RAID card encrypted volume access method and device, equipment and storage medium
By using preset secondary bitmaps on the RAID card to store user permission information and using access encryption private keys to encrypt volume operations, the data security problem of sharing security keys in traditional RAID cards is solved, and higher user data security is achieved.
Patent Information
- Application Number
- CN202510371108.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-17
AI Technical Summary
When traditional RAID cards use SED disks for data hardware encryption, they share a security key, which causes the encrypted data between users to be accessible to each other. A user leaks the key and causes data leakage from other users, making the data security low.
By introducing a preset secondary bitmap on the RAID card, the user's permission information is stored, including the attribute operation permissions of the basic storage unit and the data operation permissions, and the user-side access encryption private key is used to perform encrypted volume operations, ensuring that each encrypted volume is only accessible to its creation user.
Improves the security of data stored by users and prevents encrypted data from being accessed by users. Even if one user leaks the key, it will not affect the data security of other users.
Smart Images

Figure CN120162810A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of disk data management, and in particular, to a method, device, equipment and storage medium for accessing an encrypted volume of a RAID card. Background Art
[0002] In the field of information security technology, storage security is a very important aspect. A mobile hard disk is the most commonly used carrier for data transfer and storage. When a hard disk is in use, if critical data is stored in plain text, the theft or illegal copying of the device will directly cause information security problems. To ensure the storage security of information, data encryption is an important measure to guarantee storage security. Data encryption can be divided into software encryption and hardware encryption according to the encryption method. Software encryption has the characteristics of low implementation cost, convenience, good compatibility, etc., but software encryption occupies a lot of system resources, is slow, and is easily cracked, thus causing data security problems. Hardware encryption has the characteristics of less system resource occupation, fast speed, high security, etc., but hardware encryption requires additional hardware devices. As an important carrier for enterprises to store data, a storage server needs to use SED (Self-Encrypting Drive) hard disks to achieve hardware encryption of data. An SED disk refers to a hard disk with self-encryption function, and its main control circuit integrates a hardware module with encryption function, thus realizing the encryption and decryption of I / O (Input / Output) data at the hardware level. The RAID (Redundant Arrays of Independent Disks) card, as a standard configuration on a storage server, has been widely used. When a traditional RAID card cooperates with an SED disk to enable hardware encryption of data, a security key needs to be set. The security key is the user password of the SED disk and is used as a public key by each encrypted RAID array and encrypted volume. The encrypted information created among different users can be accessed and operated on each other. Moreover, when a user leaks the security key, it will cause the data leakage of the remaining users, and the data security is relatively low.
[0003] It can be seen that how to protect the data security of the encrypted volume in the RAID array is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a method, device, equipment and storage medium for accessing an encrypted volume of a RAID card, which can improve the security of user-stored data. The specific solutions are as follows:
[0005] In a first aspect, the present application discloses a method for accessing an encrypted volume of a RAID card, which is applied to a RAID card and includes:
[0006] Obtain an encrypted volume operation request sent by the client for a target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the client from a preset secondary bitmap; the basic storage unit includes an encrypted volume and a normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit.
[0007] Based on the permission information and the access encryption private key of the client provided in the encrypted volume operation request, determine whether the client has the operation permission corresponding to the target encrypted volume.
[0008] If the client has the operation permission corresponding to the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key.
[0009] Optionally, when the encrypted volume operation request is an encrypted volume creation request for the target encrypted volume, obtain the encrypted volume operation request sent by the client for the target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the client from a preset secondary bitmap, including:
[0010] Obtain the encrypted volume creation request sent by the client for the target encrypted volume on the RAID card, and read the attribute operation permission of the encrypted volume corresponding to the client from the preset secondary bitmap based on the encrypted volume creation request.
[0011] Correspondingly, based on the permission information and the access encryption private key of the client provided in the encrypted volume operation request, determine whether the client has the operation permission corresponding to the target encrypted volume, including:
[0012] If the attribute operation permission of the encrypted volume corresponding to the client does not include the attribute operation permission of the target encrypted volume, read the access encryption private key of the client from the encrypted volume operation request, and perform a security check on the access encryption private key; the security check is to check whether the length of the access encryption private key conforms to the preset constraint rules.
[0013] Correspondingly, if the client has the operation permission corresponding to the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key, including:
[0014] If the access encryption private key passes the security check, determine whether there is a first target RAID array corresponding to the target encrypted volume locally.
[0015] If the first target RAID array does not exist, traverse the first target self-encrypting hard disk determined based on the encrypted volume creation request, and enable the security function of the first target self-encrypting hard disk to create a first target RAID array corresponding to the first target self-encrypting hard disk locally.
[0016] Set the encryption volume attributes corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array;
[0017] If the first target RAID array exists, directly execute the step of setting the encryption volume attributes corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array.
[0018] Optionally, when the encryption volume operation request is an encryption volume creation request for the target encrypted volume, after performing the encryption volume operation corresponding to the encryption volume operation request on the target encrypted volume based on the access encryption private key, it further includes:
[0019] Obtain the access encryption private key of the client and the encryption volume attributes corresponding to the target encrypted volume;
[0020] Establish a mapping relationship between different clients and the operation permissions corresponding to the target encrypted volume based on the encryption volume attributes;
[0021] Store the operation permissions corresponding to different clients and the target encrypted volume on a preset secondary bitmap based on the mapping relationship and the preset data storage standard; the preset data storage standard is to store the user information of different clients on the first-level bitmap of the preset secondary bitmap, and store the operation permissions corresponding to different clients for the target encrypted volume on the second-level bitmap of the preset secondary bitmap.
[0022] Optionally, when the encryption volume operation request is an encryption volume modification request for the target encrypted volume, obtain the encryption volume operation request sent by the client for the target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the client from the preset secondary bitmap, including:
[0023] Obtain the encryption volume modification request sent by the client for the target encrypted volume on the RAID card, and read the attribute operation permissions of the encryption volume corresponding to the client from the preset secondary bitmap based on the encryption volume modification request;
[0024] Correspondingly, if the client has the operation permissions corresponding to the target encrypted volume, perform the encryption volume operation corresponding to the encryption volume operation request on the target encrypted volume based on the access encryption private key, including:
[0025] Judge whether the client has the modification operation permissions corresponding to the target encrypted volume based on the attribute operation permissions and the access encryption private key of the client provided in the encryption volume operation request;
[0026] If the client has the modification operation permission for the target encrypted volume, traverse all the encrypted volumes corresponding to the client, and replace the old encrypted volume attributes of all the encrypted volumes with the new encrypted volume attributes in the encrypted volume modification request; the new encrypted volume attributes include the new access encryption private key of all the encrypted volumes corresponding to the client.
[0027] Optionally, when the encrypted volume operation request is an encrypted volume deletion request for the target encrypted volume, obtain the encrypted volume operation request sent by the client for the target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the client from the preset secondary bitmap, including:
[0028] Obtain the encrypted volume deletion request sent by the client for the target encrypted volume on the RAID card, and read the attribute operation permission of the encrypted volume corresponding to the client from the preset secondary bitmap based on the encrypted volume deletion request;
[0029] Correspondingly, if the client has the operation permission for the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key, including:
[0030] Judge whether the client has the deletion operation permission for the target encrypted volume based on the attribute operation permission and the access encryption private key of the client provided in the encrypted volume operation request;
[0031] If the client has the deletion operation permission for the target encrypted volume, delete the target encrypted volume from the corresponding second target RAID array based on the encrypted volume deletion request.
[0032] Optionally, after deleting the target encrypted volume from the corresponding second target RAID array based on the encrypted volume deletion request, it further includes:
[0033] Judge whether there are other basic storage units on the second target RAID array;
[0034] If there are no other basic storage units on the second target RAID array, turn off the security function of the second target self-encrypting hard disk corresponding to the second target RAID array to delete the second target RAID array locally.
[0035] Optionally, the method further includes:
[0036] Obtain the general volume operation request sent by the client for the target general volume on the RAID card;
[0037] Read the current user information of the client from the first-level bitmap on the preset secondary bitmap, and read the attribute operation permission and storage data operation permission of the client for the target general volume from the second-level bitmap on the preset secondary bitmap based on the current user information;
[0038] Perform security verification on the normal volume operation request based on the attribute operation permission and storage data operation permission of the client for the target normal volume, and after the security verification passes, perform the normal volume operation corresponding to the normal volume operation request on the target normal volume.
[0039] In a second aspect, the present application discloses a RAID card encrypted volume access device, which is applied to a RAID card and includes:
[0040] A permission information acquisition module, configured to acquire an encrypted volume operation request sent by the client for the target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the client from a preset secondary bitmap; the basic storage unit includes an encrypted volume and a normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit;
[0041] A right judgment module, configured to judge whether the client has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the client provided in the encrypted volume operation request;
[0042] An encrypted volume operation module, configured to, if the client has the operation permission corresponding to the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key.
[0043] In a third aspect, the present application discloses an electronic device, including:
[0044] A memory, configured to store a computer program;
[0045] A processor, configured to execute the computer program to implement the foregoing RAID card encrypted volume access method.
[0046] In a fourth aspect, the present application discloses a computer-readable storage medium, configured to store a computer program, and when the computer program is executed by a processor, implement the foregoing RAID card encrypted volume access method.
[0047] In the present invention, an encrypted volume operation request sent by the client for the target encrypted volume on the RAID card is acquired, and the permission information of the basic storage unit corresponding to the client is read from a preset secondary bitmap; the basic storage unit includes an encrypted volume and a normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit; it is judged whether the client has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the client provided in the encrypted volume operation request; if the client has the operation permission corresponding to the target encrypted volume, the encrypted volume operation corresponding to the encrypted volume operation request is performed on the target encrypted volume based on the access encryption private key.
[0048] As can be seen from the above technical solutions, in the present invention, the original security encryption public keys used for each encrypted volume are replaced with access encryption private keys corresponding to the client separately. In this way, the encrypted volumes corresponding to this client cannot be accessed by other users, and the encrypted volumes belong to the created users, which can improve the security of the data stored by the users. And by presetting a secondary bitmap to store the attribute operation permissions of each client for the basic storage unit and the storage data operation permissions of the basic storage unit, the security of the data stored by the client is further improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0050] Figure 1 It is a flowchart of a method for accessing an encrypted volume of a RAID card disclosed by the present invention;
[0051] Figure 2 It is a schematic diagram of a specific RAID card user management structure disclosed by the present invention;
[0052] Figure 3 It is a schematic flowchart of a specific preset secondary bitmap structure disclosed by the present invention;
[0053] Figure 4 It is a flowchart of a method for creating an encrypted volume of a RAID card disclosed by the present invention;
[0054] Figure 5 It is a flowchart of a method for creating an encrypted volume of a RAID card disclosed by the present invention;
[0055] Figure 6 It is a flowchart of a method for modifying an encrypted volume of a RAID card disclosed by the present invention;
[0056] Figure 7 It is a flowchart of a method for modifying an encrypted volume of a RAID card disclosed by the present invention;
[0057] Figure 8 It is a flowchart of a method for deleting an encrypted volume of a RAID card disclosed by the present invention;
[0058] Figure 9 It is a flowchart of a method for deleting an encrypted volume of a RAID card disclosed by the present invention;
[0059] Figure 10Schematic structural diagram of a RAID card encrypted volume access device disclosed by the present invention;
[0060] Figure 11 Structural diagram of an electronic device disclosed by the present invention. Specific implementation manners
[0061] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0062] The terms "including" and "having" in the specification of the present invention and any deformations related to "including" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units not listed.
[0063] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0064] For hardware encryption of data using a RAID card, a security key needs to be set. The security key is the user password of the SED disk. When the SED disk with the self-encryption function is plugged in or unplugged, the correct security key needs to be authenticated to import the out-of-band configuration and normally manage the SED disk. This configuration method makes multiple RAID arrays and encrypted volumes share the same security key. When a server is used by multiple users, the user management function is lacking, and users can access the created encrypted data with each other without restrictions on viewing and deletion; and when the hard disk is lost, due to the shared security key, if one user leaks the secret, it will cause the data on the entire hard disk to be leaked, thus causing data security problems. Therefore, the present invention will specifically introduce a RAID card encrypted volume access method, which can improve the security of encrypted data.
[0065] See Figure 1 As shown, the embodiment of the present application discloses a RAID card encrypted volume access method, which is applied to a RAID card and includes:
[0066] Step S11: Obtain an encryption volume operation request for a target encryption volume on the RAID card sent by the client, and read the permission information of the basic storage unit corresponding to the client from a preset secondary bitmap; the basic storage unit includes an encryption volume and a normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit.
[0067] In this embodiment, a user management function is set. After the user logs in, the created normal volume can be accessed by other users. If an encryption volume is to be created, the user's own security key needs to be added, and then this encryption volume cannot be accessed by other users. The encryption volume belongs to the creating user, improving the security of the user's stored data. As Figure 2 shown, User A creates normal volume 1 and encryption volume 3, and User B creates normal volume 2, encryption volume 4, and encryption volume 5. When the user needs to operate on the target encryption volume on the RAID card, an encryption volume operation request for the target encryption volume on the RAID card needs to be sent first. After receiving the request, the RAID card first reads the permission information of the basic storage unit corresponding to the client from the preset secondary bitmap; the basic storage unit includes an encryption volume and a normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit. As Figure 3 shown, the user management mode mainly uses two-level Bitmaps (bitmaps) to record the attributes of the volumes. For example, if there are at most 32 users on the storage server, the first-level Bitmap can be set to 32 bit positions to record the location information of the users. The second-level Bitmap records the operation permission information of the user for all volumes. The space of the first-level Bitmap is fixedly allocated, and 4 Byte of storage space is allocated; the second-level Bitmap can be applied for allocation. For each registered user, 96 Byte of storage space is applied for and mounted under this bit to store the user's permission information. Figure 2 It consists of a second-level Bitmap. Horizontally, there are 256 bit positions, indicating that the users on the storage server can create at most 256 volumes; vertically, it is the permission information of each volume, from top to bottom as r (read), w (write), o (operation). For example, if User A creates normal volume 1 and encryption volume 3, then both volume 1 and volume 3 can be read, written, and operated (including deletion, expansion, etc.). For normal volume 2 created by User B, it can be read and written but not operated. The permission information of User B for the volumes is the same.
[0068] Step S12: Based on the permission information and the access encryption private key of the client provided in the encryption volume operation request, determine whether the client has the operation permission corresponding to the target encryption volume.
[0069] In this embodiment, the permission information of the volume corresponding to the client is read from the two-level Bitmap, and then it is determined whether the client has the operation permission for the target encrypted volume according to the access encryption private key sent together from the encrypted volume operation request. Specifically, if the encrypted volume operation request is an encrypted volume creation request, the access encryption private key of the client can be directly obtained to determine whether the client has the operation permission corresponding to the target encrypted volume. If the encrypted volume operation request is an encrypted volume modification or deletion request, it can be first determined whether the client has the permission to modify or delete this target encrypted volume from the permission information of the volume corresponding to the client; if so, then continue to determine whether the client has the operation permission corresponding to the target encrypted volume through the access encryption private key of the client for the operation. If not, the judgment process of the access encryption private key can be directly omitted, thereby saving processing resources.
[0070] Step S13: If the client has the operation permission corresponding to the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key.
[0071] In this embodiment, when the client has the operation permission corresponding to the target encrypted volume, the encrypted volume operation corresponding to the encrypted volume operation request can be performed on the target encrypted volume according to the access encryption private key. That is, when the client has the permission to create an encrypted volume, the target encrypted volume can be created according to the operation corresponding to the encrypted volume creation request for subsequent data storage using the encrypted volume. When the client has the permission to modify or delete the encrypted volume, the target encrypted volume can be operated according to the operation corresponding to the encrypted volume modification or deletion request.
[0072] It should be noted here that in this embodiment, the operation for the external SED disk configuration is the same as the import of the external configuration on the traditional RAID card, but the security key is stored in units of users. When performing the configuration import, after the client enters its own password, only the encrypted information belonging to itself can be viewed, and it will not cause that of other users. Therefore, the background does not reconfigure a new security key for this hard disk.
[0073] In addition, this embodiment also supports users to access normal volumes. Specifically, it obtains a normal volume operation request sent by the client for a target normal volume on the RAID card. It reads the current user information of the client from the first-level bitmap on the preset secondary bitmap, and based on the current user information, reads the attribute operation permission and storage data operation permission of the client for the target normal volume from the second-level bitmap on the preset secondary bitmap. It performs security verification on the normal volume operation request based on the attribute operation permission and storage data operation permission of the client for the target normal volume, and after the security verification passes, it performs the normal volume operation corresponding to the normal volume operation request on the target normal volume. That is, since normal volumes do not require access to an encryption private key for encrypted access. However, the access permissions for different normal volumes created by different users are different. For example, if user A creates normal volume 1 and encrypted volume 3, then both volume 1 and volume 3 are readable, writable, and operable (including deletion, expansion, etc.). For normal volume 2 created by user B, it is readable and writable but not operable. Then, at this time, after obtaining the normal volume operation request sent by the client for the target normal volume on the RAID card, it reads the attribute operation permission and storage data operation permission of the client for the target normal volume from the record of the volume attributes in the two-level Bitmap. If it is indicated that the client can operate on the target normal volume, then it performs the normal volume operation corresponding to the normal volume operation request on the target normal volume.
[0074] In this embodiment, it obtains an encrypted volume operation request sent by the client for a target encrypted volume on the RAID card, and reads the permission information of the corresponding basic storage unit of the client from the preset secondary bitmap; the basic storage unit includes the encrypted volume and normal volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit; it determines whether the client has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key provided by the client in the encrypted volume operation request; if the client has the operation permission corresponding to the target encrypted volume, it performs the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key.
[0075] It can be seen from the above technical solutions that the present invention replaces the original security encryption public keys used for each encrypted volume with the access encryption private keys corresponding to the client individually. In this way, the encrypted volumes corresponding to this client cannot be accessed by other users, and the encrypted volumes belong to the creating users, which can improve the security of user stored data. And by presetting the secondary bitmap to store the attribute operation permissions of each client for the basic storage unit and the storage data operation permissions of the basic storage unit, it further improves the security of user stored data.
[0076] When the encrypted volume operation request is an encrypted volume creation request for a target encrypted volume, refer to Figure 4As shown in the figure, an embodiment of the present application discloses a specific method for creating an encrypted volume of a RAID card, which is applied to a RAID card and includes:
[0077] Step S21: Obtain an encrypted volume creation request sent by the client for the target encrypted volume on the RAID card, and read the attribute operation permissions of the encrypted volume corresponding to the client from a preset secondary bitmap.
[0078] In this embodiment, an encrypted volume creation request sent by the client for the target encrypted volume on the RAID card is obtained. Here, it should be noted that new users need to register an account and password first, and the password is also the security key of the encrypted volume. In the present invention, the administrator can view the user's account information, but cannot query the user's security key, so the encrypted volume created by the user cannot be accessed either. After the user logs in, a normal volume can be created, and the normal volume can be accessed and operated by other users.
[0079] Step S22: If the attribute operation permissions of the encrypted volume corresponding to the client do not include the attribute operation permissions of the target encrypted volume, read the access encryption private key of the client from the encrypted volume operation request, and perform a security check on the access encryption private key; the security check is to check whether the length of the access encryption private key conforms to a preset constraint rule.
[0080] In this embodiment, if the attribute operation permissions of the encrypted volume corresponding to the client do not include the attribute operation permissions of the target encrypted volume, it means that the target encrypted volume has not been created yet. At this time, the access encryption private key of the client can be read from the encrypted volume operation request. Then, a security check is performed on the access encryption private key. Therefore, when the user creates an encrypted volume, the security key needs to be added together. Here, it should be noted that after obtaining the access encryption private key, it is necessary to check the length, characters, etc. of the access encryption key to determine whether the access encryption private key meets the key setting standard. It can be understood that the key setting standard (preset constraint rule) can be adjusted accordingly according to the actual situation.
[0081] Step S23: If the access encryption private key passes the security check, determine whether a first target RAID array corresponding to the target encrypted volume exists locally.
[0082] In this embodiment, if the access encryption private key passes the security check, it is necessary to determine whether the first target RAID array exists based on the array identifier of the first target RAID array in the encrypted volume creation request.
[0083] Step S24: If the first target RAID array does not exist, traverse the first target self-encrypting hard disk determined based on the encrypted volume creation request, and enable the security function of the first target self-encrypting hard disk to create a first target RAID array corresponding to the first target self-encrypting hard disk locally.
[0084] In this embodiment, if the first target RAID array does not exist, it indicates that the first target encrypted RAID array needs to be created at this time. Then, the background checks the SED disk and enables the security function of the hard disk to create the first target RAID array corresponding to the first target self-encrypting hard disk locally.
[0085] Step S25: Set the encryption volume attributes corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array.
[0086] In this embodiment, after the first target RAID array is successfully created, the user's security key is verified again. If the security key verification passes, the encrypted volume is successfully created. Then, the encryption volume attributes corresponding to the target encrypted volume are set to create the target encrypted volume on the first target RAID array. The encryption volume attributes here refer to binding the encrypted volume with the corresponding access encryption private key.
[0087] Step S26: If the first target RAID array exists, directly execute the step of setting the encryption volume attributes corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array.
[0088] In this embodiment, if the first target RAID array exists, directly verify the user's security key. If the security key verification passes, the encrypted volume is successfully created. Then, the encryption volume attributes corresponding to the target encrypted volume are set to create the target encrypted volume on the first target RAID array.
[0089] In this embodiment, obtain the access encryption private key of the client and the encryption volume attributes corresponding to the target encrypted volume; establish a mapping relationship between different clients and the operation permissions corresponding to the target encrypted volume based on the encryption volume attributes; store the operation permissions corresponding to different clients and the target encrypted volume on a preset secondary bitmap based on the mapping relationship and a preset data storage standard; the preset data storage standard is to store the user information of different clients on the first-level bitmap of the preset secondary bitmap and store the operation permissions corresponding to different clients for the target encrypted volume on the second-level bitmap of the preset secondary bitmap. That is, after the corresponding encrypted volume is created, a two-level Bitmap can be used to record the attributes of the volume. The first-level Bitmap is used to record the location information of the user. The second-level Bitmap is used to record the operation permission information of the user for all volumes.
[0090] In this embodiment, such as Figure 5As shown, the RAID card enables the security function of the SED disk and binds it to the encrypted volume created by the user. The security key is stored in the user information on the RAID card in units of users. When creating an encrypted volume, the security key needs to be input at the same time. When the security key meets the constraint conditions, the encrypted volume is created. Multiple volumes can be created on one RAID array, and different encrypted volumes can belong to different users. In this way, when the user creates and deletes an encrypted volume, the security key needs to be added, and the encrypted volume cannot be accessed by other users, which can improve the security of the user's stored data. Moreover, by using a secondary Bitmap to record the operation permission information of the user for all volumes and restricting the operation permission for the encrypted information of other users, even if the hard disk is lost or the security key of a certain user is leaked, it will not affect the data security of other users, thus improving the security of the encrypted data.
[0091] When the encrypted volume operation request is an encrypted volume modification request for the target encrypted volume, refer to Figure 6 As shown, an embodiment of the present application discloses a specific method for modifying an encrypted volume of a RAID card, which is applied to the RAID card and includes:
[0092] Step S31: Obtain an encrypted volume modification request sent by the user terminal for the target encrypted volume on the RAID card, and read the attribute operation permission of the encrypted volume corresponding to the user terminal from a preset secondary bitmap.
[0093] In this embodiment, an encrypted volume modification request sent by the user terminal for the target encrypted volume on the RAID card is obtained. It should be noted here that when the user modifies the access encryption key of the target encrypted volume, that is, modifies the security key of all encrypted volumes created by the user, the old access private key needs to be input. However, before verifying the old access key, it is necessary to first read the attribute operation permission of the encrypted volume corresponding to the user terminal from the preset secondary bitmap.
[0094] Step S32: Determine whether the user terminal has the modification operation permission corresponding to the target encrypted volume based on the attribute operation permission and the access encryption private key of the user terminal provided in the encrypted volume operation request.
[0095] In this embodiment, if the attribute operation permission of the encrypted volume corresponding to the user terminal read from the preset secondary bitmap indicates that the user terminal has the modification operation permission corresponding to the target encrypted volume, then read the access encryption private key sent by the user terminal through the access request to determine whether the user terminal has the modification operation permission corresponding to the target encrypted volume.
[0096] Step S33: If the client has the modification operation permission for the target encrypted volume, traverse all the encrypted volumes corresponding to the client, and replace the old encrypted volume attributes of all the encrypted volumes with the new encrypted volume attributes in the encrypted volume modification request; the new encrypted volume attributes include the new access encryption private key of all the encrypted volumes corresponding to the client.
[0097] In this embodiment, after verifying that the input security key meets the constraint conditions, traverse all the encrypted volumes created by the user and modify the security key of the encrypted volume. The new security key can be the same as the old security key, so the special process of verifying the security key on the traditional RAID card is omitted. It should be noted here that the above constraint conditions are also to verify the compliance of the length of the access encryption private key based on the preset constraint rules.
[0098] It can be seen that, as Figure 7 shown, to modify the security information of the encrypted volume, it is necessary to traverse all the encrypted volumes created by the user, obtain the security key of the volume, and then compare it with the input old security key; if the comparison is correct, perform parameter verification on the new security key, and after passing, set the new security information to complete the modification of the encrypted volume security information. In this way, the special process of verifying the security key on the traditional RAID card is omitted, which can improve the management efficiency of the encrypted volume.
[0099] When the encrypted volume operation request is an encrypted volume deletion request for the target encrypted volume, as shown in Figure 8 shown, an embodiment of the present application discloses a specific method for deleting an encrypted volume of a RAID card, which is applied to the RAID card and includes:
[0100] Step S41: Obtain the encrypted volume deletion request sent by the client for the target encrypted volume on the RAID card, and read the attribute operation permission of the encrypted volume corresponding to the client from the preset secondary bitmap.
[0101] In this embodiment, obtain the encrypted volume deletion request sent by the client for the target encrypted volume on the RAID card. It should be noted here that when the user deletes the access encryption key of the target encrypted volume, that is, deletes the security keys of all the encrypted volumes created by the user, the old access private key needs to be input. However, before verifying the old access key, it is necessary to first read the attribute operation permission of the encrypted volume corresponding to the client from the preset secondary bitmap.
[0102] Step S42: Based on the attribute operation permission and the access encryption private key of the client provided in the encrypted volume operation request, determine whether the client has the deletion operation permission for the target encrypted volume.
[0103] In this embodiment, if the operation permission for reading the attributes of the encrypted volume corresponding to the client on the preset secondary bitmap indicates that the client has the deletion operation permission for the target encrypted volume, then the access encryption private key sent by the client through the access request is read to determine whether the client has the deletion operation permission for the target encrypted volume.
[0104] Step S43: If the client has the deletion operation permission for the target encrypted volume, then delete the target encrypted volume from the corresponding second target RAID array based on the encrypted volume deletion request.
[0105] In this embodiment, since the security key is stored on a per-user basis, a security key is added when setting the deletion of the encrypted volume, and the deletion can be successful if the security key parameters are correct. Further, in this embodiment, after deleting the target encrypted volume from the corresponding second target RAID array based on the encrypted volume deletion request, it further includes: determining whether there are other basic storage units on the second target RAID array; if there are no other basic storage units on the second target RAID array, then turn off the security function of the second target self-encrypting hard disk corresponding to the second target RAID array to delete the second target RAID array locally. That is, when the volume deleted by a certain user is the last volume on the RAID array, the encrypted RAID array will be deleted simultaneously; at the same time, the security functions of all member disks are turned off. In addition, when the encrypted volume deletion request is obtained, it can first be determined according to the encrypted volume deletion request whether there is only the target encrypted volume on the corresponding second target RAID array. If so, it means that after deleting the target encrypted volume, this second target RAID array is an empty array. At this time, the second target RAID array can be directly deleted and the security function of the member disk (the second target self-encrypting hard disk) can be turned off. In this way, the operation of deleting the encrypted volume is omitted, and the management efficiency of the encrypted volume can be improved.
[0106] In this embodiment, as Figure 9 shown, for the traditional RAID to turn off the security function of the SED disk, there is a dedicated process, and turning off the security function of the SED disk is bound to turning off the security function of the RAID card. And the SED disk needs to be not in use, and when it is a member disk of the encrypted RAID array, the array needs to be deleted. This embodiment sets the separation of turning off the security function of the SED disk from turning off the security function of the RAID card itself, and binds the process of turning off the security function of the SED hard disk to the process of deleting the encrypted volume. And when deleting the encrypted volume, the user needs to input the security key for verification, and the encrypted volume can be deleted after successful verification. When the deleted encrypted volume is the last volume on the array, after deleting the array, all member disks are traversed to turn off the security function of the SED disk. In this way, the security key is bound to the user account, so that the encrypted volumes of different users have different security keys.
[0107] ReferenceFigure 10 , an embodiment of the present application also correspondingly discloses a RAID card encrypted volume access device, which is applied to a RAID card and includes:
[0108] A permission information acquisition module 11, configured to acquire an encrypted volume operation request sent by a user terminal for a target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the user terminal from a preset secondary bitmap; the basic storage unit includes an encrypted volume and a normal volume corresponding to a self-encrypting hard disk for storing data; the permission information includes the attribute operation permission for the basic storage unit and the storage data operation permission for the basic storage unit;
[0109] A right judgment module 12, configured to judge whether the user terminal has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the user terminal provided in the encrypted volume operation request;
[0110] An encrypted volume operation module 13, configured to, if the user terminal has the operation permission corresponding to the target encrypted volume, perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key.
[0111] It can be seen that in this embodiment, by replacing the original security encryption public key used for each encrypted volume with an access encryption private key corresponding to the user terminal alone, in this way, the encrypted volume corresponding to this user terminal cannot be accessed by other users, and the encrypted volume belongs to the created user, which can improve the security of the user's stored data. And by presetting a secondary bitmap to store the attribute operation permission of each user terminal for the basic storage unit and the storage data operation permission of the basic storage unit, the security of the user terminal's stored data is further improved.
[0112] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 11 It is a structural diagram of an electronic device shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation to the use scope of the present application. The electronic device may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the RAID card encrypted volume access method disclosed in any of the foregoing embodiments. In addition, the electronic device in this embodiment may specifically be an electronic computer.
[0113] In this embodiment, the power supply 23 is used to provide operating voltages for each hardware device on the electronic device; the communication interface 24 can create a data transmission channel between the electronic device and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is imposed on it here.
[0114] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, an optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0115] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device, and it can be Windows Server, Netware, Unix, Linux, etc. The computer program 222, in addition to including a computer program capable of implementing the RAID card encrypted volume access method executed by the electronic device disclosed in any of the foregoing embodiments, may further include a computer program capable of performing other specific tasks.
[0116] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the RAID card encrypted volume access method disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0117] Furthermore, this application also discloses a computer program product including a computer program / instructions; wherein, when the computer program / instructions are executed by a processor, the alarm aggregation method disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0118] In this specification, the various embodiments are described in a progressive manner, and the key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for related parts.
[0119] Those skilled in the art may further realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0120] The steps of the methods or algorithms described in connection with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0121] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0122] The technical solutions provided in this application have been introduced in detail above. Specific examples are used herein to illustrate the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for accessing a RAID card encrypted volume, characterized in that: Applicable to RAID cards, including: Obtain an encrypted volume operation request for a target encrypted volume on a RAID card sent by a user terminal, and read permission information of a basic storage unit corresponding to the user terminal from a preset secondary bitmap; the basic storage unit includes an encrypted volume and a common volume corresponding to a self-encrypting hard disk for storing data; the permission information includes attribute operation permissions for the basic storage unit and storage data operation permissions for the basic storage unit; Determining whether the user terminal has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the user terminal provided in the encrypted volume operation request; If the user terminal has the operation permission corresponding to the target encrypted volume, the encrypted volume operation corresponding to the encrypted volume operation request is performed on the target encrypted volume based on the access encryption private key.
2. The RAID card encrypted volume access method according to claim 1, characterized in that: When the encrypted volume operation request is an encrypted volume creation request for the target encrypted volume, obtaining the encrypted volume operation request for the target encrypted volume on the RAID card sent by the user terminal and reading the permission information of the basic storage unit corresponding to the user terminal from the preset secondary bitmap includes: Obtain an encrypted volume creation request for a target encrypted volume on the RAID card sent by the user terminal, and read the attribute operation permission of the encrypted volume corresponding to the user terminal from a preset secondary bitmap based on the encrypted volume creation request; Correspondingly, judging whether the user terminal has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the user terminal provided in the encrypted volume operation request includes: If the attribute operation permission of the encrypted volume corresponding to the user terminal does not include the attribute operation permission of the target encrypted volume, the access encryption private key of the user terminal is read from the encrypted volume operation request, and the access encryption private key is security-verified; the security verification is to verify the length of the access encryption private key based on the preset constraint rules; Correspondingly, if the user terminal has the operation permission corresponding to the target encrypted volume, performing the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key includes: If the access encryption private key passes the security check, determining whether there is a first target RAID array corresponding to the target encrypted volume locally; If the first target RAID array does not exist, traversing the first target self-encrypting hard disk determined based on the encrypted volume creation request, and enabling the security function of the first target self-encrypting hard disk to locally create the first target RAID array corresponding to the first target self-encrypting hard disk; Setting the encrypted volume attribute corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array; If the first target RAID array exists, the step of directly setting the encryption volume attribute corresponding to the target encrypted volume to create the target encrypted volume on the first target RAID array is performed.
3. The RAID card encrypted volume access method according to claim 2, characterized in that: When the encrypted volume operation request is an encrypted volume creation request for the target encrypted volume, after performing the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key, the method further includes: Acquire the access encryption private key of the user terminal and the encryption volume attribute corresponding to the target encryption volume; Establishing a mapping relationship between operation permissions corresponding to different user terminals and the target encrypted volume based on the encrypted volume attribute and the encrypted volume attribute; Based on the mapping relationship and the preset data storage standard, the operation permissions corresponding to the different user terminals and the target encrypted volume are stored in the preset secondary bitmap; the preset data storage standard is to store the user information of the different user terminals in the first-level bitmap of the preset secondary bitmap, and to store the operation permissions corresponding to the different user terminals for the target encrypted volume in the second-level bitmap of the preset secondary bitmap.
4. The RAID card encrypted volume access method according to claim 1, characterized in that: When the encrypted volume operation request is an encrypted volume modification request for the target encrypted volume, the step of obtaining the encrypted volume operation request for the target encrypted volume on the RAID card sent by the user terminal and reading the permission information of the basic storage unit corresponding to the user terminal from the preset secondary bitmap includes: Obtaining an encrypted volume modification request for a target encrypted volume on the RAID card sent by the user terminal, and reading attribute operation permissions of the encrypted volume corresponding to the user terminal from a preset secondary bitmap based on the encrypted volume modification request; Correspondingly, if the user terminal has the operation permission corresponding to the target encrypted volume, performing the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key includes: Determining whether the user terminal has the modification operation permission corresponding to the target encrypted volume based on the attribute operation permission and the access encryption private key of the user terminal provided in the encrypted volume operation request; If the user terminal has the modification operation permission corresponding to the target encrypted volume, all encrypted volumes corresponding to the user terminal are traversed, and the old encrypted volume attributes of all encrypted volumes are replaced based on the new encrypted volume attributes in the encrypted volume modification request; the new encrypted volume attributes include new access encryption private keys for all encrypted volumes corresponding to the user terminal.
5. The RAID card encrypted volume access method according to claim 1, characterized in that: When the encrypted volume operation request is an encrypted volume deletion request for the target encrypted volume, the step of obtaining the encrypted volume operation request for the target encrypted volume on the RAID card sent by the user terminal and reading the permission information of the basic storage unit corresponding to the user terminal from the preset secondary bitmap includes: Obtaining an encrypted volume deletion request sent by a user terminal for a target encrypted volume on the RAID card, and reading attribute operation permissions of the encrypted volume corresponding to the user terminal from a preset secondary bitmap based on the encrypted volume deletion request; Correspondingly, if the user terminal has the operation permission corresponding to the target encrypted volume, performing the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key includes: Determining whether the user terminal has the deletion operation permission corresponding to the target encrypted volume based on the attribute operation permission and the access encryption private key of the user terminal provided in the encrypted volume operation request; If the user terminal has the deletion operation permission corresponding to the target encrypted volume, the target encrypted volume is deleted from the corresponding second target RAID array based on the encrypted volume deletion request.
6. The RAID card encrypted volume access method according to claim 5, characterized in that: After deleting the target encrypted volume from the corresponding second target RAID array based on the encrypted volume deletion request, the method further includes: Determining whether the second target RAID array includes other basic storage units; If the second target RAID array does not include the other basic storage units, the security function of the second target self-encrypting hard disk corresponding to the second target RAID array is disabled to delete the second target RAID array locally.
7. The method for accessing a RAID card encrypted volume according to any one of claims 1 to 6, characterized in that: Also includes: Obtaining a common volume operation request for a target common volume on a RAID card sent by a user end; Reading the current user information of the user terminal from the first level bitmap on the preset secondary bitmap, and reading the attribute operation permission and storage data operation permission of the user terminal for the target common volume from the second level bitmap on the preset secondary bitmap based on the current user information; The common volume operation request is security verified based on the attribute operation permission and storage data operation permission of the user terminal for the target common volume, and after the security verification passes, the common volume operation corresponding to the common volume operation request is performed on the target common volume.
8. A RAID card encrypted volume access device, characterized in that: Applicable to RAID cards, including: The permission information acquisition module is used to obtain the encrypted volume operation request sent by the user end for the target encrypted volume on the RAID card, and read the permission information of the basic storage unit corresponding to the user end from the preset secondary bitmap; the basic storage unit includes the encrypted volume and the ordinary volume corresponding to the self-encrypting hard disk for storing data; the permission information includes the attribute operation permission of the basic storage unit and the storage data operation permission of the basic storage unit; A permission determination module, configured to determine whether the user terminal has the operation permission corresponding to the target encrypted volume based on the permission information and the access encryption private key of the user terminal provided in the encrypted volume operation request; The encrypted volume operation module is used to perform the encrypted volume operation corresponding to the encrypted volume operation request on the target encrypted volume based on the access encryption private key if the user terminal has the operation permission corresponding to the target encrypted volume.
9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor is used to execute the computer program to implement the steps of the RAID card encrypted volume access method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the RAID card encrypted volume access method according to any one of claims 1 to 7 are implemented.