Method and system for protecting hard disk information of notebook computer
By designing a laptop hard disk information protection system that integrates hardware and software functions, the problem that the existing technology cannot effectively deal with advanced persistent threats and complex network attacks is solved, and comprehensive protection and security management of hard disk data is achieved, which significantly improves the system's defense capabilities.
Patent Information
- Application Number
- CN202510295487.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-20
AI Technical Summary
Existing laptop hard drive protection measures are unable to effectively respond to advanced persistent threats (APTs), internal data breaches and complex cyber attacks, and lack the ability to dynamically monitor user behavior, real-time data encryption and comprehensive security audits, resulting in sensitive data being vulnerable when facing advanced attack methods.
A laptop hard disk information protection system with integrated hardware and software functions is designed, including data acquisition module, initialization and configuration module, hardware security module, identity authentication module, encryption engine module and security audit module. Through real-time monitoring and acquisition of data, encryption and decryption operations, and multi-factor authentication and security audit, we ensure the confidentiality and integrity of the data.
It realizes comprehensive protection of laptop hard disk data, improves the system's access control security, ensures complete encryption of data during transmission and storage, enhances the detection and management capabilities of security threats, and significantly improves the system's defense capabilities.
Smart Images

Figure CN120180475A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information protection, and specifically provides a method and system for protecting the hard disk information of a notebook computer. Background Art
[0002] With the rapid development of information technology, notebook computers have become an indispensable tool in daily life and work. As the core component for storing personal and enterprise critical data, the security of the hard disk is of utmost importance. However, with the frequent occurrence of data leakage incidents, traditional notebook computer hard disk security protection measures (such as simple password protection and basic encryption technologies) can no longer meet modern security requirements. Therefore, the development of an efficient and reliable notebook computer hard disk information protection system that can not only provide enhanced data encryption but also perform real-time security monitoring and response has become a key technology for protecting sensitive information from unauthorized access and theft.
[0003] Currently, the hard disk protection measures for notebook computers on the market mainly rely on software-level solutions, such as antivirus software and firewalls. Although these measures provide protection to a certain extent, they are unable to cope effectively with advanced persistent threats (APTs), internal data leakage, and complex network attacks. These systems often lack the ability to dynamically monitor user behavior, perform real-time data encryption, and conduct comprehensive security audits, leaving sensitive data vulnerable to advanced attack methods. In addition, these traditional security measures are usually invasive to user operations, which may reduce system performance and user experience.
[0004] The existence of these security flaws is largely due to the fact that early security designs did not fully anticipate the complexity and variability of today's network environment. With the advancement of attackers' technology and the diversification of attack methods, the old security systems have failed to effectively adapt to these changes. For example, systems lacking real-time monitoring and response mechanisms may not be able to detect intrusions or unauthorized data access in a timely manner, resulting in data leakage incidents occurring without being noticed. This delayed response not only increases the risk of data loss but may also lead to damage to the enterprise's reputation and economic losses. Therefore, a notebook computer hard disk information protection system integrating hardware and software functions and capable of providing comprehensive protection is particularly important, as it can enhance data security at multiple levels and effectively prevent and counter modern network threats. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a method and system for protecting the hard disk information of a notebook computer, which solves the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A notebook computer hard disk information protection system, including a data collection module, an initialization and configuration module, a hardware security module, an identity authentication module, an encryption engine module, and a security audit module; The data collection module is used to monitor and record data of various operations within the system, involving user identity authentication, hardware security module operations, and security events, and format and standardize the collected data; The initialization and configuration module is responsible for the initial configuration of the system, including setting security parameters, initializing the hardware security module HSM, and generating and distributing encryption keys; The hardware security module is used to store and manage encryption keys, perform all encryption and decryption operations, provide a physically isolated environment to protect the keys from external access, and ensure the security of critical encryption materials; The identity authentication module uses multi-factor authentication technologies, including passwords and biometric technologies, to verify the identity of accessing users, and only allows users who pass the verification to access hard disk data, improving the security of system access control; The encryption engine module is used to perform real-time encryption and decryption operations on data according to the keys provided by the HSM, ensure the security of data during the reading and writing process, realize full encryption during the data storage and transmission process, and guarantee the confidentiality and integrity of data; The security audit module is used to monitor system operations, record all logs of hard disk access and security events, and implement the detection and response of security events.
[0007] Preferably, the data collection module includes a key management data collection unit, a user authentication related situation collection unit, a system operation data collection unit, and a data processing unit; The key management data collection unit is used for data collection related to key management, including key length KL, encryption algorithm update frequency EAUF, key update frequency KUF, hardware security module access attempt HSMAA, and encryption operation error rate EOER; The user authentication related situation collection unit is used to collect data related to user authentication by adjusting the identity authentication mechanism according to user access control data, including multi-factor authentication usage rate MFAU, number of identity authentication failures AFC, biometric success rate BSR, access control policy update frequency ACPF, and number of unauthorized access attempts UAAC; The system operation data collection unit is used to collect data related to system operation logs, monitor security events and policy violations, and obtain: audit log integrity ALI, audit response time ART, audit coverage AC, security event detection rate SEDR, and number of security policy violations SPVC; The data processing unit is used to format, standardize and preliminarily analyze the collected data, calculate the encryption strength assessment coefficient ESAC, the user access control coefficient UACC and the system audit efficiency coefficient SAEC, and combine the security strength of the encryption operation, user access control and the efficiency of system audit to obtain: the comprehensive security performance index CSPI.
[0008] Preferably, the encryption strength assessment coefficient ESAC is calculated and obtained through the following formula: ; In the formula, α, β, γ, δ and ϵ are weight factors, which are adjusted according to the system security requirements, KL represents the key length, EAUF represents the encryption algorithm update frequency, KUF represents the key update frequency, HSMAA represents the number of access attempts to the hardware security module, and EOER represents the encryption operation error rate; The user access control coefficient UACC is calculated and obtained through the following formula: ; In the formula, ζ, η, θ, ι and κ are weight factors, which are adjusted according to the system security policy, MFAU represents the multi-factor authentication usage rate, AFC represents the number of authentication failures, BSR represents the biometric success rate, ACPF represents the access control policy update frequency, and UAAC represents the number of unauthorized access attempts; The system audit efficiency coefficient SAEC is calculated and obtained through the following formula: ; In the formula, λ, μ, ν, ξ and ο are weight factors, ALI represents the audit log integrity, ART represents the audit response time, AC represents the audit coverage rate, SEDR represents the security event detection rate, and SPVC represents the number of security policy violations; The comprehensive security performance index CSPI is calculated and obtained through the following formula: ; In the formula, w1, w2 and w3 are weight coefficients, which are adjusted according to the influence degree of each coefficient on the system security.
[0009] Preferably, the initialization and configuration module includes a system setting unit, an HSM configuration unit and a key management unit; The system setting unit is used to perform initial settings on the system, including the configuration of the security level, operation parameters and environment, so that all operations are executed within a preset security framework; The HSM configuration unit is used to set the operation parameters of the hardware security module, including the key length and the selection of the encryption algorithm; The key management unit is responsible for the life cycle management of encryption keys, including generation, distribution, update, and revocation, and protecting the keys from unauthorized access.
[0010] Preferably, the hardware security module includes a key storage unit and a key protection unit; The key storage unit is used to securely store encryption keys and other sensitive security information using physical and logical security measures to prevent unauthorized access and key leakage, and to perform all encryption and decryption operations; The key protection unit is used to monitor the security status of the keys, execute key update and revocation policies, and prevent the keys from expiring or continuing to be used when the security level drops.
[0011] Preferably, the authentication module includes a multi-factor authentication unit and an access control unit; The multi-factor authentication unit is used to increase the difficulty for unauthorized users to access the system through a multi-verification mechanism, implement multi-factor authentication including passwords and biometric technologies, manage and maintain user authentication information, including passwords and biometric data, to keep all user authentication information up-to-date; The access control unit is used to control the access rights of users to system resources according to their authentication status, and users with a perfect match can access specific system resources.
[0012] Preferably, the encryption engine module includes an encryption execution unit, a decryption execution unit, and a key scheduling unit; The encryption execution unit is used to encrypt data in real time according to the keys provided by the HSM, ensure that all sensitive data is encrypted before being written to the storage medium, and prevent the data from being stolen in an unencrypted state; The decryption execution unit is used to decrypt the encrypted data so that authorized users can access its content, and only verified users can view the decrypted data; The key scheduling unit is responsible for the scheduling and management of keys during the encryption and decryption processes, including the selection and replacement of keys.
[0013] Preferably, the security audit module includes a response management unit; The response management unit is used to record all detailed logs of hard disk access and security events, analyze the log data, automatically detect security events and suspicious activities, and execute corresponding security measures according to the severity and type of the events, including notifying the administrator, restricting user permissions, or initiating a more in-depth investigation.
[0014] Preferably, the analysis of log data is used to compare the security performance index CSPI with the preset security thresholds A and S to obtain a level evaluation scheme; If the CSPI score < security threshold A, it is considered that the system is at the first security level. Increase the encryption strength, upgrade the encryption algorithm and increase the key length, strengthen the user authentication process, introduce or optimize the multi-factor authentication mechanism, and deploy multi-factor authentication for all sensitive operations, including biometrics and hardware tokens; If security threshold A ≤ CSPI < security threshold S, it is considered that the system is at the second security level. Expand the function of the audit log system, conduct a security audit once every quarter, evaluate the effectiveness of existing security measures, and conduct simulation drills regularly; If CSPI ≥ security threshold S, it is considered that the system is at the third security level. Introduce artificial intelligence and machine learning technologies to enhance threat detection and response capabilities.
[0015] A method for protecting notebook computer hard disk information includes the following steps: Step 1: Monitor and record the data of various operations within the system, involving user authentication, hardware security module operations, and security events, and format and standardize the collected data; Step 2: Initial configuration of the system, including setting security parameters, initial configuration of the hardware security module HSM, and generation and distribution of encryption keys; Step 3: Store and manage encryption keys, perform all encryption and decryption operations, provide a physically isolated environment to protect the keys from external access, and ensure the security of critical encryption materials; Step 4: Use multi-factor authentication technologies, including passwords and biometric technologies, to verify the identity of accessing users, and only allow users who pass the verification to access the hard disk data to improve the security of system access control; Step 5: Perform real-time encryption and decryption operations on the data according to the keys provided by the HSM to ensure the security of the data during the read and write processes, achieve full encryption during the data storage and transmission processes, and ensure the confidentiality and integrity of the data; Step 6: Monitor system operations, record all logs regarding hard disk access and security events, and implement the detection and response of security events.
[0016] The present invention provides a method and system for protecting notebook computer hard disk information, having the following beneficial effects: (1)When the system is running, it monitors and records the data of various operations within the system, formats and standardizes the collected data, stores and manages encryption keys, performs all encryption and decryption operations, provides a physically isolated environment to protect the keys from external access, uses multi-factor authentication technology to verify the identity of accessing users, only allows authenticated users to access the hard disk data, improves the access control security of the system, performs real-time encryption and decryption operations on the data according to the keys provided by the HSM, ensures the security of the data during the reading and writing process, realizes full encryption during the data storage and transmission process, guarantees the confidentiality and integrity of the data, monitors the system operations, records all logs regarding hard disk access and security events, and implements the detection and response of security events.
[0017] (2)This laptop hard disk information protection system provides comprehensive data protection and security management through six carefully designed modules. The data collection module can effectively monitor the system operations, ensuring the real-time collection and processing of key information. The initialization and configuration module ensures that a strong security foundation is established from the system startup, including the setting of security parameters and the reasonable distribution of encryption keys. In the hardware security module, the physical isolation storage and management of keys enhance the protection measures, preventing key leakage and unauthorized access. The authentication module uses multi-factor authentication technology, significantly improving the security of access control, while the encryption engine module ensures that the data is always in an encrypted state during transmission and storage, effectively preventing data leakage. Finally, the security audit module enhances the detection and management capabilities of security threats through detailed logging and instant response mechanisms.
[0018] (3)Through the collaborative work of these modules, the system not only completes the basic tasks of real-time data encryption and security monitoring, but also realizes advanced security management and response functions. These functions include dynamic key management, complex user authentication processes, and comprehensive security event analysis and response. Such a design not only protects the security and integrity of the data, but also improves the system's defense capabilities against internal and external threats. These features of the system make it stand out among the existing technologies, providing a secure and easy-to-manage protection solution for laptop users.
[0019] (4)Compared with traditional security measures, the system brings significant improvements in multiple aspects. First, the dynamic and multi-level security policies ensure a higher level of protection and can adapt to the evolution of various threats. Second, the system's real-time monitoring and response capabilities greatly reduce the impact of potential risks and prevent possible security events in advance. In addition, through integrated security management, the system simplifies complex security operations, enhances the user experience, and reduces the cost and complexity of security management. These advantages ultimately enable laptop users to maintain the security and privacy of their data in an increasingly complex security threat environment, ensuring the confidentiality and integrity of the information. Brief Description of the Drawings
[0020] Figure 1 It is a block diagram of a notebook computer hard disk information protection system according to the present invention; Figure 2 It is a schematic diagram of the steps of a notebook computer hard disk information protection method according to the present invention; Figure 3 It is a line chart for comparing thresholds of a notebook computer hard disk information protection system according to the present invention. Detailed Embodiments
[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0022] Embodiment 1 The present invention provides a notebook computer hard disk information protection system. Please refer to Figure 1 and includes a data acquisition module, an initialization and configuration module, a hardware security module, an identity authentication module, an encryption engine module, and a security audit module; The data acquisition module is used to monitor and record data of various operations within the system, involving user identity authentication, hardware security module operations, and security events, and format and standardize the collected data; The initialization and configuration module is responsible for the initial configuration of the system, including setting security parameters, initializing the hardware security module HSM, and generating and distributing encryption keys; The hardware security module is used to store and manage encryption keys, perform all encryption and decryption operations, provide a physically isolated environment to protect the keys from external access, and ensure the security of critical encryption materials; The identity authentication module uses multi-factor identity authentication technologies, including passwords and biometric technologies, to verify the identity of accessing users, and only allows users who pass the verification to access the hard disk data, improving the access control security of the system; The encryption engine module is used to perform real-time encryption and decryption operations on data according to the keys provided by the HSM, ensure the security of data during reading and writing, and achieve full encryption during data storage and transmission, protecting the confidentiality and integrity of data; The security audit module is used to monitor system operations, record all logs related to hard disk access and security events, and implement the detection and response of security events.
[0023] In this embodiment, by monitoring and recording data of various operations within the system, which involve user authentication, hardware security module operations, and security events, the collected data is formatted and standardized. The initial configuration of the system includes setting security parameters, initial configuration of the hardware security module (HSM), and generation and distribution of encryption keys. Encryption keys are stored and managed, and all encryption and decryption operations are performed. A physically isolated environment is provided to protect the keys from external access, ensuring the security of critical encryption materials. Multi-factor authentication technologies, including passwords and biometric technologies, are used to verify the identity of accessing users, and only authenticated users are allowed to access hard disk data, improving the access control security of the system. Real-time encryption and decryption operations of data are performed based on the keys provided by the HSM to ensure the security of data during the read and write processes, achieving full encryption during data storage and transmission, and protecting the confidentiality and integrity of data. The system operations are monitored, and all logs related to hard disk access and security events are recorded to implement detection and response to security events.
[0024] Embodiment 2 This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The data acquisition module includes a key management data acquisition unit, a user authentication-related situation acquisition unit, a system operation data acquisition unit, and a data processing unit; The key management data acquisition unit is used for data acquisition related to key management, including key length (KL), encryption algorithm update frequency (EAUF), key update frequency (KUF), hardware security module access attempts (HSMAA), and encryption operation error rate (EOER); The user authentication-related situation acquisition unit is used to adjust the authentication mechanism according to user access control data and acquire data related to user authentication, including multi-factor authentication usage rate (MFAU), number of authentication failures (AFC), biometric success rate (BSR), access control policy update frequency (ACPF), and number of unauthorized access attempts (UAAC); The system operation data acquisition unit is used to acquire data related to system operation logs, monitor security events and policy violations, and obtain: audit log integrity (ALI), audit response time (ART), audit coverage (AC), security event detection rate (SEDR), and number of security policy violations (SPVC); The data processing unit is used to format, standardize, and preliminarily analyze the collected data, calculate the encryption strength evaluation coefficient (ESAC), user access control coefficient (UACC), and system audit efficiency coefficient (SAEC), and combine the security strength of encryption operations, user access control, and the efficiency of system audit to obtain: comprehensive security performance index (CSPI).
[0025] The encryption strength evaluation coefficient ESAC is calculated and obtained through the following formula: ; Wherein, α, β, γ, δ, and ϵ are weighting factors, adjusted according to system security requirements, KL represents the key length, EAUF represents the encryption algorithm update frequency, KUF represents the key update frequency, HSMAA represents the number of hardware security module access attempts, and EOER represents the encryption operation error rate; The user access control coefficient UACC is calculated through the following formula: ; Wherein, ζ, η, θ, ι, and κ are weighting factors, adjusted according to system security policies, MFAU represents the multi-factor authentication usage rate, AFC represents the number of authentication failures, BSR represents the biometric success rate, ACPF represents the access control policy update frequency, and UAAC represents the number of unauthorized access attempts; The system audit efficiency coefficient SAEC is calculated through the following formula: ; Wherein, λ, μ, ν, ξ, and ο are weighting factors, ALI represents the audit log integrity, ART represents the audit response time, AC represents the audit coverage rate, SEDR represents the security event detection rate, and SPVC represents the number of security policy violations; The comprehensive security performance index CSPI is calculated through the following formula: ; Wherein, w1, w2, and w3 are weighting coefficients, adjusted according to the influence degree of each coefficient on system security.
[0026] In this embodiment, through a carefully designed data acquisition module, this laptop hard disk information protection system can comprehensively monitor and analyze key security data, from key management to user authentication, and then to every link of system operation. The system can not only identify and respond to potential security threats in a timely manner, but also dynamically adjust security measures through real-time data analysis, thereby significantly improving the overall security protection level. By calculating the encryption strength assessment coefficient ESAC, the user access control coefficient UACC, and the system audit efficiency coefficient SAEC, and then integrating them into the comprehensive security performance index CSPI, the system provides a quantitative tool for managers to evaluate and optimize security policies, ensure the security of sensitive data under various threats, and thus achieves the effect of enhancing the system's protection ability and response speed.
[0027] Embodiment 3 This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The initialization and configuration module includes a system setting unit, an HSM configuration unit, and a key management unit; The system setup unit is used to perform initial setup of the system, including configuration of security levels, operation parameters, and environment, ensuring that all operations are executed within a preset security framework; The HSM configuration unit is used to set the operation parameters of the hardware security module, including key length and encryption algorithm selection; The key management unit is responsible for the lifecycle management of encryption keys, including generation, distribution, update, and revocation, protecting the keys from unauthorized access.
[0028] The hardware security module includes a key storage unit and a key protection unit; The key storage unit is used to securely store encryption keys and other sensitive security information using physical and logical security measures to prevent unauthorized access and key leakage, and to perform all encryption and decryption operations; The key protection unit is used to monitor the security status of keys, execute key update and revocation policies, and prevent keys from expiring or continuing to be used when security degrades.
[0029] The authentication module includes a multi-factor authentication unit and an access control unit; The multi-factor authentication unit is used to increase the difficulty of unauthorized users accessing the system through a multi-verification mechanism, implement multi-factor authentication including passwords and biometric technologies, manage and maintain user authentication information, including passwords and biometric data, ensuring that all user authentication information is up-to-date; The access control unit is used to control a user's access rights to system resources based on their authentication status, allowing fully authenticated users to access specific system resources.
[0030] In this embodiment, the integrated design and functional implementation of the initialization and configuration module, the hardware security module, and the authentication module provide users with a high level of security protection and data protection. Through the precise configuration of the system setup unit, all operations are ensured to be executed within a strict security framework, effectively preventing security vulnerabilities and configuration errors. The professional management of the HSM configuration unit and the key management unit guarantees the secure storage and lifecycle management of keys, effectively preventing unauthorized access and leakage of keys, while also ensuring the efficiency and security of encryption and decryption operations. In addition, the multi-factor authentication and fine-grained access control mechanisms of the authentication module greatly enhance the system's protection against unauthorized access, ensuring that only authenticated users can access sensitive data and system resources, thus significantly improving the overall security and reliability of the system. These measures work together to form an impregnable security defense line, providing comprehensive protection for the user's data security.
[0031] Example 4 This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1, specifically: The encryption engine module includes an encryption execution unit, a decryption execution unit, and a key scheduling unit; The encryption execution unit is used to encrypt data in real time according to the key provided by the HSM, ensuring that all sensitive data is encrypted before being written to the storage medium to prevent the data from being stolen in an unencrypted state; The decryption execution unit is used to decrypt the encrypted data, enabling authorized users to access its content, and only verified users can view the decrypted data; The key scheduling unit is responsible for the scheduling and management of keys during the encryption and decryption processes, including the selection and replacement of keys.
[0032] The security audit module includes a response management unit; The response management unit is used to record detailed logs of all hard disk access and security events, analyze the log data, detect security events and suspicious activities automatically, and execute corresponding security measures according to the severity and type of the events, including notifying the administrator, restricting user permissions, or initiating a more in-depth investigation.
[0033] Analyzing the log data is used to compare the security performance index CSPI with the preset security thresholds A and S to obtain a level evaluation scheme; If the score of CSPI < security threshold A, it is considered that the system is in the first security level. Increase the encryption intensity, upgrade the encryption algorithm and increase the key length, implement end-to-end encryption to ensure that the data is protected during transmission and in the static state, strengthen the user authentication process, introduce or optimize the multi-factor authentication mechanism, deploy multi-factor authentication for all sensitive operations, including biometrics and hardware tokens, real-time behavior monitoring and alerts for abnormal login attempts, ensuring that all sensitive operations require advanced authentication; If security threshold A ≤ CSPI < security threshold S, it is considered that the system is in the second security level. Expand the functions of the audit log system, including performing time series analysis on all accesses and operations, using advanced pattern recognition techniques to predict potential internal threats, conducting a security audit quarterly, evaluating the effectiveness of existing security measures, and conducting regular simulation drills; If CSPI ≥ security threshold S, it is considered that the system is in the third security level. Use AI and machine learning technologies not only for threat detection but also to implement an automated security response system that can make decisions and execute protection measures in milliseconds, deploy advanced user and entity behavior analysis UEBA tools, and use machine learning to identify potential threats found from minor behaviors.
[0034] In this embodiment, the collaborative work of the encryption engine module and the security audit module brings significant security benefits to the notebook computer hard disk information protection system. The encryption execution unit and the decryption execution unit ensure that all sensitive data remains encrypted during storage and transmission, effectively preventing the risks of data leakage and unauthorized access. The key scheduling unit ensures the security and reliability of the encryption process by efficiently managing the key lifecycle. At the same time, the security audit module enhances the ability to identify and respond to potential security threats by detailed recording and analysis of all system activities through its response management unit. By implementing automated security event monitoring and response strategies, the system can quickly respond to security events and reduce potential damages. In addition, by comparing with the preset security thresholds A and S, the system can automatically evaluate its security level, further guiding the administrator to take appropriate security enhancement measures, such as upgrading the encryption algorithm, expanding the audit function, or introducing advanced artificial intelligence technologies. These measures work together to greatly improve the overall security of the system, ensure the integrity and confidentiality of data, and at the same time enhance the management efficiency and user trust.
[0035] Embodiment 5 A method for protecting notebook computer hard disk information, please refer to Figure 2 , specifically: including the following steps: Step 1: Monitor and record the data of various operations within the system, involving user authentication, hardware security module operations, and security events, and perform formatting and standardization processing on the collected data; Step 2: Initial configuration of the system, including setting security parameters, initial configuration of the hardware security module HSM, and generation and distribution of encryption keys; Step 3: Store and manage encryption keys, execute all encryption and decryption operations, provide a physically isolated environment to protect the keys from external access, and ensure the security of critical encryption materials; Step 4: Use multi-factor authentication technologies, including passwords and biometric technologies, to verify the identity of accessing users, and only allow authenticated users to access hard disk data to improve the access control security of the system; Step 5: Perform real-time encryption and decryption operations on data according to the keys provided by the HSM to ensure the security of data during reading and writing, achieve full encryption during data storage and transmission, and guarantee the confidentiality and integrity of data; Step 6: Monitor system operations, record all logs of hard disk access and security events, and implement detection and response to security events.
[0036] In this embodiment, through six rigorous implementation steps, comprehensive and in-depth protection is provided for data security. First, by continuously monitoring and recording all operations within the system, the system can collect key data in real time and perform necessary processing, which provides a solid data foundation for security analysis and immediate response. During the initial configuration phase of the system, by setting high security standards and precisely configuring the Hardware Security Module (HSM), the system ensures comprehensive security control from the lowest level to the highest level. Meanwhile, the secure generation and distribution of keys further enhance the reliability of data encryption. In addition, the application of multi-factor authentication technology significantly improves the security level of access control, ensuring that only strictly authenticated users can access sensitive data. The real-time operation of the encryption execution unit guarantees the security status of data at any moment, preventing potential leakage during transmission or storage. Finally, through effective monitoring and recording of system operations, combined with rapid and effective security event detection and response, the system can not only prevent the occurrence of security threats but also take measures immediately at the initial stage of problems, greatly reducing potential damage. Generally speaking, these steps together build a powerful security protection network, significantly improving the data protection level and the system's defense ability, bringing confidence and guarantee to users and enterprises.
[0037] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A notebook computer hard disk information protection system, characterized in that: It includes data acquisition module, initialization and configuration module, hardware security module, identity authentication module, encryption engine module and security audit module; The data acquisition module is used to monitor and record data from various operations within the system, including user identity authentication, hardware security module operations, and security events, and to format and standardize the collected data; The initialization and configuration module is responsible for the initial configuration of the system, including the setting of security parameters, the initial configuration of the hardware security module HSM, and the generation and distribution of encryption keys; The hardware security module is used to store and manage encryption keys, perform all encryption and decryption operations, and provide a physically isolated environment to protect the keys from external access, ensuring the security of critical encryption materials; The authentication module is used to use multi-factor authentication technology, including passwords and biometrics, to verify the identity of the accessing user, allowing only authenticated users to access the hard disk data, thus improving the access control security of the system; The encryption engine module is used to perform real-time encryption and decryption operations on data according to the key provided by the HSM, ensuring the security of data during reading and writing, achieving complete encryption during data storage and transmission, and protecting the confidentiality and integrity of data; The security audit module is used to monitor system operations, record all logs about hard disk access and security events, and implement security event detection and response.
2. A notebook computer hard disk information protection system according to claim 1, characterized in that: The data collection module includes a key management data collection unit, a user authentication related situation collection unit, a system operation data collection unit and a data processing unit; The key management data collection unit is used to collect data related to key management, including key length KL, encryption algorithm update frequency EAUF, key update frequency KUF, hardware security module access attempt HSMAA and encryption operation error rate EOER; The user authentication related situation collection unit is used to adjust the identity authentication mechanism according to the user access control data and collect the data related to the user authentication, including the multi-factor authentication usage rate MFAU, the number of identity authentication failures AFC, the biometric success rate BSR, the access control policy update frequency ACPF and the number of unauthorized access attempts UAAC; The system operation data collection unit is used to collect data related to the system operation log, monitor security events and policy violations, and obtain: audit log integrity ALI, audit response time ART, audit coverage AC, security event detection rate SEDR and security policy violation count SPVC; The data processing unit is used to format, standardize and preliminarily analyze the collected data, calculate the encryption strength assessment coefficient ESAC, the user access control coefficient UACC and the system audit efficiency coefficient SAEC, and combine the security strength of encryption operations, the efficiency of user access control and system audit to obtain: the comprehensive security performance index CSPI.
3. A notebook computer hard disk information protection system according to claim 2, characterized in that: The encryption strength assessment coefficient ESAC is calculated using the following formula: ; Where α, β, γ, δ, and ϵ are weight factors, which are adjusted according to the system security requirements, KL represents the key length, EAUF represents the encryption algorithm update frequency, KUF represents the key update frequency, HSMAA represents the number of hardware security module access attempts, and EOER represents the encryption operation error rate; The user access control coefficient UACC is calculated using the following formula: ; Where ζ, η, θ, ι and κ are weight factors, which are adjusted according to the system security policy, MFAU represents the multi-factor authentication usage rate, AFC represents the number of identity authentication failures, BSR represents the biometric success rate, ACPF represents the access control policy update frequency, and UAAC represents the number of unauthorized access attempts; The system audit efficiency coefficient SAEC is calculated by the following formula: ; Where λ, μ, ν, ξ and ο are weight factors, ALI represents audit log integrity, ART represents audit response time, AC represents audit coverage, SEDR represents security event detection rate, and SPVC represents the number of security policy violations; The comprehensive safety performance index CSPI is calculated using the following formula: ; Where w1, w2 and w3 are weight coefficients, which are adjusted according to the degree of influence of each coefficient on system security.
4. The notebook computer hard disk information protection system according to claim 1, characterized in that: The initialization and configuration module includes a system setting unit, an HSM configuration unit, and a key management unit; The system setting unit is used to perform initial settings on the system, including the configuration of security level, operating parameters and environment, so that all operations are performed within the preset security framework; The HSM configuration unit is used to set the operating parameters of the hardware security module, including key length and encryption algorithm selection; The key management unit is responsible for the life cycle management of encryption keys, including generation, distribution, update and revocation, and protecting keys from unauthorized access.
5. The notebook computer hard disk information protection system according to claim 1, characterized in that: The hardware security module includes a key storage unit and a key protection unit; The key storage unit is used to securely store encryption keys and other sensitive security information using physical and logical security measures to prevent unauthorized access and key leakage, and to implement all encryption and decryption operations; The key protection unit is used to monitor the security status of the key, implement key update and revocation policies, and prevent the key from expiring or continuing to be used when the security is reduced.
6. The notebook computer hard disk information protection system according to claim 1, characterized in that: The identity authentication module includes a multi-factor authentication unit and an access control unit; The multi-factor authentication unit is used to increase the difficulty of unauthorized users accessing the system through multiple verification mechanisms, implement multi-factor authentication including passwords and biometrics, manage and maintain user authentication information, including passwords and biometric data, and keep all user authentication information up to date; The access control unit is used to control the access rights of users to system resources according to their authentication status. Completely qualified users can access specific system resources.
7. The notebook computer hard disk information protection system according to claim 1, characterized in that: The encryption engine module includes an encryption execution unit, a decryption execution unit and a key scheduling unit; The encryption execution unit is used to encrypt data in real time according to the key provided by the HSM, ensuring that all sensitive data is encrypted before being written to the storage medium to prevent the data from being stolen in an unencrypted state; The decryption execution unit is used to decrypt the encrypted data so that the authorized users can access its content, and only the authenticated users can view the decrypted data; The key scheduling unit is responsible for the scheduling and management of keys during encryption and decryption, including the selection and replacement of keys.
8. The notebook computer hard disk information protection system according to claim 1, characterized in that: The security audit module includes a response management unit; The response management unit is used to record detailed logs of all hard disk access and security events, analyze log data, automatically detect security events and suspicious activities, and perform corresponding security measures based on the severity and type of the event, including notifying administrators, restricting user permissions, or launching a more in-depth investigation.
9. A notebook computer hard disk information protection system according to claim 8, characterized in that: The log data is analyzed to compare the safety performance index CSPI with the preset safety threshold A and safety threshold S to obtain a level assessment scheme; If the CSPI score is less than the security threshold A, the system is considered to be at the first security level, and the encryption strength is increased, the encryption algorithm is upgraded and the key length is increased, the user identity authentication process is strengthened, the multi-factor authentication mechanism is introduced or optimized, and multi-factor authentication is deployed on all sensitive operations, including biometrics and hardware tokens; If the security threshold A≤CSPI<security threshold S, the system is considered to be at the second security level. The function of the audit log system is expanded, a security audit is conducted every quarter to evaluate the effectiveness of existing security measures, and simulation drills are conducted regularly. If CSPI ≥ security threshold S, the system is considered to be at the third security level, and artificial intelligence and machine learning technologies are introduced to enhance threat detection and response capabilities.
10. A method for protecting information on a notebook computer hard disk, characterized in that: The following steps are involved: Step 1: Monitor and record data from various operations within the system, including user authentication, hardware security module operations, and security events, and format and standardize the collected data; Step 2: Initial configuration of the system, including setting of security parameters, initial configuration of the hardware security module HSM, and generation and distribution of encryption keys; Step 3: Store and manage encryption keys, perform all encryption and decryption operations, provide a physically isolated environment to protect keys from external access, and ensure the security of critical encryption materials; Step 4: Use multi-factor authentication technology, including passwords and biometrics, to verify the identity of the accessing user, allowing only authenticated users to access the hard disk data, thus improving the access control security of the system; Step 5: Perform real-time encryption and decryption operations on data based on the key provided by the HSM to ensure data security during the reading and writing process, achieve complete encryption during data storage and transmission, and protect data confidentiality and integrity; Step 6: Monitor system operations, record all logs about hard disk access and security events, and implement security incident detection and response.