup stage: expanding the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, and expanding the file system of the decrypted data.

[0012] In a third aspect, the present invention discloses an electronic device, including: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above method.

[0013] Fourthly, the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above method is implemented.

[0014] Fifthly, the present invention discloses a computer program product, including a computer program. When the computer program is executed by a processor, the above method is implemented.

[0015] To achieve the above object, the technical solution of the present invention is implemented as follows: The present invention discloses a method, device, equipment and product for quickly encrypting system partition data, including reducing the capacity of the file system and the physical partition during the system initrd startup phase, so that the set capacity of the physical partition is equal to the first used capacity; encrypting the data in the reduced-capacity physical partition; during the system full startup phase, expanding the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, and expanding the file system of the decrypted data. The present invention discloses a method, device, equipment and product for quickly encrypting system partition data, which can also implement encryption protection for the data after the system is installed, and through the capacity reduction processing during the system initrd startup phase and the capacity expansion processing during the system full startup phase, effectively improve the data encryption speed while not affecting the later user's demand for the data usage operation space. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0017] In the drawings: Figure 1 is a schematic diagram of an application scenario of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 2 is a schematic diagram of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 3 is a schematic diagram of the overall logical structure of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 4 is a schematic diagram of capacity reduction of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 5 is a schematic diagram of capacity expansion of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 6 is a schematic diagram of the LUKS data-by-block encryption method of a method for quickly encrypting system partition data according to an embodiment of the present invention; Figure 7Schematic diagram of the LUKS formatting and migrating data encryption method for quickly encrypting system partition data in an embodiment of the present invention; Figure 8 Schematic diagram of a device for quickly encrypting system partition data in an embodiment of the present invention; Figure 9 Schematic diagram of an electronic device for quickly encrypting system partition data in an embodiment of the present invention. Detailed implementation manners

[0018] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.

[0019] In the description of the present invention, it should be further noted that the terms "first", "second", etc. are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise stated, the meaning of "a plurality of" is two or more.

[0020] An application scenario of a method, device, equipment, and product for quickly encrypting system partition data disclosed by the present invention is as Figure 1 shown. Under the existing technical conditions, the commonly used encryption protection method can only complete the encryption protection of system data during the system installation stage, and for the system data that has been installed, effective data encryption protection cannot be carried out anymore. A method, device, equipment, and product for quickly encrypting system partition data disclosed by the present invention can also achieve encryption protection for the data after system installation, and through the capacity reduction processing in the system initrd startup stage and the capacity expansion processing in the system full startup stage, while effectively improving the data encryption speed, it does not affect the later user's demand for data operation space.

[0021] The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0022] In an embodiment disclosed by the present invention, as Figure 2 and Figure 3 shown, a method for quickly encrypting system partition data includes: Step S201, in the system initrd startup stage: Obtain the first set capacity and the first used capacity of the physical partition in the system; Reduce the capacity of the file system and the physical partition, so that the set capacity of the physical partition is equal to the first used capacity; Encrypt the data in the reduced-capacity physical partition; Step S202, during the complete system startup phase: Expand the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, and expand the file system of the decrypted data.

[0023] In this embodiment, both the shrinking and expanding operations can be implemented using the existing shrinking and expanding commands in the prior art.

[0024] Exemplarily, the shrinking operation mainly may include: cleaning up garbage data in the file system, shrinking the block data in the superblock, releasing inode free blocks, and updating file system metadata, etc.

[0025] In this embodiment, during the system initrd startup phase, the data is encrypted and shrunk; during the complete system startup phase, decryption and expansion are performed to ensure that it does not affect the later user's requirement for the data usage operation space. This embodiment can perform block device-level fast encryption on the physical partition where the system data is located while retaining the system data, avoiding attacks and data tampering. The shrinking process can effectively improve the efficiency of later data encryption, and the expansion operation can ensure that it does not affect the later user's requirement for the data usage operation space.

[0026] Based on the previous embodiment, in another embodiment of the present invention, encrypting the data in the shrunk physical partition includes: If the ratio of the total used capacity to the total set capacity in the system partition is greater than the set threshold, then use the LUKS data-by-block encryption method for encryption; In this embodiment, exemplarily, the set threshold is 0.3, that is, 30%.

[0027] As Figure 6 shown, the LUKS data-by-block encryption method encrypts each data block of the system data in the system partition one by one, and replaces the original data block with the encrypted data block after encryption. This encryption method is only performed on the existing disk device and has no obvious requirements for the free space of the existing disk device, nor does it require an additional storage device medium.

[0028] In this embodiment, using the LUKS data-by-block encryption method for encryption includes: creating a temporary space in the metadata area of the LUKS header, and storing the position of the currently encrypted data block in the temporary space for resuming the encryption of subsequent data blocks after the encryption process is abnormally interrupted.

[0029] If the ratio of the total used capacity to the total set capacity in the system partition is less than or equal to the set threshold, then use the LUKS formatted migration data encryption method for encryption.

[0030] In this embodiment, by way of example, the set threshold is 0.3, that is, 30%.

[0031] As Figure 7 shown, in this embodiment, the process of using the LUKS formatting migration data encryption method is as follows: First, since the physical partition has been shrunk in advance, a corresponding free storage space appears in the system partition. A LUKS partition is created in the free storage space, and the system data to be encrypted is copied to the mapped device of the newly created LUKS partition decryption mapping, and further synchronized to the newly created LUKS partition through the dm-crypt module to achieve encrypted storage of the system data. Finally, the original system data is deleted, and the encrypted data in the newly created LUKS partition is retained to achieve encryption of the original system data. This encryption method can achieve a relatively high data encryption speed and is performed on existing disk devices without the need to provide additional storage device media.

[0032] In this embodiment, a configuration table is established, and the position of the currently encrypted data block is stored in the configuration table for resuming the encryption of subsequent data blocks after the encryption process is abnormally interrupted.

[0033] Based on the previous embodiment, in another embodiment of the present invention, as Figure 4 shown, the method further includes: If the system uses the Logical Volume Manager (LVM) for partitioning, before shrinking the physical partition so that the set capacity of the physical partition is equal to the first used capacity, it further includes; obtaining the second set capacity and the second used capacity of the logical volume, and shrinking the logical volume so that the set capacity of the logical volume is equal to the second used capacity; In this embodiment, the method further includes: Before shrinking the physical partition, if there are multiple logical volumes on the physical partition, move the physical segment position of the logical volume on the physical partition to cover the free physical segment between the two logical volumes on the physical partition, making the logical volumes more compact, so as to be able to shrink the capacity of the physical partition as much as possible later without losing the original system data.

[0034] As Figure 5 shown, if the system uses the Logical Volume Manager (LVM) for partitioning, after expanding the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, it further includes: expanding the logical volume so that the set capacity of the logical volume is equal to the second set capacity.

[0035] In one implementation of the present invention, after encrypting the data in the shrunk physical partition, it includes: updating the encryption configuration file so that the encrypted data can be decrypted after the system is fully started.

[0036] In one embodiment of the present invention, exemplarily, the system partitions that need to be encrypted are the ROOT partition and the DATA partition, and the process is as follows: The system is partitioned using the Logical Volume Manager LVM. Both the ROOT root partition and the DATA data partition exist in the form of logical volumes. For example, the total set capacity of the two logical volumes is 100GB, the set capacity of the ROOT logical volume is 70GB, the used capacity is 60GB, the set capacity of the DATA logical volume is 30GB, and the used capacity is 20GB. If (60 GB + 20GB) / 100 GB is greater than the set threshold, the LUKS data block-by-block encryption method is used for encryption; During the system initrd startup phase: When shrinking, first shrink the file systems on the physical partition, and then shrink the corresponding logical volumes. Shrink the ROOT logical volume to 60GB, and the DATA logical volume to 20GB. Then move the logical volumes to make them more compact, and then shrink the corresponding physical partitions as much as possible.

[0037] Use LUKS data block-by-block encryption to encrypt the reduced data; During the full system startup phase: When expanding the capacity, first expand the total capacity of the physical partition that stores LUKS format encrypted data to 100GB, remap the device, and then the total capacity of the mapped device is synchronously updated to 100GB. After updating the physical partition on the mapped device, expand the capacity of the ROOT logical volume to 70GB, and expand the capacity of the DATA logical volume to 30GB. Finally, expand and restore the file system on each logical volume to complete the entire recovery expansion.

[0038] In another embodiment of the present invention, exemplarily, the system partitions that need to be encrypted are the ROOT partition and the DATA partition, and the process is as follows: When the system does not use the logical volume manager LVM partition, the ROOT root partition and the DATA data partition are both in the form of physical partitions. For example, the set capacity of the ROOT physical partition is 150GB, and the used capacity is 40GB; the set capacity of the DATA physical partition is 50GB, and the used capacity is 10GB. If (40GB+10GB) / 200GB is less than the set threshold, the LUKS formatted migration data encryption mode is used for encryption; During the system initrd startup phase: When shrinking, first shrink the file system on each physical partition, then shrink the ROOT physical partition to 40GB, shrink the DATA physical partition to 10GB, and then perform LUKS formatting and migration data encryption; Encrypt the data after downsizing using the LUKS formatted migration data encryption mode method; During the system's full startup phase: When expanding the capacity, expand and restore two physical partitions storing LUKS-formatted encrypted data to 150GB and 50GB respectively, remap the devices. At this time, the capacities of the mapped devices are synchronously updated to 150GB and 50GB. Finally, expand and restore the file systems on the mapped devices to complete all restorative capacity expansions.

[0039] As Figure 8 shown, the present invention also discloses a fast encryption device for system partition data, including: An initrd startup module 601, used during the system's initrd startup phase: obtain the first set capacity and the first used capacity of the physical partitions in the system; downsize the file system and downsize the physical partitions so that the set capacity of the physical partitions is equal to the first used capacity; encrypt the data in the downsized physical partitions; A system full startup module 602, used during the system's full startup phase: expand the physical partitions corresponding to the decrypted data so that the set capacity of the physical partitions is equal to the first set capacity, and expand the file systems of the decrypted data.

[0040] The present invention also discloses an electronic device, as Figure 9 shown, discloses a block diagram of an embodiment of an electronic device applicable to the fast encryption of the above system partition data.

[0041] This embodiment of the electronic device 90 includes a processor 901, which can perform various appropriate actions and processes according to the program stored in the ROM 902 or the program loaded from the storage section 908 into the RAM 903. The processor 901 can include, for example, a general microprocessor, an instruction set processor, and / or a related chipset and / or a dedicated microprocessor, etc. The processor 901 can also include on-board memory for caching purposes. The processor 901 can include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present invention.

[0042] In the RAM 903, various programs and data required for the operation of the electronic device 90 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other through a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present invention by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the program can also be stored in one or more memories other than the ROM 902 and the RAM 903, and the processor 901 can also perform various operations of the method flow according to the embodiments of the present invention by executing the programs stored in one or more memories.

[0043] According to an embodiment of the present invention, the electronic device 90 may further include an I / O interface 905, and the I / O interface 905 is also connected to the bus 904. The electronic device 90 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube, a liquid crystal display, a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. The drive 9010 is also connected to the I / O interface 905 as needed. A removable medium 9011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 9010 as needed so that a computer program read therefrom is installed into the storage portion 908 as needed.

[0044] The present invention also provides a computer-readable storage medium.

[0045] The computer-readable storage medium may be included in the electronic device / device system described in the above embodiments; or may exist separately without being assembled into the electronic device / device. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present invention is implemented.

[0046] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory RAM, a read-only memory ROM, an erasable programmable read-only memory EPROM or a flash memory, a portable compact disk read-only memory CD-ROM, an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, device, or device.

[0047] An embodiment of the present invention further includes a computer program product.

[0048] The computer program product includes a computer program, and the computer program includes program codes for executing the method provided by the embodiments of the present invention. When the computer program product runs on an electronic device, the program codes are used to cause the electronic device to implement the method provided by the embodiments of the present invention.

[0049] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium. The program code included in the computer program may be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0050] According to an embodiment of the present invention, the program code for executing the computer program provided by the embodiments of the present invention can be written using any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedures and / or object-oriented programming languages. Programming languages include but are not limited to, for example, Java, C++, Python, C language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network or a wide area network, or can be connected to an external computing device.

[0051] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented using a dedicated hardware-based system for performing the specified functions or operations, or can be implemented using a combination of dedicated hardware and computer instructions. Those skilled in the art can understand that the features described in various embodiments and / or claims of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in various embodiments and / or claims of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

[0052] The embodiments of the present invention have been described above. However, these embodiments are merely for illustrative purposes and not for limiting the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present invention is defined by the appended claims and their equivalents. Without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present invention.

Claims

1. A method for fast encryption of system partition data, characterized in that: include: During the system initrd startup phase: Obtaining a first set capacity and a first used capacity of a physical partition in the system; Shrinking the file system and the physical partition so that the set capacity of the physical partition is equal to the first used capacity; Encrypting the data in the reduced physical partition; During the full system startup phase: The physical partition corresponding to the decrypted data is expanded so that the set capacity of the physical partition is equal to the first set capacity, and the file system of the decrypted data is expanded.

2. A method for fast encryption of system partition data according to claim 1, characterized in that: The encrypting the data in the reduced physical partition includes: If the ratio of the total used capacity to the total set capacity in the system partition is greater than the set threshold, LUKS data block-by-block encryption is used for encryption; If the ratio of the total used capacity to the total set capacity in the system partition is less than or equal to the set threshold, the LUKS formatted migration data encryption method is used for encryption.

3. A method for fast encryption of system partition data according to claim 1, characterized in that: The method further includes: if the system is partitioned using a logical volume manager LVM, before the physical partition is reduced in capacity so that the set capacity of the physical partition is equal to the first used capacity, the method further includes: obtaining a second set capacity and a second used capacity of the logical volume, and reducing the logical volume so that the set capacity of the logical volume is equal to the second used capacity; If the system is partitioned using a logical volume manager LVM, then after expanding the physical partition corresponding to the decrypted data so that the set capacity of the physical partition is equal to the first set capacity, the method further includes: expanding the logical volume so that the set capacity of the logical volume is equal to the second set capacity.

4. A method for fast encryption of system partition data according to claim 2, characterized in that: The encryption is performed using the LUKS data block-by-block encryption method, including: creating a temporary space in the metadata area of ​​the LUKS header, storing and recording the position of the currently encrypted data block in the temporary space, and used for restoring the subsequent data block encryption after the encryption process is abnormally interrupted.

5. A method for fast encryption of system partition data according to claim 2, characterized in that: The encryption using the LUKS formatted migration data encryption method includes: establishing a configuration table, in which the location of the currently encrypted data block is stored and recorded, and is used to restore the subsequent data block encryption after the encryption process is abnormally interrupted.

6. A method for fast encryption of system partition data according to claim 1, characterized in that: After encrypting the data in the reduced physical partition, the method includes: updating an encryption configuration file so as to decrypt the encrypted data after the system is fully started.

7. A fast encryption device for system partition data, characterized in that: The device comprises: The initrd startup module is used to: obtain a first set capacity and a first used capacity of a physical partition in the system during the initrd startup phase; shrink the file system and the physical partition so that the set capacity of the physical partition is equal to the first used capacity; and encrypt data in the physical partition after shrinking; The system full startup module is used to expand the physical partition corresponding to the decrypted data during the system full startup phase, so that the set capacity of the physical partition is equal to the first set capacity, and expand the file system of the decrypted data.

8. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to perform the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that When the computer program is executed by a processor, it implements the method described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Method and apparatus for performing electronic data file protection based on encrypted partition

    CN105740717A

  • Encryption expansion method and device of block equipment and intelligent terminal

    CN107358131A

  • Method, device and equipment for automatically migrating data after cluster capacity expansion or reduction

    CN111694518A

  • Computer data security intelligent management system

    CN112765643A

  • Partition capacity expansion and contraction method and system

    CN114936095A