SSD trusted starting method and system based on national cryptographic algorithm and storage medium
By integrating SM2 and SM3 national secret algorithms on SSDs, the firmware is processed by message digest and digital signature processing, which solves the problem of firmware untrusted during SSD startup, and achieves a trusted startup with high security and high efficiency.
Patent Information
- Application Number
- CN202510262472.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The lack of firmware trustworthy checks during the startup process of existing SSD products, which leads to untrustworthy firmware, which may lead to user data leakage or loss. The commonly used RSA algorithms have problems such as insufficient security and low efficiency.
The SSD system-on-chip Soc integrates SM2 and SM3 national secret algorithms, generate message digests through SM3 algorithm, and generate digital signatures for message digests using SM2 algorithm, bind the message digests and digital signatures to each level program and burn them into the SSD, and compare and verify them when the SSD is powered on to ensure the integrity and legality of the program.
The trusted startup of SSD is achieved, ensuring the security and efficiency of firmware, avoiding the risk of user data leakage and loss, and reducing the requirements of performance consumption and storage density.
Smart Images

Figure CN120110646A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of solid state drives, and in particular to a SSD trusted startup method, system and storage medium based on a national secret algorithm. Background Art
[0002] As an important carrier for storing data, the operation of SSD is controlled and completed by firmware. Since the SSD firmware is stored in the internal non-volatile medium (NAND) when it is not working (power off), it needs to be loaded from NAND to its main control cache before it works normally (power on), which is the startup process of SSD. If an attacker uses illegal means to tamper with the firmware in NAND, the firmware becomes untrustworthy; the SSD running untrustworthy firmware will cause the SSD behavior to be uncontrolled, resulting in user data leakage and loss. Therefore, it is very necessary to add a trusted check on the firmware during the SSD startup process. However, most SSD products on the market today do not have this function, or the commonly used implementation algorithms, such as the RSA algorithm, have shortcomings such as insufficient security and low efficiency. Summary of the invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and to provide an SSD trusted boot method, system and storage medium based on a national secret algorithm.
[0004] The objective of the present invention is achieved through the following technical solutions: The first aspect of the present invention provides: an SSD trusted boot method based on a national secret algorithm, comprising the following steps: Integrate SM2 and SM3 algorithms on the SSD system-on-chip (Soc); Each level of program first uses the SM3 algorithm to output different message digests of fixed length, then uses the SM2 algorithm to generate a corresponding digital signature for each message digest, and then binds the message digest and digital signature to each level of program and burns them into the SSD together; When the SSD is powered on, the message digest of each level of the program is recalculated by the previous level program and compared with the message digest bound to it. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in turn. If the message digest or digital signature verification of any level of program fails, the program of that level will not be run.
[0005] Preferably, when performing firmware encryption, the following steps are included: A set of 256-bit random numbers is generated using a random function as a private key, and then the private key is multiplied by an elliptic curve to obtain a public key. The private key is used to generate a digital signature, and the public key is used to verify the digital signature. Data signed by the private key can only be verified by the public key. Call the SM3 algorithm to calculate the message digest of each level of program; Use the SM2 algorithm and the private key to encrypt the message digests of each level of programs in turn to obtain the digital signatures of each level of programs; The message digests and digital signatures of each level of the program are inserted into specific locations of the original firmware, and after recombining, a complete digitally signed firmware program is obtained. Finally, the firmware program is written into the SSD by burning or upgrading.
[0006] Preferably, when performing signature verification, the following steps are included: After the SSD is powered on, the Rom program is first run. The Rom program reads the Preloader program and its corresponding message digest from the non-volatile medium NAND, and then calls the SM3 algorithm to calculate the message digest of the Preloader program and compare it with the read message digest; after the comparison is successful, the public key and the corresponding digital signature stored in the SSD are read, and the SM2 algorithm module uses the public key to decode the digital signature of the Preloader program. The Preloader program is run only after the verification is successful; After the Preloader program is running, it first reads the solid-state image firmware image and its corresponding message digest from the non-volatile medium NAND, then calls the SM3 algorithm to calculate the solid-state image firmware image to obtain the message digest, compares the two message digests, and performs the next step of signature verification after the comparison passes. After the signature verification passes, the solid-state image firmware image is run.
[0007] Preferably, the public key is stored in the OTP inside the system on chip Soc, and the private key is stored by the firmware publisher.
[0008] Preferably, the fixed length is 256 bits.
[0009] The second aspect of the present invention provides: an SSD trusted boot system based on a national secret algorithm, used to implement any of the above-mentioned SSD trusted boot methods based on a national secret algorithm, comprising: Integrated module, used to integrate SM2 algorithm and SM3 algorithm on the SSD system on chip Soc; The message digest and digital signature generation module is used to output different message digests of fixed length through SM3 algorithm calculation, and then use SM2 algorithm to generate corresponding digital signatures for each message digest, and then bind the message digest and digital signature with various levels of programs and burn them into the SSD together; The signature verification module is used to recalculate the message digest of each level program through the previous level program and compare it with the message digest bound to it when the SSD is powered on. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in sequence. If the message digest or digital signature verification of any level program fails, the program of that level will not be run.
[0010] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned SSD trusted boot methods based on the national secret algorithm is implemented.
[0011] The beneficial effects of the present invention are: 1) The SM2\SM3 national encryption algorithm that uses software and hardware collaboration not only has higher security and efficiency, but also has lower requirements on performance consumption and storage density.
[0012] 2) The combination of SM3 and SM2 algorithms can achieve the dual effects of ensuring data integrity and identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is a schematic diagram comparing the general startup method and the trusted startup method process; Figure 2 Encryption flow chart for firmware; Figure 3 The following is a flow chart of signature verification. DETAILED DESCRIPTION
[0014] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0015] First, some professional terms of the present invention are explained: SSD: solid state drive; National cryptographic algorithm: domestic cryptographic algorithms approved by the State Cryptography Administration, mainly SM1, SM2, SM3, and SM4; Rom: Read-only memory, which can only be programmed once and the content cannot be changed again, is generally integrated inside the SOC; OTP: One-time programmable memory, data cannot be changed or cleared after being written, usually integrated inside the SOC.
[0016] See also Figure 1-Figure 3The first aspect of the present invention provides: an SSD trusted boot method based on a national secret algorithm, comprising the following steps: Integrate SM2 and SM3 algorithms on the SSD system-on-chip (Soc); Each level of program first uses the SM3 algorithm to output different message digests of fixed length, then uses the SM2 algorithm to generate a corresponding digital signature for each message digest, and then binds the message digest and digital signature to each level of program and burns them into the SSD together; When the SSD is powered on, the message digest of each level of the program is recalculated by the previous level program and compared with the message digest bound to it. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in turn. If the message digest or digital signature verification of any level of program fails, the program of that level will not be run.
[0017] In this embodiment, when the SSD is started, it may be necessary to start multiple programs in sequence. In the general startup process, after the SSD is powered on, the startup program solidified in the Rom first loads the preloader program from the NAND into the main control DDR. After the preloader program is running, the official firmware image in the NAND is loaded into the DDR. After the firmware runs normally, the SSD can be recognized and operated by the host; but in this startup process, it is impossible to identify whether the preloader program and firmware image in the NAND have been tampered with or replaced. If the SSD runs illegally tampered firmware, the data security on the SSD cannot be guaranteed. However, if each level of program has been trusted by the previous level program before loading and running, the above problems can be avoided, which is also the purpose of this method. A prerequisite for the implementation of this method is that the Soc of the SSD has integrated the calculation modules of the SM2 and SM3 algorithms, and the corresponding algorithm functions can be realized by calling the corresponding interfaces of the programs at all levels. The implementation process is roughly as follows: each level of program first uses the SM3 algorithm to output a message digest of a fixed length (256 bits), and the message digest is then used to generate a signature after the SM2 algorithm is used. The message digest and signature are bound to the programs at each level and burned into the SSD together; when the SSD is powered on, the message digest of each level of program is recalculated by the previous level program, and then compared with the bound message digest to confirm whether the program is complete; after the comparison is passed, the previous level program verifies the bound signature to confirm whether the program is authentic and legal. After all confirmations are correct, the programs at each level are loaded and run in turn. Once the message value digest or signature verification of a certain level of program fails, indicating that the program is no longer trustworthy, the program at that level will not be run.
[0018] The national secret algorithms used in the implementation process of this method are the SM2 elliptic curve public key algorithm and the SM3 cryptographic hash algorithm. SM2 is an asymmetric cryptographic algorithm based on the elliptic curve cryptography (ECC), which can be used to implement functions such as digital signatures, key agreement and public key encryption, and can ensure the legitimacy of the data source. Although the SM2 algorithm has higher computational efficiency than the RSA algorithm of the same type, if all the original data are to be digitally signed, there will be disadvantages such as large amount of computation and more data to be verified. Therefore, in actual applications, a hash value is calculated by the hash algorithm for the original data, and the hash value can ensure the integrity of the data. Then the hash value is signed to obtain a digital signature. Therefore, in addition to the SM2 algorithm, the SM3 algorithm is also used in this method. The SM3 hash algorithm is a cryptographic hash function that converts data of any length into fixed-length output data. Its output result is irreversible, that is, the original input data cannot be derived from the output data result. Therefore, it has high anti-collision and anti-second original image attack capabilities, effectively ensuring the security of the data, and is often used in the generation and verification of digital signatures and message authentication codes. Therefore, the combination of SM3 and SM2 algorithms can achieve the dual effects of ensuring data integrity and identity authentication.
[0019] Algorithm principle: 1. The implementation of SM2 algorithm is based on the mathematical characteristics of elliptic curves and combined with the principles of public key cryptography, so it is consistent with the general elliptic curve key algorithm in principle. Elliptic curve is an algebraic structure defined on a finite field. Its expression formula is similar to the integral expression for calculating the circumference of an ellipse. It has addition and scalar multiplication operations. The SM2 algorithm uses point operations on the elliptic curve to implement operations such as encryption, decryption, and key generation. 2. The SM3 algorithm is essentially a cryptographic hash function, which is improved based on the SHA-256 algorithm. It adopts a block cipher structure design, and achieves data obfuscation and diffusion through permutation, nonlinear functions, and modular calculations. The output value changes dramatically due to a small change in the input value, thereby ensuring data security. The encryption of the SM3 algorithm includes message padding, message grouping, iterative encryption, message expansion, and iterative compression. The hash value finally generated is used as the data encryption result.
[0020] Algorithm advantages: 1. The SM2 algorithm has high security. The 256-bit password strength is higher than the 2048-bit RSA algorithm. Even at the same password strength, its computing efficiency is higher than traditional public key cryptographic algorithms such as RSA. 2. The security strength and budget efficiency of the SM3 algorithm are comparable to those of SHA-256, but higher than those of MD5 and SHA-1 algorithms. Its high security and efficiency make it more suitable for large-scale data encryption scenarios. 3. The SM2 and SM3 algorithms are my country's independently innovated cryptographic algorithms with independent intellectual property rights, which can ensure the information security of key national information systems.
[0021] In some embodiments, when performing firmware encryption, the following steps are included: A set of 256-bit random numbers is generated using a random function as a private key, and then the private key is multiplied by an elliptic curve to obtain a public key. The private key is used to generate a digital signature, and the public key is used to verify the digital signature. Data signed by the private key can only be verified by the public key. Call the SM3 algorithm to calculate the message digest of each level of program; Use the SM2 algorithm and the private key to encrypt the message digests of each level of programs in turn to obtain the digital signatures of each level of programs; The message digests and digital signatures of each level of the program are inserted into specific locations of the original firmware, and after recombining, a complete digitally signed firmware program is obtained. Finally, the firmware program is written into the SSD by burning or upgrading.
[0022] In some embodiments, when performing signature verification, the following steps are included: After the SSD is powered on, the Rom program is first run. The Rom program reads the Preloader program and its corresponding message digest from the non-volatile medium NAND, and then calls the SM3 algorithm to calculate the message digest of the Preloader program and compare it with the read message digest; after the comparison is successful, the public key and the corresponding digital signature stored in the SSD are read, and the SM2 algorithm module uses the public key to decode the digital signature of the Preloader program. The Preloader program is run only after the verification is successful; After the Preloader program is running, it first reads the solid-state image firmware image and its corresponding message digest from the non-volatile medium NAND, then calls the SM3 algorithm to calculate the solid-state image firmware image to obtain the message digest, compares the two message digests, and performs the next step of signature verification after the comparison passes. After the signature verification passes, the solid-state image firmware image is run.
[0023] In this embodiment, if multiple programs need to be loaded in time-sharing mode, the above-mentioned calculation, message digest comparison, and signature verification operations can be repeated.
[0024] In some embodiments, the public key is stored in the OTP inside the system on chip Soc, and the private key is stored by the firmware publisher.
[0025] In this embodiment, the signature verification operation of the trusted boot relies on the SM2 public key. However, if it is replaced by an attacker, it is possible that the attacker can use the private key that matches their public key to forge a signature, which will cause the tampered firmware program to pass the signature verification process. To avoid this situation, the public key needs to be saved in the OTP on the SSD Soc. Once the public key is written into the OTP, it cannot be modified or cleared, which can protect the public key from being tampered with. The private key is in the hands of the firmware publisher and cannot be obtained by others, so the signature cannot be forged.
[0026] In some embodiments, the fixed length is 256 bits.
[0027] The second aspect of the present invention provides: an SSD trusted boot system based on a national secret algorithm, used to implement any of the above-mentioned SSD trusted boot methods based on a national secret algorithm, comprising: Integrated module, used to integrate SM2 algorithm and SM3 algorithm on the SSD system on chip Soc; The message digest and digital signature generation module is used to output different message digests of fixed length through SM3 algorithm calculation, and then use SM2 algorithm to generate corresponding digital signatures for each message digest, and then bind the message digest and digital signature with various levels of programs and burn them into the SSD together; The signature verification module is used to recalculate the message digest of each level program through the previous level program and compare it with the message digest bound to it when the SSD is powered on. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in sequence. If the message digest or digital signature verification of any level program fails, the program of that level will not be run.
[0028] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned SSD trusted boot methods based on the national secret algorithm is implemented.
[0029] The above is only a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be modified within the scope of the concept described herein through the above teachings or the technology or knowledge of the relevant field. The changes and modifications made by those skilled in the art shall not deviate from the spirit and scope of the present invention, and shall be within the scope of protection of the claims attached to the present invention.
Claims
1. A SSD trusted boot method based on a national secret algorithm, characterized by: The following steps are involved: Integrate SM2 and SM3 algorithms on the SSD system-on-chip (Soc); Each level of program first uses the SM3 algorithm to output different message digests of fixed length, then uses the SM2 algorithm to generate a corresponding digital signature for each message digest, and then binds the message digest and digital signature to each level of program and burns them into the SSD together; When the SSD is powered on, the message digest of each level of the program is recalculated by the previous level program and compared with the message digest bound to it. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in turn. If the message digest or digital signature verification of any level of program fails, the program of that level will not be run.
2. The SSD trusted boot method based on the national secret algorithm according to claim 1 is characterized in that: When encrypting the firmware, the following steps are included: A set of 256-bit random numbers is generated using a random function as a private key, and then the private key is multiplied by an elliptic curve to obtain a public key. The private key is used to generate a digital signature, and the public key is used to verify the digital signature. Data signed by the private key can only be verified by the public key. Call the SM3 algorithm to calculate the message digest of each level of program; Use the SM2 algorithm and the private key to encrypt the message digests of each level of programs in turn to obtain the digital signatures of each level of programs; The message digests and digital signatures of each level of the program are inserted into specific locations of the original firmware, and after recombining, a complete digitally signed firmware program is obtained. Finally, the firmware program is written into the SSD by burning or upgrading.
3. The SSD trusted boot method based on the national secret algorithm according to claim 2 is characterized in that: The following steps are included when performing signature verification: After the SSD is powered on, the Rom program is first run. The Rom program reads the Preloader program and its corresponding message digest from the non-volatile medium NAND, and then calls the SM3 algorithm to calculate the message digest of the Preloader program and compare it with the read message digest; after the comparison is successful, the public key and the corresponding digital signature stored in the SSD are read, and the SM2 algorithm module uses the public key to decode the digital signature of the Preloader program. The Preloader program is run only after the verification is successful; After the Preloader program is running, it first reads the solid-state image firmware image and its corresponding message digest from the non-volatile medium NAND, then calls the SM3 algorithm to calculate the solid-state image firmware image to obtain the message digest, compares the two message digests, and performs the next step of signature verification after the comparison passes. After the signature verification passes, the solid-state image firmware image is run.
4. The SSD trusted boot method based on the national secret algorithm according to claim 2 is characterized in that: The public key is stored in the OTP inside the system on chip Soc, and the private key is stored by the firmware publisher.
5. The SSD trusted boot method based on the national secret algorithm according to any one of claims 1 to 4, characterized in that: The fixed length is 256 bits.
6. An SSD trusted boot system based on a national secret algorithm, characterized by: The method for implementing the SSD trusted boot method based on the national secret algorithm as described in any one of claims 1 to 5 comprises: Integrated module, used to integrate SM2 algorithm and SM3 algorithm on the SSD system on chip Soc; The message digest and digital signature generation module is used to output different message digests of fixed length through SM3 algorithm calculation, and then use SM2 algorithm to generate corresponding digital signatures for each message digest, and then bind the message digest and digital signature with various levels of programs and burn them into the SSD together; The signature verification module is used to recalculate the message digest of each level program through the previous level program and compare it with the message digest bound to it when the SSD is powered on. After the comparison is passed, the previous level program verifies the digital signature bound to the current level program. After the comparison and verification are passed, the programs of each level are loaded and run in sequence. If the message digest or digital signature verification of any level program fails, the program of that level will not be run.
7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are loaded and executed by the processor, the SSD trusted startup method based on the national secret algorithm as described in any one of claims 1 to 5 is implemented.