Partition isolation storage method and storage device
By implementing partition isolation storage methods and secure reading and writing equipment on the storage device, combined with the self-destruction mechanism, the problem of difficult data security in the existing technology is solved, and high security level data protection and flexible self-destruction methods are realized.
Patent Information
- Application Number
- CN202510228470.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-17
AI Technical Summary
Data security means of existing storage devices are difficult to effectively ensure data security when facing diverse data security scenarios and the uncontrollability of mobile storage devices, especially during illegal access and data transmission.
By implementing a partition isolation storage method on the storage device, the second storage partition is randomly distributed in the real physical address of the storage device using nonlinear logical operations, and the security level and flexibility of data are improved through secure reading and writing devices and self-destruction mechanisms.
It realizes high security level protection for data, ensures access independence with different permissions, enhances the security of data during illegal access and transmission, and provides a flexible self-destruct mechanism to deal with uncontrollable situations.
Smart Images

Figure CN120162834A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data information security of storage devices, and particularly to a method and device for isolating and storing data in partitions on a storage device. Background Art
[0002] Since the advent of storage media and devices, technological advancements have made various attempts to improve the data security of storage devices to meet different requirements of users for data confidentiality and hiding.
[0003] Earlier methods were relatively simple, such as hiding file data or locking and hiding storage partitions. Since the execution object (file data) and the confidentiality means are essentially on the same medium device, the non-independent relationship between the execution object and the execution means causes these methods to often rely on the local terminal host to implement configuration and execution. Therefore, they are naturally restricted by the security level of the local device. When the permissions of the local terminal host are improperly obtained, the earlier methods such as hiding or locking and hiding will not be able to guarantee data security. With the emergence of various storage solutions, many limitations of the foregoing solutions are more difficult to apply in new data security aspects.
[0004] It should also be noted that data security has gradually become diversified due to the innovation of storage-related technologies. Common application scenarios include, for example, data transmission of different security levels between devices of the same or different security levels, or different users with different access permissions accessing data of different security levels under the same storage device, or long-term access to data saved by a remote device, and conditional self-deletion after long-term access, etc. It can be seen that the diverse scenario requirements also call for richer data confidentiality means applicable to fixed-end storage and / or mobile storage. Summary of the Invention
[0005] In view of this, the present invention provides a partition isolation storage method and a storage device, which solve at least one of the above problems.
[0006] To solve the above technical problems, a first aspect of the present invention provides a partition isolation storage method. The method determines the capacity and size of the second storage partition according to the total capacity of the current storage device, and accordingly obtains the number of second storage partition blocks, determines the user parameter value and the address range of each second storage partition block, and then performs a non-linear logical operation on the user parameter value and the device signature code to obtain the offset address of each second storage partition block in each area one by one. In this way, according to the quantitative relationship between the first storage partition and the second storage partition, the logical address of each first storage partition can be mapped to the physical address, and the logical address of each second storage partition can be mapped to the physical address, realizing the random distribution of the second storage partition in the true physical address of the storage device. When the second storage partition is used as a confidential partition, the security level of the data therein can be significantly improved. Moreover, since the first and second storage partitions have independent continuous logical address lists and mapped physical addresses, independent access to the confidential partition and the non-confidential partition can be realized for access requests with different permissions.
[0007] Due to the above settings, when a non-classified user accesses the partitioned storage device, it is difficult to be aware of the existence of the confidential partition and the confidential data.
[0008] A second aspect of the present invention provides a device for executing the partition isolation storage method based on the partition isolation storage method described in the first aspect of the present invention. The device system includes a storage device and an optionally accessible access device. The storage device can be directly connected to the host computer or can be connected to the host computer through the access device. In the former case, since there is no security authentication through the access device, only the non-confidential partition of the storage device can be accessed. In the latter case, access to the confidential partition can be performed after being authorized by the access device.
[0009] A third aspect of the present invention provides a flexible and optional self-destruction mechanism for the storage device based on the first and second aspects of the present invention. Data is accumulated according to the usage of the storage device. When the accumulated result reaches a preset condition value, the self-destruction mechanism is triggered. At the same time, on the basis of the existing natural physical self-destruction method of the device, the self-destruction mechanism adds a software self-destruction method to make the content in the confidential partition no longer able to be found by destroying the file system of the access device or destroying the address mapping of the storage unit, or deleting the device in the confidential partition according to the guidance of the file system and the address mapping. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 It is a schematic diagram schematically showing the state of allocating the second storage partition to n + 1 address areas in a preferred embodiment of the present invention;
[0011] Figure 2 It is a state diagram showing the non-linear distribution state of the first and second storage partitions;
[0012] Figure 3 is a schematic diagram, schematically showing the framework structure of a storage device controller and an interface in a preferred embodiment of the present invention;
[0013] Figure 4 is a schematic diagram, schematically showing the framework structure of a secure read / write device in a preferred embodiment of the present invention. Detailed implementation manners
[0014] In the known solutions in the storage field, data security means are involved. The confidentiality directions can be generally divided into two types: encrypting the original data file and restricting access to the data file and the compiled program. Combining the two is also a relatively conventional technical choice in this field. Among them, for encrypting the data file, the ciphertext algorithm is usually used to compile the original data during the data file transmission process to form ciphertext data that cannot be directly obtained, which is usually presented in the form of file garbled characters; the restriction of access to data and programs refers to restricting access to data files, as well as user permissions, accounts, etc. required for the program to be executed. Common simple methods are, for example, at the software level, data reading and file reading / writing are restricted to administrator permissions, and for another example, at the hardware level, access to a specific storage device is restricted to users with a key password to access the device with additional security.
[0015] However, in the existing solutions, even the encryption solution that combines the two, the encryption of the original data file and the restriction of access rights, should still be regarded as two independent means that are executed synchronously or successively. This is because the results of their respective executions usually do not affect each other's execution processes, or in the successive execution method, the result of the former judgment is only used as the basis for whether to execute the latter. The result of this superposition and / or combination of technical means only increases the number of data confidentiality steps quantitatively, but does not substantially improve the security level of the data file. Even so, because this technical choice of superposition means is easy to implement, it is still used in most scenarios.
[0016] For example, in the prior art, a dongle device carried by a USB flash drive is provided. The dongle device can serve as the key for the execution of specific applications in the host computer, or can also be regarded as the threshold for accessing or interacting with the storage device of the host computer. The specific manifestations of such a key and threshold include, but are not limited to, the account password required for program execution or account login, and the encryption algorithm required for decrypting the data in the storage device, etc. When an operator who has the dongle device and also has the key connects the dongle device to the host computer for communication, they can log in to the host computer device and perform operations such as accessing and modifying the data and files in its storage space. However, considering the efficiency of data acquisition and storage, in the actual application scenario, it is obviously not expected to configure a specific decryption algorithm after obtaining the execution permission. Therefore, the result of superimposing the means of this dongle device is still that after connecting the device to the host computer and inputting the key, the device will decrypt the encrypted file. It can be seen that as long as one of the dongle device and the key is possessed, it is impossible to prevent the data and files in the host computer from being obtained.
[0017] Based on the above situation, another attempt in the prior art is to pre-divide the storage space, then encrypt each partition, and then store the data in different storage areas according to different data types or security levels. For example, in the Chinese patent application for invention with the publication number CN111079106A, a solution for realizing multi-partition secure login of SSD based on the BIOS security mechanism is disclosed. This solution sets corresponding passwords for each storage partition by using the hard disk encryption function on the motherboard BIOS. When accessing, the correct password needs to be input to access the corresponding storage partition. The idea of this partitioned secure storage provided by this solution is that illegal visitors cannot directly know the capacity and location of each storage area. Therefore, similar known solutions have improved the data security level to a certain extent, but still have the following defects:
[0018] 1) Since it is a technical means based on the motherboard BIOS function, the key can still be regarded as stored locally and can still be accessed by the host CPU. In this way, when the host computer permission is breached (such as a virus program, an illegal process), this non-independent relationship between the host computer and the key will still lead to the ultimate loss of the key that can be accessed by the CPU;
[0019] 2) There are problems of simple and single functions in relying on the BIOS hard disk encryption function for configuration. When a certain partition after division is found, other hidden or non-hidden encrypted partitions can still be accessed by addressing according to a certain rule. Therefore, although the data is scattered and stored in different storage spaces after division, due to the division of the storage space can only be executed according to the preset rules, it still cannot meet the transmission and storage conditions of high-security-level data;
[0020] In addition, in the new situation described in the technical background, due to the plug-and-play feature of mobile storage devices, the use of mobile storage devices (external hard drives, mobile flash drives) is usually not limited to a fixed single scenario. As the storage device is used while being moved, the host computer connected to it is not unique either. Therefore, the earlier encryption technologies can no longer meet the new application requirements and scenarios. Compared with existing fixed storage devices, mobile storage devices have a higher degree of uncontrollability. The manifestations of this uncontrollability include, but are not limited to, the identity of the user, the usage duration, the usage frequency, etc. The resulting new application problems are as follows:
[0021] 1) The confidential data and non-confidential data are not isolated from each other, which affects the legitimate access of non-secret-level users.
[0022] 2) For the aforementioned uncontrollable situations (lending, transferring) of mobile devices, better data destruction strategies and means should be provided.
[0023] Regarding the new application problems, the cited solution (CN111079106A) also proposes a strategy for temporarily and urgently destroying data through a destruction password. These destruction passwords are also stored in a partitioned area. It is easy to think that the destruction passwords stored in the local partition also have the same security problems as the storage partition keys mentioned above. It should be noted that the destruction of data in the cited solution still relies on the operation of the host computer and the connection of the data line. If the host computer cannot operate normally or the connection line fails, then the destruction password cannot be executed normally either.
[0024] When solving the above technical problems, the idea of the preferred embodiment of the present invention includes two aspects. First, a higher degree of randomness should be introduced in the partitioning of the storage area. For example, the partition for storing confidential data is randomly configured at different positions in the storage partition, and the specific configuration method of the storage partition is integrated with other security and random feature factors of the current device. In this way, since the specific configuration method of the storage partition is not known, even if an illegal access obtains the location of a certain storage partition, it is impossible to deduce the existence and location of other storage partitions. Second, the data self-destruction strategy should have a higher degree of flexibility, that is, multiple selectable data self-destruction methods are adapted to different self-destruction conditions.
[0025] The embodiments of the present invention will be described below with reference to the accompanying drawings. Those of ordinary skill in the art can recognize that the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the drawings and the description are illustrative in nature and are not used to limit the protection scope of the claims. In addition, in this specification, the drawings are not drawn to scale, and the same reference numerals represent the same parts.
[0026] It should be noted that in the embodiments of the present invention, the expressions "first" and "second" are used to distinguish two entities or parameters with the same name but different identities. It can be seen that "first" and "second" are only for the convenience of expression and should not be construed as a limitation on the embodiments of the invention. This will not be elaborated one by one in the subsequent embodiments.
[0027] In a storage device, there is a mapping relationship between the logical address during program compilation and the actual physical address of the storage medium. That is, a logical address during program compilation corresponds to an actual physical address of the storage medium. From this, it can be known that the essence of partitioning the storage area is to select some continuous or discontinuous storage address ranges from the actual addresses of the storage device and configure the corresponding logical address ranges. One aspect of the preferred embodiment of the present invention is to make the above-mentioned method of selecting and partitioning addresses more random.
[0028] For the convenience of description, in the preferred embodiment of the present invention, a first storage partition and a second storage partition are defined. The first storage partition and the second storage partition can be used to store non-confidential data and confidential data respectively, or can be used to store data with different confidentiality levels. In the following text, it is defined that the first storage partition stores non-confidential data and the second storage partition stores confidential data.
[0029] The first storage partition and the second storage partition belong to the same overall storage medium, or storage unit, or storage device. Moreover, the total capacity of the first storage partition and the second storage partition should be equal to or slightly less than the total storage capacity of the storage medium, unit or device. In general, in the preferred embodiment of the present invention, it is expected that a third party with legal permissions can normally read the data in the non-confidential partition during legal access and use. In other words, the data in the first storage partition should be able to be normally accessed and obtained at this time. Starting from this, as in the prior art, the first aspect considered from the perspective of data security is to prevent the data in the second storage partition from being detected (such as the lock-and-hide method used earlier). However, since the total amount of the storage device is clear, when the capacity of the first storage partition is less than the total storage capacity of the storage device, it is obvious that the existence of the second storage partition cannot be concealed. In some preferred embodiments of the present invention, when the space occupied by the confidential data involved is extremely small (generally dozens to hundreds of KB), the capacity of the second storage block is correspondingly set to be extremely small, so that it is not easy to find the existence of the second storage partition after comparing the first storage partition and the total capacity of the device. But in some extreme storage requirements, when the confidential data may also include larger-capacity data (audio and video streaming media), a better solution should be provided. On the one hand, in the preferred embodiments of the present invention, the overall storage space of the device is generally scattered to form multiple first storage blocks and second storage blocks. At the same time, the larger-capacity confidential data is scattered and stored in multiple second storage partitions.
[0030] Of course, the randomness steps for the first and second storage partitions should also be executable and implementable. By "executable and implementable", it means that the scheme of dividing the overall storage space into multiple first and second storage blocks and dispersing the second storage blocks within the first storage blocks is computer-implementable. Specifically, in a preferred embodiment of the present invention, after determining the actual capacity of the storage device, first, the user with the permission determines the storage space required for the confidential files, that is, the total space of the second storage blocks. Subsequently, the size of the space occupied by a single second storage block is determined. For ease of implementation, in some preferred embodiments of the present invention, the space occupied by the second storage blocks can be configured as a fixed value K ( Figure 1 in the example, the value is 2) consecutive basic storage units. In this way, the specific number of the second storage blocks included can be calculated based on the total capacity size occupied by the second storage blocks and the fixed capacity of each second storage partition. For example, taking a storage device with a capacity of mTB as an example, first configure the required confidential storage capacity as K(n + 1) basic storage units, and the capacity of each second storage block is fixed at K consecutive basic storage units. Then the specific number of the second storage blocks can be obtained as n + 1, that is, 『K(n + 1) / K』 storage blocks. Subsequently, it is necessary to randomly disperse the n + 1 second storage blocks into the first storage block.
[0031] The first storage block can be regarded as the space obtained by removing all the second storage blocks from the total storage space. Then the partitioning principle of this scheme can be understood as taking a part of the real physical address of the total storage space as the address of the first storage block, and the remaining part is the address of the second storage block. If the addresses of the first and second storage blocks are regarded as two sets composed of real physical addresses, then the union of the two sets is the address range of the real physical address. Still taking the aforementioned mTB removable storage device as an example, in a preferred embodiment of the present invention, when allocating n + 1 second storage blocks each containing K ( Figure 1 in the example, the value is 2) consecutive basic storage units to n + 1 address regions, first divide the real physical address into n + 1 storage regions according to a fixed length, and then make any K consecutive addresses within each storage region form the second storage block. In this way, a non-linear distribution of the first and second storage blocks on the consecutive real physical addresses is formed.
[0032] To achieve the aforementioned non-linear distribution, in a preferred embodiment of the present invention, based on the idea of "fitting the configuration method of the storage partition with other security and randomness characteristic factors", a non-linear algorithm is introduced, and this algorithm is data-fitted with the characteristic parameters of the storage device itself and the configuration method parameters of the second storage partition by the user (abbreviated as user parameters). Thus, if the non-linear algorithm is F, the offset address of a certain second storage block should satisfy:
[0033] Offset address of the second storage block = F(sequence number, characteristic parameter, user parameter).
[0034] In a specific embodiment, taking the SM4 algorithm that meets the non-linear condition under the prior art as an example, the addresses of the second storage blocks are numbered according to the total number of the second storage blocks configured in the aforementioned user configuration process, and n + 1 offset addresses of the second storage blocks from 0 to n are obtained. Subsequently, at least one device code of the current removable storage device is selected as a characteristic parameter, such as the device ID, device capacity code, or device model code of the storage device, etc., to determine the value. Then, a pre-set non-linear F operation (such as SM4) is selectively performed between the characteristic parameters, and / or between the characteristic parameters and the sequence number, and between the characteristic parameters and the user parameter, so as to obtain a set of storage block offset physical addresses of each area of the n + 1 second storage blocks. According to the guidance of this set, the system will disperse the n + 1 second storage partition addresses in n + 1 divided address areas. Figure 1 Schematically shows the state of allocating the second storage partition to n + 1 address areas in a preferred embodiment of the present invention Figure 1 The middle part shows a set of consecutive real physical addresses of the storage device composed of n + 1 address areas. Each address area contains a second storage block composed of 2 consecutive basic storage units. And, as can be seen from the figure, each address area is composed of 8 basic storage units, and the offset addresses of each second storage block in each corresponding area are randomly non-linearly distributed. It should be noted that the so-called "allocating the second storage block" is just an easy-to-understand statement used to explain the technical purpose of the first aspect of the present invention. In fact, the realization of this so-called allocation process is achieved by creating a logical address range of different storage blocks as shown in Figure 1 and then mapping between the logical address of the storage block and the real physical address of the storage device. The presented style after allocation can also be referred to the structure shown in Figure 2 In Figure 2 the first storage partition and the second storage partition are distinguished by different colors. The white-filled squares are the first storage blocks, and the gray-filled squares are the second storage blocks. It can be seen that the second storage blocks are randomly scattered throughout the storage space. This part of the content will be elaborated below and will not be expanded here.
[0035] As described above, in legal access scenarios such as lending and transferring, non-confidential users of the storage device can normally access, read, and write the data in the first storage partition without being aware of the existence of the second storage partition. In other words, the access and read / write permissions of non-confidential users and confidential users for the two storage partitions should be independent of each other. In the above example, it should be shown that non-confidential users can only access, read, write, and delete the data in the first storage block, and only confidential users can access, read, write, and delete the data in the second storage block. It should be noted that the aforementioned non-confidential users and confidential users only differ in their usage identities. In specific implementation, it should be understood that confidential users can also access, read, write, and delete the data in the first storage block in the manner of non-confidential user permissions. Conversely, non-confidential users can only modify the data in the second storage block after obtaining the permission key. Importantly, in the preferred embodiment of the present invention, the data in the first storage block and the second storage block should be independent of each other, and users cannot operate on the data in different storage blocks simultaneously. Of course, when considering the convenience of data access in actual applications, it is also possible to set other user permissions that can simultaneously access and modify the data in different storage blocks, but in this case, it is difficult to achieve the independence of data between storage blocks, which is not conducive to improving data security.
[0036] After dividing the address area, to achieve the purpose of the above-mentioned independence of storage block data, it is still necessary to solve the addressing problems of the first and second storage blocks. The addressing problems include two aspects. First, make the first storage block and the second storage block form an independent and continuous logical address space, so that when addressing, after determining the current access permission, the addressing will only be performed within the storage block corresponding to the permission. Second, looking back at the mapping relationship between the logical address and the physical address, data access, modification, and reading / writing are still performed on the real physical address, so it is necessary to solve the addressing problem from the storage block logical address to the real address. According to the first aspect above, continue to refer to Figure 1 , Figure 1 The right part and the left part of respectively show the continuous logical address set of the first storage block and the continuous logical address set of the second storage block. It can be seen that the logical addresses of the first and second storage blocks are continuous, while the physical addresses are non-continuous. Combining the real addresses of the first and second storage blocks, that is, Figure 1 the sum of the real physical addresses of the storage device shown in the middle part. In this way, the isolation of addresses between different storage blocks is achieved, and then it is necessary to solve the mapping between the logical address and the physical address.
[0037] Generally, when a program is compiled, it is determined that the logical address starts from address 0. According to the real address pointed to by logical address 0, an offset between the two can be determined. Under the existing technology, the usual practice of program compilation addressing is to obtain the real address mapped by the subsequent logical address according to this offset. However, this method cannot be applied to the preferred embodiment of the present invention because:
[0038] 1) The first and second storage partitions are independent of each other, and the ranges of the real physical addresses mapped by the first storage partition and the second storage partition are not continuous;
[0039] 2) More importantly, in the preferred embodiment of the present invention, before the user specifically configures the configuration method of the second storage block (i.e., user parameters), the specific positions of the storage units of the second storage block cannot be determined.
[0040] In other words, in the preferred embodiment of the present invention, the offset between each second storage block and its real physical address is not fixed. Looking back Figure 1 , comparison Figure 1 shows that in the logical address and real physical address regions, the offset address of the second storage block in address region (0) is 2, the offset address of the second storage block in address region (1) is 0, the offset address of the second storage block in address region (2) is 6, and the offset address of the second storage block in address region (n) is 4. Therefore, during the addressing process, the offsets between the logical address and the real physical address need to be calculated separately.
[0041] Although the specific position of each second storage is not determined, when its specific number is determined, the number of address regions included in the total storage space is certain. In this way, according to the total real physical address and the number of address regions, the number of basic storage units included in each address region can be obtained. After determining the number of basic storage units included in each second storage block, the number of basic storage units included in each first storage block can be determined. And after the above steps, logical addresses have been assigned to the second storage block and the basic storage units therein, and corresponding real physical addresses within the storage device. Then, according to the real address of the second storage block and the quantity relationship of the basic storage units included in the first and second storage blocks, the real physical address of each first storage block can be deduced. For example, in the Figure 1 shown embodiment, each address region contains 8 basic storage units, each first storage block contains 6 basic storage units, and the logical address is represented in decimal and the physical address is represented in octal. Thus, the real physical address corresponding to the first storage block can be expressed as:
[0042] The physical address corresponding to the storage unit of the first storage block logical address = the first storage block logical address + the number of basic storage units K included in the second storage block × (the first storage block logical address / the number of basic storage units included in the first storage block in the address area),
[0043] Among them, 『the number of basic storage units K included in the second storage block × (the first storage block logical address / the number of basic storage units included in the first storage block in the address area)』 is also the size of the offset that needs to be added during logical address addressing. For example, looking back Figure 1 , Figure 1 Taking the logical address 16 of the first storage partition in as an example, the corresponding storage real physical address is: 16 + 2 × (16 / 6) = 20 (where the result of 『16 / 6』 is rounded), which is also the octal number 24. Thus, the independence between different storage partitions and the addressing problem of different storage partitions are realized.
[0044] It should be noted that in the foregoing embodiments, first, the capacity of a single second storage block is set to a fixed value, and this fixed value is greater than or equal to 1 basic storage unit. Second, for a second storage block, the addresses between the basic storage units of the fixed value size it contains are continuous. The purpose of such a configuration is to facilitate configuring the storage block address range and subsequent determination of the mapping relationship between the logical address and the physical address of the storage blocks. However, obviously, on the premise of meeting the computer computing power level and ensuring the smooth operation of the system and programs, those skilled in the art should know and can make more choices after understanding the technical guidance of this solution. For example:
[0045] 1) Set the capacity of the second storage block to 1 basic storage unit, so as to set the second storage block more dispersedly in the storage space;
[0046] 2) Set the maximum value of the capacity of the second storage block, and make it float within the numerical range determined by this maximum value. During the subsequent allocation process, the capacity sizes of the second storage blocks included in different first storage blocks can also be dynamic;
[0047] 3) For a second storage block with a fixed capacity, the addresses of the basic storage units it contains can also be non - continuous, so that when addressing, it is necessary to calculate each of the multiple non - continuous basic storage units corresponding to the current second storage block one by one. The above - mentioned methods, as well as combinations of other methods that are easy for those skilled in the art to think of, can better improve the randomness in the configuration of the first and second storage blocks, which also means improving the level of data confidentiality.
[0048] Based on the first aspect of the preferred embodiment of the present invention, a storage device using the partition isolation storage method can be further configured. Generally, such a storage device uses a common memory as a carrier. In the control logic of the memory, a part for executing the aforementioned partition isolation storage method is added, and the memory still maintains its connection to the host computer through the original bus interface. The user inputs user parameters through the host computer software. The software configures the storage partitions in the storage device according to the aforementioned algorithm, and non-linearly configures multiple encrypted storage blocks in the memory. However, when reviewing the prior art, the second aspect of the present invention realizes that if information such as the configuration software and the key configuration method is still stored locally on the host computer, then even if the encrypted data is stored on the mobile storage device side, when the permissions of the host computer are breached (such as by viruses, scripts, etc.), the aforementioned architecture will still have the same problems as the cited solution; similarly, if information such as the configuration software and the key configuration method is written into the mobile storage device used as a carrier and moves with the storage device, and then the algorithm in the storage device controller is called through the host computer software, then it still cannot solve the problem of the host computer infecting the storage device controller after being breached. Moreover, in addition to this, since the algorithm needs to be called to perform interactive verification of the key every time the device is connected, there is still the same problem of inconvenient use as the existing dongle. For example, when the device is connected, the legitimate access of non-confidential users to non-confidential storage partitions also requires key verification, so at this time the mobile device has also lost its original plug-and-play feature.
[0049] In view of this, the second aspect of the present invention proposes a secure read-write device that is erected as a bridge between the host computer and the mobile storage device. Ideally, for the legitimate access of non-confidential users to non-confidential storage blocks, the storage device still maintains its plug-and-play feature without the need to rely on the secure read-write device, while for the access to confidential storage blocks, it must rely on the secure read-write device to be configured between the host computer and the storage device. In addition, the non-linear configuration of the storage area of the storage device during initialization, and the reading, writing, deletion, etc. of the data information in the confidential storage blocks after the device is initialized must also rely on this secure read-write device to execute and implement. Correspondingly, the controller (control logic) of the storage device should also be added with a part adapted to the secure read-write device. In addition to the basic parsing of the transmission protocol and power supply, the storage device should be configured to be combined with the aforementioned secure read-write device to realize the non-linear distribution of the storage partitions in the first aspect of the present invention. It should also be noted that until the first aspect of the present invention, although the isolation and addressing of the storage blocks are realized, the system should still distinguish the permissions of the current operation to correctly point to the correct address area according to the current operating user and the source of the user operation. Therefore, a verification mechanism should also be provided between the storage device and the secure read-write device to distinguish whether the current access is secure. In this way, the host computer, the secure read-write device, and the secure storage device are combined to form the overall architecture of the second aspect of the present invention.
[0050] First, let's talk about the secure read / write device. Figure 4 The framework structure of the secure read / write device is schematically shown, including two interfaces. Among them, the PC bus interface is used to connect to the interface on the host computer, and the storage device interface bus is used to dock with the secure storage device. When specifically configuring, for the specific selection of the aforementioned two interfaces, it can also be various general interfaces on the host computer and the storage device. The two interfaces can be bus interfaces of the same standard, or different standards, and can also be configured as other forms of the same interface through an adapter on the basis of different interfaces. For example, select a bus interface that is the same as the USB interface or Ethernet interface on the host computer as the aforementioned PC bus interface, and then select various common interfaces on the storage device (such as USB, EMMC, SATA, SCSI, and SAS, etc.) as the storage device interface. Obviously, the preferred embodiments of the present invention should not be limited by the specific interface forms selected. Continuing to refer to Figure 4 It is found that between the PC bus interface and the storage device interface, there are also multiple functional modules, which Figure 3 In the storage device framework structure shown, there is a matching or combination relationship with the multiple functional modules correspondingly added in the controller (control logic) after initializing the storage device.
[0051] Figure 3 The framework structure of the controller of the partition isolation storage device described in the second aspect of the present invention is schematically shown. In the structure shown in the figure, from the bus interface to the memory read / write controller, there are four structural units. Among them, in the command parsing module part, the access commands transmitted by the host computer through the bus interface are analyzed to obtain the control meaning and address information of the current operation. The function of the non-linear address transformation module part is that in the first aspect of the present invention, the non-linear address transformation module obtains the physical address where the data of the access request is located according to the address information parsed and sent by the command parsing module; the bright and dark space isolation access module part corresponds to the part in the first aspect that isolates the logical address and physical address of different storage blocks. The basic purpose of the security authentication illegal access detection part is to provide a means of two-way password verification to confirm whether the current access is secure. In this preferred embodiment, the "security" should be understood as whether access to a certain storage block is allowed. In the aforementioned example, the allowed access situations are, for example, non-secret users can only access, read, and delete the data in the first storage block, and secret users can only access, read, and delete the data in the second storage block, while the avoided situations are, for example, non-secret users try to bypass the verification mechanism (because they have not been verified by the secure access device) to access the data in the secret storage block.
[0052] Looking back Figure 4In the secure access device, there is a key management module and a security authentication unit. The authentication and management of keys by this module and unit generally include the generation, rotation, revocation, destruction, activation / deactivation, archiving, and recycling of system keys, as well as the verification and judgment of keys input by the host computer, etc. The execution mechanism of this module and unit is that when the secure access device is connected to the host computer, the mutual key matching is required to confirm the permissions of the current user, or rather, the security level, and thus determine the specific storage blocks that the current user should access on the removable storage device. In specific implementation, since non-secret users do not have a secure access device, they directly connect the secure storage device to the host computer. In this way, since there is no key matching confirmation, the system will judge that they can only access the data content in the non-secret partition (i.e., the aforementioned first storage block). Only secret users who have a secure access device and possess keys can access the data content in the secret partition (i.e., the aforementioned second storage partition) after connecting the secure access device and correctly inputting the keys.
[0053] Looking back at the first part of the present invention, during the initialization process of the non-linear transformation, the user will select and input the total capacity of the second storage block and the number of basic storage units included in each second storage block. These data inputs will be sent to the non-linear transformation module of the secure storage device for generation. In a read operation request when the secure access device is connected to the host computer, after mutual authentication between the secure access device and the secure storage device, the storage partition requested to be accessed is confirmed, and then, according to the real physical address of the corresponding data in the partition real physical address sequence in the file system created on the secure storage device after initialization, a request is sent to the controller of the secure storage device. The command parsing unit of the secure storage device parses the instruction and obtains the data from the real physical address of the storage array according to the parsed address. In a write operation request when the secure storage device is connected to the host computer through the secure access device, the difference in the same steps is that the data written into the secure storage partition will first undergo arithmetic compilation by the encryption arithmetic unit and then be stored in the secure storage block. In addition, those skilled in the art can easily think that in the second aspect of the preferred embodiment of the present invention, the storage device parameters, device ID numbers, user parameter inputs, encryption parameters, and different user logins, file requests, and read / write records involved in the above process are saved as logs in the secure storage device for query and invocation.
[0054] The encryption operation unit and the cryptographic operation unit constitute the main operation units of the secure read-write device in the present invention. In particular, in the preferred embodiment of the present invention, the True-RND algorithm is selected as the algorithm used by the encryption operation unit when writing data into the secure storage partition. However, any known standard algorithms (such as SM1, SM2, SM3, SM4 widely selected in China, and AES, ECC, RSA, etc. commonly used abroad) and combinations thereof can be used for the encryption operation unit part of this solution. During specific calculations, the encryption operation unit cooperates with the key management unit and the authentication unit to achieve mutual authentication using random numbers and encryption algorithms. For the specific implementation of this authentication process, a common method is, for example, to deploy corresponding software on the host computer and rely on the host computer's IO device for input and output. However, to avoid data loss caused by host computer security issues and improve data security, the means of external authentication using an IC card is also adopted to confirm security by the method of matching after sending random numbers. It should be understood that the specific algorithm selected by the encryption operation unit and the specific execution means should all be optional and should not be regarded as a limitation within the scope of the preferred embodiment of the present invention. The specific implementation of a preferred embodiment of the second aspect of the present invention includes the following steps: 1) First, the main key for encrypting data and files is agreed upon. The formed main key after the agreement will be stored in the secure read-write device. Therefore, the secure read-write device must be connected to the host computer for the agreement of the main key. After the device is connected, the user calls the key management module and the cryptographic operation module on the secure read-write device through the host computer and specifically generates the main key for encrypting confidential data;
[0055] 2) After the main key is agreed upon, the secure storage device needs to be configured, that is, the storage space therein is divided into storage blocks according to the partition isolation method referred to in the first aspect of the present invention. Similarly, this requires connecting the secure storage device to the storage device interface of the secure read-write device through its bus interface while keeping the secure read-write device connected to the host computer. Subsequently, the user calls the True-RND and cryptographic operation modules on the secure read-write device and the security authentication module on the secure storage device through the host computer to complete the access authentication between the two. If the current user completes the authentication process, it means that the user has the permission to access the data in the secure storage block. Then, the user still uses the secure read-write device through the host computer to configure the data and rules such as the storage block size and storage block distribution rules involved in the non-linear address transformation, light and dark isolation access module, and security authentication illegal access detection module in the secure storage device, so as to form the non-linear distribution mode of storage blocks as described in the first aspect of the present invention in the secure storage device. During this process, the above configuration data, parameters, and records performed by the user through the host computer will be saved to the parameter log module of the secure read-write device for calling, exporting, and backing up;
[0056] 3) In a single write operation of confidential data, the secure storage device must be connected to the host computer through the secure read / write device. After completing the secure access authentication as described above, the secure read / write device encrypts the file to be written through the main key and the password operation module according to the previously agreed main key, and sends a write command to the command analysis module of the secure storage device. Thereafter, according to the analysis result of the command analysis module, the secure storage device completes the conversion between the logical address and the physical address through its non-linear address transformation and light / dark space isolation access module, and finally drives the read / write controller of the secure storage device to complete the writing of the encrypted data file.
[0057] 4) In a single read operation of confidential data, the connection relationship for communication between the secure storage device and the host computer through the secure read / write device must still be maintained. After completing the secure access authentication, the user sends a read command to the command analysis module of the secure storage device through the read / write control module of the secure read / write device. Thereafter, according to the analysis result of the command analysis module, the conversion between the logical address and the physical address is completed through its non-linear address transformation and light / dark space isolation access module, and the read / write controller of the secure storage device is driven to complete the reading of the confidential data file. However, at this point, the read data file is still encrypted data, and it is also necessary to use the secure read / write device to decrypt the read encrypted data with the previously agreed main key and the password operation module.
[0058] After implementing the first and second aspects of the present invention, a method for partitioned isolation storage and access of data, as well as a read / write device based on the partitioned isolation storage method, have been implemented, and corresponding technical effects have been achieved. However, considering the extreme uncontrollability involved in data security, the situations are roughly as follows:
[0059] 1) Loss of a removable storage device storing classified data, or lending, transfer for an indefinite period, etc.;
[0060] 2) Users without a secure access device bypass the security verification mechanism and access the confidential data of the storage device;
[0061] 3) Users without a secure access device attempt to access the confidential data after obtaining the key;
[0062] In view of the mobile characteristics of the removable storage device, it is difficult for the first and second aspects of the present invention to completely avoid the occurrence of the above uncontrollable situations. Therefore, to further enhance data security and solve the technical problems existing in the self-destruction scheme of the cited existing solutions, the third aspect of the present invention is to provide a more flexible self-destruction guarantee means. The self-destruction guarantee means generally includes two aspects. One is a circuit for realizing the self-destruction of the storage device; the other is a condition judgment mechanism for controlling the operation of the self-destruction circuit.
[0063] The configuration difficulty of the self-destruction circuit lies in that the destruction means in the prior art all require the device to be connected to a host computer. This is because the self-destruction circuit needs the connection port of the host computer for power supply, and at the same time, the host computer is also required as the sender of the self-destruction instruction. In other words, if the device is lost and no longer connected to the terminal device, the data inside it will never be destroyed. Most of the destruction of devices in the prior art is rough and irreparable. For example, the power supply circuit unit of the memory is improved to add a high-voltage power supply branch on the basis of the original low-voltage power supply, and a switching mechanism that can switch between high and low voltage power supplies is configured. In this way, when self-destruction needs to be triggered, after the host computer connected to the network receives the self-destruction instruction, it can drive the switching mechanism to select the high-voltage power supply branch to cause self-destruction. However, firstly, the destruction means of self-destruction is limited by factors such as power supply, making it difficult to completely destroy the data. Secondly, with the trigger of the device self-destruction, all the data inside it will be destroyed together, which are all manifestations of the lack of flexibility of the self-destruction means in the prior art.
[0064] The ideas for solving the above technical problems in the third aspect of the present invention include:
[0065] 1) Since the secure access device and the storage device are two independent devices, when the above-mentioned uncontrollable situation occurs, there is mostly no secure access device. Therefore, the self-destruction functional unit should first be configured at the storage device end;
[0066] 2) It should be possible to choose between the overall self-destruction of the device and the optional destruction of confidential data;
[0067] 3) The conditions for triggering self-destruction should also be selectable and configurable.
[0068] Therefore, in the third aspect of the present invention, the preferred embodiment first retains the existing self-destruction circuit. This is because, in order to avoid the lost device from no longer being connected to the network or the power supply host computer, the rough device self-destruction means is still necessary. On this basis, when further improving, when the preset conditions are met, the self-destruction means corresponding to the preset conditions can be selected.
[0069] Let's first talk about the preset conditions. The preset conditions are also selections stored on the storage device side (for example, in the security authentication illegal access detection unit on it), and are generated based on the long-term practice of existing technologies and the changing needs after the long-term use of existing products. For example, for temporarily confidential or data with a confidentiality time limit, when the device power-on time exceeds the preset duration, self-destruction is triggered. Similarly, the number of times the storage device is connected to the host computer or the security access device can also be set. Another example is in the scenario of illegal access. When the number of authentication failures accumulates to the preset number, or when the security authentication status register is modified by non-determinable means to attempt to access the dark area, self-destruction means can also be triggered. Of course, for the triggering of the latter means, it is also necessary to specifically judge the access process and various data during the process to avoid the occurrence of mis-triggering situations (such as non-malicious errors like incorrect key input and device transmission errors).
[0070] The self-destruction means triggered by meeting the above preset conditions can be set during the initialization process. In addition to directly triggering the burning means of the high-voltage circuit, according to the content of the second aspect of the present invention, it is also possible to achieve the separate destruction of the data in the secure storage partition through means. For example, when the condition is triggered, the data in the second storage block on the memory of the storage device will be self-deleted. After the data deletion is completed, the user-set parameters will be deleted, and finally, the destruction circuit will be activated for the physical self-destruction of the device.
[0071] The above embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the appended claims.
Claims
1. A partition isolation storage method, the method is used to form different storage partitions on a storage device, the method comprising the following steps: Configure at least one first storage partition and at least one second storage partition under the storage device, and form a set of user parameters corresponding to the number of the first and second storage partitions according to the number of the first and second storage partitions; Selecting at least one device code of the storage device, fitting the device code with the user parameter as input of the address algorithm, and assigning mappings between logical addresses and physical addresses of each second storage partition one by one according to the address algorithm, so that the second storage partitions are randomly distributed in the storage device; Configuring a logical address range of the first storage partition, and acquiring an offset between a logical address and a real address of each of the first storage partitions one by one according to the user parameters; respectively configuring a threshold for independent access to the first or second storage partition, so that data in the first storage partition and data in the second storage partition are isolated; When data access is requested, the access threshold is determined to access the data in the corresponding storage partition.
2. The partition isolation storage method according to claim 1, wherein: The steps of configuring the number of the first storage partition and the second storage partition are specifically as follows: Divide the device storage space into multiple address areas; Configuring the total capacity of the second storage partition and the number of basic storage units included in the second storage partition to obtain the number of second storage partitions in the storage device; The number of basic storage units included in the second storage partition and the number of second storage partitions are taken as the user parameters.
3. The partition isolation storage method according to claim 2, wherein: The device code is at least one of a storage device ID, a device capacity code, or a device model code, or a combination of several of them. The specific steps of fitting the device code with the user parameters are: Perform logical operations between multiple device codes and between the device code and the user parameter.
4. The partition isolation storage method according to any one of claims 1 to 3, wherein: A block cipher algorithm is used to fit the device code and the user parameters to obtain a plain text input of the block cipher algorithm to output a logical address offset of each of the second storage partitions, so that the second storage partitions are nonlinearly distributed in the storage device.
5. The partition isolation storage method according to claim 2 or 3, wherein: The second storage partitions are randomly distributed in the storage device in the form of: Each address region includes a second storage partition with a fixed capacity, and the basic storage units included in the second storage partition are randomly distributed in each address region, or, Each address partition includes a second storage partition with a non-fixed capacity, and the basic storage units included in the second storage partition are randomly distributed in each address area.
6. The partition isolation storage method according to claim 4, wherein: The second storage partition is nonlinearly distributed in the storage device in the form of: comprising multiple address areas, some of which contain second storage partitions with fixed or non-fixed capacity, and the basic storage units contained in the second storage partition are randomly distributed in the address areas.
7. The partition isolation storage method according to claim 5, wherein: The steps of obtaining the offset between the logical address and the real address of each of the first storage partitions one by one according to the user parameters are specifically as follows: Obtain the number of the address areas; Calculate the number of basic storage units contained in the first storage partition within each of the address regions according to the number of basic storage units contained in the second storage partition; Then the real physical address corresponding to the first storage partition satisfies: The physical address corresponding to the logical address of the first storage partition = the logical address of the first storage partition + the number of basic storage units of the second storage partition × (the logical address of the first storage partition / the number of basic storage units contained in the first storage partition within the address area), The offset is "the number of basic storage units in the second storage partition × (the logical address of the first storage partition / the number of basic storage units contained in the first storage partition within the address area)".
8. A storage device, comprising a host computer, an access device, and a storage unit configured according to the partition isolation storage method according to any one of claims 1 to 7, wherein when the storage unit is connected to the host computer, the content in the non-confidential partition is accessed, and when the storage unit is connected to the host computer through the access device, the content in the confidential partition is accessed, wherein: The control unit of the access device includes: A key unit, a master key stored in the key unit, encrypting and / or decrypting data interaction between the access device and the storage unit; A cryptographic operation module, used for agreeing on and generating a master key stored in the key unit; A first authentication unit, the first authentication unit calls the cryptographic operation module and the second authentication unit of the storage device to perform mutual authentication; A read-write control module, which sends read-write instruction information to the storage unit; The control unit of the storage unit comprises: A command parsing unit, which parses the received access command to obtain request information and address information; The address conversion unit converts the address information to obtain an address corresponding to the request information.
9. The storage device according to claim 8, wherein: The access device also includes a file management unit, which maps data and addresses according to the result of the storage partition arrangement performed by the cryptographic operation unit.
10. The storage device according to claim 8, wherein: The control unit of the storage unit also includes an access detection unit, which receives the control information obtained by the command parsing unit, and performs authentication with the authentication unit of the access device, detects the access request, and activates a self-destruction unit if the current access request is an illegal access. The self-destruction unit is configured to self-destruct the storage device and / or data when a preset condition is met.
11. The storage device according to claim 10, wherein: The control unit of the storage unit further includes a self-destruct unit, and activation of the self-destruct unit is configured to trigger a self-destruct mechanism according to preset conditions, wherein the preset conditions include: Conditions for determining the total power-on time of the device; Conditions for determining the total number of times the device is powered on; A condition for determining the number of authentication times of the authentication unit; And, determining one or a combination of conditions for modifying the behavior of the device unit.
12. The storage device according to claim 11, wherein: The self-destruct unit comprises: A high-voltage power supply circuit and a low-voltage power supply circuit are configured to power the storage device. When the self-destruct unit is not activated, the storage device is powered by the low-voltage power supply circuit. When the self-destruct unit is activated, the storage device switches to the high-voltage power supply circuit.
13. The storage device according to claim 11, wherein: The self-destruct unit is configured to: When the preset condition is met, the address conversion unit in the storage device and / or the file management unit in the access device are self-deleted, or When the preset condition is met, the data pointed to by the address is deleted accordingly according to the instructions of the file management unit and the address conversion unit.
Citation Information
Patent Citations
SSD multi-partition login method based on BIOS security mechanism and storage medium
CN111079106A